Draytek Vigor 2100 Series User Manual page 46

Broadband
Table of Contents

Advertisement

Duplicate to LAN
Branch to other Filter
Set
Log
Direction
Protocol
IP Address
Subnet Mask
Operator, Start Port
and End Port
Keep State
Fragments
40
If you want to log the matched packets to another network device,
check this box to enable it. The MAC Address of the specified
network device or PC is defined in Firewall >>General Setup >>
MAC Address for Logged Packets Duplication.
If the packet matches the filter rule, the next filter rule will branch
to the specified filter set. Select next filter rule to branch from the
drop-down menu.
Check this box to enable the log function. Use the Telnet command
log-f to view the logs.
Set the direction of packet flow. It is for Data Filter only. For the
Call Filter, this setting is not available since Call Filter is only
applied to outgoing traffic.
Specify the protocol(s) which this filter rule will apply to.
Specify the source and destination IP addresses for this filter rule to
apply to. Place the symbol "!" before a specific IP Address will
prevent this rule from being applied to that IP address. To apply the
rule to all IP address, enter any or leave the field blank.
Select the Subnet Mask for the IP Address column for this filter rule
to apply from the drop-down menu.
The operator column specifies the port number settings. If the Start
Port is empty, the Start Port and the End Port column will be
ignored. The filter rule will filter out any port number.
(=) If the End Port is empty, the filter rule will set the port number
to be the value of the Start Port. Otherwise, the port number ranges
between the Start Port and the End Port (including the Start Port
and the End Port).
(!=)If the End Port is empty, the port number is not equal to the
value of the Start Port. Otherwise, this port number is not between
the Start Port and the End Port (including the Start Port and End
Port).
(>) Specify the port number is larger than the Start Port (includes
the Start Port).
(<) Specify the port number is less than the Start Port (includes the
Start Port).
This function should work along with Direction, Protocol, IP address,
Subnet Mask, Operator, Start Port and End Port settings. It is used
for Data Filter only.
Keep State is in the same nature of modern term Stateful Packet
Inspection. It tracks packets, and accept the packets with appropriate
characteristics showing its state is legal as the protocol defines. It
will deny unsolicited incoming data. You may select protocols from
any, TCP, UDP, TCP/UDP, ICMP and IGMP.
Specify the action for fragmented packets. And it is used for Data
Filter only.
Don't care -No action will be taken towards fragmented packets.
Unfragmented -Apply the rule to unfragmented packets.
Fragmented - Apply the rule to fragmented packets.
Too Short - Apply the rule only to packets that are too short to contain
a complete header.
Vigor2100 Series User's Guide

Advertisement

Table of Contents
loading

This manual is also suitable for:

Vigor2100vVigor2100vgVigor2100g

Table of Contents