IP filter table
An IP filter is an access policy that determines whether the device forwards or drops IP packets. A filter consists of source and destination IP information and the action to take when a packet matches the values in the filter.
The following objects define IP filters.
|
Name, OID, and syntax |
Access |
Description |
|---|---|---|
| snRtIpFilterTable
brcdIp.1.2.2.3 |
None |
The IP filter table. |
| snRtIpFilterIndex
brcdIp.1.2.2.3.1.1 Syntax: Integer32 |
Read-only |
Shows the index for an entry in the IP filter table. |
| snRtIpFilterAction
brcdIp.1.2.2.3.1.2 Syntax: Integer |
Read-write |
Determines the action to be taken if the IP packet matches this filter: When you configure an IP access policy, the device denies all IP packets by default unless you explicitly permit them. Thus, if you want the device to permit all IP packets except the ones that you filter out, you must configure the last IP access policy to permit all IP packets. |
| snRtIpFilterProtocol
brcdIp.1.2.2.3.1.3 Syntax: Integer |
Read-write |
Specifies the transport protocol that you can filter. Only the traffic for the transport protocol selected will be allowed:
In addition, if you filter TCP or UDP, you can also specify a particular application port (such as “HTTP” or “80”) or a logical expression consisting of an operator and port names or numbers. |
| snRtIpFilterSourceIp
brcdIp.1.2.2.3.1.4 Syntax: IpAddress |
Read-write |
Shows the source IP address. The policy will be applied to packets that come from this IP address. |
| snRtIpFilterSourceMask
brcdIp.1.2.2.3.1.5 Syntax: IpAddress |
Read-write |
Shows the source IP subnet mask. The policy will be applied to packets that come from this subnet mask. |
| snRtIpFilterDestIp
brcdIp.1.2.2.3.1.6 Syntax: IpAddress |
Read-write |
Shows the destination IP address. The IP access policy will be applied to packets that are going to this IP address. |
| snRtIpFilterDestMask
brcdIp.1.2.2.3.1.7 Syntax: IpAddress |
Read-write |
Shows the destination IP subnet mask. The IP access policy will be applied to packets that are going to this subnet mask. |
| snRtIpFilterOperator
brcdIp.1.2.2.3.1.8 Syntax: Integer |
Read-write |
Applies only if the value of the IP filter table object is TCP or UDP. It specifies the type of comparison to be performed to TCP and UDP packets:
|
| snRtIpFilterOperand
brcdIp.1.2.2.3.1.9 Syntax: Integer |
Read-write |
Applies only if the value of the IP filter table object is TCP or UDP. Specifies the TCP or UDP port number that will be used in this filter. Valid values: 0 - 65535. 0 means that this object is not applicable. |
| snRtIpFilterRowStatus
brcdIp.1.2.2.3.1.10 Syntax: Integer |
Read-write |
Controls the management of the table rows. The following values can be written: If the row exists, then a SET with a value of create(4) returns a "bad value" error. Deleted rows are removed from the table immediately. The following values can be returned on reads: |
| snRtIpFilterEstablished
brcdIp.1.2.2.3.1.11 Syntax: Integer |
Read-write |
Applies only to TCP packets. Indicates if the filtering of established TCP packets is enabled for packets that have the ACK or RESET flag on: |
| snRtIpFilterQosPriority
brcdIp.1.2.2.3.1.12 Syntax: Integer |
Read-write |
The router Layer 4 QoS Priority values are: The Priority values are: |