IP filter table

An IP filter is an access policy that determines whether the device forwards or drops IP packets. A filter consists of source and destination IP information and the action to take when a packet matches the values in the filter.

The following objects define IP filters.

Name, OID, and syntax

Access

Description

snRtIpFilterTable

1.3.6.1.4.1.1991.1.2.2.3

None

The IP filter table.

snRtIpFilterIndex

1.3.6.1.4.1.1991.1.2.2.3.1.1

Syntax: Integer32

Read-only

Shows the index for an entry in the IP filter table.

snRtIpFilterAction

1.3.6.1.4.1.1991.1.2.2.3.1.2

Syntax: Integer

Read-write

Determines the action to be taken if the IP packet matches this filter:

  • deny(0)
  • permit(1)
  • qosEnabled(2)

When you configure an IP access policy, the device denies all IP packets by default unless you explicitly permit them. Thus, if you want the device to permit all IP packets except the ones that you filter out, you must configure the last IP access policy to permit all IP packets.

snRtIpFilterProtocol

1.3.6.1.4.1.1991.1.2.2.3.1.3

Syntax: Integer

Read-write

Specifies the transport protocol that you can filter. Only the traffic for the transport protocol selected will be allowed:

  • all(0) - All traffic of the following transport protocols listed is permitted.
  • ICMP(1)
  • IGMP(2)
  • IGRP(88)
  • OSPF(89)
  • TCP(6)
  • UDP(17)

In addition, if you filter TCP or UDP, you can also specify a particular application port (such as “HTTP” or “80”) or a logical expression consisting of an operator and port names or numbers.

snRtIpFilterSourceIp

1.3.6.1.4.1.1991.1.2.2.3.1.4

Syntax: IpAddress

Read-write

Shows the source IP address. The policy will be applied to packets that come from this IP address.

snRtIpFilterSourceMask

1.3.6.1.4.1.1991.1.2.2.3.1.5

Syntax: IpAddress

Read-write

Shows the source IP subnet mask. The policy will be applied to packets that come from this subnet mask.

snRtIpFilterDestIp

1.3.6.1.4.1.1991.1.2.2.3.1.6

Syntax: IpAddress

Read-write

Shows the destination IP address. The IP access policy will be applied to packets that are going to this IP address.

snRtIpFilterDestMask

1.3.6.1.4.1.1991.1.2.2.3.1.7

Syntax: IpAddress

Read-write

Shows the destination IP subnet mask. The IP access policy will be applied to packets that are going to this subnet mask.

snRtIpFilterOperator

1.3.6.1.4.1.1991.1.2.2.3.1.8

Syntax: Integer

Read-write

Applies only if the value of the IP filter table object is TCP or UDP.

It specifies the type of comparison to be performed to TCP and UDP packets:

  • greater(1) - The policy applies to TCP or UDP port numbers that are greater than the value of the IP filter table object.
  • equal(2) - The policy applies to TCP or UDP port numbers that are equal to the value of the IP filter table object.
  • less(3) - The policy applies to TCP or UDP port numbers that are less than the value of the IP filter table object.
  • notEqual(4) - The policy applies to all TCP or UDP port numbers except to those that are equal to the value of the IP filter table object.
snRtIpFilterOperand

1.3.6.1.4.1.1991.1.2.2.3.1.9

Syntax: Integer

Read-write

Applies only if the value of the IP filter table object is TCP or UDP.

Specifies the TCP or UDP port number that will be used in this filter.

Valid values: 0 - 65535. 0 means that this object is not applicable.

snRtIpFilterRowStatus

1.3.6.1.4.1.1991.1.2.2.3.1.10

Syntax: Integer

Read-write

Controls the management of the table rows. The following values can be written:

  • delete(3) - Delete the row.
  • create(4) - Create a new row.
  • modify(5) - Modify an existing row.

If the row exists, then a SET with a value of create(4) returns a "bad value" error. Deleted rows are removed from the table immediately.

The following values can be returned on reads:

  • noSuch(0) - No such row.
  • invalid(1) - Row is inoperative.
  • valid(2) - Row exists and is valid.
snRtIpFilterEstablished

1.3.6.1.4.1.1991.1.2.2.3.1.11

Syntax: Integer

Read-write

Applies only to TCP packets.

Indicates if the filtering of established TCP packets is enabled for packets that have the ACK or RESET flag on:

  • disabled(0)
  • enabled(1)
snRtIpFilterQosPriority

1.3.6.1.4.1.1991.1.2.2.3.1.12

Syntax: Integer

Read-write

The router Layer 4 QoS Priority values are:

  • low(0) - lower priority
  • high(1) - higher priority

The Priority values are:

  • level0(0) - Lower priority
  • level1(1)
  • level2(2)
  • level3(3),
  • level4(4)
  • level5(5)
  • level6(6)
  • level7(7) - Higher priority