
Configuration Examples and Implementation Notes
A-5
9. Click on Done.
You are returned to the protocol-specific Traffic Filter window.
10. Click on Create.
11. In the Create Filter window, enter a name for the filter.
12. Select the template file you just created in the Templates scroll box.
13. Click on OK.
The filter is now applied to the selected interface.
Table A-1. Predefined Criteria, Ranges, and Actions for Example Inbound Traffic Filters
Filtering Goal Criterion to Specify Ranges to Specify Action to Specify Notes
Drop Telnet traffic Criteria➔Add➔IP➔
TCP Frame➔TCP
Destination Port
23
Refer to Table 5-6 in
Chapter 5 for a list
of common TCP
destination port
codes.
Action➔Add➔Drop This filter will not
stop remote users
from establishing a
Telnet session with
the router itself. To
do that, set up a
drop filter on the
synchronous port
with the same
criterion, or create
outbound filters on
the remote links.
Configure a
subset of
allowed Telnet,
TFTP, and FTP
users
Criteria➔Add➔IP
Source Address
Client addresses
(Use dotted decimal
format)
Action➔Add➔
Accept
This strategy works
only if the
destination IP
address is one of
the router’s
interfaces and if the
protocol or well-
known port is
Telnet, TFTP, or
FTP.
Configure a
router to drop
BOOTP requests
from particular
clients
Criteria➔Add➔UDP
Frame➔UDP
Destination Port
MAC addresses of
BOOTP clients
Action➔Add➔Drop
Commenti su questo manuale