Avaya BCM 4.0 Networking Průvodce konfigurací Strana 727

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 758
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 726
Appendix D Stateful Packet Filters 727
BCM 4.0 Networking Configuration Guide
Example 2: UDP with DSCP Marking
Setup:
Default rule: Disabled – Pass all
Outbound rules:
Disposition: Mark with DSCP value 0xC0, SA: 10.10.10.0/24, stateful is enabled
Inbound rules:
1 Disposition: Pass, SA: 10.10.10.3/32, stateful is enabled
2 Disposition: Pass, SA: 10.10.10.4/32, stateful is disabled
3 Disposition: Mark with DSCP value 0xA0, SA: 10.10.10.5/32, stateful is enabled
Assumptions: No stateful sessions present to start
Scenario:
Inbound PT: ICMP, SA: 10.10.10.2, DA: 10.10.10.1
ICMP: type 8 (echo request), IID:100, ISEQ: 1
Stateful session with tuple [ICMP, 10.10.10.1,
10.10.10.2, 100, 1] is found and the rule is “pass”
<wait 10 seconds> Stateful session with tuple [ICMP, 10.10.10.1,
10.10.10.2, 100, 1] is deleted
Outbound PT: ICMP, SA: 10.10.10.1, DA: 10.10.10.2
ICMP: type 8 (echo request), IID:101, ISEQ: 1
No stateful session [ICMP, 10.10.10.1, 10.10.10.2,
101, 1]] is found. No user rule is found so the
default rule is used. A stateful session is created
with a disposition to “pass”. “pass”
<wait 10 seconds> Stateful session with tuple [ICMP, 10.10.10.1,
10.10.10.2, 101, 1] is deleted
Inbound PT: ICMP, SA: 10.10.10.2, DA: 10.10.10.1
ICMP: type 8 (echo request), IID:101, ISEQ: 1
No stateful session with tuple [ICMP, 10.10.10.1,
10.10.10.2, 101, 1] is found. An inbound user rule
is found and stateful is enabled. A stateful session
is created with a disposition to “block”.
Inbound PT: ICMP, SA: 10.10.10.2, DA: 10.10.10.1
ICMP: type 8 (echo request), IID:101, ISEQ: 1
Stateful session with tuple [ICMP, 10.10.10.1,
10.10.10.2, 101, 1] is found and the rule is “block”
Table 182 Example 2: UDP with DSCP Marking
Direction IP Datagram Outcome
Outbound PT: UDP, SA: 10.10.10.1, SP: 1000, DA:
10.10.10.2, DP: 1001
No stateful session [UDP, 10.10.10.1, 10.10.10.2,
1000, 1001] is found. An outbound user rule is
found and stateful is enabled. A new stateful
session is created with a disposition to “pass” and
“mark” with DSCP value 0xC0.
Inbound PT: UDP, SA: 10.10.10.2, SP: 1001, DA:
10.10.10.1, DP: 1000
Stateful session with tuple [UDP, 10.10.10.1,
10.10.10.2, 1000, 1001] is found and the rule is
“pass” but no marking takes place inbound
Outbound PT: UDP, SA: 10.10.10.1, SP: 1000, DA:
10.10.10.2, DP: 1001
Stateful session with tuple [UDP, 10.10.10.1,
10.10.10.2, 1000, 1001] found and the rule is
“pass” and “mark” with DSCP value 0xC0
Table 181 Example 1: ICMP (Sheet 2 of 2)
Zobrazit stránku 726
1 2 ... 722 723 724 725 726 727 728 729 730 731 732 ... 757 758

Komentáře k této Příručce

Žádné komentáře