Differences

This shows you the differences between two versions of the page.

firewall:syntax [2010/11/04 14:07]
tibor
firewall:syntax [2015/02/25 11:04] (current)
mats
Line 22: Line 22:
===== Packet processing pipeline ===== ===== Packet processing pipeline =====
-{{:firewall:setup_rules.gif|Pipeline schematics}}+{{ :firewall:setup_rules.gif|Pipeline schematics}}
Incoming packets on an interface are first checked for validity using a predefined set of checks. After that fragments are handled specifically. The first user controlled filtering stage is the supervisor rule set. Supervisor rules are often used as a coarse filter to get rid of unwanted traffic. An example of this is the so-called "spoof protection", which makes sure that an incoming package comes from a valid IP address range. Incoming packets on an interface are first checked for validity using a predefined set of checks. After that fragments are handled specifically. The first user controlled filtering stage is the supervisor rule set. Supervisor rules are often used as a coarse filter to get rid of unwanted traffic. An example of this is the so-called "spoof protection", which makes sure that an incoming package comes from a valid IP address range.
Line 222: Line 222:
^ Pre-processor parameters ^ Description ^ ^ Pre-processor parameters ^ Description ^
-| $(net.et1.ip=) | IP address of the et1 interface | +| $(net.if.ip=[et1]) | IP address of the et1 interface | 
-| $(net.et2.ip=) | IP address of the et2 interface | +| $(net.if.ip=[et2]) | IP address of the et2 interface | 
-| $(net.usb.ip=) | IP address of the USB interface | +| $(net.if.mask=[et1]) | Subnet Mask of the et1 interface | 
-| $(net.et1.mask=) | Subnet Mask of the et1 interface | +| $(net.if.mask=[et2]) | Subnet Mask of the et2 interface |
-| $(net.et2.mask=) | Subnet Mask of the et2 interface | +
-| $(net.usb.mask=) | Subnet Mask of the USB interface |+
firewall/syntax.1288876030.txt.gz · Last modified: 2010/11/04 14:07 by tibor
CC Attribution-Noncommercial-Share Alike 3.0 Unported
www.chimeric.de Valid CSS Driven by DokuWiki do yourself a favour and use a real browser - get firefox!! Recent changes RSS feed Valid XHTML 1.0