User's Manual

Table Of Contents
234 Operation
Chapter 4 - Operation and Administration
4.11.4.10 Filtering Examples
Example 1: Block All Broadcasts Except ARP and PPPoE
To block all broadcasts except ARP and PPPoE, define an L2 Filtering Rule that
includes all other broadcasts. Typically this includes broadcasts with IP
Ethertype. The parameters of this rule will be:
MAC Address: FF-FF-FF-FF-FF-FF
MAC Address Mask: FF-FF-FF-FF-FF-FF
MAC Address Direction: Destination
Ethertype: 800
Assuming the intention is to block this broadcast in both directions, this Filtering
Rule should be included in the L2 Filtering Rules List of both the From Network
Filtering and the From Wireless Filtering. In addition, for both Interfaces the
following configuration should be defined:
Active Rule Type: Layer 2
Admin Status: Enabled
Default Action: Deny
If broadcasts using other Ethertypes except IP, ARP and PPPoE are excepted,
similar Layer 2 Filtering Rules should be defined for these Ethertypes (with the
broadcast MAC Address), and these rules should be added to the applicable Layer
2 Filtering Rules Lists.
Example 2: Block DHCP Server behind SU
To prevent the use of a DHCP server behind an SU, define the following L3/L4
Filtering Rule:
IP Address: Any (empty)
Protocol: 17 (UDP)
Port: 67 (the source port of the DHCP server)