Product Info

Table Of Contents
Infinet Wireless: Technical Documentation – InfiMAN Evolution
Operation & Administration – 129
1.
2.
3.
TheMACaddress of the destination station or of the source station.
The figure below illustrates how packets are processed by the filtering mechanism of the router:
There are two classes (sets) of filters - prohibiting (reject) and permitting (accept).
Furthermore, a filter may be applied to all inbound packets or only to packets arriving via a specific interface. Each
received packet is checked against all filters in the order they are put in the set.
The first filter that matches the received packet determines how the packet are treated. If the filter is an accept
filter, the packet is accepted, otherwise it is rejected. If the packet matches no filter in the set, or if the set is empty,
the packet is accepted.
7.3.6.1 Packet filtering rules
Every packet entering a router passes through a set of input filters (blocking filters). The packets accepted by the
input filter set are further processed by theIPlayer of the router kernel. If theIPlayer determines that the packet
should go further and not landing here, it hands the packet to the set of outgoing filters (forwarding filters).
Information on packets rejected by any filter is displayed on the operator’s terminal and the packets themselves are
discarded without any notice to their sender.
A packet, "advancing through" a set of filters, is checked by every filter in the set, from the first one till the end of
the set, or until the first matching filter. The algorithm is the following:
If the filter set is empty, the packet is accepted
Otherwise, the first matching filter decides what to do with the packet. If it is an accept filter, the packet is
accepted. If it’s a reject filter, the packet is rejected (discarded)
If no filter has been found that matches the packet, it is accepted.
7.3.6.2 IPFirewall parameters
In the "IPFirewall parameters" section, you can view theIPFirewall rules that are already created; you can create a
new rule for the current switch group by clicking the «Add Rule» button, or you can permanently remove the rule
from the configuration by clicking the «Remove Rule» button.
IP firewall rule parameter Description
Action Set the action for the rule: permit/deny/pass:
Permit” - the packet is processed by the system
(ignoring other firewall rules)
Deny” - the packet is dropped
Pass” - the packet is passed to the next rule in the list
and logged in the system log (only if the log check box
is marked)
NOTE
The rejected packet are discarded without notification to the sender.