Net Optics Smart Filtering Appliance User Manual Page 40

  • Download
  • Add to my manuals
  • Print
  • Page
    / 57
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 39
36
*** Condential - DO NOT Distribute ***
Director
Understand pending and active lters
To understand the actions of lter commands such as ltercommit,lterdiscard,andlterdelete, it is helpful to
visualize the pending lter list and the CAM that holds the active lters.
The previous section explained how the active lters are stored in a CAM, which can be thought of as list of active
lters. These lters, which are actively running in the device, may be referred to as active, running, or committed.
Pending lters, that is, lters that have been dened using lteraddand lterins commands but not yet committed,
are kept in a pending lter list that shadows the CAM. These lters may be referred to as pending or uncommitted. The
following table shows which lter commands affect the pending lter list and which affect the CAM.
Commands apply to
Pending lter list CAM
lter add
lter del
lter discard
lter ins
lter list
lter sync
commit
lter clear
lter commit
lter running
As can be seen from the table, most of the time you work with the contents of the pending lter list. When you have
the lters set up the way you want them in the pending lter list, a commit or ltercommit command transfers the
contents of the pending lter list to the CAM, activating that lter set-up.
A common workow for changing the Director lter conguration might be as follows.
TochangetheDirectorlterconguration:
Pending lter list
Address Filter
CAM
Address Filter
1 n1.1 ip_proto=UDP action=drop
2 n1.1 m.1
Starting stateFigure 39:
Enter 1. lterrunningto view the currently active lters in the CAM.
Net Optics> lter running
001 ip_src=00000000/ffffffff,ip_dst=00000000/ffffffff,ip_proto=0017
l4_src_port=0000,l4_dst_port=0000,vlan=0000,action=1
in_ports=00
002 ip_src=00000000/ffffffff,ip_dst=00000000/ffffffff,ip_proto=0000
l4_src_port=0000,l4_dst_port=0000,vlan=0000,action=3
in_ports=00
redir_ports=12
Net Optics>
Filter running command Figure 40:
Enter 2. ltersync.The contents of the CAM are copied to the pending lter list.
Page view 39
1 2 ... 35 36 37 38 39 40 41 42 43 44 45 ... 56 57

Comments to this Manuals

No comments