
Configuration Examples and Implementation Notes
A-3
With a drop-all filter specified, higher-precedence accept filters create exceptions
(or “holes”) in the drop-all range. For example, to configure a circuit that only
accepts IP traffic addressed for destination address 192.32.28.55, apply a drop-all
filter and one accept filter, as follows:
Filter Action Rule Nunber Start of Range End of Range
Accept 1 (highest precedence) 192.32.28.55 192.32.28.55
Drop 2 (lower precedence) 0.0.0.0.0 255.255.255.255
Note: Try to create the filters on each interface in order of precedence. The
first filter you create has the highest precedence and a rule number of 1.
Subsequent filters created on the interface have decreasing precedence. Refer
to the section “Changing Filter Precedence” in Chapter 6 (inbound filters) or
Chapter 7 (outbound filters).
Kommentare zu diesen Handbüchern