ELSA Documentation


Rule-table

Use the rule table to combine individual objects into filter rules. The rule table contains the protocol to be filtered, the source objects, the target objects and the required filter action.

The protocol and the source or target objects can contain combined objects and also direct descriptions (e.g. %P6 for TCP).

A close look at the action options reveals that the previously implemented options are reduced to four separate settings. The selection of options is initially limited by an input set for this reason. It contains the following setting options:

Always-filter The packet is always filtered
Connect-filter The packet is filtered if a connection must be established
Internet-filter The packet is filtered if it is sent via the default route or received from it
Accept The packet is always accepted

The rule table has the following structure (with DEFAULT values):

Name Prot. Source Target Action
WINS UDP, TCP anyhost netbios anyhost Internet-filt.

In addition to objects and object descriptions, protocol numbers can be entered directly in the protocol field, i.e. instead of %P6 for TCP, entering the protocol number 6 is sufficient. Objects can also be separated here with commas in addition to '+' and spaces (due to protocol list). A protocol range (separation with '-') can not be specified, however.

Adding the old filters

The previous LAN and WAN filters were added to the rules list as direct descriptions as follows:

LAN-filters

The following table provides an overview of how the old LAN filters are entered into the new rule table. This is demonstrated in the last column using the NetBIOS filter as an example.

Field in rule-table Entry in LAN-filter Replacement in rule-table Example
NetBIOS
Name Idx LAN-Idx LAN-WIN
Prot. ICMP 1 6, 17

TCP 6

UDP 17

T/U 6, 17

All 0
Source S-st. S-end &SS-st. S-end %S137-139

Source %ASource address %A0.0.0.0

Src-netmask %MSrc netmask %M0.0.0.0
Target D-st. D-end %SD-st. D-end %S0-0
Action Type Type (is retained and recoded internally) Always-filter

WAN-filters

The following table provides the corresponding overview for the old WAN filters:

Field in rule-table Entry in WAN-filter Replacement in rule-table
Name Idx WAN-Idx
Prot. ICMP 1

TCP 6

UDP 17

T/U 6,17

All 0
Source S-st. S-end &SS-st. S-end
Target D-st. D-end %SD-st. D-end

Dst-address %ADest

Dst-netmask %MDst-netmask
Action No entry Always-filter


© Copyright 2001, ELSA AG
http://www.elsa.de