TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ----------------------------------------------------------------------------
What I'd like to be able to do is create a filter rule to ignore some protocols other than TCP/ICMP/UDP (eg. IKE) from a point to point perspective, eg ignore all IKE to my VPN termination point but alert me when there is IKE somewhere else.... Cheers Tyson Mitchell, Brian (ISS Atlanta) wrote: >TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to >[EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! >---------------------------------------------------------------------------- > >You are talking about IPUnknownProtocol, right? ARP can't be filtered, >because it is not an IP protocol. The rest of those you mentioned can, just >go to IPUnknownProtocol advanced option, and seperate the protocol numbers >by commas. I hope this helps. > > >-----Original Message----- >From: NGHE/NG, K.M. HENRY (IT-ISD-OOCL/HKG) [mailto:[EMAIL PROTECTED]] >Sent: Thursday, October 18, 2001 11:38 PM >To: [EMAIL PROTECTED] >Subject: How to filter out protocols other than ICMP/TCP/UDP? > > > >TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to >[EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any >problems! >---------------------------------------------------------------------------- > >Hi > >The filter function allows us to filter out some traffic in the network >in the form of TCP(6), UDP(17) and ICMP(1) only. >If I want to filter protocols like ARP(255) , IGP(9), GRE(47), ESP(50) >etc from normal sources in the network, say the routers or VPN gateway, >how can I do that? > >Regards, >Henry Ng > > > >
