
Configuring Topologies
Exception Filtering
SCALANCE WLC711
4-12 C79000-G8976-C260-03, 07/2012, User Guide, V8.11
Note:
An interface for which Allow Management is enabled, can be reached by any other interface. By default,
Allow Management is disabled and shipped interface filters will only permit the interface to be visible directly
from it's own subnet.
The visible exception filter definitions, both in physical ports and topology definitions, allow
administrators to define a set of rules to be prepended to the system's dynamically updated
exception filter protection rules. Rule evaluation is performed top to bottom, until an exact match
is determined. Therefore, these user-defined rules are evaluated before the system’s own
generated rules. As such, these user-defined rules may inadvertently create security lapses in the
system's protection mechanism or create a scenario that filters out packets that are required by the
system.
Note:
Use exception filters only if absolutely necessary. Siemens recommends that you avoid defining general allow
all or deny all rule definitions since those definitions can easily be too liberal or too restrictive to all types of
traffic.
The exception rules are evaluated in the context of referring to the specific controller's interface.
The destination address for the filter rule definition is typically defined as the interface's own IP
address. The port number for the filter definition corresponds to the target (destination) port
number for the applicable service running on the controller's management plane.
The exception filter on an topology applies only to the packets directed to the controller and can
be applied to the destination portion of the packet, or to the source portion of the packet when
filtering is enabled. Traffic to a specified IP address and IP port is either allowed or denied.
Adding exception filtering rules allows network administrators to either tighten or relax the built-
in filtering that automatically drops packets not specifically allowed by filtering rule definitions.
The exception filtering rules can deny access in the event of a DoS attack, or can allow certain
types of management traffic that would otherwise be denied. Typically, Allow Management is
enabled.
To Define Exception Filters:
1. On the Topologies page, click the Exception Filters tab.
Kommentare zu diesen Handbüchern