Table 17-12, Figure 17-15 – H3C Technologies H3C SecBlade IPS Cards User Manual
Page 174

17-17
Figure 17-15 Add a static filtering rule
describes the operation items for adding a static filtering rule.
Table 17-12 Operation items for adding a static filtering rule
Item
Description
Segment ID
Select the segment to which to add the static filtering rule
Direction
Select the application direction: inbound or outbound.
Source IP
Set the source IP address range to be matched.
Any means all source IP addresses will be matched.
Because the OAA module sends only packets matching a policy application to the
IPS service card, either or both of the Source IP and Destination IP must be
contained in the protected IP address range of the corresponding DDoS policy
application; otherwise, the static filtering rule does not take effect.
Protocol
Protocol to be matched
Action Set
Action set of the static filtering rule
Destination IP
Set the destination IP address range to be matched.
Any means all destination IP addresses will be matched.
Because the OAA module sends only packets matching a policy application to the
IPS service card, either or both of the Source IP and Destination IP must be
contained in the protected IP address range of the corresponding DDoS policy
application; otherwise, the static filtering rule does not take effect.
Status
Set the status of the static filtering rule, enabled or disabled.