beautypg.com

Table 17-12, Figure 17-15 – H3C Technologies H3C SecBlade IPS Cards User Manual

Page 174

background image

17-17

Figure 17-15 Add a static filtering rule

Table 17-12

describes the operation items for adding a static filtering rule.

Table 17-12 Operation items for adding a static filtering rule

Item

Description

Segment ID

Select the segment to which to add the static filtering rule

Direction

Select the application direction: inbound or outbound.

Source IP

Set the source IP address range to be matched.

Any means all source IP addresses will be matched.

Because the OAA module sends only packets matching a policy application to the
IPS service card, either or both of the Source IP and Destination IP must be
contained in the protected IP address range of the corresponding DDoS policy
application; otherwise, the static filtering rule does not take effect.

Protocol

Protocol to be matched

Action Set

Action set of the static filtering rule

Destination IP

Set the destination IP address range to be matched.

Any means all destination IP addresses will be matched.

Because the OAA module sends only packets matching a policy application to the
IPS service card, either or both of the Source IP and Destination IP must be
contained in the protected IP address range of the corresponding DDoS policy
application; otherwise, the static filtering rule does not take effect.

Status

Set the status of the static filtering rule, enabled or disabled.