You can select a protocol for filtering from one of the following options:
•
•
•
•
•
•
• Source IP/mask
Destination IP/mask A host IP address or subnetwork IP address in the form: hostIPaddress or networkIPaddress/NN. If you specify a source IP, incoming packets are filtered for the specified IP address. If you specify a destination IP, outgoing packets are filtered for the specified IP address. Input or Output Interface The input or output interface used by the incoming or outgoing packet. Choices are:
• Public 1 (eth0)
• Public 2 (eth1)
• Failover (bond0)
• PCMCIA (eth2)
• PCMCIA (eth3)
•
•
• Any of the options in Filter Options for Packet Filtering Rules can be given the inverted flag, so that the target action is performed on packets that do not match any of the specified criteria. For example, if DROP is the target action, if “Inverted” is specified for a source IP address, and if no other criteria are specified in the rule, any packets arriving from any other source IP address are dropped.