Filter Policies
7705 SAR OS Router Configuration Guide 281
Each filter entry contains:
• match criteria
• an action
Applying Filter Policies
IPv4 filter policies can be applied at:
• the ingress and egress of network IP interfaces
• the ingress of Ethernet and IP pseudowire SAPs, VPLS SAPs, VPRN SAPs, and IES
SAPs
• the ingress of VPLS SDPs (spoke and mesh)
• the ingress of VPRN and IES spoke SDPs
• the ingress of IES in-band management SAPs
• the egress of VPRN and IES SAPs and egress of VPLS SAPs (Ethernet only)
IPv6 filters can be applied at:
• the ingress and egress of Ethernet network interfaces (with null or dot1q
encapsulation)
• the ingress and egress of network interfaces on the 4-port OC3/STM1 Clear Channel
Adapter card (with POS encapsulation)
• the ingress and egress of IES SAPs
MAC filter policies can be applied at the ingress of VPLS SAPs (Ethernet, and ATM on clear
channel OC3 adapter cards) and SDPs (spoke and mesh).
VLAN filters can only be applied to ring ports on the 2-port 10GigE (Ethernet) Adapter card
and 2-port 10GigE (Ethernet) module.
Figure 10 shows the process to create filter policies and apply them to a network interface.
Note: By default, all created filters have a default action of drop (implicit drop). That is, if
none of the entries in the filter match the packet, and a default action is not explicitly
configured by the user, the packet is dropped.