Wireless LAN – WLAN
BAT54-Rail/F..
Release
7.54
06/08
3.5
Extended WLAN protocol filters
89
D Redirect: The packet is forwarded on, albeit with changed destination
IP address and target MAC address.
D Interface list: List of the interfaces to which the filter applies.
All of the LAN interfaces, DMZ interfaces, logical WLAN networks and
point-to-point connections in the WLAN may be entered as interfaces.
The following examples illustrate how interfaces are specified: 'LAN-1'
for the first LAN interface, 'WLAN-2-3' for the third logical WLAN network
on the second physical WLAN interface, 'P2P-1-2' for the second point-
to-point connection on the first physical WLAN interface.
Groups of interfaces may be specified in the form 'WLAN-1-1~WLAN-1-
6' (logical WLANs 1 to 6 on the first physical WLAN interface) or with a
wildcard as 'P2P-1-*' (all P2P connections on the first physical interface).
Note: Only filter rules with valid entries in the interface list are active. A rule
with no specification of the interfaces does not apply to all of them - it is
ignored instead.
D Redirect IP address: Destination IP address for the "Redirect" action
On redirection, the destination IP address of the packets is replaced by
the Redirect IP address entered here. Furthermore, the destination MAC
address is replaced by the MAC address determined using ARP for the
Redirect IP address.
Note: If ARP was unable to determine the destination MAC address, the
packet is dropped rather than redirected.
Example:
ARP, DHCP, ICMP are allowed to pass, Telnet and HTTP are redirected to
192.168.11.5 and all other packets are rejected.
Name DHCP
source
MAC:
Destina-
tion MAC
address.
Prot. IP
address
IP net-
work:
Sub-
type
Start
port
End
port
Inter-
face list
Action Redirect
IP
address
ARP irrele-
vant
00000000
0000
0806 0.0.0.0 0.0.0.0 0 0 0 WLAN-
1-2
Pass 0.0.0.0
DHCP irrele-
vant
00000000
0000
0800 0.0.0.0 0.0.0.0 17 67 68 WLAN-
1-2
Pass 0.0.0.0
TEL-
NET
irrele-
vant
00000000
0000
0800 0.0.0.0 0.0.0.0 6 23 23 WLAN-
1-2
Redirect 192.168.1
1.5
ICMP irrele-
vant
00000000
0000
0800 0.0.0.0 0.0.0.0 1 0 0 WLAN-
1-2
Pass 0.0.0.0
HTTP irrele-
vant
00000000
0000
0800 0.0.0.0 0.0.0.0 6 80 80 WLAN-
1-2
Redirect 192.168.1
1.5