Filtering incoming and outgoing data

You can create filters to be associated with a mobile network interface (MNI) to control data access to and from all IP-attached clients.

When filters are associated with a mobile network interface (MNI), the filters help to control data exchanges with IP-attached clients. To create a filter, right-click the organizational unit (OU) in which you want to add the filter, clickAdd Resource > Filter, and then select the filter type.

Filtering can be used to screen out the ping command that is used to test a connection or prevent unsolicited broadcast messages.

Filtering criteria depends on packet type. You can create filters for four types of packets: transmission control protocol (TCP), user diagram protocol (UDP), Internet control message protocol (ICMP), and other.

For all types of filters, you can specify to:
  • Filter data from a single IP address or from a group (subnet) or IP addresses
  • Filter data to a single IP address or to a group (subnet) or IP addresses
  • Filter data only when the packet is going to a SafeLinx Client or coming from a SafeLinx Client.
  • Block or pass data through negative or positive packets that match the defined filter.
The following table describes more filtering criteria that you can specify according to the type of packet that is received by the SafeLinx Server:
Filter type Filter criteria
TCP packets

You can qualify the filter according to the port used by the originator or the receiver of the packet.

You can select a specific flag within the packet header to further qualify the filter.
Note: Flags should only be used by protocol experts who require this level of differentiation for a special purpose.
UDP packets You can qualify the filter according to the port used by the originator or the receiver of the packet.
ICMP packets You can qualify the filter according to a specific type of ICMP packet. For some specific ICMP packets, you can further qualify according to the code that applies to the packet.
Other packets You can qualify the filter according to a specific type of IP-protocol. Specify a search for a specific character string within the packet header.

Filters that work together can be put into groups. Default groups of ICMP filters are provided at installation.