TOPIC
This article describes how to use the TCP Filter Admin program to control access to the ASIP 6.1 server. It includes the following sections:
DISCUSSION
What is TCP Filtering? TCP/IP Filters allow the server administrator to restrict access to TCP services running on the ASIP server by port number, by IP address of the client, or a combination of both. This powerful feature allows the administrator a great deal of flexibility in offering services and providing extra security. Here are some examples of how an administrator could filter services on the ASIP server:
TCP/IP Filtering includes a TCP Filter Admin program which is used to create the filters (like other ASIP administration programs, launching the TCP/IP Admin program requires the admin name & password). The other components are extensions which interpret the filters created and allow or deny services accordingly.
Figure 1 , TCP Filter folder contents
Hardware
The TCP/IP Filtering extension module verifies all incoming TCP/IP packets and the admin application is used for configuring the TCP filters for each TCP/IP port. The initial state is off and thus by default all TCP/IP packets are accepted. How it works TCP/IP Filters may be defined for individual ports on the server or as server-wide filters that apply to "All ports" on the server machine. When a packet comes in, the software first checks to see if there is a filter that applies to that particular port. If more than one filter has been defined for that port, it will then check the IP address field, and use the filter that most closely matches the sender's IP address.
If no filter exists for that specific port, then it will look for the "All Ports" filters, and again, apply the one that most closely matches the sender's IP address.
TCP Filtering is installed on the server machine in the "off " or disabled state which means that there are no restrictions on incoming TCP/IP packets after installation. The administrator must enable TCP Filtering and restart the server before any filters can be operational; he should at this time also choose the Default filter state. The Default filter may be set to "Deny All" clients not specifically allowed by another filter or "Allow All" clients if not specifically denied by another filter. The initial state of the Default filter is "Deny All". After enabling TCP Filtering, the Default filter state should be either changed to "allow all", or supplemented by adding new filters.
Figure 2 , TCP Filter List
Services or Port numbers When adding TCP filters, you may choose a service or a well-known TCP port number from the Port pop-up menu or you may type in any valid port number for which to define filters (port number only; no text). In addition, you may choose the "All ports" designation from the Port pop-up menu to apply the filter to all services running on the server system. These are the ports that map to services offered by AppleShare IP 6.x:
Figure 3 , All Ports pop-up menu
Three wildcard characters are always assumed. If the administrator has specified only one or two wildcard characters for an individual byte of the address, the user interface will expand the wildcard character(s) to three. The following is the appropriate wildcard interpretation within individual bytes:
Access Type Filters may Allow or Deny access to ports on your servers. The initial Default of the TCP Filter is that all incoming packets are denied so you must add Allow filters after enabling filtering, to provide client access to your server.
The interpretation of the filters is not order dependent; in fact, the filters are sorted in order by port, with "All Ports" appearing first, and other specific port numbers listed numerically. The following examples will clarify how filters are interpreted.
Example 1
: In this case, the administrator wishes to restrict access to the local LANs, but they do want to open mail service to everyone except one particular site, which is a known spammer. He might set up his filters like this:
Figure 4
, Filter set-up for Example 1
Example 2 : The administrator wishes to allow everyone access to everything, but wants to limit access to the IMAP Admin Access port to his own computer.
Figure 5
, Filter set-up for Example 2
Creating, Editing, Duplicating, and Deleting Filters The icons on the toolbar can be used to create, edit, duplicate, and delete filters, respectively:
Figure 6
, Filter toolbar icons: New, Edit, Duplicate, Delete
To add or edit a filter,
Figure 7 , TCP Filter dialog box
When you select "Save" then the filter is added to the list for this port. Selecting "Cancel" will discard this entry or any modification to an existing filter. To duplicate a filter , select it and click the "duplicate" icon in the toolbar; then edit as needed. To delete a filter , select it and click the trash can icon in the toolbar. "Find...' The TCP/IP Filter Admin also lets you do DNS lookups (Find IP Address). Figure 8 , Find IP Address dialog box
For example, if the IP address returned for "marvin.apple.com" is 17.104.104.86, and the server administrator knows that they are using subnet mask 255.255.255.0, then a filter can be created for IP address 17.104.104.***, thus applying not only to marvin.apple.com, but every other client on that network as well.
|
Document Information | |
Product Area: | Apple Software; Communications-Networking |
Category: | AppleShare |
Sub Category: | AppleShare for Mac OS |
Keywords: | kasip |
Copyright © 2000 Apple Computer, Inc. All rights reserved.