📄 filters.html
字号:
><TTCLASS="COMPUTEROUTPUT">0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Protocols</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">All IP: Y</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Include/Exclude</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">E</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Match opposite</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">Y</TT></TD><TD> </TD></TR></TBODY></TABLE><P></P></DIV><P> You can enter as many parameters as you wish. All of them will be interpreted until the first match is found.</P></DIV><DIVCLASS="SECT3"><H3CLASS="SECT3"><ANAME="AEN1745">Excluding Certain Sites</A></H3><P> Filters follow an implicit "no-match" policy, that is, only packets matching defined rules will be matched, others will be filtered out. This is similar to the access-list policy "whatever is not explicitly permitted is denied". If you want to show all traffic to/from everywhere, except certain places, you can specify the sites you wish to exclude, mark them with <TTCLASS="COMPUTEROUTPUT">E</TT> in the <TTCLASS="COMPUTEROUTPUT">Include/Excludefield</TT>, and define a general catch-all entry with source address<TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT>, mask <TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT>, port <TTCLASS="COMPUTEROUTPUT">0</TT>, and destination<TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT>, mask <TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT>,port <TTCLASS="COMPUTEROUTPUT">0</TT>, tagged with an <TTCLASS="COMPUTEROUTPUT">I</TT>in the <TTCLASS="COMPUTEROUTPUT">Include/Exclude</TT> field as the last entry.</P><P> For example:</P><P>To see all traffic except all SMTP (both directions), Web (both directions), and traffic(only) from 207.0.115.44</P><DIVCLASS="INFORMALTABLE"><ANAME="AEN1760"></A><P></P><TABLEBORDER="0"WIDTH="100%"BGCOLOR="#E0E0E0"CELLSPACING="0"CELLPADDING="4"CLASS="CALSTABLE"><TBODY><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Host name/IP address</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Wildcard mask</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Port</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">25</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Protocols</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">TCP: Y</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Include/Exclude</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">E</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Match opposite</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">Y</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"> </TD><TD> </TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Host name/IP address</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT"> 0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Wildcard mask</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Port</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">80</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Protocols</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">TCP: Y</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Include/Exclude</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">E</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Match opposite</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">Y</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"> </TD><TD> </TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Host name/IP address</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">207.0.115.44</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Wildcard mask</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">255.255.255.255</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Port</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Protocols</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">All IP: Y</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Include/Exclude</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">E</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Match opposite</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">N</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"> </TD><TD> </TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Host name/IP address</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Wildcard mask</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Port</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0</TT></TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">0</TT></TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Protocols</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">All IP: Y</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Include/Exclude</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">I</TT></TD><TD> </TD></TR><TR><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP">Match opposite</TD><TDWIDTH="33%"ALIGN="LEFT"VALIGN="TOP"><TTCLASS="COMPUTEROUTPUT">N</TT></TD><TD> </TD></TR></TBODY></TABLE><P></P></DIV><DIVCLASS="TIP"><P></P><TABLECLASS="TIP"WIDTH="100%"BORDER="0"><TR><TDWIDTH="25"ALIGN="CENTER"VALIGN="TOP"><IMGSRC="./stylesheet-images/tip.gif"HSPACE="5"ALT="Tip"></TD><THALIGN="LEFT"VALIGN="CENTER"><B>Tip</B></TH></TR><TR><TD> </TD><TDALIGN="LEFT"VALIGN="TOP"><P> To filter out all TCP, define a filter with a single entry, with a source of <TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT> mask<TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT> port <TTCLASS="COMPUTEROUTPUT">0</TT>, and a destination of <TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT> mask <TTCLASS="COMPUTEROUTPUT">0.0.0.0</TT>port <TTCLASS="COMPUTEROUTPUT">0</TT>,with the <TTCLASS="COMPUTEROUTPUT">Include/Exclude</TT> field marked <TTCLASS="COMPUTEROUTPUT">E</TT> (exclude). Then apply this filter.</P></TD></TR></TABLE></DIV></DIV></DIV><DIVCLASS="SECT2"><H2CLASS="SECT2"><ANAME="AEN1903">Applying a Filter</A></H2><P> The above steps only add the filter to a defined list. To actually apply the filter, you must select <ICLASS="EMPHASIS">Apply filter...</I> from the menu. You will be presented with a list of filters you already defined. Select the one you want to apply, and press Enter.</P><P> The applied filter stays in effect over exits and restarts of the IPTraf program until it is detached.</P></DIV><DIVCLASS="SECT2"><H2CLASS="SECT2"><ANAME="AEN1908">Editing a Defined Filter</A></H2><P> Select <ICLASS="EMPHASIS">Edit filter...</I> to modify an existing filter. Once you select this option, you will be presented with the list of defined filters. Select the filter you want to edit by moving the selection bar and press Enter.</P><P> Edit the description if you wish. Pressing Ctrl+X at this point will abort the operation, and the filter will remain unmodified. Press Enter to accept any changes to the filter description.</P><P> After pressing Enter, you will see the filter's rules. To edit an existing filter rule, move the selection bar to the desired entry and press Enter. A prefilled dialog box will appear. Edit its contents as desired. Press Enter to accept the changes or Ctrl+X to discard.</P><P> You can add a new filter rule by pressing I to insert at the selection bar's current position. When you press I, you will be presented with a dialog box asking you to enter the new rule data. Pressing A results in a similar operation, except the rule will be appended as the last entry in the rule list.</P><P> Pressing D deletes the currently pointed entry.</P><P> Press X or Ctrl+X to end the edit and save the changes.</P><DIVCLASS="NOTE"><P></P><TABLECLASS="NOTE"WIDTH="100%"BORDER="0"><TR><TDWIDTH="25"ALIGN="CENTER"VALIGN="TOP"><IMGSRC="./stylesheet-images/note.gif"HSPACE="5"ALT="Note"></TD><THALIGN="LEFT"VALIGN="CENTER"><B>Note</B></TH></TR><TR><TD> </TD><TDALIGN="LEFT"VALIGN="TOP"><P>If you're editing the currently applied filter, you will need to re-apply the filter for the changes to take effect. </P></TD></TR></TABLE></DIV><DIVCLASS="NOTE"><P></P><TABLECLASS="NOTE"WIDTH="100%"BORDER="0"><TR><TDWIDTH="25"ALIGN="CENTER"VALIGN="TOP"><IMGSRC="./stylesheet-images/note.gif"HSPACE="5"ALT="Note"></TD><THALIGN="LEFT"VALIGN="CENTER"><B>Note</B></TH></TR><TR><TD> </TD><TDALIGN="LEFT"VALIGN="TOP"><P> Be aware that the filter processes the rules in order. In other words, if a packet matches more than one rule, only the first matching rule is followed.</P></TD></TR></TABLE></DIV></DIV><DIVCLASS="SECT2"><H2CLASS="SECT2"><ANAME="AEN1923">Deleting a Defined Filter</A></H2><P> Select <ICLASS="EMPHASIS">Delete filter...</I> from the menu to remove a filter from the list. Just move the selection bar to the filter you want to delete, and press Enter.</P></DIV><DIVCLASS="SECT2"><H2CLASS="SECT2"><ANAME="AEN1927">Detaching a Filter</A></H2><P> The <ICLASS="EMPHASIS">Detach filter</I> option deactivates the filter currently in use. Selecting this option causes all TCP traffic to be passed to the monitors.</P><P> When you're done with the menu, just select the Exit menu option.</P></DIV></DIV></DIV><DIVCLASS="NAVFOOTER"><HRALIGN="LEFT"WIDTH="100%"><TABLEWIDTH="100%"BORDER="0"CELLPADDING="0"CELLSPACING="0"><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top"><AHREF="morelanmoninfo.html"><<< Previous</A></TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"><AHREF="manual.html">Home</A></TD><TDWIDTH="33%"ALIGN="right"VALIGN="top"><AHREF="nonipfilters.html">Next >>></A></TD></TR><TR><TDWIDTH="33%"ALIGN="left"VALIGN="top">Additional Information</TD><TDWIDTH="34%"ALIGN="center"VALIGN="top"> </TD><TDWIDTH="33%"ALIGN="right"VALIGN="top">ARP, RARP, and other Non-IP Packet Filters</TD></TR></TABLE></DIV></BODY></HTML>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -