9.3.1.16. show advanced-configuration packet-filtering
A - Introduction
The `packet-filtering` command of the `show advanced-configuration` sub-group enables displaying the static packet filtering rules.
Note
Packet filtering is not supported when the MTU > 3000.
B - Prerequisites
User: setup
Dépendances :
the detection engine must be switched off
A network capture interface must be enabled
C - Command
`show advanced-configuration packet-filtering`
D - Procedure to display the flow filtering rules
The command prompt is displayed.
(gcap-cli)
Enter the command
show advanced-configuration packet-filtering
- ValidateThe system displays the result
Current XDP filters: - 0: iface mon1 native vlan 10 - 1: iface mon2 native vlan 1 - 2: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto TCP range 22:22 - 3: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto TCP range 443:443 - 4: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto TCP range 465:465 - 5: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto TCP range 993:993 - 6: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto TCP range 995:995 - 7: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto UDP range 500:500 - 8: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto UDP range 4500:4500 - 9: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto GRE - 10: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto ESP - 11: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto AH - 12: iface mon1 drop vlan 110 prefix 0.0.0.0/0 proto L2TP