Security 12-29
Example 4
Incoming packet has the source address of 200.1.1.104
Since the Source IP Network Address in the Netopia R310 is 01100000, and the source IP address after the
logical AND is 01100000, this rule DOES match and this packet will NOT be passed.
Example 5
Incoming packet has the source address of 200.1.1.96
Since the Source IP Network Address in the Netopia R310 is 01100000, and the source IP address after the
logical AND is 01100000, this rule DOES match and this packet will NOT be passed. This rule masks off a
SINGLE IP address.
Filter Rule: 200.1.1.96 (Source IP Network Address)
255.255.255.240 (Source IP Mask)
Forward = No (What happens on match)
IP Address Binary Representation
200.1.1.104 01101000 (Source address in incoming IP packet)
AND
255.255.255.240 11110000 (Perform the logical AND)
01100000 (Logical AND result)
Filter Rule: 200.1.1.96 (Source IP Network Address)
255.255.255.255 (Source IP Mask)
Forward = No (What happens on match)
IP Address Binary Representation
200.1.1.96 01100000 (Source address in incoming IP packet)
AND
255.255.255.255 11111111 (Perform the logical AND)
01100000 (Logical AND result)