pptp的包过滤规则

14.11.3. Packet Filtering Characteristics of PPTP

PPTP negotiation takes place on TCP port 1723. The actual tunnel is based on GRE, which is IP protocol 47, and uses GRE protocol hexadecimal 880B (indicating that the tunneled packets are PPP). GRE is discussed further in Chapter 4, "Packets and Protocols ".

 

Direction

 

 

Source Addr.

 

 

Dest. Addr.

 

 

Protocol

 

 

Source Port

 

 

Dest. Port

 

 

ACK Set

 

 

Notes

 

 

In

 

 

Ext

 

 

Int

 

 

GRE

 

 

[37]

 

 

[37][38]

 

 

Tunnel data, external client to internal server

 

 

Out

 

 

Int

 

 

Ext

 

 

GRE

 

 

[37][37][38]Tunnel reply, internal server to external client

 

 

In

 

 

Ext

 

 

Int

 

 

TCP

 

 

>1023

 

 

1723

 

 

[39]

 

 

Setup request, external client to internal server

 

 

Out

 

 

Int

 

 

Ext

 

 

TCP

 

 

1723

 

 

>1023

 

 

Yes

 

 

Setup response, internal server to external client

 

 

Out

 

 

Int

 

 

Ext

 

 

GRE

 

 

[37][37][38]Tunnel data, internal client to external server

 

 

In

 

 

Ext

 

 

Int

 

 

GRE

 

 

[37][37][38]Tunnel reply, external server to internal client

 

 

Out

 

 

Int

 

 

Ext

 

 

TCP

 

 

>1023

 

 

1723

 

 

[39]

 

 

Setup request, internal client to external server

 

 

In

 

 

Ext

 

 

Int

 

 

TCP

 

 

1723

 

 

>1023

 

 

Yes

 

 

Setup response, external server to internal client

 

 

[37]GRE does not have ports. GRE does have protocol types, and PPTP is protocol type hexadecimal 880B.

 

 

[38]GRE has no ACK equivalent.

 

 

[39]ACK will not be set on the first packet (establishing connection) but will be set on the rest.

参考:http://www.unix.org.ua/orelly/networking_2ndEd/fire/ch14_11.htm

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值