Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| en:dpi:dpi_options:opt_filtration:filtration_ctrl:start [2023/11/27 15:06] – elena.krasnobryzh | en:dpi:dpi_options:opt_filtration:filtration_ctrl:start [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== Management ====== | ||
| - | {{indexmenu_n> | ||
| - | In order to filter a traffic of some particular subscribers, | ||
| - | |||
| - | < | ||
| - | |||
| - | As a result, this service is configured on level of individual subscribers by [[en: | ||
| - | |||
| - | Instruction format: | ||
| - | < | ||
| - | fdpi_ctrl command --service 4 [IP_list] | ||
| - | </ | ||
| - | <note important> | ||
| - | |||
| - | <note tip>When the service is activated, only TCP traffic is blocked. To block UDP traffic as well, you must [[en: | ||
| - | |||
| - | Examples: | ||
| - | |||
| - | Activate the service for all subscribers and switch filtering off for an administrator: | ||
| - | < | ||
| - | fdpi_ctrl load --service 4 --cidr 192.168.0.0/ | ||
| - | fdpi_ctrl del --service 4 --ip 192.168.0.1 | ||
| - | </ | ||
| - | |||
| - | Enable the service for an independent system AS50538: | ||
| - | < | ||
| - | fdpi_ctrl load --service 4 --cidr 37.110.240.0/ | ||
| - | </ | ||
| - | |||
| - | Creating named profile and activating it to several subcribers | ||
| - | < | ||
| - | fdpi_ctrl load profile --service 4  --profile.name test_black --profile.json '{ " | ||
| - | fdpi_ctrl load --service 4 --profile_name test_black --ip 192.168.0.1 | ||
| - | fdpi_ctrl load --service 4 --profile_name test_black --ip 192.168.0.2 | ||
| - | </ | ||
| - | here\\ | ||
| - | in json format sets folowing profiles' | ||
| - | redirect - web page to redirect to\\ | ||
| - | federal : 0/1/2/etc. using local athorities blacklist\\  | ||
| - | url_list - URL blacklist\\  | ||
| - | ip_list - IP: | ||
| - | cn_list - Common Name blacklist | ||
| - | |||
| - | Blacklist can be loaded from external source, like " | ||
| - | |||
| - | Searching subscribers with named profile: | ||
| - | < | ||
| - | fdpi_ctrl list all --service 4 --profile.name test_black</ | ||
| - | |||
| - | Deleting subscribers with named profile (the named profile has no subscribers using it) | ||
| - | < | ||
| - | fdpi_ctrl del profile --service 4 --profile.name test_black | ||
| - | </ | ||
| - | |||
| - | Changing parameters of named profile (new settings apply to all subscribers with the named profile) | ||
| - | < | ||
| - | fdpi_ctrl load profile --service 4 --profile.name test_black --profile.json '{ " | ||
| - | </ | ||
| - | |||
| - | Maximum number of profiles for blacklist service is configuerd by a parameter in / | ||
| - | < | ||
| - | max_profiles_black_list=64 | ||
| - | </ | ||
| - | here\\ | ||
| - | 64 default value, 65535 maximum value\\ | ||
| - | <note warning> | ||
| - | |||
| - | =====Activation of IPv6 traffic blocking service===== | ||
| - | Instruction format: | ||
| - | <code bash> | ||
| - | fdpi_ctrl команда --service 49 [options list] [list_IP or login] | ||
| - | </ | ||
| - | <note important> | ||
| - | |||
| - | Activate the service: | ||
| - | <code bash> | ||
| - | fdpi_ctrl load --service 49 --login DEMO | ||
| - | </ | ||
| - | or | ||
| - | <code bash> | ||
| - | fdpi_ctrl load --service 49 --vchannel 1 | ||
| - | </ | ||
| - | |||
| - | <note tip>When the service is activated, only TCP traffic is blocked. To block UDP traffic as well, you must [[en: | ||
| - | |||
| - | ===== Configuring TCP and UDP protocol blocking ===== | ||
| - | The '' | ||
| - | |||
| - | To start blocking UDP protocols (e.g. QUIC), it is necessary to add the '' | ||
| - | <code bash> | ||
| - | udp_block=3 | ||
| - | </ | ||
| - | |||
| - | Adding a parameter does not require a DPI restart, just a reload: | ||
| - | <code bash> | ||
| - | service fastdpi reload | ||
| - | </ | ||