Herunterladen Inhalt Inhalt Diese Seite drucken

Belden Hirschmann EAGLE40-03 Referenzhandbuch Seite 561

Hisecos grafische benutzeroberfläche industrial security router
Vorschau ausblenden Andere Handbücher für Hirschmann EAGLE40-03:
Inhaltsverzeichnis

Werbung

3 0 Pa cke t Filt e r
3 0 .1
pa cke t -filt e r
Creation and configuration of Firewall rules.
3 0 .1 .1
pa c k e t -filt e r l3 c om m it
Writes all changes made in the L3 firewall configuration to the device
Mode: Global Config Mode
Privilege Level: Operator
Format: packet-filter l3 commit
3 0 .1 .2
pa c k e t -filt e r l3 de fa ult polic y
Sets the default policy of the L3 and DynFw rule tables
Mode: Global Config Mode
Privilege Level: Operator
Format: packet-filter l3 defaultpolicy <P-1>
Parameter Value
P-1
accept
drop
reject
3 0 .1 .3
pa c k e t -filt e r l3 c he c k sum -va lida t ion
Configures the connection tracking checksum validation in Netfilter
Mode: Global Config Mode
Privilege Level: Operator
Format: packet-filter l3 checksum-validation
no pa c k e t -filt e r l3 c he c k sum -va lida t ion
Disable the option
Mode: Global Config Mode
Privilege Level: Operator
Format: no packet-filter l3 checksum-validation
3 0 .1 .4
pa c k e t -filt e r l3 a ddrule
Adds a rule to the L3 firewall table
Mode: Global Config Mode
Privilege Level: Operator
Format: packet-filter l3 addrule <P-1> <P-2> <P-3> <P-4> <P-5> <P-6> <P-7> <P-8>
[description <P-9>] [profile-index <P-10>]
[description]: Rule description/name for the L3 firewall rule
[profile-index]: Profile index of the DPI profile this rule is assigned to depending on enforcer action. Value
0 no profile this rule is assigned to. You cannot assign the rule to an inactive profile if an active enforcer will
mapping to it.
Parameter Value
P-1
1..2048
string
P-2
string
P-3
string
P-4
P-5
string
P-6
icmp
igmp
ipip
tcp
udp
esp
ah
any
string
P-7
114
Meaning
Accept packets
Drop packets without notification
Drop packets and notify source
Meaning
Rule index
Source IP address/CIDR mask/'any'
Source port/port list with comma/port range with hyphen/'any'
Target IP address/CIDR mask/'any'
Target port/port list with comma/port range with hyphen/'any'
Internet Control Message Protocol
Internet Group Management Protocol
IP-within-IP Encapsulation Protocol
Transmission Control Protocol
User Datagram Protocol
Encapsulating Security Protocol
Authentication Header
Any of the above
Parameters for rule (or 'none')
RM CLI EAGLE40-03
Release 04.1 03/2021

Werbung

Inhaltsverzeichnis
loading

Inhaltsverzeichnis