User Guide
DDOC0099-000-AH
DTS1 CSfC
12 - 14
Command Line Interface
© 2020 Curtiss-Wright Defense Solutions
Revision 5.0
12.3.8
fwall
Description
The fwall command is used to determine the configuration of the firewall. This command does not
start or start DTS services, but only allows the firewall to pass or block traffic for them. The default
zone used is the public zone. The default configuration of the firewall is ON. The boot flash needs
to be writeable to make changes to the firewall configuration permanent. There is a way to pass a
user defined command straight through (no error checking) to the underlying firewall-cmd utility.
Syntax
fwall
[
-h
|
--help
|
--version
]
fwall
[
--status
] [
--start
] [
--stop
] [
--restart
]
Options
-h
,
--help
............................Print help message.
--version
............................Print program version.
--status
..............................Show the firewall status
--unmask
..............................Unmask the firewall
--start
................................Start the firewall
--enable
..............................Enable the firewall at boot
--stop
..................................Stop the firewall
--disable
............................Disable the firewall at boot
--mask
..................................Mask the firewall
--restart
............................Restart the firewall
--reload
..............................Reload the firewalls permanent rules
--perm
..................................Make action permanent
--dhcp
..................................Add/remove dhcp
--ftp
, ...................................Add/remove ftp
--http
..................................Add/remove http
--iscsi
................................Add/remove iscsi targets
--nfs
....................................Add/remove nfs
--telnet
..............................Add/remove telnet
--cifs
..................................Add/remove cifs
--ssh
....................................Add/remove ssh
--snmp
..................................Add/remove snmp
--tftp
..................................Add/remove tftp
--all
....................................Add/remove all DTSx services
--add
....................................Add a port, service, or interface
--rem
....................................Remove a port, service or interface
--port
..................................Port number to add/remove
--iface
................................Interface to add/remove: eth0, etc.
--udp
....................................Define a port as udp
--tcp
....................................Define a port as tcp
--cmd
"options" .....................Pass "options" to firewall-cmd
Example:
Status display
cw_dts>
fwall
[fwall]
FIREWALL: status=OK "The firewall IS running"
public (active)
target: default
icmp-block-inversion: no
interfaces: eth0 eth1
sources:
services: dhcp ssh
ports:
protocols:
masquerade: no
forward-ports:
sourceports:
icmp-blocks:
rich rules:
[!fwall] <summary>