
SBC session border controllers
115
<ACTION>
<P_IDX>
host-precedence-
violation
precedence-cutoff
source-quench
redirect
network-redirect
host-redirect
TOS-network-redirect
TOS-host-redirect
echo-request
router-advertisement
router-solicitation
time-exceeded
ttl-zero-during-
transit
ttl-zero-during-
reassembly
parameter-problem
ip-header-bad
required-option-
missing
timestamp-request
timestamp-reply
address-mask-request
address-mask-reply
accept, drop, reject
1-65535
Action — action executed by this rule:
–
ACCEPT — packets falling under this rule will
be accepted by the firewall;
–
DROP — packets falling under this rule will
be rejected by the firewall without informing
the party that has sent these packets;
–
DROP — packets falling under this rule will
be rejected by the firewall; the party that has
sent the packet will receive either TCP RST
packet or 'ICMP destination unreachable'.
Firewall profile number
add rule geoip
<direction>
<ENABLE>
<RULE_NAME>
<COUNTRY>
<PROTO>
<S_PORT_START>
<S_PORT_END>
<D_PORT_START>
<D_PORT_END>
<ICMP_TYPE>
input
output
enable/disable
Text, 63 characters
max.
Country name
any
tcp
udp
icmp
tcp+udp
1-65535
1-65535
1-65535
1-65535
Add firewall GeoIP-rule
Rule direction
Enable/disable rule
Rule name
The country to which the address belongs
Protocol type
Source starting port
Source ending port
Destination starting port
Destination ending port
ICMP packet type