6
Firewall
101
If
the
‐
verbose
option
is
used,
the
matching
reverse
flow
for
a
connection
is
also
shown.
The
command
form
is
as
follows:
Device:/>
flow
‐
show
‐
verbose
All
options
for
the
flow
command
can
be
found
in
the
SEG
‐
100
Command
Line
Interface
Reference
.
These
include
filtering
parameters
to
only
list
certain
flows.
The
use
of
this
command
with
IPsec
tunnels
is
discussed
in
IPsec
troubleshooting
on
page
143
.
First matching principle
If
several
IP
rules
in
an
IP
rules
set
match
the
same
filtering
parameters,
the
first
matching
rule
in
a
scan
from
top
to
bottom
is
the
one
that
decides
how
the
flow
will
be
handled.
Non-matching traffic
Incoming
packets
that
do
not
match
any
rule
in
the
rule
set
and
do
not
have
an
already
opened
matching
flow
will
automatically
be
subject
to
a
Deny
action.
To
have
more
precise
control
over
such
non
‐
matching
traffic,
it
is
recommended
to
create
an
explicit
rule
called
Deny
All
as
the
final
rule
in
the
rule
set,
with
an
action
of
Deny
for
source
and
destination
network
all
‐
nets
,
source
and
destination
interface
all
,
and
service
all_services
.
This
example
allows
logging
to
be
turned
on
for
traffic
that
has
no
matching
IP
rule.
IP rule actions
A
rule
consists
of
two
parts:
the
filtering
parameters
and
the
action
to
take
if
there
is
a
match
with
those
parameters.
As
described
above,
the
parameters
of
any
SEG
rule,
including
IP
rules
are:
•
Source
interface
•
Source
network
•
Destination
interface
•
Destination
network
•
Service