Firewall Commands
E-DOC-CTC-20050531-0058 v1.0
314
firewall config
Configure the firewall options.
SYNTAX:
where:
firewall config
[state = <{disabled | enabled}>]
[keep = <{disabled | enabled}>]
[tcpchecks = <{none | fast | exact}>]
[udpchecks = <{disabled|enabled}>]
[icmpchecks = <{disabled | enabled}>]
[logdefault = <{disabled | enabled}>]
[logthreshold = <{disabled | enabled}>]
[tcpwindow = <number{0-1073725440}>]
state
Enable or disable the firewall.
The default is
enabled
.
OPTIONAL
keep
The firewall keeps active connections (enabled) or not (disabled) when the
firewall rules change.
The default is
disabled
.
OPTIONAL
tcpchecks
Select the level of TCP sequence number checks. Choose between:
none
: no TCP checks are done.
fast
: check all the combinations of flag and disallow all the possible illegal
combinations shown below:
SYN PSH (SYN PSH URG,...)
SYN FIN (SYN FIN PSH, SYN FIN RST PSH,...)
FIN flag set without ACK
All flags set
No flags set.
exact
: check and permit only combinations of flag with the TCP state of a
connection:
SYN: request to open connection
SYN ACK: agree to open connection
A, PA, AU, PAU: acknowledgement of receipt
FA, FAP, FAU, FAP, FAPU, FAU, FPAU: request to close connection
R, RA, RP, RU, RPA, RPU, RAU, RPAU: tear down connection.
The default is
fast
.
OPTIONAL
udpchecks
Disable or enable keeping UDP checks.
The default is
enabled
.
OPTIONAL
icmpchecks
Disable or enable keeping ICMP checks.
The default is
enabled
.
OPTIONAL
logdefault
Disable or enable logging of default firewall rule.
The default is
disabled
.
OPTIONAL
logthreshold
Disable or enable log thresholding.
The default is
enabled
.
OPTIONAL
tcpwindow
A number between 0 and 1073725440.
This parameter permits to modify the TCP window for fast TCP checks.
The default is
65536
.
OPTIONAL
Summary of Contents for SpeedTouch 585
Page 1: ...SpeedTouch 585 Wireless Residential ADSL Gateway CLI Reference Guide Release R5 3 1...
Page 2: ......
Page 3: ...SpeedTouch 585 CLI Reference Guide R5 3 1...
Page 26: ...ADSL Commands E DOC CTC 20050531 0058 v1 0 6...
Page 78: ...ATM Commands E DOC CTC 20050531 0058 v1 0 58...
Page 82: ...AutoPVC Commands E DOC CTC 20050531 0058 v1 0 62...
Page 90: ...Config Commands E DOC CTC 20050531 0058 v1 0 70...
Page 116: ...CWMP Commands E DOC CTC 20050531 0058 v1 0 96...
Page 262: ...DSD Commands E DOC CTC 20050531 0058 v1 0 242...
Page 320: ...Eth Commands E DOC CTC 20050531 0058 v1 0 300...
Page 332: ...Expr Commands E DOC CTC 20050531 0058 v1 0 312...
Page 396: ...IDS Commands E DOC CTC 20050531 0058 v1 0 376...
Page 538: ...PPTP Commands E DOC CTC 20050531 0058 v1 0 518...
Page 574: ...SNMP Commands E DOC CTC 20050531 0058 v1 0 554...
Page 602: ...System Commands E DOC CTC 20050531 0058 v1 0 582...
Page 620: ...User Commands E DOC CTC 20050531 0058 v1 0 600...
Page 656: ...System Logging Messages E DOC CTC 20050531 0058 v1 0 636...
Page 666: ...Supported Key Names E DOC CTC 20050531 0058 v1 0 646...
Page 681: ......