data:image/s3,"s3://crabby-images/d84bf/d84bfa857ed9499c5ad610ed77c9f93960d5703e" alt="Black Box ET0010A Скачать руководство пользователя страница 89"
Creating Policies
90
ETEP CLI User Guide
Related topics:
●
“Viewing the Policy Set” on page 91
●
“Backing Up the Policy Set” on page 91
●
“Deploying Management Policies” on page 92
Example
The following example adds a policy named BypassICMP. It is a bypass policy that passes ICMP traffic
(protocol 1) in the clear from anywhere to anywhere. This policy will have the highest priority of all the
policies on the ETEP.
admin>
configure
config>
management-interface
man-if>
ipsec-config
ipsec-config>
policy-add BypassICMP
ipsec-config>
policy-config BypassICMP
policy-config>
policy-action bypass
policy-config> p
olicy-selector 0.0.0.0/0 0.0.0.0/0 1 any any
policy-config>
policy-priority 65500
Deploying Policies
We recommend taking the following steps when deploying policies on the management port:
●
Review the active management policies and pending changes.
●
Make a backup copy of the active policies running on the ETEP.
●
Deploy the new policy set to the ETEP.
Table 48
Policy-selector command
Command
Description
policy-selector
<remote-ip> <local-ip> <protocol> <remote-port> <local-port>
The defaults are: 0.0.0.0/0 (remote ip), 0.0.0.0/0 (local ip), any (protocol), any
(remote port), any (local port).
remote-ip
IPv4 or IPv6 address of the endpoint on the far side of the untrusted
network in CIDR notation (IP address/prefix). The default is set to 0.0.0.0/0,
which means “process all packets” coming from any address
local-ip
IPv4 or IPv6 address of the local endpoint in CIDR notation (IP address/
prefix). he default is set to 0.0.0.0/0, “process all packets.”
Protocol
A decimal value that identifies the IP layer protocol. “Any” accepts all
protocols. Range is 1-254.
Remote and local ports
A decimal value that identifies the transport layer protocol port number for the
remote or local endpoint. “Any” means “accept all.” Range is 1-65535.
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...