Firewall Feature Set Commands
16-118 Configuring Security
Defaults
Deny
all
Mode
Global
configuration:
XSR(config)#
Example
The
following
example
permits
any
remote
host
to
run
a
PPTP
tunnel
to
a
server
on
the
internal
network:
XSR(config)#ip firewall network pptp-server 120.21.1.18/32 internal
XSR(config)#ip fire filter allow--gre ANY_EXTERNAL pptp-server 47 protocol-id
XSR(config)#ip firewall filter allow--gre pptp-server ANY_EXTERNAL protocol-id 47
ip firewall icmp timeout
This
command
defines
the
object
which
handles
all
configuration
for
ICMP
packet
inspection.
Syntax
ip firewall icmp timeout
<
seconds
>
Syntax of the “no” Form
The
no
form
of
this
command
sets
the
timeout
to
the
default
value:
no ip firewall icmp timeout
Default
Timeout:
60
seconds
Mode
Global
configuration:
XSR(config)#
Example
The
following
example
resets
the
ICMP
idle
timeout
interval:
XSR(config)#ip firewall icmp timeout 300
ip firewall java and ip firewall activex
This
command
defines
the
object
that
allows
or
denies
HTML
pages
with
embedded
Java
or
ActiveX
applets
from
particular
or
all
IP
addresses.
A
name
for
any
firewall
object
must
use
these
alpha
‐
numeric
characters
only
:
A
‐
Z
(upper
or
lower
case),
0
‐
9
,
-
(dash),
or
_
(underscore).
Also,
all
firewall
object
names
are
case
‐
sensitive.
seconds
Idle
timeout
for
ICMP
sessions,
ranging
from
60
to
86400
seconds.
Содержание X-Pedition XSR
Страница 1: ...X Pedition Security Router XSR CLI Reference Guide Version 7 6 P N 9033842 07...
Страница 2: ......
Страница 10: ...viii...
Страница 14: ...xii...
Страница 134: ...Bootrom Monitor Mode Commands 3 128 Configuring the XSR Platform...
Страница 278: ...VRRP Clear and Show Commands 5 202 Configuring the Internet Protocol...
Страница 352: ...IGMP Clear and Show Commands 7 104 Configuring IP Multicast...
Страница 406: ...Multilink Show Commands 8 136 Configuring the Point to Point Protocol...
Страница 436: ...Frame Relay Clear and Show Commands 9 112 Configuring Frame Relay...
Страница 460: ...Dialer Watch Commands 10 106 Configuring the Dialer Interface...