![Enterasys X-Pedition XSR Скачать руководство пользователя страница 666](http://html1.mh-extra.com/html/enterasys/x-pedition-xsr/x-pedition-xsr_cli-reference-manual_2414758666.webp)
Firewall Feature Set Commands
16-122 Configuring Security
Also,
all
firewall
object
names
including
pre
‐
defined
objects
such
as
ANY_EXTERNAL
and
user
‐
defined
object
names
are
case
‐
sensitive.
Syntax
ip firewall network
name
{
A.B.C.D
mask
A.B.C.D
|
A.B.C.D
A.B.C.D
}{
internal
|
external
}
Syntax of the “no” Form
The
no
form
of
this
command
disables
the
firewall
network
object:
no ip firewall network
name
Syntax
Global
configuration:
XSR(config)#
Example
This
example
defines
internal
and
external
IP
addresses
for
the
network
objects
sales
and
remote
‐
access
.
Note
how
the
internal
and
external
tags
have
meaning
in
the
way
the
network
objects
are
used
in
a
policy.
XSR(config)#ip firewall network sales 192.168.100.0 mask 255.255.255.0 internal
XSR(config)#ip firewall network remote-access 10.1.1.0 mask 255.255.255.0 external
ip firewall network-group
This
command
comprises
a
set
of
network
objects,
serving
the
same
function
as
a
network
object.
Intrinsic
values
ANY_INTERNAL
(all
internal
network
objects
defined)
and
ANY_EXTERNAL
(all
external
network
objects
defined)
are
a
convenient
option
to
define
a
set
of
network
objects.
Membership
in
these
sets
is
unlimited.
A
name
for
any
firewall
object
must
use
these
alpha
‐
numeric
characters
only
:
A
‐
Z
(upper
or
lower
case),
0
‐
9
,
-
(dash),
or
_
(underscore).
Also,
all
firewall
object
names
including
pre
‐
defined
Notes:
A DMZ is considered an
internal
network.
Use care when you have a configuration with internal and external addresses that overlap and exist
off the same physical interface. In this case, the XSR may not be able to identify an address in the
overlap range as being internal or external. If this is so, packets may not match policies as expected.
Once you specify a network name you cannot switch internal/external settings. To switch settings
you must delete the network and add it again.
name
Name
of
the
network
object,
not
to
exceed
16
characters.
Match
this
with
policy
source/destination
name
exactly
.
A.B.C.D A.B.C.D
Start
and
end
addresses.
A.B.C.D
mask
A.B.C.D
Base
address
and
mask
in
dotted
decimal
format.
internal
or
external
Address
qualifier.
Содержание X-Pedition XSR
Страница 1: ...X Pedition Security Router XSR CLI Reference Guide Version 7 6 P N 9033842 07...
Страница 2: ......
Страница 10: ...viii...
Страница 14: ...xii...
Страница 134: ...Bootrom Monitor Mode Commands 3 128 Configuring the XSR Platform...
Страница 278: ...VRRP Clear and Show Commands 5 202 Configuring the Internet Protocol...
Страница 352: ...IGMP Clear and Show Commands 7 104 Configuring IP Multicast...
Страница 406: ...Multilink Show Commands 8 136 Configuring the Point to Point Protocol...
Страница 436: ...Frame Relay Clear and Show Commands 9 112 Configuring Frame Relay...
Страница 460: ...Dialer Watch Commands 10 106 Configuring the Dialer Interface...