
Configuration Objects
163
source-interface
List of NMTOKEN -
Source interface(s)
source-ip
List
of
-
Source IP address range(s)
source-port
List of PortRange
-
Source port(s)
startup-delay
1:00
Startup interval to use ignore instead of
reject/drop
table
(unsignedByte 0-99)
routetable
0
Applicable routing table
target-interface
List of NMTOKEN -
Target interface(s)
target-ip
List
of
-
Target IP address range(s)
target-port
List of PortRange
-
Target port(s)
Table H.76. rule-set: Elements
Element
Type
Instances
Description
ip-group
Optional, unlimited
Named IP groups
rule
Optional, unlimited
Individual rules, first match applies
H.2.57. session-rule: Firewall rules
Firewall rule
The individual firewall rules are checked in order within the rule-set, and the first match applied. The default
action for a rule is continue, so once matched the next rule-set is considered.
Table H.77. session-rule: Attributes
Attribute
Type
Default
Description
action
continue
Action taken on match
comment
-
Comment
cug
List of PortRange
-
Closed user group ID(s)
hash
-
Use hash of IPs for load sharing
interface
List of NMTOKEN -
Source or target interface(s)
ip
List
of
-
Source or target IP address range(s)
log
As rule-set
Log session start
log-end
As rule-set
Log session end
name
-
Name
pcp
-
If
mapped
by
NAT-PMP
/
PCP
(experimental)
profile
-
Profile name
protocol
List of unsignedByte -
Protocol(s) [1=ICMP, 6=TCP, 17=UDP]
set-gateway
-
New gateway
set-graph
-
Graph name for shaping/logging
set-graph-dynamic
-
Dynamically create graph
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......