freeGuard 100 CLI User Manual
137
address_ipv4mask>
netmask.
end_port <port_integer> The end port number of a port range for a policy route.
Match packets that have this destination port range. You
must configure both the
start_port
and
end_portkeywords
for destination port range
matchingto take effect.
0
gateway
<address_ipv4>
Send packets that match the policy to this next hop
router.
0.0.0.0
input_device <interface-
name_str>
Match packets that are received on this interface.
null
output_device<interface-
name_str>
Send packets that match the policy out thisinterface.
null
protocol
<protocol_integer>
Match packets that have this protocol number.
0
src <source-
address_ipv4mask>
Match packets that have this source IP address and
netmask.
0.0.0.0 0.0.0.0
start_port
<port_integer>
The start port number of a port range for apolicy route.
Match packets that have this destination port range. You
must configure both the
start_port
and
end_port
keywords for destination port range matchingto take
effect.
0
Example
If a FreeGuard 100 provides Internet access for multiple internal subnets, you can use policy routing to
control the route that traffic from each network takes to the Internet. For example, if the internal
network includes the subnets 192.168.10.0 and 192.168.20.0 you can enter the following policy
routes:
•
Enter the following command to route traffic from the 192.168.10.0 subnet to the 100.100.100.0
subnet. Force the packets to the next hop gateway at IP address 1.1.1.1 through the interface named
external.
config router policy
edit 1
set input_device internal
set src 192.168.10.0 255.255.255.0
set dst 100.100.100.0 255.255.255.0
set output_device external
set gateway 1.1.1.1
end
Содержание freeGuard 100
Страница 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Страница 3: ......
Страница 7: ......
Страница 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Страница 183: ...176...
Страница 309: ...302 100 from a TFTP server with the address 192 168 21 54 set vpn certificates local import branch_cert 192 168 21 54...