freeGuard 100 CLI User Manual
57
inbound {disable |
enable}
Enable inbound to allow inbound VPN tunnels that
match this policy or disable inbound to deny inbound
tunnels thatmatch this policy.
enable
ippool {disable |
enable}
Configure a NAT policy to translate the source
address to an address randomly selected from the
first IP pool added to the destination interface of the
policy. Use IP pools if you must specify fixedportfor a
service or for dynamic NAT.
disable
logtraffic {disable |
enable}
Enable or disable recording traffic logmessages for
this policy.
disable
maxbandwidth
<bandwidth_integer>
Limit the maximum amount of bandwidth available
for traffic controlled by the policy. bandwidth_integer
can be 0 to 100000 Kbytes/second. If maximum
bandwidth is set to 0 no traffic is allowed by the
policy.
100
nat {disable | enable}
Configure the policy for network address translation
(NAT). NAT translates the source address and the
source port of packets accepted by the policy. If you
enable NAT you can enable or disable ippool and
fixedport.
disable
natinbound {disable |
enable}
Enable or disable inbound NAT for VPN tunnels that
match this policy.
disable
natip
<address_ipv4mask>
Configure natip for a firewall policy with action set to
encrypt and with outbound NAT enabled. Specify the
IP address and subnet mask to translate the source
address of outgoing packets. Set natip for peer to
peer VPNs to control outbound NAT IP address
translation for outgoing VPN packets. If you do not
use natip to translate IP addresses, the source
addresses of outbound VPN packets are translated
into the IP address of the freeGuard 100 external
interface. If you use natip, the freeGuard 100unit
uses a static mapping scheme to translate the
source addresses of VPN packets into
corresponding IP addresses on the subnet that you
specify. For example, if the source address in the
encryption policy is 192.168.1.0/24 and the natip is
172.16.2.0/24, a sourceaddress of 192.168.1.7 is
translated to 172.16.2.7
0.0.0.0 0.0.0.0
natoutbound {disable |
enable}
Enable or disable outbound NAT for VPN tunnels
that match this policy.
disable
outbound {disable |
enable}
Enable outbound to allow outbound VPN tunnels
that match this policy or disable outbound to deny
outbound tunnels that match this policy.
enable
poolname <name_str> Enter the name of the IP pool to use for the policy.
This command only appears if nat and ippool are
No default.
Содержание freeGuard 100
Страница 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Страница 3: ......
Страница 7: ......
Страница 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Страница 183: ...176...
Страница 309: ...302 100 from a TFTP server with the address 192 168 21 54 set vpn certificates local import branch_cert 192 168 21 54...