Chapter 6
Security
RUGGEDCOM ROX II
CLI User Guide
206
Adding a Rule
!
fwrule Rule2
action accept
source-zone man
destination-zone man
no description
!
!
!
!
If no rules have been configured, add rules as needed. For more information, refer to
.
Section 6.9.15.2
Adding a Rule
To configure a rule for a firewall, do the following:
1. Make sure the CLI is in Configuration mode.
2. Add the rule by typing:
security
firewall fwconfig
firewall
fwrule
rule
Where:
•
firewall
is the name of the firewall
•
rule
is the name of the rule
3. Configure the following parameter(s) as required:
NOTE
When applying new rules, previous traffic seen by the router might still be considered as having
valid connections by the connection tracking table. For instance:
a. A rule for the TCP and UDP protocols is applied.
b. The router sees both TCP and UDP traffic that qualifies for NAT.
c. The rule is then modified to allow only UDP.
d. The router will still see TCP packets (i.e. retransmission packets).
If required, reboot the router to flush all existing connection streams.
Parameter
Description
iptype { iptype }
Synopsis:
{ ipv4, ipv6, ipv4ipv6 }
Default:
ipv4
Internet protocol type - use both when no addresses are used, otherwise define IPv4 and
IPv6 rules for each type of addresses used.
action { action }
Synopsis:
{ accept, drop, reject, continue, redirect, dnat-, dnat, copy-dnat }
Default:
reject
The final action to take on incoming packets matching this rule.
Options include:
• accept: Allows the connection request to proceed.
• continue: Passes the connection request past any other rules.
• copy-dnat: Sends a copy to a second system using a DNAT rule. Protocol must be set to
'udp', and Original Destination must be defined.
Содержание RUGGEDCOM ROX II
Страница 2: ...RUGGEDCOM ROX II CLI User Guide ii ...
Страница 4: ...RUGGEDCOM ROX II CLI User Guide iv ...
Страница 39: ...RUGGEDCOM ROX II CLI User Guide Table of Contents xxxix 19 5 VLANs 752 ...
Страница 40: ...Table of Contents RUGGEDCOM ROX II CLI User Guide xl ...
Страница 46: ...Preface RUGGEDCOM ROX II CLI User Guide xlvi Customer Support ...
Страница 96: ...Chapter 2 Using RUGGEDCOM ROX II RUGGEDCOM ROX II CLI User Guide 50 Accessing Maintenance Mode ...
Страница 170: ...Chapter 5 System Administration RUGGEDCOM ROX II CLI User Guide 124 Deleting a Scheduled Job ...
Страница 256: ...Chapter 6 Security RUGGEDCOM ROX II CLI User Guide 210 Enabling Disabling a Firewall ...
Страница 402: ...Chapter 11 Wireless RUGGEDCOM ROX II CLI User Guide 356 Managing Cellular Modem Profiles ...
Страница 646: ...Chapter 13 Unicast and Multicast Routing RUGGEDCOM ROX II CLI User Guide 600 Deleting a Multicast Group Prefix ...
Страница 732: ...Chapter 15 Network Discovery and Management RUGGEDCOM ROX II CLI User Guide 686 Viewing NETCONF Statistics ...
Страница 790: ...Chapter 17 Time Services RUGGEDCOM ROX II CLI User Guide 744 Deleting a Broadcast Multicast Address ...