Firewall Commands
E-DOC-CTC-20040907-0010 v1.0
165
firewall rule create
Create a rule.
SYNTAX:
where:
firewall rule create
chain = <string>
[index = <number>]
[srcintf [!]= <string>]
[srcintfgrp [!]= <{wan | local | lan} or number>]
[src [!]= <ip-address>]
[dstintf [!]= <string>]
[dstintfgrp [!]= <{wan | local | lan} or number>]
[dst [!]= <ip-address>]
[tos [!]= <number{1-255}>]
[precedence [!]= <number{0-7}>]
[dscp [!]= <number{0-63}>]
[prot [!]= <{<supported IP protocol name> | <number>}>]
[syn = <yes | no>]
[urg = <yes | no>]
[ack = <yes | no>]
[srcport [!]= <{<supported TCP/UDP port name>|<number>}>]
[srcportend = <{<supported TCP/UDP port name>|<number>}>]
[dstport [!]= <{<supported TCP/UDP port name>|<number>}>]
[dstportend = <{<supported TCP/UDP port name>|<number>}>]
[icmptype [!]= <{<supported ICMP type name> | <number>}>]
[icmpcode [!]= <number{0-15}>]
[icmpcodeend = <number{0-15}>]
[clink = <string>]
[log = <{no | yes}>]
action = <{accept | deny | drop | count}>
If a value is preceded by a “!”, it means NOT.
For example “srcintfgrp=!wan” means “if the source interface group is different from WAN”.
chain
The name of the chain in which the rule must be inserted.
REQUIRED
index
The number of the rule before which the new rule must be added.
OPTIONAL
srcintf
The name of the interface the packet should [or should NOT] arrive on to make
this rule apply.
Note
NOT applicable if used in a chain assigned to the
output
hook.
OPTIONAL
srcintfgrp
The interface group the packet should [or should NOT] arrive on. Choose
between:
wan
local
lan.
Note
NOT applicable if used in a chain assigned to the
output
hook.
OPTIONAL
Содержание SpeedTouch 510v5
Страница 1: ...SpeedTouchTM 516 536 546 510v5 530v5 Multi User ADSL Gateways CLI Reference Guide Release R5 2 7...
Страница 2: ......
Страница 3: ...SpeedTouchTM 516 536 546 510v5 530v5 CLI Reference Guide R5 2 7...
Страница 16: ...Contents E DOC CTC 20040907 0010 v1 0 14...
Страница 34: ...ADSL Commands E DOC CTC 20040907 0010 v1 0 32...
Страница 60: ...Bridge Commands E DOC CTC 20040907 0010 v1 0 58...
Страница 116: ...DHCP Commands E DOC CTC 20040907 0010 v1 0 114...
Страница 200: ...IP Commands E DOC CTC 20040907 0010 v1 0 198 ip auto flush Flush the autoIP interfaces SYNTAX ip auto flush...
Страница 224: ...IPQoS Commands E DOC CTC 20040907 0010 v1 0 222...
Страница 236: ...Label Commands E DOC CTC 20040907 0010 v1 0 234 label chain flush Flush all chains SYNTAX label chain flush...
Страница 266: ...NAT Commands E DOC CTC 20040907 0010 v1 0 264...
Страница 272: ...Phonebook Commands E DOC CTC 20040907 0010 v1 0 270...
Страница 314: ...PPTP Commands E DOC CTC 20040907 0010 v1 0 312...
Страница 322: ...QoSBook Commands E DOC CTC 20040907 0010 v1 0 320...
Страница 338: ...Software Commands E DOC CTC 20040907 0010 v1 0 336...
Страница 346: ...Switch Commands E DOC CTC 20040907 0010 v1 0 344...
Страница 383: ......