ZyXEL Confidential
340adq4c0
22/36
udp-idle-timeout
<seconds>
Edit the timeout for an idle UDP session before it
is terminated
connection-timeo
ut <seconds>
Edit the wait time for the SYN TCP sessions
before it is terminated
fin-wait-timeout
<seconds>
Edit the wait time for FIN in concluding a TCP
session before it is terminated
tcp-idle-timeout
<seconds>
Edit the timeout for an idle TCP session before it
is terminated
pnc <yes|no>
PNC is allowed when 'yes' is set even there is a
rule to block PNC
log <yes|no>
Switch on/off sending the log for matching the
default permit
rule
<rule#>
permit
<forward|block>
Edit whether a packet is dropped or allowed when
it matches this rule
active <yes|no>
Edit whether a rule is enabled or not
protocol <0~255>
Edit the protocol number for a rule. 1=ICMP,
6=TCP, 17=UDP...
log
<none|match|not-matc
h|both>
Sending a log for a rule when the packet
none|matches|not match|both the rule
alert <yes|no>
Activate or deactivate the notification when a DoS
attack occurs or there is a violation of any alert
settings. In case of such instances, the function
will send an email to the SMTP destination
address and log an alert.
srcaddr-single
<ip
address>
Select and edit a source address of a packet which
complies to this rule
srcaddr-subnet
<ip
address> <subnet
mask>
Select and edit a source address and subnet mask
if a packet which complies to this rule.
srcaddr-range
<start
ip
address> <end ip
address>
Select and edit a source address range of a packet
which complies to this rule.
destaddr-single
<ip
address>
Select and edit a destination address of a packet
which complies to this rule
destaddr-subnet
<ip
address> <subnet
mask>
Select and edit a destination address and subnet
mask if a packet which complies to this rule.
destaddr-range
<start
ip address> <end ip
address>
Select and edit a destination address range of a
packet which complies to this rule.
tcp
destport-single
<port#>
Select and edit the destination port of a packet
which comply to this rule. For non-consecutive
port numbers, the user may repeat this command
line to enter the multiple port numbers.
tcp
destport-range
<start port#> <end
port#>
Select and edit a destination port range of a packet
which comply to this rule.
udp
destport-single
<port#>
Select and edit the destination port of a packet
which comply to this rule. For non-consecutive
port numbers, users may repeat this command line
to enter the multiple port numbers.
udp
destport-range
<start port#> <end
port#>
Select and edit a destination port range of a packet
which comply to this rule.