Chapter 25 Secure Policy
ZyWALL / USG (ZLD) CLI Reference Guide
167
25.2.1 Secure Policy Sub-Commands
The following table describes the sub-commands for several
secure-policy
and
secure-policy6
commands.
session-status-update alg {active|inactive}
Enables or Disables ALG session updates
show session-status-update reply-time
Displays idle session timeout
Table 85
Command Summary: Secure Policy (continued)
COMMAND
DESCRIPTION
Table 86
firewall Sub-commands
COMMAND
DESCRIPTION
action {allow|deny|reject}
Sets the action the ZyWALL / USG takes when packets
match this rule.
[no] activate
Enables a secure policy rule. The
no
command disables the
rule.
[no] ctmatch {dnat | snat}
Use
dnat
to block packets sent from a computer on the
ZyWALL / USG’s WAN network from being forwarded to an
internal network according to a virtual server rule.
Use
snat
to block packets sent from a computer on the
ZyWALL / USG’s internal network from being forwarded to
the WAN network according to a 1:1 NAT or Many 1:1 NAT
rule.
The
no
command forwards the matched packets.
Subcommands cannot be used with secure-policy6.
[no] description
description
Sets a descriptive name (up to 60 printable ASCII
characters) for a secure policy rule. The
no
command
removes the descriptive name from the rule.
[no] destinationip
address_object
Sets the destination IP address. The
no
command resets
the destination IP address(es) to the default (
any
).
any
means all IP addresses.
[no] destinationip6
address_object
Sets the destination IPv6 address. The
no
command resets
the destination IP address(es) to the default (
any
).
any
means all IP addresses.
[no] from
zone_object
Sets the zone on which the packets are received. The
no
command removes the zone on which the packets are
received and resets it to the default (any) meaning all
interfaces or VPN tunnels.
[no] log [alert]
Sets the ZyWALL / USG to create a log (and optionally an
alert) when packets match this rule. The
no
command sets
the ZyWALL / USG not to create a log or alert when packets
match this rule.
[no] schedule
schedule_object
Sets the schedule that the rule uses. The
no
command
removes the schedule settings from the rule.
[no] service
service_name
Sets the service to which the rule applies. The
no
command
resets the service settings to the default (
any
).
any
means
all services.
[no] sourceip
address_object
Sets the source IP address(es). The
no
command resets
the source IP address(es) to the default (
any
).
any
means
all IP addresses.
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...