Multi Service Edge Device HL950
Administrator’s Guide
Page 115 (159)
EN/LZT 108 5995 R3
June
2003
CFILE<STR>
:
Path and file to read certificate from, i.e. /root/cert/cfile.txt
WDIR<STR>
:
Path and directory to write certificate to. Default: /root/cert/certreq.txt
6.6.4 CONNECTION
Used to manage firewall connection limits, etc.
Authority: ADMIN
Prefixes
Parameters and Descriptions
SET
SHOW
LAN<NUM>
:
Maximum number of connections from LAN
WAN<NUM>
:
Maximum number of connections from WAN
SELF<NUM>
:
Maximum number of connections from Self
WSELF<NUM>
:
Maximum number of connections from WAN to Self
DMZ<NUM>
:
Maximum number of connections from DMZ
LIMITS<BOOL>
:
Display configured connection limits
STATS<BOOL>
:
Display connection statistics
6.6.5 FIREWALL
Used to manage the firewall daemon and policies.
Authority: ADMIN
Prefixes
Parameters and Descriptions
SET
SHOW
ADD
DEL
START
STOP
PNUM<NUM>
:
Policy number
TYPE<STR>
:
Policy type (LANtoWAN, WANtoLAN, DMZtoWAN, or WANtoDMZ)
Packet Source Identifiers:
IPSN<STR>
:
Source IP address name (ANY or OTHER). Default: OTHER
IPSS<IP>
:
Start source IP address range
IPSE<IP>
:
End source IP address range
SMASK<NUM>
:
Source IP address mask bits (0 to 32)
PSN<STR>
:
Source port name (ANY, SAFE, or OTHER)
PSS<NUM>
:
Start source port range
PSE<NUM>
:
End source port range
Packet Destination Identifiers:
IPDN<STR>
:
Destination IP address name (ANY or OTHER) Default: OTHER
IPDS<IP>
:
Start destination IP address range
IPDE<IP>
:
End destination IP address range
DMASK<NUM>
:
Destination IP address mask bits (0 to 32)
PDN<STR>
:
Destination port name (ANY, SAFE, OTHER, or Service name)
PDS<NUM>
:
Start destination port range
PDE<NUM>
:
End destination port range
Other Packet Identifiers:
PROT<STR>
:
Protocol type (TCP, UDP, ICMP, AH, ESP, ALL, or OTHER)
PRNUM<STR>
:
Protocol number, if the protocol type is OTHER
Firewall Policy Action:
ALLOW<BOOL>
:
Allow or deny the specified traffic. Set this to TRUE to allow the specified
traffic and to FALSE to deny the specified traffic.
LOG<BOOL>
:
Enable or disable logging
Parameters for changing the priority and position:
PPOS<STR>
:
Policy position (BEGIN, END, BEFORE, or AFTER)