136
•
get router info routing_table
8.8 policy
When you create a policy route, any packets that match the policy are forwarded to the IP address of
the next hop gateway through the specified outbound interface.
You can configure the freeGuard 100 to route packets based on:
•
a source address
•
a protocol, service type, or port range
•
the inbound interface
When the freeGuard 100 receives a packet, it starts at the top of the policy routing list and attempts to
match the packet with a policy in ascending order. If no packets match the policy route, the freeGuard
100 routes the packet using the regular routing table (policy routing is processed before static routing).
Note
: For static routing, any number of static routes can be defined for the same destination IP/mask.
When multiple routes for the same destination IP/mask exist, the freeGuard 100 chooses the route
with the lowest number in the Distance field. Route redundancy is not available for policy routing: any
packets that match a policy route are forwarded according to the route specified in the policy.
Command syntax pattern
Add, edit or delete a policy route with the specified sequence number.
config router policy
edit <sequence_integer>
set <keyword> <variable>
end
config router policy
edit <sequence_integer>
unset <keyword>
end
config router policy
delete <sequence_integer>
end
get router policy <sequence_integer>
show router policy <sequence_integer>
policy command keywords and variables
Keywords & Variables
Description
Default
dst <destination-
Match packets that have this destination IP address and
0.0.0.0 0.0.0.0
Summary of Contents for freeGuard 100
Page 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Page 3: ......
Page 7: ......
Page 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Page 183: ...176...