56
interface, and enable or disable fixedport so that the
NAT policy does not translate the packet source port.
Enter deny to deny packets that match the firewall
policy. Enter encrypt to configure the policy tobe an
encrypt policy for IPSec tunnels. If you enter encrypt
you can also enable or disable inbound, natinbound,
outbound, and natoutbound to control the VPN traffic
allowed by the policy.
comments
<comment_str>
Optionally add a description or other information
about the policy. comment_stris limited to 63
characters. You can enclose the string in single
quotes to enter special characters or spaces. For
more information, see “Using single quotes to enter
tabs or spaces instrings”
No default.
diffserv_forward
{disable | enable}
Enable or disable forward (original) Differentiated
Services traffic for this policy.
disable
diffserv_reverse
{disable | enable}
Enable or disable reverse (reply) Differentiated
Services traffic for this policy.
disable
diffservcode_forward
<outbound_binary>
Set the Differentiated Services Code Point (DSCP)
value in the Diffserv field ofoutbound packets. The
value is 6 bitsbinary. The valid range is
000000111111.
000000
diffservcode_rev
<reply_binary>
Set the Differentiated Services Code Point (DSCP)
value in the Diffserv field ofreply packets. The value
is 6 bits binary. The valid range is 000000-111111.
000000
dstaddr <name_str>
Enter the destination address for the policy. For a
NAT policy you can also add a virtual IP. See “vip” on
page 103. name_str is case-sensitive.
No default.
dstintf <name_str>
Enter the destination interface for the policy. The
interface can be a physical interface, a VLAN
subinterface or a zone. You cannot use an interface
or VLAN subinterface for dstintfif the interface or
VLAN subinterface has been added to a zone.
No default.
fixedport {disable |
enable}
Prevent a NAT policy from translating the source
port. Some applications do not function correctly if
the source port is changed. If you enter fixedport,
youshould also enable IP pools. If you do not enable
IP pools a policy with fixedportcan only allow one
connection at a time for this port or service.
disable
gbandwidth
<bandwidth_integer>
Guarantee the amount of bandwidth available for
traffic controlled by the policy. bandwidth_integer can
be 0 to 100000 Kbytes/second.
0
groups <name_str>
Enter one or more user group names for users that
authenticate through this policy. When user groups
are created, they are paired with protection
profiles.The user group name is case sensitive.
No Default.
Summary of Contents for freeGuard 100
Page 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Page 3: ......
Page 7: ......
Page 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Page 183: ...176...