804
Usage guidelines
If the specified rule ID does not exist, this command creates a rule. Otherwise, this command
changes the configuration of the specified rule.
If you do not configure any object groups in a rule, the rule applies to all packets.
If you do not specify any options in the
undo
rule
command, the command deletes the entire rule.
Otherwise, the command deletes only the specified part of the rule statement.
You cannot delete a nonexistent rule. You can use the
display
object-policy ip
command to display
rules in an IPv4 object policy.
To use applications or application groups in an object policy, use only PBAR-classified applications.
NBAR-classified applications cannot match any packets. For more information about PBAR and
NBAR, see
Security Configuration Guide
.
Examples
# Configure a rule to allow packets that match source IPv4 address object group
sourceip1
to pass
through during time range
time1
.
<Sysname> system-view
[Sysname] object-policy ip permit
[Sysname-object-policy-ip-permit] rule pass source-ip sourceip1 logging time-range time1
# Configure a rule to apply DPI application profile
profile1
to packets that match source IPv4
address object group
sourceip1
.
<Sysname> system-view
[Sysname] object-policy ip dpiproc
[Sysname-object-policy-ip-dpiproc] rule inspect profile1 source-ip sourceip1 logging
# Configure a rule to permit packets that match application
aaa
.
<Sysname> system-view
[Sysname] object-policy ip dpiproc
[Sysname-object-policy-ip-dpiproc] rule pass application aaa
Related commands
app-profile
(
DPI Command Reference
)
display
object-policy ip
move rule
object-policy ip
time-range
(
ACL and QoS Command Reference
)
track
(
High Availability Command Reference
)
rule (IPv6 object policy view)
Use
rule
to configure a rule for an IPv6 object policy.
Use
undo
rule
to partially or completely delete a rule for an IPv6 object policy.
Syntax
rule
[
rule-id
] {
drop
|
pass
|
inspect
app-profile-name
} [ [
source-ip
{
object-group-name
|
any
}
]
[
destination-ip
{
object-group-name
|
any
} ] [
service
{
object-group-name
|
any
} ] [
vrf
vrf-name
]
[
application
application-name
] [
app-group
app-group-name
] [
counting
] [
disable
] [
logging
]
[
track
[
negative
]
track-entry-number
] [
time-range time-range-name
] ]
*
undo
rule
rule-id
[
source-ip
|
destination-ip
|
service
|
vrf
|
application
|
app-group
|
counting
|
disable
|
logging
|
track
|
time-range
]
*
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...