Patton electronic 3231 manual firewall add portfilter, Add a port filter to a firewall policy

Page 40

Model 3231 CLI Reference Guide

5 • Firewall Commands

 

 

firewall add portfilter

Add a port filter to a firewall policy.

 

Note Begin each top-level command in the table below with

 

 

firewall add portfilter <name> <policyname>.

 

 

 

Table 24. firewall add portfilter <name> <policyname>

 

 

 

 

 

Command

 

 

 

Explanation

 

 

 

 

 

 

ftp

both

 

 

 

Allow inbound/outbound transport of FTP pack-

 

 

 

 

 

ets between inside and outside interfaces.

 

 

 

 

 

 

 

inbound

 

 

 

Allow transport of FTP packets from an outside

 

 

 

 

 

interface to an inside interface. Outbound trans-

 

 

 

 

 

port is not allowed..

 

 

 

 

 

 

 

outbound

 

 

 

Allow transport of FTP packets from an inside

 

 

 

 

 

interface to an outside interface. Inbound trans-

 

 

 

 

 

port is not allowed.

 

 

 

 

 

 

http

both

 

 

 

Allow inbound/outbound transport of HTTP pack-

 

 

 

 

 

ets between inside and outside interfaces.

 

 

 

 

 

 

 

inbound

 

 

 

Allow transport of HTTP packets from an outside

 

 

 

 

 

interface to an inside interface. Outbound trans-

 

 

 

 

 

port is not allowed.

 

 

 

 

 

 

 

outbound

 

 

 

Allow transport of HTTP packets from an inside

 

 

 

 

 

interface to an outside interface. Inbound trans-

 

 

 

 

 

port is not allowed.

 

 

 

 

 

 

icmp

both

 

 

 

Allow inbound/outbound transport of ICMP

 

 

 

 

 

packets between inside and outside interfaces

 

 

 

 

 

 

 

inbound

 

 

 

Allow transport of ICMP packets from an outside

 

 

 

 

 

interface to an inside interface. Outbound trans-

 

 

 

 

 

port is not allowed.

 

 

 

 

 

 

 

outbound

 

 

 

Allow transport of ICMP packets from an inside

 

 

 

 

 

interface to an outside interface. Inbound trans-

 

 

 

 

 

port is not allowed.

 

 

 

 

 

 

protocol

<number>

 

both

 

Allow inbound/outbound transport of packets of

 

 

 

 

 

the specified protocol number between inside

 

 

 

 

 

and outside interfaces.

 

 

 

 

 

 

 

 

 

inbound

 

Allow transport of packets of the specified proto-

 

 

 

 

 

col number from an outside interface to an inside

 

 

 

 

 

interface. Outbound transport is not allowed.

 

 

 

 

 

 

 

 

 

outbound

 

Allow transport of packets of the specified proto-

 

 

 

 

 

col number from an inside interface to an outside

 

 

 

 

 

interface. Inbound transport is not allowed.

 

 

 

 

 

 

firewall add portfilter

40

Image 40
Contents LCD Patton Electronics, Inc Trademark Statement Summary Table of Contents Table of Contents Firewall Commands Help Commands Port Commands Source Commands User Commands This guide is intended for administrators and operators About this guideAudience StructureUsing the CLI Connect a PC and logTypographical conventions used in this document PrecautionsGeneral conventions Alarm Commands Chapter contentsAlarm all alarmStatus Set the alarm state for all alarmsAlarm all alarmStatus clear Alarm all alarmStatus resetAlarm set index alarmSeverity Set the index for the severity level of an alarmCritical/Major = The most severe alarms Alarm set index alarm SeveritySet the index for the status level of an alarm Alarm set index alarmStatusAlarm set index alarm Status Show alarm status Alarm showExample Output alarm show Bridge Commands Bridge add interface Add a named interface to the bridgeBridge attach Attach existing transport to existing bridge interfaceBridge clear interfaces Remove all bridge interfacesBridge delete interface Remove specific bridge interfaceBridge detach Detach a transport from a bridge interfaceList bridge interfaces Bridge list interfacesExample Output bridge list interfaces Bridge set Configure bridge attributesDisplay bridge/interface settings Bridge showExample Output bridge show Example Output bridge show interface br1CPE Config Commands Cpeconfig action get Cpeconfig actionCpeconfig action set Cpeconfig set Cpeconfig show Example Output cpeconfig showEthernet Commands Ethernet add transport Create ethernet transportEthernet clear transports Remove all ethernet transportsEthernet delete transport Remove single ethernet transportEthernet list List ethernet ports and transportsExample Output ethernet list ports Example Output ethernet list transportsEthernet set transport Set port of an existing ethernet transportEthernet set transport name ethernetport port Ethernet set transport name port port Display existing ethernet transport Ethernet show transport Example Output ethernet show transport eth1 Firewall Commands firewall add policy Add a firewall policyAdd a port filter to a firewall policy firewall add portfilterFirewall add portfilter name policyname Smtp Both Tcp Startport Endport BothTelnet Both Udp Startport Endport BothAdd a validator to a firewall policy firewall add validatorFirewall add validator name policyname firewall clear policies firewall clearfirewall clear portfilters policyname firewall delete firewall delete policy namefirewall delete portfilter name policyname firewall delete validator name policynamefirewall disable Disable firewall featuresfirewall enable Enable firewall featuresShow information about specific firewall features firewall listExample Output firewall list policies Example Output firewall list portfilters pexinExample Output firewall list protocol Example Output firewall list validators pdmzinfirewall set IDS firewall set securitylevel Set the desired level of security for the firewallfirewall set validator Configure the settings for a validatorFirewall set validator name policyname Display information about a firewall setting firewall showExample Output firewall show IDS Example Output firewall show IDS blacklistExample Output firewall show portfilter heihttp pexin Example Output firewall show validator item0 pdmzinfirewall status Example Output firewall statusShdsl Commands Gshdsl set BERMeterMode Configure patetrn generationGshdsl set BERMeterMode Gshdsl set BERMeterMode 511EConfigure clock mode Gshdsl set ClockingConfigure the EthLinkKill feature Gshdsl set EthLinkKill disableGshdsl set EthLinkKill enable Gshdsl set EthLinkKillConfigure the line probe feature Gshdsl set LineProbe disableGshdsl set LineProbe enable Gshdsl set LineProbeGshdsl set action Save or shut down DSL configurationsGshdsl set action deactivate Gshdsl set action startGshdsl set clockingcombination Set I-bit of data rate Gshdsl set datarateIGshdsl set datarateI newvalue Gshdsl set dslrateTS Set data rateGshdsl set errMonIntervalCnt Set the number of allowable errors per interval Gshdsl set errMonIntervalThresholdGshdsl set errMonIntervalTime Set the length in seconds of the current intervalGshdsl set errMonStartupDelay Gshdsl set errMonTotalIntervals Gshdsl set errMonTotalIntervals newvalueGshdsl set gshannex Set the annex for the dsl portGshdsl set gshannex AnnexA Gshdsl set gshannex AnnexBGshdsl set interface Set the interface for the dsl portGshdsl set interface atm Gshdsl set interface hdlcGshdsl set terminal Set the unit as a CO or a CPEGshdsl set terminal central Gshdsl set terminal remoteGshdsl seta Modify an attribute for G.SHDSLGshdsl show Display an atttribute for G.SHDSLExample Output gshdsl show Gshdsl showGshdsl showTestMode Display test mode informationExample Output gshdsl showTestMode Gshdsl showc Display error countersExample Output gshdsl showc Help Commands Display help menu HelpHelp IP Commands Ip add defaultrouteIp add defaultroute Configure default IP routesIp add defaultroute gateway gatewayip Ip add defaultroute interface interfaceIp add interface Add an IP interfaceIp add route Add an IP routeIp add route name destip netmask Gateway gatewayipIp attach Add a transport to an IP interfaceIp attachbridge Attach a bridge to the routerCreate a virtual interface Ip attachvirtualIp attachvirtual name realinterface Ip clear Clear attributes from an IP interfaceIp delete Delete an IP interface or routeIp delete interface name Ip delete route nameIp detach Detach a transport from an IP interfaceConfigure an IP interface Ip interfaceIp interface name Example Output ip interface ip1 list proxyarpentries Example Output ip interface ip1 list secondaryipaddressesIp list Display information for an IP addressExample Output ip list arpentries Example Output ip list connectionsExample Output ip list riproutes Example Output ip list interfacesExample Output ip list routes Ip ping Ping an IP addressIp set interface Configure specific settings for an IP interfaceIp set interface name Configure RIP settings for an IP interface Ip set ripIp set route Configure settings for an IP routeIp set route name Display information for an IP interface Ip showExample Output ip show debuginfo Example Output ip show route default Example Output ip show interface ip1Ip traceroute Start or stop a trace route processIp traceroute start Ip traceroute start nameLogger Commands Logger set Configure syslogLogger show Display syslog informationExample Output logger show Logger showPort Commands Port ethernet Configure the Ethernet portPort list Example Output port list allExample Output port list atm Example Output port list ethernetPPP Commands Ppp add transport Add a PPP over Hdlc PPPoH transportRemove all PPPoH transports Ppp clear transportsPpp clear transports Ppp delete transport Remove a single PPPoH transportList existing PPPoH transports Ppp list transportsExample Output ppp list transports Configure properties for a PPPoH transport Ppp set transportPpp set transport name Specificroute Disabled Theylogin ChapWelogin Auto LcpmaxfailDisplay properties for a specific PPPoH transport Ppp show transportExample Output ppp show transport ppp1 PPPoA Commands Add a PPP over ATM PPPoA transport Pppoa add transportPppoa add transport name Pppoa clear transports Remove all PPPoA transportsPppoa delete Remove a single PPPoA transportList existing PPPoA transports Pppoa list transportsExample Output pppoa list transports Configure properties for a PPPoA transport Pppoa set transportPppoa set transport name Port Control Protocol echo request frame at specifiedIntervals in seconds Provide the server-end of a connectionQosclass Abr CbrQfc Ubr121 Display properties for a specific PPPoA transport Pppoa show transportExample Output pppoa show transport ppp1 PPPoE Commands Add a PPP over Ethernet PPPoE transport Pppoe add transportPppoe add transport name dialout Pppoe clear transports Remove all PPPoE transportsPppoe delete transport Remove a single PPPoE transportList existing PPPoE transports Pppoe list transportsExample Output pppoe list transports Configure properties for a PPPoE transport Pppoe set transportPppoe set transport name Eth Port MbsPvc Portvpivci Create a default route to the subnet Pppoe show transport Display properties for a specific PPPoE transportRFC1483 Commands Create a new transport Rfc1483 add transportRfc1483 add transport name Rfc1483 clear transports Remove all RFC1483 transportsRfc1483 delete transport Remove a single RFC1483 transportRfc1483 list transports List existing RFC1483 transportsExample Output rfc1483 list transports Rfc1483 list transportsRfc1483 set transport Configure properties for an RFC1483 transportRfc1483 set transport name Rfc1483 set transportDisplay properties for a specific RFC1483 transport Rfc1483 show transportExample Output rfc1483 show transport rfc1 Security Commands Security add Add security interfaces and triggersSecurity clear Clear interfaces and triggersSecurity clear interfaces Security clear triggersSecurity delete Delete a specified interface or triggerSecurity delete interface name Security delete trigger nameSecurity disable Disable security featuresSecurity enable Enable security featuresSecurity list List interfaces and triggersExample Output security list interfaces Example Output security list triggersConfigure settings for security triggers Security set triggerSecurity show Display information about a specific interface or triggerExample Output security show interface ip1 Example Output security show trigger t2h323Display information about all security features Security statusExample Output security status Security statusSnmp Commands Snmp add Add community and trap entriesSnmp delete Delete community and trap entriesSnmp delete community IndexSnmp save Save configurationConfigure Snmp properties Snmp setSnmp set Snmp show Display information for an Snmp configurationExample Output snmp show Snmp showSource Commands Read a file of commands Source filenameSystem Commands System add login Name System addAdd a user to the system CommentSystem config Manage the system configurationSystem cpu Example Output system cpu npOverThresholdExample Output system cpu npThreshold get Example Output system cpu npUsageExample Output system cpu ppThreshold get Example Output system cpu ppUsageSystem delete login name System deleteRemove system users System delete user nameSystem ifTable reset Reset packet countersDisplay hardware/software information System infoExample Output system info Show copyright information System legalExample Output system legal Example Output system list errors Example Output system list loginsSystem list List system informationExample Output system list users Set system logging options System logExample Output system log list Example Output system log list op System restart Set user privileges System setSystem set Example Output system show firmware update protection System showDisplay system information Example Output system show aticmemTransport Commands Transports clear Clear all transportsTransports delete Delete a specific transportList all transports Transports listExample Output transports list Display information about a specific transport Transports showExample Output transports show eth1 User Commands Switch users User changeUser logout Log out from the systemUser password Change a user’s passwordWebserver Commands Webserver clear Clear Web Server statisticsWebserver disable Disable the Web Server processWebserver enable Enable the Web Server processLoad derived archive for static content Webserver loadWebserver set Webserver setWebserver show Display information about the Web ServerExample Output webserver show info Example Output webserver show stats
Related manuals
Manual 58 pages 54.63 Kb