Enabling the Firewall

Enable Drop mode using the command pnic default-drop-enable. Disable Drop mode using the command pnic default-drop-disable. These commands are shown in Figure 39.

Figure 39 Enabling and Disabling Drop Mode

[root@localhost ~]# pnic default-drop-disable

No device number specified. Assuming device 0

***Disabling Default-Packet-Drop on card:0 successful!

***Temporary memory enabled.

[root@localhost ~]# pnic default-drop-enable

No device number specified. Assuming device 0

***Enabling Default-Packet-Drop on card:0 successful.

***Temporary memory disabled.

[root@localhost SW]# pnic showconf

No device number specified. Assuming device 0

Drop mode Disabled

Drop mode Enabled

DMA Capture

: on

 

MAC Rewrite state

: CH0 - disabled; CH1 - disabled

Verify Drop mode is Enabled

Default Drop Packet

: enabled

 

 

Temporary memory

: disabled

 

Aggregate mode

: enabled

 

PHY passive mode

: disabled

 

####################### On MASTER FPGA #######################

Per Flow Packet Limit

: unlimited

 

Timeout for Flow Garbage Collection : 16

 

Truncation after Match Packet

: full packet

 

####################### On PCI FPGA #######################

 

DMA Burst Size

: 1024 (Bytes)

 

DMA Flush Timer

: 1 (ms)

 

Interrupt Frequency Timer

: 5 (ms)

 

Version : P2.3.0.2 [root@localhost SW]#

76

Firewall

Page 76
Image 76
Force10 Networks 100-00055-01 manual Enabling the Firewall