Chapter 20 Application Patrol

 

 

Table 63 app Commands: Rules in Pre-Defined Applications (continued)

COMMAND

DESCRIPTION

app protocol_name rule rule_number or app

Enters sub-command mode for editing the rule at

protocol_name rule modify rule_number

the specified row.

app protocol_name rule default or app

Enters sub-command mode for editing the default

protocol_name rule modify default

rule for the application.

no app protocol_name rule rule_number

Deletes the specified rule.

20.2.2.1 Rule Sub-commands

The following table describes the sub-commands for several application patrol rule commands. Note that not all rule commands use all the sub-commands listed here.

Table 64 app protocol rule Sub-commands

COMMAND

DESCRIPTION

access {forward drop reject}

Specifies the action when traffic matches the rule.

[no] action-block

Blocks use of a specific feature.

{loginmessageaudiovideofile-transfer}

 

[no] activate

Turns on this rule. The no command turns off this

 

rule.

bandwidth {inboundoutbound} <0..1048576>

Limits inbound or outbound bandwidth, in kilobits

 

per second. 0 disables bandwidth management for

 

traffic matching this rule.

 

 

[no] bandwidth excess-usage

Enables maximize bandwidth usage to let the traffic

 

matching this policy “borrow” any unused

 

bandwidth on the out-going interface.

 

 

bandwidth priority <1..7>

Set the priority for traffic that matches this rule. The

 

smaller the number, the higher the priority.

[no] destination address_object

Adds the specified destination address to the rule.

[no] from zone_name

Specifies the source zone.

[no] inbound-dscp-mark {<0..63> class

This is how the NXC handles the DSCP value of

{default dscp_class}}

the outgoing packets to a connection’s initiator that

 

match this policy.

 

Enter a DSCP value to have the NXC apply that

 

DSCP value. Set this to the class default to have

 

the NXC set the DSCP value to 0.

 

dscp_class: default af11 af12 af13 af21

 

af22 af23 af31 af32 af33 af41 af42 af43

 

wmm_bk8 wmm_bk16 wmm_be0 wmm_be24

 

wmm_vi32 wmm_vi40 wmm_vo48 wmm_vo56

 

User_define

 

 

[no] log [alert]

Creates log entries (and alerts) for traffic that

 

matches the rule. The no command does not

 

create any log entries.

 

129

NXC CLI Reference Guide