P-660R/H-D Series User’s Guide

 

Table 130 Firewall Commands (continued)

 

 

 

 

 

 

FUNCTION

COMMAND

DESCRIPTION

 

 

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

 

minute-low <0-255>

sessions where the Prestige stops deleting

 

 

 

half-opened sessions.

 

 

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

 

max-incomplete-high <0-255>

sessions where the Prestige starts deleting old

 

 

 

half-opened sessions until it gets them down

 

 

 

to the max incomplete low.

 

 

 

 

 

 

config edit firewall attack

This command sets the threshold where the

 

 

max-incomplete-low <0-255>

Prestige stops deleting half-opened sessions.

 

 

 

 

 

 

config edit firewall attack

This command sets the threshold of half-open

 

 

tcp-max-incomplete <0-255>

TCP sessions with the same destination

 

 

 

where the Prestige starts dropping half-open

 

 

 

sessions to that destination.

 

 

 

 

 

Sets

config edit firewall set <set

This command sets a name to identify a

 

 

#> name <desired name>

specified set.

 

 

 

 

 

 

Config edit firewall set <set

This command sets whether a packet is

 

 

#> default-permit <forward

dropped or allowed through, when it does not

 

 

block>

meet a rule within the set.

 

 

 

 

 

 

Config edit firewall set <set

This command sets the time period to allow an

 

 

#> icmp-timeout <seconds>

ICMP session to wait for the ICMP response.

 

 

 

 

 

 

Config edit firewall set <set

This command sets how long a UDP

 

 

#> udp-idle-timeout <seconds>

connection is allowed to remain inactive

 

 

 

before the Prestige considers the connection

 

 

 

closed.

 

 

 

 

 

 

Config edit firewall set <set

This command sets how long Prestige waits

 

 

#> connection-timeout

for a TCP session to be established before

 

 

<seconds>

dropping the session.

 

 

 

 

 

 

Config edit firewall set <set

This command sets how long the Prestige

 

 

#> fin-wait-timeout <seconds>

leaves a TCP session open after the firewall

 

 

 

detects a FIN-exchange (indicating the end of

 

 

 

the TCP session).

 

 

 

 

 

 

Config edit firewall set <set

This command sets how long Prestige lets an

 

 

#> tcp-idle-timeout <seconds>

inactive TCP connection remain open before

 

 

 

considering it closed.

 

 

 

 

 

 

 

 

 

 

 

 

Appendix I Firewall Commands

364