Step Description Command Keys
25 Create applications lists which will be
used in DPI mechanism.
esr(config)# object-group
application <NAME>
<NAME> – application profile
name, set by the string of up to
31 characters.
26 Specify applications list description
(optional).
esr(config-object-group-
application)# description
<description>
<description> – profile
description, set by the string of
up to 255 characters.
27 Add necessary applications to the lists. esr(config-object-group-
application)# application <
APPLICATION >
<APPLICATION> – specifies
the application covered by the
given profile
28 Add interfaces (physical, logical, E1/
Multilink and connected), remote-
access server (l2tp, openvpn, pptp) or
tunnels (gre, ip4ip4, l2tp, lt, pppoe, pptp)
into security zones (optional).
esr(config-if-gi)# security-zone
<zone-name>
<zone-name> – up to 12
characters.
Disable Firewall functions on the
network interface (physical, logical, E1/
Multilink and connected), remote-
access server (l2tp, openvpn, pptp) or
tunnels (gre, ip4ip4, l2tp, lt, pppoe, pptp)
(optional).
esr(config-if-gi)# ip firewall disable
29 Create an interzone interaction rule set. esr(config)# security zone-pair
<src-zone-name1> <dst-zone-
name2>
<src-zone-name> – up to 12
characters.
<dst-zone-name> – up to 12
characters.
30 Create an interzone interaction rule set. esr(config-zone-pair)# rule <rule-
number>
<rule-number> – 1..10000.
31 Specify rule description (optional). esr(config-zone-rule)# description
<description>
<description> – up to 255
characters..
32 Specify the given rule force. esr(config-zone-rule)# action
<action> [ log ]
<action> – permit/deny/reject/
netflow-sample/sflow-sample
log – activation key for logging
of sessions established
according to the given rule.