Security Mode Configuration Commands
135
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Command example: See the command example for the security firewall ipv4 add_rule dmz_wan
outbound command.
Related show command: show security firewall ipv4 setup dmz_wan
security firewall ipv4 add_rule dmz_wan inbound
This command configures a new IPv4 DMZ WAN inbound firewall rule. After you have issued
the security firewall ipv4 add_rule dmz_wan inbound command, you enter the
security-config [firewall-ipv4-dmz-wan-inbound] mode, and then you can configure one
keyword and associated parameter or associated keyword at a time in the order that you
prefer. However, note that the setting of the action keyword determines which other
keywords and parameters can you can apply to a rule.
nat_ip type Auto, WAN1, WAN2, WAN3, or
WAN4
Specifies the type of NAT IP
address for a nonblocking rule:
• Auto. The source address of the
outgoing packets is autodetected
through the configured routing
and load balancing rules.
• WAN1, WAN2, WAN3, or WAN4.
The IP address of the selected
WAN interface.
Note: The nat_ip type and
nat_ip address keywords are
mutually exclusive.
nat_ip address ipaddress The NAT IP address, if the address
is different from the IP address of a
WAN interface, for example, a
secondary WAN IP address.
Note: The nat_ip type and
nat_ip address keywords are
mutually exclusive.
Step 1 Format security firewall ipv4 add_rule dmz_wan inbound
Mode security
Keyword (might consist of two
separate words)
Associated Keyword to Select or
Parameter to Type
Description