Chapter6
policy(firewall)
TableofContents:
policyadd.........................................................................69
policymodify....................................................................71
policydelete.....................................................................73
policyadd
Command
Function
Thiscommandisusedtoaddoneaccesscontrolrule.
CommandFormatpolicyaddaction<accept|deny>[srcarea<string1>][dstarea
<string2>][srcvlan<string3>][dstvlan<string4>][src
<string5>][dst<string6>][service<string7>][schedule<str
ing8>][sport<string9>][orig_dst<string10>][permanent
<on|off>][log<on|off|alarm>][enable<yes|no>][before
<number>]
Parameter
Description
Parameter
Description
addThisaddsoneFWaccesscontrolrule.
action
Thissetsaccessprivilege,thatistopermit
ordenypacketsmatchingthisruletopass
throughFW.
accept|denypermit/deny
srcarea
Thissetssourcearea.
<string1>
Thisisonestring.Itmustbeoneormore
presetareaname(s).Asformultiplearea
names,spaceisusedbetweeneachtwoarea
namesandalladdressesarequotedwith
singlequotes,suchasāarea_gei_5/1ā.
dstareaThissetsdestinationarea.
<string2>
Thisisonestring.Itmustbeoneormore
presetareaname(s).Asformultiplearea
names,spaceisusedbetweeneachtwoarea
namesandalladdressesarequotedwith
singlequotes,suchasāarea_gei_5/1ā.
srcvlanThissetssourceVLAN.
<string3>
Thisisonestring,indicatingpresetvlan
number.
ConfidentialandProprietaryInformationofZTECORPORATION69