Chapter6policy(firewall)
Parameter
Description
logThisisoptional.Itsetswhethertorecordthe
eventinlogorpromptalarmmessagewhena
packetmatchesrule.Itdoesnātrecordevent
intologbydefault.
on|off|alarm
Thisrecordstheeventintolog/doesnātrecord
theeventintolog/generatesalarm.
enableThisisoptional,indicatingwhethertoenable
thisrule.Theruleisenabledbydefault.
yes|noEnable/Disable
before
Thisisoptional.Whenaddingonenewaccess
controlrule,itisavailabletoselectbefore
whichruletoplacethisnewrule.Thenew
ruleisplacedatendbydefault.
<number>
Thisisonenumber,indicatingIDofadded
accesscontrolrule.
ExampleT oaddoneaccesscontrolrule,executethefollowingcommand:
policyaddactionacceptsrcareaāarea_gei_5/1āsrc
āanyāserviceIPdpiāhttp_policyāarāmsnāavon
logon
enableyesvsid0
policymodify
Command
Function
Thiscommandisusedtomodifyoneaddedaccesscontrolrule.
CommandFormatpolicymodifyid<number1>[action<accept|deny>][srcarea
<string1>][dstarea<string2>][srcvlan<string3>][dstvlan
<string4>][src<string5>][dst<string6>][service<str
ing7>][schedule<string8>][sport<string9>][orig_dst
<string10>][dpi<string11>][ar<string12>][av<on|off>][
permanent<on|off>][log<on|off>][enable<yes|no>]
Parameter
Description
Parameter
Description
modifyThismodifiesoneFWaccessrule.
id
ThisisIDofdefinedaccesscontrolrule.
<number1>Thisisonenumber.
action
Thissetsaccessright.
accept|denypermit/deny
srcarea
Thissetssourcearea.
<string1>
Thisisonestring.Itmustbeoneormore
presetareaname(s).Asformultiplearea
names,spaceisusedbetweeneachtwoarea
namesandalladdressesarequotedwith
singlequotes,suchasāarea_gei_5/1ā.
dstareaThissetsdestinationarea.
ConfidentialandProprietaryInformationofZTECORPORATION71