Download Print this page

Override-Current - HP FlexNetwork MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

Parameters
application-name: Specifies an application protocol by its name, a case-insensitive string of 1 to 63
characters. The following names are not allowed:
invalid.
other.
Names of predefined application protocols.
http: Specifies HTTP packets to which the NBAR rule is applied.
tcp: Specifies TCP packets to which the NBAR rule is applied.
udp: Specifies UDP packets to which the NBAR rule is applied.
Usage guidelines
By default, predefined NBAR rules exist, and these NBAR rules cannot be deleted or modified. If the
predefined NBAR rules cannot meet the user needs, use this command to create user-defined
NBAR rules.
A user-defined NBAR rule can contain the following match criteria:
Destination IP subnet.
Source IP subnet.
Direction at which the application is recognized.
Port number.
Signatures. The logical relation of these signatures is OR, which indicates that a packet that
matches any signature matches the NBAR rule.
You can specify more than one match criterion for the rule. To match the NBAR rule, packets must
match all the match criteria in the rule.
Examples
# Create a user-defined NBAR rule named abc and apply the rule to HTTP packets.
<Sysname> system-view
[Sysname] nbar application abcd protocol http
[Sysname-nbar-application-abcd]

override-current

Use override-current to overwrite the current signature file for an update operation if the APR
signature database is automatically updated at a regular basis.
Use undo port-mapping to restore the default.
Syntax
override-current
undo override-current
Default
If the APR signature database is automatically updated at a regular basis, the current APR signature
file is not overwritten for an update operation. Instead, the device will back up the current APR
signature file.
Views
Auto-update configuration view
697

Advertisement

loading