NETGEAR ProSafe SRX5308 Cli Reference Manual page 132

Gigabit quad wan ssl vpn firewall
Hide thumbs Also See for ProSafe SRX5308:
Table of Contents

Advertisement

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Keyword (might consist of two
separate words)
nat_ip address
Command example:
SRX5308> security firewall ipv4 add_rule dmz_wan outbound
security-config[firewall-ipv4-dmz-wan-outbound]>
security-config[firewall-ipv4-dmz-wan-outbound]> action BLOCK_BY_SCHEDULE_ELSE_BLOCK
security-config[firewall-ipv4-dmz-wan-outbound]> schedule Schedule2
security-config[firewall-ipv4-dmz-wan-outbound]> dmz_users ANY
security-config[firewall-ipv4-dmz-wan-outbound]> wan_users ANY
security-config[firewall-ipv4-dmz-wan-outbound]> qos_profile Video
security-config[firewall-ipv4-dmz-wan-outbound]> log Never
security-config[firewall-ipv4-dmz-wan-outbound]> nat_ip type WAN1
security-config[firewall-ipv4-dmz-wan-outbound]> save
Related show command:
security firewall ipv4 edit_rule dmz_wan outbound <row id>
This command configures an existing IPv4 DMZ WAN outbound firewall rule. After you have
issued the security firewall ipv4 edit_rule dmz_wan outbound command to
specify the row to be edited (for row information, see the output of the
command), you enter the security-config
ipv4 setup dmz_wan
[firewall-ipv4-dmz-wan-outbound] mode. You can then edit one keyword and associated
parameter or associated keyword at a time in the order that you prefer. However, note that
the setting of the action keyword determines which other keywords and parameters you
can apply to a rule.
Step 1
Format
security firewall ipv4 edit_rule dmz_wan outbound <row id>
Mode
security
Step 2
Format
service_name {default_services <default service name> |
action {ALWAYS_BLOCK | ALWAYS_ALLOW |
Associated Keyword to Select or
Parameter to Type
ipaddress
show security firewall ipv4 setup dmz_wan
{custom_services <custom service name>}
BLOCK_BY_SCHEDULE_ELSE_ALLOW {schedule {Schedule1 |
Schedule2 | Schedule3}} | ALLOW_BY_SCHEDULE_ELSE_BLOCK
{schedule {Schedule1 | Schedule2 | Schedule3}}}
Security Mode Configuration Commands
132
Description
The NAT IP address, if the address
is different from the IP address of a
WAN interface, for example, a
secondary WAN IP address.
Note:
The nat_ip type and
nat_ip address keywords are
mutually exclusive.
service_name default_services CU-SEEME:TCP
show security firewall

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents