Global Filter Set ("Ipv6 Firewall") Commands - Arris NVG599 Administrator's Handbook

Vdsl2 gateway
Table of Contents

Advertisement

Administrator's Handbook

Global Filter Set ("IPv6 Firewall") Commands

Global filter sets exist at the root level of the hierarchy, outside the umbrella of both the "ip" and "ip6"
subtrees, since they pertain to both.
Global filter set rules allow for the specification of these match attributes:
IP Protocol
Source and/or destination port:
UDP
TCP
TCP flags, for rules that specify TCP traffic
ICMP type, for IP-protocol types 1 (ICMP) and 58 (IPv6-ICMP)
LAN-side device/range:
By MAC address (or current IPv4/6 address, host name, equivalently)
IPv4 address, range, or subnet
IPv6 address or subnet
WAN-side range:
IPv4 address, range, or subnet
IPv6 address or subnet
Ingress and egress interface, by link-oid (such as "LAN")
set gfs name filterset_name enable [ on | off ]
Dynamically enables or disables the specified filter set rule.
set gfs name filterset_name default-action value [ pass | drop ]
Executes the named filter set's default action: pass or drop.
set gfs name filterset_name rule number enable [ on | off ]
Dynamically enables or disables the specified filter set rule.
set gfs name filterset_name rule number active [ on | off ]
Activates or deactivates the specified filter set rule.
set gfs name filterset_name rule number type [ either | ipv4 | ipv6 ]
Specifies whether the named filter set rule applies to IPv4, IPv6, or both (either).
set gfs name filterset_name rule number action value [ pass | drop | accept ]
Executes the named filter set's action: pass, drop, or accept.
set gfs name filterset_name rule number order number
Determines order of execution of filter set rules (1 before 2, etc). If order is unspecified, the value of order is
set to 1 more than the last order in the filter set. If order is set to an already existing order value, order values
of other rules are incremented automatically.
set gfs name filterset_name rule number match number category [ src-ip-addr |
dst-ip-addr | ip-proto | src-port | dst-port | tcp-flags | src-host-mac | dst-host-
mac | in-link-oid
128

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents