Managing Policies; Viewing A List Of Policies - Siemens RUGGEDCOM ROX II User Manual

Cli
Hide thumbs Also See for RUGGEDCOM ROX II:
Table of Contents

Advertisement

RUGGEDCOM ROX II
CLI User Guide
Section 5.17.11

Managing Policies

Policies define the default actions for establishing a connection between different firewall zones. Each policy
consists of a source zone, a destination zone and an action to be performed when a connection request is
received.
The following example illustrates the policies for establishing connections between a local network and the
Internet.
Table: Example
Policy
1
2
3
Each policy controls the connection between the source and destination zones. The first policy accepts all
connection requests from the local network to the Internet. The second policy drops or ignores all connection
requests from the Internet to any device on the network. The third policy rejects all other connection requests and
sends a TCP RST or an ICMP destination-unreachable packet to the client.
The order of the policies is important. If the last policy in the example above were to be the first policy, the firewall
would reject all connection requests.
NOTE
The source and destination zones must be configured before a policy can be created. For more
information about zones, refer to
NOTE
Policies for specific hosts or types of traffic can be overridden by rules. For more information about
rules, refer to
The following sections describe how to configure and manage policies for a firewall:
Section 5.17.11.1, "Viewing a List of Policies"
Section 5.17.11.2, "Adding a Policy"
Section 5.17.11.3, "Configuring the Source Zone"
Section 5.17.11.4, "Configuring the Destination Zone"
Section 5.17.11.5, "Deleting a Policy"
Section 5.17.11.1

Viewing a List of Policies

To view a list of policies, type:
show running-config security firewall fwconfig firewall fwpolicy
Where:
• firewall is the name of the firewall
If policies have been configured, a table or list similar to the following example appears:
Managing Policies
Source Zone
Loc
Net
All
Section 5.17.8, "Managing
Section 5.17.14, "Managing
Destination Zone
Net
All
All
Zones".
Rules".
Chapter 5
Setup and Configuration
Action
ACCEPT
DROP
REJECT
283

Advertisement

Table of Contents
loading

This manual is also suitable for:

Rx1500Rx1512Rx1501Rx1510Rx1511

Table of Contents