Enterasys X-Pedition XSR CLI Cli Reference Manual page 666

Enterasys security router reference guide
Table of Contents

Advertisement

Firewall Feature Set Commands
Also, all firewall object names including pre‐defined objects such as ANY_EXTERNAL and user‐
defined object names are case‐sensitive.
Syntax
ip firewall network name {A.B.C.D mask A.B.C.D | A.B.C.D A.B.C.D}{internal |
external}
name
A.B.C.D A.B.C.D
A.B.C.D mask A.B.C.D
internal or external
Syntax of the "no" Form
The no form of this command disables the firewall network object:
no ip firewall network name
Syntax
Global configuration: 
Example
This example defines internal and external IP addresses for the network objects sales and remote‐
access. Note how the internal and external tags have meaning in the way the network objects are 
used in a policy.
XSR(config)#ip firewall network sales 192.168.100.0 mask 255.255.255.0 internal
XSR(config)#ip firewall network remote-access 10.1.1.0 mask 255.255.255.0 external
ip firewall network-group
This command comprises a set of network objects, serving the same function as a network object. 
Intrinsic values ANY_INTERNAL (all internal network objects defined) and ANY_EXTERNAL 
(all external network objects defined) are a convenient option to define a set of network objects.
Membership in these sets is unlimited.
A name for any firewall object must use these alpha‐numeric characters only: 
case), 
16-122 Configuring Security
Notes: A DMZ is considered an internal network.
Use care when you have a configuration with internal and external addresses that overlap and exist
off the same physical interface. In this case, the XSR may not be able to identify an address in the
overlap range as being internal or external. If this is so, packets may not match policies as expected.
Once you specify a network name you cannot switch internal/external settings. To switch settings
you must delete the network and add it again.
XSR(config)#
0
9
-
_
 ‐ 
 (dash), or
 (underscore). Also, all firewall object names including pre‐defined 
Name of the network object, not to exceed 16 characters. 
Match this with 
policy
Start and end addresses.
Base address and mask in dotted decimal format.
Address qualifier.
 source/destination name exactly.
A
Z
 ‐ 
 (upper or lower 

Advertisement

Table of Contents
loading

This manual is also suitable for:

X-pedition xsr

Table of Contents