ADTRAN AOS Version R10.1.0 Command Reference Manual page 3158

Adtran operating system (aos)
Table of Contents

Advertisement

Command Reference Guide
policy <ipv4 acp name>
overload
no-alg
Default Values
By default, all AOS security features are disabled and there are no configured IPv4 ACP entries.
Command History
Release 2.1
Release 16.1
Release 17.1
Release A4.01
Release A5.01
60000CRG0-35E
Optional. Specifies the IPv4 ACP against which to match traffic.
The firewall attempts to match the specified IPv4 ACP with the
IPv4 ACP that is applied to the packet's egress interface as
determined by the routing table or policy-based routing
configuration. If there is a match, the firewall will process the
packet. If there is no match, the firewall will process the packet
based on the next IPv4 ACP entry or implicitly discard it if no
further IPv4 ACP entries exist.
Allows multiple source IPv4 addresses to be replaced with the
single IPv4 address specified or the primary IPv4 address of the
specified interface. This conceals private IPv4 addresses from acl
nameoutside the local network. The overload command is not
optional and must be used when using the nat source list
command with a single address or interface. To perform static 1:1
NAT, use a network address translation (NAT) pool instead (refer
to
nat source list <ipv4 acl name> pool <pool name> on page
3160).
Optional. Allows packets matching the IPv4 ACP entry to traverse
the firewall without being processed by the application-level
gateways (ALGs). This parameter, along with the appropriate IPv4
ACL, prevents specific sources from being processed by the
ALGs. For example, this option can be used to prevent specific
hosts from being uniform resource locator (URL) filtered by
configuring an IPv4 ACP entry with the no-alg parameter that
matches specific hosts followed by another IPv4 ACP entry that
matches remaining hosts. The no-alg parameter can be placed
before or after the policy <acp name> parameter.
Command was introduced.
Command was expanded to include the no-alg parameter.
Command was expanded to include the vrf parameter.
Command was expanded to include the Metro Ethernet Forum
(MEF) Metro Ethernet interface and alter the syntax for the
address vrf parameter.
Command was expanded to include the Gigabit Ethernet
interface.
Copyright © 2012 ADTRAN, Inc.
IPv4 Access Control Policy Command Set
3158

Advertisement

Table of Contents
loading

Related Products for ADTRAN AOS Version R10.1.0

This manual is also suitable for:

Aos r10.1.0

Table of Contents