beautypg.com

ZyXEL Communications ZYWALL10 User Manual

Page 247

background image

ZyWALL 10 Internet Security Gateway

CLI Commands

I

Function

CLI Syntax

Description

Config edit firewall set
default-permit

Edits whether a packet is dropped or allowed through, when
it does not meet a rule within the set.

Config edit firewall set
icmp-timeout

Edits the time limit, in seconds, for an idle ICMP session,
before it is terminated.

Config edit firewall set
udp-idle-timeout

Edits the time limit, in seconds, for an idle UDP session,
before it is terminated.

Config edit firewall set
connection-timeout

Edits the wait time, in seconds, for the SYN traffic in initiating
a TCP session, before it is terminated.

Config edit firewall set
fin-wait-timeout

Edits the wait time, in seconds, for the FIN traffic in
concluding a TCP session, before it is terminated.

Config edit firewall set
tcp-idle-timeout

Edits the time limit, in seconds, for an idle TCP session,
before it is terminated.

Config edit firewall set
log

Switches on/off the logs for matching default permit.

R

R

u

u

l

l

e

e

s

s

Config edit firewall set
rule
permit

Edits whether a packet is dropped or allowed through, when
it meets this rule.

Config edit firewall set
rule
active

Edits whether a rule is enabled or not.

Config edit firewall set
rule
protocol protocol value >

Edits the protocol specification number made in this rule for
ICMP currently.

Config edit firewall set
rule
log match | both>

Edits whether traffic that does match the rule, doesn't match,
both or neither is logged.

Config edit firewall set
rule
alert

Activates or deactivates the notification function, for when a
DOS attack occurs or there is a violation of any alert settings.
In case of such instances, the function will send an e-mail to
the SMTP destination address and log an alert.

config edit firewall set
rule
srcaddr-single address>

Selects and edits a source address of the traffic which
comply to this rule.