Fortinet Document Library

Version:


Table of Contents

CLI Reference

6.2.1
Copy Link

Configure IPv6 interface policies.

  config firewall interface-policy6
      Description: Configure IPv6 interface policies.
      edit <policyid>
          set status [enable|disable]
          set comments {var-string}
          set logtraffic [all|utm|...]
          set address-type [ipv4|ipv6]
          set interface {string}
          set srcaddr6 <name1>, <name2>, ...
          set dstaddr6 <name1>, <name2>, ...
          set service6 <name1>, <name2>, ...
          set application-list-status [enable|disable]
          set application-list {string}
          set ips-sensor-status [enable|disable]
          set ips-sensor {string}
          set dsri [enable|disable]
          set av-profile-status [enable|disable]
          set av-profile {string}
          set webfilter-profile-status [enable|disable]
          set webfilter-profile {string}
          set emailfilter-profile-status [enable|disable]
          set emailfilter-profile {string}
          set dlp-sensor-status [enable|disable]
          set dlp-sensor {string}
          set label {string}
      next
  end

config firewall interface-policy6

Parameter Name Description Type Size
status Enable/disable this policy.
enable: Enable this policy.
disable: Disable this policy.
option -
comments Comments. var-string Maximum length: 1023
logtraffic Logging type to be used in this policy (Options: all utm disable, Default: utm).
all: Log all sessions accepted or denied by this policy.
utm: Log traffic that has a security profile applied to it.
disable: Disable all logging for this policy.
option -
address-type Policy address type (IPv4 or IPv6).
ipv4: IPv4.
ipv6: IPv6.
option -
interface Monitored interface name from available interfaces. string Maximum length: 35
srcaddr6 <name> IPv6 address object to limit traffic monitoring to network traffic sent from the specified address or range.
Address name.
string Maximum length: 79
dstaddr6 <name> IPv6 address object to limit traffic monitoring to network traffic sent to the specified address or range.
Address name.
string Maximum length: 79
service6 <name> Service name.
Address name.
string Maximum length: 79
application-list-status Enable/disable application control.
enable: Enable application control
disable: Disable application control
option -
application-list Application list name. string Maximum length: 35
ips-sensor-status Enable/disable IPS.
enable: Enable IPS.
disable: Disable IPS.
option -
ips-sensor IPS sensor name. string Maximum length: 35
dsri Enable/disable DSRI.
enable: Enable DSRI.
disable: Disable DSRI.
option -
av-profile-status Enable/disable antivirus.
enable: Enable antivirus
disable: Disable antivirus
option -
av-profile Antivirus profile. string Maximum length: 35
webfilter-profile-status Enable/disable web filtering.
enable: Enable web filtering.
disable: Disable web filtering.
option -
webfilter-profile Web filter profile. string Maximum length: 35
emailfilter-profile-status Enable/disable email filter.
enable: Enable Email filter.
disable: Disable Email filter.
option -
emailfilter-profile Email filter profile. string Maximum length: 35
dlp-sensor-status Enable/disable DLP.
enable: Enable setting.
disable: Disable setting.
option -
dlp-sensor DLP sensor name. string Maximum length: 35
label Label. string Maximum length: 63

Configure IPv6 interface policies.

  config firewall interface-policy6
      Description: Configure IPv6 interface policies.
      edit <policyid>
          set status [enable|disable]
          set comments {var-string}
          set logtraffic [all|utm|...]
          set address-type [ipv4|ipv6]
          set interface {string}
          set srcaddr6 <name1>, <name2>, ...
          set dstaddr6 <name1>, <name2>, ...
          set service6 <name1>, <name2>, ...
          set application-list-status [enable|disable]
          set application-list {string}
          set ips-sensor-status [enable|disable]
          set ips-sensor {string}
          set dsri [enable|disable]
          set av-profile-status [enable|disable]
          set av-profile {string}
          set webfilter-profile-status [enable|disable]
          set webfilter-profile {string}
          set emailfilter-profile-status [enable|disable]
          set emailfilter-profile {string}
          set dlp-sensor-status [enable|disable]
          set dlp-sensor {string}
          set label {string}
      next
  end

config firewall interface-policy6

Parameter Name Description Type Size
status Enable/disable this policy.
enable: Enable this policy.
disable: Disable this policy.
option -
comments Comments. var-string Maximum length: 1023
logtraffic Logging type to be used in this policy (Options: all utm disable, Default: utm).
all: Log all sessions accepted or denied by this policy.
utm: Log traffic that has a security profile applied to it.
disable: Disable all logging for this policy.
option -
address-type Policy address type (IPv4 or IPv6).
ipv4: IPv4.
ipv6: IPv6.
option -
interface Monitored interface name from available interfaces. string Maximum length: 35
srcaddr6 <name> IPv6 address object to limit traffic monitoring to network traffic sent from the specified address or range.
Address name.
string Maximum length: 79
dstaddr6 <name> IPv6 address object to limit traffic monitoring to network traffic sent to the specified address or range.
Address name.
string Maximum length: 79
service6 <name> Service name.
Address name.
string Maximum length: 79
application-list-status Enable/disable application control.
enable: Enable application control
disable: Disable application control
option -
application-list Application list name. string Maximum length: 35
ips-sensor-status Enable/disable IPS.
enable: Enable IPS.
disable: Disable IPS.
option -
ips-sensor IPS sensor name. string Maximum length: 35
dsri Enable/disable DSRI.
enable: Enable DSRI.
disable: Disable DSRI.
option -
av-profile-status Enable/disable antivirus.
enable: Enable antivirus
disable: Disable antivirus
option -
av-profile Antivirus profile. string Maximum length: 35
webfilter-profile-status Enable/disable web filtering.
enable: Enable web filtering.
disable: Disable web filtering.
option -
webfilter-profile Web filter profile. string Maximum length: 35
emailfilter-profile-status Enable/disable email filter.
enable: Enable Email filter.
disable: Disable Email filter.
option -
emailfilter-profile Email filter profile. string Maximum length: 35
dlp-sensor-status Enable/disable DLP.
enable: Enable setting.
disable: Disable setting.
option -
dlp-sensor DLP sensor name. string Maximum length: 35
label Label. string Maximum length: 63