config firewall interface-policy
Configure IPv4 interface policies.
config firewall interface-policy
Description: Configure IPv4 interface policies.
edit <policyid>
set status [enable|disable]
set comments {var-string}
set logtraffic [all|utm|...]
set interface {string}
set srcaddr <name1>, <name2>, ...
set dstaddr <name1>, <name2>, ...
set service <name1>, <name2>, ...
set application-list-status [enable|disable]
set application-list {string}
set ips-sensor-status [enable|disable]
set ips-sensor {string}
set dsri [enable|disable]
set av-profile-status [enable|disable]
set av-profile {string}
set webfilter-profile-status [enable|disable]
set webfilter-profile {string}
set emailfilter-profile-status [enable|disable]
set emailfilter-profile {string}
set dlp-profile-status [enable|disable]
set dlp-profile {string}
next
end
config firewall interface-policy
Parameter |
Description |
Type |
Size |
Default |
||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
status |
Enable/disable this policy. |
option |
- |
enable |
||||||||
|
|
|||||||||||
comments |
Comments. |
var-string |
Maximum length: 1023 |
|
||||||||
logtraffic |
Logging type to be used in this policy (Options: all | utm | disable, Default: utm). |
option |
- |
utm |
||||||||
|
|
|||||||||||
interface |
Monitored interface name from available interfaces. |
string |
Maximum length: 35 |
|
||||||||
srcaddr |
Address object to limit traffic monitoring to network traffic sent from the specified address or range. Address name. |
string |
Maximum length: 79 |
|
||||||||
dstaddr |
Address object to limit traffic monitoring to network traffic sent to the specified address or range. Address name. |
string |
Maximum length: 79 |
|
||||||||
service |
Service object from available options. Service name. |
string |
Maximum length: 79 |
|
||||||||
application-list-status |
Enable/disable application control. |
option |
- |
disable |
||||||||
|
|
|||||||||||
application-list |
Application list name. |
string |
Maximum length: 35 |
|
||||||||
ips-sensor-status |
Enable/disable IPS. |
option |
- |
disable |
||||||||
|
|
|||||||||||
ips-sensor |
IPS sensor name. |
string |
Maximum length: 35 |
|
||||||||
dsri |
Enable/disable DSRI. |
option |
- |
disable |
||||||||
|
|
|||||||||||
av-profile-status |
Enable/disable antivirus. |
option |
- |
disable |
||||||||
|
|
|||||||||||
av-profile |
Antivirus profile. |
string |
Maximum length: 35 |
|
||||||||
webfilter-profile-status |
Enable/disable web filtering. |
option |
- |
disable |
||||||||
|
|
|||||||||||
webfilter-profile |
Web filter profile. |
string |
Maximum length: 35 |
|
||||||||
emailfilter-profile-status |
Enable/disable email filter. |
option |
- |
disable |
||||||||
|
|
|||||||||||
emailfilter-profile |
Email filter profile. |
string |
Maximum length: 35 |
|
||||||||
dlp-profile-status |
Enable/disable DLP. |
option |
- |
disable |
||||||||
|
|
|||||||||||
dlp-profile |
DLP profile name. |
string |
Maximum length: 35 |
|