config firewall service custom
Configure custom services.
Syntax
config firewall service custom
edit <name>
set category {string}
set check-reset-range [disable|strict|...]
set comment {var-string}
set fqdn {string}
set icmpcode {integer}
set icmptype {integer}
set iprange {user}
set protocol [TCP/UDP/SCTP|ICMP|...]
set protocol-number {integer}
set sctp-portrange {user}
set session-ttl {user}
set tcp-halfclose-timer {integer}
set tcp-halfopen-timer {integer}
set tcp-portrange {user}
set tcp-rst-timer {integer}
set tcp-timewait-timer {integer}
set udp-idle-timer {integer}
set udp-portrange {user}
next
end
Parameters
|
Parameter |
Description |
Type |
Size |
Default |
||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
category |
Service category. |
string |
Maximum length: 63 |
|||||||||||
|
check-reset-range |
Configure the type of ICMP error message verification. |
option |
- |
default |
||||||||||
|
|
|
|||||||||||||
|
comment |
Comment. |
var-string |
Maximum length: 255 |
|||||||||||
|
fqdn |
Fully qualified domain name. |
string |
Maximum length: 255 |
|||||||||||
|
icmpcode |
ICMP code. |
integer |
Minimum value: 0 Maximum value: 255 |
|||||||||||
|
icmptype |
ICMP type, value from 0 to 255 |
integer |
Minimum value: 0 Maximum value: 255 |
|||||||||||
|
iprange |
Start and end of the IP range associated with service. |
user |
Not Specified |
|||||||||||
|
name |
Custom service name. |
string |
Maximum length: 79 |
|||||||||||
|
protocol |
Protocol type based on IANA numbers. |
option |
- |
TCP/UDP/SCTP |
||||||||||
|
|
|
|||||||||||||
|
protocol-number |
IP protocol number. |
integer |
Minimum value: 0 Maximum value: 254 |
0 |
||||||||||
|
sctp-portrange |
Multiple SCTP port ranges. |
user |
Not Specified |
|||||||||||
|
session-ttl |
Session TTL. |
user |
Not Specified |
|||||||||||
|
tcp-halfclose-timer |
Wait time to close a TCP session waiting for an unanswered FIN packet. |
integer |
Minimum value: 0 Maximum value: 86400 |
0 |
||||||||||
|
tcp-halfopen-timer |
Wait time to close a TCP session waiting for an unanswered open session packet. |
integer |
Minimum value: 0 Maximum value: 86400 |
0 |
||||||||||
|
tcp-portrange |
Multiple TCP port ranges. |
user |
Not Specified |
|||||||||||
|
tcp-rst-timer |
Set the length of the TCP CLOSE state in seconds. |
integer |
Minimum value: 5 Maximum value: 300 |
0 |
||||||||||
|
tcp-timewait-timer |
Set the length of the TCP TIME-WAIT state in seconds. |
integer |
Minimum value: 0 Maximum value: 300 |
0 |
||||||||||
|
udp-idle-timer |
UDP half close timeout. |
integer |
Minimum value: 0 Maximum value: 86400 |
0 |
||||||||||
|
udp-portrange |
Multiple UDP port ranges. |
user |
Not Specified |
|||||||||||