config policy
Description: Configure firewall policies.
config policy
edit <name>
set *srcintf <name1>, <name2>, …
set *dstintf <name1>, <name2>, …
set *srcaddr <name1>, <name2>, …
set dnat [enable | disable]
set *dstaddr <name1>, <name2>, …
set action [accept | deny]
set status [enable | disable]
set *service <name1>, <name2>, …
set nat [enable | disable]
next
delete <name>
move <name1> [after | before] <name2>
end
purge
show
Sample command:
config firewall policy
edit test1
set srcintf lo
set dstintf any
set srcaddr all
set dnat disable
set dstaddr all
set action accept
set status enable
set service AH
set nat enable
next
edit test2
set srcintf any
set dstintf lan
set srcaddr all
set dnat disable
set dstaddr all
set action accept
set status disable
set service ALL
set nat enable
next
edit all-pass
set srcintf any
set dstintf any
set srcaddr all
set dnat disable
set dstaddr all
set action accept
set status enable
set service ALL
set nat enable
next
end
| Parameter | Description | Type | Size | Default | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| srcintf | Incoming (ingress) interface. | option | - | none | ||||||||||
|
||||||||||||||
| dstintf | Outgoing (egress) interface. | option | - | none | ||||||||||
|
||||||||||||||
| srcaddr | Source address. | option | - | none | ||||||||||
|
||||||||||||||
| dnat | Destination NAT. | option | - | disable | ||||||||||
|
||||||||||||||
|
dstaddr |
Destination address. |
option |
- |
none |
||||||||||
|
|
|
|||||||||||||
|
action |
Policy action. |
option |
- |
accept |
||||||||||
|
|
|
|||||||||||||
|
status |
Status of the policy. |
option |
- |
enable |
||||||||||
|
|
|
|||||||||||||
|
service |
Service/service group name. |
option |
- |
none |
||||||||||
|
|
|
|||||||||||||
|
nat |
Source NAT. |
option |
- |
disable |
||||||||||
|
|
|
|||||||||||||
(policy) # move test2 after all-pass
(policy) <M> # show
config firewall policy
edit test1
set srcintf lo
set dstintf any
set srcaddr all
set dnat disable
set dstaddr all
set action accept
set status enable
set service AH
set nat enable
next
edit all-pass
set srcintf any
set dstintf any
set srcaddr all
set dnat disable
set dstaddr all
set action accept
set status enable
set service ALL
set nat enable
next
edit test2
set srcintf any
set dstintf lan
set srcaddr all
set dnat disable
set dstaddr all
set action accept
set status disable
set service ALL
set nat enable
next
end