Zyxel USG 1900 [179/438] Secure policy command examples

Zyxel USG 1900 [179/438] Secure policy command examples
Chapter 26 Secure Policy
ZyWALL / USG (ZLD) CLI Reference Guide
179
26.2.2 Secure Policy Command Examples
These are IPv4 secure policy configuration examples. The IPv6 secure policy commands are similar.
The following example shows you how to add an IPv4 secure policy rule to allow a MyService
connection from the WAN zone to the IP addresses Dest_1 in the LAN zone.
Enter configuration command mode.
Create an IP address object.
Create a service object.
Enter the secure policy sub-command mode to add a secure policy rule.
Set the direction of travel of packets to which the rule applies.
Set the destination IP address(es).
Set the service to which this rule applies.
Set the action the ZyWALL / USG is to take on packets which match this rule.
[no] ssl-profile <profile name> {[no log]|[log by-
profile]} {activate | deactivate}
Applies the (already-created) named anti- x profile to
traffic that matches the secure-policy rule. Log by-
profile generates a log for all traffic that matches criteria
in the anti- x profile. no log does turns off logging and
overrides the anti- x profile log setting. The no command
does not apply the named anti- x profile to traffic that
matches the secure-policy rule.
[no] app-profile <profile name> {[no log]|[log by-
profile]} {activate | deactivate}
Applies the (already-created) named anti- x profile to
traffic that matches the secure-policy rule. Log by-
profile generates a log for all traffic that matches criteria
in the anti- x profile. no log does turns off logging and
overrides the anti- x profile log setting. The no command
does not apply the named anti- x profile to traffic that
matches the secure-policy rule.
Table 88 firewall Sub-commands (continued)
COMMAND DESCRIPTION
Router# configure terminal
Router(config)# service-object MyService tcp eq 1234
Router(config)# address-object Dest_1 10.0.0.10-10.0.0.15
Router(config)# secure-policy insert 3
Router(secure-policy)# from WAN
Router(v)# to LAN
Router(secure-policy)# destinationip Dest_1
Router(secure-policy)# service MyService
Router(secure-policy)# action allow

Содержание

Похожие устройства

Скачать