Use this syntax when you create firewall rules for the Network IPS appliance.
Syntax rule | Description | Examples |
---|---|---|
Adapter clause | Indicates a specific adapter where the rule is applied. Note: Supported
adapter clauses are any or the letters A through
H. If you do not specify an adapter clause, the rule matches packets
on any adapter
|
adapter A adapter B adapter any |
Ethernet Clause | Filters 802.1q VLAN traffic or allows or denies specific types of Ethernet protocols. | ether vid
2 ether proto 0x86dd ether vid 3-199 proto 0x0800,0x86dd |
IP clause | Indicates the version of IP protocol and the conditions in the header that must be satisfied for the statement to match the rule. | ip IP-source-address-condition IP-destination-address-condition ipv6 IP-source-address-condition IP-destination-address-condition |
IP datagram clause | Indicates
the protocol and the protocol-specific conditions
that must be satisfied for the statement to match. Note: The supported
protocols are ICMP, ICMPv6, TCP, and UDP. You can also specify a set
of IP protocol numbers.
|
icmp ICMP-type-condition
ICMP-code-condition icmpv6 ICMP-type-condition ICMP-code-condition tcp TCP-source-port-number-condition TCP-destination-port-number-condition udp UDP-source-port-number-condition UDP-destination-port-number-condition proto protocol-number-expression |
Source and target address conditions | Indicates the set of allowable IPv4 or IPv6 addresses for the source or target for the establishment of a TCP-based connection, UDP packet, ICMP packet, or ICMPv6 packet. | src
addrIP-source-address-expression dst addrIP-destination-address-expression |
TCP/UDP source and target port conditions | Indicates the set of TCP or UDP ports for the source or target of the establishment of a (TCP) connection or a (UDP) packet. | src portport-number-expression dst portport-number-expression |
ICMP type and code conditions | Indicates the set of ICMP and ICMPv6 types or codes for either side of the packet. | type ICMP-type-expression code ICMP-code-expression |
Using ranges | Indicates a range of values for IP addresses, port numbers, ICMP message types and codes, and protocol numbers by using a dash (-) between the first and last values in the range. | ip
src addrxxx.xxx.x.x - xxx.xxx.x.xx Note: x is
a number in the IP address.
tcp dst port 20 - 80 |
Using any | Specifies any in all expressions. | ip dstaddr any icmp type any |