
Chapter 19 Application Patrol
ZyWALL (ZLD) CLI Reference Guide
164
19.2.3 Exception Commands for Pre-defined Applications
This table lists the commands for exception rules for application access controls. These
commands are used for backward compatible only.
[no] inbound-dscp-mark {<0..63> | class
{default | dscp_class}}
This is how the ZyWALL handles the DSCP value
of the outgoing packets to a connection’s initiator
that match this policy.
Enter a DSCP value to have the ZyWALL apply
that DSCP value. Set this to the class default to
have the ZyWALL set the DSCP value to 0.
[no] log [alert] Creates log entries (and alerts) for traffic that
matches the rule. The
no command does not
create any log entries.
[no] outbound-dscp-mark {<0..63> | class
{default | dscp_class}}
This is how the ZyWALL handles the DSCP value
of the outgoing packets from a connection’s initiator
that match this policy.
Enter a DSCP value to have the ZyWALL apply
that DSCP value. Set this to the class default to
have the ZyWALL set the DSCP value to 0.
port <0..65535> Specifies the destination port. 0 means any.
[no] schedule profile_name Adds the specified schedule to the rule.
show Displays the rule’s configuration
[no] source profile_name Adds the specified source address to the rule.
[no] to zone_name Specifies the destination zone.
[no] user username Adds the specified user to the rule.
Table 80 app protocol rule Sub-commands (continued)
COMMAND DESCRIPTION
Table 81 app Commands: Exception Rules in Pre-Defined Applications
COMMAND DESCRIPTION
app protocol_name exception insert rule_number Creates a new rule at the specified row and enters
sub-command mode. See Table 82 on page 165 for
the sub-commands.
app protocol_name exception append Creates a new rule, appends it to the end of the list,
and enters sub-command mode. See Table 82 on
page 165 for the sub-commands.
app protocol_name exception rule_number Enters sub-command mode for editing the rule at
the specified row. See Table 82 on page 165 for the
sub-commands.
app protocol_name exception rule_number
or
app protocol_name exception modify rule_number
Enters sub-command mode for editing the rule at
the specified row. See Table 82 on page 165 for the
sub-commands.
app protocol_name exception default
or
app protocol_name exception modify default
Enters sub-command mode for editing the default
rule for the application. See Table 82 on page 165
for the sub-commands.
app protocol_name exception move rule_number
to rule_number
Moves the specified rule (first index) to the
specified location. The process is (1) remove the
specified rule from the table; (2) re-number; (3)
insert the rule at the specified location.
Comentários a estes Manuais