D-Link DFL-800 CLI Guide - Page 112

Reject, Drop, FwdFast, Allow, NAT, SAT or SLB_SAT.

Page 112 highlights

3.26. IPRule Chapter 3. Configuration Reference 3.26. IPRule Description An IP rule specifies what action to perform on network traffic that matches the specified filter criteria. Properties Index Name Action SourceInterface SourceNetwork DestinationInterface DestinationNetwork Service Schedule NATAction NATSenderAddress NATSenderPort NATPool SATTranslate SATTranslateToIP SATTranslateToPort SATAllToOne SLBStickiness SLBIdleTimeOut SLBMaxSlots SLBNetSize The index of the object, starting at 1. (Identifier) Specifies a symbolic name for the rule. (Optional) Reject, Drop, FwdFast, Allow, NAT, SAT or SLB_SAT. Specifies the name of the receiving interface to be compared to the received packet. Specifies the sender span of IP addresses to be compared to the received packet. Specifies the the destination interface to be compared to the received packet. Specifies the span of IP addresses to be compared to the destination IP of the received packet. Specifies a service that will be used as a filter parameter when matching traffic with this rule. By adding a schedule to a rule, the security gateway will only allow that rule to trigger at those designated times. (Optional) Specify sender address or Use interface address. (Default: UseInterfaceAddress) Specifies which sender address will be used. Translate to this port. (Optional) Specifies which sender address will be used. Specifies whether to translate source IP or destination IP. (Default: DestinationIP) Translate to this IP address. Translate to this port. (Optional) Rewrite all destination IPs to a single IP. (Default: No) Specifies stickiness mode. (Default: None) New connections that arrive within the idle timeout are assigned to the same real server as previous connections from that address. The timeout is refreshed after each new connection. (Default: 30) Specifies maximum number of slots for IP and network stickiness. (Default: 2048) Specifies network size for network stickiness. (Default: 24) 112

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166

3.26. IPRule
Description
An IP rule specifies what action to perform on network traffic that matches the specified filter criter-
ia.
Properties
Index
The index of the object, starting at 1. (Identifier)
Name
Specifies a symbolic name for the rule. (Optional)
Action
Reject, Drop, FwdFast, Allow, NAT, SAT or SLB_SAT.
SourceInterface
Specifies the name of the receiving interface to be compared to
the received packet.
SourceNetwork
Specifies the sender span of IP addresses to be compared to the re-
ceived packet.
DestinationInterface
Specifies the the destination interface to be compared to the re-
ceived packet.
DestinationNetwork
Specifies the span of IP addresses to be compared to the destina-
tion IP of the received packet.
Service
Specifies a service that will be used as a filter parameter when
matching traffic with this rule.
Schedule
By adding a schedule to a rule, the security gateway will only al-
low that rule to trigger at those designated times. (Optional)
NATAction
Specify sender address or Use interface address. (Default: UseIn-
terfaceAddress)
NATSenderAddress
Specifies which sender address will be used.
NATSenderPort
Translate to this port. (Optional)
NATPool
Specifies which sender address will be used.
SATTranslate
Specifies
whether
to
translate
source
IP
or
destination
IP.
(Default: DestinationIP)
SATTranslateToIP
Translate to this IP address.
SATTranslateToPort
Translate to this port. (Optional)
SATAllToOne
Rewrite all destination IPs to a single IP. (Default: No)
SLBStickiness
Specifies stickiness mode. (Default: None)
SLBIdleTimeOut
New connections that arrive within the idle timeout are assigned
to the same real server as previous connections from that address.
The timeout is refreshed after each new connection. (Default: 30)
SLBMaxSlots
Specifies maximum number of slots for IP and network stickiness.
(Default: 2048)
SLBNetSize
Specifies network size for network stickiness. (Default: 24)
3.26. IPRule
Chapter 3. Configuration Reference
112