[index] AT-AR3050S/AT-AR4050S コマンドリファレンス 5.4.5
awplus(config)# firewall ↓ |
awplus(config-firewall)# rule permit any from private to public ↓ |
awplus(config-firewall)# rule permit mydb from private to private.wired.dbserver ↓ |
awplus(config-firewall)# rule permit any from private to private ↓ |
awplus(config-firewall)# rule permit ssh from private.wired.adminpc to dmz.servernet ↓ |
awplus(config-firewall)# rule permit http from public to dmz.servernet.web log ↓ |
awplus(config-firewall)# rule permit isakmp from public.internet.vpngw to public.internet.myself ↓ awplus(config-firewall)# rule permit esp from public.internet.vpngw to public.internet.myself ↓ |
awplus(config-firewall)# protect ↓ |
awplus# show firewall ↓ Firewall protection is enabled Active connections: 21 |
awplus# show firewall connections ↓ tcp ESTABLISHED src=192.168.1.2 dst=172.16.1.2 sport=58616 dport=23 packets=16 bytes=867 src=172.16.1.2 dst=172.16.1.1 sport=23 dport=58616 packets=11 bytes=636 [ASSURED] icmpv6 src=2001:db8::2 dst=2001:db8::1 type=128 code=0 id=1416 packets=34 bytes=3536 src=2001:db8::1 dst=2001:db8::2 type=129 code=0 id=1416 packets=34 bytes=3536 tcp TIME_WAIT src=2001:db8:1::2 dst=2001:db8:2::2 sport=42532 dport=80 packets=7 bytes=597 src=2001:db8:2::2 dst=2001:db8:1::2 sport=80 dport=42532 packets=5 bytes=651 [ASSURED] tcp TIME_WAIT src=2001:db8:1::2 dst=2001:db8:2::2 sport=48740 dport=80 packets=5 bytes=564 src=2001:db8:2::2 dst=2001:db8:1::2 sport=80 dport=48740 packets=5 bytes=594 [ASSURED] |
awplus# clear firewall connections ↓ |
Note - 本コマンドを実行すると、ファイアウォール経由のTCP通信が切断されるため注意してください。UDPやICMPの通信は継続されます。
awplus# show firewall rule ↓ [* = Rule is not valid - see "show firewall rule config-check"] ID Action App From To Hits -------------------------------------------------------------------------------- 10 permit openvpn public private 0 20 deny samba-tcp private public 0 30 deny samba-udp private public 0 40 permit ssh branch private 0 |
awplus# show firewall rule config-check ↓ Rule 10: Application does not have a protocol configured |
awplus# show firewall rule config-check ↓ All rules are valid |
(C) 2015 アライドテレシスホールディングス株式会社
PN: 613-002107 Rev.A