Install guide
Software Version 2.9.1 69
Software Version 2.9.1
C613-10486-00 REV C
These commands limit sessions only as they are created; new or modified limit
rules do not end any sessions already established by a device.
To delete a limit rule, use the new delete firewall policy limitrule command:
delete firewall policy=policy-name limitrule=rule-id
To display the limit rules set for a policy, use the new show firewall policy
limitrule command:
show firewall policy=policy-name
limitrule[=rule-id[-rule-id]] [detail]
The show firewall policy command has also been modified to show a
summary of the number of limit rules attached to a policy.
The firewall debugging feature has been enhanced to encompass the addition
of limit rules to the firewall. The enable firewall policy debug and disable
firewall policy debug commands now include the limitrule option for
displaying debugging related to limit rules.
Command Changes
The following table summarises the new and modified commands:
Monitoring Firewall Sessions using SNMP
This Software Version allows you to use SNMP to monitor these firewall
session details:
■ the total number of sessions through the firewall
■ the number of current sessions that each private and public device has
established through the firewall
To monitor the number of current sessions that individual devices are using,
the firewall must generate a session report database. To enable the firewall to
generate this database, use the command:
enable firewall sessionreport
Note that there is a resource cost for the router or switch to maintain this
database, so session reporting is disabled by default.
To disable session reporting, use the command:
disable firewall sessionreport
Command Change
add firewall policy limitrule New command
delete firewall policy limitrule New command
disable firewall policy debug New limitrule option for debug parameter
enable firewall policy debug New limitrule option for debug parameter
set firewall policy limitrule New command
show firewall policy New Number of Limitrules field
show firewall policy limitrule New command