Operation Manual

Vigor122 User’s Guide
116
T
T
e
e
l
l
n
n
e
e
t
t
C
C
o
o
m
m
m
m
a
a
n
n
d
d
:
:
i
i
p
p
f
f
v
v
i
i
e
e
w
w
IPF users to view the version of the IP filter, to view/set the log flag, to view the running IP
filter rules.
S
S
y
y
n
n
t
t
a
a
x
x
ipf view [-VcdhrtzZ]
S
S
y
y
n
n
t
t
a
a
x
x
D
D
e
e
s
s
c
c
r
r
i
i
p
p
t
t
i
i
o
o
n
n
Parameter Description
-V It means to show the version of this IP filter.
-c It means to show the running call filter rules.
-d It means to show the running data filter rules.
-h It means to show the hit-number of the filter rules.
-r It means to show the running call and data filter rules.
-t It means to display all the information at one time.
-z It means to clear a filter rule’s statistics.
-Z It means to clear IP filters gross statistics.
E
E
x
x
a
a
m
m
p
p
l
l
e
e
> > ipf view -V -c -d
------ Call Filter Rules ------
[Set 1 Rule 1]
Schedule:
Source IP: any
Destination IP: any
Service Type: TCP/UDP port from 137-139 to any
Fragments: Don't Care
Action: Block immediately
T
T
e
e
l
l
n
n
e
e
t
t
C
C
o
o
m
m
m
m
a
a
n
n
d
d
:
:
i
i
p
p
f
f
s
s
e
e
t
t
This command is used to set general rule for firewall.
S
S
y
y
n
n
t
t
a
a
x
x
ipf set [SET_NO] rule [RULE_NO] [Options]
ipf set [Options]
S
S
y
y
n
n
t
t
a
a
x
x
D
D
e
e
s
s
c
c
r
r
i
i
p
p
t
t
i
i
o
o
n
n
Parameter Description
SET_NO It means to specify the index number (from 1 to 12) of filter set.
RULE_NO It means to specify the index number (from 1 to 7) of filter rule set.
Options There are several options provided here, such as -v, -c [SET_NO], -d
[SET_NO],… and etc.
-v Type “-v” to view the configuration of general set.
-c [SET_NO] It means to setup Call Filter, e.g., -c 2. The range for the index
number you can type is “0” to “12” (0 means “disable).
-d [SET_NO] It means to setup Data Filter, e.g., -d 3. The range for the index