diff options
Diffstat (limited to 'templates/firewall/name')
64 files changed, 64 insertions, 64 deletions
diff --git a/templates/firewall/name/node.def b/templates/firewall/name/node.def index 88e01c2..2f2d05b 100644 --- a/templates/firewall/name/node.def +++ b/templates/firewall/name/node.def @@ -27,4 +27,4 @@ end: if sudo /opt/vyatta/sbin/vyatta-firewall.pl --update-rules name "$VAR(@)" ; create: sudo /opt/vyatta/sbin/vyatta-firewall.pl --setup iptables name -help: Set IPv4 firewall rule set name +help: IPv4 firewall rule-set name diff --git a/templates/firewall/name/node.tag/default-action/node.def b/templates/firewall/name/node.tag/default-action/node.def index 000b3ce..db160f0 100644 --- a/templates/firewall/name/node.tag/default-action/node.def +++ b/templates/firewall/name/node.tag/default-action/node.def @@ -1,6 +1,6 @@ type: txt -help: Set firewall default-action +help: Default-action for rule-set default: "drop" diff --git a/templates/firewall/name/node.tag/description/node.def b/templates/firewall/name/node.tag/description/node.def index f56909a..e8e221b 100644 --- a/templates/firewall/name/node.tag/description/node.def +++ b/templates/firewall/name/node.tag/description/node.def @@ -1,3 +1,3 @@ type: txt -help: Set IPv4 firewall rule set description +help: Rule-set description diff --git a/templates/firewall/name/node.tag/enable-default-log/node.def b/templates/firewall/name/node.tag/enable-default-log/node.def index 96b37ea..e540d3f 100644 --- a/templates/firewall/name/node.tag/enable-default-log/node.def +++ b/templates/firewall/name/node.tag/enable-default-log/node.def @@ -1 +1 @@ -help: Set logging on default-action +help: Option to log packets hitting default-action diff --git a/templates/firewall/name/node.tag/rule/node.def b/templates/firewall/name/node.tag/rule/node.def index 08a7488..e2dc34e 100644 --- a/templates/firewall/name/node.tag/rule/node.def +++ b/templates/firewall/name/node.tag/rule/node.def @@ -2,6 +2,6 @@ tag: type: u32 -help: Set firewall rule number (1-9999) +help: Rule number (1-9999) syntax:expression: $VAR(@) > 0 && $VAR(@) <= 9999; "firewall rule number must be between 1 and 9999" diff --git a/templates/firewall/name/node.tag/rule/node.tag/action/node.def b/templates/firewall/name/node.tag/rule/node.tag/action/node.def index 88c9b53..d2af3c7 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/action/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/action/node.def @@ -1,6 +1,6 @@ type: txt -help: Set firewall rule action [REQUIRED] +help: Rule action [REQUIRED] syntax:expression: $VAR(@) in "drop", "reject", "accept", "inspect"; "action must be one of drop, reject, accept, or inspect" diff --git a/templates/firewall/name/node.tag/rule/node.tag/description/node.def b/templates/firewall/name/node.tag/rule/node.tag/description/node.def index b49b91e..90bf88b 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/description/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/description/node.def @@ -1,3 +1,3 @@ type: txt -help: Set rule description +help: Rule description diff --git a/templates/firewall/name/node.tag/rule/node.tag/destination/address/node.def b/templates/firewall/name/node.tag/rule/node.tag/destination/address/node.def index e78fd70..99d7b8a 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/destination/address/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/destination/address/node.def @@ -1,6 +1,6 @@ type: txt -help: Set destination IP address, subnet, or range +help: Destination IP address, subnet, or range comp_help: Possible completions: <x.x.x.x> IPv4 address to match diff --git a/templates/firewall/name/node.tag/rule/node.tag/destination/group/address-group/node.def b/templates/firewall/name/node.tag/rule/node.tag/destination/group/address-group/node.def index 32084d8..b768dee 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/destination/group/address-group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/destination/group/address-group/node.def @@ -1,5 +1,5 @@ type: txt -help: Set group of addresses +help: Group of addresses commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \ --action=check-set-type \ diff --git a/templates/firewall/name/node.tag/rule/node.tag/destination/group/network-group/node.def b/templates/firewall/name/node.tag/rule/node.tag/destination/group/network-group/node.def index 5fa4b9f..77a8e81 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/destination/group/network-group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/destination/group/network-group/node.def @@ -1,5 +1,5 @@ type: txt -help: Set group of networks +help: Group of networks commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \ --action=check-set-type \ diff --git a/templates/firewall/name/node.tag/rule/node.tag/destination/group/node.def b/templates/firewall/name/node.tag/rule/node.tag/destination/group/node.def index f3d9347..bb11dae 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/destination/group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/destination/group/node.def @@ -1 +1 @@ -help: Set group to match +help: Destination group diff --git a/templates/firewall/name/node.tag/rule/node.tag/destination/group/port-group/node.def b/templates/firewall/name/node.tag/rule/node.tag/destination/group/port-group/node.def index d7187cd..f6a6844 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/destination/group/port-group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/destination/group/port-group/node.def @@ -1,5 +1,5 @@ type: txt -help: Set group of ports +help: Group of ports commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \ --action=check-set-type \ diff --git a/templates/firewall/name/node.tag/rule/node.tag/destination/node.def b/templates/firewall/name/node.tag/rule/node.tag/destination/node.def index 500e0bb..dc227b7 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/destination/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/destination/node.def @@ -1 +1 @@ -help: Set firewall destination parameters +help: Destination parameters diff --git a/templates/firewall/name/node.tag/rule/node.tag/destination/port/node.def b/templates/firewall/name/node.tag/rule/node.tag/destination/port/node.def index b292864..760c0e8 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/destination/port/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/destination/port/node.def @@ -1,6 +1,6 @@ type: txt -help: Set destination port +help: Destination port comp_help: Destination port(s) can be specified as a comma-separated list of: <port name> Named port (any name in /etc/services, e.g., http) diff --git a/templates/firewall/name/node.tag/rule/node.tag/disable/node.def b/templates/firewall/name/node.tag/rule/node.tag/disable/node.def index 498a027..5c2cdfd 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/disable/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/disable/node.def @@ -1 +1 @@ -help: Set firewall rule disabled
\ No newline at end of file +help: Option to disable firewall rule diff --git a/templates/firewall/name/node.tag/rule/node.tag/fragment/match-frag/node.def b/templates/firewall/name/node.tag/rule/node.tag/fragment/match-frag/node.def index 75338e3..2f830a1 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/fragment/match-frag/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/fragment/match-frag/node.def @@ -1 +1 @@ -help: Match second and further fragments of fragmented packets +help: Second and further fragments of fragmented packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/fragment/match-non-frag/node.def b/templates/firewall/name/node.tag/rule/node.tag/fragment/match-non-frag/node.def index 3105271..3590869 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/fragment/match-non-frag/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/fragment/match-non-frag/node.def @@ -1 +1 @@ -help: Match head fragments or unfragmented packets +help: Head fragments or unfragmented packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/fragment/node.def b/templates/firewall/name/node.tag/rule/node.tag/fragment/node.def index c532d49..c3d9f02 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/fragment/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/fragment/node.def @@ -1 +1 @@ -help: Set IP fragment matching +help: IP fragment match diff --git a/templates/firewall/name/node.tag/rule/node.tag/icmp/code/node.def b/templates/firewall/name/node.tag/rule/node.tag/icmp/code/node.def index 8ff1c09..84f77b4 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/icmp/code/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/icmp/code/node.def @@ -1,5 +1,5 @@ type: u32; "ICMP code must be between 0 and 255" -help: Set ICMP code (0-255) +help: ICMP code (0-255) syntax:expression: $VAR(@) >=0 && $VAR(@) <= 255; "ICMP code must be between 0 and 255" diff --git a/templates/firewall/name/node.tag/rule/node.tag/icmp/node.def b/templates/firewall/name/node.tag/rule/node.tag/icmp/node.def index dcf9fcc..33a8e89 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/icmp/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/icmp/node.def @@ -1 +1 @@ -help: Set rule ICMP type and code information +help: ICMP type and code information diff --git a/templates/firewall/name/node.tag/rule/node.tag/icmp/type-name/node.def b/templates/firewall/name/node.tag/rule/node.tag/icmp/type-name/node.def index 4669142..c3d4420 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/icmp/type-name/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/icmp/type-name/node.def @@ -1,5 +1,5 @@ type: txt -help: Set icmp type-name to match +help: ICMP type-name allowed: array=(any echo-reply pong destination-unreachable network-unreachable host-unreachable protocol-unreachable port-unreachable diff --git a/templates/firewall/name/node.tag/rule/node.tag/icmp/type/node.def b/templates/firewall/name/node.tag/rule/node.tag/icmp/type/node.def index 9cd72b3..ce69c45 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/icmp/type/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/icmp/type/node.def @@ -1,5 +1,5 @@ type: u32; "ICMP type must be between 0 and 255" -help: Set ICMP type (0-255) +help: ICMP type (0-255) syntax:expression: $VAR(@) >=0 && $VAR(@) <= 255; "ICMP type must be between 0 and 255" diff --git a/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-ipsec/node.def b/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-ipsec/node.def index 8d4bf12..96ada47 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-ipsec/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-ipsec/node.def @@ -1 +1 @@ -help: Match inbound IPsec packets +help: Inbound IPsec packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-none/node.def b/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-none/node.def index cfcbc8a..2d717d5 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-none/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/ipsec/match-none/node.def @@ -1 +1 @@ -help: Match inbound non-IPsec packets +help: Inbound non-IPsec packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/ipsec/node.def b/templates/firewall/name/node.tag/rule/node.tag/ipsec/node.def index c905e2d..96ada47 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/ipsec/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/ipsec/node.def @@ -1 +1 @@ -help: Set inbound IPsec packet matching +help: Inbound IPsec packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/limit/burst/node.def b/templates/firewall/name/node.tag/rule/node.tag/limit/burst/node.def index 307e602..9097370 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/limit/burst/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/limit/burst/node.def @@ -1,4 +1,4 @@ type: u32 default: 1 -help: Set maximum number of packets to allow in excess of rate +help: Maximum number of packets to allow in excess of rate syntax:expression: ($VAR(@) >0) ; "Burst should be a value greater then zero" diff --git a/templates/firewall/name/node.tag/rule/node.tag/limit/node.def b/templates/firewall/name/node.tag/rule/node.tag/limit/node.def index 42081fe..75460b1 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/limit/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/limit/node.def @@ -1 +1 @@ -help: Set to match rule at a limited rate using a token bucket filter +help: Rate limit using a token bucket filter diff --git a/templates/firewall/name/node.tag/rule/node.tag/limit/rate/node.def b/templates/firewall/name/node.tag/rule/node.tag/limit/rate/node.def index 7a3b7d0..cd108f4 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/limit/rate/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/limit/rate/node.def @@ -1,5 +1,5 @@ type: txt -help: Set maximum average matching rate +help: Maximum average matching rate syntax:expression: pattern $VAR(@) "^[[:digit:]]+/(second|minute|hour|day)$" ; \ "Invalid value for rate. Rate should be specified as an integer followed by a forward slash '/' and either of these time units - second, minute, hour or day diff --git a/templates/firewall/name/node.tag/rule/node.tag/log/node.def b/templates/firewall/name/node.tag/rule/node.tag/log/node.def index 5023547..ba0e74b 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/log/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/log/node.def @@ -1,3 +1,3 @@ type: txt; "firwall logging must be enable or disable" -help: Set firewall logging +help: Option to log packets matching rule syntax:expression: $VAR(@) in "enable", "disable"; "firwall logging must be enable or disable" diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/all/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/all/node.def index 3359454..bd61a90 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/all/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/all/node.def @@ -1 +1 @@ -help: Match AppleJuice/BitTorrent/Direct Connect/eDonkey/eMule/Gnutella/KaZaA application packets +help: AppleJuice/BitTorrent/Direct Connect/eDonkey/eMule/Gnutella/KaZaA application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/applejuice/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/applejuice/node.def index 35c2182..8e9f704 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/applejuice/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/applejuice/node.def @@ -1 +1 @@ -help: Match AppleJuice application packets +help: AppleJuice application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/bittorrent/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/bittorrent/node.def index a6330de..1a56963 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/bittorrent/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/bittorrent/node.def @@ -1 +1 @@ -help: Match BitTorrent application packets +help: BitTorrent application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/directconnect/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/directconnect/node.def index ab11805..eb84108 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/directconnect/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/directconnect/node.def @@ -1 +1 @@ -help: Match Direct Connect application packets +help: Direct Connect application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/edonkey/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/edonkey/node.def index 25a97e5..255e618 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/edonkey/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/edonkey/node.def @@ -1 +1 @@ -help: Match eDonkey/eMule application packets +help: eDonkey/eMule application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/gnutella/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/gnutella/node.def index 52d9d6c..f21b60b 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/gnutella/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/gnutella/node.def @@ -1 +1 @@ -help: Match Gnutella application packets +help: Gnutella application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/kazaa/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/kazaa/node.def index a6eab48..44c3156 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/kazaa/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/kazaa/node.def @@ -1 +1 @@ -help: Match KaZaA application packets +help: KaZaA application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/p2p/node.def b/templates/firewall/name/node.tag/rule/node.tag/p2p/node.def index 9013fe5..5959d3d 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/p2p/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/p2p/node.def @@ -1 +1 @@ -help: Set P2P application packet matching +help: P2P application packets diff --git a/templates/firewall/name/node.tag/rule/node.tag/protocol/node.def b/templates/firewall/name/node.tag/rule/node.tag/protocol/node.def index 21a58eb..1e9bf89 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/protocol/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/protocol/node.def @@ -1,6 +1,6 @@ type: txt -help: Set protocol to match (protocol name in /etc/protocols or protocol number or "all") +help: Protocol to match (protocol name in /etc/protocols or protocol number or "all") comp_help:Possible completions: <text> An IP protocol name from /etc/protocols (e.g. "tcp" or "udp") diff --git a/templates/firewall/name/node.tag/rule/node.tag/recent/count/node.def b/templates/firewall/name/node.tag/rule/node.tag/recent/count/node.def index 7f72b46..efd8dd8 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/recent/count/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/recent/count/node.def @@ -1,3 +1,3 @@ type: u32 -help: Set to N to only match source addresses seen more than N times +help: Source addresses seen more than N times syntax:expression: $VAR(@) >=1 && $VAR(@) <= 255; "recent count value must be between 1 and 255" diff --git a/templates/firewall/name/node.tag/rule/node.tag/recent/node.def b/templates/firewall/name/node.tag/rule/node.tag/recent/node.def index e1be0a3..3acc871 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/recent/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/recent/node.def @@ -1 +1 @@ -help: Set parameters for matching recently seen sources +help: Parameters for matching recently seen sources diff --git a/templates/firewall/name/node.tag/rule/node.tag/recent/time/node.def b/templates/firewall/name/node.tag/rule/node.tag/recent/time/node.def index b84a0b7..9c49ed8 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/recent/time/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/recent/time/node.def @@ -1,2 +1,2 @@ type: u32 -help: Set to N to only match source addresses seen in the last N seconds +help: Source addresses seen in the last N seconds diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/address/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/address/node.def index a11b2ba..eab1cb8 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/address/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/address/node.def @@ -1,5 +1,5 @@ type: txt -help: Set source IP address, subnet, or range +help: Source IP address, subnet, or range comp_help: Possible completions: <x.x.x.x> IP address to match <x.x.x.x/x> Subnet to match diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/group/address-group/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/group/address-group/node.def index 163c068..d70ba0f 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/group/address-group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/group/address-group/node.def @@ -1,5 +1,5 @@ type: txt -help: Set group of addresses +help: Group of addresses commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \ --action=check-set-type \ diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/group/network-group/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/group/network-group/node.def index 5fa4b9f..77a8e81 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/group/network-group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/group/network-group/node.def @@ -1,5 +1,5 @@ type: txt -help: Set group of networks +help: Group of networks commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \ --action=check-set-type \ diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/group/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/group/node.def index f3d9347..7b36071 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/group/node.def @@ -1 +1 @@ -help: Set group to match +help: Source group diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/group/port-group/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/group/port-group/node.def index d7187cd..f6a6844 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/group/port-group/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/group/port-group/node.def @@ -1,5 +1,5 @@ type: txt -help: Set group of ports +help: Group of ports commit:expression: exec "sudo /opt/vyatta/sbin/vyatta-ipset.pl \ --action=check-set-type \ diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/mac-address/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/mac-address/node.def index fd10e26..ad07881 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/mac-address/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/mac-address/node.def @@ -1,3 +1,3 @@ type: txt -help: Set source MAC address +help: Source MAC address syntax:expression: exec "/opt/vyatta/sbin/vyatta-validate-type.pl macaddr_negate '$VAR(@)'" ; "invalid MAC address \"$VAR(@)\"" diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/node.def index 16ab3ad..84cdc1f 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/node.def @@ -1 +1 @@ -help: Set firewall source parameters +help: Source parameters diff --git a/templates/firewall/name/node.tag/rule/node.tag/source/port/node.def b/templates/firewall/name/node.tag/rule/node.tag/source/port/node.def index e65cbfd..4cec3cf 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/source/port/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/source/port/node.def @@ -1,5 +1,5 @@ type: txt -help: Set source port +help: Source port comp_help: Source port(s) can be specified as a comma-separated list of: <port name> Named port (any name in /etc/services, e.g., http) <1-65535> Numbered port diff --git a/templates/firewall/name/node.tag/rule/node.tag/state/established/node.def b/templates/firewall/name/node.tag/rule/node.tag/state/established/node.def index 802e35d..a4f3120 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/state/established/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/state/established/node.def @@ -1,3 +1,3 @@ type: txt -help: Set established state +help: Established state syntax:expression: $VAR(@) in "enable", "disable" ; "state value must be enable or disable" diff --git a/templates/firewall/name/node.tag/rule/node.tag/state/invalid/node.def b/templates/firewall/name/node.tag/rule/node.tag/state/invalid/node.def index ddba99f..dc6110d 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/state/invalid/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/state/invalid/node.def @@ -1,3 +1,3 @@ type: txt -help: Set invalid state +help: Invalid state syntax:expression: $VAR(@) in "enable", "disable" ; "state value must be enable or disable" diff --git a/templates/firewall/name/node.tag/rule/node.tag/state/new/node.def b/templates/firewall/name/node.tag/rule/node.tag/state/new/node.def index 23854e7..6ef1f7a 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/state/new/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/state/new/node.def @@ -1,3 +1,3 @@ type: txt -help: Set new state +help: New state syntax:expression: $VAR(@) in "enable", "disable" ; "state value must be enable or disable" diff --git a/templates/firewall/name/node.tag/rule/node.tag/state/node.def b/templates/firewall/name/node.tag/rule/node.tag/state/node.def index 3b7b383..0e38df4 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/state/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/state/node.def @@ -1 +1 @@ -help: Set session state +help: Session state diff --git a/templates/firewall/name/node.tag/rule/node.tag/state/related/node.def b/templates/firewall/name/node.tag/rule/node.tag/state/related/node.def index acddc3b..2364c31 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/state/related/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/state/related/node.def @@ -1,3 +1,3 @@ type: txt -help: Set related state +help: Related state syntax:expression: $VAR(@) in "enable", "disable" ; "state value must be enable or disable" diff --git a/templates/firewall/name/node.tag/rule/node.tag/tcp/flags/node.def b/templates/firewall/name/node.tag/rule/node.tag/tcp/flags/node.def index 95f6a68..b86e707 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/tcp/flags/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/tcp/flags/node.def @@ -1,5 +1,5 @@ type: txt -help: Set TCP flags to match +help: TCP flags to match syntax:expression: pattern $VAR(@) "^((!?ALL)|((!?(SYN|ACK|FIN|RST|PSH|URG),)*(!?(SYN|ACK|FIN|RST|PSH|URG))))$" ; \ "Invalid value for TCP flags. Allowed values : SYN ACK FIN RST URG PSH ALL When specifying more than one flag, flags should be comma-separated. diff --git a/templates/firewall/name/node.tag/rule/node.tag/tcp/node.def b/templates/firewall/name/node.tag/rule/node.tag/tcp/node.def index 636f4a2..66bc295 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/tcp/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/tcp/node.def @@ -1 +1 @@ -help: Set tcp flags to match +help: TCP flags to match diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/monthdays/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/monthdays/node.def index b5d3285..14c1d5c 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/monthdays/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/monthdays/node.def @@ -1,5 +1,5 @@ type: txt -help: Set monthdays on which to match rule +help: Monthdays to match rule on syntax:expression: pattern $VAR(@) "^!?([[:digit:]]\{1,2\}\,)*[[:digit:]]\{1,2\}$" ; \ "Incorrect value for monthdays. Monthdays should be specified as 2,12,21 For negation, add ! in front eg. !2,12,21" diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/node.def index b7e283b..238acd2 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/node.def @@ -1 +1 @@ -help: Set to match rule at a specified time +help: Time to match rule diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/startdate/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/startdate/node.def index 09a2f19..46f9eb9 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/startdate/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/startdate/node.def @@ -1,5 +1,5 @@ type: txt -help: Set to match rule starting from the given date +help: Date to start matching rule syntax:expression: pattern $VAR(@) "^[[:digit:]]\{4\}[-][[:digit:]]\{2\}[-][[:digit:]]\{2\}(T[[:digit:]]\{2\}[:][[:digit:]]\{2\}[:][[:digit:]]\{2\})?$" ; \ "Invalid value for startdate. Date should use yyyy-mm-dd format. To specify time of date with startdate, append 'T' to date followed by time in 24 hour notation diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/starttime/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/starttime/node.def index b5b149d..ab69c45 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/starttime/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/starttime/node.def @@ -1,5 +1,5 @@ type: txt -help: Set to match rule starting from the given time of day +help: Time of day to start matching rule syntax:expression: pattern $VAR(@) "^[[:digit:]]\{2\}[:][[:digit:]]\{2\}[:][[:digit:]]\{2\}$" ; \ "Incorrect value for starttime. Time should be entered using 24 hour notation - hh:mm:ss" diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/stopdate/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/stopdate/node.def index 5e58b2a..93fc8b6 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/stopdate/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/stopdate/node.def @@ -1,5 +1,5 @@ type: txt -help: Set to match rule until the given date +help: Date to stop matching rule syntax:expression: pattern $VAR(@) "^[[:digit:]]\{4\}[-][[:digit:]]\{2\}[-][[:digit:]]\{2\}(T[[:digit:]]\{2\}[:][[:digit:]]\{2\}[:][[:digit:]]\{2\})?$" ; \ "Invalid value for stopdate. Date should use yyyy-mm-dd format. To specify time of date with stopdate, append 'T' to date followed by time in 24 hour notation diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/stoptime/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/stoptime/node.def index a3afce3..4a42ca3 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/stoptime/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/stoptime/node.def @@ -1,5 +1,5 @@ type: txt -help: Set to match rule to the given time of day +help: Time of day to stop matching rule syntax:expression: pattern $VAR(@) "^[[:digit:]]\{2\}[:][[:digit:]]\{2\}[:][[:digit:]]\{2\}$" ; \ "Incorrect value for stoptime. Time should be entered using 24 hour notation - hh:mm:ss" diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/utc/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/utc/node.def index 68a0689..89c17f7 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/utc/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/utc/node.def @@ -1 +1 @@ -help: Set to interpret the times given for startdate, stopdate, starttime and stoptime to be UTC +help: Interpret times for startdate, stopdate, starttime and stoptime to be UTC diff --git a/templates/firewall/name/node.tag/rule/node.tag/time/weekdays/node.def b/templates/firewall/name/node.tag/rule/node.tag/time/weekdays/node.def index fe167ac..dd2649b 100644 --- a/templates/firewall/name/node.tag/rule/node.tag/time/weekdays/node.def +++ b/templates/firewall/name/node.tag/rule/node.tag/time/weekdays/node.def @@ -1,5 +1,5 @@ type: txt -help: Set weekdays on which to match rules on +help: Weekdays to match rule on syntax:expression: pattern $VAR(@) "^!?([[:upper:]][[:lower:]]\{2\}\,)*[[:upper:]][[:lower:]]\{2\}$" ; \ "Incorrect value for weekdays. Weekdays should be specified using the first three characters of the day with the first character capitalized eg. Mon,Thu,Sat |