diff options
Diffstat (limited to 'docs/configuration/firewall/general.rst')
-rw-r--r-- | docs/configuration/firewall/general.rst | 56 |
1 files changed, 50 insertions, 6 deletions
diff --git a/docs/configuration/firewall/general.rst b/docs/configuration/firewall/general.rst index f2e01e03..c217ba6c 100644 --- a/docs/configuration/firewall/general.rst +++ b/docs/configuration/firewall/general.rst @@ -297,9 +297,9 @@ the action of the rule will be executed. Use this command to enable the logging of the default action. .. cfgcmd:: set firewall name <name> rule <1-999999> action [accept | drop | - jump | reject | return] + jump | queue | reject | return] .. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> action [accept | - drop | jump | reject | return] + drop | jump | queue | reject | return] This required setting defines the action of the current rule. If action is set to ``jump``, then ``jump-target`` is also needed. @@ -310,6 +310,20 @@ the action of the rule will be executed. To be used only when ``action`` is set to ``jump``. Use this command to specify jump target. +.. cfgcmd:: set firewall name <name> rule <1-999999> queue <0-65535> +.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> queue <0-65535> + + Use this command to set the target to use. Action queue must be defined + to use this setting + +.. cfgcmd:: set firewall name <name> rule <1-999999> queue-options + <bypass-fanout> +.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> queue-options + <bypass-fanout> + + Options used for queue target. Action queue must be defined to use this + setting + .. cfgcmd:: set firewall name <name> rule <1-999999> description <text> .. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> description <text> @@ -321,13 +335,36 @@ the action of the rule will be executed. Enable or disable logging for the matched packet. -.. cfgcmd:: set firewall name <name> rule <1-999999> log-level [emerg | - alert | crit | err | warn | notice | info | debug] -.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-level [emerg | - alert | crit | err | warn | notice | info | debug] +.. cfgcmd:: set firewall name <name> rule <1-999999> log-options level + [emerg | alert | crit | err | warn | notice | info | debug] +.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options level + [emerg | alert | crit | err | warn | notice | info | debug] Define log-level. Only applicable if rule log is enable. +.. cfgcmd:: set firewall name <name> rule <1-999999> log-options group + <0-65535> +.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options group + <0-65535> + + Define log group to send message to. Only applicable if rule log is enable. + +.. cfgcmd:: set firewall name <name> rule <1-999999> log-options snaplen + <0-9000> +.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options snaplen + <0-9000> + + Define length of packet payload to include in netlink message. Only + applicable if rule log is enable and log group is defined. + +.. cfgcmd:: set firewall name <name> rule <1-999999> log-options + queue-threshold <0-65535> +.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options + queue-threshold <0-65535> + + Define number of packets to queue inside the kernel before sending them to + userspace. Only applicable if rule log is enable and log group is defined. + .. cfgcmd:: set firewall name <name> rule <1-999999> disable .. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> disable @@ -612,6 +649,13 @@ geoip) to keep database and rules updated. Match based on packet length criteria. Multiple values from 1 to 65535 and ranges are supported. +.. cfgcmd:: set firewall name <name> rule <1-999999> packet-type + [broadcast | host | multicast | other] +.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> packet-type + [broadcast | host | multicast | other] + + Match based on packet type criteria. + .. cfgcmd:: set firewall name <name> rule <1-999999> protocol [<text> | <0-255> | all | tcp_udp] .. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> protocol [<text> | |