############ Route Policy ############ Route and IPv6 route policies are defined in this section. This route policies can then be associated to interfaces. ************* Configuration ************* Route ===== .. cfgcmd:: set policy route This command creates a new route policy, identified by . .. cfgcmd:: set policy route description Set description for the route policy. .. cfgcmd:: set policy route enable-default-log Option to log packets hitting default-action. .. cfgcmd:: set policy route rule <1-9999> description Set description for rule in route policy. .. cfgcmd:: set policy route rule <1-9999> action drop Set rule action to drop. .. cfgcmd:: set policy route rule <1-9999> destination address Set match criteria based on destination address, where could be: * : IP address to match. * : Subnet to match. * -: IP range to match. * !: Match everything except the specified address. * !: Match everything except the specified subnet. * !-: Match everything except the specified range. .. cfgcmd:: set policy route rule <1-9999> destination group Set destination match criteria based on groups, where would be the group name/identifier. .. cfgcmd:: set policy route rule <1-9999> destination port Set match criteria based on destination port, where could be: * : Named port (any name in /etc/services, e.g., http). * <1-65535>: Numbered port. * -: Numbered port range (e.g., 1001-1005). Multiple destination ports can be specified as a comma-separated list. The whole list can also be "negated" using '!'. For example: '!22,telnet,http,123,1001-1005' .. cfgcmd:: set policy route rule <1-9999> disable Option to disable rule. .. cfgcmd:: set policy route rule <1-9999> fragment Set IP fragment match, where: * match-frag: Second and further fragments of fragmented packets. * match-non-frag: Head fragments or unfragmented packets. .. cfgcmd:: set policy route rule <1-9999> icmp Set ICMP match criterias, based on code and/or types. Types could be referenced by number or by name. .. cfgcmd:: set policy route rule <1-9999> ipsec Set IPSec inbound match criterias, where: * match-ipsec: match inbound IPsec packets. * match-none: match inbound non-IPsec packets. .. cfgcmd:: set policy route rule <1-9999> limit burst <0-4294967295> Set maximum number of packets to alow in excess of rate .. cfgcmd:: set policy route rule <1-9999> limit rate Set maximum average matching rate. Format for rate: integer/time_unit, where time_unit could be any one of second, minute, hour or day.For example 1/second implies rule to be matched at an average of once per second. .. cfgcmd:: set policy route rule <1-9999> log Option to enable or disable log matching rule. .. cfgcmd:: set policy route rule <1-9999> log Option to log matching rule. .. cfgcmd:: set policy route rule <1-9999> protocol Set protocol to match. Protocol name in /etc/protocols or protocol number, or "tcp_udp" or "all". Also, protocol could be denied by using !. .. cfgcmd:: set policy route rule <1-9999> recent <1-255|0-4294967295> Set parameters for matching recently seen sources. This match could be used by seeting count (source address seen more than <1-255> times) and/or time (source address seen in the last <0-4294967295> seconds). .. cfgcmd:: set policy route rule <1-9999> set dscp <0-63> Set packet modifications: Packet Differentiated Services Codepoint (DSCP) .. cfgcmd:: set policy route rule <1-9999> set mark <1-2147483647> Set packet modifications: Packet marking .. cfgcmd:: set policy route rule <1-9999> set table Set packet modifications: Routing table to forward packet with. .. cfgcmd:: set policy route rule <1-9999> set tcp-mss <500-1460> Set packet modifications: Explicitly set TCP Maximum segment size value. .. cfgcmd:: set policy route rule <1-9999> source address Set match criteria based on source address, where could be: * : IP address to match. * : Subnet to match. * -: IP range to match. * !: Match everything except the specified address. * !: Match everything except the specified subnet. * !-: Match everything except the specified range. .. cfgcmd:: set policy route rule <1-9999> source group Set source match criteria based on groups, where would be the group name/identifier. .. cfgcmd:: set policy route rule <1-9999> source port Set match criteria based on source port, where could be: * : Named port (any name in /etc/services, e.g., http). * <1-65535>: Numbered port. * -: Numbered port range (e.g., 1001-1005). Multiple source ports can be specified as a comma-separated list. The whole list can also be "negated" using '!'. For example: '!22,telnet,http,123,1001-1005' .. cfgcmd:: set policy route rule <1-9999> state Set match criteria based on session state. .. cfgcmd:: set policy route rule <1-9999> tcp flags Set match criteria based on tcp flags. Allowed values for TCP flags: SYN ACK FIN RST URG PSH ALL. When specifying more than one flag, flags should be comma-separated. For example : value of 'SYN,!ACK,!FIN,!RST' will only match packets with the SYN flag set, and the ACK, FIN and RST flags unset. .. cfgcmd:: set policy route rule <1-9999> time monthdays Set monthdays to match rule on. Format for monthdays: 2,12,21. To negate add ! at the front eg. !2,12,21 .. cfgcmd:: set policy route rule <1-9999> time startdate Set date to start matching rule. Format for date: yyyy-mm-dd. To specify time of date with startdate, append 'T' to date followed by time in 24 hour notation hh:mm:ss. For eg startdate value of 2009-01-21T13:30:00 refers to 21st Jan 2009 with time 13:30:00. .. cfgcmd:: set policy route rule <1-9999> time starttime Set time of day to start matching rule. Format of time: hh:mm:ss using 24 hours notation. .. cfgcmd:: set policy route rule <1-9999> time stopdate Set date to stop matching rule. Format for date: yyyy-mm-dd. To specify time of date with stopdate, append 'T' to date followed by time in 24 hour notation hh:mm:ss. For eg startdate value of 2009-01-21T13:30:00 refers to 21st Jan 2009 with time 13:30:00. .. cfgcmd:: set policy route rule <1-9999> time stoptime Set time of day to stop matching rule. Format of time: hh:mm:ss using 24 hours notation. .. cfgcmd:: set policy route rule <1-9999> time utc Interpret times for startdate, stopdate, starttime and stoptime to be UTC. .. cfgcmd:: set policy route rule <1-9999> time weekdays Weekdays to match rule on. Format for weekdays: Mon,Thu,Sat. To negate add ! at the front eg. !Mon,Thu,Sat. IPv6 Route ========== .. cfgcmd:: set policy ipv6-route This command creates a new IPv6 route policy, identified by . .. cfgcmd:: set policy ipv6-route description Set description for the IPv6 route policy. .. cfgcmd:: set policy ipv6-route enable-default-log Option to log packets hitting default-action. .. cfgcmd:: set policy ipv6-route rule <1-9999> action drop Set rule action to drop. .. cfgcmd:: set policy ipv6-route rule <1-9999> description Set description for rule in IPv6 route policy. .. cfgcmd:: set policy ipv6-route rule <1-9999> destination address Set match criteria based on destination IPv6 address, where could be: * : IPv6 address to match. * : IPv6 prefix to match. * -: IPv6 range to match. * !: Match everything except the specified address. * !: Match everything except the specified prefix. * !-: Match everything except the specified range. .. cfgcmd:: set policy ipv6-route rule <1-9999> destination port Set match criteria based on destination port, where could be: * : Named port (any name in /etc/services, e.g., http). * <1-65535>: Numbered port. * -: Numbered port range (e.g., 1001-1005). Multiple destination ports can be specified as a comma-separated list. The whole list can also be "negated" using '!'. For example: '!22,telnet,http,123,1001-1005'. .. cfgcmd:: set policy ipv6-route rule <1-9999> disable Option to disable rule. .. cfgcmd:: set policy ipv6-route rule <1-9999> icmpv6 type Set ICMPv6 match criterias, based on ICMPv6 type/code name. .. cfgcmd:: set policy ipv6-route rule <1-9999> ipsec Set IPSec inbound match criterias, where: * match-ipsec: match inbound IPsec packets. * match-none: match inbound non-IPsec packets. .. cfgcmd:: set policy ipv6-route rule <1-9999> limit burst <0-4294967295> Set maximum number of packets to alow in excess of rate .. cfgcmd:: set policy ipv6-route rule <1-9999> limit rate Set maximum average matching rate. Format for rate: integer/time_unit, where time_unit could be any one of second, minute, hour or day.For example 1/second implies rule to be matched at an average of once per second. .. cfgcmd:: set policy ipv6-route rule <1-9999> log Option to enable or disable log matching rule. .. cfgcmd:: set policy ipv6-route rule <1-9999> log Option to log matching rule. .. cfgcmd:: set policy ipv6-route rule <1-9999> protocol Set IPv6 protocol to match. IPv6 protocol name from /etc/protocols or protocol number, or "tcp_udp" or "all". Also, protocol could be denied by using !. .. cfgcmd:: set policy ipv6-route rule <1-9999> recent <1-255|0-4294967295> Set parameters for matching recently seen sources. This match could be used by seeting count (source address seen more than <1-255> times) and/or time (source address seen in the last <0-4294967295> seconds). .. cfgcmd:: set policy ipv6-route rule <1-9999> set dscp <0-63> Set packet modifications: Packet Differentiated Services Codepoint (DSCP) .. cfgcmd:: set policy ipv6-route rule <1-9999> set mark <1-2147483647> Set packet modifications: Packet marking. .. cfgcmd:: set policy ipv6-route rule <1-9999> set table Set packet modifications: Routing table to forward packet with. .. cfgcmd:: set policy ipv6-route rule <1-9999> set tcp-mss Set packet modifications: pmtu option automatically set to Path Maximum Transfer Unit minus 60 bytes. Otherwise, expliicitly set TCP MSS value from 500 to 1460. .. cfgcmd:: set policy ipv6-route rule <1-9999> source address Set match criteria based on IPv6 source address, where could be: * : IPv6 address to match * : IPv6 prefix to match * -: IPv6 range to match * !: Match everything except the specified address * !: Match everything except the specified prefix * !-: Match everything except the specified range .. cfgcmd:: set policy ipv6-route rule <1-9999> source mac-address Set source match criteria based on MAC address. Declare specific MAC address to match, or match everything except the specified MAC. .. cfgcmd:: set policy ipv6-route rule <1-9999> source port Set match criteria based on source port, where could be: * : Named port (any name in /etc/services, e.g., http). * <1-65535>: Numbered port. * -: Numbered port range (e.g., 1001-1005). Multiple source ports can be specified as a comma-separated list. The whole list can also be "negated" using '!'. For example: '!22,telnet,http,123,1001-1005'. .. cfgcmd:: set policy ipv6-route rule <1-9999> state Set match criteria based on session state. .. cfgcmd:: set policy ipv6-route rule <1-9999> tcp flags Set match criteria based on tcp flags. Allowed values for TCP flags: SYN ACK FIN RST URG PSH ALL. When specifying more than one flag, flags should be comma-separated. For example : value of 'SYN,!ACK,!FIN,!RST' will only match packets with the SYN flag set, and the ACK, FIN and RST flags unset. .. cfgcmd:: set policy ipv6-route rule <1-9999> time monthdays Set monthdays to match rule on. Format for monthdays: 2,12,21. To negate add ! at the front eg. !2,12,21 .. cfgcmd:: set policy ipv6-route rule <1-9999> time startdate Set date to start matching rule. Format for date: yyyy-mm-dd. To specify time of date with startdate, append 'T' to date followed by time in 24 hour notation hh:mm:ss. For eg startdate value of 2009-01-21T13:30:00 refers to 21st Jan 2009 with time 13:30:00. .. cfgcmd:: set policy ipv6-route rule <1-9999> time starttime Set time of day to start matching rule. Format of time: hh:mm:ss using 24 hours notation. .. cfgcmd:: set policy ipv6-route rule <1-9999> time stopdate Set date to stop matching rule. Format for date: yyyy-mm-dd. To specify time of date with stopdate, append 'T' to date followed by time in 24 hour notation hh:mm:ss. For eg startdate value of 2009-01-21T13:30:00 refers to 21st Jan 2009 with time 13:30:00. .. cfgcmd:: set policy ipv6-route rule <1-9999> time stoptime Set time of day to stop matching rule. Format of time: hh:mm:ss using 24 hours notation. .. cfgcmd:: set policy ipv6-route rule <1-9999> time utc Interpret times for startdate, stopdate, starttime and stoptime to be UTC. .. cfgcmd:: set policy ipv6-route rule <1-9999> time weekdays Weekdays to match rule on. Format for weekdays: Mon,Thu,Sat. To negate add ! at the front eg. !Mon,Thu,Sat.