NGFW Command Line Interface Reference 233
NGFW{running-snat-rule-snat1}delete src-address exclude ipaddress 192.168.1.1
NGFW{running-snat-rule-snat1}description
Apply rule description.
Syntax
description TEXT
Example
NGFW{running-snat-rule-snat1}description "source nat rule 1"
NGFW{running-snat-rule-snat1}dst-address
Apply destination address.
Syntax
dst-address (include|exclude) group ADDRESSGROUP
dst-address (include|exclude) ipaddress A.B.C.D
dst-address (include|exclude) ipaddress A.B.C.D/M
dst-address (include|exclude) range A.B.C.D A.B.C.D
Example
NGFW{running-snat-rule-snat1}dst-address include ipaddress 192.168.1.0/24
NGFW{running-snat-rule-snat1}dst-address exclude ipaddress 192.168.1.1
NGFW{running-snat-rule-snat1}dst-address include range 192.168.1.100 192.168.1.200
NGFW{running-snat-rule-snat1}dst-zone
Apply destination security zone.
Syntax
dst-zone (include|exclude) ZONENAME
Example
NGFW{running-snat-rule-snat1}dst-zone include myzone1
NGFW{running-snat-rule-snat1}dst-zone exclude myzone1
NGFW{running-snat-rule-snat1}move
Move rule position in the rule table.
Syntax
move after SRCNATRULEID
move before SRCNATRULEID
move to position VALUE
Valid entries:
after Move rule position after the rule identifier
SRCNATRULEID Apply source NAT rule identifier
before Move rule position before the rule identifier
to Move to rule position
position Apply rule position
VALUE Apply rule position number
Example
NGFW{running-snat-rule-snat1}move after snat1
Commenti su questo manuale