-
Notifications
You must be signed in to change notification settings - Fork 74
add appliance firewall
stack add appliance firewall {appliance ...} {action=string} {chain=string} {protocol=string} {service=string} [comment=string] [flags=string] [network=string] [output-network=string] [rulename=string] [table=string]
Add a firewall rule for an appliance type.
-
[appliance]
Appliance type (e.g., "backend").
-
[action=string]
-
[chain=string]
-
[protocol=string]
-
[service=string]
-
{comment=string}
-
{flags=string}
-
{network=string}
-
{output-network=string}
-
{rulename=string}
-
{table=string}
The table to add the rule to. Valid values are 'filter', 'nat', 'mangle', and 'raw'. If this parameter is not specified, it defaults to 'filter'
-
stack add appliance firewall login network=private service="all" protocol="all" action="ACCEPT" chain="FORWARD"
Accept all services and all protocols on the private network for the FORWARD chain. If 'eth0' is associated with the private network on a login appliance, then this will be translated as the following iptables rule: "-A FORWARD -i eth0 -j ACCEPT"
-
stack add appliance firewall login service="8649" protocol="udp" action="REJECT" chain="INPUT"
Reject UDP packets with a destination port of 8649 on all networks for the INPUT chain. On login appliances, this will be translated into the following iptables rule: "-A INPUT -p udp --dport 8649 -j REJECT"
Checkout our Google Group or our Slack Team for any support or other questions.
Want to contribute to this Wiki? Fork it and send a pull request.
-
add
- add api blacklist command
- add api group
- add api group perms
- add api sudo command
- add api user
- add api user group
- add api user perms
- add appliance
- add appliance attr
- add appliance firewall
- add appliance route
- add appliance storage controller
- add appliance storage partition
- add attr
- add bootaction
- add box
- add cart
- add copyright
- add environment
- add environment attr
- add environment firewall
- add environment route
- add environment storage controller
- add environment storage partition
- add firewall
- add firmware
- add firmware imp
- add firmware make
- add firmware model
- add firmware version_regex
- add group
- add host
- add host attr
- add host bonded
- add host bridge
- add host firewall
- add host firmware mapping
- add host group
- add host interface
- add host interface alias
- add host key
- add host message
- add host partition
- add host route
- add host storage controller
- add host storage partition
- add network
- add os attr
- add os firewall
- add os route
- add os storage controller
- add os storage partition
- add pallet
- add pallet tag
- add route
- add storage controller
- add storage partition
- add switch host
- add switch partition
- add switch partition member
- compile
- config
- create
- disable
- dump
- enable
- help
- iterate
- list
- load
- pack
- remove
- report
- run
- set
- swap
- sync
- unload
- verify