Section 31.3.4 – Westermo RedFox Series User Manual

Page 737

Advertising
background image

Westermo OS Management Guide

Version 4.17.0-0

31.3.4

Configure Packet Modify Rule

Syntax [no] modify [pos <NUM>] [passive]

[match [in <IFNAME>] [out <IFNAME>]

[src <ADDR[/LEN]>] [dst <ADDR[/LEN]>]
[proto <NAME|NUM>] [dport <PORTRANGE>] ]

set dscp <VALUE> [adjust-prio]

Context

Firewall Configuration

context

Usage Add or delete a modify rule to change the DSCP bits in the IP header for

routed traffic.

Rule maintenance parameters (insert position, activate/deactivate or

delete rule):

Modifier rules are inserted and evaluated in order. The ”pos <NUM>”

parameter controls at what position in the rule order this modify rule
should be inserted, or when it comes to removing a rule, which rule
to remove. The order is kept compact (see ”Delete rule” below).
Use the ”show modify” command to list the current modifier rule
list and their position numbers. Examples:

Insert rule: Use, e.g., ”modify pos 4 match in vlan2 set dscp

30” will insert a modifier rule at position 4 in the list of modifier
rules. The rule previously at position 4 will now have position 5,
and so on.

If no position argument is given, the modifier rule will be inserted
last in the list. The position of a command can be modified using
the ”move” command (see

section 31.3.10

).

Delete rule: Use, e.g., ”no modify pos 5” to delete the modi-

fier rule at position 5 from the list of modifier rules. The rule pre-
viously at position 6 will now have position 5, and so on, keeping
the list compact.

A rule can also be deleted by using the no-form, e.g., the rule
”modify match in vlan1 out vlan2 set dscp 0” can be deleted
by the command ”no modify match in vlan1 out vlan2 set
dscp 0”
.

The ”passive” parameter specify that this rule is created as in-

active. It will be shown in config but not used. To enable use
”passive” command, see

section 31.3.11

.

➞ 2015 Westermo Teleindustri AB

737

Advertising
This manual is related to the following products: