Appendix A: CLI Guide
1447
SonicOS Enhanced 5.6 Administrator’s Guide
Table 7 Configure Level Commands
Command Description
ACCESS RULES SUB-COMMANNDS
access-rules <from-zone>
<to-zone>
Allows configuration of access rules
between one zone and another
<add> commands
action <allow|deny|dis-
card>
Sets the action to allow, deny, or
discard an access rule
advanced Allows configuration of advanced
access rule settings
[no] allow-fragments Allows/Disallows fragmented packets
to be transferred
comment <comments> Allows administrators to record
comments related to this access rule
destination <address
object>
Configures an address object
destination for an access rule
info Displays current access rule
[no] logging Enables/Disables access rule packet
logging
maxconns <percentage> Configures maximum number of
connections in a pool
qos dscp <none|
preserve|explicit|map>
[<arg>]
Sets DSCP packet header markings
qoa 802.1p <none|
preserve|explicit|map>
[<arg>]
Sets 802.1p Ethernet packet header
markings
[no] reflexive Creates/Removes a reflexive access
ru
le
schedule <schedule
object>
Configures the schedule object for an
access rule
service <service object> Configures the service object for an
access rule
source <address object> Configures an address object source
for an access rule
tcptimeout <minutes> Sets TCP timeout in minutes
udptimeout <seconds> Sets UDP timeout in seconds
user <user object> Configures the user object for an
access rule
delete <index> Deletes specified index of access rules
list [<index>] Displays one access rule whose index
matches the specified value input. If
index is not available, all access rules
in the current zone to zone context will
display