15.07.2012 Views

How to use fw monitor

How to use fw monitor

How to use fw monitor

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Relative position using an Alias<br />

Another possibility <strong>to</strong> specify the position of the <strong>fw</strong> moni<strong>to</strong>r module is <strong>to</strong> <strong>use</strong> a modules alias (shown in<br />

parenthesis). Compared <strong>to</strong> the relative positioning by numbers you have the additional possibility <strong>to</strong><br />

decide whether you want <strong>to</strong> insert the <strong>fw</strong> moni<strong>to</strong>r module before or after the module you specified. This<br />

can be done using + or – in front of the module alias:<br />

[Expert@cpmodule]# <strong>fw</strong> ctl chain<br />

in chain (9):<br />

0: -7f800000 (ca8d9698) IP Options Strip (ipopt_strip)<br />

1: - 2000000 (cb1c1c64) vpn decrypt (vpn)<br />

2: - 1fffff6 (ca8da0f8) Stateless verifications (asm)<br />

3: - 1fffff0 (cb1c17f0) vpn decrypt verify (vpn_ver)<br />

4: - 1000000 (ca8eb688) SecureXL connection syn (secxl_sync)<br />

5: 0 (ca8aa0c0) <strong>fw</strong> VM inbound (<strong>fw</strong>)<br />

6: 2000000 (cb1c2aa0) vpn policy inbound (vpn_pol)<br />

7: 10000000 (ca8eb728) SecureXL inbound (secxl)<br />

8: 7f800000 (ca8d98e4) IP Options Res<strong>to</strong>re (ipopt_res)<br />

out chain (8):<br />

0: -7f800000 (ca8d9698) IP Options Strip (ipopt_strip)<br />

1: - 1ffffff (cb1c16fc) vpn nat outbound (vpn_nat)<br />

2: - 1f00000 (ca8da0f8) Stateless verifications (asm)<br />

3: 0 (ca8aa0c0) <strong>fw</strong> VM outbound (<strong>fw</strong>)<br />

4: 2000000 (cb1c26e0) vpn policy outbound (vpn_pol)<br />

5: 10000000 (ca8eb728) SecureXL outbound (secxl)<br />

6: 20000000 (cb1c2164) vpn encrypt (vpn)<br />

7: 7f800000 (ca8d98e4) IP Options Res<strong>to</strong>re (ipopt_res)<br />

Figure 21: <strong>fw</strong> ctl chain – module aliases<br />

<strong>How</strong> <strong>to</strong> <strong>use</strong> <strong>fw</strong> moni<strong>to</strong>r Page 25 of 70<br />

Revision: 1.01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!