12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

484CHAPTER 24Configuring a Firewall--dccp-types [!] Match if DCCP packet type is , where is a comma-separated list oftypes. Valid types are REQUEST, RESPONSE, DATA, ACK, DATAACK, CLOSEREQ, CLOSE,RESET, SYNC, SYNCACK, and INVALID.--dccp-option [!] Match if DCP option is set to .dscpMatch according to 6-bit DSCP field within the TOS field in the IP header.--dscp Match if DSCP value matches.--dscp-class Match if DSCP class matches the BE, EF, AFxx, or CSx class provided.ecnMatch ECN bits of the IPv4 and TCP header.--ecn-tcp-cwrMatch if the TCP ECN CWR bit is set.--ecn-tcp-eceMatch if the TCP ECN ECE (ECN Echo) bit is set.--ecn-ip-ect Match a specific IPv4 ECT (ECN-Capable Transport). The number must bebetween 0 and 3.espMatch the SPIs in the ESP header of IPsec packets.--espspi [!] :Set specific SPI or a range of SPIs to match.fuzzyMatch the rate limit from the fuzzy logic controller.--lower-limit Minimum rate limit in packets per second.--upper-limit Maximum rate limit in packets per second.hashlimitMatch based on upper limit of average packet transfer rate. Limit is for single destinationsystem or a destination with its port. Similar to limit.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!