1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
| policy
lists data-prefix-list list-name ip-prefix prefix/length
zone source-zone-name vpn vpn-id [one or more VPNs]
zone destination-zone-name vpn vpn-id [one or more VPNs]
zone-to-no-zone-internet (allow | deny)
zone-pair pair-name
source-zone source-zone-name
destination-zone destination-zone-name
zone-policy policy-name
zone-based-policy policy-name sequence number
match ip-address or port only; protocol match-parameters
action
inspect (allows a return connection),drop, pass (does not allow return connection), log other actions
default-action (drop | pass | inspect) [default is drop]
|