当前位置:网站首页>FortiGate firewall filters the specified session and cleans it up
FortiGate firewall filters the specified session and cleans it up
2022-06-29 03:09:00 【Call me a little match】
This article mainly introduces how to set session filtering conditions through the command line , The corresponding filtering session details and clearing sessions are displayed .
FG600D3918701304 # diagnose sys session filter( Set filter conditions )
vd Index of virtual domain. -1 matches all.
sintf Source interface.
dintf Destination interface.
src Source IP address.
nsrc NAT'd source ip address
dst Destination IP address.
proto Protocol number.
sport Source port.
nport NAT'd source port
dport Destination port.
policy Policy ID.
expire expire
duration duration
proto-state Protocol state.
session-state1 Session state1.
session-state2 Session state2.
clear Clear session filter.
negate Inverse filter.
FG600D3918701304 # diagnose sys session filter src 10.10.10.1( Set filter condition as source address 10.10.10.1)
FG600D3918701304 # diagnose sys session list( List the sessions that match the filter criteria )
session info: proto=17 proto_state=01 duration=18 expire=161 timeout=0 flags=00000000 sockflag=00000000 sockport=7900 av_idx=0 use=6
origin-shaper=
reply-shaper=
per_ip_shaper=
ha_id=0 policy_dir=0 tunnel=/ helper=dns-udp vlan_cos=0/255
state=redir log local may_dirty nlb none
statistic(bytes/packets/allow_err): org=55/1/1 reply=71/1/1 tuples=3
tx speed(Bps/kbps): 2/0 rx speed(Bps/kbps): 3/0
orgin->sink: org pre->post, reply pre->post dev=18->54/54->18 gwy=113.102.128.1/10.10.10.1
hook=post dir=org act=snat 10.10.10.1:54831->223.5.5.5:53(113.102.131.230:54831)
hook=pre dir=reply act=dnat 223.5.5.5:53->113.102.131.230:54831(10.10.10.1:54831)
hook=post dir=reply act=noop 223.5.5.5:53->10.10.10.1:54831(0.0.0.0:0)
misc=0 policy_id=47 auth_info=0 chk_client_info=0 vd=0
serial=012ee90e tos=40/40 app_list=0 app=0 url_cat=0
dd_type=0 dd_mode=0
npu_state=0x040400
no_ofld_reason: redir-to-av non-npu-intf
session info: proto=17 proto_state=01 duration=9 expire=170 timeout=0 flags=00000000 sockflag=00000000 sockport=7900 av_idx=0 use=6
origin-shaper=
reply-shaper=
per_ip_shaper=
ha_id=0 policy_dir=0 tunnel=/ helper=dns-udp vlan_cos=0/255
state=redir log local may_dirty nlb none
statistic(bytes/packets/allow_err): org=71/1/1 reply=148/1/1 tuples=3
tx speed(Bps/kbps): 7/0 rx speed(Bps/kbps): 15/0
orgin->sink: org pre->post, reply pre->post dev=18->54/54->18 gwy=113.102.128.1/10.10.10.1
hook=post dir=org act=snat 10.10.10.1:56119->223.5.5.5:53(113.102.131.230:56119)
hook=pre dir=reply act=dnat 223.5.5.5:53->113.102.131.230:56119(10.10.10.1:56119)
hook=post dir=reply act=noop 223.5.5.5:53->10.10.10.1:56119(0.0.0.0:0)
misc=0 policy_id=47 auth_info=0 chk_client_info=0 vd=0
serial=012eedd7 tos=40/40 app_list=0 app=0 url_cat=0
dd_type=0 dd_mode=0
npu_state=0x040400
no_ofld_reason: redir-to-av non-npu-intf
......
FG600D3918701304 # diagnose sys session clear( Clear all sessions that match the filter criteria )
FG600D3918701304 # diagnose sys session list( View all sessions that match the filter criteria again )
total session 0( Session is 0)
FG600D3918701304 # diagnose sys session filter clear( Clear the set filter conditions )
边栏推荐
- Ten commands commonly used in SVN
- 信息学奥赛一本通 1361:产生数(Produce) | 洛谷 P1037 [NOIP2002 普及组] 产生数
- Merge sort
- matlab习题 —— 图像绘制练习
- Map and set use pari as the key value. How to define
- Tortoise does not display a green Icon
- Is the account opening of GF Securities really safe and reliable
- LinkedList learning
- 线程池是什么老鸡?
- PAT甲级 A1057 Stack
猜你喜欢

2022-2028 global pneumatic test probe industry survey and trend analysis report

音响是如何把微弱声音放大呢

Nvisual helps integrators transform

层次分析法(AHP)

sql连续登录问题

18. `bs object Node name next_ Sibling` get sibling nodes
![[leetcode daily question] number of schemes to reconstruct a tree](/img/82/2ed8c9747f9fa36fde4f18cf8966be.jpg)
[leetcode daily question] number of schemes to reconstruct a tree

Double click events and click events

FPGA(七)RTL代码之三(复杂电路设计2)
![The continued movement of Jerry's watch [chapter]](/img/3e/f8b98997320580431a8e7117f4a506.jpg)
The continued movement of Jerry's watch [chapter]
随机推荐
LinkedList learning
18. `bs对象.节点名.next_sibling` 获取兄弟节点
In depth analysis of Apache bookkeeper series: Part 3 - reading principle
PAT甲级 A1057 Stack
PWN新手入门Level0
Concise words tell about technical people who must master basic IT knowledge and skills. Part 1
Is it safe for qiniu school to open an account in 2022?
PMP商业分析概述
认证培训|StreamNative Certification 培训第2期
PWN攻防世界guess_num
逆序对对数计算,顺序对对数计算——归并排序
Démarrer le test - test d'intégration
How to optimize databases and tables
PWN attack and defense world guess_ num
Matlab exercises - image drawing exercises
Altium Designer中从已有的PCB中导出所有元件的封装的方法
Leetcode counts the logarithm of points that cannot reach each other in an undirected graph
In the name of love, fresh e-commerce companies rush to sell flowers on Valentine's Day
There's a mystery behind the little login
MySQL binlog log cleanup