Update vm-interface.md

Added the "dpi" Deep Packet Inspection option for supporting L7 firewall rules
This commit is contained in:
Zrubi 2017-05-25 11:07:49 +02:00 committed by GitHub
parent 1c01026478
commit d380133d19

View File

@ -96,6 +96,7 @@ Possible options for a single rule:
together with `proto=tcp` or `proto=udp`; for example `1-1024`, `80-80` together with `proto=tcp` or `proto=udp`; for example `1-1024`, `80-80`
- `icmptype`, value: numeric (decimal) icmp message type, for example `8` for - `icmptype`, value: numeric (decimal) icmp message type, for example `8` for
echo request, valid only together with `proto=icmp` echo request, valid only together with `proto=icmp`
- 'dpi', value: Deep Packet Inspection protocol (like: HTTP, SSL, SMB, SSH, SMTP) or the default 'NO' as no DPI, only packet filtering
Rule matches only when all predicates matches. Only one of `dst4`, `dst6`, Rule matches only when all predicates matches. Only one of `dst4`, `dst6`,
`dstname`, `specialtarget` can be used in a single rule. `dstname`, `specialtarget` can be used in a single rule.