conntrack
---------
.. osdx:cfgcmd:: system conntrack
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Connection tracking engine options
.. osdx:cfgcmd:: system conntrack app-detect
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Application detection
.. osdx:cfgcmd:: system conntrack app-detect debug
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Show more verbose log messages
.. osdx:cfgcmd:: system conntrack app-detect dictionary
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
:arg u32:
Priority of the dictionary, affects in the search order
:instances: Unique
.. osdx:cfgcmd:: system conntrack app-detect dictionary custom
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Custom application dictionary
.. osdx:cfgcmd:: system conntrack app-detect dictionary custom app-id
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
:arg u32:
Custom application id
:instances: Multiple
.. osdx:cfgcmd:: system conntrack app-detect dictionary custom app-id fqdn
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
:arg txt:
FQDN pattern of custom application id
:instances: Multiple
.. osdx:cfgcmd:: system conntrack app-detect dictionary custom app-id name
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
:arg txt:
Name of custom application id
.. osdx:cfgcmd:: system conntrack app-detect dictionary filename
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
:arg file:
Name of application dictionary file
.. osdx:cfgcmd:: system conntrack app-detect dns
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
DNS detection
.. osdx:cfgcmd:: system conntrack app-detect dns-host
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
DNS query hostname detection
.. osdx:cfgcmd:: system conntrack app-detect dns-host max-cnames
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Size of DNS CNAME cache
:arg u32:
Number of entries allowed in DNS CNAME cache (1-10000)
.. osdx:cfgcmd:: system conntrack app-detect enable_dict_match_priv_ip
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Allow matches of private ip addresses on no custom dictionaries
.. osdx:cfgcmd:: system conntrack app-detect http
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
HTTP detection
.. osdx:cfgcmd:: system conntrack app-detect http-host
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
HTTP Host header detection
.. osdx:cfgcmd:: system conntrack app-detect http-referer
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
HTTP Referer header detection
.. osdx:cfgcmd:: system conntrack app-detect http-url
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
HTTP request URL detection
.. osdx:cfgcmd:: system conntrack app-detect http-user-agent
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
HTTP User-Agent header detection
.. osdx:cfgcmd:: system conntrack app-detect refresh-flow-appid
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
refresh flow appid when fqdn's appid is different than ip-cache's one
.. osdx:cfgcmd:: system conntrack app-detect ssl
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
SSL/TLS detection
.. osdx:cfgcmd:: system conntrack app-detect ssl-host
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
SSL/TLS certificate host detection
.. osdx:cfgcmd:: system conntrack debug
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Show verbose conntrack log messages
.. osdx:cfgcmd:: system conntrack disable
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Disable connection tracking
.. osdx:cfgcmd:: system conntrack expect-table-size
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Size of connection tracking expect table
:arg u32:
Number of entries allowed in connection tracking expect table (1-50000000)
.. osdx:cfgcmd:: system conntrack hash-size
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Hash size for connection tracking table
:arg u32:
Size of hash to use for connection tracking table (1-50000000)
.. osdx:cfgcmd:: system conntrack modules
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Connection tracking modules settings
.. osdx:cfgcmd:: system conntrack modules ftp
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
FTP connection tracking settings
.. osdx:cfgcmd:: system conntrack modules ftp disable
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Disable FTP connection tracking
.. osdx:cfgcmd:: system conntrack modules h323
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
H.323 connection tracking settings
.. osdx:cfgcmd:: system conntrack modules h323 disable
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Disable H.323 connection tracking
.. osdx:cfgcmd:: system conntrack modules pptp
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
PPTP connection tracking settings
.. osdx:cfgcmd:: system conntrack modules pptp disable
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Disable PPTP connection tracking
.. osdx:cfgcmd:: system conntrack modules sip
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
SIP connection tracking settings
.. osdx:cfgcmd:: system conntrack modules sip disable
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Disable SIP connection tracking
.. osdx:cfgcmd:: system conntrack modules sip enable-indirect-media
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Option to support for indirect media streams
.. osdx:cfgcmd:: system conntrack modules sip enable-indirect-signalling
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Option to support for indirect signalling streams
.. osdx:cfgcmd:: system conntrack modules sip port
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Port number that SIP traffic is carried on
:arg u32:
SIP port number (1-65535)
:instances: Multiple
.. osdx:cfgcmd:: system conntrack modules tftp
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TFTP connection tracking settings
.. osdx:cfgcmd:: system conntrack modules tftp disable
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Disable TFTP connection tracking
.. osdx:cfgcmd:: system conntrack replace-clash
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Enable replace-clash feature
.. osdx:cfgcmd:: system conntrack table-size
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Size of connection tracking table
:arg u32:
Number of entries allowed in connection tracking table (1-50000000)
.. osdx:cfgcmd:: system conntrack tcp
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP options
.. osdx:cfgcmd:: system conntrack tcp half-open-connections
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Maximum number of TCP half-open connections
:arg u32:
Number of connections (1-2147483647)
.. osdx:cfgcmd:: system conntrack tcp max-retrans
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP maximum retransmit attempts
:arg u32:
Generic connection timeout in seconds (1-2147483647)
.. osdx:cfgcmd:: system conntrack tcp no-loose
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Do not track previously established connections
.. osdx:cfgcmd:: system conntrack timeout
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Connection timeout options
.. osdx:cfgcmd:: system conntrack timeout icmp
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
ICMP timeout in seconds
:arg u32:
ICMP timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout other
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
Generic connection timeout in seconds
:arg u32:
Generic connection timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP connection timeout options
.. osdx:cfgcmd:: system conntrack timeout tcp close
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP CLOSE timeout in seconds
:arg u32:
TCP CLOSE timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp close-wait
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP CLOSE-WAIT timeout in seconds
:arg u32:
TCP CLOSE-WAIT timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp established
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP ESTABLISHED timeout in seconds
:arg u32:
TCP ESTABLISHED timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp fin-wait
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP FIN-WAIT timeout in seconds
:arg u32:
TCP FIN-WAIT timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp last-ack
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP LAST-ACK timeout in seconds
:arg u32:
TCP LAST-ACK timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp syn-recv
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP SYN-RECEIVED timeout in seconds
:arg u32:
TCP SYN-RECEIVED timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp syn-sent
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP SYN-SENT timeout in seconds
:arg u32:
TCP SYN-SENT timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout tcp time-wait
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
TCP TIME-WAIT timeout in seconds
:arg u32:
TCP TIME-WAIT timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout udp
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
UDP timeout
.. osdx:cfgcmd:: system conntrack timeout udp other
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
UDP generic timeout in seconds
:arg u32:
UDP generic timeout in seconds (1-21474836)
.. osdx:cfgcmd:: system conntrack timeout udp stream
.. raw:: html
SDE
M10-Smart
M2
RS420
AresC640
UDP stream timeout in seconds
:arg u32:
UDP stream timeout in seconds (1-21474836)