Stateful inspection configuration on the CLI

Do as follows to configure stateful inspection on the CLI:
1. Run the system-view command to enter the system view.
2. Enable or disable the stateful inspection function as required.
- Enable the stateful inspection function.
Run the firewall session link-state [ icmp | tcp | sctp ] check command to enable IPv4 stateful inspection.
Run the firewall ipv6 session link-state [ icmpv6 | tcp | sctp ] check command to enable IPv6 stateful inspection.
- Disable the stateful inspection function.
Run the undo firewall session link-state [ icmp | tcp ] check command to disable IPv4 stateful inspection.
Run the undo firewall ipv6 session link-state [ icmpv6 | tcp ] check command to disable IPv6 stateful inspection.
Note that after the stateful inspection function is enabled, a session can be created only when the first packet passes through the firewall. After the stateful inspection function is disabled, sessions can be created even if no subsequent packets are found.

Scroll to top