HP VPN Firewall Appliances Access Control Configuration Guide

61
Ste
p
Command
Remarks
3. Create a subnet address
object and enter subnet
address object view.
object network subnet name
By default, no subnet address
object is configured.
If the object already exists, you
enter its view.
4. Configure a description for
the object.
description description-string
Optional.
By default, no description is
configured for an object.
5. Add a subnet IP address to
the object.
subnet { net-address wildcard-mask |
exclude ip-address }
By default, a subnet address
object has no members.
Configuring an IP address group object
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter VD system view.
switchto vd vd-name
Required only when you are first logged in to the
system view of the default VD and want to
configure an object for a non-default VD.
3. Create an IP address
group object and enter IP
address group object view.
object-group network
object-group-name
By default, no IP address group object is
configured.
If the object already exists, you enter its view.
4. Configure a description for
the object.
description
description-string
Optional.
By default, no description is configured for an
object.
5. Add an IP address object
or another IP address
group object to the object.
network-object
object-name
By default, an IP address group object has no IP
address object or IP address group object
members.
The IP address object or IP address group object
member must already exist.
An IP address group object can comprise
multiple IP address object and IP address group
object members. To add multiple members,
execute this command multiple times.
Configuring a MAC address object
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter VD system view.
switchto vd vd-name
Required only when you are first logged in to the
system view of the default VD and want to
configure an object for a non-default VD.
3. Create a MAC address
object and enter MAC
address object view.
object mac name
By default, no MAC address object is configured.
If the object already exists, you enter its view.