Guidelines for Using the flowbits Keyword
Note the following when using the
flowbits keyword:
-
When using the
setxoperator, the specified state can only belong to the specified group, and not to any other group. -
You can define the
setxoperator multiple times, specifying different states and the same group with each instance. -
When you use the
setxoperator and specify a group, you cannot use theset,toggle, orunsetoperators on that specified group. -
The
issetandisnotsetoperators evaluate for the specified state regardless of whether the state is in a group. -
During intrusion policy saves, intrusion policy reapplies, and access control policy applies (regardless of whether the access control policy references one intrusion policy or multiple intrusion policies), if you enable a rule that contains the
issetorisnotsetoperator without a specified group, and you do not enable at least one rule that affectsflowbitsassignment (set,setx,unset,toggle) for the corresponding state name and protocol, all rules that affectflowbitsassignment for the corresponding state name are enabled. -
During intrusion policy saves, intrusion policy reapplies, and access control policy applies (regardless of whether the access control policy references one intrusion policy or multiple intrusion policies), if you enable a rule that contains the
issetorisnotsetoperator with a specified group, all rules that affectflowbitsassignment (set,setx,unset,toggle) and define a corresponding group name are also enabled.