Displaying And Maintaining Aspf; Aspf Configuration Examples; Aspf Ftp Application Inspection Configuration Example - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

You can apply both ASPF and packet filter to implement packet filtering. For example, you can apply a
packet filtering policy to the inbound direction of the external interface and apply an ASPF policy to the
outbound direction of the external interface. The application denies unsolicited access from the external
network to the internal network and allows return packets from external to the internal network.
Check that a connection initiation packet and the corresponding return packet pass through the same
interface, because an ASPF stores and maintains the application layer protocol status based on
interfaces.
To apply an ASPF policy on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Apply an ASPF policy to the
interface.

Displaying and maintaining ASPF

Execute display commands in any view and reset commands in user view.
Task
Display the configuration of all ASPF policies
and their applications to interfaces.
Display ASPF policy applications to interfaces.
Display the configuration of an ASPF policy.
Display ASPF sessions.
Clear ASPF session statistics.

ASPF configuration examples

ASPF FTP application inspection configuration example

Network requirements
Configure an ASPF policy on Router A to inspect the FTP traffic flows passing through Router A. Only
return packets for FTP connections initiated by users on the internal network are permitted to pass through
Router A and get into the internal network. All other types of packets from the external network to the
internal network are blocked.
Command
system-view
interface interface-type
interface-number
aspf apply policy
aspf-policy-number { inbound |
outbound }
Command
display aspf all
display aspf interface
display aspf policy aspf-policy-number
display aspf session [ ipv4 | ipv6] [ verbose ]
reset aspf session [ ipv4 | ipv6 ]
291
Remarks
N/A
N/A
By default, no ASPF policy is
applied to the interface.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents