Applying An Advanced Acl - Huawei AR1200-S Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
l

10.4.5 Applying an Advanced ACL

An advanced ACL can be applied to some services and functions to classify packets.
Prerequisites
An advanced ACL has been created and rules have been configured in the advanced ACL.
Context
An advanced ACL can be applied to the following services and functions:
l
l
l
l
l
l
l
Procedure
l
l
l
l
l
Issue 02 (2012-03-30)
Run the rule command with rule-id specified to add a new rule between existing rules when
the configuration order is used.
Traffic classifier
Blacklist for local attack defense
IP multicast
IPSec
Firewall
NAT
Packet filtering on an interface
Apply an advanced ACL to a traffic classifier.
To provide differentiated services based on packet information, configure traffic classifiers.
Advanced ACLs can be referenced by traffic classifiers to define rules for classifying
traffic. For details, see Configuring a Traffic Classifier.
Apply an advanced ACL to add specified users to the blacklist for local attack defense.
A blacklist is a set of unauthorized users. The AR1200-S uses advanced ACLs to add users
with a specific characteristic to a blacklist and discards the packets from the users in the
blacklist. For details, see
Apply an advanced ACL to IP multicast.
Certain functions of the Internet Group Management Protocol (IGMP), Protocol
Independent Multicast-Dense Mode (PIM-DM) and Protocol Independent Multicast-
Sparse Mode (PIM-SM) need to reference advanced ACLs. For details, see Configuration
Guide - Multicast.
Apply an advanced ACL to IPSec.
The IP Security (IPSec) protocol family is a series of protocols defined by the Internet
Engineering Task Force (IETF). This protocol family provides high quality, interoperable,
and cryptology-based security for IP packets. IPSec peers can use various security
protection measures (authentication, encryption, or both) on different data flows. The
AR1200-S can use advanced ACLs to define data flows. For details, see IPSec
Configuration.
Apply an advanced ACL to a firewall.
The attack defense system protects an internal network against attacks from external
networks. Generally, firewalls are deployed between the internal and external networks to
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
9.4.3 (Optional) Configuring a
10 ACL Configuration
Blacklist.
200

Advertisement

Table of Contents
loading

Table of Contents