Huawei AR1200-S Configuration Manual page 99

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
[Huawei-Vlanif100] quit
[Huawei] interface gigabitethernet 0/0/1
[Huawei-GigabitEthernet0/0/1] ip address 202.39.2.1
24
[Huawei-GigabitEthernet0/0/1] zone untrust
[Huawei-GigabitEthernet0/0/1] quit
Step 3 Configure the ACL on Router .
[Huawei] acl 2102
[Huawei-acl-basic-2102] rule permit source 129.38.1.2 0.0.0.0
[Huawei-acl-basic-2102] quit
[Huawei] acl 3102
[Huawei-acl-adv-3102] rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.2 0.0.0.0
[Huawei-acl-adv-3102] rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.3 0.0.0.0
[Huawei-acl-adv-3102] rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.4 0.0.0.0
[Huawei-acl-adv-3102] rule deny ip
[Huawei-acl-adv-3102] quit
Step 4 Configure packet filtering on Router .
[Huawei] firewall interzone trust untrust
[Huawei-interzone-trust-untrust] packet-filter 3102 inbound
[Huawei-interzone-trust-untrust] quit
Step 5 Configure ASPF on the Router .
[Huawei-interzone-trust-untrust] detect aspf ftp
[Huawei-interzone-trust-untrust] quit
Step 6 Configure port mapping on the Router .
[Huawei] port-mapping ftp port 2121 acl 2102
Step 7 Verify the configuration.
Run the display firewall interzone zone-name1 zone-name2 command on the Router , and the
result is as follows:
[Huawei] display firewall interzone trust untrust
interzone trust untrust
firewall enable
packet-filter default deny inbound
packet-filter default permit outbound
packet-filter 3102 inbound
detect aspf ftp
Run the display port-mapping ftp command on the Router , and the result is as follows:
[Huawei] display port-mapping ftp
Service
-------------------------------------------------
ftp
ftp
-------------------------------------------------
Total number is : 2
----End
Configuration Files
#
vlan 100
#
acl number 2102
rule 5 permit source 129.38.1.2
0
Issue 02 (2012-03-30)
-------------------------------------------------
Port
21
2121
2102
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Acl
Type
system defined
user
defined
3 Firewall Configuration
85

Advertisement

Table of Contents
loading

Table of Contents