Displaying And Maintaining Aspf; Aspf Configuration Examples; Aspf Ftp Application Inspection Configuration Example - HP MSR2000 Configuration Manual

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

You can apply both ASPF and packet filtering to implement packet filtering. For example, you can apply
a packet filtering policy to the inbound direction of the external interface and apply an ASPF policy to the
outbound direction of the external interface. The application denies unsolicited access from the external
network to the internal network and allows response packets from external to the internal network.
Check that a connection initiation packet and the corresponding response packet pass through the same
interface, because an ASPF stores and maintains the application layer protocol status based on
interfaces.
To apply an ASPF policy on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Apply an ASPF policy to the
interface.

Displaying and maintaining ASPF

Execute display commands in any view and reset commands in user view.
Task
Display the configuration of all ASPF policies
and their applications to interfaces.
Display ASPF policy applications to interfaces.
Display the configuration of a specific ASPF
policy.
Display ASPF sessions.
Clear ASPF session statistics.

ASPF configuration examples

ASPF FTP application inspection configuration example

Network requirements
To allow local users on the internal network to access the FTP server on the external network and protect
the internal network against external network attacks, configure an ASPF policy on Router A to inspect
the FTP traffic flows passing through Router A. Only return packets for FTP connections initiated by users
on the internal network are permitted to pass through Router A and get into the internal network. All other
types of packets from the external network to the internal network are blocked.
Command
system-view
interface interface-type
interface-number
aspf policy aspf-policy-number
{ inbound | outbound }
Command
display aspf all
display aspf interface
display aspf policy aspf-policy-number
display aspf session [ ipv4 | ipv6] [ verbose ]
reset aspf session [ ipv4 | ipv6 ]
250
Remarks
N/A
N/A
By default, no ASPF policy is
applied to the interface.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents