HP MSR2000 Configuration Manual page 262

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

Figure 71 Network diagram
Internal network
Host
192.168.1.2/24
Configuration procedure
# Configure ACL 31 1 1 to deny all IP packets.
<RouterA> system-view
[RouterA] acl number 3111
[RouterA-acl-adv-3111] rule deny ip
[RouterA-acl-adv-3111] quit
# Create ASPF policy 1 for FTP inspection.
[RouterA] aspf-policy 1
[RouterA-aspf-policy-1] detect ftp
[RouterA-aspf-policy-1] quit
# Apply ACL 31 1 1 to the inbound direction of interface Ethernet 1/0 to prohibit all IP packets from
entering into the internal network.
[RouterA] interface ethernet 1/0
[RouterA-Ethernet1/0] packet-filter 3111 inbound
# Apply ASPF policy 1 to the outbound direction of interface Ethernet 1/0, so return packets of the FTP
connections can enter into the internal network.
[RouterA-Ethernet1/0] aspf policy 1 outbound
Verifying the configuration
# Display ASPF sessions on Router A.
<RouterA> display aspf session ipv4
Initiator:
Source
Destination IP/port: 2.2.2.11/21
VPN instance/VLAN ID/VLL ID: -/-/-
Protocol: TCP(6)
Total sessions found: 1
The output shows that an ASPF session has been established for the FTP connection between the host and
the FTP server. The host can initiate a FTP connection to the external FTP server, but unsolicited access
from the external network to the internal network is denied.
Router A
Router B
Eth1/0
10.1.1.1/24
Eth1/1
192.168.1.1/24
IP/port: 192.168.1.2/1877
External network
Server
2.2.2.11/24
251

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents