Aspf Configuration Task List; Configuring An Aspf Policy; Applying An Aspf Policy To An Interface - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

addresses and source/destination port numbers as the outgoing packets (but reversed) Otherwise, the
return packets are blocked. Therefore, for multi-channel application layer protocols like FTP, the
deployment of TCP inspection without application layer inspection leads to failure of establishing a data
connection.

ASPF configuration task list

Tasks at a glance
(Required.)
(Required.)

Configuring an ASPF policy

Follow these guidelines when you configure an ASPF policy:
For a multi-channel protocol, if you enable TCP or UDP inspection without configuring application
layer protocol inspection, the device might not be able to receive return packets. HP recommends
that you enable application layer protocol inspection together with TCP/UDP inspection.
For a single-channel protocol, such as Telnet, you only need to configure the transport layer protocol
(TCP or UDP) inspection.
To configure an ASPF policy:
Step
1.
Enter system view.
2.
Create an ASPF policy and
enter its view.
3.
(Optional.) Configure ASPF
inspection for application
layer or transport layer
protocols.
4.
(Optional.) Enable ICMP error
message check.
5.
(Optional.) Enable TCP SYN
check.

Applying an ASPF policy to an interface

You can apply an ASPF policy to inspect incoming or outgoing traffic on an interface. ASPF matches all
incoming or outgoing packets against session entries. If a packet does not match any existing session
entry, ASPF creates a new session entry.
Configuring an ASPF policy
Applying an ASPF policy to an interface
Command
system-view
aspf-policy aspf-policy-number
detect { dccp | ftp | gtp | h323 |
icmp | icmpv6 | ils | mgcp | nbt |
pptp | rawip | rsh | rtsp | sccp |
sctp | sip | sqlnet | tcp | tftp | udp
| udp-lite | xdmcp }
icmp-error drop
tcp syn-check
290
Remarks
N/A
By default, no ASPF policy exists.
By default, ASPF inspection is not
configured.
By default, the ICMP error message
check is disabled. ASPF does not
drop faked ICMP error messages.
By default, TCP SYN check is
disabled. ASPF does not drop the
non-SYN packet when it is the first
packet to establish a TCP
connection.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents