Firewall Configuration - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
About This Chapter
The attack defense system protects an internal network against attacks from external networks;
therefore, firewalls are generally deployed between the internal and external networks to prevent
attacks.
2.1 Firewall Overview
A firewall discards unwanted packets and protects the systems and key resources on the internal
network.
2.2 Firewall Features Supported by the SPU
The firewall features supported by the SPU include ACL-based packet filtering, blacklist,
whitelist, application specific packet filter (ASPF), port mapping, transparent firewall, virtual
firewall, attack defense, traffic statistics and monitoring, and logs.
2.3 Configuring Zones
All the security policies of the firewall are enforced based on zones.
2.4 Configuring the Packet Filtering Firewall
The packet filtering firewall filters packets by using an ACL.
2.5 Configuring the Blacklist
You can manually add entries to the blacklist or configure a dynamic blacklist. If you choose
the dynamic blacklist, enable IP address scanning and port scanning defense on the attack defense
module of the SPU. When the SPU detects that the connection rate of an IP address or a port
exceeds the threshold, the SPU considers that a scanning attack occurs, and adds the source IP
address to the blacklist. All the packets from this source IP address are then filtered out.
2.6 Configuring the Whitelist
Whitelists are applicable to networks where devices send valid service packets that resemble IP
address or port scanning attack packets. Whitelists prevent these devices from being added to
the blacklist.
2.7 Configuring ASPF
The ASPF function can detect sessions that attempt to traverse the application layer and deny
the undesired packets. In addition, ASPF enables application protocols that cannot traverse
firewalls to function properly.
2.8 Configuring Port Mapping
Issue 01 (2012-03-15)
2
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

Firewall Configuration

2 Firewall Configuration
26

Advertisement

Table of Contents
loading

Table of Contents