Checking The Configuration; Configuring The Whitelist; Establishing The Configuration Task - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
The entries in the whitelist take effect directly and you do not need to enable the whitelist
function.
A blacklist supports up to 4096 entries, and a whitelist supports up to 1024 entries.
----End
Follow-up Procedure
Run the firewall black-white-list save command to save the blacklist and whitelist to the
specified configuration file to load next time.

2.5.5 Checking the Configuration

After the blacklist is configured, you can view information about the blacklist.
Procedure
l
----End
Example
Run the display firewall blacklist command to view information about the blacklist.
<Quidway> display firewall blacklist all
Firewall blacklist items :
------------------------------------------------------------------------
IP-Address
------------------------------------------------------------------------
10.1.1.1
------------------------------------------------------------------------
Total number is : 1

2.6 Configuring the Whitelist

Whitelists are applicable to networks where devices send valid service packets that resemble IP
address or port scanning attack packets. Whitelists prevent these devices from being added to
the blacklist.

2.6.1 Establishing the Configuration Task

Before configuring the whitelist, familiarize yourself with the applicable environment, complete
the pre-configuration tasks, and obtain the data required for the configuration. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
Whitelists are applicable to networks where some devices send valid service packets that
resemble IP address scanning attack or port scanning attack. Whitelists prevent these devices
from being added to the blacklist.
If you add the VPN and IP address of a host to the whitelist, the firewall does not check the
packets sent by the host that look like IP address scanning or port scanning attack, or add the IP
address to the blacklist.
Issue 01 (2012-03-15)
Run the display firewall blacklist command to view information about the blacklist.
Reason
Manual
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Expire-Time(m)
VPN-Instance
100
2 Firewall Configuration
42

Advertisement

Table of Contents
loading

Table of Contents