Checking The Configuration; Configuring Aspf; Establishing The Configuration Task - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU

2.6.4 Checking the Configuration

After the whitelist is configured, you can view information about the whitelist.
Procedure
l
----End
Example
Run thedisplay firewall whitelist { all | ip-address [ vpn-instance vpn-instance-name ] | vpn-
instance vpn-instance-name } command to view information about the whitelist.
<Quidway> display firewall whitelist all
Firewall whitelist items
------------------------------------------------------------------------
IP-Address
------------------------------------------------------------------------
1.1.1.1
1.1.1.2
1.1.1.3
------------------------------------------------------------------------
Total number is : 3

2.7 Configuring ASPF

The ASPF function can detect sessions that attempt to traverse the application layer and deny
the undesired packets. In addition, ASPF enables application protocols that cannot traverse
firewalls to function properly.

2.7.1 Establishing the Configuration Task

Before configuring ASPF, familiarize yourself with the applicable environment, complete the
pre-configuration tasks, and obtain the data required for the configuration. This will help you
complete the configuration task quickly and accurately.
Applicable Environment
When data is transmitted between two zones, ASPF checks the packets at the application layer
and discards the unmatched packets.
Pre-configuration Tasks
Before configuring ASPF, complete the following tasks:
l
l
Data Preparation
To configure ASPF, you need the following data.
Issue 01 (2012-03-15)
Run the display firewall whitelist { all | ip-address [ vpn-instance vpn-instance-name ] |
vpn-instance vpn-instance-name } command to view information about the whitelist.
Expire-Time(m)
3
Permanent
6
Configuring zones and adding interfaces to the zones
Configuring the interzone and enabling the firewall function in the interzone
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
:
Vpn-Instance
vpn1
vpn2
2 Firewall Configuration
45

Advertisement

Table of Contents
loading

Table of Contents