Configuring Port Mapping; Establishing The Configuration Task - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
packet-filter default permit outbound
packet-filter default permit inbound
session-log 2006 inbound
detect aspf ftp
detect aspf sip
detect aspf rtsp
detect aspf http
detect aspf http java-blocking
detect aspf http activex-blocking
total number is : 1

2.8 Configuring Port Mapping

Port mapping defines new port numbers for different application-layer protocols, protecting the
server against the service specific attacks.

2.8.1 Establishing the Configuration Task

Before configuring port mapping, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the data required for the configuration. This
will help you complete the configuration task quickly and accurately.
Applicable Environment
Through port mapping, the firewall can identify packets of the application-layer protocols that
use the non-well-known ports. The port mapping function can be applied to features sensitive
to application-layer protocols, such as ASPF. Port mapping is applicable to the application-layer
protocols such as FTP, DNS, HTTP, SIP, and RTSP.
Port mapping is implemented based on the ACL. Only the packets matching an ACL rule are
mapped. Port mapping employs the basic ACL (2000 to 2999). In the ACL-based packet filtering,
the SPU matches the destination IP address of the packet with the IP address configured in the
basic ACL rule.
Pre-configuration Tasks
Before configuring port mapping, complete the following tasks:
l
l
l
Data Preparation
To configure port mapping, you need the following data.
No.
1
Issue 01 (2012-03-15)
NOTE
Port mapping is applied only to the data within the interzone; therefore, when configuring port mapping,
you must configure the zones and interzone.
Configuring zones and adding interfaces to the zones
Configuring the interzone and enabling the firewall function in the interzone
Creating the basic ACL and configuring ACL rules
Data
Type of application-layer protocol
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 Firewall Configuration
47

Advertisement

Table of Contents
loading

Table of Contents