Huawei S9700 Series Configuration Manual page 84

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
Step 2 Configure zones and the interzone on the SPU.
[SPU] firewall zone trust
[SPU-zone-trust] priority 100
[SPU-zone-trust] quit
[SPU] firewall zone untrust
[SPU-zone-untrust] priority 1
[SPU-zone-untrust] quit
[SPU] firewall interzone trust untrust
[SPU-interzone-trust-untrust] firewall enable
[SPU-interzone-trust-untrust] quit
Step 3 Add SPU interfaces to zones.
[SPU] interface Eth-trunk0.1
[SPU-Eth-trunk0.1] zone trust
[SPU-Eth-trunk0.1] quit
[SPU] interface Eth-trunk0.2
[SPU-Eth-trunk0.2] zone untrust
[SPU-Eth-trunk0.2] quit
Step 4 Configure ACLs on the SPU.
[SPU] acl 2102
[SPU-acl-basic-2102] rule permit source 129.38.1.2 0.0.0.0
[SPU-acl-basic-2102] quit
[SPU] acl 3102
[SPU-acl-adv-3102] rule permit tcp source 202.39.2.3 0.0.0.0 destination 129.38.1.2
0.0.0.0
[SPU-acl-adv-3102] rule permit tcp source 202.39.2.3 0.0.0.0 destination 129.38.1.3
0.0.0.0
[SPU-acl-adv-3102] rule permit tcp source 202.39.2.3 0.0.0.0 destination 129.38.1.4
0.0.0.0
[SPU-acl-adv-3102] rule deny ip
[SPU-acl-adv-3102] quit
Step 5 Configure packet filtering on the SPU.
[SPU] firewall interzone trust untrust
[SPU-interzone-trust-untrust] packet-filter 3102 inbound
[SPU-interzone-trust-untrust] quit
Step 6 Configure ASPF on the SPU.
[SPU-interzone-trust-untrust] detect aspf ftp
[SPU-interzone-trust-untrust] quit
Step 7 Configure port mapping on the SPU.
[SPU] port-mapping ftp port 2121 acl 2102
Step 8 Verify the configuration.
Run the display firewall interzone [ zone-name1 zone-name2 ] command on the SPU, and the
result is as follows:
[SPU] display firewall interzone trust untrust
interzone trust untrust
Issue 01 (2012-03-15)
[SPU-Eth-trunk0] trunkport XGigabitEthernet 0/0/1
[SPU-Eth-trunk0] trunkport XGigabitEthernet 0/0/2
[SPU-Eth-trunk0] quit
[SPU] interface Eth-trunk0.1
[SPU-Eth-trunk0.1] control-vid 10 dot1q-termination
[SPU-Eth-trunk0.1] dot1q termination vid 10
[SPU-Eth-trunk0.1] ip address 129.38.1.1 255.255.255.0
[SPU-Eth-trunk0.1] arp broadcast enable
[SPU-Eth-trunk0.1] quit
[SPU] interface Eth-trunk0.2
[SPU-Eth-trunk0.2] control-vid 20 dot1q-termination
[SPU-Eth-trunk0.2] dot1q termination vid 20
[SPU-Eth-trunk0.2] ip address 202.39.2.1 255.255.0.0
[SPU-Eth-trunk0.2] arp broadcast enable
[SPU-Eth-trunk0.2] quit
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 Firewall Configuration
73

Advertisement

Table of Contents
loading

Table of Contents