Huawei S9700 Series Configuration Manual page 88

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU
Step 2 Configure zones and the interzone on the SPU.
[SPU] firewall zone trust
[SPU-zone-trust] priority 100
[SPU-zone-trust] quit
[SPU] firewall zone untrust
[SPU-zone-untrust] priority 1
[SPU-zone-untrust] quit
[SPU] firewall interzone trust untrust
[SPU-interzone-trust-untrust] firewall enable
[SPU-interzone-trust-untrust] quit
Step 3 Add the interfaces of the SPU to zones.
[SPU] interface Eth-Trunk1.1
[SPU-Eth-Trunk1.1] zone trust
[SPU-Eth-Trunk1.1] quit
[SPU] interface Eth-Trunk1.2
[SPU-Eth-Trunk1.2] zone untrust
[SPU-Eth-Trunk1.2] quit
Step 4 Enable the blacklist function.
[SPU] firewall blacklist enable
Step 5 Add an entry to the blacklist.
[SPU] firewall blacklist 202.39.1.2
Step 6 Enable the IP address sweeping and port scanning attack defense.
[SPU] firewall defend ip-sweep enable
[SPU] firewall defend port-scan enable
Step 7 Configure the maximum session rate and blacklist timeout for the defense against IP address
sweeping or port scanning attack.
[SPU] firewall defend ip-sweep max-rate 5000
[SPU] firewall defend ip-sweep blacklist-expire-time 30
[SPU] firewall defend port-scan max-rate 5000
[SPU] firewall defend port-scan blacklist-expire-time 30
Step 8 Verify the configuration.
Run the display firewall interzone [ zone-name1 zone-name2 ] command on the SPU, and the
result is as follows:
[SPU] display firewall interzone trust untrust
interzone trust untrust
firewall enable
packet-filter default permit outbound
packet-filter default permit inbound
Run the display firewall blacklist all command on the SPU, and the result is as follows:
Issue 01 (2012-03-15)
[SPU-Eth-Trunk1] trunkport XGigabitEthernet 0/0/1
[SPU-Eth-Trunk1] trunkport XGigabitEthernet 0/0/2
[SPU-Eth-Trunk1] quit
[SPU] interface Eth-Trunk 1.1
[SPU-Eth-Trunk1.1] control-vid 101 dot1q-termination
[SPU-Eth-Trunk1.1] dot1q termination vid 101
[SPU-Eth-Trunk1.1] ip address 201.0.0.1 255.255.255.0
[SPU-Eth-Trunk1.1] arp broadcast enable
[SPU-Eth-Trunk1.1] quit
[SPU] interface Eth-Trunk 1.2
[SPU-Eth-Trunk1.2] control-vid 102 dot1q-termination
[SPU-Eth-Trunk1.2] dot1q termination vid 102
[SPU-Eth-Trunk1.2] ip address 202.0.0.1 255.255.255.0
[SPU-Eth-Trunk1.2] arp broadcast enable
[SPU-Eth-Trunk1.2] quit
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 Firewall Configuration
77

Advertisement

Table of Contents
loading

Table of Contents