Firewall Packet-Filter - H3C MSR 20-20 Command Reference Manual

Msr 20/30/50 series routers
Hide thumbs Also See for MSR 20-20:
Table of Contents

Advertisement

1996
C
130: P
HAPTER
ACKET
Example

firewall packet-filter

Syntax
View
Parameter
Description
Related command:
Example
F
F
C
ILTER
IREWALL
ONFIGURATION
Use the
undo firewall ipv6 fragments-inspect
fragments inspection.
By default, IPv6 fragments inspection is disabled.
# Enable IPv6 fragments inspection.
<Sysname> system-view
[Sysname] firewall ipv6 fragments-inspect
firewall packet-filter { acl-number | name acl-name } { inbound | outbound }
[ match-fragments { normally | exactly } ]
undo firewall packet-filter acl-number { inbound | outbound }
Interface view
acl-number: Basic ACL number, in the range 2000 to 2999; advanced ACL
number, in the range 3000 to 3999.
name acl-name: Specifies the name of a basic or advanced IPv4 ACL, a
case-insensitive string of 1 to 32 characters that must start with an English letter a
to z or A to Z. To avoid confusion, the word "all" cannot be used as the ACL
name.
inbound: Filters packets in the inbound direction.
outbound: Filters packets in the outbound direction.
match-fragments: Specifies the fragment match mode (for advanced ACLs only).
normally: Specifies the normal match mode, which is the default mode.
exactly: Specifies the exact match mode.
Use the
firewall packet-filter
the interface.
Use the
undo firewall packet-filter
Packets are not filtered on an interface by default.
firewall fragments-inspect.
# Apply ACL 2001 on Serial 2/0 to filter packets forwarded by the interface.
<Sysname> system-view
[Sysname] interface serial 2/0
[Sysname-Serial2/0] firewall packet-filter 2001 outbound
C
OMMANDS
command to configure IPv4 packet filtering on
command to cancel the configuration.
command to disable IPv6

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr 20-21Msr 30-16Msr 30-20Msr 30-40Msr 30-60Msr 50 ... Show all

Table of Contents