Configuring A Packet Filter Firewall; Packet Filter Firewall Configuration Task List; Enabling The Firewall Function; Configuring The Default Filtering Action Of The Firewall - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1794
C
94: F
HAPTER
IREWALL
Configuring a Packet
Filter Firewall
Packet Filter Firewall
Configuration Task list
Enabling the Firewall
Function
Configuring the Default
Filtering Action of the
Firewall
Enabling Fragment
Inspection
C
ONFIGURATION
Task
"Enabling the Firewall Function" on page 1794
"Configuring the Default Filtering Action of the Firewall" on page
1794
"Enabling Fragment Inspection" on page 1794
"Configuring the High and Low Watermarks for Fragment Inspection"
on page 1795
"Configuring Packet Filtering on an Interface" on page 1795
"Configuring Ethernet Frame Filtering" on page 1796
Following these steps to enable the firewall function:
To do...
Enter system view
Enable the Firewall Function
The default filtering action configuration is used for the firewall to determine
whether to permit a data packet to pass or deny the packet when there is no
appropriate criterion for judgment.
Follow these steps to configure the default filtering action:
To do...
Enter system view
Set the default filtering action
of the firewall to "permit" or
"deny"
Exact match can be implemented only after fragment inspection is enabled. In
doing so, packet filtering firewall records the status of the fragment and performs
exact match to information of layer 3 or above based on advanced ACL rules.
The packet filter firewall records the status of fragments at the price of system
resource consumption. If exact match is not required, you can disable fragments
inspection to improve system performance and reduce system overhead.
1 Enable the IPv4 fragment inspection function:
To do...
Enter system view
Enable IPv4 fragment
inspection
Use the command...
system-view
firewall enable
Use the command...
system-view
firewall default { permit |
deny }
Use the command...
system-view
firewall fragments-inspect
Remarks
Required
Optional
Optional
Optional
Required
Optional
Remarks
-
Required
Disabled by default
Remarks
-
Optional
Permit" by default
Remarks
-
Required
Disabled by default

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents