Configuring An Aspf Policy; Applying An Aspf Policy To An Interface - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

Configuring an ASPF
Policy
n
Applying an ASPF Policy
to an Interface
To do...
Enable the Firewall Function
Follow these steps to configure an ASPF policy:
To do...
Enter system view
Create an ASPF policy
and enter its view
Configure the timeout for
SYN, FIN, TCP, and UDP
sessions
Configure ASPF detection
for application layer and
transport layer protocols
If you enable TCP or UDP detection without configuring application layer
protocol detection, some packets may fail to get a response. Therefore, it is
recommended that you enable application layer protocol together with
TCP/UDP detection.
In the case of a Telnet application, you only need to configure TCP detection.
The timeout value specified in the detect command takes precedence to that
specified in the aging-time command.
Two concepts are distinguished in ASPF policy: internal interface and external
interface. If the device is connected to both the internal network and the Internet,
and employs ASPF to protect the internal network server, the interface connected
to the internal network is the internal interface and the one connected to the
Internet is the external interface. When both ASPF and packet filter firewall are
applied to the external interface, accesses to the internal network from the
Internet will be denied. Yet, the response packet can pass ASPF when internal
network users access the Internet.
To monitor the traffic through an interface, you must apply the configured ASPF
policy to that interface.
As it is based on interfaces that an ASPF stores and maintains the application layer
protocol status, make sure that a connection initiation packet and the
corresponding return packet are based on the same interface.
Follow these steps to apply an ASPF policy on an Interface:
Use the command...
firewall enable
Use the command...
Remarks
system-view
-
aspf-policy
Required
aspf-policy-number
aging-time { syn | fin |
Optional
tcp | udp } seconds
The defaults are as follows:
30 seconds for SYN; 5 seconds for FIN;
3,600 seconds for TCP; and 30 seconds
for UDP
detect protocol
Optional
[ java-blocking
The default timeouts are as follows:
acl-number ]
[ aging-time seconds ]
3,600 seconds for application layer
protocols;
3,600 seconds for TCP; and 30 seconds
for UDP.
Configuring an ASPF
1799
Remarks
Required
Disabled by default

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents