Enabling The Session Logging Function For Aspf; Configuring Port Mapping; Displaying And Maintaining An Aspf - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1800
C
94: F
HAPTER
IREWALL
Enabling the Session
Logging Function for
ASPF
Configuring Port
Mapping
Displaying and
Maintaining an ASPF
C
ONFIGURATION
To do...
Enter system view
Enter interface view
Apply an ASPF policy to the
interface
ASPF provides an enhanced session logging function, which can record the
information of each connection, including the duration, source and destination
addresses of the connection, the port used by the connection and number of
bytes transmitted.
Follow these steps to enable the session logging function of ASPF:
To do...
Enter system view
Enter ASPF policy view
Enable the session logging
function of the ASPF
Two mapping mechanisms exist: general port mapping and basic ACL-based host
port mapping.
A general port mapping refers to a mapping of a user-defined port number to an
application layer protocol. If port 8080 is mapped to HTTP, for example, all TCP
packets the destination port of which is port 8080 are regarded as HTTP packets.
A host port mapping refers to a mapping of a user-defined port number to an
application layer protocol for packets to/from some specific hosts. For example,
you can establish a host port mapping so that all TCP packets using port 8080 sent
to the network segment 10.110.0.0 are regarded as HTTP packets. The address
range of hosts can be specified by means of a basic ACL.
Follow these steps to configure port mapping
To do...
Enter system view
Configure mapping between
the port and the application
protocol
To do...
View all ASPF policy and session
information
View the ASPF policy configuration
applied the interface
Use the command...
system-view
interface interface-type
interface-number
firewall aspf
aspf-policy-number
{ inbound | outbound }
Use the command...
system-view
aspf-policy
aspf-policy-number
log enable
Use the command...
system-view
port-mapping application-name
port port-number [ acl acl-number ]
Use the command...
display aspf all
display aspf interface
Remarks
-
-
Required
Not applied by default
Remarks
-
Required
Optional
Disabled by default
Remarks
-
Required
Not configured by
default
Remarks
Available in any view
Available in any view

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents