Figure 1 Packet Filtering Configuration Example - Zte ZXR10 8900 Series User Manual

10g routing switch
Hide thumbs Also See for ZXR10 8900 Series:
Table of Contents

Advertisement

ZXR10 8900 Series User Manual (FW Volume)
74
Confidential and Proprietary Information of ZTE CORPORATION
F
1 P
F
IGURE
ACKET
ILTERING
Configuration Points:
Specifying server host address;
Configuring default packet block policy
Configuring packet block policy;
1. To configure default packet block policy——permit any packets
to pass through FW, execute the following command:
ZXR10_FW #pf rule set default action accept
log yes
2. To add host doc_server, execute the following command:
ZXR10_FW #define host add name doc_server
ipaddr 192.168.83.234
3. To add area_vlan3 (setting gei_2/3 to be in vlan 3; it is the in-
terface connecting to router), execute the following command:
ZXR10_FW #define area add name area_vlan3
access off attribute gei_2/3
4. To configure packet filtering rule: forbid the host whose MAC
address is 00:50:04:C3:B0:31 to access document server, ex-
ecute the following command:
ZXR10_FW #pf rule add smac 00:50:04:C3:B0:31
area area_vlan2 dip doc_server dport 8000 action reject
C
E
ONFIGURATION
XAMPLE

Advertisement

Table of Contents
loading

Table of Contents