
Run the
ftp 172.16.104.110
command on PC B (172.16.107.111/24) in subnet 2 on Monday in
2010. PC B cannot connect to the FTP server. Run the
ftp 172.16.104.110
command on PC B
(172.16.107.111/24) in subnet 2 at 15:00 on Saturday in 2010. PC B can connect to the FTP
server.
Run the
ftp 172.16.104.110
command on PC C (10.10.10.1/24). PC C cannot connect to the FTP
server.
----End
Configuration Files
# Configuration file of the Router
#
sysname Router
#
ftp server enable
ftp acl 2001
#
time-range ftp-access from 0:0 2009/1/1 to 23:59 2011/12/31
time-range ftp-access 14:00 to 18:00 off-day
#
acl number 2001
rule 5 permit source 172.16.104.0 0.0.1.255
rule 10 permit source 172.16.106.0 0.0.1.255 time-range ftp-access
#
return
10.6.2 Example for Using Advanced ACLs to Configure the Firewall
Function
In this example, advanced ACLs are used to configure the packet filtering firewall between the
internal network and the external network.
Networking Requirements
, an enterprise that provides Web, FTP, and Telnet services accesses
an external network through GE0/0/1 of the Router and joins a VLAN through Ethernet0/0/0 of
the Router.
The enterprise is located on the network segment 202.169.10.0 and the IP addresses of the Web
server, FTP server, and Telnet server of the enterprise are 202.169.10.5/24, 202.169.10.6/24,
and 202.169.10.7/24.
To ensure security, the enterprise requires the Router to be configured with the firewall function.
By doing this, only specified users are allowed to access internal servers of the enterprise and
only internal servers of the enterprise are allowed to access the external network.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
210