
Procedure
l
Run the
display firewall interzone
[
zone-name1
zone-name2
] command to view ASPF
information of the interzone.
----End
Example
Run the
display firewall interzone
[
zone-name1
zone-name2
] command to view the ASPF
information of the interzone.
<Huawei>
display firewall interzone
interzone zone2 zone1
firewall enable
packet-filter default permit outbound
packet-filter default permit inbound
session-log 2006 inbound
detect aspf ftp
detect aspf sip
detect aspf rtsp
detect aspf http
detect aspf http java-blocking
detect aspf http activex-blocking
total number is : 1
3.8 Configuring Port Mapping
Port mapping defines new port numbers for different application-layer protocols, protecting the
server against the service specific attacks.
3.8.1 Establishing the Configuration Task
Before configuring port mapping, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the data required for the configuration. This
will help you complete the configuration task quickly and accurately.
Applicable Environment
Through port mapping, the firewall can identify packets of the application-layer protocols that
use the non-well-known ports. The port mapping function can be applied to features sensitive
to application-layer protocols, such as ASPF. Port mapping is applicable to the application-layer
protocols such as FTP, DNS, HTTP, SIP, and RTSP.
Port mapping is implemented based on the ACL. Only the packets matching an ACL rule are
mapped. Port mapping employs the basic ACL (2000 to 2999). In the ACL-based packet filtering,
the AR1200-S matches the destination IP address of the packet with the IP address configured
in the basic ACL rule.
NOTE
Port mapping is applied only to the data within the interzone; therefore, when configuring port mapping,
you must configure the zones and interzone.
Pre-configuration Tasks
Before configuring port mapping, complete the following tasks:
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
63