
[Huawei-Vlanif100]
quit
[Huawei]
interface gigabitethernet 0/0/1
[Huawei-GigabitEthernet0/0/1]
ip address 202.39.2.1
24
[Huawei-GigabitEthernet0/0/1]
zone untrust
[Huawei-GigabitEthernet0/0/1]
quit
Step 3
Configure the ACL on Router .
[Huawei]
acl 2102
[Huawei-acl-basic-2102]
rule permit source 129.38.1.2 0.0.0.0
[Huawei-acl-basic-2102]
quit
[Huawei]
acl 3102
[Huawei-acl-adv-3102]
rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.2 0.0.0.0
[Huawei-acl-adv-3102]
rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.3 0.0.0.0
[Huawei-acl-adv-3102]
rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.4 0.0.0.0
[Huawei-acl-adv-3102]
rule deny ip
[Huawei-acl-adv-3102]
quit
Step 4
Configure packet filtering on Router .
[Huawei]
firewall interzone trust untrust
[Huawei-interzone-trust-untrust]
packet-filter 3102 inbound
[Huawei-interzone-trust-untrust]
quit
Step 5
Configure ASPF on the Router .
[Huawei-interzone-trust-untrust]
detect aspf ftp
[Huawei-interzone-trust-untrust]
quit
Step 6
Configure port mapping on the Router .
[Huawei]
port-mapping ftp port 2121 acl 2102
Step 7
Verify the configuration.
Run the
display firewall interzone
zone-name1
zone-name2
command on the Router , and the
result is as follows:
[Huawei]
display firewall interzone trust untrust
interzone trust untrust
firewall enable
packet-filter default deny inbound
packet-filter default permit outbound
packet-filter 3102 inbound
detect aspf ftp
Run the
display port-mapping
ftp
command on the Router , and the result is as follows:
[Huawei]
display port-mapping ftp
-------------------------------------------------
Service Port Acl Type
-------------------------------------------------
ftp 21 system defined
ftp 2121 2102 user defined
-------------------------------------------------
Total number is : 2
----End
Configuration Files
#
vlan 100
#
acl number 2102
rule 5 permit source 129.38.1.2
0
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
85