
3.3.6 Checking the Configuration
After configuring the zones and interzone, you can view information about the zones and
interzone.
Procedure
l
Run the
display firewall zone
[
zone-name
] [
interface
|
priority
] command to view
information about the zones.
l
Run the
display firewall interzone
[
zone-name1
zone-name2
] command to view
information about the interzone.
----End
3.4 Configuring the Packet Filtering Firewall
The packet filtering firewall filters packets by using an ACL.
3.4.1 Establishing the Configuration Task
Before configuring the ACL-based packet filtering firewall, familiarize yourself with the
applicable environment, complete the pre-configuration tasks, and obtain the data required for
the configuration. This will help you complete the configuration task quickly and accurately.
Applicable Environment
When data is transmitted between two zones, the ACL-based packet filtering firewall enforces
the packet filtering policies according to the ACL rules. The ACLs for filtering packet include
basic ACLs and advanced ACLs.
Pre-configuration Tasks
Before configuring ACL-based packet filtering, complete the following tasks:
l
Configuring zones and adding interfaces to the zones
l
Configuring the interzone and enabling the firewall function in the interzone
l
Creating the basic ACL and advanced ACL and configuring ACL rules
Data Preparation
To configure ACL-based packet filtering, you need the following data.
No.
Data
1
Zone names
2
ACL number
3
Packet direction to which the ACL is applied
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
53