
3.11.1 Establishing the Configuration Task
Before configuring traffic statistics and monitoring, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the data required for the
configuration. This will help you complete the configuration task quickly and accurately.
Applicable Environment
System-level traffic statistics and monitoring take effect on all the data flows in interzones that
are enabled with the firewall feature. That is, the AR1200-S collects statistics on packets of
ICMP, TCP, TCP proxy, and UDP sessions in the interzones. When the number of sessions
exceeds the threshold, the AR1200-S restricts the sessions until the number of sessions is less
than the threshold.
The zone-based traffic statistics and monitoring take effect on the data flows between zones.
That is, the AR1200-S counts the total number of TCP and UDP sessions between the local zone
and other zones. When the number of sessions exceeds the threshold, the AR1200-S restricts
the sessions until the number of sessions is less than the threshold. The zone-based traffic
statistics and monitoring can be configured in the inbound or outbound direction. The inbound
direction means that the AR1200-S counts and monitors the sessions initiated by the local zone.
The outbound direction means that the AR1200-S counts and monitors the sessions destined for
this zone.
The IP address-based traffic statistics and monitoring count and monitor the TCP and UDP
sessions set up by an IP address in the zone. When the number of sessions set up by an IP address
exceeds the threshold, the AR1200-S restricts the sessions until the number of sessions is less
than the threshold. The IP address-based traffic statistics and monitoring can be configured in
the inbound or outbound direction. The inbound direction means that the AR1200-S counts and
monitors the sessions initiated by the IP address in the local zone. The outbound direction means
that the AR1200-S counts and monitors the sessions destined for this IP address.
Pre-configuration Tasks
Before configuring traffic statistics and monitoring, complete the following tasks:
l
Configuring zones and adding interfaces to the zones
l
Configuring the interzone and enabling the firewall function in the interzone
Data Preparation
To configure traffic statistics and monitoring, you need the following data.
No.
Data
1
Type of sessions to be monitored, including TCP and UDP
2
Session threshold
3
Direction of traffic statistics and monitoring
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
73