Generic Routing Encapsulation
Left running head:
Chapter name (automatic)
850
Beta
Beta
CLI Configuration Guide
Alcatel-Lucent
O
N
OA700-1
In conjunction with above configuration, define the filters as follows:
1.
Configure rule using match-list to permit all traffic only from 10.3.3.1/24 network.
2.
Configure filter by performing actions of permit/deny on the rules configured
above.
3.
Apply filters configured to the tunnel interface.
a) Configure rules
ALU-1(config)#match-list permit-traffic
ALU-1(config-match-list-permit-traffic)#ip prefix 10.3.3.1/
24 any
ALU-1(config-match-list-permit-traffic)#exit
b) Configure filter
ALU-1(config)#ip filter tr-access
ALU-1(config-filter-tr-access)#match any permit-traffic
permit log
ALU-1(config-filter-tr-access)#exit
c) Apply the filter to the tunnel interface in the ingress direction
ALU-1(config)#interface tunnel1
ALU-1(config-if tunnel1)#ip filter in tr-access
ALU-1(config-if tunnel1)#exit
Create Firewall Policy for protecting the network against DOS attacks
1.
Configure
a rule using match-list for any packet that matches classification.
2.
Create an attack policy, which includes the signature against DoS attack.
3.
Create a firewall policy, which uses the rule and attack policy created earlier.
4.
Apply the firewall policy to the tunnel interface.
a) Configure a rule for protecting the network against DoS attack
ALU-1(config)#match-list dos
ALU-1(config-match-list-dos)#ip any any
ALU-1(config-match-list-dos)#exit
b) Create attack policy
ALU-1(config)#firewall
ALU-1(config-firewall)#attack atk1
ALU-1(config-firewall-attack-atk1)#all
ALU-1(config-firewall-attack-atk1)#exit
c) Create firewall policy
ALU-1(config)#policy p1
ALU-1(config-fiewall-p1)#match dos attack atk1 drop
ALU-1(config-fiewall-p1)#exit
d) Apply the firewall policy to the tunnel interface in the ingress direction
ALU-1(config)#interface tunnel 1
ALU-1(config-if tunnel1)#firewall policy in p1
ALU-1(config-if tunnel1)#exit
Содержание OmniAccess 700
Страница 38: ...Left running head Chapter name automatic 12 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 176: ...Left running head Chapter name automatic 150 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 224: ...Per VLAN Spanning Tree Left running head Chapter name automatic 198 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 258: ...Port Monitoring Left running head Chapter name automatic 232 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 260: ...Left running head Chapter name automatic 234 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 296: ...T1E1 Line Card Left running head Chapter name automatic 270 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 360: ...Point to Point Protocol Left running head Chapter name automatic 334 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 434: ...Left running head Chapter name automatic 408 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 462: ...Common Classifiers Left running head Chapter name automatic 436 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 464: ...Left running head Chapter name automatic 438 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 534: ...Border Gateway Protocol Left running head Chapter name automatic 508 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 638: ...Left running head Chapter name automatic 612 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 762: ...Filter and Firewall Left running head Chapter name automatic 736 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 890: ...Transparent Firewall Left running head Chapter name automatic 864 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 940: ...Left running head Chapter name automatic 914 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1000: ...Quality of Service Left running head Chapter name automatic 974 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1002: ...Left running head Chapter name automatic 976 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1044: ...DNS Domain Name Service Client Left running head Chapter name automatic 1018 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1046: ...Left running head Chapter name automatic 1020 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1058: ...Left running head Chapter name automatic 1032 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1074: ...Lifeline Left running head Chapter name automatic 1048 Beta Beta CLI Configuration Guide Alcatel Lucent line con 0 end ...
Страница 1076: ...Left running head Chapter name automatic 1050 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1118: ...Web Cache Server Left running head Chapter name automatic 1092 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1120: ...Left running head Chapter name automatic 2 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1140: ...QoS Values and Mnemonics Left running head Chapter name automatic 22 Beta Beta CLI Configuration Guide Alcatel Lucent ...
Страница 1156: ...IPsec Interoperability of OA 700 Left running head Chapter name automatic 38 Beta Beta CLI Configuration Guide Alcatel Lucent ...