
Figure 10-2
Using advanced ACLs to configure the firewall function
202.169.10.6
Telnet server
FTP server
202.169.10.5
202.39.2.3
Web server
Internal
network
Router
202.169.10.7
Internet
GE0/0/1
Eth0/0/0
Configuration Roadmap
The configuration roadmap is as follows:
l
Configure zones on the internal and external networks.
l
Configure an interzone and enable the firewall function in the interzone.
l
Configure advanced ACLs to classify external users and internal servers.
l
Configure ACL-based packet filtering in the interzone.
Data Preparation
To complete the configuration, you need the following data:
l
Name of the zone on the internal network: company
l
Priority of the zone
company
: 12
l
Name of the zone on the external network: external
l
Priority of the zone
external
: 5
l
VLAN that the enterprise joins: VLAN 100
l
IP address of VLANIF 100: 202.169.10.1/24
l
IP address of GE0/0/1: 129.39.10.8/24
l
IP address of the user that can access internal servers: 202.39.2.3/24
l
Number of the advanced ACL that classifies specified users: ACL 3001
l
Number of the advanced ACL that classifies internal servers: ACL 3002
Procedure
Step 1
Configure zones.
# Configure a zone on the internal network.
<Huawei>
system-view
[Huawei]
sysname Router
[Router]
firewall zone company
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
211