
3.1 Firewall Overview............................................................................................................................................44
3.2 Firewall Features Supported by the AR1200-S................................................................................................44
3.3 Configuring Zones............................................................................................................................................50
3.3.1 Establishing the Configuration Task.......................................................................................................50
3.3.2 Creating a Zone.......................................................................................................................................51
3.3.3 Adding an Interface to the Zone..............................................................................................................51
3.3.4 Creating an Interzone...............................................................................................................................52
3.3.5 Enabling Firewall in the Interzone..........................................................................................................52
3.3.6 Checking the Configuration.....................................................................................................................53
3.4.1 Establishing the Configuration Task.......................................................................................................53
3.4.2 Configuring ACL-based Packet Filtering in an Interzone.......................................................................54
3.4.3 Checking the Configuration.....................................................................................................................55
3.5.1 Establishing the Configuration Task.......................................................................................................55
3.5.2 Enabling the Blacklist Function..............................................................................................................56
3.5.3 Adding IP Addresses to the Blacklist Manually......................................................................................56
3.5.4 Configuring Blacklist and Whitelist Using the Configuration File.........................................................57
3.5.5 Checking the Configuration.....................................................................................................................58
3.6.1 Establishing the Configuration Task.......................................................................................................58
3.6.2 Adding Entries to the Whitelist Manually...............................................................................................59
3.6.3 Configuring Blacklist and Whitelist Using the Configuration File.........................................................60
3.6.4 Checking the Configuration.....................................................................................................................61
3.7.1 Establishing the Configuration Task.......................................................................................................61
3.7.2 Configuring ASPF Detection...................................................................................................................62
3.7.3 Checking the Configuration.....................................................................................................................62
3.8.1 Establishing the Configuration Task.......................................................................................................63
3.8.2 Configuring Port Mapping.......................................................................................................................64
3.8.3 Checking the Configuration.....................................................................................................................64
3.9.1 Establishing the Configuration Task.......................................................................................................65
3.9.2 Configuring the Aging Time of the Firewall Session Table...................................................................65
3.9.3 Checking the Configuration.....................................................................................................................66
3.10.1 Establishing the Configuration Task.....................................................................................................67
3.10.2 Enabling the Attack Defense Function..................................................................................................67
3.10.3 Setting the Parameters for Flood Attack Defense..................................................................................70
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
Contents
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
vi