
Applicable Environment
Whitelists are applicable to networks where some devices send valid service packets that
resemble IP address scanning attack or port scanning attack. Whitelists prevent these devices
from being added to the blacklist.
If you add the VPN and IP address of a host to the whitelist, the firewall does not check the
packets sent by the host that look like IP address scanning or port scanning attack, or add the IP
address to the blacklist.
Pre-configuration Tasks
Before configuring the whitelist, complete the following tasks:
l
Configuring zones and adding interfaces to the zones
l
Configuring the interzone and enabling the firewall function in the interzone
Data Preparation
To configure the whitelist, you need the following data.
No.
Data
2
(Optional) Aging time of whitelist entries
3.6.2 Adding Entries to the Whitelist Manually
The entries in the whitelist take effect directly and you do not need to enable the whitelist
function.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
firewall whitelist
ip-address
[
vpn-instance
vpn-instance-name
] [
expire-time
minutes
]
An entry is added to the whitelist.
By running this command, you can add an entry to the whitelist manually. You can specify the
IP address, VPN instance, and aging time when adding the entry.The aging time refers to the
period in which the IP address is effective after it is added to the whitelist. When the IP address
expires, it is released from the whitelist. If the aging time is not specified, the IP address is always
valid in the whitelist.
You can create up to 32 entries in the whitelist.
----End
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
59