
4.
Configure ACL-based packet filtering in the interzone.
Procedure
Step 1
Configure zones and an interzone on the Router .
<Huawei>
system-view
[Huawei]
firewall zone trust
[Huawei-zone-trust]
priority 15
[Huawei-zone-trust]
quit
[Huawei]
firewall zone untrust
[Huawei-zone-untrust]
priority 1
[Huawei-zone-untrust]
quit
[Huawei]
firewall interzone trust untrust
[Huawei-interzone-trust-untrust]
firewall enable
[Huawei-interzone-trust-untrust]
quit
Step 2
Add Router interfaces to zones.
[Huawei]
vlan 100
[Huawei-vlan100]
quit
[Huawei]
interface vlanif 100
[Huawei-Vlanif100]
ip address 129.38.1.1 24
[Huawei-Vlanif100]
quit
[Huawei]
interface Ethernet 0/0/0
[Huawei-Ethernet0/0/0]
port link-type access
[Huawei-Ethernet0/0/0]
port default vlan 100
[Huawei-Ethernet0/0/0]
quit
[Huawei]
interface vlanif 100
[Huawei-Vlanif100]
zone trust
[Huawei-Vlanif100]
quit
[Huawei]
interface gigabitethernet 0/0/1
[Huawei-GigabitEthernet0/0/1]
ip address 202.39.2.1 24
[Huawei-GigabitEthernet0/0/1]
zone
untrust
[Huawei-GigabitEthernet0/0/1]
quit
Step 3
Configure the ACL on the Router .
[Huawei]
acl 3102
[Huawei-acl-adv-3102]
rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.2 0.0.0.0
[Huawei-acl-adv-3102]
rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.3 0.0.0.0
[Huawei-acl-adv-3102]
rule permit tcp source 202.39.2.3 0.0.0.0 destination
129.38.1.4 0.0.0.0
[Huawei-acl-adv-3102]
rule deny ip
[Huawei-acl-adv-3102]
quit
Step 4
Configure packet filtering on the Router .
[Huawei]
firewall interzone trust untrust
[Huawei-interzone-trust-untrust]
packet-filter 3102 inbound
[Huawei-interzone-trust-untrust]
quit
Step 5
Verify the configuration.
After the configuration, only the specified host (202.39.2.3) can access the servers on the internal
network.
Run the
display firewall interzone
[
zone-name1
zone-name2
] command on the Router , and
the result is as follows:
[Huawei]
display firewall interzone trust untrust
interzone trust untrust
firewall enable
packet-filter default deny inbound
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
82