
3.1 Firewall Overview
A firewall discards unwanted packets and protects the systems and key resources on the internal
network.
In a building, a firewall is designed to prevent the spread of fire from one place to other places.
Similarly, a firewall on the network prevents hazards on the Internet from spreading to the
internal network.
Located at the network boundary, a firewall prevents unauthorized access to the protected
network and allows the internal users' secure access to the web service across the Internet.
Both the packets from the Internet to the internal network and the packets from the internal
network to the Internet pass through the firewall; therefore, the firewall is a guard that can discard
the undesired packets.
A firewall can also be used to protect systems and key resources such as data on the internal
network. A firewall filters the access to the protected data, even the internal access to the data.
Ae firewall also serves as an authority control gateway to restrict the access to the Internet. For
example, it allows the specified internal users to access the Internet. Firewalls also provide other
functions, such as identity authentication and security processing (packet encryption).
The AR1200-S has the following functions:
l
ACL-based packet filtering: filters packets through an ACL.
l
ASPF: filters packets at the application layer.
l
Blacklist: filters packets based on source IP addresses.
l
Whitelist: prevents the specified IP addresses from being added to the blacklist and filters
packets based on source IP addresses.
l
Port mapping: defines new port numbers for different application-layer protocols,
protecting the server against service-specific attacks.
l
Attack defense: detects various network attacks and takes measures to protect the internal
network against attacks.
l
Traffic statistics and monitoring: monitors traffic volume, detects the connections between
internal and external networks, and carries out calculation and analysis.
3.2 Firewall Features Supported by the AR1200-S
The firewall features supported by the AR1200-S include ACL-based packet filtering, blacklist,
whitelist, application specific packet filter (ASPF), port mapping, virtual firewall, attack defense,
traffic statistics and monitoring, and logs.
Security Zone
The security zone, also referred to as a zone, is the basis of a firewall. All the security policies
are enforced based on zones.
A zone is an interface or a group of multiple interfaces. The users in a zone have the same security
attributes. Each zone has a unique security priority. That is, the priorities of any two zones are
different.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
44