
NOTE
The blacklist entries without the aging time are added to the configuration file. The entries configured with
the aging time are not added to the configuration file, but you can view them by using the
display firewall
blacklist
command.
----End
Follow-up Procedure
Run the
firewall black-white-list save
command to save the blacklist and whitelist to the
specified configuration file.
3.5.4 Configuring Blacklist and Whitelist Using the Configuration
File
You can configure blacklist and whitelist entries in a batch by loading the configuration file.
Prerequisites
The configuration file for storing the blacklist and whitelist is available.
Context
The configuration file must be in txt format, and the contents are as follows:
[FirewallBlacklist] # A blacklist entry
IPAddress = # An IP address in the blacklist, in dotted decimal
notation
VPNName = # (Optional) VPN instance of the blacklist
[FirewallWhitelist] # A whitelist entry
IPAddress = # An IP address in the whitelist, in dotted decimal
notation
VPNName = # (Optional) VPN instance of the whitelist, in dotted
decimal notation
A configuration file can contain multiple entries, but each entry must be edited separately. Blank
lines are allowed between lines.
[FirewallBlacklist]
IPAddress = 210.10.10.1
VPNName = vpna
[FirewallBlacklist]
IPAddress = 220.10.10.2
VPNName =
[FirewallWhitelist]
IPAddress = 10.10.10.1
VPNName = vpnb
[FirewallWhitelist]
IPAddress =20.20.20.1
VPNName =
NOTE
A configuration file can contain up to 50000 lines.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
57