
Pre-configuration Tasks
Before configuring ASPF, complete the following tasks:
l
Configuring zones and adding interfaces to the zones
l
Configuring the interzone and enabling the firewall function in the interzone
Data Preparation
To configure ASPF, you need the following data.
No.
Data
1
Names of the two zones
2
Type of the application protocol
3
(Optional) Aging time of the session table for each application layer protocol
3.7.2 Configuring ASPF Detection
ASPF can detect and filter FTP, HTTP, SIP, and RTSP packets at the application layer.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
firewall interzone
zone-name1
zone-name2
The interzone view is displayed.
Step 3
Run:
detect
aspf
{
all
|
ftp
|
http
[
activex-blocking
|
java-blocking
] |
rtsp
|
sip
}
ASPF is configured.
Generally, the application-layer protocol packets are exchanged between the two parties in
communication, so the direction does not need to be configured. The AR1200-S automatically
checks the packets in both directions.
By default, ASPF is not configured in the interzone.
----End
3.7.3 Checking the Configuration
After ASPF is configured, you can view information about ASPF.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
62