
3.14 Configuration Examples
This section provides several configuration examples of firewall.
3.14.1 Example for Configuring the ACL-based Packet Filtering
Firewall
This example shows the configuration of the ACL-based packet filtering firewall on a network.
The firewall improves data flow security by filtering packets based on source/destination IP
addresses, source/destination port numbers, and IP protocol numbers.
Networking Requirements
, Ethernet0/0/0 of the Router is connected to a highly secure internal
network, and GE0/0/1 is connected to the insecure external network. The Router must filter the
packets between the internal network and the external network. The following requirements
must be met:
l
A host (202.39.2.3) on the external network is allowed to access the servers in the internal
network.
l
Other hosts are not allowed to access the servers on the internal network.
Figure 3-2
Network diagram for configuring ACL-based packet filtering
Telnet server
FTP server
129.38.1.2
202.39.2.3
Web server
Internal
network
Router
129.38.1.4
129.38.1.3
Ethernet0/0/0
GE0/0/1
Configuration Roadmap
The configuration roadmap is as follows:
1.
Configure zones and an interzone.
2.
Add interfaces to the zones.
3.
Configure an ACL.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
3 Firewall Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
81