558 CHAPTER 39: CONFIGURING FIREWALL
Tabl e 627 Configure Rules for Applying Access Control List on Interface
By default no rule for filtering messages on interface is specified.
In one direction of an interface (inbound or outbound), up to 20 access rules can
be applied. That is to say, 20 rules can be applied in firewall packet-filter
inbound, and 20 rules can be applied in firewall packet-filter outbound.
If two rules with different sequence numbers conflict, then the number with
greater acl-number should be matched preferentially.
Specifying Logging Host Firewall supports a logging function. When an access rule is matched, and if the
user has specified to generate logging for this rule, logs can be sent to and
recorded and saved by the logging host.
Perform the following configurations in system view.
Tabl e 628 Specify Logging Host
For detailed description logging host parameters, see “Logging Function” in
“System Management”.
Displaying and
Debugging Firewall Use debugging, reset and display commands in all views.
Tabl e 629 Display and Debug Firewall
Firewall Configuration
Example The following is a sample firewall configuration in an enterprise.
This enterprise accesses the Internet through interface Serial 0 of one 3Com
router, and the enterprise provides www, FTP and Telnet services to the outside.
The internal sub-network of the enterprise is 129.38.1.0, the internal ftp server
address 129.38.1.1, internal Telnet server address 129.38.1.2, and the internal
Operation Command
Specify rule for filtering receive/send
messages on interface firewall packet-filter acl-number [
inbound | outbound ]]
Cancel rule for filtering receive/send
messages on interface undo firewall packet-filter
acl-number [ inbound | outbound ]]
Operation Command
Specify logging host ip host unix-hostname ip-address
Cancel logging host undo ip host
Operation Command
Display firewall status display firewall
Display packet filtering rule and its
application on interface display acl [ all | acl-number |
interface type number ]
Display current timerange display timerange
Display whether the current time is within
special timerange display isintr
Clear access rule counters reset acl counters [ acl-number ]
Enable the information debugging of
firewall packet filtering debugging filter { all | icmp | tcp |
udp}