常见问题 H3C/华三通信/华为3Com路由器的常见问题>>

华为VRP3.40版本的路由器ASPF配置,在配置完ASPF策略后,注意在接口上应用ASPF策略的方向?

发布时间:2010-10-21 10:50:02

答案:

[Quidway-Serial1/0/0] firewall aspf 1 outbound  (而非inbound)

在接口上应用访问控制列表3111

[Quidway-Serial1/0/0] firewall packet-filter 3111 inbound

生效后,使用内网计算机测试结果

debug aspf session

创建aspf临时控制表

*0.4174601 aspf ASPF/8/OBJ_CREATE: Create session entry 0x505EBC4 address 192.168.100.2 bucket 1068Connected to 192.168.100.1.
*0.4174720 aspf ASPF/8/OBJ_CREATE: Create the temporary ACL entry 0x
507F204 originator 192.168.100.1(21:21) destination 192.168.100.2(1041:1041) bucket 1066

删除aspf临时控制表
*0.4207772 aspf ASPF/8/OBJ_DELETE: Delete session entry 0x505EBC4 address 192.168.100.2 bucket 1068
*0.4207890 aspf ASPF/8/OBJ_DELETE: Delete the temporary ACL entry 0x
507F204 originator 192.168.100.1(21:21) destination 192.168.100.2(1041:1041) bucket 1066

会话信息

<aspf>dis aspf sess
[Established Sessions]
Session Initiator             Responder             Application     Status

5031DA4 192.168.200.2:1028    192.168.100.1:21      ftp             FTP_CONXN_UP

下一步您可以:
查看H3C/华三通信/华为3Com路由器产品 >>
查看路由器产品 >>
查看H3C/华三通信/华为3Com路由器常见问题 >>