Eudemon Basic Function and Configuration: Huawei Technologies Co., Ltd. All Rights Reserved
Eudemon Basic Function and Configuration: Huawei Technologies Co., Ltd. All Rights Reserved
T
www.huawei.com
This course will introduce work mode of firewall, security area concept, ACL, NAT such basic function and configuration.
Page 2
Upon completion of this course, you will be able to: Master the concept of security area Master work mode of firewall Master the function and configuration of ACL Master the function and configuration of NAT
Page 3
Chapter 3 ACL
Chapter 4 NAT
Page 4
Route Mode
Page 5
Transparent Mode
Trust
PC
PC
PC Untrust
Page 6
Composite Mode
Eudemonactive
Trust
PC VRRP
PC
PC Untrust
Page 7
Page 8
Chapter 3 ACL
Chapter 4 NAT
Page 9
Interface 2
Local Zone 100 Zone defined by user DMZ Zone 50 UnTrust Zone 5 Interface 4 Interface 3
Trust Zone 85
Interface 1
Page 10
outbound Eudemon Local E1/0/2 E1/0/0 Eth1/0/1 outbound inbound Server Server DMZ outbound inbound
Trust
External network
Untrust
Page 11
[Eudemon]display zone username username priority is 60 interface of the zone is (1): Ethernet0/0/1
Page 12
PC Trust Zone
PC
PC
Untrust Zone
Eudemon Server Internal network HUAWEI TECHNOLOGIES CO., LTD.. All rights reserved Server External network
Page 13
Chapter 3 ACL
Chapter 4 NAT
Page 14
ACL Application
Packet filtering
Page 15
ACL Classification
Basic ACL range: 20002999
Use source address,destination address,source port number,destination port number ,up-level protocol number and so on combination to define data flow
Firewall ACL range:50005499
Use source address,destination address, destination port number to define data flow
Page 16
ACL Classification
acl [ number ] acl-number rule [ rule-id ] { permit | deny } [ source { sour-address sourwildcard | any } ] [ time-range time-name ]
rule [ rule-id ] { permit | deny } protocol [ source { souraddress sour-wildcard | any } ] [ destination { dest-address dest-mask | any } ] [ source-port operator port1 [ port2 ] ] [ destination-port operator port1 [ port2 ] ] [ icmp-type { icmp-type icmp-code | icmp-message } ] [ precedence precedence ] [ tos tos ] [ time-range time-name ]
Firewall ACL
Advanced ACL
Match priorly the route with Acl-number
Basic ACL
Match priorly the route with small Rule-id HUAWEI TECHNOLOGIES CO., LTD.. All rights reserved
Page 17
WAN
Page 18
Page 19
Chapter 3 ACL
Chapter 4 NAT
Page 20
IP address shortage Save public IP address Security element Shield private network Enterprise combination Easy to combine networks
Page 21
Internet
192.168.0.1
LAN3
10.0.0.0-10.255.255.255
172.16.0.0-172.31.255.255 192.168.0.0-192.168.255.255
Page 22
Eudemon NAT
Data packet 1 Source 192.168.1.3 destination 202.120.10.2 PC A 192.168.1.3 Trust
Server B 202.120.10.2
Page 23
Eudemon NAPT
Data packet 1 source 192.168.1.3 Source port 1357 Data packet 2 PC A source 192.168.1.3 192.168.1.3 Source port 2468 Trust Data packet 1 source 202.169.10.1 Source port 1357 Data packet2 source 202.169.10.1 Source port 2468 Untrust Internet
Server B
202.120.10.2
192.168.1.1 Data packet3 source 192.168.1.1 Source port 11111 Data packet4 source 192.168.1.2 Source port 11111
202.169.10.1 Data packet3 source 202.169.10.1 Source port 11111 Data packet4 source 202.169.10.1 Source port 22222 PC C 202.130.10.3
PC B 192.168.1.2
Page 24
Untrust
E0/0/1 202.168.0.1/26
Data packet 1 source 202.168.0,2 Destination 202.168.0.11 Data packet 1 source 202.168.0,2 destination 192.168.0.101
Page 25
Eudemon
Private address
ACL
Public address
Page 26
DMZ
Page 27
Page 28
Page 29
Server in private network information: zone ---------Total GlobalAddr GlobalPort ---8080 1021 InsideAddr InsidePort ---8080 21(ftp) Pro --VPN public
Page 30
Summary
advanced ACL?
Which kind of NAT does Eudemon support?
Page 31
Thank you
www.huawei.com
T