H3c-technologies H3C SecPath F1000-E manuels

Manuels d'utilisation et guides de l'utilisateur pour Sécurité H3c-technologies H3C SecPath F1000-E.
Nous fournissons des manuels en pdf 10 H3c-technologies H3C SecPath F1000-E à télécharger gratuitement par type de document : Manuel d'utilisateur


Table des matières

Table of Contents

1

Portal Configuration

2

Portal System Components

3

Portal Authentication Modes

4

Configuration Prerequisites

8

RADIUS Configuration

12

Firewall Web

12

Configuration Manual

12

Portal Packets

13

2. Probe parameters

15

Logging Off Portal Users

17

Step2 Configure Device

21

DHCP Configuration

24

Functions

27

Information Synchronization

34

Configuration considerations

35

Troubleshooting Portal

42

ALG Configuration

45

2. Authenticating the user

46

ALG Configuration Examples

47

Enabling ALG

47

# Enable ALG for NBT

50

# Configure NAT

50

RSH Configuration

52

RSH Configuration Example

53

SSH2.0 Configuration

57

Version negotiation

58

Authentication

58

Session request

59

Interaction

59

SSH Connection Across VPNs

60

Public Key Commands

61

Security Volume

61

Interface Commands

62

System Volume

62

Configuring an SSH User

63

SFTP Service

80

Working with SFTP Files

83

Displaying Help Information

84

SSL Configuration

91

SSL Configuration Task List

92

Configuration Procedure

93

Troubleshooting SSL

97

Web Filtering Configuration

100

Java Blocking

101

ActiveX Blocking

101

Configuring Web Filtering

102

Network requirements

103

Configuration procedure

104

Invalid Use of Wildcard

107

Invalid Blocking Suffix

107

Public Key Configuration

109

Connection Limit Overview

118

Verification

121

Symptom

121

Analysis

121

Solution

122

Contents

123

Firewall configuration

124

IPsec Configuration

129

Implementation of IPsec

130

Basic Concepts of IPsec

130

Encapsulation modes

131

IPsec Tunnel Interface

132

Configuring IPsec

134

Implementing ACL-Based IPsec

135

Mirror image ACLs

137

Protection modes

138

Configuring an IPsec Policy

139

NOTE:

143

Configuring an IPsec Profile

148

Tunneling Commands

150

IP Services Volume

150

IPsec Configuration Examples

152

2. Configure Device B

153

Configuation procedure

157

3. Configure Device C

162

IKE Configuration

165

Operation of IKE

166

IKE Configuration Task List

167

Gateway

168

Configuring an IKE Proposal

168

Configuring an IKE Peer

169

Setting Keepalive Timers

171

Configuring a DPD

172

IKE Configuration Examples

173

Traversal

175

Troubleshooting IKE

180

Proposal Mismatch

181

ACL Configuration Error

181

Table des matières

Table of Contents

1

ARP Configuration

2

Operation of ARP

3

Configuring ARP

4

Enabling the ARP Entry Check

6

ARP Configuration Example

8

[Device] display arp static

9

Gratuitous ARP Configuration

10

Configuring Gratuitous ARP

11

Proxy ARP Configuration

13

Enabling Proxy ARP

14

Isolation

16

Step2 Configure the device

19

Connected Network

22

Configuring TCP Attributes

24

Introduction

25

Optimization

27

Adjacency Table Overview

29

DHCP Overview

33

DHCP Address Allocation

34

DHCP Message Format

35

DHCP Options

36

Self-Defined Options

37

1. Normal padding format

38

Option 184

39

DHCP Server Configuration

41

Configuration Task List

43

Creating a DHCP Address Pool

44

Address Pool

44

Service

49

Enabling DHCP

50

Analysis

58

Application Environment

59

Fundamentals

59

Agent Interface

62

Functions

63

Enabling Offline Detection

65

DHCP-RELEASE Messages

66

Option 82

66

DHCP Client Configuration

71

2. Configure Device B

73

3. Verification

73

BOOTP Client Configuration

75

IP Address Through BOOTP

76

DHCPv6 Overview

80

Address/Prefix Lease Renewal

81

Operation

83

DHCPv6 Server Configuration

84

Basic Concepts

85

Prefix Selection Process

85

Enabling the DHCPv6 Server

86

Creating a Prefix Pool

86

Configuration considerations

89

DHCPv6 Client Configuration

97

IPv6 Basics Configuration

101

IPv6 Addresses

103

Unicast addresses

104

Multicast addresses

104

Address resolution

106

Duplicate address detection

107

IPv6 PMTU Discovery

108

IPv6 Transition Technologies

109

Protocols and Standards

109

Enabling IPv6

111

Addresses

111

Manual configuration

112

Configuring IPv6 ND

114

Learned

115

Message for DAD

118

Enabling ND Proxy

118

Configuring PMTU Discovery

119

Interval

122

Messages

123

Configuration

124

IPv6 Configuration Example

125

Verification

126

Symptom

129

Solution

129

FTP Configuration

131

Configuring the FTP Client

132

Network requirements

136

Configuration procedure

137

Configuring the FTP Server

138

Device Management Commands

141

System Volume

141

TFTP Configuration

142

Configuring the TFTP Client

143

Tunneling Configuration

147

IPv6 over IPv4 Tunnel

148

5. ISATAP tunnel

151

IPv4 over IPv4 Tunnel

152

IPv4/IPv6 over IPv6 Tunnel

152

6PE Overview

153

Configuration Prerequisites

155

Configuration Procedure

155

Static Routing Configuration

156

IP Routing Volume

156

Configuration Example

157

Configuration verification

158

Configuring a 6to4 Tunnel

163

Configuring an ISATAP Tunnel

168

NAT-PT Configuration

186

Implementing NAT-PT

187

NAT-PT Limitations

188

Configuring NAT-PT

189

Enabling NAT-PT

190

Configuring a NAT-PT Prefix

190

natpt-prefix

193

Troubleshooting NAT-PT

198

Table des matières

Preface

3

Obtaining documentation

4

Technical support

5

Documentation feedback

5

Contents

6

Configuring ACLs

11

Match order

12

ACL rule numbering

13

IPv4 ACL acceleration

13

Configuration task list

14

Creating an ACL

14

Configuring a basic ACL rule

15

Configuring ACL acceleration

21

ACL configuration example

21

Creating a time range

22

Defining an ACL

22

ACL configuration task list

25

Configuring a basic ACL

26

Configuring an advanced ACL

27

Copying an ACL

30

Configuring security zones

34

Zone configuration task list

35

Creating a zone

35

Configuring a zone member

36

Zone ID Display the zone ID

37

Zone configuration example

38

Configuration consideration

39

HTTP configuration example

45

Creating a basic ACL

46

HTTPS configuration example

49

Creating a PKI domain

50

Generating an RSA key pair

51

Adding a local user

53

Address resource overview

55

Exporting configuration

62

Exporting configurations

68

Importing configurations

69

Interzone policy overview

73

Enable Syslog

93

Function

93

Managing sessions

95

3. Click Apply

98

Clearing sessions

108

Overview

109

Network requirements

110

Configuring the host

110

Configuring the SecPath

110

Configuration guidelines

112

Configuring ASPF

113

ASPF configuration example

114

Configuration procedure

115

Verifying the configuration

120

Authentication client

123

Access device

123

Portal server

123

Security policy server

123

Portal authentication mode

124

Configuration prerequisites

127

Logging off portal users

136

SecPathHost

138

RADIUS server

138

{ Name: newpt

147

{ IP address: 192.168.0.111

147

{ Key: portal

147

{ Port number: 50100

147

Configuration considerations

153

Troubleshooting portal

158

Configuring AAA

159

Client/server model

160

RADIUS packet format

162

Extended RADIUS attributes

164

HWTACACS

165

Domain-based user management

167

AAA across VPNs

168

Protocols and standards

169

RADIUS attributes

169

Configuring AAA at the CLI

172

Configuring AAA schemes

174

Command

176

Remarks

176

Configuring SecPath

189

Creating a RADIUS scheme

192

Creating an HWTACACS scheme

204

Configuring HWTACACS server

205

Item Descri

207

Telnet user

209

HWTACACS server

209

10.1.1.1/24

209

Creating an ISP domain

219

AAA configuration examples

226

$enab1$ pass1 1

239

$enab2$ pass2 2

239

$enab3$ pass3 3

239

Troubleshooting AAA

254

Troubleshooting HWTACACS

256

Configuring password control

257

{ Digits 0 to 9

259

Configuring FIPS

268

FIPS self-tests

269

Conditional self-tests

270

Triggering a self-test

270

Task Command

271

A C D E F I L O P S T V Z

272

Table des matières

Configuration Guide

1

Preface

3

GUI conventions

4

Symbols

4

Network topology icons

4

Port numbering in examples

4

Obtaining documentation

5

Technical support

5

Documentation feedback

5

Contents

6

Device information

12

System resource state

13

Device interface information

13

Recent system logs

14

Tracert

17

Prerequisites

18

System debugging

20

Debugging a feature

21

Ping example

22

Ping and tracert example

24

Configuration example

26

Configuring TCP attributes

27

Configuring TCP timers

29

Managing the file system

33

Displaying file contents

34

Renaming a file

34

Copying a file

34

Moving a file

34

Deleting a file

34

Managing directories

35

Managing storage media

36

Partitioning a CF card

37

Performing batch operations

39

Upgrading software

41

Upgrading the BootWare

42

Installing hotfixes

44

Patch states

45

DEACTIVE state

46

ACTIVE state

46

Patch installation task list

47

Installation prerequisites

47

Loading a patch file

49

Activating patches

49

Confirming running patches

49

Stopping running patches

50

Hotfix configuration example

52

Managing configuration files

54

Backing up the configuration

56

Restoring configuration

56

Resetting the configuration

57

System information levels

67

System information formats

70

PRI (priority)

71

1.1.0.1/16 1.2.0.1/16

85

[SecPath] quit

89

Managing logs

90

Configuring user logging

92

Exporting user logs

97

<SecPath> system-view

98

Configuring session logging

99

Log report

101

Displaying system logs

102

Displaying blacklist logs

104

Displaying user logs

106

Configuring NTP

109

How NTP works

110

NTP message format

111

NTP operation modes

112

Symmetric peers mode

113

Broadcast mode

113

NTP for VPNs

114

NTP configuration task list

115

Configuration guidelines

116

Configuration procedure

116

Configuration prerequisites

120

NTP configuration examples

123

Network requirements

124

delay disper

129

Root delay: 40.00 ms

129

Root delay: 31.00 ms

133

Configuring RMON

134

History group

135

Event group

135

Alarm group

135

Private alarm group

136

Configuring SNMP

144

SNMP operations

145

SNMP protocol versions

145

Slot IDInterface Type

148

Offset Chassis ID

148

Configuring SNMP logging

149

Configuring SNMP traps

149

SNMP configuration examples

152

SNMPv3 configuration example

153

Configuring MIB style

157

Configuring RSH

158

Configuring the remote host

159

Configuring the SecPath

160

Configuring SSH

161

Version negotiation

162

Authentication

162

Session request

163

Interaction

163

SSH support for VPNs

164

Configuring an SSH user

167

Configuring SFTP

186

Working with SFTP files

189

Displaying help information

190

Managing virtual firewalls

197

Configuring a virtual device

198

VD_BVD_A

202

GE0/2GE0/1

202

Overview

205

Configuration task list

205

Specifying service type

206

Configuring FTP

212

Task Command

222

Remarks

222

Configuring TFTP

223

Configuring the TFTP client

224

<Sysname> reboot

226

Address acquisition process

229

File types

230

TFTP request sending mode

231

Table des matières

Preface

3

Obtaining documentation

4

Technical support

5

Documentation feedback

5

Contents

6

Overview

26

Creating an interface

29

Configuring IPv4 address

48

Special IP addresses

49

Subnetting and masking

49

Configuring VLANs

53

VLAN types

54

Creating a VLAN

55

Modifying a VLAN

56

Modifying a port

57

VLAN configuration example

58

Configuring VLANs at the CLI

61

Configuring port-based VLANs

63

Adding a MAC address entry

74

Configuring MSTP

81

How STP works

82

Introduction to RSTP

88

Introduction to MSTP

89

Basic concepts in MSTP

90

Roles of ports

92

How MSTP works

93

Configuring MSTP globally

96

Item Descri

98

• You cannot configure both

98

Configuring MSTP on a port

99

MSTP configuration example

101

Configuration procedure

102

Verifying the configurations

105

Configuring MSTP at the CLI

107

Task Remarks

108

Configuring an MST region

111

Configuring edge ports

116

Configuration example

118

Getting Started Guide

120

Performing mCheck

121

Configuring Digest Snooping

122

[DeviceB-Ethernet1/1] quit

124

Configuration prerequisites

125

Enabling BPDU guard

126

Enabling root guard

127

Enabling loop guard

127

Enabling TC-BPDU guard

128

Network requirements

129

Configuration guidelines

133

Configuring PPP

134

CHAP authentication

135

MS-CHAP authentication

136

MS-CHAP-V2

136

PPP link phases

137

Access Control

140

Configuration Guide

140

Configuring PPP negotiation

144

IP address negotiation

145

DNS address negotiation

145

PPP configuration examples

150

Symptom 3

151

Analysis

151

Solution

151

Configuring PPPoE

152

PPPoE client

153

Configuration task list

153

Creating a PPPoE client

154

Configuring the PPPoE client

157

Configuring the PPPoE server

158

Verifying the configuration

158

Configuring a PPPoE session

160

Working mechanism

164

Web interface

166

DHCP overview

171

IP address lease extension

172

DHCP message format

173

DHCP options

174

Protocols and standards

177

Configuring DHCP server

178

Enabling DHCP

180

Enabling DHCP Required

191

Creating a DHCP address pool

192

Enabling Option 82 handling

202

Symptom

208

Configuring DHCP relay agent

210

DHCP relay agent

213

Creating a DHCP server group

215

group-id

221

Configuring DHCP client

229

Configuring BOOTP client

233

IP address through BOOTP

234

Configuring DNS

236

DNS proxy

237

DNS client

238

DNS server

238

Configuring DNS proxy

242

Configuring the DNS server

244

Configuring the DNS client

246

Configuring DNS at the CLI

247

Configuring the DNS proxy

248

Configuring DNS spoofing

249

Configuring DDNS

256

DDNS configuration example

258

Configuring DDNS at the CLI

261

Configuring a DDNS policy

262

DDNS configuration example I

264

Configuring ARP

267

ARP table

268

Displaying ARP entries

269

Creating a static ARP entry

270

Configuring ARP at the CLI

274

Configuring the SecPath

277

Configuring gratuitous ARP

279

Configuring proxy ARP

281

Enabling common proxy ARP

282

Enabling local proxy ARP

282

Configuring the switch

285

Layer 3 forwarding overview

288

Configure the firewall card

290

GE3/0/1 GE3/0/2

298

XGE2/0/1

298

Configuring UDP helper

300

Configuring QoS

303

QoS techniques

304

QoS configuration approaches

305

Traffic policing

306

Congestion management

308

Line rate

311

Configuring a QoS policy

312

Configuring a class

313

Configuring a policy

318

Defining a class

321

Defining a traffic behavior

321

Defining a policy

322

QoS configuration examples

324

Configuring traffic policing

343

Token bucket

344

Complicated evaluation

344

Creating a CAR list

345

FIB table

353

Task Command

354

Remarks

354

IP routing overview

356

Configuring static routing

358

Configuration considerations

360

BFD control packet mode

363

BFD echo packet mode

364

Configuring RIP

372

Configuring interface RIP

373

Configuring RIP at the CLI

376

Configuring a RIP version

378

Advertising a default route

381

Configuring RIP timers

383

Specifying a RIP neighbor

386

Configuring BFD for RIP

387

Troubleshooting RIP

404

Configuring OSPF

405

Configuration overview

406

Configuring OSPF globally

406

Configuring OSPF areas

407

Configuring OSPF interfaces

409

Configuring OSPF at the CLI

418

Enabling OSPF

419

Configuring an NSSA area

422

Configuring a virtual link

422

Configuring OSPF preference

429

Advertising a host route

430

Configuring stub routers

434

Enabling message logging

437

Configuring BFD for OSPF

438

# Configure Router B

442

# Configure Router C

442

# Configure Router D

442

# Configure Router A

454

# Configure SecPath B

454

Configuring BGP

467

Configuring BGP globally

468

Configuring BGP peer

468

Configuring BGP at the CLI

473

Creating a BGP connection

474

Controlling route generation

476

Configuring a shortcut route

481

Configuring BGP soft-reset

489

Configuring BGP peer groups

493

Configuring BGP community

495

Enabling Trap

497

Configuring BFD for BGP

497

Displaying BGP

498

Resetting BGP connections

500

Clearing BGP information

500

# Use ping for verification

506

Troubleshooting BGP

524

Configuring IS-IS

526

Enabling IS-IS

527

Configuring IS-IS link cost

529

Configuring LSP parameters

536

Specifying LSP lengths

537

Enabling LSP flash flooding

538

Limiting LSP flooding

538

Configuring SPF parameters

539

Enabling IS-IS SNMP trap

544

IS-IS configuration examples

545

# Configure SecPath D

547

# Configure SecPath C

551

# Configure SecPath

555

SecPath:

556

Configuring load sharing

561

Displaying the routing table

562

PBR and Track

565

Creating a policy

566

Configuring a policy node

568

Applying a policy

569

Configuring PBR at the CLI

575

Configuring local PBR

576

Configuring interface PBR

576

Multicast overview

587

Tracing a multicast path

593

Changing an RPF route

594

Creating an RPF route

596

Configuring IGMP

603

Configuring SecPath A

606

Configuring SecPath B

607

Configuring SecPath C

608

Configuring IGMP at the CLI

609

Enabling IGMP

610

Configuring IGMP versions

610

Configuring static joining

610

Adjusting IGMP performance

612

Configuring IGMP SSM mapping

616

Configuring IGMP proxying

617

Task Command Remarks

619

NOTE:

619

Troubleshooting IGMP

626

Configuring PIM

628

Configuring PIM interfaces

629

Configuring PIM at the CLI

635

Configuring PIM-SM

637

Enabling PIM-SM

638

Configuring an RP

639

Configuring a BSR

641

mask-length

645

Configuring PIM-SSM

647

Configuring the prune delay

652

PIM-DM configuration example

656

Troubleshooting PIM

673

Configuring MSDP

676

Enabling MSDP

677

MSDP configuration examples

683

Anycast RP configuration

692

Configuration Procedure

697

Troubleshooting MSDP

700

IPv6 addresses

703

IPv6 address types

704

Unicast addresses

704

Multicast addresses

705

Address resolution

706

Duplicate address detection

707

IPv6 path MTU discovery

708

IPv6 transition technologies

709

Enabling IPv6

711

EUI-64 IPv6 addressing

712

Manual configuration

712

Configuring IPv6 ND

715

Enabling ND proxy

719

DHCPv6 overview

732

Address/prefix lease renewal

733

Introduction

734

Application environment

736

Basic concepts

736

Prefix selection process

737

Enabling the DHCPv6 server

738

Creating a prefix pool

738

VPN Configuration Guide

739

(4) Reply

744

(2) Relay-forward

744

(3) Relay-reply

744

Configuring IPv6 DNS

751

Figure 376 Creating a record

755

Configuring RIPng

763

Configuring RIPng timers

767

RIPng configuration examples

770

Configuring OSPFv3

778

Enabling OSPFv3

779

Configuratioon prerequisites

782

Configuring OSPFv3 timers

786

Configuring BFD for OSPFv3

788

Configuring OSPFv3 areas

791

Configuing IPv6 BGP

809

Specifying an IPv6 BGP peer

811

Injecting a local IPv6 route

811

Configuring route dampening

818

Configuring IPv6 BGP timers

821

Performing manual soft-reset

822

VPN Comman

825

Reference

825

Configuring BFD for IPv6 BGP

828

Displaying IPv6 BGP

829

Configuring IPv6 IS-IS

844

Configuring IPv6 IS-IS MTR

846

Policy-based routing

856

IPv6 PBR

856

Configuring IPv6 PBR

858

Configuring IPv6 local PBR

859

Configuring IPv6 PIM

874

Enabling IPv6 PIM-DM

875

Configuring IPv6 PIM-SM

877

Enabling IPv6 PIM-SM

878

Configuring a static RP

879

Configuring a C-RP

879

Appendix Protocol References

880

Configuring C-BSR timers

883

Configuring IPv6 PIM-SSM

887

For example:

898

Ethernet

899

EthernetEthernet

899

Troubleshooting IPv6 PIM

919

Configuring MLD

922

Enabling MLD

923

Configuring the MLD version

924

Adjusting MLD performance

926

Configuring MLD SSM mapping

930

Configuring MLD proxying

931

Enabling MLD proxying

932

MLD configuration examples

934

Troubleshooting MLD

940

Configuring routing policies

942

IP prefix list

943

AS-PATH list

943

Community list

943

Routing policy

943

Defining filters

944

Defining an AS path list

945

Configuring a routing policy

946

Creating a routing policy

947

Defining if-match clauses

947

Defining apply clauses

948

Defining a continue clause

949

Configuring SSL

956

SSL configuration task list

958

VPN Command Reference

961

Troubleshooting SSL

963





Plus de produits et de manuels pour Sécurité H3c-technologies

Modèles Type de document
H3C SecPath F5000-S Firewall Manuel d'utilisateur   H3C Technologies H3C SecPath F5000-S Firewall User Manual, 2 pages
H3C SecPath F5000-A5 Firewall Manuel d'utilisateur   H3C Technologies H3C SecPath F5000-A5 Firewall User Manual, 121 pages
H3C SecPath F100-C-SI Manuel d'utilisateur    H3C Technologies H3C SecPath F100-C-SI Benutzerhandbuch, 26 pages
H3C SecPath F5020 Manuel d'utilisateur   H3C Technologies H3C SecPath F5020 User Manual, 4 pages
H3C SecPath F5000-S Firewall Manuel d'utilisateur   H3C Technologies H3C SecPath F5000-S Firewall User Manual, 86 pages
H3C SecPath F5000-S Firewall Manuel d'utilisateur   H3C Technologies H3C SecPath F5000-S Firewall User Manual, 4 pages
H3C SecPath F5020 Manuel d'utilisateur   H3C Technologies H3C SecPath F5020 User Manual, 82 pages
H3C SecPath F5020 Manuel d'utilisateur   H3C Technologies H3C SecPath F5020 User Manual, 56 pages
H3C SecPath F1000-C-SI Manuel d'utilisateur    H3C Technologies H3C SecPath F1000-C-SI Benutzerhandbuch, 20 pages
H3C SecPath F1000-C-SI Manuel d'utilisateur   H3C Technologies H3C SecPath F1000-C-SI User Manual, 4 pages
H3C SecPath F1030 Manuel d'utilisateur   H3C Technologies H3C SecPath F1030 User Manual, 4 pages
H3C SecBlade FW Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade FW Cards User Manual, 12 pages
H3C SecBlade FW Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade FW Cards User Manual, 16 pages
H3C SecBlade FW Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade FW Cards User Manual, 6 pages
H3C SecBlade FW Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade FW Cards User Manual, 45 pages
H3C SecBlade IPS Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade IPS Cards User Manual, 31 pages
H3C SecBlade IPS Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade IPS Cards User Manual, 18 pages
H3C SecBlade SSL VPN Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade SSL VPN Cards User Manual, 21 pages
H3C SecBlade SSL VPN Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade SSL VPN Cards User Manual, 52 pages
H3C SecBlade IPS Cards Manuel d'utilisateur   H3C Technologies H3C SecBlade IPS Cards User Manual, 85 pages

H3c-technologies appareils