Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 104

5
Figure 1 Network diagram for URL parameter filtering configuration
Configuration procedure
# Configure IP addresses for the interfaces. (Omitted)
# Configure the NAT policy for the outbound interface.
[Device] acl number 2200
[Device-acl-basic-2200] rule 0 permit source 192.168.1.0 0.0.0.255
[Device-acl-basic-2200] rule 1 deny source any
[Device-acl-basic-2200] quit
[Device] nat address-group 1 2.2.2.10 2.2.2.11
[Device] interface gigabitethernet 0/1
[Device-GigabitEthernet0/1] nat outbound 2200 address-group 1
[Device-GigabitEthernet0/1] quit
# Enable the URL parameter filtering function and add URL parameter filtering entry group.
[Device] firewall http url-filter parameter enable
[Device] firewall http url-filter parameter keywords group
Use the display firewall http url-filter parameter verbose command to display detailed URL
parameter filtering information.
[Device] display firewall http url-filter parameter verbose
URL-filter parameter is enabled.
There are 1 packet(s) being filtered.
There are 2 packet(s) being passed.
Use the display firewall http url-filter parameter all command to display URL parameter
filtering information about all filtering entries.
[Device] display firewall http url-filter parameter all
SN Match-Times Keywords
------------------------------------
1 1 group