Configuration considerations, Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 351
Figure 5 Network diagram for PBR
Configuration considerations
To meet these requirements:
•
Configure ACL 3101 to match TCP packets and ACL 3102 to match all packets.
•
Configure node 5 of the policy to send the inbound packets matching ACL 3101 to GigabitEthernet
0/2.
•
Configure node 10 of the policy not to process the inbound packets matching ACL 3102.
•
Apply the policy on GigabitEthernet 0/1.
Configuration procedure
NOTE:
Before performing the following configuration, use the firewall default deny command to specify the
default filtering action as denying packets to pass the firewall.
Step1
Configure IP addresses for interfaces and configure security zones (omitted).
Step2
Defining the ACLs.
# Create ACL 3101.
•
Select Firewall > ACL from the navigation tree, and then click Add. Then make the following
configurations as shown in
.
•
Type 3101 for ACL Number.
•
Click Apply.