Got it

Blocking WannaCry – Defense Solution for Huawei CE Series Switches

Latest reply: Mar 21, 2019 04:29:32 650 1 0 0 0

Hello everyone,
This post will tell you the defense solution for Huawei CE Series Switches.

Guide to Defense Configuration on CE Series Switche

Product Family

Enterprise network products

Product Model

Data center network switch

Released On


Updated On


Versions Involved

All versions



Note: Before the configuration, ensure that no service is using ports 135, 137, 139, 445, and 3389. Otherwise, the services are affected.
1. Configure an advanced ACL that is not in use on the device to match the destination ports to be protected. For example:

Acl 3000
 Rule  5 permit tcp destination-port eq 135
 Rule  10 permit udp destination-port eq 135
 Rule  15 permit tcp destination-port eq 137
 Rule  20 permit udp destination-port eq 137
 Rule  25 permit tcp destination-port eq 139
 Rule  30 permit udp destination-port eq 139
 Rule  35 permit tcp destination-port eq 445
 Rule  40 permit udp destination-port eq 445 

 Rule  45 permit tcp destination-port eq 3389 

 Rule  50 permit udp destination-port eq 3389

2. Configure a traffic classifier to match the ACL.
Traffic  classifier test
 if-match  acl 3000

3. Configure the traffic behavior to discard packets.
Traffic  behavior test

4. Configure a traffic policy.
Traffic  policy test
 classifier test behavior test

5. Apply the policy to the global inbound direction.
Traffic-policy  test global  inbound

6. Commit the configuration.

Note: Apply the policy to the inbound direction of the device. The outbound policy of the CE12800 that matches the IP addresses of traffic takes effect only on forwarded Layer 3 traffic.

That is all I want to share with you! Thank you!



  • x
  • convention:

Admin Created Mar 21, 2019 04:29:32

View more
  • x
  • convention:


You need to log in to comment to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits


Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Please bind your phone number to obtain invitation bonus.