Is QQ controlled on an AR


In V200R005 and later versions, AR routers control the use of QQ.
1. Log in to the web management page.
2. Choose Security > Network Behavior Management > Basic Configuration, and select the interface to which the online behavior management is applied. Click Apply, and the online behavior management function is enabled.
3. Choose Security > Network Behavior Management > Advanced Configuration, and click Create on the Time Range Management page. In the Create Time Range dialog box, set parameters and set the name to workday (for reference only), and click OK.
4. Choose Security > Network Behavior Management > Basic Configuration, and click Create in the Application List area. Select qq and web_qq in the Select Application Procotol Set area, set Control Mode to Deny and Flow limiting, and set Repeat Time to workday. Click OK.

Other related questions:
Users can open QQ but cannot access the Internet
Q: Users can open QQ but cannot access the Internet A: Check whether the DNS configuration on the PC is correctly configured. Check whether the configuration is improved using the public DNS or Contact the carrier for further analysis if there is no improvement. The causes are as follows: The main difference between the Internet access and QQ is that the DNS resolution is the first step to access a web page, while QQ does not require resolution. Therefore, the rate of the DNS returned packets determines failed or slow Internet access. If QQ can run normally, the link is available. The problem may exist in DNS if the web page is not displayed.

Viewing users of QQ on the USG2000 series
The USG2000 series does not have the audit policy for QQ and therefore cannot display users of QQ.

How is access control configured on an AR
You can configure a traffic policy on an AR to implement access control. For example, to prevent users on a network segment from accessing the Internet, perform the following operations: # acl number 2015 //Configure an ACL to define the network segment. rule 5 permit source # traffic classifier c1 operator or //Configure a traffic classifier and reference the ACL. if-match acl 2015 # traffic behavior b1 //Configure a traffic behavior and define the deny action. deny # traffic policy p1 //Configure a traffic policy and bind the traffic classifier and traffic behavior to the traffic policy. classifier c1 behavior b1 # interface Ethernet5/0/0 traffic-policy p1 inbound //Apply the traffic policy to an interface. #

Can an AR limit P2P download
Starting from V200R005, the AR supports P2P download limiting or rate limiting on P2P download. You must purchase the license.

How to configure access control on the AR
AR series routers can implement access control through ACL filtering. Traffic filtering can be used on an interface to filter packets based on ACLs, but only WAN interfaces support this configuration. You can also configure a traffic policy to implement access control. Unidirectional access is implemented based on firewall zones but not ACLs.
Model 1:
Configure Eth2/0/0 to allow packet with the source IP address of to pass through based on an ACL.
< system-view
[Huawei] acl 3000
[Huawei-acl-adv-3000] rule 5 permit ip source 0
[Huawei-acl-adv-3000] quit
[Huawei] interface ethernet 2/0/0
[Huawei-Ethernet2/0/0] traffic-filter inbound acl 3000
Model 2: The method used to create the ACL is similar to that in mode 1. The difference is that the traffic policy is used.
< system-view
[Huawei] traffic classifier c1
[Huawei-classifier-c1] if-match acl  3000
[Huawei-classifier-c1] quit
[Huawei] traffic behavior b1
[Huawei-behavior-b1] quit
[Huawei] traffic policy p1
[Huawei-trafficpolicy-p1] classifier c1 behavior b1 
# Apply the traffic policy p1 to Eth2/0/0 in the inbound direction.
[Huawei] interface ethernet 2/0/0
[Huawei-Ethernet2/0/0] traffic-policy p1 inbound
[Huawei-Ethernet2/0/0] quit

