How to check whether configured deep security defense security takes effect on an AR router


If the configuration procedure of deep security defense is correct, simulate an attack to verify whether the configured deep security defense takes effect.

Other related questions:
Does the deep security defense function of an AR router need a license
Whether the deep security defense function of an AR router needs a license is subject to the router model and software version. For details, see the product manuals of corresponding software versions. For example, for a router with the V200R007 software, choose IPS Configuration > Configuration Notes and URL Filtering Configuration > Configuration Notes in the Security Configuration Guide > Deep Security Defense Configuration through the URL: AR100&AR120&AR150&AR160&AR200&AR1200& AR1600&AR2200&AR3200&AR3600 V200R007 Product Documentation.

How to enable the deep security defense function on an AR router
By default, the deep security defense function is limited and cannot be used. To use this function, users must obtain a license. Users can contact a branch office of Huawei to apply for and purchase a license.

Create a security zone and add interfaces into the security zone on an AR router
A router considers that data flows occurring within a security zone are trustful and therefore no security policy needs to be implemented. If data flows occur between different security zones, the security check function of the firewall is triggered, and corresponding policy is implemented. To configure firewall services, create relevant security zones and specify priorities for the security zones so as to determine deployment of security services according to the priorities between different security zones. The specified priorities cannot be modified; otherwise, other configuration cannot be performed. Different security zones have different priorities. The larger the value, the higher the priority of a zone. After a security zone is created, interfaces must be added to the zone to activate the firewall. The specific configuration procedure is as follows: 1. Run the system-view command to access the system view. 2. Run the firewall zone zone-name command to create a security zone. By default, no security zone is created on the router. 3. Run the priority security-priority command to configure a priority for the security zone. 4. Run the quit command to access the system view. 5. Run the interface interface-type interface-number command to access the interface view. 6. Run the zone zone-name command to add interfaces to the security zone.//Each security zone can contain multiple interfaces, but an interface can be added to one zone only. Note: The router will automatically create a security zone named Local which has the highest priority. This security zone cannot be deleted or contain any interface, and its priority cannot be modified. To apply the firewall functions to the control packets which are reported to this router, the Local security zone may be used. For details about the commands for creating a security zone and adding interfaces into the security zone as well as creating an interzone, see the URL: The AR router creates a security domain and adds the interface to the security zone.

WLAN security of AR routers
WLAN security is as follows: User access security: Link authentication, access authentication, and data encryption are used to ensure validity and security of user access on wireless networks. Service security: This feature protects service data of authorized user from being intercepted by unauthorized users during transmission. For details, see WLAN Security Configuration.

How to check whether the Interface Is Added to the Security Zone ?
Run the display zone command to check whether the interface is correctly added to a security zone. display zone If the interface is not added to any security zone, run the following command to add the interface to a security zone. [HUAWEI] firewall zone trust [HUAWEI-zone-trust] add interface GigabitEthernet1/0/1

If you have more questions, you can seek help from following ways:
To iKnow To Live Chat
Scroll to top