How to test whether a remote UDP interface is reachable based on an IP address on an AR router

5

An AR router cannot detect whether a remote UDP interface is reachable based on an IP address.

Other related questions:
Does an AR support rate limiting based on an individual IP address
In V200R002C00 and later versions, you can run the qos car command to configure rate limiting based on an individual IP address.

How do I configure the AR router to map multiple internal IP addresses to external IP addresses using Easy IP
A Huawei AR router can use Easy IP to implement mapping between internal IP addresses and public IP addresses. Internal users access the Internet by performing Easy IP on GE0/0/1.The configuration is as follows: 1.Configure an ACL rule and configure NAT on the internal network address segment 192.168.0.0/24 . [Huawei] acl 2000 [Huawei-acl-basic-2000] rule 5 permit source 192.168.0.0 0.0.0.255 [Huawei-acl-basic-2000] quit 2. Assign IP addresses to interfaces on the router. [Huawei] interface ethernet0/0/1 [Huawei-Ethernet0/0/1] ip address 192.168.0.1 24 [Huawei-Ethernet0/0/1] quit [Huawei] interface gigabitethernet 3/0/0 [Huawei-GigabitEthernet3/0/0] ip address 200.100.1.2 24 [Huawei-GigabitEthernet3/0/0] quit 3. Configure outbound NAT in Easy IP mode on the outbound interface. [Huawei] interface gigabitethernet 0/0/1 [Huawei-GigabitEthernet0/0/1] nat outbound 2000 [Huawei-GigabitEthernet0/0/1] quit

Configure attack defense on an AR router
Attack defense mainly defends the CPU against attack packets to ensure that the server can normally run in case of an attack. Attack defense configuration is composed of the following parts: enabling attack defense, (optional) configuring flooding defense parameters, super-large ICMP packet defense parameters, and scan attack defense parameters, and checking configuration result. By default, no type of attack defense is enabled. For details about how to configure attack defense of AR series routers using command lines and through the web NMS, see the URL: AR router configuration attack defense .

Configure the IP address of the management interface on AR routers
The procedure of changing the management IP addresses on the AR router is as follows: 1. You can configure a management IP address on the CLI using either of the following methods: a. Configure a management IP address on the management interface of the AR router. For example, the management interface is GE0/0/0. Set the management IP address to 192.168.1.10 and the mask length to 24. 2. On the VLANIF interface, configure the management IP address. Note: In the factory settings, all LAN interfaces on the AR150&AR160&AR200&AR120&-S&AR150-S&AR160-S&AR200-S are added to VLAN 1 by default. The default IP address 192.168.1.1/24 is configured for VLAN 1. Any LAN interface can use this IP address as the management IP address. The procedure for changing the IP address of VLAN 1 is as follows: For example, when LAN ports of the AR150 are added to VLAN 1, configure the management IP address as 192.168.1.10 and set the mask length to 24. system-view [Huawei] vlan 1 [Huawei-vlan1] quit [Huawei] interface vlanif 1 [Huawei-Vlanif1] ip address 192.168.1.10 24 [Huawei-Vlanif1] quit 2. Configure the management IP address through the web platform. Log in to the web platform, access WAN Access, and find the corresponding management interface in Ethernet Interface. Click the Modify under Operation on the right of the interface to configure an IP address for the corresponding interface.

How to configure remote interface mirroring on AR series routers
Remote interface mirroring is only supported in V200R005C32 and earlier versions. By configuring remote interface mirroring, you can replicate the packets transmitted through the interface to remote monitoring devices for analysis and surveillance. Before configuring remote interface mirroring, ensure that the routing protocol and GRE tunnels are configured. 1. Configure the remote observing server. Procedure Run the system-view command to enter the system view. Run the observe-server destination-ip destination-ip-address source-ip source-ip-address [ dscp dscp-value ] command to configure the observing server in remote interface mirroring. Note: The destination-ip-address parameter indicates the IP address of the monitoring device. The source-ip-address parameter indicates the IP address of the mirroring interface. If the IP addresses of the monitoring device and the mirroring interface are private IP addresses, GRE tunnels must be configured first to ensure the interworking between private IP addresses on public networks. 2. Configure the remote mirroring interface. Background A mirroring interface can be an IP-Trunk interface, an Ethernet interface, or an Eth-Trunk interface. - If an Eth-trunk interface is configured as a mirroring interface, a member interface of the Eth-trunk interface cannot be configured as a mirroring interface separately. If you want to configure a member interface of the Eth-trunk as a mirroring interface, you must unbind the member interface from the Eth-trunk interface. - If a member interface of an Eth-trunk is configured as a mirroring interface, the Eth-trunk interface cannot be configured as a mirroring interface. If you want to configure the Eth-trunk interface as a mirroring interface, you must unbind the member interface that is configured as the mirroring interface from the Eth-trunk interface. Procedure Run the system-view command to enter the system view. Run the interface interface-type interface-number command to enter the interface view. Run the mirror to observe-server{ both | inbound | outbound } command to configure the remote mirroring interface.

If you have more questions, you can seek help from following ways:
To iKnow To Live Chat
Scroll to top