Got it

Traffic Filter

Created: Sep 27, 2020 02:25:16Latest reply: Sep 27, 2020 03:17:30 408 2 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hi community,

I want to prohibit intranet PCs from accessing certain websites. According to the document, I have configured the following traffic Filter for tests.

Now it is found that although the PC cannot ping 8.8.8.8, the AR can still ping 8.8.8.8. Is this normal?

PC----AR1220-(G0/0/1)---internet

acl number 3001 

 rule 5 deny icmp destination 8.8.8.8 0

 rule 10 permit ip 

interface GigabitEthernet0/0/1

 traffic-filter outbound acl 3001 

#


Featured Answers

Recommended answer

Popeye_Wang
Admin Created Sep 27, 2020 02:26:35

Hello,

The AR software includes the control and forwarding planes. The differences are as follows:

  • The forwarding panel forwards packets destined for another device. Generally, packets with inbound and outbound physical interfaces are called packets destined for another device.

  • Packets sent by the control plane do not enter the forwarding plane. Most of these packets are irrelevant to services deployed on the forwarding plane.

The ping 8.8.8.8 command executed on the AR is directly sent from the protocol stack to the outbound interface without entering the forwarding plane. Traffic filtering applies to the forwarding plane without involving the QoS process, so packets cannot be filtered. This is a normal situation that destination address 8.8.8.8 can be pinged on the AR.

View more
  • x
  • convention:

All Answers

Hello,

The AR software includes the control and forwarding planes. The differences are as follows:

  • The forwarding panel forwards packets destined for another device. Generally, packets with inbound and outbound physical interfaces are called packets destined for another device.

  • Packets sent by the control plane do not enter the forwarding plane. Most of these packets are irrelevant to services deployed on the forwarding plane.

The ping 8.8.8.8 command executed on the AR is directly sent from the protocol stack to the outbound interface without entering the forwarding plane. Traffic filtering applies to the forwarding plane without involving the QoS process, so packets cannot be filtered. This is a normal situation that destination address 8.8.8.8 can be pinged on the AR.

View more
  • x
  • convention:

Hi friend hope below can help u:

Configuring URL Filtering

   Configuring a URL Filtering Profile
   Binding a URL Filtering Profile to a Security Policy
   Binding the Security Policy to an Interzone
   (Optional) Configuring the Device to Control generating of URL Filtering Logs
   Checking the Configuration
https://support.huawei.com/enterprise/en/doc/EDOC1000097189/1b439cbc/configuring-url-filtering


Thanks!

View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.