Manual Version

20081111-C-1.03

Feature List

This manual is the security volume of the H3C SR6600 series routers. It describes the configuration of the supported security protocols and features, such as AAA and user management, firewall, NAT, IPSec, ACL, session management, and SSH2.0. The supported features are listed as follows:

Feature

Operation and command manual

Feature description

AAA RADIUS HWTACACS

AAA Configuration

AAA Commands

Authentication, authorization and accounting (AAA) provide a uniform framework used for configuring these three security functions to implement the network security management.

l      AAA configuration

l      RADIUS configuration

l      HWTACACS configuration

Firewall

Firewall Configuration

Firewall Commands

Firewall can prevent unauthorized or unauthenticated users on the Internet from accessing a protected network while allowing the users on the internal network to access web sites on the Internet and transceive E-mails.

l      Configuring a packet filter firewall

l      Configuring an ASPF

ALG

ALG Configuration

ALG Commands

The application level gateway (ALG) feature is used to process application layer packets.

PKI

PKI Configuration

PKI Commands

Public key infrastructure (PKI) is a system which uses public key technology and digital certificate to protect system security and authenticate digital certificate users.

l      Generating an RSA pair for PKI

l      Configuring PKI certificate registration

l      Submitting a PKI certificate request

l      Configuring PKI certificate validation

l      Configuring access control policy of certificate attribute

Session Management

Session Management Configuration

Session Management Commands

The session management feature is a common feature designed to implement session-based services such as network address translation (NAT), application specific packet filter (ASPF), and intrusion protection.

l      Session management configuration

l      Specifying the permanent session ACL

NAT

NAT Configuration

NAT Commands

Network Address Translation (NAT) is to translate the IP address in IP data packet header into another IP address, which is mainly used to implement private network accessing external network in practice.

l      Configuring EASY IP

l      Configuring static NAT

l      Configuring many-to-many NAT

l      Configuring many-to-one NAPT

l      Configuring internal server

l      Configuring NAT Log

l      Configuring connection limit

ACL

ACL Configuration

ACL Commands

Access Control List, used to implement flow identification. Flow template is not supported.

l      Configuring effective period of an 
IPv4 ACL

l      Basic IPv4 ACL configuration

l      Advanced IPv4 ACL configuration

l      Basic IPv6 ACL configuration

l      Advanced IPv6 ACL configuration

IPSec

IPSec Configuration

IPSec Commands

Layer 3 tunnel encryption protocol defined by IETF, which provides security for IP data packets transmitted on the Internet.

l      Configuring an IPSec proposal

l      Configuring an IPSec policy

l      Configuring an IPSec policy template

l      Applying an IPSec policy

l      Configuring an IKE proposal

l      Configuring an IKE peer

l      Configuring IKE keepalive timer

SSH2.0

SSH2.0 Configuration

SSH2.0 Commands

Security shell. When routers are connected by remote users across insecure networks, secure shell (SSH) can provide them authentication and security.

l      Configuring the SSH server

l      Configuring the SSH client

l      Configuring the device as an SSH client

Portal

Portal Configuration

Portal Commands

Portal authentication is also called web authentication and a website implementing portal authentication is called a portal website.

Public Key

Public Key Configuration

Public Key Commands

l      Local asymmetric key pair configuration

l      The public key of a peer configuration

 

download
>

Related Documentation