03-Security Configuration Guide

HomeSupportConfigure & DeployConfiguration GuidesH3C SecPath M9000 Configuration Guide(V7)(E9X71)-6W70003-Security Configuration Guide
29-Location identification configuration
Title Size Download
29-Location identification configuration 172.22 KB

Configuring location identification

About location identification

This feature identifies the locations of the source and destination IP addresses of packets and works with a security policy to implement location-based packet control.

A location in this feature refers to a set of IP addresses in the location. You can add locations and their IP addresses to the location identification module by loading a location signature file or manually configuring locations. The device determines the source and destination locations of packets by examining the source and destination IP addresses of the packets. Then, the device works with a security policy to implement location-based packet control.

Figure 1 Location identification

Location identification tasks at a glance

To configure location identification, perform the following tasks:

1.     Configuring a location

2.     Configuring a location group

3.     Updating the location signature library

Configuring a location

About this task

Locations include the following types:

·     Predefined locations—Locations defined in the location signature library, including countries, provinces, and cities.

·     User-defined locations—Locations created by the user. This type of location can be used to define a smaller geographical area, such as a district or a street in a city.

·     Unknown location—A particular location in the location signature library, which is used to store IP addresses that do not have a location.

Restrictions and guidelines

The name of a user-defined location cannot be the same as that of a predefined location.

The IPv4 addresses in different locations cannot be overlapping.

When manually added IPv4 addresses overlap with predefined IPv4 addresses, the predefined IPv4 addresses do not take effect.

Only user-defined locations can be configured with the longitude and latitude.

Procedure

1.     Enter system view.

system-view

2.     Enter location view.

geo-location { unknown | { pre-defined | user-defined } geo-location-name }

3.     Add IPv4 addresses to the location.

ip address { ip-address { mask-length | mask } | range ip-address1 ip-address2 }

By default, only a predefined location or the unknown location contains IPv4 addresses.

The undo ip address command can only remove manually added IPv4 addresses.

4.     (Optional.) Specify the longitude and latitude of the location.

coordinate longitude longitude-value latitude latitude-value

By default, the longitude and latitude are not specified.

5.     (Optional.) Configure a description for the location.

description text

By default, no description is configured.

Configuring a location group

About this task

You can add multiple locations to a location group to process the packets of the locations in the same way. You can also add a location group to another location group.

Restrictions and guidelines

Two location groups cannot contain each other at the same time.

The system supports a maximum of three location group hierarchy layers. For example, if groups 1 and 2 are members of groups 2 and 3, respectively, group 3 cannot have members and group 1 cannot be members of another group.

Procedure

1.     Enter system view.

system-view

2.     Enter location group view.

geo-location-group geo-location-group-name

3.     Add a location to the location group.

add geo-location geo-location-name

By default, a location group does not contain any locations.

4.     Add a location group to the location group.

add geo-location-group geo-location-group-name

By default, a location group does not contain any location groups.

5.     (Optional.) Configure a description for the location group.

description text

By default, no description is configured.

Updating the location signature library

About this task

The location signature library contains predefined countries, provinces, and cities as locations and contains public IP addresses of each location. The device is loaded with a location signature file by default. To update the location signature library, copy the latest signature file from the official website to the local root directory and load it.

Procedure

1.     Enter system view.

system-view

2.     Load a location signature file to update the location signature library.

geo-load file-name

Display and maintenance commands for location identification

Execute display commands in any view.

 

Task

Command

Display information about locations.

display geo-location { all | type { pre-defined | unknown | user-defined } | name geo-location-name }

Display the location of an IP address.

display geo-location ip ip-address

Display information about location groups.

display geo-location-group [ name geo-location-group-name ]

Example: Configuring location identification

See "Configuring security policies."

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网