No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


HUAWEI Firewall Comprehensive Configuration Examples

This document describes the application scenarios and configuration methods in typical projects of the firewall.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Solution Overview

Solution Overview

As the rapid growth of education informatization and the gradual improvement of campus network construction, teachers and students are facing increasingly serious security issues of the campus network while enjoying rich network resources. These security issues affect the teaching, management, and scientific research activities of the campus. Constructing a secure campus network with a high access speed has become the urgent problems for for campus managers.

The network layer to the application layer of the campus network face different security threat:

  • Network border protection: The campus generally has multiple egresses, the link bandwidth is higher, and the network structure is complex. The spread of viruses and worms has become the most notorious threat to the campus. More and more remote network access brings great challenges to the campus security.

  • Content security defense: Network intrusion behaviors cannot be detected and blocked in a timely manner. URL access control is required to control the online behaviors of users. Improper network messages and contents need to be prevented to minimize their negative impact on society.

As a high-performance next generation firewall (NGFW), the FW can be deployed on the egress of the campus network to reduce security threats and help implement effective network management. Besides security isolation and routine attack defense, the FW provides multiple advanced application security capabilities, such as attack defense, IPS, antivirus, and online behavior auditing. It provides application-layer protection while implementing border protection.

As shown in Figure 1-1, the FW is deployed on the egress of the campus network as a security gateway to provide security isolation and protection for access between the intranet and extranet. The FW provides not only IP address-based security policies and network access control but also user-based access control and source tracking of user behaviors. The FW allows the network administrator to select the most effective management and control policies and reduces the security maintenance workload.

Figure 1-1  Application of the FW on a campus network
Updated: 2019-01-26

Document ID: EDOC1100062972

Views: 16571

Downloads: 713

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Previous Next