Basic Protocol Control Switch
Whether BGP, BFD, DHCP, DHCPv6, LDP, and OSPF are controlled by security policies is determined by the basic protocol control switch (which can be configured using the firewall packet-filter basic-protocol enable command). To quickly access a network, you can run the undo firewall packet-filter basic-protocol enable command to disable security policy control for these protocols.
The default status of the basic protocol control switch and the controlled protocol type vary depending on the model and version of firewalls. Table 8-1 lists the default status of the basic protocol control switch on different models and versions.
Product Model |
Version |
Default Setting |
OSPF |
OSPFv3 |
BGP |
BGP4+ |
LDP |
BFD |
DHCPv4 |
DHCPv6 |
---|---|---|---|---|---|---|---|---|---|---|
USG6000E |
V600R006C00 and later versions |
Disabled in V600R006C00 and enabled in V600R007C00 and later versions. |
Y |
Y |
Y |
Y |
Y |
Y |
N |
Y |
USG6000 |
V100R001C10SPC100 and later versions |
Enabled in V100R001C10SPC100 and later versions Disabled in V100R001C30SPC700 and later versions |
Y |
Y |
Y |
Y |
Y |
Y |
Y Supported in V100R001C30SPC700 and later versions |
N |
USG6000 |
V500R001C00 and later versions |
Enabled in V500R001C00 and later versions Enabled in V500R001C20 and later versions Enabled in V500R005C20SPC300 and later versions |
Y |
Y |
Y |
Y |
Y |
Y |
N |
Y Supported in V500R001C30 and later versions |
USG9500 |
Supported only in V300R001C01SPCa00 |
Disabled |
Y |
Y |
Y |
Y |
Y |
N |
N |
Y |
USG9500 |
V500R001C00 and later versions |
Enabled in V500R001C00 and later versions Disabled in V500R001C20 and later versions Enabled in V500R005C20SPC300 and later versions |
Y |
Y |
Y |
Y |
Y |
Y Supported in V500R001C30 and later versions |
Y Supported in V500R001C30 and later versions |
Y Supported in V500R001C30 and later versions |
The basic protocol control switch setting of the NGFW Module is the same as that of the USG6000. Y indicates that the firewall packet-filter basic-protocol enable command supports the protocol, and N indicates that the firewall packet-filter basic-protocol enable command does not support the protocol. |