
Configuring BaySecure FireWall-1
3-2
117384-D Rev 00
You can also use the Technician Interface, which lets you modify parameters by
issuing
set and commit commands that specify the MIB object ID. This process
is equivalent to modifying parameters using the BCC. For more information about
using the Technician Interface to access the MIB, see Using Technician Interface
Software.
Beginning at the top-level BCC box prompt, enter:
ip
The IP global prompt appears.
To create a base firewall configuration on the router, enter:
firewall primary-log-host <
IP_address
> local-host <
IP_address
>
The primary log host address is the IP address of the primary firewall management
station. The local host address is the IP address of the router to be protected by the
firewall.
By default, the firewall is enabled on the router; however, the firewall cannot
function unless you have followed the proper licensing sequence. (For information
on the firewall licensing procedure, see Chapter 2.) To disable or reenable the
firewall on the router, see “D
isabling and Reenabling a Firewall on a Router” on
page 3-3
.
For example, the following command sequence invokes the IP global prompt and
creates a base firewall configuration:
box# ip
ip# firewall primary-log-host 1.1.1.1 local-host 2.2.2.2
firewall#
Caution:
The Technician Interface does not verify that the value you enter for
a parameter is valid. Entering an invalid value can corrupt your configuration.
Comentários a estes Manuais