Brocade Communications Systems 5600 vRouter Manuel utilisateur

53-1003710-03
14 September 2015
Brocade 5600 vRouter
Firewall
Reference Guide
Supporting Brocade 5600 vRouter 3.5R6

© 2015, Brocade Communications Systems, Inc. All Rights Reserved.
ADX, Brocade, Brocade Assurance, the B-wing symbol, DCX, Fabric OS, HyperEdge, ICX, MLX, MyBrocade, OpenScript, The Effortless
Network, VCS, VDX, Vplane, and Vyatta are registered trademarks, and Fabric Vision and vADX are trademarks of Brocade
Communications Systems, Inc., in the United States and/or in other countries. Other brands, products, or service names mentioned may be
trademarks of others.
Notice: This document is for informational purposes only and does not set forth any warranty, expressed or implied, concerning any
equipment, equipment feature, or service offered or to be offered by Brocade. Brocade reserves the right to make changes to this document
at any time, without notice, and assumes no responsibility for its use. This informational document describes features that may not be
currently available. Contact a Brocade sales office for information on feature and product availability. Export of technical data contained in
this document may require an export license from the United States government.
The authors and Brocade Communications Systems, Inc. assume no liability or responsibility to any person or entity with respect to the
accuracy of this document or any loss, cost, liability, or damages arising from the information contained herein or the computer programs that
accompany it.
The product described by this document may contain open source software covered by the GNU General Public License or other open
source license agreements. To find out which open source software is included in Brocade products, view the licensing terms applicable to
the open source software, and obtain a copy of the programming source code, please visit http://www.brocade.com/support/oscd.

Contents
Preface.....................................................................................................................................7
Document conventions......................................................................................7
Text formatting conventions.................................................................. 7
Command syntax conventions.............................................................. 7
Notes, cautions, and warnings.............................................................. 8
Brocade resources............................................................................................ 9
Contacting Brocade Technical Support.............................................................9
Document feedback........................................................................................ 10
About This Guide.....................................................................................................................11
Firewall Overview.................................................................................................................... 13
Brocade firewall functionality...........................................................................13
Firewall and fragmented packets........................................................ 13
Defining firewall instances...............................................................................14
Firewall rules....................................................................................... 14
Implicit drop.........................................................................................14
Exclusion rules.................................................................................... 14
Stateful firewall and connection tracking.........................................................15
TCP strict tracking...........................................................................................15
Applying firewall instances to interfaces......................................................... 16
Interaction between firewall, NAT, and routing............................................... 16
Traffic flow through firewall, NAT, and routing.................................... 16
Zone-based firewall.........................................................................................17
Configuration Examples.......................................................................................................... 19
Packet-filtering................................................................................................ 19
Filtering on source IP address............................................................ 20
Filtering on source and destination IP addresses............................... 20
Filtering on source IP address and destination protocol..................... 21
Defining a network-to-network filter.....................................................22
Filtering on source MAC address........................................................23
Excluding an address..........................................................................24
Matching TCP flags.............................................................................25
Matching ICMP type names................................................................ 25
Matching groups..................................................................................26
Stateful behavior............................................................................................. 27
Configuring stateful behavior per rule set........................................... 27
Configuring global state policies......................................................... 28
Zone-based firewall.........................................................................................28
Filtering traffic between zones............................................................ 29
Filtering traffic between the transit zones............................................30
Using firewall with VRRP interfaces................................................................32
Applying a rule set to a VRRP interface..............................................32
Using VRRP with a zone-based firewall..............................................33
Viewing firewall information.............................................................................34
Showing firewall instance information................................................. 34
Brocade 5600 vRouter Firewall Reference Guide 3
53-1003710-03

Showing firewall configuration on interfaces.....................................34
Showing firewall configuration...........................................................34
Global Firewall Commands....................................................................................................37
clear firewall.................................................................................................. 38
security firewall..............................................................................................39
show security firewall <interface>................................................................. 40
Firewall Commands.............................................................................................................. 41
security firewall all-ping <state>....................................................................42
security firewall broadcast-ping <state>........................................................43
security firewall config-trap <state>...............................................................44
security firewall global-state-policy <protocol>............................................. 45
security firewall name <name>..................................................................... 46
security firewall name <name> default-action <action>................................47
security firewall name <name> default-log <action>.....................................48
security firewall name <name> description <description>............................ 49
security firewall name <name> rule <rule-number>......................................50
security firewall name <name> rule <rule-number> action <action>............ 51
security firewall name <name> rule <rule-number> description
<description>...........................................................................................52
security firewall name <name> rule <rule-number> destination
<destination>...........................................................................................53
security firewall name <name> rule <rule-number> disable......................... 55
security firewall name <name> rule <rule-number> dscp <value>............... 56
security firewall name <name> rule <rule-number> ethertype <type>..........57
security firewall name <name> rule <rule-number> fragment...................... 58
security firewall name <name> rule <rule-number> icmp............................. 59
security firewall name <name> rule <rule-number> icmpv6......................... 60
security firewall name <name> rule <rule-number> ipv6-route type
<number>................................................................................................ 61
security firewall name <name> rule <rule-number> log................................62
security firewall name <name> rule <rule-number> mark <action>..............63
security firewall name <name> rule <rule-number> pcp <number>............. 64
security firewall name <name> rule <rule-number> police <limiting-
method>.................................................................................................. 65
security firewall name <name> rule <rule-number> protocol........................67
security firewall name <name> rule <rule-number> source <source>..........68
security firewall name <name> rule <rule-number> state <state>................70
security firewall name <name> rule <rule-number> tcp flags <flags>.......... 71
security firewall session-log <protocol>........................................................ 72
security firewall tcp-strict...............................................................................74
interfaces <interface> firewall <state>.......................................................... 75
Related commands....................................................................................... 76
Zone-Based Firewall Commands........................................................................................... 77
clear zone-policy........................................................................................... 78
show zone-policy...........................................................................................79
security zone-policy zone <zone>.................................................................80
security zone-policy zone <zone> default-action <action>........................... 81
security zone-policy zone <zone> description <description>........................82
security zone-policy zone <from-zone> to <to-zone>................................... 83
security zone-policy zone <from-zone> to <to-zone> firewall <name>.........84
security zone-policy zone <zone> interface <interface-name>.....................85
4Brocade 5600 vRouter Firewall Reference Guide
53-1003710-03

ICMP Types.............................................................................................................................87
ICMPv6 Types......................................................................................................................... 89
List of Acronyms......................................................................................................................93
Brocade 5600 vRouter Firewall Reference Guide 5
53-1003710-03

6 Brocade 5600 vRouter Firewall Reference Guide
53-1003710-03

Preface
● Document conventions......................................................................................................7
● Brocade resources............................................................................................................ 9
● Contacting Brocade Technical Support.............................................................................9
● Document feedback........................................................................................................ 10
Document conventions
The document conventions describe text formatting conventions, command syntax conventions, and
important notice formats used in Brocade technical documentation.
Text formatting conventions
Text formatting conventions such as boldface, italic, or Courier font may be used in the flow of the text
to highlight specific words or phrases.
Format Description
bold text Identifies command names
Identifies keywords and operands
Identifies the names of user-manipulated GUI elements
Identifies text to enter at the GUI
italic text Identifies emphasis
Identifies variables
Identifies document titles
Courier font Identifies CLI output
Identifies command syntax examples
Command syntax conventions
Bold and italic text identify command syntax components. Delimiters and operators define groupings of
parameters and their logical relationships.
Convention Description
bold text Identifies command names, keywords, and command options.
italic text Identifies a variable.
value In Fibre Channel products, a fixed value provided as input to a command
option is printed in plain text, for example, --show WWN.
Brocade 5600 vRouter Firewall Reference Guide 7
53-1003710-03

Convention Description
[ ] Syntax components displayed within square brackets are optional.
Default responses to system prompts are enclosed in square brackets.
{ x | y | z } A choice of required parameters is enclosed in curly brackets separated by
vertical bars. You must select one of the options.
In Fibre Channel products, square brackets may be used instead for this
purpose.
x | yA vertical bar separates mutually exclusive elements.
< > Nonprinting characters, for example, passwords, are enclosed in angle
brackets.
... Repeat the previous element, for example, member[member...].
\Indicates a “soft” line break in command examples. If a backslash separates
two lines of a command input, enter the entire command at the prompt without
the backslash.
Notes, cautions, and warnings
Notes, cautions, and warning statements may be used in this document. They are listed in the order of
increasing severity of potential hazards.
NOTE
A Note provides a tip, guidance, or advice, emphasizes important information, or provides a reference
to related information.
ATTENTION
An Attention statement indicates a stronger note, for example, to alert you when traffic might be
interrupted or the device might reboot.
CAUTION
A Caution statement alerts you to situations that can be potentially hazardous to you or cause
damage to hardware, firmware, software, or data.
DANGER
A Danger statement indicates conditions or situations that can be potentially lethal or
extremely hazardous to you. Safety labels are also attached directly to products to warn of
these conditions or situations.
Notes, cautions, and warnings
8 Brocade 5600 vRouter Firewall Reference Guide
53-1003710-03

Brocade resources
Visit the Brocade website to locate related documentation for your product and additional Brocade
resources.
You can download additional publications supporting your product at www.brocade.com. Select the
Brocade Products tab to locate your product, then click the Brocade product name or image to open the
individual product page. The user manuals are available in the resources module at the bottom of the
page under the Documentation category.
To get up-to-the-minute information on Brocade products and resources, go to MyBrocade. You can
register at no cost to obtain a user ID and password.
Release notes are available on MyBrocade under Product Downloads.
White papers, online demonstrations, and data sheets are available through the Brocade website.
Contacting Brocade Technical Support
As a Brocade customer, you can contact Brocade Technical Support 24x7 online, by telephone, or by e-
mail. Brocade OEM customers contact their OEM/Solutions provider.
Brocade customers
For product support information and the latest information on contacting the Technical Assistance
Center, go to http://www.brocade.com/services-support/index.html.
If you have purchased Brocade product support directly from Brocade, use one of the following methods
to contact the Brocade Technical Assistance Center 24x7.
Online Telephone E-mail
Preferred method of contact for non-
urgent issues:
•My Cases through MyBrocade
•Software downloads and licensing
tools
•Knowledge Base
Required for Sev 1-Critical and Sev
2-High issues:
• Continental US: 1-800-752-8061
• Europe, Middle East, Africa, and
Asia Pacific: +800-AT FIBREE
(+800 28 34 27 33)
• For areas unable to access toll
free number: +1-408-333-6061
•Toll-free numbers are available in
many countries.
Please include:
• Problem summary
• Serial number
• Installation details
• Environment description
Brocade OEM customers
If you have purchased Brocade product support from a Brocade OEM/Solution Provider, contact your
OEM/Solution Provider for all of your product support needs.
• OEM/Solution Providers are trained and certified by Brocade to support Brocade® products.
• Brocade provides backline support for issues that cannot be resolved by the OEM/Solution Provider.
Brocade resources
Brocade 5600 vRouter Firewall Reference Guide 9
53-1003710-03

• Brocade Supplemental Support augments your existing OEM support contract, providing direct
access to Brocade expertise. For more information, contact Brocade or your OEM.
• For questions regarding service levels and response times, contact your OEM/Solution Provider.
Document feedback
To send feedback and report errors in the documentation you can use the feedback form posted with
the document or you can e-mail the documentation team.
Quality is our first concern at Brocade and we have made every effort to ensure the accuracy and
completeness of this document. However, if you find an error or an omission, or you think that a topic
needs further development, we want to hear from you. You can provide feedback in two ways:
• Through the online feedback form in the HTML documents posted on www.brocade.com.
• By sending your feedback to [email protected].
Provide the publication title, part number, and as much detail as possible, including the topic heading
and page number if applicable, as well as your suggestions for improvement.
Document feedback
10 Brocade 5600 vRouter Firewall Reference Guide
53-1003710-03
Autres manuels pour 5600 vRouter
8
Table des matières

















