381
URL parameter filtering configuration example
Network requirements
The hosts in the network segment 192.168.1.0/24 access the Internet through the router. The router is
enabled with the URL parameter filtering function, which uses the user-defined filtering entry
group
to
filter web requests.
Figure 130
Network diagram for URL parameter filtering configuration
Configuration procedure
# Configure IP addresses for the interfaces. (Omitted)
# Configure the NAT policy for the outbound interface.
<Router> system-view
[Router] acl number 2200
[Router-acl-basic-2200] rule 0 permit source 192.168.1.0 0.0.0.255
[Router-acl-basic-2200] rule 1 deny source any
[Router-acl-basic-2200] quit
[Router] nat address-group 1 2.2.2.10 2.2.2.11
[Router] interface gigabitethernet 1/0/1
[Router-GigabitEthernet1/0/1] nat outbound 2200 address-group 1
[Router-GigabitEthernet1/0/1] quit
# Enable the URL parameter filtering function, and add URL parameter filtering entry
group
.
[Router] firewall http url-filter parameter enable
[Router] firewall http url-filter parameter keywords group
Use
display firewall http url-filter parameter verbose
to display detailed URL parameter filtering
information.
[Router] display firewall http url-filter parameter verbose
URL-filter parameter is enabled.
There are 1 packet(s) being filtered.
There are 2 packet(s) being passed.
Use
display firewall http url-filter parameter all
to display URL parameter filtering information about all
filtering entries.
[Router] display firewall http url-filter parameter all
SN Match-Times Keywords
------------------------------------
1 1 group