Troubleshooting Flowchart
shows the troubleshooting flowchart.
Figure 10-13
Troubleshooting flowchart for a packet filtering firewall failure
Packet filtering
firewall is invalid
Seek technical
support
End
Is referenced
ACL correct?
Modify ACL rules
Is the fault
rectified?
No
No
Yes
Yes
Troubleshooting Procedure
NOTE
Saving the results of each troubleshooting step is recommended. If troubleshooting fails to correct the fault,
you will have a record of your actions to provide Huawei technical support personnel.
Procedure
Step 1
Check that the ACL referenced by the packet filtering firewall is configured correctly.
Run the
display firewall interzone
command to view the referenced ACL number and direction
in which the ACL is applied. Multiple ACLs may exist on the firewall. Ensure that the correct
ACL is referenced.
l
If the ACL number or direction is incorrect, run the
undo packet-filter
{
acl-number
|
default
{
deny
|
permit
}} {
inbound
|
outbound
} command in the interzone view to disable
packet filtering. Then run the
packet-filter
{
acl-number
|
default
{
deny
|
permit
}}
{
inbound
|
outbound
} command to reconfigure the packet filtering function.
l
If the ACL number and direction are correct, run the
display acl
command to check the
configuration of ACL rules. If the ACL rules are incorrect, modify them. If the ACL rules
are correct, go to 2.
Step 2
Collect the following information and contact Huawei technical support personnel:
l
Results of the preceding troubleshooting procedure
l
Configuration files, log files, and alarm files of the switches
----End
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
308