Command Reference Guide

136firewall aspf 3Com Router 5000 Family and Router 6000 Family
Command Reference
firewall aspf
Purpose Use the firewall aspf command to apply ASPF policy in specified direction to an
interface.
Use the undo firewall aspf command to delete the applied ASPF policy on the
interface.
Syntax firewall aspf aspf-policy-number { inbound | outbound }
undo firewall aspf aspf-policy-number { inbound | outbound }
Parameters aspf-policy-number
ASPF policy number used on the interface.
inbound
Applies ASPF policy in inbound direction of the
interface.
outbound
Applies ASPF policy in outbound direction of the
interface.
Example Configure ASPF firewall function in outbound direction of the interface
ethernet1/0/0.
[3Com-Ethernet1/0/0] firewall aspf 1 outbound
View This command can be used in the following views:
Interface view
Description There are two concepts in ASPF: inbound interface and outbound interface. If the
router connects with both intranet and internet, and uses ASPF to protect the servers
of intranet, the router interface connected with intranet is regarded as inbound
interface and that connected with internet is regarded as outbound interface.
When ASPF is applied on outbound interface, ASPF will refuse the access of intranet
from internet users, but the returning packets of intranet users accessing internet can
pass the detection of ASPF.