< Home

firewall third-party-ids enable

Function

The firewall third-party-ids enable command enables the interworking with a third-party IDS.

The undo firewall third-party-ids enable command disables the interworking with a third-party IDS.

Format

firewall third-party-ids enable

undo firewall third-party-ids enable

Parameters

None

Views

System view

Default Level

3: Management level

Usage Guidelines

By default, the interworking between the FW and third-party IDS is disabled.

Currently, the FW can interwork with only one type of third-party IDS devices, namely, the Suricata.

The FW can interwork with a third-party IDS, which can identify malicious traffic and deliver blocking instructions to the FW so that the FW can delete existing sessions or blacklist source or destination addresses to block attacks.

For the secure transmission of interworking packets, you must directly connect the FW to the third-party IDS and must use the firewall third-party-ids trust-interface { interface-name | interface-type interface-number } command to configure trusted interfaces on the FW. The FW analyzes only interworking packets from trusted interfaces and execute corresponding instructions.

Example

# Enable the interworking between the FW and third-party IDS.

<sysname> system-view
[sysname] firewall third-party-ids enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >