Read limitations and precautions before configuring security policy.
The security policy function is supported by all models.
The security policy function is not license-controlled.
All models except USG6680E and USG6712E/6716E support the MAC address.
The MAC address configured in the policy relies on the across-Layer-3 MAC identification function or the firewall ARP entries are learned.
When the FW has only one interface to receive mirroring traffic or has multiple interfaces to receive mirroring traffic but applies the same security policy to the traffic, you can add the interface or interfaces to any security zone and set the source and destination security zones to any.
When the FW has multiple interfaces to receive mirroring traffic and applies different security policies to the interfaces, you must add the interfaces to different security zones and set the source and destination security zones of each security policy to the security zone where the corresponding interface resides.
The policy backup-based acceleration function is disabled by default , except for the USG6680E and USG6712E/6716E.
Only the USG6000E (not including USG6680E and USG6712E/6716E ) supports the configuration of policy backup-based acceleration on the web UI. In addition, you can configure this function on the web UI only after this function is enabled or the number of configured policies reaches 100.
The FW rapidly matches policies by querying indexes. If a policy is created, modified, or deleted, its index is re-created. The FW uses the policy acceleration or policy backup-based acceleration function to generate indexes.
Wildcard characters in domain names can only be asterisks (*). In addition, a domain name can contain only one asterisk and must start with it. A domain name supports two to four periods (.) that cannot be consecutive and cannot end with a period. That is, the format must be *.X.X, *.X.X.X, or *.X.X.X.X.
DNS request and response packets must pass through the FW. Otherwise, the FW cannot learn the mappings between domain names and IP addresses.
The application association configuration is checked only when a single application is referenced in a security policy. If the security policy references an application group, category, or sub-category, the application association configuration will not be checked.
For application and relating application information, see isecurity.huawei.com. When you download the SA signature database, you can download the signature
database description file (for example, SA-SDB_Classified Application Protocol ID_2.0.xls) to understand the relationship between the application and relating application.