3Com Switch 8800 Family Firewall Module Configuration and Command Reference Guide

108 CHAPTER 7: FIREWALL CONFIGURATION
Network diagram
Figure 20 Network diagram for ASPF configuration
Configuration procedure
1 For the PC, the IP address and gateway address 10.0.0.1/24 are 10.0.0.254 and
respectively.
For the server host, the IP address is 202.0.0.1.
2 Switch 8807 (SecBlade)
# Divide VLANs.
<SW8800> system-view
[SW8800] vlan 10
[3Com-vlan10] quit
[SW8800] vlan 30
[3Com-vlan30] quit
[SW8800] vlan 50
[3Com-vlan50] quit
# Configure the IP address.
[SW8800] interface vlan-interface 10
[3Com-Vlan-interface10] ip address 10.0.0.254 24
[3Com-Vlan-interface10] quit
[SW8800] interface vlan-interface 30
[3Com-Vlan-interface30] ip address 30.0.0.1 24
[3Com-Vlan-interface30] quit
# Configure the static route.
[SW8800] ip route-static 0.0.0.0 0 30.0.0.254
# Configure aggregation of module interfaces (the module card resides in slot 2).
[SW8800] secblade aggregation slot 2
SecBlade
S8505
Vlan
30
Vlan10
Router
Vlan
50
Vlan
50
Trust Zone
Untrust
Zone
50.0.0.1/24
PC 10.0.0.1/24
30.0.0.254/24
50.0.0.254/24
30.0.0.1/24
10.0.0.254/24
Server Host
202.0.0.1
SecBlade
S8800
Vlan
30
Vlan10
Router
Vlan
50
Vlan
50
Trust Zone
Untrust
Zone
50.0.0.1/24
PC 10.0.0.1/24
30.0.0.254/24
50.0.0.254/24
30.0.0.1/24
10.0.0.254/24
Server Host
202.0.0.1