Configuring an isatap tunnel, Configuration prerequisites, Configuration guidelines – H3C Technologies H3C SecPath F1000-E User Manual
Page 110: Configuration procedure
98
Configuring an ISATAP tunnel
Configuration prerequisites
Configure IP addresses for interfaces (such as the VLAN interface, GigabitEthernet interface, and
loopback interface) on the firewall to ensure normal communication. One of the interfaces will be used
as the source interface of the tunnel.
Configuration guidelines
Follow these guidelines when you configure an ISATAP tunnel:
•
No destination address needs to be configured for an ISATAP tunnel. The destination address of the
tunnel can be automatically obtained through the IPv4 address embedded in the ISATAP address.
•
To encapsulate and forward IPv6 packets whose destination address does not belong to the subnet
where the receiving tunnel interface resides, configure a static route to reach the destination IPv6
address through this tunnel interface on the firewall. Because automatic tunnels do not support
dynamic routing, you can configure a static route to that destination IPv6 address with this tunnel
interface as the outbound interface or the peer tunnel interface address as the next hop. A similar
configuration needs to be performed at the other tunnel end. For the detailed configuration, see
Network Management Configuration Guide.
•
The automatic tunnel interfaces using the same encapsulation protocol cannot share the same
source IP address.
Configuration procedure
To configure an ISATAP tunnel:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable IPv6.
ipv6
By default, the IPv6 forwarding
function is disabled.
3.
Enter tunnel interface
view.
interface tunnel number N/A
4.
Configure an IPv6
address for the tunnel
interface.
•
Configure an IPv6 global unicast
address or site-local address:
{
ipv6 address { ipv6-address
prefix-length |
ipv6-address/prefix-length }
{
ipv6 address
ipv6-address/prefix-length
eui-64
•
Configure an IPv6 link-local
address:
{
ipv6 address auto link-local
{
ipv6 address ipv6-address
link-local
IPv6 link-local address configuration
is optional.
By default,
•
No IPv6 global unicast address
is configured for the tunnel
interface.
•
A link-local address will
automatically be generated
when an IPv6 global unicast
address or link-local address is
configured.
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS