beautypg.com

Configuring an isatap tunnel, Configuration prerequisites, Configuration guidelines – H3C Technologies H3C SecPath F1000-E User Manual

Page 110: Configuration procedure

background image

98

Configuring an ISATAP tunnel

Configuration prerequisites

Configure IP addresses for interfaces (such as the VLAN interface, GigabitEthernet interface, and

loopback interface) on the firewall to ensure normal communication. One of the interfaces will be used
as the source interface of the tunnel.

Configuration guidelines

Follow these guidelines when you configure an ISATAP tunnel:

No destination address needs to be configured for an ISATAP tunnel. The destination address of the
tunnel can be automatically obtained through the IPv4 address embedded in the ISATAP address.

To encapsulate and forward IPv6 packets whose destination address does not belong to the subnet
where the receiving tunnel interface resides, configure a static route to reach the destination IPv6

address through this tunnel interface on the firewall. Because automatic tunnels do not support

dynamic routing, you can configure a static route to that destination IPv6 address with this tunnel

interface as the outbound interface or the peer tunnel interface address as the next hop. A similar
configuration needs to be performed at the other tunnel end. For the detailed configuration, see

Network Management Configuration Guide.

The automatic tunnel interfaces using the same encapsulation protocol cannot share the same
source IP address.

Configuration procedure

To configure an ISATAP tunnel:

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Enable IPv6.

ipv6

By default, the IPv6 forwarding
function is disabled.

3.

Enter tunnel interface
view.

interface tunnel number N/A

4.

Configure an IPv6
address for the tunnel

interface.

Configure an IPv6 global unicast

address or site-local address:

{

ipv6 address { ipv6-address

prefix-length |

ipv6-address/prefix-length }

{

ipv6 address

ipv6-address/prefix-length

eui-64

Configure an IPv6 link-local

address:

{

ipv6 address auto link-local

{

ipv6 address ipv6-address
link-local

IPv6 link-local address configuration
is optional.
By default,

No IPv6 global unicast address

is configured for the tunnel
interface.

A link-local address will

automatically be generated
when an IPv6 global unicast

address or link-local address is

configured.