beautypg.com

Verifying the configuration – H3C Technologies H3C SecPath F1000-E User Manual

Page 85

background image

73

NOTE:

Configuring the 4to6 AFT policy for source address translation is optional. If the policy is not configured,
AFT uses the first configured DNS64 prefix to translate the source IPv4 address into an IPv6 address.

2.

Configure SecPath A:
# Enable IPv6.

system-view

[SecPathA] ipv6

# Configure an IPv6 address for interface GigabitEthernet 0/1.

[SecPathA] interface GigabitEthernet 0/1

[SecPathA-GigabitEthernet0/1] ipv6 address 6:0:ff06:606:200::/64

[SecPathA-GigabitEthernet0/1] quit

# Configure a static route to IPv6 network 2000::/32 (the DNS64 prefix).

[SecPathA] ipv6 route-static 2000:: 32 6:0:ff06:606:100::

3.

Configure SecPath C:
# Configure an IP address for interface GigabitEthernet 0/1.

system-view

[SecPathC] interface GigabitEthernet 0/1

[SecPathC-GigabitEthernet0/1] ip address 4.4.4.2 24

[SecPathC-GigabitEthernet0/1] quit

# Configure a static route to the IPv4 network (6.6.6.0/24) embedded in the IVI address.

[SecPathC] ip route-static 6.6.6.0 24 4.4.4.1

Verifying the configuration

Execute the ping 6.6.6.2 command on SecPath C. The ping operation should be successful.
# Execute the display session table verbose command on SecPath B to display the established sessions.

[SecPathB] display session table verbose

Initiator:

Source IP/Port : 4.4.4.2/2048

Dest IP/Port : 6.6.6.2/1

VPN-Instance/VLAN ID/VLL ID:

Responder:

Source IP/Port : 0006:0:ff06:0606:0200::/33024

Dest IP/Port : 2000:0:0404:0402::/1

VPN-Instance/VLAN ID/VLL ID:

Pro: ICMP(1) App: unknown State: ICMP-CLOSED

Start time: 2010-12-21 16:27:00 TTL: 23s

Root Zone(in): Management

Zone(out):

Received packet(s)(Init): 5 packet(s) 420 byte(s)

Received packet(s)(Reply): 5 packet(s) 520 byte(s)

Total find: 1