Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 595
570
Figure 321 Network diagram
Configuration procedure
1.
Configure IP addresses and unicast routing:
Configure the IP address and subnet mask for each interface as per
shown.)
Enable OSPF on the firewalls in the PIM-DM domain to make sure the network-layer on the PIM-DM
network is interoperable and the routing information among the firewalls can be dynamically
updated. (Details not shown.)
2.
Enable IP multicast routing, and enable PIM-DM and IGMP:
# Enable IP multicast routing on SecPath B, enable PIM-DM on each interface, and enable IGMP
on GigabitEthernet 0/1.
[SecPathB] multicast routing-enable
[SecPathB] interface GigabitEthernet 0/1
[SecPathB-GigabitEthernet0/1] igmp enable
[SecPathB-GigabitEthernet0/1] pim dm
[SecPathB-GigabitEthernet0/1] quit
[SecPathB] interface GigabitEthernet 0/2
[SecPathB-GigabitEthernet0/2] pim dm
[SecPathB-GigabitEthernet0/2] quit
[SecPathB] interface GigabitEthernet 0/3
[SecPathB-GigabitEthernet0/3] pim dm
[SecPathB-GigabitEthernet0/3] quit
# Enable IP multicast routing on SecPath A, and enable PIM-DM on each interface.
[SecPathA] multicast routing-enable
[SecPathA] interface GigabitEthernet 0/1
[SecPathA-GigabitEthernet0/1] pim dm
Multicast static route
SecPath A
SecPath B
SecPath C
GE0/3
30.1.1.2/24
GE0/2
40.1.1.2/24
GE0/1
50.1.1.1/24
GE0/2
40.1.1.1/24
GE0/1
20.1.1.2/24
GE0/2
20.1.1.1/24
GE0/3
30.1.1.1/24
GE0/1
10.1.1.1/24
Source
Receiver
50.1.1.100/24
10.1.1.100/24
PIM-DM
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS H3C SecBlade LB Cards H3C SecPath L1000-A Load Balancer