Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 684
659
Figure 349 Network diagram
Device
Interface
IP address
Device
Interface IP
address
Router A
GE0/1
10.110.1.2/24
Router B
GE0/1
10.110.4.2/24
GE0/2
10.110.2.1/24
GE0/2 10.110.5.1/24
GE0/3
10.110.3.1/24
SecPath C
GE0/1 10.110.6.1/24
SecPath A
GE0/1
10.110.1.1/24
GE0/2
192.168.3.2/24
GE0/2
192.168.1.1/24
Loop0 3.3.3.3/32
Loop0
1.1.1.1/32
Router C
GE0/1 10.110.6.2/24
SecPath B
GE0/1
10.110.4.1/24
GE0/2
10.110.7.1/24
GE0/2
192.168.3.1/24 Source 1
—
10.110.2.100/24
GE0/3
192.168.1.2/24 Source 2
—
10.110.5.100/24
Loop0
2.2.2.2/32
Configuration procedure
1.
Configure IP addresses and unicast routing:
Configure the IP address and subnet mask for each interface as per
shown.)
Configure OSPF on routers and firewalls in each AS to make sure the network-layer in each AS is
interoperable and routing information among the routers and firewalls can be dynamically
updated. (Details not shown.)
2.
Enable IP multicast routing, enable PIM-SM and IGMP, and configure a PIM-SM domain border:
# Enable IP multicast routing on Router A, enable PIM-SM on each interface, and enable IGMP on
the host-side interface GigabitEthernet 0/3.
[RouterA] multicast routing-enable
[RouterA] interface GigabitEthernet 0/1
[RouterA-GigabitEthernet0/1] pim sm
[RouterA-GigabitEthernet0/1] quit
GE0/1
G
E0/1
GE0/3
GE0/2
GE0/2
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS H3C SecBlade LB Cards H3C SecPath L1000-A Load Balancer