Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 693
668
Figure 351 Network diagram
Device Interface
IP
address
Device
Interface
IP address
Source 1
—
10.110.5.100/24
Router B
GE0/1
192.168.1.2/24
Source 2
—
10.110.6.100/24
GE0/2
192.168.2.2/24
Router A
GE0/1
10.110.5.1/24
SecPath B
GE0/1
10.110.3.1/24
GE0/2
10.110.2.2/24
GE0/2
10.110.4.1/24
SecPath A
GE0/1
10.110.1.1/24
GE0/3
192.168.2.1/24
GE0/2
10.110.2.1/24
Loop0
2.2.2.2/32
GE0/3
192.168.1.1/24
Loop10
4.4.4.4/32
Loop0
1.1.1.1/32
Loop20
10.1.1.1/32
Loop10
3.3.3.3/32
Router C
GE0/1
10.110.6.1/24
Loop20
10.1.1.1/32
GE0/2
10.110.4.2/24
Configuration procedure
1.
Configure IP addresses and unicast routing:
Configure the IP address and subnet mask for each interface as per
shown.)
Configure OSPF on the routers and firewalls in the PIM-SM domain to make sure the network-layer
in the PIM-SM domain is interoperable and routing information among the routers and firewalls
can be dynamically updated. (Details not shown.)
2.
Enable IP multicast routing, and enable PIM-SM and IGMP:
# Enable IP multicast routing on SecPath A, enable PIM-SM on each interface, and enable IGMP
on the host-side interface GigabitEthernet 0/1.
[SecPathA] multicast routing-enable
[SecPathA] interface GigabitEthernet 0/1
[SecPathA-GigabitEthernet0/1] igmp enable
[SecPathA-GigabitEthernet0/1] pim sm
[SecPathA-GigabitEthernet0/1] quit
Loo
p0
Lo
op20
Loop2
0
Loo
p0
G
E
0
/3
G
E
0
/2
G
E
0
/1
G
E
0
/3
G
E
0
/2
G
E
0
/2
G
E
0
/2
G
E
0
/2
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS H3C SecBlade LB Cards H3C SecPath L1000-A Load Balancer