Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 863
838
Figure 396 Network diagram
Configuration procedure
NOTE:
In this example, RIPng is configured to ensure the reachability among devices.
1.
Configure SecPath A:
# Configure RIPng.
[SecPathA] ipv6
[SecPathA] ripng 1
[SecPathA-ripng-1] quit
[SecPathA] interface GigabitEthernet0/3
[SecPathA-GigabitEthernet0/3] ipv6 address 1::1 64
[SecPathA-GigabitEthernet0/3] ripng 1 enable
[SecPathA-GigabitEthernet0/3] quit
[SecPathA] interface GigabitEthernet 0/2
[SecPathA-GigabitEthernet0/2] ipv6 address 2::1 64
[SecPathA-GigabitEthernet0/2] ripng 1 enable
[SecPathA-GigabitEthernet0/2] quit
# Define ACL 3001 to match TCP packets.
[SecPathA] acl ipv6 number 3001
[SecPathA-acl6-adv-3001] rule permit tcp
[SecPathA-acl6-adv-3001] quit
# Define Node 5 of policy aaa, so that TCP packets are forwarded via GigabitEthernet 0/3.
[SecPathA] ipv6 policy-based-route aaa permit node 5
[SecPathA-pbr6-aaa-5] if-match acl6 3001
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS H3C SecBlade LB Cards H3C SecPath L1000-A Load Balancer