H3C Technologies H3C SecPath F1000-E User Manual
Page 900
875
Enable IPv6 forwarding on each router and firewall, and configure the IPv6 address and prefix
length for each interface as per
. (Details not shown.)
Configure OSPFv3 on the routers and firewalls in the IPv6 PIM-SM domain to make sure the
network-layer on the IPv6 PIM-SM network is interoperable and the routing information among the
routers and firewalls can be dynamically updated. (Details not shown.)
2.
Enable IPv6 multicast routing, and enable IPv6 PIM-SM and MLD:
# Enable IPv6 multicast routing on SecPath A, enable IPv6 PIM-SM on each interface, and enable
MLD on GigabitEthernet 0/1, which connects SecPath A to N1.
[SecPathA] multicast ipv6 routing-enable
[SecPathA] interface GigabitEthernet 0/1
[SecPathA-GigabitEthernet0/1] mld enable
[SecPathA-GigabitEthernet0/1] pim ipv6 sm
[SecPathA-GigabitEthernet0/1] quit
[SecPathA] interface GigabitEthernet 0/2
[SecPathA-GigabitEthernet0/2] pim ipv6 sm
[SecPathA-GigabitEthernet0/2] quit
[SecPathA] interface GigabitEthernet 0/3
[SecPathA-GigabitEthernet0/2] pim ipv6 sm
[SecPathA-GigabitEthernet0/2] quit
The configuration on Router A and Router B is similar to that on SecPath A. The configuration on
SecPath B and SecPath C is also similar to that on SecPath A except that it is not necessary to
enable MLD on the corresponding interfaces on these two routers.
3.
Configure C-BSRs and C-RPs:
# On SecPath B, configure the service scope of RP advertisements, specify a C-BSR and a C-RP,
and set the hash mask length to 128 and the priority of the C-BSR to 10.
[SecPathB] acl ipv6 number 2005
[SecPathB-acl6-basic-2005] rule permit source ff0e::101 64
[SecPathB-acl6-basic-2005] quit
[SecPathB] pim ipv6
[SecPathB-pim6] c-bsr 4002::1 128 10
[SecPathB-pim6] c-rp 4002::1 group-policy 2005
[SecPathB-pim6] quit
# On SecPath C, configure the service scope of RP advertisements, specify a C-BSR and a C-RP,
and set the hash mask length to 128 and the priority of the C-BSR to 20.
[SecPathC] acl ipv6 number 2005
[SecPathC-acl6-basic-2005] rule permit source ff0e::101 64
[SecPathC-acl6-basic-2005] quit
[SecPathC] pim ipv6
[SecPathC-pim6] c-bsr 1003::2 128 20
[SecPathC-pim6] c-rp 1003::2 group-policy 2005
[SecPathC-pim6] quit
4.
Verify the configuration:
Use the display pim ipv6 interface command to display IPv6 PIM information on each interface of
firewalls. For example:
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS H3C SecBlade LB Cards H3C SecPath L1000-A Load Balancer