Network requirements, Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 768
22
Configuration Example for P2MP GRE Tunnel Backup at a
Branch
Network requirements
As shown in
, a branch uses two gateways at the egress of the internal network, with Device C
for backup. A P2MP GRE tunnel template is created on Device A, the gateway at the headquarters,
allowing Device A to establish two GRE tunnels to the branch network, one for connecting Device B and
the other for connecting Device C. Device A decides which GRE tunnel to use to send packets to the hosts
on the branch network.
To meet the above requirements, you need to configure different GRE keys for the GRE tunnels on Device
B and Device C, so that Device A can choose a tunnel according to the GRE key values.
In this example, the GRE tunnel between Device A and Device B has a higher priority.
Figure 40 Network diagram for P2MP GRE tunnel backup at a branch
GE0/1
GE0/1
Device B
Device C
(Backup gateway)
IPv4 network
Device A
GE0/1
GE0/2
Tunnel0
Tunnel0
Tunnel0
Host B
Host A
GE0/2
GE0/2
Headquarters
Branch
GRE P2MP tunnel
Device
Interface
IP address
Device
Interface
IP address
Device A
GE0/1
11.1.1.1/24
Device B
GE0/1
11.1.1.2/24
GE0/2
172.17.17.1/24
GE0/2
192.168.1.2/24
Tunnel0
192.168.22.1/24
Tunnel0
192.168.22.2/24
Device C
GE0/1
11.1.1.3/24
Device C
Tunnel0
192.168.22.3/24
GE0/2
192.168.1.3/24
Configuration procedure
Step1
Configure Device A
# Configure an IPv4 address for each interface and assign the interfaces to security zones (omitted).
# Create a P2MP GRE tunnel interface.
•
Select VPN > GRE > P2MP from the navigation tree and then click Add to perform the
configurations shown in
.