Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual

Page 863

Advertising
background image

838

Figure 396 Network diagram

Configuration procedure

NOTE:

In this example, RIPng is configured to ensure the reachability among devices.

1.

Configure SecPath A:
# Configure RIPng.

<SecPathA> system-view

[SecPathA] ipv6

[SecPathA] ripng 1

[SecPathA-ripng-1] quit

[SecPathA] interface GigabitEthernet0/3

[SecPathA-GigabitEthernet0/3] ipv6 address 1::1 64

[SecPathA-GigabitEthernet0/3] ripng 1 enable

[SecPathA-GigabitEthernet0/3] quit

[SecPathA] interface GigabitEthernet 0/2

[SecPathA-GigabitEthernet0/2] ipv6 address 2::1 64

[SecPathA-GigabitEthernet0/2] ripng 1 enable

[SecPathA-GigabitEthernet0/2] quit

# Define ACL 3001 to match TCP packets.

[SecPathA] acl ipv6 number 3001

[SecPathA-acl6-adv-3001] rule permit tcp

[SecPathA-acl6-adv-3001] quit

# Define Node 5 of policy aaa, so that TCP packets are forwarded via GigabitEthernet 0/3.

[SecPathA] ipv6 policy-based-route aaa permit node 5

[SecPathA-pbr6-aaa-5] if-match acl6 3001

Advertising