HP VPN Firewall Appliances Network Management Configuration Guide

344
Figure 243 Network diagram
Device Interface IP address
Device
Interface
IP address
Firewall A GE1/1 12.1.1.1/24 Firewall B GE1/1 11.1.1.2/24
GE1/2 10.1.1.102/24
GE1/2
13.1.1.1/24
Loop1 1.1.1.9/32
Loop1
2.2.2.9/32
Router A GE1/1 10.1.1.100/24 Router B GE1/1 12.1.1.2/24
GE1/2 13.1.1.2/24
GE1/2
11.1.1.1/24
Configuration procedure
1. Configure IP addresses for interfaces. (Details not shown.)
2. Configure static routes and BFD:
# Configure static routes on Firewall A and enable BFD control mode for the static route that
traverses Router B.
<FirewallA> system-view
[FirewallA] interface loopback 1
[FirewallA -LoopBack1] bfd min-transmit-interval 500
[FirewallA -LoopBack1] bfd min-receive-interval 500
[FirewallA -LoopBack1] bfd detect-multiplier 9
[FirewallA -LoopBack1] quit
[FirewallA] ip route-static 120.1.1.0 24 2.2.2.9 bfd control-packet bfd-source
1.1.1.9
[FirewallA] ip route-static 120.1.1.0 24 gigabitethernet 1/2 10.1.1.100 preference
65
[FirewallA] quit
# Configure static routes on Firewall B and enable BFD control mode for the static route that
traverses Router B.
<FirewallB> system-view
[FirewallB] interface loopback 1
[FirewallB -LoopBack1] bfd min-transmit-interval 500
[FirewallB -LoopBack1] bfd min-receive-interval 500
[FirewallB -LoopBack1] bfd detect-multiplier 9
[FirewallB -LoopBack1] quit
[FirewallB] ip route-static 121.1.1.0 24 1.1.1.9 bfd control-packet bfd-source
2.2.2.9
[FirewallB] ip route-static 121.1.1.0 24 gigabitethernet 1/2 13.1.1.2 preference 65
[FirewallB] quit