HP VPN Firewall Appliances Network Management Configuration Guide

836
Hardware Com
p
atibilit
y
F1000-A-EI/F1000-S-EI No
F1000-E No
F5000 Yes
F5000-S/F5000-C No
VPN firewall modules No
20-Gbps VPN firewall modules No
Network requirements
As shown in Figure 402, configure OSPFv3 as the IGP in AS 200.
Establish two IBGP connections between Firewall A and Firewall B. When both links are working,
Firewall B adopts the link Firewall A<—>Router A<—>Firewall B to exchange packets with network
1200::0/64. Configure BFD over the link. Then if the link fails, BFD can quickly detect the failure
and notify it to IPv6 BGP. Then the link Firewall A<—>Router B<—>Firewall B takes effect
immediately.
Figure 402 Network diagram
Configuration procedure
1. Configure IP addresses for interfaces. (Details not shown.)
2. Configure OSPFv3 to make sure that Firewall A and Firewall B are reachable to each other.
(Details not shown.)
3. Configure IPv6 BGP on Firewall A:
# Establish two IBGP connections between Firewall A and Firewall B.
<FirewallA> system-view
[FirewallA] bgp 200
[FirewallA-bgp] ipv6-family
[FirewallA-bgp-af-ipv6] peer 3002::2 as-number 200
[FirewallA-bgp-af-ipv6] peer 2002::2 as-number 200
[FirewallA-bgp-af-ipv6] quit