F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices Network Management Configuration Guide-6PW100
460
ISIS(1) IPv4 Level-1 Forwarding Table
-------------------------------------
IPV4 Destination IntCost ExtCost ExitInterface NextHop Flags
--------------------------------------------------------------------------
10.1.1.0/24 10 NULL GE1/1 Direct D/L/-
10.1.2.0/24 10 NULL GE1/3 Direct D/L/-
192.168.0.0/24 10 NULL GE1/2 Direct D/L/-
Flags: D-Direct, R-Added to RM, L-Advertised in LSPs, U-Up/Down Bit Set
ISIS(1) IPv4 Level-2 Forwarding Table
-------------------------------------
IPV4 Destination IntCost ExtCost ExitInterface NextHop Flags
--------------------------------------------------------------------------
10.1.1.0/24 10 NULL GE1/1 Direct D/L/-
10.1.2.0/24 10 NULL GE1/3 Direct D/L/-
192.168.0.0/24 10 NULL GE1/2 Direct D/L/-
10.1.4.0/24 10 NULL GE1/2 192.168.0.2 R/L/-
10.1.5.0/24 20 NULL GE1/2 192.168.0.2 R/L/-
10.1.6.0/24 20 NULL GE1/2 192.168.0.2 R/L/-
Flags: D-Direct, R-Added to RM, L-Advertised in LSPs, U-Up/Down Bit Set
702BIS-IS authentication configuration example
In this example, Device A is the firewall.
1476BNetwork requirements
As shown in 2647HFigure 282, Device A, Device B, Device C, and Device D reside in the same IS-IS routing
domain.
Device A, Device B, and Device C belong to Area 10, and Device D belongs to Area 20.
Configure neighbor relationship authentication between neighbors. Configure area authentication in
Area 10 to prevent untrusted routes from entering into the area. Configure routing domain authentication
on Device C and Device D to prevent untrusted routes from entering the routing domain.