F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices VPN Configuration Guide-6PW100
95
Hardware DS-lite tunnel com
p
atible
Firewall module Yes
U200-A Yes
U200-S No
The following section describes the DS-lite tunnel configuration on the CPE and on the AFTR.
154BConfiguration prerequisites
Configure IPv6 addresses for interfaces (such as the VLAN interface, Ethernet interface, and loopback
interface). One of the interfaces is used as the source interface of the tunnel.
155BConfiguring the CPE of a tunnel
You can configure the CPE of a DS-lite tunnel or IPv4 over IPv6 manual tunnel:
• If you configure a DS-lite tunnel on the CPE, the CPE automatically obtains the IPv6 address of the
AFTR through DHCPv6 and uses the address as the destination address of the tunnel.
• If you configure an IPv4 over IPv6 manual tunnel on the CPE, you must manually specify the address
of the AFTR as the destination address of the tunnel.
This section describes how to configure a DS-lite tunnel on the CPE. For information about how to
configure an IPv4 over IPv6 manual tunnel on the CPE, see "
720HConfiguring an IPv4 over IPv6 manual
tunnel."
Follow these guidelines when you configure the CPE of a DS-lite tunnel:
• Tunnel interfaces using the same encapsulation protocol must have different source and destination
addresses.
• To encapsulate and forward IPv4 packets whose destination address does not belong to the subnet
where the receiving tunnel interface resides, configure a static route or dynamic routing for
forwarding those packets through this tunnel interface. If you configure a static route to that
destination IPv4 address, specify this tunnel interface as the outbound interface, or the peer tunnel
interface address as the next hop. A similar configuration is required at the other tunnel end. If you
configure dynamic routing at both ends, enable the dynamic routing protocol on both tunnel
interfaces. For more configurations about static routes or other routing protocols, see Network
Management Configuration Guide.
• If you configure a DS-lite tunnel on the CPE, you can specify the source interface but not source
address for the tunnel interface. The primary IP address of the source interface is the source address
of the tunnel. After you configure the source interface for the tunnel, the CPE automatically obtains
the address of the AFTR through DHCPv6 and uses the address as the destination address of the
tunnel.
To configure the CPE of a DS-lite tunnel:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enable IPv6.
ipv6 No enabled by default.
3. Enter tunnel interface view. interface tunnel number N/A