F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices VPN Configuration Guide-6PW100
76
Figure 65 Network diagram
374BConfiguration procedure
Before configuring an automatic IPv4-compatible IPv6 tunnel, make sure Firewall A and Firewall B can
reach each other through IPv4.
• Configure Firewall A:
# Enable IPv6.
<FirewallA> system-view
[FirewallA] ipv6
# Configure an IPv4 address for GigabitEthernet 0/1.
[FirewallA] interface gigabitethernet 0/1
[FirewallA-GigabitEthernet0/1] ip address 192.168.100.1 255.255.255.0
[FirewallA-GigabitEthernet0/1] quit
# Configure an automatic IPv4-compatible IPv6 tunnel.
[FirewallA] interface tunnel 0
[FirewallA-Tunnel0] ipv6 address ::192.168.100.1/96
[FirewallA-Tunnel0] source gigabitethernet 0/1
[FirewallA-Tunnel0] tunnel-protocol ipv6-ipv4 auto-tunnel
• Configure Firewall B:
# Enable IPv6.
<FirewallB> system-view
[FirewallB] ipv6
# Configure an IPv4 address for GigabitEthernet 0/1.
[FirewallB] interface gigabitethernet 0/1
[FirewallB-GigabitEthernet0/1] ip address 192.168.50.1 255.255.255.0
[FirewallB-GigabitEthernet0/1] quit
# Configure an automatic IPv4-compatible IPv6 tunnel.
[FirewallB] interface tunnel 0
[FirewallB-Tunnel0] ipv6 address ::192.168.50.1/96
[FirewallB-Tunnel0] source gigabitethernet 0/1
[FirewallB-Tunnel0] tunnel-protocol ipv6-ipv4 auto-tunnel
375BVerifying the configuration
# Display the status of the tunnel interfaces on Firewall A and Firewall B, respectively.
[FirewallA-Tunnel0] display ipv6 interface tunnel 0
Tunnel0 current state :UP
Line protocol current state :UP
IPv6 is enabled, link-local address is FE80::C0A8:6401
Global unicast address(es):
::192.168.100.1, subnet is ::/96
Joined group address(es):