R3166-R3206-HP High-End Firewalls Network Management Configuration Guide-6PW101
320
10.2.1.0/24 Direct 0 0 10.2.1.1 GE0/1
10.2.1.1/32 Direct 0 0 127.0.0.1 InLoop0
10.3.1.0/24 OSPF 10 4 10.1.1.2 GE0/0
10.4.1.0/24 OSPF 10 13 10.2.1.2 GE0/1
10.5.1.0/24 OSPF 10 14 10.1.1.2 GE0/0
127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0
127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0
The route destined for network 3.1.3.0/24 is filtered out.
5. Configure Firewall to filter out route 10.5.1.1/24.
# Configure the ACL on Firewall.
<Firewall> system-view
[Firewall] acl number 2000
[Firewall-acl-basic-2000] rule 0 deny source 10.5.1.0 0.0.0.255
[Firewall-acl-basic-2000] rule 1 permit source any
[Firewall-acl-basic-2000] quit
# Use the ACL to filter route 10.5.1.0/24.
[Firewall] ospf 1
[Firewall-ospf-1] filter-policy 2000 import
[Firewall-ospf-1] quit
# Display the OSPF routing table of Firewall.
[Firewall] display ip routing-table
Routing Tables: Public
Destinations : 10 Routes : 10
Destination/Mask Proto Pre Cost NextHop Interface
3.1.1.0/24 O_ASE 150 1 10.2.1.2 GE0/1
3.1.2.0/24 O_ASE 150 1 10.2.1.2 GE0/1
10.1.1.0/24 Direct 0 0 10.1.1.1 GE0/0
10.1.1.1/32 Direct 0 0 127.0.0.1 InLoop0
10.2.1.0/24 Direct 0 0 10.2.1.1 GE0/1
10.2.1.1/32 Direct 0 0 127.0.0.1 InLoop0
10.3.1.0/24 OSPF 10 4 10.1.1.2 GE0/0
10.4.1.0/24 OSPF 10 13 10.2.1.2 GE0/1
127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0
127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0
The route to 10.5.1.1/24 is filtered out.
Troubleshooting OSPF configuration
No OSPF neighbor relationship established
Symptom
No OSPF neighbor relationship can be established.