R3166-R3206-HP High-End Firewalls Network Management Configuration Guide-6PW101
478
[FirewallA] multicast routing-enable
[FirewallA] interface gigabitethernet 0/0
[FirewallA-GigabitEthernet0/0] igmp enable
[FirewallA-GigabitEthernet0/0] igmp version 3
[FirewallA-GigabitEthernet0/0] pim sm
[FirewallA-GigabitEthernet0/0] quit
[FirewallA] interface gigabitethernet 0/1
[FirewallA-GigabitEthernet0/1] pim sm
[FirewallA-GigabitEthernet0/1] quit
[FirewallA] interface gigabitethernet 0/2
[FirewallA-GigabitEthernet0/2] pim sm
[FirewallA-GigabitEthernet0/2] quit
The configuration on Firewall B and Firewall C is similar to that on Firewall A. The configuration on
Firewall D and Firewall E is also similar to that on Firewall A except that it is not necessary to enable
IGMP on the corresponding interfaces on these two devices.
3. Configure the SSM group range
# Configure the SSM group range to be 232.1.1.0/24 on Firewall A.
[FirewallA] acl number 2000
[FirewallA-acl-basic-2000] rule permit source 232.1.1.0 0.0.0.255
[FirewallA-acl-basic-2000] quit
[FirewallA] pim
[FirewallA-pim] ssm-policy 2000
[FirewallA-pim] quit
The configuration on Firewall B, Firewall C, Firewall D and Firewall E is similar to that on Firewall A.
4. Verify the configuration
Use the display pim interface command to view the PIM configuration and running status on each
interface. For example:
# Verify the PIM configuration information on Firewall A.
[FirewallA] display pim interface
VPN-Instance: public net
Interface NbrCnt HelloInt DR-Pri DR-Address
GE0/0 0 30 1 10.110.1.1 (local)
GE0/1 1 30 1 192.168.1.2
GE0/2 1 30 1 192.168.9.2
Assume that Host A needs to receive the information a specific multicast source S (10.110.5.100/24)
sends to multicast group G (232.1.1.1). Firewall A builds an SPT toward the multicast source. Firewalls on
the SPT path (Firewall A and Firewall D) have generated (S, G) entry, while Firewall E, which is not on the
SPT path, does not have multicast routing entries. You can use the display pim routing-table command to
view the PIM routing table information on each device. For example:
# View the PIM routing table information on Firewall A.
[FirewallA] display pim routing-table
VPN-Instance: public net
Total 0 (*, G) entry; 1 (S, G) entry
(10.110.5.100, 232.1.1.1)
Protocol: pim-ssm, Flag: