R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
349
16.4.1.1/32 Direct 0 0 127.0.0.1 InLoop0
127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0
127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0
3. Configure RIP route redistribution.
# Configure RIP 200 to redistribute direct routes and routes from RIP 100 on Firewall B.
[FirewallB] rip 200
[FirewallB-rip-200] import-route rip 100
[FirewallB-rip-200] import-route direct
[FirewallB-rip-200] quit
# Display the routing table of Firewall C.
[FirewallC] display ip routing-table
Routing Tables: Public
Destinations : 8 Routes : 8
Destination/Mask Proto Pre Cost NextHop Interface
10.2.1.0/24 RIP 100 1 12.3.1.1 GE0/1
11.1.1.0/24 RIP 100 1 12.3.1.1 GE0/1
12.3.1.0/24 Direct 0 0 12.3.1.2 GE0/1
12.3.1.2/32 Direct 0 0 127.0.0.1 InLoop0
16.4.1.0/24 Direct 0 0 16.4.1.1 GE0/2
16.4.1.1/32 Direct 0 0 127.0.0.1 InLoop0
127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0
127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0
4. Configure a filtering policy for redistributed routes.
# On Firewall B, define ACL 2000 and reference it to a filtering policy to filter routes redistributed
from RIP 100, making the route not advertised to Firewall C.
[FirewallB] acl number 2000
[FirewallB-acl-basic-2000] rule deny source 10.2.1.1 0.0.0.255
[FirewallB-acl-basic-2000] rule permit
[FirewallB-acl-basic-2000] quit
[FirewallB] rip 200
[FirewallB-rip-200] filter-policy 2000 export rip 100
# Display the routing table on Firewall C.
[FirewallC] display ip routing-table
Routing Tables: Public
Destinations : 7 Routes : 7
Destination/Mask Proto Pre Cost NextHop Interface
11.1.1.0/24 RIP 100 1 12.3.1.1 GE0/1
12.3.1.0/24 Direct 0 0 12.3.1.2 GE0/1
12.3.1.2/32 Direct 0 0 127.0.0.1 InLoop0
16.4.1.0/24 Direct 0 0 16.4.1.1 GE0/2
16.4.1.1/32 Direct 0 0 127.0.0.1 InLoop0
127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0
127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0