R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
416
Configuring route filtering at the CLI
Network requirements
As shown in Figure 270:
All the routers in the network run OSPF. The AS is divided into three areas.
Firewall A works as the ABR between Area 0 and Area 1. Router A works as the ABR between Area
0 and Area 2.
Configure Firewall B as an ASBR to redistribute external routes (static routes), and configure a filter policy
on Firewall B to filter out route 3.1.3.0/24. Configure a routing policy on Firewall A to filter route
10.5.1.0/24.
Figure 270 Network diagram
Configuration procedure
1. Configure IP addresses for interfaces. (Details not shown)
2. Configure OSPF basic functions (see “Configuring OSPF basic functions at the CLI”).
3. Configure OSPF to redistribute routes.
# On Firewall B, configure a static route destined for network 3.1.1.0/24.
<FirewallB> system-view
[FirewallB] ip route-static 3.1.1.0 24 10.4.1.2
# On Firewall B, configure a static route destined for network 3.1.2.0/24.
[FirewallB] ip route-static 3.1.2.0 24 10.4.1.2
# On Firewall B, configure a static route destined for network 3.1.3.0/24.
[FirewallB] ip route-static 3.1.3.0 24 10.4.1.2
# Configure OSPF to redistribute static routes on Firewall B.
[FirewallB] ospf 1
[FirewallB-ospf-1] import-route static
[FirewallB-ospf-1] quit
# Display the OSPF routing table of Firewall A.
<FirewallA> display ip routing-table
Routing Tables: Public
Destinations : 12 Routes : 12
Destination/Mask Proto Pre Cost NextHop Interface