R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
474
AS-path : 100
Origin : igp
Attribute value : MED 0, localpref 100, pref-val 0, pre 255
State : valid, internal, best,
Not advertised to any peers yet
The output information shows that:
{ Firewall F can send route information to Firewall B and Firewall C through the confederation by
establishing only an EBGP connection with Firewall A.
{ Firewall B and Firewall D are in the same confederation, but belong to different sub ASs. They
obtain external route information from Firewall A and generate the same BGP route entries; it
seems like that they reside in the same AS although they have no direct connection in between.
BGP path selection configuration at the CLI
Network requirements
In Figure 290, all firewalls run BGP. Between Firewall A and Firewall B, and between Firewall A and
Firewall C are EBGP connections. Between Firewall B and Firewall D, and between Firewall D and
Firewall C are IBGP connections. OSPF is the IGP protocol in AS 200.
Configure routing policies to make Firewall D give priority to the route 1.0.0.0/8 learned from Firewall
C.
Figure 290 Network diagram
Device Interface IP address
Device
Interface IP address
Firewall
A
GE0/1 1.0.0.0/8
Firewall
D
GE0/1 195.1.1.1/24
GE0/2 192.1.1.1/24 GE0/2 194.1.1.1/24
GE0/3 193.1.1.1/24
Firewall
C
GE0/1 195.1.1.2/24
Firewall B GE0/1 192.1.1.2/24
GE0/2 193.1.1.2/24
GE0/2 194.1.1.2/24
Configuration procedure
1. Configure IP addresses for interfaces. (Details not shown)
2. Configure OSPF on Firewall B, C, and D:
# Configure Firewall B.
<FirewallB> system-view
[FirewallB] ospf
[FirewallB-ospf] area 0