R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
475
[FirewallB-ospf-1-area-0.0.0.0] network 192.1.1.0 0.0.0.255
[FirewallB-ospf-1-area-0.0.0.0] network 194.1.1.0 0.0.0.255
[FirewallB-ospf-1-area-0.0.0.0] quit
[FirewallB-ospf-1] quit
# Configure Firewall C.
<FirewallC> system-view
[FirewallC] ospf
[FirewallC-ospf] area 0
[FirewallC-ospf-1-area-0.0.0.0] network 193.1.1.0 0.0.0.255
[FirewallC-ospf-1-area-0.0.0.0] network 195.1.1.0 0.0.0.255
[FirewallC-ospf-1-area-0.0.0.0] quit
[FirewallC-ospf-1] quit
# Configure Firewall D.
<FirewallD> system-view
[FirewallD] ospf
[FirewallD-ospf] area 0
[FirewallD-ospf-1-area-0.0.0.0] network 194.1.1.0 0.0.0.255
[FirewallD-ospf-1-area-0.0.0.0] network 195.1.1.0 0.0.0.255
[FirewallD-ospf-1-area-0.0.0.0] quit
[FirewallD-ospf-1] quit
3. Configure BGP connections:
# Configure Firewall A.
<FirewallA> system-view
[FirewallA] bgp 100
[FirewallA-bgp] peer 192.1.1.2 as-number 200
[FirewallA-bgp] peer 193.1.1.2 as-number 200
# Inject network 1.0.0.0/8 into the BGP routing table of Firewall A.
[FirewallA-bgp] network 1.0.0.0 8
[FirewallA-bgp] quit
# Configure Firewall B.
[FirewallB] bgp 200
[FirewallB-bgp] peer 192.1.1.1 as-number 100
[FirewallB-bgp] peer 194.1.1.1 as-number 200
[FirewallB-bgp] quit
# Configure Firewall C
[FirewallC] bgp 200
[FirewallC-bgp] peer 193.1.1.1 as-number 100
[FirewallC-bgp] peer 195.1.1.1 as-number 200
[FirewallC-bgp] quit
# Configure Firewall D
[FirewallD] bgp 200
[FirewallD-bgp] peer 194.1.1.2 as-number 200
[FirewallD-bgp] peer 195.1.1.2 as-number 200
[FirewallD-bgp] quit
4. Configure different attribute values for the route 1.0.0.0/8 to make Firewall D give priority to the
route learned from Firewall C: