R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
628
[FirewallA-GigabitEthernet0/1] quit
[FirewallA] interface gigabitethernet 0/2
[FirewallA-GigabitEthernet0/2] pim sm
[FirewallA-GigabitEthernet0/2] quit
[FirewallA] interface gigabitethernet 0/3
[FirewallA-GigabitEthernet0/3] pim sm
[FirewallA-GigabitEthernet0/3] quit
The configuration on Router A and Router B is similar to that on Firewall A. The configuration on
Firewall B and Firewall C is also similar to that on Firewall A except that it is not necessary to
enable IGMP on the corresponding interfaces on these two routers.
3. Configure the SSM group range:
# Configure the SSM group range to be 232.1.1.0/24 on Firewall A.
[FirewallA] acl number 2000
[FirewallA-acl-basic-2000] rule permit source 232.1.1.0 0.0.0.255
[FirewallA-acl-basic-2000] quit
[FirewallA] pim
[FirewallA-pim] ssm-policy 2000
[FirewallA-pim] quit
The configuration on Router A, Router B, Firewall B and Firewall C is similar to that on Firewall A.
4. Verify the configuration
Use the display pim interface command to display PIM information on each interface of firewalls.
For example:
# Display PIM configuration information on Firewall A.
[FirewallA] display pim interface
Interface NbrCnt HelloInt DR-Pri DR-Address
GE0/1 0 30 1 10.110.1.1 (local)
GE0/2 1 30 1 192.168.1.2
GE0/3 1 30 1 192.168.9.2
Assume that Host A needs to receive the information a specific multicast source S
(10.110.5.100/24) sends to multicast group G (232.1.1.1). Firewall A builds an SPT toward the
multicast source. Firewalls on the SPT path (Firewall A and Firewall B) have generated (S, G) entry,
but Firewall C, which is not on the SPT path, does not have multicast routing entries. You can use
the display pim routing-table command to display PIM routing table information on each firewall.
For example:
# Display PIM routing table information on Firewall A.
[FirewallA] display pim routing-table
Total 0 (*, G) entry; 1 (S, G) entry
(10.110.5.100, 232.1.1.1)
Protocol: pim-ssm, Flag:
UpTime: 00:13:25
Upstream interface: GigabitEthernet0/3
Upstream neighbor: 192.168.1.2
RPF prime neighbor: 192.168.1.2
Downstream interface(s) information:
Total number of downstreams: 1
1: GigabitEthernet0/1