R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
743
To configure BFD for OSPFv3, you need to configure OSPFv3 first.
To configure BFD for OSPFv3:
Ste
p
Command
Remarks
Enter system view system-view N/A
Enter OSPFv3 view
ospfv3 [ process-id ]
N/A
Specify a router ID router-id router-id N/A
Quit the OSPFv3 view quit N/A
Enter interface view
interface interface-type
interface-number
N/A
Enable an OSPFv3 process on the
interface
ospfv3 process-id area area-id
[ instance instance-id ]
Not enabled by default.
Enable BFD on the interface
ospfv3 bfd enable [ instance
instance-id ]
Not enabled by defaul
Applying IPsec policies for OSPFv3
To protect routing information and defend attacks, OSPFv3 can authenticate protocol packets by using
an IPsec policy.
Outbound OSPFv3 packets carry the Security Parameter Index (SPI) defined in the relevant IPsec policy.
A device uses the SPI carried in a received packet to match against the configured IPsec policy. If they
match, the device accepts the packet; otherwise, it discards the packet and will not establish a neighbor
relationship with the sending device.
You can configure an IPsec policy for an area, an interface or a virtual link.
To implement area-based IPsec protection, you need to configure the same IPsec policy on the
routers in the target area.
To implement interface-based IPsec protection, you need to configure the same IPsec policy on the
interfaces between two neighboring routers.
To implement virtual link-based IPsec protection, you need to configure the same IPsec policy on the
two routers connected over the virtual link.
If an interface and its area each have an IPsec policy configured, the interface uses its own IPsec policy.
If a virtual link and area 0 each have an IPsec policy configured, the virtual link uses its own IPsec policy.
Prerequisites
Before you apply an IPsec policy for OSPFv3, complete following tasks.
Create an IPsec proposal
Create an IPsec policy
For more information about IPsec policy configuration, see VPN Configuration Guide.
Configuration guidelines
An IPsec policy used for OSPFv3 can only be in manual mode. For more information, see VPN
Configuration Guide.