R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
780
For more information about IPsec policy configuration, see VPN Configuration Guide.
Configuration procedure
To apply an IPsec policy to a peer/peer group:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter BGP view.
bgp as-number N/A
3. Enter IPv6 address
family view.
ipv6-family N/A
4. Apply an IPsec policy to
a peer/peer group.
peer { group-name | ip-address } ipsec-policy
policy-name
Not configured by default.
NOTE:
A
n IPsec policy used for IPv6 BGP can be only in manual mode. For more information,
see VPN Command
Reference.
Configuring a large scale IPv6 BGP network
In a large-scale IPv6 BGP network, configuration and maintenance become no convenient due to too
many peers. Configuring peer groups makes management easier and improves route distribution
efficiency. Peer group includes iBGP peer group, where peers belong to the same AS, and eBGP peer
group, where peers belong to different ASs. If peers in an eBGP group belong to the same external AS,
the eBGP peer group is a pure eBGP peer group, and if not, a mixed eBGP peer group.
In a peer group, all members have a common policy. Using the community attribute can make a set of
IPv6 BGP routers in multiple ASs have the same policy, because community sending between IPv6 BGP
peers is not limited by AS.
To ensure connectivity between iBGP peers, you need to make them fully meshed, but it becomes
unpractical when too many iBGP peers exist. Using route reflectors or confederation can solve it. In a
large-scale AS, both of them can be used.
Confederation configuration of IPv6 BGP is identical to that of BGP4, so it is not mentioned here.
Prerequisites
Make peer nodes accessible to each other at the network layer
Enable BGP and configure a router ID.
Configuring IPv6 BGP peer group
Configuring an iBGP peer group
To configure an iBGP group:
Ste
p
Command
Remarks
1. Enter system view. system-view N/A
2. Enter BGP view.
bgp as-number N/A