R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
819
[FirewallA-pbr6-aaa-5] quit
# Apply policy aaa on GigabitEthernet 0/1.
[FirewallA] interface gigabitethernet00/1
[FirewallA-GigabitEthernet0/1] ipv6 address 10::2 64
[FirewallA-GigabitEthernet0/1] undo ipv6 nd ra halt
[FirewallA-GigabitEthernet0/1] ripng 1 enable
[FirewallA-GigabitEthernet0/1] ipv6 policy-based-route aaa
[FirewallA-GigabitEthernet0/1] quit
2. Configure Firewall B:
# Configure RIPng.
<FirewallB> system-view
[FirewallB] ipv6
[FirewallB] ripng 1
[FirewallB-ripng-1] quit
[FirewallB] interface gigabitethernet00/1
[FirewallB-GigabitEthernet0/1] ipv6 address 1::2 64
[FirewallB-GigabitEthernet0/1] ripng 1 enable
[FirewallB-GigabitEthernet0/1] quit
3. Configure Firewall C:
# Configure RIPng.
<FirewallC> system-view
[FirewallC] ipv6
[FirewallC] ripng 1
[FirewallC-ripng-1] quit
[FirewallC] interface gigabitethernet00/1
[FirewallC-GigabitEthernet0/1] ipv6 address 2::2 64
[FirewallC-GigabitEthernet0/1] ripng 1 enable
[FirewallC-GigabitEthernet0/1] quit
4. Verify the configuration:
Enable IPv6 on Host A and configure the IPv6 address of Host A as 10::3.
C:\>ipv6 install
Installing...
Succeeded.
C:\>ipv6 adu 4/10::3
On Host A, telnet to Firewall B (1::2) that is directly connected to Firewall A. The operation
succeeds.
On Host A, telnet to Firewall C (2::2) that is directly connected to Firewall A. The operation fails.
Ping Firewall C from Host A. The operation succeeds.
Telnet uses TCP, and ping uses ICMP. The preceding results show that all TCP packets received on
interface GigabitEthernet 0/1 of Firewall A are forwarded via GigabitEthernet 0/3, and other
packets are forwarded via GigabitEthernet 0/2. The PBR configuration is effective.