R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
888
[FirewallB] interface gigabitethernet 0/2
[FirewallB-GigabitEthernet0/2] pim ipv6 dm
[FirewallB-GigabitEthernet0/2] quit
# Enable IPv6 multicast routing on Firewall C, enable IPv6 PIM-DM on each interface, and enable
MLD on the host-side interface GigabitEthernet 0/1.
<FirewallC> system-view
[FirewallC] multicast ipv6 routing-enable
[FirewallC] interface gigabitethernet 0/1
[FirewallC-GigabitEthernet0/1] mld enable
[FirewallC-GigabitEthernet0/1] pim ipv6 dm
[FirewallC-GigabitEthernet0/1] quit
[FirewallC] interface gigabitethernet 0/3
[FirewallC-GigabitEthernet0/3] pim ipv6 dm
[FirewallC-GigabitEthernet0/3] quit
3. Configure an IPv6 multicast group filter:
# Configure an IPv6 multicast group filter on Firewall A, so that the hosts connected to
GigabitEthernet 0/1 can join IPv6 multicast group FF1E::101 only.
[FirewallA] acl ipv6 number 2001
[FirewallA-acl6-basic-2001] rule permit source ff1e::101 128
[FirewallA-acl6-basic-2001] quit
[FirewallA] interface gigabitethernet 0/1
[FirewallA-GigabitEthernet0/1] mld group-policy 2001
[FirewallA-GigabitEthernet0/1] quit
4. Verify the configuration:
Use the display mld interface command to display MLD information on each interface of firewalls.
For example:
# Display MLD information on GigabitEthernet 0/1 of Firewall B.
[FirewallB] display mld interface gigabitethernet 0/1
GigabitEthernet0/1(FE80::200:5EFF:FE66:5100):
MLD is enabled
Current MLD version is 1
Value of query interval for MLD(in seconds): 125
Value of other querier present interval for MLD(in seconds): 255
Value of maximum query response time for MLD(in seconds): 10
Querier for MLD: FE80::200:5EFF:FE66:5100 (this Firewall)
Total 1 MLD Group reported
MLD SSM mapping configuration example
Network requirements
As shown in Figure 399, the IPv6 PIM-SM domain applies both the ASM model and SSM model for IPv6
multicast delivery. Firewall's GigabitEthernet 0/3 serves as the C-BSR and C-RP. The SSM group range is
FF3E::/64.
MLDv2 runs on Firewall's GigabitEthernet 0/1. The receiver host runs MLDv1, and does not support
MLDv2. Therefore, the Receiver host cannot specify expected multicast sources in its membership reports.