R3721-F3210-F3171-HP High-End Firewalls Network Management Configuration Guide-6PW101

Table Of Contents
904
Figure 401 Network diagram
Configuration procedure
1. Configure Firewall A.
# Configure IPv6 addresses for interfaces GigabitEthernet 0/1 and GigabitEthernet0/2.
<FirewallA> system-view
[FirewallA] ipv6
[FirewallA] interface gigabitethernet 0/1
[FirewallA-GigabitEthernet0/1] ipv6 address 10::1 32
[FirewallA-GigabitEthernet0/1] quit
[FirewallA] interface gigabitethernet 0/2
[FirewallA-GigabitEthernet0/2] ipv6 address 11::1 32
[FirewallA-GigabitEthernet0/2] quit
# Enable RIPng on GigabitEthernet 0/1.
[FirewallA] interface gigabitethernet 0/1
[FirewallA-GigabitEthernet0/1] ripng 1 enable
[FirewallA-GigabitEthernet0/1] quit
# Configure three static routes on Firewall A.
[FirewallA] ipv6 route-static 20:: 32 gigabitethernet 0/2
[FirewallA] ipv6 route-static 30:: 32 gigabitethernet 0/2
[FirewallA] ipv6 route-static 40:: 32 gigabitethernet 0/2
# Configure a routing policy.
[FirewallA] ip ipv6-prefix a index 10 permit 30:: 32
[FirewallA] route-policy static2ripng deny node 0
[FirewallA-route-policy] if-match ipv6 address prefix-list a
[FirewallA-route-policy] quit
[FirewallA] route-policy static2ripng permit node 10
[FirewallA-route-policy] quit
# Enable RIPng and apply routing policy static3ripng to filter redistributed static routes on Firewall
A.
[FirewallA] ripng
[FirewallA-ripng-1] import-route static route-policy static2ripng
2. Configure Firewall B.
# Configure the IPv6 address of GigabitEthernet 0/1.
<FirewallB> system-view
[FirewallB] ipv6
[FirewallB] interface gigabitethernet 0/1
[FirewallB-GigabitEthernet0/1] ipv6 address 10::2 32
# Enable RIPng on the interface.