R0106-HP MSR Router Series Layer 3 - IP Services Configuration Guide(V7)
376
Table 17 Interface and IP address assignment
Device Interface IP
address
Device
Interface IP address
Hub 1 GE1/0/1 1::1/64 Spoke 1 GE1/0/1 1::4/64
Tunnel1 192:168:1::1/64
GE1/0/2 192:168:10::1/64
Tunnel2 192:168::1/64 Tunnel1 192:168:1::3/64
Hub 2 GE1/0/1 1::2/64 Spoke 2 GE1/0/1 1::5/64
Tunnel1 192:168:1::2/64
GE1/0/2 192:168:20::1/64
Tunnel2 192:168::2/64 GE1/0/3 192:168:30::1/64
Hub 3 GE1/0/1 1::3/64 Tunnel1 192:168:1::4/64
Tunnel1 192:168:2::1/64
Spoke 3 GE1/0/1 1::6/64
Tunnel2 192:168::3/64 GE1/0/2 192:168:40::1/64
AAA server 1::10/64 Tunnel1 192:168:2::2/64
Primary server GE1/0/1 1::11/64 Spoke 4 GE1/0/1 1::7/64
Secondary server GE1/0/1 1::12/64 GE1/0/2 192:168:50::1/64
GE1/0/3 192:168:60::1/64
Tunnel1 192:168:2::3/64
Configuring the primary VAM server
1. Configure IP addresses for the interfaces. (Details not shown.)
2. Configure AAA:
# Configure RADIUS scheme abc.
<PrimaryServer> system-view
[PrimaryServer] radius scheme abc
[PrimaryServer-radius-abc] primary authentication ipv6 1::10 1812
[PrimaryServer-radius-abc] primary accounting ipv6 1::10 1813
[PrimaryServer-radius-abc] key authentication simple 123
[PrimaryServer-radius-abc] key accounting simple 123
[PrimaryServer-radius-abc] user-name-format without-domain
[PrimaryServer-radius-abc] quit
[PrimaryServer] radius session-control enable
# Configure AAA methods for the ISP domain abc.
[PrimaryServer] domain abc
[PrimaryServer-isp-abc] authentication advpn radius-scheme abc
[PrimaryServer-isp-abc] accounting advpn radius-scheme abc
[PrimaryServer-isp-abc] quit
[PrimaryServer] domain default enable abc
3. Configure the VAM server:
# Create ADVPN domain abc.
[PrimaryServer] vam server advpn-domain abc id 1
# Create hub group 0.
[PrimaryServer-vam-server-domain-abc] hub-group 0