HP VPN Firewall Appliances NAT and ALG Configuration Guide
45
[Firewall] interface gigabitethernet 0/1
[Firewall-GigabitEthernet0/1] ip address 8.0.0.1 255.255.255.0
[Firewall-GigabitEthernet0/1] natpt enable
[Firewall-GigabitEthernet0/1] quit
[Firewall] interface gigabitethernet 0/2
[Firewall-GigabitEthernet0/2] ipv6 address 2001::1/64
[Firewall-GigabitEthernet0/2] natpt enable
[Firewall-GigabitEthernet0/2] quit
# Configure a NAT-PT prefix.
[Firewall] natpt prefix 3001::
# Configure a static IPv4/IPv6 mapping on the IPv4 side.
[Firewall] natpt v4bound static 9.0.0.2 3001::5
# Configure a static IPv4/IPv6 mapping on the IPv6 side.
[Firewall] natpt v6bound static 2001::2 8.0.0.5
2. Configure Router A:
# Configure an IP address for GigabitEthernet 0/1.
<RouterA> system-view
[RouterA] interface gigabitethernet 0/1
[RouterA-GigabitEthernet0/1] ip address 8.0.0.2 255.255.255.0
[RouterA-GigabitEthernet0/1] quit
# Configure a static route to subnet 9.0.0.0/24.
<RouterA> system-view
[RouterA] ip route-static 9.0.0.0 24 8.0.0.1
3. Configure Router B on the IPv6 side:
# Enable IPv6.
<RouterB> system-view
[RouterB] ipv6
# Configure an IP address for GigabitEthernet 0/1.
[RouterB] interface gigabitethernet 0/1
[RouterB-GigabitEthernet0/1] ipv6 address 2001::2/64
[RouterB-GigabitEthernet0/1] quit
# Configure a static route to the subnet with the NAT-PT prefix.
[RouterB] ipv6 route-static 3001:: 16 2001::1
Troubleshooting NAT-PT
Symptom
NAT-PT fails when a session is initiated on the IPv6 side.
Solution
1. Enable debugging for NAT-PT and locate the fault according to the debugging information about
the device.