HP VPN Firewall Appliances VPN Configuration Guide

70
Figure 64 Network diagram
Configuration procedure
Make sure Firewall A and Firewall B can reach each other through IPv4.
Configure Firewall A:
# Enable IPv6.
<FirewallA> system-view
[FirewallA] ipv6
# Configure an IPv4 address for GigabitEthernet 0/2.
[FirewallA] interface gigabitethernet 0/2
[FirewallA-GigabitEthernet0/2] ip address 192.168.100.1 255.255.255.0
[FirewallA-GigabitEthernet0/2] quit
# Configure an IPv6 address for GigabitEthernet 0/1.
[FirewallA] interface gigabitethernet 0/1
[FirewallA-GigabitEthernet0/1] ipv6 address 3002::1 64
[FirewallA-GigabitEthernet0/1] quit
# Configure an IPv6 manual tunnel.
[FirewallA] interface tunnel 0
[FirewallA-Tunnel0] ipv6 address 3001::1/64
[FirewallA-Tunnel0] source gigabitethernet 0/2
[FirewallA-Tunnel0] destination 192.168.50.1
[FirewallA-Tunnel0] tunnel-protocol ipv6-ipv4
[FirewallA-Tunnel0] quit
# Configure a static route to IPv6 Group 2 through Tunnel 0 on Firewall A.
[FirewallA] ipv6 route-static 3003:: 64 tunnel 0
Configure Firewall B:
# Enable IPv6.
<FirewallB> system-view
[FirewallB] ipv6
# Configure an IPv4 address for GigabitEthernet 0/2.
[FirewallB] interface gigabitethernet 0/2
[FirewallB-GigabitEthernet0/2] ip address 192.168.50.1 255.255.255.0
[FirewallB-GigabitEthernet0/2] quit
# Configure an IPv6 address for GigabitEthernet 0/1.
[FirewallB] interface gigabitethernet 0/1
[FirewallB-GigabitEthernet0/1] ipv6 address 3003::1 64
[FirewallB-GigabitEthernet0/1] quit
# Configure an IPv6 manual tunnel.