Configuration procedure – H3C Technologies H3C SecPath F1000-E User Manual
Page 115
103
Figure 76 Network diagram
Configuration procedure
NOTE:
Before configuring an IPv4 over IPv4 tunnel, make sure that Router A and Router B are reachable to each
other.
•
Configure Router A:
# Configure an IPv4 address for GigabitEthernet 0/1.
<RouterA> system-view
[RouterA] interface GigabitEthernet 0/1
[RouterA-GigabitEthernet0/1] ip address 10.1.1.1 255.255.255.0
[RouterA-GigabitEthernet0/1] quit
# Configure an IPv4 address for GigabitEthernet 0/2 (the physical interface of the tunnel).
[RouterA] interface GigabitEthernet 0/2
[RouterA-GigabitEthernet0/2] ip address 2.1.1.1 255.255.255.0
[RouterA-GigabitEthernet0/2] quit
# Create interface Tunnel 1.
[RouterA] interface tunnel 1
# Configure an IPv4 address for interface Tunnel 1.
[RouterA-Tunnel1] ip address 10.1.2.1 255.255.255.0
# Configure the tunnel encapsulation mode.
[RouterA-Tunnel1] tunnel-protocol ipv4-ipv4
# Configure a source address for interface Tunnel 1 (IP address of GigabitEthernet 0/2).
[RouterA-Tunnel1] source 2.1.1.1
# Configure a destination address for interface Tunnel 1 (IP address of GigabitEthernet 0/2 of
Router B).
[RouterA-Tunnel1] destination 3.1.1.1
[RouterA-Tunnel1] quit
# Configure a static route from Router A through interface Tunnel 1 to Group 2.
[RouterA] ip route-static 10.1.3.0 255.255.255.0 tunnel 1
•
Configure Router B:
# Configure an IPv4 address for GigabitEthernet 0/1.
<RouterB> system-view
[RouterB] interface GigabitEthernet 0/1
[RouterB-GigabitEthernet0/1] ip address 10.1.3.1 255.255.255.0
[RouterB-GigabitEthernet0/1] quit
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS