02-Typical configuration example

HomeSupportRoutersCR16000-F SeriesConfigure & DeployConfiguration ExamplesH3C CR16000-F Routers Configuration Examples All-In-One-R838x-6W10002-Typical configuration example
Table of Contents
Related Documents
37-OSPFv3_Configuration_Examples
Title Size Download
37-OSPFv3_Configuration_Examples 97.67 KB

Introduction

This document provides OSPFv3 route filtering configuration examples.

Prerequisites

The configuration examples in this document were created and verified in a lab environment, and all the devices were started with the factory default configuration. When you are working on a live network, make sure you understand the potential impact of every command on your network.

This document assumes that you have basic knowledge of OSPFv3 route filtering.

Example: Configuring OSPFv3 route filtering

Network configuration

As shown in Figure 1, the devices of an enterprise reside in OSPFv3 and RIPng domains.

Configure route redistribution between OSPFv3 and RIPng to interconnect the devices.

Configure route filtering on Device E, Device C, and Device D to meet the following requirements:

·     The route destined for R&D department 2 is not redistributed to OSPFv3.

·     Marketing department 1 cannot reach R&D department 1.

·     R&D department 1 and the After-sale service department cannot reach Marketing department 2.

Figure 1 Network diagram

 

Table 1 Interface and IP address assignment

Device

Interface

IP address

Device

Interface

IP address

Device A

XGE3/1/1

1::1/64

Device B

XGE3/1/1

1::2/64

 

XGE3/1/2

2::1/64

 

XGE3/1/2

3::1/64

 

XGE3/1/3

4::1/64

 

 

 

Device C

XGE3/1/1

2::2/64

Device D

XGE3/1/1

3::2/64

 

Loop0

13::1/64

 

Loop0

11::1/64

 

 

 

 

Loop1

12::1/64

Device E

XGE3/1/1

4::2/64

Device F

XGE3/1/1

5::2/64

 

XGE3/1/2

5::1/64

 

Loop0

14::1/64

 

 

 

 

Loop1

15::1/64

 

Restrictions and guidelines

When you configure OSPFv3 route filtering, follow these restrictions and guidelines:

·     The filter-policy export command that filters redistributed routes takes effect only on an ASBR.

·     OSPFv3 filters routes calculated using received LSAs. It does not filter LSAs.

·     IP communication is bidirectional. If a router filters a route destined for Network A, the subnets attached to the router cannot reach Network A, and Network A cannot reach the subnets.

·     When you configure route filtering by referencing an ACL, configure the rule permit source any item following multiple rule deny source items to allow unmatched routes to pass.

·     Specify a Router ID when you configure OSPFv3.

Procedures

Configuring IPv6 addresses

# Configure an IPv6 address for Ten-GigabitEthernet3/1/1.

<DeviceA> system-view

[DeviceA] interface Ten-GigabitEthernet 3/1/1

[DeviceA-Ten-GigabitEthernet3/1/1] ipv6 address 1::1 64

# Configure IPv6 addresses for other interfaces, as shown in Figure 1. (Details not shown.)

Configuring OSPFv3

# Enable OSPFv3 on Device A.

<DeviceA> system-view

[DeviceA] ospfv3

[DeviceA-ospfv3-1] router-id 6.6.6.6

[DeviceA-ospfv3-1] quit

[DeviceA] interface Ten-GigabitEthernet 3/1/1

[DeviceA-Ten-GigabitEthernet3/1/1] ospfv3 1 area 0

[DeviceA-Ten-GigabitEthernet3/1/1]quit

[DeviceA] interface Ten-GigabitEthernet 3/1/2

[DeviceA-Ten-GigabitEthernet3/1/2] ospfv3 1 area 2

[DeviceA-Ten-GigabitEthernet3/1/2]quit

[DeviceA] interface Ten-GigabitEthernet 3/1/3

[DeviceA-Ten-GigabitEthernet3/1/3] ospfv3 1 area 1

[DeviceA-Ten-GigabitEthernet3/1/3]quit

# Enable OSPFv3 on Device B.

<DeviceB> system-view

[DeviceB] ospfv3

[DeviceB-ospfv3-1] router-id 5.5.5.5

[DeviceB-ospfv3-1] quit

[DeviceB] interface Ten-GigabitEthernet 3/1/1

[DeviceB-Ten-GigabitEthernet3/1/1] ospfv3 1 area 0

[DeviceB-Ten-GigabitEthernet3/1/1]quit

[DeviceB] interface Ten-GigabitEthernet 3/1/2

[DeviceB-Ten-GigabitEthernet3/1/2] ospfv3 1 area 3

[DeviceB-Ten-GigabitEthernet3/1/2]quit

# Enable OSPFv3 on Device C.

<DeviceC> system-view

[DeviceC] ospfv3

[DeviceC-ospfv3-1] router-id 4.4.4.4

[DeviceC-ospfv3-1] quit

[DeviceC] interface Ten-GigabitEthernet 3/1/1

[DeviceC-Ten-GigabitEthernet3/1/1] ospfv3 1 area 2

[DeviceC-Ten-GigabitEthernet3/1/1]quit

[DeviceC]interface LoopBack 0

[DeviceC-LoopBack0] ospfv3 1 area 2

[DeviceC-LoopBack0] quit

# Enable OSPFv3 on Device D.

<DeviceD> system-view

[DeviceD] ospfv3

[DeviceD-ospfv3-1] router-id 3.3.3.3

[DeviceD-ospfv3-1] quit

[DeviceD] interface Ten-GigabitEthernet 3/1/1

[DeviceD-Ten-GigabitEthernet3/1/1] ospfv3 1 area 3

[DeviceD-Ten-GigabitEthernet3/1/1]quit

[DeviceD]interface LoopBack 0

[DeviceD-LoopBack0] ospfv3 1 area 3

[DeviceD-LoopBack0] quit

[DeviceD]interface LoopBack 1

[DeviceD-LoopBack1] ospfv3 1 area 3

[DeviceD-LoopBack1] quit

# Enable OSPFv3 on Device E.

<DeviceE> system-view

[DeviceE] ospfv3

[DeviceE-ospfv3-1] router-id 2.2.2.2

[DeviceE-ospfv3-1] quit

[DeviceE] interface Ten-GigabitEthernet 3/1/1

[DeviceE-Ten-GigabitEthernet3/1/1] ospfv3 1 area 1

[DeviceE-Ten-GigabitEthernet3/1/1]quit

Configure RIPng

# Enable RIPng on Device E.

<DeviceE> system-view

[DeviceE] ripng

[DeviceE-ripng-1] quit

[DeviceE] interface Ten-GigabitEthernet 3/1/2

[DeviceE-Ten-GigabitEthernet3/1/2] ripng 1 enable

[DeviceE-Ten-GigabitEthernet3/1/2] quit

# Enable RIPng on Device F.

<DeviceF> system-view

[DeviceF] ripng

[DeviceF-ripng-1] quit

[DeviceF] interface Ten-GigabitEthernet 3/1/1

[DeviceF-Ten-GigabitEthernet3/1/1] ripng 1 enable

[DeviceF-Ten-GigabitEthernet3/1/1] quit

[DeviceF]interface LoopBack 0

[DeviceF-LoopBack0] ripng 1 enable

[DeviceF-LoopBack0] quit

[DeviceF]interface LoopBack 1

[DeviceF-LoopBack1] ripng 1 enable

[DeviceF-LoopBack1] quit

Configuring route redistribution

# Configure Device E to redistribute OSPFv3 and direct routes to RIPng.

<DeviceE> system-view

[DeviceE] ripng

[DeviceE-ripng-1] import-route direct

[DeviceE-ripng-1] import-route ospfv3

[DeviceE-ripng-1] quit

# Configure Device E to redistribute RIPng and direct routes to OSPFv3.

[DeviceE] ospfv3

[DeviceE-ospfv3-1] import-route direct

[DeviceE-ospfv3-1] import-route ripng

[DeviceE-ospfv3-1] quit

# Verify that Device E has routes to all networks.

[Device E]display ipv6 routing-table

 

Destinations : 15        Routes : 15

 

Destination: ::1/128                                     Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 1::/64                                      Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:124D                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 2

 

Destination: 2::/64                                      Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:124D                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 2

 

Destination: 3::/64                                      Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:124D                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: 4::/64                                      Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : XGE3/1/1                                    Cost      : 0

 

Destination: 4::2/128                                    Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 5::/64                                      Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : XGE3/1/2                                    Cost      : 0

 

Destination: 5::1/128                                    Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 11::1/128                                   Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:124D                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: 12::1/128                                   Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:124D                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: 13::1/128                                   Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:124D                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 2

 

Destination: 14::/64                                     Protocol  : RIPng

NextHop    : FE80::2E0:FCFF:FE11:19B5                    Preference: 100

Interface  : XGE3/1/2                                    Cost      : 1

 

Destination: 15::/64                                     Protocol  : RIPng

NextHop    : FE80::2E0:FCFF:FE11:19B5                    Preference: 100

Interface  : XGE3/1/2                                    Cost      : 1

 

Destination: FE80::/10                                   Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: FF00::/8                                    Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : NULL0

# Verify that other devices have routes to all networks. (Details not shown.)

Configuring OSPFv3 route filtering

# On Device C, configure IPv6 basic ACL 2000 to deny 12::1/64.

<DeviceC> system-view

[DeviceC] acl ipv6 basic 2000

[DeviceC-acl-ipv6-basic-2000] rule 0 deny source 12::1 64

[DeviceC-acl-ipv6-basic-2000] rule permit source any

[DeviceC-acl-ipv6-basic-2000] quit

# On Device C, use IPv6 ACL 2000 to filter received routes.

[DeviceC] ospfv3

[DeviceC-ospfv3-1] filter-policy 2000 import

[DeviceC-ospfv3-1] quit

# On Device D, configure IPv6 basic ACL 2000 to deny 15::1/64.

<DeviceD> system-view

[DeviceD] acl ipv6 basic 2000

[DeviceD-acl-ipv6-basic-2000] rule 0 deny source 15::1 64

[DeviceD-acl-ipv6-basic-2000] rule permit source any

[DeviceD-acl-ipv6-basic-2000] quit

# On Device D, use IPv6 ACL 2000 to filter received routes.

[DeviceD] ospfv3

[DeviceD-ospfv3-1] filter-policy 2000 import

[DeviceD-ospfv3-1] quit

# On Device E, configure IPv6 basic ACL 2000 to deny 14::1/64.

<DeviceE> system-view

[DeviceE] acl ipv6 basic 2000

[DeviceE-acl-ipv6-basic-2000] rule 0 deny source 14::1 64

[DeviceE-acl-ipv6-basic-2000] rule permit source any

[DeviceE-acl-ipv6-basic-2000] quit

# On Device E, use IPv6 ACL 2000 to filter routes redistributed from RIPng.

[DeviceE] ospfv3

[DeviceE-ospfv3-1] filter-policy 2000 export ripng 1

[DeviceE-ospfv3-1] quit

Verifying the configuration

# Verify that Device C does not have a route to 12::/64.

[DeviceC]display ipv6 routing-table

 

Destinations : 13        Routes : 13

 

Destination: ::1/128                                     Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 1::/64                                      Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:1245                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 2

 

Destination: 2::/64                                      Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : XGE3/1/1                                    Cost      : 0

 

Destination: 2::2/128                                    Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 3::/64                                      Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:1245                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: 4::/64                                      Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:1245                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 2

 

Destination: 5::/64                                      Protocol  : O_ASE2

NextHop    : FE80::2E0:FCFF:FE58:1245                    Preference: 150

Interface  : XGE3/1/1                                    Cost      : 1

 

Destination: 11::1/128                                   Protocol  : O_INTER

NextHop    : FE80::2E0:FCFF:FE58:1245                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: 13::/64                                     Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : Loop0                                       Cost      : 0

 

Destination: 13::1/128                                   Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 15::/64                                     Protocol  : O_ASE2

NextHop    : FE80::2E0:FCFF:FE58:1245                    Preference: 150

Interface  : XGE3/1/1                                    Cost      : 1

 

Destination: FE80::/10                                   Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: FF00::/8                                    Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : NULL0

# Verify that Marketing department 1 cannot reach R&D department 1.

[DeviceC] ping ipv6 -a 13::1 12::1

Ping6(56 data bytes) 13::1 --> 12::1, press CTRL_C to break

Request time out

Request time out

Request time out

Request time out

Request time out

 

--- Ping6 statistics for 12::1 ---

5 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss

# Verify that Device D does not have a route to 15::/64.

[DeviceD]display ipv6 routing-table

 

Destinations : 14        Routes : 14

 

Destination: ::1/128                                     Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 1::/64                                      Protocol  : O_INTER

NextHop    : FE80::2A0:FCFF:FE00:5815                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 2

 

Destination: 2::/64                                      Protocol  : O_INTER

NextHop    : FE80::2A0:FCFF:FE00:5815                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: 3::/64                                      Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : XGE3/1/1                                    Cost      : 0

 

Destination: 3::2/128                                    Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 4::/64                                      Protocol  : O_INTER

NextHop    : FE80::2A0:FCFF:FE00:5815                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: 5::/64                                      Protocol  : O_ASE2

NextHop    : FE80::2A0:FCFF:FE00:5815                    Preference: 150

Interface  : XGE3/1/1                                    Cost      : 1

 

Destination: 11::/64                                     Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : Loop0                                       Cost      : 0

 

Destination: 11::1/128                                   Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 12::/64                                     Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : Loop1                                       Cost      : 0

 

Destination: 12::1/128                                   Protocol  : Direct

NextHop    : ::1                                         Preference: 0

Interface  : InLoop0                                     Cost      : 0

 

Destination: 13::1/128                                   Protocol  : O_INTER

NextHop    : FE80::2A0:FCFF:FE00:5815                    Preference: 10

Interface  : XGE3/1/1                                    Cost      : 3

 

Destination: FE80::/10                                   Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : NULL0                                       Cost      : 0

 

Destination: FF00::/8                                    Protocol  : Direct

NextHop    : ::                                          Preference: 0

Interface  : NULL0

# Verify that the After-sale service department cannot reach Marketing department 2.

[DeviceD] ping ipv6 -a 11::1 15::1

Ping6(56 data bytes) 11::1 --> 15::1, press CTRL_C to break

Request time out

Request time out

Request time out

Request time out

Request time out

 

--- Ping6 statistics for 15::1 ---

5 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss

# Verify that R&D department 1 cannot reach Marketing department 2.

[DeviceD] ping ipv6 -a 12::1 15::1

Ping6(56 data bytes) 12::1 --> 15::1, press CTRL_C to break

Request time out

Request time out

Request time out

Request time out

Request time out

 

--- Ping6 statistics for 15::1 ---

5 packet(s) transmitted, 0 packet(s) received, 100.0% packet loss

The output on Device C and Device D shows that Device E has filtered the route destined for R&D development 2.

Configuration files

·     Device A:

#

ospfv3 1

 router-id 6.6.6.6

 area 0.0.0.0

 area 0.0.0.1

 area 0.0.0.2

#

interface Ten-GigabitEthernet3/1/1

 ospfv3 1 area 0.0.0.0

 ipv6 address 1::1/64

#

interface Ten-GigabitEthernet3/1/2

 ospfv3 1 area 0.0.0.2

 ipv6 address 2::1/64

#

interface Ten-GigabitEthernet3/1/3

 ospfv3 1 area 0.0.0.1

 ipv6 address 4::1/64

#

·     Device B:

#

ospfv3 1

 router-id 5.5.5.5

 area 0.0.0.0

 area 0.0.0.3

#

interface Ten-GigabitEthernet3/1/1

 ospfv3 1 area 0.0.0.0

 ipv6 address 1::2/64

#

interface Ten-GigabitEthernet3/1/2

 ospfv3 1 area 0.0.0.3

 ipv6 address 3::1/64

#

·     Device C:

#

ospfv3 1

 router-id 4.4.4.4

 filter-policy 2000 import

 area 0.0.0.2

#

interface LoopBack0

 ospfv3 1 area 0.0.0.2

 ipv6 address 13::1/64

#

interface Ten-GigabitEthernet3/1/1

 ospfv3 1 area 0.0.0.2

 ipv6 address 2::2/64

#

acl ipv6 basic 2000

 rule 0 deny source 12::/64

 rule 5 permit

#

·     Device D:

#

ospfv3 1

 router-id 3.3.3.3

 filter-policy 2000 import

 area 0.0.0.3

#

interface LoopBack0

 ospfv3 1 area 0.0.0.3

 ipv6 address 11::1/64

#

interface LoopBack1

 ospfv3 1 area 0.0.0.3

 ipv6 address 12::1/64

#

interface Ten-GigabitEthernet3/1/1

 ospfv3 1 area 0.0.0.3

 ipv6 address 3::2/64

#

acl ipv6 basic 2000

 rule 0 deny source 15::/64

 rule 5 permit

#

·     Device E:

#

ospfv3 1

 router-id 2.2.2.2

 import-route direct

import-route ripng 1

 filter-policy 2000 export ripng 1

 area 0.0.0.1

#

ripng 1

 import-route direct

 import-route ospfv3 1

#

interface Ten-GigabitEthernet3/1/1

 ospfv3 1 area 0.0.0.1

 ipv6 address 4::2/64

#

interface Ten-GigabitEthernet3/1/2

 ipv6 address 5::1/64

 ripng 1 enable

#

acl ipv6 basic 2000

 rule 0 deny source 14::/64

 rule 5 permit

#

·     Device F:

#

ripng 1

#

interface LoopBack0

 ipv6 address 14::1/64

 ripng 1 enable

#

interface LoopBack1

 ipv6 address 15::1/64

 ripng 1 enable

#

interface Ten-GigabitEthernet3/1/1

 ipv6 address 5::2/64

 ripng 1 enable

#

Related documentation

·     H3C CR16000-F Routers Layer—3 IP Routing Configuration Guide-R8385P09

·     H3C CR16000-F Routers Layer—3 IP Routing Command Reference-R8385P09

·      

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网