Professional Documents
Culture Documents
Huawei Certification
HCDA-HNTD
Huawei Networking Technology and Device
Lab Guide
HUAWEI TECHNOLOGIES
HCDA-HNTD
Huawei Certification
HCDA-HNTD Huawei Networking Technology and Device
Lab Guide
Edition v1.6
HUAWEI TECHNOLOGIES
HCDA-HNTD
HUAWEI TECHNOLOGIES
HCDA-HNTD
Referenced icon
Router
L3 Switch
L2 Switch
Firewall
Serial line
Ethernet line
HUAWEI TECHNOLOGIES
Net cloud
HCDA-HNTD
Identifier
Device
OS version
R1
AR 2220
R2
AR 2220
R3
AR 2220
S1
S5700-28C-EI-24S
S2
S5700-28C-EI-24S
S3
S3700-28TP-EI-AC
S4
S3700-28TP-EI-AC
FW
Eudemon 200E-X2
HUAWEI TECHNOLOGIES
HCDA-HNTD
CONTENTS
Chapter 1 Basic Operations on the VRP Platform ............................................................................................... 1
Lab 1-1 Basic Operations on the VRP Platform ............................................................................................... 1
Chapter 2 Configuring Static Routes and Default Routes .................................................................................. 23
Lab 2-1 Configuring Static Routes and Default Routes .................................................................................. 23
Chapter 3 RIP Configuration ............................................................................................................................. 42
Lab 3-1 Configuring RIPv1 and RIPv2 ............................................................................................................ 42
Lab 3-2 RIPv2 Route Aggregation and Authentication .................................................................................. 59
Chapter 4 OSPF Configuration .......................................................................................................................... 75
Lab 4-1 OSPF Single-area Configuration ....................................................................................................... 75
Lab 4-2 OSPF Multi-area and Authentication Configuration ......................................................................... 90
Chapter 5 RIP and OSPF Route Import ............................................................................................................ 104
Lab 5-1 RIP and OSPF Route Import ........................................................................................................... 104
Chapter 6 Ethernet and STP ........................................................................................................................... 115
Lab 6-1 Ethernet Interface and Link Configuration ..................................................................................... 115
Lab 6-2 STP Configuration .......................................................................................................................... 122
Lab 6-3 VLAN Configuration ....................................................................................................................... 135
Chapter 7 Layer3 Configuration and VRRP ...................................................................................................... 146
Lab 7-1 Configuring Layer 3 Switching ........................................................................................................ 146
Lab 7-2 Configuring the VRRP .................................................................................................................... 160
Chapter 8 WAN Configuration ........................................................................................................................ 176
Lab 8-1 HDLC and PPP Configuration.......................................................................................................... 176
Lab 8-2 FR Configuration (Back to Back) ..................................................................................................... 192
HUAWEI TECHNOLOGIES
HCDA-HNTD
HUAWEI TECHNOLOGIES
HCDA-HNTD
Restart a router.
HC Series
HUAWEI TECHNOLOGIES
HCDA-HNTD
Topology
Figure 1.1 Lab topology of the basic operations on the VRP platform
Scenario
A company purchases two AR G3 routers. You need to commission
the two AR G3 routers before using them. Items to be commissioned
include configuration modes, device names, time, passwords, file
management, and restart operations.
Tasks
Step 1 Connect devices.
This step describes how to connect to a router using the Windows XP
built-in HyperTerminal.
Connect a PC to a router using a console cable. Run a terminal
emulation program such as Windows XP HyperTerminal on the PC to
create a connection, as shown in Figure 3.1. The name and icon provided
in the figure are only examples.Creating a connection.
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
If the PC has multiple COM ports, select a proper one. The serial port
of a PC is usually COM1.Setting port communication parameters.
HC Series
HUAWEI TECHNOLOGIES
HCDA-HNTD
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
......output omit......
Run the display clock command to check that the new system time
has taken effect.
<Huawei>display clock
2011-09-15 12:00:21
Thursday
Time Zone(Default Zone Name) : UTC+00:00
AAA
access-user
accounting-scheme
acl
User access
Accounting scheme
<Group> acl command group
adp-ipv4
Ipv4 information
adp-mpls
Adp-mpls module
anti-attack
arp
arp-limit
atm
authentication-scheme
Authentication scheme
authorization-scheme
If you want to display all the commands that start with a specific letter
HC Series
HUAWEI TECHNOLOGIES
HCDA-HNTD
or string of letters, enter the desired letters and the question mark (?).
The system displays all the commands that start with the letters you
enter. For example, if you enter dis?, the system displays all the
commands that start with dis.
Make sure that there is a space between the string and the question
mark (?). The system identifies the command corresponding to the string
and displays the parameters of the command. For example, if you enter
dis ? and only the display command starts with dis, the system displays
the parameters of the display command. If multiple commands start
with dis, the system displays an error.
You can also press Tab to complete a command. For example, if you
enter dis and press Tab, the system completes the display command. If
multiple commands start with dis, you can select the appropriate one.
If there are no other commands start with the same letters, you can
type dis or disp to indicate display, and int or inter to indicate interface.
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Step 8 Configure
the
login
authentication
mode
and
HC Series
HUAWEI TECHNOLOGIES
HCDA-HNTD
[R1-ui-console0]idle-timeout 20 0
Log out of the system and log back in to verify that you need to enter
the password.
[R1-ui-console0]return
<R1>quit
Configuration console exit, please press any key to log on
Welcome to Huawei certification lab
<R1>
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
Return
: 2011-09-16 17:38:45
0, multicasts:
0, runts:
0, align errors:
0, aborts:
0
0, giants:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
The command output shows that the physical status and protocol
status of the interface are UP, and the corresponding physical layer and
data link layer are functional.
The interface link cables are V.35 DCE.
Once you have verified the status, configure the IP address and
description for the interface of R2.
HC Series
HUAWEI TECHNOLOGIES
HCDA-HNTD
Step 10
10
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
user-interface vty 16 20
#
Return
Note: You can run the quit command to return to the previous view
or the return command to return to the user view.
[R2]aaa
[R2-aaa]local-user huawei password simple huawei
[R2-aaa]local-user huawei privilege level 15
[R2-aaa]local-user huawei service-type telnet
HC Series
HUAWEI TECHNOLOGIES
11
HCDA-HNTD
Login authentication
Username:huawei
Password:
---------------------------------------------------------------------------User last login information:
---------------------------------------------------------------------------Access Type: Telnet
IP-Address : 10.0.12.1
Time
: 2011-09-14 13:19:59+00:00
---------------------------------------------------------------------------<R2>
Step 11
When there are low user rights, for example, the value of user
privilege level is 0 or 1 for the telnet login, you can use the super
command to increase the user rights. To minimize risks caused by illegal
right elevations, set super passwords.
Set a super password for R1. The super password is stored in simple
(plain text) mode.
12
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Step 12
Run the dir command in the user view to display the list of files in the
current directory.
<R1>dir
Directory of sd1:/
Idx Attr
Size(Byte) Date
Time(LMT) FileName
0 -rw-
1 -rw-
HC Series
web.zip
ar2220_V200R001C01SPC300.cc
HUAWEI TECHNOLOGIES
13
HCDA-HNTD
Size(Byte) Date
Time(LMT) FileName
0 -rw-
1 -rw-
web.zip
ar2220_V200R001C01SPC300.cc
Step 13
using FTP.
Routers are considered as FTP clients by default. In this lab, R1 is
considered as an FTP client, and R2 is considered as an FTP server.
Enable the FTP server function on R2.
[R2]ftp server enable
Info: Succeeded in starting the FTP server
[R2]set default ftp-directory sd1:/
14
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Note: The source file names on the lab device may be different. You
need to use the actual file name. Run the dir command in the R1 user
view to check the file names in the file list.
Run the dir command to view the result of the transfer.
[R1-ftp]dir
200 Port command okay.
150 Opening ASCII mode data connection for *.
-rwxrwxrwx
1 noone
nogroup
-rwxrwxrwx
1 noone
ar2220_V200R001C01SPC300.cc
-rwxrwxrwx
1 noone
nogroup
Exit from the R2 FTP server and check the file list on R1. Make sure
that the file-from-r2.bak file has been downloaded successfully.
[R1-ftp]quit
221 Server closing.
HC Series
HUAWEI TECHNOLOGIES
15
HCDA-HNTD
<R1>dir
Directory of sd1:/
Idx Attr
Size(Byte) Date
Time(LMT) FileName
0 -rw-
1 -rw-
2 -rw-
web.zip
ar2220_V200R001C01SPC300.cc
file-from-r2.bak
Size(Byte) Date
Time(LMT) FileName
0 -rw-
1 -rw-
2 -rw-
web.zip
ar2220_V200R001C01SPC300.cc
file-from-r1.bak
Size(Byte) Date
Time(LMT) FileName
0 -rw-
1 -rw-
web.zip
ar2220_V200R001C01SPC300.cc
16
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Compare the file list with the preceding file list and make sure that
the file-from-r1.bak file has been deleted.
Delete the file-from-r2.bak file from R1.
<R1>delete /unreserved file-from-r2.bak
Warning: The contents of file sd1:/file-from-r2.bak cannot be recycled. Continue?
(y/n)[n]:y
Info: Deleting file sd1:/file-from-r2.bak...succeed.
<R1>dir
Directory of sd1:/
Idx Attr
Size(Byte) Date
Time(LMT) FileName
0 -rw-
1 -rw-
web.zip
ar2220_V200R001C01SPC300.cc
Step 14
HC Series
HUAWEI TECHNOLOGIES
17
HCDA-HNTD
A router can store multiple configuration files. You can select the
configuration file to be used after the next startup of the router as
required.
<R1>startup saved-configuration iascfg.zip
This operation will take several minutes, please wait.........
Info: Succeeded in setting the file for booting system
<R1>
sd1:/ar2220_V200R001C01SPC300.cc
sd1:/ar2220_V200R001C01SPC300.cc
null
null
sd1:/iascfg.zip
null
null
null
null
null
null
18
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Step 15
Restart a router.
The system asks whether you want to save the current configuration.
Determine whether to save the current configuration based on the
requirements for the lab. If you are unsure whether you should save the
current confirmation, do not save it.
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
tftp client-source -i Serial2/0/0
header shell information "Welcome to Huawei certification lab"
#
voice
HC Series
HUAWEI TECHNOLOGIES
19
HCDA-HNTD
#
http server enable
#
drop illegal-mac alarm
#
l2tp aging 0
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Ethernet3/0/0
#
interface Ethernet3/0/1
#
interface Serial1/0/0
link-protocol ppp
description This interface connect to R2-S2/0/0
ip address 10.0.12.1 255.255.255.0
#
interface Serial2/0/0
link-protocol ppp
#
interface GigabitEthernet0/0/0
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/2
#
interface Cellular0/0/0
link-protocol ppp
#
interface Cellular0/0/1
link-protocol ppp
#
interface NULL0
#
super password level 3 simple huawei
20
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
user-interface con 0
authentication-mode password
set authentication password simple huawei
idle-timeout 10 0
user-interface vty 0 4
user privilege level 3
set authentication password simple huawei
user-interface vty 16 20
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
ftp server enable
set default ftp-directory sd1:/
#
board add 0/1 1SA
board add 0/2 1SA
board add 0/3 2FE
#
voice
#
http server enable
#
drop illegal-mac alarm
#
l2tp aging 0
#
dhcp enable
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
local-user ftpuser password cipher N`C55QK<`=/Q=^Q`MAF4<1!!
local-user ftpuser privilege level 15
local-user ftpuser service-type ftp
HC Series
HUAWEI TECHNOLOGIES
21
HCDA-HNTD
22
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
23
HCDA-HNTD
Topology
Scenario
Assume that you are a network administrator of a company with a
headquarters (HQ) and two branches. R1 is the router in the HQ, and the
HQ has a network segment. R2 and R3 are the routers in the two
branches. R1 is connected to R2 and R3 through the Ethernet and serial
cables. R2 and R3 are connected through serial cables.
Because the network scale is small, static routes and default routes
are used to implement interworking. For the IP addressing information,
see Figure 2.1.
24
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Tasks
Step 16
addresses.
Configure the device names and IP addresses for R1, R2, and R3.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]ip address 10.0.12.1 24
[R1-Serial1/0/0]description this port connect to R2-S1/0/0
[R1-Serial1/0/0]quit
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ip address 10.0.13.1 24
[R1-GigabitEthernet0/0/0]description this port connect to R3-G0/0/0
[R1-GigabitEthernet0/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
HC Series
HUAWEI TECHNOLOGIES
25
HCDA-HNTD
......output omit......
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface serial 1/0/0
[R2-Serial1/0/0]ip address 10.0.12.2 24
[R2-Serial1/0/0]description this port connect to R1-S1/0/0
[R2-Serial1/0/0]interface serial 2/0/0
[R2-Serial2/0/0]ip address 10.0.23.2 24
[R2-Serial2/0/0]description this port connect to R3-S2/0/0
[R2-Serial2/0/0]interface loopback0
[R2-LoopBack0]ip address 10.0.2.2 24
[R2-LoopBack0]display current-configuration
......output omit......
interface Serial1/0/0
link-protocol ppp
description this port connect to R1-S1/0/0
ip address 10.0.12.2 255.255.255.0
#
interface Serial2/0/0
link-protocol ppp
description this port connect to R3-S2/0/0
ip address 10.0.23.2 255.255.255.0
#
......output omit......
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface Serial 2/0/0
[R3-Serial2/0/0]ip address 10.0.23.3 24
[R3-Serial2/0/0]description this port connect to R2-S2/0/0
[R3-Serial2/0/0]quit
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]ip address 10.0.13.3 24
[R3-GigabitEthernet0/0/0]description this port connect to R1-G0/0/0
[R3-GigabitEthernet0/0/0]interface loopback 0
[R3-LoopBack0]ip address 10.0.3.3 24
[R3-LoopBack0]display current-configuration
26
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
......output omit......
#
interface Serial2/0/0
link-protocol ppp
description this port connect to R2-S2/0/0
ip address 10.0.23.3 255.255.255.0
#
interface GigabitEthernet0/0/0
description this port connect to R1-G0/0/0
ip address 10.0.13.3 255.255.255.0
#
......output omit......
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
......output omit......
HC Series
HUAWEI TECHNOLOGIES
27
HCDA-HNTD
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 2/2/6 ms
<R2>ping 10.0.23.3
PING 10.0.23.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.23.3: bytes=56 Sequence=1 ttl=255 time=31 ms
Reply from 10.0.23.3: bytes=56 Sequence=2 ttl=255 time=31 ms
Reply from 10.0.23.3: bytes=56 Sequence=3 ttl=255 time=41 ms
Reply from 10.0.23.3: bytes=56 Sequence=4 ttl=255 time=31 ms
Reply from 10.0.23.3: bytes=56 Sequence=5 ttl=255 time=41 ms
--- 10.0.23.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/35/41 ms
Step 17
10.0.3.0/24.
[R2]ping 10.0.13.3
PING 10.0.13.3: 56 data bytes, press CTRL_C to break
Request time out
Request time out
Request time out
Request time out
Request time out
--- 10.0.13.3 ping statistics --5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
[R2]ping 10.0.3.3
PING 10.0.3.3: 56 data bytes, press CTRL_C to break
Request time out
Request time out
Request time out
Request time out
28
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Proto
Routes : 15
Pre Cost
Flags NextHop
Interface
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.0/8
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
29
HCDA-HNTD
Step 18
Step 19
30
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Step 20
Proto
Routes : 17
Pre Cost
Flags NextHop
Interface
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
Static 60
RD
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.0/24 Static 60
RD
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.3.0/24
127.0.0.0/8
10.0.23.3
10.0.23.3
Serial2/0/0
Serial2/0/0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
The routing table contains two static routes that are configured in
step 3. The value of the Proto field is Static, indicating a static route. The
value of the Pre field is 60, indicating the default preference of a route.
Test network connectivity when the link between R2 and R3 works
properly.
[R2]ping 10.0.13.3
PING 10.0.13.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.13.3: bytes=56 Sequence=1 ttl=255 time=34 ms
Reply from 10.0.13.3: bytes=56 Sequence=2 ttl=255 time=34 ms
Reply from 10.0.13.3: bytes=56 Sequence=3 ttl=255 time=34 ms
Reply from 10.0.13.3: bytes=56 Sequence=4 ttl=255 time=34 ms
Reply from 10.0.13.3: bytes=56 Sequence=5 ttl=255 time=34 ms
HC Series
HUAWEI TECHNOLOGIES
31
HCDA-HNTD
31 ms 30 ms
<R2>tracert 10.0.3.3
traceroute to
30 ms 30 ms
Step 21
32
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Compare the routing tables with the previous routing tables before
Serial2/0/0 was disabled.
[R2]int Serial 2/0/0
[R2-Serial2/0/0]shutdown
[R2-Serial2/0/0]quit
[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 13
Destination/Mask
Proto
Routes : 13
Pre Cost
Flags NextHop
Interface
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
Static 80
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.3.0/24
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.0/24 Static 80
10.0.12.2
Serial1/0/0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
The next hops and preferences of the two routes in the preceding
information are changed.
Test connectivity between R2 and the destination addresses 10.0.13.3
and 10.0.3.3 on R2.
<R2>ping 10.0.3.3
PING 10.0.3.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.3.3: bytes=56 Sequence=1 ttl=255 time=3 ms
Reply from 10.0.3.3: bytes=56 Sequence=2 ttl=255 time=2 ms
Reply from 10.0.3.3: bytes=56 Sequence=3 ttl=255 time=2 ms
Reply from 10.0.3.3: bytes=56 Sequence=4 ttl=255 time=2 ms
Reply from 10.0.3.3: bytes=56 Sequence=5 ttl=255 time=2 ms
--- 10.0.3.3 ping statistics --5 packet(s) transmitted
HC Series
HUAWEI TECHNOLOGIES
33
HCDA-HNTD
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 2/2/3 ms
<R2>ping 10.0.13.3
PING 10.0.13.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.13.3: bytes=56 Sequence=1 ttl=255 time=3 ms
Reply from 10.0.13.3: bytes=56 Sequence=2 ttl=255 time=2 ms
Reply from 10.0.13.3: bytes=56 Sequence=3 ttl=255 time=2 ms
Reply from 10.0.13.3: bytes=56 Sequence=4 ttl=255 time=2 ms
Reply from 10.0.13.3: bytes=56 Sequence=5 ttl=255 time=2 ms
--- 10.0.13.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 2/2/3 ms
to break
1 10.0.12.1 40 ms
21 ms 21 ms
2 10.0.13.3 30 ms
21 ms 21 ms
<R2>tracert 10.0.3.3
traceroute to
to break
1 10.0.12.1 40 ms
21 ms 21 ms
2 10.0.13.3 30 ms
21 ms 21 ms
34
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Step 22
network connectivity.
Enable the interface that was disabled in step 6 on R2.
[R2]int Serial 2/0/0
[R2-Serial2/0/0]undo shutdown
HC Series
HUAWEI TECHNOLOGIES
35
HCDA-HNTD
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 2/2/3 ms
Step 23
Step 24
Proto
Routes : 16
Pre Cost
Flags NextHop
0.0.0.0/0
Static 60
RD
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
Static 60
RD
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.0/24 Direct 0
10.0.13.1
GigabitEthernet0/0/0
10.0.13.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.3.0/24
36
10.0.13.3
Interface
10.0.13.3
HUAWEI TECHNOLOGIES
GigabitEthernet0/0/0
GigabitEthernet0/0/0
HC Series
HCDA-HNTD
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Proto
Routes : 12
Pre Cost
Flags NextHop
0.0.0.0/0
Static 80
RD
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
10.0.12.2
Interface
Serial1/0/0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
37
HCDA-HNTD
to break
1 10.0.12.2 30 ms
26 ms 26 ms
2 10.0.23.3 60 ms
53 ms 56 ms
38
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Preference
Direct
OSPF
10
IS-IS
15
Static
60
RIP
100
OSPF ASE
150
BGP
255
Final Configurations
<R1>display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface Serial1/0/0
link-protocol ppp
description this port connect to R2-S1/0/0
ip address 10.0.12.1 255.255.255.0
#
interface GigabitEthernet0/0/0
description this port connect to R3-G0/0/0
ip address 10.0.13.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.13.3
ip route-static 0.0.0.0 0.0.0.0 10.0.12.2 preference 80
ip route-static 10.0.3.0 255.255.255.0 10.0.13.3
HC Series
HUAWEI TECHNOLOGIES
39
HCDA-HNTD
#
return
<R2>display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
interface Serial1/0/0
link-protocol ppp
description this port connect to R1-S1/0/0
ip address 10.0.12.2 255.255.255.0
#
interface Serial2/0/0
link-protocol ppp
description this port connect to R3-S2/0/0
ip address 10.0.23.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ip route-static 10.0.3.0 255.255.255.0 10.0.23.3
ip route-static 10.0.3.0 255.255.255.0 Serial1/0/0 preference 80
ip route-static 10.0.13.0 255.255.255.0 10.0.23.3
ip route-static 10.0.13.0 255.255.255.0 Serial1/0/0 preference 80
#
return
<R3>display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface Serial2/0/0
link-protocol ppp
description this port connect to R2-S2/0/0
ip address 10.0.23.3 255.255.255.0
#
interface GigabitEthernet0/0/0
description this port connect to R1-G0/0/0
ip address 10.0.13.3 255.255.255.0
#
interface LoopBack0
40
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
41
HCDA-HNTD
42
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
Scenario
Assume that you are a network administrator of a company that has a
small intranet with three routers and five networks. You want to use RIP
to transfer routing information. Considering compatibility, you want to
use RIPv1 at first, but you realize that RIPv2 also has many advantages.
After certain tests, you finally select RIPv2.
HC Series
HUAWEI TECHNOLOGIES
43
HCDA-HNTD
Tasks
Step 1 Perform basic configurations and IP addressing.
Configure basic device information and set IP addresses based on the
topology.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]ip address 10.0.12.1 24
[R1-Serial1/0/0]description this port connect to R2-S1/0/0
[R1-Serial1/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
[R1-LoopBack0]quit
44
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
45
HCDA-HNTD
Enable RIP on R2, and then advertise the 10.0.0.0 network segment to
RIP.
46
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R2]rip 1
[R2-rip-1]network 10.0.0.0
Enable RIP on R3, and then advertise the 10.0.0.0 network segment to
RIP.
[R3]rip 1
[R3-rip-1]net 10.0.0.0
Proto
Routes : 14
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.3.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.12.2
Serial1/0/0
10.0.23.0/24 RIP
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 17
HC Series
Routes : 17
HUAWEI TECHNOLOGIES
47
HCDA-HNTD
Destination/Mask
Proto
Pre Cost
10.0.1.0/24
RIP
10.0.2.0/24
Direct 0
10.0.2.2/32
10.0.2.255/32
10.0.3.0/24
Interface
10.0.12.1
Serial1/0/0
10.0.2.2
LoopBack0
Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
RIP
100 1
Flags NextHop
100 1
10.0.23.3
Serial2/0/0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
[R3]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Proto
Routes : 14
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 2
10.0.23.2
Serial2/0/0
10.0.2.0/24
RIP
100 1
10.0.23.2
Serial2/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.23.2
Serial2/0/0
10.0.12.0/24 RIP
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
48
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
You can run the debug command to view RIP periodic updates.
Run the debug command to enable the RIP debugging function. The
debug command can be used only in the user view. Then run the
terminal debugging and terminal monitor commands to display the
debugging information.
The information about RIP interactions between routers is displayed.
<R1>debug rip 1
<R1>terminal debugging
Info: Current terminal debugging is on.
<R1>terminal monitor
Info: Current terminal monitor is on.
Sep 19 2011 19:15:22.630.1+00:00 R1 RM/6/RMDEBUG: 6: 11647: RIP 1: Receiving v1
response on Serial1/0/0 from 10.0.12.2 with 2 RTEs
Sep 19 2011 19:15:22.630.2+00:00 R1 RM/6/RMDEBUG: 6: 11698: RIP 1: Receive response
from 10.0.12.2 on Serial1/0/0
Sep 19 2011 19:15:22.630.3+00:00 R1 RM/6/RMDEBUG: 6: 11709: Packet: Version 1,
Cmd response, Length 44
Sep 19 2011 19:15:22.630.4+00:00 R1 RM/6/RMDEBUG: 6: 11758: Dest 10.0.3.0, Cost
2
Sep 19 2011 19:15:22.630.5+00:00 R1 RM/6/RMDEBUG: 6: 11758: Dest 10.0.23.0, Cost
1
Sep 19 2011 19:15:52.650.1+00:00 R1 RM/6/RMDEBUG: 6: 11647: RIP 1: Receiving v1
response on Serial1/0/0 from 10.0.12.2 with 2 RTEs
Sep 19 2011 19:15:52.650.2+00:00 R1 RM/6/RMDEBUG: 6: 11698: RIP 1: Receive response
HC Series
HUAWEI TECHNOLOGIES
49
HCDA-HNTD
You can run the undo debug rip or undo debug all command to
disable debugging functions.
<R1>undo debug rip 1
In addition, you can run the commands that have more parameters to
view the debugging information of a certain type. For example, run the
debug rip 1 event command to view the periodical update events sent
or received by routers. You can add the question mark (?) to the
command to query other parameters.
<R1>debug rip 1 event
Sep 19 2011 19:23:44.200.1+00:00 R1 RM/6/RMDEBUG: 25: 3873: RIP 1: Periodic timer
expired for interface Serial1/0/0 (10.0.12.1) and its added to periodic update
queue
Sep 19 2011 19:23:44.210.1+00:00 R1 RM/6/RMDEBUG: 25: 4201: RIP 1: Interface
Serial1/0/0 (10.0.12.1) is deleted from the periodic update queue
<R1>undo debug all
Info: All possible debugging has been turned off
50
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3]rip 1
[R3-rip-1]version 2
Proto
Routes : 14
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.3.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.12.2
Serial1/0/0
10.0.23.0/24 RIP
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 17
Destination/Mask
10.0.1.0/24
HC Series
Proto
RIP
Routes : 17
Pre Cost
100 1
Flags NextHop
D
10.0.12.1
HUAWEI TECHNOLOGIES
Interface
Serial1/0/0
51
HCDA-HNTD
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
[R3]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Proto
Routes : 14
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 2
10.0.23.2
Serial2/0/0
10.0.2.0/24
RIP
100 1
10.0.23.2
Serial2/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.23.2
Serial2/0/0
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 RIP
127.0.0.0/8
100
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Note: The route learning of RIPv1 is the same of the route learning of
RIPv2. Why is this true?
52
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
You can run the debug command to view the RIPv2 periodic updates.
<R1>terminal debugging
Info: Current terminal debugging is on.
<R1>terminal monitor
Info: Current terminal monitor is on.
<R1>debug rip 1 event
Sep 19 2011 19:55:46.600.1+00:00 R1 RM/6/RMDEBUG: 25: 3873: RIP 1: Periodic timer
expired for interface Serial1/0/0 (10.0.12.1) and its added to periodic update
queue
Sep 19 2011 19:55:46.610.1+00:00 R1 RM/6/RMDEBUG: 25: 4201: RIP 1: Interface
Serial1/0/0 (10.0.12.1) is deleted from the periodic update queue
<R1>undo debug rip 1
<R1>debug rip 1 packet
Sep 19 2011 20:31:34.230.1+00:00 R1 RM/6/RMDEBUG: 6: 11689: RIP 1: Sending response
on interface Serial1/0/0 from 10.0.12.1 to 224.0.0.9
Sep 19 2011 20:31:34.230.2+00:00 R1 RM/6/RMDEBUG: 6: 11709: Packet: Version 2,
Cmd response, Length 24
Sep 19 2011 20:31:34.230.3+00:00 R1 RM/6/RMDEBUG: 6: 11777: Dest 10.0.1.0/24,
Nexthop 0.0.0.0, Cost 1, Tag 0
<R1>undo debug all
Info: All possible debugging has been turned off
HUAWEI TECHNOLOGIES
53
HCDA-HNTD
Import the static route to the RIP routing information so that R1 can
communicate with 172.16.3.3.
Configure the loopback interface on R3.
[R3]interface LoopBack 1
[R3-LoopBack1]ip address 172.16.3.3 24
54
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Proto
Routes : 15
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
Direct 0
10.0.1.255/32
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.3.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.12.2
Serial1/0/0
10.0.23.0/24 RIP
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
172.16.3.0/24
RIP
100 1
255.255.255.255/32 Direct 0
D
D
127.0.0.1
10.0.12.2
127.0.0.1
InLoopBack0
Serial1/0/0
InLoopBack0
[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 18
Destination/Mask
Proto
Routes : 18
Pre Cost
10.0.1.0/24
RIP
10.0.2.0/24
Direct 0
10.0.2.2/32
10.0.2.255/32
10.0.3.0/24
Interface
10.0.12.1
Serial1/0/0
10.0.2.2
LoopBack0
Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
RIP
100 1
Flags NextHop
100 1
10.0.23.3
Serial2/0/0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
HC Series
HUAWEI TECHNOLOGIES
55
HCDA-HNTD
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
172.16.3.0/24
Static 60
0
0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
RD
10.0.23.3
Serial2/0/0
127.0.0.1
InLoopBack0
[R3]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 17
Destination/Mask
Proto
Routes : 17
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 2
10.0.23.2
Serial2/0/0
10.0.2.0/24
RIP
100 1
10.0.23.2
Serial2/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.23.2
Serial2/0/0
10.0.12.0/24 RIP
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
172.16.3.0/24
Direct 0
172.16.3.3
LoopBack1
172.16.3.3/32
Direct 0
127.0.0.1
InLoopBack0
172.16.3.255/32
Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
56
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 63/69/74 ms
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface Serial1/0/0
link-protocol ppp
description this port connect to R2-S1/0/0
ip address 10.0.12.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
rip 1
version 2
network 10.0.0.0
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
HC Series
HUAWEI TECHNOLOGIES
57
HCDA-HNTD
interface Serial1/0/0
link-protocol ppp
description this port connect to R1-S1/0/0
ip address 10.0.12.2 255.255.255.0
#
interface Serial2/0/0
link-protocol ppp
description this port connect to R3-S2/0/0
ip address 10.0.23.2 255.255.255.0
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
rip 1
version 2
network 10.0.0.0
import-route static
#
ip route-static 172.16.3.0 255.255.255.0 10.0.23.3
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface Serial2/0/0
link-protocol ppp
description this port connects to R2-S2/0/0
ip address 10.0.23.3 255.255.255.0
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
interface LoopBack1
ip address 172.16.3.3 255.255.255.0
#
rip 1
version 2
network 10.0.0.0
#
return
58
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
HC Series
HUAWEI TECHNOLOGIES
59
HCDA-HNTD
Scenario
Assume that you are a network engineer of a company. The company
is small; therefore, RIPv2 is used. There are too many routes; therefore,
route aggregation is required to control and advertise routes.
Malicious attackers may forge a valid router to receive and modify
valid routes, so RIPv2 authentication is used to protect the network.
Tasks
Step 1 Configure IP addresses for interfaces.
Configure device names and IP addresses for R1, R2, and R3.
<Huawei>system
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]ip address 10.0.12.1 24
[R1- Serial1/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface serial 1/0/0
[R2-Serial1/0/0]ip address 10.0.12.2 24
[R2-Serial1/0/0]interface serial 2/0/0
[R2-Serial2/0/0]ip address 10.0.23.2 24
[R2-Serial2/0/0]interface loopback0
[R2-LoopBack0]ip address 10.0.2.2 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface Serial 2/0/0
[R3-Serial2/0/0]ip address 10.0.23.3 24
[R3- Serial2/0/0]interface loopback0
[R3-LoopBack0]ip address 10.0.3.3 24
60
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3-LoopBack0]interface loopback 2
[R3-LoopBack2]ip address 172.16.0.1 24
[R3-LoopBack2]interface loopback 3
[R3-LoopBack3]ip address 172.16.1.1 24
[R3-LoopBack3]interface loopback 4
[R3-LoopBack4]ip address 172.16.2.1 24
[R3-LoopBack4]interface loopback 5
[R3-LoopBack5]ip address 172.16.3.1 24
After you have configured the IP addresses for the interfaces, test
network connectivity.
<R1>ping 10.0.12.2
PING 10.0.12.2: 56 data bytes, press CTRL_C to break
Reply from 10.0.12.2: bytes=56 Sequence=1 ttl=255 time=30 ms
Reply from 10.0.12.2: bytes=56 Sequence=2 ttl=255 time=30 ms
Reply from 10.0.12.2: bytes=56 Sequence=3 ttl=255 time=30 ms
Reply from 10.0.12.2: bytes=56 Sequence=4 ttl=255 time=30 ms
Reply from 10.0.12.2: bytes=56 Sequence=5 ttl=255 time=30 ms
--- 10.0.12.2 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 30/30/30 ms
<R2>ping 10.0.23.3
PING 10.0.23.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.23.3: bytes=56 Sequence=1 ttl=255 time=31 ms
Reply from 10.0.23.3: bytes=56 Sequence=2 ttl=255 time=31 ms
Reply from 10.0.23.3: bytes=56 Sequence=3 ttl=255 time=41 ms
Reply from 10.0.23.3: bytes=56 Sequence=4 ttl=255 time=31 ms
Reply from 10.0.23.3: bytes=56 Sequence=5 ttl=255 time=41 ms
--- 10.0.23.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/35/41 ms
HC Series
HUAWEI TECHNOLOGIES
61
HCDA-HNTD
Proto
Routes : 18
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.3.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.12.2
Serial1/0/0
10.0.23.0/24 RIP
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
172.16.0.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
172.16.1.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
172.16.2.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
62
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
172.16.3.0/24
RIP
100 2
255.255.255.255/32 Direct 0
10.0.12.2
Serial1/0/0
127.0.0.1
InLoopBack0
The information in grey shows that R1 has learned specific routes but
not aggregated routes.
Test network connectivity.
<R1>ping 172.16.0.1
PING 172.16.0.1: 56
Proto
Routes : 15
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
63
HCDA-HNTD
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.3.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.12.2
Serial1/0/0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
10.0.12.2
Serial1/0/0
127.0.0.1
InLoopBack0
10.0.23.0/24 RIP
127.0.0.0/8
Direct 0
127.0.0.1/32 Direct 0
127.255.255.255/32 Direct 0
172.16.0.0/16
RIP
100 2
255.255.255.255/32 Direct 0
64
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Proto
Routes : 15
Pre Cost
Flags NextHop
Interface
10.0.1.0/24 Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.3.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.12.2
Serial1/0/0
10.0.23.0/24 RIP
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
10.0.12.2
Serial1/0/0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
172.16.0.0/16
RIP
100 2
255.255.255.255/32 Direct 0
<R2>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 21
Destination/Mask
HC Series
Proto
Routes : 21
Pre Cost
Flags NextHop
HUAWEI TECHNOLOGIES
Interface
65
HCDA-HNTD
10.0.1.0/24
RIP
10.0.2.0/24
Direct 0
10.0.2.2/32
10.0.2.255/32
10.0.3.0/24
10.0.12.1
Serial1/0/0
10.0.2.2
LoopBack0
Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
10.0.23.3
Serial2/0/0
RIP
100 1
100 1
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
172.16.0.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
172.16.1.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
172.16.2.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
172.16.3.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
<R3>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 26
Destination/Mask
Proto
Routes : 26
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 2
10.0.23.2
Serial2/0/0
10.0.2.0/24
RIP
100 1
10.0.23.2
Serial2/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.23.2
Serial2/0/0
10.0.12.0/24 RIP
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
66
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
172.16.0.0/24
Direct 0
172.16.0.1
LoopBack2
172.16.0.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.0.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.1.0/24
Direct 0
172.16.1.1
LoopBack3
172.16.1.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.1.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.2.0/24
Direct 0
172.16.2.1
LoopBack4
172.16.2.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.2.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.3.0/24
Direct 0
172.16.3.1
LoopBack5
172.16.3.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.3.255/32
Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Proto
Routes : 11
Pre
Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
67
HCDA-HNTD
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Proto
Routes : 23
Pre
Cost
Flags NextHop
Interface
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
68
127.0.0.1
HUAWEI TECHNOLOGIES
InLoopBack0
HC Series
HCDA-HNTD
172.16.0.0/24
Direct 0
172.16.0.1
LoopBack2
172.16.0.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.0.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.1.0/24
Direct 0
172.16.1.1
LoopBack3
172.16.1.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.1.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.2.0/24
Direct 0
172.16.2.1
LoopBack4
172.16.2.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.2.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.3.0/24
Direct 0
172.16.3.1
LoopBack5
172.16.3.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.3.255/32
Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Verify that routes in routing tables of R1, R2, and R3 are correct.
<R1>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 15
Destination/Mask
Proto
Routes : 15
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
Direct 0
10.0.1.255/32
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.3.0/24
RIP
100 2
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.12.2
Serial1/0/0
10.0.23.0/24 RIP
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
69
HCDA-HNTD
127.255.255.255/32 Direct 0
172.16.0.0/16
RIP
100
0
2
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2
Serial1/0/0
127.0.0.1
InLoopBack0
<R2>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 21
Destination/Mask
Proto
Routes : 21
Pre Cost
10.0.1.0/24
RIP
10.0.2.0/24
Direct 0
10.0.2.2/32
10.0.2.255/32
10.0.3.0/24
Interface
10.0.12.1
Serial1/0/0
10.0.2.2
LoopBack0
Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
10.0.23.3
Serial2/0/0
RIP
100 1
Flags NextHop
100 1
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
172.16.0.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
172.16.1.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
172.16.2.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
172.16.3.0/24
RIP
100 1
10.0.23.3
Serial2/0/0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
<R3>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 26
Destination/Mask
70
Proto
Routes : 26
Pre Cost
Flags NextHop
HUAWEI TECHNOLOGIES
Interface
HC Series
HCDA-HNTD
10.0.1.0/24
RIP
100 2
10.0.23.2
Serial2/0/0
10.0.2.0/24
RIP
100 1
10.0.23.2
Serial2/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.23.2
Serial2/0/0
10.0.12.0/24 RIP
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
172.16.0.0/24
Direct 0
172.16.0.1
LoopBack2
172.16.0.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.0.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.1.0/24
Direct 0
172.16.1.1
LoopBack3
172.16.1.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.1.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.2.0/24
Direct 0
172.16.2.1
LoopBack4
172.16.2.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.2.255/32
Direct 0
127.0.0.1
InLoopBack0
172.16.3.0/24
Direct 0
172.16.3.1
LoopBack5
172.16.3.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.3.255/32
Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Appendix A:
Routers
<Huawei>debugging rip 1 ?
brief
error
event
HC Series
HUAWEI TECHNOLOGIES
71
HCDA-HNTD
packet
receive
route-processing
send
timer
<cr>
Final Configurations
<R1>display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface Serial1/0/0
link-protocol ppp
ip address 10.0.12.1 255.255.255.0
rip authentication-mode simple huawei
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
rip 1
version 2
network 10.0.0.0
#
Return
<R2>display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
interface Serial1/0/0
link-protocol ppp
ip address 10.0.12.2 255.255.255.0
rip authentication-mode simple huawei
rip summary-address 172.16.0.0 255.255.0.0
#
72
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
interface Serial2/0/0
link-protocol ppp
ip address 10.0.23.2 255.255.255.0
rip authentication-mode md5 usual gg^dP=F.[>=H)H2[EInB~.2#
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
rip 1
version 2
network 10.0.0.0
#
return
<R3>display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface Serial2/0/0
link-protocol ppp
ip address 10.0.23.3 255.255.255.0
rip authentication-mode md5 usual gg^dP=F.[>=H)H2[EInB~.2#
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
interface LoopBack2
ip address 172.16.0.1 255.255.255.0
#
interface LoopBack3
ip address 172.16.1.1 255.255.255.0
#
interface LoopBack4
ip address 172.16.2.1 255.255.255.0
#
interface LoopBack5
ip address 172.16.3.1 255.255.255.0
#
rip 1
version 2
network 10.0.0.0
HC Series
HUAWEI TECHNOLOGIES
73
HCDA-HNTD
network 172.16.0.0
#
Return
74
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Router ID usage.
Method used to change the OSPF hello interval and dead interval.
HC Series
HUAWEI TECHNOLOGIES
75
HCDA-HNTD
Topology
Scenario
Assume that you are a network administrator of a company. The
company will use OSPF to exchange routes. All the routers belong to
OSPF area 0. OSPF is required to advertise default routes and the DR or
BDR will be elected.
Tasks
Step 1 Configure IP addresses for interfaces.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface serial1/0/0
76
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HUAWEI TECHNOLOGIES
77
HCDA-HNTD
Proto
Routes : 16
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.2/32
OSPF
10
1562 D
10.0.12.2
Serial1/0/0
10.0.3.3/32
OSPF
10
10.0.13.3
GigabitEthernet0/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.0/24 Direct 0
10.0.13.1
GigabitEthernet0/0/0
10.0.13.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
78
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
<R2>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Proto
Routes : 14
Pre Cost
Interface
10.0.1.1/32
OSPF
1562
10.0.12.1
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
OSPF
1563
10.0.12.1
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
1563
10.0.12.1
Serial1/0/0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.3.3/32
10.0.13.0/24 OSPF
127.0.0.0/8
10
Flags NextHop
10
10
Serial1/0/0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
<R3>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 16
Destination/Mask
Proto
Routes : 16
Pre Cost
Flags NextHop
Interface
10.0.1.1/32
OSPF
10
10.0.13.1
GigabitEthernet0/0/0
10.0.2.2/32
OSPF
10
1563 D
10.0.13.1
GigabitEthernet0/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
1563 D
10.0.13.1
GigabitEthernet0/0/0
10.0.13.0/24 Direct 0
10.0.13.3
GigabitEthernet0/0/0
10.0.13.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
10.0.12.0/24 OSPF
127.0.0.0/8
10
79
HCDA-HNTD
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
172.16.0.0/24
Direct 0
172.16.0.1
LoopBack2
172.16.0.1/32
Direct 0
127.0.0.1
InLoopBack0
172.16.0.255/32
Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
80
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Routes : 2
Proto
Routes : 2
Pre Cost
Flags NextHop
Interface
10.0.2.2/32
OSPF
10
1562 D
10.0.12.2
Serial1/0/0
10.0.3.3/32
OSPF
10
10.0.13.3
GigabitEthernet0/0/0
Routes : 0
Run the display ospf peer command to view the OSPF neighbor
status.
[R1]display ospf peer
OSPF Process 1 with Router ID 10.0.1.1
Neighbors
Area 0.0.0.0 interface 10.0.12.1(Serial1/0/0)'s neighbors
Router ID: 10.0.2.2
State: Full
DR: None
Address: 10.0.12.2
BDR: None
MTU: 0
Address: 10.0.13.3
DR: 10.0.13.1
HC Series
HUAWEI TECHNOLOGIES
81
HCDA-HNTD
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Full
0.0.0.0
GigabitEthernet0/0/0
10.0.3.3
Full
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.1.1
Full
Interface
Neighbor id
0.0.0.0
GigabitEthernet0/0/0
10.0.1.1
State
Full
----------------------------------------------------------------------------
82
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Cost: 1
State: DR
Type: Broadcast
MTU: 1500
Priority: 1
Designated Router: 10.0.13.1
Backup Designated Router: 10.0.13.3
Timers: Hello 10 , Dead 40 , Poll 120 , Retransmit 5 , Transmit Delay 1
Run the ospf timer command to change the OSPF hello interval and
dead interval on GE0/0/0 of R1 to 15s and 60s respectively.
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ospf timer hello 15
[R1-GigabitEthernet0/0/0]ospf timer dead 60
[R1-GigabitEthernet0/0/0]display ospf interface GigabitEthernet 0/0/0
OSPF Process 1 with Router ID 10.0.1.1
Interfaces
State: DR
Type: Broadcast
MTU: 1500
Priority: 1
Designated Router: 10.0.13.1
Backup Designated Router: 10.0.13.3
Timers: Hello 15 , Dead 60 , Poll 120 , Retransmit 5 , Transmit Delay 1
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Full
----------------------------------------------------------------------------
The preceding information shows that R1 has only one neighbor, R2.
Because OSPF hello intervals and dead intervals on R1 and R3 are
different, R1 and R3 cannot establish an OSPF neighbor relationship.
Run the ospf timer command to change the OSPF hello interval and
dead interval on GE0/0/0 of R3 to 15s and 60s respectively.
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]ospf timer hello 15
HC Series
HUAWEI TECHNOLOGIES
83
HCDA-HNTD
State: DR
Type: Broadcast
MTU: 1500
Priority: 1
Designated Router: 10.0.13.3
Backup Designated Router: 10.0.13.1
Timers: Hello 15 , Dead 60 , Poll 120 , Retransmit 5 , Transmit Delay 1
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Full
0.0.0.0
GigabitEthernet0/0/0
10.0.3.3
Full
----------------------------------------------------------------------------
View routing tables of R1 and R2. You can see that R1 and R2 have
learned the default routes advertised by R3.
[R1]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
84
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Destinations : 17
Destination/Mask
0.0.0.0/0
Proto
O_ASE
Routes : 17
Pre Cost
150
Flags NextHop
Interface
10.0.13.3
GigabitEthernet0/0/0
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.2/32
OSPF
10
1562 D
10.0.12.2
Serial1/0/0
10.0.3.3/32
OSPF
10
10.0.13.3
GigabitEthernet0/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.0/24 Direct 0
10.0.13.1
GigabitEthernet0/0/0
10.0.13.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 15
Destination/Mask
Proto
Routes : 15
Pre Cost
0.0.0.0/0
O_ASE
150
10.0.1.1/32
OSPF
10
1562
10.0.2.0/24
Direct 0
10.0.2.2/32
10.0.2.255/32
Flags NextHop
10.0.12.1
Serial1/0/0
10.0.12.1
Serial1/0/0
10.0.2.2
LoopBack0
Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
OSPF
1563
10.0.12.1
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.3.3/32
10
10.0.12.255/32 Direct 0
Interface
127.0.0.1
InLoopBack0
1563
10.0.12.1
Serial1/0/0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
10.0.13.0/24 OSPF
127.0.0.0/8
10
85
HCDA-HNTD
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Address: 10.0.13.3
DR: 10.0.13.3
86
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Run the display ospf peer command to view the DR and BDR of R1
and R3.
[R1-GigabitEthernet 0/0/0]display ospf peer 10.0.3.3
OSPF Process 1 with Router ID 10.0.1.1
Neighbors
Area 0.0.0.0 interface 10.0.13.1(GigabitEthernet0/0/0)'s neighbors
Router ID: 10.0.3.3
State: Full
Address: 10.0.13.3
DR: 10.0.13.1
HC Series
HUAWEI TECHNOLOGIES
87
HCDA-HNTD
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface Serial1/0/0
link-protocol ppp
ip address 10.0.12.1 255.255.255.0
#
interface GigabitEthernet0/0/0
ip address 10.0.13.1 255.255.255.0
ospf dr-priority 200
ospf timer hello 15
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
ospf 1 router-id 10.0.1.1
area 0.0.0.0
network 10.0.1.0 0.0.0.255
network 10.0.13.0 0.0.0.255
network 10.0.12.0 0.0.0.255
#
return
[R2]display current-configuration
[V200R001C01SPC300]
88
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
sysname R2
#
interface Serial1/0/0
link-protocol ppp
ip address 10.0.12.2 255.255.255.0
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ospf 10 router-id 10.0.2.2
area 0.0.0.0
network 10.0.2.0 0.0.0.255
network 10.0.12.0 0.0.0.255
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface GigabitEthernet0/0/0
ip address 10.0.13.3 255.255.255.0
ospf dr-priority 100
ospf timer hello 15
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
interface LoopBack2
ip address 172.16.0.1 255.255.255.0
#
ospf 100 router-id 10.0.3.3
default-route-advertise
area 0.0.0.0
network 10.0.13.0 0.0.0.255
network 10.0.3.0 0.0.0.255
#
ip route-static 0.0.0.0 0.0.0.0 LoopBack2
#
return
HC Series
HUAWEI TECHNOLOGIES
89
HCDA-HNTD
Topology
90
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company. The
company will use OSPF to advertise routes. As the network scale
increases, OSPF multi-area is used to plan the company network. OSPF
authentication is required to ensure security. During this configuration,
you will learn about OSPF LSA types and functions.
Tasks
Step 1 Configure IP addresses for interfaces.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface serial1/0/0
[R1-Serial1/0/0]ip address 10.0.12.1 24
[R1-Serial1/0/0]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ip address 10.0.13.1 24
[R1-GigabitEthernet0/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface serial 1/0/0
[R2-Serial1/0/0]ip address 10.0.12.2 24
[R2-Serial1/0/0]interface loopback 0
[R2-LoopBack0]ip address 10.0.2.2 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]ip address 10.0.13.3 24
[R3-GigabitEthernet0/0/0]interface loopback 0
[R3-LoopBack0]ip address 10.0.3.3 24
[R3-LoopBack0]interface loopback 2
HC Series
HUAWEI TECHNOLOGIES
91
HCDA-HNTD
92
Routes : 2
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Routes : 2
Proto
Pre Cost
Flags NextHop
Interface
10.0.2.2/32 OSPF
10
1562
10.0.12.2
Serial1/0/0
10.0.3.3/32 OSPF
10
10.0.13.3
GigabitEthernet0/0/0
Routes : 0
Routes : 3
Routes : 3
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.1/32
OSPF
10
1562
10.0.12.1
Serial1/0/0
10.0.3.3/32
OSPF
10
1563
10.0.12.1
Serial1/0/0
10.0.13.0/24 OSPF
10
1563
10.0.12.1
Serial1/0/0
Routes : 0
Routes : 3
Routes : 3
Proto
Pre Cost
10.0.1.1/32 OSPF
10
10.0.2.2/32 OSPF
10
1563
10.0.12.0/24 OSPF
10
1563
Flags NextHop
D
D
D
Interface
10.0.13.1
GigabitEthernet0/0/0
10.0.13.1
GigabitEthernet0/0/0
10.0.13.1
GigabitEthernet0/0/0
HC Series
Routes : 0
HUAWEI TECHNOLOGIES
93
HCDA-HNTD
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Full
0.0.0.1
GigabitEthernet0/0/0
10.0.3.3
Full
94
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.1.1
Full
Interface
Neighbor id
0.0.0.1
GigabitEthernet0/0/0
10.0.1.1
State
Full
----------------------------------------------------------------------------
Verify that the OSPF process ID and router ID of each router is correct
and the neighbor relationships are in full state.
View routing tables of R1 and R2. R1 and R2 have learned the route
10.0.3.0/24 and 172.16.0.0/24.
[R1]display ip routing-table protocol ospf
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Public routing table : OSPF
Destinations : 4
Routes : 4
HC Series
Proto
10
Routes : 4
Pre Cost
1562
Flags NextHop
10.0.12.2
HUAWEI TECHNOLOGIES
Interface
Serial1/0/0
95
HCDA-HNTD
10.0.3.0/24 O_ASE
150 1
10.0.13.3
GigabitEthernet0/0/0
10.0.3.3/32 OSPF
10
10.0.13.3
GigabitEthernet0/0/0
172.16.0.0/24 O_ASE
1
150 1
10.0.13.3
GigabitEthernet0/0/0
Routes : 0
Routes : 5
Routes : 5
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.1/32
OSPF
10
1562
10.0.12.1
Serial1/0/0
10.0.3.0/24
O_ASE
150
10.0.12.1
Serial1/0/0
10.0.3.3/32
OSPF
10
1563
10.0.12.1
Serial1/0/0
10.0.13.0/24 OSPF
10
1563
10.0.12.1
Serial1/0/0
10.0.12.1
Serial1/0/0
172.16.0.0/24
O_ASE
150
Routes : 0
The routes in grey are imported routes. The value of Proto is O_ASE,
indicating an external route.
Run the ping command with the source address specified to test
network connectivity.
[R2]ping -a 10.0.2.2 10.0.3.3
PING 10.0.3.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.3.3: bytes=56 Sequence=1 ttl=254 time=35 ms
Reply from 10.0.3.3: bytes=56 Sequence=2 ttl=254 time=33 ms
Reply from 10.0.3.3: bytes=56 Sequence=3 ttl=254 time=33 ms
Reply from 10.0.3.3: bytes=56 Sequence=4 ttl=254 time=33 ms
Reply from 10.0.3.3: bytes=56 Sequence=5 ttl=254 time=33 ms
--- 10.0.3.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
96
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Run the display ospf lsdb command to view the LSDB of R1.
[R1]display ospf lsdb
OSPF Process 1 with Router ID 10.0.1.1
Link State Database
Area: 0.0.0.0
Type
LinkState ID
AdvRouter
Age Len
Sequence
Metric
Router
10.0.2.2
10.0.2.2
908 60
80000003
1562
Router
10.0.1.1
10.0.1.1
918 48
80000003
1562
Sum-Net
10.0.13.0
10.0.1.1
1022 28
80000001
Sum-Net
10.0.3.3
10.0.1.1
720 28
80000001
Sum-Net
10.0.1.1
10.0.1.1
1016 28
80000001
Sum-Asbr
10.0.3.3
10.0.1.1
393 28
80000001
Age Len
Sequence
Metric
Area: 0.0.0.1
Type
LinkState ID
AdvRouter
Router
10.0.3.3
10.0.3.3
394 48
80000005
Router
10.0.1.1
10.0.1.1
719 48
80000006
Network
10.0.13.1
10.0.1.1
719 32
80000002
Sum-Net
10.0.12.0
10.0.1.1
1022 28
80000001
1562
Sum-Net
10.0.2.2
10.0.1.1
908 28
80000001
1562
AS External Database
Type
AdvRouter
Age Len
Sequence
External
LinkState ID
10.0.3.0
10.0.3.3
395 36
80000001
External
10.0.13.0
10.0.3.3
395 36
80000001
HC Series
HUAWEI TECHNOLOGIES
Metric
97
HCDA-HNTD
External
10.0.3.3
395 36
80000001
Type
: Sum-Net
Ls id
: 10.0.3.3
Adv rtr
: 10.0.1.1
Ls age
: 869
Len
: 28
Options
seq#
: 80000001
chksum
: 0x4cf3
: Sum-Asbr
Ls id
: 10.0.3.3
Adv rtr
: 10.0.1.1
Ls age
: 591
Len
: 28
Options
98
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
seq#
: 80000001
chksum
: 0x3e01
Tos 0 metric: 1
Area: 0.0.0.1
Link State Database
[R1]display ospf lsdb ase 172.16.0.0
OSPF Process 1 with Router ID 10.0.1.1
Link State Database
Type
: External
Ls id
: 172.16.0.0
Adv rtr
: 10.0.3.3
Ls age
: 607
Len
: 36
Options
seq#
: 80000001
chksum
: 0xf70c
: 2
: 1
Priority : Low
HC Series
HUAWEI TECHNOLOGIES
99
HCDA-HNTD
Area Id
Interface
Neighbor id
0.0.0.1
GigabitEthernet0/0/0
10.0.3.3
State
Full
----------------------------------------------------------------------------
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Full
0.0.0.1
GigabitEthernet0/0/0
10.0.3.3
Full
----------------------------------------------------------------------------
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Full
----------------------------------------------------------------------------
100
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Full
0.0.0.1
GigabitEthernet0/0/0
10.0.3.3
Full
----------------------------------------------------------------------------
O_ASE
150
10.0.12.1
Serial1/0/0
10.0.3.3/32
OSPF
10
1563
10.0.12.1
Serial1/0/0
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
HC Series
HUAWEI TECHNOLOGIES
101
HCDA-HNTD
interface Serial1/0/0
link-protocol ppp
ip address 10.0.12.1 255.255.255.0
ospf authentication-mode simple plain huawei
#
interface GigabitEthernet0/0/0
ip address 10.0.13.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
ospf 1 router-id 10.0.1.1
area 0.0.0.0
network 10.0.12.0 0.0.0.255
area 0.0.0.1
authentication-mode md5 1 cipher gg^dP=F.[>=H)H2[EInB~.2#
network 10.0.13.0 0.0.0.255
network 10.0.1.0 0.0.0.255
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
interface Serial1/0/0
link-protocol ppp
ip address 10.0.12.2 255.255.255.0
ospf authentication-mode simple plain huawei
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ospf 1 router-id 10.0.2.2
area 0.0.0.0
network 10.0.12.0 0.0.0.255
network 10.0.2.0 0.0.0.255
#
return
[R3]display current-configuration
[V200R001C01SPC300]
102
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
sysname R3
#
interface GigabitEthernet0/0/0
ip address 10.0.13.3 255.255.255.0
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
interface LoopBack2
ip address 172.16.0.1 255.255.255.0
#
ospf 1 router-id 10.0.3.3
import-route direct
area 0.0.0.1
authentication-mode md5 1 cipher gg^dP=F.[>=H)H2[EInB~.2#
network 10.0.3.0 0.0.0.255
network 10.0.13.0 0.0.0.255
#
return
HC Series
HUAWEI TECHNOLOGIES
103
HCDA-HNTD
Topology
104
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company, and the
company network uses RIPv2 and OSPF. RIP needs to import OSPF
routes and OSPF needs to import RIP routes to enable communication
between RIP-enabled devices and OSPF-enabled devices. The metrics of
different routing protocols are different.
Tasks
Step 1 Configure IP addresses for interfaces.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface serial 1/0/0
[R1-Serial1/0/0]ip address 10.0.12.1 24
[R1-Serial1/0/0]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ip address 10.0.13.1 24
[R1-GigabitEthernet0/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface serial1/0/0
[R2-Serial1/0/0]ip address 10.0.12.2 24
[R2-Serial1/0/0]interface loopback 0
[R2-LoopBack0]ip address 10.0.2.2 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]ip address 10.0.13.3 24
[R3-GigabitEthernet0/0/0]interface loopback 0
[R3-LoopBack0]ip address 10.0.3.3 24
[R3-LoopBack0]interface loopback 2
HC Series
HUAWEI TECHNOLOGIES
105
HCDA-HNTD
Routes : 1
Proto
OSPF
Routes : 1
Pre Cost
10
1562
Flags NextHop
D
10.0.12.2
Interface
Serial1/0/0
Routes : 0
106
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Routes : 5
Proto
Routes : 5
Pre Cost
100 1
Flags NextHop
10.0.13.3
Interface
GigabitEthernet0/0/0
172.16.0.0/24 RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
172.16.1.0/24 RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
172.16.2.0/24 RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
172.16.3.0/24 RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
Routes : 0
HC Series
HUAWEI TECHNOLOGIES
107
HCDA-HNTD
Routes : 2
Proto
Routes : 2
Pre Cost
100 1
Flags NextHop
100 1
10.0.13.1
D
Interface
GigabitEthernet0/0/0
10.0.13.1
GigabitEthernet0/0/0
Routes : 0
Proto
Routes : 20
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
108
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
10.0.2.2/32
OSPF
10
1562 D
10.0.3.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.13.3
GigabitEthernet0/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
10.0.13.1
GigabitEthernet0/0/0
10.0.13.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
10.0.13.0/24
127.0.0.0/8
127.255.255.255/32 Direct 0
172.16.0.0/24
RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
172.16.1.0/24
RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
172.16.2.0/24
RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
172.16.3.0/24
RIP
100 1
10.0.13.3
GigabitEthernet0/0/0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
Routes : 7
Proto
Routes : 7
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
O_ASE
150
100
10.0.12.1
Serial1/0/0
10.0.3.0/24
O_ASE
150
100
10.0.12.1
Serial1/0/0
10.0.13.0/24 O_ASE
150
100
10.0.12.1
Serial1/0/0
172.16.0.0/24
O_ASE
150
100
10.0.12.1
Serial1/0/0
172.16.1.0/24
O_ASE
150
100
10.0.12.1
Serial1/0/0
172.16.2.0/24
O_ASE
150 100
10.0.12.1
Serial1/0/0
172.16.3.0/24
O_ASE
150
10.0.12.1
Serial1/0/0
100
HC Series
Routes : 0
HUAWEI TECHNOLOGIES
109
HCDA-HNTD
Routes : 3
Routes : 3
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 1
10.0.13.1
GigabitEthernet0/0/0
10.0.2.2/32
RIP
100 2
10.0.13.1
GigabitEthernet0/0/0
10.0.12.0/24 RIP
100 1
10.0.13.1
GigabitEthernet0/0/0
Routes : 0
110
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Routes : 17
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
OSPF
1562
10.0.12.2
Serial1/0/0
10.0.2.2/32
10.0.3.0/24 RIP
10
100 1
10.0.13.3
GigabitEthernet0/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.13.0/24 Direct 0
10.0.13.1/32 Direct 0
10.0.13.255/32 Direct 0
D
0
10.0.13.1
D
GigabitEthernet0/0/0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
172.16.0.0/22 RIP
100 1
255.255.255.255/32 Direct 0
D
D
127.0.0.1
10.0.13.3
D
127.0.0.1
InLoopBack0
GigabitEthernet0/0/0
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
111
HCDA-HNTD
Destinations : 4
Routes : 4
Routes : 4
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
O_ASE
150
100
10.0.12.1
Serial1/0/0
10.0.3.0/24
O_ASE
150
100
10.0.12.1
Serial1/0/0
10.0.13.0/24 O_ASE
150
100
10.0.12.1
Serial1/0/0
150
100
10.0.12.1
Serial1/0/0
172.16.0.0/22
O_ASE
Routes : 0
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface Serial1/0/0
link-protocol ppp
ip address 10.0.12.1 255.255.255.0
#
interface GigabitEthernet0/0/0
112
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
113
HCDA-HNTD
114
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
Scenario
Assume that you are a network administrator of a company that has
two Huawei S5700 switches. You need to commission the switches. The
Ethernet interface rate and duplex mode will be tested.
HC Series
HUAWEI TECHNOLOGIES
115
HCDA-HNTD
Tasks
Step 1 Perform basic configurations on Ethernet switches.
Auto-negotiation is enabled on Huawei switch interfaces by default.
In this example, the rate and duplex mode of G0/0/9 and G0/0/10 on S1
and S2 are set manually.
Change the system name and view detailed information about
G0/0/9 and G0/0/10 on S1.
<Quidway>system-view
[Quidway]sysname S1
[S1]display interface GigabitEthernet 0/0/9
GigabitEthernet0/0/9 current state : UP
Line protocol current state : UP
Description:HUAWEI, Quidway Series, GigabitEthernet0/0/9 Interface
Switch Port,PVID :
: AUTO
Broadcast
CRC
70,Multicast
6643714,Jumbo
0,Giants
5011357
:
:
0
0
Jabbers
0,Throttles
Runts
0,DropEvents
Alignments
0,Symbols
Ignoreds
0,Frames
Discard
69,Total Error
Broadcast
Collisions
345,Multicast
6642808,Jumbo
0,Deferreds
:
:
Late Collisions:
0,ExcessiveCollisions:
Buffers Purged :
116
5009016
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Discard
5,Total Error
: AUTO
Broadcast
CRC
115,Multicast
6642648,Jumbo
3,Giants
5009062
:
:
0
0
Jabbers
0,Throttles
Runts
0,DropEvents
Alignments
0,Symbols
Ignoreds
0,Frames
Discard
218,Total Error
Broadcast
Collisions
245,Multicast
6643751,Jumbo
0,Deferreds
:
:
Late Collisions:
0,ExcessiveCollisions:
Buffers Purged :
Discard
107,Total Error
5011284
HUAWEI TECHNOLOGIES
117
HCDA-HNTD
Verify the rate and duplex mode of G0/0/9 and G0/0/10 on S1.
[S1]display interface GigabitEthernet 0/0/9
GigabitEthernet0/0/9 current state : UP
Line protocol current state : UP
Description:HUAWEI, Quidway Series, GigabitEthernet0/0/9 Interface
Switch Port,PVID :
: AUTO
output omit
[S1]display interface GigabitEthernet 0/0/10
118
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
: AUTO
output omit
---------------------------------------------------------------------------PortName
Status
Weight
GigabitEthernet0/0/9
Up
GigabitEthernet0/0/10
Up
HC Series
HUAWEI TECHNOLOGIES
119
HCDA-HNTD
[S2]display eth-trunk 1
Eth-Trunk1's state information is:
WorkingMode: NORMAL
---------------------------------------------------------------------------PortName
Status
Weight
GigabitEthernet0/0/9
Up
GigabitEthernet0/0/10
Up
Final Configurations
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
interface Eth-Trunk1
#
interface GigabitEthernet0/0/9
eth-trunk 1
undo negotiation auto
speed 100
#
interface GigabitEthernet0/0/10
eth-trunk 1
undo negotiation auto
speed 100
#
return
[S2]display current-configuration
#
!Software Version V100R006C00SPC800
120
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
sysname S2
#
interface Eth-Trunk1
#
interface GigabitEthernet0/0/9
eth-trunk 1
undo negotiation auto
speed 100
#
interface GigabitEthernet0/0/10
eth-trunk 1
undo negotiation auto
speed 100
#
return
HC Series
HUAWEI TECHNOLOGIES
121
HCDA-HNTD
Topology
122
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company. The
company network consists of two layers: core layer and access layer. The
network uses a redundancy design. STP will be used to prevent loops.
STP has different modes. You can set the bridge priority to control STP
root bridge election, and configure features to speed up STP route
convergence at the edge network.
Tasks
Step 1 Configure STP and verify the STP configuration.
Irrelevant interfaces must be disabled to ensure test result accuracy.
Shut down E0/0/1 on S3 before starting STP configuration. Ensure
that the devices start without any configuration files. If STP is disabled,
run the stp enable command to enable STP.
In the lab, traditional STP is used.
<Quidway>system-view
Enter system view, return user view with Ctrl+Z.
[Quidway]sysname S1
[S1]stp mode stp
[S1]stp root secondary
<Quidway>system-view
Enter system view, return user view with Ctrl+Z.
[Quidway]sysname S2
[S2]stp mode stp
[S2]stp root primary
<Quidway>system-view
Enter system view, return user view with Ctrl+Z.
[Quidway]sysname S3
[S3]stp mode stp
<Quidway>system-view
Enter system view, return user view with Ctrl+Z.
[Quidway]sysname S4
[S4]stp mode stp
HC Series
HUAWEI TECHNOLOGIES
123
HCDA-HNTD
Run the display stp brief command to view brief information about
STP.
[S1]display stp brief
MSTID
Port
Protection
GigabitEthernet0/0/9
ROOT FORWARDING
NONE
GigabitEthernet0/0/10
ALTE DISCARDING
NONE
GigabitEthernet0/0/13
DESI FORWARDING
NONE
GigabitEthernet0/0/14
DESI FORWARDING
NONE
Port
Protection
GigabitEthernet0/0/9
DESI FORWARDING
NONE
GigabitEthernet0/0/10
DESI FORWARDING
NONE
GigabitEthernet0/0/23
DESI FORWARDING
NONE
GigabitEthernet0/0/24
DESI FORWARDING
NONE
Port
Protection
Ethernet0/0/13
ALTE
DISCARDING
NONE
Ethernet0/0/23
ROOT FORWARDING
NONE
Port
Protection
Ethernet0/0/14
ALTE DISCARDING
NONE
Ethernet0/0/24
ROOT FORWARDING
NONE
Run the display stp interface command to view the STP status of a
port.
[S1]display stp interface GigabitEthernet 0/0/10
----[CIST][Port10(GigabitEthernet0/0/10)][DISCARDING]---Port Protocol
Port Role
Port Priority
:enabled
:Alternate Port
:128
Port Cost(Dot1T )
:Config=auto / Active=20000
Desg. Bridge/Port
:0.0018-82e1-aea6 / 128.10
Port Edged
:Config=default / Active=disabled
Point-to-point
:Config=auto / Active=true
Transit Limit
:147 packets/hello-time
Protection Type
:None
124
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Port Stp Mode
:STP
:Config=auto / Active=dot1s
:Hello 2s MaxAge 20s FwDly 15s RemHop 0
:2
TC or TCN received
BPDU Sent
:64
:24
:350601
:0
.0018-82e1-aea6
Bridge Times
CIST Root/ERPC
:0
.0018-82e1-aea6 / 0
CIST RegRoot/IRPC
:0
.0018-82e1-aea6 / 0
CIST RootPortId
:0.0
BPDU-Protection
:disabled
:PRIMARY root
:Nomal
HC Series
HUAWEI TECHNOLOGIES
125
HCDA-HNTD
Run the display stp command to view information about the new
root bridge.
[S1]display stp
-------[CIST Global Info][Mode STP]------CIST Bridge
:4096 .0018-82e1-aea6
Bridge Times
CIST Root/ERPC
:4096 .0018-82e1-aea6 / 0
CIST RegRoot/IRPC
:4096 .0018-82e1-aea6 / 0
CIST RootPortId
:0.0
BPDU-Protection
:disabled
:Nomal
[S2]display stp
-------[CIST Global Info][Mode STP]------CIST Bridge
:8192 .0018-82e1-ae82
Bridge Times
CIST Root/ERPC
CIST RegRoot/IRPC
:8192 .0018-82e1-ae82 / 0
CIST RootPortId
:128.9
BPDU-Protection
:disabled
:Nomal
126
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
:8192 .0018-82e1-ae82
Bridge Times
CIST Root/ERPC
:8192 .0018-82e1-ae82 / 0
CIST RegRoot/IRPC
:8192 .0018-82e1-ae82 / 0
CIST RootPortId
:0.0
BPDU-Protection
:disabled
:Nomal
:4096 .0018-82e1-aea6
Bridge Times
CIST Root/ERPC
:4096 .0018-82e1-aea6 / 0
CIST RegRoot/IRPC
:4096 .0018-82e1-aea6 / 0
CIST RootPortId
:0.0
BPDU-Protection
:disabled
HC Series
HUAWEI TECHNOLOGIES
127
HCDA-HNTD
:Nomal
[S2]display stp
-------[CIST Global Info][Mode STP]------CIST Bridge
:8192 .0018-82e1-ae82
Bridge Times
CIST Root/ERPC
CIST RegRoot/IRPC
:8192 .0018-82e1-ae82 / 0
CIST RootPortId
:128.9
BPDU-Protection
:disabled
:Nomal
Port
Protection
GigabitEthernet0/0/9
ROOT FORWARDING
NONE
GigabitEthernet0/0/10
ALTE DISCARDING
NONE
GigabitEthernet0/0/23
DESI FORWARDING
NONE
GigabitEthernet0/0/24
DESI FORWARDING
NONE
The preceding information shows that G0/0/9 is the root port and
G0/0/10 is the alternate port. You can change port priorities so that
G0/0/10 becomes the root port and G0/0/9 becomes the alternate port.
Change priorities of G0/0/9 and G0/0/10 on S1.
The default port priority is 128. A larger port priority value indicates a
lower priority. The priorities of G0/0/9 and G0/0/10 on S1 are set to 32
128
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Note that the port priorities are changed on S1, not S2.
[S1]display stp interface GigabitEthernet 0/0/9
----[CIST][Port9(GigabitEthernet0/0/9)][FORWARDING]---Port Protocol
:enabled
Port Role
:Designated Port
Port Priority
:32
Port Cost(Dot1T )
:Config=auto / Active=20000
Desg. Bridge/Port
:4096.0018-82e1-aea6 / 32.9
Port Edged
:Config=default / Active=disabled
Point-to-point
:Config=auto / Active=true
Transit Limit
:147 packets/hello-time
Protection Type
:None
:STP
:Config=auto / Active=dot1s
:Hello 2s MaxAge 20s FwDly 15s RemHop 20
:0
TC or TCN received
BPDU Sent
:0
:229
:3
:enabled
:Designated Port
:16
Port Cost(Dot1T )
:Config=auto / Active=20000
Desg. Bridge/Port
:4096.0018-82e1-aea6 / 16.10
Port Edged
:Config=default / Active=disabled
Point-to-point
:Config=auto / Active=true
Transit Limit
:147 packets/hello-time
Protection Type
:None
:STP
HC Series
:Config=auto / Active=dot1s
:Hello 2s MaxAge 20s FwDly 15s RemHop 20
HUAWEI TECHNOLOGIES
129
HCDA-HNTD
TC or TCN send
:0
TC or TCN received
BPDU Sent
:0
:210
:3
Port
Protection
GigabitEthernet0/0/9
ALTE DISCARDING
NONE
GigabitEthernet0/0/10
ROOT FORWARDING
NONE
GigabitEthernet0/0/23
DESI FORWARDING
NONE
GigabitEthernet0/0/24
DESI FORWARDING
NONE
Port
Protection
GigabitEthernet0/0/9
ROOT FORWARDING
NONE
GigabitEthernet0/0/23
DESI FORWARDING
NONE
GigabitEthernet0/0/24
DESI FORWARDING
NONE
130
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Final Configurations
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
vlan batch 1
#
stp mode stp
stp instance 0 priority 4096
stp enable
#
interface GigabitEthernet0/0/9
stp instance 0 port priority 32
ntdp enable
ndp enable
bpdu enable
HC Series
HUAWEI TECHNOLOGIES
131
HCDA-HNTD
#
interface GigabitEthernet0/0/10
stp instance 0 port priority 16
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/13
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/14
ntdp enable
ndp enable
bpdu enable
#
return
[S2]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 1
#
stp mode stp
stp instance 0 priority 8192
stp enable
#
interface GigabitEthernet0/0/9
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/10
shutdown
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/23
132
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/24
ntdp enable
ndp enable
bpdu enable
#
return
[S3]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S3
#
stp mode stp
stp enable
#
interface Ethernet0/0/1
shutdown
bpdu enable
#
interface Ethernet0/0/3
HC Series
HUAWEI TECHNOLOGIES
133
HCDA-HNTD
134
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
VLAN functions.
VLAN security.
VLAN configurations.
Topology
Scenario
Assume that you are a network administrator of a company and need
to configure VLANs on the network. Your company has two switches.
You need to configure VLANs and relevant features.
HC Series
HUAWEI TECHNOLOGIES
135
HCDA-HNTD
Tasks
Step 1 Configure an Eth-Trunk.
Irrelevant interfaces must be disabled to ensure test result accuracy.
In this lab, Ethernet0/0/1 and Ethernet0/0/23 on S3 and
Ethernet0/0/14 on S4 need to be shut down.
Two links exist between S1 and S2. If STP is enabled, one link will be
disabled, which wastes bandwidth. If STP is not used, loops may occur. In
this situation, you can configure an Eth-Trunk.
Before configuring an Eth-Trunk, delete the original configurations
on the member interfaces.
You can add physical interfaces to an Eth-Trunk in the interface view
or in the Eth-Trunk view.
On S1, add interfaces to an Eth-Trunk in the interface view.
<Quidway>system-view
[Quidway]sysname S1
[S1] interface eth-trunk 1
[S1-Eth-Trunk1]quit
[S1]interface gigabitethernet0/0/9
[S1-gigabitethernet0/0/9]eth-trunk 1
[S1-gigabitethernet0/0/9]interface gigabitethernet0/0/10
[S1-gigabitethernet0/0/10]eth-trunk 1
By default, the link type of a interface is hybrid. You can change the
link type to trunk.
By default, a interface of trunk type rejects data from any VLANs.
[S1]interface Eth-Trunk 1
136
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HUAWEI TECHNOLOGIES
137
HCDA-HNTD
<Quidway>system-view
[Quidway]sysname S3
[S3]interface vlanif 1
[S3-vlanif1]ip address 10.0.3.3 24
<Huawei>system-view
[Huawei]sysname R1
[R1]interface GigabitEthernet0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.4.1 24
<Huawei>system-view
[Huawei]sysname R3
[R3]interface GigabitEthernet0/0/2
[R3-GigabitEthernet0/0/2]ip address 10.0.4.3 24
<Quidway>system-view
[Quidway]sysname S4
[S4]interface vlanif 1
[S4-vlanif1]ip address 10.0.5.4 24
138
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
139
HCDA-HNTD
140
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
the interface.
[S1] interface GigabitEthernet0/0/13
[S1-GigabitEthernet0/0/13]undo port default vlan
[S1-GigabitEthernet0/0/13]port link-type hybrid
[S1-GigabitEthernet0/0/13]port hybrid pvid vlan 3
[S1-GigabitEthernet0/0/13]port hybrid untagged vlan 3 to 4
Final Configurations
[S1]display current-configuration
#
HC Series
HUAWEI TECHNOLOGIES
141
HCDA-HNTD
142
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
ntdp enable
ndp enable
bpdu enable
#
interface NULL0
#
return
[S2]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 1 3 to 5
#
interface Vlanif1
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
bpdu enable
#
interface GigabitEthernet0/0/3
port hybrid pvid vlan 4
port hybrid untagged vlan 3 to 4
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/9
eth-trunk 1
undo ntdp enable
undo ndp enable
#
interface GigabitEthernet0/0/10
eth-trunk 1
undo ntdp enable
undo ndp enable
#
interface GigabitEthernet0/0/24
port link-type access
HC Series
HUAWEI TECHNOLOGIES
143
HCDA-HNTD
144
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface GigabitEthernet0/0/2
ip address 10.0.6.4 255.255.255.0
#
return
HC Series
HUAWEI TECHNOLOGIES
145
HCDA-HNTD
Topology
146
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company and the
current network of your company has four users: S3, R1, R3, and S4. The
users belong to different virtual local area networks (VLANs). S3 belongs
to VLAN 3, R1 belongs to VLAN 4, R3 belongs to VLAN 6, and S4 belongs
to VLAN 7. Users in these VLANs can communicate with each other. S1
and S2 communicate with each other through a Layer 3 link, so routing
protocols are used.
Tasks
Step 1 Configure the links between S1 and S2 as Eth-Trunk
links.
Irrelevant interfaces must be disabled to ensure test result accuracy.
In this example, Ethernet0/0/1 and Ethernet0/0/23 of S3 and
Ethernet0/0/14 of S4 must be disabled.
<Quidway>system-view
[Quidway]sysname S1
[S1]interface Eth-Trunk 1
[S1-Eth-Trunk1]quit
[S1]interface GigabitEthernet 0/0/9
[S1-GigabitEthernet0/0/9]eth-trunk 1
[S1-GigabitEthernet0/0/9]interface GigabitEthernet 0/0/10
[S1-GigabitEthernet0/0/10]eth-trunk 1
<Quidway>system-view
[Quidway]sysname S2
[S2]interface Eth-Trunk 1
[S2-Eth-Trunk1]quit
[S2]interface GigabitEthernet 0/0/9
[S2-GigabitEthernet0/0/9]eth-trunk 1
[S2-GigabitEthernet0/0/9]interface GigabitEthernet 0/0/10
[S2-GigabitEthernet0/0/10]eth-trunk 1
HC Series
HUAWEI TECHNOLOGIES
147
HCDA-HNTD
D: Down;
TG: Tagged;
MP: Vlan-mapping;
UT: Untagged;
ST: Vlan-stacking;
#: ProtocolTransparent-vlan;
*: Management-vlan;
---------------------------------------------------------------------------VID Type
Ports
--------------------------------------------------------------------------1
common UT:GE0/0/1(U)
common
common
common
common
common
GE0/0/2(U)
GE0/0/3(U)
GE0/0/4(D)
GE0/0/5(D)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/9(U)
GE0/0/10(U)
GE0/0/11(D)
GE0/0/12(D)
GE0/0/13(U)
GE0/0/14(U)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(U)
GE0/0/22(U)
GE0/0/23(U)
GE0/0/24(D)
--------------------------------------------------------------------------1
enable default
enable disable
VLAN 0001
enable default
enable disable
VLAN 0003
enable default
enable disable
VLAN 0004
enable default
enable disable
VLAN 0005
enable default
enable disable
VLAN 0006
enable default
enable disable
VLAN 0007
148
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[S2]display vlan
The total number of vlans is : 6
---------------------------------------------------------------------------U: Up;
D: Down;
TG: Tagged;
MP: Vlan-mapping;
UT: Untagged;
ST: Vlan-stacking;
#: ProtocolTransparent-vlan;
*: Management-vlan;
---------------------------------------------------------------------------VID Type
Ports
---------------------------------------------------------------------------1
common UT:GE0/0/1(U)
common
common
common
common
common
GE0/0/2(U)
GE0/0/3(U)
GE0/0/4(D)
GE0/0/5(D)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/9(U)
GE0/0/10(U)
GE0/0/11(D)
GE0/0/12(D)
GE0/0/13(D)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(D)
GE0/0/22(D)
GE0/0/23(U)
GE0/0/24(U)
---------------------------------------------------------------------------1
enable default
enable disable
VLAN 0001
enable default
enable disable
VLAN 0003
enable default
enable disable
VLAN 0004
enable default
enable disable
VLAN 0005
enable default
enable disable
VLAN 0006
enable default
enable disable
VLAN 0007
HC Series
HUAWEI TECHNOLOGIES
149
HCDA-HNTD
150
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
151
HCDA-HNTD
[R1]ping 10.0.3.33
PING 10.0.3.33: 56 data bytes, press CTRL_C to break
Reply from 10.0.3.33: bytes=56 Sequence=1 ttl=254 time=16 ms
Reply from 10.0.3.33: bytes=56 Sequence=2 ttl=254 time=5 ms
Reply from 10.0.3.33: bytes=56 Sequence=3 ttl=254 time=4 ms
Reply from 10.0.3.33: bytes=56 Sequence=4 ttl=254 time=4 ms
Reply from 10.0.3.33: bytes=56 Sequence=5 ttl=254 time=4 ms
--- 10.0.3.33 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 4/6/16 ms
to break
1 10.0.4.1 62 ms
2
4 ms 4 ms
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[S1]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 8
Destination/Mask
Routes : 8
Flags NextHop
Interface
10.0.3.0/24
Direct 0
10.0.3.1
10.0.3.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.4.0/24
Direct 0
10.0.4.1
Vlanif4
10.0.4.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.5.0/24
Direct 0
10.0.5.1
Vlanif5
10.0.5.1/32
Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Vlanif3
[S2]ospf 1
[SW2-ospf-1]area 0
[S2-ospf-1-area-0.0.0.0]network 10.0.0.0 0.255.255.255
HC Series
Routes : 10
HUAWEI TECHNOLOGIES
153
HCDA-HNTD
Destination/Mask
Flags NextHop
Interface
10.0.3.0/24
Direct 0
10.0.3.1
Vlanif3
10.0.3.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.4.0/24
Direct 0
10.0.4.1
Vlanif4
10.0.4.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.5.0/24
Direct 0
10.0.5.1
Vlanif5
10.0.5.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.6.0/24
OSPF
10
10.0.5.2
Vlanif5
OSPF
10.0.7.0/24
10
10.0.5.2
Vlanif5
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
154
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Final Configurations
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
vlan batch 1 3 to 7
#
interface Vlanif1
#
interface Vlanif3
ip address 10.0.3.1 255.255.255.0
#
interface Vlanif4
ip address 10.0.4.1 255.255.255.0
#
interface Vlanif5
ip address 10.0.5.1 255.255.255.0
#
HC Series
HUAWEI TECHNOLOGIES
155
HCDA-HNTD
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type access
port default vlan 5
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 4
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/9
eth-trunk 1
undo ntdp enable
undo ndp enable
#
interface GigabitEthernet0/0/10
eth-trunk 1
undo ntdp enable
undo ndp enable
#
interface GigabitEthernet0/0/13
port link-type access
port default vlan 3
ntdp enable
ndp enable
bpdu enable
#
ospf 1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
return
[S2]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 1 3 to 7
#
156
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
interface Vlanif1
#
interface Vlanif5
ip address 10.0.5.2 255.255.255.0
#
interface Vlanif6
ip address 10.0.6.1 255.255.255.0
#
interface Vlanif7
ip address 10.0.7.1 255.255.255.0
#
interface MEth0/0/1
#
interface Eth-Trunk1
port link-type access
port default vlan 5
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 6
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/9
eth-trunk 1
undo ntdp enable
undo ndp enable
#
interface GigabitEthernet0/0/10
eth-trunk 1
undo ntdp enable
undo ndp enable
#
interface GigabitEthernet0/0/24
port link-type access
port default vlan 7
ntdp enable
ndp enable
bpdu enable
#
ospf 1
area 0.0.0.0
HC Series
HUAWEI TECHNOLOGIES
157
HCDA-HNTD
158
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface GigabitEthernet0/0/2
ip address 10.0.6.33 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.6.1
#
return
HC Series
HUAWEI TECHNOLOGIES
159
HCDA-HNTD
160
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
Scenario
Assume that you are a network administrator of a company and the
current network of your company has two users: R2 and R3. A loopback
interface of R1 simulates an Internet server. The network has two
gateways, and you use VRRP to implement gateway redundancy.
Tasks
Step 1 Perform basic configurations and IP addressing.
Irrelevant interfaces must be disabled to ensure test result accuracy.
In this lab, GigabitEthernet0/0/9, GigabitEthernet0/0/13 and
GigabitEthernet0/0/14 on S1 need to be shut down.
The user network uses VLAN 1; S1 connects to R1 using VLAN 2; S2
connects to R1 using VLAN 3; a loopback interface has been configured
on R1; IP addresses and default gateways have been configured on R2
HC Series
HUAWEI TECHNOLOGIES
161
HCDA-HNTD
and R3.
The router R1 simulates a wide area network (WAN), while its
loopback interface simulates a server on the WAN.
[Huawei]sysname R1
[R1]interface LoopBack 0
[R1-LoopBack0]ip address 10.0.1.1 24
[R1-LoopBack0]interface GigabitEthernet 0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.11.2 24
[R1-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[R1-GigabitEthernet0/0/2]ip address 10.0.12.2 24
Create VLAN 1 to VLAN 3 on the switch S1. The default link type of
interfaces is hybrid. Configure G0/0/10 as a Trunk interface and
configure it to allow all VLANs. Configure G0/0/1 as an access interface
and add it to VLAN 2. Configure G0/0/2 as an access interface and add it
to VLAN 1. Create VLANIF 1 to provide gateway for VLAN 1 and assign IP
address 10.0.123.2/24 to VLANIF 1. Create VLANIF 2 as a Layer 3 link
connecting to R1 and assign IP address 10.0.11.1/24 to VLANIF 2.
<Huawei>system-view
[Huawei]sysname S1
[S1]vlan batch 1 to 3
162
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Create VLAN 1 to VLAN 3 for the switch S2. The interfaces by default
adopt the hybrid mode. Define G0/0/10 as a Trunk interface to allow the
access of all VLANs. Define G0/0/1 as an access interface belonging to
VLAN 3. Define G0/0/3 as an access interface belonging to VLAN 1. Set
the IP address of VLANIF 1 to 10.0.123.3/24 and use VLANIF 1 to provide
gateway services for VLAN 1. Set the IP address of VLANIF 2 to
10.0.12.1/24 and use VLANIF 2 as a Layer 3 link for connecting to R1.
<Huawei>system-view
[Huawei]sysname S2
[S2]vlan batch 1 to 3
[S2]interface GigabitEthernet 0/0/10
[S2-GigabitEthernet0/0/10]port link-type trunk
[S2-GigabitEthernet0/0/10]port trunk allow-pass vlan all
[S2-GigabitEthernet0/0/10]interface GigabitEthernet 0/0/1
[S2-GigabitEthernet0/0/1]port link-type access
[S2-GigabitEthernet0/0/1]port default vlan 3
[S2-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/3
[S2-GigabitEthernet0/0/3]port link-type access
[S2-GigabitEthernet0/0/3]port default vlan 1
[S2-GigabitEthernet0/0/3]interface Vlanif 1
[S2-Vlanif1]ip address 10.0.123.3 24
[S2-Vlanif1]interface Vlanif 3
[S2-Vlanif3]ip address 10.0.12.1 24
HC Series
HUAWEI TECHNOLOGIES
163
HCDA-HNTD
one ping packet. If you do not use this parameter, the system sends five
packets by default.
[S2]ping -c 1 10.0.12.2
PING 10.0.12.2: 56 data bytes, press CTRL_C to break
Reply from 10.0.12.2: bytes=56 Sequence=1 ttl=255 time=10 ms
--- 10.0.12.2 ping statistics --1 packet(s) transmitted
1 packet(s) received
0.00% packet loss
round-trip min/avg/max = 10/10/10 ms
[S2]ping -c 1 10.0.123.2
PING 10.0.123.2: 56
164
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
165
HCDA-HNTD
[S2]ping -c 1 10.0.12.2
PING 10.0.12.2: 56 data bytes, press CTRL_C to break
Reply from 10.0.2.2: bytes=56 Sequence=1 ttl=255 time=1 ms
--- 10.0.12.2 ping statistics --1 packet(s) transmitted
1 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/1/1 ms
166
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Delay time : 0
TimerRun : 1
TimerConfig : 1
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : normal-vrrp
Config track link-bfd down-number : 0
HC Series
HUAWEI TECHNOLOGIES
167
HCDA-HNTD
Delay time : 0
TimerRun : 1
TimerConfig : 1
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : normal-vrrp
Config track link-bfd down-number : 0
[S2]display vrrp
Vlanif1 | Virtual Router 1
State : Master
Virtual IP : 10.0.123.1
Master IP : 10.0.123.3
PriorityRun : 100
PriorityConfig : 100
MasterPriority : 100
Preempt : YES
Delay time : 0
TimerRun : 1
TimerConfig : 1
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : normal-vrrp
Config track link-bfd down-number : 0
168
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Delay time : 0
TimerRun : 1
TimerConfig : 1
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : normal-vrrp
Config track link-bfd down-number : 0
Interface
Type
Virtual IP
-------------------------------------------------------1
Master
Vlanif1
Normal 10.0.123.1
Note: You can use the brief parameter to display only the brief
information.
HC Series
HUAWEI TECHNOLOGIES
169
HCDA-HNTD
170
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[S1-GigabitEthernet0/0/1]shutdown
R2 can communicate with the Internet server. Check the VRRP state
on S1.
[S1]display vrrp
Vlanif1 | Virtual Router 1
State : Backup
Virtual IP : 10.0.123.1
Master IP : 10.0.123.3
PriorityRun : 95
PriorityConfig : 105
MasterPriority : 100
Preempt : YES
Delay time : 0
TimerRun : 1
TimerConfig : 1
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : normal-vrrp
Track IF : GigabitEthernet0/0/1
Priority reduced : 10
IF state : DOWN
Config track link-bfd down-number : 0
HC Series
HUAWEI TECHNOLOGIES
171
HCDA-HNTD
resource waste.
Design a scheme based on the current topology to implement
redundancy and load balancing.
Final Configurations
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
vlan batch 1 to 3
#
interface Vlanif1
ip address 10.0.123.2 255.255.255.0
vrrp vrid 1 virtual-ip 10.0.123.1
vrrp vrid 1 priority 105
vrrp vrid 1 track interface GigabitEthernet0/0/1
#
interface Vlanif2
ip address 10.0.11.1 255.255.255.0
#
interface GigabitEthernet0/0/1
shutdown
port link-type access
port default vlan 2
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/2
port link-type access
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/10
port link-type trunk
port trunk allow-pass vlan 2 to 4094
ntdp enable
ndp enable
172
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
bpdu enable
#
interface NULL0
#
ospf 1
silent-interface Vlanif1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
user-interface con 0
user-interface vty 0 4
#
return
[S2]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 1 to 3
#
interface Vlanif1
ip address 10.0.123.3 255.255.255.0
vrrp vrid 1 virtual-ip 10.0.123.1
vrrp vrid 1 track interface GigabitEthernet0/0/1
#
interface Vlanif3
ip address 10.0.12.1 255.255.255.0
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 3
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/3
port link-type access
ntdp enable
ndp enable
bpdu enable
#
ospf 1
HC Series
HUAWEI TECHNOLOGIES
173
HCDA-HNTD
silent-interface Vlanif1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
user-interface con 0
user-interface vty 0 4
#
return
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface GigabitEthernet0/0/1
ip address 10.0.11.2 255.255.255.0
#
interface GigabitEthernet0/0/2
ip address 10.0.12.2 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
ospf 1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
interface GigabitEthernet0/0/1
ip address 10.0.123.4 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.123.1
#
174
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface GigabitEthernet0/0/2
ip address 10.0.123.5 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.123.1
#
user-interface con 0
user-interface vty 0 4
user-interface vty 16 20
#
return
HC Series
HUAWEI TECHNOLOGIES
175
HCDA-HNTD
WAN technologies.
PPP implementation.
Topology
176
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Scenario
You are a network administrator of a company. R1, R2, R3 in 0 are
routers. R1 is located in the headquarters, and R2 and R3 are located in
two branches. The headquarters and branches need to be
interconnected. Use HDLC and PPP on WAN links and use different
authentication modes to ensure security.
Tasks
Step 1 Configure IP addresses.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]ip address 10.0.12.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface Serial 1/0/0
[R2-Serial1/0/0]ip address 10.0.12.2 24
[R2-Serial1/0/0]quit
[R2]interface Serial 2/0/0
[R2-Serial2/0/0]ip address 10.0.23.2 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface Serial 2/0/0
[R3-Serial2/0/0]ip address 10.0.23.3 24
HC Series
HUAWEI TECHNOLOGIES
177
HCDA-HNTD
: 2011-10-09 14:39:44
0, multicasts:
errors:
0, runts:
0, giants:
CRC:
0, align errors:
dribbles:
0, aborts:
frame errors:
0, overruns:
0
0
0, no buffers:
0, underruns:
deferred:
0, collisions:
178
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Test connectivity of the directly connected link after verifying that the
physical status and protocol status of the interface are Up.
[R2]ping 10.0.12.1
PING 10.0.12.1: 56 data bytes, press CTRL_C to break
Reply from 10.0.12.1: bytes=56 Sequence=1 ttl=255 time=44 ms
Reply from 10.0.12.1: bytes=56 Sequence=2 ttl=255 time=39 ms
Reply from 10.0.12.1: bytes=56 Sequence=3 ttl=255 time=39 ms
Reply from 10.0.12.1: bytes=56 Sequence=4 ttl=255 time=40 ms
Reply from 10.0.12.1: bytes=56 Sequence=5 ttl=255 time=39 ms
--- 10.0.12.1 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 39/40/44 ms
[R2]ping 10.0.23.3
PING 10.0.23.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.23.3: bytes=56 Sequence=1 ttl=255 time=44 ms
Reply from 10.0.23.3: bytes=56 Sequence=2 ttl=255 time=39 ms
Reply from 10.0.23.3: bytes=56 Sequence=3 ttl=255 time=39 ms
Reply from 10.0.23.3: bytes=56 Sequence=4 ttl=255 time=40 ms
Reply from 10.0.23.3: bytes=56 Sequence=5 ttl=255 time=39 ms
--- 10.0.23.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 39/40/44 ms
HC Series
HUAWEI TECHNOLOGIES
179
HCDA-HNTD
[R3]rip
[R3-rip-1]version 2
[R3-rip-1]network 10.0.0.0
After the configurations are complete, check whether all the routes
are learned. Verify that corresponding routes are learned by RIP.
[R1]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 8
Destination/Mask
Routes : 8
Proto
Pre Cost
Flags NextHop
Interface
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct
10.0.23.0/24 RIP
100 1
127.0.0.0/8
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
Direct
10.0.12.2
Serial1/0/0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
180
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
: 2011-10-09 16:25:55
0, multicasts:
errors:
CRC:
0, runts:
0, align errors:
dribbles:
0, aborts:
frame errors:
0
0, giants:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
HC Series
HUAWEI TECHNOLOGIES
181
HCDA-HNTD
[R1-Serial1/0/0]baudrate 128000
After the configurations are complete, view the serial interface status.
[R1]display interface Serial1/0/0
Serial1/0/0 current state : UP
Line protocol current state : UP
Last line protocol up time : 2011-10-10 11:56:41
Description:HUAWEI, AR Series, Serial1/0/0 Interface
Route Port,The Maximum Transmit Unit is 1500, Hold timer is 10(sec)
Internet Address is 10.0.12.1/24
Link layer protocol is PPP
LCP opened, IPCP opened
Last physical up time
: 2011-10-10 11:56:38
0, multicasts:
0, runts:
0, align errors:
dribbles:
frame errors:
0, aborts:
0
0, giants:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
182
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R1-Serial1/0/0]link-protocol ppp
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R1-Serial1/0/0]
HC Series
HUAWEI TECHNOLOGIES
183
HCDA-HNTD
If the ping operation fails, check the interface status and check
whether the link layer protocol type is correct.
[R1]display interface Serial1/0/0
Serial1/0/0 current state : UP
Line protocol current state : UP
Last line protocol up time : 2011-10-10 16:26:28
Description:HUAWEI, AR Series, Serial1/0/0 Interface
Route Port,The Maximum Transmit Unit is 1500, Hold timer is 10(sec)
Internet Address is 10.0.12.1/24
Link layer protocol is PPP
LCP opened, IPCP opened
Last physical up time
: 2011-10-10 16:26:25
0, multicasts:
0, runts:
0, align errors:
dribbles:
frame errors:
0, aborts:
0
0, giants:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
184
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Proto
Routes : 12
Pre Cost
Flags NextHop
Interface
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Think about the origin and functions of the two routes. Check the
following items:
If HDLC is used, do the two routes exist?
Can R1 and R2 communicate using HDLC or PPP when the IP
addresses of S1/0/0 interfaces on R1 and R2 are located on different
network segments?
HC Series
HUAWEI TECHNOLOGIES
185
HCDA-HNTD
186
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3]aaa
[R3-aaa]local-user user1 password cipher huawei
info: A new user added
[R3-aaa]local-user user1 service-type ppp
[R3-aaa]quit
[R3]interface Serial 2/0/0
[R3-Serial2/0/0]undo shutdown
After the configurations are complete, the interface becomes Up. The
ping command output is as follows:
[R2]ping 10.0.23.3
PING 10.0.23.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.23.3: bytes=56 Sequence=1 ttl=255 time=35 ms
Reply from 10.0.23.3: bytes=56 Sequence=2 ttl=255 time=41 ms
Reply from 10.0.23.3: bytes=56 Sequence=3 ttl=255 time=41 ms
Reply from 10.0.23.3: bytes=56 Sequence=4 ttl=255 time=41 ms
Reply from 10.0.23.3: bytes=56 Sequence=5 ttl=255 time=41 ms
--- 10.0.23.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 35/39/41 ms
HC Series
HUAWEI TECHNOLOGIES
187
HCDA-HNTD
188
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
HC Series
HUAWEI TECHNOLOGIES
189
HCDA-HNTD
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
local-user huawei password simple hello
local-user huawei service-type ppp
#
interface Serial1/0/0
link-protocol ppp
ppp authentication-mode pap
ip address 10.0.12.1 255.255.255.0
baudrate 128000
#
rip 1
version 2
network 10.0.0.0
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Serial1/0/0
link-protocol ppp
ppp pap local-user huawei password simple hello
190
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
191
HCDA-HNTD
PVC functions.
Topology
Scenario
You are a network administrator of a company. R1, R2, R3 in 0 are
routers. R1 is located in the headquarters, and R2 and R3 are located in
two branches. The headquarters and branches need to be
interconnected. You need to configure FR on WAN links and mapping
between DLCIs and IP addresses.
192
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Tasks
Step 1 Configure IP addresses.
<Huawei>system-view
[Huawei]sysname R1
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]ip address 10.0.12.1 24
[R1-Serial1/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
[Huawei]sysname R2
[R2]int Serial 1/0/0
[R2-Serial1/0/0]ip address 10.0.12.2 24
[R2-Serial1/0/0]interface loopback 0
[R2-LoopBack0]ip address 10.0.2.2 24
[R2-LoopBack0]interface Serial 2/0/0
[R2-Serial2/0/0]ip address 10.0.23.2 24
<Huawei>system-view
[Huawei]sysname R3
[R3]int Serial 2/0/0
[R3-Serial2/0/0]ip address 10.0.23.3 24
[R3-Serial2/0/0]interface loopback 0
[R3-LoopBack0]ip address 10.0.3.3 24
HC Series
HUAWEI TECHNOLOGIES
193
HCDA-HNTD
[R2]ping 10.0.23.3
PING 10.0.23.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.23.3: bytes=56 Sequence=1 ttl=255 time=41 ms
Reply from 10.0.23.3: bytes=56 Sequence=2 ttl=255 time=37 ms
Reply from 10.0.23.3: bytes=56 Sequence=3 ttl=255 time=37 ms
Reply from 10.0.23.3: bytes=56 Sequence=4 ttl=255 time=37 ms
Reply from 10.0.23.3: bytes=56 Sequence=5 ttl=255 time=37 ms
--- 10.0.23.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 37/37/41 ms
: 2011-10-11 14:40:34
194
0, multicasts:
0, runts:
0
0, giants:
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
CRC:
dribbles:
frame errors:
0, align errors:
0, aborts:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
HC Series
HUAWEI TECHNOLOGIES
195
HCDA-HNTD
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 34/34/38 ms
: 2011-10-11 14:44:25
0, multicasts:
0, runts:
0, align errors:
dribbles:
frame errors:
0, aborts:
0
0, giants:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
196
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
: 2011-10-11 09:43:20
0, multicasts:
0, runts:
0, align errors:
0, aborts:
0
0, giants:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
HC Series
HUAWEI TECHNOLOGIES
197
HCDA-HNTD
The greyed line indicates that S2/0/0 on R3 connects to the DCE port.
[R2]interface Serial 2/0/0
[R2-Serial2/0/0]link-protocol fr
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R2-Serial2/0/0]fr interface-type dte
[R2-Serial2/0/0]fr inarp
198
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
: 2011-10-11 15:01:31
0, multicasts:
0, runts:
0
0, giants:
0, align errors:
0, aborts:
0, overruns:
0, no buffers:
0, collisions:
0, underruns:
deferred:
HUAWEI TECHNOLOGIES
199
HCDA-HNTD
Proto
Routes : 13
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.12.2
Serial1/0/0
10.0.12.0/24 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.2/32 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
100 1
10.0.23.0/24 RIP
10.0.12.2
Serial1/0/0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HUAWEI TECHNOLOGIES
201
HCDA-HNTD
[R2-Serial1/0/0]shutdown
[R2-Serial1/0/0]undo shutdown
Proto
Routes : 15
Pre Cost
Flags NextHop
Interface
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
202
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Proto
10.0.1.0/24 RIP
Routes : 16
Pre Cost
100 1
Flags NextHop
Interface
10.0.12.1
Serial1/0/0
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32 Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.255/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.3/32 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
203
HCDA-HNTD
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
204
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Proto
Routes : 11
Pre Cost
Flags NextHop
Interface
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
The preceding information shows that R3 does not learn the routes
sent by R2.
By default, OSPF considers that the network mode on the FR-enabled
port is NBMA and devices do not detect neighbors.
[R3]display ospf interface Serial 2/0/0
OSPF Process 1 with Router ID 10.0.3.3
Interfaces
State: Waiting
Type: NBMA
MTU: 1500
Priority: 1
Designated Router: 0.0.0.0
Backup Designated Router: 0.0.0.0
Timers: Hello 30 , Dead 120 , Poll 120 , Retransmit 5 , Transmit Delay 1
HC Series
HUAWEI TECHNOLOGIES
205
HCDA-HNTD
[R2]ospf 1
[R2-ospf-1]peer 10.0.23.3
[R3]ospf 1
[R3-ospf-1]peer 10.0.23.2
Address: 10.0.23.2
DR: 10.0.23.2
BDR: None
MTU: 0
Proto
10.0.2.2/32
OSPF
10.0.3.0/24
Routes : 13
Pre Cost
Interface
1562
10.0.23.2
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
3124
10.0.23.2
Serial2/0/0
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 OSPF
206
10
Flags NextHop
10
HUAWEI TECHNOLOGIES
Serial2/0/0
HC Series
HCDA-HNTD
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
207
HCDA-HNTD
State: DR
Type: NBMA
MTU: 1500
Priority: 1
Designated Router: 10.0.23.3
Backup Designated Router: 10.0.23.2
Timers: Hello 30 , Dead 120 , Poll 120 , Retransmit 5 , Transmit Delay 1
Address: 10.0.23.2
208
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Proto
10.0.2.2/32
OSPF
10.0.3.0/24
Routes : 13
Pre
Flags NextHop
Interface
1562
10.0.23.2
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
3124
10.0.23.2
Serial2/0/0
10.0.23.0/24 Direct 0
10.0.23.3
Serial2/0/0
10.0.23.2/32 Direct 0
10.0.23.2
Serial2/0/0
10.0.23.3/32 Direct 0
127.0.0.1
InLoopBack0
10.0.23.255/32 Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
10.0.12.0/24 OSPF
127.0.0.0/8
10
Cost
10
Serial2/0/0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
State: DR
Type: Broadcast
MTU: 1500
Priority: 1
Designated Router: 10.0.23.3
Backup Designated Router: 10.0.23.2
Timers: Hello 10 , Dead 40 , Poll 120 , Retransmit 5 , Transmit Delay 1
[R3]ping 10.0.2.2
PING 10.0.2.2: 56 data bytes, press CTRL_C to break
HC Series
HUAWEI TECHNOLOGIES
209
HCDA-HNTD
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface Serial1/0/0
link-protocol fr
fr interface-type dce
undo fr inarp
fr dlci 102
fr map ip 10.0.12.2 102
ip address 10.0.12.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
rip 1
undo summary
version 2
peer 10.0.12.2
network 10.0.0.0
210
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
router id 10.0.2.2
#
interface Serial1/0/0
link-protocol fr
fr dlci 102
undo fr inarp
fr map ip 10.0.12.1 102
ip address 10.0.12.2 255.255.255.0
#
interface Serial2/0/0
link-protocol fr
ip address 10.0.23.2 255.255.255.0
ospf network-type broadcast
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ospf 1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
rip 1
undo summary
version 2
peer 10.0.12.1
network 10.0.0.0
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
router id 10.0.3.3
HC Series
HUAWEI TECHNOLOGIES
211
HCDA-HNTD
#
interface Serial2/0/0
link-protocol fr
fr interface-type dce
fr dlci 203
ip address 10.0.23.3 255.255.255.0
ospf network-type broadcast
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
ospf 1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
Return
212
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
HC Series
HUAWEI TECHNOLOGIES
213
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company. R1, R2,
R3 in Figure 8.3 are routers. R1 is located at the company headquarters,
and R2 and R3 are located in two branches. To interconnect the
headquarters and branches, you need to configure FR on WAN links in
hub-spoke mode.
Tasks
Step 1 Configure IP addresses.
Set basic parameters, such as IP addresses. When configuring FR
encapsulation, you must disable the Inarp function and manually define
mapping between the PVC DLCI numbers and IP addresses.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface Serial 2/0/0
[R1-Serial2/0/0]link-protocol fr
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R1-Serial2/0/0]ip address 10.0.123.1 24
[R1-Serial2/0/0]undo fr inarp
[R1-Serial2/0/0]fr map ip 10.0.123.2 102 broadcast
[R1-Serial2/0/0]fr map ip 10.0.123.3 103 broadcast
[R1-Serial2/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface Serial 3/0/0
[R2-Serial3/0/0]link-protocol fr
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R2-Serial3/0/0]ip address 10.0.123.2 24
[R2-Serial3/0/0]undo fr inarp
[R2-Serial3/0/0]fr map ip 10.0.123.1 201 broadcast
[R2-Serial3/0/0]interface loopback 0
[R2-LoopBack0]ip address 10.0.2.2 24
214
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface Serial 1/0/0
[R3-Serial1/0/0]link-protocol fr
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R3-Serial1/0/0]ip address 10.0.123.3 24
[R3-Serial1/0/0]undo fr inarp
[R3-Serial1/0/0]fr map ip 10.0.123.1 301 broadcast
[R3-Serial1/0/0]interface loopback 0
[R3-LoopBack0]ip address 10.0.3.3 24
HC Series
HUAWEI TECHNOLOGIES
215
HCDA-HNTD
View the routing tables on R1, R2, and R3 to check the learned
routes.
[R1]display ip routing-table protocol rip
Route Flags: R - relay, D - download to fib
----------------------------------------------------------------------------
216
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Routes : 2
Routes : 2
Proto
Pre Cost
Flags NextHop
Interface
10.0.2.0/24
RIP
100 1
10.0.123.2
Serial2/0/0
10.0.3.0/24
RIP
100 1
10.0.123.3
Serial2/0/0
Routes : 0
Routes : 2
Routes : 2
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 1
10.0.123.1
Serial3/0/0
10.0.3.0/24
RIP
100 2
10.0.123.1
Serial3/0/0
Routes : 0
Routes : 2
HC Series
Proto
RIP
Routes : 2
Pre Cost
100 1
Flags NextHop
D
10.0.123.1
HUAWEI TECHNOLOGIES
Interface
Serial1/0/0
217
HCDA-HNTD
10.0.2.0/24
RIP
100 2
10.0.123.1
Serial1/0/0
Routes : 0
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
If R3 can reach the next hop and there is mapping between Layer-3 IP
addresses and Layer-2 PVCs, check the devices on the route to
determine whether there is any route that can reach IP address 10.0.2.2,
whether the next hop of this route is reachable, and whether there is
mapping between Layer-3 IP addresses and Layer-2 PVCs.
If there is a route that can reach IP address 10.0.2.2 and there is
mapping between Layer-3 IP addresses and Layer-2 PVCs, check R2 to
determine whether there is any route that reaches the destination IP
address of response packets and whether the next hop of this route is
reachable.
If the next hop of this route is unreachable and the destination IP
address of the response packets is 10.0.123.3, R2 has the route that
reaches this address but there is no mapping between Layer-3 IP
addresses and Layer-2 PVCs.
The following is the output of the commands used in the preceding
fault diagnosis procedure.
[R3]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 13
Destination/Mask
Proto
Routes : 13
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 1
10.0.123.1
Serial1/0/0
10.0.2.0/24
RIP
100 2
10.0.123.1
Serial1/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.0/24
Direct 0
10.0.123.3
Serial1/0/0
10.0.123.1/32
Direct 0
10.0.123.1
Serial1/0/0
10.0.123.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.255/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
219
HCDA-HNTD
Proto
Routes : 14
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.123.2
Serial2/0/0
10.0.3.0/24
RIP
100 1
10.0.123.3
Serial2/0/0
10.0.123.0/24
Direct 0
10.0.123.1
Serial2/0/0
10.0.123.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.2/32
Direct 0
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct 0
10.0.123.3
Serial2/0/0
10.0.123.255/32
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
220
Proto
RIP
Routes : 13
Pre Cost
100 1
Flags NextHop
D
10.0.123.1
HUAWEI TECHNOLOGIES
Interface
Serial3/0/0
HC Series
HCDA-HNTD
10.0.2.0/24
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.1
Serial3/0/0
10.0.3.0/24
RIP
100 2
10.0.123.0/24
Direct 0
10.0.123.2
Serial3/0/0
10.0.123.1/32
Direct 0
10.0.123.1
Serial3/0/0
10.0.123.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.255/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1/32 Direct 0
D
D
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
221
HCDA-HNTD
222
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3]
State: DR
Type: NBMA
MTU: 1500
Priority: 1
Designated Router: 10.0.123.3
Backup Designated Router: 0.0.0.0
Timers: Hello 30 , Dead 120 , Poll 120 , Retransmit 5 , Transmit Delay 1
IO Statistics
Type
Hello
Input
Output
DB Description
Link-State Req
Link-State Update
Link-State Ack
OpaqueId: 0
PrevState: Waiting
HUAWEI TECHNOLOGIES
223
HCDA-HNTD
After you set the OSPF network type, wait until the neighbor
relationship is established. Then check the neighbor relationship and
route information.
[R1]display ospf peer brief
OSPF Process 1 with Router ID 10.0.1.1
Peer Statistic Information
---------------------------------------------------------------------------Area Id
Interface
Neighbor id
State
0.0.0.0
Serial2/0/0
10.0.2.2
Full
0.0.0.0
Serial2/0/0
10.0.3.3
Full
---------------------------------------------------------------------------[R1]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Proto
Routes : 14
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
Direct 0
10.0.1.1
LoopBack0
10.0.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.2/32
OSPF
10
1562
10.0.123.2
Serial2/0/0
10.0.3.3/32
OSPF
10
1562
10.0.123.3
Serial2/0/0
10.0.123.1
Serial2/0/0
10.0.123.0/24
224
Direct 0
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
10.0.123.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.2/32
Direct 0
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct 0
10.0.123.3
Serial2/0/0
10.0.123.255/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
Interface
Neighbor id
State
0.0.0.0
Serial3/0/0
10.0.1.1
Full
---------------------------------------------------------------------------[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Proto
10.0.1.1/32
OSPF
10.0.2.0/24
Routes : 14
Pre Cost
Interface
1562
10.0.123.1
Direct 0
10.0.2.2
LoopBack0
10.0.2.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct 0
127.0.0.1
InLoopBack0
OSPF
10.0.3.3/32
10
Flags NextHop
3124
10.0.123.1
Serial3/0/0
10.0.123.0/24
Direct 0
10.0.123.2
Serial3/0/0
10.0.123.1/32
Direct 0
10.0.123.1
Serial3/0/0
10.0.123.2/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.3/32
OSPF
3124
10.0.123.1
Serial3/0/0
127.0.0.1
InLoopBack0
10.0.123.255/32
127.0.0.0/8
10
Serial3/0/0
10
Direct 0
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
HC Series
HUAWEI TECHNOLOGIES
225
HCDA-HNTD
---------------------------------------------------------------------------Area Id
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.1.1
Full
---------------------------------------------------------------------------[R3]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Routes : 14
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.1/32
OSPF
10
1562
10.0.123.1
Serial1/0/0
10.0.2.2/32
OSPF
10
3124
10.0.123.1
Serial1/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.0/24
Direct 0
10.0.123.3
Serial1/0/0
10.0.123.1/32
Direct 0
10.0.123.1
Serial1/0/0
10.0.123.2/32
OSPF
3124
10.0.123.1
Serial1/0/0
10.0.123.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.255/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
10
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
226
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3]ping 10.0.2.2
PING 10.0.2.2: 56 data bytes, press CTRL_C to break
Reply from 10.0.2.2: bytes=56 Sequence=1 ttl=254 time=116 ms
Reply from 10.0.2.2: bytes=56 Sequence=2 ttl=254 time=121 ms
Reply from 10.0.2.2: bytes=56 Sequence=3 ttl=254 time=121 ms
Reply from 10.0.2.2: bytes=56 Sequence=4 ttl=254 time=120 ms
Reply from 10.0.2.2: bytes=56 Sequence=5 ttl=254 time=120 ms
--- 10.0.2.2 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 116/119/121 ms
[R3]ping 10.0.123.2
PING 10.0.123.2: 56
HC Series
HUAWEI TECHNOLOGIES
227
HCDA-HNTD
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface Serial2/0/0
link-protocol fr
undo fr inarp
fr map ip 10.0.123.2 102 broadcast
fr map ip 10.0.123.3 103 broadcast
ip address 10.0.123.1 255.255.255.0
ospf network-type p2mp
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
ospf 1 router-id 10.0.1.1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
interface Serial3/0/0
link-protocol fr
undo fr inarp
fr map ip 10.0.123.1 201 broadcast
ip address 10.0.123.2 255.255.255.0
ospf network-type p2mp
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ospf 1 router-id 10.0.2.2
area 0.0.0.0
network 10.0.0.0 0.255.255.255
228
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface Serial1/0/0
link-protocol fr
undo fr inarp
fr map ip 10.0.123.1 301 broadcast
ip address 10.0.123.3 255.255.255.0
ospf network-type p2mp
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
ospf 1 router-id 10.0.3.3
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
return
HC Series
HUAWEI TECHNOLOGIES
229
HCDA-HNTD
Topology
230
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company. The
company bought a Eudemon 200E firewall and intends to connect it to
S1, the core switch, to filter packets transmitted across different VLANs.
You need to familiarize yourself with various operations of the firewall.
Tasks
Step 1 Log in to the firewall and change its name.
Like a router, a firewall provides a console interface, which can
connect to the COM interface on a computer. The computer can connect
to the firewall using the super terminal software that comes with the
Windows operating system. For details, see "Lab 1-1 Basic Operations on
the VRP Platform."
The firewall provides default configurations and the default user
name and password are admin and Admin@123. Enter the
case-sensitive user name and password when logging in to the firewall.
***********************************************************
*
*
*
*
***********************************************************
User interface con0 is available
Please Press ENTER.
Login authentication
HC Series
HUAWEI TECHNOLOGIES
231
HCDA-HNTD
Username:admin
Password:
NOTICE:This is a private communication system.
Unauthorized access or use may lead to prosecution.
<Eudemon 200E>
The method for changing the firewall name is the same as that for
changing the router name.
Because both the firewall and router use the VRP operating system,
the command level and help operations for them are the same.
<Eudemon 200E>system-view
Enter system view, return user view with Ctrl+Z.
[Eudemon 200E]sysname FW
[FW]
Step 2 Change the time and time zone for the firewall.
By default, the time zone is not defined on the firewall. Therefore, the
firewall system time may be inconsistent with the actual time. You should
change the time and time zone information based on the actual
information for your location. During the exercise, the time zone GMT+8
is used and the standard time is defined.
<FW>clock timezone 1 add 08:00:00
<FW>display clock
2011-11-17 18:39:48
Thursday
Time Zone : 1 add 08:00:00
<FW>clock datetime 10:36:00 2011/11/17
<FW>display clock
2011-11-17 10:36:09
Thursday
Time Zone : 1 add 08:00:00
232
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Login authentication
Username:admin
Password:
NOTICE:This is a private communication system.
Unauthorized access or use may lead to prosecution.
<FW>
Log out of the firewall system and then log in to the system again to
check whether the change takes effect.
Please Press ENTER.
Welcome to Eudemon 200E
Login authentication
Username:admin
HC Series
HUAWEI TECHNOLOGIES
233
HCDA-HNTD
Password:
Welcome to Eudemon 200E
You are logining in system Please donot delete system config files
NOTICE:This is a private communication system.
Unauthorized access or use may lead to prosecution.
<FW>
After you set the authentication mode to aaa, log out of the system
and check whether the newly created user name and password take
effect.
[FW-ui-console0]return
<FW>quit
*************************************************************************
*
234
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
*
*
*
*************************************************************************
User interface con0 is available
Username:user1
Password:
Welcome to Eudemon 200E
You are logining in system Please donot delete system config files
NOTICE:This is a private communication system.
Unauthorized access or use may lead to prosecution.
<FW>
To save time during the exercise, you can set the authentication
mode that does not require a user name and password.
[FW]user-interface console 0
[FW-ui-console0]authentication-mode none
After setting this authentication mode, you can log in to the system
directly.
<FW>quit
Please Press ENTER.
Welcome to Eudemon 200E
You are logining in system Please donot delete system config files
<FW>
HC Series
HUAWEI TECHNOLOGIES
235
HCDA-HNTD
236
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
237
HCDA-HNTD
[FW]vlan 2
[FW-vlan-2]interface vlanif 2
[FW-Vlanif2]ip address 10.0.2.1 24
238
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
239
HCDA-HNTD
Final Configurations
[FW]display current-configuration
#
sysname FW
#
undo firewall ipv6 session link-state check
#
vlan batch 1 to 2
#
undo firewall session link-state check
#
runmode firewall
#
update schedule ips daily 6:12
update schedule av daily 6:12
security server domain sec.huawei.com
#
web-manager enable
#
l2fwdfast enable
#
interface Vlanif2
ip address 10.0.2.1 255.255.255.0
240
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
interface Cellular5/0/0
link-protocol ppp
#
interface Ethernet0/0/0
ip address 10.0.1.1 255.255.255.0
#
interface Ethernet1/0/0
portswitch
port link-type access
port access vlan 2
#
interface Ethernet1/0/1
portswitch
port link-type access
#
interface Ethernet1/0/2
portswitch
port link-type access
#
interface Ethernet1/0/3
portswitch
port link-type access
#
interface Ethernet1/0/4
portswitch
port link-type access
#
interface Ethernet1/0/5
portswitch
port link-type access
#
interface Ethernet1/0/6
portswitch
port link-type access
#
interface Ethernet1/0/7
portswitch
port link-type access
#
interface Ethernet2/0/0
ip address 10.0.3.1 255.255.255.0
#
HC Series
HUAWEI TECHNOLOGIES
241
HCDA-HNTD
interface NULL0
#
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
#
firewall zone untrust
set priority 5
#
firewall zone dmz
set priority 50
#
aaa
local-user admin password cipher ]MQ;4\]B+4Z,YWX*NZ55OA!!
local-user admin service-type web terminal
local-user admin level 3
local-user user1 password simple huawei@123
local-user user1 service-type terminal
local-user user1 level 3
authentication-scheme default
#
authorization-scheme default
#
accounting-scheme default
#
domain default
domain dot1x
#
#
nqa-jitter tag-version 1
#
header shell information "Welcome to Eudemon 200E
You are logining in system Please donot delete system config files
"
header login information "Welcome to Eudemon 200E "
banner enable
#
user-interface con 0
authentication-mode none
user-interface tty 2
242
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
authentication-mode none
modem both
user-interface vty 0 4
#
slb
#
cwmp
#
right-manager server-group
#
return
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
dns resolve
#
vlan batch 2 to 3
#
stp enable
#
interface Vlanif1
ip address 10.0.1.2 255.255.255.0
#
interface Vlanif2
ip address 10.0.2.2 255.255.255.0
#
interface Vlanif3
ip address 10.0.3.2 255.255.255.0
#
interface GigabitEthernet0/0/21
port link-type access
ntdp enable
ndp enable
bpdu enable
#
interface GigabitEthernet0/0/22
port link-type access
port default vlan 2
ntdp enable
ndp enable
HC Series
HUAWEI TECHNOLOGIES
243
HCDA-HNTD
bpdu enable
#
interface GigabitEthernet0/0/23
port link-type access
port default vlan 3
ntdp enable
ndp enable
bpdu enable
#
interface NULL0
#
return
244
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
Scenario
Assume that you are a network administrator of a company. The
company's network at the headquarters is divided into three zones. You
HC Series
HUAWEI TECHNOLOGIES
245
HCDA-HNTD
intend to control inter-zone traffic using the firewall. On S1, you need to
configure three network segments: G0/0/1 and G0/0/21 for accessing
VLAN11, G0/0/2 to G0/0/22 for accessing VLAN12, and G0/0/3 to
G0/0/23 for accessing VLAN13.
You need to achieve the following configurations to meet work
requirements:
The Telnet and ICMP ping services at the IP address 10.0.3.3 are
available for all other network segments.
Tasks
Step 1 Configure IP addresses.
Configure names and IP addresses for R1, R2, and R3.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface GigabitEthernet 0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.10.1 24
[R1-GigabitEthernet0/0/1]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface GigabitEthernet0/0/1
[R2-GigabitEthernet0/0/1]ip address 10.0.20.2 24
[R2-GigabitEthernet0/0/1]interface loopback 0
[R2-LoopBack0]ip address 10.0.2.2 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface GigabitEthernet 0/0/1
[R3-GigabitEthernet0/0/1]ip address 10.0.30.3 24
246
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3-GigabitEthernet0/0/1]interface loopback 0
[R3-LoopBack0]ip address 10.0.3.3 24
Note that E1/0/0 is an interface on the Layer-2 switch and you cannot
directly set an IP address for it. In this exercise, configure the VLAN12
and VLANIF12 on the firewall. In addition, configure the IP address
10.0.20.254/24 for the gateway in the 10.0.20.0/24 network segment. By
default, the firewall automatically assigns an IP address for its VLANIF1.
Delete this configuration to prevent any interference during the exercise.
<Eudemon 200E>system-view
Enter system view, return user view with Ctrl+Z.
[Eudemon 200E]sysname FW
[FW]vlan 12
[FW-vlan-12]quit
[FW]interface Vlanif 12
[FW-Vlanif12]ip address 10.0.20.254 24
[FW-Vlanif12]interface ethernet 1/0/0
[FW-Ethernet1/0/0]port access vlan 12
[FW-Ethernet1/0/0]quit
[FW]undo interface Vlanif 1
[FW]interface Ethernet 0/0/0
[FW-Ethernet0/0/0]ip address 10.0.10.254 24
[FW-Ethernet0/0/0]interface ethernet 2/0/0
[FW-Ethernet2/0/0]ip address 10.0.30.254 24
On S1, configure the VLAN and map the VLAN and associated
interface.
[Quidway]sysname S1
[S1]vlan batch 11 to 13
[S1]interface GigabitEthernet 0/0/1
[S1-GigabitEthernet0/0/1]port link-type access
[S1-GigabitEthernet0/0/1]port default vlan 11
[S1-GigabitEthernet0/0/1]interface GigabitEthernet 0/0/2
[S1-GigabitEthernet0/0/2]port link-type access
[S1-GigabitEthernet0/0/2]port default vlan 12
[S1-GigabitEthernet0/0/2]interface GigabitEthernet 0/0/3
[S1-GigabitEthernet0/0/3]port link-type access
[S1-GigabitEthernet0/0/3]port default vlan 13
[S1-GigabitEthernet0/0/3]interface GigabitEthernet 0/0/21
[S1-GigabitEthernet0/0/21]port link-type access
[S1-GigabitEthernet0/0/21]port default vlan 11
HC Series
HUAWEI TECHNOLOGIES
247
HCDA-HNTD
248
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
to
implement
network
connectivity.
Configure default routes on R1, R2, and R3 and specific static routes
on the firewall to implement the connectivity between the three network
segments that are connected by three Loopback0 interfaces.
[R1]ip route-static 0.0.0.0 0 10.0.10.254
[R2]ip route-static 0.0.0.0 0 10.0.20.254
[R3]ip route-static 0.0.0.0 0 10.0.30.254
[FW]ip route-static 10.0.1.0 24 10.0.10.1
[FW]ip route-static 10.0.2.0 24 10.0.20.2
[FW]ip route-static 10.0.3.0 24 10.0.30.3
HC Series
HUAWEI TECHNOLOGIES
249
HCDA-HNTD
The Telnet and ping functions on the host (IP address: 10.0.3.3/24)
are available for the 10.0.20.0/24 and 10.0.2.0/24 network
segments.
The Telnet and ping functions for the host (IP address: 10.0.3.3/24)
are available for 10.0.10.0/24 and 10.0.1.0/24 network segments.
250
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Note that the session link-state check function on the firewall must
be enabled and the ACL must be deployed.
Configure three ACLs: ACL3000, ACL3001, and ACL3002.
[FW]firewall session link-state check
[FW]acl number 3000
[FW-acl-adv-3000]rule 5 permit tcp destination 10.0.3.3 0 destination-port eq
telnet
[FW-acl-adv-3000]rule 10 permit icmp destination 10.0.3.3 0
[FW-acl-adv-3000]rule 15 deny ip
[FW-acl-adv-3000]quit
[FW]acl number 3001
[FW-acl-adv-3001]rule 5 deny ip
[FW-acl-adv-3001]quit
[FW]acl number 3002
[FW-acl-adv-3002]rule 5 deny ip
HUAWEI TECHNOLOGIES
251
HCDA-HNTD
252
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
253
HCDA-HNTD
254
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
255
HCDA-HNTD
1 packet(s) transmitted
0 packet(s) received
100.00% packet loss
[R3]ping -c 1 10.0.30.254
PING 10.0.30.254: 56
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface GigabitEthernet0/0/1
ip address 10.0.10.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.10.254
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
256
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
interface GigabitEthernet0/0/1
ip address 10.0.20.2 255.255.255.0
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.20.254
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface GigabitEthernet0/0/1
ip address 10.0.30.3 255.255.255.0
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.30.254
#
user-interface vty 0 4
authentication-mode none
#
return
[FW]display current-configuration
#
sysname FW
#
vlan batch 1 12
#
firewall session link-state check
#
#
runmode firewall
#
acl number 3000
rule 5 permit tcp destination 10.0.3.3 0 destination-port eq telnet
rule 10 permit icmp destination 10.0.3.3 0
HC Series
HUAWEI TECHNOLOGIES
257
HCDA-HNTD
rule 15 deny ip
#
acl number 3001
rule 5 deny ip
#
acl number 3002
rule 5 deny ip
#
interface Vlanif12
ip address 10.0.20.254 255.255.255.0
firewall packet-filter 3001 outbound
#
interface Ethernet0/0/0
ip address 10.0.10.254 255.255.255.0
#
interface Ethernet1/0/0
portswitch
port link-type access
port access vlan 12
#
interface Ethernet2/0/0
ip address 10.0.30.254 255.255.255.0
firewall packet-filter 3002 inbound
firewall packet-filter 3000 outbound
#
ip route-static 10.0.1.0 255.255.255.0 10.0.10.1
ip route-static 10.0.2.0 255.255.255.0 10.0.20.2
ip route-static 10.0.3.0 255.255.255.0 10.0.30.3
#
return
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
dns resolve
#
vlan batch 11 to 13
#
stp enable
#
drop illegal-mac alarm
258
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 11
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 12
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 13
#
interface GigabitEthernet0/0/21
port link-type access
port default vlan 11
#
interface GigabitEthernet0/0/22
port link-type access
port default vlan 12
#
interface GigabitEthernet0/0/23
port link-type access
port default vlan 13
#
return
HC Series
HUAWEI TECHNOLOGIES
259
HCDA-HNTD
Topology
260
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company. The
company's network at headquarters is divided into three zones: trust,
untrust, and DMZ. You intend to control inter-zone traffic using the
firewall. On S1, configure three network segments: G0/0/1 to G0/0/21 for
accessing VLAN11, G0/0/2 to G0/0/22 for accessing VLAN12, and G0/0/3
to G0/0/23 for accessing VLAN13.
You need to achieve the following configurations to meet work
requirements:
Users in the trust zone can access users in the untrust zone.
Users in the trust and untrust zones can access users in the DMZ
zone.
Users in the untrust zone cannot directly access users in the trust
zone.
Users in the DMZ zone cannot directly access users in the trust
and untrust zones.
Tasks
Step 1 Configure IP addresses.
Set IP addresses for R1, R2, and R3.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface GigabitEthernet 0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.10.1 24
[R1-GigabitEthernet0/0/1]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface GigabitEthernet0/0/1
[R2-GigabitEthernet0/0/1]ip address 10.0.20.2 24
[R2-GigabitEthernet0/0/1]interface loopback 0
HC Series
HUAWEI TECHNOLOGIES
261
HCDA-HNTD
Note that E1/0/0 is an interface on the Layer-2 switch and you cannot
directly set an IP address for it. In this exercise, configure the VLAN12,
the VLANIF12 interface, and the IP address 10.0.20.254/24 for the
gateway in the inside zone. By default, the firewall automatically assigns
an IP address for its VLANIF1. Delete this configuration to prevent any
interference during the exercise.
<Eudemon 200E>system-view
Enter system view, return user view with Ctrl+Z.
[Eudemon 200E]sysname FW
[FW]vlan 12
[FW-vlan-12]quit
[FW]interface Vlanif 12
[FW-Vlanif12]ip address 10.0.20.254 24
[FW-Vlanif12]interface ethernet 1/0/0
[FW-Ethernet1/0/0]port access vlan 12
[FW-Ethernet1/0/0]quit
[FW]undo interface Vlanif 1
[FW]interface Ethernet 0/0/0
[FW-Ethernet0/0/0]ip address 10.0.10.254 24
[FW-Ethernet0/0/0]interface ethernet 2/0/0
[FW-Ethernet2/0/0]ip address 10.0.30.254 24
262
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
263
HCDA-HNTD
[FW]ping 10.0.30.3
PING 10.0.30.3: 56 data bytes, press CTRL_C to break
Request time out
Reply from 10.0.30.3: bytes=56 Sequence=2 ttl=255 time=1 ms
Reply from 10.0.30.3: bytes=56 Sequence=3 ttl=255 time=1 ms
Reply from 10.0.30.3: bytes=56 Sequence=4 ttl=255 time=1 ms
Reply from 10.0.30.3: bytes=56 Sequence=5 ttl=255 time=1 ms
--- 10.0.30.3 ping statistics --5 packet(s) transmitted
4 packet(s) received
20.00% packet loss
round-trip min/avg/max = 1/1/1 ms
to
implement
network
connectivity.
Configure default routes on R1, R2, and R3 and specific static routes
on the firewall to implement the connectivity between the three network
segments that are connected by three Loopback0 interfaces.
[R1]ip route-static 0.0.0.0 0 10.0.10.254
[R2]ip route-static 0.0.0.0 0 10.0.20.254
[R3]ip route-static 0.0.0.0 0 10.0.30.254
[FW]ip route-static 10.0.1.0 24 10.0.10.1
[FW]ip route-static 10.0.2.0 24 10.0.20.2
[FW]ip route-static 10.0.3.0 24 10.0.30.3
264
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
265
HCDA-HNTD
266
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HC Series
HUAWEI TECHNOLOGIES
267
HCDA-HNTD
268
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
HUAWEI TECHNOLOGIES
269
HCDA-HNTD
270
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[FW-policy-interzone-dmz-untrust-inbound]policy 2
[FW-policy-interzone-dmz-untrust-inbound-2]policy service service-set telnet
[FW-policy-interzone-dmz-untrust-inbound-2]policy destination 10.0.3.3 0
[FW-policy-interzone-dmz-untrust-inbound-2]action permit
[FW-policy-interzone-dmz-untrust-inbound-2]quit
[FW-policy-interzone-dmz-untrust-inbound]policy 3
[FW-policy-interzone-dmz-untrust-inbound-3]action deny
HC Series
HUAWEI TECHNOLOGIES
271
HCDA-HNTD
[R1]ping 10.0.30.3
PING 10.0.30.3: 56 data bytes, press CTRL_C to break
Request time out
Request time out
Request time out
Request time out
Request time out
--- 10.0.30.3 ping statistics --5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
<R1>telnet 10.0.3.3
Press CTRL_] to quit telnet mode
Trying 10.0.3.3 ...
Connected to 10.0.3.3 ...
<R3>quit
Configuration console exit, please retry to log on
The connection was closed by the remote host
<R1>telnet 10.0.30.3
Press CTRL_] to quit telnet mode
Trying 10.0.30.3 ...
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
272
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
sysname R1
#
interface GigabitEthernet0/0/1
ip address 10.0.10.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.10.254
#
return
[R2]display current-configuration
[V200R001C01SPC300]
#
sysname R2
#
interface GigabitEthernet0/0/1
ip address 10.0.20.2 255.255.255.0
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.20.254
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface GigabitEthernet0/0/1
ip address 10.0.30.3 255.255.255.0
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.30.254
#
user-interface vty 0 4
authentication-mode none
HC Series
HUAWEI TECHNOLOGIES
273
HCDA-HNTD
#
return
[FW]display current-configuration
#
sysname FW
#
firewall packet-filter default deny interzone local trust direction inbound
firewall packet-filter default deny interzone local trust direction outbound
firewall packet-filter default deny interzone local untrust direction inbound
firewall packet-filter default deny interzone local untrust direction outbound
firewall packet-filter default deny interzone local dmz direction inbound
firewall packet-filter default deny interzone local dmz direction outbound
firewall packet-filter default deny interzone trust untrust direction inbound
firewall packet-filter default deny interzone trust dmz direction inbound
firewall packet-filter default deny interzone dmz untrust direction inbound
firewall packet-filter default deny interzone dmz untrust direction outbound
#
vlan batch 1 12
#
firewall session link-state check
#
#
runmode firewall
#
interface Vlanif12
ip address 10.0.20.254 255.255.255.0
#
interface Ethernet0/0/0
ip address 10.0.10.254 255.255.255.0
#
interface Ethernet1/0/0
portswitch
port link-type access
port access vlan 12
#
interface Ethernet2/0/0
ip address 10.0.30.254 255.255.255.0
#
firewall zone local
set priority 100
#
firewall zone trust
274
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
set priority 85
add interface Vlanif12
#
firewall zone untrust
set priority 5
add interface Ethernet0/0/0
#
firewall zone dmz
set priority 50
add interface Ethernet2/0/0
#
ip route-static 10.0.1.0 255.255.255.0 10.0.10.1
ip route-static 10.0.2.0 255.255.255.0 10.0.20.2
ip route-static 10.0.3.0 255.255.255.0 10.0.30.3
#
policy interzone dmz untrust inbound
policy 1
action permit
policy service service-set icmp
policy destination 10.0.3.3 0
policy 2
action permit
policy service service-set telnet
policy destination 10.0.3.3 0
policy 3
action deny
#
return
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
dns resolve
#
vlan batch 11 to 13
#
stp enable
#
drop illegal-mac alarm
HC Series
HUAWEI TECHNOLOGIES
275
HCDA-HNTD
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 11
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 12
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 13
#
interface GigabitEthernet0/0/21
port link-type access
port default vlan 11
#
interface GigabitEthernet0/0/22
port link-type access
port default vlan 12
#
interface GigabitEthernet0/0/23
port link-type access
port default vlan 13
#
Return
276
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
Figure 9.4 Lab topology for NAT configuration on the Eudemon firewall
HC Series
HUAWEI TECHNOLOGIES
277
HCDA-HNTD
Scenario
Assume that you are a network administrator of a company. The
company network is isolated into three zones by the Eudemon firewall:
untrust zone, trust zone, and demilitarized zone (DMZ). You need to
release the Telnet service that is provided by a server with IP address
10.0.3.3 in the DMZ zone. The external IP address of the server is
10.0.10.20/24. Users in the trust zone can access the untrust zone by
means of Easy IP. Other access methods are not allowed.
On S1, you need to configure three network segments: G0/0/1 to
G0/0/21 for accessing VLAN11, G0/0/2 to G0/0/22 for accessing VLAN12,
and G0/0/3 to G0/0/23 for accessing VLAN13.
Tasks
Step 1 Configure IP addresses.
Configure IP addresses for R1, R2, and R3.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
[R1]interface GigabitEthernet 0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.10.1 24
[R1-GigabitEthernet0/0/1]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface GigabitEthernet0/0/1
[R2-GigabitEthernet0/0/1]ip address 10.0.20.2 24
[R2-GigabitEthernet0/0/1]interface loopback 0
[R2-LoopBack0]ip address 10.0.2.2 24
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R3
[R3]interface GigabitEthernet 0/0/1
[R3-GigabitEthernet0/0/1]ip address 10.0.30.3 24
278
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
[R3-GigabitEthernet0/0/1]interface loopback 0
[R3-LoopBack0]ip address 10.0.3.3 24
Note that E1/0/0 is an interface on the Layer-2 switch and you cannot
directly set an IP address for it. In this exercise, you need to configure
VLAN12, the VLANIF12 interface, and the IP address 10.0.20.254/24 for
the gateway in the trust zone. By default, the firewall automatically
assigns an IP address for its VLANIF1. You need to delete this
configuration to prevent any interference during the experiment.
<Eudemon 200E>system-view
Enter system view, return user view with Ctrl+Z.
[Eudemon 200E]sysname FW
[FW]vlan 12
[FW-vlan-12]quit
[FW]interface Vlanif 12
[FW-Vlanif12]ip address 10.0.20.254 24
[FW-Vlanif12]interface ethernet 1/0/0
[FW-Ethernet1/0/0]port access vlan 12
[FW-Ethernet1/0/0]quit
[FW]undo interface Vlanif 1
[FW]interface Ethernet 0/0/0
[FW-Ethernet0/0/0]ip address 10.0.10.254 24
[FW-Ethernet0/0/0]interface ethernet 2/0/0
[FW-Ethernet2/0/0]ip address 10.0.30.254 24
HC Series
HUAWEI TECHNOLOGIES
279
HCDA-HNTD
280
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
to
implement
network
connectivity.
Configure default routes on R2 and R3 and specific static routes on
the firewall to implement the connectivity between the three network
segments that are connected by three Loopback0 interfaces. R1, an
Internet device, does not require you to define default routes because R1
does not need to know any private network information about the trust
and DMZ zones.
[R2]ip route-static 0.0.0.0 0 10.0.20.254
[R3]ip route-static 0.0.0.0 0 10.0.30.254
[FW]ip route-static 10.0.1.0 24 10.0.10.1
[FW]ip route-static 10.0.2.0 24 10.0.20.2
[FW]ip route-static 10.0.3.0 24 10.0.30.3
HC Series
HUAWEI TECHNOLOGIES
281
HCDA-HNTD
[FW]ping 10.0.2.2
PING 10.0.2.2: 56 data bytes, press CTRL_C to break
Reply from 10.0.2.2: bytes=56 Sequence=1 ttl=255 time=1 ms
Reply from 10.0.2.2: bytes=56 Sequence=2 ttl=255 time=1 ms
Reply from 10.0.2.2: bytes=56 Sequence=3 ttl=255 time=1 ms
Reply from 10.0.2.2: bytes=56 Sequence=4 ttl=255 time=1 ms
Reply from 10.0.2.2: bytes=56 Sequence=5 ttl=255 time=1 ms
--- 10.0.2.2 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/1/1 ms
[FW]ping 10.0.3.3
PING 10.0.3.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.3.3: bytes=56 Sequence=1 ttl=255 time=1 ms
Reply from 10.0.3.3: bytes=56 Sequence=2 ttl=255 time=1 ms
Reply from 10.0.3.3: bytes=56 Sequence=3 ttl=255 time=1 ms
Reply from 10.0.3.3: bytes=56 Sequence=4 ttl=255 time=1 ms
Reply from 10.0.3.3: bytes=56 Sequence=5 ttl=255 time=1 ms
--- 10.0.3.3 ping statistics --5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/1/1 ms
282
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
After the configurations are complete, check whether the trust and
untrust zones can access each other.
[R2]ping 10.0.1.1
HC Series
HUAWEI TECHNOLOGIES
283
HCDA-HNTD
284
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Enable the Telnet function on R3 and test it on R1. Note that the
external IP address of R3 is 10.0.10.20. When R1 needs to access 10.0.3.3,
the destination address must be 10.0.10.20.
[R3]user-interface vty 0 4
[R3-ui-vty0-4]authentication-mode none
<R1>telnet 10.0.10.20
Press CTRL_] to quit telnet mode
Trying 10.0.10.20 ...
Connected to 10.0.10.20 ...
<R3>
Final Configurations
[R1]display current-configuration
[V200R001C01SPC300]
#
sysname R1
#
interface GigabitEthernet0/0/1
ip address 10.0.10.1 255.255.255.0
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
return
[R2]display current-configuration
[V200R001C01SPC300]
HC Series
HUAWEI TECHNOLOGIES
285
HCDA-HNTD
#
sysname R2
#
interface GigabitEthernet0/0/1
ip address 10.0.20.2 255.255.255.0
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.20.254
#
return
[R3]display current-configuration
[V200R001C01SPC300]
#
sysname R3
#
interface GigabitEthernet0/0/1
ip address 10.0.30.3 255.255.255.0
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
ip route-static 0.0.0.0 0.0.0.0 10.0.30.254
#
user-interface vty 0 4
authentication-mode none
#
return
[FW]display current-configuration
#
sysname FW
#
nat server 0 protocol tcp global 10.0.10.20 telnet inside 10.0.3.3 telnet
#
vlan batch 1 12
#
firewall session link-state check
#
#
runmode firewall
286
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
#
interface Vlanif12
ip address 10.0.20.254 255.255.255.0
#
interface Ethernet0/0/0
ip address 10.0.10.254 255.255.255.0
#
interface Ethernet1/0/0
portswitch
port link-type access
port access vlan 12
#
interface Ethernet2/0/0
ip address 10.0.30.254 255.255.255.0
#
firewall zone local
set priority 100
#
firewall zone trust
set priority 85
add interface Vlanif12
#
firewall zone untrust
set priority 5
add interface Ethernet0/0/0
#
firewall zone dmz
set priority 50
add interface Ethernet2/0/0
#
ip route-static 10.0.1.0 255.255.255.0 10.0.10.1
ip route-static 10.0.2.0 255.255.255.0 10.0.20.2
ip route-static 10.0.3.0 255.255.255.0 10.0.30.3
#
policy interzone trust untrust outbound
policy 0
action permit
policy source 10.0.2.0 0.0.0.255
#
policy interzone dmz untrust inbound
policy 0
action permit
policy service service-set telnet
HC Series
HUAWEI TECHNOLOGIES
287
HCDA-HNTD
288
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
interface GigabitEthernet0/0/23
port link-type access
port default vlan 13
#
return
HC Series
HUAWEI TECHNOLOGIES
289
HCDA-HNTD
Layer 3 switching.
DHCP relay.
Firewall.
290
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
Topology
Scenario
Assume that you are a network administrator of a company.
The company network is divided into three areas: headquarters
network area, company branch network area, and branch office network
area. The three network areas communicate with each other using the FR
network connected to routers: R1, R2 and R3. Private lines are leased to
provide line backups for network services.
Router R1 resides in the headquarters network area, router R2 resides
in the company branch network area and router R3 resides in the branch
office network.
The firewall located in HQ area divides it into three zones:
Demilitarized Zone (DMZ), internal network zone and external network
zone.
For details about interface and IP address configurations, see the
preceding figure.
HC Series
HUAWEI TECHNOLOGIES
291
HCDA-HNTD
Tasks
The purpose of this comprehensive exercise is to test whether you
have understood the configuration methods described in the previous
19 labs. Therefore, only a brief description of the configuration
procedures and verification methods, not specific commands, is
provided.
292
HUAWEI TECHNOLOGIES
HC Series
HCDA-HNTD
huawei.
On the firewall, configure a default route with the next hop of
10.0.200.2. Set the route type to Type 1 and cost value to 20, and import
this route to the OSPF area in permanent advertisement mode.
HC Series
HUAWEI TECHNOLOGIES
293
HCDA-HNTD
Final Configurations
[R1]display current-configuration
[R2]display current-configuration
[R3]display current-configuration
[S1]display current-configuration
[S2]display current-configuration
[S3]display current-configuration
[S4]display current-configuration
[FW]display current-configuration
294
HUAWEI TECHNOLOGIES
HC Series