Professional Documents
Culture Documents
Mo
ni
ar
Le
ng
ur
so
Re
s:
ce
ht
tp
ea
/l
:/
rn
in
g.
hu
aw
ei
.c
om
/e
n
aw
ei
.c
om
/e
Huawei Certification
in
g.
hu
HCNA-HNTD
INTERMEDIATE
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
:/
/l
ea
Lab Guide
rn
aw
ei
.c
om
/e
hu
g.
Notice
ht
tp
:/
/l
ea
rn
in
s:
Huawei Certification
ur
ce
re
Le
ar
ni
ng
Re
so
Mo
Version 2.1
aw
ei
.c
om
/e
g.
hu
comprised of three levels to support and validate the growth and value of customer
in
The Huawei Certified Network Associate (HCNA) certification validates the skills
rn
ea
/l
networks, along with the capability to implement services and features within
:/
tp
HCNA certification covers fundamental skills for TCP/IP, routing, switching and
products,
ht
operation and
s:
management.
(VRP)
ce
ur
so
Re
ng
ni
network security, high availability and QoS, as well as application of the covered
ar
Le
re
for the diagnosis and troubleshooting of Huawei products, to equip engineers with
Mo
networks.
re
Mo
ni
ar
Le
ng
s:
ce
ur
so
Re
ht
tp
ea
/l
:/
rn
hu
g.
in
aw
ei
.c
om
/e
L3 Switch
L2 Switch
Cloud
g.
hu
Router
aw
ei
.c
om
/e
Reference Icons
Serial link
ea
rn
in
Ethernet link
/l
ht
tp
:/
In order to ensure that that the configuration given in this lab is supported on all
devices, it is recommended that the following device models and VRP versions
be used:
Device Model
R1
AR 2220
R2
AR 2220
R3
AR 2220
S5700-28C-EI-24S
ce
ur
so
Re
ng
S1
Le
ar
S3
Mo
re
S4
VRP version
S5700-28C-EI-24S
S3700-28TP-EI-AC
S3700-28TP-EI-AC
ni
S2
s:
Identifier
re
Mo
ni
ar
Le
ng
s:
ce
ur
so
Re
ht
tp
ea
/l
:/
rn
hu
g.
in
aw
ei
.c
om
/e
HCNA-HNTD Content
aw
ei
.c
om
/e
CONTENTS
MODULE 1 ETHERNET AND VLAN ....................................................................................................... 1
hu
in
g.
rn
ea
/l
:/
tp
ht
LAB 3-1 FILTERING ENTERPRISE DATA WITH ACCESS CONTROL LISTS. ........................................................... 103
s:
ce
so
ur
Re
ng
ni
Mo
re
Le
ar
HC Series
HUAWEI TECHNOLOGIES
Page1
re
Mo
ni
ar
Le
ng
s:
ce
ur
so
Re
ht
tp
ea
/l
:/
rn
hu
g.
in
aw
ei
.c
om
/e
Learning Objectives
aw
ei
.c
om
/e
in
g.
rn
hu
As a result of this lab section, you should achieve the following tasks:
ce
s:
ht
tp
:/
/l
ea
Topology
ur
Re
so
Scenario
Mo
re
Le
ar
ni
ng
HC Series
HUAWEI TECHNOLOGIES
Page1
aw
ei
.c
om
/e
Tasks
Step 1 Perform basic configuration on the Ethernet switches.
hu
Change the system name and view detailed information for G0/0/9 and
G0/0/10 on S1.
<Quidway>system-view
g.
[Quidway]sysname S1
in
rn
ea
Switch Port,PVID :
/l
tp
:/
: AUTO
ht
s:
Broadcast
CRC
0,Giants
Jabbers
0,Throttles
Runts
0,DropEvents
0,Symbols
0,Frames
5009016
Late Collisions :
0,ExcessiveCollisions :
Buffers Purged :
Discard
5,Total Error
ni
Discard
ng
Alignments
Ignoreds
ur
70,Multicast
6643714,Jumbo
so
Re
Unicast
ce
69,Total Error
Broadcast
Collisions
Mo
re
Le
ar
Unicast
Page2
345,Multicast
6642808,Jumbo
0,Deferreds
HUAWEI TECHNOLOGIES
HC Series
: 0.00%
aw
ei
.c
om
/e
hu
g.
in
rn
ea
5009062
CRC
3,Giants
Jabbers
0,Throttles
Runts
0,DropEvents
Alignments
0,Symbols
Ignoreds
0,Frames
Discard
5011284
Late Collisions :
0,ExcessiveCollisions :
Buffers Purged :
6642648,Jumbo
tp
ht
Broadcast
115,Multicast
s:
218,Total Error
ce
Unicast
:/
/l
Collisions
so
Broadcast
245,Multicast
6643751,Jumbo
0,Deferreds
Re
Unicast
ur
107,Total Error
ng
Discard
ni
: 0.00%
Le
ar
Mo
re
Set the rate of G0/0/9 and G0/0/10 on S1 to 100 Mbit/s and configure them to
work in full duplex mode. Before changing the interface rate and duplex mode,
disable auto-negotiation.
HC Series
HUAWEI TECHNOLOGIES
Page3
aw
ei
.c
om
/e
[S1-GigabitEthernet0/0/9]speed 100
[S1-GigabitEthernet0/0/9]duplex full
[S1-GigabitEthernet0/0/9]quit
[S1]interface GigabitEthernet 0/0/10
[S1-GigabitEthernet0/0/10]undo negotiation auto
[S1-GigabitEthernet0/0/10]speed 100
[S1-GigabitEthernet0/0/10]duplex full
g.
hu
Set the rate of G0/0/9 and G0/0/10 on S2 to 100 Mbit/s and configure them to
work in full duplex mode.
<Quidway>system-view
in
[Quidway]sysname S2
[S2-GigabitEthernet0/0/9]undo negotiation auto
ea
[S2-GigabitEthernet0/0/9]speed 100
/l
[S2-GigabitEthernet0/0/9]duplex full
:/
[S2-GigabitEthernet0/0/9]quit
[S2]interface GigabitEthernet 0/0/10
rn
[S2-GigabitEthernet0/0/10]speed 100
tp
ht
[S2-GigabitEthernet0/0/10]duplex full
ce
s:
Confirm that the rate and duplex mode of G0/0/9 and G0/0/10 have been set
on S1.
[S1]display interface GigabitEthernet 0/0/9
ur
Re
Switch Port,PVID :
so
ng
ni
Mo
re
Le
ar
output omitted
Page4
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
: AUTO
g.
hu
output omitted
in
ea
rn
Create Eth-Trunk 1 on S1 and S2. Delete the default configuration from G0/0/9
and G0/0/10 on S1 and S2, and then add G0/0/9 and G0/0/10 to Eth-Trunk 1.
/l
[S1]interface Eth-Trunk 1
[S1]interface GigabitEthernet 0/0/9
[S1-GigabitEthernet0/0/9]eth-trunk 1
tp
[S1-GigabitEthernet0/0/9]quit
:/
[S1-Eth-Trunk1]quit
ht
[S2]interface Eth-Trunk 1
ce
[S2-Eth-Trunk1]quit
s:
[S1-GigabitEthernet0/0/10]eth-trunk 1
ur
[S2-GigabitEthernet0/0/9]eth-trunk 1
so
[S2-GigabitEthernet0/0/9]quit
[S2-GigabitEthernet0/0/9]interface GigabitEthernet 0/0/10
Re
[S2-GigabitEthernet0/0/10]eth-trunk 1
ng
ni
[S1]display eth-trunk 1
Eth-Trunk1's state information is:
ar
WorkingMode: NORMAL
Le
----------------------------------------------------------------------------
re
PortName
Weight
Up
Mo
GigabitEthernet0/0/9
Status
HC Series
HUAWEI TECHNOLOGIES
Page5
GigabitEthernet0/0/10
aw
ei
.c
om
/e
[S2]display eth-trunk 1
Eth-Trunk1's state information is:
WorkingMode: NORMAL
---------------------------------------------------------------------------Status
Weight
Up
GigabitEthernet0/0/10
Up
g.
GigabitEthernet0/0/9
hu
PortName
rn
in
The greyed lines in the preceding information indicate that the Eth-Trunk works
properly.
ea
/l
:/
[S1-GigabitEthernet0/0/9]undo eth-trunk
tp
[S1-GigabitEthernet0/0/9]quit
ht
[S1-GigabitEthernet0/0/10]undo eth-trunk
s:
ce
[S2-GigabitEthernet0/0/9]undo eth-trunk
[S2-GigabitEthernet0/0/9]quit
ur
so
[S2-GigabitEthernet0/0/10]undo eth-trunk
Re
Create Eth-Trunk 1 and set the load balancing mode of the Eth-Trunk to static
LACP mode.
ng
[S1]interface Eth-Trunk 1
ni
[S1-Eth-Trunk1]mode lacp-static
[S1-Eth-Trunk1]quit
ar
Le
[S1-GigabitEthernet0/0/9]eth-trunk 1
[S1-GigabitEthernet0/0/9]quit
[S1]interface GigabitEthernet 0/0/10
Mo
re
[S1-GigabitEthernet0/0/10]eth-trunk 1
Page6
HUAWEI TECHNOLOGIES
HC Series
[S2-Eth-Trunk1]mode lacp-static
aw
ei
.c
om
/e
[S2-Eth-Trunk1]quit
[S2]interface GigabitEthernet 0/0/9
[S2-GigabitEthernet0/0/9]eth-trunk 1
[S2-GigabitEthernet0/0/9]interface GigabitEthernet 0/0/10
[S2-GigabitEthernet0/0/10]eth-trunk 1
Verify that the LACP-static mode has been enabled on the two links.
hu
[S1]display eth-trunk
Eth-Trunk1's state information is:
g.
Local:
WorkingMode: STATIC
Least Active-linknumber: 1
Max Active-linknumber: 8
Operate status: up
ea
rn
in
LAG ID: 1
Status
GigabitEthernet0/0/9
Selected 100M
32768
289
10111100 1
32768
10
289
10111100 1
tp
:/
ActorPortName
/l
----------------------------------------------------------------------------
Partner:
ht
---------------------------------------------------------------------------SysPri
SystemID
GigabitEthernet0/0/9
32768
4c1f-cc45-aacc
s:
ActorPortName
32768
4c1f-cc45-aacc 32768
289
10111100
10
289
10111100
ur
ce
GigabitEthernet0/0/10 32768
Re
so
Set the priority of the interface and determine active links on S1.
ng
ni
[S1-GigabitEthernet0/0/9]quit
ar
Mo
re
Le
HC Series
HUAWEI TECHNOLOGIES
Page7
[S1]display eth-trunk 1
aw
ei
.c
om
/e
WorkingMode: STATIC
Least Active-linknumber: 1
Max Active-linknumber: 8
Operate status: up
ActorPortName
Status
Selected 100M
100
289
100
10
289
10111100 1
in
Partner:
10111100 1
g.
GigabitEthernet0/0/9
hu
----------------------------------------------------------------------------
rn
--------------------------------------------------------------------------SysPri
SystemID
GigabitEthernet0/0/9
32768
4c1f-cc45-aacc 32768
289
10111100
GigabitEthernet0/0/10 32768
4c1f-cc45-aacc 32768
10
289
10111100
/l
ea
ActorPortName
:/
[S2]display eth-trunk 1
tp
WorkingMode: STATIC
Least Active-linknumber: 1
Max Active-linknumber: 8
ce
Operate status: up
s:
ht
LAG ID: 1
---------------------------------------------------------------------------Status
Selected 100M
so
GigabitEthernet0/0/9
ur
ActorPortName
289
10111100 1
32768
10
289
10111100 1
Re
Partner:
32768
---------------------------------------------------------------------------SysPri
GigabitEthernet0/0/9
100
4c1f-cc45-aace
100
289
10111100
GigabitEthernet0/0/10 100
4c1f-cc45-aace
100
10
289
10111100
SystemID
ar
ni
ng
ActorPortName
Le
Final Configuration
[S1]display current-configuration
re
Mo
Page8
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
g.
in
interface GigabitEthernet0/0/10
eth-trunk 1
rn
ea
/l
ht
tp
[S2]display current-configuration
:/
return
sysname S2
s:
#
interface Eth-Trunk1
ce
mode lacp-static
ur
interface GigabitEthernet0/0/9
so
eth-trunk 1
Re
ng
interface GigabitEthernet0/0/10
ni
eth-trunk 1
Le
ar
speed 100
Mo
re
return
HC Series
HUAWEI TECHNOLOGIES
Page9
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
g.
hu
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
Topology
Re
Scenario
so
Mo
re
Le
ar
ni
ng
Page10
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 2. For those continuing from previous labs, begin at step 2.
Establish an Eth-trunk link between S1 and S2.
hu
<Quidway>system-view
[Quidway]sysname S1
g.
[S1]interface Eth-trunk 1
in
[S1-Eth-Trunk1]mode lacp-static
[S1-Eth-Trunk1]quit
rn
[S1]interface GigabitEthernet0/0/9
[S1-Gigabitethernet0/0/9]eth-trunk 1
ea
[S1-Gigabitethernet0/0/9]interface GigabitEthernet0/0/10
/l
[S1-Gigabitethernet0/0/10]eth-trunk 1
:/
tp
<Quidway>system-view
ht
[Quidway]sysname S2
[S2]interface eth-trunk 1
[S2-Eth-Trunk1]mode lacp-static
s:
ce
so
ur
ng
Re
Unused interfaces must be disabled to ensure test result accuracy. In this lab,
interfaces Ethernet 0/0/1 and Ethernet 0/0/23 on S3 and Ethernet0/0/14 on S4
need to be shut down.
<Quidway>system-view
ni
ar
Le
[S3-Ethernet0/0/1]shutdown
[S3-Ethernet0/0/1]quit
[S3]interface Ethernet 0/0/23
Mo
re
[S3-Ethernet0/0/23]shutdown
HC Series
HUAWEI TECHNOLOGIES
Page11
<Quidway>system-view
aw
ei
.c
om
/e
hu
The link type of a switch port interface is hybrid by default. Configure the port
link-type for Eth-Trunk 1 to become a trunk port. Additionally, allow all VLANS
to be permitted over the trunk port.
[S1]interface Eth-Trunk 1
g.
in
rn
[S2]interface Eth-Trunk 1
/l
ea
tp
:/
s:
ht
Use S3, R1, R3, and S4 as non-VLAN aware hosts. There are two methods to
create VLANs, and two methods to bind interfaces to the created VLANs, S1
and S2 are used to demonstrate the two methods. All interfaces associated
with hosts should be configured as access ports.
ur
ce
On S1, associate interface Gigabit Ethernet 0/0/13 with VLAN 3, and interface
Gigabit Ethernet 0/0/1 with VLAN 4.
so
On S2, associate interface Gigabit Ethernet 0/0/2 with VLAN4, and Gigabit
Ethernet 0/0/24 with VLAN 2.
Re
[S1]interface GigabitEthernet0/0/13
[S1-GigabitEthernet0/0/13]port link-type access
ng
[S1-GigabitEthernet0/0/13]quit
[S1]interface GigabitEthernet0/0/1
ni
ar
[S1]vlan 2
Le
[S1-vlan2]vlan 3
[S1-vlan3]port GigabitEthernet0/0/13
[S1-vlan3]vlan 4
Mo
re
[S1-vlan4]port GigabitEthernet0/0/1
Page12
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
Verify that the VLAN configuration has been correctly applied to S1 and S2.
<S1>display vlan
g.
TG: Tagged;
MP: Vlan-mapping;
UT: Untagged;
ST: Vlan-stacking;
*: Management-vlan;
ea
#: ProtocolTransparent-vlan;
rn
U: Up;
in
----------------------------------------------------------------------------
Ports
:/
VID Type
/l
----------------------------------------------------------------------------
UT:GE0/0/2(U) GE0/0/3(U)
GE0/0/4(U)
GE0/0/5(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(D)
GE0/0/12(D)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(U)
GE0/0/22(U)
GE0/0/23(U)
GE0/0/24(D)
tp
common
s:
ht
----------------------------------------------------------------------------
Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common UT:GE0/0/13(U)
common UT:GE0/0/1(U)
ur
ce
so
TG:Eth-Trunk1(U)
Re
TG:Eth-Trunk1(U)
Mo
re
Le
ar
ni
ng
output omitted
HC Series
HUAWEI TECHNOLOGIES
Page13
U: Up;
D: Down;
TG: Tagged;
MP: Vlan-mapping;
UT: Untagged;
ST: Vlan-stacking;
#: ProtocolTransparent-vlan;
*: Management-vlan;
aw
ei
.c
om
/e
----------------------------------------------------------------------------
---------------------------------------------------------------------------VID Type
Ports
---------------------------------------------------------------------------GE0/0/4(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/12(U)
GE0/0/13(U)
GE0/0/14(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/20(D)
GE0/0/21(D)
GE0/0/22(D)
common UT:GE0/0/3(U)
GE0/0/23(D)
:/
GE0/0/19(D)
/l
TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
GE0/0/15(D)
ea
common UT:GE0/0/24(U)
GE0/0/11(U)
rn
Eth-Trunk1(U)
2
GE0/0/5(U)
hu
UT:GE0/0/1(U) GE0/0/2(U)
g.
common
in
TG:Eth-Trunk1(U)
tp
output omitted
s:
ht
The highlighted entries confirm the binding of the interfaces to each created
VLAN. All VLANs are permitted over the trunk (TG) port Eth-Trunk 1.
ur
ce
Re
so
Configure IP addresses on hosts, R1, S3, R3, and S4 as part of the respective
VLANs. Physical port interfaces on switches cannot be configured with IP
addresses, therefore configure the native management interface Vlanif1 with
the IP address for the switch.
ng
<Huawei>system-view
[Huawei]sysname R1
ni
[R1]interface GigabitEthernet0/0/1
ar
Le
[S3]interface vlanif 1
Mo
re
Page14
HUAWEI TECHNOLOGIES
HC Series
<Huawei>system-view
aw
ei
.c
om
/e
[Huawei]sysname R3
[R3]interface GigabitEthernet0/0/2
[R3-GigabitEthernet0/0/2]ip address 10.0.4.3 24
[S4]interface vlanif 1
[S4-vlanif1]ip address 10.0.4.4 24
hu
in
g.
rn
[R1]ping 10.0.4.3
ea
/l
:/
ht
s:
tp
ce
ur
[R1]ping 10.0.4.4
so
Re
ng
ni
ar
Le
0 packet(s) received
re
Mo
You may wish to also try between R1 and S3, and between R3 and S4.
HC Series
HUAWEI TECHNOLOGIES
Page15
aw
ei
.c
om
/e
hu
in
g.
rn
ea
/l
:/
tp
[S2-GigabitEthernet0/0/3]quit
ht
s:
ur
ce
Re
so
The port hybrid pvid vlan command will ensure frames received from the
host are tagged with the appropriate VLAN tag. Frames received from VLAN 2
or 4 will be untagged at the interface before being forwarded to the host.
ng
ni
<R1>ping 10.0.4.3
ar
Le
Mo
re
Page16
HUAWEI TECHNOLOGIES
HC Series
5 packet(s) transmitted
aw
ei
.c
om
/e
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/2/10 ms
Use the ping command to test whether S4 in VLAN 2 is now reachable from R1
in VLAN 4.
<R1>ping 10.0.4.4
hu
g.
in
ea
rn
/l
5 packet(s) transmitted
0.00% packet loss
tp
:/
5 packet(s) received
so
ur
Final Configuration
ce
s:
ht
In using the hybrid port link type, frames originating from VLAN 4 are now able
to be received by VLAN 2 and vice versa, whilst still being unable to reach the
host address of 10.0.4.2 in VLAN 3.
[R1]display current-configuration
Re
[V200R003C00SPC200]
#
ng
sysname R1
#
ni
interface GigabitEthernet0/0/1
#
ar
Le
return
re
[S3]display current-configuration
Mo
HC Series
HUAWEI TECHNOLOGIES
Page17
sysname S3
aw
ei
.c
om
/e
#
interface Vlanif1
ip address 10.0.4.2 255.255.255.0
#
interface Ethernet0/0/1
shutdown
#
interface Ethernet0/0/23
hu
shutdown
#
in
g.
return
[S1]display current-configuration
rn
ea
/l
:/
vlan batch 2 to 4
#
tp
ht
interface Eth-Trunk1
port link-type trunk
s:
ce
ur
interface GigabitEthernet0/0/1
port hybrid pvid vlan 4
so
Re
interface GigabitEthernet0/0/9
eth-trunk 1
ng
ni
ar
Le
interface GigabitEthernet0/0/10
eth-trunk 1
lacp priority 100
re
Mo
speed 100
Page18
HUAWEI TECHNOLOGIES
HC Series
interface GigabitEthernet0/0/13
aw
ei
.c
om
/e
hu
sysname S2
#
g.
vlan batch 2 4
in
#
interface Eth-Trunk1
rn
ea
/l
:/
interface GigabitEthernet0/0/3
port hybrid pvid vlan 4
tp
ht
interface GigabitEthernet0/0/9
eth-trunk 1
s:
ce
ur
interface GigabitEthernet0/0/10
eth-trunk 1
so
Re
speed 100
#
interface GigabitEthernet0/0/24
ng
ni
Le
ar
interface NULL0
user-interface con 0
user-interface vty 0 4
re
Mo
return
HC Series
HUAWEI TECHNOLOGIES
Page19
[R3]display current-configuration
aw
ei
.c
om
/e
[V200R003C00SPC200]
#
sysname R3
#
interface GigabitEthernet0/0/2
ip address 10.0.4.3 255.255.255.0
#
hu
return
[S4]display current-configuration
g.
in
rn
ea
interface Vlanif1
ip address 10.0.4.4 255.255.255.0
/l
:/
interface Ethernet0/0/14
shutdown
tp
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
return
Page20
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
Configuration of GVRP.
Setting of the GVRP registration mode.
ht
tp
:/
/l
ea
rn
in
g.
hu
Topology
s:
ur
ce
Scenario
Mo
re
Le
ar
ni
ng
Re
so
HC Series
HUAWEI TECHNOLOGIES
Page21
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
<Quidway>system-view
[Quidway]sysname S1
hu
g.
[S1-GigabitEthernet0/0/9]shutdown
[S1-GigabitEthernet0/0/9]quit
in
rn
[S1-GigabitEthernet0/0/10]shutdown
ea
<Quidway>system-view
[Quidway]sysname S2
/l
ht
[S2-GigabitEthernet0/0/10]shutdown
[Quidway]sysname S3
ur
[Quidway]sysname S4
ce
[S3-Ethernet0/0/23]shutdown
s:
<Quidway>system-view
<Quidway>system-view
tp
:/
[S2-GigabitEthernet0/0/9]shutdown
Re
so
[S4-Ethernet0/0/14]shutdown
ng
ar
ni
Remove the unsed VLANs and disable the Eth-Trunk interface on S1 and S2.
Remove Vlanif1 on S3 and S4 and bring up interface Ethernet 0/0/1 on S3.
[S1]undo vlan batch 2 to 4
Le
re
[S1]interface Eth-Trunk 1
Mo
[S1-Eth-Trunk1]shutdown
Page22
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Info: This operation may take a few seconds. Please wait for a moment...done.
[S2]interface Eth-Trunk 1
[S2-Eth-Trunk1]shutdown
[S2-Eth-Trunk1]quit
[S2]interface GigabitEthernet 0/0/24
[S2-GigabitEthernet0/0/24]undo port hybrid vlan 2 4
[S3]interface Ethernet 0/0/1
hu
[S3-Ethernet0/0/1]undo shutdown
[S3-Ethernet0/0/1]quit
g.
in
Info: This operation may take a few seconds. Please wait for a moment...succeeded.
rn
/l
ea
Info: This operation may take a few seconds. Please wait for a moment...succeeded.
:/
tp
ht
s:
ce
ur
so
Re
ng
ni
ar
Le
re
Mo
HC Series
HUAWEI TECHNOLOGIES
Page23
aw
ei
.c
om
/e
hu
[S3-Ethernet0/0/13]quit
[S3]interface Ethernet 0/0/1
in
g.
[S3-Ethernet0/0/1]gvrp
[S2]gvrp
rn
ea
[S2-Gigabitethernet0/0/24]gvrp
/l
[S4]gvrp
[S4]interface Ethernet0/0/24
:/
[S4-Ethernet0/0/24]gvrp
tp
[S4-Ethernet0/0/24]quit
[S4]interface Ethernet 0/0/1
ht
[S4-Ethernet0/0/1]gvrp
s:
Create VLAN 100 on S1, VLAN 200 on S2 and VLAN 2 on S1, S2, S3 and S4.
ce
ur
[S3]vlan 2
so
[S4]vlan 2
Re
Run the display gvrp statistics command on S3 and S4 to view the GVRP
statistics.
ng
: 0
: 5489-98ec-f012
: Normal
Le
GVRP status
ar
ni
Mo
re
Page24
: Enabled
HUAWEI TECHNOLOGIES
HC Series
: 4c1f-cc45-aace
: Normal
aw
ei
.c
om
/e
: 0
: 781d-ba99-d977
: Normal
hu
GVRP status
: 0
: 4c1f-cc45-aacc
: Normal
ea
rn
in
g.
GVRP status
/l
The registration type is set as normal by default. Use the display vlan
command to verify the VLAN configuration on S3 and S4.
:/
[S3]display vlan
tp
---------------------------------------------------------------------------D: Down;
TG: Tagged;
MP: Vlan-mapping;
ht
U: Up;
UT: Untagged;
ST: Vlan-stacking;
*: Management-vlan;
s:
#: ProtocolTransparent-vlan;
VID Type
ce
---------------------------------------------------------------------------Ports
common
UT:Eth0/0/1(U) Eth0/0/2(D)
so
ur
---------------------------------------------------------------------------Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
ng
Re
Eth0/0/5(D)
ni
common
Eth0/0/4(D)
TG:Eth0/0/1(U) Eth0/0/13(U)
ar
Eth0/0/3(D)
Le
Mo
re
output omitted
HC Series
HUAWEI TECHNOLOGIES
Page25
U: Up;
D: Down;
TG: Tagged;
MP: Vlan-mapping;
UT: Untagged;
ST: Vlan-stacking;
#: ProtocolTransparent-vlan;
*: Management-vlan;
aw
ei
.c
om
/e
----------------------------------------------------------------------------
---------------------------------------------------------------------------VID Type
Ports
----------------------------------------------------------------------------
common
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/13(D)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(U)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
hu
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/5(D)
Eth0/0/12(D)
g.
Eth0/0/16(D)
Eth0/0/20(D)
in
rn
common
TG:Eth0/0/1(U) Eth0/0/24(U)
ea
/l
:/
output omitted
ht
tp
S3 and S4 are learning VLAN 100 and VLAN 200 dynamically, but only in one
direction. VLAN 2 has been statically defined. Create VLAN 200 on S1 and
VLAN 100 on S2 to enable 2-way propagation.
[S1]vlan 200
s:
[S2]vlan 100
ce
so
VID Type
ur
[S3]display vlan
---------------------------------------------------------------------------UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
Re
common
ar
ni
ng
common
Le
TG:Eth0/0/1(U) Eth0/0/13(U)
re
Mo
output omitted
Page26
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
VID Type
output omitted
---------------------------------------------------------------------------common
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(D)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(U)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
hu
TG:Eth0/0/1(U) Eth0/0/24(U)
g.
in
rn
output omitted
/l
ea
The highlighted entries indicate the interfaces that have been added to
VLAN100 and VLAN200 on both S3 and S4.
:/
ht
tp
Change the registration type of Ethernet 0/0/1 on S3 to fixed. The same steps
can be performed on Ethernet 0/0/1 of S4.
[S3]interface Ethernet 0/0/1
ce
s:
Run the display gvrp statistics command on S3 and S4 to view the changes.
ur
so
: Enabled
: 12
: 5489-98ec-f012
: Fixed
ng
Re
Mo
re
Le
ar
ni
HC Series
HUAWEI TECHNOLOGIES
Page27
Run the display vlan command to view the effect of the fixed registration type.
[S3]display vlan
VID Type
aw
ei
.c
om
/e
output omitted
Ports
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
in
Eth0/0/24(D)
g.
hu
----------------------------------------------------------------------------
rn
/l
ea
The highlighted entries show that interface Ethernet 0/0/1 is not in registering
dynamic VLANs 100 and 200.
tp
:/
ht
s:
Run the display gvrp statistics command to view the changes to GVRP.
ce
ur
: Enabled
: 18
: 5489-98ec-f012
: Forbidden
ng
Re
so
Mo
re
Le
ar
ni
The GVRP registration type is set to forbidden on the Ethernet 0/0/1 interface.
Page28
HUAWEI TECHNOLOGIES
HC Series
Run the display vlan command to view the effect of the forbidden registration.
[S3]display vlan
aw
ei
.c
om
/e
Ports
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
TG:Eth0/0/13(U)
Eth0/0/20(D)
Eth0/0/24(D)
g.
common
in
hu
----------------------------------------------------------------------------
rn
ea
:/
/l
Forbidden mode only allows VLAN1 pass over interface Ethernet 0/0/1, all
other VLANS are restricted.
ht
tp
Final Configuration
[S1]dis current-configuration
#
s:
ce
sysname S1
vlan batch 2 100 200
#
so
gvrp
ur
Re
interface Eth-Trunk1
ng
shutdown
ni
ar
mode lacp-static
Le
interface GigabitEthernet0/0/1
port hybrid untagged vlan 2 4
re
interface GigabitEthernet0/0/9
Mo
shutdown
HC Series
HUAWEI TECHNOLOGIES
Page29
aw
ei
.c
om
/e
hu
speed 100
#
g.
interface GigabitEthernet0/0/13
in
rn
gvrp
ea
/l
return
:/
[S2]dis current-configuration
!Software Version V100R006C00SPC800
sysname S2
ht
tp
s:
#
gvrp
ce
#
shutdown
so
ur
interface Eth-Trunk1
Re
ng
interface GigabitEthernet0/0/3
ni
ar
interface GigabitEthernet0/0/9
Le
shutdown
eth-trunk 1
undo negotiation auto
re
speed 100
Mo
Page30
HUAWEI TECHNOLOGIES
HC Series
shutdown
aw
ei
.c
om
/e
eth-trunk 1
undo negotiation auto
speed 100
#
interface GigabitEthernet0/0/24
port link-type trunk
port trunk allow-pass vlan 2 to 4094
gvrp
hu
g.
return
in
[S3]display current-configuration
#
rn
ea
sysname S3
#
/l
vlan batch 2
:/
#
gvrp
tp
#
interface Ethernet0/0/1
ht
s:
gvrp
#
port link-type trunk
ur
interface Ethernet0/0/13
ce
so
Re
gvrp
#
shutdown
ar
return
ni
ng
interface Ethernet0/0/23
Le
[S4]display current-configuration
#
re
sysname S4
Mo
HC Series
HUAWEI TECHNOLOGIES
Page31
aw
ei
.c
om
/e
gvrp
#
interface Ethernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
gvrp
gvrp registration forbidden
#
hu
interface Ethernet0/0/14
shutdown
g.
in
interface Ethernet0/0/24
port link-type trunk
rn
ea
gvrp
#
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
:/
/l
return
Page32
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
Establishment of a trunk inteface for VLAN routing.
Configuration of sub-interfaces on a single physical interface.
Enabling of ARP messages to be broadcast between VLANS.
hu
so
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
g.
Topology
ng
Re
ni
Scenario
Mo
re
Le
ar
HC Series
HUAWEI TECHNOLOGIES
Page33
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
hu
Configure the system name for R1, R3 and S1. Configure the IP address
10.0.4.1/24 on interface Gigabit Ethernet 0/0/1.
g.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
in
[Huawei]sysname R1
ea
rn
/l
<Huawei>system-view
tp
:/
[Huawei]sysname R3
<Quidway>system-view
ht
[Quidway]sysname S1
ce
s:
so
ur
Remove the IP address 10.0.4.3 from R3, and disable the swich interfaces
between S1 and S3 and S2 and S4 respectively.
[R3]interface GigabitEthernet 0/0/2
ng
Re
[R3-GigabitEthernet0/0/2]undo ip address
[S1]undo gvrp
ni
ar
Info: This operation may take a few seconds. Please wait for a moment...done.
[S1]interface GigabitEthernet 0/0/13
Le
re
[S1-GigabitEthernet0/0/13]quit
Mo
Page34
HUAWEI TECHNOLOGIES
HC Series
[S1-GigabitEthernet0/0/1]quit
aw
ei
.c
om
/e
Info: This operation may take a few seconds. Please wait for a moment...done.
[S2]undo gvrp
Info: This operation may take a few seconds. Please wait for a moment...done.
[S2]interface GigabitEthernet 0/0/24
hu
g.
[S2-GigabitEthernet0/0/24]quit
[S2-GigabitEthernet0/0/3]undo port hybrid vlan 2 4
rn
[S2-GigabitEthernet0/0/3]quit
in
ea
:/
/l
Info: This operation may take a few seconds. Please wait for a moment...done.
[S3]undo gvrp
tp
ht
s:
ce
ur
[S4]undo gvrp
Re
[S3]undo vlan 2
so
[S3-Ethernet0/0/1]quit
ng
Info: This operation may take a few seconds. Please wait for a moment...done.
ni
ar
Le
[S4-Ethernet0/0/24]quit
[S4]interface Ethernet 0/0/1
[S4-Ethernet0/0/1]undo port trunk allow-pass vlan 2 to 4094
re
[S4-Ethernet0/0/1]quit
Mo
[S4]undo vlan 2
HC Series
HUAWEI TECHNOLOGIES
Page35
aw
ei
.c
om
/e
hu
in
g.
/l
ea
rn
Info: This operation may take a few seconds. Please wait for a moment...done.
[S1]interface GigabitEthernet 0/0/1
[S1-GigabitEthernet0/0/1]quit
:/
[S1]interface GigabitEthernet0/0/3
tp
ht
[S1-GigabitEthernet0/0/3]quit
s:
Set interface Gigabit Ethernet 0/0/2 as a trunk link for VLANs 4 and 8.
ce
[S1]interface GigabitEthernet0/0/2
ur
so
Re
ni
ng
ar
Le
[Huawei]sysname R2
[R2]interface GigabitEthernet0/0/1.1
[R2-GigabitEthernet0/0/1.1]ip address 10.0.4.254 24
Mo
re
Page36
HUAWEI TECHNOLOGIES
HC Series
[R2-GigabitEthernet0/0/1.1]quit
aw
ei
.c
om
/e
[R2]interface GigabitEthernet0/0/1.3
[R2-GigabitEthernet0/0/1.3]ip address 10.0.8.254 24
[R2-GigabitEthernet0/0/1.3]dot1q termination vid 8
[R2-GigabitEthernet0/0/1.3]arp broadcast enable
hu
g.
in
ea
rn
/l
5 packet(s) transmitted
:/
0 packet(s) received
tp
ht
s:
ce
so
<R1>ping 10.0.8.1
ur
Re
ng
ni
ar
Le
Mo
re
5 packet(s) received
HC Series
HUAWEI TECHNOLOGIES
Page37
aw
ei
.c
om
/e
Routes : 10
Cost Flags NextHop
Interface
10.0.4.0/24
Direct 0
10.0.4.254
GigabitEthernet0/0/1.1
10.0.4.254/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.1
10.0.4.255/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.1
10.0.8.0/24
Direct 0
10.0.8.254
GigabitEthernet0/0/1.3
10.0.8.254/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.3
10.0.8.255/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.3
127.0.0.0/8
Direct 0
127.0.0.1
127.0.0.1/32
Direct 0
127.0.0.1
127.255.255.255/32 Direct 0
127.0.0.1
255.255.255.255/32 Direct 0
127.0.0.1
in
g.
hu
InLoopBack0
InLoopBack0
InLoopBack0
/l
ea
rn
InLoopBack0
tp
:/
Final Configuration
[R1]display current-configuration
ht
[V200R003C00SPC200]
#
s:
sysname R1
#
ce
interface GigabitEthernet0/0/1
ur
so
Re
user-interface con 0
authentication-mode password
ng
ar
ni
user-interface vty 0 4
#
Mo
re
Le
return
Page38
HUAWEI TECHNOLOGIES
HC Series
[V200R003C00SPC200]
aw
ei
.c
om
/e
#
sysname R2
#
interface GigabitEthernet0/0/1
#
interface GigabitEthernet0/0/1.1
dot1q termination vid 4
ip address 10.0.4.254 255.255.255.0
hu
g.
interface GigabitEthernet0/0/1.3
in
rn
ea
#
user-interface con 0
/l
authentication-mode password
:/
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
tp
user-interface vty 0 4
#
s:
ht
return
[V200R003C00SPC200]
ur
ce
[R3]dis current-configuration
sysname R3
so
Re
interface GigabitEthernet0/0/1
ip address 10.0.8.1 255.255.255.0
#
ng
ni
user-interface con 0
ar
authentication-mode password
Le
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
#
return
Mo
re
user-interface vty 0 4
HC Series
HUAWEI TECHNOLOGIES
Page39
aw
ei
.c
om
/e
hu
#
interface GigabitEthernet0/0/2
g.
in
rn
interface GigabitEthernet0/0/3
ea
/l
:/
user-interface con 0
user-interface vty 0 4
tp
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
return
Page40
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
hu
g.
ce
s:
ht
tp
:/
/l
ea
rn
in
Topology
so
ur
Re
Scenario
Mo
re
Le
ar
ni
ng
The introduction of layer three switches into the enterprise network opened up
opportunities for streamlining the current VLAN routing configuration. The
network administrator has been given the task to implement VLAN routing
using only the layer three switches to support communication between the
VLANs in the network as displayed in the topology. VLANs should be capable
of inter VLAN communication. Additionally S1 and S2 are expected to
communicate over a Layer 3 for which routing protocol support is required.
HC Series
HUAWEI TECHNOLOGIES
Page41
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
hu
g.
<Huawei>system-view
in
ea
rn
[Huawei]sysname R1
/l
<Huawei>system-view
tp
:/
[Huawei]sysname R3
<Quidway>system-view
ht
[Quidway]sysname S1
[S1]interface Eth-Trunk 1
s:
[S1-Eth-Trunk1]mode lacp-static
[S1-Eth-Trunk1]port link-type trunk
ce
ur
[S1-Eth-Trunk1]quit
so
[S1-GigabitEthernet0/0/9]eth-trunk 1
[S1-GigabitEthernet0/0/9]interface GigabitEthernet 0/0/10
Re
[S1-GigabitEthernet0/0/10]eth-trunk 1
ng
<Quidway>system-view
ni
[Quidway]sysname S2
[S2]interface Eth-Trunk 1
ar
[S2-Eth-Trunk1]mode lacp-static
[S2-Eth-Trunk1]port link-type trunk
Le
re
Mo
[S2-GigabitEthernet0/0/9]eth-trunk 1
Page42
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
[S2-GigabitEthernet0/0/10]eth-trunk 1
<Quidway>system-view
[Quidway]sysname S3
[S3]interface Ethernet 0/0/23
[S3-Ethernet0/0/23]shutdown
<Quidway>system-view
[Quidway]sysname S4
hu
rn
in
g.
[S4-Ethernet0/0/14]shutdown
ea
/l
:/
ht
tp
[R3-GigabitEthernet0/0/1]undo ip address
s:
[R3-GigabitEthernet0/0/1]quit
ur
ce
so
Info: This operation may take a few seconds. Please wait for a moment...done.
Re
ng
ni
[S1-GigabitEthernet0/0/13]undo shutdown
ar
[S2]interface GigabitEthernet0/0/24
Mo
re
Le
[S2-GigabitEthernet0/0/24]undo shutdown
HC Series
HUAWEI TECHNOLOGIES
Page43
aw
ei
.c
om
/e
[S1]interface Eth-Trunk 1
[S1-Eth-Trunk1]undo shutdown
[S2]interface Eth-Trunk 1
[S2-Eth-Trunk1]undo shutdown
hu
in
g.
Info: This operation may take a few seconds. Please wait for a moment...done.
[S2]vlan batch 3 to 7
ea
rn
Info: This operation may take a few seconds. Please wait for a moment...done.
/l
:/
tp
VID Type
common UT:GE0/0/1(U)
GE0/0/2(D)
GE0/0/3(U)
GE0/0/4(U)
GE0/0/5(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/11(D)
GE0/0/12(D)
GE0/0/13(D)
GE0/0/14(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/20(D)
GE0/0/21(U)
GE0/0/22(U)
GE0/0/24(D)
Eth-Trunk1(U)
s:
ht
----------------------------------------------------------------------------
GE0/0/19(D)
ur
GE0/0/23(U)
ce
GE0/0/15(D)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
ng
Re
so
GE0/0/8(D)
Mo
re
Le
ar
ni
output omitted
Page44
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
output omitted
Ports
---------------------------------------------------------------------------common UT:GE0/0/1(U)
GE0/0/2(D)
GE0/0/3(U)
GE0/0/4(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(U)
GE0/0/12(U)
GE0/0/13(U)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(D)
GE0/0/22(D)
GE0/0/23(D)
GE0/0/24(D)
Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
g.
common TG:Eth-Trunk1(U)
in
hu
GE0/0/5(U)
rn
/l
ea
tp
:/
Add interfaces Gigabit Ethernet 0/0/1 and 0/0/13 of S1 to VLAN 4 and VLAN 3
respectively. For S2, add interfaces Gigabit Ethernet 0/0/3 and G0/0/24 to
VLAN 6 and VLAN 7 respectively.
[S1]interface Eth-Trunk 1
ht
s:
ce
ur
[S1-GigabitEthernet0/0/1]quit
so
Re
ng
ni
[S2-Eth-Trunk1]quit
[S2]interface GigabitEthernet 0/0/3
ar
Le
re
Mo
HC Series
HUAWEI TECHNOLOGIES
Page45
aw
ei
.c
om
/e
output omitted
Ports
---------------------------------------------------------------------------1
common UT:GE0/0/2(D)
GE0/0/3(U)
GE0/0/4(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(D)
GE0/0/12(D)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(U)
GE0/0/22(U)
GE0/0/23(U)
GE0/0/24(D)
hu
Eth-Trunk1(U)
3
common UT:GE0/0/13(U)
g.
TG:Eth-Trunk1(U)
common UT:GE0/0/1(U)
in
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
ea
rn
TG:Eth-Trunk1(U)
:/
/l
output omitted
<S2>display vlan
tp
ht
output omitted
VID Type
GE0/0/5(U)
Ports
common UT:GE0/0/1(U)
GE0/0/6(D)
GE0/0/2(D)
GE0/0/4(U)
GE0/0/5(U)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(U)
GE0/0/13(U)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(D)
GE0/0/22(D)
GE0/0/23(D)
so
ur
GE0/0/12(U)
ce
s:
----------------------------------------------------------------------------
Re
Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common UT:GE0/0/3(U)
ni
ng
TG:Eth-Trunk1(U)
common UT:GE0/0/24(U)
TG:Eth-Trunk1(U)
Mo
re
Le
ar
Page46
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
g.
hu
in
rn
[S2-Vlanif5]interface Vlanif 6
[S2-Vlanif6]ip address 10.0.6.254 24
ea
[S2-Vlanif6]interface Vlanif 7
/l
tp
:/
Step 6 IP addressing and default routes for R1, R3, S3 and S4.
ce
s:
ht
ur
so
[S3]interface Vlanif 1
Re
[S3-Vlanif1]quit
ng
ni
Le
ar
re
Mo
[S4-Vlanif1]quit
[S4]ip route-static 0.0.0.0 0.0.0.0 10.0.7.254
HC Series
HUAWEI TECHNOLOGIES
Page47
aw
ei
.c
om
/e
g.
hu
in
5 packet(s) transmitted
rn
5 packet(s) received
0.00% packet loss
/l
:/
<R1>ping 10.0.6.3
ea
tp
ht
s:
ce
ur
so
0 packet(s) received
Re
ng
ni
[R1]tracert 10.0.6.3
ar
Le
1 10.0.4.254 17 ms 4 ms 4 ms
Mo
re
2 * * *
Page48
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
According to the command output, R1 has sent data packets to the destination
address 10.0.6.3, but the gateway at 10.0.4.254 responds that the network is
unreachable.
Check whether the network is unreachable on the gateway (S1).
[S1]display ip routing-table
Route Flags: R - relay, D - download to fib
Destination/Mask
10.0.3.0/24
Direct
10.0.3.254 Vlanif3
10.0.3.254/32
Direct
127.0.0.1
10.0.4.0/24
Direct
10.0.4.254 Vlanif4
10.0.4.254/32
Direct
10.0.5.0/24
Direct
10.0.5.1/32
Direct
127.0.0.0/8
Direct
127.0.0.1/32
Direct
in
rn
ea
127.0.0.1
InLoopBack0
InLoopBack0
10.0.5.1
Vlanif5
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
/l
tp
:/
Interface
g.
Flags NextHop
hu
Destinations : 8
ce
s:
ht
According to the command output, S1 does not have a route to the network
segment 10.0.6.0 because the network segment is not directly connected to
S1. In addition, no static route or dynamic routing protocol has been configured
to advertise the routes.
[S1-ospf-1]area 0
so
ur
ng
Re
[S2-ospf-1]area 0
Mo
re
Le
ar
ni
HC Series
HUAWEI TECHNOLOGIES
Page49
After the configuration, wait until S1 and S2 exchange OSPF routes and
complete the link state database, then view the resulting routing table of S1.
aw
ei
.c
om
/e
[S1]display ip routing-table
Route Flags: R - relay, D - download to fib
Destination/Mask
Routes : 10
Flags NextHop
Interface
hu
Destinations : 10
Direct 0
10.0.3.254
10.0.3.254/32
Direct 0
127.0.0.1
10.0.4.0/24
Direct 0
10.0.4.254
Vlanif4
10.0.4.254/32
Direct 0
127.0.0.1
InLoopBack0
10.0.5.0/24
Direct 0
10.0.5.1
Vlanif5
10.0.5.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.6.0/24
OSPF
10
10.0.5.2
Vlanif5
10.0.7.0/24
OSPF
10
10.0.5.2
Vlanif5
127.0.0.0/8
Direct 0
127.0.0.1/32
Direct 0
/l
ea
rn
in
g.
10.0.3.0/24
Vlanif3
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
tp
:/
ht
S1 has learned two routes using OSPF. Test connectivity between R1 and R3.
[R1]ping 10.0.6.3
s:
ce
ur
so
Re
ng
5 packet(s) received
0.00% packet loss
Mo
re
Le
ar
ni
Page50
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
5 packet(s) received
0.00% packet loss
in
g.
rn
Final Configuration
ea
[R1]display current-configuration
/l
[V200R003C00SPC200]
#
#
interface GigabitEthernet0/0/1
ht
tp
:/
sysname R1
s:
ce
user-interface con 0
authentication-mode password
ur
so
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
Re
ng
return
ar
ni
[S1]display current-configuration
!Software Version V100R006C00SPC800
Le
sysname S1
re
vlan batch 3 to 7
Mo
HC Series
HUAWEI TECHNOLOGIES
Page51
aw
ei
.c
om
/e
#
interface Vlanif4
ip address 10.0.4.254 255.255.255.0
#
interface Vlanif5
ip address 10.0.5.1 255.255.255.0
#
interface Eth-Trunk1
hu
g.
mode lacp-static
in
#
interface GigabitEthernet0/0/1
rn
ea
/l
interface GigabitEthernet0/0/9
:/
eth-trunk 1
lacp priority 100
tp
ht
#
interface GigabitEthernet0/0/10
s:
eth-trunk 1
undo negotiation auto
ur
speed 100
ce
so
interface GigabitEthernet0/0/13
Re
ng
ospf 1
ni
area 0.0.0.0
ar
Le
user-interface con 0
user-interface vty 0 4
#
Mo
re
return
Page52
HUAWEI TECHNOLOGIES
HC Series
[S2]display current-configuration
aw
ei
.c
om
/e
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 3 to 7
#
interface Vlanif5
ip address 10.0.5.2 255.255.255.0
hu
#
interface Vlanif6
g.
in
#
interface Vlanif7
rn
ea
#
interface Eth-Trunk1
/l
:/
tp
#
interface GigabitEthernet0/0/3
ht
s:
#
eth-trunk 1
ur
ce
interface GigabitEthernet0/0/9
speed 100
so
#
eth-trunk 1
Re
interface GigabitEthernet0/0/10
speed 100
ni
ng
interface GigabitEthernet0/0/24
ar
Le
ospf 1
re
area 0.0.0.0
Mo
HC Series
HUAWEI TECHNOLOGIES
Page53
user-interface con 0
aw
ei
.c
om
/e
user-interface vty 0 4
#
return
[S3]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S3
hu
#
interface Vlanif1
g.
in
#
interface Ethernet0/0/23
rn
shutdown
ip route-static 0.0.0.0 0.0.0.0 10.0.3.254
/l
ea
:/
user-interface con 0
user-interface vty 0 4
tp
ht
return
s:
[S4]display current-configuration
#
ce
ur
sysname S4
#
so
Re
ng
aaa
ni
authentication-scheme default
authorization-scheme default
ar
accounting-scheme default
Le
domain default
domain default_admin
local-user admin password simple admin
re
Mo
Page54
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
#
interface Ethernet0/0/14
shutdown
#
ip route-static 0.0.0.0 0.0.0.0 10.0.7.254
#
user-interface con 0
user-interface vty 0 4
hu
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
g.
return
HC Series
HUAWEI TECHNOLOGIES
Page55
aw
ei
.c
om
/e
hu
As a result of this lab section, you should achieve the following tasks:
rn
in
g.
ea
ht
tp
:/
/l
Topology
ce
s:
ur
Scenario
Mo
re
Le
ar
ni
ng
Re
so
Page56
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
<Huawei>system-view
hu
g.
[Huawei]sysname R1
<Huawei>system-view
in
rn
[Huawei]sysname R2
ea
<Huawei>system-view
/l
:/
[Huawei]sysname R3
ht
tp
s:
Remove the static routes to R2 and disable the Ethernet interfaces to avoid
creating alternative routes. Remove any unnecessary VLAN configuration.
ce
so
ur
[R1-GigabitEthernet0/0/1]shutdown
[R3]undo ip route-static 0.0.0.0 0
Re
ng
[R3-GigabitEthernet0/0/2]shutdown
[S1]undo interface Vlanif 3
ni
ar
Le
Info: This operation may take a few seconds. Please wait for a moment...done.
[S1]interface GigabitEthernet 0/0/1
re
Mo
[S1-GigabitEthernet0/0/1]quit
[S1]undo ospf 1
HC Series
HUAWEI TECHNOLOGIES
Page57
aw
ei
.c
om
/e
Info: This operation may take a few seconds. Please wait for a moment...done.
[S2]interface GigabitEthernet 0/0/3
[S2-GigabitEthernet0/0/3]undo port default vlan
[S2-GigabitEthernet0/0/3]quit
[S2]undo ospf 1
hu
in
g.
ea
rn
:/
/l
tp
ht
s:
ur
ce
so
Re
ng
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
ni
ar
[R2-Serial1/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
Le
[R2-Serial1/0/0]quit
[R2]interface Serial 2/0/0
re
[R2-Serial2/0/0]link-protocol hdlc
Mo
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
Page58
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
After HDLC is enabled on the serial interfaces, view the serial interface status.
The displayed information for R1 should be used as an example.
[R1]display interface Serial1/0/0
Serial1/0/0 current state : UP
Line protocol current state : UP
hu
g.
in
rn
ea
/l
:/
tp
ht
0, Multicast:
Errors:
0, Runts:
Giants:
0, CRC:
Alignments:
0, Overruns:
Dribbles:
0, Aborts:
0, Frame Error:
ur
ce
s:
Broadcast:
so
No Buffers:
Re
Collisions:
0, Deferred:
No Buffers:
ng
Total Error:
ni
ar
Mo
re
Le
HC Series
[R3-Serial2/0/0]link-protocol hdlc
HUAWEI TECHNOLOGIES
Page59
Test connectivity of the directly connected link after verifying that the physical
status and protocol status of the interface are Up.
aw
ei
.c
om
/e
<R2>ping 10.0.12.1
PING 10.0.12.1: 56 data bytes, press CTRL_C to break
hu
g.
5 packet(s) transmitted
5 packet(s) received
in
rn
ea
[R2]ping 10.0.23.3
/l
:/
tp
ht
ce
5 packet(s) received
s:
so
ur
Re
ni
ng
Enable the RIP routing protocol to advertise the remote networks of R1 & R3
[R1]rip
[R1-rip-1]version 2
Le
ar
[R1-rip-1]network 10.0.0.0
[R2]rip
[R2-rip-1]version 2
Mo
re
[R2-rip-1]network 10.0.0.0
Page60
HUAWEI TECHNOLOGIES
HC Series
[R3-rip-1]version 2
aw
ei
.c
om
/e
[R3-rip-1]network 10.0.0.0
After the configuration is complete, check that all the routes have been learned.
Verify that corresponding routes are learned by RIP.
<R1>display ip routing-table
Route Flags: R - relay, D - download to fib
----------------------------------------------------------------------------
Proto
Pre Cost
Flags NextHop
g.
Destination/Mask
Routes : 8
in
Destinations : 8
hu
Interface
Direct 0
10.0.12.1
10.0.12.1/32
Direct 0
127.0.0.1
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
100 1
10.0.12.2
Serial1/0/0
10.0.23.0/24
RIP
ea
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
:/
Serial1/0/0
/l
Serial1/0/0
tp
rn
10.0.12.0/24
s:
ht
ce
On R1, run the ping command to test connectivity between R1 and R3.
<R1>ping 10.0.23.3
ur
so
Re
ng
ni
ar
5 packet(s) received
Le
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page61
aw
ei
.c
om
/e
hu
g.
in
rn
ea
/l
:/
tp
output omitted
s:
ht
ce
Change the clock frequency on the link between R1 and R2 to 128000 bit/s.
This operation must be performed on the DCE, R1.
ur
so
[R1-Serial1/0/0]baudrate 128000
Re
ng
ni
ar
Le
re
: 2013-12-10 11:23:55
Mo
Page62
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
g.
hu
Configure PPP between R1 and R2, as well as R2 and R3. Both ends of the
link must use the same encapsulation mode. If different encapsulation modes
are used, interfaces may display as Down.
in
rn
[R1-Serial1/0/0]link-protocol ppp
ea
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R2]interface Serial 1/0/0
/l
[R2-Serial1/0/0]link-protocol ppp
[R2-Serial1/0/0]quit
[R2]interface Serial 2/0/0
ht
[R2-Serial2/0/0]link-protocol ppp
tp
:/
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
s:
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R3-Serial2/0/0]link-protocol ppp
ce
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
so
<R2>ping 10.0.12.1
ur
Re
ng
ni
ar
Le
Mo
re
5 packet(s) received
HC Series
HUAWEI TECHNOLOGIES
Page63
aw
ei
.c
om
/e
hu
5 packet(s) received
0.00% packet loss
in
g.
rn
If the ping operation fails, check the interface status and whether the link layer
protocol type is correct.
ea
/l
:/
tp
s:
ht
: 2013-12-10 11:57:20
ce
ur
so
Re
ng
output omitted
ar
ni
Mo
re
Le
Page64
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
Proto
Pre Cost
Flags
NextHop
Interface
Direct 0
10.0.12.2
Direct 0
10.0.12.1
10.0.12.2/32
Direct 0
127.0.0.1
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
Serial1/0/0
10.0.23.0/24
Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32
Direct 0
127.0.0.1
Serial2/0/0
10.0.23.3/32
Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
Serial2/0/0
127.0.0.0/8
Direct 0
127.0.0.1/32
Direct 0
127.255.255.255/32 Direct 0
255.255.255.255/32 Direct 0
Serial1/0/0
Serial1/0/0
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
:/
127.0.0.1
tp
/l
ea
in
g.
10.0.12.0/24
10.0.12.1/32
rn
Destination/Mask
Routes : 12
hu
Destinations : 12
ht
s:
Think about the origin and functions of the two routes. Check the following
items:
ce
so
ur
Re
ng
ni
ar
[R1-Serial1/0/0]quit
Le
[R1]aaa
re
Mo
HC Series
HUAWEI TECHNOLOGIES
Page65
aw
ei
.c
om
/e
hu
g.
<R1>terminal debugging
in
<R1>display debugging
PPP PAP packets debugging switch is on
rn
<R1>system-view
ea
:/
/l
[R1-Serial1/0/0]undo shutdown
tp
PPP Packet:
ht
s:
[R1-Serial1/0/0]
ce
ur
Re
so
ni
ng
Le
ar
Mo
re
Page66
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
[R3-Serial2/0/0]quit
[R3]aaa
[R3-aaa]local-user huawei password cipher huawei
info: A new user added
[R3-aaa]local-user huawei service-type ppp
[R3-aaa]quit
[R3]interface Serial 2/0/0
[R3-Serial2/0/0]shutdown
g.
hu
[R3-Serial2/0/0]undo shutdown
in
rn
Serial2/0/0, authentication failed and PPP link was closed because CHAP was
disabled on the peer.
ea
[R3-Serial2/0/0]
/l
:/
ht
tp
s:
ce
so
<R2>ping 10.0.23.3
ur
Re
ng
ni
ar
Le
Mo
re
5 packet(s) received
HC Series
HUAWEI TECHNOLOGIES
Page67
aw
ei
.c
om
/e
hu
Run the debugging ppp chap all and the terminal debugging commands to
display the debugging information.
g.
[R2-Serial2/0/0]return
in
rn
ea
<R2>display debugging
PPP CHAP packets debugging switch is on
/l
:/
tp
ht
s:
ce
[R2-Serial2/0/0]undo shutdown
ur
so
Re
ng
ni
PPP Packet:
ar
Le
Value_Size: 16 Value: fc 9b 56 e1 53 e3 a6 26 1b 54 e5 e2 a1 ed 90 87
Name:
[R2-Serial2/0/0]
re
Mo
PPP Event:
Page68
HUAWEI TECHNOLOGIES
HC Series
state ListenChallenge
Dec 10 2013 09:10:38.710.3+00:00 R2 PPP/7/debug2:
PPP Packet:
Serial2/0/0 Output CHAP(c223) Pkt, Len 31
State ListenChallenge, code Response(02), id 1, len 27
aw
ei
.c
om
/e
[R2-Serial2/0/0]
Value_Size: 16 Value: f9 54 1 69 30 59 a0 af 52 a1 1d de 85 77 27 6b
Name: huawei
Dec 10 2013 09:10:38.710.4+00:00 R2 PPP/7/debug2:
PPP State Change:
g.
hu
[R2-Serial2/0/0]
PPP Packet:
ea
rn
in
[R2-Serial2/0/0]
/l
Message: Welcome to .
:/
[R2-Serial2/0/0]
tp
PPP Event:
ht
state SendResponse
[R2-Serial2/0/0]
s:
ur
ce
so
The highlighted debugging information shows the key CHAP behavior. Disable
the debugging process.
Re
[R2-Serial2/0/0]return
<R2>undo debugging all
ni
ng
ar
Mo
re
Le
HC Series
HUAWEI TECHNOLOGIES
Page69
aw
ei
.c
om
/e
Final Configuration
[R1]display current-configuration
[V200R003C00SPC200]
#
sysname R1
#
aaa
authentication-scheme default
hu
authorization-scheme default
accounting-scheme default
g.
domain default
in
domain default_admin
rn
ea
/l
#
interface Serial1/0/0
ppp authentication-mode pap
ip address 10.0.12.1 255.255.255.0
ht
baudrate 128000
tp
:/
link-protocol ppp
s:
rip 1
version 2
ce
network 10.0.0.0
user-interface con 0
ur
so
authentication-mode password
Re
ng
ar
ni
return
[R2]display current-configuration
Le
[V200R003C00SPC200]
#
re
sysname R2
Mo
Page70
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
#
rip 1
g.
version 2
in
network 10.0.0.0
#
rn
user-interface con 0
ea
authentication-mode password
set authentication password
/l
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
:/
user-interface vty 0 4
#
ht
tp
return
[R3]display current-configuration
s:
[V200R003C00SPC200]
#
ce
sysname R3
ur
#
aaa
so
authentication-scheme default
Re
authorization-scheme default
accounting-scheme default
domain default
ng
domain default_admin
ni
ar
Le
interface Serial2/0/0
re
link-protocol ppp
Mo
HC Series
HUAWEI TECHNOLOGIES
link-protocol ppp
Page71
aw
ei
.c
om
/e
rip 1
version 2
network 10.0.0.0
#
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
hu
user-interface vty 0 4
#
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
g.
return
Page72
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
hu
g.
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
Topology
ng
Scenario
Re
so
Mo
re
Le
ar
ni
The enterprise network has existing frame relay virtual circuits between the HQ
and some branch offices. A recent change in equipment requires that these
frame relay VC be re-established. The virtual circuits had been provided by the
service provider at the time the service was first implemented and it is the task
of the administrator to implement the frame relay configuration on the edge
routers for the HQ and branch offices. The administrator must configure frame
relay on the WAN links and perform mapping between the local DLCI and IP
addresses.
HC Series
HUAWEI TECHNOLOGIES
Page73
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
g.
hu
[Huawei]sysname R1
<Huawei>system-view
in
rn
[Huawei]sysname R2
ea
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
:/
/l
[Huawei]sysname R3
tp
ce
[R1-Serial1/0/0]shutdown
s:
ht
Disable the serial interfaces used for establishing the HDLC & PPP networks.
ur
so
Re
[R2-Serial2/0/0]shutdown
ni
ng
[R3-Serial2/0/0]shutdown
Le
ar
Mo
re
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R1-Serial2/0/0]ip address 10.0.123.1 24
[R1-Serial2/0/0]undo fr inarp
[R1-Serial2/0/0]fr map ip 10.0.123.2 102 broadcast
[R1-Serial2/0/0]fr map ip 10.0.123.3 103 broadcast
[R1-Serial2/0/0]interface loopback 0
[R1-LoopBack0]ip address 10.0.1.1 24
hu
g.
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
rn
in
ea
[R2-Serial3/0/0]interface loopback 0
/l
:/
tp
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R3-Serial1/0/0]ip address 10.0.123.3 24
ht
[R3-Serial1/0/0]undo fr inarp
s:
[R3-Serial1/0/0]interface loopback 0
ce
so
ur
Re
ng
ar
ni
Le
5 packet(s) transmitted
5 packet(s) received
round-trip min/avg/max = 59/60/64 ms
Mo
re
HC Series
HUAWEI TECHNOLOGIES
[R1-Serial2/0/0]link-protocol fr
Page75
aw
ei
.c
om
/e
hu
5 packet(s) received
0.00% packet loss
in
g.
/l
ea
rn
Run the following commands to view the FR encapsulation information for the
R1 interfaces.
:/
tp
ht
s:
ce
ur
so
Re
Mo
re
Le
ar
ni
ng
Page76
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Configure RIPv2 on R1, R2 and R3. If you are continuing from the previous
HDLC/PPP lab, the RIP routes for network 10.0.0.0 may have already been
configured, however the automatic summary must still be disabled to uniquely
identify the routes of the peers.
hu
g.
[R1-rip-1]version 2
[R1-rip-1]network 10.0.0.0
rn
in
[R1-rip-1]undo summary
[R2]rip 1
ea
[R2-rip-1]version 2
/l
[R2-rip-1]network 10.0.0.0
:/
[R2-rip-1]undo summary
tp
[R3]rip 1
[R3-rip-1]version 2
ht
[R3-rip-1]network 10.0.0.0
s:
[R3-rip-1]undo summary
ce
View the routing tables on R1, R2, and R3 to check the learned routes.
<R1>display ip routing-table protocol rip
ur
so
Routes : 2
Re
Destinations : 2
ni
ng
Destinations : 2
Proto
ar
Destination/Mask
Le
10.0.2.0/24 RIP
10.0.3.0/24 RIP
Routes : 2
Pre Cost
Flags NextHop
Interface
100 1
10.0.123.2
Serial2/0/0
100 1
10.0.123.3
Serial2/0/0
Destinations : 0
Routes : 0
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page77
aw
ei
.c
om
/e
Routes : 2
Proto
Pre Cost
Flags NextHop
100 1
10.0.123.1
10.0.3.0/24 RIP
100 2
10.0.123.1
Serial3/0/0
rn
ea
Routes : 0
/l
Destinations : 0
Serial3/0/0
in
10.0.1.0/24 RIP
Interface
hu
Destination/Mask
Routes : 2
g.
Destinations : 2
:/
----------------------------------------------------------------------------
tp
Routes : 2
ht
Destinations : 2
Pre Cost
ce
Proto
ur
Destination/Mask
Routes : 2
s:
Destinations : 2
Flags NextHop
Interface
100 1
10.0.123.1
Serial1/0/0
10.0.2.0/24 RIP
100 2
10.0.123.1
Serial1/0/0
Re
so
10.0.1.0/24 RIP
Mo
re
Le
ar
ni
ng
Destinations : 0
Page78
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
g.
5 packet(s) transmitted
5 packet(s) received
in
rn
/l
ea
Perform the same test to network 10.0.2.2 of R2 from network 10.0.3.3 of R3.
<R3>ping -a 10.0.3.3 10.0.2.2
:/
tp
ht
s:
ce
so
ur
5 packet(s) received
Re
Mo
re
Le
ar
ni
ng
The RIP routing protocol has enabled a route between the loopback interfaces
of R2 and R3 to be established via R1.
HC Series
HUAWEI TECHNOLOGIES
Page79
aw
ei
.c
om
/e
hu
g.
5 packet(s) transmitted
in
0 packet(s) received
rn
:/
/l
ea
ht
tp
View the R3 routing table and check whether any route is destined for the IP
address 10.0.2.2.
s:
If there is such a route, find out the next hop IP address of this route. Then
check whether R3 can reach the next hop and whether there is mapping
between the layer-3 IP addresses and layer-2 PVCs.
Re
so
ur
ce
If R3 can reach the next hop and there is mapping between Layer-3 IP
addresses and Layer-2 PVCs, check the devices on the route to determine
whether there is any route that can reach IP address 10.0.2.2, whether the
next hop of this route is reachable, and whether there is mapping between
Layer-3 IP addresses and Layer-2 PVCs.
ni
ng
If there is a route that can reach IP address 10.0.2.2 and there is mapping
between Layer-3 IP addresses and Layer-2 PVCs, check R2 to determine
whether there is any route that reaches the destination IP address of the
response packets and whether the next hop of this route is reachable.
Le
ar
If the next hop of this route is unreachable and the destination IP address of
the response packets is 10.0.123.3, R2 has the route that reaches this address
but there is no mapping between Layer-3 IP addresses and Layer-2 PVCs.
Mo
re
The following is the output of the commands used in the preceding fault
diagnosis procedure.
Page80
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Routes : 13
Proto
Pre Cost
10.0.1.0/24
RIP
100 1
100 2
Flags NextHop
Interface
10.0.123.1
Serial1/0/0
10.0.2.0/24
RIP
10.0.123.1
10.0.3.0/24
Direct 0
10.0.3.3
10.0.3.3/32
Direct 0
127.0.0.1
10.0.3.255/32
Direct 0
127.0.0.1
10.0.123.0/24
Direct 0
10.0.123.3
10.0.123.1/32
Direct 0
10.0.123.1
Serial1/0/0
10.0.123.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.255/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1/32
Direct 0
127.255.255.255/32 Direct 0
255.255.255.255/32 Direct 0
Serial1/0/0
hu
LoopBack0
ea
rn
in
g.
InLoopBack0
Serial1/0/0
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
tp
InLoopBack0
127.0.0.1
/l
:/
ht
s:
ce
ur
<R1>display ip routing-table
so
----------------------------------------------------------------------------
Re
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1
LoopBack0
10.0.1.1/32
Direct
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct
127.0.0.1
InLoopBack0
Flags NextHop
Interface
10.0.2.0/24
RIP
100 1
10.0.123.2
Serial2/0/0
10.0.3.0/24
RIP
100 1
10.0.123.3
Serial2/0/0
10.0.123.0/24
Direct
10.0.123.1
Serial2/0/0
10.0.123.1/32
Direct
127.0.0.1
InLoopBack0
Mo
re
Le
ar
ng
Destination/Mask
Routes : 14
ni
Destinations : 14
HC Series
HUAWEI TECHNOLOGIES
Page81
Direct
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct
10.0.123.3
Serial2/0/0
10.0.123.255/32 Direct
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct
127.0.0.1
127.0.0.1/32
Direct
127.0.0.1
127.255.255.255/32 Direct 0
127.0.0.1
255.255.255.255/32 Direct 0
127.0.0.1
aw
ei
.c
om
/e
10.0.123.2/32
InLoopBack0
InLoopBack0
InLoopBack0
InLoopBack0
hu
g.
in
/l
ea
<R2>display ip routing-table
rn
:/
Pre
Cost
10.0.1.0/24
RIP
100 1
10.0.123.1
Serial3/0/0
10.0.2.0/24
Direct
10.0.2.2
LoopBack0
10.0.2.2/32
Direct
127.0.0.1
InLoopBack0
10.0.2.255/32
Direct
127.0.0.1
InLoopBack0
Flags NextHop
Interface
10.0.3.0/24
RIP
100 2
10.0.123.1
Serial3/0/0
10.0.123.0/24
Direct
10.0.123.2
Serial3/0/0
Direct
10.0.123.1
Serial3/0/0
Direct
127.0.0.1
InLoopBack0
10.0.123.255/32 Direct
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
Re
10.0.123.1/32
ur
ce
s:
ht
Proto
so
Destination/Mask
Routes : 13
tp
Destinations : 13
Mo
re
Le
ar
ni
ng
10.0.123.2/32
Page82
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
g.
ea
rn
in
The fault diagnosis results from step 2 indicate that communication fails since
there is no virtual circuit between the frame relay interfaces on R2 and R3. In
order to resolve this, configure a frame relay PVC between the interfaces on
R2 and R3.
:/
/l
ht
tp
s:
After the mapping has been configured between IP addresses and PVCs,
check the IP address-PVC mapping tables on R2 and R3 and detect network
connectivity.
ce
ur
so
Re
ng
ni
ar
Le
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page83
aw
ei
.c
om
/e
hu
5 packet(s) received
0.00% packet loss
in
g.
ea
rn
/l
Delete the RIP configurations referenced in step 2 and the frame relay
mapping between R2 and R3 that was established during step 3.
:/
[R1]undo rip 1
tp
ht
s:
[R2]undo rip 1
ce
ur
so
Re
[R3-Serial1/0/0]quit
[R3]undo rip 1
ng
[R3]
ni
ar
Le
[R1-ospf-1]area 0
Mo
re
Page84
HUAWEI TECHNOLOGIES
HC Series
[R2-ospf-1]area 0
aw
ei
.c
om
/e
g.
hu
After the basic parameters are set, OSPF cannot establish neighbor
adjacencies. When using frame relay for data link layer encapsulation, OSPF
will set the network type to NBMA by default. As a result, OSPF does not
support broadcasts, and therefore cannot automatically discover neighbors.
in
rn
ea
Interfaces
Cost: 1562
State: DR
Type: NBMA
MTU: 1500
:/
Priority: 1
/l
tp
ht
Output
DB Description
ce
Hello
s:
Input
ur
Type
Link-State Update
Link-State Ack
PrevState: Waiting
Re
OpaqueId: 0
so
Link-State Req
ng
Mo
re
Le
ar
ni
HC Series
HUAWEI TECHNOLOGIES
Page85
[R1-ospf-1]peer 10.0.123.2
aw
ei
.c
om
/e
[R1-ospf-1]peer 10.0.123.3
[R1-ospf-1]interface Serial 2/0/0
[R1-Serial2/0/0]ospf dr-priority 255
[R2]ospf
[R2-ospf-1]peer 10.0.123.1
[R3]ospf
g.
hu
[R3-ospf-1]peer 10.0.123.1
ea
/l
Interfaces
:/
rn
in
State: DR
Type: NBMA
tp
Priority: 255
MTU: 1500
ht
Input
32
OpaqueId: 0
29
2
16
30
20
Re
Link-State Ack
32
so
Link-State Req
ur
DB Description
Output
ce
Hello
Link-State Update
s:
PrevState: BDR
ng
ar
ni
If R1 is not the designated router, reset the ospf process on all routers using
the following command and reattempt the above display command
Le
Mo
re
Display the routing table to confirm that OSPF has been established over the
frame relay network.
Page86
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Routes : 14
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1
10.0.1.1/32
Direct
127.0.0.1
10.0.1.255/32
Direct
127.0.0.1
10.0.2.2/32
OSPF
10
1562
10.0.123.2
10.0.3.3/32
OSPF
10
1562
10.0.123.3
10.0.123.0/24
Direct
10.0.123.1
10.0.123.1/32
Direct
127.0.0.1
Serial2/0/0
10.0.123.2/32
Direct
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct
10.0.123.3
Serial2/0/0
10.0.123.255/32 Direct
127.0.0.0/8
Direct
127.0.0.1/32
255.255.255.255/32 Direct
LoopBack0
LoopBack0
hu
g.
in
rn
ea
LoopBack0
Serial2/0/0
Serial2/0/0
Serial2/0/0
127.0.0.1
Serial2/0/0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
ht
Interface
/l
:/
Direct
127.255.255.255/32 Direct
Flags NextHop
tp
Destination/Mask
s:
ce
ur
so
Re
ng
ni
Mo
re
Le
ar
HC Series
HUAWEI TECHNOLOGIES
Page87
aw
ei
.c
om
/e
hu
in
g.
/l
tp
:/
ea
rn
ht
s:
ce
so
ur
After setting the OSPF network type, wait until the neighbor relationship is
established, then check the neighbor relationship and route information.
Re
ng
ni
---------------------------------------------------------------------------Interface
Neighbor id
State
0.0.0.0
Serial2/0/0
10.0.2.2
Full
0.0.0.0
Serial2/0/0
10.0.3.3
Full
Le
ar
Area Id
Mo
re
----------------------------------------------------------------------------
Page88
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Routes : 14
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1
10.0.1.1/32
Direct
127.0.0.1
10.0.1.255/32
Direct
127.0.0.1
10.0.2.2/32
OSPF
10
1562
10.0.123.2
10.0.3.3/32
OSPF
10
1562
10.0.123.3
10.0.123.0/24
Direct
10.0.123.1
10.0.123.1/32
Direct
127.0.0.1
Serial2/0/0
10.0.123.2/32
Direct
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct
10.0.123.3
Serial2/0/0
10.0.123.255/32 Direct
127.0.0.0/8
Direct
127.0.0.1/32
255.255.255.255/32 Direct
LoopBack0
LoopBack0
hu
LoopBack0
ea
rn
in
g.
Serial2/0/0
Serial2/0/0
Serial2/0/0
127.0.0.1
Serial2/0/0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
ht
Interface
/l
:/
Direct
127.255.255.255/32 Direct
Flags NextHop
tp
Destination/Mask
s:
ce
---------------------------------------------------------------------------Interface
0.0.0.0
Serial3/0/0
ur
Area Id
Neighbor id
State
10.0.1.1
Full
Re
so
---------------------------------------------------------------------------<R2>display ip routing-table
Route Flags: R - relay, D - download to fib
ng
----------------------------------------------------------------------------
ni
Proto
Pre Cost
10.0.1.1/32
OSPF
10
1562
10.0.123.1
Serial3/0/0
10.0.2.0/24
Direct
10.0.2.2
LoopBack0
10.0.2.2/32
Direct
127.0.0.1
LoopBack0
Le
Destination/Mask
Flags NextHop
Interface
Mo
re
Routes : 14
ar
Destinations : 14
HC Series
HUAWEI TECHNOLOGIES
Page89
Direct
127.0.0.1
LoopBack0
10.0.3.3/32
OSPF
10
3124
10.0.123.1
Serial3/0/0
10.0.123.0/24
Direct
10.0.123.2
Serial3/0/0
10.0.123.1/32
Direct
10.0.123.1
10.0.123.2/32
Direct
127.0.0.1
10.0.123.3/32
OSPF
10
3124
10.0.123.1
10.0.123.255/32 Direct
127.0.0.1
127.0.0.0/8
Direct
127.0.0.1
127.0.0.1/32
Direct
127.0.0.1
127.255.255.255/32 Direct
127.0.0.1
255.255.255.255/32 Direct
127.0.0.1
Serial3/0/0
Serial3/0/0
Serial3/0/0
Serial3/0/0
InLoopBack0
InLoopBack0
InLoopBack0
hu
InLoopBack0
in
g.
aw
ei
.c
om
/e
10.0.2.255/32
rn
ea
---------------------------------------------------------------------------Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.1.1
Full
/l
Area Id
:/
----------------------------------------------------------------------------
tp
<R3>display ip routing-table
ht
Flags NextHop
Interface
OSPF
10
1562
10.0.123.1
Serial1/0/0
10.0.2.2/32
OSPF
10
3124
10.0.123.1
Serial1/0/0
Direct
10.0.3.3
LoopBack0
Re
so
10.0.1.1/32
10.0.3.0/24
Direct
127.0.0.1
LoopBack0
10.0.3.255/32
Direct
127.0.0.1
LoopBack0
10.0.123.0/24
Direct
10.0.123.3
Serial1/0/0
10.0.123.1/32
Direct
10.0.123.1
Serial1/0/0
10.0.123.2/32
OSPF
10
3124
10.0.123.1
Serial1/0/0
10.0.123.3/32
Direct
127.0.0.1
Serial1/0/0
10.0.123.255/32 Direct
127.0.0.1
Serial1/0/0
Le
ar
ni
ng
10.0.3.3/32
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
re
Mo
Pre Cost
ce
Proto
ur
Destination/Mask
Routes : 14
s:
Destinations : 14
Page90
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
g.
5 packet(s) transmitted
5 packet(s) received
in
rn
ea
/l
:/
tp
ht
s:
ce
5 packet(s) received
so
ur
Re
ng
ni
ar
Le
Mo
re
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 101/103/110 ms
HC Series
HUAWEI TECHNOLOGIES
Page91
aw
ei
.c
om
/e
Final Configuration
[R1]display current-configuration
[V200R003C00SPC200]
#
sysname R1
#
interface Serial2/0/0
link-protocol fr
hu
undo fr inarp
fr map ip 10.0.123.2 102 broadcast
g.
in
rn
ea
interface LoopBack0
/l
:/
tp
area 0.0.0.0
network 10.0.0.0 0.255.255.255
ht
#
user-interface con 0
s:
authentication-mode password
set authentication password
ur
user-interface vty 0 4
ce
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
#
Re
so
return
[R2]display current-configuration
[V200R003C00SPC200]
ng
ni
sysname R2
#
ar
interface Serial3/0/0
link-protocol fr
Le
undo fr inarp
fr map ip 10.0.123.1 201 broadcast
re
Mo
Page92
HUAWEI TECHNOLOGIES
HC Series
interface LoopBack0
aw
ei
.c
om
/e
hu
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
g.
user-interface vty 0 4
in
rn
return
ea
[R3]display current-configuration
[V200R003C00SPC200]
/l
:/
sysname R3
#
tp
interface Serial1/0/0
link-protocol fr
ht
undo fr inarp
s:
ce
ur
interface LoopBack0
so
#
area 0.0.0.0
Re
ng
ni
user-interface con 0
authentication-mode password
ar
Le
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
#
Mo
re
return
HC Series
HUAWEI TECHNOLOGIES
Page93
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
so
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
g.
hu
Topology
Re
ni
ng
Scenario
Mo
re
Le
ar
The enterprise subscribes to a (typically high speed) DSL service from the
service provider over which WAN services are supported. R1 and R3 are
enterprise edge routers of different offices, and establish a connection to the
service provider through the PPPoE server (R2). The enterprise is required to
establish a PPPoE dialer on the edge routers to allow hosts in the local area
network to access external resources transparently via the service provider
network over PPPoE.
Page94
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
g.
hu
[Huawei]sysname R1
<Huawei>system-view
in
rn
[Huawei]sysname R2
ea
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
:/
/l
[Huawei]sysname R3
tp
ce
[R1-Serial2/0/0]shutdown
s:
ht
Disable the serial interfaces to avoid routing over the frame relay network.
ur
so
[R3-Serial1/0/0]shutdown
Re
ni
ng
The PPPoE server is not part of the enterprise network, however it is required
to allow the enterprise edge routers R1 and R3 to be authenticated.
ar
Le
re
[R2-ip-pool-pool1]quit
Mo
[R2]interface Virtual-Template 1
[R2-Virtual-Template1]ppp authentication-mode chap
HC Series
HUAWEI TECHNOLOGIES
Page95
hu
rn
in
g.
aw
ei
.c
om
/e
[R2-Virtual-Template1]quit
tp
:/
/l
[R2-aaa]quit
ea
s:
ht
ce
[R1]dialer-rule
[R1-dialer-rule]quit
ur
[R1-dialer-rule]dialer-rule 1 ip permit
so
[R1]interface Dialer 1
Re
ng
ni
ar
[R1-Dialer1]dialer queue-length 8
Le
Mo
re
[R1-Dialer1]quit
Page96
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
[R1-GigabitEthernet0/0/0]pppoe-client dial-bundle-number 1
[R1-GigabitEthernet0/0/0]quit
hu
g.
[R3-dialer-rule]dialer-rule 1 ip permit
in
[R3-dialer-rule]quit
[R3]interface Dialer 1
rn
ea
[R3-Dialer1]dialer-group 1
[R3-Dialer1]dialer bundle 1
/l
:/
tp
[R3-Dialer1]dialer queue-length 8
ht
[R3-Dialer1]quit
s:
ce
[R3-GigabitEthernet0/0/0]pppoe-client dial-bundle-number 1
ur
[R3-GigabitEthernet0/0/0]quit
so
Re
ng
ni
ar
Virtual-Template1:0
UP
GE0/0/0
00e0.fc03.d0ae 00e0.fc03.7516
Virtual-Template1:1
UP
GE0/0/0
00e0.fc03.aedd 00e0.fc03.7516
OIntf
RemMAC
LocMAC
Mo
re
Le
SID Intf
HUAWEI TECHNOLOGIES
Page97
aw
ei
.c
om
/e
0%
0%
hu
g.
in
rn
ea
0%
tp
:/
/l
s:
ht
Check the dialer interface of R1 and R3, and ensure both can obtain an IP
address from the PPPoE server.
<R1>display ip interface brief
ce
ur
^down: standby
(s): spoofing
so
(l): loopback
Re
ni
ng
Physical
Protocol
Cellular0/0/0
unassigned
down
down
Cellular0/0/1
unassigned
down
down
Dialer1
119.84.111.253/32
up
up(s)
GigabitEthernet0/0/0
unassigned
up
down
Le
ar
Interface
Mo
re
output omitted
Page98
HUAWEI TECHNOLOGIES
HC Series
Physical
Protocol
Cellular0/0/0
unassigned
down
down
Cellular0/0/1
unassigned
down
down
Dialer1
119.84.111.252/32
up
up(s)
GigabitEthernet0/0/0
unassigned
up
down
aw
ei
.c
om
/e
Interface
output omitted
output omitted
hu
Final Configuration
g.
[R1]display current-configuration
[V200R003C00SPC200]
in
rn
sysname R1
#
ea
aaa
/l
authentication-scheme default
authorization-scheme default
:/
accounting-scheme default
tp
domain default
domain default_admin
ht
s:
ce
#
link-protocol ppp
ur
interface Dialer1
so
Re
ip address ppp-negotiate
dialer user user1
ng
dialer bundle 1
dialer queue-length 8
ni
ar
dialer-group 1
Le
interface GigabitEthernet0/0/0
pppoe-client dial-bundle-number 1
re
Mo
dialer-rule
HC Series
HUAWEI TECHNOLOGIES
Page99
aw
ei
.c
om
/e
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
#
g.
hu
return
in
[R2]dis current-configuration
[V200R003C00SPC200]
rn
ea
sysname R2
#
/l
ip pool pool1
:/
gateway-list 119.84.111.254
network 119.84.111.0 mask 255.255.255.0
tp
#
aaa
ht
authentication-scheme default
accounting-scheme default
domain default
ce
domain default_admin
s:
authorization-scheme default
ur
so
Re
ng
ni
interface Virtual-Template1
ppp authentication-mode chap
ar
Le
interface GigabitEthernet0/0/0
re
Mo
Page100
HUAWEI TECHNOLOGIES
HC Series
authentication-mode password
aw
ei
.c
om
/e
[R3]display current-configuration
hu
[V200R003C00SPC200]
#
g.
sysname R3
in
#
aaa
rn
authentication-scheme default
ea
authorization-scheme default
accounting-scheme default
/l
domain default
:/
domain default_admin
local-user admin service-type http
tp
ht
s:
interface Dialer1
ppp chap user huawei2
ce
link-protocol ppp
ur
Re
dialer bundle 1
so
ip address ppp-negotiate
dialer queue-length 8
dialer timer idle 300
ng
dialer-group 1
ni
interface GigabitEthernet0/0/0
Le
ar
pppoe-client dial-bundle-number 1
#
dialer-rule
re
dialer-rule 1 ip permit
Mo
HC Series
HUAWEI TECHNOLOGIES
Page101
aw
ei
.c
om
/e
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
#
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
g.
hu
return
Page102
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
As a result of this lab section, you should achieve the following tasks:
in
g.
ur
ce
s:
ht
tp
:/
/l
ea
rn
Topology
Re
Scenario
so
Figure 3.1 Filtering enterprise network data with Access Control Lists
Mo
re
Le
ar
ni
ng
Assume that you are a network administrator of a company that has three
networks belonging to three sites. R2 is deployed at the border of the network
for the main site, while R1 and R3 are deployed at the boundary of the
remaining sites. The routers are interconnected over a private WAN
connection. The company needs to control the access of employees to telnet
and FTP services. Only site R1 has permission to access the telnet server in
the main site. Only site R3 has permission to access the FTP server.
HC Series
HUAWEI TECHNOLOGIES
Page103
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
[Huawei]sysname R1
hu
[Huawei]sysname R2
g.
[Huawei]sysname R3
in
[Huawei]sysname S1
[S1]vlan 4
rn
[S1-vlan4]quit
[S1]interface vlanif 4
/l
ea
:/
[S2]vlan 6
tp
[S2-vlan6]quit
[S2]interface vlanif 6
ht
ce
s:
[R1]ospf
Re
[R1-ospf-1]area 0
so
ur
Remove the current network being advertised in OSPF, the PPPoE dialer
interfaces, as well as the PPPoE server virtual template configuration from R2.
ng
ni
[R1]interface Dialer 1
ar
Le
[R1]dialer-rule
re
[R1-dialer-rule]undo dialer-rule 1
Mo
[R2]ospf
Page104
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
[R3]ospf
[R3-ospf-1]area 0
g.
in
rn
[R3]interface Dialer 1
ea
/l
[R3]dialer-rule
ht
tp
:/
[R3-dialer-rule]undo dialer-rule 1
s:
ce
ur
so
Re
ng
ni
ar
Le
Mo
re
Establish VLAN trunks on S1 and S2. The port link type should already be
configured for interface GigabitEthernet 0/0/2 on S1.
HC Series
HUAWEI TECHNOLOGIES
Page105
aw
ei
.c
om
/e
hu
g.
[S2-GigabitEthernet0/0/2]quit
rn
in
/l
ea
Configure OSPF for R1, R2, and R3. Ensure that all are part of the same
OSPF area and advertise the networks that have been created.
[R1]ospf
:/
[R1-ospf-1]area 0
tp
ht
[R2]ospf
[R2-ospf-1]area 0
s:
[R3-ospf-1]area 0
so
[R3]ospf
ur
ce
Re
ng
Configure a static route on S1 and S2, the nexthop as the private networks
gateway.
ni
Le
ar
Mo
re
Page106
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
5 packet(s) received
0.00% packet loss
in
g.
rn
ea
/l
:/
tp
ht
5 packet(s) transmitted
5 packet(s) received
s:
ce
ur
<R3>ping 10.0.4.254
so
Re
ni
ng
ar
5 packet(s) transmitted
Le
5 packet(s) received
0.00% packet loss
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page107
aw
ei
.c
om
/e
hu
5 packet(s) received
0.00% packet loss
in
g.
rn
ea
/l
[S1]user-interface vty 0 4
[S1-ui-vty0-4]authentication-mode password
tp
:/
ht
s:
ur
ce
so
Re
ng
ni
ar
[R2-acl-adv-3000]quit
Le
Mo
re
Page108
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
<R1>telnet 10.0.4.254
Press CTRL_] to quit telnet mode
Trying 10.0.4.254 ...
Connected to 10.0.4.254 ...
Login authentication
hu
Password:
Info: The max number of VTY users is 5, and the number
g.
in
<S1>
ea
rn
/l
:/
tp
ht
Note: The FTP connection may take a while to respond (approx 60 seconds).
<R3>telnet 10.0.4.254
s:
<R3>ftp 10.0.6.254
so
ur
ce
Re
Connected to 10.0.6.254.
220 FTP service ready.
ng
User(10.0.6.254:(none)):huawei
ni
ar
Le
[R3-ftp]
Mo
re
Note: The bye command can be used to close the FTP connection
HC Series
HUAWEI TECHNOLOGIES
Page109
aw
ei
.c
om
/e
Should basic ACL and advanced ACL be deployed near the source network or
target network, and why?
Final Configuration
hu
<R1>display current-configuration
[V200R003C00SPC200]
g.
in
sysname R1
#
rn
aaa
ea
authentication-scheme default
authorization-scheme default
/l
accounting-scheme default
domain default
:/
domain default_admin
local-user admin service-type http
tp
ht
s:
interface GigabitEthernet0/0/0
ce
ur
so
area 0.0.0.0
Re
user-interface con 0
ng
authentication-mode password
ni
ar
user-interface vty 0 4
Le
Mo
re
return
Page110
HUAWEI TECHNOLOGIES
HC Series
[V200R003C00SPC200]
aw
ei
.c
om
/e
#
sysname R2
#
acl number 3000
hu
rule 15 deny ip
#
g.
interface GigabitEthernet0/0/0
in
rn
ea
interface GigabitEthernet0/0/1
ip address 10.0.4.2 255.255.255.0
/l
#
ip address 10.0.6.2 255.255.255.0
tp
:/
interface GigabitEthernet0/0/2
ht
area 0.0.0.0
network 10.0.4.0 0.0.0.255
s:
ce
ur
user-interface con 0
authentication-mode password
so
Re
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
user-interface vty 0 4
#
ni
ng
return
ar
<R3>display current-configuration
Le
[V200R003C00SPC200]
#
sysname R3
re
Mo
interface GigabitEthernet0/0/0
HC Series
HUAWEI TECHNOLOGIES
Page111
aw
ei
.c
om
/e
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
hu
user-interface vty 0 4
#
in
g.
return
rn
<S1>display current-configuration
ea
#
!Software Version V100R006C00SPC800
/l
sysname S1
:/
#
vlan batch 4
tp
#
interface Vlanif4
ht
s:
interface GigabitEthernet0/0/2
port trunk pvid vlan 4
ce
ur
so
Re
user-interface con 0
user-interface vty 0 4
ng
Mo
re
Le
ar
return
ni
Page112
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
authentication-scheme default
authorization-scheme default
g.
accounting-scheme default
in
domain default
domain default_admin
rn
ea
:/
/l
tp
interface Vlanif6
ht
#
interface GigabitEthernet0/0/2
s:
ce
ur
so
Re
user-interface con 0
user-interface vty 0 4
#
Mo
re
Le
ar
ni
ng
return
HC Series
HUAWEI TECHNOLOGIES
Page113
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
g.
hu
Topology
ng
Scenario
Re
so
Mo
re
Le
ar
ni
Page114
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
[Huawei]sysname R1
hu
[R1]inter GigabitEthernet0/0/1
g.
in
[R3]interface GigabitEthernet0/0/2
rn
ea
[Huawei]sysname S1
/l
[S1]vlan 4
[S1]interface vlanif 4
tp
:/
[S1-vlan3]quit
ht
[S1-Vlanif4]quit
[Huawei]sysname S2
s:
[S2]vlan 6
[S2]interface vlanif 6
ce
[S2-vlan6]quit
so
[S2-Vlanif6]quit
ur
Re
ni
ng
ar
Le
re
[R1]undo ospf 1
Mo
HC Series
HUAWEI TECHNOLOGIES
Page115
[R3-GigabitEthernet0/0/0]undo ip address
[R3]interface GigabitEthernet 0/0/2
[R3-GigabitEthernet0/0/2]undo shutdown
[R3]undo ospf 1
Warning: The OSPF process will be deleted. Continue? [Y/N]:y
hu
aw
ei
.c
om
/e
g.
rn
in
ea
/l
:/
tp
ht
[S1-GigabitEthernet0/0/1]quit
[S2]interface GigabitEthernet 0/0/3
s:
ur
ce
Re
so
Mo
re
Le
ar
ni
ng
Page116
HUAWEI TECHNOLOGIES
HC Series
<R1>ping 10.0.4.254
aw
ei
.c
om
/e
hu
5 packet(s) transmitted
5 packet(s) received
g.
in
rn
<R1>ping 119.84.111.3
ea
/l
:/
tp
ht
s:
5 packet(s) received
0.00% packet loss
ur
ce
so
Re
Configure an advanced ACL on R1 and select the data flow with the source of
S1, the destination of R3, and destined for the telnet service port.
ng
[R1]acl 3000
[R1-acl-adv-3000]rule 5 permit tcp source 10.0.4.254 0.0.0.0 destination
ni
ar
Le
[R1-acl-adv-3000]rule 15 deny ip
Mo
re
Configure a basic ACL on R3 and select the data flow whose source IP
address is 10.0.6.0/24.
[R3]acl 2000
[R3-acl-basic-2000]rule permit source 10.0.6.0 0.0.0.255
HC Series
HUAWEI TECHNOLOGIES
Page117
aw
ei
.c
om
/e
g.
hu
in
[R3]user-interface vty 0 4
rn
[R3-ui-vty0-4]authentication-mode password
/l
ea
[R3-ui-vty0-4]quit
:/
tp
-------------------------------------Start-address
End-address
ht
Index
-------------------------------------1
119.84.111.240
119.84.111.243
s:
--------------------------------------
ce
Total : 1
so
ur
Test connectivity to the gateway of the remote peer from the internal network.
<S1>ping 119.84.111.3
Re
ng
ar
ni
Le
5 packet(s) transmitted
4 packet(s) received
Mo
re
Page118
HUAWEI TECHNOLOGIES
HC Series
<S1>telnet 119.84.111.3
aw
ei
.c
om
/e
g.
hu
Do not exit the telnet session, instead open a second session window to R1
and view the results of the ACL and NAT session translation.
in
rn
Acl's step is 5
ea
/l
:/
rule 15 deny ip
tp
ht
: 10.0.4.254
s:
SrcAddr
: ICMP(1)
: 119.84.111.3
: 8
ce
DestAddr Vpn
Protocol
Re
New IcmpId
: 119.84.111.242
so
New SrcAddr
New DestAddr
44003
ur
NAT-Info
: ---: 10247
: TCP(6)
: 10.0.4.254
49646
: 119.84.111.3
23
ni
ng
: 119.84.111.242
New SrcPort
: 10249
Le
ar
New SrcAddr
: ----
New DestPort
: ----
re
New DestAddr
Mo
Total : 2
HC Series
HUAWEI TECHNOLOGIES
Page119
aw
ei
.c
om
/e
The ICMP session has a lifetime of only 20 seconds and therefore may not
appear to be present when displaying the NAT session results. The following
command can be used in this case to extend the period over which the ICMP
results are maintained:
[R1]firewall-nat session icmp aging-time 300
hu
Configure easyIP on the Gigabit Ethernet 0/0/0 interface of R3, associating the
easyIP configuration with ACL 2000 that had been configured earlier.
g.
in
rn
ea
/l
:/
tp
ht
5 packet(s) transmitted
5 packet(s) received
s:
ce
ur
so
Re
ng
ni
--------------------------------------------------------------------Interface
Acl
Address-group/IP/Interface
Type
ar
--------------------------------------------------------------------2000
119.84.111.3
easyip
Le
GigabitEthernet0/0/0
---------------------------------------------------------------------
Mo
re
Total : 1
Page120
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Final Configuration
<R1>display current-configuration
[V200R003C00SPC200]
#
sysname R1
#
firewall-nat session icmp aging-time 300
#
hu
g.
eq telnet
in
rn
ea
/l
interface GigabitEthernet0/0/0
interface GigabitEthernet0/0/1
ht
tp
:/
s:
user-interface con 0
authentication-mode password
ce
ur
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
so
Re
return
ng
<R3>display current-configuration
#
ni
[V200R003C00SPC200]
ar
sysname R3
Le
re
Mo
interface GigabitEthernet0/0/0
HC Series
HUAWEI TECHNOLOGIES
Page121
aw
ei
.c
om
/e
#
interface GigabitEthernet0/0/2
ip address 10.0.6.3 255.255.255.0
#
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
hu
user-interface vty 0 4
authentication-mode password
g.
in
cipher %$%$7ml|,!ccE$SQ~CZ{GtaE%hO>v}~bVk18p5qq<:UPtI:9hOA%%$%$
#
ea
rn
return
/l
<S1>display current-configuration
:/
#
!Software Version V100R006C00SPC800
tp
sysname S1
#
ht
vlan batch 4
#
s:
interface Vlanif4
ce
#
port link-type trunk
ur
interface GigabitEthernet0/0/1
so
Re
interface GigabitEthernet0/0/2
ng
ni
ar
Le
interface GigabitEthernet0/0/14
shutdown
re
Mo
Page122
HUAWEI TECHNOLOGIES
HC Series
user-interface vty 0 4
aw
ei
.c
om
/e
<S2>display current-configuration
#
!Software Version V100R006C00SPC800
hu
sysname S2
#
g.
vlan batch 6
in
#
interface Vlanif6
rn
ea
#
interface GigabitEthernet0/0/2
/l
tp
:/
interface GigabitEthernet0/0/3
ht
s:
ce
interface GigabitEthernet0/0/23
ur
shutdown
#
so
Re
user-interface con 0
user-interface vty 0 4
ng
Mo
re
Le
ar
ni
return
HC Series
HUAWEI TECHNOLOGIES
Page123
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
g.
hu
tp
:/
/l
ea
rn
in
Topology
ht
s:
Scenario
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
R1 and R3 have been deployed on the network and are to provide remote
authentication services using AAA. The company requires that both routers
are made part of the huawei domain and that the telnet service is made
available to users, with limited privileges given once authenticated.
Page124
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
[Huawei]sysname R1
hu
[R1]interface GigabitEthernet0/0/0
g.
[R3]inter GigabitEthernet0/0/0
ea
rn
in
[Huawei]sysname R3
:/
/l
ht
tp
Remove the previous NAT and ACL configuration from R1 and R3.
s:
ce
ur
so
Re
ng
ni
<R1>ping 119.84.111.3
PING 119.84.111.3: 56 data bytes, press CTRL_C to break
ar
Le
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page125
5 packet(s) transmitted
aw
ei
.c
om
/e
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 10/26/70 ms
hu
g.
[R1]aaa
in
[R1-aaa]authentication-scheme auth1
[R1-aaa-authen-auth1]authentication-mode local
[R1-aaa-authen-auth1]quit
ea
[R1-aaa]authorization-scheme auth2
rn
/l
tp
:/
[R1-aaa-author-auth2]quit
ht
Configure the domain huawei on R1, then create a user and apply the user to
this domain.
s:
[R1-aaa]domain huawei
[R1-aaa-domain-huawei]authentication-scheme auth1
ce
[R1-aaa-domain-huawei]authorization-scheme auth2
ur
[R1-aaa-domain-huawei]quit
so
Re
ng
Mo
re
Le
ar
ni
[R1-ui-vty0-4]authentication-mode aaa
Page126
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
<R3>telnet 119.84.111.1
Press CTRL_] to quit telnet mode
Trying 119.84.111.1 ...
Connected to 119.84.111.1 ...
Login authentication
Username:user1@huawei
hu
Password:
<R1>system-view
g.
in
rn
<R1>quit
/l
ea
Operations are restricted as user privileges are limited to privilege level 0 for
user1@huawei.
[R3]aaa
ht
[R3-aaa]authentication-scheme auth1
tp
:/
s:
[R3-aaa-authen-auth1]authentication-mode local
ce
[R3-aaa]authorization-scheme auth2
ur
Re
so
[R3-aaa-author-auth2]quit
ng
Configure the domain huawei on R3, then create a user and apply the user to
this domain.
[R3-aaa]domain huawei
ni
[R3-aaa-domain-huawei]authentication-scheme auth1
ar
[R3-aaa-domain-huawei]authorization-scheme auth2
[R3-aaa-domain-huawei]quit
Le
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page127
[R3-ui-vty0-4]authentication-mode aaa
hu
aw
ei
.c
om
/e
[R3]user-interface vty 0 4
in
g.
Login authentication
Username:user3@huawei
rn
Password:
ea
<R3>system-view
^
/l
:/
<R3>
ht
tp
Operations are restricted as user privileges are set to privilege level 0 for
user3@huawei.
s:
ur
ce
so
Domain-state
: huawei
: Active
: auth1
Accounting-scheme-name
: default
Re
Authentication-scheme-name
Authorization-scheme-name : auth2
: -
RADIUS-server-template
: -
HWTACACS-server-template
: -
User-group
: -
Mo
re
Le
ar
ni
ng
Service-scheme-name
Page128
HUAWEI TECHNOLOGIES
HC Series
State
: active
Service-type-mask
: T
Privilege level
: 0
Ftp-directory
: -
Access-limit
: -
Accessed-num
: 0
Idle-timeout
: -
User-group
: -
hu
aw
ei
.c
om
/e
Password
: Active
Authentication-scheme-name
: auth1
Accounting-scheme-name
: default
Authorization-scheme-name
: auth2
Service-scheme-name
: -
RADIUS-server-template
: -
HWTACACS-server-template
: -
User-group
: -
rn
Domain-state
ea
: huawei
ht
tp
:/
/l
Domain-name
in
g.
s:
: ****************
State
: active
Service-type-mask
: T
so
: 0
: : -
Mo
re
Le
ar
ni
ng
User-group
: -
Re
Idle-timeout
: 0
: -
Access-limit
Accessed-num
ur
Privilege level
Ftp-directory
ce
Password
HC Series
HUAWEI TECHNOLOGIES
Page129
aw
ei
.c
om
/e
Final Configuration
<R1>display current-configuration
[V200R003C00SPC200]
#
sysname R1
#
aaa
authentication-scheme default
hu
authentication-scheme auth1
authorization-scheme default
g.
authorization-scheme auth2
in
accounting-scheme default
domain default
rn
domain default_admin
domain huawei
ea
authentication-scheme auth1
/l
authorization-scheme auth2
:/
tp
ht
s:
ce
interface GigabitEthernet0/0/0
ur
so
Re
user-interface con 0
authentication-mode password
set authentication password
ng
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
ni
user-interface vty 0 4
authentication-mode aaa
ar
Mo
re
Le
return
Page130
HUAWEI TECHNOLOGIES
HC Series
[V200R003C00SPC200]
aw
ei
.c
om
/e
#
sysname R3
#
aaa
authentication-scheme default
authentication-scheme auth1
authorization-scheme default
authorization-scheme auth2
hu
accounting-scheme default
domain default
g.
domain default_admin
in
domain huawei
authentication-scheme auth1
rn
authorization-scheme auth2
ea
/l
:/
tp
ht
#
interface GigabitEthernet0/0/0
s:
ce
ur
user-interface con 0
authentication-mode password
so
Re
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
authentication-mode aaa
ng
Mo
re
Le
ar
ni
return
HC Series
HUAWEI TECHNOLOGIES
Page131
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
hu
g.
tp
:/
/l
ea
rn
in
Topology
ht
ce
s:
Scenario
Mo
re
Le
ar
ni
ng
Re
so
ur
Page132
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
<Huawei>system-view
[Huawei]sysname R1
[R1]interface Serial 1/0/0
hu
in
g.
rn
[Huawei]sysname R2
ea
tp
:/
/l
ht
<Huawei>system-view
[R3]interface Serial 2/0/0
s:
[Huawei]sysname R3
ce
[R3-Serial2/0/0]interface loopback 0
so
ur
Re
ng
Remove the addressing for the Gigabit Ethernet 0/0/0 interface on R1 & R3,
and disable the interfaces as shown to prevent alternative routes.
[R1]interface GigabitEthernet 0/0/0
ni
[R1-GigabitEthernet0/0/0]undo ip address
ar
[R1-GigabitEthernet0/0/0]quit
[R1]interface GigabitEthernet 0/0/1
Le
[R1-GigabitEthernet0/0/1]shutdown
[R1-GigabitEthernet0/0/1]quit
re
Mo
[R1-Serial1/0/0]undo shutdown
HC Series
HUAWEI TECHNOLOGIES
Page133
[R2-Serial1/0/0]undo shutdown
aw
ei
.c
om
/e
g.
hu
[R3-Serial2/0/0]undo shutdown
in
rn
[R1-LoopBack0]interface loopback 1
ea
/l
[R3-LoopBack0]interface loopback 1
:/
ht
tp
ce
s:
Use the IP address of Loopback 0 as the router ID, use the default OSPF
process (1), and specify the public network segments 10.0.12.0/24, and
10.0.23.0/24 as part of OSPF area 0.
[R1-ospf-1]area 0
ur
so
Re
ng
ni
Le
ar
re
[R3-ospf-1]area 0
Mo
Page134
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
---------------------------------------------------------------------------Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.1.1
Full
0.0.0.0
Serial2/0/0
10.0.3.3
hu
Area Id
Full
g.
----------------------------------------------------------------------------
in
<R1>display ip routing-table
rn
----------------------------------------------------------------------------
10.0.1.0/24
Direct
10.0.1.1/32
Direct
10.0.1.255/32
Direct
10.0.2.2/32
OSPF
10
781
10.0.3.3/32
OSPF
10
10.0.11.0/24
Direct
10.0.11.11/32
/l
Pre Cost
Flags NextHop
Interface
10.0.1.1
LoopBack0
127.0.0.1
LoopBack0
127.0.0.1
LoopBack0
10.0.12.2
Serial1/0/0
2343
10.0.12.2
Serial1/0/0
10.0.11.11
LoopBack1
Direct
127.0.0.1
LoopBack1
10.0.11.255/32 Direct
127.0.0.1
LoopBack1
10.0.12.0/24
Direct
10.0.12.1
Serial1/0/0
10.0.12.1/32
Direct
127.0.0.1
Serial1/0/0
Direct
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct
127.0.0.1
Serial1/0/0
10.0.23.0/24
OSPF
10
2343
10.0.12.2
Serial1/0/0
10.0.33.33/32
OSPF
10
2343
10.0.12.2
Serial1/0/0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
Le
ar
ni
ng
ce
ur
Re
10.0.12.2/32
ht
s:
tp
Proto
so
Destination/Mask
Routes : 17
:/
Destinations : 17
ea
Mo
re
If the baudrate is maintained as 128000 from lab 6-1, the OSPF cost will be set
as shown, and thus may vary due to the the metric calculation used by OSPF.
HC Series
HUAWEI TECHNOLOGIES
Page135
aw
ei
.c
om
/e
Routes : 17
Proto
Pre Cost
10.0.1.1/32
OSPF
10
3124
10.0.23.2
Flags NextHop
Interface
Serial2/0/0
10.0.2.2/32
OSPF
10
1562
10.0.23.2
10.0.3.0/24
Direct
10.0.3.3
10.0.3.3/32
Direct
127.0.0.1
10.0.3.255/32
Direct
127.0.0.1
10.0.11.11/32
OSPF
10
3124
10.0.23.2
10.0.12.0/24
OSPF
10
3124
10.0.23.2
Serial2/0/0
10.0.23.0/24
Direct
10.0.23.3
Serial2/0/0
10.0.23.2/32
Direct
10.0.23.2
Serial2/0/0
10.0.23.3/32
Direct
10.0.23.255/32 Direct
10.0.33.0/24
Direct
10.0.33.33/32
Direct
10.0.33.255/32 Direct
127.0.0.0/8
Direct
127.0.0.1/32
Direct
127.255.255.255/32 Direct
255.255.255.255/32 Direct
hu
g.
in
rn
ea
LoopBack0
Serial2/0/0
Serial2/0/0
127.0.0.1
Serial2/0/0
/l
127.0.0.1
10.0.33.33
LoopBack1
127.0.0.1
LoopBack1
127.0.0.1
LoopBack1
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
tp
ht
LoopBack0
ce
s:
Serial2/0/0
LoopBack0
:/
ur
Re
so
An advanced ACL is created to identify interesting traffic for which the IPsec
VPN will be applied. The advanced ACL is capable of filtering based on
specific parameters for selective traffic filtering.
ng
[R1]acl 3001
[R1-acl-adv-3001]rule 5 permit ip source 10.0.1.0 0.0.0.255 destination 10.0.3.0
ar
ni
0.0.0.255
[R3]acl 3001
Le
Mo
re
0.0.0.255
Page136
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
g.
in
ea
rn
/l
Number of proposals: 1
tran1
Encapsulation mode :
Tunnel
Transform
esp-new
ESP protocol
Authentication SHA1-HMAC-96
3DES
tran1
Tunnel
so
Encapsulation mode :
ur
Number of proposals: 1
ce
s:
ht
Encryption
tp
:/
:
:
esp-new
Authentication SHA1-HMAC-96
Encryption
3DES
ng
ESP protocol
Re
Transform
ar
ni
Le
Create an IPsec policy and define the parameters for establishing the SA.
[R1]ipsec policy P1 10 manual
re
Mo
[R1-ipsec-policy-manual-P1-10]proposal tran1
[R1-ipsec-policy-manual-P1-10]tunnel remote 10.0.23.3
HC Series
HUAWEI TECHNOLOGIES
Page137
aw
ei
.c
om
/e
g.
hu
in
rn
ea
/l
:/
===========================================
tp
ht
===========================================
s:
Sequence number: 10
ce
ur
so
Proposal name:tran1
AH SPI:
Re
Inbound AH setting:
AH string-key:
ng
ni
ar
Le
Outbound AH setting:
Mo
re
AH SPI:
AH string-key:
Page138
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
in
g.
===========================================
Sequence number: 10
rn
ea
/l
:/
Proposal name:tran1
Inbound AH setting:
tp
AH SPI:
AH string-key:
ht
s:
ce
ur
so
AH SPI:
Re
AH string-key:
ng
ni
Mo
re
Le
ar
HC Series
HUAWEI TECHNOLOGIES
Page139
aw
ei
.c
om
/e
Apply the policy to the physical interface upon which traffic will be subjected to
IPsec processing.
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]ipsec policy P1
[R3]interface Serial 2/0/0
hu
[R3-Serial2/0/0]ipsec policy P1
g.
in
Observe and verity that non-interesting traffic bypasses the IPsec processing.
rn
ea
/l
:/
tp
ht
5 packet(s) transmitted
5 packet(s) received
s:
ce
ur
: 0
so
: 0
Re
: 0
: 0
: 0
: 0
: 0
BadAuthLen count
: 0
AuthFail count
: 0
InSAAclCheckFail count
: 0
PktDuplicateDrop count
: 0
ar
ng
Outpacket count
ni
: 0
Le
re
PktSeqNoTooSmallDrop count : 0
Mo
PktInSAMissDrop count
Page140
: 0
HUAWEI TECHNOLOGIES
HC Series
Observe that only the interesting traffic will be secured by the IPsec VPN.
aw
ei
.c
om
/e
hu
g.
5 packet(s) received
0.00% packet loss
rn
in
: 0
Outpacket count
: 5
: 0
: 0
: 0
: 0
BadAuthLen count
: 0
AuthFail count
: 0
InSAAclCheckFail count
: 0
ce
PktDuplicateDrop count
/l
:/
: 0
tp
ht
: 5
s:
Inpacket count
ea
: 0
ur
PktSeqNoTooSmallDrop count : 0
: 0
Re
so
PktInSAMissDrop count
ng
Step 10
ni
Le
ar
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page141
aw
ei
.c
om
/e
---------------------------------------------------------------------------Area Id
Interface
Neighbor id
0.0.0.0
Serial1/0/0
10.0.2.2
State
Init
---------------------------------------------------------------------------<R1>display ip routing-table
hu
----------------------------------------------------------------------------
in
Pre Cost
10.0.1.0/24
Direct
10.0.1.1/32
Direct
10.0.11.11/32
Direct
10.0.11.255/32 Direct
10.0.12.0/24
Direct
10.0.12.1/32
Direct
10.0.12.2/32
Direct
10.0.12.255/32 Direct
127.0.0.0/8
127.0.0.1/32
Interface
10.0.1.1
LoopBack0
127.0.0.1
LoopBack0
/l
127.0.0.1
LoopBack0
10.0.11.11
LoopBack1
127.0.0.1
LoopBack1
127.0.0.1
LoopBack1
10.0.12.1
Serial1/0/0
127.0.0.1
Serial1/0/0
10.0.12.2
Serial1/0/0
127.0.0.1
Serial1/0/0
Direct
127.0.0.1
InLoopBack0
Direct
127.0.0.1
InLoopBack0
:/
tp
Direct
ht
Direct
10.0.11.0/24
ce
s:
10.0.1.255/32
Flags NextHop
rn
Proto
ur
Destination/Mask
Routes : 14
ea
Destinations : 14
g.
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
Re
so
127.255.255.255/32 Direct
ng
ni
---------------------------------------------------------------------------Interface
Neighbor id
State
0.0.0.0
Serial2/0/0
10.0.2.2
Init
Le
ar
Area Id
Mo
re
----------------------------------------------------------------------------
Page142
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Routes : 14
Proto
Pre Cost
10.0.3.0/24
Direct
10.0.3.3
10.0.3.3/32
Direct
127.0.0.1
10.0.3.255/32
Direct
127.0.0.1
10.0.23.0/24
Direct
10.0.23.3
10.0.23.2/32
Direct
10.0.23.2
10.0.23.3/32
Direct
127.0.0.1
10.0.23.255/32 Direct
127.0.0.1
Serial2/0/0
10.0.33.0/24
Direct
10.0.33.33
LoopBack1
10.0.33.33/32
Direct
127.0.0.1
LoopBack1
10.0.33.255/32 Direct
127.0.0.0/8
Direct
127.0.0.1/32
255.255.255.255/32 Direct
LoopBack0
LoopBack0
hu
g.
in
rn
ea
LoopBack0
Serial2/0/0
Serial2/0/0
Serial2/0/0
127.0.0.1
LoopBack1
127.0.0.1
InLoopBack0
/l
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
:/
Interface
ht
Direct
127.255.255.255/32 Direct
Flags NextHop
tp
Destination/Mask
ur
ce
s:
OSPF hello messages fail to be encapsulated using IPsec, causing the link
state to fail, returning OSPF to an Init state and effectively breaking the
established OSPF adjacent relationship of R1 and R3 with R2. Lab 7-5 will
introduce solutions to the problem of dynamic routing over IPsec VPN.
so
Final Configuration
Re
<R1>display current-configuration
[V200R003C00SPC200]
ng
ni
sysname R1
#
ar
Le
re
Mo
HC Series
HUAWEI TECHNOLOGIES
Page143
aw
ei
.c
om
/e
hu
#
interface Serial1/0/0
g.
link-protocol ppp
in
rn
ipsec policy P1
ea
baudrate 128000
#
/l
interface LoopBack0
:/
tp
interface LoopBack1
ht
#
ospf 1 router-id 10.0.1.1
s:
area 0.0.0.0
ce
so
user-interface con 0
ur
Re
authentication-mode password
set authentication password
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
ng
user-interface vty 0 4
#
Mo
re
Le
ar
return
ni
authentication-mode aaa
Page144
HUAWEI TECHNOLOGIES
HC Series
[V200R003C00SPC200]
aw
ei
.c
om
/e
#
sysname R2
#
interface Serial1/0/0
link-protocol ppp
hu
interface Serial2/0/0
link-protocol ppp
g.
in
rn
ea
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
/l
:/
tp
ht
#
user-interface con 0
s:
authentication-mode password
set authentication password
ur
user-interface vty 0 4
ce
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
#
Re
so
return
<R3>display current-configuration
ng
[V200R003C00SPC200]
ni
#
#
ar
sysname R3
Le
re
Mo
HC Series
HUAWEI TECHNOLOGIES
Page145
aw
ei
.c
om
/e
hu
g.
interface Serial2/0/0
in
link-protocol ppp
ppp authentication-mode chap
rn
ea
ipsec policy P1
#
/l
interface LoopBack0
:/
tp
interface LoopBack1
ht
#
ospf 1 router-id 10.0.3.3
s:
area 0.0.0.0
ce
so
user-interface con 0
ur
Re
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
ng
user-interface vty 0 4
#
Mo
re
Le
ar
return
ni
authentication-mode aaa
Page146
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
As a result of this lab section, you should achieve the following tasks:
Configuration of an ACL to support GRE encapsulation
Establishment of a tunnel interface for GRE
Implementation of the GRE keepalive feature.
hu
tp
:/
/l
ea
rn
in
g.
Topology
ht
s:
Scenario
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
HC Series
HUAWEI TECHNOLOGIES
Page147
aw
ei
.c
om
/e
Tasks
Note: It is a prerequisite that lab 3-4 be completed before attempting this lab.
Reconfigure the access control list establish GRE encapsulation over IPsec.
hu
[R1]acl 3001
g.
in
[R3]acl 3001
ea
/l
rn
tp
:/
Create a tunnel interface and specify GRE as the encapsulation type. Set the
tunnel source address or source interface, and set the tunnel destination
address.
ht
s:
[R1-Tunnel0/0/1]tunnel-protocol gre
[R1-Tunnel0/0/1]source 10.0.12.1
ce
[R1-Tunnel0/0/1]destination 10.0.23.3
ur
so
Re
[R3-Tunnel0/0/1]source 10.0.23.3
ni
ng
[R3-Tunnel0/0/1]destination 10.0.12.1
ar
Mo
re
Le
Add the tunnel interface network to OSPF 1 process, and create a second
OSPF instance of the link state database (process 2) for the 10.0.12.0 and
10.0.23.0 networks, be sure to remove these networks from OSPF 1.
Page148
HUAWEI TECHNOLOGIES
HC Series
[R1-ospf-1]area 0
aw
ei
.c
om
/e
g.
hu
[R3-ospf-1]area 0
rn
in
[R3-ospf-2]area 0
/l
ea
OSPF LSDB are significant only to the local router, therefore allowing routes
from OSPF LSDB 2 of R1 and R3 to reach OSPF LSDB 1 of R2.
:/
Run the display interface Tunnel 0/0/1 command to verify the configuration.
tp
ht
s:
ce
ur
so
Re
ng
ni
ar
Le
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page149
hu
keepalive disabled
aw
ei
.c
om
/e
g.
in
rn
/l
tp
:/
ea
ht
Step 4 Verify that the routes are being carried via GRE
s:
Run the display ip routing-table command to check the IPv4 routing table.
ce
<R1>display ip routing-table
ur
----------------------------------------------------------------------------
so
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1
LoopBack0
10.0.1.1/32
Direct
127.0.0.1
LoopBack0
10.0.1.255/32
Direct
127.0.0.1
LoopBack0
10.0.2.2/32
OSPF
10
781
10.0.12.2
Serial1/0/0
10.0.3.3/32
OSPF
10
1562
100.1.1.2
Tunnel0/0/1
10.0.11.0/24
Direct
10.0.11.11
LoopBack1
10.0.11.11/32
Direct
127.0.0.1
LoopBack1
10.0.11.255/32 Direct
127.0.0.1
LoopBack1
Mo
re
Le
ni
ng
Destination/Mask
Routes : 21
ar
Re
Destinations : 21
Page150
Flags NextHop
HUAWEI TECHNOLOGIES
Interface
HC Series
Direct
10.0.12.1
Serial1/0/0
10.0.12.1/32
Direct
127.0.0.1
Serial1/0/0
10.0.12.2/32
Direct
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct
127.0.0.1
10.0.23.0/24
OSPF
10
2343
10.0.12.2
10.0.33.33/32
OSPF
10
1562
100.1.1.2
100.1.1.0/24
Direct
100.1.1.1
100.1.1.1/32
Direct
127.0.0.1
100.1.1.255/32 Direct
127.0.0.1
127.0.0.1
Direct
127.0.0.1
127.255.255.255/32 Direct
127.0.0.1
255.255.255.255/32 Direct
127.0.0.1
Serial1/0/0
Tunnel0/0/1
Tunnel0/0/1
Tunnel0/0/1
Tunnel0/0/1
InLoopBack0
InLoopBack0
hu
Direct
127.0.0.1/32
Serial1/0/0
InLoopBack0
InLoopBack0
in
g.
127.0.0.0/8
aw
ei
.c
om
/e
10.0.12.0/24
<R3>display ip routing-table
rn
ea
----------------------------------------------------------------------------
Pre Cost
10.0.1.1/32
OSPF
10
1562
10.0.2.2/32
OSPF
10
1562
10.0.3.0/24
Direct
10.0.3.3/32
Direct
10.0.3.255/32
Direct
10.0.11.11/32
OSPF
10.0.12.0/24
OSPF
10.0.23.0/24
Direct
10.0.23.2/32
Direct
Direct
:/
Proto
Flags NextHop
Interface
100.1.1.1
Tunnel0/0/1
10.0.23.2
Serial2/0/0
10.0.3.3
LoopBack0
127.0.0.1
LoopBack0
127.0.0.1
LoopBack0
10
1562
100.1.1.1
Tunnel0/0/1
10
3124
10.0.23.2
Serial2/0/0
10.0.23.3
Serial2/0/0
10.0.23.2
Serial2/0/0
127.0.0.1
Serial2/0/0
10.0.23.255/32 Direct
127.0.0.1
Serial2/0/0
10.0.33.0/24
Direct
10.0.33.33
LoopBack1
10.0.33.33/32
Direct
127.0.0.1
LoopBack1
10.0.33.255/32 Direct
127.0.0.1
LoopBack1
ni
ng
s:
ce
ur
Re
10.0.23.3/32
ht
so
Destination/Mask
Routes : 21
tp
Destinations : 21
/l
Direct
100.1.1.2
Tunnel0/0/1
100.1.1.2/32
Direct
127.0.0.1
Tunnel0/0/1
100.1.1.255/32 Direct
127.0.0.1
Tunnel0/0/1
Le
ar
100.1.1.0/24
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
Mo
re
127.0.0.0/8
HC Series
HUAWEI TECHNOLOGIES
Page151
aw
ei
.c
om
/e
After a GRE tunnel is set up, the router can exchange OSPF packets through
the GRE tunnel. Clear the IPsec statistics and test the connection
<R1>reset ipsec statistics esp
[R1]ping -a 10.0.1.1 10.0.3.3
PING 10.0.3.3: 56 data bytes, press CTRL_C to break
hu
g.
in
5 packet(s) transmitted
rn
5 packet(s) received
0.00% packet loss
/l
: 0
Outpacket count
: 8
: 0
: 0
: 0
: 0
ce
BadAuthLen count
: 0
: 0
ur
AuthFail count
tp
: 0
ht
s:
: 8
:/
ea
so
InSAAclCheckFail count
PktDuplicateDrop count
: 0
: 0
Re
PktSeqNoTooSmallDrop count : 0
: 0
ng
PktInSAMissDrop count
ni
GRE encapsulates all OSPF traffic including the hello packets over IPsec, the
gradual increment of the IPsec esp statistics verifies this.
Le
ar
Mo
re
[R1-Tunnel0/0/1]keepalive period 3
Page152
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Verify that the keepalive feature has been enabled on the tunnel interface.
<R1>display interface Tunnel 0/0/1
Tunnel0/0/1 current state : UP
Line protocol current state : UP
Last line protocol up time : 2013-12-18 09:50:21
Description:HUAWEI, AR Series, Tunnel0/0/1 Interface
Route Port,The Maximum Transmit Unit is 1500
Internet Address is 100.1.1.1/24
hu
g.
in
rn
ea
/l
:/
tp
ce
Final Configuration
s:
ht
[V200R003C00SPC200]
so
#
sysname R1
Re
ur
<R1>display current-configuration
ng
ni
ar
Le
re
Mo
proposal tran1
HC Series
HUAWEI TECHNOLOGIES
Page153
aw
ei
.c
om
/e
hu
g.
baudrate 128000
in
#
interface LoopBack0
rn
ea
#
interface LoopBack1
/l
ht
keepalive period 3
tp
interface Tunnel0/0/1
:/
destination 10.0.23.3
#
ce
s:
source 10.0.12.1
ur
area 0.0.0.0
so
Re
ng
area 0.0.0.0
ni
ar
user-interface con 0
Le
authentication-mode password
set authentication password
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
re
user-interface vty 0 4
Mo
authentication-mode aaa
Page154
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
return
<R2>display current-configuration
[V200R003C00SPC200]
#
sysname R2
#
interface Serial1/0/0
hu
link-protocol ppp
g.
in
#
interface Serial2/0/0
rn
link-protocol ppp
ea
/l
ht
tp
interface LoopBack0
:/
area 0.0.0.0
s:
ce
ur
so
authentication-mode password
Re
ng
ar
ni
return
Le
<R3>display current-configuration
[V200R003C00SPC200]
#
re
sysname R3
Mo
HC Series
HUAWEI TECHNOLOGIES
Page155
aw
ei
.c
om
/e
#
ipsec proposal tran1
esp authentication-algorithm sha1
esp encryption-algorithm 3des
#
ipsec policy P1 10 manual
security acl 3001
proposal tran1
hu
g.
in
rn
ea
#
interface Serial2/0/0
/l
link-protocol ppp
:/
tp
ipsec policy P1
#
ht
interface LoopBack0
s:
#
interface LoopBack1
ce
ur
so
Re
tunnel-protocol gre
source 10.0.23.3
destination 10.0.12.1
ng
ni
ar
Le
re
Mo
area 0.0.0.0
Page156
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
authentication-mode aaa
#
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
:/
/l
ea
rn
in
g.
hu
return
HC Series
HUAWEI TECHNOLOGIES
Page157
aw
ei
.c
om
/e
hu
As a result of this lab section, you should achieve the following tasks:
in
g.
ur
ce
s:
ht
tp
:/
/l
ea
rn
Topology
ng
Re
so
Scenario
Mo
re
Le
ar
ni
With the continued growth of the enterprise network it has become apparent
that new measures need to be taken to manage and monitor the health of the
network so as to minimize network downtime. The network administrator has
decided that an NMS solution should be deployed, with tests performed to
observe the basic capability of the NMS solution to monitor devices, before
deploying the solution in the enterprise network.
Page158
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
<Huawei>system-view
hu
[Huawei]sysname R1
[R1]interface LoopBack 0
in
g.
rn
[Huawei]sysname R3
[R3]interface LoopBack 0
/l
ea
:/
ht
tp
Disable the unused serial interfaces and remove the OSPF processes from all
routers.
[R1]interface Serial 1/0/0
s:
[R1-Serial1/0/0]shutdown
ce
[R1-Serial1/0/0]quit
[R1]undo ospf 1
ur
so
[R1]undo ospf 2
Re
ng
[R3-Serial2/0/0]shutdown
[R3-Serial2/0/0]quit
ni
[R3]undo ospf 1
ar
Mo
re
Le
HC Series
HUAWEI TECHNOLOGIES
Page159
aw
ei
.c
om
/e
hu
g.
[R1]ospf
[R1-ospf-1]area 0
rn
in
ea
/l
:/
ht
tp
s:
ce
ur
so
Re
ng
ni
5 packet(s) transmitted
5 packet(s) received
ar
Mo
re
Le
Page160
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
g.
rn
in
Enable the trap function of R1. Configure contact information about the
device administrator.
ea
/l
:/
tp
public
ht
ce
s:
After the configuration is complete, run the following commands to verify that
the configuration has taken effect.
ur
Re
so
ng
Shenzhen China
ni
ar
SNMPv2c
Le
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page161
Traphost list:
aw
ei
.c
om
/e
hu
g.
in
ea
rn
Total number is 1
/l
Re
so
ur
ce
s:
ht
tp
:/
Under the Resource > Add Device > Single path, add the Network Element
(NE) R1 and R3 to the NMS, and configure the SNMP parameters as shown.
Mo
re
Le
ar
ni
ng
Verify that the Network Elements have been added to the NMS under the
Resource > Resource Management > Equipment Resources > NE Resources
path.
Page162
HUAWEI TECHNOLOGIES
HC Series
:/
/l
ea
rn
in
g.
hu
aw
ei
.c
om
/e
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
Select the Interface Manager option under Device Config in the resource menu
to the left of the screen. The given output represents a scenario in which all
labs throughout the lab guide have been completed in succession, thus
producing multiple addresses.
HC Series
HUAWEI TECHNOLOGIES
Page163
rn
in
g.
hu
aw
ei
.c
om
/e
:/
/l
ea
tp
[R1-ui-vty0-4]authentication-mode password
ht
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
The telnet feature in the Basic Information panel of the resource menu grants
remote management of the NE via the NMS, however privileges currently
prevent configuration.
Page164
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
If the AAA configuration has been maintained from lab 7-3, first increase the
privilege from level 0 to level 3.
[R1]aaa
[R1-aaa]local-user user1@huawei privilege level 3
g.
hu
in
tp
:/
/l
ea
rn
Changes that occur to the NE can be monitored in the NMS using traps which
trigger alarms. Select the Alarm List from the view panel from the resource
menu .
s:
ht
Currently no alarms are recorded. Access the NE through the telnet feature in
the NMS and shut down the loopback 0 interface to trigger alarms on the NMS.
[R1-LoopBack0]shutdown
ce
[R1]interface LoopBack 0
Mo
re
Le
ar
ni
ng
Re
so
ur
[R1-LoopBack0]undo shutdown
HC Series
HUAWEI TECHNOLOGIES
Page165
aw
ei
.c
om
/e
Verify that the relevant alarms have been generated in the Alarm List for the
resource, once the interface state has been changed.
g.
hu
If the interface of R1 that is linked to the NMS is down, will the failure be
detected by the NMS?
in
Final Configuration
rn
<R1>dis current-configuration
ea
[V200R003C00SPC200]
#
/l
sysname R1
:/
tp
ht
s:
ce
trap-paramsname public
ur
so
Re
snmp-agent
#
ng
aaa
authentication-scheme default
ni
authentication-scheme auth1
authorization-scheme default
ar
authorization-scheme auth2
Le
accounting-scheme default
domain default
domain default_admin
Mo
re
domain huawei
Page166
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
interface GigabitEthernet0/0/0
ip address 10.0.13.1 255.255.255.0
g.
in
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
rn
ea
/l
:/
tp
user-interface con 0
authentication-mode password
ht
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
s:
user-interface vty 0 4
authentication-mode aaa
ce
so
ur
return
Re
<R3>display current-configuration
[V200R003C00SPC200]
#
ng
sysname R3
ni
ar
Le
re
Mo
trap-paramsname public
HC Series
authorization-scheme auth2
HUAWEI TECHNOLOGIES
Page167
aw
ei
.c
om
/e
hu
authorization-scheme auth2
accounting-scheme default
g.
domain default
in
domain default_admin
domain huawei
rn
authentication-scheme auth1
ea
authorization-scheme auth2
/l
:/
tp
ht
s:
interface GigabitEthernet0/0/0
ce
ur
so
Re
user-interface con 0
ng
authentication-mode password
ni
ar
user-interface vty 0 4
Le
authentication-mode aaa
#
Mo
re
return
Page168
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
hu
As a result of this lab section, you should achieve the following tasks:
ea
rn
in
g.
Mo
re
Le
ar
ni
ng
Re
so
ur
ce
s:
ht
tp
:/
/l
Topology
HC Series
HUAWEI TECHNOLOGIES
Page169
aw
ei
.c
om
/e
Scenario
In line with plans for deployment of solutions for next generation networks, it
has been decided that the enterprise network should implement an IPv6
design to the existing infrastructure. As the administrator you have been
tasked with the job of implementing the addressing scheme and routing for
IPv6, as well as providing stateful addressing solutions for IPv6.
hu
Tasks
in
g.
ea
rn
If you are starting this section with a non-configured device, begin here and
then move to step 2. For those continuing from previous labs, begin at step 2.
<huawei>system-view
:/
/l
[huawei]sysname R1
<huawei>system-view
ht
tp
[huawei]sysname R2
<huawei>system-view
ur
ce
s:
[huawei]sysname R3
so
ni
[R1]ipv6
ng
Re
[R1]interface loopback 0
ar
[R1-LoopBack0]ipv6 enable
Le
Mo
re
Page170
HUAWEI TECHNOLOGIES
HC Series
[R2]interface loopback 0
aw
ei
.c
om
/e
[R2-LoopBack0]ipv6 enable
[R2-LoopBack0]ipv6 address 2001:2::B 64
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]ipv6 enable
[R2-GigabitEthernet0/0/0]ipv6 address fe80::2 link-local
[R3]ipv6
hu
[R3]interface loopback 0
[R3-LoopBack0]ipv6 enable
g.
in
ea
rn
:/
/l
tp
ht
s:
FF02::2
FF02::1
ce
ur
so
Re
Mo
re
Le
ar
ni
ng
HC Series
HUAWEI TECHNOLOGIES
Page171
aw
ei
.c
om
/e
hu
[R1-GigabitEthernet0/0/0]ospfv3 1 area 0
[R1-GigabitEthernet0/0/0]quit
g.
[R1]interface loopback 0
in
[R1-LoopBack0]ospfv3 1 area 0
rn
[R2]ospfv3 1
ea
[R2-ospfv3-1]router-id 2.2.2.2
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]ospfv3 1 area 0
:/
[R2-GigabitEthernet0/0/0]quit
/l
[R2-ospfv3-1]quit
tp
[R2]interface loopback 0
ht
[R2-LoopBack0]ospfv3 1 area 0
[R3]ospfv3 1
s:
[R3-ospfv3-1]router-id 3.3.3.3
[R3-ospfv3-1]quit
ce
ur
[R3-GigabitEthernet0/0/0]ospfv3 1 area 0
[R3-GigabitEthernet0/0/0]quit
so
[R3]interface loopback 0
Re
[R3-LoopBack0]ospfv3 1 area 0
ni
ng
Run the display ospfv3 peer command on R1 and R3 to verify the OSPFv3
peering has been established.
<R1>display ospfv3 peer
ar
Dead Time
Interface
2.2.2.2
Full/Backup
00:00:30
GE0/0/0
3.3.3.3
Full/DROther
00:00:40
GE0/0/0
Mo
re
Le
Neighbor ID Pri
Page172
HUAWEI TECHNOLOGIES
Instance ID
HC Series
State
Dead Time
Interface
1.1.1.1
Full/DR
00:00:32
GE0/0/0
2.2.2.2
Full/Backup
00:00:38
GE0/0/0
aw
ei
.c
om
/e
If 1.1.1.1 is not currently the DR, the following command can be used to reset
the OSPFv3 process
g.
hu
rn
in
Test connectivity to the peer link local address and the global unicast address
of interface LoopBack 0.
ea
/l
:/
tp
ht
s:
ce
ur
so
5 packet(s) received
Re
ng
ni
ar
Le
Mo
re
HC Series
HUAWEI TECHNOLOGIES
Page173
aw
ei
.c
om
/e
g.
hu
rn
in
ea
/l
:/
[R2-dhcpv6-pool-pool1]excluded-address 2001:FACE::1
tp
[R2-dhcpv6-pool-pool1]quit
s:
ht
ce
ur
Re
so
Enable the DHCPv6 client function on R1 and R3 so that devices can obtain
IPv6 addresses using DHCPv6.
[R1]dhcp enable
ng
ni
ar
[R3]dhcp enable
[R3]interface GigabitEthernet 0/0/0
Mo
re
Le
Page174
HUAWEI TECHNOLOGIES
HC Series
aw
ei
.c
om
/e
Run the display dhcpv6 pool command on R2 to check information about the
DHCPv6 address pool.
<R2>display dhcpv6 pool
DHCPv6 pool: pool1
Address prefix: 2001:FACE::/64
Lifetime valid 172800 seconds, preferred 86400 seconds
2 in use, 0 conflicts
Excluded-address 2001:FACE::1
1 excluded addresses
hu
g.
in
ea
rn
Run the display ipv6 interface brief command on R1 and R3 to check the
IPv6 address information.
/l
Physical
up
ht
GigabitEthernet0/0/0
[IPv6 Address] 2001:FACE::2
up
s:
LoopBack0
Protocol
up
up(s)
ce
tp
:/
ur
so
(l): loopback
Re
(s): spoofing
Interface
GigabitEthernet0/0/0
Physical
Protocol
up
up
up
up(s)
ni
LoopBack0
ng
Mo
re
Le
ar
HC Series
HUAWEI TECHNOLOGIES
Page175
aw
ei
.c
om
/e
Final Configuration
<R1>display current-configuration
[V200R003C00SPC200]
#
sysname R1
#
ipv6
#
hu
dhcp enable
#
g.
ospfv3 1
in
router-id 1.1.1.1
#
rn
interface GigabitEthernet0/0/0
ipv6 enable
ea
/l
:/
tp
#
interface LoopBack0
ht
ipv6 enable
s:
ce
ur
user-interface con 0
authentication-mode password
so
Re
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
authentication-mode aaa
ng
Mo
re
Le
ar
ni
return
Page176
HUAWEI TECHNOLOGIES
HC Series
[V200R003C00SPC200]
aw
ei
.c
om
/e
#
sysname R2
#
ipv6
#
dhcp enable
#
dhcpv6 pool pool1
hu
g.
dns-server 2001:444E:5300::1
in
#
ospfv3 1
rn
router-id 2.2.2.2
ea
#
interface GigabitEthernet0/0/0
/l
ipv6 enable
:/
tp
s:
ht
interface LoopBack0
ce
ipv6 enable
ur
so
Re
user-interface con 0
authentication-mode password
ng
ni
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
#
ar
user-interface vty 0 4
Mo
re
Le
return
HC Series
HUAWEI TECHNOLOGIES
Page177
[V200R003C00SPC200]
aw
ei
.c
om
/e
#
sysname R3
#
ipv6
#
dhcp enable
#
ospfv3 1
hu
router-id 3.3.3.3
#
g.
interface GigabitEthernet0/0/0
in
ipv6 enable
ip address 10.0.13.3 255.255.255.0
rn
ea
/l
ht
tp
ipv6 enable
:/
interface LoopBack0
s:
user-interface con 0
authentication-mode password
ce
ur
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
so
authentication-mode aaa
Re
Mo
re
Le
ar
ni
ng
return
Page178
HUAWEI TECHNOLOGIES
HC Series
re
Mo
ni
ar
Le
ng
ur
so
Re
s:
ce
ht
tp
ea
/l
:/
rn
in
g.
hu
aw
ei
.c
om
/e