No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Configuration Guide - IP Unicast Routing

S7700 and S9700 V200R010C00

This document describes IP Unicast Routing configurations supported by the switch, including the principle and configuration procedures of IP Routing Overview, Static Route, RIP, RIPng, OSPF, OSPFv3, IS-IS(IPv4), IS-IS(IPv6), BGP, Routing Policy ,and PBR, and provides configuration examples.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Example for Configuring PBR to Import Traffic to the Firewall in Bypass Mode

Example for Configuring PBR to Import Traffic to the Firewall in Bypass Mode

Networking Requirements

In Figure 1, enterprise users need to access the Internet through SwitchA (core switch) and the router (access gateway).

To ensure enterprise intranet security, traffic entering the enterprise intranet needs to be imported to the firewall in bypass mode.

Figure 12-3  Networking for configuring PBR to import traffic to the firewall in bypass mode

Configuration Roadmap

The configuration roadmap is as follows:

  • Configure an IP address for each interface and configure a routing protocol between the switch and firewall to ensure that there is a reachable route.
  • Configure PBR on SwitchA to redirect traffic that is sent from the external network to the enterprise intranet to the firewall for detection.
NOTE:

This section provides only the switch configuration. For the firewall configuration, see the firewall documentation.

Procedure

  1. Configure an IP address for each interface on SwitchA and the firewall, and configure a routing protocol on SwitchA.

    # Assign an IP address to each interface of SwitchA. By default, a switch interface is a Layer 2 interface. Before configuring an IP address for a switch interface, run the undo portswitch command to switch the interface to a Layer 3 interface.

    <HUAWEI> system-view
    [HUAWEI] sysname SwitchA
    [SwitchA] interface gigabitethernet 1/0/1
    [SwitchA-GigabitEthernet1/0/1] undo portswitch
    [SwitchA-GigabitEthernet1/0/1] ip address 10.1.1.2 24
    [SwitchA-GigabitEthernet1/0/1] quit
    [SwitchA] interface gigabitethernet 1/0/2
    [SwitchA-GigabitEthernet1/0/2] undo portswitch
    [SwitchA-GigabitEthernet1/0/2] ip address 10.1.20.1 24
    [SwitchA-GigabitEthernet1/0/2] quit
    [SwitchA] interface gigabitethernet 1/0/3
    [SwitchA-GigabitEthernet1/0/3] undo portswitch
    [SwitchA-GigabitEthernet1/0/3] ip address 10.1.10.6 24
    [SwitchA-GigabitEthernet1/0/3] quit
    [SwitchA] interface gigabitethernet 1/0/4
    [SwitchA-GigabitEthernet1/0/4] undo portswitch
    [SwitchA-GigabitEthernet1/0/4] ip address 10.1.11.6 24
    [SwitchA-GigabitEthernet1/0/4] quit
    

    # Configure a routing protocol on SwitchA to ensure Layer 3 connectivity. OSPF is used here.

    Generally, two OSPF processes are configured on the firewall to advertise uplink and downlink network segments, so two OSPF processes need to be configured on SwitchA.

    [SwitchA] ospf 100
    [SwitchA-ospf-100] area 0       
    [SwitchA-ospf-100-area-0.0.0.0] network 10.1.1.0 0.0.0.255 
    [SwitchA-ospf-100-area-0.0.0.0] network 10.1.10.0 0.0.0.255
    [SwitchA-ospf-100-area-0.0.0.0] quit
    [SwitchA-ospf-100] quit 
    [SwitchA] ospf 200
    [SwitchA-ospf-200] area 0  
    [SwitchA-ospf-200-area-0.0.0.0] network 10.1.11.0 0.0.0.255 
    [SwitchA-ospf-200-area-0.0.0.0] network 10.1.20.0 0.0.0.255
    [SwitchA-ospf-200-area-0.0.0.0] quit
    [SwitchA-ospf-200] quit

  2. Configure PBR on SwitchA to redirect traffic that is sent from the external network to the enterprise intranet to the firewall for detection.

    # Configure a traffic classifier to match all traffic.
    [SwitchA] traffic classifier c1
    [SwitchA-classifier-c1] if-match any
    [SwitchA-classifier-c1] quit
    
    # Configure a traffic behavior to redirect matching traffic to the firewall (next hop address 10.1.10.5).
    [SwitchA] traffic behavior b1
    [SwitchA-behavior-b1] redirect ip-nexthop 10.1.10.5
    [SwitchA-behavior-b1] quit
    
    # Configure a traffic policy.
    [SwitchA] traffic policy p1
    [SwitchA-trafficpolicy-p1] classifier c1 behavior b1
    [SwitchA-trafficpolicy-p1] quit
    
    # Apply the traffic policy to GigabitEthernet1/0/1 on SwitchA in the inbound direction.
    [SwitchA] interface gigabitethernet 1/0/1
    [SwitchA-GigabitEthernet1/0/1] traffic-policy p1 inbound
    [SwitchA-GigabitEthernet1/0/1] quit
    [SwitchA] quit
    

  3. Verify the configuration.

    # Check the traffic classifier configuration.

    <SwitchA> display traffic classifier user-defined c1
     User Defined Classifier Information:                                          
      Classifier: c1                                                               
       Precedence: 5                                                               
       Operator: OR                                                                
       Rule(s) : if-match any  

    # Check the traffic behavior configuration.

    <SwitchA> display traffic behavior user-defined b1
      User Defined Behavior Information:                                            
        Behavior: b1
          Permit
          Redirect: no forced                                                       
            Redirect ip-nexthop                                                     
            10.1.10.5                    

    # Check the traffic policy configuration.

    <SwitchA> display traffic policy user-defined p1
      User Defined Traffic Policy Information:                                      
      Policy: p1                                                                    
       Classifier: c1                                                                
        Operator: OR                                                                
         Behavior: b1                                                               
          Permit                                                                    
          Redirect: no forced                                                       
            Redirect ip-nexthop                                                     
            10.1.10.5    

    # Check the traffic policy record.

    <SwitchA> display traffic-policy applied-record
    #                                                                               
    -------------------------------------------------                               
      Policy Name:   p1                                                             
      Policy Index:  0                                                              
         Classifier:c1     Behavior:b1                                               
    -------------------------------------------------                               
     *interface GigabitEthernet1/0/1     
        traffic-policy p1 inbound                                                   
          slot 1    :  success                                                      
    -------------------------------------------------                               
      Policy total applied times: 1.                                                
    # 
    

Configuration Files

  • SwitchA configuration file
    #
    sysname SwitchA
    #
    traffic classifier c1 operator or precedence 5
     if-match any
    #
    traffic behavior b1
     permit
     redirect ip-nexthop 10.1.10.5
    #
    traffic policy p1 match-order config
     classifier c1 behavior b1 
    #
    interface GigabitEthernet1/0/1
     undo portswitch                                                                
     ip address 10.1.1.2 255.255.255.0                                              
     traffic-policy p1 inbound            
    #
    interface GigabitEthernet1/0/2
     undo portswitch                                                                
     ip address 10.1.20.1 255.255.255.0  
    #
    interface GigabitEthernet1/0/3
     undo portswitch                                                                
     ip address 10.1.10.6 255.255.255.0  
    #
    interface GigabitEthernet1/0/4
     undo portswitch                                                                
     ip address 10.1.11.6 255.255.255.0  
    #                                                                               
    ospf 100                                                                        
     area 0.0.0.0                                                                   
      network 10.1.1.0 0.0.0.255
      network 10.1.10.0 0.0.0.255                                                  
    #                                                                               
    ospf 200                                                                        
     area 0.0.0.0                                                                   
      network 10.1.11.0 0.0.0.255
      network 10.1.20.0 0.0.0.255                                                   
    #                                              
    return
    
Translation
Download
Updated: 2019-08-21

Document ID: EDOC1000141900

Views: 194510

Downloads: 194

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Share
Previous Next