No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

S600-E V200R012C00 Configuration Guide - VPN

This document describes the configurations of VPN, including IPSec, MCE.
Rate and give feedback :
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Configure Route Exchange Between an MCE Device and VPN Sites

Configure Route Exchange Between an MCE Device and VPN Sites

Context

Routing protocols that can be used between an MCE device and VPN sites are static routing, RIP (Routing Information Protocol), OSPF (Open Shortest Path First). Choose one of the following configurations as needed:

The following configurations are performed on the MCE device. On the devices in the site, you only need to configure the corresponding routing protocol.

Configure Static Routes Between an MCE Device and a Site

Perform the following configurations on the MCE device. You only need to configure a static route to the MCE device in the site. The site configuration is not provided here. For detailed configuration of static routes, see Static Route Configuration in the S600-E V200R012C00 Configuration Guide - IP Unicast Routing.

Table 3-2  MCE configuration

Action

Command

Description

Enter the system view.

system-view

-

Configure a static route to the site.

ip route-static vpn-instance vpn-source-name destination-address { mask | mask-length } { nexthop-address [ public ] | interface-type interface-number [ nexthop-address ] } [ preference preference | tag tag ] *

You must specify the next hop address on the MCE device.

Configure RIP Between an MCE Device and a Site

Perform the following configurations on the MCE device. Configure RIPv1 or RIPv2 in the site. The site configuration is not provided here. For detailed RIP configuration, see RIP Configuration in the S600-E V200R012C00 Configuration Guide - IP Unicast Routing.
Table 3-3  MCE configuration

Action

Command

Description

Enter the system view.

system-view

-

Create a RIP process running between the MCE device and the site and enter the RIP view.

rip process-id vpn-instance vpn-instance-name

A RIP process can be bound to only one VPN instance. If a RIP process is not bound to any VPN instance before it is started, this process becomes a public network process and can no longer be bound to a VPN instance.

Enable RIP on the network segment of the interface to which the VPN instance is bound.

network network-address

-

(Optional) Import the routes to the remote sites advertised by the PE device in to the RIP routing table.

import-route { { static | direct | unr } | { { rip | ospf } [ process-id ] } } [ cost cost | route-policy route-policy-name ] *

Perform this step if another routing protocol is running between the MCE and PE devices in the VPN instance.

Configure OSPF Between an MCE Device and a Site

Perform the following configurations on the MCE device. Configure OSPF in the site. The site configuration is not provided here. For detailed OSPF configuration, see OSPF Configuration in the S600-E V200R012C00 Configuration Guide - IP Unicast Routing.

Table 3-4  MCE configuration

Action

Command

Description

Enter the system view.

system-view

-

Create an OSPF process running between the MCE device and the site and enter the OSPF view.

ospf [ process-id | router-id router-id ] * vpn-instance vpn-instance-name

-

(Optional) Import the routes to the remote sites advertised by the PE device into the OSPF routing table.

import-route { limit limit-number | { direct | unr | rip [ process-id-rip ] | static | ospf [ process-id-ospf ] } [ cost cost | type type | tag tag | route-policy route-policy-name ] * }

Perform this step if another routing protocol is running between the MCE and PE devices in the VPN instance.

Configure an OSPF area and enter the OSPF area view.

area { area-id | area-id-address }

-

Enable OSPF on the network segment of the interface to which the VPN instance is bound.

network ip-address wildcard-mask

-

Translation
Download
Updated: 2018-09-01

Document ID: EDOC1100037956

Views: 2559

Downloads: 7

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next