No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

NE40E V800R010C10SPC500 Configuration Guide - User Access 01

This is NE40E V800R010C10SPC500 Configuration Guide - User Access
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Example for Assigning IPv6 Prefixes to Users from the User-side Delegation Address Pool

Example for Assigning IPv6 Prefixes to Users from the User-side Delegation Address Pool

This section provides an example for assigning IPv6 prefixes to users from a user-side delegation address pool, including the networking requirements, configuration roadmap, configuration procedure, and configuration files.

Networking Requirements

The CPE obtains IPv6 address or prefixes in NDRA+DHCPv6(IA_PD) mode from the NE40E, and the LAN users attached to the CPE use the prefixes and the interface IDs to generate IPv6 addresses.

As shown in Figure 5-11:

  • The NE40E functions as a delegating router assigning IPv6 prefixes to a requesting router.

  • The requesting router is located in domain isp1. It connects to the delegating router through GE 1/0/1, and adopts the PPP authentication method.

  • RADIUS authentication and RADIUS accounting are used.

  • The IP address of the RADIUS server is 10.6.55.55, the respective numbers of authentication and accounting ports are 1550 and 1551, and the standard RADIUS protocol is adopted with the key being it-is-my-secret1.

  • The IP address of the DNS server is 3002:3101::2:2.

Figure 5-11 Networking diagram of assigning IPv6 prefixes to users from the local delegation address pool on the user side
NOTE:

Interfaces 1 through 2 in this example are 1/0/1, 1/0/2, respectively.



Configuration Roadmap

The configuration roadmap is as follows:

  1. Configure a VT.
  2. Configure the AAA scheme.
  3. Configure a RADIUS server group.
  4. Configure a prefix pool, an address pool (with the IP address of the DNS server specified), and the binding between the two.
  5. Configure a domain named isp1.
  6. Configure a DUID for the DHCPv6 server.
  7. Configure interfaces.

Data Preparation

To complete the configuration, you need the following data:

  • Name of the authentication template and authentication method
  • Name of the accounting template and accounting mode
  • Name of the RADIUS server group and IP addresses and port numbers of the RADIUS authentication server and accounting server
  • Names of the local IPv6 prefix pool and IPv6 delegation pool, address prefix, and assignable prefix length
  • Names of the user-side local IPv6 address pool and user-side delegation address pool
  • Domain name
  • Parameters of the BAS interface

Procedure

  1. Only the configuration procedure for the NE40E is provided.

    # Configure the virtual template.

    [*Device] interface Virtual-Template 1
    [*Device-Virtual-Template1] ppp authentication-mode pap
    [*Device-Virtual-Template1] commit
    [~Device-Virtual-Template1] quit

  2. Configure AAA schemes.

    # Configure an authentication scheme.

    [*Device] aaa
    [*Device-aaa] authentication-scheme auth1
    [*Device-aaa-authen-auth1] authentication-mode radius
    [*Device-aaa-authen-auth1] commit
    [~Device-aaa-authen-auth1] quit

    # Configure an accounting scheme.

    [*Device-aaa] accounting-scheme acct1
    [*Device-aaa-accounting-acct1] accounting-mode radius
    [*Device-aaa-accounting-acct1] commit
    [~Device-aaa-accounting-acct1] quit
    [~Device-aaa] quit

  3. Configure a RADIUS server group.

    [*Device] radius-server group rd1
    [*Device-radius-rd1] radius-server authentication 10.6.55.55 1550
    [*Device-radius-rd1] radius-server accounting 10.6.55.55 1551
    [*Device-radius-rd1] radius-server type standard
    [*Device-radius-rd1] radius-server shared-key-cipher it-is-my-secret1
    [*Device-radius-rd1] commit
    [~Device-radius-rd1] quit

  4. Configure a local prefix pool.

    [*Device] ipv6 prefix pre1 local
    [*Device-ipv6-prefix-pre1] prefix 2010:2021::/64
    [*Device-ipv6-prefix-pre1] commit
    [~Device-ipv6-prefix-pre1] quit

  5. Configure a user-side local address pool.

    [*Device] ipv6 pool pool1 bas local
    [*Device-ipv6-pool-pool1] prefix pre1
    [*Device-ipv6-pool-pool1] dns-server 3002:3101::2:2
    [*Device-ipv6-pool-pool1] commit
    [~Device-ipv6-pool-pool1] quit

  6. Configure a delegation prefix pool.

    [*Device] ipv6 prefix pre2 delegation
    [*Device-ipv6-prefix-pre2] prefix 2011:2022::/62 delegating-prefix-length 63
    [*Device-ipv6-prefix-pre2] commit
    [~Device-ipv6-prefix-pre2] quit

  7. Configure a user-side delegation address pool.

    [*Device] ipv6 pool pool2 bas delegation
    [*Device-ipv6-pool-pool2] prefix pre2
    [*Device-ipv6-pool-pool2] dns-server 3002:3101::2:2
    [*Device-ipv6-pool-pool2] commit
    [~Device-ipv6-pool-pool2] quit

  8. Configure a domain named isp1.

    [*Device] aaa
    [*Device-aaa] domain isp1
    [*Device-aaa-domain-isp1] authentication-scheme auth1
    [*Device-aaa-domain-isp1] accounting-scheme acct1
    [*Device-aaa-domain-isp1] radius-server group rd1
    [*Device-aaa-domain-isp1] ipv6-pool pool1
    [*Device-aaa-domain-isp1] ipv6-pool pool2
    [*Device-aaa-domain-isp1] commit
    [~Device-aaa-domain-isp1] quit
    [~Device-aaa] quit

  9. Configure a DUID for the DHCPv6 server.

    [*Device] dhcpv6 duid llt
      Warning:The change of DUID will cause the accessed user work abnormally,
    are you sure to change ? [Y/N]: y

  10. Configure interfaces.

    # Bind GE 1/0/1.1 to a virtual template.

    [*Device] interface GigabitEthernet 1/0/1.1
    [*Device-GigabitEthernet1/0/1.1] pppoe-server bind virtual-template 1

    # Configure a BAS interface.

    [*Device-GigabitEthernet1/0/1.1] user-vlan 1
    [*Device-GigabitEthernet1/0/1.1] bas
    [*Device-GigabitEthernet1/0/1.1-bas] access-type layer2-subscriber default-domain authentication isp1
    [*Device-GigabitEthernet1/0/1.1-bas] commit
    [~Device-GigabitEthernet1/0/1.1-bas] quit

    # Enable IPv6 on GE 1/0/1.1.

    [*Device-GigabitEthernet1/0/1.1] ipv6 enable
    [*Device-GigabitEthernet1/0/1.1] ipv6 address auto link-local
    [*Device-GigabitEthernet1/0/1.1] commit
    [~Device-GigabitEthernet1/0/1.1] quit

    # Configure an upstream interface.

    [*Device] interface GigabitEthernet 1/0/2
    [*Device-GigabitEthernet1/0/2] ipv6 enable
    [*Device-GigabitEthernet1/0/2] ipv6 address auto link-local
    [*Device-GigabitEthernet1/0/2] ipv6 address 2011::1/64 eui-64
    [*Device-GigabitEthernet1/0/2] commit
    [~Device-GigabitEthernet1/0/2] quit

  11. Verify the configuration.

    # Check information about the prefix pool named pre1. You can see that the prefix pool is a local prefix pool and the prefix address is 2010:2021::/64.

    <HUAWEI> display ipv6 prefix pre1
     -------------------------------------------------------------
     Prefix Name        : pre1
     Prefix Index       : 4
     Prefix constant index: -
     Prefix Type        : LOCAL
     Prefix Address     : 2010:2021::
     Prefix Length      : 64
     Reserved Type      : NONE  
     Valid Lifetime     : 3 Days 0 Hours 0 Minutes
     Preferred Lifetime: 2 Days 0 Hours 0 Minutes
     IfLocked            : Unlocked
     Vpn instance       : -       
     Conflict address   : -
     Free Prefix Count  : 262144
     Used Prefix Count  : 0
     Reserved Prefix Count: 0   
     -------------------------------------------------------------
    

    # Check information about the prefix pool named pre2. You can see that the prefix pool is a delegation prefix pool with the prefix address being 2011:2022::/62.

    <HUAWEI> display ipv6 prefix pre2
     -------------------------------------------------------------
     Prefix Name        : pre2
     Prefix Index       : 5
     Prefix constant index: -
     Prefix Type        : DELEGATION
     Prefix Address     : 2011:2022::
     Prefix Length      : 62
     Valid Lifetime     : 3 Days 0 Hours 0 Minutes
     Preferred Lifetime : 2 Days 0 Hours 0 Minutes
     IfLocked           : Unlocked
     Vpn instance       : -      
     PD Prefix Len      : 64
     PD Prefix/C-DUID   : -
     slaac-unshare-only : FALSE
     Conflict address   : -
     Free Prefix Count  : 4
     Used Prefix Count  : 0
     Binded Prefix Count (Free): 0
     Binded Prefix Count (Used): 0
     Reserved Prefix Count: 0     
     -------------------------------------------------------------
    

    # Check information about the address pool named pool1. You can see that the address pool is a local address pool at the user side and the address pool is bound to the prefix pool named pre1.

    <HUAWEI> display ipv6 pool pool1
     ----------------------------------------------------------------------
     Pool name          : pool1
     Pool No            : 4 
      Pool-constant-index :- 
     Pool type          : BAS LOCAL
     Preference         : 0
     Renew time         : 50
     Rebind time        : 80
     Status              : UNLOCKED
     Refresh interval   : 0 Days 0 Hours 0 Minutes
     Used by domain     : 1
     Dhcpv6 Unicast     : disable
     Dhcpv6 rapid-commit: disable
     Dns list             : -
     Dns server master  : 3002:3101::2:2
     Dns server slave   : -
     AFTR name          : - 
     ----------------------------------------------------------------------
     Prefix-Name                      Prefix-Type
     ----------------------------------------------------------------------
     pre1                               LOCAL
    ----------------------------------------------------------------------
    

    # Check information about the address pool named pool2. You can see that the address pool is a user-side delegation address pool and the address pool is bound to the local prefix pool named pre2.

    <HUAWEI> display ipv6 pool pool2
    ----------------------------------------------------------------------
     Pool name          : pool2
     Pool No            : 5 
      Pool-constant-index :- 
     Pool type          : BAS DELEGATION
     Preference         : 255
     Renew time         : 50
     Rebind time        : 80
     Status              : UNLOCKED
     Refresh interval   : 0 Days 0 Hours 0 Minutes
     Used by domain     : 0
     Dhcpv6 Unicast     : disable
     Dhcpv6 rapid-commit: disable
     Dns list            : -
     Dns server master  : -
     Dns server slave   : -
     AFTR name          : - 
     ----------------------------------------------------------------------
     Prefix-Name                      Prefix-Type
     ----------------------------------------------------------------------
     pre2                               DELEGATION
    ----------------------------------------------------------------------
    

    # Check configurations of the domain isp1. You can see that the domain is bound to IPv6 address pools pool1 and pool2.

    <HUAWEI> display domain isp1
    ------------------------------------------------------------------------------
      Domain-name                     : isp1
      Domain-state                    : Active
      Authentication-scheme-name      : auth1
      Accounting-scheme-name          : acct1
      Authorization-scheme-name       :
      Primary-DNS-IP-address          : -
      Second-DNS-IP-address           : -
      Web-server-URL-parameter        : No
      Portal-server-URL-parameter     : No
      Primary-NBNS-IP-address         : -
      Second-NBNS-IP-address          : -
      User-group-name                 : -
      Idle-data-attribute (time,flow) : 0, 60
      Install-BOD-Count               : 0
      Report-VSM-User-Count           : 0
      Value-added-service             : COPS
      User-access-limit               : 279552
      Online-number                   : 0
      Web-IP-address                  : -
      Web-URL                         : -
      Slave Web-IP-address            : -
      Slave Web-URL                   : -
      Slave Web-auth-server           : - 
      Slave Web-auth-state            : - 
      Portal-server-IP                : -
      Portal-URL                      : -
      Portal-force-times              : 2
      PPPoE-user-URL                  : Disable
      IPUser-ReAuth-Time(second)      : 300
      mscg-name-portal-key            : -
      Portal-user-first-url-key       : -
      Ancp auto qos adapt             : Disable
      RADIUS-server-template          : rd1
      Two-acct-template               : -
      HWTACACS-server-template        : -
      Bill Flow                       : Disable
      Tunnel-acct-2867                : Disabled
    
      Flow Statistic:
      Flow-Statistic-Up               : Yes
      Flow-Statistic-Down             : Yes
      Source-IP-route                 : Disable
      IP-warning-threshold            : -
      IPv6-warning-threshold          : - 
      Multicast Forwarding            : Yes
      Multicast Virtual               : No
      Multicast-profile ipv6          : -
      Max-multilist num               : 4
      Multicast-profile               : -
      IPv6-Pool-name                  : pool1
      IPv6-Pool-name                  : pool2
      Quota-out                     : Offline
      Service-type                    : -
      User-basic-service-ip-type      : -/-/-
      PPP-ipv6-address-protocol       : Ndra
      IPv6-information-protocol       : Stateless dhcpv6
      IPv6-PPP-assign-interfaceid     : Disable
      Trigger-packet-wait-delay       : 60s
      Peer-backup                     : enable    
      ------------------------------------------------------------------------------
    

Configuration Files

  • router Configuration Files

    #
     sysname HUAWEI
    #
    ipv6
    #
    dhcpv6 duid 006735f300188253a56a
    #
    radius-server group rd1
     radius-server authentication 10.6.55.55 1550 weight 0
    radius-server accounting 10.6.55.55 1551 weight 0
    radius-server shared-key-cipher %^%#vS%796FO7%C~pB%CR=q;j}gSCqR-X6+P!.DYI@)%^%
    #
    interface Virtual-Template1
     ppp authentication-mode pap
    #
    ipv6 prefix pre1 local
     prefix 2010:2021::/64
    #
    ipv6 prefix pre2 delegation
     prefix 2011:2022::/62
     delegating-prefix-length 63
    #
    ipv6 pool pool1 bas local
    prefix pre1
    #
    ipv6 pool pool2 bas delegation
     prefix pre2
    dns-server 3002:3101::2:2
    #
    aaa
    authentication-scheme default0
     authentication-scheme default1
    authentication-scheme auth1
    authentication-mode radius
    #
    accounting-scheme default0
     accounting-scheme default1
    accounting-scheme acct1
    accounting-mode radius
    #
    domain  isp1
     authentication-scheme auth1
     accounting-scheme acct1
     radius-server group rd1
     ipv6-pool pool1
     ipv6-pool pool2
    #
    interface GigabitEthernet1/0/1.1
     pppoe-server bind Virtual-Template 1
     ipv6 enable
     ipv6 address auto link-local
     bas
      access-type layer2-subscriber default-domain authentication isp1
    #
    interface GigabitEthernet1/0/2
     ipv6 enable
     ipv6 address 2011::1/64 eui-64
     ipv6 address auto link-local
    #
    return
    
Translation
Download
Updated: 2019-01-03

Document ID: EDOC1100055031

Views: 17754

Downloads: 72

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next