04-MSR係列路由器6to4中繼及ISATAP隧道功能配置舉例
本章節下載: 04-MSR係列路由器6to4中繼及ISATAP隧道功能配置舉例 (151.72 KB)
MSR係列路由器6to4中繼及ISATAP隧道功能配置舉例
|
Copyright © 2014杭州華三通信技術有限公司 版權所有,保留一切權利。 非經本公司書麵許可,任何單位和個人不得擅自摘抄、複製本文檔內容的部分或全部, 並不得以任何形式傳播。本文檔中的信息可能變動,恕不另行通知。 |
|
目 錄
本文檔介紹了通過6to4中繼實現6to4網絡和其它IPv6網絡的通信的功能及ISATAP隧道實現IPv4網絡中的IPv6主機和IPv6網絡的通信功能的配置舉例。
本文檔不嚴格與具體軟、硬件版本對應,如果使用過程中與產品實際情況有差異,請參考相關產品手冊,或以設備實際情況為準。
本文檔中的配置均是在實驗室環境下進行的配置和驗證,配置前設備的所有參數均采用出廠時的缺省配置。如果您已經對設備進行了配置,為了保證配置效果,請確認現有配置和以下舉例中的配置不衝突。
本文檔假設您已了解6to4中繼和ISATAP隧道的特性。
如圖1所示,Router B為6to4路由器,其IPv6側的網絡使用6to4地址。Router A作為6to4中繼路由器和ISATAP路由器,它和IPv6網絡相連。Host C側IPv4網絡中分布著一些IPv6主機,要求在Router A和Router B之間配置6to4隧道,使得Host A與Host B互通;Host C通過ISATAP隧道接入到IPv6網絡。
圖1 MSR路由器6to4中繼及ISATAP隧道功能配置組網圖

· 在Router B上配置一條靜態路由,下一跳地址指向Router A的6to4地址,這樣,所有去往IPv6網絡的報文都會被轉發到Router A,之後再由Router A轉發到IPv6網絡中,從而實現6to4網絡與IPv6網絡的互通。
· 通過配置ISATAP隧道將IPv4網絡中的IPv6主機接入IPv6網絡
本舉例是在Release 2317版本上進行配置和驗證的。
· Router A的ISATAP隧道需要取消ND路由器通告的抑製。
· Router B要配置2條靜態路由,一條6to4靜態路由,另一條是訪問其他IPv6站點的,下一跳是Router A的6to4隧道地址。
# 使能IPv6轉發功能。
<RouterB> system-view
[RouterB] ipv6
# 配置接口Ethernet1/2的地址。
[RouterB] interface ethernet 1/2
[RouterB-Ethernet1/2] ip address 2.1.1.1 255.255.255.0
[RouterB-Ethernet1/2] quit
# 配置接口Ethernet1/1的地址。
[RouterB] interface ethernet 1/1
[RouterB-Ethernet1/1] ipv6 address 2002:0201:0101:1::1/64
[RouterB-Ethernet1/1] quit
# 配置6to4隧道。
[RouterB] interface tunnel 0
[RouterB-Tunnel0] ipv6 address 2002:0201:0101::1/64
[RouterB-Tunnel0] source ethernet 1/2
[RouterB-Tunnel0] tunnel-protocol ipv6-ipv4 6to4
[RouterB-Tunnel0] quit
# 配置到6to4中繼的靜態路由。
[RouterB] ipv6 route-static 2002:0601:0101:: 64 tunnel 0
# 配置到純IPv6網絡的缺省路由。
[RouterB] ipv6 route-static :: 0 2002:0601:0101::1
# 使能IPv6轉發功能。
<RouterA> system-view
[RouterA] ipv6
# 配置接口Ethernet1/2的地址。
[RouterA] interface ethernet 1/2
[RouterA-Ethernet1/2] ip address 6.1.1.1 255.255.255.0
[RouterA-Ethernet1/2] quit
# 配置接口Ethernet1/0的地址。
[RouterA] interface ethernet 1/0
[RouterA-Ethernet1/0] ipv6 address 2001::1/64
[RouterA-Ethernet1/0] quit
# 配置接口Ethernet1/1的地址。
[RouterA] interface ethernet 1/1
[RouterA-Ethernet1/1] ip address 1.1.1.1 255.0.0.0
[RouterA-Ethernet1/1] quit
# 配置6to4隧道。
[RouterA] interface tunnel 0
[RouterA-Tunnel0] ipv6 address 2002:0601:0101::1/64
[RouterA-Tunnel0] source ethernet 1/2
[RouterA-Tunnel0] tunnel-protocol ipv6-ipv4 6to4
[RouterA-Tunnel0] quit
# 配置到目的地址2002::/16,下一跳為Tunnel接口的靜態路由。
[RouterA] ipv6 route-static 2002:: 16 tunnel 0
# 配置ISATAP隧道。
[RouterA] interface tunnel 1
[RouterA-Tunnel1] ipv6 address 2001::5efe:0101:0101 64
[RouterA-Tunnel1] source ethernet 1/1
[RouterA-Tunnel1] tunnel-protocol ipv6-ipv4 isatap
# 取消對RA消息發布的抑製,使主機可以通過路由器發布的RA消息獲取地址前綴等信息。
[RouterA-Tunnel1] undo ipv6 nd ra halt
[RouterA-Tunnel1] quit
# 配置到ISATAP主機的靜態路由。
[RouterA] ipv6 route-static 2001:: 16 tunnel 1
# 可以通過如下顯示,查看6to4隧道接口狀態。
<RouterB> display ipv6 interface tunnel 0
Tunnel0 current state :UP
Line protocol current state :UP
IPv6 is enabled, link-local address is FE80::201:101
Global unicast address(es):
2002:201:101::1, subnet is 2002:201:101::/64
Joined group address(es):
FF02::1:FF01:101
FF02::1:FF00:1
FF02::1:FF00:0
FF02::2
FF02::1
MTU is 1480 bytes
ND reachable time is 30000 milliseconds
ND retransmit interval is 1000 milliseconds
Hosts use stateless autoconfig for addresses
IPv6 Packet statistics:
InReceives: 0
InTooShorts: 0
InTruncatedPkts: 0
InHopLimitExceeds: 0
InBadHeaders: 0
InBadOptions: 0
ReasmReqds: 0
ReasmOKs: 0
InFragDrops: 0
InFragTimeouts: 0
OutFragFails: 0
InUnknownProtos: 0
InDelivers: 0
OutRequests: 0
OutForwDatagrams: 0
InNoRoutes: 0
InTooBigErrors: 0
OutFragOKs: 0
OutFragCreates: 0
InMcastPkts: 0
InMcastNotMembers: 0
OutMcastPkts: 0
InAddrErrors: 0
InDiscards: 0
OutDiscards: 0
# Host A可以ping通Host B,說明6to4隧道建立成功。
C:\>ping6 -s 2002:201:101:1::2 2001::2
Pinging 2001::2
from 2002:201:101:1::2 with 32 bytes of data:
Reply from 2001::2: bytes=32 time=13ms
Reply from 2001::2: bytes=32 time=1ms
Reply from 2001::2: bytes=32 time=1ms
Reply from 2001::2: bytes=32 time<1ms
Ping statistics for 2001::2:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 13ms, Average = 3ms
# Host C可以ping通tunnel1接口IPv6地址,表明ISATAP隧道已經成功建立。
C:\>ping 2001::5efe:1.1.1.1
Pinging 2001::5efe:1.1.1.1 with 32 bytes of data:
Reply from 2001::5efe:1.1.1.1: time=1ms
Reply from 2001::5efe:1.1.1.1: time=1ms
Reply from 2001::5efe:1.1.1.1: time=1ms
Reply from 2001::5efe:1.1.1.1: time=1ms
Ping statistics for 2001::5efe:1.1.1.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 1ms, Average = 1ms
· Router B:
#
ipv6
#
interface Ethernet1/2
port link-mode route
ip address 2.1.1.1 255.255.255.0
#
interface Ethernet1/1
port link-mode route
ipv6 address 2002:201:101:1::1/64
#
interface Tunnel0
ipv6 address 2002:201:101::1/64
tunnel-protocol ipv6-ipv4 6to4
source Ethernet1/2
#
ipv6 route-static :: 0 2002:601:101::1
ipv6 route-static 2002:601:101:: 64 Tunnel0
#
· Router A:
#
ipv6
#
interface Ethernet1/1
port link-mode route
ip address 1.1.1.1 255.0.0.0
#
interface Ethernet1/2
ip address 6.1.1.1 255.255.255.0
#
interface Ethernet1/0
[RouterA-Ethernet1/0] ipv6 address 2001::1/64
#
interface Tunnel0
ipv6 address 2002:601:101::1/64
tunnel-protocol ipv6-ipv4 6to4
source Ethernet1/2
#
interface Tunnel1
undo ipv6 nd ra halt
ipv6 address 2001::5EFE:101:101/64
tunnel-protocol ipv6-ipv4 isatap
source Ethernet1/1
#
ipv6 route-static 2001:: 16 Tunnel1
ipv6 route-static 2002:: 16 Tunnel0
· H3C MSR 係列路由器 命令參考(V5)-R2311
· H3C MSR 係列路由器 配置指導(V5)-R2311
不同款型規格的資料略有差異, 詳細信息請向具體銷售和400谘詢。H3C保留在沒有任何通知或提示的情況下對資料內容進行修改的權利!
