Académique Documents
Professionnel Documents
Culture Documents
Notice
The information in this document is subject to change without notice. Every effort has
been made in the preparation of this document to ensure accuracy of the contents, but all
statements, information, and recommendations in this document do not constitute the
warranty of any kind, express or implied.
1) Career Certification
This is a three-tier certification levels which aim to provide IP skills development and
assessment for typical job positions in the telecom industry.
A. Huawei Certified Datacom Associate (HCDA) is a basic level certification. It is for
IP network maintenance engineers and other interested professionals who are
working with the carrier IP networks. After certification, the certified practitioners are
able to follow the norms of the industry, possess skills to apply routing and switching
technology, and network security basics into IP network access layer equipment
maintenance.
There are two different tracks of Huawei Certified Datacom Professional and Huawei Certified
Datacom Expert.
B.
i.
i.
C)
ii.
2) Specialist Certification is targeted for those who desire to acquire specific technical
skills, such as installation, configuration and troubleshooting on Huawei datacom
products.
3) Compatibility Certification is a fast-track certification. It accommodates the
certifications issued by other networking vendors and allows those certification holders to
attain the Huawei datacom certification within the shortest feasible period.
Table of Contents
Lab Environment Description
Section 1: VRP Basic Laboratory Guide
Section 2: Routing Technology Laboratory Guide
Section 3: Switching Technology Laboratory Guide
Section 4: WAN Protocol Laboratory Guide
Section 5:Firewall Eudemon Laboratory Guide
There are four routers, five switches, one firewall and several PCs. One set
of lab environment can support four trainees hand on exercise at the same
time.
IP address Planning
The suggested IP address of the device to plan as follow:
RT1
RT1
RT2
RT3
RT4
RT2
RT3
RT4
Loopback
12.1.1.0/30 13.1.1.0/30 14.1.1.0/30 1.1.1.1/32
12.1.1.0/30
23.1.1.0/30 24.1.1.0/30 2.2.2.2/32
13.1.1.0/30 23.1.1.0/30
34.1.1.0/30 3.3.3.3/32
14.1.1.0/30 24.1.1.0/30 34.1.1.0/30
4.4.4.4/32
The device with smaller number in the name uses the smaller IP address of
the segment. For example, for the connection between RT1 and RT2, RT1
uses 12.1.1.1/30 and RT2 uses 12.1.1.2/30.
Devices Introduction
To meet the requirement of HCDA-HNTD,.We suggest every set of
environment to adopt the configuration as follow:
Devices
Name
Choice
Devices
Types
Software
Version
S3500
series
switch or
over above.
VRP3
Ethernet
24
AR18 or
AR28
RT1
series
RT4
router or
over above
VRP3\
VRP5
Ethernet\
Serial
2\2
Eudemon
100/
200/500/
1000
VRP3
Ethernet
SW1
SW5
FW1
Devices Name
SW1SW5
RT1RT5
FW1
Content
VRP basic operationethernet basic
configuration, port aggregation, VLAN, VLAN
routing, route on stick, STP.
VRP basic operation, PPP, HDLCFRstatic
routeRIPOSPFVRRP
firewall configurationNATACL
Section 1
VRP Basic Laboratory Guide
Table of Contents
Table of Contents
Lab Description .................................................................................................................1
Introduction................................................................................................................1
Version ......................................................................................................................1
Objectives..................................................................................................................1
Tasks .........................................................................................................................1
References ................................................................................................................1
Chapter1 Configure the router by Console port.................................................................2
1.1 Networking and service description.....................................................................2
1.2 Configuration and Verification..............................................................................2
Chapter2 Configure the router via telnet ...........................................................................4
2.1 Networking and Service description ....................................................................4
2.2 Configuration and Verification..............................................................................4
Chapter3 Ping....................................................................................................................6
3.1 Networking and Service description ....................................................................6
3.2 Configuration and Verification..............................................................................6
3.3 FAQ .....................................................................................................................9
Chapter4 FTP/TFTP ..........................................................................................................10
4.1 Networking and Service Description....................................................................10
4.2 Configuration and Verification..............................................................................10
Lab Description
Lab Description
Introduction
The Versatile Routing Platform (VRP) is a versatile operating system
platform, developed for all data communication products of Huawei.
With the IP service as its core, the VRP adopts the componentized
architecture. The VRP realizes rich functions and provides tailorability
and scalability based on applications.
This
Laboratory
Guide
covers
some
important
and
basic
Version
This Guide is applicable to VRP 5.10
Objectives
z
Tasks
References
VRP Configuration Guide 5.10
Chapter1
Run the terminal emulation program on the PC. Set the terminal
communication parameters to be 9600 bps, data bit to be 8, stop
bit to be 1. Specify no parity and no flow control as shown in the
following figure.
(2)
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter2
<Quidway>system-view
[Quidway]interface Ethernet 0/0
[Quidway-Ethernet0/0]ip address 10.1.1.4 255.0.0.0
Also need to configure IP address of the PC after you have finished
the IP configuration of the router.
There are three login methods via telnet and two of them will be shown
as follow:
z
[Quidway]user-interface vty 0 4
[Quidway-ui-vty0-4]authentication-mode scheme
[Quidway]local-user test\\Create one local user: test
[Quidway-luser-test]password cipher test
[Quidway-luser-test]service-type telnet
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
[Quidway-luser-test]level 3
The router will ask for username and password when you telnet to
router.
level to 0
Using the super command, you can change the user's current level.
User level indicates the type of the login user. There are four user
levels. Different from the use of command level, a login user can only
use the commands with the levels no higher than the user level.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter3Ping
Chapter3 Ping
3.1 Networking and Service description
On VRP
ping [ -c
number ] [ -t
address ]
ip-address
number ] [ -s
number ] [ -a
source ip
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter3Ping
[Quidway-luser-test]level 3
The router will ask for username and password when you telnet to
router.
level to 0
Using the super command, you can change the user's current level.
User level indicates the type of the login user. There are four user
levels. Different from the use of command level, a login user can only
use the commands with the levels no higher than the user level.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter3Ping
3.2.3 Verification
(1)
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter3Ping
8 packet(s) received
0.00% packet loss
round-trip min/avg/max = 32/32/32 ms
(3)
3.3 FAQ
QAs shown in the figure 3-1, what is the result if we use Tracert
command?
AUsing the tracert command, you can test the gateways that
datagram pass along from sending host to the destination. This
command is mainly used to check whether the network connection
is reachable and locate failures that have occurred in the network.
[RT4]tracert 10.1.1.2
traceroute to
1 10.1.1.2 31 ms
31 ms
32 ms
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter4FTP/TFTP
Chapter4 FTP/TFTP
4.1 Networking and Service Description
FTP and TFTP are file transfer protocols which are used to
transfer files between the host and the equipment. VRP platform
supports software update and configuration file backup via
FTP/TFTP.
ftp-directory
flash:/ftp/quidway
In this case, you just need to configure interface IP address for the
router.
10
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter4FTP/TFTP
(3)
In this case, you just need to configure interface IP address for the
router.
FTP/TFTP transfers the files in two formats:
z
4.2.2 Verification
(1)
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
11
Chapter4FTP/TFTP
FTP:
5805100
byte(s)
received
in
19.898
second(s)
291.74Kbyte(s)/sec.
Access to FTP Server via FTP Client and transmit file.
(3)
<Quidway>
5805100
byte(s)
received
in
19.898
second(s)
291.74Kbyte(s)/sec
12
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Section 2
Routing Tech. Laboratory Guide
Table of Contents
Table of Contents
Table of Contents .............................................................................................................1
Lab Description..................................................................................................................3
Introduction................................................................................................................3
Version ......................................................................................................................3
Objectives ..................................................................................................................3
Tasks .........................................................................................................................3
References ................................................................................................................3
Chapter 1 Static Route Lab Guide .................................................................................... ..4
1.1 Networking and Service Description .....................................................................4
1.2 Configuration Flow ................................................................................................4
1.3 Configuration Steps ..............................................................................................4
1.4 Configuration and Verification...............................................................................5
Chapter 2 Default Route Configuration...............................................................................8
2.1 Networking and Service Description .....................................................................8
2.2 Configuration Flow ................................................................................................ 8
2.3 Configuration Steps ..............................................................................................8
2.4 Configuration and Verification...............................................................................9
Chapter 3 Route Backup of static route ............................................................................1 1
3.1 Networking and Service Description ...................................................................1 1
3.2 Configuration Flows ............................................................................................1 1
3.3 Configuration Steps ............................................................................................1 1
3.4 Configuration and Verification.............................................................................1 2
3.5 Additional Tasks.................................................................................................. 1 4
Chapter 4 Basic Configuration of RIPv2 ...........................................................................1 6
4.1 Networking and Service Descriptions .................................................................1 6
4.2 Configuration Flows ............................................................................................1 6
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Lab Description
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Lab Description
Lab Description
Introduction
This Lab Guide introduces the configuration and operation of routing
protocol for HCDA-HNTD, including static routing, RIP and OSPF. The
trainees can get familiarity with the configuration of Huawei products
through these exercises, so as to grasp the routing protocol part of HNTD
and pass the HCDA exam.
Version
This Guide is applicable to VRP versions 3.4.
Objectives
z
Tasks
References
VRP 3.4 Operation Manual
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Configure Interfaces
(2)
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2. Configure RT2
[RT2] interface Ethernet 0
[RT2-Ethernet0] ip address 12.1.1.2 255.255.255.252
[RT2] interface LoopBack 1
[RT2-LoopBack1] ip address 2.2.2.2 255.255.255.255
2. Configure RT2
[RT2] ip route-static 1.1.1.1 255.255.255.255 12.1.1.1
Routes : 6
Proto Pre Cost
NextHop
Interface
1.1.1.1/32 Direct 0
127.0.0.1
12.1.1.2
InLoopBack0
2.2.2.2/32 Static 60
Ethernet0
12.1.1.0/30 Direct 0
12.1.1.1
Ethernet0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
[RT2] display ip routing-table
Routing Tables: Public
Destinations : 6
Destination/Mask
Routes : 6
NextHop
Interface
1.1.1.1/32 Static 60
12.1.1.1
127.0.0.1
Ethernet0
2.2.2.2/32 Direct 0
InLoopBack0
12.1.1.0/30 Direct 0
12.1.1.2
127.0.0.1
Ethernet0
12.1.1.2/32 Direct 0
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
127.0.0.1/32 Direct 0
127.0.0.1
InLoopBack0
InLoopBack0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Configure IP address
Configure Interface
(2)
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
In RT1, configure a static route with the destination address as the loopback
address of RT2; In RT2, configure a static route with the destination address
as the loopback address of RT1.
2. Configure RT2:
[RT2] interface Ethernet 0
[RT2-Ethernet0] ip address 12.1.1.2 255.255.255.252
[RT2] interface LoopBack 1
[RT2-LoopBack1] ip address 2.2.2.2 255.255.255.255
2. Configure RT2
[RT2] ip route-static 1.1.1.1 255.255.255.255 12.1.1.1
Routes : 6
Proto
Pre
Cost
NextHop
Interface
1.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
0.0.0.0/0
Static 60
12.1.1.2
Ethernet0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Routes : 6
Proto
1.1.1.1/32
Pre
NextHop
12.1.1.1
Ethernet0
127.0.0.1
InLoopBack0
Static 60
Cost
2.2.2.2/32
Direct 0
Interface
12.1.1.0/30
Direct 0
12.1.1.2
Ethernet0
12.1.1.2/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
10
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
E0
.1
12.1.1.0/30
E0
.2
.5
12.1.1.0/30
.6
RT2
L1:
2.2.2.2/32
S0
S0
figture 3-1 Networking topology for route backup of static route configuration
z
Router RT1 and Rt2 are connected through Ethernet interface and
serial port interface. L1 is the loopback interface in the router.
Configure Interface
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
11
configure the
primary static route and the backup static route with destination address as
the loopback address of RT1.
2. Configure RT2:
[RT2]interface Ethernet 0
[RT2-Ethernet0]ip address 12.1.1.2 255.255.255.252
[RT2] interface Serial 0
[RT2-Serial0] ip address 12.1.1.6 255.255.255.252
[RT2]interface LoopBack 1
[RT2-LoopBack1]ip address 2.2.2.2 255.255.255.255
12
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Routes : 6
Proto
Pre
Cost
NextHop
Interface
1.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
2.2.2.2/32
Static 60
12.1.1.2
Ethernet0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
[RT2]display ip routing-table
Routing Tables: Public
Destinations : 6
Destination/Mask
Routes : 6
Proto
Pre
1.1.1.1/32
Static 60
2.2.2.2/32
Direct 0
Cost
NextHop
12.1.1.1
Ethernet0
Interface
127.0.0.1
InLoopBack0
12.1.1.0/30
Direct 0
12.1.1.2
Ethernet0
12.1.1.2/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
3.4.3 Use TRACERT command to check the connectivity and the route
used
[RT1] tracert -a 1.1.1.1
traceroute to
2.2.2.2
1 12.1.1.2 40 ms
30 ms
70 ms
1 12.1.1.1 50 ms
60 ms
60 ms
3.4.4 Shutdown the primary interface, then check IP routing table again
[RT1]interface Ethernet 0
[RT1-Ethernet0]shutdown
[RT1]display ip routing-table
Routing Tables: Public
Destinations : 6
Destination/Mask
Proto
Routes : 6
Pre
Cost
NextHop
Interface
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
13
Direct 0
127.0.0.1
InLoopBack0
2.2.2.2/32
Static 100
12.1.1.6
Serial0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
[RT2]display ip routing-table
Routing Tables: Public
Destinations : 6
Destination/Mask
Proto
Routes : 6
NextHop
Interface
1.1.1.1/32
Static 100
Pre
0
Cost
12.1.1.5
Serial0
2.2.2.2/32
Direct 0
127.0.0.1
InLoopBack0
12.1.1.0/30
Direct 0
12.1.1.2
Ethernet0
12.1.1.2/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
The current active route is the backup route according to pre and next
hop field.
3.4.5 Use command tracert to check the connectivity and the used route
[RT1]tracert -a 1.1.1.1 2.2.2.2
traceroute to 2.2.2.2(2.2.2.2) 30 hops max,40 bytes packet
1 12.1.1.6 50 ms 60 ms 70 ms
[RT2]tracert -a 2.2.2.2 1.1.1.1
traceroute to 1.1.1.1(1.1.1.1) 30 hops max,40 bytes packet
1 12.1.1.5 40 ms 30 ms 30 ms
14
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Loading sharing of the two static routes will be taken effect if two preference
value are the same.
[RT1] ip route-static 2.2.2.2 255.255.255.255 12.1.1.6 preference 60
[RT2] ip route-static 1.1.1.1 255.255.255.255 12.1.1.5 preference 60
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
15
Run RIPv2
Configure RIPv2
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
(3)
(4)
2. Configure RT2:
[RT2]interface Ethernet 0/0/0
[RT2-Ethernet0/0/0]ip address 12.1.1.2 255.255.255.252
[RT2] interface Serial 0/0/1
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
17
3. Configure RT3:
[RT3] interface Serial 0/0/1
[RT3-Serial0/0/1] ip address 13.1.1.2 255.255.255.252
[RT3] interface LoopBack 1
[RT3-LoopBack1] ip address 3.3.3.3 255.255.255.255
4. Configure RT4:
[RT4] interface Serial 0/0/1
[RT4-Serial0/0/1] ip address 24.1.1.2 255.255.255.252
[RT4] interface LoopBack 1
[RT4-LoopBack1] ip address 4.4.4.4 255.255.255.255
4.4.2 Enable RIP and Enable RIP for the Specified Prefix
1. Configure RT1
[RT1] rip
[RT1-rip] network 1.0.0.0
[RT1-rip] network 12.0.0.0
[RT1-rip] network 13.0.0.0
2. Configure RT2
[RT2] rip
[RT2-rip] network 2.0.0.0
[RT2-rip] network 12.0.0.0
[RT2-rip] network 24.0.0.0
3. Configure RT3
[RT3] rip
[RT3-rip] network 3.0.0.0
[RT3-rip] network 13.0.0.0
4. Configure RT4
[RT4] rip
[RT4-rip] network 4.0.0.0
[RT4-rip] network 24.0.0.0
18
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2. Configure RT2
[RT2]interface Ethernet 0/0/0
[RT2-Ethernet0/0/0]rip version 2
[RT2]interface Serial 0/0/1
[RT2-Serial0/0/1]rip version 2
[RT1]interface loopback 1
[RT1-loopback1]rip version 2
3. Configure RT3
[RT3]interface serial 0/0/1
[RT3-Serial0/0/1]rip version 2
[RT3]interface loopback 1
[RT3-loopback1]rip version 2
4. Configure RT4
[RT4]interface serial 0/0/1
[RT4-Serial0/0/1]rip version 2
[RT4]interface loopback 1
[RT4-loopback1]rip version 2
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
19
Routes : 12
Proto
Pre
Cost
0
NextHop
Interface
127.0.0.1
InLoopBack0
1.1.1.1/32
Direct 0
2.2.2.2/32
RIP
100
12.1.1.2
Ethernet0/0/0
3.3.3.3/32
RIP
100
13.1.1.2
Serial0/0/1
4.4.4.4/32
RIP
100
12.1.1.2
Ethernet0/0/0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0/0/0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.0/30
Direct 0
13.1.1.1
Serial0/0/1
13.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.2/32
Direct 0
13.1.1.2
Serial0/0/1
24.1.1.0/30
RIP
100
12.1.1.2
Ethernet0/0/0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
[RT2]display ip routing-table
Routing Tables: Public
Destinations : 12
Destination/Mask
Routes : 12
Proto
Pre
100
Cost
1
NextHop
12.1.1.1
Interface
1.1.1.1/32
RIP
2.2.2.2/32
Direct 0
3.3.3.3/32
RIP
100
12.1.1.1
Ethernet0/0/0
4.4.4.4/32
RIP
100
24.1.1.2
Serial0/0/1
127.0.0.1
Ethernet0/0/0
InLoopBack0
12.1.1.0/30
Direct 0
12.1.1.2
Ethernet0/0/0
12.1.1.2/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.0/30
RIP
24.1.1.0/30
Direct 0
24.1.1.1
Serial0/0/1
24.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
24.1.1.2/32
Direct 0
24.1.1.2
Serial0/0/1
100
12.1.1.1
Ethernet0/0/0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
[RT4]display ip routing-table
Routing Tables: Public
Destinations : 11
Destination/Mask
20
Proto
Routes : 11
Pre
Cost
NextHop
Interface
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
RIP
100
24.1.1.1
Serial0/0/1
2.2.2.2/32
RIP
100
24.1.1.1
Serial0/0/1
3.3.3.3/32
RIP
100
24.1.1.1
Serial0/0/1
4.4.4.4/32
Direct 0
127.0.0.1
InLoopBack0
12.1.1.0/30
RIP
100
24.1.1.1
Serial0/0/1
13.1.1.0/30
RIP
100
24.1.1.1
Serial0/0/1
24.1.1.0/30
Direct 0
24.1.1.2
Serial0/0/1
24.1.1.1/32
Direct 0
24.1.1.1
Serial0/0/1
24.1.1.2/32
Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
[RT3]display ip routing-table
Routing Tables: Public
Destinations : 11
Destination/Mask
Routes : 11
Proto
Pre
Cost
NextHop
Interface
1.1.1.1/32
RIP
100
13.1.1.1
Serial0/0/1
2.2.2.2/32
RIP
100
13.1.1.1
Serial0/0/1
3.3.3.3/32
Direct 0
127.0.0.1
InLoopBack0
4.4.4.4/32
RIP
13.1.1.1
Serial0/0/1
100
12.1.1.0/30
RIP
100
13.1.1.0/30
Direct 0
13.1.1.2
Serial0/0/1
13.1.1.1/32
Direct 0
13.1.1.1
Serial0/0/1
13.1.1.2/32
Direct 0
127.0.0.1
InLoopBack0
24.1.1.0/30
RIP
13.1.1.1
Serial0/0/1
100
13.1.1.1
Serial0/0/1
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
21
4.5
FAQ
QIf you use RIPv1 to finish the exercise above, what are the difference
between the final IP routing table with RIPv2? Why?
AUsing RIPv1 to finish the exercise above, get the routing table as follow:
[RT1]display ip routing-table
Routing Tables: Public
Destinations : 12
Destination/Mask
22
Routes : 12
Proto
Pre
Cost
0
NextHop
Interface
127.0.0.1
InLoopBack0
1.1.1.1/32
Direct 0
2.0.0.0/8
RIP
100
12.1.1.2
Ethernet0/0/0
3.0.0.0/8
RIP
100
13.1.1.2
Serial0/0/1
4.0.0.0/8
RIP
100
12.1.1.2
Ethernet0/0/0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0/0/0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.0/30
Direct 0
13.1.1.1
13.1.1.1/32
Direct 0
127.0.0.1
13.1.1.2/32
Direct 0
13.1.1.2
Serial0/0/1
InLoopBack0
Serial0/0/1
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
RIP
100
12.1.1.2
Ethernet0/0/0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
Because RIPv1 is one of the classful routing protocol, it will auto summary
the route into class, the route learned through RIPv1 are classful.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
23
24
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Enable RIP
Configure RIPv2
(2)
Enable RIP
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
25
(3)
(4)
(5)
(6)
2. Configure RT2:
[RT2]interface Ethernet 0/0/0
[RT2-Ethernet0/0/0]ip address 12.1.1.2 255.255.255.252
[RT2] interface Serial 0/0/1
[RT2-Serial0/0/1] ip address 24.1.1.1 255.255.255.252
[RT2]interface LoopBack 1
[RT2-LoopBack1]ip address 2.2.2.2 255.255.255.255
3. Configure RT3:
[RT3] interface Serial 0/0/1
[RT3-Serial0/0/1] ip address 13.1.1.2 255.255.255.252
[RT3] interface LoopBack 1
[RT3-LoopBack1] ip address 3.3.3.3 255.255.255.255
[RT3] interface Loopback2
[RT3-LoopBack2] ip address 3.3.3.1 255.255.255.255
[RT3] interface Loopback3
[RT3-LoopBack3] ip address 3.3.3.2 255.255.255.255
26
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
4. Configure RT4:
[RT4] interface Serial 0/0/1
[RT4-Serial0/0/1] ip address 24.1.1.2 255.255.255.252
[RT4] interface LoopBack 1
[RT4-LoopBack1] ip address 4.4.4.4 255.255.255.255
2. Configure RT2
[RT2] rip
[RT2-rip-1] network 2.0.0.0
[RT2-rip-1] network 12.0.0.0
[RT2-rip-1] network 24.0.0.0
3. Configure RT3
[RT3] rip
[RT3-rip-1] network 3.0.0.0
[RT3-rip-1] network 13.0.0.0
4. Configure RT4
[RT4] rip
[RT4-rip-1] network 4.0.0.0
[RT4-rip-1] network 24.0.0.0
5.4.3 Configure RIPv2 and disable auto summary on RT1, RT2 and RT4
1. Configure RT1
[RT1-rip-1] version 2
[RT1-rip-1] undo summary
2. Configure RT2
[RT2-rip-1] version 2
[RT2-rip-1] undo summary
3. Configure RT3
[RT3-rip-1] version 2
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
27
4. Configure RT4
[RT4-rip-1] version 2
[RT4-rip-1] undo summary
Routes : 12
Proto
Pre
Cost
NextHop
Interface
127.0.0.1
InLoopBack0
1.1.1.1/32
Direct 0
2.2.2.2/32
RIP
100
12.1.1.2
Ethernet0/0/0
3.0.0.0/8
RIP
100
13.1.1.2
Serial0/0/1
4.4.4.4/32
RIP
100
12.1.1.2
Ethernet0/0/0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0/0/0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.0/30
Direct 0
13.1.1.1
Serial0/0/1
13.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.2/32
Direct 0
13.1.1.2
Serial0/0/1
24.1.1.0/30
RIP
100
12.1.1.2
127.0.0.0/8
Direct 0
127.0.0.1
127.0.0.1/32
Direct 0
127.0.0.1
Ethernet0/0/0
InLoopBack0
InLoopBack0
Seen from above, the route sent from RT3 has already been auto
summarized into classful route. But the routes sent from other routes are
still classless.
Similarly, network 3.0.0.0/32 can be seen after aggregation on RT2 and
RT4, other subnet are still classless.
5.4.5 Disable auto summary on RT3 and configure manual summary in the
interface view by using command rip summary, then check the IP routing
table on RT1
[RT3-rip-1] undo summary
[RT3] interface serial 0/0/1
[RT3-Serial0/0/1] rip summary 3.3.3.0 255.255.255.0
[RT1]display ip routing-table
Routing Tables: Public
28
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Routes : 12
Proto
Pre
Cost
NextHop
Interface
127.0.0.1
InLoopBack0
1.1.1.1/32
Direct 0
2.2.2.2/32
RIP
100
12.1.1.2
Ethernet0/0/0
3.3.3.0/24
RIP
100
13.1.1.2
Serial0/0/1
4.4.4.4/32
RIP
100
12.1.1.2
Ethernet0/0/0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0/0/0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.0/30
Direct 0
13.1.1.1
Serial0/0/1
13.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.2/32
Direct 0
13.1.1.2
Serial0/0/1
24.1.1.0/30
RIP
100
12.1.1.2
127.0.0.0/8
Direct 0
127.0.0.1
127.0.0.1/32
Direct 0
127.0.0.1
Ethernet0/0/0
InLoopBack0
InLoopBack0
Routes from RT3 have been aggregated, but the routes from other routers
are still classless.
Similarly, network 3.3.3.0/24 in the routing table of RT2 and RT4 is
summarized; all the other routes are still classless.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
29
RT1, RT2, RT3 and RT4 are connected through Ethernet cable and
serial cable; L1 is the loopback interface of each router.
RT1 communicates with RT3 through static route. RT1, RT2 and RT4
run RIPv2, import the static route on RT1 into RIPv2 in order that
network 3.3.3.3/32 and 4.4.4.4/32 can access each other.
30
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Run RIP
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
31
2. Configure RT2:
[RT2]interface Ethernet 0/0/0
[RT2-Ethernet0/0/0]ip address 12.1.1.2 255.255.255.252
[RT2] interface Serial 0/0/1
[RT2-Serial0/0/1] ip address 24.1.1.1 255.255.255.252
[RT2]interface LoopBack 1
[RT2-LoopBack1]ip address 2.2.2.2 255.255.255.255
3. Configure RT3:
[RT3] interface Serial 0/0/1
[RT3-Serial0/0/1] ip address 13.1.1.2 255.255.255.252
[RT3] interface LoopBack 1
[RT3-LoopBack1] ip address 3.3.3.3 255.255.255.255
4. Configure RT4:
[RT4] interface Serial 0/0/1
[RT4-Serial0/0/1] ip address 24.1.1.2 255.255.255.252
32
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2. Configure RT2
[RT2] rip
[RT2-rip] network 2.0.0.0
[RT2-rip] network 12.0.0.0
[RT2-rip] network 24.0.0.0
[RT1-rip] undo summary
3. Configure RT4
[RT4] rip
[RT4-rip] network 4.0.0.0
[RT4-rip] network 24.0.0.0
[RT1-rip] undo summary
2. Configure RT2
[RT2]interface Ethernet 0/0/0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
33
3. Configure RT4
[RT4]interface serial 0/0/1
[RT4-Serial0/0/1]rip version 2
[RT4]interface loopback 1
[RT4-loopback1]rip version 2
routing-table
Routes : 12
Proto
Pre
Cost
1.1.1.1/32
Direct 0
2.2.2.2/32
RIP
3.3.3.3/32
Static
4.4.4.4/32
RIP
100
Interface
127.0.0.1
InLoopBack0
12.1.1.2
60
100
NextHop
13.1.1.2
12.1.1.2
Ethernet0/0/0
Serial0/0/1
Ethernet0/0/0
12.1.1.0/30
Direct 0
12.1.1.1
Ethernet0/0/0
12.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.0/30
Direct 0
13.1.1.1
Serial0/0/1
13.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
13.1.1.2/32
Direct 0
13.1.1.2
Serial0/0/1
24.1.1.0/30
RIP
100
12.1.1.2
Ethernet0/0/0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
[RT2]display ip routing-table
Routing Tables: Public
Destinations : 11
34
Routes : 11
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Proto
Pre
100
Cost
1
NextHop
12.1.1.1
Interface
1.1.1.1/32
RIP
2.2.2.2/32
Direct 0
3.3.3.3/32
RIP
100
12.1.1.1
Ethernet0/0/0
4.4.4.4/32
RIP
100
24.1.1.2
Serial0/0/1
127.0.0.1
Ethernet0/0/0
InLoopBack0
12.1.1.0/30
Direct 0
12.1.1.2
Ethernet0/0/0
12.1.1.2/32
Direct 0
127.0.0.1
InLoopBack0
24.1.1.0/30
Direct 0
24.1.1.1
Serial0/0/1
24.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
24.1.1.2/32
Direct 0
24.1.1.2
Serial0/0/1
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
The routing table of RT4 is similar to RT2, seen from the routing table above;
RT1 import the static route into RIPv2 and announce them.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
35
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 70/86/110 ms
6.5
FAQ
QHow to control the router to import only one static route if RT1 have more
than one static route?
AUse route-policy to import the specified route when the route redistributed,
or use command filter-policy to filter the undesired route when the routes
are announced.
36
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
RT1, RT2, RT3 and RT4 are connected through Ethernet cable and
serial cable; L1 is one of the loopback interfaces of each router.
All routers run OSPF and all interfaces of the routers belong to OSPF
AREA 0.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
37
Chapter 7
Configure Router ID
Enable OSPF
Create Area 0
38
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 7
2. Configure RT2
[RT2]interface Ethernet 0/0/0
[RT2-Ethernet0/0/0]ip address 12.1.1.2 255.255.255.252
[RT2] interface Serial 0/0/1
[RT2-Serial0/0/1] ip address 24.1.1.1 255.255.255.252
[RT2]interface LoopBack 1
[RT2-LoopBack1]ip address 2.2.2.2 255.255.255.255
3. Configure RT3
[RT3] interface Serial 0/0/1
[RT3-Serial0/0/1] ip address 13.1.1.2 255.255.255.252
[RT3] interface LoopBack 1
[RT3-LoopBack1] ip address 3.3.3.3 255.255.255.255
4. Configure RT4
[RT4] interface Serial 0/0/1
[RT4-Serial0/0/1] ip address 24.1.1.2 255.255.255.252
[RT4] interface LoopBack 1
[RT4-LoopBack1] ip address 4.4.4.4 255.255.255.255
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
39
Chapter 7
7.4.3 Run OSPF and announce the subnet in the specified area
1. Configure RT1
[RT1] ospf
[RT1-ospf-1]area 0
[RT1-ospf-1-area-0.0.0.0] network 1.1.1.1 0.0.0.0
[RT1-ospf-1-area-0.0.0.0] network 12.1.1.0 0.0.0.3
[RT1-ospf-1-area-0.0.0.0] network 13.1.1.0 0.0.0.3
2. Configure RT2
[RT2] ospf
[RT2-ospf-1]area 0
[RT2-ospf-1-area-0.0.0.0] network 2.2.2.2 0.0.0.0
[RT2-ospf-1-area-0.0.0.0] network 12.1.1.0 0.0.0.3
[RT2-ospf-1-area-0.0.0.0] network 24.1.1.0 0.0.0.3
3. Configure RT3
[RT3] ospf
[RT3-ospf-1]area 0
[RT3-ospf-1-area-0.0.0.0] network 3.3.3.3 0.0.0.0
[RT3-ospf-1-area-0.0.0.0] network 13.1.1.0 0.0.0.3
4. Configure RT4
[RT4] ospf
[RT4-ospf-1]area 0
[RT4-ospf-1-area-0.0.0.0] network 4.4.4.4 0.0.0.0
[RT4-ospf-1-area-0.0.0.0] network 24.1.1.0 0.0.0.3
40
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 7
Address: 12.1.1.2
Mode:Nbr is
DR: 12.1.1.1
Master
BDR: 12.1.1.2
GR State: Normal
Priority: 1
MTU: 0
sec
Address: 13.1.1.2
Mode:Nbr is
BDR: None
Master
GR State: Normal
Priority: 1
MTU: 0
sec
Routes : 12
Proto
Pre
Cost
NextHop
127.0.0.1
Interface
1.1.1.1/32
Direct
2.2.2.2/32
OSPF
10
12.1.1.2
InLoopBack0
3.3.3.3/32
OSPF
10
1563
13.1.1.2
Serial0/0/1
4.4.4.4/32
OSPF
10
1564
12.1.1.2
Ethernet0/0/0
Ethernet0/0/0
12.1.1.0/30
Direct
12.1.1.1
Ethernet0/0/0
12.1.1.1/32
Direct
127.0.0.1
InLoopBack0
13.1.1.0/30
Direct
13.1.1.1
Serial0/0/1
13.1.1.1/32
Direct
127.0.0.1
InLoopBack0
13.1.1.2/32
Direct
24.1.1.0/30
OSPF
127.0.0.0/8
10
Direct
13.1.1.2
1563
0
12.1.1.2
127.0.0.1
Serial0/0/1
Ethernet0/0/0
InLoopBack0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
41
Chapter 7
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
7.5
FAQ
QFor OSPF practice, if you find the neighbor relationship between two
routers is abnormal, what commands are used to find the trouble?
AUse display ospf error to display all OSPF error information, user can
locate the trouble according to the error information.
42
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
RT1, RT2, RT3 and RT4 run the OSPF concurrently. All routers are
connect with eath other through Ethernet and serial cable. L1 is the
Loopback interface.
Configure Router
Enable OSPF
Create Area
Announce Subnets
figture 8-2 OSPF Multi-Area Configuration Flows
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
43
Chapter 8
OSPF Multi-AreaConfigurati on
Configure interface
(2)
Configure Router ID
(3)
Enable OSPF
(4)
(5)
44
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 8
OSPF Multi-AreaConfigurati on
2. Configure RT2
[RT2]interface Ethernet 0/0/0
[RT2-Ethernet0/0/0]ip address 12.1.1.2 255.255.255.252
[RT2] interface Serial 0/0/1
[RT2-Serial0/0/1] ip address 24.1.1.1 255.255.255.252
[RT2]interface LoopBack 1
[RT2-LoopBack1]ip address 2.2.2.2 255.255.255.255
3. Configure RT3
[RT3] interface Serial 0/0/1
[RT3-Serial0/0/1] ip address 13.1.1.2 255.255.255.252
[RT3] interface LoopBack 1
[RT3-LoopBack1] ip address 3.3.3.3 255.255.255.255
4. Configure RT4
[RT4] interface Serial 0/0/1
[RT4-Serial0/0/1] ip address 24.1.1.2 255.255.255.252
[RT4] interface LoopBack 1
[RT4-LoopBack1] ip address 4.4.4.4 255.255.255.255
[RT1-ospf-1]area 1
2. Configure RT2
[RT2] ospf
[RT2-ospf-1]area 0
[RT2-ospf-1]area 2
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
45
Chapter 8
OSPF Multi-AreaConfigurati on
3. Configure RT3
[RT3] ospf
[RT3-ospf-1]area 1
4. Configure RT4
[RT4] ospf
[RT4-ospf-1]area 2
2. Configure RT2
[RT2-ospf-1-area-0.0.0.0] network 2.2.2.2 0.0.0.0
[RT2-ospf-1-area-0.0.0.0] network 12.1.1.0 0.0.0.3
[RT2-ospf-1-area-0.0.0.2] network 24.1.1.0 0.0.0.3
3. Configure RT3
[RT3-ospf-1-area-0.0.0.1] network 3.3.3.3 0.0.0.0
[RT3-ospf-1-area-0.0.0.1] network 13.1.1.0 0.0.0.3
4. Configure RT4
[RT4-ospf-1-area-0.0.0.2] network 4.4.4.4 0.0.0.0
[RT4-ospf-1-area-0.0.0.2] network 24.1.1.0 0.0.0.3
Address: 12.1.1.2
Mode:Nbr is
Master
BDR: 12.1.1.2
GR State: Normal
Priority: 1
MTU: 0
sec
46
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 8
OSPF Multi-AreaConfigurati on
Address: 13.1.1.2
Mode:Nbr is
BDR: None
Master
GR State: Normal
Priority: 1
MTU: 0
sec
Routes : 12
Proto
Pre
Cost
NextHop
127.0.0.1
Interface
1.1.1.1/32
Direct
2.2.2.2/32
OSPF
10
12.1.1.2
InLoopBack0
3.3.3.3/32
OSPF
10
1563
13.1.1.2
Serial0/0/1
4.4.4.4/32
OSPF
10
1564
12.1.1.2
Ethernet0/0/0
Ethernet0/0/0
12.1.1.0/30
Direct
12.1.1.1
Ethernet0/0/0
12.1.1.1/32
Direct
127.0.0.1
InLoopBack0
13.1.1.0/30
Direct
13.1.1.1
Serial0/0/1
13.1.1.1/32
Direct
127.0.0.1
InLoopBack0
13.1.1.2/32
Direct
24.1.1.0/30
OSPF
10
13.1.1.2
1563
12.1.1.2
Serial0/0/1
Ethernet0/0/0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
47
Chapter 8
OSPF Multi-AreaConfigurati on
8.5
FAQ
QFor OSPF labs, Single area experiment and multi-area experiment get
the same routing information, so what is the advantage of multi-area?
AUse multiple areas to reduce the size of LSDB, and also reduce the
calculation of SPF. Use display ospf lsdb to check the difference.
48
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Section 3
Switching Tech. Laboratory Guide
Table of Contents
Table of Contents
Lab Description ............................................................................................................... 1
Introductions ........................................................................................................... 1
Version .................................................................................................................... 1
Objectives ............................................................................................................... 1
Tasks....................................................................................................................... 1
References.............................................................................................................. 1
Chapter 1 Ethernet Port Auto Negotiation ...................................................................... 2
1.1 Networking and Service Description ................................................................. 2
1.2 Configuration Flow ............................................................................................ 2
1.3 Configuration Steps .......................................................................................... 2
1.4 Configuration and Verification ........................................................................... 3
Chapter 2 Manual Port Aggregation ............................................................................... 7
2.1 Networking and Service Description ................................................................. 7
2.2 Configuration Flow ............................................................................................ 7
2.3 Configuration Steps .......................................................................................... 7
2.4 Configuration and Verification ........................................................................... 7
Chapter 3 Basic Configuration of VLAN........................................................................ 10
3.1 Networking and Service Description ............................................................... 10
3.2 Configuration Flow .......................................................................................... 10
3.3 Configuration Steps ........................................................................................ 10
3.4 Configuration and Verification ......................................................................... 11
Chapter 4 Route on Stick Configuration ....................................................................... 14
4.1 Networking and Service Description ............................................................... 14
4.2 Configuration Flow .......................................................................................... 15
4.3 Configuration Steps ........................................................................................ 15
4.4 Configuration and Verification ......................................................................... 15
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Table of Contents
ii
Lab Description
Lab Description
Introductions
This Lab Guide introduces the configuration and operation of Ethernet
switching technology for HCDA-HNTD, including the technology of
Ethernet port, VLAN, VLAN routing, STP and VRRP; the trainees can get
familiarity with the configuration of Huawei products through these
exercises, so as to grasp the technology of HNTD and pass the HCDA
exam.
Version
This guide is applicable to VRP versions 3.
Objectives
z
Tasks
References
VRP 3 Operation Manual
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 1
SW2 connect SW3 through Ethernet interface; modify the speed and
duplex mode of interface Ethernet 0/6 of SW2, then check the status
of interface Ethernet 0/6 of SW3. The objective is to get familiar with
the principle of Ethernet auto negotiation.
Use the command speed to configure the operating speed of the interface
Ethernet 0/6 on SW2.
Use the command duplex to configure the operating mode of the interface
Ethernet0/6 on SW3.
Check the status of interface Ethernet 0/6 in RT3
2
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 1
The status of Ethernet 0/6 of SW3 is the same with Ethernet 0/6 of SW2,
both of them are 100M Full duplex mode after auto negotiation.
Now, the operation speed of interface Ethernet 0/6 of SW2 is 100M and the
Duplex mode is Full duplex.
Check the status of interface Ethernet 0/6 of SW3:
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 1
The interface status of Ethernet 0/6 of SW3 is 100M and Full duplex after
negotiation.
Try to modify the operation speed of Ethernet 0/6 of SW2 to 10M:
[SW2]interface Ethernet 0/6
[SW2-Ethernet0/6]speed 10
[SW2]display interface Ethernet 0/0/6
Ethernet0/0/6 current state : UP
Description : Huawei, Quidway Series, Ethernet0/0/6 Interface,
Switch Port
PVID :
The interface status of Ethernet 0/6 of SW2 is 10M and the duplex mode is
Full duplex.
Check the status of Ethernet 0/6 of SW3:
[SW3]display interface Ethernet 0/0/6
Ethernet0/0/6 current state : UP
Description : Huawei, Quidway Series, Ethernet0/0/6 Interface,
Switch Port
PVID :
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 1
The status of interface Ethernet 0/6 of SW3 is 10M and full duplex.
2. Configure the operation mode of ethernet 0/6 of SW2:
[SW2]interface Ethernet 0/6
[SW2-Ethernet0/6]duplex half
[SW2]display interface Ethernet 0/0/6
Ethernet0/0/6 current state : UP
Description : Huawei, Quidway Series, Ethernet0/0/6 Interface,
Switch Port
PVID :
The interface operation speed of Ethernet 0/6 of SW2 is set to 10M and the
duplex mode is half duplex.
Check the status of interface Ethernet 0/6 of SW3:
[SW3]display interface Ethernet 0/0/6
Ethernet0/0/6 current state : UP
Description : Huawei, Quidway Series, Ethernet0/0/6 Interface,
Switch Port
PVID :
The interface status of Ethernet 0/6 of SW3 is set to 10M and the operation
mode is half duplex after auto negotiation.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 1
Seen from above, the result of auto negotiation is the best operation mode
of two sides, which they can support. The fiber does not support
negotiation.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
(3)
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2. Configure on SW3
[SW2]interface Ethernet 0/6
[SW2-Ethernet0/0/6]undo port default vlan
[SW2-Ethernet0/0/6]bpdu disable
[SW2-Ethernet0/0/6]undo ntdp enable
[SW2-Ethernet0/0/6]undo ndp enable
[SW2-Ethernet0/0/6]interface Ethernet 0/7
[SW2-Ethernet0/0/7]undo port default vlan
[SW2-Ethernet0/0/7]bpdu disable
[SW2-Ethernet0/0/7]undo ntdp enable
[SW2-Ethernet0/0/7]undo ndp enable
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2.4.3 Associate the configured ports with the Ether-trunk on both SW2 and
SW3
1. Configure on SW2
[SW2]interface Ethernet0/0/6
[SW2-Ethernet0/0/6]eth-trunk 1
[SW2]interface Ethernet0/0/7
[SW2-Ethernet0/0/6]eth-trunk 1
2. Configure on SW3
[SW2]interface Ethernet0/0/6
[SW2-Ethernet0/0/6]eth-trunk 1
[SW2]interface Ethernet0/0/7
[SW2-Ethernet0/0/6]eth-trunk 1
--------------------------------------------------------PortName
Status
Weight
Ethernet0/0/6
Up
Ethernet0/0/7
Up
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
E0/1
SW2
SW3
E0/8
E0/9
E0/8
PC21:VLAN10 PC22:VLAN20
IP:172.16.1.21 IP:172.16.1.22
PC31:VLAN10
IP:172.16.1.31
E0/9
PC32:VLAN20
IP:172.16.1.32
Create VLAN
10
Create VLAN
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Configure
Port VLAN
Add the corresponding port in the VLAN view. For example, add
interface E0/8 in VLAN 10, add interface E0/9 in VLAN 20.
Configure the VLAN of the port in the local port view. For example,
configure VLAN 10 in the port view of E0/8 on SW2.
2. Configure SW3
//add the corresponding port in the VLAN view
[SW3] vlan10
[SW3-vlan10] port Ethernet 0/8
[SW3] vlan 20
[SW3-vlan20]port Ethernet 0/9
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
11
2. Configure SW3
//Configure the link-type of the port to be trunk and permit the passing of
VLAN10 and VLAN 20
[SW3]interface Ethernet0/0/1
[SW3-Ethernet0/0/1] undo port default vlan
[SW3-Ethernet0/0/1] port link-type trunk
[SW3-Ethernet0/0/1] port trunk allow-pass vlan 10 20
3.4.3 Verification
1. Display the state of the interface
[SW3]display interface Ethernet 0/8
Ethernet0/8 current state : UP
IP Sending Frames' Format is PKTFMT_ETHNT_2, Hardware address
is 000f-e221-3780
The Maximum Transmit Unit is 1500
Media type is twisted pair, loopback not set
Port hardware type is 100_BASE_TX
100Mbps-speed mode, full-duplex mode
Link speed type is autonegotiation, link duplex type is
autonegotiation
Flow-control is not enabled
Port-flow-constrain has not been configured completely
The Maximum Frame Length is 1552
Broadcast MAX-ratio: 100%
PVID: 10
Mdi type: auto
Port link-type: access
Tagged
VLAN ID : none
Untagged VLAN ID : 10
With the verification information shown above, the link-type of E0/8 on SW3
is access, and this port only permits the passing of VLAN10. For other
access ports, such as E0/9 on SW3, E0/8,E0/9 on SW2, the interface
information are similar to E0/8 on SW3.
[SW2]display port allow-vlan Ethernet0/0/1
Port
Status
PVID
allowed on trunk
12
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
vlans
---------------------------------------------------------Ethernet0/0/1
trunking
0
10
Ethernet0/0/1
trunking
20
From above, the link-type of E0/1 on SW2 is Trunk, and it permits traffic of
VLAN10 and VLAN20 to pass. For other trunk port, such as E0/1 on SW3,
the interface information is similar to E0/1 on SW3.
2. Check the connectivity of PC21,PC22,PC31,PC32
Use ping to check the connectivity between different VLANs.
PC21 and PC31 of VLAN10 can access each other through switches;
PC22 and PC32 of VLAN20 can access each other through switches; but
PCs in different VLAN cannot access each other.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
13
14
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Configure VLAN
on the port
Configure sub-interface
on the router
Create VLAN
Add the corresponding port in the VLAN view: Add E0/8 in the view of
VLAN10 on SW1; add E0/9 in the view of VLAN20.
The port linking the switch and the router permits several VLAN to pass, so
configure the link-type of the port to be TRUNK and then configure the
VLAN ID permitted.
(3)
Create sub-interface on the port E0/0 linking to SW1, and configure the
corresponding VLAN ID and IP address of the sub-interface.
15
Nexthop
Interface
127.0.0.0/8
DIRECT
127.0.0.1
InLoopBack0
127.0.0.1/32
DIRECT
127.0.0.1
InLoopBack0
172.16.10.0/24
DIRECT
0 172.16.10.1
172.16.10.1/32
DIRECT
172.16.20.0/24
DIRECT
0 172.16.20.1
DIRECT
Ethernet0/0/0.1
127.0.0.1
InLoopBack0
Ethernet0/0/0.2
172.16.20.1/32
127.0.0.1
InLoopBack0
16
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
4.4.4 Verification
1. Check of the connectivity of PC21 and PC22
Check the connectivity of PC21 and PC22 using ping.
PC21 in VLAN10 and PC22 in VLAN20 can access each other.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
17
18
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Create VLAN
Configure layer3
interface in the router
Create VLAN
19
2. Configure SW3
[SW3] vlan10
[SW3-vlan10] port Ethernet 0/8
Attention: only when at least one interface in the VLAN is UP, the layer3
interface of the VLAN would be UP.
The states of the layer3 interface of VLAN20, VLAN1 are the same as
VLAN10, so all of the layer3 interfaces on SW2 are UP.
2. Configure SW3
[SW3]interface Vlan-interface 10
20
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
The state of the layer3 interface of VLAN1 is the same as VLAN10, so all
the layer3 interface on SW3 are UP.
Nexthop
Interface
127.0.0.0/8
DIRECT 0
127.0.0.1
InLoopBack0
127.0.0.1/32
DIRECT 0
127.0.0.1
InLoopBack0
172.16.1.0/30
DIRECT 0
172.16.1.1
172.16.1.1/32
DIRECT 0
127.0.0.1
172.16.10.0/24
DIRECT 0
172.16.10.1
172.16.10.1/32
DIRECT 0
127.0.0.1
172.16.20.0/24
DIRECT 0
172.16.20.1
DIRECT 0
127.0.0.1
Vlan-interface1
InLoopBack0
Vlan-interface10
InLoopBack0
Vlan-interface20
172.16.20.1/32
172.16.30.0/24
STATIC 60 0
InLoopBack0
172.16.1.2
Vlan-interface1
Seen from above, the static route is active in the ip routing table.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
21
2. Configure SW3
[SW3]ip route-static 172.16.10.0 255.255.255.0 172.16.1.1
[SW3]ip route-static 172.16.20.0 255.255.255.0 172.16.1.1
Nexthop
Interface
127.0.0.0/8
DIRECT
127.0.0.1
InLoopBack0
127.0.0.1/32
DIRECT
127.0.0.1
InLoopBack0
172.16.1.0/30
DIRECT
172.16.1.2
172.16.1.2/32
DIRECT
127.0.0.1
172.16.10.0/24
STATIC
60
0 172.16.1.1
STATIC
60
0 172.16.1.1
DIRECT
172.16.30.1
DIRECT
127.0.0.1
Vlan-interface1
InLoopBack0
Vlan-interface1
172.16.20.0/24
Vlan-interface1
172.16.30.0/24
Vlan-interface10
172.16.30.1/32
InLoopBack0
Seen from above, the static route is active in the ip routing table.
5.4.4 Verification
1. Check of the connectivity of PC21,PC22,PC31
Use ping command to check the connectivity of PC21,PC22 and PC31.
C:\>ping 172.16.30.31
Pinging 172.16.30.31 with 32 bytes of data:
Reply from 172.16.30.31: bytes=32 time=1ms TTL=254
Reply from 172.16.30.31: bytes=32 time=2ms TTL=254
Reply from 172.16.30.31: bytes=32 time=2ms TTL=254
Reply from 172.16.30.31: bytes=32 time=2ms TTL=254
Ping statistics for 172.16.30.31:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 2ms, Average = 1ms
22
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
23
SW1, SW2 and SW3 connect with each other through Ethernet, using
STP to prevent the loop.
Manipulate the selection of the root bridge through the change of the
priority of the bridges
Enable STP
24
Enable STP.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Change the bridge priority of SW1 to be 8192 to make SW1 the root switch
2. Configure SW2
[SW2]stp mode stp
[SW2]stp enable
3. Configure SW3
[SW3]stp mode stp
[SW3]stp enable
25
26
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
417
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
27
598
28
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
561
561
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
29
Alternate
RP
SW1
E0/1
E0/2
DP
DP
E0/1
SW2
E0/6
E0/6
E0/7
E0/7
Bridge ID:
32768.00E0.FC41.3E99
Alternate
RP
DP
E0/2
ROOT
Bridge
SW3
DP
Bridge ID:
32768.00E0.FC18.05D0
(1) Compare the bridge ID of every switch, and select the one with the
smallest ID to be the ROOT Bridge;
30
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
The bridge times: Hello Time 2 sec, Max Age 20 sec, Forward
Delay 15 sec
Root bridge ID(Pri.MAC): 8192.00e0-fc41-43b9
Root path cost: 0
Bridge bpdu-protection: disabled
Timeout factor: 3
Port 1 (Ethernet0/1) of bridge is Forwarding
Port spanning tree protocol: enabled
Port role: Designated Port
Port path cost: 200
Port priority: 128
Designated bridge ID(Pri.MAC): 8192.00e0-fc41-43b9
The Port is a non-edged port
Connected to a point-to-point LAN segment
Maximum transmission limit is 3 Packets / hello time
Times: Hello Time 2 sec, Max Age 20 sec
Forward Delay 15 sec, Message Age 0
BPDU sent:
93
93
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
31
[SW2]display stp
Protocol mode: IEEE compatible STP
The bridge ID (Pri.MAC): 32768.00e0-fc41-3e99
The bridge times: Hello Time 2 sec, Max Age 20 sec, Forward
Delay 15 sec
Root bridge ID(Pri.MAC): 8192.00e0-fc41-43b9
Root path cost: 200
Bridge bpdu-protection: disabled
Timeout factor: 3
Port 1 (Ethernet0/1) of bridge is Forwarding
Port spanning tree protocol: enabled
Port role: Root Port
Port path cost: 200
Port priority: 128
Designated bridge ID(Pri.MAC): 8192.00e0-fc41-43b9
The Port is a non-edged port
Connected to a point-to-point LAN segment
Maximum transmission limit is 3 Packets / hello time
Times: Hello Time 2 sec, Max Age 20 sec
Forward Delay 15 sec, Message Age 0
BPDU sent:
1429
32
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
33
1536
1978
1978
34
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
figture 6-4 Network topology after chance of bridge priority and STP
convergence
The solid lines in the figure present the calculated shortest path tree, and
the dotted lines present the pruned link, RP is the root port, DP is the
designated port, Alternate is the blocking port.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
35
Single virtual router VRRP make all the users traffic go out through
RT3.
36
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Up-link port track VRRP monitors the state of the up-link port to select
Master dynamically.
Create Loopback interface in RT1, RT3 and RT4; configure the IP address
of the loopback interfaces and the physical interfaces.
(2)
Run OSPF in the entire network; enable OSPF on all the interfaces of the
routers and all the interfaces belong to area 0.
(3)
Enable ping packet of the Master in the system view. Configure virtual
router ID, virtual IP address and priority in the interface view.
(4)
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
37
Enable the track of the up-link port in the interface view. The backup works
not only when the router is down but also when the tracked interface of the
network is down.
2. Configure RT3
[RT3]interface LoopBack 1
[RT3-LoopBack1]ip address 3.3.3.3 32
[RT3]interface ethernet 0
[RT3-Ethernet0]ip address 13.1.1.2 30
[RT3]interface ethernet 1
[RT3-Ethernet1]ip address 10.1.1.251 24
3. Configure RT4
[RT4]interface LoopBack 1
[RT4-LoopBack1]ip address 4.4.4.4 32
[RT4]interface ethernet 0
[RT4-Ethernet0]ip address 14.1.1.2 30
[RT4]interface ethernet 1
[RT4-Ethernet1]ip address 10.1.1.252 24
38
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2. Configure RT3
[RT3]ospf
[RT3-ospf-1]area 0
[RT3-ospf-1-area-0.0.0.0]network 3.3.3.3 0.0.0.0
[RT3-ospf-1-area-0.0.0.0]network 13.1.1.0 0.0.0.3
[RT3-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
3. Configure RT4
[RT4]ospf
[RT4-ospf-1]area 0
[RT4-ospf-1-area-0.0.0.0]network 4.4.4.4 0.0.0.0
[RT4-ospf-1-area-0.0.0.0]network 14.1.1.0 0.0.0.3
[RT4-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
Routes : 11
NextHop
Interface
1.1.1.1/32 Direct
127.0.0.1
InLoopBack0
3.3.3.3/32 OSPF
10
13.1.1.2
Ethernet0
4.4.4.4/32 OSPF
10
14.1.1.2
Ethernet1
10.1.1.0/24 OSPF
10
13.1.1.2
Ethernet0
OSPF
10
14.1.1.2
Ethernet1
13.1.1.0/30 Direct
13.1.1.1
127.0.0.1
14.1.1.1
127.0.0.1
Ethernet0
13.1.1.1/32 Direct
InLoopBack0
14.1.1.0/30 Direct
Ethernet1
14.1.1.1/32 Direct
InLoopBack0
127.0.0.0/8
Direct
127.0.0.1
127.0.0.1/32 Direct
127.0.0.1
InLoopBack0
InLoopBack0
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
39
As shown in above, OSPF discovers all the network segments and ready
for the practice.
Delay Time : 0
Timer : 1
Auth Type : NONE
[RT4]display vrrp
Ethernet1 | Virtual Router 1
state : Backup
Virtual IP : 10.1.1.253
Priority : 100
Preempt : YES
Delay Time : 0
Timer : 1
Auth Type : NONE
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Delay Time : 0
Timer : 1
Auth Type : NONE
Configure RT3
[RT3]interface Ethernet 1
(2)
Configure RT4
[RT4]interface Ethernet 1
[RT4-Ethernet1]vrrp vrid 1 virtual-ip 10.1.1.253
Delay Time : 0
Timer : 1
Auth Type : NONE
Ethernet1 | Virtual Router 2
state : Backup
Virtual IP : 10.1.1.254
Priority : 100
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
41
Delay Time : 0
Timer : 1
Auth Type : NONE
[RT4]display vrrp
Ethernet1 | Virtual Router 1
state : Backup
Virtual IP : 10.1.1.253
Priority : 100
Preempt : YES
Delay Time : 0
Timer : 1
Auth Type : NONE
Ethernet1 | Virtual Router 2
state : Master
Virtual IP : 10.1.1.254
Priority : 150
Preempt : YES
Delay Time : 0
Timer : 1
Auth Type : NONE
As shown above, for virtual router 1, RT3 has higher priority as the Master,
and RT4 as the Backup; for virtual router 2, RT4 has higher priority as the
Master, and RT3 is the Backup.
When configure default gateway on user PCs, the default gateway of PC1
should set to 10.1.1.253, and the default gateway of PC2 should set to
10.1.1.254. Thus, the traffic from PC1 to 1.1.1.1/32 is forwarded by RT3
and that of PC2 is forwarded by RT4. The load-sharing is realized.
If RT3 is out of the network, RT4 will become the Master of both group1
and group2.
[RT4]display vrrp
Ethernet1 | Virtual Router 1
state : Master
Virtual IP : 10.1.1.253
Priority : 100
Preempt : YES
Delay Time : 0
Timer : 1
Auth Type : NONE
Ethernet1 | Virtual Router 2
state : Master
42
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Delay Time : 0
Timer : 1
Auth Type : NONE
Delay Time : 0
Timer : 1
Auth Type : NONE
Track IF : Ethernet0
Delay Time : 0
Timer : 1
Auth Type : NONE
[RT4]display vrrp
Ethernet1 | Virtual Router 1
state : Backup
Virtual IP : 10.1.1.253
Priority : 100
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
43
Delay Time : 0
Timer : 1
Auth Type : NONE
Ethernet1 | Virtual Router 2
state : Master
Virtual IP : 10.1.1.254
Priority : 150
Preempt : YES
Delay Time : 0
Timer : 1
Auth Type : NONE
Track IF : Ethernet0
Delay Time : 0
Timer : 1
Auth Type : NONE
Track IF : Ethernet0
Delay Time : 0
Timer : 1
Auth Type : NONE
[RT4]display vrrp
Ethernet1 | Virtual Router 1
state : Master
Virtual IP : 10.1.1.253
Priority : 100
Preempt : YES
Delay Time : 0
Timer : 1
Auth Type : NONE
Ethernet1 | Virtual Router 2
44
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Delay Time : 0
Timer : 1
Auth Type : NONE
Track IF : Ethernet0
Due to the inactivation of the up-link, system reduces the priority of RT3 for
virtual router 1 from 150 to 50, lower than the priority of RT4, so RT4
becomes the Master of virtual group 1.
All of the traffic is now forwarded by RT4 because of the automatic
selection of Master when the up-link is inactivated.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
45
Section 4
WAN Protocol Laboratory Guide
Table of Contents
Table of Contents
Table of Contents ............................................................................................................1
Lab Description ...............................................................................................................3
Introduction..............................................................................................................3
Version ....................................................................................................................3
Objectives................................................................................................................3
Tasks.......................................................................................................................3
References ..............................................................................................................3
Chapter 1 HDLC Basic Configuration..............................................................................4
1.1 Networking and Service Description .................................................................4
1.2 Configuration Flow ............................................................................................4
1.3 Configuration and Verification ...........................................................................4
Chapter 2 IP unnumbered configuration of HDLC...........................................................6
2.1 Networking and Service Description .................................................................6
2.2 Configuration Flow ............................................................................................6
2.3 Configuration and Verification ...........................................................................7
Chapter 3 PPP Basic Configuration ................................................................................ 9
3.1 Networking and Service Description ................................................................. 9
3.2 Configuration Flow ............................................................................................ 9
3.3 Configuration and Verification ........................................................................... 9
Chapter 4 Configuring PPP Authentication ...................................................................12
4.1 Networking and Service Description ...............................................................12
4.2 Configuration Flow ..........................................................................................12
4.3 Configuration and Verification .........................................................................13
Chapter 5 FR Basic Configuration.................................................................................15
5.1 Networking and Service Description ...............................................................15
5.2 Configuration Flow ..........................................................................................15
5.3 Configuration and Verification .........................................................................16
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Table of Contents
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Lab Description
Lab Description
Introduction
This experiment guide introduces the configuration methods and
configuration procedure of the WAN protocol, and covers the currently
prevalent technologies of WAN, such as HDLC, PPP and FR.
Version
This guide is applicable to VRP versions 3.40.
Objectives
z
Tasks
method
z
References
VRP 3.40 Operation Manual
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2. Configure RT2
[RT2]interface Serial 0/0/1
[RT2-Serial0/0/1]link-protocol hdlc
4
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 1
1.3.2 Verification
You can use PING command to check whether the configuration of the
router is correct.
[RT1]ping 10.1.1.2
PING 10.1.1.2: 56 data bytes, press CTRL_C to break
Reply from 10.1.1.2: bytes=56 Sequence=1 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=2 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=3 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=4 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=5 ttl=255 time=31 ms
10.1.1.2 ping statistics
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/31/31 ms
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Encapsulation an interface
with HDLC
IP unnumbered
configuration
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
\\Static
Route
2. Configure RT2
[RT2]interface Serial 0/0/1
[RT2-Serial0/0/1]link-protocol hdlc
[RT2-Serial0/0/1]ip address 10.1.1.2 24
2.3.2 Verification
1. Use display ip interface brief command to check the IP address
information of the interface.
In this example, you can see the same IP address was configured on Serial
0/0/1 and loopback 0. Normally, IP address duplication will occurre if you
dont configure IP unnumbered. For this example, there is no IP address
duplication as the interface serial 0/0/1 borrowed IP address from loopback
0.
[RT1]display ip interface brief
*down: administratively down
(l): loopback
(s): spoofing
Interface
IP Address
Physical
LoopBack0
10.1.1.1
up
Protocol Description
up(s)
HUAWEI,
Quidway
Serial0/0/0
unassigned
up
up
HUAWEI,
10.1.1.1
up
up
HUAWEI,
Quidway
Serial0/0/1
Quidway
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
[RT1-Serial0/0/1]link-protocol ppp
[RT1-Serial0/0/1]ip address 10.1.1.1 30
2. Configure RT2
[RT2]interface Serial 0/0/1
[RT2-Serial0/0/1]link-protocol ppp
[RT2-Serial0/0/1]ip address 10.1.1.2 30
3.3.2 Verification
Use PING command to check whether the configuration of the routers is
correct.
[RT1]ping 10.1.1.2
PING 10.1.1.2: 56 data bytes, press CTRL_C to break
Reply from 10.1.1.2: bytes=56 Sequence=1 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=2 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=3 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=4 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=5 ttl=255 time=31 ms
10.1.1.2 ping statistics
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/31/31 ms
2. Configure RT2
[RT2]interface Serial 0
[RT2-Serial0]link-protocol ppp
[RT2-Serial0]ip address 10.1.1.2 30
10
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Routes : 5
NextHop
Interface
10.1.1.0/30 Direct
10.1.1.2
10.1.1.1
127.0.0.1
127.0.0.1
Serial0
10.1.1.1/32 Direct
Serial0
10.1.1.2/32 Direct
InLoopBack0
127.0.0.0/8 Direct
InLoopBack0
127.0.0.1/32 Direct
127.0.0.1
InLoopBack0
Seen from the above routing-table, the remote PPP link is a host route in the
local routing-table as both communication parties can know IP address of
the remote link by using IPCP message.
2. After Configuration
[RT1]display ip routing-table
Routing Tables: Public
Destinations : 4
Destination/Mask
Routes : 4
Proto Pre Cost NextHop
Interface
10.1.1.1/32
Direct 0
127.0.0.1
InLoopBack0
10.1.1.2/32
Direct 0
10.1.1.2
Serial0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct0
127.0.0.1
InLoopBack0
Notes:
1. IP address obtain by negotiation is a host address; the route entity will not
be added to IP routing-table.
2. You need to reset the interface of RT2.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
11
Chapter 4
12
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 4
(Password
Authentication
Protocol)
is
2-way
handshake
(2)
1. Configuration on RT1:
[RT1]local-user huawei
[RT1-luser-huawei] password simple hello
[RT1-luser-huawei] service-type ppp
[RT1]interface Serial 0/0/1
[RT1-Serial0/0/1]link-protocol ppp
[RT1-Serial0/0/1]ppp authentication-mode pap
[RT1-Serial0/0/1]ip address 10.1.1.1 30
2. Configuration on RT2:
[RT2]interface Serial 0
[RT2-Serial0]link-protocol ppp
[RT2-Serial0]ppp pap local-user huawei password simple hello
[RT2-Serial0]ip address 10.1.1.2 30
(Challenge-Handshake
Authentication
Protocol)
is
3-way
1. Configuration on RT1 :
[RT1]local-user huawei
[RT1-luser-huawei] password cipher hello
[RT1-luser-huawei] service-type ppp
[RT1]interface Serial 0
[RT1-Serial0]link-protocol ppp
[RT1-Serial0]ppp authentication-mode chap
[RT1-Serial0]ip address 10.1.1.1
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
13
Chapter 4
2. Configuration on RT2:
[RT2]interface Serial 0
[RT2-Serial0]link-protocol ppp
[RT2-Serial0]ppp chap user huawei
[RT2-Serial0]ppp chap password cipher hello
[RT2-Serial0]ip address 10.1.1.2 30
4.3.3 Verification
Use PING to check whether the configuration on the routers is correct.
[RT1ping 10.1.1.2
PING 10.1.1.2: 56 data bytes, press CTRL_C to break
Reply from 10.1.1.2: bytes=56 Sequence=1 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=2 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=3 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=4 ttl=255 time=31 ms
Reply from 10.1.1.2: bytes=56 Sequence=5 ttl=255 time=31 ms
10.1.1.2 ping statistics
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/31/31 ms
14
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 5
FR Basic Configuration
Configuration DLCI
15
Chapter 5
FR Basic Configuration
2. Configuration on RT2:
[RT2-Serial0/0/1]link-protocol fr ietf
[RT2-Serial0/0/1] undo fr inarp
\\disable Inverse
ARP
[RT2-Serial0/0/1]fr interface-type dte
[RT2-Serial0/0/1]fr dlci 100
[RT2-Serial0/0/1]ip address 10.1.1.2 30
[RT2-Serial0/0/1]fr map ip 10.1.1.1 100
In frame relay, the two sides in communication are classified into user side
and network side. The user side is called DTE, and the network side is
called DCE. As shown in the figure, Interfaces need to be configured with
these two formats according to their own positions in the network.
2. Configuration on RT2:
[RT2-Serial0/0/1]link-protocol fr ietf
[RT2-Serial0/0/1]fr interface-type dte
[RT2-Serial0/0/1]ip address 10.1.1.2 30
[RT2-Serial0/0/1]fr inarp
16
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 5
FR Basic Configuration
5.3.3 Verification
1. Check the status of each FR interface, including the interface type,
physical status and link layer protocol status.
[RT1]display fr interface
Serial0/0/1, DCE, physical up, protocol up
2. Check the physical interface status, protocol status, IP address, link layer
encapsulation type and standard.
[RT2]display interface Serial 0/0/1
Serial0/0/1 current state : UP
Line protocol current state : UP
Description
3. Check the address mapping table between network address and Frame
Relay address.
[RT1]display fr map-info
Map Statistics for interface Serial0/0/1 (DCE)
DLCI = 100, IP 10.1.1.2, Serial0/0/1
create time = 2007/01/25 13:57:33, status = ACTIVE
encapsulation = ietf, vlink = 3
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
17
Chapter 6
18
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Chapter 6
2. Configuration on RT1
[RT1-Serial0/0/0]link-protocol fr ietf
[RT1-Serial0/0/0]fr interface-type dce
[RT1-Serial0/0/0]fr dlci 100
[RT1-Serial0/0/1]link-protocol fr ietf
[RT1-Serial0/0/1]fr interface-type nni
[RT1-Serial0/0/1]fr dlci 200
\\Enable Frame-Relay Switching
[RT1] fr switching
\\Configure the switching PVC number of Frame-Relay//
[RT1] fr switch 1 interface Serial0/0/0 dlci 100 interface
Serial0/0/1 dlci 200
3. Configuration on RT2
[RT2-Serial0/0/0]link-protocol fr ietf
[RT2-Serial0/0/0]fr interface-type dce
[RT2-Serial0/0/0]fr dlci 300
[RT2-Serial0/0/1]link-protocol fr ietf
[RT2-Serial0/0/1]fr interface-type nni
[RT2-Serial0/0/1]fr dlci 200
//Enable Frame-Relay Switching Function
[RT2] fr switching
//Configure the switching PVC number of Frame-Relay //
[RT2] fr switch 2 interface Serial0/0/1 dlci 200 interface
Serial0/0/0 dlci 300
4. Configuration on RT4
[RT4-Serial0/0/0]link-protocol fr ietf
[RT4-Serial0/0/0]fr interface-type dte
[RT4-Serial0/0/0]ip address 10.1.1.2 30
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
19
Chapter 6
Note:
To Use FR switching function, you need to
1.
2.
6.3.2 Verification
1. After the configuration, use the display fr switch-table all command to
check the information of frame relay switch table in the router.
[RT1]dis fr switch-table all
Total PVC switch records:1
PVC-Name
Status
Interface(Dlci) <----->
Interface(Dlci)
1
Active
Serial0/0/0(100)
Serial0/0/1(200)
Status
Interface(Dlci) <----->
Interface(Dlci)
2
Active
Serial0/0/1(200)
Serial0/0/0(300)
20
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Section 5
Firewall Tech. Laboratory Guide
Table of Contents
Table of Contents
Lab Description .................................................................................................................2
Introduction................................................................................................................2
Version ......................................................................................................................2
Objectives..................................................................................................................2
Tasks.........................................................................................................................2
References ................................................................................................................2
Chapter 1 Eudemon Security Policy..................................................................................3
1.1 Networking and Service Description ...................................................................3
1.2 Configuration Flow ..............................................................................................3
1.3 Configuration and Verification .............................................................................4
Chapter 2 Basic Configuration of NAT ..............................................................................6
2.1 Networking and Service Description ...................................................................6
2.2 Configuration Flow ..............................................................................................6
2.3 Configuration and Verification .............................................................................7
2.4 FAQ .....................................................................................................................8
Chapter 3 The Application of NAT Server .......................................................................... 9
3.1 Networking and Service Description .................................................................... 9
3.2 Configuration Flow ..............................................................................................10
3.3 Configuration and Verification .............................................................................10
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Lab Description
Lab Description
Introduction
This Lab Guide describes the technical theory and basic operations about
how Huawei Eudemon firewall applies the ACL, defending attacks and
backup technology HRP to ensure uninterrupted service of the default
firewall, so that the network can provide interrupted service.
Version
This Guide is applicable to VRP versions 3.30.
Objectives
z
NAT configuration
Tasks
References
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Two interfaces are used in the firewall: Ethernet 0/0/0 in Trust zone and
Ethernet 0/0/1 in Untrust zone.
PC1 is located in the Trust Zone; PC2 is located in the Untrust Zone.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Configure PC
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
4. Deploy the ACL rule to filter interzone traffic; Pay attention to the
direction.
[Eudemon-interzone-trust-untrust] packet-filter 2000 inbound
5. After deploy the policy, try to ping from PC2 to PC1. PC2 can ping PC1
because the access from untrust zone to trust zone is permitted by the
deployed security policy.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
packet-filter
2001
outbound
[Eudemon-interzone-trust-untrust]nat
outbound
2001
address-group 1
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
2.3.2 Verification
1. PC1 ping PC2 till manual termination with parameter -t.
2. Check the session table to get more information about NAT translation.
[Eudemon]display firewall session table
icmp:192.168.0.2:768[202.168.0.6:12889]-->202.168.0.7:768
icmp:202.168.0.7:768<--192.168.0.2:768
icmp:192.168.0.1:768<--192.168.0.2:768
NBT datagram:202.168.0.255:138<--202.168.0.7:138
2.4 FAQ
QPC1 and PC2 are belonging to different network segments. PC2 can
receive ICMP message from PC1 as PC1 has configured gateway
address. But how can PC1 receive ICMP message from PC2 which has
no gateway address?
A: This is one of the advantages of NAT, which guarantees the
confidentiality of NAT users. PC2 does not know that the users who access
to it are in the network of 192.168.0.0, but only see 202.168.0.6, which is in
the same network segment with itself. Thus, there is no need of the gateway.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Configure Eudemon NAT Server address and bind with FTP Server.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
Configure PC
Configure ACL
10
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
[Eudemon-Ethernet0/0/0]quit
[Eudemon]interface ethernet 0/0/1
[Eudemon-Ethernet0/0/1]ip address 202.168.0.1 24
[Eudemon-Ethernet0/0/1]quit
[Eudemon]firewall zone trust
[Eudemon-zone-trust]add interface ethernet 0/0/0
[Eudemon-zone-trust]quit
[Eudemon]firewall zone untrust
[Eudemon-zone-untrust]add interface ethernet 0/0/1
[Eudemon-zone-untrust]quit
2. Configure ACL
[Eudemon]acl 2001
[Eudemon-acl-basic-2]rule permit source 202.168.0.0 0.0.0.255
[Eudemon]firewall interzone trust untrust
[Eudemon-interzone-trust-untrust]packet-filter 2001 inbound
3.3.2 Verification
1. PC1 can access to ftp server 202.168.0.6 and carry out data transfering
service.
C
Copyright2010
Huawei Technologies Co.Ltd. , All Rights Reserved.
11