Professional Documents
Culture Documents
HCNA-HNTD V2.0 Intermediate Lab Manual (March 17,2014) PDF
HCNA-HNTD V2.0 Intermediate Lab Manual (March 17,2014) PDF
m
o
c
With any Huawei Career Certification, you have the privilege on http://learning.huawei.com/en to enjoy:
.
i
e
Methods to get the E-learning privilege : submit Huawei Account and email being used for Huawei Account
w
a
u
h
.
g
registration to Learning@huawei.com .
Content: Huawei product training material and Huawei career certification training material
MethodLogon http://learning.huawei.com/en and enter HuaWei Training/Classroom Training ,then you can
r
a
e
download training material in the specific training introduction page.
l
3 Priority to participate in Huawei Online Open Class(LVC) //
: all ICT technical domains like R&S, UC&C, Security,
ContentThe Huawei career certification training covering
p
tprofessional instructors
Storage and so on, which are conducted by Huawei
t
h
MethodThe plan and participate method please refer to LVC Open Courses Schedule
:
s
4Learning Tool: eNSP
e
c
eNSP (Enterprise Network Simulation r
Platform) is a graphical network simulation tool which is developed by
u
Huawei and free of charge. eNSP
o mainly simulates enterprise routers, switches as close to the real hardware as
s
it possible, which makes the e
lab practice available and easy without any real device.
R
In addition, Huawei has built up Huawei Technical Forum which allows candidates to discuss technical issues with
g
Huawei experts , share n
exam experiences with others or be acquainted with Huawei Products(
i
n
http://support.huawei.com/ecommunity/
r
a
Le
e TECHNOLOGIES CO., LTD. Huawei Confidential
HUAWEI
1
r
o
n
i
n
n
e
/
e
r
Mo
Huawei Certification
HCNA-HNTD
INTERMEDIATE
u
h
.
Huawei Networking Technology and Device
g
n
i
Lab Guide
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
s
Re
g
n
ni
r
a
e
e
/
m
i
e
aw
o
c
.
e
r
Mo
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
:
p
tt
Huawei Certification
:
s
eNetworking Technology and Device
HCNA-HNTD Huawei
c
r
u
o Intermediate Lab Guide
s
Re
Version 2.0
g
n
i
n
r
a
Le
o
c
.
e
/
m
e
r
Mo
e
/
m
certification, and addresses the need for the development of quality engineers that
are capable of supporting enterprise networks in the face of an ever changing ICT
industry. The Huawei certification portfolio for routing and switching (R&S) is
i
e
aw
comprised of three levels to support and validate the growth and value of customer
skills and knowledge in routing and switching technologies.
u
h
.
g
n
The Huawei Certified Network Associate (HCNA) certification validates the skills
i
n
ar
e
l
//
networks, along with the capability to implement services and features within
existing enterprise networks, to effectively support true industry operations.
:
p
tt
HCNA certification covers fundamental skills for TCP/IP, routing, switching and
related IP network technologies, together with Huawei data communications
products, and skills for versatile routing platform (VRP) operation and
management.
c
r
u
o
s
e
R
:
s
e
g
n
i
n
r
a
Le
network security, high availability and QoS, as well as application of the covered
technologies in Huawei products.
The Huawei Certified Internet Expert (HCIE-R&S) certification is designed to imbue
engineers with a variety of IP network technologies and proficiency in maintenance,
for the diagnosis and troubleshooting of Huawei products, to equip engineers with
in-depth competency in the planning, design and optimization of large-scale IP
networks.
o
c
.
e
r
Mo
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
Le
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
i
e
aw
e
r
Mo
Reference Icons
Router
L3 Switch
L2 Switch
Ethernet link
e
/
m
Cloud
u
h
.
g
n
Serial link
i
e
aw
i
n
ar
e
l
//
In order to ensure that that the configuration given in this lab is supported on all
devices, it is recommended that the following device models and VRP versions
be used:
Identifier
R1
R2
c
r
u
o
s
e
R
AR 2220
VRP version
AR 2220
AR 2220
S1
S5700-28C-EI-24S
S2
S5700-28C-EI-24S
S3
S3700-28TP-EI-AC
S4
S3700-28TP-EI-AC
ng
R3
i
n
r
a
e
L
:
s
e
Device Model
:
p
tt
o
c
.
e
r
Mo
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
Le
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
i
e
aw
e
r
Mo
HCNA-HNTD Content
CONTENTS
CHAPTER 1 ETHERNET AND VLAN ...................................................................................................... 1
LAB 1-1 ETHERNET INTERFACE AND LINK CONFIGURATION ................................................................................ 1
LAB 1-2 VLAN CONFIGURATION................................................................................................................ 10
LAB 1-3 GVRP CONFIGURATION ............................................................................................................... 21
o
c
.
i
e
aw
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
g
n
i
Le
n
r
a
HC Series
HUAWEI TECHNOLOGIES
Page1
e
/
m
e
r
Mo
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
Le
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
Learning Objectives
As a result of this lab section, you should achieve the following tasks:
u
h
.
g
n
i
e
aw
i
n
ar
Topology
e
l
//
:
s
e
:
p
tt
c
r
u
o
s
Scenario e
R
g
As a n
network administrator of an existing enterprise network, it has been
i that the connections between the switches be used more effectively
requested
n
arby preparing the switches to support link aggregation before establishing
Figure 1.1 Ethernet link aggregation topology
Le
manual link aggregation, for which the media between the switches are to be
configured as member links.
HC Series
HUAWEI TECHNOLOGIES
Page1
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Perform basic configuration on the Ethernet switches.
Auto-negotiation is enabled on Huawei switch interfaces by default. The rate
and duplex mode of G0/0/9 and G0/0/10 on S1 and S2 are to be set manually.
Change the system name and view detailed information for G0/0/9 and
G0/0/10 on S1.
<Quidway>system-view
[Quidway]sysname S1
u
h
.
g
n
i
n
ar
i
e
aw
e
l
//
:
p
tt
: AUTO
:
s
e
c
r
u
o
s
e
R
70,Multicast
6643714,Jumbo
5011357
0,Giants
0,Throttles
0,DropEvents
0,Symbols
Ignoreds
0,Frames
Discard
Jabbers
Runts
ng
ni
Alignments
ar
Le
69,Total Error
Broadcast
Collisions
5009016
Late Collisions :
0,ExcessiveCollisions :
Buffers Purged :
Discard
5,Total Error
Page2
345,Multicast
6642808,Jumbo
0,Deferreds
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
: 0.01%
e
/
m
o
c
.
i
e
aw
u
h
.
g
n
: AUTO
i
n
ar
e
l
//
Broadcast
CRC
Jabbers
Runts
Alignments
Ignoreds
Discard
c
r
u
o
s
e
R
:
:
115,Multicast
5009062
3,Giants
0,Throttles
0,DropEvents
0,Symbols
0,Frames
:
p
tt
6642648,Jumbo
:
s
e
218,Total Error
g
n
i
Collisions
:
:
245,Multicast
Late Collisions :
n
r
a
Buffers Purged :
Le
Discard
5011284
0,ExcessiveCollisions :
6643751,Jumbo
0,Deferreds
0
107,Total Error
: 0.01%
Set the rate of G0/0/9 and G0/0/10 on S1 to 100 Mbit/s and configure them to
work in full duplex mode. Before changing the interface rate and duplex mode,
disable auto-negotiation.
HC Series
HUAWEI TECHNOLOGIES
Page3
e
r
Mo
HCNA-HNTD
e
/
m
[S1-GigabitEthernet0/0/10]speed 100
o
c
.
[S1-GigabitEthernet0/0/10]duplex full
i
e
aw
Set the rate of G0/0/9 and G0/0/10 on S2 to 100 Mbit/s and configure them to
work in full duplex mode.
u
h
.
g
n
<Quidway>system-view
[Quidway]sysname S2
[S2]interface GigabitEthernet 0/0/9
i
n
ar
e
l
//
[S2-GigabitEthernet0/0/9]quit
[S2]interface GigabitEthernet 0/0/10
:
p
tt
:
s
e
Confirm that the rate and duplex mode of G0/0/9 and G0/0/10 have been set
on S1.
c
r
u
o
s
e
R
ng
Switch Port,PVID :
i
n
r
a
e
L
: AUTO
output omitted
Page4
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
: AUTO
i
e
aw
output omitted
u
h
. G0/0/9
Create Eth-Trunk 1 on S1 and S2. Delete the default configuration from
g
and G0/0/10 on S1 and S2, and then add G0/0/9 and G0/0/10 to n
Eth-Trunk 1.
i
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
s
Re
g
n
i the Eth-Trunk configuration.
Verify
n
ar
Step 2 Configure manual link aggregation.
[S1]interface Eth-Trunk 1
[S1-Eth-Trunk1]quit
[S1-GigabitEthernet0/0/9]eth-trunk 1
[S1-GigabitEthernet0/0/9]quit
[S2-GigabitEthernet0/0/9]eth-trunk 1
[S2-GigabitEthernet0/0/9]quit
[S2-GigabitEthernet0/0/10]eth-trunk 1
Le
[S1]display eth-trunk 1
---------------------------------------------------------------------------PortName
GigabitEthernet0/0/9
HC Series
Status
Weight
Up
HUAWEI TECHNOLOGIES
Page5
e
r
Mo
HCNA-HNTD
GigabitEthernet0/0/10
Up
[S2]display eth-trunk 1
Eth-Trunk1's state information is:
WorkingMode: NORMAL
e
/
m
---------------------------------------------------------------------------PortName
GigabitEthernet0/0/9
Status
o
c
.
Weight
Up
i
e
w
The greyed lines in the preceding information indicate that the Eth-Trunk works
a
u
properly.
h
.
g
Step 3 Configuring Link Aggregation in Static LACP n
Mode
i
n
r
Delete the configurations from G0/0/9 and G0/0/10 on S1
and S2.
a
e
l
/
/
:
p
t
t
h
:
s
e
c
r
u
o
s
e
R
Create Eth-Trunk 1 and set the load balancing mode of the Eth-Trunk to static
g
LACP n
mode.
i
n
ar
GigabitEthernet0/0/10
Up
[S1-GigabitEthernet0/0/9]undo eth-trunk
[S1-GigabitEthernet0/0/9]quit
[S1-GigabitEthernet0/0/10]undo eth-trunk
[S2]interface GigabitEthernet 0/0/9
[S2-GigabitEthernet0/0/9]undo eth-trunk
[S2-GigabitEthernet0/0/9]quit
[S2-GigabitEthernet0/0/10]undo eth-trunk
Le
[S1]interface Eth-Trunk 1
[S1-Eth-Trunk1]mode lacp-static
[S1-Eth-Trunk1]quit
[S1]interface GigabitEthernet 0/0/9
[S1-GigabitEthernet0/0/9]eth-trunk 1
[S1-GigabitEthernet0/0/9]quit
[S1]interface GigabitEthernet 0/0/10
[S1-GigabitEthernet0/0/10]eth-trunk 1
Page6
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
[S2]interface Eth-Trunk 1
[S2-Eth-Trunk1]mode lacp-static
[S2-Eth-Trunk1]quit
[S2]interface GigabitEthernet 0/0/9
[S2-GigabitEthernet0/0/9]eth-trunk 1
[S2-GigabitEthernet0/0/9]interface GigabitEthernet 0/0/10
[S2-GigabitEthernet0/0/10]eth-trunk 1
e
/
m
o
c
.
Verify that the LACP-static mode has been enabled on the two links.
[S1]display eth-trunk
Eth-Trunk1's state information is:
Local:
u
h
.
g
n
LAG ID: 1
WorkingMode: STATIC
Least Active-linknumber: 1
Max Active-linknumber: 8
Operate status: up
i
e
aw
i
n
ar
e
l
//
---------------------------------------------------------------------------ActorPortName
Status
GigabitEthernet0/0/9
Selected 100M
GigabitEthernet0/0/10
Selected 100M
32768
:
p
tt
32768
Partner:
289
10111100 1
10
289
10111100 1
---------------------------------------------------------------------------ActorPortName
SysPri
SystemID
GigabitEthernet0/0/9
32768
4c1f-cc45-aacc
:
s
e
289
10111100
c
r
uon S1 to 100 to ensure S1 remains the Actor.
Set the system priority
o
s
e
R
g of the interface and determine active links on S1.
Set the
priority
n
i
n
ar
GigabitEthernet0/0/10
32768
4c1f-cc45-aacc
32768
10
289
10111100
Le
HC Series
HUAWEI TECHNOLOGIES
Page7
e
r
Mo
HCNA-HNTD
WorkingMode: STATIC
Least Active-linknumber: 1
Max Active-linknumber: 8
Operate status: up
e
/
m
---------------------------------------------------------------------------ActorPortName
Status
i
e
aw
GigabitEthernet0/0/9
Selected 100M
100
289
10111100 1
GigabitEthernet0/0/10
Selected 100M
100
10
289
10111100 1
u
h
.
g
n
Partner:
---------------------------------------------------------------------------
i
n
ar
ActorPortName
SysPri
SystemID
GigabitEthernet0/0/9
32768
4c1f-cc45-aacc 32768
289
10111100
GigabitEthernet0/0/10
32768
4c1f-cc45-aacc 32768
10
289
10111100
e
l
//
[S2]display eth-trunk 1
:
p
tt
WorkingMode: STATIC
:
s
e
Least Active-linknumber: 1
c
r
u
o
s
e
R
Operate status: up
Max Active-linknumber: 8
Number Of Up Port In Trunk: 2
---------------------------------------------------------------------------ActorPortName
Status
GigabitEthernet0/0/9
Selected 100M
32768
289
10111100 1
GigabitEthernet0/0/10
Selected 100M
32768
10
289
10111100 1
g
n
i
Partner:
----------------------------------------------------------------------------
ea
rn
ActorPortName
SysPri
GigabitEthernet0/0/9
100
4c1f-cc45-aace
100
289
10111100
GigabitEthernet0/0/10
100
4c1f-cc45-aace
100
10
289
10111100
SystemID
Final Configuration
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
Page8
o
c
.
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
sysname S1
#
lacp priority 100
#
interface Eth-Trunk1
mode lacp-static
#
e
/
m
interface GigabitEthernet0/0/9
o
c
.
eth-trunk 1
lacp priority 100
undo negotiation auto
speed 100
#
u
h
.
g
n
interface GigabitEthernet0/0/10
eth-trunk 1
lacp priority 100
i
n
ar
e
l
//
#
return
:
p
tt
[S2]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S2
#
c
r
u
o
s
e
R
interface Eth-Trunk1
mode lacp-static
#
:
s
e
interface GigabitEthernet0/0/9
eth-trunk 1
g
n
i
n
r
a
#
Le
interface GigabitEthernet0/0/10
eth-trunk 1
undo negotiation auto
speed 100
#
return
HC Series
HUAWEI TECHNOLOGIES
Page9
i
e
aw
e
r
Mo
HCNA-HNTD
u
h
.
g
n
Topology
i
e
aw
i
n
ar
e
l
//
g
n
i
Scenario
c
r
u
o
s
e
R
:
s
e
:
p
tt
The
n enterprise network currently operates in a single broadcast domain
r
a resulting in a large amount of traffic being flooded to all network nodes. It is
Le
required that the administrator attempt to control the flow of traffic at the link
layer by implementing VLAN solutions. The VLAN solutions are to be applied
to switches S1 and S2.
Page10
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 2. For those continuing from previous labs, begin at step 2.
o
c
.
u
h
.
g
n
[S1-Eth-Trunk1]mode lacp-static
[S1-Eth-Trunk1]quit
[S1]interface GigabitEthernet0/0/9
i
e
aw
i
n
ar
[S1-Gigabitethernet0/0/9]eth-trunk 1
[S1-Gigabitethernet0/0/9]interface GigabitEthernet0/0/10
[S1-Gigabitethernet0/0/10]eth-trunk 1
e
l
//
:
p
tt
<Quidway>system-view
[Quidway]sysname S2
[S2]interface eth-trunk 1
:
s
e
[S2-Eth-Trunk1]mode lacp-static
c
r
u interfaces and establish a VLAN trunk.
Step 2 Disable unused
o
s
e
Unused interfaces
must be disabled to ensure test result accuracy. In this lab,
R
interfaces
Ethernet 0/0/1 and Ethernet 0/0/23 on S3 and Ethernet0/0/14 on S4
g
nbe shut down.
need to
i
n
r
a
[S2-Eth-Trunk1]trunkport GigabitEthernet 0/0/10
Le
<Quidway>system-view
[S3-Ethernet0/0/1]quit
[S3]interface Ethernet 0/0/23
[S3-Ethernet0/0/23]shutdown
HC Series
e
/
m
HUAWEI TECHNOLOGIES
Page11
e
r
Mo
HCNA-HNTD
<Quidway>system-view
Enter system view, return user view with Ctrl+Z.
[Quidway]sysname S4
[S4]interface Ethernet 0/0/14
[S4-Ethernet0/0/14]shutdown
The link type of a switch port interface is hybrid by default. Configure the port
link-type for Eth-Trunk 1 to become a trunk port. Additionally, allow all VLANS
to be permitted over the trunk port.
[S1]interface Eth-Trunk 1
[S1-Eth-Trunk1]port link-type trunk
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
:
p
tt
Use S3, R1, R3, and S4 as non-VLAN aware hosts. There are two methods to
create VLANs, and two methods to bind interfaces to the created VLANs, S1
and S2 are used to demonstrate the two methods. All interfaces associated
with hosts should be configured as access ports.
:
s
On S1, associate interface Gigabit
Ethernet 0/0/13 with VLAN 3, and interface
e
c
Gigabit Ethernet 0/0/1 with VLAN 4.
r
u
On S2, associate interface
Gigabit Ethernet 0/0/2 with VLAN4, and Gigabit
o
s
Ethernet 0/0/24 with VLAN 2.
Re
g
n
i
n
ar
[S1]interface GigabitEthernet0/0/13
[S1-GigabitEthernet0/0/13]quit
Le
[S1]interface GigabitEthernet0/0/1
[S1-vlan3]vlan 4
[S1-vlan4]port GigabitEthernet0/0/1
Page12
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
[S2]vlan batch 2 to 4
[S2]interface GigabitEthernet 0/0/3
[S2-GigabitEthernet0/0/3]port link-type access
[S2-GigabitEthernet0/0/3]port default vlan 4
[S2-GigabitEthernet0/0/3]quit
[S2]interface GigabitEthernet 0/0/24
[S2-GigabitEthernet0/0/24]port link-type access
e
/
m
o
c
.
Verify that the VLAN configuration has been correctly applied to S1 and S2.
<S1>display vlan
The total number of vlans is : 4
u
h
.
g
n
i
e
aw
---------------------------------------------------------------------------U: Up;
D: Down;
TG: Tagged;
MP: Vlan-mapping;
UT: Untagged;
ST: Vlan-stacking;
#: ProtocolTransparent-vlan;
i
n
ar
*: Management-vlan;
---------------------------------------------------------------------------VID Type
e
l
//
Ports
---------------------------------------------------------------------------1
common
:
p
tt
UT:GE0/0/2(U) GE0/0/3(U)
GE0/0/4(U)
GE0/0/5(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(D)
GE0/0/12(D)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/22(U)
GE0/0/23(U)
GE0/0/24(D)
GE0/0/21(U)
c
r
u
o
s
e
R
:
s
e
Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common UT:GE0/0/13(U)
common UT:GE0/0/1(U)
TG:Eth-Trunk1(U)
g
n
i
TG:Eth-Trunk1(U)
output omitted
n
r
a
Le
HC Series
HUAWEI TECHNOLOGIES
Page13
e
r
Mo
HCNA-HNTD
<S2>display vlan
The total number of vlans is : 4
---------------------------------------------------------------------------U: Up;
D: Down;
MP: Vlan-mapping;
#: ProtocolTransparent-vlan;
TG: Tagged;
UT: Untagged;
ST: Vlan-stacking;
*: Management-vlan;
---------------------------------------------------------------------------VID Type
---------------------------------------------------------------------------1
common
UT:GE0/0/1(U) GE0/0/2(U)
GE0/0/4(U)
GE0/0/5(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(U)
GE0/0/12(U)
GE0/0/13(U)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(D)
GE0/0/22(D)
GE0/0/23(D)
Eth-Trunk1(U)
2
TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common UT:GE0/0/3(U)
i
e
aw
i
n
ar
common UT:GE0/0/24(U)
u
h
.
g
n
e
l
//
TG:Eth-Trunk1(U)
:
p
t of the interfaces to each created
The highlighted entries confirm the binding
t
VLAN. All VLANs are permitted overh
the trunk (TG) port Eth-Trunk 1.
:
s
e
Step 4 Configure IP addressing
for each VLAN.
c
r
u on hosts, R1, S3, R3, and S4 as part of the respective
o
Configure IP addresses
sport interfaces on switches cannot be configured with IP
VLANs. Physical
e
R configure the native management interface Vlanif1 with
addresses, therefore
g for the switch.
the IP address
n
i
n
ar
output omitted
<Huawei>system-view
Le
[Huawei]sysname R1
[R1]interface GigabitEthernet0/0/1
Page14
HUAWEI TECHNOLOGIES
HC Series
e
/
m
o
c
.
Ports
e
r
Mo
HCNA-HNTD
<Huawei>system-view
[Huawei]sysname R3
[R3]interface GigabitEthernet0/0/2
[R3-GigabitEthernet0/0/2]ip address 10.0.4.3 24
[S4]interface vlanif 1
e
/
m
i
e
Use the ping command. R1 and R3 in VLAN 4 should be able to communicatew
a
with one another. Devices in other VLANs should be unable to communicate.
u
h
.
g
n
i
n
r
a
e
l
/
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
o
c
.
[R1]ping 10.0.4.3
Le
You may wish to also try between R1 and S3, and between R3 and S4.
HC Series
HUAWEI TECHNOLOGIES
Page15
e
r
Mo
HCNA-HNTD
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
:
p
tt
[S2-GigabitEthernet0/0/3]quit
[S2]interface GigabitEthernet 0/0/24
:
s
e
c
r
u vlan command will ensure frames received from the
The port hybrid pvid
o
s the appropriate VLAN tag. Frames received from VLAN 2
host are tagged with
e
or 4 will be untagged
R at the interface before being forwarded to the host.
g
n
Usei
the ping command to verify that R3 in VLAN 4 is still reachable.
n
ar
[S2-GigabitEthernet0/0/24]port hybrid pvid vlan 2
Le
<R1>ping 10.0.4.3
Page16
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
Use the ping command to test whether S4 in VLAN 2 is now reachable from R1
in VLAN 4.
o
c
.
<R1>ping 10.0.4.4
PING 10.0.4.4: 56 data bytes, press CTRL_C to break
Reply from 10.0.4.4: bytes=56 Sequence=1 ttl=255 time=41 ms
Reply from 10.0.4.4: bytes=56 Sequence=2 ttl=254 time=2 ms
u
h
.
g
n
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
i
e
aw
i
n
ar
e
l
//
:
p
toriginating from VLAN 4 are now able
In using the hybrid port link type, frames
t
h whilst still being unable to reach the
to be received by VLAN 2 and vice versa,
host address of 10.0.4.2 in VLAN
:3.
s
e
c
r
u
Final Configuration
o
s
Re
g
n
i
n
ar
round-trip min/avg/max = 2/10/41 ms
[R1]display current-configuration
[V200R003C00SPC200]
#
sysname R1
Le
interface GigabitEthernet0/0/1
HC Series
HUAWEI TECHNOLOGIES
e
/
m
Page17
e
r
Mo
HCNA-HNTD
e
/
m
shutdown
o
c
.
#
interface Ethernet0/0/23
shutdown
#
return
u
h
.
g
n
[S1]display current-configuration
#
i
n
ar
e
l
//
#
vlan batch 2 to 4
#
:
p
tt
:
s
e
c
r
u
o
s
e
R
mode lacp-static
#
interface GigabitEthernet0/0/1
port hybrid pvid vlan 4
g
n
i
interface GigabitEthernet0/0/9
n
r
a
eth-trunk 1
Le
#
interface GigabitEthernet0/0/10
eth-trunk 1
lacp priority 100
undo negotiation auto
speed 100
Page18
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
#
interface GigabitEthernet0/0/13
port link-type access
port default vlan 3
#
return
e
/
m
[S2]display current-configuration
o
c
.
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 2 4
u
h
.
g
n
#
interface Eth-Trunk1
port link-type trunk
i
n
ar
e
l
//
#
interface GigabitEthernet0/0/3
port hybrid pvid vlan 4
:
p
tt
c
r
u
o
s
e
R
:
s
e
interface GigabitEthernet0/0/10
eth-trunk 1
g
n
i
speed 100
#
n
r
a
interface GigabitEthernet0/0/24
Le
#
interface NULL0
#
user-interface con 0
user-interface vty 0 4
#
return
HC Series
HUAWEI TECHNOLOGIES
Page19
i
e
aw
e
r
Mo
HCNA-HNTD
[R3]display current-configuration
[V200R003C00SPC200]
#
sysname R3
#
interface GigabitEthernet0/0/2
e
/
m
o
c
.
#
return
[S4]display current-configuration
#
u
h
.
g
n
i
n
ar
interface Vlanif1
ip address 10.0.4.4 255.255.255.0
e
l
//
#
interface Ethernet0/0/14
shutdown
:
p
tt
#
return
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
Le
Page20
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
Configuration of GVRP.
Setting of the GVRP registration mode.
o
c
.
Topology
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u contains multiple switches which are expected to be
The enterprise network
o
s VLANs are required to be applied and removed as
regularly managed.
e
Rall switches however this tends to be a laborious task for the
necessary on
administrator
and often configuration mistakes occur due to human error. The
g
n
administrator
wishes to simplify the VLAN management process and has
i
n that GVRP be enabled on all switchs and the registration mode on
requested
r
a the interfaces be set.
Scenario
Le
HC Series
HUAWEI TECHNOLOGIES
Page21
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
[Quidway]sysname S1
[S1]interface GigabitEthernet 0/0/9
[S1-GigabitEthernet0/0/9]shutdown
[S1-GigabitEthernet0/0/9]quit
u
h
.
g
n
[Quidway]sysname S2
e
l
//
:
p
tt
[Quidway]sysname S3
c
r
u
o
s
e
R
[S3-Ethernet0/0/23]shutdown
:
s
e
i
e
aw
i
n
ar
<Quidway>system-view
<Quidway>system-view
<Quidway>system-view
[Quidway]sysname S4
[S4-Ethernet0/0/14]shutdown
g
n
Stepi2 Clean up the previous configuration
n
r
a Remove the unsed VLANs and disable the Eth-Trunk interface on S1 and S2.
Le
Page22
e
/
m
o
c
.
<Quidway>system-view
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
e
aw
Info: This operation may take a few seconds. Please wait for a moment...succeeded.
[S4]undo interface Vlanif 1
i
n
r
a
Step 3 Configure trunk links between the switches.
e
l
/
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Info: This operation may take a few seconds. Please wait for a moment...succeeded.
[S3-Ethernet0/0/13]quit
Le
HC Series
HUAWEI TECHNOLOGIES
Page23
e
r
Mo
HCNA-HNTD
e
/
m
[S3]gvrp
[S3]interface Ethernet 0/0/13
o
c
.
[S3-Ethernet0/0/13]gvrp
[S3-Ethernet0/0/13]quit
[S3]interface Ethernet 0/0/1
[S3-Ethernet0/0/1]gvrp
u
h
.
g
n
[S2]gvrp
[S2]interface GigabitEthernet 0/0/24
i
e
aw
i
n
ar
[S2-Gigabitethernet0/0/24]gvrp
[S4]gvrp
e
l
//
[S4]interface Ethernet0/0/24
[S4-Ethernet0/0/24]gvrp
:
p
tt
[S4-Ethernet0/0/24]quit
[S4]interface Ethernet 0/0/1
[S4-Ethernet0/0/1]gvrp
:
s
e
Create VLAN 100 on S1, VLAN 200 on S2 and VLAN 2 on S1, S2, S3 and S4.
c
r
u
o
s
e
R
g
n
i
Run the display gvrp statistics command on S3 and S4 to view the GVRP
statistics.
n
r
a
Le
: Enabled
: 0
: 5489-98ec-f012
: Normal
Page24
: Enabled
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
: 0
: 4c1f-cc45-aace
: Normal
: Enabled
: 0
: 781d-ba99-d977
: Normal
e
/
m
o
c
.
: Enabled
: 0
: 4c1f-cc45-aacc
: Normal
u
h
.
g
n
i
e
aw
i
n
ar
The registration type is set as normal by default. Use the display vlan
command to verify the VLAN configuration on S3 and S4.
e
l
//
[S3]display vlan
:
p
tt
---------------------------------------------------------------------------U: Up;
D: Down;
MP: Vlan-mapping;
TG: Tagged;
UT: Untagged;
ST: Vlan-stacking;
:
s
e
#: ProtocolTransparent-vlan;
*: Management-vlan;
---------------------------------------------------------------------------VID Type
c
r
u
o
s
e
R
Ports
---------------------------------------------------------------------------1
common
ng
ni
r
a
e
2
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
TG:Eth0/0/1(U) Eth0/0/13(U)
HC Series
HUAWEI TECHNOLOGIES
Page25
e
r
Mo
HCNA-HNTD
[S4]display vlan
The total number of vlans is : 4
---------------------------------------------------------------------------U: Up;
D: Down;
TG: Tagged;
MP: Vlan-mapping;
UT: Untagged;
ST: Vlan-stacking;
#: ProtocolTransparent-vlan;
*: Management-vlan;
---------------------------------------------------------------------------VID Type
o
c
.
---------------------------------------------------------------------------1
common
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(D)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(U)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
TG:Eth0/0/1(U) Eth0/0/24(U)
u
h
.
g
n
i
e
aw
i
n
ar
e
l
S3 and S4 are learning VLAN 100 and VLAN 200/
dynamically, but only in one
/
direction. VLAN 2 has been statically defined.
Create VLAN 200 on S1 and
:
p
VLAN 100 on S2 to enable 2-way propagation.
t
t
h
:to verify the configuration.
s
Run the display vlan command
e
c
r
u
o
s
Re
g
n
i
n
ar
200 dynamic TG:Eth0/0/24(U)
output omitted
[S1]vlan 200
[S2]vlan 100
[S3]display vlan
output omitted
VID Type
Ports
---------------------------------------------------------------------------1
common
Le
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
TG:Eth0/0/1(U) Eth0/0/13(U)
Page26
e
/
m
Ports
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
[S4]display vlan
output omitted
VID Type
Ports
---------------------------------------------------------------------------1
common
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(D)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(U)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
TG:Eth0/0/1(U) Eth0/0/24(U)
e
/
m
i
e
aw
u
h
.
g
n added to
The highlighted entries indicate the interfaces that have been
i
n
VLAN100 and VLAN200 on both S3 and S4.
r
ea
Step 2 Change the registration type for thelinterfaces
/
/
Change the registration type of Ethernet 0/0/1:on S3 to fixed. The same steps
p
can be performed on Ethernet 0/0/1 of S4.
t
ht
:
s
e command on S3 and S4 to view the changes.
c
Run the display gvrp statistics
r
u
o
s
Re
g
n
i
n
ar
200 dynamic TG:Eth0/0/1(U) Eth0/0/24(U)
output omitted
Le
GVRP status
: Enabled
: 12
: 5489-98ec-f012
: Fixed
HC Series
HUAWEI TECHNOLOGIES
Page27
o
c
.
e
r
Mo
HCNA-HNTD
Run the display vlan command to view the effect of the fixed registration type.
[S3]display vlan
output omitted
VID Type
Ports
---------------------------------------------------------------------------1
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
common TG:Eth0/0/1(U)
u
h
.
g
n
Eth0/0/13(U)
e
/
m
i
e
aw
i
n
ar
The highlighted entries show that interface Ethernet 0/0/1 is not in registering
dynamic VLANs 100 and 200.
e
l
//
:
p
tt
:
s
e
Run the display gvrp statistics command to view the changes to GVRP.
c
r
u
o
s
e
R
: Enabled
: 18
ng
: 5489-98ec-f012
i
n
rThe GVRP registration type is set to forbidden on the Ethernet 0/0/1 interface.
GVRP registration type
: Forbidden
a
e
L
Page28
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
r
Mo
HCNA-HNTD
Run the display vlan command to view the effect of the forbidden registration.
[S3]display vlan
The total number of vlans is : 4
output omitted
VID Type
Ports
---------------------------------------------------------------------------1
common
common
UT:Eth0/0/1(U) Eth0/0/2(D)
Eth0/0/3(D)
Eth0/0/4(D)
Eth0/0/5(D)
Eth0/0/6(D)
Eth0/0/7(D)
Eth0/0/8(D)
Eth0/0/9(D)
Eth0/0/10(D)
Eth0/0/11(D)
Eth0/0/12(D)
Eth0/0/13(U)
Eth0/0/14(D)
Eth0/0/15(D)
Eth0/0/16(D)
Eth0/0/17(D)
Eth0/0/18(D)
Eth0/0/19(D)
Eth0/0/20(D)
Eth0/0/21(D)
Eth0/0/22(D)
Eth0/0/23(D)
Eth0/0/24(D)
GE0/0/1(D)
GE0/0/2(D)
GE0/0/3(D)
GE0/0/4(D)
TG:Eth0/0/13(U)
u
h
.
g
n
e
/
m
i
e
aw
i
n
Forbidden mode only allows VLAN1 pass over interfacerEthernet 0/0/1, all
a
other VLANS are restricted.
e
l
/
/
Final Configuration
:
p
t
ht
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
200 dynamic TG:Eth0/0/13(U)
[S1]dis current-configuration
#
gvrp
interface Eth-Trunk1
shutdown
Le
mode lacp-static
#
interface GigabitEthernet0/0/1
port hybrid untagged vlan 2 4
#
interface GigabitEthernet0/0/9
shutdown
HC Series
HUAWEI TECHNOLOGIES
Page29
o
c
.
e
r
Mo
HCNA-HNTD
eth-trunk 1
lacp priority 100
undo negotiation auto
speed 100
#
interface GigabitEthernet0/0/10
shutdown
e
/
m
eth-trunk 1
o
c
.
u
h
.
g
n
i
n
ar
#
return
e
l
//
[S2]dis current-configuration
#
:
p
tt
c
r
u
o
s
e
R
:
s
e
interface Eth-Trunk1
shutdown
g
n
i
n
r
a
#
Le
interface GigabitEthernet0/0/3
port hybrid untagged vlan 2 4
#
interface GigabitEthernet0/0/9
shutdown
eth-trunk 1
undo negotiation auto
speed 100
#
Page30
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
interface GigabitEthernet0/0/10
shutdown
eth-trunk 1
undo negotiation auto
speed 100
#
interface GigabitEthernet0/0/24
e
/
m
o
c
.
u
h
.
g
n
[S3]display current-configuration
#
!Software Version V100R006C00SPC800
i
n
ar
sysname S3
#
e
l
//
vlan batch 2
#
gvrp
:
p
tt
#
interface Ethernet0/0/1
port link-type trunk
c
r
u
o
s
e
R
:
s
e
interface Ethernet0/0/13
port link-type trunk
g
n
i
gvrp
#
n
r
a
interface Ethernet0/0/23
Le
shutdown
return
[S4]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S4
#
HC Series
HUAWEI TECHNOLOGIES
Page31
i
e
aw
e
r
Mo
HCNA-HNTD
vlan batch 2
#
gvrp
#
interface Ethernet0/0/1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
e
/
m
gvrp
o
c
.
u
h
.
g
n
interface Ethernet0/0/24
port link-type trunk
port trunk allow-pass vlan 2 to 4094
i
n
ar
gvrp
#
e
l
//
return
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
Le
Page32
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
Topology
u
h
.
g
n
e
/
m
i
e
aw
i
n
ar
e
l
//
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
n
r
a Scenario
Le
HC Series
HUAWEI TECHNOLOGIES
Page33
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
Configure the system name for R1, R3 and S1. Configure the IP address
10.0.4.1/24 on interface Gigabit Ethernet 0/0/1.
<Huawei>system-view
u
h
.
g
n
i
n
ar
i
e
aw
e
l
//
:
p
tt
<Quidway>system-view
[Quidway]sysname S1
:
s
e
c
r
u
o
s
e
R
Remove the IP address 10.0.4.3 from R3, and disable the swich interfaces
between S1 and S3 and S2 and S4 respectively.
[R3]interface GigabitEthernet 0/0/2
g
n
i
[R3-GigabitEthernet0/0/2]undo ip address
Le
n
r
a
[S1]undo gvrp
Warning: All information about the GVRP will be deleted . Continue?[Y/N]:y
Info: This operation may take a few seconds. Please wait for a moment...done.
[S1]interface GigabitEthernet 0/0/13
[S1-GigabitEthernet0/0/13]undo port trunk allow-pass vlan 2 to 4094
[S1-GigabitEthernet0/0/13]shutdown
[S1-GigabitEthernet0/0/13]quit
[S1]interface GigabitEthernet 0/0/1
Page34
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
Info: This operation may take a few seconds. Please wait for a moment...done.
[S2]interface GigabitEthernet 0/0/24
[S2-GigabitEthernet0/0/24]undo port trunk allow-pass vlan 2 to 4094
[S2-GigabitEthernet0/0/24]shutdown
[S2-GigabitEthernet0/0/24]quit
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
Info: This operation may take a few seconds. Please wait for a moment...done.
[S3]undo gvrp
:
p
tt
:
s
e
c
r
u
o
s
e
R
[S3-Ethernet0/0/13]quit
g
n
i
[S4]undo gvrp
n
r
a
Le
Info: This operation may take a few seconds. Please wait for a moment...done.
[S4]interface Ethernet 0/0/24
[S4-Ethernet0/0/24]undo port trunk allow-pass vlan 2 to 4094
HC Series
HUAWEI TECHNOLOGIES
Page35
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
i
e
aw
u
h
.
g
n
[S1]vlan batch 4 8
Info: This operation may take a few seconds. Please wait for a moment...done.
i
n
ar
e
l
//
[S1-GigabitEthernet0/0/1]quit
[S1]interface GigabitEthernet0/0/3
:
p
tt
h
Set interface Gigabit Ethernet 0/0/2
: as a trunk link for VLANs 4 and 8.
s
e
c
r
u
o
s
e
R
Step 5 Configure VLAN routing through the sub-interface of R2
g
n
i sub-interfaces GigabitEthernet0/0/1.1 and GigabitEthernet0/0/1.3,
Configure
n
arto act as the gateway of VLAN 4, and act as the gateway of VLAN 8.
[S1]interface GigabitEthernet0/0/2
Le
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
[R2]interface GigabitEthernet0/0/1.1
[R2-GigabitEthernet0/0/1.1]ip address 10.0.4.254 24
[R2-GigabitEthernet0/0/1.1]dot1q termination vid 4
Page36
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
<R1>ping 10.0.8.1
PING 10.0.8.1: 56 data bytes, press CTRL_C to break
Request time out
Request time out
u
h
.
g
n
i
n
ar
e
l
//
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
:
p
tt
:
s
e
c
r
Test connectivity between
u R1 and R3 again.
o
s
e
R
g
n
i
n
ar
<R1>ping 10.0.8.1
Le
HC Series
HUAWEI TECHNOLOGIES
Page37
i
e
aw
e
r
Mo
HCNA-HNTD
[R2]display ip routing-table
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------Routing Tables: Public
Destinations : 10
Routes : 10
Cost Flags
NextHop
Interface
10.0.4.0/24
Direct 0
10.0.4.254
GigabitEthernet0/0/1.1
10.0.4.254/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.1
10.0.4.255/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.1
10.0.8.0/24
Direct 0
10.0.8.254
GigabitEthernet0/0/1.3
10.0.8.254/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.3
10.0.8.255/32
Direct 0
127.0.0.1
GigabitEthernet0/0/1.3
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
:
p
tt
[R1]display current-configuration
#
sysname R1
#
c
r
u
o
s
e
R
:
s
e
i
n
ar
e
l
//
Final Configuration
[V200R003C00SPC200]
u
h
.
g
n
interface GigabitEthernet0/0/1
g
n
i
user-interface con 0
ea
rn
authentication-mode password
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
#
return
Page38
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
[R2]display current-configuration
[V200R003C00SPC200]
#
sysname R2
#
interface GigabitEthernet0/0/1
#
e
/
m
interface GigabitEthernet0/0/1.1
o
c
.
u
h
.
g
n
i
n
ar
#
user-interface con 0
e
l
//
authentication-mode password
set authentication password
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
:
p
tt
user-interface vty 0 4
#
return
c
r
u
o
s
e
R
:
s
e
[R3]dis current-configuration
[V200R003C00SPC200]
#
sysname R3
#
g
n
i
interface GigabitEthernet0/0/1
ip address 10.0.8.1 255.255.255.0
n
r
a
Le
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
#
return
HC Series
HUAWEI TECHNOLOGIES
Page39
i
e
aw
e
r
Mo
HCNA-HNTD
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
vlan batch 4 8
#
e
/
m
interface GigabitEthernet0/0/1
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
#
user-interface con 0
user-interface vty 0 4
:
p
tt
#
return
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
Le
Page40
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
Topology
u
h
.
g
n
e
/
m
i
e
aw
i
n
ar
e
l
//
:
s
e
:
p
tt
c
r
u
o
s
e
Scenario R
g of layer three switches into the enterprise network opened up
n
The introduction
i for streamlining the current VLAN routing configuration. The
opportunities
n
arnetwork administrator has been given the task to implement VLAN routing
Figure 5.5 Layer 3 switching topology
Le
using only the layer three switches to support communication between the
VLANs in the network as displayed in the topology. VLANs should be capable
of inter VLAN communication. Additionally S1 and S2 are expected to
communicate over a Layer 3 for which routing protocol support is required.
HC Series
HUAWEI TECHNOLOGIES
Page41
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
Configure R1 with the address 10.0.4.1/24 on interface Gigabit Ethernet 0/0/1.
Establish an Eth-Trunk beween S1 an S2. Disable any unnecessary interfaces
on S1 and S2 to S3 and S4.
<Huawei>system-view
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
<Quidway>system-view
[Quidway]sysname S1
[S1]interface Eth-Trunk 1
:
s
e
[S1-Eth-Trunk1]mode lacp-static
c
r
u
o
s
e
R
g
n
i
[S1-GigabitEthernet0/0/10]eth-trunk 1
n
r
a
<Quidway>system-view
Le
[Quidway]sysname S2
[S2]interface Eth-Trunk 1
[S2-Eth-Trunk1]mode lacp-static
Page42
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
<Quidway>system-view
[Quidway]sysname S4
[S4]interface Ethernet 0/0/14
[S4-Ethernet0/0/14]shutdown
u
h
.
g
ndevices.
Remove the VLAN routing configuration and sub-interfaces on the
i
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Step 2 Clean up the previous configuration
i
e
aw
[R3-GigabitEthernet0/0/1]undo ip address
[R3-GigabitEthernet0/0/1]quit
Info: This operation may take a few seconds. Please wait for a moment...done.
[S1]interface GigabitEthernet 0/0/2
Le
[S1-GigabitEthernet0/0/13]undo shutdown
[S2]interface GigabitEthernet0/0/24
[S2-GigabitEthernet0/0/24]undo shutdown
HC Series
HUAWEI TECHNOLOGIES
Page43
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
i
e
aw
Info: This operation may take a few seconds. Please wait for a moment...done.
u
h
.
g
n
[S2]vlan batch 3 to 7
Info: This operation may take a few seconds. Please wait for a moment...done.
i
n
ar
e
l
//
[S1]display vlan
The total number of vlans is : 6
:
p
tt
output omitted
VID Type
Ports
---------------------------------------------------------------------------1
common UT:GE0/0/1(U)
GE0/0/5(U)
GE0/0/13(D)
GE0/0/14(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(U)
GE0/0/22(U)
GE0/0/23(U)
GE0/0/24(D)
Eth-Trunk1(U)
c
r
u
o
s
e
R
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
GE0/0/8(D)
common TG:Eth-Trunk1(U)
rn
7
g
n
i
GE0/0/4(U)
GE0/0/12(D)
GE0/0/15(D)
a
e
L
:
s
e
GE0/0/3(U)
GE0/0/7(D)
GE0/0/11(D)
GE0/0/2(D)
GE0/0/6(D)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
output omitted
Page44
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
[S2]display vlan
The total number of vlans is : 6
output omitted
VID Type
Ports
---------------------------------------------------------------------------1
common UT:GE0/0/1(U)
GE0/0/2(D)
GE0/0/3(U)
GE0/0/4(U)
GE0/0/5(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/11(U)
GE0/0/12(U)
GE0/0/13(U)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(D)
GE0/0/22(D)
GE0/0/23(D)
GE0/0/24(D)
Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
GE0/0/8(D)
u
h
.
g
n
e
/
m
i
e
aw
i
n
r
a
Add interfaces Gigabit Ethernet 0/0/1 and 0/0/13 of S1 to
VLAN 4 and VLAN 3
e 0/0/3 and G0/0/24 to
respectively. For S2, add interfaces Gigabit Ethernet
l
/
VLAN 6 and VLAN 7 respectively.
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Step 4 Set the Eth-Trunk link between S1 and S2 with PVID 5.
[S1]interface Eth-Trunk 1
[S1-GigabitEthernet0/0/1]quit
Le
[S2-Eth-Trunk1]quit
HC Series
HUAWEI TECHNOLOGIES
Page45
o
c
.
e
r
Mo
HCNA-HNTD
<S1>display vlan
The total number of vlans is : 6
output omitted
VID Type
Ports
---------------------------------------------------------------------------1
common UT:GE0/0/2(D)
GE0/0/3(U)
GE0/0/4(U)
GE0/0/5(U)
GE0/0/6(D)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(D)
GE0/0/12(D)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(U)
GE0/0/22(U)
GE0/0/23(U)
GE0/0/24(D)
Eth-Trunk1(U)
3
common UT:GE0/0/13(U)
TG:Eth-Trunk1(U)
u
h
.
g
n
common UT:GE0/0/1(U)
TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
e
l
//
<S2>display vlan
:
p
tt
:
s
e
---------------------------------------------------------------------------1
c
r
u
o
s
e
R
common UT:GE0/0/1(U)
GE0/0/6(D)
Le
GE0/0/4(U)
GE0/0/5(U)
GE0/0/7(D)
GE0/0/8(D)
GE0/0/11(U)
GE0/0/12(U)
GE0/0/13(U)
GE0/0/14(D)
GE0/0/15(D)
GE0/0/16(D)
GE0/0/17(D)
GE0/0/18(D)
GE0/0/19(D)
GE0/0/20(D)
GE0/0/21(D)
GE0/0/22(D)
GE0/0/23(D)
Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
n
r
a
4
g
n
i
GE0/0/2(D)
common TG:Eth-Trunk1(U)
common TG:Eth-Trunk1(U)
common UT:GE0/0/3(U)
TG:Eth-Trunk1(U)
common UT:GE0/0/24(U)
TG:Eth-Trunk1(U)
Page46
HUAWEI TECHNOLOGIES
HC Series
o
c
.
i
e
aw
i
n
ar
output omitted
VID Type
e
/
m
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
[S2]interface Vlanif 5
[S2-Vlanif5]ip address 10.0.5.2 24
[S2-Vlanif5]interface Vlanif 6
[S2-Vlanif6]ip address 10.0.6.254 24
[S2-Vlanif6]interface Vlanif 7
[S2-Vlanif7]ip address 10.0.7.254 24
i
n
ar
i
e
aw
e
l
Step 6 IP addressing and default routes/
for R1, R3, S3 and S4.
/
:
p
IP addresses on a switch much be assigned to a Vlanif, where Vlanif1 is a
t
common (untagged) Vlanif. InterfacestEthernet 0/0/13 of S3 and Ethernet
0/0/24 of S4 should be associatedh with the common VLAN1. R1 should
: 10.0.4.1/24.
already be configured with the address
s
e
c
r
u
o
s
Re
g
n
i
n
ar
[R1]ip route-static 0.0.0.0 0.0.0.0 10.0.4.254
[S3]interface Vlanif 1
Le
HC Series
HUAWEI TECHNOLOGIES
Page47
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
i
e
aw
:
p
tt
c
r
u
o
s
e
R
:
s
e
g
n
Thei
connectivity between R1 and R3 fails. Use the tracert command to
n
troubleshoot
the fault:
r
a
100.00% packet loss
Le
[R1]tracert 10.0.6.3
4 ms 4 ms
* *
Page48
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
According to the command output, R1 has sent data packets to the destination
address 10.0.6.3, but the gateway at 10.0.4.254 responds that the network is
unreachable.
Check whether the network is unreachable on the gateway (S1).
[S1]display ip routing-table
Route Flags: R - relay, D - download to fib
e
/
m
----------------------------------------------------------------------------
o
c
.
Routes : 8
Proto Pre Cost
Flags NextHop
Interface
u
h
.
g
n
10.0.3.0/24
Direct
10.0.3.254 Vlanif3
10.0.3.254/32
Direct
127.0.0.1
InLoopBack0
10.0.4.0/24
Direct
10.0.4.254
Vlanif4
10.0.4.254/32
Direct
127.0.0.1
InLoopBack0
10.0.5.0/24
Direct
10.0.5.1
Vlanif5
10.0.5.1/32
Direct
127.0.0.0/8
Direct
127.0.0.1/32
Direct
e
l
//
:
p
tt
i
e
aw
i
n
ar
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
According to the command output, S1 does not have a route to the network
segment 10.0.6.0 because the network segment is not directly connected to
S1. In addition, no static route or dynamic routing protocol has been configured
to advertise the routes.
c
r
u
o
s
e
R
:
s
e
[S1-ospf-1]area 0
g
n
i
n
r
a
[S2]ospf
Le
[S2-ospf-1]area 0
[S2-ospf-1-area-0.0.0.0]network 10.0.0.0 0.255.255.255
HC Series
HUAWEI TECHNOLOGIES
Page49
e
r
Mo
HCNA-HNTD
After the configuration, wait until S1 and S2 exchange OSPF routes and
complete the link state database, then view the resulting routing table of S1.
[S1]display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 10
Destination/Mask
e
/
m
Routes : 10
Flags NextHop
10.0.3.0/24
Direct 0
10.0.3.254
Vlanif3
10.0.3.254/32
Direct 0
127.0.0.1
InLoopBack0
10.0.4.0/24
Direct 0
10.0.4.254
Vlanif4
10.0.4.254/32
Direct 0
127.0.0.1
InLoopBack0
10.0.5.0/24
Direct 0
10.0.5.1
Vlanif5
10.0.5.1/32
Direct 0
127.0.0.1
InLoopBack0
10.0.6.0/24
OSPF
10
10.0.5.2
Vlanif5
10.0.7.0/24
OSPF
10
10.0.5.2
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
Vlanif5
:
p
tt
S1 has learned two routes using OSPF. Test connectivity between R1 and R3.
[R1]ping 10.0.6.3
:
s
e
c
r
u
o
s
e
R
g
n
i
ea
rn
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/4/11 ms
Page50
HUAWEI TECHNOLOGIES
o
c
.
Interface
HC Series
e
r
Mo
HCNA-HNTD
[R1]ping 10.0.7.4
PING 10.0.7.4: 56 data bytes, press CTRL_C to break
Reply from 10.0.7.4: bytes=56 Sequence=1 ttl=253 time=30 ms
Reply from 10.0.7.4: bytes=56 Sequence=2 ttl=252 time=2 ms
Reply from 10.0.7.4: bytes=56 Sequence=3 ttl=252 time=3 ms
Reply from 10.0.7.4: bytes=56 Sequence=4 ttl=252 time=2 ms
Reply from 10.0.7.4: bytes=56 Sequence=5 ttl=252 time=2 ms
e
/
m
o
c
.
u
h
.
g
n
Final Configuration
i
n
ar
[R1]display current-configuration
[V200R003C00SPC200]
e
l
//
#
sysname R1
:
p
tt
#
interface GigabitEthernet0/0/1
ip address 10.0.4.1 255.255.255.0
#
:
s
e
c
r
u
o
s
e
R
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
#
g
n
i
return
Le
n
r
a
[S1]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S1
#
vlan batch 3 to 7
#
HC Series
HUAWEI TECHNOLOGIES
Page51
i
e
aw
e
r
Mo
HCNA-HNTD
interface Vlanif3
ip address 10.0.3.254 255.255.255.0
#
interface Vlanif4
ip address 10.0.4.254 255.255.255.0
#
interface Vlanif5
e
/
m
o
c
.
#
interface Eth-Trunk1
port link-type trunk
port trunk allow-pass vlan 2 to 4094
mode lacp-static
u
h
.
g
n
#
interface GigabitEthernet0/0/1
port link-type access
i
n
ar
e
l
//
interface GigabitEthernet0/0/9
eth-trunk 1
lacp priority 100
:
p
tt
c
r
u
o
s
e
R
:
s
e
interface GigabitEthernet0/0/13
g
n
i
n
r
a
#
Le
ospf 1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
user-interface con 0
user-interface vty 0 4
#
return
Page52
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
[S2]display current-configuration
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 3 to 7
e
/
m
o
c
.
interface Vlanif5
ip address 10.0.5.2 255.255.255.0
#
interface Vlanif6
ip address 10.0.6.254 255.255.255.0
u
h
.
g
n
#
interface Vlanif7
ip address 10.0.7.254 255.255.255.0
i
n
ar
#
interface Eth-Trunk1
e
l
//
:
p
tt
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 6
#
c
r
u
o
s
e
R
:
s
e
interface GigabitEthernet0/0/9
eth-trunk 1
g
n
i
interface GigabitEthernet0/0/10
eth-trunk 1
n
r
a
Le
speed 100
interface GigabitEthernet0/0/24
port link-type access
port default vlan 7
#
ospf 1
area 0.0.0.0
network 10.0.0.0 0.255.255.255
HC Series
HUAWEI TECHNOLOGIES
Page53
i
e
aw
e
r
Mo
HCNA-HNTD
#
user-interface con 0
user-interface vty 0 4
#
return
[S3]display current-configuration
e
/
m
o
c
.
u
h
.
g
n
#
interface Ethernet0/0/23
shutdown
i
n
ar
#
ip route-static 0.0.0.0 0.0.0.0 10.0.3.254
e
l
//
#
user-interface con 0
user-interface vty 0 4
:
p
tt
#
return
:
s
e
[S4]display current-configuration
#
c
r
u
o
s
e
R
g
n
i
n
r
a
#
Le
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
Page54
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
interface Vlanif1
ip address 10.0.7.4 255.255.255.0
#
interface Ethernet0/0/14
shutdown
#
ip route-static 0.0.0.0 0.0.0.0 10.0.7.254
e
/
m
o
c
.
user-interface con 0
user-interface vty 0 4
#
return
u
h
.
g
n
i
n
ar
e
l
//
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
Le
HC Series
HUAWEI TECHNOLOGIES
Page55
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
Learning Objectives
As a result of this lab section, you should achieve the following tasks:
u
h
.
g
n
i
e
aw
i
n
ar
Topology
e
l
//
:
s
e
:
p
tt
c
r
u
o
s enterprise business, multiple branch offices have been
As an expanding
e
established and
are to be part of the companys administrative domain. WAN
R
solutionsgare required and as the network administrator the company you have
n with establishing HDLC and PPP solutions at the edge router to
been tasked
i
bencarried over some service provider network, possibly MPLS, however the
r
a details of this have not been revealed to you since the service provider network
Scenario
Le
remains outside of the scope of your task. R2 is an edge router located in the
HQ, and R1 and R3 are located in branch offices. The HQ and branches need
to be established as a single administrative domain. Use HDLC and PPP on
the WAN links, and establish authentication as a simple security measure.
Page56
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
o
c
.
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
u
h
.
g
n
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R2
i
e
aw
i
n
ar
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
e
l
//
[Huawei]sysname R3
:
p
t the Ethernet interfaces to avoid
t
Remove the static routes to R2 and disable
h
creating alternative routes. Remove any unnecessary VLAN configuration.
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Step 2 Clean up the previous configuration
Le
HC Series
HUAWEI TECHNOLOGIES
e
/
m
Page57
e
r
Mo
HCNA-HNTD
e
/
m
[S2-GigabitEthernet0/0/3]quit
o
c
.
[S2]undo ospf 1
i
e
aw
u
h
Step 3 Configure serial interface IP addressing for R1, R2
. & R3
g
n
i
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
Step 4 Enable s
the HDLC protocol on the serial interfaces.
Re
g
n
i
n
ar
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
Le
[R2-Serial1/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R2-Serial1/0/0]quit
[R2]interface Serial 2/0/0
[R2-Serial2/0/0]link-protocol hdlc
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
Page58
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
After HDLC is enabled on the serial interfaces, view the serial interface status.
The displayed information for R1 should be used as an example.
e
/
m
o
c
.
u
h
.
g
n
: 2013-12-10 11:23:55
i
n
ar
e
l
//
:
p
tt
Broadcast:
0, Multicast:
Errors:
0, Runts:
Giants:
0, CRC:
Alignments:
0, Overruns:
Dribbles:
0, Aborts:
0, Frame Error:
c
r
u
o
s
e
R
No Buffers:
g
n
i
:
s
e
0
0
Collisions:
0, Deferred:
No Buffers:
rn
ea
Total Error:
HC Series
HUAWEI TECHNOLOGIES
Page59
i
e
aw
e
r
Mo
HCNA-HNTD
Test connectivity of the directly connected link after verifying that the physical
status and protocol status of the interface are Up.
<R2>ping 10.0.12.1
PING 10.0.12.1: 56 data bytes, press CTRL_C to break
Reply from 10.0.12.1: bytes=56 Sequence=1 ttl=255 time=44 ms
Reply from 10.0.12.1: bytes=56 Sequence=2 ttl=255 time=39 ms
e
/
m
o
c
.
u
h
.
g
n
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 39/40/44 ms
i
n
ar
[R2]ping 10.0.23.3
PING 10.0.23.3: 56 data bytes, press CTRL_C to break
i
e
aw
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
5 packet(s) received
g
n
i the RIP routing protocol to advertise the remote networks of R1 & R3
Enable
n
ar
Step 5 Configure RIPv2.
Le
[R1]rip
[R1-rip-1]version 2
[R1-rip-1]network 10.0.0.0
[R2]rip
[R2-rip-1]version 2
[R2-rip-1]network 10.0.0.0
Page60
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
[R3]rip
[R3-rip-1]version 2
[R3-rip-1]network 10.0.0.0
After the configuration is complete, check that all the routes have been learned.
Verify that corresponding routes are learned by RIP.
e
/
m
<R1>display ip routing-table
Route Flags: R - relay, D - download to fib
o
c
.
Proto
Routes : 8
Pre Cost
Flags NextHop
10.0.12.0/24
Direct 0
10.0.12.1
10.0.12.1/32
Direct 0
127.0.0.1
10.0.12.255/32 Direct 0
127.0.0.1
10.0.23.0/24
RIP
10.0.12.2
127.0.0.0/8
Direct 0
127.0.0.1
127.0.0.1/32
Direct 0
127.0.0.1
127.255.255.255/32 Direct 0
255.255.255.255/32 Direct 0
:
p
tt
100
:
s
e
u
h
.
g
n
Interface
Serial1/0/0
e
l
//
i
n
ar
Serial1/0/0
Serial1/0/0
Serial1/0/0
InLoopBack0
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
On R1, run the ping command to test connectivity between R1 and R3.
c
r
u
o
s
e
R
<R1>ping 10.0.23.3
g
n
i
n
r
a
Le
HC Series
HUAWEI TECHNOLOGIES
Page61
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
: 2013-12-10 11:23:55
i
e
aw
i
n
ar
e
l
//
:
p
The preceding information shows that S1/0/0
on R1 connects to a DCE cable
t
and the clock frequency is 64000 bit/s.tThe DCE controls the clock frequency
h
and bandwidth.
s:the link between R1 and R2 to 128000 bit/s.
Change the clock frequencyeon
c on the DCE, R1.
This operation must be performed
r
u
o
s
e
R
After theg
configuration is complete, view the serial interface status.
n
i
n
r
a
output omitted
[R1-Serial1/0/0]baudrate 128000
Le
: 2013-12-10 11:23:55
Page62
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
u
h
.
g
n
i
n
ar
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R2]interface Serial 1/0/0
e
l
//
[R2-Serial1/0/0]link-protocol ppp
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
:
p
tt
[R2-Serial1/0/0]quit
[R2]interface Serial 2/0/0
[R2-Serial2/0/0]link-protocol ppp
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R3]interface Serial 2/0/0
:
s
e
c
r
uis complete, test link connectivity.
After the configuration
o
s
e
R
g
n
i
n
ar
[R3-Serial2/0/0]link-protocol ppp
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
<R2>ping 10.0.12.1
Le
HC Series
HUAWEI TECHNOLOGIES
Page63
o
c
.
i
e
aw
Configure PPP between R1 and R2, as well as R2 and R3. Both ends of the
link must use the same encapsulation mode. If different encapsulation modes
are used, interfaces may display as Down.
e
r
Mo
HCNA-HNTD
<R2>ping 10.0.23.3
PING 10.0.23.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.23.3: bytes=56 Sequence=1 ttl=255 time=35 ms
Reply from 10.0.23.3: bytes=56 Sequence=2 ttl=255 time=40 ms
Reply from 10.0.23.3: bytes=56 Sequence=3 ttl=255 time=40 ms
Reply from 10.0.23.3: bytes=56 Sequence=4 ttl=255 time=40 ms
Reply from 10.0.23.3: bytes=56 Sequence=5 ttl=255 time=40 ms
e
/
m
o
c
.
u
h
.
g
n
i
e
aw
If the ping operation fails, check the interface status and whether the link layer
protocol type is correct.
i
n
ar
e
l
//
:
p
tt
:
s
e
: 2013-12-10 11:57:20
c
r
u
o
s
e
R
g
n
i
n
r
a Step 8 Check routing entry changes.
Le
Page64
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
Proto
e
/
m
Routes : 12
Pre Cost
Flags
NextHop
Interface
10.0.12.0/24
Direct 0
10.0.12.2
Serial1/0/0
10.0.12.1/32
Direct 0
10.0.12.1
Serial1/0/0
10.0.12.2/32
Direct 0
127.0.0.1
Serial1/0/0
10.0.12.255/32 Direct 0
127.0.0.1
Serial1/0/0
10.0.23.0/24
Direct 0
10.0.23.2
Serial2/0/0
10.0.23.2/32
Direct 0
127.0.0.1
Serial2/0/0
10.0.23.3/32
Direct 0
10.0.23.3
Serial2/0/0
10.0.23.255/32 Direct 0
127.0.0.1
Serial2/0/0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
:
s
e
i
n
ar
e
l
//
:
p
tt
D
u
h
.
g
n
i
e
aw
Think about the origin and functions of the two routes. Check the following
items:
c
r
u using HDLC or PPP when the IP addresses of
Can R1 and R2 communicate
o
S1/0/0 interfacess
on R1 and R2 are located on different network segments?
e
R
Step 9 Enable PAP authentication between R1 and R2.
g
n
i PAP authentication with R1 as the PPP PAP authenticator.
Configure
n
ar
If HDLC encapsulation is used, do these two routes exist?
Le
HC Series
HUAWEI TECHNOLOGIES
Page65
o
c
.
e
r
Mo
HCNA-HNTD
u
h
.
g
n
<R1>display debugging
PPP PAP packets debugging switch is on
<R1>system-view
i
e
aw
i
n
ar
e
l
//
[R1-Serial1/0/0]undo shutdown
:
p
tt
PPP Packet:
c
r
u
o
s
e
R
:
s
e
g
n
i
[R1-Serial1/0/0]return
n
r
a
Le
Page66
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
e
/
m
[R3-aaa]quit
o
c
.
u
h
.
g
n
i
e
aw
Serial2/0/0, authentication failed and PPP link was closed because CHAP was
i
n
ar
e
l
/ is unable to initialize.
The highlighted output indicates that authentication
/
:
p
Configure R2 as the CHAP client.
t
t
h
:
s
e
c
rcomplete, the interface changes to an Up state. The
After the configuration is
u
command output
o is as follows:
s
Re
g
n
i
n
ar
Serial2/0/0, LCP negotiation failed because the result cannot be accepted.
ping
<R2>ping 10.0.23.3
Le
HC Series
HUAWEI TECHNOLOGIES
Page67
e
r
Mo
HCNA-HNTD
e
/
m
Run the debugging ppp chap all and the terminal debugging commands to
display the debugging information.
[R2-Serial2/0/0]return
u
h
.
g
n
i
n
ar
<R2>display debugging
PPP CHAP packets debugging switch is on
e
l
//
i
e
aw
:
p
tt
:
s
e
c
r
u information is displayed:
The following debugging
o
s
e
R
g
n
i
n
ar
[R2-Serial2/0/0]undo shutdown
[R2-Serial2/0/0]
Le
16 Value: fc 9b 56 e1 53 e3 a6 26 1b 54 e5 e2 a1 ed 90 87
Name:
[R2-Serial2/0/0]
Dec 10 2013 09:10:38.710.2+00:00 R2 PPP/7/debug2:
PPP Event:
Page68
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
r
Mo
HCNA-HNTD
e
/
m
Value_Size: 16 Value: f9 54 1 69 30 59 a0 af 52 a1 1d de 85 77 27 6b
o
c
.
Name: huawei
[R2-Serial2/0/0]
Dec 10 2013 09:10:38.710.4+00:00 R2 PPP/7/debug2:
PPP State Change:
Serial2/0/0 CHAP : ListenChallenge --> SendResponse
u
h
.
g
n
[R2-Serial2/0/0]
Dec 10 2013 09:10:38.720.1+00:00 R2 PPP/7/debug2:
PPP Packet:
i
e
aw
i
n
ar
e
l
//
Message: Welcome to .
[R2-Serial2/0/0]
:
p
tt
PPP Event:
:
s
e
c
r
u information shows the key CHAP behavior. Disable
o
The highlighted debugging
s
the debugging e
process.
R
g
n
i
n
ar
PPP State Change:
[R2-Serial2/0/0]return
Le
HC Series
HUAWEI TECHNOLOGIES
Page69
e
r
Mo
HCNA-HNTD
Final Configuration
[R1]display current-configuration
[V200R003C00SPC200]
#
sysname R1
e
/
m
#
aaa
o
c
.
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
u
h
.
g
n
domain default_admin
i
n
ar
e
l
//
interface Serial1/0/0
link-protocol ppp
:
p
tt
c
r
u
o
s
e
R
network 10.0.0.0
#
:
s
e
user-interface con 0
authentication-mode password
set authentication password
g
n
i
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
n
r
a
user-interface vty 0 4
#
Le
return
[R2]display current-configuration
[V200R003C00SPC200]
#
sysname R2
#
Page70
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
interface Serial1/0/0
link-protocol ppp
ppp pap local-user huawei password cipher %$%$u[hr6d<JVHR@->T7xr1<$.iv%$%$
ip address 10.0.12.2 255.255.255.0
#
interface Serial2/0/0
link-protocol ppp
e
/
m
o
c
.
u
h
.
g
n
network 10.0.0.0
#
user-interface con 0
i
n
ar
authentication-mode password
set authentication password
e
l
//
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
user-interface vty 0 4
#
:
p
tt
return
[R3]display current-configuration
[V200R003C00SPC200]
#
sysname R3
#
aaa
c
r
u
o
s
e
R
:
s
e
authentication-scheme default
g
n
i
authorization-scheme default
accounting-scheme default
n
r
a
domain default
Le
domain default_admin
local-user admin password cipher %$%$=i~>Xp&aY+*2cEVcS-A23Uwe%$%$
HC Series
HUAWEI TECHNOLOGIES
Page71
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
authentication-mode password
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
Le
Page72
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
u
h
.
g
n
Topology
e
/
m
i
e
aw
i
n
ar
e
l
//
c
r
u
o
s
e
R
:
s
e
:
p
tt
g
n
i
Scenario
n enterprise network has existing frame relay virtual circuits between the HQ
r
The
a
Le
and some branch offices. A recent change in equipment requires that these
frame relay VC be re-established. The virtual circuits had been provided by the
service provider at the time the service was first implemented and it is the task
of the administrator to implement the frame relay configuration on the edge
routers for the HQ and branch offices. The administrator must configure frame
relay on the WAN links and perform mapping between the local DLCI and IP
addresses.
HC Series
HUAWEI TECHNOLOGIES
Page73
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
<Huawei>system-view
u
h
.
g
n
i
e
aw
i
n
ar
e
l
/
Step 2 Clean up the previous configuration.
/
:
p
t the HDLC & PPP networks.
Disable the serial interfaces used for establishing
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
[Huawei]sysname R3
Le
[R3-Serial2/0/0]shutdown
HUAWEI TECHNOLOGIES
e
/
m
o
c
.
<Huawei>system-view
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
[R1-Serial2/0/0]interface loopback 0
o
c
.
i
e
aw
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
u
h
.
g
n
i
n
ar
[R2-Serial3/0/0]interface loopback 0
[R2-LoopBack0]ip address 10.0.2.2 24
e
l
//
:
p
tt
Warning: The encapsulation protocol of the link will be changed. Continue? [Y/N]:y
[R3-Serial1/0/0]ip address 10.0.123.3 24
[R3-Serial1/0/0]undo fr inarp
:
s
e
[R3-Serial1/0/0]interface loopback 0
c
r
After the IP addresses
uare configured, test network connectivity.
o
s
e
R
g
n
i
n
ar
[R3-LoopBack0]ip address 10.0.3.3 24
<R1>ping 10.0.123.2
PING 10.0.123.2: 56
Le
HC Series
HUAWEI TECHNOLOGIES
Page75
e
r
Mo
HCNA-HNTD
<R1>ping 10.0.123.3
PING 10.0.123.3: 56
e
/
m
o
c
.
u
h
.
g
n
i
e
aw
Run the following commands to view the FR encapsulation information for the
R1 interfaces.
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
g
n
i
a
e
L
rn
Page76
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
u
h
.
g
n
[R1-rip-1]network 10.0.0.0
[R1-rip-1]undo summary
i
e
aw
i
n
ar
[R2]rip 1
[R2-rip-1]version 2
[R2-rip-1]network 10.0.0.0
e
l
//
[R2-rip-1]undo summary
:
p
tt
[R3]rip 1
[R3-rip-1]version 2
[R3-rip-1]network 10.0.0.0
[R3-rip-1]undo summary
:
s
e
View the routing tables on R1, R2, and R3 to check the learned routes.
c
r
u
o
s
e
R
ng
Destinations : 2
i
n
r
Routes : 2
a
e
L
Destinations : 2
Destination/Mask
Proto
Routes : 2
Pre Cost
Flags NextHop
Interface
10.0.2.0/24
RIP
100 1
10.0.123.2
Serial2/0/0
10.0.3.0/24
RIP
100 1
10.0.123.3
Serial2/0/0
HC Series
Routes : 0
HUAWEI TECHNOLOGIES
Page77
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
Routes : 2
e
/
m
Proto
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 1
10.0.123.1
Serial3/0/0
10.0.3.0/24
RIP
100 2
10.0.123.1
Serial3/0/0
u
h
.
g
n
i
e
aw
i
n
ar
Routes : 0
e
l
//
----------------------------------------------------------------------------
:
p
tt
Routes : 2
:
s
e
Routes : 2
c
r
u
o
s
e
R
Destination/Mask
Pre Cost
Flags NextHop
Interface
10.0.1.0/24
RIP
100 1
10.0.123.1
Serial1/0/0
10.0.2.0/24
RIP
100 2
10.0.123.1
Serial1/0/0
g
n
i
n
r
a
Destinations : 0
Routes : 0
Le
Page78
o
c
.
Routes : 2
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 63/64/68 ms
i
e
aw
i
n
ar
Perform the same test to network 10.0.2.2 of R2 from network 10.0.3.3 of R3.
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
g
n
i
The RIP routing protocol has enabled a route between the loopback interfaces
of R2 and R3 to be established via R1.
n
r
a
Le
HC Series
HUAWEI TECHNOLOGIES
Page79
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
i
e
aw
u
h
.
g
n with R2
The preceding test results indicate that R3 is unable to communicate
i
n the routes to
(and vice versa) when the serial interface is the source. Check
r
find out why R3 and R2 are disconnected. The procedure
for diagnosing this
a
e
fault is as follows:
l
/
View the R3 routing table and check whether any
route is destined for the IP
/
:
address 10.0.2.2.
p
t
If there is such a route, find out the next
t hop IP address of this route. Then
h
check whether R3 can reach the next hop and whether there is mapping
: and layer-2 PVCs.
between the layer-3 IP addresses
s
ehop and there is mapping between Layer-3 IP
If R3 can reach the next
c
rPVCs, check the devices on the route to determine
addresses and Layer-2
u
o route that can reach IP address 10.0.2.2, whether the
whether there is any
s
next hop of this
route is reachable, and whether there is mapping between
e
R
Layer-3 IP addresses and Layer-2 PVCs.
gis a route that can reach IP address 10.0.2.2 and there is mapping
If there
n
i Layer-3 IP addresses and Layer-2 PVCs, check R2 to determine
between
n
arwhether there is any route that reaches the destination IP address of the
0 packet(s) received
100.00% packet loss
Le
response packets and whether the next hop of this route is reachable.
If the next hop of this route is unreachable and the destination IP address of
the response packets is 10.0.123.3, R2 has the route that reaches this address
but there is no mapping between Layer-3 IP addresses and Layer-2 PVCs.
The following is the output of the commands used in the preceding fault
diagnosis procedure.
Page80
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
<R3>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 13
Destination/Mask
Routes : 13
Proto
Pre Cost
Flags NextHop
10.0.1.0/24
RIP
100 1
10.0.2.0/24
RIP
100 2
10.0.123.1
Serial1/0/0
10.0.3.0/24
Direct 0
10.0.3.3
LoopBack0
10.0.3.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.3.255/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.0/24
Direct 0
10.0.123.3
Serial1/0/0
10.0.123.1/32
Direct 0
10.0.123.1
Serial1/0/0
10.0.123.3/32
Direct 0
127.0.0.1
InLoopBack0
10.0.123.255/32 Direct 0
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct 0
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct 0
127.0.0.1
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
e
l
//
InLoopBack0
127.0.0.1
InLoopBack0
Interface
:
p
tt
10.0.123.1
e
/
m
u
h
.
g
n
i
e
aw
i
n
ar
:
s
e
c
r
u
o
s
e
R
g
n
i
Destinations : 14
Le
n
r
a
Destination/Mask
Routes : 14
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1
LoopBack0
10.0.1.1/32
Direct
127.0.0.1
InLoopBack0
10.0.1.255/32
Direct
127.0.0.1
InLoopBack0
10.0.2.0/24
RIP
100 1
10.0.123.2
Serial2/0/0
10.0.3.0/24
RIP
100 1
10.0.123.3
Serial2/0/0
10.0.123.0/24
Direct
10.0.123.1
Serial2/0/0
10.0.123.1/32
Direct
127.0.0.1
InLoopBack0
HC Series
Flags NextHop
HUAWEI TECHNOLOGIES
o
c
.
Serial1/0/0
Interface
Page81
e
r
Mo
HCNA-HNTD
10.0.123.2/32
Direct
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct
10.0.123.3
Serial2/0/0
10.0.123.255/32 Direct
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct 0
127.0.0.1
InLoopBack0
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
<R2>display ip routing-table
e
l
//
i
e
aw
Pre Cost
RIP
c
r
u
o
s
e
R
:
s
e
Flags NextHop
Interface
100 1
10.0.123.1
Serial3/0/0
10.0.2.2
LoopBack0
127.0.0.1
InLoopBack0
10.0.2.0/24
Direct
10.0.2.2/32
Direct
10.0.2.255/32
Direct
127.0.0.1
InLoopBack0
10.0.3.0/24
RIP
100 2
10.0.123.1
Serial3/0/0
10.0.123.0/24
Direct
10.0.123.2
Serial3/0/0
10.0.123.1/32
g
n
i
Direct
10.0.123.1
Serial3/0/0
10.0.123.2/32
Direct
127.0.0.1
InLoopBack0
10.0.123.255/32 Direct
127.0.0.1
InLoopBack0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
n
r
a
Le
Proto
:
p
tt
Routes : 13
Page82
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
i
e
w
The fault diagnosis results from step 2 indicate that communication fails since
a
u In
there is no virtual circuit between the frame relay interfaces on R2 andhR3.
. on
order to resolve this, configure a frame relay PVC between the interfaces
g
R2 and R3.
n
i
n
r
a
e
l
/
/
:
p
t
After the mapping has been configured
t between IP addresses and PVCs,
h
check the IP address-PVC mapping tables on R2 and R3 and detect network
:
connectivity.
s
e
c
r
u
o
s
Re
g
n
i
n
ar
o
c
.
Le
HC Series
HUAWEI TECHNOLOGIES
Page83
e
/
m
e
r
Mo
HCNA-HNTD
<R3>ping 10.0.2.2
PING 10.0.2.2: 56 data bytes, press CTRL_C to break
Reply from 10.0.2.2: bytes=56 Sequence=1 ttl=254 time=118 ms
Reply from 10.0.2.2: bytes=56 Sequence=2 ttl=254 time=123 ms
Reply from 10.0.2.2: bytes=56 Sequence=3 ttl=254 time=123 ms
Reply from 10.0.2.2: bytes=56 Sequence=4 ttl=254 time=123 ms
Reply from 10.0.2.2: bytes=56 Sequence=5 ttl=254 time=123 ms
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
Delete the RIP configurations referenced in step 2 and the frame relay
mapping between R2 and R3 that was established during step 3.
e
l
//
[R1]undo rip 1
:
p
tt
c
r
u
o
s
e
R
:
s
e
g
n
i
[R3]undo rip 1
n
r
a
[R3]
Le
Page84
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
After the basic parameters are set, OSPF cannot establish neighbor
adjacencies. When using frame relay for data link layer encapsulation, OSPF
will set the network type to NBMA by default. As a result, OSPF does not
support broadcasts, and therefore cannot automatically discover neighbors.
u
h
.
g
n
i
n
ar
Interfaces
Interface: 10.0.123.3 (Serial1/0/0)
Cost: 1562
State: DR
Type: NBMA
i
e
aw
e
l
//
MTU: 1500
Priority: 1
:
p
tt
DB Description
:
s
e
0
Link-State Req
Type
Hello
c
r
u
o
s
e
R
Link-State Update
Link-State Ack
OpaqueId: 0
Input
Output
PrevState: Waiting
Le
g
n
Stepi7 Configuring the NBMA environment.
n
r
a
HC Series
HUAWEI TECHNOLOGIES
Page85
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
[R1]ospf
[R1-ospf-1]peer 10.0.123.2
[R1-ospf-1]peer 10.0.123.3
[R1-ospf-1]interface Serial 2/0/0
[R1-Serial2/0/0]ospf dr-priority 255
[R2]ospf
e
/
m
[R2-ospf-1]peer 10.0.123.1
o
c
.
[R3]ospf
i
e
Optionally the DR priority for R2 and R3 can be set to 0 to force theirw
a
exemption from any DR election.
u
h
.
g
n
i
n
r
a
e
l
/
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
arIf R1 is not the designated router, reset the ospf process on all routers using
[R3-ospf-1]peer 10.0.123.1
State: DR
Type: NBMA
MTU: 1500
Priority: 255
Type
Hello
Input
Output
32
32
DB Description
29
Link-State Req
16
30
20
Link-State Update
Link-State Ack
OpaqueId: 0
PrevState: BDR
Le
Display the routing table to confirm that OSPF has been established over the
frame relay network.
Page86
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
<R1>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Routes : 14
Proto
Pre Cost
Direct
10.0.1.1
LoopBack0
10.0.1.1/32
Direct
127.0.0.1
LoopBack0
10.0.1.255/32
Direct
127.0.0.1
LoopBack0
10.0.2.2/32
OSPF
10
1562
10.0.123.2
Serial2/0/0
10.0.3.3/32
OSPF
10
1562
10.0.123.3
Serial2/0/0
10.0.123.0/24
Direct
10.0.123.1
Serial2/0/0
10.0.123.1/32
Direct
127.0.0.1
Serial2/0/0
10.0.123.2/32
Direct
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct
10.0.123.3
Serial2/0/0
10.0.123.255/32 Direct
127.0.0.1
Serial2/0/0
127.0.0.0/8
Direct
127.0.0.1
127.0.0.1/32
e
l
//
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
10.0.1.0/24
Flags NextHop
Direct
127.255.255.255/32 Direct
255.255.255.255/32 Direct
:
p
tt
D
Interface
u
h
.
g
n
e
/
m
i
e
aw
i
n
ar
:
s
e
c
r
u
o
s
e
R
g
n
i
n
r
a
5 packet(s) received
Le
HC Series
HUAWEI TECHNOLOGIES
Page87
o
c
.
e
r
Mo
HCNA-HNTD
e
/
m
[R1]ospf
[R1-ospf-1]undo peer 10.0.123.2
o
c
.
u
h
.
g
n
[R3]ospf
[R3-ospf-1]undo peer 10.0.123.1
i
e
aw
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
After setting the OSPF
network type, wait until the neighbor relationship is
u
o
established, then check the neighbor relationship and route information.
s
e
R
g
n
i
n
ar
<R1>display ospf peer brief
Le
---------------------------------------------------------------------------Area Id
Interface
Neighbor id
State
0.0.0.0
Serial2/0/0
10.0.2.2
Full
0.0.0.0
Serial2/0/0
10.0.3.3
Full
----------------------------------------------------------------------------
Page88
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
<R1>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Routes : 14
Proto
Pre Cost
Direct
10.0.1.1
LoopBack0
10.0.1.1/32
Direct
127.0.0.1
LoopBack0
10.0.1.255/32
Direct
127.0.0.1
LoopBack0
10.0.2.2/32
OSPF
10
1562
10.0.123.2
Serial2/0/0
10.0.3.3/32
OSPF
10
1562
10.0.123.3
Serial2/0/0
10.0.123.0/24
Direct
10.0.123.1
Serial2/0/0
10.0.123.1/32
Direct
127.0.0.1
Serial2/0/0
10.0.123.2/32
Direct
10.0.123.2
Serial2/0/0
10.0.123.3/32
Direct
10.0.123.3
Serial2/0/0
10.0.123.255/32 Direct
127.0.0.1
Serial2/0/0
127.0.0.0/8
Direct
127.0.0.1
127.0.0.1/32
e
l
//
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
10.0.1.0/24
Flags NextHop
Direct
127.255.255.255/32 Direct
255.255.255.255/32 Direct
:
s
e
Interface
u
h
.
g
n
e
/
m
i
e
aw
i
n
ar
:
p
tt
D
c
r
u
o
s
e
R
---------------------------------------------------------------------------Area Id
0.0.0.0
Interface
Neighbor id
State
Serial3/0/0
10.0.1.1
Full
----------------------------------------------------------------------------
g
n
i
<R2>display ip routing-table
n
r
a
Le
Routes : 14
Proto
Pre Cost
10.0.1.1/32
OSPF
10
1562
10.0.123.1
Serial3/0/0
10.0.2.0/24
Direct
10.0.2.2
LoopBack0
10.0.2.2/32
Direct
127.0.0.1
LoopBack0
HC Series
Flags NextHop
HUAWEI TECHNOLOGIES
Interface
Page89
o
c
.
e
r
Mo
HCNA-HNTD
10.0.2.255/32
Direct
127.0.0.1
LoopBack0
10.0.3.3/32
OSPF
10
3124
10.0.123.1
Serial3/0/0
10.0.123.0/24
Direct
10.0.123.2
Serial3/0/0
10.0.123.1/32
Direct
10.0.123.1
Serial3/0/0
10.0.123.2/32
Direct
127.0.0.1
Serial3/0/0
10.0.123.3/32
OSPF
10
3124
10.0.123.1
Serial3/0/0
10.0.123.255/32 Direct
127.0.0.1
Serial3/0/0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
u
h
.
g
n
e
/
m
i
e
aw
i
n
ar
---------------------------------------------------------------------------Area Id
Interface
Neighbor id
0.0.0.0
Serial1/0/0
10.0.1.1
e
l
//
State
Full
----------------------------------------------------------------------------
:
p
tt
<R3>display ip routing-table
Pre Cost
10.0.1.1/32
OSPF
10
1562
10.0.123.1
Serial1/0/0
10.0.2.2/32
OSPF
10
3124
10.0.123.1
Serial1/0/0
10.0.3.0/24
g
n
i
Direct
10.0.3.3
LoopBack0
10.0.3.3/32
Direct
127.0.0.1
LoopBack0
10.0.3.255/32
Direct
127.0.0.1
LoopBack0
10.0.123.0/24
Direct
10.0.123.3
Serial1/0/0
10.0.123.1/32
Direct
10.0.123.1
Serial1/0/0
10.0.123.2/32
OSPF
10
3124
10.0.123.1
Serial1/0/0
10.0.123.3/32
Direct
127.0.0.1
Serial1/0/0
10.0.123.255/32 Direct
127.0.0.1
Serial1/0/0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
n
r
a
Le
Routes : 14
c
r
u
o
s
e
R
Destination/Mask
:
s
e
Page90
Flags NextHop
HUAWEI TECHNOLOGIES
Interface
HC Series
o
c
.
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 50/54/60 ms
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
5 packet(s) received
0.00% packet loss
g
n
i
ea
rn
HC Series
HUAWEI TECHNOLOGIES
Page91
i
e
aw
e
r
Mo
HCNA-HNTD
Final Configuration
[R1]display current-configuration
[V200R003C00SPC200]
#
sysname R1
e
/
m
#
interface Serial2/0/0
o
c
.
link-protocol fr
undo fr inarp
fr map ip 10.0.123.2 102 broadcast
fr map ip 10.0.123.3 103 broadcast
u
h
.
g
n
i
n
ar
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
e
l
//
#
ospf 1 router-id 10.0.1.1
:
p
tt
area 0.0.0.0
network 10.0.0.0 0.255.255.255
#
user-interface con 0
:
s
e
authentication-mode password
set authentication password
c
r
u
o
s
e
R
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
#
return
g
n
i
[R2]display current-configuration
n
r
a
[V200R003C00SPC200]
#
Le
sysname R2
interface Serial3/0/0
link-protocol fr
undo fr inarp
fr map ip 10.0.123.1 201 broadcast
ip address 10.0.123.2 255.255.255.0
ospf network-type p2mp
Page92
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
#
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
#
ospf 1 router-id 10.0.2.2
area 0.0.0.0
network 10.0.0.0 0.255.255.255
e
/
m
o
c
.
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
user-interface vty 0 4
u
h
.
g
n
#
return
i
n
ar
[R3]display current-configuration
[V200R003C00SPC200]
e
l
//
#
sysname R3
#
:
p
tt
interface Serial1/0/0
link-protocol fr
undo fr inarp
fr map ip 10.0.123.1 301 broadcast
:
s
e
c
r
u
o
s
e
R
interface LoopBack0
g
n
i
n
r
a
Le
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
#
return
HC Series
HUAWEI TECHNOLOGIES
Page93
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
Topology
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
ng
i
n
rScenario
c
r
u
o
s
e
R
:
s
e
:
p
tt
a The enterprise subscribes to a (typically high speed) DSL service from the
e
L
service provider over which WAN services are supported. R1 and R3 are
enterprise edge routers of different offices, and establish a connection to the
service provider through the PPPoE server (R2). The enterprise is required to
establish a PPPoE dialer on the edge routers to allow hosts in the local area
network to access external resources transparently via the service provider
network over PPPoE.
Page94
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname R1
<Huawei>system-view
u
h
.
g
n
i
n
ar
i
e
aw
e
l
/
Step 2 Clean up the previous configuration
/
:
p
t over the frame relay network.
Disable the serial interfaces to avoid routing
t
h
:
s
e
c
r
u
o
s
e
R
Step 3 Configure
PPPoE Server.
g
n
i
n PPPoE server is not part of the enterprise network, however it is required
The
r
a to allow the enterprise edge routers R1 and R3 to be authenticated.
[Huawei]sysname R3
Le
HC Series
HUAWEI TECHNOLOGIES
e
/
m
o
c
.
<Huawei>system-view
Page95
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
i
e
aw
e
l
//
:
p
t the dialer interface needs to be
Configure R1 as a PPPoE client, for t
which
h The PPP authenticated username
created, and PPP authentication enabled.
and password should match that:configured on the PPPoE server.
s
e
c
r
u
o
s
e
R
g
n
i
n
ar
Step 4 Configure PPPoE Client.
[R1]dialer-rule
[R1-dialer-rule]dialer-rule 1 ip permit
[R1-dialer-rule]quit
[R1]interface Dialer 1
[R1-Dialer1]dialer-group 1
[R1-Dialer1]dialer bundle 1
Le
Page96
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
u
h
.
g
n
[R3-dialer-rule]quit
[R3]interface Dialer 1
[R3-Dialer1]dialer user user2
i
n
ar
[R3-Dialer1]dialer-group 1
[R3-Dialer1]dialer bundle 1
e
l
//
:
p
tt
[R3-Dialer1]dialer queue-length 8
[R3-Dialer1]ip address ppp-negotiate
[R3-Dialer1]quit
:
s
e
i
e
aw
c
r
u
o
s static route to the PPPoE server
Configure a default
e
R
g
n
i5 Verify the configuration results
Step
n
arExecute the command display pppoe-server session all command to view
[R3]interface GigabitEthernet 0/0/0
[R3-GigabitEthernet0/0/0]pppoe-client dial-bundle-number 1
[R3-GigabitEthernet0/0/0]quit
Le
State
OIntf
RemMAC
LocMAC
Virtual-Template1:0
UP
GE0/0/0
00e0.fc03.d0ae 00e0.fc03.7516
Virtual-Template1:1
UP
GE0/0/0
00e0.fc03.aedd 00e0.fc03.7516
HUAWEI TECHNOLOGIES
Page97
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
<R2>display virtual-access
Virtual-Template1:0 current state : UP
Line protocol current state : UP
Last line protocol up time : 2013-12-12 04:15:54
Description:HUAWEI, AR Series, Virtual-Template1:0 Interface
Route Port,The Maximum Transmit Unit is 1492, Hold timer is 10(sec)
Link layer protocol is PPP
e
/
m
o
c
.
0%
0%
u
h
.
g
n
i
n
ar
e
l
//
0%
0%
:
p
tand ensure both can obtain an IP
Check the dialer interface of R1 and R3,
t
h
address from the PPPoE server.
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
<R1>display ip interface brief
(s): spoofing
Le
Interface
IP Address/Mask
Physical
Protocol
Cellular0/0/0
unassigned
down
down
Cellular0/0/1
unassigned
down
down
Dialer1
119.84.111.253/32
up
up(s)
GigabitEthernet0/0/0
unassigned
up
down
output omitted
Page98
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
IP Address/Mask
Physical
Protocol
Cellular0/0/0
unassigned
down
down
Cellular0/0/1
unassigned
down
down
Dialer1
119.84.111.252/32
up
up(s)
GigabitEthernet0/0/0
unassigned
up
down
e
/
m
output omitted
o
c
.
Final Configuration
[R1]display current-configuration
u
h
.
g
n
[V200R003C00SPC200]
#
sysname R1
i
n
ar
#
aaa
authentication-scheme default
e
l
//
authorization-scheme default
accounting-scheme default
:
p
tt
domain default
domain default_admin
:
s
e
c
r
u
o
s
e
R
interface Dialer1
link-protocol ppp
g
n
i
ip address ppp-negotiate
dialer user user1
n
r
a
dialer bundle 1
Le
dialer queue-length 8
dialer timer idle 300
dialer-group 1
#
interface GigabitEthernet0/0/0
pppoe-client dial-bundle-number 1
#
dialer-rule
HC Series
HUAWEI TECHNOLOGIES
Page99
i
e
aw
e
r
Mo
HCNA-HNTD
dialer-rule 1 ip permit
#
ip route-static 0.0.0.0 0.0.0.0 Dialer1
#
user-interface con 0
authentication-mode password
set authentication password
e
/
m
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
o
c
.
user-interface vty 0 4
#
return
u
h
.
g
n
[R2]dis current-configuration
[V200R003C00SPC200]
#
i
n
ar
sysname R2
#
e
l
//
ip pool pool1
gateway-list 119.84.111.254
network 119.84.111.0 mask 255.255.255.0
:
p
tt
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
c
r
u
o
s
e
R
domain default
domain default_admin
:
s
e
g
n
i
n
r
a
Le
interface Virtual-Template1
ppp authentication-mode chap
remote address pool pool1
ip address 119.84.111.254 255.255.255.0
#
interface GigabitEthernet0/0/0
pppoe-server bind Virtual-Template 1
Page100
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
user-interface vty 0 4
#
return
e
/
m
o
c
.
[R3]display current-configuration
[V200R003C00SPC200]
#
sysname R3
u
h
.
g
n
#
aaa
authentication-scheme default
i
n
ar
authorization-scheme default
accounting-scheme default
e
l
//
domain default
domain default_admin
:
p
tt
c
r
u
o
s
e
R
link-protocol ppp
:
s
e
g
n
i
dialer bundle 1
dialer queue-length 8
n
r
a
Le
dialer-group 1
interface GigabitEthernet0/0/0
pppoe-client dial-bundle-number 1
#
#
dialer-rule
dialer-rule 1 ip permit
#
HC Series
HUAWEI TECHNOLOGIES
Page101
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
return
u
h
.
g
n
i
n
ar
e
l
//
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
Le
Page102
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
Learning Objectives
As a result of this lab section, you should achieve the following tasks:
i
e
aw
u
h
.
g
n
Topology
i
n
ar
e
l
//
c
r
u
o
s
e
R
:
s
e
:
p
tt
Figure 3.1 Filtering enterprise network data with Access Control Lists
g
n
i that you are a network administrator of a company that has three
Assume
n
arnetworks belonging to three sites. R2 is deployed at the border of the network
Scenario
Le
for the main site, while R1 and R3 are deployed at the boundary of the
remaining sites. The routers are interconnected over a private WAN
connection. The company needs to control the access of employees to telnet
and FTP services. Only site R1 has permission to access the telnet server in
the main site. Only site R3 has permission to access the FTP server.
HC Series
HUAWEI TECHNOLOGIES
Page103
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
o
c
.
[Huawei]sysname R1
[Huawei]sysname R2
[Huawei]sysname R3
u
h
.
g
n
[Huawei]sysname S1
[S1]vlan 4
[S1-vlan4]quit
i
e
aw
i
n
ar
[S1]interface vlanif 4
[S1-Vlanif4]ip address 10.0.4.254 24
e
l
//
[Huawei]sysname S2
[S2]vlan 6
:
p
tt
[S2-vlan6]quit
[S2]interface vlanif 6
[S2-Vlanif6]ip address 10.0.6.254 24
:
s
e
c
r
u
o
s
e
R
Remove the current network being advertised in OSPF, the PPPoE dialer
interfaces, as well as the PPPoE server virtual template configuration from R2.
[R1]ospf
g
n
i
[R1-ospf-1]area 0
n
r
a
Le
Page104
e
/
m
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]undo network 10.0.0.0 0.255.255.255
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]undo pppoe-server bind
[R2]undo interface Virtual-Template 1
[R2]undo ip pool pool1
[R2]aaa
e
/
m
o
c
.
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
[R3]dialer-rule
[R3-dialer-rule]undo dialer-rule 1
:
p
tt
c
r
u
o
s
e
R
:
s
e
g
n
i
n
r
a
Le
Establish VLAN trunks on S1 and S2. The port link type should already be
configured for interface GigabitEthernet 0/0/2 on S1.
HC Series
HUAWEI TECHNOLOGIES
Page105
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
i
e
aw
u
h
.
g
Configure OSPF for R1, R2, and R3. Ensure that all are partnof the same
OSPF area and advertise the networks that have been created.i
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
s
Re
ga static route on S1 and S2, the nexthop as the private networks
n
Configure
i
gateway.
n
ar
Step 4 Configure OSPF to enable internetwork communication
[R1]ospf
[R1-ospf-1]area 0
[R2]ospf
[R2-ospf-1]area 0
[R3-ospf-1]area 0
Le
Page106
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
<R1>ping 10.0.4.254
PING 10.0.4.254: 56
e
/
m
o
c
.
u
h
.
g
n
<R1>ping 10.0.6.254
PING 10.0.6.254: 56
i
n
ar
e
l
//
:
p
tt
c
r
u
o
s
e
R
:
s
e
PING 10.0.4.254: 56
g
n
i
n
r
a
Le
HC Series
HUAWEI TECHNOLOGIES
Page107
i
e
aw
e
r
Mo
HCNA-HNTD
<R3>ping 10.0.6.254
PING 10.0.6.254: 56
e
/
m
o
c
.
i
e
aw
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 2/5/10 ms
u
h
Step 5 Configure Filters using Access Control Lists
.
g
n
i
Configure S1 as a telnet server.
n
r
a
e
l
/
/
:
Configure S2 as an FTP server.
p
t
ht
:
s
e
c
r
u
Configure an access
control list on R2 to allow R1 to access the telnet server,
o
s
and R3 to access
the FTP server.
Re
g
n
i
n
ar
[S1]user-interface vty 0 4
[S1-ui-vty0-4]authentication-mode password
[R2]acl 3000
Le
Page108
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
Login authentication
o
c
.
Password:
Info: The max number of VTY users is 5, and the number
of current VTY users on line is 1.
u
h
.
g
n
<S1>
i
n
ar
<R1>ftp 10.0.6.254
e
l
//
i
e
aw
:
p
tt
Note: The FTP connection may take a while to respond (approx 60 seconds).
<R3>telnet 10.0.4.254
:
s
e
c
r
u
o
s
e
R
g
n
i
Connected to 10.0.6.254.
n
r
a
Le
User(10.0.6.254:(none)):huawei
331 Password required for huawei.
Enter password:
230 User logged in.
[R3-ftp]
Note: The bye command can be used to close the FTP connection
HC Series
HUAWEI TECHNOLOGIES
Page109
e
r
Mo
HCNA-HNTD
Final Configuration
o
c
.
<R1>display current-configuration
[V200R003C00SPC200]
#
u
h
.
g
n
sysname R1
#
aaa
i
n
ar
authentication-scheme default
authorization-scheme default
e
l
//
accounting-scheme default
domain default
domain default_admin
:
p
tt
:
s
e
interface GigabitEthernet0/0/0
c
r
u
o
s
e
R
g
n
i
n
r
a
user-interface con 0
authentication-mode password
Le
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
#
return
Page110
e
/
m
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
<R2>display current-configuration
[V200R003C00SPC200]
#
sysname R2
#
acl number 3000
rule 5 permit tcp source 10.0.13.1 0 destination 10.0.4.254 0 destination-port
e
/
m
eq telnet
o
c
.
u
h
.
g
n
i
n
ar
interface GigabitEthernet0/0/1
ip address 10.0.4.2 255.255.255.0
e
l
//
#
interface GigabitEthernet0/0/2
ip address 10.0.6.2 255.255.255.0
:
p
tt
#
ospf 1 router-id 10.0.2.2
area 0.0.0.0
network 10.0.4.0 0.0.0.255
:
s
e
c
r
u
o
s
e
R
user-interface con 0
authentication-mode password
set authentication password
g
n
i
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
user-interface vty 0 4
n
r
a
#
Le
return
<R3>display current-configuration
[V200R003C00SPC200]
#
sysname R3
#
interface GigabitEthernet0/0/0
HC Series
HUAWEI TECHNOLOGIES
Page111
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
authentication-mode password
o
c
.
u
h
.
g
n
<S1>display current-configuration
i
n
ar
#
!Software Version V100R006C00SPC800
e
l
//
sysname S1
#
vlan batch 4
:
p
tt
#
interface Vlanif4
:
s
e
interface GigabitEthernet0/0/2
c
r
u
o
s
e
R
g
n
i
user-interface con 0
n
r
a
user-interface vty 0 4
Le
return
Page112
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
<S2>dis current-configuration
#
!Software Version V100R006C00SPC800
sysname S2
#
FTP server enable
#
e
/
m
vlan batch 6
o
c
.
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
u
h
.
g
n
domain default
domain default_admin
local-user admin password simple admin
i
n
ar
e
l
//
:
p
tt
interface Vlanif6
ip address 10.0.6.254 255.255.255.0
#
interface GigabitEthernet0/0/2
port link-type trunk
c
r
u
o
s
e
R
:
s
e
g
n
i
user-interface con 0
user-interface vty 0 4
n
r
a
#
Le
return
HC Series
HUAWEI TECHNOLOGIES
Page113
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
Topology
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
c
r
u
o
s
e
R
:
s
e
:
p
tt
g
n
i
Scenario
Le
n
In order to conserve addressing the offices of the enterprise network have
r
a implemented private addressing internally. Users however require a means to
be routed between these private networks and the public network domain. R1
and R3 represent edge routers of the enterprise branch offices ,the branch
network need access to the public network. The administrator of the network is
requested to configure dynamic NAT solutions on the in order to allow R1 to
perform address translation. An easyIP NAT solution is to be applied to R3.
Page114
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
o
c
.
[Huawei]sysname R1
[R1]inter GigabitEthernet0/0/1
[R1-GigabitEthernet0/0/1]ip address 10.0.4.1 24
u
h
.
g
n
[Huawei]sysname R3
[R3]interface GigabitEthernet0/0/2
[R3-GigabitEthernet0/0/2]ip address 10.0.6.3 24
e
l
//
[S1-vlan3]quit
[S1]interface vlanif 4
:
p
tt
c
r
u
o
s
e
R
[S2]interface vlanif 6
i
e
aw
i
n
ar
[Huawei]sysname S1
[S1]vlan 4
:
s
e
g
n
i the connection to S1 and S2 via Gigabit Ethernet 0/0/1 on R1 and
Re-establish
n
arGigabit Ethernet 0/0/2 on R3. Remove OSPF from all routers.
Step 2 Clean up the previous configuration
Le
HC Series
HUAWEI TECHNOLOGIES
e
/
m
Page115
e
r
Mo
HCNA-HNTD
[R2]undo ospf 1
Warning: The OSPF process will be deleted. Continue? [Y/N]:y
[R3-GigabitEthernet0/0/0]undo ip address
[R3]interface GigabitEthernet 0/0/2
[R3-GigabitEthernet0/0/2]undo shutdown
[R3]undo ospf 1
e
/
m
o
c
.
u
h
.
g
Step 3 Implement VLAN configuration for S1 and S2 n
i
n
r
a
e
l
/
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
[S2]undo ip route-static 0.0.0.0 0.0.0.0
[R3]interface GigabitEthernet0/0/0
Le
Page116
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s Access Control Lists for R1 and R3
Step 4 Configure
e
R
Configure an advanced ACL on R1 and select the data flow with the source of
g
S1, the
destination of R3, and destined for the telnet service port.
n
i
n
ar
0.00% packet loss
[R1]acl 3000
Le
Configure a basic ACL on R3 and select the data flow whose source IP
address is 10.0.6.0/24.
[R3]acl 2000
[R3-acl-basic-2000]rule permit source 10.0.6.0 0.0.0.255
HC Series
HUAWEI TECHNOLOGIES
Page117
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
e
aw
i
n
r
Verify the address group has been configured correctly a
e
l
/
/
:
p
t
t
h
:
s
e
c
r
u
Test connectivity to the gateway of the remote peer from the internal network.
o
s
Re
g
n
i
n
ar
[R3-ui-vty0-4]quit
-------------------------------------Index
Start-address
End-address
-------------------------------------1
119.84.111.240
119.84.111.243
-------------------------------------Total : 1
<S1>ping 119.84.111.3
Le
Page118
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
Password:
<R3>
i
e
aw
Do not exit the telnet session, instead open a second session window to R1
and view the results of the ACL and NAT session translation.
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
Vpn
c
r
u
o
s
e
R
Vpn
Le
:
s
e
: 10.0.4.254
: 119.84.111.3
: 8
44003
New SrcAddr
: 119.84.111.242
New DestAddr
: ----
g
n
i
New IcmpId
n
r
a
: ICMP(1)
: 10247
Protocol
: TCP(6)
: 10.0.4.254
49646
: 119.84.111.3
23
NAT-Info
New SrcAddr
: 119.84.111.242
New SrcPort
: 10249
New DestAddr
: ----
New DestPort
: ----
Total : 2
HC Series
HUAWEI TECHNOLOGIES
Page119
e
r
Mo
HCNA-HNTD
The ICMP session has a lifetime of only 20 seconds and therefore may not
appear to be present when displaying the NAT session results. The following
command can be used in this case to extend the period over which the ICMP
results are maintained:
[R1]firewall-nat session icmp aging-time 300
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
c
r
u
o
s
e
R
:
s
e
g
n
i
n
r
a
Le
--------------------------------------------------------------------Interface
Acl
Address-group/IP/Interface
Type
--------------------------------------------------------------------GigabitEthernet0/0/0
2000
119.84.111.3
easyip
--------------------------------------------------------------------Total : 1
Page120
HUAWEI TECHNOLOGIES
HC Series
e
/
m
o
c
.
Configure easyIP on the Gigabit Ethernet 0/0/0 interface of R3, associating the
easyIP configuration with ACL 2000 that had been configured earlier.
i
e
aw
e
r
Mo
HCNA-HNTD
Final Configuration
<R1>display current-configuration
[V200R003C00SPC200]
#
sysname R1
e
/
m
#
firewall-nat session icmp aging-time 300
o
c
.
#
acl number 3000
i
e
aw
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
#
interface GigabitEthernet0/0/1
ip address 10.0.4.1 255.255.255.0
#
user-interface con 0
:
s
e
authentication-mode password
c
r
u
o
s
e
R
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
#
return
n
r
a
g
n
i
<R3>display current-configuration
Le
[V200R003C00SPC200]
#
sysname R3
#
acl number 2000
rule 5 permit source 10.0.6.0 0.0.0.255
#
interface GigabitEthernet0/0/0
HC Series
HUAWEI TECHNOLOGIES
Page121
e
r
Mo
HCNA-HNTD
e
/
m
authentication-mode password
o
c
.
u
h
.
g
n
cipher %$%$7ml|,!ccE$SQ~CZ{GtaE%hO>v}~bVk18p5qq<:UPtI:9hOA%%$%$
#
return
i
n
ar
e
l
//
<S1>display current-configuration
#
!Software Version V100R006C00SPC800
:
p
tt
sysname S1
#
vlan batch 4
#
interface Vlanif4
c
r
u
o
s
e
R
:
s
e
interface GigabitEthernet0/0/1
port link-type trunk
g
n
i
n
r
a
interface GigabitEthernet0/0/2
Le
#
interface GigabitEthernet0/0/14
shutdown
#
ip route-static 0.0.0.0 0.0.0.0 10.0.4.1
#
Page122
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
user-interface con 0
user-interface vty 0 4
set authentication password cipher N`C55QK<`=/Q=^Q`MAF4<1!!
#
return
e
/
m
<S2>display current-configuration
o
c
.
#
!Software Version V100R006C00SPC800
sysname S2
#
vlan batch 6
u
h
.
g
n
#
interface Vlanif6
ip address 10.0.6.254 255.255.255.0
i
n
ar
#
interface GigabitEthernet0/0/2
e
l
//
:
p
tt
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk pvid vlan 6
:
s
e
c
r
u
o
s
e
R
interface GigabitEthernet0/0/23
shutdown
#
g
n
i
user-interface con 0
n
r
a
user-interface vty 0 4
Le
return
HC Series
HUAWEI TECHNOLOGIES
Page123
i
e
aw
e
r
Mo
HCNA-HNTD
u
h
.
g
n
Topology
i
e
aw
i
n
ar
e
l
//
:
p
tt
Scenario
c
r
u
o
s
e
R
:
s
e
R1 and R3 have been deployed on the network and are to provide remote
authentication services using AAA. The company requires that both routers
are made part of the huawei domain and that the telnet service is made
available to users, with limited privileges given once authenticated.
n
r
a
g
n
i
Le
Page124
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
/
m
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
o
c
.
[Huawei]sysname R1
[R1]interface GigabitEthernet0/0/0
[R1-GigabitEthernet0/0/0]ip address 119.84.111.1 24
u
h
.
g
n
[Huawei]sysname R3
[R3]inter GigabitEthernet0/0/0
[R3-GigabitEthernet0/0/0]ip address 119.84.111.3 24
i
n
ar
e
l
Remove the previous NAT and ACL configuration/
from R1 and R3.
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
g
n
Stepi3 Verify connectivity between R1 and R3
n
r
a
Step 2 Clean up the previous configuration
[R3-GigabitEthernet0/0/0]quit
[R3]undo acl 2000
Le
<R1>ping 119.84.111.3
HC Series
HUAWEI TECHNOLOGIES
e
/
m
Page125
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
u
h
.
g
n
[R1-aaa]authentication-scheme auth1
Info: Create a new authentication scheme.
[R1-aaa-authen-auth1]authentication-mode local
i
n
ar
[R1-aaa-authen-auth1]quit
[R1-aaa]authorization-scheme auth2
Info: Create a new authorization scheme.
i
e
aw
e
l
//
[R1-aaa-author-auth2]authorization-mode local
[R1-aaa-author-auth2]quit
:
p
tt
Configure the domain huawei on R1, then create a user and apply the user to
this domain.
[R1-aaa]domain huawei
:
s
e
[R1-aaa-domain-huawei]authentication-scheme auth1
c
r
u
o
s
e
R
[R1-aaa-domain-huawei]authorization-scheme auth2
[R1-aaa-domain-huawei]quit
n
r
a
g
n
i
Le
[R1]user-interface vty 0 4
[R1-ui-vty0-4]authentication-mode aaa
Page126
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
r
Mo
HCNA-HNTD
e
/
m
Login authentication
o
c
.
Username:user1@huawei
i
e
aw
Password:
<R1>system-view
^
u
h
.
g
n level 0 for
Operations are restricted as user privileges are limited to privilege
i
user1@huawei.
n
r
a
e
Step 5 Perform AAA configuration on R3 l
/
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
Configure
the domain huawei on R3, then create a user and apply the user to
g
n
this domain.
i
n
r
a
Error: Unrecognized command found at '^' position.
<R1>quit
[R3]aaa
[R3-aaa]authentication-scheme auth1
[R3-aaa-authen-auth1]authentication-mode local
[R3-aaa-authen-auth1]quit
[R3-aaa]authorization-scheme auth2
[R3-aaa-author-auth2]authorization-mode local
[R3-aaa-author-auth2]quit
Le
[R3-aaa]domain huawei
[R3-aaa-domain-huawei]authentication-scheme auth1
[R3-aaa-domain-huawei]authorization-scheme auth2
[R3-aaa-domain-huawei]quit
[R3-aaa]local-user user3@huawei password cipher huawei
[R3-aaa]local-user user3@huawei service-type telnet
[R3-aaa]local-user user3@huawei privilege level 0
HC Series
HUAWEI TECHNOLOGIES
Page127
e
r
Mo
HCNA-HNTD
e
/
m
<R1>telnet 119.84.111.3
o
c
.
u
h
.
g
n
Username:user3@huawei
Password:
<R3>system-view
^
i
n
ar
i
e
aw
e
l
/set to privilege level 0 for
/
Operations are restricted as user privileges are
:
user3@huawei.
p
t
t
h
Step 6 Observe the results of the AAA configuration
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Error: Unrecognized command found at '^' position.
<R3>
: huawei
Domain-state
: Active
Authentication-scheme-name
: auth1
Accounting-scheme-name
: default
Authorization-scheme-name : auth2
Le
Service-scheme-name
: -
RADIUS-server-template
: -
HWTACACS-server-template
: -
User-group
: -
Page128
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
: ****************
State
: active
Service-type-mask
: T
Privilege level
: 0
Ftp-directory
: -
Access-limit
: -
Accessed-num
: 0
Idle-timeout
: -
User-group
: -
e
/
m
o
c
.
: huawei
Domain-state
: Active
Authentication-scheme-name
: auth1
Accounting-scheme-name
: default
Authorization-scheme-name
: auth2
Service-scheme-name
: -
RADIUS-server-template
: -
HWTACACS-server-template
: -
User-group
: -
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
Service-type-mask
: active
: T
Privilege level
: 0
Ftp-directory
: -
g
n
i
Access-limit
: -
Accessed-num
: 0
n
r
a
Le
: ****************
Idle-timeout
: -
User-group
: -
HC Series
HUAWEI TECHNOLOGIES
Page129
i
e
aw
e
r
Mo
HCNA-HNTD
Final Configuration
<R1>display current-configuration
[V200R003C00SPC200]
#
sysname R1
e
/
m
#
aaa
o
c
.
authentication-scheme default
authentication-scheme auth1
authorization-scheme default
authorization-scheme auth2
u
h
.
g
n
accounting-scheme default
domain default
domain default_admin
i
n
ar
domain huawei
authentication-scheme auth1
authorization-scheme auth2
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
interface GigabitEthernet0/0/0
user-interface con 0
g
n
i
authentication-mode password
n
r
a
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
Le
user-interface vty 0 4
authentication-mode aaa
#
return
Page130
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
<R3>dis current-configuration
[V200R003C00SPC200]
#
sysname R3
#
aaa
authentication-scheme default
e
/
m
authentication-scheme auth1
o
c
.
authorization-scheme default
authorization-scheme auth2
accounting-scheme default
domain default
domain default_admin
u
h
.
g
n
domain huawei
authentication-scheme auth1
authorization-scheme auth2
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
user-interface con 0
authentication-mode password
set authentication password
g
n
i
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
n
r
a
authentication-mode aaa
Le
return
HC Series
HUAWEI TECHNOLOGIES
Page131
i
e
aw
e
r
Mo
HCNA-HNTD
Topology
u
h
.
g
n
e
/
m
i
e
aw
i
n
ar
e
l
//
:
p
tt
Scenario
n
r
a
Le
c
r
u
o
s
e
R
:
s
e
g
n
i
Page132
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment.
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
e
/
m
<Huawei>system-view
[Huawei]sysname R1
o
c
.
u
h
.
g
n
<Huawei>system-view
[Huawei]sysname R2
i
n
ar
e
l
//
:
p
tt
:
s
e
i
e
aw
c
r
u
o
s
e
Step 2 Clean
R up the previous configuration.
gthe addressing for the Gigabit Ethernet 0/0/0 interface on R1 & R3,
Remove
n
andi
disable the interfaces as shown to prevent alternative routes.
n
ar
[R3-Serial2/0/0]ip address 10.0.23.3 24
[R3-Serial2/0/0]interface loopback 0
Le
[R1-GigabitEthernet0/0/0]undo ip address
[R1-GigabitEthernet0/0/0]quit
[R1]interface GigabitEthernet 0/0/1
[R1-GigabitEthernet0/0/1]shutdown
[R1-GigabitEthernet0/0/1]quit
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]undo shutdown
HC Series
HUAWEI TECHNOLOGIES
Page133
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
[R3-GigabitEthernet0/0/2]shutdown
[R3]interface Serial 2/0/0
[R3-Serial2/0/0]undo shutdown
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
i
e
aw
Use the IP address of Loopback 0 as the router ID, use the default OSPF
process (1), and specify the public network segments 10.0.12.0/24, and
10.0.23.0/24 as part of OSPF area 0.
c
r
u
o
s
e
R
:
s
e
g
n
i
n
r
a
Le
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]network 10.0.2.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 10.0.12.0 0.0.0.255
[R2-ospf-1-area-0.0.0.0]network 10.0.23.0 0.0.0.255
[R3]ospf router-id 10.0.3.3
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]network 10.0.23.0 0.0.0.255
Page134
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.1.1
Full
0.0.0.0
Serial2/0/0
10.0.3.3
Full
i
e
aw
----------------------------------------------------------------------------
u
h
.
g
n
<R1>display ip routing-table
Route Flags: R - relay, D - download to fib
i
n
ar
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1/32
Direct
10.0.1.255/32
Direct
10.0.2.2/32
OSPF
10
781
10.0.3.3/32
OSPF
10
10.0.11.0/24
Direct
:
s
e
10.0.11.11/32
e
l
//
Flags NextHop
:
p
tt
LoopBack0
127.0.0.1
LoopBack0
127.0.0.1
LoopBack0
10.0.12.2
Serial1/0/0
2343
10.0.12.2
Serial1/0/0
10.0.11.11
LoopBack1
Direct
127.0.0.1
LoopBack1
10.0.11.255/32 Direct
127.0.0.1
LoopBack1
10.0.12.0/24
Direct
10.0.12.1
Serial1/0/0
10.0.12.1/32
Direct
127.0.0.1
Serial1/0/0
10.0.12.2/32
Direct
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct
127.0.0.1
Serial1/0/0
10.0.23.0/24
OSPF
10
2343
10.0.12.2
Serial1/0/0
10.0.33.33/32
OSPF
10
2343
10.0.12.2
Serial1/0/0
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
ng
c
r
u
o
s
e
R
r
a
e
Interface
10.0.1.1
ni
Routes : 17
If the baudrate is maintained as 128000 from lab 6-1, the OSPF cost will be set
as shown, and thus may vary due to the the metric calculation used by OSPF.
HC Series
HUAWEI TECHNOLOGIES
Page135
o
c
.
e
r
Mo
HCNA-HNTD
<R3>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 17
Destination/Mask
Routes : 17
Proto
Pre Cost
10.0.1.1/32
OSPF
10
10.0.2.2/32
OSPF
10
1562
10.0.23.2
Serial2/0/0
10.0.3.0/24
Direct
10.0.3.3
LoopBack0
10.0.3.3/32
Direct
127.0.0.1
LoopBack0
10.0.3.255/32
Direct
127.0.0.1
LoopBack0
10.0.11.11/32
OSPF
10
3124
10.0.23.2
Serial2/0/0
10.0.12.0/24
OSPF
10
3124
10.0.23.2
Serial2/0/0
10.0.23.0/24
Direct
10.0.23.3
Serial2/0/0
10.0.23.2/32
Direct
10.0.23.2
Serial2/0/0
10.0.23.3/32
Direct
127.0.0.1
Serial2/0/0
10.0.23.255/32 Direct
127.0.0.1
10.0.33.0/24
Direct
10.0.33.33
LoopBack1
10.0.33.33/32
Direct
127.0.0.1
LoopBack1
10.0.33.255/32 Direct
e
l
//
Serial2/0/0
127.0.0.1
LoopBack1
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
Flags NextHop
3124
:
s
e
Interface
10.0.23.2
u
h
.
g
n
c
r
u
o
s is created to identify interesting traffic for which the IPsec
An advanced ACL
e
VPN will beRapplied. The advanced ACL is capable of filtering based on
specific g
parameters for selective traffic filtering.
n
i
n
ar
Step 5 Configure the ACL to define interesting traffic
[R1]acl 3001
Le
[R3]acl 3001
[R3-acl-adv-3001]rule 5 permit ip source 10.0.3.0 0.0.0.255 destination 10.0.1.0
0.0.0.255
Page136
HUAWEI TECHNOLOGIES
o
c
.
i
e
aw
i
n
ar
:
p
tt
e
/
m
Serial2/0/0
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
Number of proposals: 1
e
l
//
tran1
Encapsulation mode :
Tunnel
Transform
esp-new
ESP protocol
Authentication SHA1-HMAC-96
Encryption
c
r
u
o
s
e
R
Number of proposals: 1
IPSec proposal name :
Encapsulation mode :
g
n
i
Transform
ESP protocol
Le
n
r
a
:
s
e
:
p
tt
3DES
tran1
Tunnel
esp-new
Authentication SHA1-HMAC-96
Encryption
3DES
Create an IPsec policy and define the parameters for establishing the SA.
[R1]ipsec policy P1 10 manual
[R1-ipsec-policy-manual-P1-10]security acl 3001
[R1-ipsec-policy-manual-P1-10]proposal tran1
[R1-ipsec-policy-manual-P1-10]tunnel remote 10.0.23.3
HC Series
HUAWEI TECHNOLOGIES
Page137
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
[R3-ipsec-policy-manual-P1-10]proposal tran1
[R3-ipsec-policy-manual-P1-10]tunnel remote 10.0.12.1
[R3-ipsec-policy-manual-P1-10]tunnel local 10.0.23.3
[R3-ipsec-policy-manual-P1-10]sa spi outbound esp 12345
[R3-ipsec-policy-manual-P1-10]sa spi inbound esp 54321
u
h
.
g
n
Run the display ipsec policy command to verify the configuration.
i
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
[R3-ipsec-policy-manual-P1-10]sa string-key outbound esp simple huawei
[R3-ipsec-policy-manual-P1-10]sa string-key inbound esp simple huawei
===========================================
IPSec policy group: "P1"
Using interface:
===========================================
Sequence number: 10
Inbound AH setting:
AH SPI:
AH string-key:
Le
Page138
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
===========================================
IPSec policy group: "P1"
Using interface:
===========================================
u
h
.
g
n
Sequence number: 10
Security data flow: 3001
i
n
ar
e
l
//
:
p
tt
AH SPI:
AH string-key:
AH authentication hex key:
Inbound ESP setting:
:
s
e
c
r
u
o
s
e
R
g
n
i
AH string-key:
n
r
a
Le
HC Series
HUAWEI TECHNOLOGIES
Page139
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
[R3-Serial2/0/0]ipsec policy P1
u
h
.
g
n
i
e
aw
Observe and verity that non-interesting traffic bypasses the IPsec processing.
<R1>ping -a 10.0.11.11 10.0.33.33
PING 10.0.33.33: 56
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
: 0
: 0
: 0
Outpacket count
: 0
n
r
a
Le
g
n
i
: 0
: 0
: 0
: 0
BadAuthLen count
: 0
AuthFail count
: 0
InSAAclCheckFail count
: 0
PktDuplicateDrop count
: 0
PktSeqNoTooSmallDrop count : 0
PktInSAMissDrop count
Page140
: 0
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
Observe that only the interesting traffic will be secured by the IPsec VPN.
<R1>ping -a 10.0.1.1 10.0.3.3
PING 10.0.3.3: 56 data bytes, press CTRL_C to break
Reply from 10.0.3.3: bytes=56 Sequence=1 ttl=255 time=80 ms
Reply from 10.0.3.3: bytes=56 Sequence=2 ttl=255 time=77 ms
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
: 5
: 0
: 0
Outpacket count
: 5
: 0
: 0
: 0
: 0
e
l
//
InSAAclCheckFail count
:
s
e
PktDuplicateDrop count
: 0
BadAuthLen count
AuthFail count
c
r
u
o
s
e
R
: 0
:
p
tt
: 0
: 0
PktSeqNoTooSmallDrop count : 0
PktInSAMissDrop count
: 0
Step 10
Le
n
r
Change the ACL to define OSPF traffic as interesting traffic.
a
[R1]acl 3001
[R1-acl-adv-3001]rule 5 permit ospf source any destination any
[R3]acl 3001
[R3-acl-adv-3001]rule 5 permit ospf source any destination any
HC Series
HUAWEI TECHNOLOGIES
Page141
i
e
aw
e
r
Mo
HCNA-HNTD
Interface
Neighbor id
State
0.0.0.0
Serial1/0/0
10.0.2.2
Init
e
/
m
----------------------------------------------------------------------------
o
c
.
<R1>display ip routing-table
Route Flags: R - relay, D - download to fib
i
e
aw
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1
10.0.1.1/32
Direct
10.0.1.255/32
Direct
10.0.11.0/24
Direct
10.0.11.11/32
Direct
10.0.11.255/32 Direct
10.0.12.0/24
Direct
10.0.12.1/32
Direct
10.0.12.2/32
Direct
c
r
u
o
s
e
R
10.0.12.255/32 Direct
u
h
.
g
n
Routes : 14
Flags NextHop
Interface
i
n
ar
LoopBack0
127.0.0.1
127.0.0.1
LoopBack0
10.0.11.11
LoopBack1
e
l
//
LoopBack0
127.0.0.1
LoopBack1
127.0.0.1
LoopBack1
10.0.12.1
Serial1/0/0
127.0.0.1
Serial1/0/0
10.0.12.2
Serial1/0/0
127.0.0.1
Serial1/0/0
127.0.0.1
InLoopBack0
:
s
e
:
p
tt
127.0.0.0/8
Direct
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
g
n
i
Le
n
r
a
---------------------------------------------------------------------------Area Id
Interface
Neighbor id
State
0.0.0.0
Serial2/0/0
10.0.2.2
Init
----------------------------------------------------------------------------
Page142
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
<R3>display ip routing-table
Route Flags: R - relay, D - download to fib
---------------------------------------------------------------------------Routing Tables: Public
Destinations : 14
Destination/Mask
Routes : 14
Proto
Pre Cost
Direct
10.0.3.3
LoopBack0
10.0.3.3/32
Direct
127.0.0.1
LoopBack0
10.0.3.255/32
Direct
127.0.0.1
LoopBack0
10.0.23.0/24
Direct
10.0.23.3
Serial2/0/0
10.0.23.2/32
Direct
10.0.23.2
Serial2/0/0
10.0.23.3/32
Direct
127.0.0.1
Serial2/0/0
10.0.23.255/32 Direct
127.0.0.1
Serial2/0/0
10.0.33.0/24
Direct
10.0.33.33
LoopBack1
10.0.33.33/32
Direct
127.0.0.1
LoopBack1
10.0.33.255/32 Direct
127.0.0.1
LoopBack1
127.0.0.0/8
Direct
127.0.0.1
127.0.0.1/32
e
l
//
InLoopBack0
10.0.3.0/24
Flags NextHop
Interface
u
h
.
g
n
Direct
127.0.0.1
InLoopBack0
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
:
p
tt
OSPF hello messages fail to be encapsulated using IPsec, causing the link
state to fail, returning OSPF to an Init state and effectively breaking the
established OSPF adjacent relationship of R1 and R3 with R2. Lab 7-5 will
introduce solutions to the problem of dynamic routing over IPsec VPN.
c
r
u
o
s
Final Configuration
e
R
g
n
i
n
ar
<R1>display current-configuration
[V200R003C00SPC200]
#
Le
sysname R1
HC Series
HUAWEI TECHNOLOGIES
Page143
o
c
.
i
e
aw
i
n
ar
127.255.255.255/32 Direct
:
s
e
e
/
m
e
r
Mo
HCNA-HNTD
#
ipsec policy P1 10 manual
security acl 3001
proposal tran1
tunnel local 10.0.12.1
tunnel remote 10.0.23.3
sa spi inbound esp 12345
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
baudrate 128000
#
e
l
//
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
:
p
tt
interface LoopBack1
ip address 10.0.11.11 255.255.255.0
#
ospf 1 router-id 10.0.1.1
area 0.0.0.0
c
r
u
o
s
e
R
:
s
e
user-interface con 0
g
n
i
authentication-mode password
set authentication password
n
r
a
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
Le
user-interface vty 0 4
authentication-mode aaa
#
return
Page144
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
<R2>display current-configuration
[V200R003C00SPC200]
#
sysname R2
#
interface Serial1/0/0
link-protocol ppp
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
interface LoopBack0
ip address 10.0.2.2 255.255.255.0
e
l
//
#
ospf 1 router-id 10.0.2.2
area 0.0.0.0
:
p
tt
:
s
e
authentication-mode password
c
r
u
o
s
e
R
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
user-interface vty 0 4
#
return
n
r
a
g
n
i
<R3>display current-configuration
Le
[V200R003C00SPC200]
#
sysname R3
#
acl number 3001
rule 5 permit ospf
#
ipsec proposal tran1
esp authentication-algorithm sha1
HC Series
HUAWEI TECHNOLOGIES
Page145
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
link-protocol ppp
ppp authentication-mode chap
ip address 10.0.23.3 255.255.255.0
i
n
ar
ipsec policy P1
#
e
l
//
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
:
p
tt
interface LoopBack1
ip address 10.0.33.33 255.255.255.0
#
ospf 1 router-id 10.0.3.3
area 0.0.0.0
c
r
u
o
s
e
R
:
s
e
user-interface con 0
g
n
i
authentication-mode password
set authentication password
n
r
a
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
Le
user-interface vty 0 4
authentication-mode aaa
#
return
Page146
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
Topology
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
:
p
tt
Scenario
c
r
u
o
s
e
R
:
s
e
n
r
a
g
n
i
Le
HC Series
HUAWEI TECHNOLOGIES
Page147
e
r
Mo
HCNA-HNTD
Tasks
Note: It is a prerequisite that lab 3-4 be completed before attempting this lab.
e
/
m
o
c
.
Reconfigure the access control list establish GRE encapsulation over IPsec.
[R1]acl 3001
i
e
aw
u
h
.
g
n
[R3]acl 3001
i
n
ar
e
l
//
Create a tunnel interface and specify GRE as the encapsulation type. Set the
tunnel source address or source interface, and set the tunnel destination
address.
[R1]interface Tunnel 0/0/1
:
p
tt
:
s
e
[R1-Tunnel0/0/1]tunnel-protocol gre
[R1-Tunnel0/0/1]source 10.0.12.1
c
r
u
o
s
e
R
[R1-Tunnel0/0/1]destination 10.0.23.3
[R3]interface Tunnel 0/0/1
g
n
i
[R3-Tunnel0/0/1]source 10.0.23.3
[R3-Tunnel0/0/1]destination 10.0.12.1
Le
n
r
a
Page148
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
[R1]ospf 1
[R1-ospf-1]area 0
[R1-ospf-1-area-0.0.0.0]network 100.1.1.0 0.0.0.255
[R1-ospf-1-area-0.0.0.0]undo network 10.0.12.0 0.0.0.255
[R1]ospf 2 router-id 10.0.1.1
[R1-ospf-2]area 0
[R1-ospf-2-area-0.0.0.0]network 10.0.12.0 0.0.0.255
e
/
m
o
c
.
[R3]ospf 1
[R3-ospf-1]area 0
i
e
aw
u
h
.
g
n routes
OSPF LSDB are significant only to the local router, therefore allowing
i
from OSPF LSDB 2 of R1 and R3 to reach OSPF LSDB 1 ofn
R2.
r
a
Run the display interface Tunnel 0/0/1 command to e
verify the configuration.
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
[R3-ospf-2]area 0
Le
HC Series
HUAWEI TECHNOLOGIES
Page149
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
i
e
aw
e
l
//
:
p
Step 4 Verify that the routes are being
t carried via GRE
t
h
Run the display ip routing-table
:command to check the IPv4 routing table.
s
e
c
r
u
o
s
Re
g
n
i
n
ar
<R1>display ip routing-table
Destinations : 21
Destination/Mask
Le
Routes : 21
Proto
Pre Cost
10.0.1.0/24
Direct
10.0.1.1
LoopBack0
10.0.1.1/32
Direct
127.0.0.1
LoopBack0
10.0.1.255/32
Direct
127.0.0.1
LoopBack0
10.0.2.2/32
OSPF
10
781
10.0.12.2
Serial1/0/0
10.0.3.3/32
OSPF
10
1562
100.1.1.2
Tunnel0/0/1
10.0.11.0/24
Direct
10.0.11.11
LoopBack1
10.0.11.11/32
Direct
127.0.0.1
LoopBack1
10.0.11.255/32 Direct
127.0.0.1
LoopBack1
Page150
Flags NextHop
HUAWEI TECHNOLOGIES
Interface
HC Series
e
r
Mo
HCNA-HNTD
10.0.12.0/24
Direct
10.0.12.1
Serial1/0/0
10.0.12.1/32
Direct
127.0.0.1
Serial1/0/0
10.0.12.2/32
Direct
10.0.12.2
Serial1/0/0
10.0.12.255/32 Direct
127.0.0.1
Serial1/0/0
10.0.23.0/24
OSPF
10
2343
10.0.12.2
Serial1/0/0
10.0.33.33/32
OSPF
10
1562
100.1.1.2
Tunnel0/0/1
100.1.1.0/24
Direct
100.1.1.1
Tunnel0/0/1
100.1.1.1/32
Direct
127.0.0.1
Tunnel0/0/1
100.1.1.255/32 Direct
127.0.0.1
Tunnel0/0/1
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
u
h
.
g
n
<R3>display ip routing-table
Route Flags: R - relay, D - download to fib
i
n
ar
e
/
m
i
e
aw
Pre Cost
10.0.1.1/32
OSPF
10
1562
10.0.2.2/32
OSPF
10
1562
10.0.3.0/24
Direct
10.0.3.3/32
Direct
Destination/Mask
c
r
u
o
s
e
R
Flags NextHop
:
p
tt
Interface
100.1.1.1
Tunnel0/0/1
10.0.23.2
Serial2/0/0
10.0.3.3
LoopBack0
127.0.0.1
LoopBack0
127.0.0.1
LoopBack0
10
1562
100.1.1.1
Tunnel0/0/1
:
s
e
10.0.3.255/32
Direct
10.0.11.11/32
OSPF
10.0.12.0/24
OSPF
10
3124
10.0.23.2
Serial2/0/0
10.0.23.0/24
Direct
10.0.23.3
Serial2/0/0
10.0.23.2/32
Direct
10.0.23.2
Serial2/0/0
g
n
i
Direct
127.0.0.1
Serial2/0/0
10.0.23.255/32 Direct
127.0.0.1
Serial2/0/0
10.0.33.0/24
Direct
10.0.33.33
LoopBack1
10.0.33.33/32
Direct
127.0.0.1
LoopBack1
10.0.33.255/32 Direct
127.0.0.1
LoopBack1
100.1.1.0/24
Direct
100.1.1.2
Tunnel0/0/1
100.1.1.2/32
Direct
127.0.0.1
Tunnel0/0/1
100.1.1.255/32 Direct
127.0.0.1
Tunnel0/0/1
127.0.0.0/8
Direct
127.0.0.1
InLoopBack0
127.0.0.1/32
Direct
127.0.0.1
InLoopBack0
127.255.255.255/32 Direct
127.0.0.1
InLoopBack0
255.255.255.255/32 Direct
127.0.0.1
InLoopBack0
10.0.23.3/32
n
r
a
Le
e
l
//
Routes : 21
HC Series
HUAWEI TECHNOLOGIES
Page151
o
c
.
e
r
Mo
HCNA-HNTD
After a GRE tunnel is set up, the router can exchange OSPF packets through
the GRE tunnel. Clear the IPsec statistics and test the connection
<R1>reset ipsec statistics esp
[R1]ping -a 10.0.1.1 10.0.3.3
PING 10.0.3.3: 56 data bytes, press CTRL_C to break
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
: 8
: 0
: 0
Outpacket count
: 8
: 0
:
s
e
BadAuthLen count
: 0
AuthFail count
: 0
InSAAclCheckFail count
: 0
PktDuplicateDrop count
: 0
g
n
i
c
r
u
o
s
e
R
: 0
i
e
aw
:
p
tt
: 0
: 0
PktSeqNoTooSmallDrop count : 0
PktInSAMissDrop count
: 0
Le
n
r
GRE encapsulates all OSPF traffic including the hello packets over IPsec, the
a
gradual increment of the IPsec esp statistics verifies this.
Page152
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
Verify that the keepalive feature has been enabled on the tunnel interface.
<R1>display interface Tunnel 0/0/1
Tunnel0/0/1 current state : UP
Line protocol current state : UP
Last line protocol up time : 2013-12-18 09:50:21
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
:
p
tt
Final Configuration
c
r
u
o
s
e
R
:
s
e
<R1>display current-configuration
[V200R003C00SPC200]
#
sysname R1
#
g
n
i
n
r
a
Le
HC Series
HUAWEI TECHNOLOGIES
Page153
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
interface Serial1/0/0
o
c
.
link-protocol ppp
ppp authentication-mode pap
ip address 10.0.12.1 255.255.255.0
ipsec policy P1
baudrate 128000
u
h
.
g
n
#
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
i
n
ar
#
interface LoopBack1
e
l
//
:
p
tt
c
r
u
o
s
e
R
:
s
e
area 0.0.0.0
g
n
i
n
r
a
Le
area 0.0.0.0
network 10.0.12.0 0.0.0.255
#
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
authentication-mode aaa
Page154
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
#
return
<R2>display current-configuration
[V200R003C00SPC200]
#
e
/
m
sysname R2
o
c
.
#
interface Serial1/0/0
link-protocol ppp
i
e
aw
u
h
.
g
n
#
interface Serial2/0/0
link-protocol ppp
i
n
ar
e
l
//
:
p
tt
:
s
e
c
r
u
o
s
e
R
user-interface con 0
authentication-mode password
g
n
i
n
r
a
user-interface vty 0 4
Le
return
<R3>display current-configuration
[V200R003C00SPC200]
#
sysname R3
#
HC Series
HUAWEI TECHNOLOGIES
Page155
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
#
interface Serial2/0/0
e
l
//
link-protocol ppp
ppp authentication-mode chap
ip address 10.0.23.3 255.255.255.0
:
p
tt
ipsec policy P1
#
interface LoopBack0
ip address 10.0.3.3 255.255.255.0
#
c
r
u
o
s
e
R
interface LoopBack1
:
s
e
interface Tunnel0/0/1
g
n
i
tunnel-protocol gre
source 10.0.23.3
n
r
a
destination 10.0.12.1
Le
Page156
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
authentication-mode aaa
o
c
.
#
return
u
h
.
g
n
i
n
ar
e
l
//
n
r
a
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
Le
HC Series
HUAWEI TECHNOLOGIES
Page157
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
Learning Objectives
As a result of this lab section, you should achieve the following tasks:
Topology
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
c
r
u
o
s
e
R
:
s
e
:
p
tt
g
n
i
Scenario
n
r
With the continued growth of the enterprise network it has become apparent
a
Le
that new measures need to be taken to manage and monitor the health of the
network so as to minimize network downtime. The network administrator has
decided that an NMS solution should be deployed, with tests performed to
observe the basic capability of the NMS solution to monitor devices, before
deploying the solution in the enterprise network.
Page158
HUAWEI TECHNOLOGIES
HC Series
o
c
.
e
r
Mo
HCNA-HNTD
Tasks
Step 1 Preparing the environment
If you are starting this section with a non-configured device, begin here and
then move to step 3. For those continuing from previous labs, begin at step 2.
o
c
.
<Huawei>system-view
[Huawei]sysname R1
[R1]interface LoopBack 0
[R1-LoopBack0]ip address 10.0.1.1 24
u
h
.
g
n
<Huawei>system-view
[Huawei]sysname R3
[R3-LoopBack0]ip address 10.0.3.3 24
e
l
//
i
e
aw
i
n
ar
[R3]interface LoopBack 0
:
p
tt
Disable the unused serial interfaces and remove the OSPF processes from all
routers.
[R1]interface Serial 1/0/0
[R1-Serial1/0/0]shutdown
c
r
u
o
s
e
R
[R1-Serial1/0/0]quit
:
s
e
[R1]undo ospf 1
g
n
i
n
r
a
[R3-Serial2/0/0]shutdown
Le
[R3-Serial2/0/0]quit
[R3]undo ospf 1
Warning: The OSPF process will be deleted. Continue? [Y/N]:y
[R3]undo ospf 2
Warning: The OSPF process will be deleted. Continue? [Y/N]:y
HC Series
e
/
m
HUAWEI TECHNOLOGIES
Page159
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
e
l
//
[R3-ospf-1]area 0
:
p
tt
c
r
u
o
s
e
R
PING 10.0.13.254: 56
:
s
e
g
n
i
n
r
a
Le
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 1/2/10 ms
Page160
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
i
e
w
a
Enable the trap function of R1. Configure contact information about the
u
device administrator.
h
.
g
n
i
n
r
a
e
l
/
/
:
p
t
ht
After the configuration is complete,
run the following commands to verify that
:
s
the configuration has taken effect.
e
c
r
u
o
s
Re
g
n
i
n
ar
[R1]snmp-agent community write private
Le
HC Series
HUAWEI TECHNOLOGIES
Page161
e
r
Mo
HCNA-HNTD
e
/
m
Total number is 1
o
c
.
u
h
.
g
n
i
e
aw
i
n
ar
e
l
//
Under the Resource > Add Device > Single path, add the Network Element
(NE) R1 and R3 to the NMS, and configure the SNMP parameters as shown.
g
n
i
c
r
u
o
s
e
R
:
s
e
:
p
tt
Le
n that the Network Elements have been added to the NMS under the
Verify
r
a Resource > Resource Management > Equipment Resources > NE Resources
path.
Page162
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
u
h
.
g
n
i
n
ar
i
e
aw
e
l
Select the Interface Manager option under Device/
Config in the resource menu
/
to the left of the screen. The given output represents a scenario in which all
:completed in succession, thus
labs throughout the lab guide have been
p
t
producing multiple addresses.
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Le
HC Series
HUAWEI TECHNOLOGIES
Page163
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
i
e
aw
u
h
.
g
n of R1
Optionally, if the AAA authentication is not present on the VTY interface
i
and/or R3, a simple telnet authentication process can be applied
as follows
n
r
before registering the telnet parameters in the NMS.
a
e
l
/
/
:
p
t
ht
The telnet feature in the Basic Information
panel of the resource menu grants
:
s
remote management of theeNE via the NMS, however privileges currently
c
prevent configuration.
r
u
o
s
e
R
g
n
i
n
ar
[R1]user-interface vty 0 4
[R1-ui-vty0-4]authentication-mode password
Le
Page164
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
If the AAA configuration has been maintained from lab 7-3, first increase the
privilege from level 0 to level 3.
[R1]aaa
[R1-aaa]local-user user1@huawei privilege level 3
u
h
. which
Changes that occur to the NE can be monitored in the NMS using traps
g
trigger alarms. Select the Alarm List from the view panel fromn
the resource
i
menu .
n
r
a
e
l
/
/
:
p
t
Currently no alarms are recorded. Access
the NE through the telnet feature in
t
the NMS and shut down the loopbackh0 interface to trigger alarms on the NMS.
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Step 6 Manage Basic NMS Trap Functions
[R1]interface LoopBack 0
[R1-LoopBack0]shutdown
[R1-LoopBack0]undo shutdown
Le
HC Series
HUAWEI TECHNOLOGIES
o
c
.
i
e
aw
Page165
e
/
m
e
r
Mo
HCNA-HNTD
Verify that the relevant alarms have been generated in the Alarm List for the
resource, once the interface state has been changed.
e
/
m
u
h
.
g
n
Final Configuration
<R1>dis current-configuration
i
n
ar
[V200R003C00SPC200]
#
e
l
//
sysname R1
#
:
p
tt
:
s
e
c
r
u
o
s
e
R
trap-paramsname public
g
n
i
snmp-agent
#
n
r
a
aaa
Le
authentication-scheme default
authentication-scheme auth1
authorization-scheme default
authorization-scheme auth2
accounting-scheme default
domain default
domain default_admin
domain huawei
Page166
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
o
c
.
e
r
Mo
HCNA-HNTD
authentication-scheme auth1
authorization-scheme auth2
local-user admin password cipher %$%$=i~>Xp&aY+*2cEVcS-A23Uwe%$%$
local-user admin service-type http
local-user huawei password cipher %$%$B:%I)Io0H8)[%SB[idM3C/!#%$%$
local-user huawei service-type ppp
local-user user1@huawei password cipher %$%$^L*5IP'0^A!;R)R*L=LFcXgv%$%$
e
/
m
o
c
.
u
h
.
g
n
interface LoopBack0
ip address 10.0.1.1 255.255.255.0
#
i
n
ar
e
l
//
:
p
tt
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
user-interface vty 0 4
c
r
u
o
s
e
R
authentication-mode aaa
#
return
g
n
i
:
s
e
<R3>display current-configuration
[V200R003C00SPC200]
n
r
a
#
Le
sysname R3
HC Series
HUAWEI TECHNOLOGIES
Page167
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
authentication-scheme default
o
c
.
authentication-scheme auth1
authorization-scheme default
authorization-scheme auth2
accounting-scheme default
domain default
u
h
.
g
n
domain default_admin
domain huawei
authentication-scheme auth1
i
n
ar
authorization-scheme auth2
e
l
//
:
p
tt
:
s
e
interface GigabitEthernet0/0/0
c
r
u
o
s
e
R
g
n
i
n
r
a
user-interface con 0
Le
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
authentication-mode aaa
#
return
Page168
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
e
/
m
Learning Objectives
As a result of this lab section, you should achieve the following tasks:
i
n
ar
Topology
n
r
a
g
n
i
u
h
.
g
n
e
l
//
c
r
u
o
s
e
R
Le
:
s
e
:
p
tt
HC Series
HUAWEI TECHNOLOGIES
Page169
i
e
aw
o
c
.
e
r
Mo
HCNA-HNTD
Scenario
In line with plans for deployment of solutions for next generation networks, it
has been decided that the enterprise network should implement an IPv6
design to the existing infrastructure. As the administrator you have been
tasked with the job of implementing the addressing scheme and routing for
IPv6, as well as providing stateful addressing solutions for IPv6.
o
c
.
Tasks
i
e
aw
u
h
If you are starting this section with a non-configured device, begin .
here and
g
then move to step 2. For those continuing from previous labs, begin at step 2.
n
i
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
Step 2 Configure
oIPv6 addressing
s
e
R
Establish IPv6 global unicast addressing on the loopback interfaces and
manuallygconfigure link local addressing on interface Gigabit Ethernet 0/0/0 of
n
all routers.
i
n
r
a
<huawei>system-view
[huawei]sysname R1
<huawei>system-view
[huawei]sysname R2
<huawei>system-view
[huawei]sysname R3
Le
[R1]ipv6
[R1]interface loopback 0
[R1-LoopBack0]ipv6 enable
[R1-LoopBack0]ipv6 address 2001:1::A 64
[R1]interface GigabitEthernet 0/0/0
[R1-GigabitEthernet0/0/0]ipv6 enable
[R1-GigabitEthernet0/0/0]ipv6 address fe80::1 link-local
Page170
e
/
m
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
[R2]ipv6
[R2]interface loopback 0
[R2-LoopBack0]ipv6 enable
[R2-LoopBack0]ipv6 address 2001:2::B 64
[R2]interface GigabitEthernet 0/0/0
[R2-GigabitEthernet0/0/0]ipv6 enable
[R2-GigabitEthernet0/0/0]ipv6 address fe80::2 link-local
e
/
m
o
c
.
[R3]ipv6
[R3]interface loopback 0
[R3-LoopBack0]ipv6 enable
[R3-LoopBack0]ipv6 address 2001:3::C 64
u
h
.
g
n
:
p
tt
c
r
u
o
s
e
R
:
s
e
i
n
ar
e
l
//
i
e
aw
g
n
IPv6iinterfaces become part of various multicast groups for support of
n address auto-configuration (SLAAC). The Network Discovery (ND)
stateless
r
a Duplicate Address Detection (DAD) verifies the link local address is unique.
Hosts use stateless autoconfig for addresses
Le
HC Series
HUAWEI TECHNOLOGIES
Page171
e
r
Mo
HCNA-HNTD
e
/
m
[R1-ospfv3-1]router-id 1.1.1.1
[R1-ospfv3-1]quit
o
c
.
u
h
.
g
n
[R1-LoopBack0]ospfv3 1 area 0
[R2]ospfv3 1
i
n
ar
[R2-ospfv3-1]router-id 2.2.2.2
[R2-ospfv3-1]quit
[R2]interface GigabitEthernet 0/0/0
e
l
//
[R2-GigabitEthernet0/0/0]ospfv3 1 area 0
[R2-GigabitEthernet0/0/0]quit
:
p
tt
[R2]interface loopback 0
[R2-LoopBack0]ospfv3 1 area 0
[R3]ospfv3 1
:
s
e
i
e
aw
[R3-ospfv3-1]router-id 3.3.3.3
[R3-ospfv3-1]quit
c
r
u
o
s
e
R
[R3-LoopBack0]ospfv3 1 area 0
Le
g
n
Runi
the display ospfv3 peer command on R1 and R3 to verify the OSPFv3
n has been established.
peering
r
a
<R1>display ospfv3 peer
OSPFv3 Process (1)
OSPFv3 Area (0.0.0.0)
Neighbor ID Pri
State
Dead Time
Interface
2.2.2.2
Full/Backup
00:00:30
GE0/0/0
3.3.3.3
Full/DROther
00:00:40
GE0/0/0
Page172
HUAWEI TECHNOLOGIES
Instance ID
HC Series
e
r
Mo
HCNA-HNTD
State
Dead Time
Interface
Instance ID
1.1.1.1
Full/DR
00:00:32
GE0/0/0
2.2.2.2
Full/Backup
00:00:38
GE0/0/0
If 1.1.1.1 is not currently the DR, the following command can be used to reset
the OSPFv3 process
o
c
.
i
e
Test connectivity to the peer link local address and the global unicast addressw
a
of interface LoopBack 0.
u
h
.
g
n
i
n
r
a
e
l
/
/
:
p
t
t
h
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
<R1>reset ospfv3 1 graceful-restart
Le
HC Series
HUAWEI TECHNOLOGIES
Page173
e
/
m
e
r
Mo
HCNA-HNTD
e
/
m
o
c
.
i
e
w
Enable the DHCPv6 Server function on R2 so that devices can be assigned
a
u
IPv6 addresses using DHCPv6.
h
.
g
n
i
n
r
a
e
l
/
/
:
p 0/0/0 interface.
t
Configure IPv6 functions on the GigabitEthernet
Enable the DHCPv6 server function on
htthe interface.
:
s
e
c
r
u
o
s
Enable the DHCPv6
client function on R1 and R3 so that devices can obtain
e
R
IPv6 addresses using DHCPv6.
g
n
i
n
ar
Step 4 Configure DHCPv6 to distribute IPv6 addresses.
[R2]dhcp enable
[R2-dhcpv6-pool-pool1]excluded-address 2001:FACE::1
[R2-dhcpv6-pool-pool1]quit
[R1]dhcp enable
Le
Page174
HUAWEI TECHNOLOGIES
HC Series
e
r
Mo
HCNA-HNTD
Run the display dhcpv6 pool command on R2 to check information about the
DHCPv6 address pool.
<R2>display dhcpv6 pool
DHCPv6 pool: pool1
Address prefix: 2001:FACE::/64
Lifetime valid 172800 seconds, preferred 86400 seconds
e
/
m
2 in use, 0 conflicts
o
c
.
Excluded-address 2001:FACE::1
1 excluded addresses
i
e
aw
u
h
.
Run the display ipv6 interface brief command on R1 and R3 togcheck the
n
IPv6 address information.
i
n
r
a
e
l
/
/
:
p
t
ht
:
s
e
c
r
u
o
s
Re
g
n
i
n
ar
Active normal clients: 2
Physical
GigabitEthernet0/0/0
Protocol
up
up
up
up(s)
GigabitEthernet0/0/0
Le
Physical
Protocol
up
up
up
up(s)
HC Series
HUAWEI TECHNOLOGIES
Page175
e
r
Mo
HCNA-HNTD
Final Configuration
<R1>display current-configuration
[V200R003C00SPC200]
#
sysname R1
e
/
m
#
ipv6
o
c
.
#
dhcp enable
#
ospfv3 1
u
h
.
g
n
router-id 1.1.1.1
#
interface GigabitEthernet0/0/0
i
n
ar
ipv6 enable
ip address 10.0.13.1 255.255.255.0
ipv6 address FE80::1 link-local
e
l
//
:
p
tt
#
interface LoopBack0
ipv6 enable
ip address 10.0.1.1 255.255.255.0
ipv6 address 2001:1::A/64
ospfv3 1 area 0.0.0.0
#
c
r
u
o
s
e
R
:
s
e
user-interface con 0
authentication-mode password
set authentication password
cipher %$%$dD#}P<HzJ;Xs%X>hOkm!,.+Iq61QK`K6tI}cc-;k_o`C.+L,%$%$
g
n
i
user-interface vty 0 4
n
r
a
authentication-mode aaa
Le
return
Page176
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
e
r
Mo
HCNA-HNTD
<R2>display current-configuration
[V200R003C00SPC200]
#
sysname R2
#
ipv6
#
e
/
m
dhcp enable
o
c
.
#
dhcpv6 pool pool1
address prefix 2001:FACE::/64
excluded-address 2001:FACE::1
dns-server 2001:444E:5300::1
u
h
.
g
n
#
ospfv3 1
router-id 2.2.2.2
i
n
ar
#
interface GigabitEthernet0/0/0
e
l
//
ipv6 enable
ip address 10.0.13.2 255.255.255.0
ipv6 address 2001:FACE::1/64
:
p
tt
c
r
u
o
s
e
R
interface LoopBack0
ipv6 enable
:
s
e
g
n
i
user-interface con 0
n
r
a
authentication-mode password
Le
cipher %$%$|nRPL^hr2IXi7LHDID!/,.*%.8%h;3:,hXO2dk#ikaWI.*(,%$%$
user-interface vty 0 4
#
return
HC Series
HUAWEI TECHNOLOGIES
Page177
i
e
aw
e
r
Mo
HCNA-HNTD
<R3>display current-configuration
[V200R003C00SPC200]
#
sysname R3
#
ipv6
#
e
/
m
dhcp enable
o
c
.
#
ospfv3 1
router-id 3.3.3.3
#
interface GigabitEthernet0/0/0
u
h
.
g
n
ipv6 enable
ip address 10.0.13.3 255.255.255.0
ipv6 address FE80::3 link-local
i
n
ar
e
l
//
#
interface LoopBack0
ipv6 enable
:
p
tt
c
r
u
o
s
e
R
:
s
e
authentication-mode password
set authentication password
cipher %$%$W|$)M5D}v@bY^gK\;>QR,.*d;8Mp>|+EU,:~D~8b59~..*g,%$%$
user-interface vty 0 4
authentication-mode aaa
#
g
n
i
return
n
r
a
Le
Page178
HUAWEI TECHNOLOGIES
HC Series
i
e
aw
m
o
c
With any Huawei Career Certification, you have the privilege on http://learning.huawei.com/en to enjoy:
.
i
e
Methods to get the E-learning privilege : submit Huawei Account and email being used for Huawei Account
w
a
u
h
.
g
registration to Learning@huawei.com .
Content: Huawei product training material and Huawei career certification training material
MethodLogon http://learning.huawei.com/en and enter HuaWei Training/Classroom Training ,then you can
r
a
e
download training material in the specific training introduction page.
l
3 Priority to participate in Huawei Online Open Class(LVC) //
: all ICT technical domains like R&S, UC&C, Security,
ContentThe Huawei career certification training covering
p
tprofessional instructors
Storage and so on, which are conducted by Huawei
t
h
MethodThe plan and participate method please refer to LVC Open Courses Schedule
:
s
4Learning Tool: eNSP
e
c
eNSP (Enterprise Network Simulation r
Platform) is a graphical network simulation tool which is developed by
u
Huawei and free of charge. eNSP
o mainly simulates enterprise routers, switches as close to the real hardware as
s
it possible, which makes the e
lab practice available and easy without any real device.
R
In addition, Huawei has built up Huawei Technical Forum which allows candidates to discuss technical issues with
g
Huawei experts , share n
exam experiences with others or be acquainted with Huawei Products(
i
n
http://support.huawei.com/ecommunity/
r
a
Le
e TECHNOLOGIES CO., LTD. Huawei Confidential
HUAWEI
1
r
o
n
i
n
n
e
/