交换机配置接口的IPv6地址示例

配置思路
配置接口的IPv6地址思路如下:
1、使能SwitchA和SwitchB的IPv6转发能力
2、配置接口的IPv6地址

操作步骤
1、使能Switch的IPv6转发能力
# 配置SwitchA。
[SwitchA] ipv6

2、配置接口的IPv6地址
[SwitchA] vlan 100
[SwitchA-vlan100] quit
[SwitchA] interface gigabitethernet 0/0/1
[SwitchA-GigabitEthernet0/0/1] port link-type hybrid
[SwitchA-GigabitEthernet0/0/1] port hybrid pvid vlan 100
[SwitchA-GigabitEthernet0/0/1] port hybrid untagged vlan 100
[SwitchA-GigabitEthernet0/0/1] quit
[SwitchA] interface vlanif 100
[SwitchA-Vlanif100] ipv6 enable
[SwitchA-Vlanif100] ipv6 address fc00:1::1/64
[SwitchA-Vlanif100] quit

[SwitchA] display ipv6 interface vlanif 100

# 配置SwitchB。
[SwitchB] ipv6
[SwitchB] vlan 100
[SwitchB-vlan100] quit
[SwitchB] interface gigabitethernet 0/0/1
[SwitchB-GigabitEthernet0/0/1] port link-type hybrid
[SwitchB-GigabitEthernet0/0/1] port hybrid pvid vlan 100
[SwitchB-GigabitEthernet0/0/1] port hybrid untagged vlan 100
[SwitchB-GigabitEthernet0/0/1] quit
[SwitchB] interface vlanif 100
[SwitchB-Vlanif100] ipv6 enable
[SwitchB-Vlanif100] ipv6 address fc00:1::2/64
[SwitchB-Vlanif100] quit
[SwitchB] display ipv6 interface vlanif 100

3、配置文件
SwitchA的配置文件
#
sysname SwitchA
#
ipv6
#
vlan batch 100
#
interface Vlanif100
ipv6 enable
ipv6 address FC00:1::1/64
#
interface GigabitEthernet0/0/1
port link-type hybrid
port hybrid pvid vlan 100
port hybrid untagged vlan 100
#
return

SwitchB的配置文件
#
sysname SwitchB
#
ipv6
#
vlan batch 100
#
interface Vlanif100
ipv6 enable
ipv6 address FC00:1::2/64
#
interface GigabitEthernet0/0/1
port link-type hybrid
port hybrid pvid vlan 100
port hybrid untagged vlan 100
#
return

如何配置IPv4网络主动访问IPv6网络

USG6000系列配置静态NAT64映射的方法如下:
1、配置NGFW。

# 配置接口GigabitEthernet 1/0/1的IPv4地址。
[NGFW] interface GigabitEthernet 1/0/1
[NGFW-GigabitEthernet1/0/1] ip address 1.1.1.1 24
[NGFW-GigabitEthernet1/0/1] quit

# 开启NGFW的IPv6报文转发功能。
[NGFW] ipv6
# 配置接口GigabitEthernet 1/0/2的IPv6地址。
[NGFW] interface GigabitEthernet 1/0/2
[NGFW-GigabitEthernet1/0/2] ipv6 enable
[NGFW-GigabitEthernet1/0/2] ipv6 address 2001::2 64
[NGFW-GigabitEthernet1/0/2] quit

# 将接口加入安全区域,并配置安全策略。
[NGFW] firewall zone trust
[NGFW-zone-trust] add interface GigabitEthernet 1/0/1
[NGFW-zone-trust] quit
[NGFW] firewall zone untrust
[NGFW-zone-untrust] add interface GigabitEthernet 1/0/2
[NGFW-zone-untrust] quit
[NGFW] security-policy
[NGFW-policy-security] rule name policy1
[NGFW-policy-security-policy1] source-zone trust
[NGFW-policy-security-policy1] destination-zone untrust
[NGFW-policy-security-policy1] destination-address 2001::1 64
[NGFW-policy-security-policy1] action permit
[NGFW-policy-security-policy1] quit
[NGFW-policy-security] quit

# 配置NAT64静态映射关系,FTP Server的IPv6地址2001::1将转换为1.1.1.10。
[NGFW] nat64 prefix 3001:: 96
[NGFW] nat64 static protocol tcp 2001::1 21 1.1.1.10 21

# 配置黑洞路由。
[NGFW] ip route-static 1.1.1.10 32 NULL 0

2、配置PC的IPv4地址。
# 配置PC的IPv4地址为1.1.1.2/24,与接口NGFW的GigabitEthernet1/0/1同一网段。

3、配置FTP Server的IPv6地址。
# 配置Server的IPv6地址为2001::1/24,与接口NGFW的GigabitEthernet1/0/2同一网段。