配置关键点
System View: return to User View with Ctrl+Z.
[H3C]sysname SW1
[SW1]vlan 10
[SW1-vlan10]quit
[SW1]int vlan 10
[SW1-Vlan-interface10]ipv6 address 1::1 64
[SW1-Vlan-interface10]quit
[SW1]int GigabitEthernet1/0/3
[SW1-GigabitEthernet1/0/3]port link-type access
[SW1-GigabitEthernet1/0/3]port access vlan 10
[SW1-GigabitEthernet1/0/3]quit
[SW1]local-user weijianing
New local user added.
[SW1-luser-manage-weijianing]password simple weijianing
[SW1-luser-manage-weijianing]service-type http https
[SW1-luser-manage-weijianing]quit
[SW1]ip http enable
[SW1]ip https enable
Day: 2023年6月9日
交换机配置接口的IPv6地址示例
配置思路
配置接口的IPv6地址思路如下:
1、使能SwitchA和SwitchB的IPv6转发能力
2、配置接口的IPv6地址
操作步骤
1、使能Switch的IPv6转发能力
# 配置SwitchA。
[SwitchA] ipv6
2、配置接口的IPv6地址
[SwitchA] vlan 100
[SwitchA-vlan100] quit
[SwitchA] interface gigabitethernet 0/0/1
[SwitchA-GigabitEthernet0/0/1] port link-type hybrid
[SwitchA-GigabitEthernet0/0/1] port hybrid pvid vlan 100
[SwitchA-GigabitEthernet0/0/1] port hybrid untagged vlan 100
[SwitchA-GigabitEthernet0/0/1] quit
[SwitchA] interface vlanif 100
[SwitchA-Vlanif100] ipv6 enable
[SwitchA-Vlanif100] ipv6 address fc00:1::1/64
[SwitchA-Vlanif100] quit
[SwitchA] display ipv6 interface vlanif 100
# 配置SwitchB。
[SwitchB] ipv6
[SwitchB] vlan 100
[SwitchB-vlan100] quit
[SwitchB] interface gigabitethernet 0/0/1
[SwitchB-GigabitEthernet0/0/1] port link-type hybrid
[SwitchB-GigabitEthernet0/0/1] port hybrid pvid vlan 100
[SwitchB-GigabitEthernet0/0/1] port hybrid untagged vlan 100
[SwitchB-GigabitEthernet0/0/1] quit
[SwitchB] interface vlanif 100
[SwitchB-Vlanif100] ipv6 enable
[SwitchB-Vlanif100] ipv6 address fc00:1::2/64
[SwitchB-Vlanif100] quit
[SwitchB] display ipv6 interface vlanif 100
3、配置文件
SwitchA的配置文件
#
sysname SwitchA
#
ipv6
#
vlan batch 100
#
interface Vlanif100
ipv6 enable
ipv6 address FC00:1::1/64
#
interface GigabitEthernet0/0/1
port link-type hybrid
port hybrid pvid vlan 100
port hybrid untagged vlan 100
#
return
SwitchB的配置文件
#
sysname SwitchB
#
ipv6
#
vlan batch 100
#
interface Vlanif100
ipv6 enable
ipv6 address FC00:1::2/64
#
interface GigabitEthernet0/0/1
port link-type hybrid
port hybrid pvid vlan 100
port hybrid untagged vlan 100
#
return
如何配置IPv4网络主动访问IPv6网络
USG6000系列配置静态NAT64映射的方法如下:
1、配置NGFW。
# 配置接口GigabitEthernet 1/0/1的IPv4地址。
[NGFW] interface GigabitEthernet 1/0/1
[NGFW-GigabitEthernet1/0/1] ip address 1.1.1.1 24
[NGFW-GigabitEthernet1/0/1] quit
# 开启NGFW的IPv6报文转发功能。
[NGFW] ipv6
# 配置接口GigabitEthernet 1/0/2的IPv6地址。
[NGFW] interface GigabitEthernet 1/0/2
[NGFW-GigabitEthernet1/0/2] ipv6 enable
[NGFW-GigabitEthernet1/0/2] ipv6 address 2001::2 64
[NGFW-GigabitEthernet1/0/2] quit
# 将接口加入安全区域,并配置安全策略。
[NGFW] firewall zone trust
[NGFW-zone-trust] add interface GigabitEthernet 1/0/1
[NGFW-zone-trust] quit
[NGFW] firewall zone untrust
[NGFW-zone-untrust] add interface GigabitEthernet 1/0/2
[NGFW-zone-untrust] quit
[NGFW] security-policy
[NGFW-policy-security] rule name policy1
[NGFW-policy-security-policy1] source-zone trust
[NGFW-policy-security-policy1] destination-zone untrust
[NGFW-policy-security-policy1] destination-address 2001::1 64
[NGFW-policy-security-policy1] action permit
[NGFW-policy-security-policy1] quit
[NGFW-policy-security] quit
# 配置NAT64静态映射关系,FTP Server的IPv6地址2001::1将转换为1.1.1.10。
[NGFW] nat64 prefix 3001:: 96
[NGFW] nat64 static protocol tcp 2001::1 21 1.1.1.10 21
# 配置黑洞路由。
[NGFW] ip route-static 1.1.1.10 32 NULL 0
2、配置PC的IPv4地址。
# 配置PC的IPv4地址为1.1.1.2/24,与接口NGFW的GigabitEthernet1/0/1同一网段。
3、配置FTP Server的IPv6地址。
# 配置Server的IPv6地址为2001::1/24,与接口NGFW的GigabitEthernet1/0/2同一网段。