3Com Router Configuration Guide
Marlborough, MA
3Com Corporation
Campus Drive
01752-3064
Page
VPN
List conventions that are used throughout this guide
This guide describes 3Com routers and how to configure them
Text Conventions
About this Guide
3Com Router Introduction 3Com Router User Interface
Page
3COM Router Introduction
List of the 3Com Router 1.x features
Features of the 3Com
Following table lists the basic features of the 3Com Router
Router Version
RIP-1/RIP-2
NAT
Quality of service
3Com Router
New Features of the 3Com Router 1.x
3COM Router Introduction
Environment
Configuration
Establish
Port
Establish a new connection
Set port communication parameters
Establish a remote configuration environment
Environment
Configuration
Connection
Router
Workstation Ethernet
Command Line
Interface CLI
3COM Router User Interface
System view Table
Views and their prompts
Loopback 0 in any
Async 0 in any
Ethernet 0 in any
Enter controller
Full help
Helps
Partial help
For example
List of common command line error messages
Common error Message Causes
Routerdisplay ?
Display Features
Command Line
Features
Three options are available for users
User Identity
Following commands
Please perform the following commands in system view
Management
System
Configure the router name
Set the system clock
Reboot the system
By default, the system clock is 080000 1 1
Execute the following commands in all views
Display the System Information Router
System Management
Page
Storage Media and File Types Supported by the System
Softwaresoftware
Input Ctrl+D, and the following prompt information displays
Upgrade Boot ROM Software
Software
Upgrade the 3Com
Router Main Program
Main Program software
XModem Approach
Modify the terminal baud rate
Transfer File dialog box
Enable the Tftp server program
Preparation for using the Tftp server
Tftp server application can run on Windows 95/98/NT
Press Enter and the following prompts will be displayed
Tftpd32 Set interface
Enter Ctrl+B and the system prompts
Network Interface Parameters
Press Enter for loading
Download configuration files from a Tftp server
Operation Command Downloads the 3Com Router main
Get ip-addr file-name system
Prepare for using the FTP server
Set an authentication mode for an FTP server
Upgrade the 3Com Router Main Software with FTP
Enable FTP server
FTP Approach
Back up the 3Com Router Main Program Software
Tftp Approach
Copy ip-addr file-name system
Setup Users Dialog Box
Port-number user user-name password
Configure on-line upgrading of the card
Update slot slot-number ftpserver host-name
Password
Perform the following command in system view
Configuration File Management
Download Configuration File
Content and Format of the Configuration File
Router download config
Load configuration files
Download Config
Set the binary transmission protocol to XModem/CRC
Upload configuration files to a Tftp server
Display current-configurationcommand output backup approach
Back up Configuration Files
File-name config
Please use the following commands in corresponding views
View router configuration
Set the Flag Bit to Enter the Initial Setup Mode
Select and view the storage media of configuration file
Save current configuration
Erase the configuration file in storage media
Client via port 20 and transfer data
Configure FTP
Configure authentication and authorization of FTP server
Files on the router
Please enter the following commands in system view
Enter the following commands in system view
Configure Parameters of FTP Service
Set the authentication mode of FTP server
Force to shut down FTP process
Set FTP update mode
Set the connection time limit of FTP service
Force to shut down FTP process
Server Display detailed information of the FTP user
Display FTP Server Display FTP server
Display ftp-server
Display local-user
System Management
Service at Console Port
Terminal Service
Features of Terminal
Overview
Terminal Message
Service
Set the attributes of terminal service
On one router
Display Terminal Message Service
Perform the following configuration in all views
Configure Terminal Message Service
Enable/disable receiving messages from other terminals
Terminal Service
Typical Example Terminal Message Service Configuration
Dumb Terminal
Configure Auto-execute command
Configuration Examples Dumb Terminal Service
Configure Dumb Terminal
By default, no dumb terminal service is configured
Configure the auto-execute command command
Terminal Service Telnet Connection
Configure the interface to dumb terminal mode
Router-Serial1auto-execute command telnet
Service Value
Terminal service features of telnet connection
Establish Telnet Connection
Service-port
Setup Reverse Telnet Connection
Enable Reverse Telnet connection
Establish Telnet Server or Telnet Client connection
Example of Telnet
Typical Configuration Example of Telnet Reverse Telnet
Force shut down Telnet Process
Force to shut down Telnet process
Example of Reverse Telnet
Rlogin Terminal
Use Rlogin protocol
Router telnet 10.110.164.44
Rlogin ip-address username
Establish a Rlogin connection
Typical Rlogin Configuration Examples
Use local user name abc to log on
PAD Remote
Access Service
Communicate with other terminals through the X.25 network
Service-type type password
Configure X.25 PAD remote user
Configure X.25 PAD remote user
Local-user user-name
Establish an X.25 PAD call
Start AAA authentication of X.25 remote users
Enable AAA authentication for X.25 remote PAD users
Establish a X.25 PAD call
Display and Debug
II. Networking Diagram
III. Configuration Procedure
Set the Response Time to the Invite Clear Message
RouterA-serial0x25 x121-address
Fault Diagnosis Troubleshooting
Set its X.121 address as
RouterB-serial0x25 x121-address
Snmp Overview
Development of Snmp
Configuring Network Management
Snmp architecture
SNMP-supported MIB
3Com Router-supported MIB
By default, the system disables Snmp service
Engineid
Perform the following configurations in system view
Configure Snmp version and related tasks
V1 username
Configure information of router administrator
Configure the traps to be sent by the router
Interface-number
Name
Perform the following commands in all views
Display and debug Snmp
Byte-count
Configure an IP address for the Ethernet interface ethernet
Example 1 Configure Network Management of SNMPv1
Set the community name and access authority
Examples Networking Requirements
Rmon Overview
Configure an IP address for the Ethernet interface ethernet
Network equipment
Schematic diagram of Rmon application
Enable Rmon statistics
Examples Networking Requirement
RouterA-Ethernet0 rmon promiscuous
Commands to display information of the whole system
Ping command
Test Tool of Network Connection
Ping supporting IPX protocol
Ping supporting IP protocol
System displays
Ip-address
Timeout host
Following command can be executed in any command modes
Tracert command
MaxTTL -p port -q nqueries
Configure on the router
Log Function
Set the direction of syslog outputting log information
Sylog-defined severity is as follows
Set Severity of Log Information
Perform the following task in system view
Set Filter of Log Information
Display and Debug Syslog
Configuration of Log Host
Turn on/turn off syslog
Turn on/turn off syslog
Routerinfo-center enable
Syslog Configuration Example
Turn on debugging switch of PPP module
Routerdebug ppp all
Display and Debugging Tools
POS Terminal Access Service
Dial-up POS Access
POS Network Access
Advantages of POS network access are as follows
Configure POS access port
POS Access Service Configuration
Start POS server
App-number
Configure a POS application
Interface-type interface-number
Ip-address port-number
Default app-number
Configure POS multi-application mapping table
Bind the source address of TCP connection
Set the parameters of FCM used during Modem negotiation
Display and Debug POS Access
Display and debug POS access
Set the parameters of FCM used during Modem negotiation
Configure the POS access interface FCM0
Typical Configuration Example of POS Access Service
Configure the Ethernet interface Ethernet
Configure POS access interface FCM1
Configure POS access interface FCM0
Configure POS access interface FCM2
III. Configuration Procedure 1 Start the POS access server
III. Configuration Procedures
Configure Async 0 to operate in POS application mode
Configure Async 1 to operate in POS application mode
Configure Router a Start the POS access server
Configure Router B Configure the Ethernet interface Ethernet
RouterA ip route-static 10.1.1.2 255.255.255.0 serial
III Interface
106
Interface
Configure Interface
Enter the Interface View
Set time interval for flow control statistics
Exit the Interface View
Interface view, input quit to return to the system view
Interface-description
Display and debug interface
Please use the following commands in all views
Display and Debug Interface
Interface state information
Interface Configuration Overview
Configure Ethernet Interface
Ethernet Interface
Set IPX address
Enter view of specified Ethernet interface
Set IP address
Set frame format of sending message
Display and Debug
Select work mode of Ethernet interface
Enable or disable internal loopback and external loopback
Select working rate of fast Ethernet interface
Troubleshooting
Typical Ethernet Interface Configuration Example
II. Network Diagram
Troubleshooting
Configuring LAN Interface
Introduction
WAN Interface
Asynchronous Serial Interface
Interface async number
Enter view of specified asynchronous interface
Interface serial number
Modem in out
Set the work mode of asynchronous serial interface
Set the baud rate of asynchronous serial interface
Link-protocol slip ppp
Flow-control none software
Async Mode protocol
Hardware inbound outbound
Odd space
Works in flow mode
Parity even mark none
Stopbits 1 1.5
Set MTU of asynchronous serial interface
Backup
AUX Interface
Set the coding format of Modem
Configure Synchronous Serial Interface
Configure AUX interface
Configure AUX interface
Synchronous Serial Interface
Physical-mode sync
Enter view of specified synchronous interface
Set the link layer protocol of synchronous serial interface
Link-protocol fr hdlc
Set the baud rate of synchronous serial interface
Select work clock
Working modes have different working clocks
Synchronous serial interface is 64000 bps
Select work clock
Inversion is disabled by default
Set clock inversion
Undo detect dcd
Internal loopback/external loopback are disabled by default
Detect dcd
Reverse-rts
Technical Background
Isdn BRI Interface
Idle coding of synchronous serial interface is 7E
Graphics and video
Be clear about the following items before the configuration
Preparations before Configuration
Function group includes
Network protocols such as IP and IPX
Channelized operating mode
CE1/PRI Interface
Interface or a PRI interface
Interface
Configure CE1/PRI CE1/PRI interface configuration includes
Dial-on-Demand Routing
Enter the view for a specified interface
Bind the interface to be channel sets
Enter the synchronous serial interface view
Number set-number
Pri-set timeslot-list range
Bind the interface to be a pri set
Enter the Isdn interface view
Undo pri-set
Set the line clock of the CE1/PRI interface
Enable/disable the internal loopback/external loopback
Set the line code format on the CE1/PRI interface
Set the frame format of CE1/PRI interface
Configure CT1/PRI
CT1/PRI Interface
Controller t1 number
Operation Command Enter the view of CT1/PRI interface
Timeslot-list range speed
Interface serial number23
Set the line clock of the CT1/PRI interface
Set the line code format on the CT1/PRI interface
Set the frame format of CT1/PRI interface
E1-F Interface
Choice for E1 access
E1-F interface does not support PRI operating mode
Them into multiple channel sets
Interface serial serial-number
Set Operating mode for an E1-F interface
Enter the view of an E1-F interface
Fe1 unframed
Set line code format for E1-F interfaces
Set interface rate after binding operation
Set line clock for an E1-F interface
Display and debug E1-F interface
Enable/Disable local/remote loopback on an E1-F interface
Set frame format for an E1-F interface
Serial-number
T1-F Interface
Choice for T1 access
T1-F interface does not support PRI operating mode
193 X 8k = 1544kbps
Set line code format for T1-F interface
Set line clock for a T1-F interface
Enable/Disable local/remote loopback on a T1-F interface
Set frame format of T1-F interface
Display and Debug T1-F
Other related information
CE3 Interface
Display and debug T1-F interface
Enter the view of the specified E3 interface
Set the operating mode of E1 channel
Set the operating mode of CE3 interface
Set E1 frame format
44.736Mbps
Mode non-channelized mode
CT3 Interface
Data bandwidth 44736kbps
Enter specified CT3 interface view
Set clock mode of the CT3 interface
Set clock mode of the T1 channel
Set cable length of the CT3 interface
By default, the CT3 interface uses the C-bit frame format
By default, loopback is disabled Set Frame Format
Perform the following configurations in CT3 interface view
Set CRC of the serial interface
Set the operating mode of T1 channel
T1 line-number unframed
Disable and Enable CT3 interface
Display and debug of the CT3 interface
Configuring WAN Interface
Logical Interface
Dialer Interface
Configure Loopback
Null Interface
Sub-Interface
Number.sub-number
Configure sub-interfaces of Ethernet interface
Create and delete WAN sub-interface
Number.sub-number multipoint
Select frame relay link layer protocol
Enter the view of WAN interface Serial0 of router a
Routerinterface serial
Set its IP address to 202.38.160.1 and address mask to
Configure the static route from router a to LAN2 and LAN3
Specify DTE as its frame relay terminal type
Allocate a virtual circuit with Dlci 50 to it
Interface virtual-template
Set work parameters of virtual-template
Create or delete virtual-template
Undo interface
Display state of the specified virtual-template
Fault 1 Fail to create virtual interface
Troubleshooting the reasons may be as follows
Virtual-template-number
Link Layer Protocol
164
PPP Authentication Mode
PPP Overview
Configuring PPP and MP
For detailed description of PPP, refer to RFC1661
Configure PPP
MP Overview
Transmission time of large packets
Configure the peer authenticates the local in PAP mode
Configure the link layer protocol of the interface to PPP
Configure the local authenticates the peer in PAP mode
Name-list
Cipher password
Configure the local authenticates the peer in Chap mode
Configure as the peer authenticates the local in Chap mode
User username
Configure the time interval of PPP negotiation timeout
Configure AAA authentication and accounting of PPP
Configure PPP compression
Ppp lqc forbidden-percentage
Perform the following configuration in interface view
Configure PPP link quality monitoring
Resumptive-percentage
Create/Delete virtual template
Configure MP Protocol Parameters Create Virtual Template
Configure Operating Parameters of Virtual Template
Bind the physical Interface to a Virtual Template
Specify the conditions for MP binding
User-name
Configure virtual Baud rate on interface
Frags
Configuration Requirement
Typical PPP Configuration Example
Example
Configure to start Chap authentication at this side
Typical MP Configuration Example
II. Configuration Procedure
Set local username as Router1
Configure router-b Add a user for router-a
Configure virtual interface template
Configure router-c Add a user for router-a
Fault 2 Physical link fails to turn to Up status
Fault Diagnosis Troubleshooting
Fault 1 Link always fails to turn to up status
Indicates that the interface is shutdown
PPoE Overview
Introduction to PPPoE client
Configure PPPoE
Client
Configure PPPoE session
Reset or delete PPPoE session
Access a LAN to the Internet via Adsl
Typical PPPoE Configuration Example
Perform the display and debugging command in all views
III. Configuration Procedure 1 Configure a dialer interface
Configure the DDN interface Serial
Configure a PPPoE session
Configure the LAN interface and the default route
Use Adsl as Standby Line
Configuring Pppoe Client
Slip Overview
Configure Slip
Asynchronous mode
For further details about SLIP, you can refer to RFC1055
Time
Enable/Disable the information debugging of Slip
Typical Slip
Interconnect two Router routers via Pstn and run IP
Configure the Dialer String to router B
Configure Router a Configure Dialer Rule
Configure IP address of synchronous/asynchronous interface
Configure the default route to Route B
Routerip route-static 0.0.0.0 0.0.0.0
Configure Isdn
Isdn Overview
Configure the length of call reference
By default, DSS1 signaling is used on Isdn PRI interfaces
Configure type of signaling on Isdn interface
Configure the receiving mode
Timer-name all
Configure the sending mode
Configure interval for Qsig signaling timer
Time-interval
Perform the following configuration in Isdn interface view
Configure Call Processing Method on an Interface
Perform the display and debugging commands in all views
Configure the Isdn PRI interface
Typical Configuration Example
Configure Router a Create an Isdn PRI interface
RouterB transmit data after the call is set up
Configure Router a
Configure Router B
Lapb
Protocols Overview
PSN
25 packet and Lapb frame
By default, the Lapb modulus is Modulo
Configure Lapb
By default, k is Configure Lapb N1, N2
Configure
Set X.25 working mode
Configure X.25 Interface
Set/Cancel the X.121 address of the interface
Address
25 channel delimitation parameters
Parameter Meaning
Set/Cancel X.25 packet numbering modulo
By default, X.25 interface use modulo 8 mode
Set/cancel X.25 virtual circuit range
Finally, the following should be noted
Set the default flow control parameter
Configure X.25 flow control parameter
Configure X.25 Interface Supplementary Parameter
Out-packets
25 layer 3 timer
Set X.25 layer 3 timer delay
Alias-string
Specify/Cancel an alias for the interface
Alias match modes and meanings
Match-type alias-string
Set/Cancel the default upper layer protocol borne on
Protocol-address x121-address
Configure X.25 Datagram Transmission
Create the permanent virtual circuit PVC
Address option
X25 pvc pvc-number protocol
Configure Additional Parameters Datagram Transmission
Create/Delete permanent virtual circuit
Undo x25 pvc pvc-number
Interface view, perform the following task
Specify/Cancel packet pre-acknowledgement
Configure X.25 user facility
Configure the sending queue length of virtual circuit
Serial port view, list1 can be quoted
Address broadcast
Set broadcast via
Set interface with standby center
Address logic-channel
Configure X.25 Switching
Switching Function
Configure X.25 sub-Interface
Number.subinterface-number multipoi
Add or delete a PVC route
Configure X.25 Load Balancing
Introduction to X.25 Load Balancing
Configure X.25
List of Configuration Tasks of X.25 Load Balancing
Diagram of X.25 network load balancing
Create/Delete X.25 hunt group
Start /Close X.25 switching function
Add/Delete interfaces or XOT Tunnels in hunt group
Configure X.25 over TCP XOT
Configure X.25 over Other Protocols
Add/delete other X.25 switching routes
Introduction to XOT Protocol
Configure XOT
Configure SVC XOT switching
Start X.25 switching
Configure local switching
For PVC, perform the following tasks in interface view
Configure X.25 over Frame Relay Annex G
Configure Annex G Data Interoperation
Configure PVC XOT switching
Configure Keepalive and xot-source attributes
Configure the X.25 Attributes for a Dlci
Configure the X.25 attributes for an Annex G Dlci
Current status of Lapb
Typical Lapb Configuration Example
By default, X.25 template is not applied on DLCIs
Specify IP address for this interface
Configure Router a a Select interface
Configure Router B Select interface
Specify X.121 address of this interface
Specify address mapping to the peer
Connect the Router to X.25 Public Packet Network
Configure Router B Configure interface IP address
Configure Router a Configure interface IP address
Configure Router C Configure interface IP address
Range
Configure Virtual Circuit I. Networking Requirement
Disabled
Transmit IP Datagram via X.25 PVC
Typical Sub-Interface Configuration Example
Router-Ethernet0ip address 196.25.231.1
Configure Router D
Configure Router C
Create sub-interface serial
SVC Application of XOT I. Networking Requirement
Routerx25 switch svc 2 interface serial
Configure Router C Start X.25 switching
Configure Serial
Routerx25 switch svc 1 xot
Application of X.25 Load Balancing
S11
Enable X.25 switching in system view
Configure X.25 switching route to forward to X.25 terminal
Add Serial 1, Serial 2 and XOT Tunnel to hunt group
Load Balancing Carrying IP Data Transmission
Routerx25 switch svc 1111 xot
Routerx25 switch svc 8888 interface serial
Routerinterface serial Router-Serial0link-protocol x25 dce
Configure static route to RouterC
Configure RouterA Configure interface Ethernet
Configure interface Serial
Configure RouterB Configure interface Ethernet
Configure the local X.25 address
Configure the static route to RouterA and RouterB
Configure RouterA Create an X.25 template
Configure an IP address for the local interface
Associates an X.25 template with the Dlci
Configure RouterB Create an X.25 template
Map the Frame Relay address to the destination IP address
SVC Application of X.25 over Frame Relay
Configure Serial 0 as the X.25 interface
Configure the router Router B Enable X.25 switching
Enable switching on Frame Relay DCE
Configure Serial 1 as the Frame Relay interface
Configure the Frame Relay Annex G Dlci
Configure X.25 over Frame Relay switching
Configure the router Router C Enable X.25 switching
Configure local X.25 switching.Router-fr-dlci-100annexg dte
Configure an X.25 template
Configure Router D Configure the basic X.25 parameters
Configure Router B Enable X.25 switching
Configure S1 as the Frame Relay interface
Configure Serial Configure S1 as the Frame Relay interface
Lapb
Facility options inhibited by network have been carried
Fault Diagnosis and Troubleshooting of X.25
Configuring Lapb
Configuring Frame Relay
Relay
By default, the interfaces link layer protocol is PPP
Link-protocol fr ietf
Nonstandard
Configure Frame Relay interface type
Configure Frame Relay LMI protocol type
Fr lmi n392dce n392-value
Fr lmi n391dte n391-value
Undo fr lmi-n391dte
Undo fr lmi n392dce
Undo fr lmi t391dte
Undo fr lmi n393dce
Fr lmi t391dte t391-value
Fr lmi t392dce t392-value
Configure Frame Relay static address mapping
Configure Frame Relay dynamic address mapping
Fr dlci
Configure Frame Relay local virtual circuit number
Create Frame Relay sub-interface
Undo fr
Applying dynamic address mapping to the sub-interface
Configure virtual circuit of Frame Relay sub-interface
Establish static address mapping
Configure Frame Relay local switched PVC number
Configure the Frame Relay local virtual circuit number
Configure the route for Frame Relay PVC switching
Configure the Frame Relay switched PVC
Configure Multilink Frame Relay FRF.16
Overview
Configure MFR interface parameter
Configure MFR
Configure a MFR bundle interface MFR interface
Subnumber
Frame Relay Compression Configuration
Configure the parameters of the bundle link interface
Configure Frame Relay Fragment Attributes
By default, interfaces use initiative compression
Configure Frame Relay Fragment FRF.12
Configure Frame Relay Compression on multipoint interface
Fr traffic-shaping
Disable the Frame Relay traffic shaping
Frame Relay Traffic Shaping
Undo Fr traffic-shaping
Rate
Frame Relay Queueing Management
Frame Relay Traffic Policing
150 Kbps
100 Kbps CI R ALLOWº£ 64 Kbps
Frame Relay Congestion Management
Frame Relay DE rule list
Configure Frame Relay Traffic Shaping
By default, no Frame Relay class is created
Configure the Frame Relay class parameters
Undo fr-class class-name
Enable/Disable the Frame Relay traffic shaping
Configure the parameters of Frame Relay class
Enable/Disable the Frame Relay traffic policing
Queue-percentage
Dequeue-percentage
Configure Frame Relay Queueing Management
Configure Frame Relay DE Rule List
Configure the Frame Relay PVC queueing
Configure Pipq
Configure a tunnel interface
Configure Frame Relay over Other Protocols
Configure Frame Relay over IP
Configure Frame Relay switching
Frame Relay over Isdn Operation Process and Fundamentals
Networking of a typical Frame Relay over Isdn application
Physical Connection Between Frame Relay over Isdn Devices
Frame Relay switching connection between DTE devices
Back-to-back connection between DTE and DCE devices
Configure Frame Relay over Isdn
Configure the Frame Relay-related commands
Configure the link layer protocol of the interface
Configure the commands related to Frame Relay switching
Dlci
Display and Debug Frame Relay
Configure parameters related to dialer profiles
Display and debug Frame Relay
Isdnsubaddress
Type number dlci
Number dlci dlci-number
Number interface serial
Mfr number
Interconnect LANs via Frame Relay Network
Typical Frame Relay Configuration Example
Configure static address mapping
Router-Serial1fr map ip 202.38.163.251 dlci
Interconnect LANs via Private Line
Configure local virtual circuit
Relay FRF.16
Router-Serial1ip address 202.38.163.253
Example FRF.9
Create a MFR interface
Bundle Serial 0 and Serial 1 to mfr
Them
FRF.12
III. Configuration Procedure 1 Configure Router a
III. Configuration Procedure 1 Configure RouterA
Fragment between them
Router-fr-class-96ktraffic-shaping adaptation becn
IP Configuration
Routerfr class 96k
Typical Frame Relay over
Configure Frame Relay over IP
Configure IP interface Ethernet0
Configure tunnel interface
Router-Serial0fr interface-type dce
Router-Dialer0dialer number Router-Dialer0dialer call-in
Configure the Frame Relay parameters on Bri0
Router-Bri0fr map ip 110.0.0.2 dlci
Router-Dialer0fr interface-type dce
Configure the Frame Relay-related parameters on Bri0
Configure Frame Relay SVCs
Router-Serial1.1ip address 130.0.0.2
Fault 1 the physical layer in Down status
Fault Diagnosis Troubleshooting Frame Relay
Fault 4 Frame Relay data cannot be transmitted across Isdn
Configuring Frame Relay
By default, the link layer protocol of the interface is PPP
Configure Hdlc
Configure Hdlc Display and Debug Hdlc
Configure the link layer protocol of the interface to Hdlc
Enable Hdlc packet debugging
Debugging Hdlc Packet Interface
Bridge Overview
Configure Bridge’s Routing Function
Typical Bridge Configuration
Bridge Overview
Obtain address table
Main Functions of Bridging
Bridge Overview
Forward and Filter
Final bridging address table
Eliminating loop
Filter not forward
Preliminary examination state of bridging loops
Spanning Tree Topology
Bpdu Forwarding Mechanism
Spanning tree topology
Enable/Disable bridging functions
Configure Bridge’s Routing Function
By default, disable bridging functions
Bridge enable
Add ports to a bridge-set
Configure static address table entries
Specify the STP version supported by the bridge-set
Mac-address
Configure the aging time of dynamic address table
Enable/Disable forwarding by using dynamic address table
Disable/Enable STP on ports
Configure the path cost of bridge port
Configure the bridge priority
Configure the bridge port priority
Configure the interval for sending BPDUs
Configure the forward delay for the port status transition
Configure the Max age of Bpdu
Create ACLs based on varied Ethernet encapsulation formats
Acl acl-number
Configure a bridge-template interface
Enable/Disable bridge’s routing
Bridge-set
Link-set
Define a link-set
Share load by source MAC address
Bridgebridge-set link-set link-set
Map the bridge address to Dlci
Configuration on the interface
Define a dialer list
Display and debug bridge
Typical Bridge Configuration
Display and Debug Bridge
Transparent Bridging Multiple LANs
Configure Router B
Configure Router a
Router-Serial0bridge-set 1 stp disable
Transparent Bridging over Frame Relay
Transparent bridge over the Frame Relay
Router-Serial1dialer route bridge broadcast
Connected are failed
Asynchronous Dial-in
Standby
Please refer to Figure
Bridge-Template interface
Networking of bridge-template interface
Bridging on Sub-Interfaces
Networking for bridging on sub-interfaces
Routerbridge enable Routerbridge 1 stp ieee
Link-Set Configuration I. Networking Requirements
Router-Serial1bridge-set 1 link-set
Network Protocol
316
Configuring IP Address
IP address classes and ranges
Network IP network range Description Class
Sub-net classification of IP address
Configure master IP address of an interface
Configure IP Address Configure IP Address for an Interface
By default, the interface has no master IP address
Ip address ip-address mask
Delete slave IP address of an interface
Configure slave IP address of an interface
Ip address ip-address mask Mask-length sub
Undo ip address ip-address
Introduction to IP address unnumbered
By default, the interface has no negotiating IP address
Configure IP Address Unnumbered for an Interface
Set negotiable attribute of IP address for an interface
Configure IP address unnumbered
Configuration Example I. Configuration Requirements
Configure routing to Ethernet segment of Shenzhen router R1
Borrow IP address of Ethernet interface
Router-Ethernet0ip address 172.16.20.1
Configure router R1 of Shenzhen subsidiary
Borrow IP address of Ethernet
Router ip route-static 0.0.0.0 0.0.0.0
Page
Configuring IP Address
Undo arp static ip-address
Define a static ARP mapping
Arp static ip-address
Arp dynamic ip-address
Name Resolution
Configure Domain
Name Resolution
Display and Debug ARP
Display and Debug domain name resolution
Display and Debug Domain Name Resolution
Display ip host
Interface-number.subinterface-number
Create Ethernet subinterface
Specify the Vlan on which Ethernet subinterface is located
Vlan-type dot1q vid vlan-id
Display and Debug Display and Debug Vlan
Configure IP address of Ethernet subinterface
Typical Vlan Configuration Example
Display vlan
Troubleshooting The steps below can be taken
Configure IP address for the subinterface
Configure Vlan information of LAN Switch
Router-Ethernet0.1ip address 3.3.3.8
Dhcp vs Bootp
Dhcp Server Configuration
Fault Ping Two PCs, but fails to ping them through
Background of the Dhcp development
Following figure
Occasions in which Dhcp server is applied
Dhcp server Dhcp clients
Dhcp client logs into the network again
Dhcp Server Configuration
Undo Dhcp enable
Enable/disable the Dhcp service
Dhcp Enable
Dhcp server ip-pool pool-name
Netmask
Configure the statically binding IP address and MAC address
Network ip-address
Low-ipaddress high-ipaddress
Low-ipaddress high -ipaddress
Configure the domain names of Dhcp clients
By default, the IP address of DNS is not configured
Configure the gateway router address of client
Configure the DNS addresses in a Dhcp address pool
Nbns-list ip-address1
Set the type of NetBIOS node for Dhcp client
Set the type of NetBIOS node for Dhcp client
Ip-address2 ... ip-address8
Display and Debug Dhcp Server
Use reset, debugging and display command in All views
Configure Dhcp self-defined options
Display and Debug Dhcp servers
Router dhcp enable
III. Configuration Procedures 1 Enable the Dhcp service
Router dhcp server forbidden-ip
At the client, use ipconfig /releaseall
Router-dhcp2nbns-list Router-dhcp2gateway-list
Ip relay-address ip-address
Configure interface relay address
Operation Command Configure interface relay address
Delete interface relay address
IP address from Dhcp server through application
Dhcp Relay Configuration Requirement
Dhcp Relay
Available on Dhcp server
Configure Dhcp relay router
Networking diagram of an Dhcp relay configuration example
Fault 2 fail to forward transparent transmission protocol
Private Network Address and Public Network Address
Under which condition should the address be translated
Role the Network Address Translation NAT plays
Characteristic of Network Address Translation NAT
Mechanism of Network Address Translation NAT
End-addr pool-name
Configure address pool
Performance of Network Address Translation NAT
Pool-name
Undo nat outbound acl-number
Nat outbound acl-number
Address-group pool-name
Undo nat outbound
Nat server global global-addr global-port
Configure the Internal Server
Configure the Timeout of address translation
Www inside inside-addr inside-port any
Typical NAT Configuration Example
Display and Debug NAT Display and debug NAT
Set internal FTP server
Configure address pool and access list
Allow address translation of segment at 10.110.10.0/24
Set internal WWW server
Configure a default route to serial
Configure address access control list and dialer-list
Configure dial-up property for the interface
Correlate the address translation list and the interface
Fault 2 Internal server abnormal
Configuring IP Application
Configure maximum transmission unit on an interface
Configure IP
To configure IP performance, carry out the following steps
Performance
Configure TCP
Tcp window size
Configure Fast
Forwarding
Forwarding
Perform the following configuration in system view
Display and Debug IP
Display and Debug Fast Display and Debug fast forwarding
Router info-center enable Router debugging tcp packet
Troubleshooting IP Performance Configuration
Router info-center enable Router debugging tcp event
Configuring IP Count
Ip count enable
IP Count Configuration
Enable/Disable IP Count service
Undo ip count enable
Configure IP Count list
Configure IP Count on an interface
Specify count maximum of exterior
Specify count maximum of interior
By default, IP Count entries time out after 720 minutes
Count
Display and debug IP Count
Not been configured on the interface of the router
IV. Test Procedure
Information is displayed
Configuring IP Count
Configuring IPX
IPX address
SAP
Configure relative parameters of IPX SAP
Configure IPX
Modify length of service information reserve queue
Its first Ethernet interface as its node address
Enable/Disable a Default Route
Enable IPX interface
Configure IPX RIP static route
Perform the following task in interface view
Configure the maximum size of RIP update packet
Configure RIP updating period
Configure RIP aging period
Configure the maximum number of IPX parallel route
Configure length of route reserve queue
Configure static service information table item
Configure reply to SAP GNS request
Configure SAP aging period
Configure size of SAP maximum updated message
Ipx sap timer update seconds
Configure Using touch-off for an interface
Disable split-horizon
Modify Encapsulation Format of IPX Frame on Interface
Configure the delay of interface sending IPX packets
Configure management of IPX packet
Encapsulation format of IPX frame
Configure Router a a Activate IPX
Display and Debug IPX Display and Debug IPX
Configure an information about Server2 file service
Configure an address map to Router B
Configure a static route to network ID
Configure an information about Server2 directory service
Configure an information about Server1 directory service
DLSw Protocol
Init-window-size max-frame
Configuration of DLSw
Create DLSw local peer entity
Max-frame-size max-window
Configure Bridge set connecting to DLSw
Create DLSw remote end peer entity
Configure to add ethernet port to Bridge set
Configure Sdlc role
Sdlc-address
Configure Sdlc virtual MAC address
Configure Sdlc address
Controller sdlc-address
Configure XID of Sdlc
Configure Sdlc peer entity
Add synchronous Interface to Bridge set
Configure baud rate of synchronous Interface
Configure to stop running DLSw
Baudrate
Configure LLC2 local acknowledgement delay time
Configure Idle time encoding mode of synchronous Interface
Configure parameters of DLSw timer
Mseconds
Configure LLC2 premature acknowledgement window
Configure modulo value of LLC2
Configure Busy status time of LLC2
Configure retransmission number of LLC2
Configure LLC2 local acknowledgement time
Configure P/F wait time of LLC2
Configure Queue Length of Sending Message of Sdlc
Configure REJ status time of LLC2
Configure queue length of sending message of LLC2
Configure Sdlc local acknowledgement window
Configure retransmission number of Sdlc
Configure maximum receivable frame length of Sdlc
Configure poll time interval of Sdlc
Lsap
Configure SAP address for transforming Sdlc to LLC2
Configure data bi-directional transmission mode of Sdlc
Dsap
DLSw
Typical DLSw Configuration Example
DLSw Configuration Networking Requirement
IP across WAN
DLSw Configuration
Router a Configuration
Router B Configuration
Router dlsw local
Networking diagram of DLSw configuration of SDLC-SDLC
Networking Diagram of SDLC-LAN
Diagnosis
DLSw Fault
When using command display dlsw remote
Virtual circuit cant attain Connected state
Diagnosis and Troubleshooting of DLSw Fault
Configuring Dlsw
VI Routing
404
IP Routing Protocol
IP Routing Protocol
Routing Protocol and Routing Priority
Routing Protocol or Type Corresponding Routing Priority
Ospf ASE
Configuring Static Routes
Default Route
Configure a Static Route
Configuring a Static Route
Configuring a Static Route
Transmitting interface or next hop address
Preference
Configuring a Default Route
Displaying Debugging Routing Table
Other parameters
Static Route
Troubleshooting a
Other
RIP Overview
Configure RIP
Features is not subject to whether RIP has been enabled
Enable RIP at the Specified Network
Enabling RIP
Specify RIP Version
By default, the interface runs RIP-1
Define a Neighboring Router
Peer ip-address
Disable a Host Route
RIP Version 1 enables zero field check by default
Configure Check Zero Field of RIP Version
Specify the Status of an Interface
Summarization for RIP
Authentication on
Enabling Route
Version
Configure Route Import for RIP
By default, the default route metric for RIP is
Configure RIP Horizontal Segmentation on the Interface
Specify a Default Route Metric Value for RIP
Specify Additional Route Metric Value for RIP
Configure filtering route information received by RIP
Distribution for RIP
Set Route Preference
Filter the Routing Information Being Advertised by RIP
Reset RIP
Displaying and Debugging RIP
Display and Debug RIP
RIP Unicast
Ospf Overview
Ospf Configuration Example
Ospf Overview
Displaying and Debugging Ospf
Configuring Ospf
Router id router-id
Enable Ospf
Specify Router ID
Undo router id
Area-id
By default, Ospf is disabled
Area area-id
Ospf network-type broadcast nbma
Configure the Network Type of the Ospf Interface
Configure Sending Packet Cost
P2mp P2p
Configuring a Peer for the Nbma Interface
Cost
Ospf Dr-priority value
Operation Command Set the priority of the interface when
Specify the Router Priority
Undo Ospf dr-priority
Specify Hello Intervall
Specify Dead Interval
Specify Transmit-delay
Configuring a Stubby Area and a Totally
Specify Retransmitting Interval
Stub cost cost area area-id
Perform the following configuration under Ospf view
Configure Totally Stubby Area of Ospf
No-summary
Perform the following configuration in Ospf view
Configure an Nssa Area of Ospf
Area-id advertise notadvertise
Configure Route Summarization Within Ospf Domain
Abr-summary address mask mask area
Undo abr-summary address mask mask
Create and Configuring a Virtual Link
Area-id None Router-id None
Configure Authentication
Key-id
Configure Route Import for Ospf
Configure Parameters When Importing External Routes
Debugging Ospf
Configure filtering route information received by Ospf
Displaying
Filter for Ospf
Configuring Ospf on the Point-to-Multipoint Network
Ospf Configuration Example
Router D 201 Router B 301 302 Router C 1.3
RouterA-Serial0ospf network-type p2mp
Enable Ospf
RouterC ospf enable
RouterB-Serial0ospf network-type p2mp
Configure DR on Ospf Preference
E0 192.1.1.2/24 E0 10.1.2.3/24
1.1 4.4 E0 192.1.1.1/24
E0 192.1.1.4/24
2.2 3.3
RouterA display ospf peer
RouterD display ospf peer
Between Router B and Router C
To configure an Ospf virtual link Configure Router a
RouterB-ospfVlink peer-id 3.3.3.3 transit-area
To configure Ospf peer authentication Configure Router a
Ospf Configuration
Troubleshooting an
Normally
Ospf Configuration Example
Configuring Ospf
BGP Overview
BGP Configuration Example
BGP Overview
Displaying and Debugging BGP
Configuring BGP
By default, BGP is disabled
Resetting BGP Connections Enabling BGP
Perform the following configurations in system view
Perform the following configurations in BGP view
Set the Timers for BGP Peer
Configure the BGP Version of the Peer
Configure BGP Route-update Interval
Configure the Peer to be the Client of the Route Reflector
Configure to distribute default route to the peer
Configure to Send Community Attribute to the Peer
Configure to Distribute Default Router to the Peer
Create a BGP Route Filtering Based on AS Path for the Peer
Create a Fltering Policy Based on Access List for the Peer
Configure the BGP MED Metric
Allow Comparing Path MED
Timers keepalive-interval
Configure the Local Preference
Configure the Keepalive Timer and Holdtime Tmer for BGP
Holdtime-interval
Peer group-name
By default, there is no BGP peer in a peer group
Add a Peer to the BGP Peer Group
Group-name
Set the Timers of BGP Peer Group
Configure AS Number of BGP Peer Group
Configure Connection Between Peers Indirectly Connected
Configure BGP Routing Update Sending Interval
Configure to Send the Default Route to the Peer Group
Configure to send the default route to the peer group
Create Routing Policy for Peer Group
Configure BGP Version of Peer Group
By default, software accepts BGP Version
Create an Aggregate Addresses
As-set
By default, an aggregate is disabled
Aggregate address mask
Undo aggregate address
Clients within the reflection group
Reflect between-clients
Undo reflect between-clients
Standard-community-list-number
Configure the Cluster ID
Configure BGP Community
Extended-community-list-number
Configure the Sub-system of E Confederation
Configure a Confederation
As-number …
Schematic diagram of route dampening
Display Route Flap Information
Configure Route Import for BGP
By default, BGP synchronizes with IGP
Is insured When AS is not a transitional AS Configuring
Still exists
Define an AS Path-list entry
Define an access list entry
Entry, an AS Path-list
Define a routing policy
Define a match rule
Perform the following configurations in Routing policy view
Define an apply clause
Filter for BGP
Filter Routing Information Being Advertised by BGP
Reset BGP Connections
Debugging BGP
Display and Debug BGP
As-regular-expression acl
BGP Configuration
Procedure for each configuration
Acl-number network-address
Networking diagram of configuring AS confederation
RouterB-Serial1ip address 193.1.1.2
Configure Router B Configure BGP peers
RouterA-bgppeer 192.1.1.2 as-number
RouterC-ospfinterface serial
Configure Router D Configure BGP peers
Specify BGP transmission network
Configure peer
Start BGP
RouterA-acl-1rule permit source 1.0.0.0
RouterC-acl-1rule permit source 1.0.0.0
RouterC-bgppeer 193.1.1.1 route-policy localpref import
RouterD-ospf network 4.0.0.0 0.0.0.255 area 0 RouterD bgp
Configuring BGP
IP Routing Policy
Configuring IP Routing Policy
Policy
Configure IP Routing
Operation Command Define a routing policy and enter into
Define a Routing Policy
Configure a Matching Rules
No-export addtive none
Define a Setting Clause
Apply community aa nn
Apply tag tag-value
Route-policy route-policy-name
Configure Route Import
Tag tag-value type 1
Ip ip-prefix prefix-list-name
Define an IP Prefix List
Ge-value less-equal le-value
OSPF-ASE external route discovered by Ospf protocol
Perform the following configurations in all views
Debugging IP Routing Policy
BGP route discovered by BGP protocol
Routing Policy
Configuring IP
With different weighting values
Protocol
Route Information
Normal operation
Troubleshooting IP
Configure RIP protocol
Routerip ip-prefix p1 permit 192.1.1.0/24
Configuring IP Routing Policy
IP Policy Routing
Configuring IP Policy
Routing
Define Match Rules
Create a Routing Policy
Define Apply Clause
Displaying Debugging IP Policy Routing
By default, interface policy routing is disabled
Enable/Disable Interface Policy Routing
Interface Policy Routing
Router-acl-101rule deny tcp source any destination any
Suggested procedure for each configuration
Define access list
Router-acl-102rule permit tcp source any destination any
RouterA-Ethernet0ip policy route-policy lab1
Adopt policy aaa in Ethernet interface
Router-Ethernet0ip policy route-policy aaa
RouterB-ripnetwork
RouterAdebugging ip policy-routing
Chapter
Configuring Igmp Configuring PIM-DM Configuring PIM-SM
IP Multicast
498
IP Multicast
List for Reserved Multicast Addresses
Range and Meaning of Class D Addresses
Class D address range Meaning
IP Multicast Routing Protocols
IP Multicast
IP Multicast
IP Multicast Packet
Application
IP Multicast
Igmp Overview
Configuring Igmp
Igmp Configuration Example
Igmp Overview
Configuring Igmp
Configure the Igmp Version Number Run at Router Interface
Make the following configuration in interface view
Configure Igmp Maximum Query Response Time
Displaying and Debugging Igmp
Igmp Configuration
Debugging command in system view to debug Igmp
Interfaces are all fast Ethernet FE
Router a Router B
Configuring Igmp
Configuring PIM-DM
Enable Multicast Routing
Make the following configuration in the system view
By default, the system disables the multicast routing
Operation Command Enable multicast routing
Display and Debug PIM-DM
Start/Disable PIM-DM Protocol
Displaying and Debugging PIM-DM
Group-address source-address
Enable PIM-DM protocol
PIM-DM Configuration
Enable multicast routing protocol
Receiver 2 are the two receivers of this multicast group
PIM-SM Overview
PIM-SM Configuration
Enabling Multicast Routing
Configure Candidate BSR
By default, the interface disables PIM-SM protocol
Enable/Disable PIM-SM Protocol
Configure Candidate RP
By default, no PIM-SM domain boundary is configured
By default, no interface is configured to be candidate RP
Configure PIM-SM Domain Boundary
Use the pim command in system view to enter PIM view
Debugging PIM-SM
RouterA multicast routing-enable RouterA interface ethernet
Configure Router a Enable PIM-SM protocol
Configure Router B Enable PIM-SM protocol
RouterA-pimspt-switch-threshold 10 accept-policy
Neighbors have discovered each other
Display pim neighbor command can be used to check whether
Follow these steps
RouterB-acl-5rule permit source 225.0.0.0
Configuring PIM-SM
Viii Security
524
Access Security
Terminal Access
Configuring Terminal
Configuring a User
Configure EXECLogin Authentication
Configure Radius server and the shared secret
Enable AAA
Configure the authentication method list of Exec users
Configuring Terminal Access Security
AAA Overview
Radius Overview
Components of Radius server
Basic message interaction process of Radius
Type of Packets Decided by Code Field
Request Authenticator Adopts 16-byte random code
Code Packet type Explanation of the packet
Attribute Fields
Configure AAA Login Authentication
By default, AAA is disabled
AAA Enable/Disable AAA
Server-template-name method1
Default methods-list method1
Configuring an Authentication Method List for PPP Users
Configure PPP Authentication Method List of AAA
Default methods-list
Configure AAA Accounting Option
By default no address pool is defined by the system
Configure AAA Local-First Authentication
Configure Local IP Address Pool
Configure Callback User
By default pool-number is
Configure a User and Password
Configure Ordinary User and Password
Configure Callback User and the Callback Number
Configure User with Caller Number
Configure FTP User and the Usable Directory
Configure User with Caller Number
Configure Authorizing a User with Usable Service Types
Authorize a User with Usable Service Types
Configure FTP User and the Usable Directory
Directory
Configure Radius Server Shared Secret
Configure Radius Server Shared Secret
By default, no key is configured for the Radius server
Radius server hostname ip-address
Configure the Request Retransmission Times
Configure the Time Interval for the Inquiry Packet
Displaying Debugging AAA
Accessing User
Authentication Case
AAA and Radius
Router aaa authentication-scheme local-first
Configure IP address and port of Radius server
Configure local-first authentication
Routerradius server
Troubleshooting AAA
Radius
Connected user cannot be seen in display aaa user
Users Radius authentication is always rejected
Can
Configuring AAA and Radius Protocol
Firewall Overview
Classification of Firewalls
Packet filtering schematic diagram
Command format when the protocol is TCP or UDP
Extended access control list
Command format when the protocol is IGMP, IP, GRE or Ospf
Operators of the Extended Access Control List
Mnemonic Symbol of the Port Number
Protocol Mnemonic Symbol Meaning and Actual Value
UDP
Mnemonic Symbol of the Icmp Message Type
Configure the match sequence of access control list
Operator and Syntax Meaning
Firewalls are disabled by default
Configure Firewall
Effect Perform the following configurations in system view
Firewall
Configure Standard Access Control List
Configure Extended Access Control List
Set Default Firewall Filtering Mode
Enabling and disabling filtering according to timerange
Configuring Special Timerange
Destination dest-addr dest- wildcard
Set Special Time Range
Enable/Disable Filtering According to Timerange
Set special time range
Settr begin-time end-time
Specify Logging Host
Use debugging, reset and display commands in all views
Displaying and Debugging Firewall
Display and Debug Firewall
Routerfirewall enable
Enable firewall
Configure access rules to inhibit passing of all packets
Routerfirewall default permit
Router-Ethernet0firewall packet-filter 101 inbound
Apply rule 102 on packets coming in from interface Serial0
Router-Serial0firewall packet-filter 102 inbound
IPSec Protocol
Following terms are important to an understanding of IPSec
IPSec Related Terms
IPSec Message Processing
Access Control List
Configuring IPSec
Creating an Encryption
Create Encryption Access Control List
Operator port1 port2
By default, all the crypto cards are enabled
Configure Ndec Cards Enable the crypto cards
Set the output of the crypto card log
Set the Mode for Security Protocol to Encapsulate Messages
By default, no proposal view is configured
Enable/Disable the Host to Backup the Ndec Cards
Define IPSec proposal
Select Security Protocol
Selecting the Encryption Authentication Algorithm
Default mode is tunnel-encapsulation mode
Select Security Protocol
Select Encryption Algorithm and Authentication Algorithm
Creating a Security Policy
Perform the following configurations in IPSec policy view
By default, no security policy is created
Configure access control list quoted in security policy
Set start point and end point of security tunnel
Set IPSec proposal quoted in security policy
By default, the security policy quotes no IPSec proposal
Configure IPSec Proposal Quoted in Security Policy
Set SPI of security policy association and its adopted key
Configure Key Used by Security Policy Association
By default, no key is used by any security policy
Configure SPI Parameters of Security Policy Association
Hex-key
Creating a Security Policy Association with
Set access control list quoted by security policy
Set end point of security tunnel
Specify End Point of Security Tunnel
Proposal proposal-name1
Set the IPSec proposal quoted in security policy
Set SA lifetime
Proposal-name2...proposal-name6
Configure Global SA LIfetime
Configure a separate SA lifetime
By default, apply the global SA lifetime
Configure Separate SA LIfetime
Apply Security Policy Group on Interface
Use debugging, reset and display commands in all views
Debugging IPSec
Ipsec sa dynamic-detect
Display and Debug IPSec
Reset crypto card
Dest-address protocol spi
Displaying and Debugging the crypto card
IPSec Configuration Example
Use the debugging, reset and display command in all views
Creating an SA Manually
Quote access list
Adopt tunnel mode as the message-encapsulating form
Select authentication algorithm and encryption algorithm
Create the IPSec proposal view named tran1
Apply security policy group on serial interface
Configure the route
Create a security policy with negotiation mode as manual
Exit to system view
Create the IPSec proposal view named trans1
Create a security policy with negotiation mode as isakmp
Set remote addresses
Configure serial interface Serial0
Configure ip address of the serial interface
Configure corresponding IKE
Create a security policy with negotiation view as isakmp
Return to system view
Establish a security policy with manual negotiation mode
Adopt tunnel module for packets encapsulation form
RouterB ike pre-shared-key abcde remote
Set encryption key
Enter Ethernet interface view and configure IP address
Set local address
Apply security policy base on serial port
Return to the system view
Establish a security policy with manual configuration mode
Troubleshooting IPSec Ndec card cannot be configured
RouterB ipsec policy map1 10 manual
Do the following
Configuring Ipsec
Configuring IKE
IKE features
Configuring IKE
Policy
View Delete IKE policy
Create IKE Policy
Ike proposal policy-number
Undo ike
Configure Pre-shared Key
Selecting an Authentication Algorithm
Select Authentication Method
Select Encryption Algorithm
Select DH Group ID
By default, 768-bit Diffie-Hellman group is selected
Select Hashing Algorithm
Set Lifetime of IKE Negotiation SA
Displaying and Debugging IKE
Configure IKE Keepalive Timer
Reset ike sa connection-ike-sa-id
Display and Debug IKE
IKE Configuration
Invalid user ID information
Unmatched policy
Unable to establish security channel
Configuring VPN Configuring L2TP Configuring GRE
IX VPN
596
VPN Overview
Classification of IP
Basic Networking
Applications of VPN
Authority given by local ISP
Layer 3 tunneling protocol
Layer 2 tunneling protocol
Comparison of layer 2 and layer 3 tunnel protocols
Configuring VPN
Vpdn and L2TP
Vpdn Operation
Methods of Implementing Vpdn
L2TP channel
Networking diagram of two typical methods of Vpdn
Tunnel and session
IV. Call setup flow of L2TP tunnel
Control message and data message
Features of L2TP
Call setup flow of L2TP channel
Enable/Disable L2TP
Basic Configuration at
Enable L2TP
L2tp enable
L2tp-group group-number
Originate L2TP Connection Request and LNS Address
Ip-address … domain domain-name
Default list-name method1
By default, L2TP is disabled
Configure AAA and Local Users
L2TP Attribute Table
Create/Delete L2TP Group
Operation Command Create a L2TP group
Operation Command Create a virtual template
Create/Delete a Virtual Template
Configure the Name of the Receiving End of the Tunnel
Advanced Configuration at LAC or LNS
By default, receiving dial-in from LAC is disabled
Configure Local VPN Users
Set Local Name
Enable Tunnel Authentication Setting Password
By default, the local name is the host name of router
Tunnel name name
Set Tunnel Authentication and Password
Configure the Interval For Sending Hello Messages
Set the Interval for Sending Hello Message
Force
Configure Domain Delimiter and Searching Order
Set Domain Name Delimiter and Searching Order
Reset l2tp tunnel remote-name
This configuration is applicable to LNS only
Operation Command Force to disconnect tunnel
Force to Disconnect Channel
LCP does not renegotiate by default
Configure the Local Address and Address Pool
LCP to Renegotiate
Enable/Disable Hiding AV Pairs
Enable/Disable Hiding Attribute Value Pairs AV
By default, AV pairs are hidden
Number of L2TP Sessions
Use debugging, display command in all views
L2TP Configuration Examples
By default, the maximum number of L2TP sessions is
Display and Debug L2TP
Enable L2TP service and configure a L2TP group
Implement local AAA authentication on VPN user
Configure the IP address of Serial1 interface of LAC
Configure BDR dialup parameters
Configure the IP address of Serial0 interface of LNS
Configure the Virtual-Template-related information
Internet Connection Wizard
Internet Connection Wizard
Internet Connection Wizard
Internet Connection Wizard
Client-originated VPN Networking
Router-LACip pool 1 192.170.0.3
Configure the IP address of Serial0 interface at LNS side
Configure the IP address of Serial1 interface at LAC side
Configure BDR parameters
Disable tunnel authentication
Network Connection Wizard
Network Connection Wizard
Connect Connection to
Configure the domain suffix separator to @
Configure an IP address on Serial0 interface
Configure a L2TP group and the related attributes
Router1 l2tp domain suffix-separator @
Force to implement local Chap authentication
Enable AAA authentication
Configure Virtual-Template
III. Procedures
Configure an address pool 1 in the range of 192.168.0.2 to
Configure a L2TP group and configure the related attributes
Configuration at Router2 LNS side Enable AAA authentication
Configure an access control list and specify L2TP data
Fault 1 The users fail to log
PPP negotiation fails. The reasons may be
Troubleshooting L2TP
Configuring L2TP
Encapsulation
GRE Protocol
Packet
Encapsulated tunnel message format Refer to RFC
Enlarge network operating range
Creating a Virtual Tunnel Interface
Configuring GRE
By default, no virtual tunnel interface is created
Create Virtual Tunnel Interface
Perform the configurations in the tunnel interface view
Address of a Tunnel Must be configured Interface
Setting the Network
Address of the Tunnel
Set the Tunnel to Synchronize Datagram Sequence Numbers
Number discarded
Set Tunnel Interface to Check with Checksum
Gre key key-number
Debugging GRE
GRE Configuration Example
Group1 and group2. It can be implemented by using GRE
All views
Configure the IP address of Ethernet0 interface
Configure Router B Configure the IP address of Serial0
Configure the static route to Novell Group2
Configure Router a Activate IPX
Configure the IP address and IPX address of Ethernet0
Configure Router B Activate IPX
Networking of troubleshooting GRE
RouterB ipx route 1e 1f.a.a.a tick 30000 hop
Configuring a Standby Center Configuring Vrrp
646
Configuring Standby Center
Standby Center
Fr map protocol address dlci dlci
Enter the Logic Channel View
Address logic-channelnumber
Next-hop-address dialer-number
Undo standby timer enable-delay
Channel to check whether it has recovered
Standby timer enable-delay seconds
Standby timer disable-delay seconds
Interfaces
Please perform the following configuration in all views
Load Sharing view
Enter the view of Serial
Channel
Enter the view of logic channel
Router-logic-channel10standby interface serial
Router-Serial1logic-channel
Vrrp Overview
Vrrp Configuration Examples
Troubleshooting Vrrp
Vrrp Overview
Adding a Virtual IP
Configuring Vrrp
Address
Vrrp vrid virtualrouterid
Configure Router Priority in Standby Group
Add Virtual IP Address
Undo vrrp vrid virtualrouterid
Configure Authentication Method and Authentication Key
Configuring Authentication Method Authentication Key
Vrrp provides simple character authentication method
Virtualrouterid
Debugging Vrrp
Configure Standby
Group Timer
Monitoring
Backup with preemption aII. Networking diagram
Vrrp Configuration
Procedure for each configuration
Vrrp Single Standby
Gateway function as the master
Gateway services instead
Balancing and mutual backup are implemented
Multiple Standby
There is requent switchover of the Vrrp state
Many master routers exist within the same standby group
XI QOS
662
Three Types of QoS Services
QOS Overview
QOS Overview
Benefits of QoS for the Network Service
QOS Overview
Traffic Classification
Traffic Policing
Traffic POLICING, Traffic Shaping and Line Rate
Committed Access
Rate CAR
Qos carl carl-index precedence
Defining Rules
Define CAR Rules
Precedence-value mac mac-address
Applying the CAR Policy on the Interface
By default, no CAR rule of ACL list is established
Apply the CAR Rule on the Interface
Displaying and Debugging CAR
CAR Configuration Applying a CAR Policy to all Packets
Configure the Priority Level Based CAR Policy
Display and Debug CAR
Configure the CAR Policy Based on the MAC Address
Matches ACL
Traffic Shaping
Apply a CAR Policy on the Packets that Match ACL
Packets
Configuring shaping parameters for a specified flow
Schematic diagram of GTS processing
Configure the ACL
Configuring shaping parameters for all flows
Shape the flows matching 110 on Ethernet interface
Rate
Configure the Physical Interface LIne Rate
Physical Interface Line
Shape all the flows on Ethernet interface
Displaying Display and Debug LR Debugging LR
Operation Command Display the LR configuration conditions
Display qos lr interface type
Congestion Management
Fifo Queuing
Congestion
Management Policy
Priority Queuing
Selecting Congestion Management Policies
Comparison of Several Congestion Management Policies
Number Queues Advantage Disadvantage
Schematic diagram of the first in first out queue
Schematic diagram of the custom queuing
Weighted Fair Queuing WFQ
Schematic diagram of weighted fair queuing
Configuring priority queuing
Configuring Congestion Management
Configuring Fifo Queuing
Configure the First In First Out Queuing
Protocol-name queue-option queue
By default, no priority queue is established
Values of Queue-Option with Protocol as IP
Pql-index protocol
Applying the priority-list queuing group to the interface
By default, the interface utilizes the Fifo queue
Specifying the queue length of the priority-list queuing
Default Length Value of the Priority Queue
Configuring custom-list queuing
Configuring Custom Queuing CQ
Displaying and debugging the priority queue
Queue-number
Configure the Custom-Lst Queuing According to the Interface
Configure the Default Custom-List Queuing
Queue queue-number
Configure the Queue Length of the Custom-List Queuing
By default, the interface uses the Fifo queue
Configuring the queue length of the custom-list queuing
Applying the custom-list queuing group to the interface
Displaying and debugging the weighted fair queue
Configuring Weighted fair queuing
Displaying and debugging the custom-list queue
Apply the priority queue 1 to Serial
Congestion Management Configuration Examples
PQ Configuration Example
Apply the priority queue 2 to Serial
RouterA-Tunnel0ip address 10.1.1.1
Configure the CQ queue
Configure Router B Configure the access control list
RouterA-Tunnel1destination
Configure Tunnel1
Configure Serial0 master/slave addresses
Configure Tunnel0
WFQ Configuration Example
Congestion Management
Congestion Avoidance
Congestion Avoidance
Enable Wred
Wred Configuration
Enable the Wred
Function of the Interface
Discard-prob
Ip-precedence
Enable Wred
Congestion Avoidance Configuration Example
Configure a WFQ queue
Displaying Debugging Congestion Avoidance
Congestion Avoidance
Configuring DCC Configuring Modem
XII DIAL-UP
704
Terms in DCC Configuration
DCC Overview
Circular DCC
DCC
Resource-Shared DCC
With 3Com Routers
Basic DCC features
Implementing callback through DCC
Prepare the data for DCC configuration
Configuring DCC
Preparing to Configure
Configure the local parameters of DCC
Linklayer-protocol-type
Configuring the mode of the physical interface
Configure Physical Interface Mode
Ip address ipaddress mask
Associating a DCC dialer ACL with the interface
Configuring an interface to originate calls to a remote end
Dialer number dial-number
Configure an interface to receive calls from a remote end
Dialer enable-circular
Undo dialer number
Route protocol
Dialer
Next-hop-address dial-number
Undo dialer route protocol
Next-hop-address
Undo dialer circular-group
Undo interface dialer number
Dialer circular-group number
Dialer priority priority
Dialer circular-group number
Interface dialer number
Undo interface dialer number
Undo dialer circular-group
Router Dialer0
By default, no dialer interface is created
Configuring dialing authentication for resource-shared DCC
Configuring the dialer interface and dialer number
Enabing Resource-Shared DCC
Configuring dialing authentication for resource-shared DCC
Configure MP Binding in Circular DCC
Configuring MP binding in circular DCC
Threshold traffic-percentage
Configure MP Binding in Resource-Shared DCC
Configuring MP binding in resource-shared DCC
Configuring PPP callback in the circular DCC implementation
Dialer threshold traffic-percentage
Implement PPP Callback Client Configuration in Circular DCC
Implement PPP Callback Server Configuration in Circular DCC
Next-hop-address user username
Command
Telephone-number
Dial-number
Primary rule The best match is the number with the fewest
Features of Isdn caller identification callback
Dialer callback-center dial-number
Undo dialer call-in remote-number
Operation Command Configure the local end to implement
Identification
Callback according to the Isdn caller
Configuring Special DCC Functions
Configuring Isdn leased line
Configuring auto-dial
Configure Isdn leased line for Circular DCC
Configure Auto-Dial
Configuring dialer number circular standby
Configuring the Link Idle Time
Configure Dialer Number Circular Standby
Configuring the link idle time when interface competion
By default, the link idle time is 120 seconds
By default, the link disconnection time is 20 seconds
Configure the Link Idle Time
Configuring the buffer queue length of the dialer
Configuring the timeout of call setting up
By default, the timeout of call setting up is 60 seconds
Debugging DCC
Solution
DCC Configuration Examples
DCC Applications in Common Use
Router-Serial1dialer circular-group
Configure RouterC
Configure RouterB
Router-Serial0dialer route ip 100.1.1.1
Router-Serial0dialer bundle-member
Router-Serial1dialer bundle-member
Configure RouterC
Configure RouterC
Router-Bri0dialer bundle-member
Configure RouterA
Router-Dialer0dialer threshold
Router-Serial015dialer route ip 100.1.1.1
Router-Bri1dialer route ip 100.1.1.1
Router-Serial0dialer route ip 100.1.1.2
Router-Serial1dialer enable-circular
Router dialer-rule 1 ip permit Router interface serial
Router-Bri0dialer route ip 100.1.1.2 user usera
By the NT server
Configure the PC
Callback for DC C
NT Server-to-Router
Router-Async0dialer route ip 100.1.1.254
Dial Number Circular Standby and Internet Access for DCC
Configure subscriber PC
Router-Serial0dialer route ip 100.1.1.254
Router-Serial215ppp authentication-mode chap
Router-Serial215ppp chap password simple passb
Router-Serial1standby logic-channel
Remote end cannot be pinged after the modem is connected
DCC Fault Messages
Message Fault
DCC peeraddr matching error
Modem Function Provided by 3Com Routers
Modem Script
Modem script format in common use is as follow
Syntax description of modem script
Receive-string1 send-string1 receive-string2 send-string2
Configure the Modem Dial-in and Dial-out Authorities
Which, seconds defaults to 180 and is in the range of 0 to
By default, modem dial-in and dial-out are allowed
Configure a Modem Script
Configure Modem Through the AT Command
Configure a Modem Script
Execute a Modem Script Manually
Configure Authentication for a Modem Dial-in User
By default, the modem works in non-auto answer mode
Configure the Answer Mode for the Modem
Specify the Events Triggering the Modem Scripts
Configure a Modem adaptation baud rate
Modem Configuration Examples
Executethe debugging command in all views for the debugging
Displaying and Debugging a Modem
Configure the modem initialization parameters
Restore the ex-factory modem settings
AT&b1&c1&d2&s0=0
Directly
Power-on Initialization Through Initialization Script
Authentication for
Modem Dial-in User
Troubleshooting
Configuring Modem