3Com Router Configuration Guide
Campus Drive
3Com Corporation
Marlborough, MA
01752-3064
Page
VPN
List conventions that are used throughout this guide
This guide describes 3Com routers and how to configure them
Text Conventions
About this Guide
3Com Router Introduction 3Com Router User Interface
Page
3COM Router Introduction
Following table lists the basic features of the 3Com Router
Features of the 3Com
List of the 3Com Router 1.x features
Router Version
RIP-1/RIP-2
NAT
Quality of service
3Com Router
New Features of the 3Com Router 1.x
3COM Router Introduction
Establish
Configuration
Environment
Port
Establish a new connection
Set port communication parameters
Establish a remote configuration environment
Connection
Configuration
Environment
Router
Workstation Ethernet
Interface CLI
Command Line
3COM Router User Interface
Views and their prompts
System view Table
Ethernet 0 in any
Async 0 in any
Loopback 0 in any
Enter controller
Full help
Helps
Partial help
Common error Message Causes
List of common command line error messages
For example
Routerdisplay ?
Features
Command Line
Display Features
Three options are available for users
Please perform the following commands in system view
Following commands
User Identity
Management
System
Configure the router name
Set the system clock
Execute the following commands in all views
By default, the system clock is 080000 1 1
Reboot the system
Display the System Information Router
System Management
Page
Softwaresoftware
Storage Media and File Types Supported by the System
Input Ctrl+D, and the following prompt information displays
Upgrade Boot ROM Software
Router Main Program
Upgrade the 3Com
Software
Main Program software
XModem Approach
Modify the terminal baud rate
Transfer File dialog box
Enable the Tftp server program
Preparation for using the Tftp server
Tftp server application can run on Windows 95/98/NT
Tftpd32 Set interface
Press Enter and the following prompts will be displayed
Network Interface Parameters
Enter Ctrl+B and the system prompts
Operation Command Downloads the 3Com Router main
Download configuration files from a Tftp server
Press Enter for loading
Get ip-addr file-name system
Set an authentication mode for an FTP server
Prepare for using the FTP server
Enable FTP server
Upgrade the 3Com Router Main Software with FTP
Tftp Approach
Back up the 3Com Router Main Program Software
FTP Approach
Copy ip-addr file-name system
Setup Users Dialog Box
Update slot slot-number ftpserver host-name
Configure on-line upgrading of the card
Port-number user user-name password
Password
Download Configuration File
Configuration File Management
Perform the following command in system view
Content and Format of the Configuration File
Download Config
Load configuration files
Router download config
Set the binary transmission protocol to XModem/CRC
Back up Configuration Files
Display current-configurationcommand output backup approach
Upload configuration files to a Tftp server
File-name config
View router configuration
Please use the following commands in corresponding views
Save current configuration
Select and view the storage media of configuration file
Set the Flag Bit to Enter the Initial Setup Mode
Erase the configuration file in storage media
Configure authentication and authorization of FTP server
Configure FTP
Client via port 20 and transfer data
Files on the router
Configure Parameters of FTP Service
Enter the following commands in system view
Please enter the following commands in system view
Set the authentication mode of FTP server
Set the connection time limit of FTP service
Set FTP update mode
Force to shut down FTP process
Force to shut down FTP process
Display ftp-server
Display FTP Server Display FTP server
Server Display detailed information of the FTP user
Display local-user
System Management
Features of Terminal
Terminal Service
Service at Console Port
Overview
Set the attributes of terminal service
Service
Terminal Message
On one router
Configure Terminal Message Service
Perform the following configuration in all views
Display Terminal Message Service
Enable/disable receiving messages from other terminals
Terminal Service
Typical Example Terminal Message Service Configuration
Dumb Terminal
Configure Dumb Terminal
Configuration Examples Dumb Terminal Service
Configure Auto-execute command
By default, no dumb terminal service is configured
Configure the interface to dumb terminal mode
Terminal Service Telnet Connection
Configure the auto-execute command command
Router-Serial1auto-execute command telnet
Service Value
Terminal service features of telnet connection
Establish Telnet Connection
Enable Reverse Telnet connection
Setup Reverse Telnet Connection
Service-port
Establish Telnet Server or Telnet Client connection
Force shut down Telnet Process
Typical Configuration Example of Telnet Reverse Telnet
Example of Telnet
Force to shut down Telnet process
Use Rlogin protocol
Rlogin Terminal
Example of Reverse Telnet
Router telnet 10.110.164.44
Typical Rlogin Configuration Examples
Establish a Rlogin connection
Rlogin ip-address username
Use local user name abc to log on
PAD Remote
Access Service
Communicate with other terminals through the X.25 network
Configure X.25 PAD remote user
Configure X.25 PAD remote user
Service-type type password
Local-user user-name
Enable AAA authentication for X.25 remote PAD users
Start AAA authentication of X.25 remote users
Establish an X.25 PAD call
Establish a X.25 PAD call
III. Configuration Procedure
II. Networking Diagram
Display and Debug
Set the Response Time to the Invite Clear Message
Set its X.121 address as
Fault Diagnosis Troubleshooting
RouterA-serial0x25 x121-address
RouterB-serial0x25 x121-address
Development of Snmp
Snmp Overview
Configuring Network Management
SNMP-supported MIB
Snmp architecture
3Com Router-supported MIB
By default, the system disables Snmp service
Engineid
Configure Snmp version and related tasks
Perform the following configurations in system view
Configure the traps to be sent by the router
Configure information of router administrator
V1 username
Interface-number
Display and debug Snmp
Perform the following commands in all views
Name
Byte-count
Set the community name and access authority
Example 1 Configure Network Management of SNMPv1
Configure an IP address for the Ethernet interface ethernet
Examples Networking Requirements
Rmon Overview
Configure an IP address for the Ethernet interface ethernet
Network equipment
Schematic diagram of Rmon application
Examples Networking Requirement
Enable Rmon statistics
RouterA-Ethernet0 rmon promiscuous
Commands to display information of the whole system
Test Tool of Network Connection
Ping command
System displays
Ping supporting IP protocol
Ping supporting IPX protocol
Ip-address
Tracert command
Following command can be executed in any command modes
Timeout host
MaxTTL -p port -q nqueries
Log Function
Configure on the router
Set the direction of syslog outputting log information
Perform the following task in system view
Set Severity of Log Information
Sylog-defined severity is as follows
Set Filter of Log Information
Turn on/turn off syslog
Configuration of Log Host
Display and Debug Syslog
Turn on/turn off syslog
Turn on debugging switch of PPP module
Syslog Configuration Example
Routerinfo-center enable
Routerdebug ppp all
Display and Debugging Tools
Dial-up POS Access
POS Terminal Access Service
Advantages of POS network access are as follows
POS Network Access
Configure POS access port
POS Access Service Configuration
Start POS server
Interface-type interface-number
Configure a POS application
App-number
Ip-address port-number
Default app-number
Configure POS multi-application mapping table
Bind the source address of TCP connection
Display and debug POS access
Display and Debug POS Access
Set the parameters of FCM used during Modem negotiation
Set the parameters of FCM used during Modem negotiation
Configure the Ethernet interface Ethernet
Typical Configuration Example of POS Access Service
Configure the POS access interface FCM0
Configure POS access interface FCM1
Configure POS access interface FCM0
Configure POS access interface FCM2
III. Configuration Procedure 1 Start the POS access server
Configure Async 1 to operate in POS application mode
Configure Async 0 to operate in POS application mode
III. Configuration Procedures
Configure Router a Start the POS access server
RouterA ip route-static 10.1.1.2 255.255.255.0 serial
Configure Router B Configure the Ethernet interface Ethernet
III Interface
106
Interface
Configure Interface
Enter the Interface View
Interface view, input quit to return to the system view
Exit the Interface View
Set time interval for flow control statistics
Interface-description
Display and Debug Interface
Please use the following commands in all views
Display and debug interface
Interface state information
Interface Configuration Overview
Ethernet Interface
Configure Ethernet Interface
Set IP address
Enter view of specified Ethernet interface
Set IPX address
Set frame format of sending message
Enable or disable internal loopback and external loopback
Select work mode of Ethernet interface
Display and Debug
Select working rate of fast Ethernet interface
Troubleshooting
Typical Ethernet Interface Configuration Example
II. Network Diagram
Troubleshooting
Configuring LAN Interface
Introduction
WAN Interface
Asynchronous Serial Interface
Interface async number
Enter view of specified asynchronous interface
Interface serial number
Set the baud rate of asynchronous serial interface
Set the work mode of asynchronous serial interface
Modem in out
Link-protocol slip ppp
Flow-control none software
Async Mode protocol
Hardware inbound outbound
Parity even mark none
Works in flow mode
Odd space
Stopbits 1 1.5
AUX Interface
Backup
Set MTU of asynchronous serial interface
Set the coding format of Modem
Configure AUX interface
Configure AUX interface
Configure Synchronous Serial Interface
Synchronous Serial Interface
Set the link layer protocol of synchronous serial interface
Enter view of specified synchronous interface
Physical-mode sync
Link-protocol fr hdlc
Working modes have different working clocks
Select work clock
Set the baud rate of synchronous serial interface
Synchronous serial interface is 64000 bps
Select work clock
Inversion is disabled by default
Set clock inversion
Detect dcd
Internal loopback/external loopback are disabled by default
Undo detect dcd
Reverse-rts
Idle coding of synchronous serial interface is 7E
Isdn BRI Interface
Technical Background
Graphics and video
Be clear about the following items before the configuration
Preparations before Configuration
Function group includes
CE1/PRI Interface
Channelized operating mode
Network protocols such as IP and IPX
Interface or a PRI interface
Dial-on-Demand Routing
Configure CE1/PRI CE1/PRI interface configuration includes
Interface
Enter the view for a specified interface
Bind the interface to be channel sets
Enter the synchronous serial interface view
Number set-number
Enter the Isdn interface view
Bind the interface to be a pri set
Pri-set timeslot-list range
Undo pri-set
Set the line code format on the CE1/PRI interface
Enable/disable the internal loopback/external loopback
Set the line clock of the CE1/PRI interface
Set the frame format of CE1/PRI interface
CT1/PRI Interface
Configure CT1/PRI
Controller t1 number
Operation Command Enter the view of CT1/PRI interface
Timeslot-list range speed
Interface serial number23
Set the line clock of the CT1/PRI interface
Set the line code format on the CT1/PRI interface
Set the frame format of CT1/PRI interface
E1-F interface does not support PRI operating mode
Choice for E1 access
E1-F Interface
Them into multiple channel sets
Enter the view of an E1-F interface
Set Operating mode for an E1-F interface
Interface serial serial-number
Fe1 unframed
Set line code format for E1-F interfaces
Set interface rate after binding operation
Set line clock for an E1-F interface
Set frame format for an E1-F interface
Enable/Disable local/remote loopback on an E1-F interface
Display and debug E1-F interface
Serial-number
T1-F interface does not support PRI operating mode
Choice for T1 access
T1-F Interface
193 X 8k = 1544kbps
Set line code format for T1-F interface
Set line clock for a T1-F interface
Enable/Disable local/remote loopback on a T1-F interface
Set frame format of T1-F interface
CE3 Interface
Other related information
Display and Debug T1-F
Display and debug T1-F interface
Enter the view of the specified E3 interface
Set the operating mode of E1 channel
Set the operating mode of CE3 interface
Set E1 frame format
CT3 Interface
Mode non-channelized mode
44.736Mbps
Data bandwidth 44736kbps
Set clock mode of the T1 channel
Set clock mode of the CT3 interface
Enter specified CT3 interface view
Set cable length of the CT3 interface
By default, the CT3 interface uses the C-bit frame format
By default, loopback is disabled Set Frame Format
Perform the following configurations in CT3 interface view
Set CRC of the serial interface
Set the operating mode of T1 channel
T1 line-number unframed
Display and debug of the CT3 interface
Disable and Enable CT3 interface
Configuring WAN Interface
Dialer Interface
Logical Interface
Null Interface
Configure Loopback
Sub-Interface
Create and delete WAN sub-interface
Configure sub-interfaces of Ethernet interface
Number.sub-number
Number.sub-number multipoint
Select frame relay link layer protocol
Enter the view of WAN interface Serial0 of router a
Routerinterface serial
Specify DTE as its frame relay terminal type
Configure the static route from router a to LAN2 and LAN3
Set its IP address to 202.38.160.1 and address mask to
Allocate a virtual circuit with Dlci 50 to it
Create or delete virtual-template
Set work parameters of virtual-template
Interface virtual-template
Undo interface
Troubleshooting the reasons may be as follows
Fault 1 Fail to create virtual interface
Display state of the specified virtual-template
Virtual-template-number
Link Layer Protocol
164
PPP Overview
PPP Authentication Mode
Configuring PPP and MP
MP Overview
Configure PPP
For detailed description of PPP, refer to RFC1661
Transmission time of large packets
Configure the local authenticates the peer in PAP mode
Configure the link layer protocol of the interface to PPP
Configure the peer authenticates the local in PAP mode
Name-list
Configure as the peer authenticates the local in Chap mode
Configure the local authenticates the peer in Chap mode
Cipher password
User username
Configure the time interval of PPP negotiation timeout
Configure AAA authentication and accounting of PPP
Configure PPP compression
Configure PPP link quality monitoring
Perform the following configuration in interface view
Ppp lqc forbidden-percentage
Resumptive-percentage
Configure Operating Parameters of Virtual Template
Configure MP Protocol Parameters Create Virtual Template
Create/Delete virtual template
Bind the physical Interface to a Virtual Template
User-name
Specify the conditions for MP binding
Frags
Configure virtual Baud rate on interface
Configuration Requirement
Typical PPP Configuration Example
Example
II. Configuration Procedure
Typical MP Configuration Example
Configure to start Chap authentication at this side
Set local username as Router1
Configure router-b Add a user for router-a
Configure virtual interface template
Configure router-c Add a user for router-a
Fault 1 Link always fails to turn to up status
Fault Diagnosis Troubleshooting
Fault 2 Physical link fails to turn to Up status
Indicates that the interface is shutdown
Introduction to PPPoE client
PPoE Overview
Client
Configure PPPoE
Reset or delete PPPoE session
Configure PPPoE session
Perform the display and debugging command in all views
Typical PPPoE Configuration Example
Access a LAN to the Internet via Adsl
III. Configuration Procedure 1 Configure a dialer interface
Configure the LAN interface and the default route
Configure a PPPoE session
Configure the DDN interface Serial
Use Adsl as Standby Line
Configuring Pppoe Client
Asynchronous mode
Configure Slip
Slip Overview
For further details about SLIP, you can refer to RFC1055
Typical Slip
Enable/Disable the information debugging of Slip
Time
Interconnect two Router routers via Pstn and run IP
Configure IP address of synchronous/asynchronous interface
Configure Router a Configure Dialer Rule
Configure the Dialer String to router B
Configure the default route to Route B
Routerip route-static 0.0.0.0 0.0.0.0
Isdn Overview
Configure Isdn
Configure type of signaling on Isdn interface
By default, DSS1 signaling is used on Isdn PRI interfaces
Configure the length of call reference
Configure the receiving mode
Configure interval for Qsig signaling timer
Configure the sending mode
Timer-name all
Time-interval
Perform the following configuration in Isdn interface view
Configure Call Processing Method on an Interface
Perform the display and debugging commands in all views
Configure Router a Create an Isdn PRI interface
Typical Configuration Example
Configure the Isdn PRI interface
RouterB transmit data after the call is set up
Configure Router B
Configure Router a
Protocols Overview
Lapb
PSN
25 packet and Lapb frame
By default, the Lapb modulus is Modulo
Configure Lapb
By default, k is Configure Lapb N1, N2
Configure
Set/Cancel the X.121 address of the interface
Configure X.25 Interface
Set X.25 working mode
Address
Parameter Meaning
25 channel delimitation parameters
Set/cancel X.25 virtual circuit range
By default, X.25 interface use modulo 8 mode
Set/Cancel X.25 packet numbering modulo
Finally, the following should be noted
Configure X.25 Interface Supplementary Parameter
Configure X.25 flow control parameter
Set the default flow control parameter
Out-packets
Set X.25 layer 3 timer delay
25 layer 3 timer
Alias match modes and meanings
Specify/Cancel an alias for the interface
Alias-string
Match-type alias-string
Set/Cancel the default upper layer protocol borne on
Create the permanent virtual circuit PVC
Configure X.25 Datagram Transmission
Protocol-address x121-address
Address option
Create/Delete permanent virtual circuit
Configure Additional Parameters Datagram Transmission
X25 pvc pvc-number protocol
Undo x25 pvc pvc-number
Interface view, perform the following task
Configure X.25 user facility
Specify/Cancel packet pre-acknowledgement
Serial port view, list1 can be quoted
Configure the sending queue length of virtual circuit
Set interface with standby center
Set broadcast via
Address broadcast
Address logic-channel
Configure X.25 sub-Interface
Switching Function
Configure X.25 Switching
Number.subinterface-number multipoi
Add or delete a PVC route
Configure X.25 Load Balancing
Introduction to X.25 Load Balancing
Configure X.25
Diagram of X.25 network load balancing
List of Configuration Tasks of X.25 Load Balancing
Create/Delete X.25 hunt group
Start /Close X.25 switching function
Add/Delete interfaces or XOT Tunnels in hunt group
Add/delete other X.25 switching routes
Configure X.25 over Other Protocols
Configure X.25 over TCP XOT
Introduction to XOT Protocol
Configure XOT
Configure local switching
Start X.25 switching
Configure SVC XOT switching
For PVC, perform the following tasks in interface view
Configure PVC XOT switching
Configure Annex G Data Interoperation
Configure X.25 over Frame Relay Annex G
Configure Keepalive and xot-source attributes
Configure the X.25 attributes for an Annex G Dlci
Configure the X.25 Attributes for a Dlci
By default, X.25 template is not applied on DLCIs
Typical Lapb Configuration Example
Current status of Lapb
Specify IP address for this interface
Configure Router a a Select interface
Configure Router B Select interface
Specify X.121 address of this interface
Connect the Router to X.25 Public Packet Network
Specify address mapping to the peer
Configure Router B Configure interface IP address
Configure Router a Configure interface IP address
Configure Router C Configure interface IP address
Disabled
Configure Virtual Circuit I. Networking Requirement
Range
Transmit IP Datagram via X.25 PVC
Router-Ethernet0ip address 196.25.231.1
Typical Sub-Interface Configuration Example
Configure Router D
Configure Router C
Create sub-interface serial
SVC Application of XOT I. Networking Requirement
Configure Serial
Configure Router C Start X.25 switching
Routerx25 switch svc 2 interface serial
Routerx25 switch svc 1 xot
Application of X.25 Load Balancing
Configure X.25 switching route to forward to X.25 terminal
Enable X.25 switching in system view
S11
Add Serial 1, Serial 2 and XOT Tunnel to hunt group
Routerx25 switch svc 8888 interface serial
Routerx25 switch svc 1111 xot
Load Balancing Carrying IP Data Transmission
Routerinterface serial Router-Serial0link-protocol x25 dce
Configure interface Serial
Configure RouterA Configure interface Ethernet
Configure static route to RouterC
Configure RouterB Configure interface Ethernet
Configure RouterA Create an X.25 template
Configure the static route to RouterA and RouterB
Configure the local X.25 address
Configure an IP address for the local interface
Map the Frame Relay address to the destination IP address
Configure RouterB Create an X.25 template
Associates an X.25 template with the Dlci
SVC Application of X.25 over Frame Relay
Enable switching on Frame Relay DCE
Configure the router Router B Enable X.25 switching
Configure Serial 0 as the X.25 interface
Configure Serial 1 as the Frame Relay interface
Configure the router Router C Enable X.25 switching
Configure X.25 over Frame Relay switching
Configure the Frame Relay Annex G Dlci
Configure local X.25 switching.Router-fr-dlci-100annexg dte
Configure Router B Enable X.25 switching
Configure Router D Configure the basic X.25 parameters
Configure an X.25 template
Configure S1 as the Frame Relay interface
Lapb
Configure Serial Configure S1 as the Frame Relay interface
Facility options inhibited by network have been carried
Fault Diagnosis and Troubleshooting of X.25
Configuring Lapb
Configuring Frame Relay
Link-protocol fr ietf
By default, the interfaces link layer protocol is PPP
Relay
Nonstandard
Configure Frame Relay LMI protocol type
Configure Frame Relay interface type
Undo fr lmi-n391dte
Fr lmi n391dte n391-value
Fr lmi n392dce n392-value
Undo fr lmi n392dce
Fr lmi t391dte t391-value
Undo fr lmi n393dce
Undo fr lmi t391dte
Fr lmi t392dce t392-value
Configure Frame Relay dynamic address mapping
Configure Frame Relay static address mapping
Create Frame Relay sub-interface
Configure Frame Relay local virtual circuit number
Fr dlci
Undo fr
Applying dynamic address mapping to the sub-interface
Configure virtual circuit of Frame Relay sub-interface
Establish static address mapping
Configure the route for Frame Relay PVC switching
Configure the Frame Relay local virtual circuit number
Configure Frame Relay local switched PVC number
Configure the Frame Relay switched PVC
Overview
Configure Multilink Frame Relay FRF.16
Configure a MFR bundle interface MFR interface
Configure MFR
Configure MFR interface parameter
Subnumber
Configure the parameters of the bundle link interface
Frame Relay Compression Configuration
Configure Frame Relay Fragment FRF.12
By default, interfaces use initiative compression
Configure Frame Relay Fragment Attributes
Configure Frame Relay Compression on multipoint interface
Frame Relay Traffic Shaping
Disable the Frame Relay traffic shaping
Fr traffic-shaping
Undo Fr traffic-shaping
Rate
Frame Relay Traffic Policing
Frame Relay Queueing Management
100 Kbps CI R ALLOWº£ 64 Kbps
150 Kbps
Frame Relay DE rule list
Frame Relay Congestion Management
Configure the Frame Relay class parameters
By default, no Frame Relay class is created
Configure Frame Relay Traffic Shaping
Undo fr-class class-name
Configure the parameters of Frame Relay class
Enable/Disable the Frame Relay traffic shaping
Enable/Disable the Frame Relay traffic policing
Dequeue-percentage
Queue-percentage
Configure Frame Relay Queueing Management
Configure Frame Relay DE Rule List
Configure the Frame Relay PVC queueing
Configure Pipq
Configure Frame Relay over IP
Configure Frame Relay over Other Protocols
Configure a tunnel interface
Configure Frame Relay switching
Networking of a typical Frame Relay over Isdn application
Frame Relay over Isdn Operation Process and Fundamentals
Physical Connection Between Frame Relay over Isdn Devices
Frame Relay switching connection between DTE devices
Back-to-back connection between DTE and DCE devices
Configure the Frame Relay-related commands
Configure Frame Relay over Isdn
Configure the link layer protocol of the interface
Configure the commands related to Frame Relay switching
Dlci
Display and debug Frame Relay
Configure parameters related to dialer profiles
Display and Debug Frame Relay
Isdnsubaddress
Number interface serial
Number dlci dlci-number
Type number dlci
Mfr number
Configure static address mapping
Typical Frame Relay Configuration Example
Interconnect LANs via Frame Relay Network
Router-Serial1fr map ip 202.38.163.251 dlci
Relay FRF.16
Configure local virtual circuit
Interconnect LANs via Private Line
Router-Serial1ip address 202.38.163.253
Bundle Serial 0 and Serial 1 to mfr
Create a MFR interface
Example FRF.9
Them
III. Configuration Procedure 1 Configure RouterA
III. Configuration Procedure 1 Configure Router a
FRF.12
Fragment between them
Routerfr class 96k
IP Configuration
Router-fr-class-96ktraffic-shaping adaptation becn
Typical Frame Relay over
Configure tunnel interface
Configure IP interface Ethernet0
Configure Frame Relay over IP
Router-Serial0fr interface-type dce
Router-Bri0fr map ip 110.0.0.2 dlci
Configure the Frame Relay parameters on Bri0
Router-Dialer0dialer number Router-Dialer0dialer call-in
Router-Dialer0fr interface-type dce
Configure the Frame Relay-related parameters on Bri0
Router-Serial1.1ip address 130.0.0.2
Configure Frame Relay SVCs
Fault 1 the physical layer in Down status
Fault Diagnosis Troubleshooting Frame Relay
Fault 4 Frame Relay data cannot be transmitted across Isdn
Configuring Frame Relay
Configure Hdlc Display and Debug Hdlc
Configure Hdlc
By default, the link layer protocol of the interface is PPP
Configure the link layer protocol of the interface to Hdlc
Debugging Hdlc Packet Interface
Enable Hdlc packet debugging
Typical Bridge Configuration
Configure Bridge’s Routing Function
Bridge Overview
Bridge Overview
Main Functions of Bridging
Obtain address table
Bridge Overview
Final bridging address table
Forward and Filter
Filter not forward
Eliminating loop
Preliminary examination state of bridging loops
Spanning Tree Topology
Spanning tree topology
Bpdu Forwarding Mechanism
By default, disable bridging functions
Configure Bridge’s Routing Function
Enable/Disable bridging functions
Bridge enable
Specify the STP version supported by the bridge-set
Configure static address table entries
Add ports to a bridge-set
Mac-address
Configure the aging time of dynamic address table
Enable/Disable forwarding by using dynamic address table
Disable/Enable STP on ports
Configure the path cost of bridge port
Configure the bridge priority
Configure the bridge port priority
Configure the forward delay for the port status transition
Configure the interval for sending BPDUs
Create ACLs based on varied Ethernet encapsulation formats
Configure the Max age of Bpdu
Acl acl-number
Configure a bridge-template interface
Enable/Disable bridge’s routing
Bridge-set
Share load by source MAC address
Define a link-set
Link-set
Bridgebridge-set link-set link-set
Map the bridge address to Dlci
Configuration on the interface
Define a dialer list
Display and Debug Bridge
Typical Bridge Configuration
Display and debug bridge
Transparent Bridging Multiple LANs
Configure Router B
Configure Router a
Router-Serial0bridge-set 1 stp disable
Transparent bridge over the Frame Relay
Transparent Bridging over Frame Relay
Router-Serial1dialer route bridge broadcast
Standby
Asynchronous Dial-in
Connected are failed
Please refer to Figure
Networking of bridge-template interface
Bridge-Template interface
Networking for bridging on sub-interfaces
Bridging on Sub-Interfaces
Routerbridge enable Routerbridge 1 stp ieee
Link-Set Configuration I. Networking Requirements
Router-Serial1bridge-set 1 link-set
Network Protocol
316
Configuring IP Address
Network IP network range Description Class
IP address classes and ranges
Sub-net classification of IP address
By default, the interface has no master IP address
Configure IP Address Configure IP Address for an Interface
Configure master IP address of an interface
Ip address ip-address mask
Ip address ip-address mask Mask-length sub
Configure slave IP address of an interface
Delete slave IP address of an interface
Undo ip address ip-address
Configure IP Address Unnumbered for an Interface
By default, the interface has no negotiating IP address
Introduction to IP address unnumbered
Set negotiable attribute of IP address for an interface
Configure routing to Ethernet segment of Shenzhen router R1
Configuration Example I. Configuration Requirements
Configure IP address unnumbered
Borrow IP address of Ethernet interface
Borrow IP address of Ethernet
Configure router R1 of Shenzhen subsidiary
Router-Ethernet0ip address 172.16.20.1
Router ip route-static 0.0.0.0 0.0.0.0
Page
Configuring IP Address
Arp static ip-address
Define a static ARP mapping
Undo arp static ip-address
Arp dynamic ip-address
Name Resolution
Configure Domain
Name Resolution
Display and Debug ARP
Display and Debug domain name resolution
Display and Debug Domain Name Resolution
Display ip host
Specify the Vlan on which Ethernet subinterface is located
Create Ethernet subinterface
Interface-number.subinterface-number
Vlan-type dot1q vid vlan-id
Typical Vlan Configuration Example
Configure IP address of Ethernet subinterface
Display and Debug Display and Debug Vlan
Display vlan
Configure Vlan information of LAN Switch
Configure IP address for the subinterface
Troubleshooting The steps below can be taken
Router-Ethernet0.1ip address 3.3.3.8
Fault Ping Two PCs, but fails to ping them through
Dhcp Server Configuration
Dhcp vs Bootp
Background of the Dhcp development
Following figure
Occasions in which Dhcp server is applied
Dhcp server Dhcp clients
Dhcp client logs into the network again
Dhcp Server Configuration
Dhcp Enable
Enable/disable the Dhcp service
Undo Dhcp enable
Dhcp server ip-pool pool-name
Netmask
Configure the statically binding IP address and MAC address
Network ip-address
Low-ipaddress high -ipaddress
Low-ipaddress high-ipaddress
Configure the gateway router address of client
By default, the IP address of DNS is not configured
Configure the domain names of Dhcp clients
Configure the DNS addresses in a Dhcp address pool
Set the type of NetBIOS node for Dhcp client
Set the type of NetBIOS node for Dhcp client
Nbns-list ip-address1
Ip-address2 ... ip-address8
Configure Dhcp self-defined options
Use reset, debugging and display command in All views
Display and Debug Dhcp Server
Display and Debug Dhcp servers
Router dhcp enable
III. Configuration Procedures 1 Enable the Dhcp service
Router dhcp server forbidden-ip
Router-dhcp2nbns-list Router-dhcp2gateway-list
At the client, use ipconfig /releaseall
Operation Command Configure interface relay address
Configure interface relay address
Ip relay-address ip-address
Delete interface relay address
Dhcp Relay
Dhcp Relay Configuration Requirement
IP address from Dhcp server through application
Available on Dhcp server
Networking diagram of an Dhcp relay configuration example
Configure Dhcp relay router
Fault 2 fail to forward transparent transmission protocol
Under which condition should the address be translated
Private Network Address and Public Network Address
Role the Network Address Translation NAT plays
Characteristic of Network Address Translation NAT
Mechanism of Network Address Translation NAT
Performance of Network Address Translation NAT
Configure address pool
End-addr pool-name
Pool-name
Address-group pool-name
Nat outbound acl-number
Undo nat outbound acl-number
Undo nat outbound
Configure the Timeout of address translation
Configure the Internal Server
Nat server global global-addr global-port
Www inside inside-addr inside-port any
Display and Debug NAT Display and debug NAT
Typical NAT Configuration Example
Allow address translation of segment at 10.110.10.0/24
Configure address pool and access list
Set internal FTP server
Set internal WWW server
Configure dial-up property for the interface
Configure address access control list and dialer-list
Configure a default route to serial
Correlate the address translation list and the interface
Fault 2 Internal server abnormal
Configuring IP Application
To configure IP performance, carry out the following steps
Configure IP
Configure maximum transmission unit on an interface
Performance
Configure TCP
Tcp window size
Forwarding
Configure Fast
Display and Debug IP
Perform the following configuration in system view
Forwarding
Display and Debug Fast Display and Debug fast forwarding
Router info-center enable Router debugging tcp packet
Troubleshooting IP Performance Configuration
Router info-center enable Router debugging tcp event
Configuring IP Count
Enable/Disable IP Count service
IP Count Configuration
Ip count enable
Undo ip count enable
Configure IP Count list
Configure IP Count on an interface
Specify count maximum of exterior
Count
By default, IP Count entries time out after 720 minutes
Specify count maximum of interior
Display and debug IP Count
Not been configured on the interface of the router
IV. Test Procedure
Information is displayed
Configuring IP Count
IPX address
Configuring IPX
SAP
Modify length of service information reserve queue
Configure IPX
Configure relative parameters of IPX SAP
Its first Ethernet interface as its node address
Configure IPX RIP static route
Enable IPX interface
Enable/Disable a Default Route
Perform the following task in interface view
Configure RIP aging period
Configure RIP updating period
Configure the maximum size of RIP update packet
Configure the maximum number of IPX parallel route
Configure static service information table item
Configure length of route reserve queue
Configure size of SAP maximum updated message
Configure SAP aging period
Configure reply to SAP GNS request
Ipx sap timer update seconds
Disable split-horizon
Configure Using touch-off for an interface
Configure management of IPX packet
Configure the delay of interface sending IPX packets
Modify Encapsulation Format of IPX Frame on Interface
Encapsulation format of IPX frame
Display and Debug IPX Display and Debug IPX
Configure Router a a Activate IPX
Configure a static route to network ID
Configure an address map to Router B
Configure an information about Server2 file service
Configure an information about Server2 directory service
Configure an information about Server1 directory service
DLSw Protocol
Create DLSw local peer entity
Configuration of DLSw
Init-window-size max-frame
Max-frame-size max-window
Create DLSw remote end peer entity
Configure Bridge set connecting to DLSw
Configure Sdlc role
Configure to add ethernet port to Bridge set
Configure Sdlc address
Configure Sdlc virtual MAC address
Sdlc-address
Controller sdlc-address
Configure XID of Sdlc
Configure Sdlc peer entity
Add synchronous Interface to Bridge set
Configure baud rate of synchronous Interface
Configure to stop running DLSw
Baudrate
Configure parameters of DLSw timer
Configure Idle time encoding mode of synchronous Interface
Configure LLC2 local acknowledgement delay time
Mseconds
Configure modulo value of LLC2
Configure LLC2 premature acknowledgement window
Configure LLC2 local acknowledgement time
Configure retransmission number of LLC2
Configure Busy status time of LLC2
Configure P/F wait time of LLC2
Configure queue length of sending message of LLC2
Configure REJ status time of LLC2
Configure Queue Length of Sending Message of Sdlc
Configure Sdlc local acknowledgement window
Configure retransmission number of Sdlc
Configure maximum receivable frame length of Sdlc
Configure poll time interval of Sdlc
Configure data bi-directional transmission mode of Sdlc
Configure SAP address for transforming Sdlc to LLC2
Lsap
Dsap
DLSw Configuration Networking Requirement
Typical DLSw Configuration Example
DLSw
IP across WAN
Router B Configuration
Router a Configuration
DLSw Configuration
Router dlsw local
Networking diagram of DLSw configuration of SDLC-SDLC
Networking Diagram of SDLC-LAN
When using command display dlsw remote
DLSw Fault
Diagnosis
Virtual circuit cant attain Connected state
Diagnosis and Troubleshooting of DLSw Fault
Configuring Dlsw
VI Routing
404
IP Routing Protocol
IP Routing Protocol
Routing Protocol or Type Corresponding Routing Priority
Routing Protocol and Routing Priority
Ospf ASE
Default Route
Configuring Static Routes
Configuring a Static Route
Configuring a Static Route
Configure a Static Route
Transmitting interface or next hop address
Displaying Debugging Routing Table
Configuring a Default Route
Preference
Other parameters
Static Route
Troubleshooting a
Other
RIP Overview
Features is not subject to whether RIP has been enabled
Configure RIP
Enabling RIP
Enable RIP at the Specified Network
Define a Neighboring Router
By default, the interface runs RIP-1
Specify RIP Version
Peer ip-address
Configure Check Zero Field of RIP Version
RIP Version 1 enables zero field check by default
Disable a Host Route
Specify the Status of an Interface
Enabling Route
Authentication on
Summarization for RIP
Version
Configure RIP Horizontal Segmentation on the Interface
By default, the default route metric for RIP is
Configure Route Import for RIP
Specify a Default Route Metric Value for RIP
Distribution for RIP
Configure filtering route information received by RIP
Specify Additional Route Metric Value for RIP
Set Route Preference
Displaying and Debugging RIP
Reset RIP
Filter the Routing Information Being Advertised by RIP
Display and Debug RIP
RIP Unicast
Ospf Overview
Ospf Configuration Example
Ospf Overview
Displaying and Debugging Ospf
Configuring Ospf
Specify Router ID
Enable Ospf
Router id router-id
Undo router id
Area-id
By default, Ospf is disabled
Area area-id
Configure Sending Packet Cost
Configure the Network Type of the Ospf Interface
Ospf network-type broadcast nbma
P2mp P2p
Cost
Configuring a Peer for the Nbma Interface
Specify the Router Priority
Operation Command Set the priority of the interface when
Ospf Dr-priority value
Undo Ospf dr-priority
Specify Dead Interval
Specify Hello Intervall
Specify Transmit-delay
Configuring a Stubby Area and a Totally
Specify Retransmitting Interval
Configure Totally Stubby Area of Ospf
Perform the following configuration under Ospf view
Stub cost cost area area-id
No-summary
Configure an Nssa Area of Ospf
Perform the following configuration in Ospf view
Abr-summary address mask mask area
Configure Route Summarization Within Ospf Domain
Area-id advertise notadvertise
Undo abr-summary address mask mask
Area-id None Router-id None
Create and Configuring a Virtual Link
Key-id
Configure Authentication
Configure Parameters When Importing External Routes
Configure Route Import for Ospf
Displaying
Configure filtering route information received by Ospf
Debugging Ospf
Filter for Ospf
Configuring Ospf on the Point-to-Multipoint Network
Ospf Configuration Example
Router D 201 Router B 301 302 Router C 1.3
RouterC ospf enable
Enable Ospf
RouterA-Serial0ospf network-type p2mp
RouterB-Serial0ospf network-type p2mp
Configure DR on Ospf Preference
E0 192.1.1.4/24
1.1 4.4 E0 192.1.1.1/24
E0 192.1.1.2/24 E0 10.1.2.3/24
2.2 3.3
RouterD display ospf peer
RouterA display ospf peer
Between Router B and Router C
To configure an Ospf virtual link Configure Router a
RouterB-ospfVlink peer-id 3.3.3.3 transit-area
To configure Ospf peer authentication Configure Router a
Ospf Configuration
Troubleshooting an
Normally
Ospf Configuration Example
Configuring Ospf
BGP Overview
BGP Configuration Example
BGP Overview
Displaying and Debugging BGP
Configuring BGP
Perform the following configurations in system view
Resetting BGP Connections Enabling BGP
By default, BGP is disabled
Perform the following configurations in BGP view
Set the Timers for BGP Peer
Configure the BGP Version of the Peer
Configure BGP Route-update Interval
Configure to Send Community Attribute to the Peer
Configure to distribute default route to the peer
Configure the Peer to be the Client of the Route Reflector
Configure to Distribute Default Router to the Peer
Configure the BGP MED Metric
Create a Fltering Policy Based on Access List for the Peer
Create a BGP Route Filtering Based on AS Path for the Peer
Allow Comparing Path MED
Configure the Keepalive Timer and Holdtime Tmer for BGP
Configure the Local Preference
Timers keepalive-interval
Holdtime-interval
Add a Peer to the BGP Peer Group
By default, there is no BGP peer in a peer group
Peer group-name
Group-name
Configure Connection Between Peers Indirectly Connected
Configure AS Number of BGP Peer Group
Set the Timers of BGP Peer Group
Configure BGP Routing Update Sending Interval
Configure to Send the Default Route to the Peer Group
Configure to send the default route to the peer group
Create Routing Policy for Peer Group
Configure BGP Version of Peer Group
By default, software accepts BGP Version
Create an Aggregate Addresses
Aggregate address mask
By default, an aggregate is disabled
As-set
Undo aggregate address
Clients within the reflection group
Reflect between-clients
Undo reflect between-clients
Configure BGP Community
Configure the Cluster ID
Standard-community-list-number
Extended-community-list-number
Configure the Sub-system of E Confederation
Configure a Confederation
As-number …
Schematic diagram of route dampening
Display Route Flap Information
Is insured When AS is not a transitional AS Configuring
By default, BGP synchronizes with IGP
Configure Route Import for BGP
Still exists
Entry, an AS Path-list
Define an access list entry
Define an AS Path-list entry
Define a routing policy
Define a match rule
Perform the following configurations in Routing policy view
Define an apply clause
Filter for BGP
Debugging BGP
Reset BGP Connections
Filter Routing Information Being Advertised by BGP
Display and Debug BGP
Procedure for each configuration
BGP Configuration
As-regular-expression acl
Acl-number network-address
Networking diagram of configuring AS confederation
RouterA-bgppeer 192.1.1.2 as-number
Configure Router B Configure BGP peers
RouterB-Serial1ip address 193.1.1.2
RouterC-ospfinterface serial
Configure Router D Configure BGP peers
Start BGP
Configure peer
Specify BGP transmission network
RouterA-acl-1rule permit source 1.0.0.0
RouterC-bgppeer 193.1.1.1 route-policy localpref import
RouterC-acl-1rule permit source 1.0.0.0
RouterD-ospf network 4.0.0.0 0.0.0.255 area 0 RouterD bgp
Configuring BGP
IP Routing Policy
Configuring IP Routing Policy
Operation Command Define a routing policy and enter into
Configure IP Routing
Policy
Define a Routing Policy
Configure a Matching Rules
Apply community aa nn
Define a Setting Clause
No-export addtive none
Apply tag tag-value
Route-policy route-policy-name
Configure Route Import
Tag tag-value type 1
Ip ip-prefix prefix-list-name
Define an IP Prefix List
Ge-value less-equal le-value
Debugging IP Routing Policy
Perform the following configurations in all views
OSPF-ASE external route discovered by Ospf protocol
BGP route discovered by BGP protocol
With different weighting values
Configuring IP
Routing Policy
Protocol
Route Information
Configure RIP protocol
Troubleshooting IP
Normal operation
Routerip ip-prefix p1 permit 192.1.1.0/24
Configuring IP Routing Policy
IP Policy Routing
Configuring IP Policy
Routing
Define Match Rules
Create a Routing Policy
Define Apply Clause
Enable/Disable Interface Policy Routing
By default, interface policy routing is disabled
Displaying Debugging IP Policy Routing
Interface Policy Routing
Define access list
Suggested procedure for each configuration
Router-acl-101rule deny tcp source any destination any
Router-acl-102rule permit tcp source any destination any
Router-Ethernet0ip policy route-policy aaa
Adopt policy aaa in Ethernet interface
RouterA-Ethernet0ip policy route-policy lab1
RouterB-ripnetwork
RouterAdebugging ip policy-routing
Chapter
Configuring Igmp Configuring PIM-DM Configuring PIM-SM
IP Multicast
498
IP Multicast
List for Reserved Multicast Addresses
Range and Meaning of Class D Addresses
Class D address range Meaning
IP Multicast Routing Protocols
IP Multicast
IP Multicast
IP Multicast Packet
Application
IP Multicast
Igmp Configuration Example
Configuring Igmp
Igmp Overview
Igmp Overview
Configuring Igmp
Configure the Igmp Version Number Run at Router Interface
Make the following configuration in interface view
Configure Igmp Maximum Query Response Time
Debugging command in system view to debug Igmp
Igmp Configuration
Displaying and Debugging Igmp
Interfaces are all fast Ethernet FE
Router a Router B
Configuring Igmp
Configuring PIM-DM
By default, the system disables the multicast routing
Make the following configuration in the system view
Enable Multicast Routing
Operation Command Enable multicast routing
Displaying and Debugging PIM-DM
Start/Disable PIM-DM Protocol
Display and Debug PIM-DM
Group-address source-address
Enable multicast routing protocol
PIM-DM Configuration
Enable PIM-DM protocol
Receiver 2 are the two receivers of this multicast group
PIM-SM Overview
Enabling Multicast Routing
PIM-SM Configuration
Enable/Disable PIM-SM Protocol
By default, the interface disables PIM-SM protocol
Configure Candidate BSR
Configure Candidate RP
By default, no PIM-SM domain boundary is configured
By default, no interface is configured to be candidate RP
Configure PIM-SM Domain Boundary
Debugging PIM-SM
Use the pim command in system view to enter PIM view
Configure Router B Enable PIM-SM protocol
Configure Router a Enable PIM-SM protocol
RouterA multicast routing-enable RouterA interface ethernet
RouterA-pimspt-switch-threshold 10 accept-policy
Follow these steps
Display pim neighbor command can be used to check whether
Neighbors have discovered each other
RouterB-acl-5rule permit source 225.0.0.0
Configuring PIM-SM
Viii Security
524
Configuring Terminal
Terminal Access
Access Security
Configuring a User
Configure EXECLogin Authentication
Configure Radius server and the shared secret
Enable AAA
Configure the authentication method list of Exec users
Configuring Terminal Access Security
Radius Overview
AAA Overview
Components of Radius server
Basic message interaction process of Radius
Type of Packets Decided by Code Field
Request Authenticator Adopts 16-byte random code
Code Packet type Explanation of the packet
Attribute Fields
AAA Enable/Disable AAA
By default, AAA is disabled
Configure AAA Login Authentication
Server-template-name method1
Configure PPP Authentication Method List of AAA
Configuring an Authentication Method List for PPP Users
Default methods-list method1
Default methods-list
Configure AAA Local-First Authentication
By default no address pool is defined by the system
Configure AAA Accounting Option
Configure Local IP Address Pool
Configure a User and Password
By default pool-number is
Configure Callback User
Configure Ordinary User and Password
Configure FTP User and the Usable Directory
Configure User with Caller Number
Configure Callback User and the Callback Number
Configure User with Caller Number
Configure FTP User and the Usable Directory
Authorize a User with Usable Service Types
Configure Authorizing a User with Usable Service Types
Directory
By default, no key is configured for the Radius server
Configure Radius Server Shared Secret
Configure Radius Server Shared Secret
Radius server hostname ip-address
Configure the Time Interval for the Inquiry Packet
Configure the Request Retransmission Times
Authentication Case
Accessing User
Displaying Debugging AAA
AAA and Radius
Configure local-first authentication
Configure IP address and port of Radius server
Router aaa authentication-scheme local-first
Routerradius server
Radius
Troubleshooting AAA
Connected user cannot be seen in display aaa user
Users Radius authentication is always rejected
Can
Configuring AAA and Radius Protocol
Firewall Overview
Classification of Firewalls
Packet filtering schematic diagram
Command format when the protocol is IGMP, IP, GRE or Ospf
Extended access control list
Command format when the protocol is TCP or UDP
Operators of the Extended Access Control List
Mnemonic Symbol of the Port Number
UDP
Protocol Mnemonic Symbol Meaning and Actual Value
Mnemonic Symbol of the Icmp Message Type
Configure the match sequence of access control list
Operator and Syntax Meaning
Effect Perform the following configurations in system view
Configure Firewall
Firewalls are disabled by default
Firewall
Configure Extended Access Control List
Configure Standard Access Control List
Configuring Special Timerange
Enabling and disabling filtering according to timerange
Set Default Firewall Filtering Mode
Destination dest-addr dest- wildcard
Set special time range
Enable/Disable Filtering According to Timerange
Set Special Time Range
Settr begin-time end-time
Displaying and Debugging Firewall
Use debugging, reset and display commands in all views
Specify Logging Host
Display and Debug Firewall
Configure access rules to inhibit passing of all packets
Enable firewall
Routerfirewall enable
Routerfirewall default permit
Router-Ethernet0firewall packet-filter 101 inbound
Apply rule 102 on packets coming in from interface Serial0
Router-Serial0firewall packet-filter 102 inbound
IPSec Protocol
Following terms are important to an understanding of IPSec
IPSec Related Terms
IPSec Message Processing
Access Control List
Configuring IPSec
Creating an Encryption
Operator port1 port2
Create Encryption Access Control List
By default, all the crypto cards are enabled
Configure Ndec Cards Enable the crypto cards
Set the output of the crypto card log
Enable/Disable the Host to Backup the Ndec Cards
By default, no proposal view is configured
Set the Mode for Security Protocol to Encapsulate Messages
Define IPSec proposal
Default mode is tunnel-encapsulation mode
Selecting the Encryption Authentication Algorithm
Select Security Protocol
Select Security Protocol
Creating a Security Policy
Select Encryption Algorithm and Authentication Algorithm
Configure access control list quoted in security policy
By default, no security policy is created
Perform the following configurations in IPSec policy view
Set start point and end point of security tunnel
Configure IPSec Proposal Quoted in Security Policy
By default, the security policy quotes no IPSec proposal
Set IPSec proposal quoted in security policy
Set SPI of security policy association and its adopted key
Configure SPI Parameters of Security Policy Association
By default, no key is used by any security policy
Configure Key Used by Security Policy Association
Hex-key
Set end point of security tunnel
Set access control list quoted by security policy
Creating a Security Policy Association with
Specify End Point of Security Tunnel
Set SA lifetime
Set the IPSec proposal quoted in security policy
Proposal proposal-name1
Proposal-name2...proposal-name6
By default, apply the global SA lifetime
Configure a separate SA lifetime
Configure Global SA LIfetime
Configure Separate SA LIfetime
Debugging IPSec
Use debugging, reset and display commands in all views
Apply Security Policy Group on Interface
Ipsec sa dynamic-detect
Display and Debug IPSec
Reset crypto card
Dest-address protocol spi
Use the debugging, reset and display command in all views
IPSec Configuration Example
Displaying and Debugging the crypto card
Creating an SA Manually
Select authentication algorithm and encryption algorithm
Adopt tunnel mode as the message-encapsulating form
Quote access list
Create the IPSec proposal view named tran1
Create a security policy with negotiation mode as manual
Configure the route
Apply security policy group on serial interface
Exit to system view
Create the IPSec proposal view named trans1
Create a security policy with negotiation mode as isakmp
Set remote addresses
Configure corresponding IKE
Configure ip address of the serial interface
Configure serial interface Serial0
Create a security policy with negotiation view as isakmp
Adopt tunnel module for packets encapsulation form
Establish a security policy with manual negotiation mode
Return to system view
RouterB ike pre-shared-key abcde remote
Set local address
Enter Ethernet interface view and configure IP address
Set encryption key
Apply security policy base on serial port
Troubleshooting IPSec Ndec card cannot be configured
Establish a security policy with manual configuration mode
Return to the system view
RouterB ipsec policy map1 10 manual
Do the following
Configuring Ipsec
Configuring IKE
IKE features
Configuring IKE
Policy
Ike proposal policy-number
Create IKE Policy
View Delete IKE policy
Undo ike
Select Authentication Method
Selecting an Authentication Algorithm
Configure Pre-shared Key
Select Encryption Algorithm
Select Hashing Algorithm
By default, 768-bit Diffie-Hellman group is selected
Select DH Group ID
Set Lifetime of IKE Negotiation SA
Reset ike sa connection-ike-sa-id
Configure IKE Keepalive Timer
Displaying and Debugging IKE
Display and Debug IKE
Invalid user ID information
IKE Configuration
Unable to establish security channel
Unmatched policy
IX VPN
Configuring VPN Configuring L2TP Configuring GRE
596
VPN Overview
Applications of VPN
Basic Networking
Classification of IP
Authority given by local ISP
Layer 3 tunneling protocol
Layer 2 tunneling protocol
Comparison of layer 2 and layer 3 tunnel protocols
Configuring VPN
Vpdn Operation
Vpdn and L2TP
L2TP channel
Methods of Implementing Vpdn
Tunnel and session
Networking diagram of two typical methods of Vpdn
Control message and data message
IV. Call setup flow of L2TP tunnel
Call setup flow of L2TP channel
Features of L2TP
Enable L2TP
Basic Configuration at
Enable/Disable L2TP
L2tp enable
L2tp-group group-number
Originate L2TP Connection Request and LNS Address
Ip-address … domain domain-name
Configure AAA and Local Users
By default, L2TP is disabled
Default list-name method1
L2TP Attribute Table
Operation Command Create a virtual template
Operation Command Create a L2TP group
Create/Delete L2TP Group
Create/Delete a Virtual Template
By default, receiving dial-in from LAC is disabled
Advanced Configuration at LAC or LNS
Configure the Name of the Receiving End of the Tunnel
Configure Local VPN Users
By default, the local name is the host name of router
Enable Tunnel Authentication Setting Password
Set Local Name
Tunnel name name
Set Tunnel Authentication and Password
Configure the Interval For Sending Hello Messages
Set the Interval for Sending Hello Message
Force
Configure Domain Delimiter and Searching Order
Set Domain Name Delimiter and Searching Order
Operation Command Force to disconnect tunnel
This configuration is applicable to LNS only
Reset l2tp tunnel remote-name
Force to Disconnect Channel
LCP does not renegotiate by default
Configure the Local Address and Address Pool
LCP to Renegotiate
By default, AV pairs are hidden
Enable/Disable Hiding Attribute Value Pairs AV
Enable/Disable Hiding AV Pairs
Number of L2TP Sessions
By default, the maximum number of L2TP sessions is
L2TP Configuration Examples
Use debugging, display command in all views
Display and Debug L2TP
Configure the IP address of Serial1 interface of LAC
Implement local AAA authentication on VPN user
Enable L2TP service and configure a L2TP group
Configure BDR dialup parameters
Configure the Virtual-Template-related information
Configure the IP address of Serial0 interface of LNS
Internet Connection Wizard
Internet Connection Wizard
Internet Connection Wizard
Internet Connection Wizard
Router-LACip pool 1 192.170.0.3
Client-originated VPN Networking
Configure BDR parameters
Configure the IP address of Serial1 interface at LAC side
Configure the IP address of Serial0 interface at LNS side
Disable tunnel authentication
Network Connection Wizard
Network Connection Wizard
Connect Connection to
Configure a L2TP group and the related attributes
Configure an IP address on Serial0 interface
Configure the domain suffix separator to @
Router1 l2tp domain suffix-separator @
Configure Virtual-Template
Enable AAA authentication
Force to implement local Chap authentication
III. Procedures
Configuration at Router2 LNS side Enable AAA authentication
Configure a L2TP group and configure the related attributes
Configure an address pool 1 in the range of 192.168.0.2 to
Configure an access control list and specify L2TP data
PPP negotiation fails. The reasons may be
Fault 1 The users fail to log
Troubleshooting L2TP
Configuring L2TP
Encapsulation
GRE Protocol
Packet
Encapsulated tunnel message format Refer to RFC
Enlarge network operating range
By default, no virtual tunnel interface is created
Configuring GRE
Creating a Virtual Tunnel Interface
Create Virtual Tunnel Interface
Setting the Network
Address of a Tunnel Must be configured Interface
Perform the configurations in the tunnel interface view
Address of the Tunnel
Set Tunnel Interface to Check with Checksum
Number discarded
Set the Tunnel to Synchronize Datagram Sequence Numbers
Gre key key-number
Group1 and group2. It can be implemented by using GRE
GRE Configuration Example
Debugging GRE
All views
Configure Router B Configure the IP address of Serial0
Configure the IP address of Ethernet0 interface
Configure the IP address and IPX address of Ethernet0
Configure Router a Activate IPX
Configure the static route to Novell Group2
Configure Router B Activate IPX
RouterB ipx route 1e 1f.a.a.a tick 30000 hop
Networking of troubleshooting GRE
Configuring a Standby Center Configuring Vrrp
646
Standby Center
Configuring Standby Center
Address logic-channelnumber
Enter the Logic Channel View
Fr map protocol address dlci dlci
Next-hop-address dialer-number
Standby timer enable-delay seconds
Channel to check whether it has recovered
Undo standby timer enable-delay
Standby timer disable-delay seconds
Load Sharing view
Please perform the following configuration in all views
Interfaces
Enter the view of Serial
Channel
Enter the view of logic channel
Router-logic-channel10standby interface serial
Router-Serial1logic-channel
Troubleshooting Vrrp
Vrrp Configuration Examples
Vrrp Overview
Vrrp Overview
Adding a Virtual IP
Configuring Vrrp
Address
Add Virtual IP Address
Configure Router Priority in Standby Group
Vrrp vrid virtualrouterid
Undo vrrp vrid virtualrouterid
Vrrp provides simple character authentication method
Configuring Authentication Method Authentication Key
Configure Authentication Method and Authentication Key
Virtualrouterid
Group Timer
Configure Standby
Debugging Vrrp
Monitoring
Procedure for each configuration
Vrrp Configuration
Backup with preemption aII. Networking diagram
Vrrp Single Standby
Balancing and mutual backup are implemented
Gateway services instead
Gateway function as the master
Multiple Standby
Many master routers exist within the same standby group
There is requent switchover of the Vrrp state
XI QOS
662
QOS Overview
Three Types of QoS Services
QOS Overview
Benefits of QoS for the Network Service
QOS Overview
Traffic Policing
Traffic Classification
Traffic POLICING, Traffic Shaping and Line Rate
Rate CAR
Committed Access
Define CAR Rules
Defining Rules
Qos carl carl-index precedence
Precedence-value mac mac-address
Applying the CAR Policy on the Interface
By default, no CAR rule of ACL list is established
Apply the CAR Rule on the Interface
Configure the Priority Level Based CAR Policy
CAR Configuration Applying a CAR Policy to all Packets
Displaying and Debugging CAR
Display and Debug CAR
Configure the CAR Policy Based on the MAC Address
Apply a CAR Policy on the Packets that Match ACL
Traffic Shaping
Matches ACL
Packets
Schematic diagram of GTS processing
Configuring shaping parameters for a specified flow
Configure the ACL
Configuring shaping parameters for all flows
Shape the flows matching 110 on Ethernet interface
Physical Interface Line
Configure the Physical Interface LIne Rate
Rate
Shape all the flows on Ethernet interface
Displaying Display and Debug LR Debugging LR
Operation Command Display the LR configuration conditions
Display qos lr interface type
Congestion Management
Management Policy
Congestion
Fifo Queuing
Priority Queuing
Selecting Congestion Management Policies
Number Queues Advantage Disadvantage
Comparison of Several Congestion Management Policies
Schematic diagram of the first in first out queue
Schematic diagram of the custom queuing
Schematic diagram of weighted fair queuing
Weighted Fair Queuing WFQ
Configuring Fifo Queuing
Configuring Congestion Management
Configuring priority queuing
Configure the First In First Out Queuing
Values of Queue-Option with Protocol as IP
By default, no priority queue is established
Protocol-name queue-option queue
Pql-index protocol
Applying the priority-list queuing group to the interface
By default, the interface utilizes the Fifo queue
Specifying the queue length of the priority-list queuing
Configuring Custom Queuing CQ
Configuring custom-list queuing
Default Length Value of the Priority Queue
Displaying and debugging the priority queue
Configure the Default Custom-List Queuing
Configure the Custom-Lst Queuing According to the Interface
Queue-number
Queue queue-number
Configuring the queue length of the custom-list queuing
By default, the interface uses the Fifo queue
Configure the Queue Length of the Custom-List Queuing
Applying the custom-list queuing group to the interface
Displaying and debugging the weighted fair queue
Configuring Weighted fair queuing
Displaying and debugging the custom-list queue
PQ Configuration Example
Congestion Management Configuration Examples
Apply the priority queue 1 to Serial
Apply the priority queue 2 to Serial
Configure Router B Configure the access control list
Configure the CQ queue
RouterA-Tunnel0ip address 10.1.1.1
RouterA-Tunnel1destination
Configure Tunnel0
Configure Serial0 master/slave addresses
Configure Tunnel1
WFQ Configuration Example
Congestion Management
Congestion Avoidance
Congestion Avoidance
Enable the Wred
Wred Configuration
Enable Wred
Function of the Interface
Ip-precedence
Discard-prob
Configure a WFQ queue
Congestion Avoidance Configuration Example
Enable Wred
Displaying Debugging Congestion Avoidance
Congestion Avoidance
XII DIAL-UP
Configuring DCC Configuring Modem
704
DCC Overview
Terms in DCC Configuration
DCC
Circular DCC
Resource-Shared DCC
With 3Com Routers
Basic DCC features
Implementing callback through DCC
Preparing to Configure
Configuring DCC
Prepare the data for DCC configuration
Configure the local parameters of DCC
Configure Physical Interface Mode
Configuring the mode of the physical interface
Linklayer-protocol-type
Ip address ipaddress mask
Associating a DCC dialer ACL with the interface
Configuring an interface to originate calls to a remote end
Dialer enable-circular
Configure an interface to receive calls from a remote end
Dialer number dial-number
Undo dialer number
Route protocol
Dialer
Next-hop-address dial-number
Next-hop-address
Undo dialer route protocol
Dialer circular-group number
Undo interface dialer number
Undo dialer circular-group
Dialer priority priority
Undo interface dialer number
Interface dialer number
Dialer circular-group number
Undo dialer circular-group
Router Dialer0
Configuring the dialer interface and dialer number
Configuring dialing authentication for resource-shared DCC
By default, no dialer interface is created
Enabing Resource-Shared DCC
Configuring dialing authentication for resource-shared DCC
Configure MP Binding in Circular DCC
Configuring MP binding in circular DCC
Threshold traffic-percentage
Configuring PPP callback in the circular DCC implementation
Configuring MP binding in resource-shared DCC
Configure MP Binding in Resource-Shared DCC
Dialer threshold traffic-percentage
Implement PPP Callback Server Configuration in Circular DCC
Implement PPP Callback Client Configuration in Circular DCC
Telephone-number
Command
Next-hop-address user username
Dial-number
Primary rule The best match is the number with the fewest
Features of Isdn caller identification callback
Dialer callback-center dial-number
Identification
Operation Command Configure the local end to implement
Undo dialer call-in remote-number
Callback according to the Isdn caller
Configuring auto-dial
Configuring Isdn leased line
Configuring Special DCC Functions
Configure Isdn leased line for Circular DCC
Configuring the Link Idle Time
Configuring dialer number circular standby
Configure Auto-Dial
Configure Dialer Number Circular Standby
By default, the link disconnection time is 20 seconds
By default, the link idle time is 120 seconds
Configuring the link idle time when interface competion
Configure the Link Idle Time
By default, the timeout of call setting up is 60 seconds
Configuring the timeout of call setting up
Configuring the buffer queue length of the dialer
Debugging DCC
Solution
DCC Configuration Examples
DCC Applications in Common Use
Configure RouterB
Configure RouterC
Router-Serial1dialer circular-group
Router-Serial0dialer route ip 100.1.1.1
Router-Serial1dialer bundle-member
Router-Serial0dialer bundle-member
Configure RouterC
Configure RouterC
Router-Dialer0dialer threshold
Configure RouterA
Router-Bri0dialer bundle-member
Router-Serial015dialer route ip 100.1.1.1
Router-Bri1dialer route ip 100.1.1.1
Router-Serial0dialer route ip 100.1.1.2
Router-Serial1dialer enable-circular
Router dialer-rule 1 ip permit Router interface serial
Router-Bri0dialer route ip 100.1.1.2 user usera
Callback for DC C
Configure the PC
By the NT server
NT Server-to-Router
Router-Async0dialer route ip 100.1.1.254
Dial Number Circular Standby and Internet Access for DCC
Router-Serial0dialer route ip 100.1.1.254
Configure subscriber PC
Router-Serial215ppp chap password simple passb
Router-Serial215ppp authentication-mode chap
Router-Serial1standby logic-channel
Remote end cannot be pinged after the modem is connected
Message Fault
DCC Fault Messages
DCC peeraddr matching error
Modem Script
Modem Function Provided by 3Com Routers
Modem script format in common use is as follow
Syntax description of modem script
Receive-string1 send-string1 receive-string2 send-string2
Configure the Modem Dial-in and Dial-out Authorities
Which, seconds defaults to 180 and is in the range of 0 to
By default, modem dial-in and dial-out are allowed
Configure a Modem Script
Configure Modem Through the AT Command
Configure a Modem Script
Execute a Modem Script Manually
Configure the Answer Mode for the Modem
By default, the modem works in non-auto answer mode
Configure Authentication for a Modem Dial-in User
Specify the Events Triggering the Modem Scripts
Executethe debugging command in all views for the debugging
Modem Configuration Examples
Configure a Modem adaptation baud rate
Displaying and Debugging a Modem
Configure the modem initialization parameters
Restore the ex-factory modem settings
AT&b1&c1&d2&s0=0
Authentication for
Power-on Initialization Through Initialization Script
Directly
Modem Dial-in User
Troubleshooting
Configuring Modem