Quidway S5700 Series Ethernet Switches

V100R006C01

Configuration Guide - IP Service
Issue

01

Date

2011-10-26

HUAWEI TECHNOLOGIES CO., LTD.

Copyright © Huawei Technologies Co., Ltd. 2011. All rights reserved.
No part of this document may be reproduced or transmitted in any form or by any means without prior written
consent of Huawei Technologies Co., Ltd.

Trademarks and Permissions
and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd.
All other trademarks and trade names mentioned in this document are the property of their respective holders.

Notice
The purchased products, services and features are stipulated by the contract made between Huawei and the
customer. All or part of the products, services and features described in this document may not be within the
purchase scope or the usage scope. Unless otherwise specified in the contract, all statements, information,
and recommendations in this document are provided "AS IS" without warranties, guarantees or representations
of any kind, either express or implied.
The information in this document is subject to change without notice. Every effort has been made in the
preparation of this document to ensure accuracy of the contents, but all statements, information, and
recommendations in this document do not constitute the warranty of any kind, express or implied.

Huawei Technologies Co., Ltd.
Address:

Huawei Industrial Base
Bantian, Longgang
Shenzhen 518129
People's Republic of China

Website:

http://www.huawei.com

Email:

support@huawei.com

Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

i

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

About This Document

About This Document
Intended Audience
This document describes the configurations of the IP services of the S5700, including the basic
knowledge and configurations of secondary IP addresses, DNS, DHCP, IP performance, DHCP
Policy VLAN, basic IPv6 functions, and IPv6 over IPv4 tunnels. By reading this document, you
can learn the concepts and configuration procedures of IP services.
This document is intended for:
l

Policy planning engineers

l

Installation and commissioning engineers

l

NM configuration engineers

l

Technical support engineers

Symbol Conventions
The symbols that may be found in this document are defined as follows.
Symbol

Description

DANGER

WARNING

CAUTION

Issue 01 (2011-10-26)

Indicates a hazard with a high level of risk, which if not
avoided, will result in death or serious injury.
Indicates a hazard with a medium or low level of risk, which
if not avoided, could result in minor or moderate injury.
Indicates a potentially hazardous situation, which if not
avoided, could result in equipment damage, data loss,
performance degradation, or unexpected results.

TIP

Indicates a tip that may help you solve a problem or save
time.

NOTE

Provides additional information to emphasize or supplement
important points of the main text.

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

ii

. One item is selected. A minimum of one item or a maximum of all items can be selected. Ltd. { x | y | . # A line starting with the # sign is comments.. Change History Updates between document issues are cumulative.. Several items or no item can be selected. One item is selected or no item is selected.. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. }* Optional items are grouped in braces and separated by vertical bars. [ x | y | . ]* Optional items are grouped in brackets and separated by vertical bars. Therefore.. Changes in Issue 01 (2011-10-26) Initial commercial release.IP Service About This Document Command Conventions The command conventions that may be found in this document are defined as follows.Quidway S5700 Series Ethernet Switches Configuration Guide .. { x | y | ... ] Optional items are grouped in brackets and separated by vertical bars. iii . [] Items (keywords or arguments) in brackets [ ] are optional. Italic Command arguments are in italics. Convention Description Boldface The keywords of a command line are in boldface. [ x | y | . } Optional items are grouped in braces and separated by vertical bars. &<1-n> The parameter before the & sign can be repeated 1 to n times.. the latest document issue contains all changes made in previous issues.

...................................................................................10 2.........................16 2..........................................................1 Establishing the Configuration Task..................................................................3 Configuring Static ARP............................................................................2 Features of IP Addresses Supported by the S5700.......................2 1..................................1 Example for Setting Primary and Secondary IP Addresses.............3 Configuring Static ARP Entries in a VLAN............................................4 Configuring Static ARP Entries in a VPN Instance..................................................14 2.......3 (Optional) Configuring a Secondary IP Address for an Interface...............................5.....................10 2..........4 Optimizing Dynamic ARP................................................................................................. Ltd..4...................1 1........3 1.........................3..........................................2 Configuring Common Static ARP Entries...................................................14 2........3..........17 2.............................................................................1 Establishing the Configuration Task.................3...................................13 2.....................................................................................................2 Modify the aging parameters of dynamic ARP.3 Configuring IP Addresses for Interfaces.............................................................5 Checking the Configuration......................................................................................1 Introduction to IP Addresses..............................................................4...........................13 2.......4...............................................3.........................................9 2.....................................................8 2.....4.............................................................................................................................................................................................3................................................. iv ................................3....5.............2 Configuring a Primary IP Address for an Interface............................................................................................................5 Checking the Configuration.....................................3.......5 Configuring Routed Proxy ARP..............17 2...............4 Checking the Configuration..........................................................................IP Service Contents Contents About This Document.......................................................9 2...........................................................17 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co........5 1................2 1....................................2 Configure an IP Addresses for the Interface...6 Configuring Proxy ARP Within a VLAN....................12 2....................................................................................................4 Enabling Layer 2 Topology Detection Function..........................................4 Checking the Configuration..............................................................................................16 2............................................................3 1................................................................13 2.....4..................15 2....3 Enabling ARP Suppression Function.Quidway S5700 Series Ethernet Switches Configuration Guide .....................................................................................................................................................................................................3.................................................................1 Establishing the Configuration Task........4 1........................3 1.....................4 1.............................................4..........................15 2...................................ii 1 IP Addresses Configuration.................................3....15 2.......................................................3 Enabling the Routed Proxy ARP Function...............11 2.....................................................4 Configuration Examples.....5..................................................2 ARP Features Supported by the S5700.......................................................................5 2 ARP Configuration.............................................1 Overview of ARP........................1 Establishing the Configuration Task.............................................11 2............................5...............

.............................4..............................................49 3..................................................................9..............8....................2 Monitoring Network Operation Status of ARP.1 Establishing the Configuration Task.................................4 Configuring the DHCP Server Based on the VLANIF Interface Address Pool.........3....3..........23 2.......... v ......19 2..............................................................................................9 Configuration Examples.IP Service Contents 2........................................21 2............................................................................4 Example for Configuring Inter-VLAN Proxy ARP.................................................................................................4........................................................................54 3........5 (Optional) Configuring NetBIOS for Global Address Pool......................................43 3......................................2 Configuring Address Allocation Mode for Interface Address Pool.....2 DHCP Features Supported by the S5700........................................................................................................................................1 Establishing the Configuration Task..........................................................9 Checking the Configuration...9.....2 Configuring an IP Addresses for the Interface........7.........7.....39 3.....3 Enabling Proxy ARP Within a VLAN.....................................................................51 3.................................................................................8 (Optional) Configuring Automatic Saving of DHCP Data...........................................................................................41 3...............................................................4.....................................8.....5 Example for Configuring Layer 2 Topology Detection...................................................................................................................7 (Optional) Preventing Repetitive Allocation of an IP Address...30 2.33 3 DHCP Configuration.........................................................8 Maintaining ARP..6 (Optional) Preventing Repetitive Allocation of an IP Address...........22 2...48 3................46 3............4 (Optional) Configuring DNS for Global Address Pool.................................................50 3..........4...........6 (Optional) Configuring the Customized DHCP Option for the Global Address Pool......3..52 3.....26 2.......................................................................................37 3...6........1 Example for Configuring ARP.................3..................................................................3 Debugging ARP................................................3...................................................................................20 2...3....56 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co................3 Example for Configuring Intra-VLAN Proxy ARP................................................................................4.....................................................3 Configuring Address Allocation Mode for Global Address Pool........................53 3.........................5 Configuring the DHCP Relay Agent.............................22 2.........................2 Configuring an Interface to Use Global Address Pool...................44 3...............................................................................21 2..................................................................................6...4......5 (Optional) Configuring the Customized DHCP Option of the VLANIF Interface Address Pool...36 3................1 Introduction to DHCP.................28 2.............................45 3.47 3...........................................7...................................................................................18 2............................................................................................................9............9.................................................................................4 Checking the Configuration................................................................Quidway S5700 Series Ethernet Switches Configuration Guide .......................................21 2...55 3.............1 Establishing the Configuration Task..19 2......................47 3.................2 Example for Configuring Routed Proxy ARP..............................................................................20 2.6.................................................3 Enabling Proxy ARP Between VLANs.................................................7 Configuring Proxy ARP Between VLANs...2 Configure an IP Addresses for the Interface.............37 3..........23 2.............................................8..............19 2............8 Checking the Configuration.........................9...........7.......................4............................... Ltd...............................................................................................4...................3 (Optional) Configuring the DNS Service of the VLANIF Interface Address Pool......4 Checking the Configuration......4 (Optional) Configuring the NetBIOS Service of the VLANIF Interface Address Pool....................3......................3.......................22 2...........42 3......................................................54 3......................................40 3........................................................6.............1 Clearing ARP Entries.........................3............................18 2.................3 Configuring the DHCP Server Based on the Global Address Pool..............7 (Optional) Configuring Automatic Saving of DHCP Data.............................................1 Establishing the Configuration Task........

.......................4.....................................................4 Maintaining DHCPv6...........................61 3..79 4..................56 3...............................2 Enabling the DHCPv6 Relay Function...............3....................................................................................................................................................................................................................................................6 Checking the Configuration..........................4 (Optional) Configuring Rate Limit of DHCPv6 Messages.................................3..62 3.....78 4................................................................1 Clearing DHCP Statistics.....4 Binding an Interface to a DHCP Server Group...............................1 Example for Configuring DHCPv6 Relay..............................81 4.................1 Establishing the Configuration Task.............................................................................................3 Configuring a Destination DHCP Server Group..............................................................60 3......................................................................70 4 DHCPv6 Configuration...................................................1 Introduction to DHCPv6............................94 5............................................................................5................5.........3.........5.......................................................................2 Monitoring the Running Status of the DHCPv6 Relay Agent............................................................5 Configuration Examples........................................74 4....................................................94 5.................................................88 5.................89 5....................................................3 Optimizing IP Performance..........................................................3 Debugging IP Performance..............................87 5.............................................3..........................57 3........................................4...............5..3...................................................................................................2 Example for Configuring the DHCP Server Based on the Interface Address Pool.......................................3 (Optional) Configuring the Remote ID.................................3........90 5.......................................88 5........................................7...........7 Configuration Examples.........82 4.......62 3...........................................5.................................................................................................................1 Establishing the Configuration Task..............7................ vi .62 3.............................................Quidway S5700 Series Ethernet Switches Configuration Guide .........................................................3....6.....2 Monitoring DHCP Operation................................6....75 4........................................................................3...............................................................1 Example for Configuring a DHCP Server Based on the Global Address Pool......................95 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.....................................5 Configuration Examples......76 4...............58 3...5..............78 4.........92 5..IP Service Contents 3..................................................................88 5...........................................3................. Ltd.......................66 3..............83 4................................3 Configuring DHCPv6 Relay....88 5...............................................................................................................2 Monitoring the Running Status of IP Performance.....................4..........................63 3....90 5.....................................2 Enabling an Interface to Check the Source IP Addresses of Packets.....................................5....................................................................................4.59 3...................................................................................3 Configuring ICMP Attributes..........................................................82 4.....................1 Introduction to IP Performance............................................................................................4 Maintaining IP Performance................................1 Clearing the Statistics About DHCPv6 Messages Passing Through the DHCP Relay Agent....................................................................................................3...................................................................62 3....1 Clearing IP Performance Statistics....................6 Maintaining DHCP..................78 4....3 Example for Configuring a DHCP Relay Agent...........2 IP Performance Supported by the S5700...........................................................7........................1 Example for Disabling the Sending of ICMP Host Unreachable Packets..............................................................................................5 Checking the Configuration.......93 5.....................................................5 Checking the Configuration................................5...............83 5 IP Performance Configuration..82 4....................................91 5......92 5...............................................................................2 DHCPv6 Features Supported by the S5700..........1 Establishing the Configuration Task..........................................................................................................................................2 Configuring DHCP Relay on an Interface.........81 4....................................4 Setting TCP Parameters.............................................5 (Optional) Configuring the DHCP Relay Agent to Send DHCP Release Packet................................................................................4.......

...........................................................................3 Configuring DHCP Policy VLAN Based on MAC Addresses............................................99 6..101 6.........................114 7.......110 7.......114 7.......................1 Monitoring the Running Status....................................................................................................................................................................4.........................113 7................115 8 Basic Configurations of IPv6........123 8...................................................4 Maintaining DNS......................................6.........110 7.....3.1 Establishing the Configuration Task....................2 Configuration Procedure....................................................................111 7.............................................................................5.......................................................1 Establishing the Configuration Task............................................3..............................................................................................101 6.122 8....2 Monitoring Network Operation Status of DNS...........3.................................................................100 6..............................3 Checking the Configuration..............................4 Configuring the DHCP Policy VLAN Based on Interfaces....................103 6................................3...........................................4 Configuring an IPv6 Global Unicast Address for an Interface...............................5 Configuring Generic DHCP Policy VLAN....3..............................3 Configuring an IPv6 Link-Local Address for an Interface.....................................................................................................................................................................................................................................104 6..................................................1 Establishing the Configuration Task...............................................................................3.........................................................................110 7.........112 7............................3 Configuring an IPv6 Address for an Interface...120 8...........................120 8................99 6...................................................... vii .................................7.......................99 6...............................................................................................................................................7....103 6.....................................................2 Configuring Static DNS Entries.........4.........5..........4 Checking the Configuration....................1 Introduction...........................................................122 8.......................2 DHCP Policy VLAN Supported by the S5700................104 6.1 Establishing the Configuration Task...............................3.........................3 Configuring Dynamic DNS........................101 6...............................................................................................................................................................................................................4..........................2 Example for Configuring DHCP Policy VLAN Based on Interfaces...................................................110 7.............4..........................111 7........................................................... Ltd...............................5......................................5 Configuration Examples...................................2 Enabling IPv6 Packet Forwarding Capability..................................................109 7.................................................................................................................................................................................................3 Debugging DNS.....................................................................................................................................................................................................................................................1 Example for Configuring DHCP Policy VLAN Based on MAC Addresses...............2 Configuration Procedure................................3 Checking the Configuration.........................................................3.................104 6............................................................................1 Introduction to DNS.......................IP Service Contents 6 DHCP Policy VLAN Configuration.......1 Clearing DNS Entries................................................................................................................................2 DNS Supported by the S5700......5................100 6....3 Configuring DNS................................2 Configuration Procedure.......104 6.........................................99 6...............106 7 DNS Configuration..............................................................................................................................................................................................................123 8..3......6 Maintaining DHCP Policy VLAN..............3 Checking the Configuration.........4......104 6..................................1 Example for Configuring DNS..2 IPv6 Features Supported by the S5700............119 8....124 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co..........................................................................1 Introduction to IPv6.........................................1 Establishing the Configuration Task...............................................................................115 7....102 6..........................................3.............................................Quidway S5700 Series Ethernet Switches Configuration Guide ....................98 6............113 7...........................................................................................................................................................................................4.................102 6...3.............................7 Configuration Examples.......................

.......................................................142 9............................3................................126 8.......................................6 Configuration Examples...............................4 Configuring an IPv6 over IPv4 Tunnel................................................................................................................................................................................................................3...............................................................................................................................4..........4............139 9.................155 10.......................................................2 Enabling the Service Loopback Function on an Eth-Trunk Interface..................3 Configuring IPv4/IPv6 Dual Stacks...................3............2 Enabling IPv6 Packet Forwarding..............................................................................................................................................141 9................152 10.....................................4.........................................................................2 IPv6 over IPv4 Supported by the S5700....................................................................................................................................................................................4.........................2 Configuring Static Neighbors...........3 Configuring an IPv6 over IPv4 Manual Tunnel....3...............................5 Configuration Examples.........3 Configuring IPv6 DNS...................4.......................4...........................................154 10..............................4 Configuring IPv6 Neighbor Discovery..4.............................................Quidway S5700 Series Ethernet Switches Configuration Guide .......5.................3 Debugging IPv6................................142 9.......................................................................147 10...5 Checking the Configuration.............................133 9 IPv6 DNS Configuration.....................................................................2 Monitoring Network Operation Status of IPv6 DNS...................................4 Setting the Interval for Advertising RA Messages....................3 Configuring IPv4 and IPv6 Addresses for the Interface..................................................................................................................................................1 Introduction to IPv6 DNS.................6 Configuring the Address Prefixes to Be Advertised....................................................................................131 8...............4.132 8.........................1 Establishing the Configuration Task.......................................................5 Enabling Stateful Auto Configuration................................................132 8..............7 Configuring Other Information to Be Advertised......................141 9...........................5....................................................138 9.....3............4............128 8....................................................................................................................................1 Example for Configuring IPv6 DNS.................4 Checking the Configuration..............148 10........................5..............................139 9...............................1 Clearing IPv6 DNS Entries...............................................................................5 Maintaining IPv6............2 Configuring a Static IPv6 DNS Entry...........................................................................................................4 Checking the Configuration.........................................................3..........................................................157 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.......153 10.........................................................1 Establishing the Configuration Task................................................................................137 9................................ viii ...............4.................................125 8........................5..................6........8 Checking the Configuration......................................155 10.....................................................................................................................................................4 Maintaining IPv6 DNS.......................................................................138 9.................................133 8....3 Configuring the Dynamic IPv6 DNS Services........................................3....1 Introduction to IPv6 over IPv4..........................................................................1 Establishing the Configuration Task..............................................................138 9.....................................................................127 8......................126 8..4.........................................148 10.....................................................................156 10........................................................................1 Clearing IPv6 Statistics.125 8.............4.........3..............130 8....4...........................................125 8.....................................2 IPv6 DNS Supported by the S5700........................129 8......3...............................................1 Example for Setting an IPv6 Address for an Interface.......................140 9...........1 Establishing the Configuration Task..................... Ltd.....................................................142 10 IPv6 over IPv4 Tunnel Configuration....................4...................................................................................155 10..............3 Enabling RA Message Advertising..IP Service Contents 8...138 9...................4 Configuring a 6to4 Tunnel............................................................128 8...........152 10..............................2 Monitoring the Running Status of IPv6........................................131 8...155 10..................................................................................

......................IP Service Contents 10....................Quidway S5700 Series Ethernet Switches Configuration Guide ...4.................................................. ix ............169 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.............. Ltd.......5 Configuration Examples....................................3 Example for Configuring an ISATAP Tunnel...................5...................160 10..............................5 Configuring an ISATAP Tunnel.................................................................5..4.......................................159 10.........160 10............4......................6 Configuring Routes in the Tunnel........7 Checking the Configuration................................................................................................5................................................158 10............160 10...........165 10...........................................1 Example for Configuring an IPv6 over IPv4 Tunnel Manually.2 Example for Configuring a 6to4 Tunnel........................................................................................................

3 Configuring IP Addresses for Interfaces Assigning an IP address to a device on a network enables the device to communicate with the other devices on the network.Quidway S5700 Series Ethernet Switches Configuration Guide . 1 . 1. Internet Control Message Protocol (ICMP). Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 1.2 Features of IP Addresses Supported by the S5700 IP addresses can be obtained through static manual configuration or DHCP. you can enable data communications between the network devices.1 Introduction to IP Addresses IP is the core of the TCP/IP protocol suite. User Datagram Protocol (UDP). namely IP addresses. Ltd.4 Configuration Examples This section provides several examples of IP address configuration. The packets of the Transmission Control Protocol (TCP). 1. and Internet Group Membership Protocol (IGMP) are all transmitted in the format of IP datagrams. 1.IP Service 1 1 IP Addresses Configuration IP Addresses Configuration About This Chapter By assigning IP addresses to network devices.. Devices on different networks communicate with each other using their network layer addresses.

For example. Therefore. the network ID and host ID.1.1.1. l The primary IP address and the secondary IP address in the overlapped network segments but not same can be configured on different interfaces of the same device. after an interface on a device is configured with the IP address 20. the system prompts a message. For example.2/16 sub.2/16.1/16. However. An IP address is a 32-bit number that is composed of two parts.2 Features of IP Addresses Supported by the S5700 IP addresses can be obtained through static manual configuration or DHCP. 2 . namely IP addresses. each host must be assigned an IP address. Devices on different networks communicate with each other using their network layer addresses. The S5700 supports IP address configuration through the following methods: l Manually configuring an IP address for an interface l Obtaining an IP address by DHCP The S5700 supports the space overlapping of network segment addresses to save the address space. the configuration is still successful.1/16. l Different IP addresses in the overlapped network segments but not same can be configured on different interfaces of the same device. after an interface on a device is configured with the IP address 20. Internet Control Message Protocol (ICMP).IP Service 1 IP Addresses Configuration 1. The two IP addresses can be used as host addresses. Ltd.. if the secondary IP address is 20. However.1. there are only two IP addresses in a network segment. The S5700 supports 31-bit IP address masks.1. namely. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1.2/24 sub.1. if another interface is configured with the IP address 20. the primary IP address and the secondary IP address cannot be the same. the configuration is still successful. the system prompts a message. that is. the system prompts a message. the configuration is still successful.1 Introduction to IP Addresses IP is the core of the TCP/IP protocol suite. the system prompts an IP address conflict. However.1. The packets of the Transmission Control Protocol (TCP). The network ID identifies a network and the host ID identifies a host on the network. User Datagram Protocol (UDP).1. it indicates that the hosts are on the same network regardless of their physical locations.1. If the network IDs of hosts are the same.1. To communicate with each other on Internet Protocol (IP) networks. after the interface is configured with a primary IP address 20.Quidway S5700 Series Ethernet Switches Configuration Guide . However. For example.1. if another interface is configured with the IP address 20.1/24.2/24. The configuration fails. and Internet Group Membership Protocol (IGMP) are all transmitted in the format of IP datagrams. if another interface is configured with the IP address 20. the network address and broadcast address. l The primary IP address and the secondary IP address in the overlapped network segments but not same can be configured on the same interface.1.1. 1.

You can assign several IP addresses to each interface. Data 1 Interface number 2 Primary IP address and subnet mask of the interface 3 (Optional) Secondary IP address and subnet mask of the interface 1. configure the IP address for the interface. Pre-configuration Tasks Before configuring an IP addresses for an interface. pre-configuration tasks. Secondary IP addresses. 3 . Among them. 1. you need to configure only a primary IP address for an interface. when a device connects to a physical network through an interface. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Generally.2 Configuring a Primary IP Address for an Interface An interface can have only one primary IP address. are required in some cases. Ltd.Quidway S5700 Series Ethernet Switches Configuration Guide . you need to configure a primary IP address and a secondary IP address for this interface to ensure that the device can communication with all computers on this network.3. you need the following data. one is the primary IP address and the others are secondary IP addresses. Applicable Environment To start IP services on an interface. complete the following tasks: l Configuring the physical parameters for the interface and ensuring that the physical layer status of the interface is Up l Configuring the link layer parameters for the interface and ensuring that the status of the link layer protocol on the interface is Up Data Preparation To configure IP addresses for an interface. No.3. data preparation. For instance. however.IP Service 1 IP Addresses Configuration 1. and configuration procedure for assigning an IP address to an interface..3 Configuring IP Addresses for Interfaces Assigning an IP address to a device on a network enables the device to communicate with the other devices on the network.1 Establishing the Configuration Task This section describes the applicable environment. and computers on this network belong to two Class C networks.

3. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Prerequisite The configurations of the IP addresses for the interface are complete.3. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. Step 3 Run: ip address ip-address { mask | mask-length } A primary IP address is configured. ----End 1.4 Checking the Configuration You can view the configuration of the IP address for an interface.3 (Optional) Configuring a Secondary IP Address for an Interface To enable an interface to communicate with several networks with different network IDs.Quidway S5700 Series Ethernet Switches Configuration Guide . ----End 1. You can configure a maximum of 8 secondary IP addresses on an interface. 4 .. the newly configured primary IP address replaces the original one. If the interface already has a primary IP address. Ltd. you need to assign a secondary IP address to this interface. Step 3 Run: ip address ip-address { mask | mask-length } sub A secondary IP address is configured. Procedure Step 1 Run: system-view The system view is displayed. An interface has only one primary IP address. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed.IP Service 1 IP Addresses Configuration Procedure Step 1 Run: system-view The system view is displayed.

1/24 sub 172.16.16. 2.16.2.0/24 Configuration Roadmap The configuration roadmap is as follows: 1.0/24.0/24 cannot interconnect with the host in 172.0/24. Set the secondary IP addresses for an interface.1/24 172. Figure 1-1 Networking diagram for setting IP addresses 172.IP Service 1 IP Addresses Configuration Procedure l Run the display ip interface [ brief ] [ interface-type [ interface-number ] ] command to check the IP configuration on the interface. Analyze the address of the network segment to which each interface is connected. ----End 1. 1. that is 172. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide .2.1. Ltd.2. 5 .0/24 and 172.4 Configuration Examples This section provides several examples of IP address configuration.16.1. l Run the display interface [ interface-type [ interface-number ] ] command to check interface information. in which hosts belong to two different network segments.16. Networking Requirements As shown in Figure 1-1..2. GigabitEthernet 0/0/1 of the Switch is connected to a LAN. It is required that the Switch can access the two network segments but the host in 172.16.1 Example for Setting Primary and Secondary IP Addresses This section provides a configuration example of setting primary and secondary IP addresses.0/24 Switch GE 0/0/1 VLANIF 100 172.1.4.16.16.1.

2 PING 172.2 ping statistics --5 packet(s) transmitted 5 packet(s) received 0.16.16. The ping succeeds.0 from Switch.2: bytes=56 Sequence=5 ttl=128 time=26 --.2: 56 data bytes.1 24 [Quidway-Vlanif100] ip address 172.1.2.1. press CTRL_C to break Reply from 172. l Primary IP address and subnet mask of the VLANIF interface l Secondary IP address and subnet mask of the VLANIF interface Procedure Step 1 Set the IP address for VLANIF 100 where GigabitEthernet 0/0/1 of the Switch belongs.1 24 sub Step 2 Verify the configuration. 6 . <Quidway> ping 172.1.2.2. press CTRL_C to break Reply from 172.1.16.2 PING 172.2: bytes=56 Sequence=2 ttl=128 time=26 Reply from 172. The ping succeeds.2: bytes=56 Sequence=1 ttl=128 time=25 Reply from 172.16. <Quidway> ping 172.172.16.16.16.16..16.16.2: bytes=56 Sequence=3 ttl=128 time=26 Reply from 172.16.16.0 from the Switch.16.00% packet loss round-trip min/avg/max = 25/25/26 ms ms ms ms ms ms ----End Configuration Files Configuration file of the Switch # sysname Quidway # vlan 100 # interface Vlanif100 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1.2.2.16.16.16.2.1. you need the following data.2.1.16. Ltd.2.2: bytes=56 Sequence=1 ttl=128 Reply from 172.Quidway S5700 Series Ethernet Switches Configuration Guide .2.2: bytes=56 Sequence=5 ttl=128 --.172.2: bytes=56 Sequence=4 ttl=128 Reply from 172.16.2.1.2: 56 data bytes. # Ping a host on network segment 172.2.2: bytes=56 Sequence=2 ttl=128 Reply from 172. <Quidway> system-view [Quidway] vlan 100 [Quidway-Vlan100] quit [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [Quidway-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface vlanif 100 [Quidway-Vlanif100] ip address 172.2: bytes=56 Sequence=4 ttl=128 time=26 Reply from 172.IP Service 1 IP Addresses Configuration Data Preparation To complete the configuration.1.2: bytes=56 Sequence=3 ttl=128 Reply from 172.16.2 ping statistics --5 packet(s) transmitted 5 packet(s) received 0.00% packet loss round-trip min/avg/max = 25/26/27 ms time=25 time=27 time=26 time=26 time=26 ms ms ms ms ms Ping a host on network segment 172.16.

2.0 ip address 172..1 255.255.255.1. 7 .Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 1 IP Addresses Configuration ip address 172.255. Ltd.255.16.1 255.16.0 sub # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.

6 Configuring Proxy ARP Within a VLAN By configuring proxy ARP on a VLAN. 2.8 Maintaining ARP The operations of ARP maintenance include clearing ARP statistics and monitoring ARP operating status.1 Overview of ARP An Ethernet device must support ARP. 2. you can interconnect hosts on different VLANs. you can interconnect isolated hosts on a VLAN. 2.2 ARP Features Supported by the S5700 This section describes the ARP features supported by the S5700.4 Optimizing Dynamic ARP If dynamic ARP is configured. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 2. the system automatically resolutes an IP address into an Ethernet MAC address.5 Configuring Routed Proxy ARP Proxy ARP enables devices whose IP addresses belong to the same network segment but different physical networks to communicate with each other..9 Configuration Examples This section provides several configuration examples of ARP.3 Configuring Static ARP Static ARP indicates that there is a fixed mapping between an IP address and a MAC address. Static ARP needs to be configured by an administrator. ARP implements dynamic mapping between Layer 3 IP addresses and Layer 2 MAC addresses. 8 . 2.IP Service 2 ARP Configuration 2 ARP Configuration About This Chapter ARP can map an IP address to a MAC address and implements transmission of Ethernet frames.Quidway S5700 Series Ethernet Switches Configuration Guide . 2.7 Configuring Proxy ARP Between VLANs By configuring inter-VLAN proxy ARP. 2. Ltd. 2. 2.

and Layer 2 topology detection.Quidway S5700 Series Ethernet Switches Configuration Guide . l Dynamic ARP means that the ARP mapping table is dynamically maintained by the ARP protocol.1 Overview of ARP An Ethernet device must support ARP. Routed proxy ARP is introduced to solve this problem. By "faking" its identity. a host or a device transmits and receives Ethernet frames according to a 48-bit Medium Access Control (MAC) address. Each host or device on the Local Area Network (LAN) can be configured a 32-bit IP address to communicate with others. After receiving such a request. The Address Resolution Protocol (ARP) maps an IP address to the corresponding MAC address. on an interconnected network. l Static ARP means the mapping between manually configured IP addresses and MAC addresses. Therefore. On the Ethernet. which is assigned to an Ethernet interface when equipment is produced. The host sends an ARP Request message. ARP implements dynamic mapping between Layer 3 IP addresses and Layer 2 MAC addresses. static ARP.. the switch enabled with proxy ARP answers with its own MAC address.IP Service 2 ARP Configuration 2. The assigned IP address is independent of the hardware address. the host does not know how to reach the intermediate system of the network). 9 . if the current host connected with a switch is not configured with a default gateway address (that is. The switch enabled with proxy ARP can also hide the details of the physical networks and implement the communication between hosts that are in different physical networks but on the same network segment. 2. Ltd.2 ARP Features Supported by the S5700 This section describes the ARP features supported by the S5700. The S5700 supports dynamic ARP. l Issue 01 (2011-10-26) Intra-VLAN proxy ARP Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. proxy ARP The S5700 supports the following types of proxy ARP: l Routed proxy ARP Proxy ARP lets the PCs or switchs on the same network segment but in different physical networks communicate. In actual applications. The MAC address is also called the physical address or the hardware address. an address resolution mechanism is required to provide the mapping between MAC addresses and IP addresses. ARP ARP is classified into the following types: dynamic ARP and static ARP. the switch accepts responsibility for routing messages to the "real" destination. the host cannot forward data packets. requesting the MAC address of the destination host. proxy ARP.

and configuration procedure for configuring static ARP. Proxy ARP between VLANs is mainly applied to the following situations: – Implementing Layer 3 interworking between users in different VLANs – Implementing interworking between sub-VLANs by enabling proxy ARP between VLANs on the VLANIF interface of the super VLAN 2. Pre-configuration Tasks Before configuring ARP. Applicable Environment Static ARP is used in the following situations: l For the packets whose destination IP address is on another network segment. 10 . static ARP can bind these illegitimate addresses to a nonexistent MAC address.. Instead. In this case.1 Establishing the Configuration Task This section describes the applicable environment. The interfaces enabled with proxy ARP between VLANs do not directly discard the ARP Request messages that are not for themselves. static ARP can help these packets traverse a gateway of the local network segment so that the gateway can forward the packets to their destination. they search the ARP mappings tables on themselves for the corresponding ARP entries. Proxy ARP within a VLAN implements the interworking between isolated users in the same VLAN. if the switch is qualified to serve as a proxy. it searches the ARP mappings table for the corresponding ARP entries.3 Configuring Static ARP Static ARP indicates that there is a fixed mapping between an IP address and a MAC address.3. If the conditions for being a proxy are met. l When you need to filter out some packets with illegitimate destination IP addresses. Instead. Ltd. the interface sends the MAC address of the switch to the sender of the ARP Request message. the interface sends the MAC address of the switch to the sender of the ARP Request message.IP Service 2 ARP Configuration In the scenario where two users belong to the same VLAN but user isolation is configured in the VLAN. to implement communication between the two users. you need to enable proxy ARP between VLANs on the member interfaces of the VLANs. The interface enabled with proxy ARP within a VLAN does not directly discard the ARP Request messages that are not for themselves.Quidway S5700 Series Ethernet Switches Configuration Guide . pre-configuration tasks. to implement communication between the two users. complete the following tasks: Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Static ARP needs to be configured by an administrator. data preparation. you need to enable proxy ARP with a VLAN on the member interface of the VLAN. 2. l Inter-VLAN proxy ARP In the scenario where two users belong to different VLANs.

----End 2.. you need to enable static ARP within the VLAN on the member interface of the VLAN. No. otherwise. incorrect host routes are generated and thus packets cannot be normally forwarded. to implement communications between the two users. you need the following data. the virtual IP address of the VRRP backup group configured on the VLANIF interface cannot be the IP address contained in the static ARP entries. 11 . Procedure Step 1 Run: system-view The system view is displayed. Context If static ARP and the Virtual Router Redundancy Protocol (VRRP) are enabled on a device simultaneously. NOTE Static ARP entries keep valid when a device works normally. Ltd.3.IP Service 2 ARP Configuration l Configuring physical parameters for the interface and ensuring that the status of the physical layer of the interface is Up l Configuring link layer protocol parameters for the interface and ensuring that the status of the link layer protocol on the interface is Up l Configuring the network layer protocol for the interface Data Preparation To configure ARP.2 Configuring Common Static ARP Entries Static ARP entries are required for the communication between common interfaces. Data 1 IP address and MAC address of the static ARP entry 2 VPN instance name and VLAN ID to which the static ARP entry belongs 2. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.3.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 2 Run: arp static ip-address mac-address Configure common static ARP entries.3 Configuring Static ARP Entries in a VLAN In the scenario where two users belong to the same VLAN but user isolation is configured in the VLAN.

the system forwards the packet from the specified outbound interface. Context If static ARP and the Virtual Router Redundancy Protocol (VRRP) are enabled on a device simultaneously. If the VLAN ID and outbound interface are specified. Step 2 Run: arp static ip-address mac-address vpn-instance vpn-instance-name Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.4 Configuring Static ARP Entries in a VPN Instance To implement Layer 2 interworking of the devices in a VPN instance. 12 . if an ARP entry contains only the IP address and MAC address. To configure static ARP entries in a VLAN. Step 2 Configure static ARP entries in a Virtual Local Area Network (VLAN)..IP Service 2 ARP Configuration Context If static ARP and the Virtual Router Redundancy Protocol (VRRP) are enabled on a device simultaneously. To configure static ARP entries for VLANIF interfaces. the system selects the outbound interface automatically. NOTE Static ARP entries keep valid when a device works normally. This command is applicable to port-based VLANs. Ltd. Procedure Step 1 Run: system-view The system view is displayed. incorrect host routes are generated and thus packets cannot be normally forwarded. and the VLAN ID and outbound interface of the ARP packet are not specified. the virtual IP address of the VRRP backup group configured on the VLANIF interface cannot be the IP address contained in the static ARP entries. incorrect host routes are generated and thus packets cannot be normally forwarded. you can configure static ARP in the VPN instance.3. do as follows: l Run the arp static ip-address mac-address [ vid vlan-id interface interface-type interfacenumber ] command. otherwise. If the interface corresponding to the VLAN is bound to a Virtual Private Network (VPN). ----End 2. Procedure Step 1 Run: system-view The system view is displayed. the virtual IP address of the VRRP backup group configured on the VLAN interface cannot be the IP address contained in the static ARP entries. the device can automatically associate the configured static ARP entry with the VPN.Quidway S5700 Series Ethernet Switches Configuration Guide . otherwise.

pre-configuration tasks.Quidway S5700 Series Ethernet Switches Configuration Guide . you need the following data.3. the system automatically resolutes an IP address into an Ethernet MAC address. You do not need to run a command to enable dynamic ARP but you can modify some parameters of dynamic ARP.IP Service 2 ARP Configuration Configure static ARP entries in a VPN instance. ----End 2. Procedure l Run the display arp vpn-instance vpn-instance-name [ dynamic | static ] command to check information about ARP mapping tables based on VPN instances.4 Optimizing Dynamic ARP If dynamic ARP is configured. NOTE Static ARP entries keep valid when a device works normally. Pre-configuration Tasks None Data Preparation Optimizing dynamic ARP.5 Checking the Configuration You can view the configuration of static ARP. 2.1 Establishing the Configuration Task This section describes the applicable environment. Issue 01 (2011-10-26) No. 13 . and configuration procedure for optimizing dynamic ARP.. Data 1 Aging detection times of the dynamic ARP entry 2 Aging time of the dynamic ARP entry Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. ----End 2. Applicable Environment Dynamic ARP is one of functions owned by a device or host. l Run the display arp statistics { all } command to check the statistics for ARP entries. Ltd.4. data preparation. Prerequisite The configurations of the ARP function are complete.

Step 3 Run: arp detect-times detect-times The number of aging detection times of the dynamic ARP entries is configured. To ensure the performance of the system. Ltd. Procedure Step 1 Run: system-view The system view is displayed. Step 4 Run: arp expire-time expire-times The timeout period for aging dynamic ARP entries is configured. the aging detection times of the dynamic ARP entries is three. and the aging timeout period is 1200 seconds.3 Enabling ARP Suppression Function If the system receives a great number of ARP packets from the same source at a time. and reduce the aging detection intervals of ARP entries. the system only responds to the ARP packets but does not update ARP entries.. In this manner.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 2 Run: arp-suppress enable Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.4. By default. you can enable ARP suppression. Procedure Step 1 Run: system-view The system view is displayed. the system needs to update ARP entries repeatedly. Step 5 Run: arp detect-mode unicast The interface is configured to send ARP Aging Detection packets in unicast mode.2 Modify the aging parameters of dynamic ARP If the device needs to update ARP entries frequently. increase the number of aging detections for ARP entries. By default. 14 . Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed.IP Service 2 ARP Configuration 2. an interface sends ARP Aging Detection packets in broadcast mode. ----End 2. you can reduce the aging timeout period of ARP entries.4.

----End 2. Prerequisite The configurations of the ARP function are complete. ----End 2. Ltd. l Run the display arp statistics { all } command to check the statistics for ARP entries. this function is not enabled.4.4. ----End 2. l Run the display arp vpn-instance vpn-instance-name [ dynamic | static ] command to check information about ARP mapping tables based on VPN instances. if this Layer 2 interface goes Up.IP Service 2 ARP Configuration ARP suppression is enabled on the current device. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. By default. 15 .5 Configuring Routed Proxy ARP Proxy ARP enables devices whose IP addresses belong to the same network segment but different physical networks to communicate with each other. Step 2 Run: l2-topology detect enable The Layer 2 topology detection function is enabled. Procedure l Run the display arp interface interface-type interface-number command to check information about ARP mapping tables based on interfaces. NOTE The S5706 does not support this function.Quidway S5700 Series Ethernet Switches Configuration Guide ..5 Checking the Configuration You can view the configuration of dynamic ARP. Procedure Step 1 Run: system-view The system view is displayed.4 Enabling Layer 2 Topology Detection Function After Layer 2 topology detection is enabled. the system updates all the ARP entries corresponding to the VLANs to which a Layer 2 interface belongs.

Routed proxy ARP can be enabled only on the VLANIF interface of the S5700. 16 . You need to enable the proxy ARP on the device interface connected to the physical networks. Pre-configuration Tasks Before configuring routed proxy ARP. Procedure Step 1 Run: system-view The system view is displayed.Quidway S5700 Series Ethernet Switches Configuration Guide .5. and are separated by a device. No. Data 1 Number of the interface to be enabled with routed proxy ARP 2 IP address of the interface to be enabled with routed proxy ARP 2. data preparation. and configuration procedure for configuring routed proxy ARP. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. You need not configure default gateways for hosts. Network IDs of subnet hosts must be the same.IP Service 2 ARP Configuration 2.5.. This enables communication between the two networks. pre-configuration tasks. you need the following data. Applicable Environment The two physical networks of an enterprise are in different subnets of the same IP network. complete the following tasks: l Configuring the physical parameters for the interface and ensuring that the status of the physical layer of the interface is Up l Configuring the link layer parameters for the interface and ensuring that the status of the link layer protocol on the interface is Up Data Preparation To configure routed proxy ARP. Step 3 Run: Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.2 Configure an IP Addresses for the Interface The IP address assigned to a routed proxy ARP-enabled interface must be on the same network segment with the IP address of the host on the LAN to which this interface connects.1 Establishing the Configuration Task This section describes the applicable environment. Ltd.

3 Enabling the Routed Proxy ARP Function To interconnect the subnets in the same IP network. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. ----End 2. Prerequisite The configurations of the routed proxy ARP function are complete. After routed proxy ARP is enabled. 17 . the routed proxy ARP function is disabled on the interface.6 Configuring Proxy ARP Within a VLAN By configuring proxy ARP on a VLAN. ----End 2. Ltd. you must reduce the aging time of ARP entries in the deviece so that the number of packets received but cannot be forwarded by the device is decreased.. l Run the display arp vpn-instance vpn-instance-name [ dynamic | static ] command to check information about ARP mapping tables based on VPN instances. l Run the display arp statistics command to check statistics about ARP entries. Procedure Step 1 Run: system-view The system view is displayed. Step 3 Run: arp-proxy enable By default. you need to enable routed proxy ARP.5. Procedure l Run the display arp interface interface-type interface-number command to check information about ARP mapping tables based on interfaces. The IP address configured for the interface must be in the same network segment with that of hosts in the LAN connected with this interface. To configure the aging time of ARP entries. you can interconnect isolated hosts on a VLAN. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.5.IP Service 2 ARP Configuration ip address ip-address { mask | mask-length } The interface is configured with an IP address.Quidway S5700 Series Ethernet Switches Configuration Guide . ----End 2.4 Checking the Configuration You can view the configuration of routed proxy ARP.

. No. you need the following data. Step 3 Run: Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Procedure Step 1 Run: system-view The system view is displayed. Ltd. you need to enable proxy ARP within the VLAN on the interface associated with the VLAN.6. Intra-VLAN proxy ARP can be enabled on only the VLANIF interface of the S5700.IP Service 2 ARP Configuration 2. and configuration procedure for configuring proxy ARP on a VLAN. complete the following tasks: l Configuring physical attributes for the interface and ensuring that the status of the physical layer of the interface is Up l Configuring the VLAN l Configuring user isolation in the VLAN Data Preparation To configure proxy ARP within a VLAN. 18 . data preparation. Applicable Environment If two users are in the same VLAN but they are isolated from each other.2 Configure an IP Addresses for the Interface The IP address assigned to an interface needs to be in the same network segment with the IP addresses of the users of the VLANs associated to this interface. Pre-configuration Tasks Before configuring proxy ARP within a VLAN. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. to ensure the two users can communicate.Quidway S5700 Series Ethernet Switches Configuration Guide .1 Establishing the Configuration Task This section describes the applicable environment. Data 1 Number of the interface to be enabled with proxy ARP in a VLAN 2 IP address of the interface to be enabled with proxy ARP in a VLAN 3 VLAN ID associated with the interface to be enabled with proxy ARP in a VLAN 2. pre-configuration tasks.6.

IP Service 2 ARP Configuration ip address ip-address { mask | mask-length } The interface is configured with an IP address.6. The IP address configured for the interface must be in the same network segment with that of hosts in the VLAN associated with this interface.6.. Ltd. l Run the display arp statistics command to check statistics about ARP entries.7 Configuring Proxy ARP Between VLANs By configuring inter-VLAN proxy ARP. l Run the display arp vpn-instance vpn-instance-name [ dynamic | static ] command to check information about ARP mapping tables based on VPN instances. Step 3 Run: arp-proxy inner-sub-vlan-proxy enable Proxy ARP within a VLAN is enabled. you can interconnect hosts on different VLANs. Procedure l Run the display arp interface interface-type interface-number command to check information about ARP mapping tables based on interfaces. Prerequisite The configurations of the proxy ARP within a VLAN function are complete. Procedure Step 1 Run: system-view The system view is displayed.Quidway S5700 Series Ethernet Switches Configuration Guide . Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. ----End 2. you need to enable intra-VLAN proxy ARP on the interface associated to the VLAN. ----End 2.4 Checking the Configuration You can view the configuration of intra-VLAN proxy ARP.3 Enabling Proxy ARP Within a VLAN To interconnect isolated users on a VLAN. ----End 2. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. 19 .

pre-configuration tasks. 20 . Data 1 Number of the interface to be enabled with proxy ARP between VLANs 2 IP address of the interface to be enabled with proxy ARP between VLANs 3 VLAN ID associated with the interface to be enabled with proxy ARP between VLANs 2. Step 3 Run: ip address ip-address { mask | mask-length } Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you need the following data.. Pre-configuration Tasks Before configuring proxy ARP between VLANs. data preparation.2 Configuring an IP Addresses for the Interface The IP address assigned to an interface needs to be in the same network segment with the IP addresses of the users of all the VLANs associated to this interface. Inter-VLAN proxy ARP can be enabled only on the VLANIF interface of the S5700.1 Establishing the Configuration Task This section describes the applicable environment. and configuration procedure for configuring inter-VLAN proxy ARP. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed.IP Service 2 ARP Configuration 2. you need to enable proxy ARP between VLANs on the sub-interface associated with the VLAN. Applicable Environment If two users belong to different VLANs and they need to communicate. complete the following tasks: l Configuring physical attributes for the interface and ensuring that the status of the physical layer of the interface is Up l Configuring VLAN aggregation Data Preparation To configure proxy ARP between VLANs. No.Quidway S5700 Series Ethernet Switches Configuration Guide .7. Ltd. Procedure Step 1 Run: system-view The system view is displayed.7. IP addresses of hosts in a VLAN must be in the same network segment.

21 . Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. The IP address configured for the interface must be in the same network segment with that of hosts in the VLAN associated with this interface. Procedure l Run the display arp interface interface-type interface-number command to check information about ARP mapping tables based on interfaces. Step 3 Run: arp-proxy inter-sub-vlan-proxy enable Proxy ARP between VLANs is enabled.Quidway S5700 Series Ethernet Switches Configuration Guide . Ltd. l Run the display arp statistics command to check statistics about ARP entries. you need to enable inter-VLAN proxy ARP on the VLANIF interfaces. Procedure Step 1 Run: system-view The system view is displayed.7. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Prerequisite The configurations of Proxy ARP Between VLANs are complete.4 Checking the Configuration You can view the configuration of inter-VLAN proxy ARP.IP Service 2 ARP Configuration The interface is configured with an IP address..7.8 Maintaining ARP The operations of ARP maintenance include clearing ARP statistics and monitoring ARP operating status. ----End 2.3 Enabling Proxy ARP Between VLANs To interconnect users on different VLANs. l Run the display arp vpn-instance vpn-instance-name [ dynamic | static ] command to check information about ARP mapping tables based on VPN instances. ----End 2. ----End 2.

8. Procedure l Run the display arp interface interface-type interface-number command in any view to check the information about the ARP mapping table based on interfaces. ----End 2. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1 Clearing ARP Entries This section describes ARP entries clearance through the reset command.IP Service 2 ARP Configuration 2.3 Debugging ARP This section describes ARP debugging through the debugging command.8.Quidway S5700 Series Ethernet Switches Configuration Guide ..8. l The static ARP entries cannot restore after you clear it. ----End 2.2 Monitoring Network Operation Status of ARP This section describes ARP operation monitoring through the display command. So. 22 . Context In routine maintenance. confirm the action before you use the command. confirm the action before you use the command. Procedure Step 1 Run the reset arp { all | dynamic | interface interface-type interface-number | static } command in the user view to clear the ARP entries in the ARP mapping table. Ltd. Context CAUTION l The mapping between the IP and MAC addresses is deleted after you clear ARP entries. So. you can run the following command in any view to check the operation of ARP. l Run the display arp vpn-instance vpn-instance-name [ dynamic | static ] command in any view to check the information about ARP mapping tables based on VPN instances.

For more information.2. run the following debugging command in the user view to debug ARP and locate the fault. Ltd. l To ensure the security of the server and prevent invalid ARP packets.1 Example for Configuring ARP Networking Requirements As shown in Figure 2-1. a static ARP entry should be created on GE 0/0/2 of the Switch.2. So. see chapter "Information Center Configuration" in the Quidway S5700 Series Ethernet Switches Configuration Guide-System Management. When faults occur during ARP operation. 23 . l Run the debugging arp-proxy [ inner-sub-vlan-proxy | inter-sub-vlan-proxy ] [ interface interface-type interface-number ] command in the user view to debug proxy ARP. l To adapt to fast changes of the network and ensure correct forwarding of packets.9 Configuration Examples This section provides several configuration examples of ARP. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 2.Quidway S5700 Series Ethernet Switches Configuration Guide . When the CPU usage is close to 100%. For descriptions about the debugging commands. and GE 0/0/2 should be added to VLAN 3.9. GE 0/0/2 is connected to the server through the router. with the IP address of the router being 10. Procedure l Run the debugging arp packet [ interface interface-type interface-number ] command in the user view to debug ARP. Thus. debugging ARP may cause the board resetting. GE 0/0/1 of the Switch is connected to the host through the LAN switch (LSW). dynamic ARP parameters should be set on VLANIF 2 of the Switch. see the Quidway S5700 Series Ethernet Switches Debugging Reference.IP Service 2 ARP Configuration Context CAUTION Debugging affects the performance of the system. l Run the debugging arp process [ interface interface-type interface-number ] command in the user view to debug the processing of ARP packets.. ----End 2. after debugging. It is required that: l GE 0/0/1 should be added to VLAN 2. run the undo debugging all command to disable debugging immediately. confirm the action before you use the command.3 and the MAC address being 00e0-fc01-0000.

you need the following data: l GE 0/0/1 added to VLAN 2 and GE 0/0/2 added to VLAN 3 l VLANIF 2 with the IP address being 2. 3.255.2. Create a VLAN and add an interface to the VLAN.255.2. Set dynamic ARP parameters on a VLANIF interface at the user side.2.0.2.3. subnet mask being 255.2 and subnet mask being 255.Quidway S5700 Series Ethernet Switches Configuration Guide . aging time of ARP entries being 60s.255.255.. Data Preparation To complete the configuration. and number of detection times being 2 l VLANIF 3 with the IP address being 10. Create a static ARP entry.IP Service 2 ARP Configuration Figure 2-1 Networking diagram for configuring ARP Server Internet Router GE0/0/2 Switch GE0/0/1 LSW PC1 PC2 PC2 Configuration Roadmap The configuration roadmap is as follows: 1.0 l Interface connecting the router and the Switch. # Create VLAN 2 and VLAN 3.2.255. and MAC address being 00e0-fc01-0000 Procedure Step 1 Create a VLAN and add an interface to the VLAN. 2. with the IP address being 10.2 and subnet mask being 255.2.255. 24 . Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd.0.

Ltd.2. [Quidway] interface vlanif 3 # Assign an IP address to VLANIF 3.255.2 255.2.255.255.3 00e0-fc01-0000 vid 3 interface gigabitethernet 0/0/2 [Quidway] quit Step 4 Verify the configuration.2 255. [Quidway] interface vlanif 2 # Assign an IP address to VLANIF 2. # Create a static ARP entry with IP address 10. [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] quit 0/0/1 hybrid tagged vlan 2 0/0/2 hybrid tagged vlan 3 Step 2 Set dynamic ARP parameters on a VLANIF interface. 25 .IP Service 2 ARP Configuration <Quidway> system-view [Quidway] vlan batch 2 3 # Add GE 0/0/1 to VLAN 2 and add GE 0/0/2 to VLAN 3. and the ARP mapping table. You can view the aging time of ARP entries. # Run the display current-configuration command. # sysname Quidway # vlan batch 2 to 3 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.2. and outgoing interface GE 0/0/2.. # Create VLANIF2. <Quidway> display current-configuration | include arp arp expire-time 60 arp detect-times 2 arp static 10. [Quidway-Vlanif2] arp expire-time 60 # Set the number of detection times before deleting ARP entries to 2.2. VLAN ID 3.2. the number of detection times before deleting ARP entries.3.3 00e0-fc01-0000 vid 3 interface GigabitEthernet0/0/2 ----End Configuration Files The following is the configuration file of the Switch. [Quidway] arp static 10.0 # Set the aging time of ARP entries to 60s.2.2.0 [Quidway-Vlanif3] quit Step 3 Create a static ARP entry. [Quidway-Vlanif2] arp detect-times 2 [Quidway-Vlanif2] quit # Create VLANIF 3. [Quidway-Vlanif2] ip address 2.Quidway S5700 Series Ethernet Switches Configuration Guide .255.2. [Quidway-Vlanif3] ip address 10.2. MAC address 00e0-fc01-0000.2.

255.2.2.16.16.2.2 255.9.2.16. It is required that routed proxy ARP should be enabled on the Switch so that hosts in the two LANs can communicate. Host A and Host B are not configured with the default gateway. Enable routed proxy ARP on the interface. and the network IDs of the two LANs are 172. 2.0 # interface GigabitEthernet0/0/1 port hybrid tagged vlan 2 # interface GigabitEthernet0/0/2 port hybrid tagged vlan 3 # arp static 10.2.1. Ltd.0.255. Figure 2-2 Networking diagram for configuring routed proxy ARP Host A 172.2 Example for Configuring Routed Proxy ARP Networking Requirements As shown in Figure 2-2.1/24 VLAN 2 VLAN 3 Switch Ethernet A Ethernet B Configuration Roadmap The configuration roadmap is as follows: 1.2. you need the following data: l Issue 01 (2011-10-26) IP addresses of the interfaces Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.. Assign an IP Address to an interface.255.2/16 0000-5e33-ee10 GE0/0/1 172.255.2 255.1. GE 0/0/1 and GE 0/0/2 of the Switch are connected to a LAN respectively.Quidway S5700 Series Ethernet Switches Configuration Guide . 26 .2.1/24 GE0/0/2 172.2/16 0000-5e33-ee20 Host B 172.0 arp expire-time 60 arp detect-times 2 # interface Vlanif3 ip address 10.3 00e0-fc01-0000 vid 3 interface GigabitEthernet0/0/2 # return 2.16.16.2.0/16.IP Service 2 ARP Configuration # interface Vlanif2 ip address 2. Data Preparation To complete the configuration.

0 Step 6 Enable routed proxy ARP on VLANIF 3.255.1.16. [Quidway-Vlanif2] arp-proxy enable [Quidway-Vlanif2] quit Step 4 Create VLAN 3 and add GE 0/0/2 to VLAN 3.2/16 to Host A. # Ping Host B from Host A. <Quidway> system-view [Quidway] vlan 2 [Quidway-vlan2] quit [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port link-type access [Quidway-GigabitEthernet0/0/1] port default vlan 2 [Quidway-GigabitEthernet0/0/1] quit Step 2 Create and configure VLANIF 2.16.0 arp-proxy enable # interface Vlanif3 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.16. # Assign IP address 172. [Quidway] vlan 3 [Quidway-vlan3] quit [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] port link-type access [Quidway-GigabitEthernet0/0/2] port default vlan 3 [Quidway-GigabitEthernet0/0/2] quit Step 5 Create and configure VLANIF 3. Step 8 Verify the configuration.255.Quidway S5700 Series Ethernet Switches Configuration Guide .1 255.1 255.1 255..0 Step 3 Enable routed proxy ARP on VLANIF 2.1.IP Service l 2 ARP Configuration IP addresses of the hosts Procedure Step 1 Create VLAN 2 and add GE 0/0/1 to VLAN 2.255.255.2.16. The ping operation is successful. Ltd. [Quidway] interface vlanif 3 [Quidway-Vlanif3] ip address 172.1.2/16 to Host B. # Assign IP address 172.16.255. 27 . ----End Configuration Files Configuration file of the Switch # sysname Quidway # vlan batch 2 to 3 # interface Vlanif2 ip address 172.255.2. [Quidway] interface vlanif 2 [Quidway-Vlanif2] ip address 172. [Quidway-Vlanif3] arp-proxy enable [Quidway-Vlanif3] quit Step 7 Configure the hosts.

Add an interface to the Sub-VLAN.0.255.Quidway S5700 Series Ethernet Switches Configuration Guide . 3. Figure 2-3 Networking diagram for configuring intra-VLAN proxy ARP Internet Switch GE0/0/2 GE0/0/1 hostB 10.255.1 and 255..2/24 00-e0-fc-00-00-02 sub-VLAN2 Configuration Roadmap The configuration roadmap is as follows: 1.10. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.255.2. Create and configure a Super-VLAN and a Sub-VLAN.10.16. Create a VLANIF interface of the Super-VLAN and assign an IP address to the VLANIF interface. Ltd.3/24 00-e0-fc-00-00-03 hostA 10.10. 2.10.9. l Host A should communicate with host B at Layer 3 through intra-VLAN proxy ARP. SubVLAN 2 belong to Super-VLAN 3. It is required that: l Host A and host B in VLAN 2 should be isolated at Layer 2.3 Example for Configuring Intra-VLAN Proxy ARP Networking Requirements As shown in Figure 2-3. 28 . GE 0/0/2 and GE 0/0/1 of the Switch belong to Sub-VLAN 2.0 arp-proxy enable # interface GigabitEthernet0/0/1 port link-type access port default vlan 2 # interface GigabitEthernet0/0/2 port link-type access port default vlan 3 # return 2.10.255.10.IP Service 2 ARP Configuration ip address 172. The IP address and subnet mask of the VLANIF interface in Super-VLAN 3 should be 10.1 255.

[Quidway-Vlanif3] ip address 10.IP Service 4. Ltd.1 and 255.10. [Quidway] interface vlanif 3 # Assign an IP address to VLANIF 3. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.255.10. [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] quit 0/0/1 link-type access default vlan 2 0/0/2 link-type access default vlan 2 # Configure Super-VLAN 3 and add Sub-VLAN 2 to Super-VLAN 3. Data Preparation To complete the configuration. <Quidway> system-view [Quidway] vlan 2 [Quidway-vlan2] quit # Enable port isolation on GE 0/0/1 and GE 0/0/2.. you need the following data: l VLAN IDs of the Super-VLAN and Sub-VLAN l GE 0/0/2 and GE 0/0/1 belonging to Sub-VLAN 2 l IP address and subnet mask of VLANIF 3 of Super-VLAN 3 being 10. 29 . # Create VLANIF 3.10. # Configure Sub-VLAN 2.0 Procedure Step 1 Configure the Super-VLAN and Sub-VLAN.255. 2 ARP Configuration Enable intra-VLAN proxy ARP on the VLANIF interface of the Super-VLAN.10.1 24 Step 3 Enable intra-VLAN proxy ARP on VLANIF 3.Quidway S5700 Series Ethernet Switches Configuration Guide . [Quidway] vlan 3 [Quidway-vlan3] aggregate-vlan [Quidway-vlan3] access-vlan 2 [Quidway-vlan3] quit Step 2 Create and configure VLANIF 3. [Quidway-Vlanif3] arp-proxy inner-sub-vlan-proxy enable [Quidway-Vlanif3] quit Step 4 Verify the configuration. [Quidway] port-isolate mode l2 [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port-isolate enable [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] port-isolate enable [Quidway-GigabitEthernet0/0/2] quit # Add GE 0/0/1 and GE 0/0/2 to Sub-VLAN 2.

255.. 30 .1 255.IP Service 2 ARP Configuration # Run the display current-configuration command.10.10. l Hosts in VLAN 2 and VLAN 3 should be pinged mutually after inter-VLAN proxy ARP is enabled.9.2 00e0-fc00-0002 19 D-0 GE0/0/1 2 10. # sysname Quidway # vlan batch 2 to 3 # vlan 3 aggregate-vlan access-vlan 2 # interface Vlanif3 ip address 10.10. You can view the configurations of the Super-VLAN. Sub-VLAN.3 00e0-fc00-0003 19 D-0 GE0/0/2 2 -----------------------------------------------------------------------------Total:3 Dynamic:2 Static:0 Interface:1 ----End Configuration Files The following lists the configuration file of the Switch. see the following configuration file. <Quidway> display arp IP ADDRESS MAC ADDRESS EXPIRE(M) TYPE INTERFACE VPN-INSTANCE VLAN -----------------------------------------------------------------------------10.1 0018-2000-0083 I Vlanif3 10.0 arp-proxy inner-sub-vlan-proxy enable # interface GigabitEthernet0/0/1 port link-type access port default vlan 2 port-isolate enable group 1 # interface GigabitEthernet0/0/2 port link-type access port default vlan 2 port-isolate enable group 1 # return 2.10.10.255.4 Example for Configuring Inter-VLAN Proxy ARP Networking Requirements As shown in Figure 2-4.10. For query results.10.10. and VLANIF interface. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. VLAN 2 and VLAN 3 constitute super-VLAN 4. It is required that: l Hosts in the sub-VLANs 2 and 3 should not be pinged mutually.Quidway S5700 Series Ethernet Switches Configuration Guide . Ltd. # Run the display arp command to view all the ARP entries.

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

2 ARP Configuration

Figure 2-4 Networking diagram for configuring inter-VLAN proxy ARP

Switch

VLAN2

VLAN3

VLAN4

VLAN2

VLAN3

Configuration Roadmap
The configuration roadmap is as follows:
1.

Configure a super-VLAN and a sub-VLAN.

2.

Add an interface to the sub-VLAN.

3.

Create an VLANIF interface of the super-VLAN and assign an IP address to the VLANIF
interface.

4.

Enable inter-VLAN proxy ARP.

Data Preparation
To complete the configuration, you need the following data:
l

VLAN IDs of the super-VLAN and sub-VLAN

l

GE 0/0/2 and GE 0/0/1 belonging to sub-VLAN 2

l

GE 0/0/3 and GE 0/0/4 belonging to sub-VLAN 3

l

IP address and subnet mask of VLANIF 4 in super-VLAN 4 being 10.10.10.1 and
255.255.255.0

Procedure
Step 1 Configure the super-VLAN and sub-VLAN.
# Configure sub-VLAN 2.
<Quidway> system-view
[Quidway] vlan 2
[Quidway-vlan2] quit

# Add GE 0/0/1 and GE 0/0/2 to sub-VLAN 2.
[Quidway] interface gigabitethernet 0/0/1
[Quidway-GigabitEthernet0/0/1] port link-type access
[Quidway-GigabitEthernet0/0/1] port default vlan 2

Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

31

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

2 ARP Configuration

[Quidway-GigabitEthernet0/0/1] quit
[Quidway] interface gigabitethernet 0/0/2
[Quidway-GigabitEthernet0/0/2] port link-type access
[Quidway-GigabitEthernet0/0/2] port default vlan 2
[Quidway-GigabitEthernet0/0/2] quit

# Configure sub-VLAN 3.
<Quidway> system-view
[Quidway] vlan 3
[Quidway-vlan3] quit

# Add GE0/0/3 and GE0/0/4 to sub-VLAN 3.
[Quidway] interface gigabitethernet
[Quidway-GigabitEthernet0/0/3] port
[Quidway-GigabitEthernet0/0/3] port
[Quidway-GigabitEthernet0/0/3] quit
[Quidway] interface gigabitethernet
[Quidway-GigabitEthernet0/0/4] port
[Quidway-GigabitEthernet0/0/4] port
[Quidway-GigabitEthernet0/0/4] quit

0/0/3
link-type access
default vlan 3
0/0/4
link-type access
default vlan 3

# Configure super-VLAN 4 and add sub-VLAN 2 to super-VLAN 4.
[Quidway] vlan 4
[Quidway-vlan4] aggregate-vlan
[Quidway-vlan4] access-vlan 2
[Quidway-vlan4] access-vlan 3
[Quidway-vlan4] quit

Step 2 Create and configure VLANIF 4.
# Create VLANIF 4.
[Quidway] interface vlanif 4

# Assign an IP address to VLANIF 4.
[Quidway-Vlanif4] ip address 10.10.10.1 24

Step 3 Enable inter-VLAN proxy ARP on VLANIF 4.
[Quidway-Vlanif4] arp-proxy inter-sub-vlan-proxy enable
[Quidway-Vlanif4] quit

Step 4 Verify the configuration.
# Run the display current-configuration command. You can view the configurations of the
super-VLAN, sub-VLAN, and VLANIF interface. For query results, see the following
configuration file.
# Run the display arp command to view all the ARP entries.
<Quidway> display arp
IP ADDRESS
MAC ADDRESS

EXPIRE(M) TYPE
INTERFACE
VPN-INSTANCE
VLAN
-----------------------------------------------------------------------------10.10.10.1
0018-2000-0083
I Vlanif4
10.10.10.2
00e0-fc00-0002 19
D-0
GE0/0/1
2
10.10.10.3
00e0-fc00-0003 19
D-0
GE0/0/2
2
10.10.10.4
00e0-fc00-0004 19
D-0
GE0/0/3
3
10.10.10.5
00e0-fc00-0005 19
D-0
GE0/0/4
3
-----------------------------------------------------------------------------Total:5
Dynamic:4
Static:0
Interface:1

----End
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

32

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

2 ARP Configuration

Configuration Files
The following lists the configuration file of the Switch.
#
sysname Quidway
#
vlan batch 2 to 4
#
vlan 4
aggregate-vlan
access-vlan 2 to 3
#
interface Vlanif4
ip address 10.10.10.1 255.255.255.0
arp-proxy inter-sub-vlan-proxy enable
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 2
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 2
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 3
#
interface GigabitEthernet0/0/4
port link-type access
port default vlan 3
#
return

2.9.5 Example for Configuring Layer 2 Topology Detection
Networking Requirements
As shown in Figure 2-5, two GE interfaces are added to VLAN 100 in default mode and the IP
addresses of the two GE interfaces are shown in the figure.
Figure 2-5 Networking diagram for configuring Layer 2 topology detection

Switch

VLANIF100
10.1.1.2/24

PC A
10.1.1.1/24

Issue 01 (2011-10-26)

VLAN100

PC B
10.1.1.3/24

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

33

You can find that the Switch has learnt the MAC address of the PC. <Quidway> system-view [Quidway] vlan 100 [Quidway-vlan100] quit [Quidway] interface vlanif 100 [Quidway-vlanif100] ip address 10.2 24 [Quidway-vlanif100] quit # Add the two GE interfaces to VLAN 100 in default mode.IP Service 2 ARP Configuration Configuration Roadmap The configuration roadmap is as follows: 1.1.1. 2.1. [Quidway] display arp all IP ADDRESS MAC ADDRESS INSTANCE EXPIRE(M) TYPE INTERFACE VPN- VLAN ----------------------------------------------------------------------------10.1..3 00e0-de24-bf04 20 D-0 GE0/0/2 ----------------------------------------------------------------------------Total:3 Dynamic:2 Static:0 Interface:1 # Run the shutdown command and then the undoshutdown command on GE 0/0/1 to view the aging time of ARP entries. Add two GE interfaces to VLAN 100 in default mode. [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] quit 0/0/1 link-type access default vlan 100 0/0/2 link-type access default vlan 100 Step 2 # Enable Layer 2 topology detection.1.1.1. Data Preparation To complete the configuration. Ltd. Enable Layer 2 topology detection and view changes of ARP entries.2 00e0-c01a-4900 I Vlanif100 10. [Quidway] l2-topology detect enable Step 3 Restart GE 0/0/1 and view changes of the ARP entries and aging time. 34 .1 00e0-c01a-4901 20 D-0 GE0/0/1 10.Quidway S5700 Series Ethernet Switches Configuration Guide . [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] shutdown [Quidway-GigabitEthernet0/0/1] undo shutdown [Quidway-GigabitEthernet0/0/1] display arp all Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you need the following data: l Types and numbers of the interfaces to be added to a VLAN l IP addresses of the VLANIF interface and the PCs Procedure Step 1 Create VLAN 100 and add the two GE interfaces of the Switch to VLAN 100 in default mode. # View ARP entries on the Switch.1. # Create VLANIF 100 and assign an IP addresses to VLANIF 100.

1. the aging time is restored to the default value. 35 .3 00e0-de24-bf04 0 D-0 GE0/0/2 -----------------------------------------------------------------------------Total:2 Dynamic:1 Static:0 Interface:1 NOTE According to the displayed information.1.1. ----End Configuration Files Configuration file of the Switch # sysname Quidway # L2-topolgy detect enable # vlan 100 # interface Vlanif100 ip address 10.2 00e0-c01a-4900 I Vlanif100 10.1.2 255.3 00e0-de24-bf04 20 D-0 GE0/0/2 ---------------------------------------------------------------------------Total:2 Dynamic:1 Static:0 Interface:1 NOTE After the ARP entry is updated.1.1.0 # interface GigabitEthernet0/0/1 port link-type access port default vlan 100 # interface GigabitEthernet0/0/2 port link-type access port default vlan 100 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.255.2 00e0-c01a-4900 I Vlanif100 10. [Quidway-GigabitEthernet0/0/1] display arp all IP ADDRESS MAC ADDRESS EXPIRE(M) TYPE INTERFACE VPN-INSTANCE VLAN ---------------------------------------------------------------------------10. the ARP entry learned from GE 0/0/1 is deleted after GE 0/0/1 is shut down. Ltd. The aging time of ARP entries learned from GE 0/0/2 becomes 0 after GE0/0/1 is restored and becomes Up again.IP Service IP ADDRESS 2 ARP Configuration MAC ADDRESS EXPIRE(M) TYPE INTERFACE VPN-INSTANCE VLAN ---------------------------------------------------------------------------10. the Switch sends an ARP probe packet for updating ARP entries. When the aging time is 0.1.1. 20 minutes.1..255.1.Quidway S5700 Series Ethernet Switches Configuration Guide .

3. configuration notes. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 3.3 Configuring the DHCP Server Based on the Global Address Pool A DHCP server can allocate IP addresses to clients by using the global address pool. 3. networking diagram.4 Configuring the DHCP Server Based on the VLANIF Interface Address Pool If a DHCP server based on a VLANIF interface address pool is configured. configuration roadmap.. the DHCP clients on a local area network (LAN) can communicate with the DHCP servers on other network segments. This reduces costs and achieves centralized device management.IP Service 3 DHCP Configuration 3 DHCP Configuration About This Chapter The DHCP technology is applicable to a variety of networks. The configuration examples involve various usage scenarios of DHCP.1 Introduction to DHCP Dynamic Host Configuration Protocol (DHCP) enables a client to dynamically obtain a valid IP address. 3. 3. Ltd. 3. and obtain IP addresses from them. and configuration procedure. The DHCP clients on different network segments can also use one DHCP server.6 Maintaining DHCP After DHCP configurations are complete. 3.7 Configuration Examples DHCP configuration examples explain the networking requirements.2 DHCP Features Supported by the S5700 The S5700 can be used as a DHCP server or a DHCP relay agent.Quidway S5700 Series Ethernet Switches Configuration Guide .5 Configuring the DHCP Relay Agent By using a DHCP relay agent. It ensures proper IP address allocation and saves IP addresses on networks. all the users going online through this interface obtain IP addresses from the VLANIF interface address pool. 36 . you can clear DHCP statistics and monitor DHCP operation.

and the number of hosts often exceeds the number of available IP addresses. the server replies with a packet carrying the corresponding configurations according to policies. DHCP server based on the interface address pool The DHCP clients and DHCP server are on the same network segment.. The DHCP is developed to solve the preceding problems.Quidway S5700 Series Ethernet Switches Configuration Guide . Table 3-1 DHCP usage scenarios Issue 01 (2011-10-26) Usage Scenario DHCP server based on the global address pool The DHCP clients and DHCP server are on the same network segment or on different network segments. and default gateway.2 DHCP Features Supported by the S5700 The S5700 can be used as a DHCP server or a DHCP relay agent.1 Introduction to DHCP Dynamic Host Configuration Protocol (DHCP) enables a client to dynamically obtain a valid IP address. each network segment needs a DHCP server. Ltd. so the network configurations become increasingly complicated. Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. subnet mask. Table 3-1 describes the DHCP usage scenarios where the S5700 is used. Definition DHCP server A DHCP server allocates IP addresses to clients. The DHCP protocol requires that the DHCP clients and DHCP server be in the same network segment. After receiving the packet. 37 . A client sends a packet to the server to request for configurations such as the IP address. A DHCP client requests the DHCP server for configurations. NOTE The S5706 does not support the DHCP server or DHCP relay function. 3. For example. Overview Network scales and complexity grow fast. Both the Request and Reply packets are encapsulated in UDP packets.IP Service 3 DHCP Configuration 3. This wastes resources. DHCP relay agent A DHCP relay agent transparently transmits DHCP broadcast packets between the DHCP clients and DHCP server that are on different network segments. DHCP relay achieves address allocation between network segments. the locations of hosts such as portable computers and wireless network terminals frequently change. and the DHCP server sends the configurations to the client. therefore. DHCP works in the client/server model.

The DHCP clients on different networks can use one DHCP server. After receiving a DHCP packet from a DHCP client. Using the S5700 as a DHCP Server The S5700 can function as a DHCP server to allocate IP addresses to clients. subnet mask.5 Configuring the DHCP Relay Agent. the S5700 functioning as a DHCP relay agent forwards the DHCP packet to a DHCP server. 38 . the S5700 uses the global address pool that contains the addresses in the interface address pool. A client sends a packet to the server to request for configurations such as the IP address. On this network. For details about configuring the DHCP relay agent.3 Configuring the DHCP Server Based on the Global Address Pool. Both the Request and Reply packets are encapsulated in UDP packets. see the Quidway S5700 Series Ethernet Switches Configuration Guide . the DHCP server can use the global address pool or the interface address pool.Security. see 3. Using the S5700 as a DHCP Relay Agent When functioning as a DHCP relay agent. see 3. Ltd.IP Service 3 DHCP Configuration Usage Scenario DHCP relay agent The DHCP clients and DHCP server are different network segments. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Application The S5700 functions as a DHCP server and is in the same network segment as the DHCP clients. l Using the global address pool: When an interface of the S5700 receives a DHCP packet from a DHCP client. and default gateway. If there is no available address in the interface address pool. the S5700 allocates an IP address to the client from the interface address pool. After receiving the packet. The DHCP relay agent saves costs and facilitates device management. For details about configuring the interface address pool. the S5700 allocates an IP address to the client from the global address pool.. and then the DHCP server allocates an IP address to the client. l Using an interface address pool: When an interface of the S5700 receives a DHCP packet from a DHCP client. the S5700 forwards the DHCP packets to the DHCP servers or clients on different network segments. see 3. the server replies with a packet carrying the corresponding configurations according to policies. The S5700 allocates IP addresses to clients by using the global address pool or an interface address pool. For details about DHCP snooping. NOTE The S5700 supports the DHCP snooping function.Quidway S5700 Series Ethernet Switches Configuration Guide . For details about configuring the global address pool.4 Configuring the DHCP Server Based on the VLANIF Interface Address Pool.

Figure 3-2 DHCP clients and DHCP server are on different network segments DHCP Server 100. the DHCP server can use only the global address pool.10.10.1/24 Internet SwitchA SwitchB DHCP Relay 20.20.Quidway S5700 Series Ethernet Switches Configuration Guide .20. On this network.3 Configuring the DHCP Server Based on the Global Address Pool A DHCP server can allocate IP addresses to clients by using the global address pool.10.10.10.10.. 39 . The DHCP server and DHCP clients are on different network segments.2/24 An S5700 functions as a DHCP server and another one functions as a DHCP relay agent.IP Service 3 DHCP Configuration Figure 3-1 DHCP clients and DHCP server are on the same network segment 100.10.3/24 100. Ltd.1/24 100.10. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1/24 DHCP Client DHCP Client DHCP Client 3.10.10.4/24 DHCP Server 100.

IP Service 3 DHCP Configuration 3. Ltd. 40 . the global address pool needs to be configured on the S5700 to allocate IP addresses to computers. complete the pre-configuration tasks. complete the following tasks: l Ensuring that the link between the DHCP clients and the S5700 works properly and the DHCP clients can communicate with the S5700 l (Optional) Configuring the DNS server l (Optional) Configuring the NetBIOS server l Configuring routes from the S5700 to the DNS server and the NetBIOS server (The routes are required only when the servers are configured. if the computers are connected to the DHCP server through another network..Quidway S5700 Series Ethernet Switches Configuration Guide . This helps you complete the configuration task quickly and accurately. it must work with the DHCP relay agent. familiarize yourself with the applicable environment.1 Establishing the Configuration Task Before configuring the DHCP server based on the global address pool. Applicable Environment On an enterprise network. Pre-configuration Tasks Before configuring the DHCP server based on the global address pool. Figure 3-3 Networking diagram for configuring the DHCP server based on the global address pool NetBIOS server DHCP client DHCP client DHCP client SwtichC SwtichB SwtichA DHCP server DNS server DHCP client DHCP client DHCP client When the S5700 functions as the DHCP server based on the global address pool.) l (Optional) Configuring the customized DHCP option Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. and obtain the required data.3. as shown in Figure 3-3.

and IP address and MAC address that need to be statically bound (optional) 2 Egress gateway of the DHCP clients 3 (Optional) IP address of the DNS server and domain name of the DHCP clients 4 (Optional) IP address of the NetBIOS server and NetBIOS node type of the DHCP clients 5 (Optional) Code of the customized DHCP option and corresponding ASCII character string. Ltd. IP address range. Step 3 Run: interface vlanif vlan-id The VLANIF interface view is displayed.Quidway S5700 Series Ethernet Switches Configuration Guide . hexadecimal numeral. or IP address 3. Context Perform the following steps on the DHCP server. Step 2 Run: dhcp enable The DHCP function is enabled. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co..2 Configuring an Interface to Use Global Address Pool When a DHCP server receives a DHCP packet from a client. the server can allocate an IP address to the client from the global address pool.3. Step 4 Run: ip address ip address { mask | mask-length} An IP address is allocated to the VLANIF interface. IP address lease. If there is no DHCP relay agent between the DHCP clients and S5700. the S5700 allocates IP addresses that are in the same network segment as the interface address to the clients connected to this interface. Procedure Step 1 Run: system-view The system view is displayed. IP addresses not to be allocated in the IP address pool (optional). 41 . Data 1 Address pool name.IP Service 3 DHCP Configuration Data Preparation Before configuring the DHCP server based on the global address pool. No. you need the following data.

Ltd. The number of address pools of each type is not limited. If the gateway address does not match an entry in the address pool. Step 5 Run: dhcp select global The DHCP function is enabled on the interface and the DHCP server allocates IP addresses to clients by using the global address pool.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 2 Run: ip pool ip-pool-name The global address pool view is displayed. Procedure Step 1 Run: system-view The system view is displayed. you must specify the range of addresses to be allocated. and must be within the network segment where the gateway is located. Perform the following steps on the DHCP server. IP addresses not to be automatically allocated. including the global address pools and interface address pools. 42 . Step 3 Run: network ip-address [ mask { mask | mask-length } ] The range of IP addresses in the address pool is set. only one address can be allocated to a client.IP Service 3 DHCP Configuration If the VLANIF interface is not configured with an IP address or no address pool is on the same network segment as the interface address. the clients cannot go online. Step 4 Run: lease { day day [ hour hour [ minute minute ] ] | unlimited } Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. By default. ----End 3.3 Configuring Address Allocation Mode for Global Address Pool According to the requirements of clients. to use the static binding mode.. but the two modes cannot be enabled simultaneously for the same IP address in the global address pool. the clients cannot go online. If there is a DHCP relay agent between the DHCP clients and S5700. the S5700 parses the gateway address in the received DHCP packets forwarded by the DHCP relay agent. An address pool can contain only one address segment.3. you can select the static binding mode or the dynamic allocation mode for the address pool. To use the dynamic allocation mode. Context Up to 128 address pools can be configured on the S5700. IP address lease. The address range of the address pool is set by the mask. no global address pool exists on the S5700. and IP addresses to be statically bound to MAC addresses. The global address pool attributes include the IP address range.

but the IP addresses in one address pool must be set with the same lease.4 (Optional) Configuring DNS for Global Address Pool Each client has a domain name. Context On the DHCP server. Ltd. When a client requires a fixed IP address. the IP address of the DNS server cannot be allocated to clients. During domain name resolution. Perform the following steps on the DHCP server. The gateway address cannot be a broadcast address of a subnet. the DHCP server also sends the domain names to the clients. you can configure multiple egress gateways. NOTE To load balance the traffic and improve the reliability of the network. Different address pools on a DHCP server can be set with different IP address leases. you can set multiple IP address ranges that cannot be automatically allocated in the DHCP address pool. the domain-name command specifies a domain name for each global address pool.Quidway S5700 Series Ethernet Switches Configuration Guide . You can run the excluded-ip-address command to configure the IP addresses that are not allocated in the DHCP address pool. An IP address pool can be configured with up to eight gateway addresses. When allocating IP addresses to clients.IP Service 3 DHCP Configuration The lease of IP addresses is set. To enable DHCP clients to communicate by using their domain names and prevent IP address conflicts. and then the system uses a complete domain name for resolution. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. By default. users only need to enter a part of the domain name. Step 6 (Optional) Run: static-bind ip-address ip-address mac-address mac-address An IP address in the address pool is bound to a MAC address.. Step 7 Run: gateway-list ip-address &<1-8> The egress gateway is configured for the global address pool. the IP address lease is one day. ----End 3. bind an idle IP address in the address pool to the MAC address of the client.3. Some IP addresses are reserved for other services. ensure that this egress gateway address is the same as the egress gateway address of the DHCP relay agent. for example. Step 5 (Optional) Run: excluded-ip-address start-ip-address [ end-ip-address ] The IP addresses that cannot be automatically allocated in the DHCP address pool are configured. the DHCP server needs to specify domain names for these clients when allocating IP addresses to them. If you run the excluded-ipaddress command multiple times. 43 . When configuring an egress gateway address for the address pool on a DHCP server.

the host names must be mapped to IP addresses. configure multiple DNS servers.Quidway S5700 Series Ethernet Switches Configuration Guide . l p-node: indicates a node in peer-to-peer mode.IP Service 3 DHCP Configuration Procedure Step 1 Run: system-view The system view is displayed. To load balance the traffic and improve the reliability of the network. This node obtains the mappings by communicating with the NetBIOS server. This node obtains the mappings in broadcast mode. the DNS server used by the DHCP client is also specified. ----End 3. When a DHCP client uses the NetBIOS protocol for communication. NetBIOS nodes are classified into the following types: l b-node: indicates a node in broadcast mode. The NetBIOS server translates host names to IP addresses for the clients. Ltd. Based on the modes of obtaining mapping. that is.5 (Optional) Configuring NetBIOS for Global Address Pool DHCP clients running on the Microsoft Windows operating system use the Network Basic Input Output System (NetBIOS) protocol for communication. Context Perform the following steps on the DHCP server.3. l m-node: indicates a node in mixed mode. On the DHCP server. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. If the DNS domain name is configured. l h-node: indicates a node in hybrid mode.. the p-type node with some broadcast features. NOTE NetBIOS: Network Basic Input Output System. Step 2 Run: ip pool ip-pool-name The IP address pool view is displayed. Each address pool can be configured with a maximum of eight DNS servers. 44 . that is. Step 4 Run: dns-list ip-address &<1-8> The IP address of the DNS server is configured for the DHCP client. Step 3 Run: domain-name domain-name The DNS domain name to be allocated to the DHCP client is configured. you can specify a DNS domain name for each address pool. a b-type node enabled with the end-to-end communication mechanism.

Quidway S5700 Series Ethernet Switches Configuration Guide . the NetBIOS node type is not specified for DHCP clients. By default.. Procedure Step 1 Run: system-view Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd. add them to the attribute list of the DHCP server manually. If no configuration command of these functions is run. the server returns a DHCP Reply packet containing the option field. the related options configured by using the option command take effect. Step 4 Run: netbios-type { b-node | h-node | m-node | p-node } The NetBIOS type is set for DHCP clients. NetBIOS service.IP Service 3 DHCP Configuration Procedure Step 1 Run: system-view The system view is displayed. such as the DNS service. These commands take precedence over the option command. and IP address lease. NOTE The option command configures basic functions. Step 2 Run: ip pool ip-pool-name The IP address pool view is displayed. Each IP address pool can be configured with up to eight NetBIOS server addresses. Step 3 Run: nbns-list ip-address &<1-8> The NetBIOS server address of the DHCP client is configured. Related commands: l DNS service: domain-name and dns-list l NetBIOS service: nbns-list and netbios-type l Lease: lease Perform the following steps on the DHCP server. Context When a DHCP client requests an IP address from the DHCP server. ----End 3. The system also provides commands to configure these functions separately. 45 .3.6 (Optional) Configuring the Customized DHCP Option for the Global Address Pool DHCP provides various options. To use these options.

the DHCP server can prevent repetitive IP address allocation. and the DHCP server allocates the IP address to a client.. For details on the DHCP options.Quidway S5700 Series Ethernet Switches Configuration Guide . 46 . the maximum number of ping packets to be sent by the S5700 is 2. Procedure Step 1 Run: system-view The system view is displayed. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Step 3 Run: option code [ sub-option sub-code ] { ascii ascii-string | hex hex-string &<1-10> | ip-address ip-address &<1-8> } The DHCP option is configured. By default.IP Service 3 DHCP Configuration The system view is displayed. Context Perform the following steps on the DHCP server. The DHCP server pings an IP address to be allocated. Step 2 Run: dhcp server ping packet number The maximum number of ping packets is set. After the option command is used.3. ----End 3.7 (Optional) Preventing Repetitive Allocation of an IP Address To prevent repetitive IP address allocation. If there is no response to the ping packet within a certain period. this IP address is not in use. Ltd. see RFC 2132. Step 3 Run: dhcp server ping timeout milliseconds The period in which the S5700 waits for the response is set. By default. the period in which the S5700 waits for the response is 500 ms. If there is still no response. Step 2 Run: ip pool ip-pool-name The IP address pool view is displayed. Before using this command. After the dhcp server ping command is executed. the DHCP server pings the IP address to be allocated before allocating it to a client. ensure that you know the functions of the option to be configured. the DHCP server continues to send ping packets to this IP address until the number of ping packets reaches the maximum value. the specified option is carried by the DHCP Reply packet returned by the DHCP server.

txt files in the flash.IP Service 3 DHCP Configuration 3.3. you can enable the function of saving DHCP data so that IP address information is saved to the storage device periodically. 47 . When a fault occurs. Procedure Step 1 Run: system-view The system view is displayed. Step 3 Run: dhcp server database write-delay interval The interval for saving DHCP data is set. the S5700 restores the DHCP data in the flash. the S5700 saves data every 7200 seconds by default and the latest data overwrites the previous data. Ltd. After the dhcp server database enable command is executed. The two files save the address lease information and address conflict information..Quidway S5700 Series Ethernet Switches Configuration Guide . When the S5700 functions as the DHCP server.9 Checking the Configuration This section describes how to verify the configurations of the DHCP server based on the global address pool. ----End 3. After the S5700 is configured to automatically save DHCP data. Step 2 Run: dhcp server database enable The S5700 automatically saves DHCP data to the flash memory.8 (Optional) Configuring Automatic Saving of DHCP Data You can configure the S5700 to save DHCP data to the storage device.txt and conflict. Step 4 Run: dhcp server database recover The DHCP data in the storage device is restored. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you can restore data from the storage device. Context Perform the following steps on the DHCP server. Prerequisite The configurations of the DHCP server based on the global address pool are complete. DHCP data is not automatically saved to flash. the system generates the lease. After the dhcp server database recover command is executed. By default.3.

Quidway S5700 Series Ethernet Switches Configuration Guide . l Run the display ip pool name ip-pool-name [ low-ip-address high-ip-address | all | expired | conflict | used ] command to view information about the global address pool.4 Configuring the DHCP Server Based on the VLANIF Interface Address Pool If a DHCP server based on a VLANIF interface address pool is configured.20. The similar information is displayed.10.10.255. ----End Example Run the display dhcp server statistics command. The similar information is displayed. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.10 Mask : 255.10.10.0 Vpn instance : --------------------------------------------------------------------------Start End Total Used Idle(Expired) Conflict Disable -------------------------------------------------------------------------10.10.255.10. Ltd.10.10.. 48 .20.6 NBNS-Server0 : 20. <Quidway> display dhcp server statistics Server Statistics: Client Request: Dhcp Discover: Dhcp Request: Dhcp Decline: Dhcp Release: Dhcp Inform: Server Reply: Dhcp Offer: Dhcp Ack: Dhcp Nak: Bad Messages: 6 1 4 0 1 0 4 1 3 0 0 Run the display ip pool name ip-pool-name command to view the IP address pool named huawei.10.1 10.5 DNS-Server1 : 10. <Quidway> display ip pool name huawei Pool-Name : huawei Pool-No : 2 Lease : 3 Days 0 Hours 0 Minutes Domain-name : DNS-Server0 : 10. all the users going online through this interface obtain IP addresses from the VLANIF interface address pool.5 Netbios-type : Position : Local Status : Unlocked Gateway-0 : 10.IP Service 3 DHCP Configuration Procedure l Run the display dhcp server statistics command to view the statistics about the DHCP server.254 253 0 253 0 0 -------------------------------------------------------------------------- 3.10.

the clients connected to the interface obtain IP addresses from the interface address pool even if a global address pool is configured. as shown in Figure 3-4.) Data Preparation Before configuring the DHCP server based on the VLANIF interface address pool.IP Service 3 DHCP Configuration 3. you need the following data. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1 Establishing the Configuration Task Before configuring the DHCP server based on the interface address pool. the interface address pool needs to be configured on the S5700 to allocate IP addresses for the clients. only VLANIF interfaces can be configured with address pools. familiarize yourself with the applicable environment. Ltd. complete the following tasks: l Ensuring that the link between the DHCP clients and the S5700 works properly and the DHCP clients can communicate with the S5700 l (Optional) Configuring the DNS server l (Optional) Configuring the NetBIOS server l Configuring routes from the S5700 to the DNS server and the NetBIOS server (The routes are required only when the servers are configured. complete the pre-configuration tasks. Applicable Environment If the DHCP clients and the DHCP server are on the same network segment. Pre-configuration Tasks Before configuring the DHCP server based on the VLANIF interface address pool.4. On an S5700. This helps you complete the configuration task quickly and accurately. If an address pool is configured on an interface. 49 .. and obtain the required data.Quidway S5700 Series Ethernet Switches Configuration Guide . Figure 3-4 Networking diagram for configuring the DHCP server based on the interface address pool Client Client DHCP Server Client The interface address pool takes precedence over the global address pool.

Context The interface address pool takes precedence over the global address pool. and IP address and MAC address that need to be statically bound (optional) 2 (Optional) Egress gateway of the DHCP clients 3 (Optional) IP address of the DNS server and domain name of the DHCP clients 4 (Optional) IP address of the NetBIOS server and NetBIOS node type of the DHCP clients 5 (Optional) Code of the customized DHCP option and corresponding ASCII character string.Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 3 DHCP Configuration No.2 Configuring Address Allocation Mode for Interface Address Pool According to the requirements of clients. but you cannot enable the two modes for the same DHCP address pool. Step 5 Run: dhcp select interface The S5700 is configured to use the interface address pool. Ltd.4. IP address range.. you can select the static binding mode or the dynamic allocation mode for the address pool. Data 1 Number of the VLANIF interface configured with an address pool. IP addresses not to be allocated in the IP address pool (optional). Step 3 Run: interface vlanif vlan-id The VLANIF interface view is displayed. Step 2 Run: dhcp enable The DHCP function is enabled. 50 . IP address lease. or IP address 3. hexadecimal numeral. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Procedure Step 1 Run: system-view The system view is displayed. Step 4 Run: ip address ip-address { mask | mask-length } An IP address is allocated to the VLANIF interface.

the IP address of the DNS server cannot be allocated to clients. and then the system uses a complete domain name for resolution. Procedure Step 1 Run: system-view The system view is displayed. the DHCP server also sends the domain names to the clients. the DHCP server needs to specify domain names for these clients when allocating IP addresses to them. and such an interface address pool takes effect only on this interface. By default.. Step 7 (Optional) Run: dhcp server excluded-ip-address start-ip-address [ end-ip-address ] The IP addresses that cannot be automatically allocated in the DHCP address pool are configured. Some IP addresses are reserved for other services.4. ----End 3. Step 6 Run: dhcp server lease { day day [ hour hour [ minute minute ] ] | unlimited } The lease of IP addresses is set. bind an idle IP address in the address pool to the MAC address of the client. During domain name resolution.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 8 (Optional) Run: dhcp server static-bind ip-address ip-address mac-address mac-address An IP address in the address pool is bound to a MAC address. for example. If you run the dhcp server excluded-ip-address command multiple times.3 (Optional) Configuring the DNS Service of the VLANIF Interface Address Pool Each client has a domain name. you can set multiple IP address ranges that cannot be automatically allocated in the DHCP address pool. Step 2 Run: interface vlanif vlan-id Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Perform the following steps on the DHCP server. Ltd. When allocating IP addresses to clients. the IP address lease is one day. 51 . To enable DHCP clients to communicate by using their domain names and prevent IP address conflicts. You can run the dhcp server excluded-ip-address command to exclude these IP addresses. When a client requires a fixed IP address. Context On the DHCP server. the dhcp server domain-name command specifies a domain name for each interface address pool.IP Service 3 DHCP Configuration The interface address pool is actually the network segment to which the interface belongs. users only need to enter a part of the domain name.

configure multiple DNS servers. Based on the modes of obtaining mapping. the p-type node with some broadcast features. Each address pool can be configured with a maximum of eight DNS servers.4 (Optional) Configuring the NetBIOS Service of the VLANIF Interface Address Pool DHCP clients running on the Microsoft Windows operating system use the Network Basic Input Output System (NetBIOS) protocol for communication.. Step 3 Run: dhcp server nbns-list ip-address &<1-8> The NetBIOS server address is configured for the DHCP client. l h-node: indicates a node in hybrid mode. l m-node: indicates a node in mixed mode.IP Service 3 DHCP Configuration The VLANIF interface view is displayed.Quidway S5700 Series Ethernet Switches Configuration Guide . The NetBIOS server translates host names to IP addresses for the clients. the host names must be mapped to IP addresses. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Context Perform the following steps on the DHCP server. Procedure Step 1 Run: system-view The system view is displayed. NetBIOS nodes are classified into the following types: l b-node: indicates a node in broadcast mode. Step 4 Run: dhcp server dns-list ip-address &<1-8> The DNS server address is configured for the DHCP client. ----End 3. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. This node obtains the mappings in broadcast mode. a b-type node enabled with the end-to-end communication mechanism. Step 3 Run: dhcp server domain-name domain-name The DNS domain name is configured for the DHCP client. When a DHCP client uses the NetBIOS protocol for communication. This node obtains the mappings by communicating with the NetBIOS server. Ltd. 52 . l p-node: indicates a node in peer-to-peer mode. that is. To load balance the traffic and improve the reliability of the network.4. that is.

53 . the NetBIOS node type is not specified for DHCP clients.Quidway S5700 Series Ethernet Switches Configuration Guide . NetBIOS service. see RFC 2132. The system also provides commands to configure these functions separately. and IP address lease.. add them to the attribute list of the DHCP server manually. the server returns a DHCP Reply packet containing the option field.4.5 (Optional) Configuring the Customized DHCP Option of the VLANIF Interface Address Pool DHCP provides various options. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. Related commands: l DNS service: dhcp server domain-name and dhcp server dns-list l NetBIOS service: dhcp server nbns-list and dhcp server netbios-type l Lease: dhcp server lease Perform the following steps on the DHCP server. Ltd. ----End 3. the specified option is carried by the DHCP Reply packet returned by the DHCP server. To use these options. These commands take precedence over the option command. Step 4 Run: dhcp server netbios-type { b-node | h-node | m-node | p-node } The NetBIOS type is set for DHCP clients. ensure that you know the functions of the option to be configured. Context When a DHCP client requests an IP address from the DHCP server.IP Service 3 DHCP Configuration Each IP address pool can be configured with up to eight NetBIOS server addresses. By default. After the dhcp server option command is run. Step 3 Run: dhcp server option code [ sub-option sub-code ] { ascii ascii-string | hex hexstring &<1-10> | ip-address ip-address &<1-8> } The DHCP option is configured. Procedure Step 1 Run: system-view The system view is displayed. NOTE The option command configures basic functions. such as the DNS service. Before using this command. For details on the DHCP options.

After the dhcp server ping command is executed. If there is still no response. If there is no response to the ping packet within a certain period. Procedure Step 1 Run: system-view The system view is displayed.. the period in which the S5700 waits for the response is 500 ms. Procedure Step 1 Run: system-view The system view is displayed. Ltd. the maximum number of ping packets to be sent by the S5700 is 2. you can restore data from the storage device. the DHCP server continues to send ping packets to this IP address until the number of ping packets reaches the maximum value. Step 3 Run: dhcp server ping timeout milliseconds The period in which the S5700 waits for the response is set. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.4. Step 2 Run: dhcp server ping packet number The maximum number of ping packets is set.IP Service 3 DHCP Configuration 3. By default. the DHCP server pings the IP address to be allocated before allocating it to a client. you can enable the function of saving DHCP data so that IP address information is saved to the storage device periodically. and the DHCP server allocates the IP address to a client. this IP address is not in use. ----End 3. 54 .7 (Optional) Configuring Automatic Saving of DHCP Data You can configure the S5700 to save DHCP data to the storage device.4. When the S5700 functions as the DHCP server. The DHCP server pings an IP address to be allocated. the DHCP server can prevent repetitive IP address allocation.Quidway S5700 Series Ethernet Switches Configuration Guide . When a fault occurs. By default. Context Perform the following steps on the DHCP server. Context Perform the following steps on the DHCP server.6 (Optional) Preventing Repetitive Allocation of an IP Address To prevent repetitive IP address allocation.

the S5700 saves data every 7200 seconds by default and the latest data overwrites the previous data. Prerequisite The configurations of the DHCP server based on the VLANIF interface address pool are complete.txt files in the flash. Step 4 Run: dhcp server database recover The DHCP data in the storage device is restored. ----End 3. DHCP data is not automatically saved to flash. The similar information is displayed. By default. After the dhcp server database enable command is executed. 55 .. After the dhcp server database recover command is executed. ----End Example Run the display dhcp server statistics command.8 Checking the Configuration This section describes how to view the configuration of the DHCP server based on the VLANIF interface address pool. The two files save the address lease information and address conflict information. After the S5700 is configured to automatically save DHCP data. the S5700 restores the DHCP data in the flash. Step 3 Run: dhcp server database write-delay interval The interval for saving DHCP data is set. l Run the display ip pool interface interface-name [ start-ip-address high-ip-address | all | expired | conflict | used ] command to view information about the interface address pool. the system generates the lease. Ltd.txt and conflict.Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 3 DHCP Configuration Step 2 Run: dhcp server database enable The S5700 automatically saves DHCP data to the flash memory. <Quidway> display dhcp server statistics Server Statistics: Client Request: Dhcp Discover: Dhcp Request: Dhcp Decline: Dhcp Release: Issue 01 (2011-10-26) 6 1 4 0 1 Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.4. Procedure l Run the display dhcp server statistics command to view the statistics about the DHCP server.

The similar information is displayed.254 253 0 253 0 0 0 ----------------------------------------------------------------------------- 3.10.0 VPN instance : -----------------------------------------------------------------------------Start End Total Used Idle(Expired) Conflict Disable ----------------------------------------------------------------------------192.5.168. 56 .5 Configuring the DHCP Relay Agent By using a DHCP relay agent. and obtain IP addresses from them. the DHCP server must use a global address pool.. <Quidway> display ip pool interface vlanif10 Pool-name : vlanif10 Pool-No : 2 Lease : 1 Days 0 Hours 0 Minutes Domain-name : DNS-server0 : NBNS-server0 : Netbios-type : Position : Interface Status : Unlocked Gateway-0 : 192. Applicable Environment If no DHCP server is configured on the local network. complete the pre-configuration tasks. and no address pool can be configured on the interface connected to the DHCP relay agent.168.255.10. familiarize yourself with the applicable environment. the DHCP clients on a local area network (LAN) can communicate with the DHCP servers on other network segments. This helps you complete the configuration task quickly and accurately. and obtain the required data.2 Mask : 255.1 192.IP Service Dhcp Inform: Server Reply: Dhcp Offer: Dhcp Ack: Dhcp Nak: Bad Messages: 3 DHCP Configuration 0 4 1 3 0 0 Run the display ip pool interface ip-pool-name command to view interface address pool on VLANIF 10.10. This reduces costs and achieves centralized device management.Quidway S5700 Series Ethernet Switches Configuration Guide . Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 3.1 Establishing the Configuration Task Before configuring the DHCP relay agent. Ltd.255. To ensure that the DHCP clients obtain IP addresses. The DHCP clients on different network segments can also use one DHCP server. the DHCP relay function can be enabled on an S5700 to forward DHCP Request packets to the DHCP servers on other networks.168.

Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.10..1/24 Internet SwitchA SwitchB DHCP Relay 20. Data 1 Name of the DHCP server group 2 IP addresses of the DHCP servers in a DHCP server group 3 Number and IP address of the interface enabled with the DHCP relay function 3.5. complete the following tasks: l Configuring the DHCP server l Configuring a route from the S5700 to the DHCP server Data Preparation To configure the DHCP relay agent.10. a DHCP relay agent can be configured to forward the DHCP packets of the client to a DHCP server. you need the following data.Quidway S5700 Series Ethernet Switches Configuration Guide .2 Configuring DHCP Relay on an Interface When the network where a DHCP client resides does not have a DHCP server. No. Ltd.20. 57 .20.IP Service 3 DHCP Configuration Figure 3-5 Network diagram of DHCP relay DHCP Server 100.1/24 DHCP Client DHCP Client DHCP Client Pre-configuration Tasks Before configuring the DHCP relay agent.

Step 2 Run: dhcp enable DHCP is enabled globally. l Run the dhcp relay server-ip ip-address command in the VLANIF interface view to configure the destination DHCP server address. The DHCP servers that share one DHCP relay agent can be added to a server group to facilitate server management. Ltd. and then the DHCP packet is discarded.Quidway S5700 Series Ethernet Switches Configuration Guide . NOTE When configuring an egress gateway address for the address pool on a DHCP server. The DHCP server group allocates IP addresses for the users connected to the DHCP relay agent.4 Binding an Interface to a DHCP Server Group. Step 4 Run: ip address ip-address { mask | mask-length } An IP address is allocated to the VLANIF interface. set the DHCP server address on the VLANIF interface in either of the following ways: l Configure a destination DHCP server group and bind the group to the interface.5. the S5700 forwards the DHCP Request packets from DHCP clients to the DHCP server. ----End Follow-up Procedure When functioning as a DHCP relay agent.. ensure that this egress gateway address is the same as the egress gateway address of the DHCP relay agent. 58 . Step 5 Run: dhcp select relay The DHCP relay function is enabled for the VLANIF interface.3 Configuring a Destination DHCP Server Group and 3. 3. a DHCP relay agent serves multiple DHCP servers. After the DHCP relay function is enabled on the VLANIF interface.3 Configuring a Destination DHCP Server Group Generally.5.5. Procedure Step 1 Run: system-view The system view is displayed. Step 3 Run: interface vlanif vlan-id The VLANIF interface view is displayed. see 3. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. For details.IP Service 3 DHCP Configuration Context NOTE A DHCP packet is forwarded between a DHCP client and a DHCP server at most 16 times.

Procedure Step 1 Run: system-view The system view is displayed. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd. 59 .IP Service 3 DHCP Configuration Context Perform the following steps on the DHCP relay agent.4 Binding an Interface to a DHCP Server Group Multiple VLANIF interfaces can be bound to a DHCP server group. A maximum of 32 DHCP server groups can be configured globally. ----End 3. Procedure Step 1 Run: system-view The system view is displayed. a VLANIF interface can belong to only one DHCP server group.. That is. Step 3 Run: dhcp-server ip-address [ ip-address-index ] A DHCP server is added to the DHCP server group. the system allocates an idle index to the server. Context Perform the following steps on the DHCP relay agent. NOTE The S5706 and S5700SI do not support this command. Step 2 Run: dhcp server group group-name A DHCP server group is created and the DHCP server group view is displayed.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. Step 4 (Optional) Run: vpn-instance vpn-instance-name A VPN instance is bound to the DHCP server group. the DHCP Request packets on a VLANIF interface can be relayed to only one DHCP server group. Up to 20 DHCP servers can be added to a DHCP server group. however.5. If you do not specify the server index.

Procedure Step 1 Run: system-view The system view is displayed. the DHCP server renews the IP address for the user if it does not receive the DHCP Release packet. You can also run dhcp relay server-ip command to specify a server for the VLANIF interface.5 (Optional) Configuring the DHCP Relay Agent to Send DHCP Release Packet If a user is forcibly disconnected.. Step 2 (Optional) Run: interface vlanif vlan-id The VLANIF interface view is displayed. the DHCP relay agent will send DHCP Release packets to all the servers in the DHCP server group bound to this VLANIF interface. Context When the IP address of a user expires. the DHCP relay agent will send DHCP Release packets to the servers in all DHCP server groups bound to the DHCP relay interfaces. l When you use the dhcp relay release client-ip-address mac-address [ server-ip-address ] command in the system view: – If no DHCP server is specified. – If a DHCP server is specified. l When you use the dhcp relay release client-ip-address mac-address [ server-ip-address ] command in the VLANIF interface view: – If no DHCP server is specified. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. You can configure the DHCP relay agent to actively send DHCP Release packets to the DHCP server. Step 3 Run: dhcp relay release client-ip-address mac-address [ server-ip-address ] The DHCP relay agent is configured to send DHCP Release packets to the DHCP server.Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 3 DHCP Configuration Step 3 Run: dhcp relay server-select group-name The VLANIF interface is bound to a DHCP server group. the DHCP relay agent will send DHCP Release packets to the specified DHCP server. Ltd.5. Perform the following steps on the DHCP relay agent. ----End 3. 60 . – If a DHCP server is specified. the DHCP relay agent will send DHCP Release packets to the specified DHCP server. the IP address of the user needs to be released manually on the DHCP server. The DHCP server then releases the expired IP addresses.

10.1 (1) Server-IP : 100. If the similar information is displayed.2. l Run the display dhcp relay statistics command to view packet statistics on the DHCP relay agent.10. the configuration succeeds..2. Prerequisite The DHCP relay configurations are complete.5. ----End Example Run the display dhcp relay interface interface-type interface-number command to view the DHCP server group on VLANIF 100 and the servers in the DHCP server group.IP Service 3 DHCP Configuration 3. l Run the display dhcp server group group-name command to view the DHCP server group configuration.2.2 Gateway : -VPN instance : -- Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.10.2 Run the display dhcp relay statistics command. If the similar information is displayed. Procedure l Run the display dhcp relay { all | interface interface-type interface-number } command to view the DHCP server group on a VLANIF interface and the servers in the DHCP server group. If the similar information is displayed.3 Gateway address in use : 10. you can use commands to view the configuration result. <Quidway> display dhcp relay interface vlanif 100 DHCP relay agent running information of interface Vlanif100 : Server IP address [01] : 10. <Quidway> display dhcp relay statistics The statistics of DHCP RELAY: DHCP packets received from clients DHCP DISCOVER packets received DHCP REQUEST packets received DHCP RELEASE packets received DHCP INFORM packets received DHCP DECLINE packets received DHCP packets sent to clients Unicast packets sent to clients Broadcast packets sent to clients DHCP packets received from servers DHCP OFFER packets received DHCP ACK packets received DHCP NAK packets received DHCP packets sent to servers DHCP Bad packets received : : : : : : : : : : : : : : : 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 Run the display dhcp server group group-name command to view the configuration of DHCP server group group1.6 Checking the Configuration After the DHCP relay function is configured.10.2. <Quidway> display dhcp server group group1 Group-name : group1 (0) Server-IP : 100. 61 . Ltd. the configuration succeeds.Quidway S5700 Series Ethernet Switches Configuration Guide . the configuration succeeds.

and configuration procedure. networking diagram. l Run the display dhcp relay statistics command to view packet statistics on the DHCP relay agent.7 Configuration Examples DHCP configuration examples explain the networking requirements. l To clear DHCP relay agent statistics. l Run the display dhcp server group [ group-name ] command to view the servers in the DHCP server group.6. you can clear DHCP statistics and monitor DHCP operation. Procedure l Run the display dhcp relay { all | interface interface-type interface-number } command to view the DHCP server group on a VLANIF interface and the servers in the DHCP server group. run the reset dhcp server statistics command in the user view. you can use the reset commands to clear the statistics about the specified DHCP server group.IP Service 3 DHCP Configuration 3. ----End 3. Ltd. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. configuration notes. 62 . Procedure l To clear DHCP server statistics. ----End 3. 3.2 Monitoring DHCP Operation During routine maintenance. Exercise caution when running the reset commands.Quidway S5700 Series Ethernet Switches Configuration Guide . configuration roadmap.6. Context CAUTION DHCP statistics cannot be restored after they are cleared. run the reset dhcp relay statistics command in the user view..1 Clearing DHCP Statistics During routine maintenance. you can use the following commands in any view to monitor DHCP operation status. The configuration examples involve various usage scenarios of DHCP.6 Maintaining DHCP After DHCP configurations are complete.

126. Figure 3-6 Networking diagram for configuring the DHCP server based on the global address pool NetBIOS server DHCP client DHCP client GE 0/0/1 VLANIF10 10.1.1.1.1.0/25 Issue 01 (2011-10-26) DHCP client DHCP client Network: 10.1. Address pool 10.1.128/25 Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1.1.1.1.129/25 SwtichC SwtichB SwtichA DHCP server DNS server DHCP client Network: 10. As shown in Figure 3-6.128/25 is 2 days.1/25 and 10. SwitchA functions as the DHCP server. Networking Requirements An enterprise has two offices that are in the same network segment.0/24 consists of two network segments: 10.1.Quidway S5700 Series Ethernet Switches Configuration Guide . no NetBIOS address is set.1. There are many computers in network segment 10.1/25 DHCP client GE 0/0/2 VLANIF20 10.128/25 and the computers are often moved from one place to another.1.1.1.0/25 is 10 days. the NetBIOS address is 10. This section describes how to configure a global address pool.0/25 and the computer locations are fixed. the DNS address is 10. A global address pool or an interface address pool can be configured on SwitchA.7.1.1.1.1.1.0/25 and 10. There are a few computers in network segment 10.4.1.1. and the IP address of the egress gateway is 10.1.IP Service 3 DHCP Configuration 3.1.1.1.128/25. the DNS address is 10.254.1. 63 . The lease of an IP address in 10.1. To reduce network construction cost.1. Ltd.1. and SwitchB and SwitchC are user access switches. The lease of an IP address in 10.1.2. The IP addresses of the VLANIF interfaces on the DHCP server are 10.1.1 Example for Configuring a DHCP Server Based on the Global Address Pool This section describes how to configure a global address pool to allocate IP addresses for clients when the clients and DHCP server are in the same network segment.129/25.1..1. the enterprise uses one DHCP server to allocate IP addresses for the computers in the two offices.1.2. and the IP address of the egress gateway is 10.1.

128 dns-list 10. Ltd.2 gateway-list 10. egress gateway.1.1.255.1. including the address pool range.IP Service 3 DHCP Configuration Configuration Roadmap The configuration roadmap is as follows: 1. [Quidway] vlan batch 10 20 [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] quit Issue 01 (2011-10-26) 0/0/1 hybrid pvid vlan 10 hybrid untagged vlan 10 0/0/2 hybrid pvid vlan 20 hybrid untagged vlan 20 Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1. # Add GE 0/0/1 to VLAN 10 and GE 0/0/2 to VLAN 20. DNS address.1.255.Quidway S5700 Series Ethernet Switches Configuration Guide .1.1.128 dns-list 10.1.1. Enable the DHCP server function on SwitchA. egress gateway address.1.4 gateway-list 10. Procedure Step 1 Enable DHCP.128 mask 255. # Set the attributes of IP address pool 1. and address lease.254 lease day 2 quit Step 3 Set the address allocation mode on the VLANIF interfaces. including the address pool range. Create a global address pool on SwitchA and set the attributes of the address pool.255.2 nbns-list 10.1.1.1.126 excluded-ip-address 10. Data Preparation To complete the configuration.255. 2. DNS address. 64 . Configure VLANIF interfaces to use the global address pool to allocate IP addresses.1. [Quidway] ip pool 2 [Quidway-ip-pool-2] [Quidway-ip-pool-2] [Quidway-ip-pool-2] [Quidway-ip-pool-2] [Quidway-ip-pool-2] [Quidway-ip-pool-2] network 10. and address lease.4 lease day 10 quit # Set the attributes of IP address pool 2.1. 3.2 excluded-ip-address 10. [Quidway] ip pool 1 [Quidway-ip-pool-1] [Quidway-ip-pool-1] [Quidway-ip-pool-1] [Quidway-ip-pool-1] [Quidway-ip-pool-1] [Quidway-ip-pool-1] [Quidway-ip-pool-1] network 10.. NetBIOS address. including the range of the address pool.1.1. <Quidway> system-view [Quidway] dhcp enable Step 2 Create address pools and set the attributes of the address pools.0 mask 255. NetBIOS address.1. and address lease. egress gateway address. you need the following data: Number and range of the global address pool on SwitchA NOTE The following configurations are performed on SwitchA.

255.1. and you can view the configuration of the IP address pool.1.1 255. 65 .126 Mask : 255.255.1.126 network 10.128 [Quidway-Vlanif10] dhcp select global [Quidway-Vlanif10] quit # Configure the clients on VLANIF 20 to obtain IP addresses from the global address pool.2 lease day 10 hour 0 minute 0 # ip pool 2 gateway-list 10.255.128 excluded-ip-address 10.129 255.IP Service 3 DHCP Configuration # Configure the clients on VLANIF 10 to obtain IP addresses from the global address pool.1.1.Quidway S5700 Series Ethernet Switches Configuration Guide .128 [Quidway-Vlanif20] dhcp select global [Quidway-Vlanif20] quit Step 4 Verify the configuration.1.1.255. [Quidway] display ip pool ----------------------------------------------------------------------Pool-name : 2 Pool-No : 0 Position : Local Status : Unlocked Gateway-0 : 10.128 VPN instance : -IP address Statistic Total :250 Used :0 Expired :0 Idle Conflict :248 :0 Disable :2 ----End Configuration Files Configuration file of the SwitchA # sysname Quidway # vlan batch 10 20 # dhcp enable # ip pool 1 ip pool 2 # ip pool 1 gateway-list 10.2 excluded-ip-address 10..255.1.254 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1. [Quidway] interface vlanif 20 [Quidway-Vlanif20] ip address 10.255.255.0 mask 255. [Quidway] interface vlanif 10 [Quidway-Vlanif10] ip address 10.1.1.255.255.1.1.4 dns-list 10.1. Run the display ip pool command on the S5700.1.1.255.1. Ltd.128 VPN instance : -----------------------------------------------------------------------Pool-name : 1 Pool-No : 2 Position : Local Status : Unlocked Gateway-0 : 10.1.254 Mask : 255.1.1.

1..1.1. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd.255. SwitchA functions as the DHCP server. The DHCP server is connected to the access switches of the two equipment rooms.128 dns-list 10. which are in different network segments.1.1.4 lease day 5 hour 0 minute 0 # interface Vlanif10 ip address 10.255.128 dhcp select global # interface Vlanif20 ip address 10.255. 66 .129 255. and allocates IP addresses for the computers by using two interface address pools.1. and SwitchB and SwitchC are the access switches.1 255.255.1.255.7. A switch needs to be configured as a DHCP server to allocate IP addresses for the computers in the two equipment rooms.1.1.Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 3 DHCP Configuration network 10.2 Example for Configuring the DHCP Server Based on the Interface Address Pool A DHCP server can allocate IP addresses for the clients in the same network segment by using an interface address pool. The two VLANIF interface address pools need to be configured on GE 0/0/1 and GE 0/0/2 of SwitchA.128 mask 255.1.255.128 dhcp select global # interface GigabitEthernet0/0/1 port hybrid pvid vlan 10 port hybrid untagged vlan 10 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 20 port hybrid untagged vlan 20 # return 3.2 nbns-list 10. Networking Requirements A campus has two equipment rooms. As shown in Figure 3-7.

1.2. Enable the VLANIF interface address pools.1/24 SwitchC DHCP Client DHCP Client SwitchA DHCP Server DHCP Client Configuration Roadmap The configuration roadmap is as follows: 1.3/24 DHCP Client DNS Server 10. 4.1.IP Service 3 DHCP Configuration Figure 3-7 Networking diagram for configuring a DHCP server based on a VLANIF interface address pool NetBIOS Server 10. Ltd.1. NetBIOS server address.Quidway S5700 Series Ethernet Switches Configuration Guide . Set the address pool attributes. 3.2/24 VLANIF10 10.1.1. <Quidway> system-view [Quidway] dhcp enable Step 2 Add interfaces to VLANs. and IP address lease. Create VLANIF interfaces and allocate IP addresses to VLANIF interfaces to determine the range of address pools. Data Preparation To complete the configuration. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1/24 GE0/0/1 SwitchB GE0/0/2 VLANIF11 10.1. including the DNS server address. # Add GE 0/0/1 to VLAN 10.. Configure SwitchA as a DHCP server. 2.1. 67 . you need the following data: l IP addresses of the interfaces l DNS server address and NetBIOS server address l Address lease in the address pool Procedure Step 1 Enable DHCP.

com dns-list 10. # Configure the clients on VLANIF 10 to obtain IP addresses from the interface address pool. [Quidway] interface vlanif 10 [Quidway-Vlanif10] dhcp select interface [Quidway-Vlanif10] quit # Configure the clients on VLANIF 11 to obtain IP addresses from the interface address pool.1 24 [Quidway-Vlanif10] quit # Allocate an IP address to VLANIF 11.1 24 [Quidway-Vlanif11] quit Step 4 Enable the VLANIF interface address pool.1.3 netbios-type b-node Step 6 Set IP address leases of IP address pools. 68 .1. [Quidway] interface vlanif 10 [Quidway-Vlanif10] ip address 10. [Quidway] interface vlanif 10 [Quidway-Vlanif10] dhcp server lease day 30 [Quidway-Vlanif10] quit # Set the IP address lease of VLANIF 11 address pool to 20 days. [Quidway] interface vlanif 11 [Quidway-Vlanif11] dhcp server lease day 20 [Quidway-Vlanif11] quit Step 7 Verify the configuration.2 nbns-list 10.1..Quidway S5700 Series Ethernet Switches Configuration Guide .1.IP Service 3 DHCP Configuration [Quidway] vlan batch 10 to 11 [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port hybrid pvid vlan 10 [Quidway-GigabitEthernet0/0/1] port hybrid untagged vlan 10 [Quidway-GigabitEthernet0/0/1] quit # Add GE 0/0/2 to VLAN 11. [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] port hybrid pvid vlan 11 [Quidway-GigabitEthernet0/0/2] port hybrid untagged vlan 11 [Quidway-GigabitEthernet0/0/2] quit Step 3 Allocate IP addresses to VLANIF interfaces. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. # Set the IP address lease of VLANIF 10 address pool to 30 days.1.1.3 excluded-ip-address 10. [Quidway] interface vlanif 10 [Quidway-Vlanif10] dhcp server [Quidway-Vlanif10] dhcp server [Quidway-Vlanif10] dhcp server [Quidway-Vlanif10] dhcp server [Quidway-Vlanif10] dhcp server [Quidway-Vlanif10] dhcp server domain-name huawei.2.1.1. # Configure the DNS service and NetBIOS service of VLANIF 10 address pool. Ltd.2 excluded-ip-address 10. [Quidway] interface vlanif 11 [Quidway-Vlanif11] dhcp select interface [Quidway-Vlanif11] quit Step 5 Configure the DNS service and NetBIOS services of the address pool. [Quidway] interface vlanif 11 [Quidway-Vlanif11] ip address 10. # Allocate an IP address to VLANIF 10.1.1.1.

1.1 10.1.1.255.1.2 10.0 VPN instance : -----------------------------------------------------------------------------Start End Total Used Idle(Expired) Conflict Disable ----------------------------------------------------------------------------10.1.1.1.0 dhcp select interface dhcp server lease day 20 hour 0 minute 0 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 10 port hybrid untagged vlan 10 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.255.255.2.3 Netbios-type : b-node Position : Interface Status : Unlocked Gateway-0 : 10. 69 .255.Quidway S5700 Series Ethernet Switches Configuration Guide .2.1.2.255.1. Ltd.1.254 253 0 251 0 0 2 ----------------------------------------------------------------------------[Quidway] display ip pool interface vlanif11 Pool-Name : vlanif11 Pool-No : 1 Lease : 20 Days 0 Hours 0 Minutes Domain-name : DNS-Server0 : NBNS-Server0 : Netbios-type : Position : Interface Status : Unlocked Gateway-0 : 10.0 dhcp select interface dhcp server excluded-ip-address 10.1.1 Mask : 255.255. [Quidway] display ip pool interface vlanif10 Pool-Name : vlanif10 Pool-No : 0 Lease : 30 Days 0 Hours 0 Minutes Domain-name : huawei.3 dhcp server lease day 30 hour 0 minute 0 dhcp server domain-name huawei.1.3 dhcp server dns-list 10.1 10.1.1.1 Mask : 255.2 dhcp server netbios-type b-node dhcp server nbns-list 10.1.1.1.1.255.2 NBNS-Server0 : 10.2..1.com DNS-Server0 : 10.254 253 0 253 0 0 0 ----------------------------------------------------------------------------- ----End Configuration Files Configuration file of SwitchA # sysname Quidway # vlan batch 10 to 11 # dhcp enable # interface Vlanif10 ip address 10.1.1.1 255.0 VPN instance : -----------------------------------------------------------------------------Start End Total Used Idle(Expired) Conflict Disable ----------------------------------------------------------------------------10.1.1.1 255.255.com # interface Vlanif11 ip address 10.IP Service 3 DHCP Configuration Run the display ip pool interface command on SwitchA to view the configuration of the interface address pool.1.

which are distributed in different office buildings. As shown in Figure 3-8. Figure 3-8 DHCP relay agent networking diagram SwitchB GE0/0/1 DHCP Server Internet VLANIF20 100.20.7.20.20. and the buildings belong to different LANs.10.. and an interface-based address pool cannot allocate IP addresses to the clients in different network segments.3 Example for Configuring a DHCP Relay Agent When the DHCP server and DHCP clients are in different network segments.20.1/24 SwitchA DHCP Relay GE0/0/1 DHCP Client VLANIF100 20.10. the DHCP clients can obtain IP addresses from the DHCP server. By using the DHCP relay agent.Quidway S5700 Series Ethernet Switches Configuration Guide . 70 .1/24 DHCP Client DHCP Client VLAN100 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.10.20.0/24 and the DHCP server is in the network segment 100. Networking Requirements An enterprise has multiple offices. a DHCP relay agent is required. A global address pool in the network segment 20. The DHCP server and the clients are in different network segments. The offices in a building belong to the same local area network (LAN). the DHCP clients are in the network segment 20.10.0/24.IP Service 3 DHCP Configuration # interface GigabitEthernet0/0/2 port hybrid pvid vlan 11 port hybrid untagged vlan 11 # return 3.20.0/24 is required. The enterprise uses a DHCP server to allocate IP addresses to all clients.20.20. A Switch enabled with DHCP relay is required between the clients and server. Ltd.0/24. and the DHCP server must have a reachable route to the network segment 20.

Configure the clients connected to GE 0/0/1 of the server to obtain IP addresses from the global address pool. [Quidway] vlan 100 [Quidway-Vlan100] quit [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port link-type trunk [Quidway-GigabitEthernet0/0/1] port trunk allow-pass vlan 100 [Quidway-GigabitEthernet0/0/1] quit # Enable DHCP globally. The configuration roadmap is as follows: 1. 71 . Configure a reachable route from the DHCP server to GE 0/0/1 of the DHCP relay agent. and then enable DHCP Relay on the VLANIF 100 interface. The configuration roadmap is as follows: 1. <Quidway> system-view [Quidway] dhcp server group dhcpgroup1 # Add DHCP servers to the DHCP server group.. 3. Configure SwitchB as the DHCP server. Ltd. Data Preparation To complete the configuration. you need the following data: l Name of the DHCP server group l IP address of the DHCP server in the DHCP server group l Number and IP address of the interface enabled with DHCP relay Procedure Step 1 Create a DHCP server group and add DHCP servers to the DHCP server group.20. Enable the DHCP function on the server.1 [Quidway-dhcp-server-group-dhcpgroup1] quit Step 2 Enable DHCP relay on the VLANIF interface. Create a global address pool on the DHCP server to allocate IP addresses to clients. # Create a VLAN and add GE 0/0/1 to the VLAN.20. # Create a DHCP server group.IP Service 3 DHCP Configuration Configuration Roadmap Configure SwitchA as a DHCP relay agent. 3.10. 2. [Quidway] dhcp enable [Quidway] interface vlanif 100 [Quidway-Vlanif100] dhcp select relay [Quidway-Vlanif100] quit Step 3 Bind a VLANIF interface to a specified DHCP server group. [Quidway] interface vlanif 100 [Quidway-Vlanif100] ip address 20. [Quidway-dhcp-server-group-dhcpgroup1] dhcp-server 100.10.Quidway S5700 Series Ethernet Switches Configuration Guide . Enable DHCP relay on VLANIF 100.1 24 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Bind the DHCP server group to VLANIF 100 and specify the DHCP server for the DHCP relay agent. # Assign an IP address to the VLANIF interface. 2. Configure a DHCP server group on SwitchA and add SwitchB to the DHCP server group.

0 Vpn instance : -IP address Statistic Total :250 Used :0 Idle :248 Expired :0 Conflict :0 Disable :2 ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.255. [Quidway-Vlanif100] dhcp relay server-select dhcpgroup1 [Quidway-Vlanif100] quit Step 4 Configure the DHCP server.10. Ltd.Quidway S5700 Series Ethernet Switches Configuration Guide .20.20. [Quidway] ip pool 1 [Quidway-ip-pool-1] network 20.10. # Run the display dhcp relay command on SwitchA to view the DHCP relay configuration on the interface.. <Quidway> system-view [Quidway] dhcp enable [Quidway] interface vlanif 20 [Quidway-Vlanif20] ip address 100. [Quidway] display ip pool ----------------------------------------------------------------------Pool-Name : 1 Pool-No : 0 Position : Local Status : Unlocked Gateway-0 : Mask : 255.20.20.0 mask 24 [Quidway-ip-pool-1] quit # Configure a static route from the address pool to the DHCP relay agent to ensure that the DHCP server has a reachable route to the network segment 20.) Step 5 Verify the configuration.0/24 on the DHCP server and configure a static route from the DHCP server to the Switch.IP Service 3 DHCP Configuration # Bind the VLANIF interface to a specified DHCP server group.1 # Run the display ip pool command on SwitchB to view the address pool configuration.20.0/24.20.255.(The configuration procedure is not provided here. [Quidway] vlan 20 [Quidway-Vlan20] quit [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port link-type trunk [Quidway-GigabitEthernet0/0/1] port trunk allow-pass vlan 20 [Quidway-GigabitEthernet0/0/1] quit # Enable the DHCP function and configure the clients connected to VLANIF 20 to obtain IP addresses from the global address pool.10. Ensure that the route between the DHCP server and network segment 20.20.20.1 24 [Quidway-Vlanif20] dhcp select global [Quidway-Vlanif20] quit Configure an IP address pool 20. [Quidway] display dhcp relay interface vlanif100 DHCP relay agent running information of interface Vlanif100 : Server group name : dhcpgroup1 Gateway address in use : 100. 72 .10.0/24 is reachable. # Create a VLAN and add GE 0/0/1 to the VLAN.

Quidway S5700 Series Ethernet Switches Configuration Guide .0 dhcp select global # interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 20 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.10.IP Service 3 DHCP Configuration Configuration Files Configuration file of SwitchA # sysname Quidway # vlan 100 # dhcp enable # dhcp server group dhcpgroup1 dhcp-server 100.255.255.0 # interface Vlanif20 ip address 100.0 dhcp select relay dhcp relay server-select dhcpgroup1 # interface GigabitEthernet0/0/1 port link-type trunk port trunk allow-pass vlan 100 # return Configuration file of SwitchB # sysname Quidway # vlan batch 20 # dhcp enable # ip pool 1 network 20.20. 73 .20.10.255.20.255.0 mask 255..10.255.20.1 255. Ltd.10.1 # interface Vlanif100 ip address 20.1 255.255.

the DHCPv6 relay agents transmit DHCPv6 messages exchanged between the DHCPv6 client and the DHCPv6 server. Ltd. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you need to deploy DHCPv6 relay agents between the DHCPv6 client and the DHCPv6 server. the S5700 supports only the DHCPv6 relay function. 4.1 Introduction to DHCPv6 DHCPv6 is designed for IPv6 addressing and is used to allocate IPv6 addresses and other network configuration parameters to hosts. 4.4 Maintaining DHCPv6 This section describes how to clear the statistics about DHCPv6 messages passing through the DHCPv6 relay agent and monitor the running status of the DHCPv6 relay agent.Quidway S5700 Series Ethernet Switches Configuration Guide . 74 .3 Configuring DHCPv6 Relay When the DHCPv6 client and the DHCPv6 server are on different links. 4. This document describes how to configure Dynamic Host Configuration Protocol for IPv6 (DHCPv6) relay. and cannot function as the DHCPv6 server or client. 4. 4.IP Service 4 DHCPv6 Configuration 4 DHCPv6 Configuration About This Chapter Currently. the S5700 can function as only the DHCP relay agent on IPv6 networks. In this manner..2 DHCPv6 Features Supported by the S5700 Currently.5 Configuration Examples This section provides a configuration example of DHCPv6 relay.

Advantages of Addresses Allocated by DHCPv6 Compared with other IPv6 address allocation modes (manual configuration and stateless address auto-configuration through the network prefix in router advertisement messages). l DUID The DHCP Unique Identifier (DUID) identifies a DHCPv6-enabled device including the DHCPv6 client and is used for verification between DHCPv6-enabled devices.IP Service 4 DHCPv6 Configuration 4. All DHCP servers within a site are members of this multicast group. DHCPv6 has the following advantages: l Controls address allocation better. The address is the link-scoped multicast address and is used for communication between a DHCP client and its neighboring server or relay agent on the link. Link-layer Address and Time (DUIDLLT) to identify DHCPv6-enabled devices. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Basic Concepts of DHCPv6 l Multicast address In DHCPv6.1 Introduction to DHCPv6 DHCPv6 is designed for IPv6 addressing and is used to allocate IPv6 addresses and other network configuration parameters to hosts. and DHCP servers and relay agents listen on port 547 for DHCP messages. l Provides network configuration parameters including the IP address of the DNS server and the domain name for hosts in addition to IPv6 addresses. – FF05::1:3 (All_DHCP_Servers): indicates the multicast address of all the DHCP servers. Instead. 75 .Quidway S5700 Series Ethernet Switches Configuration Guide . The S5700 uses the DUID Based on hardware type. the client locates the DHCPv6 server by sending Solicit messages whose destination address is a multicast address. Figure 4-1 shows the format of the DUID-LLT. The address is the site-scoped address and is used for communication between DHCP relay agents and DHCP servers within a site. l UDP port number DHCPv6 messages are transmitted through UDPv6. This facilitates network management. the client does not need to be configured with the IP address of the DHCPv6 server. The device enabled with DHCPv6 can record the address allocated to the host and allocate a special address to the specified host. DHCPv6 uses the following multicast addresses: – FF02::1:2 (All_DHCP_Relay_Agents_and_Servers): indicates the multicast address of all the DHCP servers and relay agents. Ltd. All the DHCP servers and relay agents are members of the multicast group. DHCP clients listen on port 546 for DHCP messages..

– Time: time when the DUID is generated. and cannot function as the DHCPv6 server or client. The link layer address is the MAC address.. The costs are thus saved and concentrated management is implemented easily. The interface has a unique link layer address. 76 .IP Service 4 DHCPv6 Configuration Figure 4-1 DUID-LLT format 15 0 DUID type 31 Hardware type Time Link layer address – DUID type: The value of the DUID type is 0x0001. – Link layer address: The value is the link layer address of any interface. Typical Networking of DHCPv6 Figure 4-2 shows a typical networking of DHCPv6. the S5700 supports only the DHCPv6 relay function. the system time must be configured or the clock source is available. Ltd. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 4. In this case.Quidway S5700 Series Ethernet Switches Configuration Guide . – Hardware type: The hardware type supported by the device is Ethernet and the value is 0x0006. the DHCPv6 relay agent is required to forward messages. The DHCPv6 client communicates with the DHCPv6 server through the link-scoped multicast address to obtain the IPv6 address and other network configuration parameters. Before the DUID is generated.2 DHCPv6 Features Supported by the S5700 Currently. If the DHCPv6 server and the DHCPv6 client are located on different links. you do not need to deploy a DHCPv6 server on each link.

DHCPv6 Relay Function Supported by the S5700 l Forwards messages from DHCPv6 clients. If the S5700 is the non-first-hop DHCPv6 relay agent. To prevent a large number of messages of clients or relay agents from attacking the device. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. it receives DHCPv6 messages from DHCPv6 servers. it receives DHCPv6 messages from DHCPv6 clients. An alarm is generated when the number of discarded packets exceeds the threshold. 77 .IP Service 4 DHCPv6 Configuration Figure 4-2 Typical networking of DHCPv6 DHCPv6 client DHCPv6 client IPv6 network DHCPv6 relay agent DHCPv6 client DHCPv6 client DHCPv6 server NOTE Currently. l Appends the remote ID.Quidway S5700 Series Ethernet Switches Configuration Guide . If the S5700 is enabled with the DHCPv6 relay function. and cannot function as the DHCPv6 server or client. it receives DHCPv6 messages from DHCPv6 relay agents. l Forwards messages from DHCPv6 relay agents. Then the S5700 resolves. If the S5700 is the last-hop DHCPv6 relay agent. The S5700 can append or forcibly append the remote ID in Relay-Forward messages. encapsulates. l Forwards messages from DHCPv6 servers. l Collects statistics on forwarded DHCPv6 messages. the S5700 supports only the DHCPv6 relay function. Ltd. Then the S5700 resolves. encapsulates. If the S5700 is the first-hop DHCPv6 relay agent. and forwards the received DHCPv6 messages. the S5700 can limit the rate of DHCPv6 messages to be forwarded. the S5700 collects statistics on DHCPv6 messages passing through the DHCP relay agent. and forwards the received DHCPv6 messages.. and forwards the received DHCPv6 messages. encapsulates. Then the S5700 resolves. l Limits the rate of DHCPv6 messages to be forwarded.

Data 1 Type and number of the interface where DHCPv6 relay is enabled (the interface type is VLANIF) 2 Type and number of the interface where the function of appending the remote ID to DHCPv6 relay messages is enabled (the interface type can be GE. and specify the outbound interface of relay messages. Applicable Environment When the DHCPv6 client applies to the DHCPv6 server on a different link for the IP address. Pre-configuration Tasks Before configuring DHCPv6 relay.3 Configuring DHCPv6 Relay When the DHCPv6 client and the DHCPv6 server are on different links. or XGE) 3 (Optional) Maximum transmission rate of DHCPv6 messages and alarm threshold of the number of DHCPv6 messages discarded 4. pre-configuration tasks.1 Establishing the Configuration Task This section describes the applicable environment. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. In this manner. and data preparation for configuring DHCPv6 relay. Ltd. you need the following data. 78 . No. set the IPv6 address of the DHCPv6 server or the next hop relay agent.3.. you need to deploy relay agents between the DHCPv6 client and the DHCPv6 server.Quidway S5700 Series Ethernet Switches Configuration Guide .3. complete the following tasks: l Configuring the DHCPv6 server l Configuring the route between the S5700 and DHCPv6 server Data Preparation To configure DHCPv6 relay. 4.2 Enabling the DHCPv6 Relay Function You can enable the DHCPv6 relay function on a VLANIF interface of the S5700. you need to deploy DHCPv6 relay agents between the DHCPv6 client and the DHCPv6 server. the relay agents transmit DHCPv6 messages exchanged between the DHCPv6 client and the DHCPv6 server. In this manner. the DHCPv6 relay agents transmit DHCPv6 messages exchanged between the DHCPv6 client and the DHCPv6 server.IP Service 4 DHCPv6 Configuration 4.

Ltd. l If the configured IPv6 address is a local address or a multicast address. 79 . and the outbound interface of relay messages is specified. Step 7 Run: dhcpv6 relay destination ipv6-address [ interface interface-type interface-number ] The DHCPv6 relay function is enabled on the VLANIF interface.3 (Optional) Configuring the Remote ID The remote ID carries information about a client and identifies a client. Step 6 Run: ipv6 address { ipv6-address prefix-length | ipv6-address/prefix-length } The IPv6 address is configured on the interface. The DHCPv6 server sends the relay messages to the IPv6 address by searching for a route. Usually. Step 2 Run: dhcp enable DHCP is enabled. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. up to eight interfaces can be enabled with the DHCPv6 relay function and each interface can be configured with up to eight destination addresses. the DHCPv6 relay function is disabled on a VLANIF interface.3. Context The DHCPv6 server can make decisions about address allocation. On the S5700. and prefix agent according to the remote ID. parameter setting. ----End 4. the outbound interface does not need to be specified. Step 5 Run: ipv6 enable The IPv6 capability is enabled on the interface.Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 4 DHCPv6 Configuration Procedure Step 1 Run: system-view The system view is displayed. The format of the remote ID is defined by the vendor. the outbound interface of the DHCPv6 server or the next hop relay agent needs to be specified. Step 4 Run: interface vlanif vlan-id The VLANIF interface view is displayed.. Step 3 Run: ipv6 The IPv6 packet forwarding capability is enabled. By default. l If the configured IPv6 address is a global address or a site address. the IPv6 address of the DHCPv6 server or the next hop relay agent is set.

The interface can be a GE interface or an XGE interface. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. If you run the dhcpv6 remote-id insert enable and dhcpv6 remote-id rebuild enable commands simultaneously on an interface. Currently. If the original DHCPv6 messages carry the remote ID. When constructing a RelayForward message. l After the dhcpv6 remote-id rebuild enable command is used. the S5700 adds the remote ID to the Relay-Forward message according to the configuration. When the S5700 functions as the DHCPv6 relay agent. it processes the remote ID as follows: l The S5700 directly receives messages from DHCPv6 clients. the command that you run later takes effect.Quidway S5700 Series Ethernet Switches Configuration Guide . if the original DHCPv6 messages do not carry the remote ID. Step 2 Run: dhcpv6 remote-id format { default | user-defined text } The format of the remote ID in DHCPv6 messages is set. If the original DHCPv6 messages carry the remote ID. Ltd. Step 3 Run: interface interface-type interface-number The interface view is displayed. the S5700 removes the remote ID from the Relay-Reply message before forwarding it to DHCPv6 clients or other relay agents. or the peer IP address and access interface in a point-to-point connection.. the S5700 sends the DHCP messages directly. a remote ID can contain a maximum of 247 bytes. run: dhcpv6 remote-id rebuild enable The function of forcibly appending the remote ID to DHCPv6 relay messages is enabled. Procedure Step 1 Run: system-view The system view is displayed. the S5700 appends the remote ID to the DHCPv6 messages. l After the dhcpv6 remote-id insert enable command is used.IP Service 4 DHCPv6 Configuration the remote ID carries the phone number and user name in a dial-up connection. Step 4 Run: dhcpv6 remote-id insert enable The function of appending the remote ID to DHCPv6 relay messages is enabled. 80 . the S5700 deletes the original remote ID from the DHCP messages and appends a new remote ID to the DHCP messages. l If the Relay-Reply message received by the S5700 from the DHCPv6 server contains the remote ID. the S5700 appends the remote ID to the DHCPv6 messages. Or. if the original DHCPv6 messages do not carry the remote ID. the default format of the remote ID in DHCPv6 messages is used. By default.

After the log function is enabled. Step 2 Run: dhcp enable DHCP is enabled. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Step 4 Run: dhcpv6 packet-rate drop-alarm enable The alarm function for DHCPv6 messages discarded when the rate of DHCPv6 messages exceeds rate limit.5 Checking the Configuration This section describes how to check the configuration of DHCPv6 relay. the S5700 supports the log function. rate limit of DHCPv6 messages is disabled on the S5700.3. Context After rate limit of DHCPv6 messages is enabled. When the number of discarded DHCPv6 messages exceeds the threshold. Ltd. excessive DHCPv6 messages are discarded when the rate of DHCPv6 messages exceeds the limit.4 (Optional) Configuring Rate Limit of DHCPv6 Messages To prevent a large number of messages of clients or relay agents from attacking the device.3.IP Service 4 DHCPv6 Configuration 4. By default.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 3 Run: dhcpv6 packet-rate packet-rate Rate limit of DHCPv6 messages is enabled and the maximum transmission rate of DHCPv6 messages is set. if the number of DHCPv6 messages that pass through the S5700 every second exceeds the rate limit.. S5700 sends logs when the number of discarded DHCPv6 messages exceeds 100. By default. Procedure Step 1 Run: system-view The system view is displayed. Prerequisite The configurations of DHCPv6 relay are complete. 81 . ----End 4. they are discarded. Step 5 Run: dhcpv6 packet-rate drop-alarm threshold threshold The log threshold for DHCPv6 messages discarded is set when the rate of DHCPv6 messages exceeds rate limit. the S5700 can limit the rate of DHCPv6 messages to be forwarded.

the system collects statistics about DHCPv6 messages passing through the DHCP relay agent. ----End 4. Currently.Quidway S5700 Series Ethernet Switches Configuration Guide .2 Monitoring the Running Status of the DHCPv6 Relay Agent This section describes how to use the display commands to monitor the running status of the DHCPv6 relay agent. l Run the display dhcpv6 relay statistics [ interface interface-type interface-number ] command to check the statistics about DHCPv6 messages passing through the DHCPv6 relay agent. all the statistics about DHCPv6 messages are cleared. 82 . If no interface is specified. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.4 Maintaining DHCPv6 This section describes how to clear the statistics about DHCPv6 messages passing through the DHCPv6 relay agent and monitor the running status of the DHCPv6 relay agent. Context CAUTION Statistics cannot be restored after being cleared.. the interface type can only be the VLANIF interface. ----End 4.4.1 Clearing the Statistics About DHCPv6 Messages Passing Through the DHCP Relay Agent If the S5700 is enabled with the DHCPv6 relay function. confirm the action before you use the command. Currently. If the interface is specified. Procedure l Run the reset dhcpv6 relay statistics [ interface interface-type interface-number ] command to clear the statistics about DHCPv6 messages passing through the DHCPv6 relay agent. you can use the command in the user view or system view. Ltd. the statistics about DHCPv6 messages on the specified interface are cleared. the interface type can only be the VLANIF interface.4. The interface must be the VLANIF interface. To clear the statistics about DHCPv6 messages passing through the DHCPv6 relay agent. 4.IP Service 4 DHCPv6 Configuration Procedure l Run the display dhcpv6 relay [ interface interface-type interface-number ] command to check the configuration about the interface enabled with the DHCPv6 relay function. So.

Issue 01 (2011-10-26) Enable DHCP.5. By specifying the M flag bit and O flag bit in RA messages. Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide . Ltd. the DHCPv6 client address is 2000::/64 and the DHCPv6 server address is 3000::3/64. hosts on the network are enabled to obtain IPv6 addresses and other network configuration parameters through DHCPv6. ----End 4. a DHCPv6 relay agent is required to forward DHCPv6 messages.1 Example for Configuring DHCPv6 Relay This section provides a configuration example of DHCPv6 relay. Figure 4-3 Networking for configuring DHCPv6 relay DHCPv6 client DHCPv6 client GE0/0/2 GE0/0/1 Switch VLANIF20 VLANIF10 3000::1/64 2000::1/64 DHCPv6 relay agent 3000::3/64 DHCPv6 server DHCPv6 client DHCPv6 client Configuration Roadmap The configuration roadmap is as follows: 1.5 Configuration Examples This section provides a configuration example of DHCPv6 relay. The DHCPv6 client and the DHCPv6 server are on different links. therefore. In addition. Networking Requirements As shown in Figure 4-3. l Run the display dhcpv6 relay statistics [ interface interface-type interface-number ] command to check the statistics about DHCPv6 messages passing through the DHCPv6 relay agent. 83 .IP Service 4 DHCPv6 Configuration Procedure l Run the display dhcpv6 relay [ interface interface-type interface-number ] command to check the configuration about the interface enabled with the DHCPv6 relay function. It is required that the Switch should function as the DHCPv6 relay agent to forward DHCPv6 messages exchanged between the DHCPv6 client and the DHCPv6 server.. the Switch functions as the gateway device of the network at 2000::/64. 4.

[Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port hybrid pvid vlan 10 [Quidway-GigabitEthernet0/0/1] port hybrid untagged vlan 10 [Quidway-GigabitEthernet0/0/1] quit # Add GigabitEthernet0/0/2 to VLAN 20. [Quidway] ipv6 # Set the IPv6 address of VLANIF 10. # Enable the DHCPv6 relay function on VLANIF 10 and set the IP address of the DHCPv6 server.Quidway S5700 Series Ethernet Switches Configuration Guide .. 3. Create VLANIF interfaces and set IPv6 addresses of the VLANIF interfaces. Enable the DHCPv6 relay function and set the DHCPv6 server address. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Data Preparation To complete the configuration. you need the following data: l IPv6 addresses of the interfaces l IP address of the DHCPv6 server Procedure Step 1 Enable DHCP. 84 . Configure the Switch as the gateway. 4. Ltd. # Enable the IPv6 packet forwarding function. [Quidway] vlan batch 10 20 [Quidway] interface vlanif 10 [Quidway-Vlanif10] ipv6 enable [Quidway-Vlanif10] ipv6 address 2000::1 64 [Quidway-Vlanif10] quit # Set the IPv6 address of VLANIF 20.IP Service 4 DHCPv6 Configuration 2. [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] port hybrid pvid vlan 20 [Quidway-GigabitEthernet0/0/2] port hybrid untagged vlan 20 [Quidway-GigabitEthernet0/0/2] quit Step 3 Set IPv6 addresses of VLANIF interfaces. [Quidway] interface vlanif 10 [Quidway-Vlanif10] dhcpv6 relay destination 3000::3 Step 5 Configure the Switch as the gateway. # Add GigabitEthernet0/0/1 to VLAN 10. <Quidway> system-view [Quidway] dhcp enable Step 2 Add interfaces to VLANs. [Quidway] interface vlanif 20 [Quidway-Vlanif20] ipv6 enable [Quidway-Vlanif20] ipv6 address 3000::1 64 [Quidway-Vlanif20] quit Step 4 Enable the DHCPv6 relay function.

Run the display dhcpv6 relay command on the Switch. Ltd. [Quidway] display dhcpv6 relay statistics MessageType Receive Send Solicit 0 0 Advertise 0 0 Request 0 0 Confirm 0 0 Renew 0 0 Rebind 0 0 Reply 0 0 Release 0 0 Decline 0 0 Reconfigure 0 0 Information-request 0 0 Relay-forward 0 0 Relay-reply 0 0 UnknownType 0 0 Error 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ----End Configuration Files Configuration file of the Switch # sysname Quidway # vlan batch 10 20 # ipv6 # dhcp enable # interface Vlanif10 ipv6 enable ipv6 address 2000::1/64 undo ipv6 nd ra halt ipv6 nd autoconfig managed-address-flag ipv6 nd autoconfig other-flag dhcpv6 relay destination 3000::3 # interface Vlanif20 ipv6 enable ipv6 address 3000::1/64 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 10 port hybrid untagged vlan 10 # Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. and you can view the statistics about DHCP messages passing through the DHCPv6 relay agent. [Quidway-Vlanif10] [Quidway-Vlanif10] [Quidway-Vlanif10] [Quidway-Vlanif10] undo ipv6 nd ra halt ipv6 nd autoconfig managed-address-flag ipv6 nd autoconfig other-flag quit Step 6 Verify the configuration. and you can view the configuration of DHCPv6 relay. 85 ..IP Service 4 DHCPv6 Configuration # Configure the Switch to send RA messages and configure M and O flag bits. [Quidway] display dhcpv6 relay Interface Mode Destination -----------------------------------------------------------------Vlanif10 Relay 3000::3 ------------------------------------------------------------------ Run the display dhcpv6 relay statistics on the Switch.Quidway S5700 Series Ethernet Switches Configuration Guide .

IP Service 4 DHCPv6 Configuration interface GigabitEthernet0/0/2 port hybrid pvid vlan 20 port hybrid untagged vlan 20 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 86 .Quidway S5700 Series Ethernet Switches Configuration Guide .. Ltd.

5.IP Service 5 5 IP Performance Configuration IP Performance Configuration About This Chapter This chapter describes the basic concepts of IP performance. Ltd..5 Configuration Examples This section provides several configuration examples of IP performance. IP performance parameters supported by the S5700 are described.1 Introduction to IP Performance On certain networks.2 IP Performance Supported by the S5700 5. Here.3 Optimizing IP Performance This section describes how to optimize IP performance of a certain network by setting IP performance parameters.4 Maintaining IP Performance This section describes how to maintain IP performance. you need to change IP parameters to optimize the performance of networks. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 5.Quidway S5700 Series Ethernet Switches Configuration Guide . 87 . 5. and provides configuration procedures and examples of IP performance. 5.

3 Optimizing IP Performance This section describes how to optimize IP performance of a certain network by setting IP performance parameters. complete the following tasks: l Issue 01 (2011-10-26) Connecting interfaces and setting physical parameters of the interfaces to ensure that the physical layer of the interfaces is in the Up state Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide . Ltd. – The packet is not for itself. a control switch is added on the outgoing interface of ICMP messages. To solve this problem. network congestion becomes worse. This increases the traffic burden. This switch is used to respectively enable or disable the sending of ICMP host unreachable messages. l ICMP Packet Sending Switches In normal circumstance.3. you need to change IP parameters to optimize the performance of networks. the device discards the packets and returns an ICMP host unreachable message to the source to notify that the source must stop sending packets to this destination if the device encounters the following situations: – There is no route to the destination. the device does not send out the ICMP host unreachable packets.1 Introduction to IP Performance On certain networks. when devices encounter the preceding conditions frequently. To optimize the performance. Pre-configuration Tasks Before optimizing IP performance. IP performance parameters supported by the S5700 are described. 5. ICMP host unreachable messages can ensure normal packet transmission. Here. In the case of malicious attacks. If the switch is disabled.2 IP Performance Supported by the S5700 ICMP l ICMP Host Unreachable Messages When forwarding packets. you need to set parameters.IP Service 5 IP Performance Configuration 5..1 Establishing the Configuration Task Applicable Environment On certain networks. 5. This can reduce the traffic burden and protect the network from malicious attacks. 5. you need to change IP performance parameters to optimize the performance. However. network traffic becomes heavy because devices send a large number of ICMP messages. 88 .

Procedure Step 1 Run: system-view The system view is displayed.3. 89 . FIN-WAIT timer.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 5 Run: ip verify source-address Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. receiving and sending buffer size of the socket 5. No. Step 4 Run: interface vlanif vlan-id The VLANIF interface view is displayed. Step 3 Run: quit The system view is displayed. Data 1 Number of the interface 2 Number of the interface which needs source address verification 3 Number of the interface which needs to forward broadcast packets and ACL number which is used to specify the broadcast packets 4 Number of the interface which needs to configure ICMP host-unreachable 5 SYN-WAIT timer.. Step 2 Run: vlan vlan-id A VLAN is created.IP Service 5 IP Performance Configuration l Setting parameters of the link layer protocol for the interfaces to ensure that the status of the link layer protocol on the interfaces is Up l Assigning IP addresses to interfaces l Configuring access control lists (ACLs) Data Preparation To optimize IP performance. Ltd. you need the following data.2 Enabling an Interface to Check the Source IP Addresses of Packets Context Do as follows on the S5700.

By default. By default. The timeout interval of the TCP SYN-Wait timer is an integer that ranges from 2 to 600.IP Service 5 IP Performance Configuration The interface is enabled to check the source IP addresses. sending ICMP redirection packets and unreachable packets is enabled.3. TCP starts the SYN-Wait timer. 90 . the device no longer sends the ICMP host unreachable message. l FIN-Wait timer: When the TCP connection status changes from FIN_WAIT_1 to FIN_WAIT_2. the FIN-Wait timer is enabled. If no packet with the FIN flag is received before the FIN-Wait timer expires. The timeout interval of the Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide .3 Configuring ICMP Attributes Context By default. If no response is received before the SYN-Wait timer expires. Step 3 Run: icmp host-unreachable send Sending ICMP host unreachable packets is enabled. Step 2 Run: interface interface-type interface-number The interface view is displayed. the TCP connection ends. the TCP connection ends. ----End 5. Ltd. the value is 75s. the function is disabled on all interfaces. in seconds. Do as follows on the S5700: Procedure Step 1 Run: system-view The system view is displayed.3.4 Setting TCP Parameters Context You can set the following TCP parameters: l SYN-Wait timer: When sending packets with the SYN flag. CAUTION l If the transmission of ICMP host unreachable messages is disabled. ----End 5..

Procedure Step 1 Run: system-view The system view is displayed. ----End 5. the latest configuration overrides the previous configuration. If you run the tcp window command repeatedly in the same system view. the value is 675s. in seconds.5 Checking the Configuration Prerequisite The configurations of optimizing IP performance are complete. l Run the display ip statistics command to check the statistics on IP traffic. l Size of the packet receive or transmit buffer: The value is an integer that ranges from 1 to 32. Step 2 Run: tcp timer syn-timeout interval The timeout interval of the TCP SYN-Wait timer is set.3. Do as follows on the S5700.IP Service 5 IP Performance Configuration TCP FIN-Wait timer is an integer that ranges from 76 to 3600. Step 3 Run: tcp timer fin-timeout interval The timeout interval of the TCP FIN-Wait timer (FIN_WAIT_2) is set. By default. l Run the display tcp statistics command to check the statistics on TCP traffic. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Step 4 Run: tcp window window-size The size of the packet receive or transmit buffer is set. S5700SI does not support VPN-instance.. Procedure l Run the display tcp status [ [ task-id task-id ] [ socket-id socket-id ] | [ local-ip ipaddress ] [ local-port local-port-number ] [ remote-ip ip-address ] [ remote-port remoteport-number ] ] command to check the TCP connection status. l Run the display ip socket [ monitor ] [ task-id task-id socket-id socket-id | sock-type socket-type ] command to check information about the created IPv4 socket. in Kbytes. 91 .Quidway S5700 Series Ethernet Switches Configuration Guide . NOTE The S5706. By default. the value is 8 Kbytes. l Run the display udp statistics command to check the statistics on UDP traffic. Ltd. l Run the display icmp statistics command to check the statistics on ICMP traffic.

l Run the display fib [ vpn-instance vpn-instance-name ] interface interface-type interfacenumber command to check information about the FIB entries with the outgoing interface as a specified interface. l Run the reset udp statistics command in the user view to clear the statistics on UDP traffic. So.4 Maintaining IP Performance This section describes how to maintain IP performance. ----End 5. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. l Run the display fib [ vpn-instance vpn-instance-name ] next-hop ip-address command to check information about the FIB entries that match the specified next hop address.4. Procedure l Run the reset ip statistics [ interface interface-type interface-number ] command in the user view to clear the statistics on IP traffic. l Run the display fib [ slot-id ] [ vpn-instance vpn-instance-name ] statistics command to check the total number of FIB entries.Quidway S5700 Series Ethernet Switches Configuration Guide . 5. confirm the action before you use the command.1 Clearing IP Performance Statistics Context CAUTION The statistics on IP. or UDP traffic cannot be restored after you clear them. Ltd.IP Service 5 IP Performance Configuration l Run the display rawlink statistics command to check the Rawlink statistics. l Run the display fib [ slot-id ] [ vpn-instance vpn-instance-name ] [ verbose ] command to check information about the FIB table. l Run the display fib [ vpn-instance vpn-instance-name ] acl acl-number [ verbose ] command to check information about the FIB entries that match ACL rules in a certain format. l Run the display fib [ vpn-instance vpn-instance-name ] ip-prefix prefix-name [ verbose ] command to check information about the FIB entries that match a specified IP prefix list. l Run the reset ip socket monitor [ task-id task-id socket-id socket-id ] command in the user view to clear the information about the socket monitor. 92 .. l Run the display fib [ slot-id ] command to check the Forwarding Information Base (FIB) table on the Line Processing Unit (LPU). l Run the display fib [ slot-id ][ vpn-instance vpn-instance-name ] destination-address1 [ destination-mask1 ] [ longer ] [ verbose ] command to check information about the FIB entries that match destination IP addresses in a specified range. TCP. l Run the reset tcp statistics command in the user view to clear the statistics on TCP traffic.

----End 5. l Run the display ip socket [ monitor ] [ task-id task-id socket-id socket-id | sock-type socket-type ] command to check information about the created IPv4 socket..IP Service l 5 IP Performance Configuration Run the reset rawlink statistics command in the user view to clear the Rawlink statistics. 93 . l Run the display rawlink statistics command to check the Rawlink statistics. l Run the display fib [ slot-id ] [ vpn-instance vpn-instance-name ] [ verbose ] command to check information about the FIB table. you can run the following command in any view to view the running status of IP performance.2 Monitoring the Running Status of IP Performance Context In routine maintenance. l Run the display fib [ slot-id ][ vpn-instance vpn-instance-name ] destination-address1 [ destination-mask1 ] [ longer ] [ verbose ] command to check information about the FIB entries that match destination IP addresses in a specified range. l Run the display icmp statistics command to check the statistics on ICMP traffic. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. l Run the display fib [ vpn-instance vpn-instance-name ] next-hop ip-address command to check information about the FIB entries that match the specified next hop address. NOTE The S5706. l Run the display fib [ vpn-instance vpn-instance-name ] interface interface-type interfacenumber command to check information about the FIB entries with the outgoing interface as a specified interface. Ltd. l Run the display ip statistics command to check the statistics on IP traffic.4. l Run the display fib [ vpn-instance vpn-instance-name ] ip-prefix prefix-name [ verbose ] command to check information about the FIB entries that match a specified IP prefix list. S5700SI does not support VPN-instance. l Run the display fib [ slot-id ] [ vpn-instance vpn-instance-name ] statistics command to check the total number of FIB entries. l Run the display tcp statistics command to check the statistics on TCP traffic. Procedure l Run the display tcp status [ [ task-id task-id ] [ socket-id socket-id ] | [ local-ip ipaddress ] [ local-port local-port-number ] [ remote-ip ip-address ] [ remote-port remoteport-number ] ] command to check the TCP connection status. l Run the display udp statistics command to check the statistics on UDP traffic. l Run the display fib [ vpn-instance vpn-instance-name ] acl acl-number [ verbose ] command to check information about the FIB entries that match ACL rules in a certain format.Quidway S5700 Series Ethernet Switches Configuration Guide . l Run the display fib [ slot-id ] command to check the FIB table on the LPU.

run the following debugging commands in the user view to locate the fault.Quidway S5700 Series Ethernet Switches Configuration Guide . after debugging. l Run the debugging ip icmp [ verbose ] command in the user view to debug ICMP packets. l Run the debugging rawip packet [ src-ip src-address ] [ dest-ip dest-address ] [ protocol protocol-number ] [ verbose verbose-number ] or debugging rawip packet [ task-id task-id ] [ socket-id socket-id ] [ verbose verbose-number ] command in the user view to debug RAWIP packets.IP Service 5 IP Performance Configuration 5. TCP. UDP.. So.3 Debugging IP Performance Context CAUTION Debugging affects the performance of the system. Procedure l Run the debugging ip packet [ error ] [ acl acl-number ] [ verbose ] command in the user view to debug IP packets. l Run the debugging rawlink packet [ src-mac src-mac ] [ dest-mac dest-mac ] [ verbose verbose-number ] or debugging rawlink packet [ task-id task-id ] [ socket-id socket-id ] [ verbose verbose-number ] command in the user view to debug RAWLINK packets. When an IP. run the undo debugging all command to disable it immediately. 94 . For details on debugging commands. RAWIP. see the Quidway S5700 Series Ethernet Switches Debugging Reference. l Run the debugging tcp event [ local-ip local-address ] [ local-port local-port ] [ remoteip remote-address ] [ remote-port remote-port ] or debugging tcp event [ task-id taskid ] [ socket-id socket-id ] command in the user view to debug TCP events. l Run the debugging tcp md5 [ src-ip src-address ] [ src-port src-port ] [ dest-ip destaddress ] [ dest-port dest-port ] or debugging tcp md5 [ task-id task-id ] [ socket-id socket-id ] command in the user view to debug TCP Message Digest Algorithm 5 (MD5) authentication.5 Configuration Examples This section provides several configuration examples of IP performance.4. or RAWLINK fault occurs. l Run the debugging udp packet [ src-ip src-address ] [ src-port src-port ] [ dest-ip destaddress ] [ dest-port dest-port ] or debugging udp packet [ task-id task-id ] [ socket-id socket-id ] command in the user view to debug UDP packets. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd. l Run the debugging tcp packet [ src-ip src-address ] [ src-port src-port ] [ dest-ip destaddress ] [ dest-port dest-port ] [ flag flag-number ] or debugging tcp packet [ task-id task-id ] [ socket-id socket-id ] [ flag flag-number ] command in the user view to debug UDP packets. ----End 5.

4.1. and Switch C are required and these devices are connected through their GigabitEthernet interfaces. Data Preparation To complete the configuration.IP Service 5 IP Performance Configuration 5.2/24 GE0/0/2 VLANIF11 2. Figure 5-1 Networking diagram for disabling the sending of ICMP host unreachable packets GE0/0/2 VLANIF11 2. you need the following data: l Static routes to indirectly connected devices l IP address of the interface Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1/24 SwitchB GE0/0/1 SwitchC GE0/0/1 VLANIF10 1.1/24 SwitchA Configuration Roadmap The configuration roadmap is as follows: 1. If the configuration is not changed. Switch A.2.Quidway S5700 Series Ethernet Switches Configuration Guide .2.1.. 95 . NOTE By default.2/24 VLANIF10 1. the sending of ICMP host unreachable packets is enabled on the system view and on the interface view.5. Configure static routes to indirectly connected devices. 2.2.1. Ltd. 3. Switch B. to limit the sending of ICMP redirection packets. you can skip this configuration. Networking Requirements As shown in Figure 5-1.2.1 Example for Disabling the Sending of ICMP Host Unreachable Packets This section provides a configuration example of disabling the sending of ICMP host unreachable packets. Enable the sending of ICMP host unreachable packets in the system view. Assign IP addresses to interfaces on Switches.1. Enable the sending of ICMP host unreachable packets in the interface view.

1.2.IP Service 5 IP Performance Configuration Procedure Step 1 Configure Switch A.Quidway S5700 Series Ethernet Switches Configuration Guide .. <SwitchA> debugging ip icmp <SwitchA> terminal monitor <SwitchA> terminal debugging Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.2.2.1. [SwitchA] ip route-static 2.1.1.1 24 [SwitchA-Vlanif10] quit # Configure a static route on Switch A.0 24 1. <Quidway> system-view [Quidway] sysname SwitchB [SwitchB] icmp host-unreachable send [SwitchB] vlan 10 [SwitchB-Vlan10] quit [SwitchB] interface gigabitethernet0/0/1 [SwitchB-GigabitEthernet0/0/1] port hybrid tagged vlan 10 [SwitchB-GigabitEthernet0/0/1] quit [SwitchB] interface vlanif 10 [SwitchB-Vlanif10] ip address 1. 96 . Ltd.2.1 24 [SwitchB-Vlanif11] icmp host-unreachable send [SwitchB-Vlanif11] quit Step 3 Configure Switch C. # Assign an IP address to VLANIF 10. # Assign an IP address to VLANIF 10 on Switch B and disable the sending of ICMP host unreachable packets. # Assign an IP address to VLANIF 11 on Switch C.2.2 24 [SwitchB-Vlanif10] quit [SwitchB] vlan 11 [SwitchB-Vlan11] quit [SwitchB] interface gigabitethernet0/0/2 [SwitchB-GigabitEthernet0/0/2] port hybrid tagged vlan 11 [SwitchB-GigabitEthernet0/0/2] quit [SwitchB] interface vlanif 11 [SwitchB-Vlanif11] ip address 2.2 24 [SwitchC-Vlanif11] quit Step 4 Verify the configuration. <Quidway> system-view [Quidway] sysname SwitchA [SwitchA] vlan 10 [SwitchA-Vlan10] quit [SwitchA] interface gigabitethernet0/0/1 [SwitchA-GigabitEthernet0/0/1] port hybrid tagged vlan 10 [SwitchA-GigabitEthernet0/0/1] quit [SwitchA] interface vlanif 10 [SwitchA-Vlanif10] ip address 1.2. # Debug ICMP packets on Switch A.1.1. <Quidway> system-view [Quidway] sysname SwitchC [SwitchC] vlan 11 [SwitchC-Vlan11] quit [SwitchC] interface gigabitethernet0/0/2 [SwitchC-GigabitEthernet0/0/2] port hybrid tagged vlan 11 [SwitchC-GigabitEthernet0/0/2] quit [SwitchC] interface vlanif 11 [SwitchC-Vlanif11] ip address 2.2 Step 2 Configure Switch B.

2. Switch B sends host unreachable packets.2.0 255.0 1.255.1 255.0 # interface GigabitEthernet0/0/1 port hybrid tagged vlan 10 # interface GigabitEthernet0/0/2 port hybrid tagged vlan 11 # return l Configuration file of Switch C # sysname SwitchC # vlan 11 # interface vlanif 11 ip address 2.2 # return l Configuration file of Switch B # sysname SwitchB # vlan batch 10 to 11 # interface vlanif 10 ip address 1.1.255.2.2.1. 97 . Ltd.0 # interface GigabitEthernet0/0/2 port hybrid tagged vlan 11 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.255.1 255.0 # interface GigabitEthernet0/0/1 port hybrid tagged vlan 10 # ip route-static 2.1.2 255.255.3 command on Switch A. [SwitchA] ping 2.255.2 255.255.0 # interface vlanif 11 ip address 2.255.2.2.255.IP Service 5 IP Performance Configuration # Run the ping 2.3 ----End Configuration Files l Configuration file of Switch A # sysname SwitchA # vlan 10 # interface vlanif 10 ip address 1.2.2.255.1..1.255. According to the received packet captured by the tester on Switch A.1.2.Quidway S5700 Series Ethernet Switches Configuration Guide .2.

Quidway S5700 Series Ethernet Switches Configuration Guide .. and provides configuration examples. Ltd.6 Maintaining DHCP Policy VLAN This section describes how to maintain DHCP policy VLAN.4 Configuring the DHCP Policy VLAN Based on Interfaces This section describes how to configure the DHCP policy VLAN based on interfaces. and configuration of Dynamic Host Configuration Protocol (DHCP) policy Virtual Local Area Network (VLAN).5 Configuring Generic DHCP Policy VLAN This section describes how to configure Generic DHCP Policy VLAN 6. 6. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. operating mode.IP Service 6 6 DHCP Policy VLAN Configuration DHCP Policy VLAN Configuration About This Chapter This chapter describes the concept.7 Configuration Examples This section provides several configuration examples of DHCP policy VLAN. 6.3 Configuring DHCP Policy VLAN Based on MAC Addresses This section describes how to configure DHCP Policy VLAN Based on MAC Addresses 6. 98 . 6.1 Introduction 6.2 DHCP Policy VLAN Supported by the S5700 6.

Ltd. you need to configure DHCP policy VLAN based on MAC addresses so that the hosts can obtain IP addresses from the DHCP server and be added to specific VLANs.IP Service 6 DHCP Policy VLAN Configuration 6.2 DHCP Policy VLAN Supported by the S5700 The S5700 supports the following types of DHCP policy VLAN: l DHCP policy VLAN based on MAC addresses l DHCP policy VLAN based on interfaces l Generic DHCP policy VLAN 6.1 Establishing the Configuration Task Applicable Environment When multiple hosts access the network through an interface on the S5700.1 Introduction When the policy for VLANs is configured on the S5700. DHCP policy VLAN is thus introduced.. 6. the host cannot be added to its associated VLAN because it has no valid IP address. hosts that access the network for the first time can obtain valid IP addresses from the DHCP server and then be added to the VLANs whose network segments the IP addresses belong to.Quidway S5700 Series Ethernet Switches Configuration Guide . With DHCP policy VLAN. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. the VLAN to which each host connects to the interface on the S5700 belongs is determined by the network segment to which the IP address of the host belongs. 99 . complete the following tasks: l Configuring the default VLAN for the interface on the S5700 that connects to the newly added hosts Data Preparation To configure DHCP policy VLAN based on MAC addresses. you need the following data.3. Pre-configuration Tasks Before configuring DHCP policy VLAN based on MAC addresses. When a host that accesses the network for the first time is connected to an interface.3 Configuring DHCP Policy VLAN Based on MAC Addresses This section describes how to configure DHCP Policy VLAN Based on MAC Addresses 6.

.2 Configuration Procedure Context Do as follows on the S5700.3. Step 4 Run: vlan vlan-id The view of the VLAN to which the DHCP server belongs is displayed. Step 5 Run: dhcp policy-vlan mac-address priority ] mac-address1 [ to mac-address2 ] [ priority The DHCP policy VLAN based on MAC addresses is configured. Step 2 Run: interface interface-type interface-number The view of the interface on the S5700 that connects to multiple hosts is displayed. Issue 01 (2011-10-26) Action Command Check the configuration of the S5700 in the VLAN view. display this Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Data 1 MAC addresses of the newly added hosts 2 ID of the VLAN to which the DHCP server belongs 6. ----End 6.3. Procedure Step 1 Run: system-view The system view is displayed.IP Service 6 DHCP Policy VLAN Configuration No. 100 . Step 3 Run: port hybrid untagged vlan { { vlan-id1 [ to vlan-id2 ] }&<1-10> | all } The interface is added to the specified VLANs. ensuring that frames from the VLANs pass through the interface in untagged mode.3 Checking the Configuration Run the following command to check the previous configuration. Ltd.Quidway S5700 Series Ethernet Switches Configuration Guide .

4. 101 . you need to configure DHCP policy VLAN based on interfaces so that the hosts can obtain IP addresses from the DHCP server.Quidway S5700 Series Ethernet Switches Configuration Guide . 6. [Quidway-vlan2] display this # vlan 2 dhcp policy-vlan mac-address 0002-0002-0002 priority 2 # 6..4 Configuring the DHCP Policy VLAN Based on Interfaces This section describes how to configure the DHCP policy VLAN based on interfaces. No. Data 1 Number of the interface that connects to the newly added host on the S5700 2 ID of the VLAN to which the DHCP server belongs 6. you need the following data.IP Service 6 DHCP Policy VLAN Configuration Run the display this command in the VLAN view of the S5700 where DHCP policy VLAN based on MAC addresses is configured. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd.4.1 Establishing the Configuration Task Applicable Environment When multiple hosts access the network through different interfaces on the S5700. complete the following tasks: l Configuring the default VLAN for the interface that connects to the newly added host on the S5700 l Configuring the interface that connects to the newly added host on the S5700 as a hybrid interface Data Preparation To configure DHCP policy VLAN based on interfaces.2 Configuration Procedure Context Do as follows on the S5700. you can view that the configuration of DHCP policy VLAN based on MAC addresses is correct. Pre-configuration Tasks Before configuring DHCP policy VLAN based on interfaces.

[Quidway-vlan2] display this # vlan 2 dhcp policy-vlan port GigabitEthernet 0/0/2 priority 2 # 6.. Step 3 Run: port hybrid untagged vlan { { vlan-id1 [ to vlan-id2 ] }&<1-10> | all } The interface is added to the specified VLANs.3 Checking the Configuration Run the following commands to check the previous configuration. display this Run the display this command in the VLAN view of the S5700 where DHCP policy VLAN based on interfaces is configured. 102 . Ltd. Step 4 Run: vlan vlan-id The view of the VLAN to which the DHCP server belongs is displayed. Action Command Check the configuration of the S5700 in the VLAN view. you can view that the configuration of DHCP policy VLAN based on interfaces is correct. Step 5 Run: dhcp policy-vlan port interface-type interface-number1 [ to interface-number2 ] [ priority priority ] The DHCP policy VLAN based on interfaces is configured. ensuring that frames from the VLANs pass through the interface in untagged mode.Quidway S5700 Series Ethernet Switches Configuration Guide .4. ----End 6.5 Configuring Generic DHCP Policy VLAN This section describes how to configure Generic DHCP Policy VLAN Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.IP Service 6 DHCP Policy VLAN Configuration Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: interface interface-type interface-number The view of the interface that connects to the newly added host on the S5700 is displayed.

Quidway S5700 Series Ethernet Switches Configuration Guide .5. Procedure Step 1 Run: system-view The system view is displayed..2 Configuration Procedure Context Do as follows on the S5700. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Data 1 ID of the VLAN to which the DHCP server belongs 6. Step 4 Run: vlan vlan-id The view of the VLAN to which the DHCP server belongs is displayed. No. Step 2 Run: interface interface-type interface-number The view of the interface that connects to the newly added host on the S5700 is displayed. you need to configure generic DHCP policy VLAN on the S5700 so that the hosts can obtain valid IP addresses. Ltd. 103 . ensuring that frames from the VLANs pass through the interface in untagged mode. Step 3 Run: port hybrid untagged vlan { { vlan-id1 [ to vlan-id2 ] }&<1-10> | all } The interface is added to the specified VLANs. complete the following tasks: l Configuring the default VLAN for the interface that connects to the newly added host on the S5700 Data Preparation To configure generic DHCP policy VLAN.5.1 Establishing the Configuration Task Applicable Environment When hosts that do not apply DHCP policy VLAN based on MAC addresses or DHCP policy VLAN based on interfaces access the network for the first time. Pre-configuration Tasks Before configuring generic DHCP policy VLAN. you need the following data.IP Service 6 DHCP Policy VLAN Configuration 6.

IP Service 6 DHCP Policy VLAN Configuration Step 5 Run: dhcp policy-vlan generic [ priority priority ] The generic DHCP policy VLAN is configured.1 Example for Configuring DHCP Policy VLAN Based on MAC Addresses Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.7 Configuration Examples This section provides several configuration examples of DHCP policy VLAN.5. [Quidway-vlan2] display this # vlan 2 dhcp policy-vlan generic priority 2 # 6. Action Command Check the configuration of the S5700 in the VLAN view. 6. display this 6. ----End 6. Ltd. display this Run the display this command in the VLAN view of the S5700 where generic DHCP policy VLAN is configured. 104 .. 6.Quidway S5700 Series Ethernet Switches Configuration Guide .6.3 Checking the Configuration Run the following command to check the previous configuration. run the following display command in the corresponding VLAN view. you can view that the configuration of generic DHCP policy VLAN is correct. Action Command Check the configuration of DHCP policy VLAN.1 Monitoring the Running Status To check the running status of DHCP policy VLAN.6 Maintaining DHCP Policy VLAN This section describes how to maintain DHCP policy VLAN.7.

Configure the S5700. 2. 3. Figure 6-1 Networking for configuring DHCP policy VLAN based on MAC addresses PC1 001E-9089-C65A S-switch GE 0/0/4 VLAN100 GE 0/0/2 DHCP Server 192. 105 . GE 0/0/4 connects to the DHCP server that belongs to VLAN 100. and configure frames from VLAN 100 to pass through GE 0/0/2 in untagged mode. Enable DHCP globally. the MAC address of PC2 is 00E0-4C84-0B44.. The MAC address of PC1 is 001E-9089-C65A. <Quidway> system-view [Quidway] dhcp enable [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] port hybrid pvid vlan 2 [Quidway-GigabitEthernet0/0/2] port hybrid untagged vlan 2 to 100 [Quidway-GigabitEthernet0/0/2] quit Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.IP Service 6 DHCP Policy VLAN Configuration Networking Requirements As shown in Figure 6-1. Configure GE 0/0/2 and GE 0/0/4 on the S5700 as a hybrid interface. on the S5700. Data Preparation To complete the configuration.168. GE 0/0/2 connects to PC1 and PC2 that access the network for the first time. you need the following data: l MAC address of the newly added host l Default VLAN ID of the interfaces on the S5700 Configuration Procedure 1. Determine to which VLAN the DHCP server belongs. Ltd. Configure DHCP policy VLAN based on MAC addresses.31.251/16 PC2 00E0-4C84-0B44 Configuration Roadmap The configuration roadmap is as follows: 1.Quidway S5700 Series Ethernet Switches Configuration Guide . # Enable DHCP globally.

# dhcp enable interface GigabitEthernet0/0/2 port hybrid pvid vlan 2 port hybrid untagged vlan 2 to 100 interface GigabitEthernet0/0/4 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # vlan 100 dhcp policy-vlan mac-address 001e-9089-c65a priority 5 dhcp policy-vlan mac-address 00e0-4c84-0b44 priority 5 # return 6. Verify the configuration.168.251: 192.IP Service 6 DHCP Policy VLAN Configuration [Quidway] interface gigabitethernet 0/0/4 [Quidway-GigabitEthernet0/0/4] port hybrid pvid vlan 100 [Quidway-GigabitEthernet0/0/4] port hybrid untagged vlan 100 [Quidway-GigabitEthernet0/0/4] quit # Configure DHCP policy VLAN based on MAC addresses.168. <Quidway> system-view [Quidway] vlan 100 [Quidway-vlan100] dhcp policy-vlan mac-address 001E-9089-C65A priority 5 [Quidway-vlan100] dhcp policy-vlan mac-address 00E0-4C84-0B44 priority 5 [Quidway-vlan100] quit 2.168.251 Pinging 192..31. on the S5700. C:###BOT_TEXT###gt;ping 192. ping the DHCP server from PC1 and PC2. Maximum = 126ms. Approximate round trip times in milli-seconds: Minimum = 2ms.168.Quidway S5700 Series Ethernet Switches Configuration Guide . Received = 4. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.31. Lost = 0 (0% loss). Average = 33ms Configuration Files The following lists the configuration file of the S5700. GE 0/0/1 connects to the DHCP server that belongs to VLAN 100.251 with 32 bytes of data: Reply Reply Reply Reply from from from from 192.31. Ltd.7. GE 0/0/2 connects to an access switch.31. # After PC1 and PC2 go online and obtain IP addresses.251: bytes=32 bytes=32 bytes=32 bytes=32 time=126ms TTL=255 time=2ms TTL=255 time=2ms TTL=255 time=2ms TTL=255 Ping statistics for 192.31. The ping operations are successful.31. the access switch connects to 10 hosts.251: Packets: Sent = 4.2 Example for Configuring DHCP Policy VLAN Based on Interfaces Networking Requirements As shown in Figure 6-2. 106 .168.168.168.251: 192.31.251: 192.

Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. <Quidway> system-view [Quidway] dhcp enable [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] port [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface gigabitethernet [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] port [Quidway-GigabitEthernet0/0/2] quit 2. 2.251/16 .. Enable DHCP globally. Issue 01 (2011-10-26) 0/0/1 hybrid pvid vlan 10 hybrid untagged vlan 10 to 100 0/0/2 hybrid pvid vlan 20 hybrid untagged vlan 20 to 100 # Configure DHCP policy VLAN based on interfaces..IP Service 6 DHCP Policy VLAN Configuration Figure 6-2 Networking for configuring DHCP policy VLAN based on interfaces S-switch GE 0/0/1 VLAN100 GE 0/0/2 DHCP Server 192. PC1 PC10 Configuration Roadmap The configuration roadmap is as follows: 1.Quidway S5700 Series Ethernet Switches Configuration Guide .. 3.168. Determine to which VLAN the DHCP server belongs. and configure frames from VLAN 100 to pass through GE 0/0/2 in untagged mode. Data Preparation To complete the configuration. you need the following data: l Number of the S5700 interface that connects to the downstream access switch l Default VLAN ID of the interfaces on the S5700 Configuration Procedure 1. Ltd. Configure DHCP policy VLAN based on interfaces. Configure GE 0/0/1 and GE 0/0/2 on the S5700 as hybrid interfaces. Configure the S5700.31. 107 . # Enable DHCP globally.

Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 6 DHCP Policy VLAN Configuration <Quidway> system-view [Quidway] vlan 100 [Quidway-vlan100] dhcp policy-vlan port gigabitethernet 0/0/2 priority 5 Configuration Files The following lists the configuration file of the S5700.. 108 . Ltd. # dhcp enable interface GigabitEthernet0/0/1 port hybrid pvid vlan 10 port hybrid untagged vlan 10 to 100 interface GigabitEthernet0/0/2 port hybrid pvid vlan 20 port hybrid untagged vlan 20 to 100 # vlan 100 dhcp policy-vlan port GigabitEthernet 0/0/2 priority 5 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.

Quidway S5700 Series Ethernet Switches Configuration Guide .3 Configuring DNS By configuring the DNS.IP Service 7 DNS Configuration 7 DNS Configuration About This Chapter By configuring the Domain Name System (DNS). 7.. you can enable the device to communicate with other devices. 7. you can enable network devices to communicate with other through their domain names. you can set up a mapping between a domain name and an IP address.2 DNS Supported by the S5700 Domain name resolution can be performed in either dynamic mode or static mode. you can set up a mapping between the domain name and IP address of a host through. In this manner. 109 . 7. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.5 Configuration Examples This section provides a configuration example of DNS. 7. Ltd. instead of complicated IP addresses. you can use domain names.1 Introduction to DNS After each host on the Internet is assigned a domain name. In this manner. which are easy to memorize and are of significance. 7.4 Maintaining DNS The operations of DNS maintenance include clearing DNS statistics and monitoring the DNS operating status.

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

7 DNS Configuration

7.1 Introduction to DNS
After each host on the Internet is assigned a domain name, you can set up a mapping between
the domain name and IP address of a host through. In this manner, you can use domain names,
which are easy to memorize and are of significance, instead of complicated IP addresses.
The Domain Name System (DNS) is a host naming mechanism provided by TCP/IP, with which
hosts can be named in the form of character string. This system assumes a hierarchical naming
structure. It designates a meaningful name for the device in the Internet and associates the name
with the IP address through a domain name resolution server. In this manner, you can use domain
names that are easy to remember instead of memorizing complex IP addresses.

7.2 DNS Supported by the S5700
Domain name resolution can be performed in either dynamic mode or static mode.
DNS has two resolution modes: dynamic DNS resolution and static DNS resolution. To resolve
a domain name, the system first uses static DNS resolution. If this mode fails, the system uses
dynamic DNS resolution. To improve resolution efficiency, you can put common domain names
in a static domain name resolution table.
The S5700 supports static resolution and dynamic resolution.

7.3 Configuring DNS
By configuring the DNS, you can set up a mapping between a domain name and an IP address.
In this manner, you can enable the device to communicate with other devices.

7.3.1 Establishing the Configuration Task
This section describes the applicable environment, pre-configuration tasks, data preparation, and
configuration procedure for configuring the DNS.

Applicable Environment
If local users accessing devices need to communicate with other devices by using domain names,
you can configure DNS on the device. An DNS entry is an mapping between a domain name
and an IP address.
If local users communicate with other devices hardly through the domain name or if the DNS
server is unavailable, configure static DNS. Prior to configuring static DNS, you must know the
mapping between the domain name and the IP address. In case of a change in the mapping, you
must modify the DNS entry manually.
You can configure dynamic DNS on the device if local users frequently use domain names for
communicating with other devices and the DNS server is available.

Pre-configuration Tasks
Before configuring DNS, complete the following tasks:
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

110

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

7 DNS Configuration

l

Configuring physical attributes of the interface and ensuring that the physical layer status
of the interface is Up

l

Configuring parameters of the link layer protocol of the interface and ensuring that the link
layer protocol status of the interface is Up

l

Configuring routes between the local device and the DNS server

l

Configuring the DNS server

Data Preparation
To configure DNS, you need the following data.
No.

Data

1

Domain name and the corresponding IP address in a static DNS entry

2

IP address of a DNS server

3

Domain name or the domain name list of a dynamic DNS entry

7.3.2 Configuring Static DNS Entries
You can create a table of mappings between domain names and IP addresses and add commonlyused domain names to this table. When a client needs to use the IP address corresponding to a
domain name, the client can search the table for the required IP address. This improves the
efficiency of domain name resolution.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
ip host host-name ip-address

The IP address corresponding to the host name is configured.
A host name corresponds to only one IP address. When you configure an IP address for a host
for several times, only the IP address configured at the latest is valid. To resolve several host
names, repeat Step 2.
You can configure a maximum of 50 static DNS entries.
----End

7.3.3 Configuring Dynamic DNS
To perform dynamic domain name resolution, you need a special domain name resolution server,
which runs a server program. This server provides mappings between domain names and IP
addresses and receives resolution requests from the client.
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

111

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

7 DNS Configuration

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
dns resolve

Dynamic domain name resolution is enabled.
Step 3 Run:
dns server ip-address

A DNS server is specified.
Step 4 (Optional) Run:
dns server source-ip source-ip-address

The IP address of the local device is specified.
The local device uses the specified IP address to communicate with the DNS server, which
ensures communication security.
Step 5 Run:
dns domain domain-name

The suffix of the domain name is added.
----End

Follow-up Procedure
The system supports the configuration of a maximum of 6 domain name servers, 1 source
address, and 10 domain name suffixes.
To configure more than one domain name server, repeat Step 3.
To configure more than one domain name suffix, repeat Step 5.

7.3.4 Checking the Configuration
You can view the configuration of the DNS.

Prerequisite
The configurations of the DNS function are complete.

Procedure
l

Run the display ip host command to check the information about the static DNS entry
table.

l

Run the display dns server command to check the configurations about DNS servers.

l

Run the display dns domain command to check the configurations about domain name
suffixes.

Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

112

1 2 www.1. So.huawei.1. If the list of suffixes of domain names is displayed. If information about the dynamic domain name cache is displayed.16.1 Run the display dns server command. If static DNS entries including the mappings between host names and IP addresses.1 192. it means that the configuration succeeds.16. confirm the action before you use this command.huawei.168.Quidway S5700 Series Ethernet Switches Configuration Guide . For example: <Quidway> display ip host Host Age Flags hw 0 static gww 0 static Address 10.4 Maintaining DNS The operations of DNS maintenance include clearing DNS statistics and monitoring the DNS operating status.1 TTL 3521 3000 Alias 7.1. it means that the configuration succeeds. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.com 91. 113 . If IP addresses of all domain servers are displayed.2 IPv6 Dns Servers : No configured servers. Run the display dns domain command. For example: <Quidway> display dns domain No Domain-name 1 com 2 net Run the display dns dynamic-host command.1 2 172. For example: <Quidway> display dns dynamic-host No Domain-name IpAddress 1 www. are displayed.1. 7.1. For example: <Quidway> display dns server IPv4 Dns Servers : Domain-server IpAddress 1 172.1.1.4. ----End Example Run the display ip host command.com.cn 87.IP Service l 7 DNS Configuration Run the display dns dynamic-host command to check the information about dynamic DNS entries in the domain name cache.1. it means that the configuration succeeds. Ltd.1.. Context CAUTION DNS entries cannot be restored after being cleared. it means that the configuration succeeds.1 Clearing DNS Entries This section describes DNS entry clearance through the reset command.

refer to the chapter "Information Center Configuration" in the Quidway S5700 Series Ethernet Switches Configuration Guide . For more information.4.IP Service 7 DNS Configuration Procedure Step 1 Run the reset dns dynamic-host command in the user view to clear dynamic DNS entries statistics in the domain name cache. For descriptions about the debugging commands..3 Debugging DNS This section describes DNS debugging through the debugging command.4.System Management. refer to the Quidway S5700 Series Ethernet Switches Debugging Reference. So after debugging. l Run the display dns domain command to check configurations about domain name suffixes. ----End 7. l Run the display dns dynamic-host command to check the information about dynamic DNS entries in the domain name cache. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you can run the following command in any view to check the operation of DNS. Procedure l Run the display ip host command to check the information about the static DNS entry table. 114 .Quidway S5700 Series Ethernet Switches Configuration Guide . run the undo debugging all command to disable it immediately. Ltd. Run the following debugging command in the user view to debug DNS and locate the fault. Context In routine maintenance.2 Monitoring Network Operation Status of DNS This section describes DNS operation monitoring through the display command. Context CAUTION Debugging affects the performance of the system. Procedure Step 1 Run the debugging dns command in the user view to debug dynamic DNS. l Run the display dns server command to check configurations about DNS servers. ----End 7.

2.IP Service 7 DNS Configuration 7.1. Data Preparation To complete the configuration.5.1. On Switch A.1.com. 115 . Configure static DNS entries.3/16 by using the domain name huawei.1/16 Loopback0 4. Figure 7-1 Networking diagram of DNS Loopback0 4.3/16 Configuration Roadmap The configuration roadmap is as follows: 1.1.1/16 GE0/0/2 VLANIF 101 3.1. being required to access the host 2.1. You need to configure domain name suffixes "com" and "net".1.1.1.1.1.1.1/16 GE0/0/1 VLANIF 100 DNS Server 2.2/16 3.1.1. configure static DNS entries of Switch B and Switch C so that Switch A can communicate with them by using domain names.1.Quidway S5700 Series Ethernet Switches Configuration Guide . you need the following data: l Domain names of Switch B and Switch C l IP address of the DNS server Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.2/32 SwitchC GE0/0/1 VLANIF 100 2. Configure suffixes of domain names.1. Switch A acts as a DNS client. Networking Requirements As shown in Figure 7-1.1. 4. Configure an IP address for the DNS server. 3.1.2/16 huawei. Enable DNS resolution.2/16 DNS Client SwitchA GE0/0/2 VLANIF 101 1.1.1 Example for Configuring DNS This section provides a configuration example of DNS.com 2.1.. Ltd.5 Configuration Examples This section provides a configuration example of DNS. 7.1/32 GE0/0/1 VLANIF 100 SwitchB 1.

1. # Run the ping huawei.1.com ping statistics --5 packet(s) transmitted 5 packet(s) received 0.3: bytes=56 data bytes.1 static 4. For procedures for configuring routes.1.2) PING huawei. Ltd.1.1.1. 116 . # Configure static DNS entries. <SwitchA> display ip host Host Age SwitchB 0 SwitchC 0 Flags Address static 4.1.3: bytes=56 Reply from 2.3. [SwitchA] dns domain com [SwitchA] quit NOTE To complete DNS resolution.1.1.1. press CTRL_C to break Sequence=1 ttl=126 time=6 ms Sequence=2 ttl=126 time=4 ms Sequence=3 ttl=126 time=4 ms Sequence=4 ttl=126 time=4 ms Sequence=5 ttl=126 time=4 ms --. [SwitchA] dns server 3.3: bytes=56 Reply from 2.1.1.00% packet loss round-trip min/avg/max = 4/4/6 ms # Run the display ip host command on Switch A to view static DNS entries.3: bytes=56 Reply from 2. Step 2 Verify the configuration. [SwitchA] dns resolve # Configure an IP address for the DNS server.1. including mappings between host names and IP addresses.1.IP Routing.1.IP Service l 7 DNS Configuration Suffixes of domain names Procedure Step 1 Configure Switch A.1.Quidway S5700 Series Ethernet Switches Configuration Guide . Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.com command on Switch A to ping the IP address 2.com (2.1.. <SwitchA> ping huawei.1.1. The ping succeeds.com Trying DNS server (3.2 # Run the display dns dynamic-host command on Switch A to view dynamic DNS entries in the domain name cache.1.1.2 # Configure a domain name suffix "net".1 [SwitchA] ip host SwitchC 4.1.3: bytes=56 Reply from 2. <SwitchA> system-view [SwitchA] ip host SwitchB 4. refer to the Quidway S5700 Series Ethernet Switches Configuration Guide .3): 56 Reply from 2.2 # Enable DNS resolution.1.1. [SwitchA] dns domain net # Configure a domain name suffix "com".1. configuring routes from Switch A to the DNS server is mandatory.huawei.1.

0 # interface vlanif101 ip address 1.. ----End Configuration Files l Configuration file of Switch A # sysname SwitchA # vlan batch 100 # ip host SwitchB 4.1.0.com 2.Quidway S5700 Series Ethernet Switches Configuration Guide .255.2 dns domain net dns domain com # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface vlanif100 ip address 1.2 # dns resolve dns server 3.0 network 1.1.1.0 # rip 1 network 1.0.0.1 255.IP Service <SwitchA> display dns dynamic-host No Domain-name IpAddress 1 huawei.0.1.1.1.2 255.1 ip host SwitchC 4.1.0 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1 255.255.0.0 # rip 1 network 2.0.1.0.255 # interface vlanif100 ip address 2.1.1 255.0 network 4.0.1.255.1.1.255. 117 .3 7 DNS Configuration TTL 3579 Alias NOTE TTL value in the above display indicates the lifetime of an entry.0.0.0 # return l Configuration file of Switch B # sysname SwitchB # vlan batch 100 101 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 101 port hybrid untagged vlan 101 # interface LoopBack0 ip address 4. It is in seconds.1.1.1.1. Ltd.0.255.

0 network 4. 118 .1.2 255. Ltd.1.0.0.255.2 255.0.0.255 # interface vlanif100 ip address 2.1 255.0.1.IP Service l 7 DNS Configuration Configuration file of Switch C # sysname SwitchC # vlan batch 100 101 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 101 port hybrid untagged vlan 101 # interface LoopBack0 ip address 4.0.Quidway S5700 Series Ethernet Switches Configuration Guide .1.0.1.1..255.0 # rip 1 network 2.0 network 3.255.0 # interface vlanif101 ip address 3.0.255.0 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.

ICMP Device Discovery messages. 8.IP Service 8 8 Basic Configurations of IPv6 Basic Configurations of IPv6 About This Chapter This chapter describes the basic concept and configurations of IPv6. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide . 119 . 8.1 Introduction to IPv6 This section describes the basic principle of IPv6. and ICMP Redirect messages. and introduces neighbor reachability detection..6 Configuration Examples This section provides a configuration example of IPv6 addresses. 8.2 IPv6 Features Supported by the S5700 The S5700 supports the IPv6 protocol suite and TCP6 protocol suite. 8.3 Configuring an IPv6 Address for an Interface Assigning an IPv6 address to a device on a network enables the device to communicate with the other devices on the network. 8. Detailed operations include deleting information about IPv6 operation and monitoring IPv6 operation. The Neighbor Discovery Protocol (NDP) replaces the Address Resolution Protocol (ARP). 8.4 Configuring IPv6 Neighbor Discovery IPv6 neighbor discovery (ND) is a packet transmission process to identify the relationship between neighboring nodes.5 Maintaining IPv6 This section describes how to maintain IPv6. Ltd.

and A to F.d" is a standard IPv4 address. IPv6 Features Supported by the S5700 The S5700 supports the setting of IPv6 addresses on a VLANIF. Ltd.Quidway S5700 Series Ethernet Switches Configuration Guide . 0 to 9.d. A link-local address can be set automatically or manually. After the command to enable the system to automatically set link-local addresses is run.. The packets whose source or destination address is the link-local address are forwarded on only the local link. Each "X" stands for 16 bits that are represented by four hexadecimal characters. "d. 120 .d. The 16 bits of each group are represented by four hexadecimal characters. equivalent to the network ID in the IPv4 address. also called IP Next Generation (IPng). is the standard network protocol of 2nd generation.IP Service 8 Basic Configurations of IPv6 8. Loopback and tunnel interface. Overview of IPv6 Addresses A 128-bit IPv6 address has two formats: l X:X:X:X:X:X:X:X In this format. l X:X:X:X:X:X:d.d. Basic Concepts Internet Protocol Version 6 (IPv6).d Addresses in this format are classified into two types: – IPv4-compatible IPv6 addresses – IPv4-mapped IPv6 addresses IPv4-compatible IPv6 addresses are used to configure the IPv6 over IPv4 tunnel. including link-local addresses and the global unicast addresses. Every "X" represents four hexadecimal characters. Each "d" stands for 8 bits that are represented by decimal numbers. equivalent to the host ID in the IPv4 address. The groups are separated by ":".d. l Interface identifier: 128-n bits.1 Introduction to IPv6 This section describes the basic principle of IPv6. the system automatically sets a link-local Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. a 128-bit IP address is divided into eight groups. The link-local address is used in the neighbor discovery protocol and used in the communication between the nodes on the local link in the stateless address auto-configuration. Each interface supports a maximum of 20 IPv6 addresses. An IPv6 address can be divided into two parts: l Network prefix: n bits. It is designed by Internet Engineering Task Force as an upgraded version of IPv4. The major feature of IPv6 is the larger address space: addresses in IPv6 are 128 bits long versus 32 bits in IPv4. that is. 8.2 IPv6 Features Supported by the S5700 The S5700 supports the IPv6 protocol suite and TCP6 protocol suite.

The ND protocol replaces the Address Resolution Protocol (ARP). ICMP Redirect message. the FIB needs to be downloaded to the I/O board. Ltd. A FIB contains the following information: l Destination address: indicates the network or host a packet is destined for. An FIB entry usually contains the destination address. Through the route management module. 121 . From the prefix length. route flag. l Interface: indicates the outgoing interface of the packet. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you can also add static routes into the FIB. l Nexthop: indicates the address of the next hop through which the packet reaches the destination. For a global unicast address. Guided by route management policies.Quidway S5700 Series Ethernet Switches Configuration Guide . prefix length. An S5700 forwards packets according to FIB entries. A global unicast address is equal to an IP address on the IPv4 public network. The control plane (FibAgent) is responsible for interacting with the RM module and downloading the FIB to the forwarding engine. The RIB is a base of the FIB.IP Service 8 Basic Configurations of IPv6 address for an interface. which is used to forward data on the public network and mandatory for communications between users. transport port. Automatically generated link-local addresses are recommended because link-local addresses are used only for communications between link-local nodes usually to satisfy the communication request of protocols and irrelevant to communications between users. The FIB mechanism consists of two parts: FIB agent (used on the control plane) and FIB container (used on the forwarding plane). complete 128 bits of the address have to be specified. l Timestamp: time when an FIB entry is generated. For a distributed system. Forwarding Information Base (FIB) contains minimum necessary information needed by an S5700 to forward packets. and ICMP Router Discovery message on an IPv4 network and provides other functions. next-hop address. l Prefix length: indicates the length of the destination address prefix. however.. only the network bits need to be specified. the S5700 obtains minimum necessary forwarding information from the RIB and adds the information to the FIB. The link-local address manually set must be a valid link-local address (FE80::/10). you can infer that the destination address is a network address or a host address. time stamp. An EUI-64 address is equivalent to a global unicast address in view of functions. Its host bits are transformed from the MAC address of the interface. IPv6 Neighbor Discovery IPv6 neighbor discovery (ND) is a packet transmission process to identify relationships between neighboring nodes. This brings about Routing Information Base (RIB). l Flag(s): identifies route characteristics. IPv6 FIB Connecting network topologies of different types needs the configuration of different routing protocols. For an EUI-64 address.

The difference is that only the network bits need to be specified for the EUI-64 address and the host bits are transformed from the MAC addresses of the interface while a complete 128-bit address need to be specified for the global unicast address.1 Establishing the Configuration Task This section describes the applicable environment. 8. Data 1 Number of the interface 2 Link-local address configured manually 3 Global unicast address and prefix length Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Issue 01 (2011-10-26) No. and configuration procedure for assigning an IPv6 address to an interface. Applicable Environment When a device communicates with an IPv6 device. you need the following data.. data preparation. pre-configuration tasks. Note that the prefix length of the network bits in an EUI-64 address must not be longer than 64 bits. An EUI-64 address has the same function as an global unicast address.Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 8 Basic Configurations of IPv6 8. However.3 Configuring an IPv6 Address for an Interface Assigning an IPv6 address to a device on a network enables the device to communicate with the other devices on the network.3. the IP addresses configured for one interface cannot be in the same network segment. complete the following tasks: l Configuring the physical features of the interface and ensuring that the status of the physical layer of the interface is Up l Configuring the link layer parameters for the interface and ensuring that the status of the link layer protocol on the interface is Up Data Preparation To configure IPv6 addresses for an interface. 122 . you need to configure IPv6 address for the interface. Ltd. Pre-configuration Tasks Before configuring IPv6 addresses. The EUI-64 address and the global unicast address can be configured simultaneously or alternatively.

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

8 Basic Configurations of IPv6

8.3.2 Enabling IPv6 Packet Forwarding Capability
You can perform other IPv6 configurations on an interface only when IPv6 is enabled in the
interface view. To enable IPv6 packet forwarding on an interface, you must configure IPv6 in
the system view.

Context
To enable a device to forward IPv6 packets, you must enable the IPv6 capability in both the
system view and the interface view. This is because:
l

If you run the ipv6 command only in the system view, only the IPv6 packet forwarding
capability is enabled on a device. The IPv6 function, however, is not enabled on the interface
and hence you cannot perform any IPv6 configurations.

l

If you run the ipv6 enable command only in the interface view, the IPv6 capability is
enabled only on an interface but the IPv6 protocol status on the interface is Down.
Therefore, the device cannot forward IPv6 data.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
ipv6

The IPv6 packet forwarding capability is enabled.
By default, the IPv6 packet forwarding capability is disabled.
To enable a device to forward IPv6 packets, you must run this command in the system view;
otherwise, the IPv6 protocol status of the interface is Down and the device cannot forward IPv6
packets although you enable IPv6 on the interface.
Step 3 Run:
interface interface-type interface-number

The view of the VLANIF interface to be enabled with the IPv6 capability is displayed.
Step 4 Run:
ipv6 enable

The IPv6 capability is enabled on the interface.
Before performing IPv6 configurations in the interface view, you must enable the IPv6 capability
in the interface view.
By default, the IPv6 capability is disabled on the interface.
----End

8.3.3 Configuring an IPv6 Link-Local Address for an Interface
The local address of a link is used in the neighbor discovery protocol, and in the communications
between nodes on the local end of the link in stateless address auto-configuration. The local
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

123

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

8 Basic Configurations of IPv6

address of a link is valid only for the link. A packet with a link-local address as the source or
destination address is forwarded only along the local link.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
interface interface-type interface-number

The interface view is displayed.
Step 3 Perform the following as required.
Run:
ipv6 address auto link-local

Auto generation of the IPv6 link-local address is enabled.
Or
Run:
ipv6 address ipv6-address link-local

The IPv6 link-local address is manually configured.
Besides configuring a link-local address through the preceding two commands, you can also
configure a global unicast IPv6 address for auto generating a link-local address. For details, see
Configuring an IPv6 Global Unicast Address for an Interface.
----End

8.3.4 Configuring an IPv6 Global Unicast Address for an Interface
A global unicast IP address is equal to an Internet IPv4 address and can be used for links whose
route prefixes can be aggregated. In this manner, routing entries can be reduced.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
interface vlanif vlan-id

The VLANIF interface view is displayed.
Step 3 Run:
ipv6 enable

You can enable the IPv6 capability.
Step 4 Run:
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

124

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

8 Basic Configurations of IPv6

ipv6 address { ipv6-address prefix-length | ipv6-address/prefix-length } or ipv6
address { ipv6-address prefix-length | ipv6-address/prefix-length } eui-64

The global unicast address is configured on the interface.
----End

8.3.5 Checking the Configuration
Prerequisite
All configurations of the IPv6 address are complete.

Procedure
l

Run the display ipv6 interface [ interface-type interface-number | brief ] command to
check IPv6 information about the interface.

l

Run the display ipv6 statistics command to view statistics on IPv6 packets.

----End

8.4 Configuring IPv6 Neighbor Discovery
IPv6 neighbor discovery (ND) is a packet transmission process to identify the relationship
between neighboring nodes. The Neighbor Discovery Protocol (NDP) replaces the Address
Resolution Protocol (ARP), ICMP Device Discovery messages, and ICMP Redirect messages,
and introduces neighbor reachability detection.

8.4.1 Establishing the Configuration Task
This section describes the applicable environment, pre-configuration tasks, data preparation, and
configuration procedure for IPv6 neighbor discovery.

Applicable Environment
Most of the ND configurations are implemented based on the interfaces.

Pre-configuration Tasks
Before configuring IPv6 neighbor discovery, complete the following tasks:
l

Configuring the physical features for the interface and ensuring that the status of the
physical layer of the interface is Up

l

Configuring link layer parameters for the interface

l

Configuring the IPv6 address for the interface

Data Preparation
To configure IPv6 neighbor discovery, you need the following data.
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

125

the device can send router advertisement messages. Step 3 Run: ipv6 enable You can enable the IPv6 capability. ----End 8. Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: interface vlanif vlan-id The VLANIF interface view is displayed. and life duration of RA messages 4 Flag bit of automatic configuration 5 Hop limit of ND 6 Sending times of DAD 7 Intervals for re-transmitting NS messages 8 NUD reachable time 9 Interface MTU 8. Step 4 Run one of the following commands as required: l To configure a static neighbor entry on a VLANIF interface.IP Service 8 Basic Configurations of IPv6 No. providing prefixes for hosts. Data 1 Number of interface which needs to be configured with IPv6 ND 2 IPv6 address and MAC address of the static neighbor 3 Intervals.4. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co..Quidway S5700 Series Ethernet Switches Configuration Guide . run the ipv6 neighbor ipv6address mac-address vid vlan-id interface-type interface-number command.3 Enabling RA Message Advertising After being enabled with switch advertisement.4.2 Configuring Static Neighbors By configuring a static neighbor. 126 . prefix. Ltd. you can obtain the mapping of the IPv6 address and MAC address of the neighbor.

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

8 Basic Configurations of IPv6

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
interface vlanif vlan-id

The VLANIF interface view is displayed.
Step 3 Run:
ipv6 enable

You can enable the IPv6 capability.
Step 4 Run:
undo ipv6 nd ra halt

The function of advertising RA messages is enabled.
----End

8.4.4 Setting the Interval for Advertising RA Messages
The device periodically sends router advertisement messages containing information such as
prefixes and flag bits.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
interface vlanif vlan-id

The VLANIF interface view is displayed.
Step 3 Run:
ipv6 enable

You can enable the IPv6 capability.
Step 4 Run:
ipv6 nd ra { max-interval maximum-interval | min-interval minimum-interval }

The interval for advertising RA messages is configured.
By default, the maximum interval is 600 seconds and the minimum interval is 200 seconds.
The maximum interval can not be shorter than the minimum interval.
When the maximum interval is less than 9 seconds, the minimum interval is set to the same value
as the maximum interval.
----End
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

127

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

8 Basic Configurations of IPv6

8.4.5 Enabling Stateful Auto Configuration
After being enabled with stateful auto-configuration, the host can obtain an IPv6 address through
stateful auto-configuration, for example, the DHCP server.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
interface vlanif vlan-id

The VLANIF interface view is displayed.
Step 3 Run:
ipv6 enable

You can enable the IPv6 capability.
Step 4 Run:
ipv6 nd autoconfig managed-address-flag

The flag bit for stateful auto configuration addresses is set.
If this flag is set, hosts use the stateful protocol for address auto-configuration in addition to any
addresses auto-configured using stateless address auto-configuration.
Step 5 Run:
ipv6 nd autoconfig other-flag

The flag bit for other stateful configurations is set.
When this flag is set, hosts use the stateful protocol for auto-configuration of other (non-address)
information.
----End

8.4.6 Configuring the Address Prefixes to Be Advertised
Nodes of the local links can perform address auto-configuration by using prefixes of these
addresses.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
interface vlanif vlan-id

The VLANIF interface view is displayed.
Step 3 Run:
ipv6 enable

Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

128

Quidway S5700 Series Ethernet Switches
Configuration Guide - IP Service

8 Basic Configurations of IPv6

You can enable the IPv6 capability.
Step 4 Run:
ipv6 nd ra prefix { ipv6-address ipv6-prefix-length | ipv6-prefix/ipv6-prefixlength } valid-lifetime preferred-lifetime [ no-autoconfig ] [ off-link ]

The prefix of RA messages is configured.
----End

8.4.7 Configuring Other Information to Be Advertised
A router advertisement message carries information such as the maximum number of hops,
prefix option, neighbor hold time, and keepalive time.

Context
Duplicate Address Detect (DAD) is a process of IPv6 automatic address configuration. You can
configure the number of DAD messages which are sent continuously.
Set the interval of sending Neighbor Solicitation (NS) messages on the device. By default, NS
re-transmitting time interval is 1000ms.
Neighbor Unreachability Detection (NUD) checks the reachability of neighbors. By default,
NUD value is 30000ms.
The MTU of the interface determines whether to fragment IP packets on the interface. Default
MTUs vary with interface types. The MTU on an GigabitEthernet interface defaults to be 1500
bytes.

Procedure
Step 1 Run:
system-view

The system view is displayed.
Step 2 Run:
ipv6 nd hop-limit limit

ND hop limit is configured.
The value of limit ranges from 1 to 255. By default, it is 64.
Step 3 Run:
interface vlanif vlan-id

The VLANIF interface view is displayed.
Step 4 Run:
ipv6 enable

You can enable the IPv6 capability.
Step 5 Run:
ipv6 nd ra router-lifetime ra-lifetime

The life duration of RA messages is configured.
Issue 01 (2011-10-26)

Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.

129

the interval must be less than or equal to the life duration. Procedure l Run the display ipv6 neighbors [ [ vid vlan-id ] interface-type interface-number ] command to check the neighbor information in the cache. the maximum interval is 600 seconds. 8.IP Service 8 Basic Configurations of IPv6 NOTE l When the ipv6 nd ra command is run to set the interval for advertising RA messages. Step 6 Run: ipv6 nd dad attempts value Times to send DAD messages are configured. l By default. l By default. Ltd. Prerequisite The configurations of the IPv6 neighbor discovery function are complete. <Quidway> display ipv6 neighbors VLANIF10 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. the life duration of RA messages is 1800 seconds. If the cache of the neighbor information contains neighbors' IPv6 addresses and the specified interfaces.. 130 . Step 8 Run: ipv6 nd nud reachable-time value The NUD reachable time is set. ----End Example Run the display ipv6 neighbors command. ----End Follow-up Procedure If the IPv6 MTU value is changed.Quidway S5700 Series Ethernet Switches Configuration Guide . it means that the configuration succeeds.8 Checking the Configuration You can view the configuration of IPv6 neighbor discovery. run the shutdown command and the undo shudown command orderly in the interface view to validate the configuration. If the prefix is configured.4. Step 7 Run: ipv6 nd ns retrans-timer interval The interval for re-sending NS messages is set. the duration is still 1800 seconds. Step 9 Run: ipv6 mtu mtu MTU of the interface is configured. l Run the display ipv6 interface [ interface-type interface-number | brief ] command to check the IPv6 information of an interface. and the minimum interval is 200 seconds.

5. 131 . So. l To clear statistics about TCP6. 8. l To clear statistics about UDP6. If information about the IPv6 address on the interface and interface status are displayed. Detailed operations include deleting information about IPv6 operation and monitoring IPv6 operation. run the reset ipv6 neighbors { all | dynamic | static | vid vlan-id [ interface-type interface-number] | interface-type interface-number } command in the user view. confirm the action before you run the command. Procedure l To clear statistics about processing IPv6 packets. <Quidway> display ipv6 interface brief *down: administratively down (l): loopback (s): spoofing Interface Physical VLANIF20 up up [IPv6 Address] 2030::101:101 VLANIF30 up up [IPv6 Address] 2001::1 LoopBack0 up [IPv6 Address] Unassigned Protocol up(s) 8. l To clear the IPv6 neighbor cache entry. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. run the reset ipv6 statistics command in the user view.IP Service 8 Basic Configurations of IPv6 -------------------------------------------------------IPv6 Address : 3003::2 Link-layer : 00e0-fc89-fe6e State : STALE Interface : VLANIF10 Age : 7 VPN name : vpn1 VLAN : IPv6 Address : FE80::2E0:FCFF:FE89:FE6E Link-layer : 00e0-fc89-fe6e State : STALE Interface : VLANIF10 Age : 7 VPN name : vpn1 VLAN : --------------------------------------------------------Total: 2 Dynamic: 2 Static: 0 Run the display ipv6 interface brief command. Ltd.. run the reset udp ipv6 statistics command in the user view.5 Maintaining IPv6 This section describes how to maintain IPv6. run the reset tcp ipv6 statistics command in the user view.1 Clearing IPv6 Statistics Context CAUTION Statistics cannot be restored after being cleared. it means that the configuration succeeds.Quidway S5700 Series Ethernet Switches Configuration Guide .

5..5.3 Debugging IPv6 This section describes IPv6 debugging through the debugging command. you can run the following commands in any view to display the running of IPv6. refer to the chapter "Information Center Configuration" in the S5700 Ethernet Switches Configuration Guide . l Run the display ipv6 statistics command in any view to view statistics on IPv6 packets. ----End 8.IP Service 8 Basic Configurations of IPv6 8. l Run the display udp ipv6 statistics command in any view to view statistics on UDP6 packets. Procedure l Run the display ipv6 interface [ interface-type interface-number | brief ] command in any view to view information about IPv6 on an interface. 132 . refer to the S5700 Ethernet Switches Debugging Reference. l Run the display ipv6 fib [ existing-slot-id ] command in any view to view information about FIB. Context CAUTION Debugging affects the performance of the system. For descriptions about the debugging commands. Run the following debugging commands in the user view to debug IPv6 and locate the fault. For the procedures of displaying the debugging information. So. Ltd. Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. l Run the display ipv6 neighbors [ [ vid vlan-id ] interface-type interface-number ] command in any view to view the cache content of neighbors.System Management.Quidway S5700 Series Ethernet Switches Configuration Guide . Procedure l Issue 01 (2011-10-26) Run the debugging ipv6 icmpv6 command in the user view to debug ICMPv6. l Run the display ipv6 socket [ socktype socket-type ] [ task-id socket-id ] command in any view to view information about the specified socket. execute the undo debugging all command to disable it immediately. l Run the display tcp ipv6 statistics command in any view to view statistics on TCP6 packets.2 Monitoring the Running Status of IPv6 Context In routine maintenance. l Run the display tcp ipv6 status command in any view to view the status of a TCP6 connection. after debugging.

IP Service 8 Basic Configurations of IPv6 l Run the debugging ipv6 nd command in the user view to debug IPv6 neighbors status and ND messages. Enable the IPv6 forwarding capability on the Switch. l Run the debugging ipv6 pathmtu command in the user view to debug PMTU. ----End 8. The GE 0/0/1 interfaces of Switch A and Switch B correspond to their VLANIF 100 interfaces. two Switches are connected through GE 0/0/1. l Run the debugging tcp ipv6 { event | packet } [ task-id task id | socket-id socket id ] command in the user view to debug TCP6. Networking Requirements As shown in Figure 8-1. The IPv6 global unicast addresses for the interfaces are 3001::1/64 and 3001::2/64.Quidway S5700 Series Ethernet Switches Configuration Guide . l Run the debugging udp ipv6 packet [ task-id task id | socket-id socket id ] command in the user view to debug UDP6. Ltd. You need to set IPv6 global unicast addresses for the VLANIF 100 interfaces and check the Layer 3 interconnection between them.. you need the following data. 8. Data Preparation To complete the configuration.6. l Run the debugging ipv6 packet [ error ] [ acl acl-number ] command in the user view to debug IPv6 packet.1 Example for Setting an IPv6 Address for an Interface This section provides a configuration example of IPv6 address for an interface. 2.6 Configuration Examples This section provides a configuration example of IPv6 addresses. Figure 8-1 Networking diagram for setting IPv6 addresses SwitchA SwitchB GE 0/0/1 VLANIF 100 3001::1/64 GE 0/0/1 VLANIF 100 3001::2/64 Configuration Roadmap The configuration roadmap is as follows: 1. 133 . Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Set IPv6 global unicast addresses for the interfaces.

134 . # Display information about the interface on Switch A. [SwitchA] vlan 100 [SwitchA-Vlan100] quit [SwitchA] interface gigabitethernet 0/0/1 [SwitchA-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [SwitchA-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [SwitchA-GigabitEthernet0/0/1] quit [SwitchA] interface vlanif 100 [SwitchA-Vlanif100] ipv6 enable [SwitchA-Vlanif100] ipv6 address 3001::1/64 [SwitchA-Vlanif100] quit # Configure Switch B.. Ltd. # Configure Switch A.IP Service l 8 Basic Configurations of IPv6 Global unicast address of an interface Procedure Step 1 Enable the IPv6 forwarding capability on the Switch. link-local address is FE80::218:20FF:FE00:83 [TENTATIVE] Global unicast address(es): 3001::1. <Quidway> system-view [Quidway] sysname SwitchA [SwitchA] ipv6 # Configure Switch B. # Configure Switch A. [SwitchB] vlan 100 [SwitchB-Vlan100] quit [SwitchB] interface gigabitethernet 0/0/1 [SwitchB-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [SwitchB-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [SwitchB-GigabitEthernet0/0/1] quit [SwitchB] interface vlanif 100 [SwitchB-Vlanif100] ipv6 enable [SwitchB-Vlanif100] ipv6 address 3001::2/64 [SwitchB-Vlanif100] quit Step 3 Verify the configuration. number of DAD attempts: 1 ND reachable time is 30000 milliseconds Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you can view the configured global unicast addresses. [SwitchA] display ipv6 interface vlanif 100 Vlanif100 current state : UP IPv6 protocol current state : UP IPv6 is enabled.Quidway S5700 Series Ethernet Switches Configuration Guide . subnet is 3001::/64 [TENTATIVE] Joined group address(es): FF02::1:FF00:1 FF02::1:FF00:83 FF02::2 FF02::1 MTU is 1500 bytes ND DAD is enabled. The status of the interface and the IPv6 protocol are Up. If the configuration succeeds. <Quidway> system-view [Quidway] sysname SwitchB [SwitchB] ipv6 Step 2 Configure the IPv6 global unicast address for the interfaces.

link-local address is FE80::2E0:FCFF:FE33:11 [TENTATIVE] Global unicast address(es): 3001::2.3001::2 ping statistics --5 packet(s) transmitted 5 packet(s) received 0. press CTRL_C to break Reply from FE80::2E0:FCFF:FE33:11 bytes=56 Sequence=1 hop limit=64 time = 7 ms Reply from FE80::2E0:FCFF:FE33:11 bytes=56 Sequence=2 hop limit=64 time = 3 ms Reply from FE80::2E0:FCFF:FE33:11 bytes=56 Sequence=3 hop limit=64 time = 3 ms Reply from FE80::2E0:FCFF:FE33:11 bytes=56 Sequence=4 hop limit=64 time = 3 ms Reply from FE80::2E0:FCFF:FE33:11 bytes=56 Sequence=5 hop limit=64 time = 3 ms --.. [SwitchA] ping ipv6 FE80::2E0:FCFF:FE33:11 -i vlanif 100 PING FE80::2E0:FCFF:FE33:11 : 56 data bytes. number of DAD attempts: 1 ND reachable time is 30000 milliseconds ND retransmit interval is 1000 milliseconds Hosts use stateless autoconfig for addresses # On Switch A.Quidway S5700 Series Ethernet Switches Configuration Guide . Note that you need to use the parameter -i to specify the interface of the link-local address. press CTRL_C to break Reply from 3001::2 bytes=56 Sequence=1 hop limit=64 time = 12 ms Reply from 3001::2 bytes=56 Sequence=2 hop limit=64 time = 3 ms Reply from 3001::2 bytes=56 Sequence=3 hop limit=64 time = 3 ms Reply from 3001::2 bytes=56 Sequence=4 hop limit=64 time = 3 ms Reply from 3001::2 bytes=56 Sequence=5 hop limit=64 time = 3 ms --.00% packet loss round-trip min/avg/max = 3/4/12 ms ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd.00% packet loss round-trip min/avg/max = 3/3/7 ms # On Switch A. 135 . subnet is 3001::/64 [TENTATIVE] Joined group address(es): FF02::1:FF00:2 FF02::1:FF33:11 FF02::2 FF02::1 MTU is 1500 bytes ND DAD is enabled. ping the link-local address of Switch B.IP Service 8 Basic Configurations of IPv6 ND retransmit interval is 1000 milliseconds Hosts use stateless autoconfig for addresses # Display information about the interface on Switch B.FE80::2E0:FCFF:FE33:11 ping statistics --5 packet(s) transmitted 5 packet(s) received 0. [SwitchB] display ipv6 interface vlanif 100 Vlanif100 current state : UP IPv6 protocol current state : UP IPv6 is enabled. [SwitchA] ping ipv6 3001::2 PING 3001::2 : 56 data bytes. ping the IPv6 global unicast address of Switch B.

IP Service 8 Basic Configurations of IPv6 Configuration Files l Configuration file of Switch A # sysname SwitchA # ipv6 # vlan 100 # interface Vlanif100 ipv6 enable ipv6 address 3001::1/64 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # return l Configuration file of Switch B # sysname SwitchB # ipv6 # vlan 100 # interface Vlanif100 ipv6 enable ipv6 address 3001::2/64 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide . 136 . Ltd..

. you can set up a mapping between a domain name and an IPv6 address.3 Configuring IPv6 DNS By configuring the IPv6 DNS.4 Maintaining IPv6 DNS This section describes how to maintain the IPv6 DNS. 137 . Detailed operations include deleting IPv6 DNS entries and monitoring IPv6 DNS operation.Quidway S5700 Series Ethernet Switches Configuration Guide . you can use domain names. instead of complicated IP addresses. which are easy to memorize and are of significance. In this manner. you can enable network devices to communicate with other through their domain names. 9. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 9. 9.1 Introduction to IPv6 DNS After each host on the Internet is assigned a domain name. In this manner.5 Configuration Examples This section provides several configuration examples of IPv6 DNS. 9.2 IPv6 DNS Supported by the S5700 IPv6 domain name resolution can be performed in either dynamic mode or static mode. 9. you can enable the device to communicate with other devices.IP Service 9 IPv6 DNS Configuration 9 IPv6 DNS Configuration About This Chapter By configuring the IPv6 Domain Name System (DNS). Ltd. you can set up mapping between the domain name and IP address of a host.

9. If users seldom use the domain name to access other devices. which are easy to memorize and are of significance.Quidway S5700 Series Ethernet Switches Configuration Guide . you can set up mapping between the domain name and IP address of a host. data preparation. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd. or if the DNS server is unavailable. and the DNS server is available. For configurations of IPv4 DNS.1 Establishing the Configuration Task This section describes the applicable environment. instead of complicated IP addresses. the system first uses static IPv6 DNS resolution. a dynamic DNS can be configured.IP Service 9 IPv6 DNS Configuration 9. 9. Data Preparation To configure IPv6 DNS. The dynamic DNS needs to be supported by a DNS server. refer to "DNS Configuration.3. IPv6 DNS has two resolution modes: dynamic IPv6 DNS resolution and static IPv6 DNS resolution.1 Introduction to IPv6 DNS After each host on the Internet is assigned a domain name. and manually modify the IPv6 DNS entry when the relation changes. you can put common domain names in a static domain name resolution table. In this manner. you need the following data. pre-configuration tasks. IPv6 domain name system (DNS) is similar to IPv4 DNS. To resolve a domain name. To configure a static IPv6 DNS." 9. the network administrator needs to know the relation between domain names and IPv6 addresses. The IPv6 DNS entries show the mapping between domain names and IPv6 addresses. 138 .. If the users need to use the domain name to access many devices.3 Configuring IPv6 DNS By configuring the IPv6 DNS. If this mode fails. configure the route between a local device and a DNS server. Applicable Environment DNS needs to be configured if the local users log on to a device using domain names to communicate with other devices. you can use domain names.2 IPv6 DNS Supported by the S5700 IPv6 domain name resolution can be performed in either dynamic mode or static mode. In this manner. a static DNS needs to be configured. Pre-configuration Tasks Before configuring IPv6 DNS. the system uses dynamic IPv6 DNS resolution. you can set up a mapping between a domain name and an IPv6 address. you can enable the device to communicate with other devices. and configuration procedure for configuring the IPv6 DNS. To improve resolution efficiency.

the interface name should also be configured with the IPv6 address. Figure 9-1 DNS server connecting IPv4 and IPv6 networks DNS IPv4 client DNS server IPv4 link Issue 01 (2011-10-26) DNS IPv6 client IPv6 link Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. 139 . Ltd.IP Service 9 IPv6 DNS Configuration No.3 Configuring the Dynamic IPv6 DNS Services To perform dynamic domain name resolution. Step 2 Run: ipv6 You can enable the IPv6 capability. such as ping this host. Context If the IPv6 DNS server is configured with a link-local address.2 Configuring a Static IPv6 DNS Entry You can create a table of mappings between domain names and IPv6 addresses and add common domain names to this table.Quidway S5700 Series Ethernet Switches Configuration Guide . you need a special domain name resolution server.3. Procedure Step 1 Run: system-view The system view is displayed.. Step 3 Run: ipv6 host host-name ipv6-address The host name and the corresponding IPv6 address are configured. the IPv6 address configured earliest is used when needing to find the host with the IPv6 address. ----End 9. the client can search the table for the required IPv6 address. If the same host is configured with IPv6 addresses for several times (the maximum times is 8 IPv6 addresses). This improves the efficiency of domain name resolution.3. This server provides mappings between domain names and IPv6 addresses and receives resolution requests from the client. When a client needs to use the IPv6 address corresponding to a domain name. Data 1 Domain name of the static IPv6 DNS entry and the corresponding IPv6 address 2 IPv6 address of the IPv6 DNS server 3 Domain name of the dynamic IPv6 DNS or the domain name list 9. which runs a server program.

Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. it appends a domain name to the host name following a ". For example. Prerequisite The configurations of the IPv6 DNS function are complete. the A query is first sent to the IPv4 server. the system then searches for "huawei.3. Step 2 Run: dns resolve The dynamic domain name resolution is enabled. Step 5 Run: dns domain domain-name The suffix of domain names is added.IP Service 9 IPv6 DNS Configuration CAUTION If multiple DNS servers are configured. ----End 9." and continues the DNS search. If both IPv4 and IPv6 servers are configured. Do as follows on the switch: Procedure Step 1 Run: system-view The system view is displayed. the servers are queried in the order of configuration till proper response is received. Step 4 Run: dns server ipv6 source-ip ipv6-address The IPv6 address of the local device is specified. You can configure some commonly used domain names like "com". if the search for the host name "huawei" fails. the local device uses the specified source IPv6 address to communicate with the IPv6 DNS server to ensure the security of check.net".4 Checking the Configuration You can view the configuration of the IPv6 DNS. The DNS domains are configured on a device and the domain names can be searched.Quidway S5700 Series Ethernet Switches Configuration Guide . and "net". After the source IPv6 address is specified for the local device. Ltd.com" or "huawei. If the DNS fails in searching for a host name.. Step 3 Run: dns server ipv6 ipv6-address [ interface-type interface-number ] The IPv6 DNS server is configured. 140 . while AAAA query packets are first sent to the IPv6 server.

125 IPv6 Dns Servers: Domain-server Ipv6Address 1 3001::2 2 FE80::2 (Interface Name) GigabitEthernet6/0/0 Run the display dns domain command. For example: <Quidway> display dns server IPv4 Dns Servers : Domain-server IpAddress 1 169.4 Maintaining IPv6 DNS This section describes how to maintain the IPv6 DNS. it means that the configuration succeeds. it means that the configuration succeeds. Ltd.65. 141 . For example: <Quidway> display dns domain No Domain-name 1 com 2 net Run the display dns ipv6 dynamic-host command.Quidway S5700 Series Ethernet Switches Configuration Guide . If the IPv6 addresses of all DNS servers are displayed. l Run the display dns server command to check the configuration of the DNS server. Detailed operations include deleting IPv6 DNS entries and monitoring IPv6 DNS operation. 9. If the static IPv6 DNS entries. l Run the display dns domain command to check the configuration of the suffix list of the domain name. If the suffixes of the domain names are displayed. it means that the configuration succeeds.IP Service 9 IPv6 DNS Configuration Procedure l Run the display ipv6 host command to check the static IPv6 DNS table. it means that the configuration succeeds.4. ----End Example Run the display ipv6 host command. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. including the host name and the IPv6 address..1 Clearing IPv6 DNS Entries This section describes IPv6 DNS entry clearance through the reset command. If information about the cache of the dynamic domain name is displayed. For example: <Quidway> display ipv6 host Host Age RTB 0 RTA 0 Flags static static IPv6Address (es) 20::1 20::2 Run the display dns server command. are displayed. l Run the display dns ipv6 dynamic-host command to check the cache of the dynamic domain name.254. For example: <Quidway> display dns ipv6 dynamic-host No Domain-name Ipv6address TTL 1 huawei6 3001::2 6 9.

Ltd. you can run the following commands in any view to check the operation of IPv6 DNS.. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.2 Monitoring Network Operation Status of IPv6 DNS This section describes IPv6 DNS operation monitoring through the display command.IP Service 9 IPv6 DNS Configuration Context CAUTION IPv6 DNS entries cannot be restored after being cleared. Context In routine maintenance. l Run: display dns server Configurations of the DNS server are checked.5 Configuration Examples This section provides several configuration examples of IPv6 DNS.5. 142 . Procedure l Run: display dns domain Domain names are checked. ----End 9.1 Example for Configuring IPv6 DNS This section provides a configuration example of IPv6 DNS. l Run: display ipv6 host The static DNS table is checked. l Run: display dns ipv6 dynamic-host Contents about the cache of the IPv6 dynamic domain names are checked. Procedure Step 1 Run the reset dns ipv6 dynamic-host command in the user view to clear dynamic IPv6 DNS entries statistics in the domain name cache. ----End 9. confirm the action before you use this command. 9.4. So.Quidway S5700 Series Ethernet Switches Configuration Guide .

Configure static IPv6 DNS entries. Data Preparation To complete the configuration. 3. 4. functioning as the IPv6 DNS client and working jointly whose IPv6 DNS server.1/32 GE0/0/1 VLANIF100 SwitchB 2001::1/64 DNS client SwitchA GE0/0/1 VLANIF101 2001::2/64 Loopback0 4.Quidway S5700 Series Ethernet Switches Configuration Guide .1. # Configure static IPv6 DNS entries. Figure 9-2 Networking diagram of IPv6 DNS configurations Loopback0 4. This ensures that Switch A can manage both the routers based on the domain names Switch B and Switch C.com 2002::1/64 Configuration Roadmap The configuration roadmap is as follows: 1. <SwitchA> system-view Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1.1. 2. Set the domain name suffix. 143 .1. Ltd. Switch A. Configure IPv6 address of the IPv6 DNS server. you need the following data: l Domain names of Switch B and Switch C l IPv6 address of the IPv6 DNS server l Domain name suffix Procedure Step 1 Configure Switch A.2/32 GE0/0/1 VLANIF101 2003::1/64 SwitchC GE0/0/2 VLANIF100 2002::2/64 GE0/0/2 VLANIF100 DNS server 2002::3/64 2003::2/64 huawei. Enable the DNS resolution function. can access the host with the IP address as 2002::1/64 based on the domain name huawei. the static IPv6 DNS entries of Switch B and Switch C are configured..com. On Switch A.IP Service 9 IPv6 DNS Configuration Networking Requirements As shown in Figure 9-2.

you also need to configure the route from Switch A to the IPv6 DNS server. ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. and the destination IP address is 2002::1.huawei. [SwitchA] dns resolve # Configure the IPv6 address of the IPv6 DNS server.IP Service 9 IPv6 DNS Configuration [SwitchA] ipv6 host RouterB 2001::2 [SwitchA] ipv6 host RouterC 2002::3 # Enable the DNS resolution function. You can view the mapping relationships between the host names in static IPv6 DNS entries and the IPv6 addresses.net".com".com 2002::1 TTL 3579 NOTE TTL in the command output indicates the life time of the entry.com Resolved Host ( huawei..com command on Switch A.com : 56 data bytes. <SwitchA> ping ipv6 huawei.com ping statistics --5 packet(s) transmitted 5 packet(s) received 0. <SwitchA> display ipv6 host Host Age SwitchB 0 SwitchC 0 Flags static static IPv6Address (es) 2001::2 2002::3 Run the display dns ipv6 dynamic-host command on SwitchA. 144 . [SwitchA] dns server ipv6 2003::2 # Set the domain name suffix to ". Step 2 Verify the configuration.IP Routing. see Configuration example of IP static route in the Quidway S5700 Series Ethernet Switches Configuration Guide . [SwitchA] dns domain net # Set the domain name suffix to ". You can find that the Ping operation succeeds.com -> 2002::1) PING huawei. [SwitchA] dns domain com [SwitchA] quit NOTE To resolve the domain name. For details of how to configure the route. # Run the ping ipv6 huawei. Ltd.Quidway S5700 Series Ethernet Switches Configuration Guide . press CTRL_C to Reply from 2002::1: bytes=56 Sequence=1 ttl=126 Reply from 2002::1: bytes=56 Sequence=2 ttl=126 Reply from 2002::1: bytes=56 Sequence=3 ttl=126 Reply from 2002::1: bytes=56 Sequence=4 ttl=126 Reply from 2002::1: bytes=56 Sequence=5 ttl=126 break time=6 time=4 time=4 time=4 time=4 ms ms ms ms ms --.00% packet loss round-trip min/avg/max = 4/4/6 ms # Run the display ipv6 host command on SwitchA. in seconds. <SwitchA> display dns ipv6 dynamic-host No Domain-name Ipv6address 1 huawei. You can view information about dynamic IPv6 DNS entries in the dynamic cache.

. 145 .IP Service 9 IPv6 DNS Configuration Configuration Files l Configuration file of Switch A l # sysname SwitchA # vlan batch 100 # ipv6 # ipv6 host SwitchB 2001::2 ipv6 host SwitchC 2002::3 # dns resolve dns server ipv6 2003::2 dns domain net dns domain com # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface vlanif100 ipv6 enable ipv6 address 2001::1/64 # return l Configuration file of Switch B # sysname SwitchB # vlan batch 100 101 # ipv6 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 101 port hybrid untagged vlan 101 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface vlanif100 ipv6 enable ipv6 address 2002::2/64 # interface vlanif101 ipv6 enable ipv6 address 2001::2/64 # return l Configuration file of Switch C # sysname SwitchC # vlan batch 100 101 # ipv6 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 101 port hybrid untagged vlan 101 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 100 port hybrid untagged vlan 100 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide . Ltd.

Quidway S5700 Series Ethernet Switches Configuration Guide .. 146 . Ltd.IP Service 9 IPv6 DNS Configuration # interface vlanif100 ipv6 enable ipv6 address 2002::3/64 # interface vlanif101 ipv6 enable ipv6 address 2003::1/64 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.

5 Configuration Examples This section provides configuration examples of IPv6 over IPv4 tunnel.. Ltd. 10.4 Configuring an IPv6 over IPv4 Tunnel You can interconnect IPv6 networks by using IPv4 networks.2 IPv6 over IPv4 Supported by the S5700 You can configure manual IPv6 over IPv4 tunnels or 6to4 tunnels to interconnect IPv6 networks. Context The S5706 does not support this function.IP Service 10 10 IPv6 over IPv4 Tunnel Configuration IPv6 over IPv4 Tunnel Configuration About This Chapter The IPv6 over IPv4 tunnel technology is developed to address the problem in the transition from IPv4 networks to IPv6 networks.Quidway S5700 Series Ethernet Switches Configuration Guide .3 Configuring IPv4/IPv6 Dual Stacks To establish an IPv6 over IPv4 tunnel. 10. 147 . 10. you need to configure both the IPv4 protocol suite and the IPv6 protocol suite on the devices where an IPv4 network borders an IPv6 network. 10. 10. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1 Introduction to IPv6 over IPv4 An IPv6 packet is transparently transmitted after being encapsulated into an IPv4 packet.

This technology creates tunnels over IPv4 networks to connect isolated IPv6 domains. such as Ethernet. Figure 10-1 shows a single stack structure and a dual stack structure. This is similar to the situation where the tunnel technology is used to deploy VPNs on the IP networks. The link layer in the above diagram is the Ethernet.2 IPv6 over IPv4 Supported by the S5700 You can configure manual IPv6 over IPv4 tunnels or 6to4 tunnels to interconnect IPv6 networks. To implement this tunnel. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. It is not economical to connect these isolated sites with private lines. IPv4 networks have been widely deployed while IPv6 domains are isolated and dispersed around the world. the IPv6 node maintains a dual-stack structure. 10.. 148 . Dual Stacks The simplest way for an IPv6 node to remain compatible with an IPv4 node is to reserve a complete IPv4 protocol stack. In this way. Ltd. Figure 10-1 Single stack and dual stack structures (Ethernet) IPv4 Application UDP TCP IPv4 Protocol ID: 0x0800 Ethernet IPv4/IPv6 Application TCP UDP IPv6 Protocol ID: Protocol ID: 0x86DD 0x0800 Ethernet IPv4 Stack Dual Stack The characteristics of the dual-stack structure are as follows: l Supported by multiple link layer protocols Multiple link layer protocols. support dual stacks. For an Ethernet frame with the protocol ID field value of 0x0800 indicates that the network layer has IPv4 packets. During the transition from the IPv4 Internet to the IPv6 Internet. The tunnel used to connect isolated IPv6 domains over IPv4 networks is called IPv6 over IPv4 tunnel.IP Service 10 IPv6 over IPv4 Tunnel Configuration 10.1 Introduction to IPv6 over IPv4 An IPv6 packet is transparently transmitted after being encapsulated into an IPv4 packet. enable IPv4/IPv6 dual stacks on the devices at the border of the IPv4 network and the IPv6 network. The usual method is tunnel technology. The ID field value of 0x86DD indicates that the network has IPv6 packets.Quidway S5700 Series Ethernet Switches Configuration Guide .

Figure 10-2 Schematic diagram of IPv6 over IPv4 tunnel Dual Stack Router IPv6 IPv4 Tunnel Dual Stack Router IPv6 IPv6 host IPv6 host IPv6 Header IPv6 Header IPv6 Data IPv4 Header IPv6 Header IPv6 Data IPv6 Data The virtual tunnel that transmits IPv6 packets between the border devices is called the IPv6 over IPv4 tunnel. 2. IPv6 over IPv4 Tunnel Figure 10-2 shows principles of the IPv6 over IPv4 tunnel technology. The upper application. removes the IPv4 packet header. Decapsulating the packet The peer border device decapsulates the packet. 149 ..IP Service l 10 IPv6 over IPv4 Tunnel Configuration Supported by multiple applications Multiple applications such as DNS. A manual tunnel is equivalent to a permanent link between two IPv6 networks over an IPv4 backbone network.Quidway S5700 Series Ethernet Switches Configuration Guide . adds an IPv4 packet header before the payload and encapsulates it into an IPv4 packet if it finds that the destination of the packet is not for itself. it prefers the IPv6 protocol stack rather than IPv4 to be the network layer protocol. Enabling IPv4/IPv6 dual stacks Enable IPv4/IPv6 dual stacks on the border device. Ltd. The source IPv4 address and destination IPv4 address of such a tunnel must be configured statically. the border device takes the received IPv6 packet as the payload. Transmitting the encapsulated packet In the IPv4 network. The common IPv6 over IPv4 tunnel modes include: l IPv6 over IPv4 manual tunnels l 6to4 tunnels l Intrasite Automatic Tunnel Addressing Protocol (ISATAP) tunnels IPv6 over IPv4 Manual Tunnel An IPv6 over IPv4 manual tunnel is set up by configuring the border devices of two tunnel ends. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. FTP and Telnet support dual stacks. However. It is the fixed channel for regular and secure communication between the two border devices. 1. 3. 4. can select TCP or UDP as its transport layer protocol. Tunnels can be classified according to their setup modes. and forwards the resulting IPv6 packet to the remote IPv6 network. such as DNS. the encapsulated packet is transmitted to the peer border device. Encapsulating IPv6 packets After receiving a packet from the IPv6 network.

IP Service 10 IPv6 over IPv4 Tunnel Configuration The manual tunnel can be used between isolated IPv6 networks. Figure 10-3 6to4 tunnel and 6to4 relay 6to4 Router 6to4 Network Site1 6to4 Router 6to4 Network Site2 SwitchB IPv4 Network SwitchA 6to4 Relay SwitchC IPv6 Internet Site3 When the host in Site1 accesses the host in Site2.Quidway S5700 Series Ethernet Switches Configuration Guide . Site1 and Site2 are 6to4 networks. the process concerned is as follows: Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. the IPv4 address is a globally unique one requested for an isolated IPv6 domain. The border device on both the ends of the 6to4 tunnel must support the IPv4 and the IPv6 dual protocol stacks at the same time. Switch A and Switch B are both 6to4 devices. Ltd. It can also be used between a border device and a host. 150 . In this case. The IPv4 address contained in the 6to4 address of the host or device in Site1 is the IPv4 address of the interface through which Switch A accesses the IPv4 network. the IPv4 address contained in the 6to4 address of the host or device in Site2 is the IPv4 address of the interface through which Switch B accesses the IPv4 network. Similarly. Both the subnet ID and the interface ID are allocated in the isolated IPv6 domains. namely the 6to4 address with the following format: 2002:IPv4 address: subnet ID:interface ID The prefix of the 6to4 address is 2002:IPv4 address with the length of 48 bits. and the latter is only a point-to-point connection. The 6to4 tunnel can automatically find another end of the tunnel. As shown in Figure 10-3. Of these. the devices of the 6to4 tunnel are not configured in pairs. You need not specify the IPv4-compatible IPv6 address for it. and hosts and devices in the 6to4 network are allocated with 6to4 addresses. The 6to4 tunnel can be configured on the border device between the isolated IPv6 network and the IPv4 network.. 6to4 Tunnel A 6to4 tunnel is a mechanism that connects several isolated IPv6 domains to each other over an IPv4 network. and that of the interface ID is 64 bits. The key difference between the 6to4 tunnel and the manual tunnel is that the former can be a point-to-multipoint connection. like the automatic tunnel. The 6to4 tunnel uses a kind of special IPv6 address. This IPv4 address must be configured on the IPv6/IPv4 border device's physical interface that is connected with the IPv4 network. the host and the device on both ends of the tunnel must support the IPv4 and the IPv6 protocol stacks. The length of the subnet ID is 16 bits. Hence.

IP Service 10 IPv6 over IPv4 Tunnel Configuration 1. Switch C decapsulates the IPv4 packet to obtain the previous IPv6 packet. 5. It encapsulates the message into the IPv4 packet. Issue 01 (2011-10-26) The IPv4/IPv6 host obtains its IPv6 address. As shown in Figure 10-3. The ISATAP device uses a router notification message to respond to the request. The IPv4/IPv6 host uses the link-local address in the ISATAP format to send a router request message to the ISATAP device. from which Switch A obtains the remote IPv4 address of the 6to4 tunnel. the IPv4 address embedded into the ISATAP address can be either a public network address or a private network address. The router notification message contains the ISATAP prefix. The ISATAP tunnel can be created between an ISATAP host and an ISATAP device. ISATAP Tunnel The ISATAP tunnel is used when the IPv4/IPv6 host in an IPv4 network accesses an IPv6 network. One side of the 6to4 relay device is connected to the native IPv6 network. To implement the communication between the 6to4 network and native IPv6 network. 4. As shown in Figure 10-4. The IPv6 packet is routed to Switch A. 3. the process for an IPv4/IPv6 host to obtain an IPv6 address is as follows: 1. The ISATAP device responds to the request message. Its structure is as follows: Prefix (64bit)::5EFE:IPv4-Address When the ISATAP tunnel is created (since the IPv4/IPv6 host and the ISATAP device are in a same IPv4 network). Switch A checks the destination address of the IPv6 packet and finds that the address is the 6to4 address. when the host in the 6to4 network accesses the IPv6 Internet. The above process implements the communication between the 6to4 networks. and sends the IPv6 packet to the destination host in the IPv6 Internet. A 6to4 tunnel is created between Switch A and Switch C.. The ISATAP format address is needed to create the ISATAP tunnel. The so-called native IPv6 network means that both its internal host and device are not configured with the 6to4 address. 151 . Ltd. Switch A forwards the IPv4 packet in the IPv4 network to Switch B. and its source address is the local IPv4 address of the tunnel. 3. 4. Switch A encapsulates this IPv6 packet into the IPv4 packet. and then sends the IPv6 packet to the destination host in Site2. The IPv6 packet is encapsulated into the IPv4 packet and is sent to Switch C. Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.Quidway S5700 Series Ethernet Switches Configuration Guide . the process concerned is as follows: 1. 3. 2. 2. The destination address of IPv4 packet header is the remote IPv4 address of the tunnel. the other side is connected to the IPv4 network and creates the 6to4 tunnel with the 6to4 device. The 6to4 relay device is the gateway between the 6to4 network and the native IPv6 network. which is manually configured on the device. Switch B decapsulates it to obtain the previous IPv6 packet. a 6to4 relay device is needed. The IPv4/IPv6 host sends a request message to a device. 2. The IPv6 packet is transmitted to Switch A.

1. 10. data preparation. and uses this address to access the IPv6 host.IP Service 10 IPv6 over IPv4 Tunnel Configuration The IPv4/IPv6 host obtains its own IPv6 address by combining the ISATAP prefix with 5EFE:IPv4-Address. Applicable Environment If a device has both IPv4 and IPv6 connections. Figure 10-4 ISATAP tunnel IPv4 Network ISATAP Tunnel IPv6 Network IPv6 Host ISATAP Switch IPv4/IPv6 Host 2.1 Establishing the Configuration Task This section describes the applicable environment.1 FE80::5EFE:0201:0101 3FFE::5EFE:0201:0101 The principle of an IPv4 or IPv6 host accessing an IPv6 network is as follows: 1.Quidway S5700 Series Ethernet Switches Configuration Guide . complete the following tasks: Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Enable the IPv6 packet forwarding capacity in the system view and configure an IPv4 address or IPv6 address on the corresponding interface.. The device can then forward IPv4 and IPv6 packets on the corresponding interface.1. The IPv4 or IPv6 host sends packets that are encapsulated in an IPv4 packet to the host in the IPv6 network. Ltd. you need to configure both the IPv4 protocol suite and the IPv6 protocol suite on the devices where an IPv4 network borders an IPv6 network. An ISATAP device decapsulates the IPv4 packet and sends the IPv6 packets to the IPv6 host. 10. pre-configuration tasks.3 Configuring IPv4/IPv6 Dual Stacks To establish an IPv6 over IPv4 tunnel. 2. 152 . Enabling the IPv4/IPv6 dual protocol stacks on the S5700 is a simple process. The IPv4 or IPv6 host in the IPv4 network obtains an IPv6 address based on the steps given above. Pre-configuration Tasks Before configuring IPv6 tunnels. and configuration procedure for the IPv4/IPv6 dual protocol stack.3. the IPv4/IPv6 dual protocol stacks need to be enabled on the device. 3.

Procedure Step 1 Run: system-view The system view is displayed. you need to enable IPv6 in both the interface view and the system view. 153 .3. Context To enable a device to forward IPv6 packets. you must enable the IPv6 capability in both the system view and the interface view. The interface on the device is not of the IPv6 capability and hence you cannot perform any IPv6 configurations. By default. Ltd. Step 2 Run: ipv6 The IPv6 packet forwarding capability is enabled. This is because: l If you run the ipv6 command only in the system view. No. the IPv6 packet forwarding capability is disabled.IP Service 10 IPv6 over IPv4 Tunnel Configuration l Configuring the physical parameters for the interface and ensuring that the status of the physical layer of the interface is Up l Configuring the link layer parameters for the interface Data Preparation To configure IPv4/IPv6 dual stacks.2 Enabling IPv6 Packet Forwarding To enable IPv6 packet forwarding.Quidway S5700 Series Ethernet Switches Configuration Guide . the IPv6 capability is enabled only on an interface but the IPv6 protocol status on the interface is Down and the device cannot forward IPv6 data. Data 1 Type and number of the interface connected with the IPv4 network 2 IPv4 address and mask of the interface connected with the IPv4 network 3 Type and number of the interface connected with the IPv6 network 4 IPv6 address and prefix of the interface connected with the IPv6 network 10.. To enable a device to forward IPv6 packets. the IPv6 protocol status on the interface is Down and the device cannot forward IPv6 packets although the interface is configured with an IPv6 address. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. only the IPv6 packet forwarding capability is enabled on a device. l If you run the ipv6 enable command only in the interface view. you need the following data. you must run this command in the system view. otherwise.

Quidway S5700 Series Ethernet Switches Configuration Guide . 154 .3 Configuring IPv4 and IPv6 Addresses for the Interface You need to configure IPv4 and IPv6 addresses separately on the IPv4 and IPv6 networks. you must enable the IPv6 capability in the interface view. the IPv6 capability is disabled on the interface. l Run: ipv6 address { ipv6-address | prefix-length } Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Ltd. l Run: ipv6 address auto link-local The link-local address is set to be automatically generated. Before performing IPv6 configurations in the interface view. By default. Procedure Step 1 Run: system-view The system view is displayed.3. l Run: ipv6 address ipv6-address link-local The link-local address of the interface is configured. Step 2 Run: interface vlanif vlan-id The interface view of the IPv4 network is displayed. Step 6 Perform the following configuration as required. Step 4 Run: quit Return to the system view. ----End 10.IP Service 10 IPv6 over IPv4 Tunnel Configuration Step 3 Run: interface vlanif vlan-id The view of the interface to be enabled with the IPv6 capability is displayed. Step 5 Run: interface vlanif vlan-id The interface view of the IPv6 network is displayed. Step 4 Run: ipv6 enable The IPv6 capability is enabled on the interface.. Step 3 Run: ip address ip-address { mask | mask-length } An IPv4 address is assigned to the interface.

----End 10..4 Configuring an IPv6 over IPv4 Tunnel You can interconnect IPv6 networks by using IPv4 networks.IP Service 10 IPv6 over IPv4 Tunnel Configuration The global unicast address is configured.3. and configuration procedure for configuring an IPv6 over IPv4 tunnel. Ltd. complete the following tasks: l Configuring the physical parameters for the interface and ensuring that the status of the physical layer of the interface is Up l Configuring the link layer protocol for the interface and ensuring that the status of the link layer protocol on the interface is Up l Configuring the IPv4/IPv6 dual-protocol stacks Data Preparation To configure an IPv6 over IPv4 tunnel. Procedure Step 1 Run the display ipv6 interface command to view the IPv6 information about the interface.4 Checking the Configuration Prerequisite All configurations are complete. Pre-configuration Tasks Before configuring an IPv6 over IPv4 tunnel. 155 . you need the following data. 10. ----End 10. configure an IPv6 over IPv4 tunnel on the border device of the IPv4 and IPv6 networks. 10. Applicable Environment To enable communication between two IPv6 networks over the IPv4 network. l Run: ipv6 address { ipv6-address | prefix-length } eui-64 The IPv6 EUI-64 address is configured.4.1 Establishing the Configuration Task This section describes the applicable environment.2 Enabling the Service Loopback Function on an Eth-Trunk Interface Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. data preparation.Quidway S5700 Series Ethernet Switches Configuration Guide .4. pre-configuration tasks.

Border devices can communicate with each other securely and regularly through manual IPv6 over IPv4 tunnels. Context Note the following when configuring an IPv6 over IPv4 manual tunnel: l Create only one interface enabled with the service loopback function on a device first. Procedure Step 1 Run: system-view The system view is displayed. l Only one interface enabled with the service loopback function is needed on a device. Step 4 Run: interface interface-type interface-number The interface view is displayed. you must create a tunnel interface.. The source address and destination address of a manual IPv6 over IPv4 tunnel on the same device must be unique. Step 5 Run: eth-trunk trunk-id The interface is added to the Eth-Trunk.4. note that the source address of the local tunnel end is the Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. and keep it in the Up state. l Before configuring other parameters of an IPv6 tunnel. Step 2 Run: interface eth-trunk trunk-id The Eth-Trunk interface view is displayed.IP Service 10 IPv6 over IPv4 Tunnel Configuration Context Before enabling the service loopback function on an Eth-Trunk interface. create an Eth-Trunk. The source address and destination address of a manual IPv6 over IPv4 tunnel are both manually assigned. add member interfaces to the Eth-Trunk and keep it in the Up state. Do as follows on the S5700. A manual IPv6 over IPv4 tunnel acts as a permanent link that crosses an IPv4 network and connects two IPv6 networks. ----End 10.Quidway S5700 Series Ethernet Switches Configuration Guide . note the following: l Before enabling the service loopback function. l You need to conduct the following configurations on the devices on both the ends of the tunnel. 156 . Ltd.3 Configuring an IPv6 over IPv4 Manual Tunnel A manual IPv6 over IPv4 tunnel is a P2P tunnel. Step 3 Run: service type tunnel The Eth-Trunk interface is enabled with the service loopback function. During the configuration.

. l To support dynamic routing protocol. you also need to configure the tunnel interface with a network address. NOTE The destination address of the tunnel can be the address of a physical interface or the address of a loopback interface. Procedure Step 1 Run: system-view The system view is displayed.Quidway S5700 Series Ethernet Switches Configuration Guide .4 Configuring a 6to4 Tunnel A 6to4 tunnel is a P2MP tunnel and can interconnect IPv6 networks which are isolated from each other through an IPv4 network. Step 5 Run: destination dest-ip-address The destination address of the tunnel is specified. ----End 10. Step 3 Run: tunnel-protocol ipv6-ipv4 The tunnel is specified be an IPv6 over IPv4 manual tunnel.IP Service 10 IPv6 over IPv4 Tunnel Configuration destination address set for the remote tunnel end. Ltd. Step 4 Run: source { ip-address | interface-type interface-number } The source address or source interface of the tunnel is specified. the destination address of the local tunnel end is the source address set for the remote tunnel end. 157 . Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Context Note the following when configuring a 6to4 tunnel: l Issue 01 (2011-10-26) Before configuring other parameters of the tunnel. Step 6 Run: ipv6 enable IPv6 is enabled on the interface.4. create a tunnel interface. Step 2 Run: interface tunnel interface-number The tunnel interface is created. Step 7 Run: ipv6 address { ipv6-address prefix-length | ipv6-address/prefix-length } The tunnel interface is configured with an IPv6 address.

is similar to the 6to4 tunnel. l On the border device.5 Configuring an ISATAP Tunnel Intra-site Automatic Tunnel Addressing Protocol (ISATAP) tunnels are used in the situation where IPv4/IPv6 hosts in an IPv4 network need to access an IPv6 network. ----End Follow-up Procedure The configuration of 6to4 relay needed to access the IPv6 network. l When configuring a 6to4 tunnel. Step 6 Run: ipv6 address { ipv6-address prefix-length | ipv6-address/prefix-length } The interface is configured with an IPv6 address. configure an IP address for the tunnel interface. Note that the source interface of the 6to4 tunnel must be unique. For the configuration example.Quidway S5700 Series Ethernet Switches Configuration Guide . An ISATAP tunnel can be established between an ISATAP host and an ISATAP device. and configure an IPv4 address on the interface that is connected with the IPv4 network. it is recommended to set the tunnel ID to be the same as the number of the physical interface." 10. Step 3 Run: tunnel-protocol ipv6-ipv4 6to4 The tunnel is specified as a 6to4 tunnel. Step 5 Run: ipv6 enable IPv6 is enabled on the interface. Step 2 Run: interface tunnel interface-number A tunnel interface is created. configure a 6to4 address on the interface that is connected with the 6to4 network. Ltd. Procedure Step 1 Run: system-view The system view is displayed. To make the tunnel support the routing protocol.. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. you need to specify only the source tunnel interface.4.IP Service 10 IPv6 over IPv4 Tunnel Configuration l When the specified source interface of the tunnel is a physical interface. The destination address of the tunnel is automatically obtained from the destination IP address field carried in the original IPv6 packet. see "Example for Configuring 6to4 Relay. 158 . Step 4 Run: source { ip-address | interface-type interface-number } The source address or source interface of the tunnel is specified.

IP Service 10 IPv6 over IPv4 Tunnel Configuration Context Note the following when configuring an ISATAP tunnel: l Before configuring other parameters of the tunnel. it is recommended to set the tunnel ID to be the same as the number of the physical interface. l When the specified source interface of the tunnel is a physical interface. Step 6 Run: undo ipv6 nd ra halt The device is allowed to advertise routes. Ltd. Step 3 Run: tunnel-protocol ipv6-ipv4 isatap The tunnel is specified as an ISATAP tunnel. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. The destination address of the tunnel is automatically obtained from the destination IP address field carried in the original IPv6 packet.6 Configuring Routes in the Tunnel Packets can be normally forwarded only when routes exist on both the source device and destination device of the tunnel. create a tunnel interface. l When configuring an ISATAP tunnel. Note that the source interface of the ISATAP tunnel must be unique. ----End 10.4. l The IPv6 address configured on the tunnel interface is an ISATAP address with a prefix length of 64 bits. Procedure Step 1 Run: system-view The system view is displayed. you need to specify only the source address of the tunnel. Context Configuring routes in the tunnel comprises configuring static routes and dynamic routes. Step 2 Run: interface tunnel interface-number A tunnel interface is created. 159 .. Step 4 Run: source { ip-address | interface-type interface-number } The source address or source interface of the tunnel is specified.Quidway S5700 Series Ethernet Switches Configuration Guide . Step 5 Run: ipv6 address { ipv6-address prefix-length | ipv6-address/prefix-length } The tunnel interface is configured with an IPv6 address.

Procedure Step 1 Run the display ipv6 interface tunnel interface-number command to view the IPv6 attribute of the tunnel interface. rather than the destination address of the tunnel).50.7 Checking the Configuration Prerequisite All configurations of the IPv6 over IPv4 tunnel are complete. Figure 10-5 Networking diagram for configuring the IPv6 over IPv4 tunnel manually GE 0/0/1 VLANIF 100 192.4.51. Networking Requirements As shown in Figure 10-5. you need to set the next hop address to the address of the interface on the remote end of the tunnel. you need to run the ipv6 route-static dest-ipv6-address prefix-length { interface-type interface-number nexthop-ipv6-address | nexthop-ipv6address } command to configure a route destined for the destination address (the destination address specified before the packet encapsulation. manually configure an IPv6 over IPv4 tunnel between Switch A and Switch C.5.2/24 SwitchB Dual stack SwitchA Issue 01 (2011-10-26) IPv4 network Dual stack IPv6 SwitchC Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.168. two IPv6 networks are connected to Switch B on the IPv4 backbone network respectively through Switch A and Switch C.51.168.5 Configuration Examples This section provides configuration examples of IPv6 over IPv4 tunnel.2/24 IPv6 GE 0/0/2 VLANIF 200 192. 160 . l You can enable dynamic routing protocol on the tunnel interface connected to the private networks and on the device interface. In addition.IP Service 10 IPv6 over IPv4 Tunnel Configuration l When configuring a static route. ----End 10. 10.1/24 GE 0/0/1 VLANIF 100 192. Ltd..168. 10.1 Example for Configuring an IPv6 over IPv4 Tunnel Manually This section provides a configuration example of manual IPv6 over IPv4 tunnel.168.50.1/24 GE 0/0/1 VLANIF 200 192. To enable the communication between two IPv6 networks.Quidway S5700 Series Ethernet Switches Configuration Guide .

Set the tunnel protocol to IPv6-IPv4.0 [SwitchA-Vlanif100] quit # Set the tunnel protocol to IPv6-IPv4. the interface does not transmit services. 161 . source address.168. and destination address of the tunnel Procedure Step 1 Configure Switch A. you need the following data. 3.255. [SwitchA] interface tunnel 0/0/1 [SwitchA-Tunnel0/0/1] tunnel-protocol ipv6-ipv4 # Bind the tunnel interface to the Eth-Trunk. # Enabling the service loopback function on an Eth-Trunk interface.2 255. <Quidway> system-view [Quidway] interface eth-trunk 1 [Quidway-Eth-Trunk1] service type tunnel [Quidway-Eth-Trunk1] quit [Quidway] interface gigabitethernet 0/0/3 [Quidway-GigabitEthernet0/0/3] eth-trunk 1 [Quidway-GigabitEthernet0/0/3] quit # Assign IP addresses to interfaces. and destination addresses for the tunnel interfaces.IP Service 10 IPv6 over IPv4 Tunnel Configuration Configuration Roadmap The configuration roadmap is as follows: 1.255. l IP addresses of interfaces l IPv6 address. <Quidway> system-view [Quidway] sysname SwitchA [SwitchA] ipv6 [SwitchA] vlan 100 [SwitchA-Vlan100] quit [SwitchA] interface gigabitethernet0/0/1 [SwitchA-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [SwitchA-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [SwitchA-GigabitEthernet0/0/1] quit [SwitchA] interface vlanif 100 [SwitchA-Vlanif100] ip address 192. CAUTION The interface must be idle. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.50. 2. source interface. Data Preparation To complete the configuration. Configure IPv6 addresses. Ltd. Set the IP address for the VLANIF interface mapping with the physical interface.Quidway S5700 Series Ethernet Switches Configuration Guide . Enabling the service loopback function on an Eth-Trunk interface.. 4. That is.

255.2 quit Configure a static route.1 Step 2 Configure Switch B.51.51. That is. CAUTION The interface must be idle.1 255.168. 162 ..1 255. <Quidway> system-view [Quidway] sysname SwitchB [SwitchB] ipv6 [SwitchB] vlan 100 [SwitchB-Vlan100] quit [SwitchB] vlan 200 [SwitchB-Vlan200] quit [SwitchB] interface gigabitethernet0/0/1 [SwitchB-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [SwitchB-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [SwitchB-GigabitEthernet0/0/1] quit [SwitchB] interface gigabitethernet0/0/2 [SwitchB-GigabitEthernet0/0/2] port hybrid pvid vlan 200 [SwitchB-GigabitEthernet0/0/2] port hybrid untagged vlan 200 [SwitchB-GigabitEthernet0/0/2] quit [SwitchB] interface vlanif 100 [SwitchB-Vlanif100] ip address 192. Ltd.255. [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] ipv6 enable ipv6 address 3001::1/64 source vlanif 100 destination 192.50. [SwitchA] ip route-static 192.255.51.Quidway S5700 Series Ethernet Switches Configuration Guide .168. <Quidway> system-view [Quidway] interface eth-trunk 1 [Quidway-Eth-Trunk1] service type tunnel [Quidway-Eth-Trunk1] quit [Quidway] interface gigabitethernet0/0/1 [Quidway-GigabitEthernet0/0/3] eth-trunk 1 [Quidway-GigabitEthernet0/0/3] quit Assign IP addresses to interfaces. the interface does not transmit services.2 255.255.0 [SwitchB-Vlanif100] quit [SwitchB] interface vlanif 200 [SwitchB-Vlanif200] ip address 192.0 192.50.255.168.168.255.IP Service 10 IPv6 over IPv4 Tunnel Configuration [SwitchA-Tunnel0/0/1] eth-trunk 1 # Set IPv6 address and destination address for the tunnel interface. # Enabling the service loopback function on an Eth-Trunk interface.0 [SwitchB-Vlanif200] quit Step 3 Configure Switch C. Assign IP addresses to interfaces.168. <Quidway> system-view [Quidway] sysname SwitchC [SwitchC] ipv6 [SwitchC] vlan 200 [SwitchC-Vlan200] quit [SwitchC] interface gigabitethernet0/0/1 [SwitchC-GigabitEthernet0/0/1] port hybrid pvid vlan 200 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.

2 ping statistics --5 packet(s) transmitted 5 packet(s) received 0. press Reply from 3001::1 bytes=56 Sequence=1 hop limit=255 Reply from 3001::1 bytes=56 Sequence=2 hop limit=255 Reply from 3001::1 bytes=56 Sequence=3 hop limit=255 Reply from 3001::1 bytes=56 Sequence=4 hop limit=255 Reply from 3001::1 bytes=56 Sequence=5 hop limit=255 --.2 255. Switch C can receive the response packet from Switch A. [SwitchC] ping ipv6 3001::1 PING 3001::1 : 56 data bytes.1 Step 4 Verify the configuration.255.Quidway S5700 Series Ethernet Switches Configuration Guide .50.. ping the IPv4 address of VLANIF 100 of Switch A.168. press CTRL_C to break Reply from 192. [SwitchC] ping 192.50.168.50.0 [SwitchC-Vlanif200] quit # Set the tunnel protocol to IPv6-IPv4.168.255.168.3001::1 ping statistics --5 packet(s) transmitted 5 packet(s) received 0.168. [SwitchC-Tunnel0/0/1] eth-trunk 1 # Set IPv6 address and destination address for the tunnel interface.2: bytes=56 Sequence=1 ttl=255 time=84 ms Reply from 192.2 quit # Configure a static route.168.50.2: bytes=56 Sequence=3 ttl=255 time=25 ms Reply from 192.2 PING 192. [SwitchC] ip route-static 192.168.50.255.2: bytes=56 Sequence=5 ttl=255 time=24 ms --.50.50. 163 . ping the IPv6 address of Tunnel 0/0/1 of Switch A. Switch C can receive the response packet from Switch A.00% packet loss round-trip min/avg/max = 26/26/28 ms CTRL_C to break time = 28 ms time = 27 ms time = 26 ms time = 27 ms time = 26 ms ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.50.168.0 192.2: bytes=56 Sequence=4 ttl=255 time=3 ms Reply from 192.2: bytes=56 Sequence=2 ttl=255 time=27 ms Reply from 192.2: 56 data bytes.192. # On Switch C.168.2 255.51.51.50.255. Ltd.168. [SwitchC-Tunnel0/0/1] [SwitchC-Tunnel0/0/1] [SwitchC-Tunnel0/0/1] [SwitchC-Tunnel0/0/1] [SwitchC-Tunnel0/0/1] ipv6 enable ipv6 address 3001::2/64 source vlanif 200 destination 192.168. [SwitchC] interface tunnel 0/0/1 [SwitchC-Tunnel0/0/1] tunnel-protocol ipv6-ipv4 # Bind the tunnel interface to the Eth-Trunk.IP Service 10 IPv6 over IPv4 Tunnel Configuration [SwitchC-GigabitEthernet0/0/1] port hybrid untagged vlan 200 [SwitchC-GigabitEthernet0/0/1] quit [SwitchC] interface vlanif 200 [SwitchC-Vlanif200] ip address 192.00% packet loss round-trip min/avg/max = 3/32/84 ms # On Switch C.50.168.

0 255.255.255.0 # interface Vlanif200 192. 164 .2 # ip route-static 192.255.0 # interface Eth-Trunk1 service type tunnel # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface GigabitEthernet0/0/3 eth-trunk 1 # interface Tunnel0/0/1 eth-trunk 1 ipv6 enable ipv6 address 3001::1/64 tunnel-protocol ipv6-ipv4 source Vlanif100 destination 192.0 192.1 # return l Configuration file of Switch B # sysname SwitchB # vlan batch 100 200 # interface Vlanif100 192.255.51.51.168.168..0 # interface Eth-Trunk1 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.168.IP Service 10 IPv6 over IPv4 Tunnel Configuration Configuration Files l Configuration file of Switch A # sysname SwitchA # ipv6 # vlan batch 100 # interface Vlanif100 192.1 255.50.168.Quidway S5700 Series Ethernet Switches Configuration Guide .51. Ltd.51.0 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 200 port hybrid untagged vlan 200 # return l Configuration file of Switch C # sysname SwitchC # ipv6 # vlan batch 200 # interface Vlanif200 192.255.2 255.50.255.255.168.255.168.1 255.168.2 255.255.50.255.

50.255.1.1 SwitchA IPv4 GE 0/0/2 VLANIF 200 2002:201:101:1::1/64 PC1 IPv6 Issue 01 (2011-10-26) Tunnel 0/0/1 2002:201:101::1/64 2002:201:101:1::2 GE 0/0/1 VLANIF 100 2.2 SwitchB GE 0/0/2 VLANIF 200 2002:201:102:1::1/64 Tunnel 0/0/1 2002:201:102::1/64 2002:201:102:1::2 Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.50.1..51. To enable communication between two 6to4 network hosts. Therefore. As shown in Figure 10-6.2 Example for Configuring a 6to4 Tunnel This section provides a configuration example of 6to4 tunnel. To enable communication between 6to4 networks.168.IP Service 10 IPv6 over IPv4 Tunnel Configuration service type tunnel # interface GigabitEthernet0/0/1 port hybrid pvid vlan 200 port hybrid untagged vlan 200 # interface GigabitEthernet0/0/3 eth-trunk 1 # interface Tunnel0/0/1 eth-trunk 1 ipv6 enable ipv6 address 3001::2/64 tunnel-protocol ipv6-ipv4 source Vlanif200 destination 192.1. which is in the format 2002:IPv4 address.Quidway S5700 Series Ethernet Switches Configuration Guide . the 6to4 address prefix of the 6to4 network where Switch A is located is 2002:0201:0101::. the IPv4 address of the interface through which Switch A is connected to the IPv4 network is 2.5. configure 6to4 addresses for the hosts on the 6to4 network. Figure 10-6 Networking diagram for configuring a 6to4 tunnel GE 0/0/1 VLANIF 100 2. A 6to4 address has a 48-bit prefix.1.1 # return 10. Networking Requirements As shown in Figure 10-6.168. PC2 IPv6 165 .168.0 192. Switch A and Switch B are connected to a 6to4 network and an IPv4 backbone network respectively.255. Ltd.0 255.2 # ip route-static 192.1.1. you need to manually configure an 6to4 tunnel between Switch A and Switch B.1.

IP Service 10 IPv6 over IPv4 Tunnel Configuration Configuration Roadmap The configuration roadmap is as follows: 1.1. Ltd. <Quidway> system-view [Quidway] sysname SwitchA [SwitchA] ipv6 [SwitchA] vlan batch 100 200 [SwitchA] interface gigabitethernet0/0/1 [SwitchA-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [SwitchA-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [SwitchA-GigabitEthernet0/0/1] quit [SwitchA] interface vlanif 100 [SwitchA-Vlanif100] ip address 2. # Enabling the service loopback function on an Eth-Trunk interface.Quidway S5700 Series Ethernet Switches Configuration Guide . Configure related routes on the Switch. That is. Configure the IPv4/IPv6 stack on the Switch. Configure a 6to4 tunnel on the Switch. [S5700-A] interface tunnel 0/0/1 [SwitchA-Tunnel0/0/1] eth-trunk 1 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. Data Preparation To complete the configuration. 4.1. you need the following data. 166 . the interface does not transmit services..1 8 [SwitchA-Vlanif100] quit [SwitchA] interface gigabitethernet0/0/2 [SwitchA-GigabitEthernet0/0/2] port hybrid pvid vlan 200 [SwitchA-GigabitEthernet0/0/2] port hybrid untagged vlan 200 [SwitchA-GigabitEthernet0/0/2] quit [SwitchA] interface vlanif 200 [SwitchA-Vlanif200] ipv6 enable [SwitchA-Vlanif200] ipv6 address 2002:0201:0101:1::1/64 [SwitchA-Vlanif200] quit # Configure a 6to4 tunnel. 3. 2. l IPv4 and IPv6 addresses of interfaces l Source tunnel interface Procedure Step 1 # Configure Switch A. Enabling the service loopback function on an Eth-Trunk interface. CAUTION The interface must be idle. <Quidway> system-view [Quidway] interface eth-trunk 1 [Quidway-Eth-Trunk1] service type tunnel [Quidway-Eth-Trunk1] quit [Quidway] interface gigabitethernet 0/0/3 [Quidway-GigabitEthernet0/0/3] eth-trunk 1 [Quidway-GigabitEthernet0/0/3] quit # Configure the IPv4/IPv6 stack.

IP Service [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] [SwitchA-Tunnel0/0/1] 10 IPv6 over IPv4 Tunnel Configuration tunnel-protocol ipv6-ipv4 6to4 ipv6 enable ipv6 address 2002:0201:0101::1/64 source vlanif 100 quit # Configure a route to other 6to4 networks. 167 .2 8 [SwitchB-Vlanif100] quit [SwitchB] interface gigabitethernet0/0/2 [SwitchB-GigabitEthernet0/0/2] port hybrid pvid vlan 200 [SwitchB-GigabitEthernet0/0/2] port hybrid untagged vlan 200 [SwitchB-GigabitEthernet0/0/2] quit [SwitchB] interface vlanif 200 [SwitchB-Vlanif200] ipv6 enable [SwitchB-Vlanif200] ipv6 address 2002:0201:0102:1::1/64 [SwitchB-Vlanif200] quit # Configure a 6to4 tunnel. Ltd. That is. [SwitchB] interface tunnel 0/0/1 [SwitchB-Tunnel0/0/1] eth-trunk 1 [SwitchB-Tunnel0/0/1] tunnel-protocol ipv6-ipv4 6to4 [SwitchB-Tunnel0/0/1] ipv6 enable [SwitchB-Tunnel0/0/1] ipv6 address 2002:0201:0102::1/64 [SwitchB-Tunnel0/0/1] source vlanif 100 [SwitchB-Tunnel0/0/1] quit # Configure a route to other 6to4 networks.1. <Quidway> system-view [Quidway] sysname SwitchB [SwitchB] ipv6 [SwitchB] vlan batch 100 200 [SwitchB] interface gigabitethernet0/0/1 [SwitchB-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [SwitchB-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [SwitchB-GigabitEthernet0/0/1] quit [SwitchB] interface vlanif 100 [SwitchB-Vlanif100] ip address 2. [SwitchB] ipv6 route-static 2002:: 16 tunnel 0/0/1 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. [SwitchA] ipv6 route-static 2002:: 16 tunnel 0/0/1 Step 2 # Configure Switch B. CAUTION The interface must be idle. the interface does not transmit services. <Quidway> system-view [Quidway] interface eth-trunk 1 [Quidway-Eth-Trunk1] service type tunnel [Quidway-Eth-Trunk1] quit [Quidway] interface gigabitethernet 0/0/3 [Quidway-GigabitEthernet0/0/3] eth-trunk 1 [Quidway-GigabitEthernet0/0/3] quit # Configure the IPv4/IPv6 stack.1..Quidway S5700 Series Ethernet Switches Configuration Guide . # Enabling the service loopback function on an Eth-Trunk interface.

1. # View the IPv6 status of Tunnel 0/0/1 on Switch A.2002:0201:0102:1::1 ping statistics --5 packet(s) transmitted 5 packet(s) received 0. For the configuration procedure. Switch A can receive the response packet from Switch B.1. Step 3 Verify the configuration. 168 .1 255. press CTRL_C to break Reply from 2002:201:102:1::1 bytes=56 Sequence=1 hop limit=255 time = 8 ms Reply from 2002:201:102:1::1 bytes=56 Sequence=2 hop limit=255 time = 25 ms Reply from 2002:201:102:1::1 bytes=56 Sequence=3 hop limit=255 time = 4 ms Reply from 2002:201:102:1::1 bytes=56 Sequence=4 hop limit=255 time = 5 ms Reply from 2002:201:102:1::1 bytes=56 Sequence=5 hop limit=255 time = 5 ms --. In this example.0 # interface Vlanif200 ipv6 enable ipv6 address 2002:201:101:1::1/64 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.IP Routing. Ltd.. [SwitchA] display ipv6 interface tunnel 0/0/1 Tunnel0/0/1 current state : UP IPv6 protocol current state : UP IPv6 is enabled.00% packet loss round-trip min/avg/max = 4/9/25 ms ----End Configuration Files l Configuration file of Switch A # sysname SwitchA # ipv6 # vlan batch 100 200 # interface Vlanif100 ip address 2.0.0. and you can find that the status is Up. the routing protocol needs to be configured on GigabitEthernet0/0/1 of SwitchA and SwitchB to ensure a reachable route between SwitchA and SwitchB. link-local address is FE80::201:101 [TENTATIVE] Global unicast address(es): 2002:201:101::1. [SwitchA] ping ipv6 2002:0201:0102:1::1 PING 2002:0201:0102:1::1 : 56 data bytes.Quidway S5700 Series Ethernet Switches Configuration Guide .IP Service 10 IPv6 over IPv4 Tunnel Configuration NOTE There must be a reachable route between SwitchA and SwitchB. subnet is 2002:201:101::/64 [TENTATIVE] Joined group address(es): FF02::1:FF01:101 FF02::1:FF00:1 FF02::2 FF02::1 MTU is 1500 bytes ND reachable time is 30000 milliseconds ND retransmit interval is 1000 milliseconds Hosts use stateless autoconfig for addresses # On Switch A. see the Quidway S5700 Series Ethernet Switches Configuration Guide . ping the 6to4 address of VLANIF 200 of Switch B.

1.0 # interface Vlanif200 ipv6 enable ipv6 address 2002:201:102:1::1/64 # interface Eth-Trunk1 service type tunnel # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 200 port hybrid untagged vlan 200 # interface GigabitEthernet0/0/3 eth-trunk 1 # interface Tunnel0/0/1 eth-trunk 1 ipv6 enable ipv6 address 2002:201:102:1::1/64 tunnel-protocol ipv6-ipv4 6to4 source vlanif100 # ipv6 route-static 2002:: 16 Tunnel 0/0/1 # return 10.1.2 255.0.IP Service 10 IPv6 over IPv4 Tunnel Configuration # interface Eth-Trunk1 service type tunnel # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 200 port hybrid untagged vlan 200 # GigabitEthernet0/0/13 eth-trunk 1 # interface Tunnel0/0/1 eth-trunk 1 ipv6 enable ipv6 address 2002:201:101:1::1/64 tunnel-protocol ipv6-ipv4 6to4 source vlanif100 # ipv6 route-static 2002:: 16 Tunnel 0/0/1 # return l Configuration file of Switch B # sysname SwitchB # ipv6 # vlan batch 100 200 # interface Vlanif100 ip address 2. Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.0. Ltd.Quidway S5700 Series Ethernet Switches Configuration Guide ..5.3 Example for Configuring an ISATAP Tunnel This section provides a configuration example of ISATAP tunnel. 169 .

4. 2. Data Preparation To complete the configuration. That is. Configure an ISATAP tunnel. Figure 10-7 Networking diagram of the ISATAP tunnel IPv6 network IPv6 host 3001::2 ISATAP IPv4 network Switch ISATAP host GE0/0/2 GE0/0/1 FE80::5EFE:0201:0102 VLANIF 100 VLANIF 200 2.1. 3. Ltd. an IPv6 host in the IPv4 network running the Windows XP system needs to access the IPv6 network through a border device.1/8 2001::5EFE:0201:0102 Configuration Roadmap The configuration roadmap is as follows: 1..1.1.1.2 3001::1/64 2. CAUTION The interface must be idle.Quidway S5700 Series Ethernet Switches Configuration Guide . # Enabling the service loopback function on an Eth-Trunk interface. you need the following data: l IPv4 or IPv6 addresses of interfaces l Source interface of the tunnel l VLAN that the physical interface of the Switch belongs to Procedure Step 1 Configure the ISATAP device. <Quidway> system-view [Quidway] interface eth-trunk 1 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.IP Service 10 IPv6 over IPv4 Tunnel Configuration Network Requirements As shown in Figure 10-7. Then you need to set up an ISATAP tunnel between the IPv6 host and the border device. 170 . Configure static routes from the IPv6 host to the ISATAP host. Enabling the service loopback function on an Eth-Trunk interface. the interface does not transmit services. Both the IPv6 host and the border device support ISATAP. Configure IPv4/IPv6 dual protocol stacks.

.Quidway S5700 Series Ethernet Switches Configuration Guide . You can run the ipv6 if command to view the interface corresponding to the automatic tunneling pseudo interface.1. Ltd. <Quidway> system-view [Quidway] ipv6 [Quidway] vlan batch 100 200 [Quidway] interface gigabitethernet 0/0/1 [Quidway-GigabitEthernet0/0/1] port hybrid pvid vlan 100 [Quidway-GigabitEthernet0/0/1] port hybrid untagged vlan 100 [Quidway-GigabitEthernet0/0/1] quit [Quidway] interface gigabitethernet 0/0/2 [Quidway-GigabitEthernet0/0/2] port hybrid pvid vlan 200 [Quidway-GigabitEthernet0/0/2] port hybrid untagged vlan 200 [Quidway-GigabitEthernet0/0/2] quit [Quidway] interface vlanif 100 [Quidway-Vlanif100] ipv6 enable [Quidway-Vlanif100] ipv6 address 3001::1/64 [Quidway-Vlanif100] quit [Quidway] interface vlanif 200 [Quidway-Vlanif200] ip address 2. [Quidway] display ipv6 interface tunnel 0/0/2 Tunnel0/0/2 current state : UP IPv6 protocol current state : UP IPv6 is enabled. 171 . C:###BOT_TEXT###gt; netsh interface ipv6 set route 2001::/64 3001::1 Step 4 Verify the configuration. [Quidway] interface tunnel 0/0/2 [Quidway-Tunnel0/0/2] eth-trunk 1 [Quidway-Tunnel0/0/2] tunnel-protocol ipv6-ipv4 isatap [Quidway-Tunnel0/0/2] ipv6 enable [Quidway-Tunnel0/0/2] ipv6 address 2001::/64 eui-64 [Quidway-Tunnel0/0/2] source vlanif 200 [Quidway-Tunnel0/0/2] undo ipv6 nd ra halt [Quidway-Tunnel0/0/2] quit Step 2 Configure the ISATAP host. NOTE The ISATAP host needs to run IPv6 and needs to be enabled with the IPv6 function. link-local address is FE80::5EFE:201:101 [TENTATIVE] Global unicast address(es): 2001::5EFE:201:101.1. (The pseudo interface number of the host is 2. Check the status of the Tunnel 0/0/2 on the ISATAP device and find it is Up.0 [Quidway-Vlanif200] quit # Configure an ISATAP tunnel.1 255. # Configure a static route on the IPv6 host to the border device.) C:###BOT_TEXT###gt; netsh interface ipv6 isatap set router 2.1.0.0. subnet is 2001::/64 [TENTATIVE] Joined group address(es): FF02::1:FF01:101 Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co. # Configure a static route to the border device.IP Service 10 IPv6 over IPv4 Tunnel Configuration [Quidway-Eth-Trunk1] service type tunnel [Quidway-Eth-Trunk1] quit [Quidway] interface gigabitethernet 0/0/3 [Quidway-GigabitEthernet0/0/3] eth-trunk 1 [Quidway-GigabitEthernet0/0/3] quit # Enable IPv4/IPv6 dual protocol stacks and configure an IP address for each interface. so hosts in different networks can communicate through the ISATAP tunnel.1 Step 3 Configure the IPv6 host.1.

1: Packets: Sent = 4. Maximum = 1ms.IP Service 10 IPv6 over IPv4 Tunnel Configuration FF02::2 FF02::1 MTU is 1500 bytes ND reachable time is 30000 milliseconds ND retransmit interval is 1000 milliseconds ND advertised reachable time is 0 milliseconds ND advertised retransmit interval is 0 milliseconds ND router advertisement max interval 600 seconds.2001::5efe:2. ping the global unicast IP address of the ISATAP device.1. [Quidway] ping ipv6 2001::5efe:2.1. Maximum = 0ms.1.2 ping statistics --5 packet(s) transmitted 5 packet(s) received 0.1: bytes=32 time=1ms Reply from 2001::5efe:2.1: bytes=32 time=1ms Ping statistics for 2001::5efe:2. C:###BOT_TEXT###gt; ping6 2001::5efe:2.1.2 : 56 data bytes. ping the global unicast IP address of the tunnel interface on the ISATAP host.1. Average = 1ms # The ISATAP host can ping through the IPv6 host. 172 . Received = 4. Ltd.1. min interval 200 seconds ND router advertisements live for 1800 seconds Hosts use stateless autoconfig for addresses # On the ISATAP device.1.1 Pinging 2001::5efe:2. Lost = 0 (0% loss).1.. Average = 0ms ----End Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.1. Received = 4.1.1.2 with 32 bytes of data: Reply from 2001::5efe:2. Lost = 0 (0% loss).1.1.1. Approximate round trip times in milli-seconds: Minimum = 0ms.1: bytes=32 time=1ms Reply from 2001::5efe:2.1.Quidway S5700 Series Ethernet Switches Configuration Guide . Approximate round trip times in milli-seconds: Minimum = 1ms.1. C:###BOT_TEXT###gt; ping6 3001::2 Pinging 3001::2 with 32 bytes of data: Reply Reply Reply Reply from from from from 3001::2: 3001::2: 3001::2: 3001::2: time<1ms time<1ms time<1ms time<1ms Ping statistics for 3001::2: Packets: Sent = 4.1.1.2 PING 2001::5efe:2.1.1.1: bytes=32 time=1ms Reply from 2001::5efe:2.00% packet loss round-trip min/avg/max = 2/2/4 ms # On the ISATAP host.1. press CTRL_C to break Reply from 2001::5EFE:201:102 bytes=56 Sequence=1 hop limit=64 time = 4 ms Reply from 2001::5EFE:201:102 bytes=56 Sequence=2 hop limit=64 time = 3 ms Reply from 2001::5EFE:201:102 bytes=56 Sequence=3 hop limit=64 time = 2 ms Reply from 2001::5EFE:201:102 bytes=56 Sequence=4 hop limit=64 time = 2 ms Reply from 2001::5EFE:201:102 bytes=56 Sequence=5 hop limit=64 time = 2 ms --.1 from 2001::5efe:2.1.

173 .1.0 # interface Eth-Trunk1 service-type tunnel # interface GigabitEthernet0/0/3 eth-trunk 1 # interface Tunnel0/0/2 eth-trunk 1 ipv6 enable ipv6 address 2001::/64 eui-64 undo ipv6 nd ra halt tunnel-protocol ipv6-ipv4 isatap source Vlanif200 # interface GigabitEthernet0/0/1 port hybrid pvid vlan 100 port hybrid untagged vlan 100 # interface GigabitEthernet0/0/2 port hybrid pvid vlan 200 port hybrid untagged vlan 200 # return Issue 01 (2011-10-26) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co.IP Service 10 IPv6 over IPv4 Tunnel Configuration Configuration Files The configuration file of the ISATAP device is as follows: # sysname Quidway # vlan batch 100 200 # ipv6 # interface Vlanif100 ipv6 enable ipv6 address 3001::1/64 # interface Vlanif200 ip address 2.Quidway S5700 Series Ethernet Switches Configuration Guide . Ltd.1 255..1.0.0.