Step
Configuring an IPv4-to-IPv6 source address
translation policy
AFT compares an IPv4 packet with IPv4-to-IPv6 source address translation policies in the following
order:
1.
IPv4-to-IPv6 source address static mappings.
2.
IPv4-to-IPv6 source address dynamic translation policies.
3.
The first NAT64 prefix.
To configure an IPv4-to-IPv6 source address translation policy:
Step
1.
Enter system view.
2.
Configure an
IPv4-to-IPv6 source
address translation
policy.
Configuring AFT logging
For security auditing, you can configure AFT logging to record AFT session information. AFT
sessions refer to sessions whose source and destination addresses have been translated by AFT.
To configure AFT logging:
Step
1.
Enter system view.
2.
Enable AFT logging.
3.
Enable AFT session
establishment logging.
4.
Enable AFT session removal
logging.
Command
number ipv4-acl-number { prefix-general
prefix-general prefix-length | prefix-ivi prefix-ivi
[ vpn-instance ipv6-vpn-instance-name ] } }
Command
system-view
•
Configure an IPv4-to-IPv6 source address static
mapping:
aft v4tov6 source ipv4-address [ vpn-instance
ipv4-vpn-instance-name ] ipv6-address
[ vpn-instance ipv6-vpn-instance-name ]
•
Configure an IPv4-to-IPv6 source address
dynamic translation policy:
aft v4tov6 source acl { name ipv4-acl-name
prefix-nat64 prefix-nat64 prefix-length
[ vpn-instance ipv6-vpn-instance-name ] |
number ipv4-acl-number { prefix-general
prefix-general prefix-length | prefix-nat64
prefix-nat64 prefix-length [ vpn-instance
ipv6-vpn-instance-name ] } }
•
Configure a NAT64 prefix:
aft prefix-nat64 prefix-nat64 prefix-length
Command
system-view
aft log enable
aft log flow-begin
aft log flow-end
448
Remarks
Remarks
N/A
By default, no
IPv4-to-IPv6 source
address translation
policies exist.
Remarks
N/A
By default, AFT logging is
disabled.
By default, AFT session
establishment logging is disabled.
By default, AFT session removal
logging is disabled.
Need help?
Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?