Page 2
SecPro, SecPoint, SecEngine, SecPath, Comware, Secware, Storware, NQA, VVG, V G, V G, PSPT, XGbus, N-Bus, TiGem, InnoVision and HUASAN are trademarks of Hangzhou H3C Technologies Co., Ltd. All other trademarks that may be mentioned in this manual are the property of their respective owners.
Page 3
The H3C SR6600 documentation set includes 13 configuration guides, which describe the software features for the H3C SR6600 Routers and guide you through the software configuration procedures. These configuration guides also provide configuration examples to help you apply software features to different network scenarios.
Page 4
Represents a routing-capable device, such as a router or Layer 3 switch. Represents a generic switch, such as a Layer 2 or Layer 3 switch, or a router that supports Layer 2 forwarding and other Layer 2 features. About the H3C SR6600 Documentation Set The H3C SR6600 documentation set includes: Category...
Page 5
Obtaining Documentation You can access the most up-to-date H3C product documentation on the World Wide Web at http://www.h3c.com. Click the links on the top navigation bar to obtain different categories of product documentation: [Technical Support &...
Table of Contents 1 OAP Card Configuration ···························································································································1-1 OAP Card Overview································································································································1-1 Logging In to the Operating System of an OAP Card·············································································1-1 Logging In Through the Console Port of an OAP Card···································································1-1 Logging In Through the Management Ethernet Port of an OAP Card by Using SSH·····················1-1 Logging In Through the Internal Fast Ethernet Interface of an OAP Card by Using SSH ··············1-2 Redirecting to an OAP Card from the Router··················································································1-2 Resetting the System of an OAP Card ···································································································1-3...
H3C devices. The third party vendors can develop products with special functions. These products can be compatible with H3C devices as long as they conform to the OAA interface standards. Therefore, the functions of single network products can be expanded and the users can get more benefits.
Assign an IP address to the management Ethernet port of the OAP card, and make sure that the SSH client (the H3C device or a PC with the SSH client software installed) and the management Ethernet port can reach each other.
Use the command… Remarks Reset the system of an OAP card Required (on any SR6600 router but the oap reboot slot slot-number Available in user view SR6602) Reset of the OAP card may cause data loss and service interruption. Therefore, before resetting the OAP card, you need to save the configurations of the OAP card operating system and shut down the OAP card operating system to avoid service interruption and hardware data loss.
ACFP Configuration This chapter includes these sections: Introduction to ACFP Enabling the ACFP Server Configuring ACFP Client Enabling the ACFP Trap Function Displaying and Maintaining ACFP ACFP Configuration Example Introduction to ACFP Basic data communication networks comprise of routers and switches, which forward data packets. As data networks develop, more and more services run on them.
ACFP Architecture Figure 2-1 Diagram for ACFP architecture ACFP client ACFP server Interface-connecting component Routing/Switching Independent service component component As shown in Figure 2-1, the ACFP architecture consists of: Routing/switching component: As the main part of a routers and a switch, it performs complete router/switch functions and is also the core of user management control.
ACFP collaboration rules are generated on the ACFP client and sent to the ACFP server through the collaboration MIB or collaboration protocol. The SR6600 routers do not support rate restriction of the traffic on the ACFP server. ACFP Information Overview...
Page 13
ACFP client information ACFP client information contains the following: ACFP client identifier. It can be assigned by the ACFP server through a collaboration protocol or specified by the network administrator to ensure that each ACFP client has a unique client ID on the ACFP server.
Page 14
Monitoring rules: that is, to monitor, analyze, and process the packets to be sent to the ACFP client. The action types corresponding to monitoring rules are redirect and mirror. Filtering rules: that is, to determine which packets to deny and which packets to permit. The action types corresponding to filtering rules are deny and permit.
IP fragment: It indicates whether the packet is an IP packet fragment. Rate limit Row state You can use the collaboration policy to manage the collaboration rules that belong to it. Using ACFP For VLANID-context devices, after ACFP is enabled, some VLAN IDs must not be used by any other modules;...
To do… Use the command… Remarks Required Enable the ACFP server acfp server enable Disabled by default Configuring ACFP Client You need to configure the ACFP collaboration policy and ACFP collaboration rules on the ACFP client through MIB. The specific configuration depends on the service software used on the ACFP client. Enabling the ACFP Trap Function To make ACFP work normally, you must enable the router to send traps of the ACFP module.
For more information about the snmp-agent trap enable command, see SNMP in the Network Management and Monitoring Command Reference. Displaying and Maintaining ACFP To do… Use the command… Remarks Display the configuration display acfp server-info information of the ACFP server Display the configuration display acfp client-info [ client-id ] information of an ACFP client...
Figure 2-2 Network diagram for ACFP configuration ACFP client Router GE3/0/3 GE3/0/2 GE3/0/1 ACFP server Host A Host B Host C Host D 192.168.1.1/24 192.168.1.2/24 192.168.2.1/24 192.168.2.2/24 Configuration Procedure Configuring Router # Enable the ACFP server. <Router> system-view [Router] acfp server enable Configuring the collaboration policy and monitoring rules for the ACFP client through MIB # Configure the ACFP client.
Page 19
mask of the source IP address is 0.0.0.255 (by setting the node h3cAcfpRuleSrcIPMask), and the other parameters adopt the default values. Configure the ACFP rule through MIB browser to send information to Router, where the client index is 1, policy index is 2, the action is deny (by setting the node h3cAcfpRuleAction), the packets whose source IP address is 192.168.1.2 are matched (by setting the node h3cAcfpRuleSrcMAC), the wildcard mask of the source IP address mask is 0.0.0.255 (by setting the node h3cAcfpRuleSrcIPMask), and the other parameters adopt the default values.
ACSEI Configuration This chapter includes these sections: Introduction to ACSEI ACSEI Server Configuration Introduction to ACSEI As a private protocol, ACSEI provides a method for exchanging information between ACFP clients and ACFP server. It well supports Application Control Forwarding Protocol (ACFP) collaboration, ensuring valid information interaction between the ACFP clients and the ACFP server, so that the ACFP server and clients can cooperate to run a service.
Information interaction between the ACSEI server and ACSEI clients, including clock synchronization. Control of the ACSEI clients on the ACSEI server. For example, you can close ACSEI client, or restart ACSEI client on the ACSEI server. An ACSEI server can register multiple ACSEI clients. The maximum number of ACSEI clients that an ACSEI server allows to register is 10.
To do… Use the command… Remarks Enter system view system-view — Required Enable ACSEI server acsei server enable Disabled by default. Configuring the Clock Synchronization Timer Follow these steps to configure the clock synchronization timer: To do… Use the command… Remarks Enter system view system-view...
To do… Use the command… Remarks Enter system view system-view — Enable the ACSEI server function acsei server enable Required Enter ACSEI server view acsei server — Restart the specified ACSEI client acsei client reboot client-id Required Displaying and Maintaining ACSEI Server To do…...
Index Resetting the System of an OAP Card ACFP Configuration Example 2-11 ACFP Configuration Task List ACSEI Server Configuration 3-15 Configuring ACFP Client 2-10 Displaying and Maintaining ACFP 2-11 Enabling the ACFP Server Enabling the ACFP Trap Function 2-10 Introduction to ACFP Introduction to ACSEI 3-14 Logging In to the Operating System of an...
Need help?
Do you have a question about the SR6600 and is the answer not in the manual?
Questions and answers