unix su (进入Xbeam unix配置)

rsh extfw_1/intfw_1 (进入FW模块)

show run -flat

tcpdump -i exvt299 vlan and host 10.10.10.1 tcpdump -i exvt299 vlan and net 10.10.10.0

configure vap-group intfw xslinux_v5 load-balance-vap-list 1 2 3 4 5 6 7 8 9 10

configure vap-group intfw xslinux_v5 no rp-filter     #Disable RP filtering configure vap-group intfw xslinux_v5 ip-flow-rule intfw_lb     #Configure a default IP flow rule for the VAP group configure vap-group intfw xslinux_v5 ip-flow-rule intfw_lb action load-balance     #Set the IP flow rule action to load-balance traffic to all available VAP members configure vap-group intfw xslinux_v5 ip-flow-rule intfw_lb activate

configure vap-group v6fw xslinux_v5_64 configure vap-group v6fw xslinux_v5_64 max-load-count 1 configure vap-group v6fw xslinux_v5_64 ap-list ap7 ap8 configure vap-group v6fw xslinux_v5_64 load-balance-vap-list 1 2 3 4 5 6 7 8 9 10 configure vap-group v6fw xslinux_v5_64 no rp-filter configure vap-group v6fw xslinux_v5_64 enable-ipv6     #enable IPv6 support for the VAP group configure vap-group v6fw xslinux_v5_64 ip-flow-rule v6fw_lb configure vap-group v6fw xslinux_v5_64 ip-flow-rule v6fw_lb action load-balance configure vap-group v6fw xslinux_v5_64 ip-flow-rule v6fw_lb activate

configure vap-group v6fw xslinux_v5_64 non-ip-flow-rule ipv6_rule configure vap-group v6fw xslinux_v5_64 non-ip-flow-rule ipv6_rule encapsulation ethernet type 34525 configure vap-group v6fw xslinux_v5_64 non-ip-flow-rule ipv6_rule action pass-to-master configure vap-group v6fw xslinux_v5_64 non-ip-flow-rule ipv6_rule activate

configure circuit extfw_vlan_213 circuit-id 1025 domain 2 vap-group intfw   #Assign the VAP group to the management circuit configure circuit extfw_vlan_213 circuit-id 1025 domain 2 vap-group intfw default-egress-vlan-tag 213    #Assign a tag (egress) to the VLAN circuit, 给circuit加vlan tag. configure circuit extfw_vlan_213 circuit-id 1025 domain 2 vap-group intfw ip 10.10.1.81/24 10.10.1.255 increment-per-vap 10.10.1.83

configure circuit extfw_vlan_213 circuit-id 1025 domain 2 vap-group v6fw configure circuit extfw_vlan_213 circuit-id 1025 domain 2 vap-group v6fw default-egress-vlan-tag 213 configure circuit extfw_vlan_213 circuit-id 1025 domain 2 vap-group v6fw ip 10.10.1.61/24 10.10.1.255

configure circuit v6fw_vlan_66 circuit-id 1045 configure circuit v6fw_vlan_66 circuit-id 1045 device-name v6v66 configure circuit v6fw_vlan_66 circuit-id 1045 vap-group v6fw configure circuit v6fw_vlan_66 circuit-id 1045 vap-group v6fw default-egress-vlan-tag 66 configure circuit v6fw_vlan_66 circuit-id 1045 vap-group v6fw ip 172.17.0.1/27 172.17.0.31 configure circuit v6fw_vlan_66 circuit-id 1045 vap-group v6fw ip 172.17.0.1/27 172.17.0.31 alias 2001:4958:5:f001::1/64    #Assign IPv6 address configure interface ethernet 1/5     #Assign the circuit to an interface configure interface ethernet 1/5 logical ext_mgmt ingress-vlan-tag 213 213     #Add a logical with the ingress tag, logical name: ext_mgmt, tag 213, 给interface加vlan tag. configure interface ethernet 1/5 logical ext_mgmt ingress-vlan-tag 213 213 circuit extfw_vlan_213     #Assign the circuit to this interface, 合并interface和circuit. configure interface ethernet 1/9 configure interface ethernet 1/9 logical v6_vlan666 ingress-vlan-tag 666 666 configure interface ethernet 1/9 logical v6_vlan666 ingress-vlan-tag 666 666 circuit v6fw_vlan_666 configure interface ethernet 1/10 configure interface ethernet 1/10 logical v6_vlan66 ingress-vlan-tag 66 66 configure interface ethernet 1/10 logical v6_vlan66 ingress-vlan-tag 66 66 circuit v6fw_vlan_66

configure circuit extfw_sync circuit-id 1026 vap-group extfw configure circuit extfw_sync circuit-id 1026 vap-group extfw ip 2.2.2.1/24 2.2.2.255 increment-per-vap 2.2.2.3

configure interface-internal extfw_sync configure interface-internal extfw_sync logical-all extfw_sync configure interface-internal extfw_sync logical-all extfw_sync circuit extfw_sync   #assign the synchronization circuit to the interface.