WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies WSM User Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
12.07.2015 Views

Using OSPF2 In the New Policy Properties window, configure the policy to allow traffic from the IP or networkaddress of the router using RIP to the multicast address 224.0.0.9.3 Click OK.Using OSPFNoteSupport for this protocol is available only in Fireware® Pro.OSPF (Open Shortest Path First) is an interior router protocol used in larger networks. With OSPF, arouter that sees a change to its routing table or that detects a change in the network immediately sendsa multicast update to all other routers in the network. OSPF is different than RIP because:• OSPF sends only the part of the routing table that has changed in its transmission. RIP sends thefull routing table each time.• OSPF sends a multicast only when its information has changed. RIP sends the routing table every30 seconds.There are also a few specific things it is important to understand about OSFP:• If you have more than one OSPF area, one area must be area 0.0.0.0 (the backbone area).• All areas must be adjacent to the backbone area. If they are not, you must configure a virtual linkto the backbone area.OSPF daemon configurationTo create or modify a routing configuration file, here is a catalog of supported routing commands. Thesections must appear in the configuration file in the same order they appear in this table. You can alsouse the sample OSPF configuration file found in this FAQ:https://www.watchguard.com/support/advancedfaqs/fw_dynroute-ex.asp332 WatchGuard System Manager

Using OSPFSection Command DescriptionConfigure Interfaceip ospf authentication-key [PASSWORD]interface eth[N]ip ospf message-digest-key [KEY-ID] md5 [KEY]ip ospf cost [1-65535]ip ospf hello-interval [1-65535]ip ospf dead-interval [1-65535]ip ospf retransmit-interval [1-65535]ip ospf transmit-delay [1-3600]ip ospf priority [0-255]Configure OSPF Routing Daemonrouter ospfospf router-id [A.B.C.D]ospf rfc 1583compatibilityospf abr-type [cisco|ibm|shortcut|standard]passive interface eth[N]auto-cost reference bandwidth [0-429495]timers spf [0-4294967295][0-4294967295]Enable OSPF on a Network*The “Area” variable can be typed in two formats: [W.X.Y.Z]; or as an integer [Z].network [A.B.C.D/M] area [Z]Configure Properties for Backbone Area or Other Areas*The “Area” variable can be typed in two formats: [W.X.Y.Z]; or as an integer [Z].area [Z] range [A.B.C.D/M]area [Z] virtual-link [W.X.Y.Z]Set OSPF authentication passwordBegin section to set properties forinterfaceSet MD5 authentication key ID andkeySet link cost for the interface (seeOSP Interface Cost table below)Set interval to send hello packets;default is 10 secondsSet interval after last hello from aneighbor before declaring it down;default is 40 secondsSet interval between link-stateadvertisements (LSA)retransmissions; default is 5secondsSet time required to send LSAupdate; default is 1 secondSet router priority; high valueincreases eligibility to become thedesignated router (DR)Enable OSPF daemonSet router ID for OSPF manually;router will determine its own ID ifnot setEnable RFC 1583 compatibility (canlead to routing loops)More information about thiscommand can be found in draftietf-abr-alt-o5.txtDisable OSPF announcement oninterface eth[N]Set global cost (see OSPF cost tablebelow); do not use with “ip ospf[COST]” commandSet OSPF schedule delay and holdtimeAnnounce OSPF on networkA.B.C.D/M for area 0.0.0.ZCreate area 0.0.0.Z and set aclassful network for the area (rangeand interface network and masksettings should match)Set virtual link neighbor for area0.0.0.ZUser Guide 333

Using OSPFSection Command DescriptionConfigure Interfaceip ospf authentication-key [PASSWORD]interface eth[N]ip ospf message-digest-key [KEY-ID] md5 [KEY]ip ospf cost [1-65535]ip ospf hello-interval [1-65535]ip ospf dead-interval [1-65535]ip ospf retransmit-interval [1-65535]ip ospf transmit-delay [1-3600]ip ospf priority [0-255]Configure OSPF Routing Daemonrouter ospfospf router-id [A.B.C.D]ospf rfc 1583compatibilityospf abr-type [cisco|ibm|shortcut|standard]passive interface eth[N]auto-cost reference bandwidth [0-429495]timers spf [0-4294967295][0-4294967295]Enable OSPF on a Network*The “Area” variable can be typed in two formats: [W.X.Y.Z]; or as an integer [Z].network [A.B.C.D/M] area [Z]Configure Properties for Backbone Area or Other Areas*The “Area” variable can be typed in two formats: [W.X.Y.Z]; or as an integer [Z].area [Z] range [A.B.C.D/M]area [Z] virtual-link [W.X.Y.Z]Set OSPF authentication passwordBegin section to set properties forinterfaceSet MD5 authentication key ID andkeySet link cost for the interface (seeOSP Interface Cost table below)Set interval to send hello packets;default is 10 secondsSet interval after last hello from aneighbor before declaring it down;default is 40 secondsSet interval between link-stateadvertisements (LSA)retransmissions; default is 5secondsSet time required to send LSAupdate; default is 1 secondSet router priority; high valueincreases eligibility to become thedesignated router (DR)Enable OSPF daemonSet router ID for OSPF manually;router will determine its own ID ifnot setEnable RFC 1583 compatibility (canlead to routing loops)More information about thiscommand can be found in draftietf-abr-alt-o5.txtDisable OSPF announcement oninterface eth[N]Set global cost (see OSPF cost tablebelow); do not use with “ip ospf[COST]” commandSet OSPF schedule delay and holdtimeAnnounce OSPF on networkA.B.C.D/M for area 0.0.0.ZCreate area 0.0.0.Z and set aclassful network for the area (rangeand interface network and masksettings should match)Set virtual link neighbor for area0.0.0.Z<strong>User</strong> <strong>Guide</strong> 333

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!