Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Open Shortest Path First
111
213455-L, October 2005
6.
Enable OSPF on NSF-New York.
N
OTE
–
Make sure OSPF is enabled on the GRE tunnel interface (50.1.1.0) only. To avoid
infinite loops, do not configure OSPF on the 20.1.1.1/8 or 30.1.1.1/8 networks. For more
information, see
Avoiding loops in the GRE Tunnel on page 111
.
7.
Enable GRE 1 for OSPF on NSF-New York.
8.
Verifying OSPF Support.
Use the
/info/net/route/ospf
menu to verify OSPF support on your Switched
Firewall.
9.
Configure Check Point GUI for GRE support.
To support GRE on the firewall, you need special configurations and rules from Check Point.
For more information, refer to the document, 5100_OSPFWithGre.doc available on the Nortel
web site.
Avoiding loops in the GRE Tunnel
Design the network carefully to ensure that packets do not get into a loop in the GRE tunnel.
Refer to
Figure 56 on page 109
— if you enable OSPF on the GRE tunnel end points (interface
3) and GRE source-destination addresses on NSF-New York, the routes in the following table
are present on NSF-California.
>> #
/cfg/net/ospf
(Select OSPF menu )
>> OSPF#
ena y
(Enable OSPF)
>> #
/cfg/net/ospf/gre 1
(Select GRE 1 )
>> GRE 1#
ena y
(Enable GRE for OSPF routes)