H3C MPLS VPN optionB

一、拓扑图

拓扑图.png

二、配置思路

option B方案的配置
1.RT1和RT2、RT3和RT4要形成MP-IBGP对等体关系

2、RT1和RT2、RT3和RT4的loopback接口没有直连,所有配置公网OSPF,宣告互连网段和loopback接口

3.RT1和RT2、RT3和RT4公网要配置MPLS LDP协议进行公网标签分配

4.配置私网的OSPF协议,基于实例的私网OSPF,创建VPN实例,把私网接口加入VPN实例

5.配置RT2和RT3的MP-EBGP对等体
[RT2]bgp 100
[RT2-bgp-default]peer 30.1.1.2 as-number 200
[RT2-bgp-default]address-family vpnv4
[RT2-bgp-default-vpnv4]peer 30.1.1.2 enable

7.RT2和RT3各自从RT1和RT4学习到私网路由时,RT2和RT3因为没有创建VPN实例,所以不能携带RT值,所有RT2和RT3可以强制携带RT值
[RT2]bgp 100
[RT2-bgp-default]address-family vpnv4
[RT2-bgp-default-vpnv4]undo policy vpn-target

8.RT2和RT3互连的线路需要保留公网标签的分配
[RT2]interface GigabitEthernet 0/1
[RT2-GigabitEthernet0/1]mpls enable
[RT2-GigabitEthernet0/1]mpls ldp enable
//RT3连接RT2接口也需要配置

9.私网路由相互引入

三、配置命令


<AR1>dis cu
#
 version 7.1.075, Alpha 7571
#
 sysname AR1
#
ip vpn-instance vpn1
 route-distinguisher 100:1
 vpn-target 100:1 import-extcommunity
 vpn-target 100:1 export-extcommunity
#
ip vpn-instance vpn2
 route-distinguisher 100:2
 vpn-target 100:2 import-extcommunity
 vpn-target 100:2 export-extcommunity
#
ospf 1 router-id 1.1.1.1
 area 0.0.0.0
  network 1.1.1.1 0.0.0.0
  network 20.1.1.0 0.0.0.255
#
ospf 2 router-id 1.1.1.1 vpn-instance vpn1
 import-route bgp
 area 0.0.0.0
  network 192.168.2.1 0.0.0.0
#
ospf 3 router-id 1.1.1.1 vpn-instance vpn2
 import-route bgp
 area 0.0.0.0
  network 192.168.7.0 0.0.0.255
#
 mpls lsr-id 1.1.1.1
#
 system-working-mode standard
 xbar load-single
 password-recovery enable
 lpu-type f-series
#
vlan 1
#
mpls ldp

interface LoopBack0
 ip address 1.1.1.1 255.255.255.255
#
interface GigabitEthernet0/0
 port link-mode route
 combo enable copper
 ip binding vpn-instance vpn1
 ip address 192.168.2.1 255.255.255.0
#
interface GigabitEthernet0/1
 port link-mode route
 combo enable copper
 ip address 20.1.1.1 255.255.255.0
 mpls enable
 mpls ldp enable
#
interface GigabitEthernet0/2
 port link-mode route
 combo enable copper
 ip binding vpn-instance vpn2
 ip address 192.168.7.1 255.255.255.0

bgp 100
 router-id 1.1.1.1
 peer 2.2.2.2 as-number 100
 peer 2.2.2.2 connect-interface LoopBack0
 #
 address-family vpnv4
  peer 2.2.2.2 enable
 #
 ip vpn-instance vpn1
  #
  address-family ipv4 unicast
   import-route ospf 2
 #
 ip vpn-instance vpn2
  #
  address-family ipv4 unicast
   import-route ospf 3

return
<AR2>dis cur
#
 version 7.1.075, Alpha 7571
#
 sysname AR2
#
ospf 1 router-id 2.2.2.2
 area 0.0.0.0
  network 2.2.2.2 0.0.0.0
  network 20.1.1.0 0.0.0.255
#
 mpls lsr-id 2.2.2.2

#
mpls ldp

#
interface LoopBack0
 ip address 2.2.2.2 255.255.255.255
#
interface GigabitEthernet0/0
 port link-mode route
 combo enable copper
 ip address 20.1.1.2 255.255.255.0
 mpls enable
 mpls ldp enable
#
interface GigabitEthernet0/1
 port link-mode route
 combo enable copper
 ip address 30.1.1.1 255.255.255.0
 mpls enable
 mpls ldp enable
#

bgp 100
 router-id 2.2.2.2
 peer 1.1.1.1 as-number 100
 peer 1.1.1.1 connect-interface LoopBack0
 peer 30.1.1.2 as-number 200
 #
 address-family vpnv4
  undo policy vpn-target
  peer 1.1.1.1 enable
  peer 30.1.1.2 enable
#

return


<AR3>dis cur
#
 version 7.1.075, Alpha 7571
#
 sysname AR3
#
ospf 1 router-id 3.3.3.3
 area 0.0.0.0
  network 3.3.3.3 0.0.0.0
  network 40.1.1.0 0.0.0.255
#
 mpls lsr-id 3.3.3.3
#

#
mpls ldp
#
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255
#
interface GigabitEthernet0/0
 port link-mode route
 combo enable copper
 ip address 30.1.1.2 255.255.255.0
 mpls enable
 mpls ldp enable
#
interface GigabitEthernet0/1
 port link-mode route
 combo enable copper
 ip address 40.1.1.1 255.255.255.0
 mpls enable
 mpls ldp enable

#
bgp 200
 peer 4.4.4.4 as-number 200
 peer 4.4.4.4 connect-interface LoopBack0
 peer 30.1.1.1 as-number 100
 #
 address-family vpnv4
  undo policy vpn-target
  peer 4.4.4.4 enable
  peer 30.1.1.1 enable
#
return


<AR4>dis cur
#
 version 7.1.075, Alpha 7571
#
 sysname AR4
#
ip vpn-instance vpn1
 route-distinguisher 100:1
 vpn-target 100:1 import-extcommunity
 vpn-target 100:1 export-extcommunity
#
ip vpn-instance vpn2
 route-distinguisher 100:2
 vpn-target 100:2 import-extcommunity
 vpn-target 100:2 export-extcommunity
#
ospf 1 router-id 4.4.4.4
 area 0.0.0.0
  network 4.4.4.4 0.0.0.0
  network 40.1.1.0 0.0.0.255
#
ospf 2 router-id 4.4.4.4 vpn-instance vpn1
 import-route bgp
 area 0.0.0.0
  network 192.168.3.1 0.0.0.0
#
ospf 3 router-id 4.4.4.4 vpn-instance vpn2
 import-route bgp
 area 0.0.0.0
  network 192.168.8.0 0.0.0.255
#
 mpls lsr-id 4.4.4.4
#
 system-working-mode standard
 xbar load-single
 password-recovery enable
 lpu-type f-series
#
vlan 1
#
mpls ldp
#
interface LoopBack0
 ip address 4.4.4.4 255.255.255.255
#
interface GigabitEthernet0/0
 port link-mode route
 combo enable copper
 ip address 40.1.1.2 255.255.255.0
 mpls enable
 mpls ldp enable
#
interface GigabitEthernet0/1
 port link-mode route
 combo enable copper
 ip binding vpn-instance vpn1
 ip address 192.168.3.1 255.255.255.0
#
interface GigabitEthernet0/2
 port link-mode route
 combo enable copper
 ip binding vpn-instance vpn2
 ip address 192.168.8.1 255.255.255.0
#
bgp 200
 peer 3.3.3.3 as-number 200
 peer 3.3.3.3 connect-interface LoopBack0
 #
 address-family vpnv4
  peer 3.3.3.3 enable
 #
 ip vpn-instance vpn1
  #
  address-family ipv4 unicast
   import-route ospf 2
 #
 ip vpn-instance vpn2
  #
  address-family ipv4 unicast
   import-route ospf 3
#
return

CE的配置只给出R5的,其他三个CE配置类似

<AR5>dis cur
#
 version 7.1.075, Alpha 7571
#
 sysname AR5
#
ospf 1 router-id 5.5.5.5
 area 0.0.0.0
  network 192.168.2.2 255.255.255.255
 network  5.5.5.5  0.0.0.0
#
interface LoopBack0
 ip address 5.5.5.5 255.255.255.255
#
interface GigabitEthernet0/0
 port link-mode route
 combo enable copper
 ip address 192.168.2.2 255.255.255.0
#

return
©著作权归作者所有,转载或内容合作请联系作者
【社区内容提示】社区部分内容疑似由AI辅助生成,浏览时请结合常识与多方信息审慎甄别。
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。

相关阅读更多精彩内容

友情链接更多精彩内容