一、实验要求以及实验拓扑图
二、IP的地址配置
R1:
R2:
R3:
R4:
R5:
R6:
R7:
三、公网基础环境配置
1、启用OSPF协议
在R2/3/4之间启用OSPF,使得整个外网互通。
R2:
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 2.2.2.2 0.0.0.0
network 23.1.1.1 0.0.0.0
R3:
ospf 1 router-id 3.3.3.3
area 0.0.0.0
network 3.3.3.3 0.0.0.0
network 23.1.1.2 0.0.0.0
network 34.1.1.1 0.0.0.0
R4:
ospf 1 router-id 4.4.4.4
area 0.0.0.0
network 4.4.4.4 0.0.0.0
network 34.1.1.2 0.0.0.0
network 47.1.1.1 0.0.0.0
2、BGP协议启用
在R2/4之间启用BGP协议。
R2 :
bgp 1
router-id 2.2.2.2
peer 4.4.4.4 as-number 1
peer 4.4.4.4 connect-interface LoopBack0
R4:
bgp 1
router-id 4.4.4.4
peer 2.2.2.2 as-number 1
peer 2.2.2.2 connect-interface LoopBack0
3、 MPLS(解决BGP黑洞问题)
R2:
[r2]mpls lsr-id 2.2.2.2
[r2]mpls
[r2-mpls]mpls ldp
[r2-mpls-ldp]q
[r2]interface GigabitEthernet 0/0/0
[r2-GigabitEthernet0/0/0]mpls
[r2-GigabitEthernet0/0/0]mpls ldp
R3:
[r3]mpls lsr-id 3.3.3.3
[r3]mpls
[r3-mpls]mpls ldp
[r3-GigabitEthernet0/0/0]mpls
[r3-GigabitEthernet0/0/0]mpls ldp
[r3-GigabitEthernet0/0/1]mpls
[r3-GigabitEthernet0/0/1]mpls ldp
R4:
[r4]mpls lsr-id 4.4.4
[r4]mpls
[r4-mpls]mpls ldp
[r4-GigabitEthernet0/0/1]mpls
[r4-GigabitEthernet0/0/1]mpls ldp
四、MPLS VPN
在R2/4上面分别做两个VPN。
A公司:
[r2]ip vpn-instance a
[r2-vpn-instance-a]ipv4-family
[r2-vpn-instance-a-af-ipv4]route-distinguisher 1:1
[r2-vpn-instance-a-af-ipv4]vpn-target 1:1
[r2]interface GigabitEthernet 0/0/1
[r2-GigabitEthernet0/0/1]ip binding vpn-instance a
[r2-GigabitEthernet0/0/1]ip address 192.168.2.2 24
[r4]ip vpn-instance b
[r4-vpn-instance-a]ipv4-family
[r4-vpn-instance-a-af-ipv4]route-distinguisher 1:1
[r4-vpn-instance-a-af-ipv4]vpn-target 1:1
[r4]interface GigabitEthernet 0/0/0
[r4-GigabitEthernet0/0/0]ip binding vpn-instance b
[r4-GigabitEthernet0/0/0]ip address 192.168.3.1 24
B公司:
[r2]ip vpn-instance c
[r2-vpn-instance-a]ipv4-family
[r2-vpn-instance-a-af-ipv4]route-distinguisher 6: 6
[r2-vpn-instance-a-af-ipv4]vpn-target 6:6
[r2]interface GigabitEthernet 0/0/2
[r2-GigabitEthernet0/0/2]ip binding vpn-instance c
[r2-GigabitEthernet0/0/2]ip address 192.168.3.2 24
[r4]ip vpn-instance d
[r4-vpn-instance-a]ipv4-family
[r4-vpn-instance-a-af-ipv4]route-distinguisher 6:6
[r4-vpn-instance-a-af-ipv4]vpn-target 6:6
[r4]interface GigabitEthernet 4/0/0
[r4-GigabitEthernet0/0/0]ip binding vpn-instance d
[r4-GigabitEthernet0/0/0]ip address 192.168.3.3 24
五、内网互通(A:静态 B:动态)
A公司:
R1:
[R1]ip route-static 192.168.3.0 255.255.255.0 192.168.2.2
[R1]ip route-static 192.168.4.0 255.255.255.0 192.168.2.2
R2:
[R2]ip route-static vpn-instance a 192.168.1.0 255.255.255.0 192.168.2.1
R4:
[R4]ip route-static vpn-instance b 192.168.4.0 255.255.255.0 192.168.3.2
R5:
[R5]ip route-static 192.168.1.0 255.255.255.0 192.168.3.1
[R5]ip route-static 192.168.2.0 255.255.255.0 192.168.3.1
B 公司
R2(RIP):
[R2]rip 1 vpn-instance c
[R2-rip-1]version 2
[R2-rip-1] network 192.168.2.0
R6:
[R6]rip 1 router-id 6.6.6.6
[R6-rip-1]version 2
[R6-rip-1]network 192.168.1.0
[R6-rip-1-0.0.0.0]network 192.168.2.0
R4 :
[R4]ospf 2 vpn-instance d
[R4-ospf-2]area 0.0.0.0
[R4-ospf-2]network 192.168.3.3 0.0.0.0
R7:
[R7]ospf 1 router-id 7.7.7.7
[R7-ospf-1]area 0
[R7-ospf-1-area-0.0.0.0] network 192.168.3.4 0.0.0.0
[R7-ospf-1-area-0.0.0.0]network 192.168.4.2 0.0.0.0
六、重发布
A公司:
R2(双向重发布):
[r2]bgp 1
[r2-bgp]ipv4 vpn-instance a
[r2-bgp-a]import-route direct
[r2-bgp-a]import-route static
R4:
[r4]bgp 1
[r4-bgp]ipv4 vpn-instance b
[r4-bgp-a]import-route direct
[r4-bgp-a]import-route static
B公司:
R2(双向):
[R2]bgp 1
[R2-bgp]ipv4-family vpn-instance c
[R2-bgp-c] import-route rip 1
[R2] rip 1 vpn-instance c
[R2-rip-1]import-route bgp
R4:
[R4]bgp 1
[R4-bgp]ipv4-family vpn-instance d
[R4-bgp-c] import-route ospf 2
[R4]ospf 2 vpn-instance d
[R4-ospf-2] import-route bgp
七、R7访问R2/3/4环回
R7:
ospf 2
area 0.0.0.0
network 47.1.1.2 0.0.0.0
八、测试