实验拓扑
实验目的
PC1和PC2、PC3和PC2、PC1和PC3之间实现互访。
实验思路
- 部署Underlay网络,创建桥接域绑定VNI和子接口
- 部署BGP的EVPN邻居以及通告IRB路由
- Edge上创建桥接域的EVPN实例和IP VPN实例,并创建绑定VBDIF接口
- 配置NVE接口,使用BGP协议建立VXLAN隧道
实验步骤
第一步:部署Underlay网络
Border
[BORDER]ospf 1 router-id 3.3.3.3
[BORDER-ospf-1]area 0
[BORDER-ospf-1-area-0.0.0.0]q
[BORDER-ospf-1]q
[BORDER]int g1/0/0
[BORDER-GE1/0/0]undo portswitch
[BORDER-GE1/0/0]undo shutdown
[BORDER-GE1/0/0]ip add 10.1.13.3 24
[BORDER-GE1/0/0]ospf en area 0
[BORDER-GE1/0/0]q
[BORDER]int g1/0/1
[BORDER-GE1/0/1]undo portswitch
[BORDER-GE1/0/1]undo shutdown
[BORDER-GE1/0/1]ip add 10.1.23.3 24
[BORDER-GE1/0/1]ospf en area 0
[BORDER-GE1/0/1]int loo0
[BORDER-LoopBack0]ip add 3.3.3.3 32
[BORDER-LoopBack0]ospf en area 0
[BORDER-LoopBack0]q
Edge1
[Edge1]ospf 1 router-id 1.1.1.1
[Edge1-ospf-1]area 0
[Edge1-ospf-1-area-0.0.0.0]q
[Edge1-ospf-1]q
[Edge1]int g1/0/0
[Edge1-GE1/0/0]undo portswitch
[Edge1-GE1/0/0]undo shutdown
[Edge1-GE1/0/0]ip add 10.1.13.1 24
[Edge1-GE1/0/0]ospf en area 0
[Edge1-GE1/0/0]q
[Edge1]int loo0
[Edge1-LoopBack0]ip add 1.1.1.1 32
[Edge1-LoopBack0]ospf en area 0
[Edge1-LoopBack0]q
[Edge1]bridge-domain 10
[Edge1-bd10]vni 10
[Edge1-vni10]q
[Edge1]bridge-domain 30
[Edge1-bd30]vni 30
[Edge1-vni30]q
[Edge1]int g1/0/2
[Edge1-GE1/0/2]undo shutdown
[Edge1-GE1/0/2]q
[Edge1]int g1/0/2.10 mode l2
[Edge1-GE1/0/2.10]encapsulation dot1q vid 10
[Edge1-GE1/0/2.10]bridge-domain 10
[Edge1-GE1/0/2.10]q
[Edge1]int g1/0/2.30 mode l2
[Edge1-GE1/0/2.30]encapsulation dot1q vid 30
[Edge1-GE1/0/2.30]bridge-domain 30
[Edge1-GE1/0/2.30]q
Edge2
[Edge2]ospf 1 router-id 2.2.2.2
[Edge2-ospf-1]area 0
[Edge2-ospf-1-area-0.0.0.0]q
[Edge2-ospf-1]q
[Edge2]int g1/0/1
[Edge2-GE1/0/1]undo portswitch
[Edge2-GE1/0/1]undo shutdown
[Edge2-GE1/0/1]ip add 10.1.23.2 24
[Edge2-GE1/0/1]ospf en area 0
[Edge2-GE1/0/1]q
[Edge2]int loo0
[Edge2-LoopBack0]ip add 2.2.2.2 32
[Edge2-LoopBack0]ospf en area 0
[Edge2-LoopBack0]q
[Edge2]bridge-domain 20
[Edge2-bd20]vni 20
[Edge2-vni20]q
[Edge2]int g1/0/2
[Edge2-GE1/0/2]undo shutdown
[Edge2-GE1/0/2]q
[Edge2]int g1/0/2.20 mode l2
[Edge2-GE1/0/2.20]encapsulation dot1q vid 20
[Edge2-GE1/0/2.20]bridge-domain 20
[Edge2-GE1/0/2.20]q
SW1
[SW1]vlan batch 10 30
[SW1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link trunk
[SW1-GigabitEthernet0/0/2]port trunk all vlan 10 30
[SW1-GigabitEthernet0/0/2]q
[SW1]int g0/0/20
[SW1-GigabitEthernet0/0/20]port link acc
[SW1-GigabitEthernet0/0/20]port default vlan 30
[SW1-GigabitEthernet0/0/20]q
[SW1]int g0/0/10
[SW1-GigabitEthernet0/0/10]port link acc
[SW1-GigabitEthernet0/0/10]port default vlan 10
[SW1-GigabitEthernet0/0/10]q
SW2
[SW2]vlan 20
[SW2-vlan20]q
[SW2]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link trunk
[SW2-GigabitEthernet0/0/2]port trunk all vlan 20
[SW2-GigabitEthernet0/0/2]q
[SW2]int g0/0/10
[SW2-GigabitEthernet0/0/10]port link access
[SW2-GigabitEthernet0/0/10]port default vlan 20
[SW2-GigabitEthernet0/0/10]q
第二步:部署BGP的EVPN邻居以及通告IRB路由
Border
[BORDER]evpn-overlay enable ### 开启EVPN功能
[BORDER]bgp 100
[BORDER-bgp]peer 1.1.1.1 as-number 100
[BORDER-bgp]peer 1.1.1.1 connect-interface loo0
[BORDER-bgp]peer 2.2.2.2 as-number 100
[BORDER-bgp]peer 2.2.2.2 connect-interface loo0
[BORDER-bgp]l2vpn-family evpn ### 进入evpn地址族
[BORDER-bgp-af-evpn]peer 1.1.1.1 enable
Warning: This operation will reset the peer session. Continue? [Y/N]:y
[BORDER-bgp-af-evpn]peer 1.1.1.1 reflect-client ### 配置Edge1为路由反射器客户端
[BORDER-bgp-af-evpn]peer 1.1.1.1 advertise irb ### 通告irb路由
[BORDER-bgp-af-evpn]peer 2.2.2.2 enable
Warning: This operation will reset the peer session. Continue? [Y/N]:y
[BORDER-bgp-af-evpn]peer 2.2.2.2 reflect-client ### 配置Edge1为路由反射器客户端
[BORDER-bgp-af-evpn]peer 2.2.2.2 advertise irb ### 通告irb路由
[BORDER-bgp-af-evpn]undo policy vpn-target ### 重要!!!RR上关闭VPN-target检查
[BORDER-bgp-af-evpn]q
[BORDER-bgp]q
Edge1
[Edge1]evpn-overlay enable
[Edge1]bgp 100
[Edge1-bgp]peer 3.3.3.3 as-number 100
[Edge1-bgp]peer 3.3.3.3 connect-interface loo0
[Edge1-bgp]l2vpn-family evpn
[Edge1-bgp-af-evpn]peer 3.3.3.3 enable
Warning: This operation will reset the peer session. Continue? [Y/N]:y
[Edge1-bgp-af-evpn]peer 3.3.3.3 advertise irb
[Edge1-bgp-af-evpn]q
[Edge1-bgp]q
Edge2
[Edge2]evpn-overlay enable
[Edge2]bgp 100
[Edge2-bgp]peer 3.3.3.3 as-number 100
[Edge2-bgp]peer 3.3.3.3 connect-interface loo0
[Edge2-bgp]l2vpn-family evpn
[Edge2-bgp-af-evpn]peer 3.3.3.3 enable
Warning: This operation will reset the peer session. Continue? [Y/N]:y
[Edge2-bgp-af-evpn]peer 3.3.3.3 advertise irb
[Edge2-bgp-af-evpn]q
[Edge2-bgp]q
验证:
[BORDER]dis bgp evpn peer
BGP local router ID : 10.1.13.3
Local AS number : 100
Total number of peers : 2
Peers in established state : 2
Peer V AS MsgRcvd MsgSent OutQ Up/Down State PrefRcv
1.1.1.1 4 100 5 5 0 00:01:24 Established 0
2.2.2.2 4 100 4 4 0 00:00:31 Established 0
第三步:Edge上创建桥接域的EVPN实例和IP VPN实例,并创建绑定VBDIF接口
Edge1
[Edge1]bridge-domain 10
[Edge1-bd10]vxlan vni 10
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-bd10]evpn
[Edge1-bd10-evpn]route-distinguisher 10:10
[Edge1-bd10-evpn]vpn-target 10:10
IVT Assignment result:
Info: VPN-Target assignment is successful.
EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-bd10-evpn]vpn-target 11:1 export-extcommunity ### 本段主机上线,转化为EVPN路由,更新给远端时,会携带BD下的ERT
[Edge1]bridge-domain 30
[Edge1-bd30]vxlan vni 30
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-bd30]evpn
[Edge1-bd30-evpn]route-distinguisher 30:30
[Edge1-bd30-evpn]vpn-target 10:10
IVT Assignment result:
Info: VPN-Target assignment is successful.
EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-bd30-evpn]vpn
[Edge1-bd30-evpn]vpn-target 11:1 export-extcommunity
EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-bd30-evpn]q
[Edge1-bd30]q
[Edge1]ip vpn-instance Edge1
[Edge1-vpn-instance-Edge1]route-distinguisher 10:10
[Edge1-vpn-instance-Edge1-af-ipv4]vpn-target 11:1 import-extcommunity evpn
IVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-vpn-instance-Edge1-af-ipv4]q
[Edge1-vpn-instance-Edge1]vxlan vni 1000
[Edge1-vpn-instance-Edge1]q
[Edge1]interface vbdif 10
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-Vbdif10]ip binding vpn-instance Edge1
Info: All IPv4 and IPv6 related configurations on this interface are removed.
[Edge1-Vbdif10]ip add 172.16.1.254 24
[Edge1-Vbdif10]arp collect host enable
[Edge1-Vbdif10]vxlan anycast-gateway enable
[Edge1-Vbdif10]q
[Edge1]interface vbdif 30
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-Vbdif30]ip binding vpn-instance Edge1
Info: All IPv4 and IPv6 related configurations on this interface are removed.
[Edge1-Vbdif30]ip add 172.16.3.254 24
[Edge1-Vbdif30]arp collect host enable
[Edge1-Vbdif30]vxlan anycast-gateway enable
[Edge1-Vbdif30]q
Edge2
[Edge2]bridge-domain 20
[Edge2-bd20]vxlan vni 20
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge2-bd20]evpn
[Edge2-bd20-evpn]route-distinguisher 20:20
[Edge2-bd20-evpn]vpn-target 10:10
IVT Assignment result:
Info: VPN-Target assignment is successful.
EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge2-bd20-evpn]vpn-target 11:1 export-extcommunity
EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge2-bd20-evpn]q
[Edge2-bd20]q
[Edge2]ip vpn-instance Edge2
[Edge2-vpn-instance-Edge2]route-distinguisher 10:10
[Edge2-vpn-instance-Edge2-af-ipv4]vpn-target 11:1 import-extcommunity evpn
IVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge2-vpn-instance-Edge2-af-ipv4]q
[Edge2-vpn-instance-Edge2]vxlan vni 1000
[Edge2-vpn-instance-Edge2]q
[Edge2]interface Vbdif 20
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge2-Vbdif20]ip binding vpn-instance Edge2
Info: All IPv4 and IPv6 related configurations on this interface are removed.
[Edge2-Vbdif20]ip add 172.16.2.254 24
[Edge2-Vbdif20]arp collect host enable
[Edge2-Vbdif20]vxlan anycast-gateway enable
[Edge2-Vbdif20]q
第四步:配置NVE接口,使用BGP协议建立VXLAN隧道
Edge1
[Edge1]interface nve1
[Edge1-Nve1]source 1.1.1.1
[Edge1-Nve1]vni 10 head-end peer-list protocol bgp
[Edge1-Nve1]vni 30 head-end peer-list protocol bgp
[Edge1-Nve1]q
Edge2
[Edge2]int
[Edge2]interface nve1
[Edge2-Nve1]source 2.2.2.2
[Edge2-Nve1]vni 20 head-end peer-list protocol bgp
验证:
[Edge1]dis vxlan tunnel
Number of vxlan tunnel : 1
Tunnel ID Source Destination State Type Uptime
-----------------------------------------------------------------------------------
4026531841 1.1.1.1 2.2.2.2 up dynamic 00:00:56
Edge1上的bgp evpn路由表:
[Edge1]dis bgp evpn all routing-table
Local AS number : 100
BGP Local router ID is 10.1.13.1
Status codes: * - valid, > - best, d - damped, x - best external, a - add path,
h - history, i - internal, s - suppressed, S - Stale
Origin : i - IGP, e - EGP, ? - incomplete
EVPN address family:
Number of Mac Routes: 6
Route Distinguisher: 10:10
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*> 0:48:3864-0131-1200:0:0.0.0.0 0.0.0.0
*> 0:48:5489-98c3-2861:32:172.16.1.1 0.0.0.0
Route Distinguisher: 20:20
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*>i 0:48:3864-0111-1200:0:0.0.0.0 2.2.2.2
*>i 0:48:5489-987c-76fd:32:172.16.2.1 2.2.2.2
Route Distinguisher: 30:30
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*> 0:48:3864-0131-1200:0:0.0.0.0 0.0.0.0
*> 0:48:5489-9865-4ec3:32:172.16.3.1 0.0.0.0
EVPN-Instance 10:
Number of Mac Routes: 4
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*>i 0:48:3864-0111-1200:0:0.0.0.0 2.2.2.2
*> 0:48:3864-0131-1200:0:0.0.0.0 0.0.0.0
*>i 0:48:5489-987c-76fd:32:172.16.2.1 2.2.2.2
*> 0:48:5489-98c3-2861:32:172.16.1.1 0.0.0.0
EVPN-Instance 30:
Number of Mac Routes: 4
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*>i 0:48:3864-0111-1200:0:0.0.0.0 2.2.2.2
*> 0:48:3864-0131-1200:0:0.0.0.0 0.0.0.0
*> 0:48:5489-9865-4ec3:32:172.16.3.1 0.0.0.0
*>i 0:48:5489-987c-76fd:32:172.16.2.1 2.2.2.2
EVPN-Instance __RD_1_10_10__:
Number of Mac Routes: 1
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*>i 0:48:5489-987c-76fd:32:172.16.2.1 2.2.2.2
EVPN address family:
Number of Inclusive Multicast Routes: 3
Route Distinguisher: 10:10
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*> 0:32:1.1.1.1 0.0.0.0
Route Distinguisher: 20:20
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*>i 0:32:2.2.2.2 2.2.2.2
Route Distinguisher: 30:30
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*> 0:32:1.1.1.1 0.0.0.0
EVPN-Instance 10:
Number of Inclusive Multicast Routes: 2
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*> 0:32:1.1.1.1 0.0.0.0
*>i 0:32:2.2.2.2 2.2.2.2
EVPN-Instance 30:
Number of Inclusive Multicast Routes: 2
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*> 0:32:1.1.1.1 0.0.0.0
*>i 0:32:2.2.2.2 2.2.2.2
Edge2上的EVPN路由表
[Edge2]dis bgp evpn all routing-table
Local AS number : 100
BGP Local router ID is 10.1.23.2
Status codes: * - valid, > - best, d - damped, x - best external, a - add path,
h - history, i - internal, s - suppressed, S - Stale
Origin : i - IGP, e - EGP, ? - incomplete
EVPN address family:
Number of Mac Routes: 6
Route Distinguisher: 10:10
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*>i 0:48:3864-0131-1200:0:0.0.0.0 1.1.1.1
*>i 0:48:5489-98c3-2861:32:172.16.1.1 1.1.1.1
Route Distinguisher: 20:20
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*> 0:48:3864-0111-1200:0:0.0.0.0 0.0.0.0
*> 0:48:5489-987c-76fd:32:172.16.2.1 0.0.0.0
Route Distinguisher: 30:30
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*>i 0:48:3864-0131-1200:0:0.0.0.0 1.1.1.1
*>i 0:48:5489-9865-4ec3:32:172.16.3.1 1.1.1.1
EVPN-Instance 20:
Number of Mac Routes: 6
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*> 0:48:3864-0111-1200:0:0.0.0.0 0.0.0.0
*>i 0:48:3864-0131-1200:0:0.0.0.0 1.1.1.1
* i 1.1.1.1
*>i 0:48:5489-9865-4ec3:32:172.16.3.1 1.1.1.1
*> 0:48:5489-987c-76fd:32:172.16.2.1 0.0.0.0
*>i 0:48:5489-98c3-2861:32:172.16.1.1 1.1.1.1
EVPN-Instance __RD_1_10_10__:
Number of Mac Routes: 2
Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr) NextHop
*>i 0:48:5489-9865-4ec3:32:172.16.3.1 1.1.1.1
*>i 0:48:5489-98c3-2861:32:172.16.1.1 1.1.1.1
EVPN address family:
Number of Inclusive Multicast Routes: 3
Route Distinguisher: 10:10
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*>i 0:32:1.1.1.1 1.1.1.1
Route Distinguisher: 20:20
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*> 0:32:2.2.2.2 0.0.0.0
Route Distinguisher: 30:30
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*>i 0:32:1.1.1.1 1.1.1.1
EVPN-Instance 20:
Number of Inclusive Multicast Routes: 3
Network(EthTagId/IpAddrLen/OriginalIp) NextHop
*>i 0:32:1.1.1.1 1.1.1.1
* i 1.1.1.1
*> 0:32:2.2.2.2 0.0.0.0
VPN实例的路由表
[Edge1]dis ip routing-table vpn-instance Edge1
Proto: Protocol Pre: Preference
Route Flags: R - relay, D - download to fib, T - to vpn-instance, B - black hole route
------------------------------------------------------------------------------
Routing Table : Edge1
Destinations : 8 Routes : 8
Destination/Mask Proto Pre Cost Flags NextHop Interface
172.16.1.0/24 Direct 0 0 D 172.16.1.254 Vbdif10
172.16.1.254/32 Direct 0 0 D 127.0.0.1 Vbdif10
172.16.1.255/32 Direct 0 0 D 127.0.0.1 Vbdif10
172.16.2.1/32 IBGP 255 0 RD 2.2.2.2 VXLAN
172.16.3.0/24 Direct 0 0 D 172.16.3.254 Vbdif30
172.16.3.254/32 Direct 0 0 D 127.0.0.1 Vbdif30
172.16.3.255/32 Direct 0 0 D 127.0.0.1 Vbdif30
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
[Edge2]dis ip routing-table vpn-instance Edge2
Proto: Protocol Pre: Preference
Route Flags: R - relay, D - download to fib, T - to vpn-instance, B - black hole route
------------------------------------------------------------------------------
Routing Table : Edge2
Destinations : 6 Routes : 6
Destination/Mask Proto Pre Cost Flags NextHop Interface
172.16.1.1/32 IBGP 255 0 RD 1.1.1.1 VXLAN
172.16.2.0/24 Direct 0 0 D 172.16.2.254 Vbdif20
172.16.2.254/32 Direct 0 0 D 127.0.0.1 Vbdif20
172.16.2.255/32 Direct 0 0 D 127.0.0.1 Vbdif20
172.16.3.1/32 IBGP 255 0 RD 1.1.1.1 VXLAN
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
ARP信息
[Edge1]display arp vpn-instance Edge1
ARP Entry Types: D - Dynamic, S - Static, I - Interface, O - OpenFlow, RD - Redirect
EXP: Expire-time VLAN:VLAN or Bridge Domain
IP ADDRESS MAC ADDRESS EXP(M) TYPE/VLAN INTERFACE VPN-INSTANCE
----------------------------------------------------------------------------------------
172.16.1.254 3864-0131-1200 I Vbdif10 Edge1
172.16.1.1 5489-98c3-2861 18 D/BD10 GE1/0/2.10 Edge1
172.16.3.254 3864-0131-1200 I Vbdif30 Edge1
172.16.3.1 5489-9865-4ec3 18 D/BD30 GE1/0/2.30 Edge1
----------------------------------------------------------------------------------------
Total:4 Dynamic:2 Static:0 Interface:2 OpenFlow:0
Redirect:0
[Edge2]display arp vpn-instance Edge2
ARP Entry Types: D - Dynamic, S - Static, I - Interface, O - OpenFlow, RD - Redirect
EXP: Expire-time VLAN:VLAN or Bridge Domain
IP ADDRESS MAC ADDRESS EXP(M) TYPE/VLAN INTERFACE VPN-INSTANCE
----------------------------------------------------------------------------------------
172.16.2.254 3864-0111-1200 I Vbdif20 Edge2
172.16.2.1 5489-987c-76fd 17 D/BD20 GE1/0/2.20 Edge2
----------------------------------------------------------------------------------------
Total:2 Dynamic:1 Static:0 Interface:1 OpenFlow:0
Redirect:0
ping测试
PC>ping 172.16.2.1
Ping 172.16.2.1: 32 data bytes, Press Ctrl_C to break
Request timeout!
From 172.16.2.1: bytes=32 seq=2 ttl=126 time=78 ms
From 172.16.2.1: bytes=32 seq=3 ttl=126 time=78 ms
From 172.16.2.1: bytes=32 seq=4 ttl=126 time=78 ms
From 172.16.2.1: bytes=32 seq=5 ttl=126 time=63 ms
--- 172.16.2.1 ping statistics ---
5 packet(s) transmitted
4 packet(s) received
20.00% packet loss
round-trip min/avg/max = 0/74/78 ms
PC>ping 172.16.3.1
Ping 172.16.3.1: 32 data bytes, Press Ctrl_C to break
From 172.16.3.1: bytes=32 seq=1 ttl=127 time=79 ms
From 172.16.3.1: bytes=32 seq=2 ttl=127 time=78 ms
From 172.16.3.1: bytes=32 seq=3 ttl=127 time=78 ms
From 172.16.3.1: bytes=32 seq=4 ttl=127 time=78 ms
From 172.16.3.1: bytes=32 seq=5 ttl=127 time=78 ms
--- 172.16.3.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 78/78/79 ms
总结
如果你细心的看完我的配置可能会有疑问,为什么Edge1上不同网段的VBDIF绑定了相同的VPN实例?我这么做的原因是为了让PC1和PC3互通,放在相同的VPN实例下,会看做它们是直连路由。如果你想要达到互相隔离的效果,可以将这两个VBDIF绑定不同的VPN实例,这样的话他们就是相互隔离了。