VXLAN分布式网关实验

实验拓扑

image-20220720142024829

实验目的

​ PC1和PC2、PC3和PC2、PC1和PC3之间实现互访。

实验思路

  • 部署Underlay网络,创建桥接域绑定VNI和子接口
  • 部署BGP的EVPN邻居以及通告IRB路由
  • Edge上创建桥接域的EVPN实例和IP VPN实例,并创建绑定VBDIF接口
  • 配置NVE接口,使用BGP协议建立VXLAN隧道

实验步骤

第一步:部署Underlay网络

Border
[BORDER]ospf 1 router-id 3.3.3.3
[BORDER-ospf-1]area 0
[BORDER-ospf-1-area-0.0.0.0]q
[BORDER-ospf-1]q
[BORDER]int g1/0/0
[BORDER-GE1/0/0]undo portswitch 
[BORDER-GE1/0/0]undo shutdown 
[BORDER-GE1/0/0]ip add 10.1.13.3 24
[BORDER-GE1/0/0]ospf en area 0
[BORDER-GE1/0/0]q
[BORDER]int g1/0/1
[BORDER-GE1/0/1]undo portswitch 
[BORDER-GE1/0/1]undo shutdown 
[BORDER-GE1/0/1]ip add 10.1.23.3 24
[BORDER-GE1/0/1]ospf en area 0
[BORDER-GE1/0/1]int loo0
[BORDER-LoopBack0]ip add 3.3.3.3 32
[BORDER-LoopBack0]ospf en area 0
[BORDER-LoopBack0]q

Edge1
[Edge1]ospf 1 router-id 1.1.1.1
[Edge1-ospf-1]area 0
[Edge1-ospf-1-area-0.0.0.0]q
[Edge1-ospf-1]q
[Edge1]int g1/0/0
[Edge1-GE1/0/0]undo portswitch 
[Edge1-GE1/0/0]undo shutdown 
[Edge1-GE1/0/0]ip add 10.1.13.1 24
[Edge1-GE1/0/0]ospf en area 0
[Edge1-GE1/0/0]q
[Edge1]int loo0
[Edge1-LoopBack0]ip add 1.1.1.1 32
[Edge1-LoopBack0]ospf en area 0
[Edge1-LoopBack0]q
[Edge1]bridge-domain 10
[Edge1-bd10]vni 10
[Edge1-vni10]q
[Edge1]bridge-domain 30
[Edge1-bd30]vni 30
[Edge1-vni30]q
[Edge1]int g1/0/2
[Edge1-GE1/0/2]undo shutdown 
[Edge1-GE1/0/2]q
[Edge1]int g1/0/2.10 mode l2     
[Edge1-GE1/0/2.10]encapsulation dot1q vid 10
[Edge1-GE1/0/2.10]bridge-domain 10
[Edge1-GE1/0/2.10]q
[Edge1]int g1/0/2.30 mode l2
[Edge1-GE1/0/2.30]encapsulation dot1q vid 30
[Edge1-GE1/0/2.30]bridge-domain 30
[Edge1-GE1/0/2.30]q

Edge2
[Edge2]ospf 1 router-id 2.2.2.2
[Edge2-ospf-1]area 0
[Edge2-ospf-1-area-0.0.0.0]q
[Edge2-ospf-1]q
[Edge2]int g1/0/1
[Edge2-GE1/0/1]undo portswitch
[Edge2-GE1/0/1]undo shutdown
[Edge2-GE1/0/1]ip add 10.1.23.2 24
[Edge2-GE1/0/1]ospf en area 0
[Edge2-GE1/0/1]q 
[Edge2]int loo0
[Edge2-LoopBack0]ip add 2.2.2.2 32
[Edge2-LoopBack0]ospf en area 0
[Edge2-LoopBack0]q
[Edge2]bridge-domain 20
[Edge2-bd20]vni 20
[Edge2-vni20]q
[Edge2]int g1/0/2
[Edge2-GE1/0/2]undo shutdown 
[Edge2-GE1/0/2]q
[Edge2]int g1/0/2.20 mode l2
[Edge2-GE1/0/2.20]encapsulation dot1q vid 20
[Edge2-GE1/0/2.20]bridge-domain 20
[Edge2-GE1/0/2.20]q

SW1
[SW1]vlan batch 10 30
[SW1]int g0/0/2
[SW1-GigabitEthernet0/0/2]port link trunk
[SW1-GigabitEthernet0/0/2]port trunk all vlan 10 30
[SW1-GigabitEthernet0/0/2]q
[SW1]int g0/0/20
[SW1-GigabitEthernet0/0/20]port link acc
[SW1-GigabitEthernet0/0/20]port default vlan 30
[SW1-GigabitEthernet0/0/20]q
[SW1]int g0/0/10
[SW1-GigabitEthernet0/0/10]port link acc
[SW1-GigabitEthernet0/0/10]port default vlan 10
[SW1-GigabitEthernet0/0/10]q

SW2
[SW2]vlan 20 
[SW2-vlan20]q                                  
[SW2]int g0/0/2
[SW2-GigabitEthernet0/0/2]port link trunk
[SW2-GigabitEthernet0/0/2]port trunk all vlan 20
[SW2-GigabitEthernet0/0/2]q                                 
[SW2]int g0/0/10
[SW2-GigabitEthernet0/0/10]port link access
[SW2-GigabitEthernet0/0/10]port default vlan 20
[SW2-GigabitEthernet0/0/10]q

第二步:部署BGP的EVPN邻居以及通告IRB路由

Border
[BORDER]evpn-overlay enable 	### 开启EVPN功能
[BORDER]bgp 100
[BORDER-bgp]peer 1.1.1.1 as-number 100
[BORDER-bgp]peer 1.1.1.1 connect-interface loo0
[BORDER-bgp]peer 2.2.2.2 as-number 100
[BORDER-bgp]peer 2.2.2.2 connect-interface loo0
[BORDER-bgp]l2vpn-family evpn 	### 进入evpn地址族
[BORDER-bgp-af-evpn]peer 1.1.1.1 enable 
Warning: This operation will reset the peer session. Continue? [Y/N]:y
[BORDER-bgp-af-evpn]peer 1.1.1.1 reflect-client ### 配置Edge1为路由反射器客户端
[BORDER-bgp-af-evpn]peer 1.1.1.1 advertise irb	### 通告irb路由
[BORDER-bgp-af-evpn]peer 2.2.2.2 enable 
Warning: This operation will reset the peer session. Continue? [Y/N]:y    
[BORDER-bgp-af-evpn]peer 2.2.2.2 reflect-client	### 配置Edge1为路由反射器客户端 
[BORDER-bgp-af-evpn]peer 2.2.2.2 advertise irb	### 通告irb路由
[BORDER-bgp-af-evpn]undo policy vpn-target	### 重要!!!RR上关闭VPN-target检查
[BORDER-bgp-af-evpn]q
[BORDER-bgp]q

Edge1
[Edge1]evpn-overlay enable 
[Edge1]bgp 100
[Edge1-bgp]peer 3.3.3.3 as-number 100
[Edge1-bgp]peer 3.3.3.3 connect-interface loo0
[Edge1-bgp]l2vpn-family evpn
[Edge1-bgp-af-evpn]peer 3.3.3.3 enable
Warning: This operation will reset the peer session. Continue? [Y/N]:y
[Edge1-bgp-af-evpn]peer 3.3.3.3 advertise irb
[Edge1-bgp-af-evpn]q
[Edge1-bgp]q

Edge2
[Edge2]evpn-overlay enable 
[Edge2]bgp 100
[Edge2-bgp]peer 3.3.3.3 as-number 100
[Edge2-bgp]peer 3.3.3.3 connect-interface loo0
[Edge2-bgp]l2vpn-family evpn
[Edge2-bgp-af-evpn]peer 3.3.3.3 enable
Warning: This operation will reset the peer session. Continue? [Y/N]:y
[Edge2-bgp-af-evpn]peer 3.3.3.3 advertise irb
[Edge2-bgp-af-evpn]q
[Edge2-bgp]q

验证:
[BORDER]dis bgp evpn peer 
 BGP local router ID        : 10.1.13.3
 Local AS number            : 100
 Total number of peers      : 2
 Peers in established state : 2

  Peer            V          AS  MsgRcvd  MsgSent  OutQ  Up/Down       State  PrefRcv
  1.1.1.1         4         100        5        5     0 00:01:24 Established        0
  2.2.2.2         4         100        4        4     0 00:00:31 Established        0

第三步:Edge上创建桥接域的EVPN实例和IP VPN实例,并创建绑定VBDIF接口

Edge1
[Edge1]bridge-domain 10
[Edge1-bd10]vxlan vni 10
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-bd10]evpn 
[Edge1-bd10-evpn]route-distinguisher 10:10
[Edge1-bd10-evpn]vpn-target 10:10
 IVT Assignment result:
Info: VPN-Target assignment is successful.
 EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-bd10-evpn]vpn-target 11:1 export-extcommunity ### 本段主机上线,转化为EVPN路由,更新给远端时,会携带BD下的ERT
[Edge1]bridge-domain 30
[Edge1-bd30]vxlan vni 30
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-bd30]evpn
[Edge1-bd30-evpn]route-distinguisher 30:30
[Edge1-bd30-evpn]vpn-target 10:10
 IVT Assignment result:
Info: VPN-Target assignment is successful.
 EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-bd30-evpn]vpn
[Edge1-bd30-evpn]vpn-target 11:1 export-extcommunity 
 EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-bd30-evpn]q
[Edge1-bd30]q
[Edge1]ip vpn-instance Edge1
[Edge1-vpn-instance-Edge1]route-distinguisher 10:10
[Edge1-vpn-instance-Edge1-af-ipv4]vpn-target 11:1 import-extcommunity evpn
 IVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge1-vpn-instance-Edge1-af-ipv4]q
[Edge1-vpn-instance-Edge1]vxlan vni 1000
[Edge1-vpn-instance-Edge1]q
[Edge1]interface vbdif 10 
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-Vbdif10]ip binding vpn-instance Edge1
Info: All IPv4 and IPv6 related configurations on this interface are removed.
[Edge1-Vbdif10]ip add 172.16.1.254 24
[Edge1-Vbdif10]arp collect host enable 
[Edge1-Vbdif10]vxlan anycast-gateway enable 
[Edge1-Vbdif10]q
[Edge1]interface vbdif 30
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge1-Vbdif30]ip binding vpn-instance Edge1
Info: All IPv4 and IPv6 related configurations on this interface are removed.
[Edge1-Vbdif30]ip add 172.16.3.254 24
[Edge1-Vbdif30]arp collect host enable 
[Edge1-Vbdif30]vxlan anycast-gateway enable 
[Edge1-Vbdif30]q

Edge2
[Edge2]bridge-domain 20
[Edge2-bd20]vxlan vni 20
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge2-bd20]evpn
[Edge2-bd20-evpn]route-distinguisher 20:20
[Edge2-bd20-evpn]vpn-target 10:10
 IVT Assignment result:
Info: VPN-Target assignment is successful.
 EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge2-bd20-evpn]vpn-target 11:1 export-extcommunity 
 EVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge2-bd20-evpn]q
[Edge2-bd20]q
[Edge2]ip vpn-instance Edge2
[Edge2-vpn-instance-Edge2]route-distinguisher 10:10
[Edge2-vpn-instance-Edge2-af-ipv4]vpn-target 11:1 import-extcommunity evpn
 IVT Assignment result:
Info: VPN-Target assignment is successful.
[Edge2-vpn-instance-Edge2-af-ipv4]q
[Edge2-vpn-instance-Edge2]vxlan vni 1000
[Edge2-vpn-instance-Edge2]q
[Edge2]interface Vbdif 20
Info: Please disable dynamic ARP learning when the controller is used to deliver ARP entries.
[Edge2-Vbdif20]ip binding vpn-instance Edge2
Info: All IPv4 and IPv6 related configurations on this interface are removed.
[Edge2-Vbdif20]ip add 172.16.2.254 24
[Edge2-Vbdif20]arp collect host enable 
[Edge2-Vbdif20]vxlan anycast-gateway enable 
[Edge2-Vbdif20]q

第四步:配置NVE接口,使用BGP协议建立VXLAN隧道

Edge1
[Edge1]interface nve1 
[Edge1-Nve1]source 1.1.1.1
[Edge1-Nve1]vni 10 head-end peer-list protocol bgp
[Edge1-Nve1]vni 30 head-end peer-list protocol bgp
[Edge1-Nve1]q

Edge2
[Edge2]int
[Edge2]interface nve1
[Edge2-Nve1]source 2.2.2.2
[Edge2-Nve1]vni 20 head-end peer-list protocol bgp 

验证:
[Edge1]dis vxlan tunnel 
Number of vxlan tunnel : 1
Tunnel ID   Source                Destination           State  Type     Uptime
-----------------------------------------------------------------------------------
4026531841  1.1.1.1               2.2.2.2               up     dynamic  00:00:56  

Edge1上的bgp evpn路由表:

[Edge1]dis bgp evpn all routing-table 
 Local AS number : 100

 BGP Local router ID is 10.1.13.1
 Status codes: * - valid, > - best, d - damped, x - best external, a - add path,
               h - history,  i - internal, s - suppressed, S - Stale
               Origin : i - IGP, e - EGP, ? - incomplete

  
 EVPN address family:
  Number of Mac Routes: 6
 Route Distinguisher: 10:10
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>    0:48:3864-0131-1200:0:0.0.0.0                          0.0.0.0
 *>    0:48:5489-98c3-2861:32:172.16.1.1                      0.0.0.0
 Route Distinguisher: 20:20
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>i   0:48:3864-0111-1200:0:0.0.0.0                          2.2.2.2
 *>i   0:48:5489-987c-76fd:32:172.16.2.1                      2.2.2.2
 Route Distinguisher: 30:30
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>    0:48:3864-0131-1200:0:0.0.0.0                          0.0.0.0
 *>    0:48:5489-9865-4ec3:32:172.16.3.1                      0.0.0.0

   EVPN-Instance 10:
  
 Number of Mac Routes: 4
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>i   0:48:3864-0111-1200:0:0.0.0.0                          2.2.2.2
 *>    0:48:3864-0131-1200:0:0.0.0.0                          0.0.0.0
 *>i   0:48:5489-987c-76fd:32:172.16.2.1                      2.2.2.2
 *>    0:48:5489-98c3-2861:32:172.16.1.1                      0.0.0.0

   EVPN-Instance 30:
  
 Number of Mac Routes: 4
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>i   0:48:3864-0111-1200:0:0.0.0.0                          2.2.2.2
 *>    0:48:3864-0131-1200:0:0.0.0.0                          0.0.0.0
 *>    0:48:5489-9865-4ec3:32:172.16.3.1                      0.0.0.0
 *>i   0:48:5489-987c-76fd:32:172.16.2.1                      2.2.2.2

   EVPN-Instance __RD_1_10_10__:
  
 Number of Mac Routes: 1
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>i   0:48:5489-987c-76fd:32:172.16.2.1                      2.2.2.2
                
 EVPN address family:
  Number of Inclusive Multicast Routes: 3
 Route Distinguisher: 10:10
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>    0:32:1.1.1.1                                           0.0.0.0
 Route Distinguisher: 20:20
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>i   0:32:2.2.2.2                                           2.2.2.2
 Route Distinguisher: 30:30
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>    0:32:1.1.1.1                                           0.0.0.0

   EVPN-Instance 10:
  
 Number of Inclusive Multicast Routes: 2
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>    0:32:1.1.1.1                                           0.0.0.0
 *>i   0:32:2.2.2.2                                           2.2.2.2

   EVPN-Instance 30:
  
 Number of Inclusive Multicast Routes: 2
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>    0:32:1.1.1.1                                           0.0.0.0
 *>i   0:32:2.2.2.2                                           2.2.2.2

Edge2上的EVPN路由表

[Edge2]dis bgp evpn all routing-table
 Local AS number : 100

 BGP Local router ID is 10.1.23.2
 Status codes: * - valid, > - best, d - damped, x - best external, a - add path,
               h - history,  i - internal, s - suppressed, S - Stale
               Origin : i - IGP, e - EGP, ? - incomplete

  
 EVPN address family:
  Number of Mac Routes: 6
 Route Distinguisher: 10:10
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>i   0:48:3864-0131-1200:0:0.0.0.0                          1.1.1.1
 *>i   0:48:5489-98c3-2861:32:172.16.1.1                      1.1.1.1
 Route Distinguisher: 20:20
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>    0:48:3864-0111-1200:0:0.0.0.0                          0.0.0.0
 *>    0:48:5489-987c-76fd:32:172.16.2.1                      0.0.0.0
 Route Distinguisher: 30:30
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>i   0:48:3864-0131-1200:0:0.0.0.0                          1.1.1.1
 *>i   0:48:5489-9865-4ec3:32:172.16.3.1                      1.1.1.1

   EVPN-Instance 20:
  
 Number of Mac Routes: 6
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>    0:48:3864-0111-1200:0:0.0.0.0                          0.0.0.0
 *>i   0:48:3864-0131-1200:0:0.0.0.0                          1.1.1.1
 * i                                                          1.1.1.1
 *>i   0:48:5489-9865-4ec3:32:172.16.3.1                      1.1.1.1
 *>    0:48:5489-987c-76fd:32:172.16.2.1                      0.0.0.0
 *>i   0:48:5489-98c3-2861:32:172.16.1.1                      1.1.1.1

   EVPN-Instance __RD_1_10_10__:
  
 Number of Mac Routes: 2
       Network(EthTagId/MacAddrLen/MacAddr/IpAddrLen/IpAddr)  NextHop
 *>i   0:48:5489-9865-4ec3:32:172.16.3.1                      1.1.1.1
 *>i   0:48:5489-98c3-2861:32:172.16.1.1                      1.1.1.1
  
 EVPN address family:
  Number of Inclusive Multicast Routes: 3
 Route Distinguisher: 10:10
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>i   0:32:1.1.1.1                                           1.1.1.1
 Route Distinguisher: 20:20
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>    0:32:2.2.2.2                                           0.0.0.0
 Route Distinguisher: 30:30
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>i   0:32:1.1.1.1                                           1.1.1.1

   EVPN-Instance 20:
  
 Number of Inclusive Multicast Routes: 3
       Network(EthTagId/IpAddrLen/OriginalIp)                 NextHop
 *>i   0:32:1.1.1.1                                           1.1.1.1
 * i                                                          1.1.1.1
 *>    0:32:2.2.2.2                                           0.0.0.0

VPN实例的路由表

[Edge1]dis ip routing-table vpn-instance Edge1
Proto: Protocol        Pre: Preference
Route Flags: R - relay, D - download to fib, T - to vpn-instance, B - black hole route
------------------------------------------------------------------------------
Routing Table : Edge1
         Destinations : 8        Routes : 8         

Destination/Mask    Proto   Pre  Cost        Flags NextHop         Interface

     172.16.1.0/24  Direct  0    0             D   172.16.1.254    Vbdif10
   172.16.1.254/32  Direct  0    0             D   127.0.0.1       Vbdif10
   172.16.1.255/32  Direct  0    0             D   127.0.0.1       Vbdif10
     172.16.2.1/32  IBGP    255  0             RD  2.2.2.2         VXLAN
     172.16.3.0/24  Direct  0    0             D   172.16.3.254    Vbdif30
   172.16.3.254/32  Direct  0    0             D   127.0.0.1       Vbdif30
   172.16.3.255/32  Direct  0    0             D   127.0.0.1       Vbdif30
255.255.255.255/32  Direct  0    0             D   127.0.0.1       InLoopBack0

[Edge2]dis ip routing-table vpn-instance Edge2
Proto: Protocol        Pre: Preference
Route Flags: R - relay, D - download to fib, T - to vpn-instance, B - black hole route
------------------------------------------------------------------------------
Routing Table : Edge2
         Destinations : 6        Routes : 6         

Destination/Mask    Proto   Pre  Cost        Flags NextHop         Interface

     172.16.1.1/32  IBGP    255  0             RD  1.1.1.1         VXLAN
     172.16.2.0/24  Direct  0    0             D   172.16.2.254    Vbdif20
   172.16.2.254/32  Direct  0    0             D   127.0.0.1       Vbdif20
   172.16.2.255/32  Direct  0    0             D   127.0.0.1       Vbdif20
     172.16.3.1/32  IBGP    255  0             RD  1.1.1.1         VXLAN
255.255.255.255/32  Direct  0    0             D   127.0.0.1       InLoopBack0

ARP信息

[Edge1]display arp vpn-instance Edge1
ARP Entry Types: D - Dynamic, S - Static, I - Interface, O - OpenFlow, RD - Redirect
EXP: Expire-time VLAN:VLAN or Bridge Domain

IP ADDRESS      MAC ADDRESS    EXP(M) TYPE/VLAN       INTERFACE        VPN-INSTANCE
----------------------------------------------------------------------------------------
172.16.1.254    3864-0131-1200        I               Vbdif10          Edge1
172.16.1.1      5489-98c3-2861   18   D/BD10          GE1/0/2.10       Edge1
172.16.3.254    3864-0131-1200        I               Vbdif30          Edge1
172.16.3.1      5489-9865-4ec3   18   D/BD30          GE1/0/2.30       Edge1
----------------------------------------------------------------------------------------
Total:4         Dynamic:2       Static:0    Interface:2    OpenFlow:0
Redirect:0

[Edge2]display arp vpn-instance Edge2
ARP Entry Types: D - Dynamic, S - Static, I - Interface, O - OpenFlow, RD - Redirect
EXP: Expire-time VLAN:VLAN or Bridge Domain

IP ADDRESS      MAC ADDRESS    EXP(M) TYPE/VLAN       INTERFACE        VPN-INSTANCE
----------------------------------------------------------------------------------------
172.16.2.254    3864-0111-1200        I               Vbdif20          Edge2
172.16.2.1      5489-987c-76fd   17   D/BD20          GE1/0/2.20       Edge2
----------------------------------------------------------------------------------------
Total:2         Dynamic:1       Static:0    Interface:1    OpenFlow:0
Redirect:0

ping测试

PC>ping 172.16.2.1

Ping 172.16.2.1: 32 data bytes, Press Ctrl_C to break
Request timeout!
From 172.16.2.1: bytes=32 seq=2 ttl=126 time=78 ms
From 172.16.2.1: bytes=32 seq=3 ttl=126 time=78 ms
From 172.16.2.1: bytes=32 seq=4 ttl=126 time=78 ms
From 172.16.2.1: bytes=32 seq=5 ttl=126 time=63 ms

--- 172.16.2.1 ping statistics ---
  5 packet(s) transmitted
  4 packet(s) received
  20.00% packet loss
  round-trip min/avg/max = 0/74/78 ms
  
PC>ping 172.16.3.1

Ping 172.16.3.1: 32 data bytes, Press Ctrl_C to break
From 172.16.3.1: bytes=32 seq=1 ttl=127 time=79 ms
From 172.16.3.1: bytes=32 seq=2 ttl=127 time=78 ms
From 172.16.3.1: bytes=32 seq=3 ttl=127 time=78 ms
From 172.16.3.1: bytes=32 seq=4 ttl=127 time=78 ms
From 172.16.3.1: bytes=32 seq=5 ttl=127 time=78 ms

--- 172.16.3.1 ping statistics ---
  5 packet(s) transmitted
  5 packet(s) received
  0.00% packet loss
  round-trip min/avg/max = 78/78/79 ms

总结

如果你细心的看完我的配置可能会有疑问,为什么Edge1上不同网段的VBDIF绑定了相同的VPN实例?我这么做的原因是为了让PC1和PC3互通,放在相同的VPN实例下,会看做它们是直连路由。如果你想要达到互相隔离的效果,可以将这两个VBDIF绑定不同的VPN实例,这样的话他们就是相互隔离了。

评论 6
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值