58.多归属的 MPBGP MPLS VPN (PE-CE EBGP 、Soo防环)

提示:文章写完后,目录可以自动生成,如何生成可参考右边的帮助文档


前言 58

在这里插入图片描述

一、基础配置(接口IP+IGP 配置+开启MPLS LDP)

AR1

关闭自动弹出

sys
user-interface console 0
idle-timeout 0 0
q

配置接口IP

interface GigabitEthernet0/0/0
 ip address 15.1.1.1 255.255.255.252 
interface GigabitEthernet0/0/1
 ip address 16.1.1.1 255.255.255.252 
interface GigabitEthernet0/0/2
 ip address 12.1.1.1 255.255.255.252 
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255 

OSPF敲烦了来IS-IS(使能ISIS ;配置ISIS路由器类型为L2;配地址,接口下使能IS-IS)

isis 1 
is-level level-2 
network-entity 49.0000.0000.0001.00
interface GigabitEthernet0/0/2
isis enable 1
interface LoopBack0
isis enable 1

开始MPLS(全局开启MPLS ;配置LSR-id;接口使能LDP功能,运营商内部接口使能就行)

mpls lsr-id 1.1.1.1 
 mpls
 mpls ldp
interface GigabitEthernet0/0/2
mpls
 mpls ldp

AR2

sys
user-interface console 0
idle-timeout 0 0
q

mpls lsr-id 2.2.2.2
	mpls
		mpls ldp
	
isis 1
 is-level level-2
	 network-entity 49.0000.0000.0002.00
	 
interface GigabitEthernet0/0/0
 ip address 12.1.1.2 255.255.255.252 
 isis enable 1
 mpls
 mpls ldp
		 
interface GigabitEthernet0/0/1
 ip address 23.1.1.1 255.255.255.252 
 isis enable 1
 mpls
 mpls ldp
 
interface LoopBack0
 ip address 2.2.2.2 255.255.255.255 
 isis enable 1

AR3

sys
user-interface console 0
idle-timeout 0 0
q


mpls lsr-id 3.3.3.3
mpls
mpls ldp

isis 1
 is-level level-2
 network-entity 49.0000.0000.0003.00

interface GigabitEthernet0/0/0
 ip address 23.1.1.2 255.255.255.252 
 isis enable 1
 mpls
 mpls ldp

interface GigabitEthernet0/0/1
 ip address 34.1.1.1 255.255.255.252
 
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255 
 isis enable 1

二、查看基础配置状态

IS-IS邻居

[Huawei-isis-1]dis isis peer 

                          Peer information for ISIS(1)

  System Id     Interface          Circuit Id       State HoldTime Type     PRI
-------------------------------------------------------------------------------
0000.0000.0001  GE0/0/0            0000.0000.0001.01 Up   8s       L2       64 
0000.0000.0003  GE0/0/1            0000.0000.0003.01 Up   21s      L2       64 

LDP session

<Huawei>dis mpls ldp session 

 LDP Session(s) in Public Network
 Codes: LAM(Label Advertisement Mode), SsnAge Unit(DDDD:HH:MM)
 A '*' before a session means the session is being deleted.
 ------------------------------------------------------------------------------
 PeerID             Status      LAM  SsnRole  SsnAge      KASent/Rcv
 ------------------------------------------------------------------------------
 1.1.1.1:0          Operational DU   Active   0000:00:00  2/2
 3.3.3.3:0          Operational DU   Passive  0000:00:00  3/3
 ------------------------------------------------------------------------------
 TOTAL: 2 session(s) Found.
<Huawei>ping -a 1.1.1.1 3.3.3.3
  PING 3.3.3.3: 56  data bytes, press CTRL_C to break
    Reply from 3.3.3.3: bytes=56 Sequence=1 ttl=254 time=30 ms
    Reply from 3.3.3.3: bytes=56 Sequence=2 ttl=254 time=30 ms
    Reply from 3.3.3.3: bytes=56 Sequence=3 ttl=254 time=20 ms
    Reply from 3.3.3.3: bytes=56 Sequence=4 ttl=254 time=30 ms
    Reply from 3.3.3.3: bytes=56 Sequence=5 ttl=254 time=30 ms

二、配置 PE间IBGP、MP-BGP VPNV4地址族

1.PE-PE

R1
[Huawei]bgp 100
[Huawei-bgp]peer 3.3.3.3 as 100
[Huawei-bgp]peer 3.3.3.3 connect-interface lo 0

R3
[Huawei]bgp 100
[Huawei-bgp]peer 1.1.1.1  as-number 100
[Huawei-bgp]peer 1.1.1.1  connect-interface lo 0


查看BGP状态
[Huawei-bgp]dis bgp peer
 BGP local router ID : 15.1.1.1
 Local AS number : 100
 Total number of peers : 1		  Peers in established state : 1

  Peer        V      AS  MsgRcvd  MsgSent  OutQ  Up/Down       State PrefRcv

  3.3.3.3     4      100    3      5     0 00:01:46 Established    0

2.接口绑定VRF ,MP-BGP建立peer使能对等体交换 BGP-VPNv4 路由信息

接口绑定VRF

AR1

[Huawei]ip vpn-instance A
[Huawei-vpn-instance-A]route-distinguisher 100:1 
[Huawei-vpn-instance-A-af-ipv4]vpn-target 100:1
[Huawei-vpn-instance-A-af-ipv4]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip binding vpn-instance A
[Huawei-GigabitEthernet0/0/1]ip add 16.1.1.1 30
[Huawei-GigabitEthernet0/0/1]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip address 15.1.1.1 30


AR3
[Huawei]ip vpn-instance A
[Huawei-vpn-instance-A]route-distinguisher 100:1
[Huawei-vpn-instance-A-af-ipv4]vpn-target 100:1
[Huawei-vpn-instance-A-af-ipv4]int g0/0/1
[Huawei-GigabitEthernet0/0/1]ip binding vpn-instance A
[Huawei-GigabitEthernet0/0/1]ip add 34.1.1.1 30

MP-BGP建立peer使能对等体交换 BGP-VPNv4 路由信息

AR1
[Huawei]bgp 100
[Huawei-bgp]ipv4-family vpnv4
[Huawei-bgp-af-vpnv4]peer 3.3.3.3 enable 

AR3
Huawei]bgp 100
[Huawei-bgp]ipv4-family vpnv4
[Huawei-bgp-af-vpnv4]peer 1.1.1.1 enable 

确认状态

[Huawei]dis bgp vpnv4 all peer 

 BGP local router ID : 15.1.1.1
 Local AS number : 100
 Total number of peers : 1		  Peers in established state : 1

  Peer            V          AS  MsgRcvd  MsgSent  OutQ  Up/Down       State Pre  fRcv

  3.3.3.3         4         100        3        4     0 00:01:37 Established      0

三、CE-PE间EBGP

A-Hub-1

基础IP配置
interface GigabitEthernet0/0/0
 ip address 56.1.1.1 255.255.255.252 
interface GigabitEthernet0/0/1
 ip address 15.1.1.2 255.255.255.252 
interface LoopBack0
 ip address 5.5.5.5 255.255.255.255 


CE-CE  
bgp 200
peer 15.1.1.1 as-number 100 
 peer 15.1.1.1 ebgp-max-hop 2 
 peer 15.1.1.1 connect-interface GigabitEthernet0/0/1




PE-CE
bgp 200
 peer 56.1.1.2 as-number 200 
 peer 56.1.1.2 connect-interface GigabitEthernet0/0/0
 peer 56.1.1.2 next-hop-local 

A-Hub-2

interface GigabitEthernet0/0/0
 ip address 56.1.1.2 255.255.255.252 
interface GigabitEthernet0/0/1
 ip address 16.1.1.2 255.255.255.252 
interface LoopBack0
 ip address 6.6.6.6 255.255.255.255 


CE-CE  
bgp 200
 peer 16.1.1.1 as-number 100 
 peer 16.1.1.1 ebgp-max-hop 2 
 peer 16.1.1.1 connect-interface GigabitEthernet0/0/1

PE-CE
bgp 200
 peer 56.1.1.1 as-number 200 
 peer 56.1.1.1 connect-interface LoopBack0
 peer 56.1.1.1 next-hop-local 

PE1

AR1
bgp100
ipv4-family vpn-instance A 
  peer 15.1.1.2 as-number 200 
  peer 15.1.1.2 ebgp-max-hop 2 
  peer 15.1.1.2 connect-interface GigabitEthernet0/0/0
  peer 16.1.1.2 as-number 200 
  peer 16.1.1.2 ebgp-max-hop 2 
  peer 16.1.1.2 connect-interface GigabitEthernet0/0/1

容易敲错地址,记得查下哦

[Huawei-bgp]dis bgp peer

 BGP local router ID : 15.1.1.2
 Local AS number : 200
 Total number of peers : 2		  Peers in established state : 2

  Peer            V          AS  MsgRcvd  MsgSent  OutQ  Up/Down       State Pre
fRcv

  15.1.1.1        4         100        5        6     0 00:01:40 Established     0
  56.1.1.2        4         200       12       13     0 00:07:38 Established    

AR3 - A-Spoke

AR3


bgp100
[Huawei-bgp]ipv4-family vpn-instance A
[Huawei-bgp-A]peer 34.1.1.2 as 200
[Huawei-bgp-A]peer 34.1.1.2 ebgp-max-hop 2
[Huawei-bgp-A]peer 34.1.1.2 co g0/0/1


A-Spoke
[Huawei]int g0/0/0
[Huawei-GigabitEthernet0/0/0]ip add 34.1.1.2 30 
[Huawei-GigabitEthernet0/0/0]bgp 200
[Huawei-bgp]peer 34.1.1.1 as 100
[Huawei-bgp]peer 34.1.1.1 co g0/0/0
[Huawei-bgp]peer 34.1.1.1 e 2



顺手查查不吃亏
[Huawei-bgp]dis bgp peer

 BGP local router ID : 34.1.1.2
 Local AS number : 200
 Total number of peers : 1		  Peers in established state : 1

  Peer            V          AS  MsgRcvd  MsgSent  OutQ  Up/Down       State Pre
fRcv

  34.1.1.1        4         100        4        2     0 00:00:13 Established     0

四基础配置完 搞通它……

A-Hub-1宣告192。168。1。1
A-Spoke宣告192。168。2。1

查看路由表A-Hub-1 没有学习到192。168。2。1
但是AR1 的 VPN-A 有该条路由

两边CE AS号相同 ,从AR1面相CE开启 AS替换
同样AR3面相 CE
AS号替换原因+基础实验
IBGP:运行于同一AS内部的BGP称为IBGP。为防止AS内产生环路,BGP设备不将从IBGP对等体学习到的路由发布给其他IBGP对等体

AR1
[Huawei-bgp-A]peer 15.1.1.2  substitute-as 
[Huawei-bgp-A]peer 16.1.1.2 substitute-as 
AR3
[Huawei-bgp-A]peer 34.1.1.2 substitute-as 

此时查看A-Hub的路由表,出现通过下一跳15.1.1.1到达网络192.168.1.0的路由条目在这里插入图片描述
该路由从A-Hub-1、A-Hub-2、又从AR1传回
在这里插入图片描述
为避免上述问题的出现,需在 RTA 上配置 SoO 特性
AR1
bgp 100
ipv4-family vpn-instance A
peer 15.1.1.2 soo 100:100
peer 16.1.1.2 soo 100:100

BGP soo:PE传递路由给CE时,检查出口配置的SOO值是否跟从其他MP-BGP邻居学到VPN-V4路由一致,如果一致就不会将路由传递给CE

[Huawei-bgp]dis bgp routing-table

 BGP Local router ID is 15.1.1.2 
 Status codes: * - valid, > - best, d - damped,
               h - history,  i - internal, s - suppressed, S - Stale
               Origin : i - IGP, e - EGP, ? - incomplete


 Total Number of Routes: 5
      Network            NextHop        MED        LocPrf    PrefVal Path/Ogn

 *>   5.5.5.5/32         0.0.0.0         0                     0      i
 *>i  6.6.6.6/32         56.1.1.2        0          100        0      i
 *>   192.168.1.0        0.0.0.0         0                     0      i
 *>   192.168.2.0        15.1.1.1                              0      100 100i
 * i                     56.1.1.2                   100        0      100 100i

总结

[Huawei-bgp]tracert -a 192.168
Jul 31 2024 23:35:53-08:00 Huawei %%01BGP/3/STATE_CHG_UPDOWN(l)[11]:The status o
f the peer 15.1.1.1 changed from OPENCONFIRM to ESTABLISHED. (InstanceName=Publi
c, StateChangeReason=Up)  
[Huawei-bgp]tracert -a 192.168.1.1 192.168.2.1

 traceroute to  192.168.2.1(192.
168.2.1), max hops: 30 ,packet length: 40,press CTRL_C to break 

 1 15.1.1.1 30 ms  20 ms  20 ms 

 2 12.1.1.2 40 ms  40 ms  30 ms 

 3 34.1.1.1 30 ms  20 ms  30 ms 

 4 34.1.1.2 40 ms  50 ms  40 ms 

关闭 AR1的 g0/0/0

[Huawei-bgp]tracert -a 192.168.1.1 192.168.2.1

 traceroute to  192.168.2.1(192.
168.2.1), max hops: 30 ,packet length: 40,press CTRL_C to break 

 1 
Jul 31 2024 23:36:22-08:00 Huawei %%01IFPDT/4/IF_STATE(l)[12]:Interface GigabitE
thernet0/0/1 has turned into DOWN state.
[Huawei-bgp]
Jul 31 2024 23:36:22-08:00 Huawei %%01IFNET/4/LINK_STATE(l)[13]:The line protoco
l IP on the interface GigabitEthernet0/0/1 has entered the DOWN state. 
[Huawei-bgp]
Jul 31 2024 23:36:22-08:00 Huawei %%01BGP/3/STATE_CHG_UPDOWN(l)[14]:The status o
f the peer 15.1.1.1 changed from ESTABLISHED to IDLE. (InstanceName=Public, Stat
eChangeReason=CEASE/Other Configuration Change)  
[Huawei-bgp] * 56.1.1.2 20 ms  20 ms 

 2 16.1.1.1 30 ms  30 ms  40 ms 

 3 12.1.1.2 40 ms  50 ms  40 ms 

 4 34.1.1.1 30 ms  40 ms  40 ms 

 5 34.1.1.2 40 ms  40 ms  50 ms 
  • 7
    点赞
  • 12
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值