一、拓朴:
要求:客户B: R6的192.169.6.6 能通过ISP的 AS234,ping 通客户B '的 192.168.7.7
二、主要配置过程:
R2、R3、R4起IGP邻居关系,为ospf 1; R2和R4起 IBGP邻居关系;
R1起ospf,宣告192.168.6.6;R2起vpn-instanceB,配置RD、RT,并在接口G0/0/2绑定vpn-instance B;R2起ospf 100,绑定vpn-instance B,完成CE、PE之间的IGP联系; 并导入BGP路由;
R2的BGP234 起vpnv4的地址族,并在vpn-instance B中导入ospf 100;
相应地,R4和R7镜像地做一遍 ↑
三、配置命令:
[R2]:
ip vpn-instance B
ipv4-family
route-distinguisher 22:22
vpn-target 22:22 export-extcommunity
vpn-target 22:22 import-extcommunity
#
mpls lsr-id 10.1.2.2
mpls
mpls ldp
#
interface GigabitEthernet0/0/0
ip address 10.1.12.2 255.255.255.0
mpls
mpls ldp
#
interface GigabitEthernet0/0/1
ip address 10.1.23.2 255.255.255.0
mpls
mpls ldp
#
interface GigabitEthernet0/0/2
ip binding vpn-instance B
ip address 10.1.26.2 255.255.255.0
#
interface NULL0
#
interface LoopBack0
ip address 10.1.2.2 255.255.255.255
#
bgp 234
router-id 2.2.2.2
undo default ipv4-unicast
peer 10.1.4.4 as-number 234
peer 10.1.4.4 connect-interface LoopBack0
#
ipv4-family unicast
undo synchronization
undo peer 10.1.4.4 enable
#
ipv4-family vpnv4
policy vpn-target
peer 10.1.4.4 enable
#
ipv4-family vpn-instance B
import-route ospf 100
#
ospf 1 router-id 10.1.2.2
import-route static
area 0.0.0.0
network 10.1.2.2 0.0.0.0
network 10.1.12.0 0.0.0.255
network 10.1.23.0 0.0.0.255
#
ospf 100 router-id 10.1.2.2 vpn-instance B
import-route bgp
area 0.0.0.0
network 10.1.26.0 0.0.0.255
#
ip route-static 10.1.1.1 255.255.255.255 10.1.12.1
ip route-static 10.1.6.0 255.255.255.0 10.1.23.3
#
四、总结和其它:
1、PE和CE之间,如果是静态,仅在PE端做单向注入到IBGP;
如果是IGP,如ospf、isis、rip,做双向注入;
如果是BGP关系,则不需注入;
2、ospf vpn-instance,默认情况下,下发的路由,会将DN置位,可防止路由回灌风险)
dn-bit-set disable summary|ASE#如果在确定没有环路的情况下,可以设置DN不置位。这时CE可以配置配置MCE,防止计算不出路由(Send 方)
dn-bit-check disable summary|ase #不检查dn位(接收方)
vpn-instance-capability simple #关闭所有vpn-instance环路检查(类似于正常的ospf,而不是vpn-instance
3、apply-label per-instance #在vpn-instance 下敲,目的为了节省标签和系统资源,instance A下面的所有路由,分配同一标签;
4、ARF:Auto RT Filterpolicy vpnv4-target这条命令是默认存在的,用undo policy vpnv4-target 关闭ARF,则vpnv4总表会不过滤地接收任何vpnv4路由,但不会放入不符合IVT导入限制的分表
5、通过vpnv4传过来的ospf注入的BGP路由,会携带extcommunity属性,把domain id、area id、ospf路由属性一同带过来,再注入到ospf里,相同的domain-id,路由类型会一对一传,不同的domain-id,则传入的路由类型,都是五类