L3VPN over IS-IS SR-MPLS BE配置示例

L3VPN over IS-IS SR-MPLS BE配置示例

组网需求

CE1、CE2属于vpn1,vpn1使用的VPN-target属性为100:10,配置L3VPN迭代IS-IS SR-MPLS BE隧道,保证相同VPN用户之间的安全互访。


组网拓扑


配置思路

采用如下的思路配置L3VPN迭代IS-IS SR-MPLS BE隧道:

  1. 骨干网上配置IS-IS实现PE之间的互通;
  2. 骨干网上使能MPLS,配置Segment Routing,建立SR LSP;
  3. PE上配置使能IPv4地址族VPN实例,并把与CE相连的接口和相应的VPN实例绑定;
  4. PE之间配置MP-IBGP交换路由信息;
  5. CE与PE之间配置EBGP交换路由信息。

配置脚本

1. PE1配置

#
sysname NE1
#
ip vpn-instance vpn1
 ipv4-family
  route-distinguisher 100:10
  vpn-target 100:10 export-extcommunity
  vpn-target 100:10 import-extcommunity
#
mpls lsr-id 1.1.1.1
#
mplp //使能mpls,当接口下使能IS-IS功能后,接口自动使能MPLS能力,所以可以忽略接口下MPLS配置。 
#
segment-routing //使能Segment Routing功能
#
isis 10
 is-level level-2
 cost-style wide
 network-entity 50.0000.0000.0000.0001.00
 segment-routing mpls //使能OSPF的Segment Routing功能。
 segment-routing global-block 16000 17999 //配置SRGB标签范围。
#
interface Ethernet1/0/0
 undo shutdown
 ip address 10.1.12.1 255.255.255.0
 isis enable 10 //当接口下使能IS-IS功能后,接口自动使能MPLS能力,所以可以忽略接口下MPLS配置。 
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface Ethernet1/0/1
 undo shutdown
 ip binding vpn-instance vpn1
 ip address 100.1.1.1 255.255.255.252
 undo dcn
 undo dcn mode vlan
#
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255
 isis enable 10
 isis prefix-sid index 10
#
bgp 100
 router-id 1.1.1.1
 peer 6.6.6.6 as-number 100
 peer 6.6.6.6 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  peer 6.6.6.6 enable
 #
 ipv4-family vpnv4
  policy vpn-target
  peer 6.6.6.6 enable
 #
 ipv4-family vpn-instance vpn1
  peer 100.1.1.2 as-number 65510
#

2. P1配置

#
sysname NE2
#
mpls lsr-id 2.2.2.2
#
mpls
#
segment-routing
#
isis 10
 is-level level-2
 cost-style wide
 network-entity 50.0000.0000.0000.0002.00
 segment-routing mpls
 segment-routing global-block 16000 17999
#
interface Ethernet1/0/0
 undo shutdown
 ip address 10.1.12.2 255.255.255.0
 isis enable 10
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface Ethernet1/0/1
 undo shutdown
 ip address 10.1.234.2 255.255.255.0
 isis enable 10
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface LoopBack0
 ip address 2.2.2.2 255.255.255.255
 isis enable 10
 isis prefix-sid index 20
#

3. P2配置

#
sysname NE3
#
mpls lsr-id 3.3.3.3
#
mpls
#
segment-routing
#
isis 10
 is-level level-2
 cost-style wide
 network-entity 50.0000.0000.0000.0003.00
 segment-routing mpls
 segment-routing global-block 16000 17999
#
interface Ethernet1/0/0
 undo shutdown
 ip address 10.1.234.3 255.255.255.0
 isis enable 10
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface Ethernet1/0/1
 undo shutdown
 ip address 10.1.35.3 255.255.255.0
 isis enable 10
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255
 isis enable 10
 isis prefix-sid index 30
#

4. P3配置

#
sysname NE4
#
mpls lsr-id 4.4.4.4
#
mpls
#
segment-routing
#
isis 10
 is-level level-2
 cost-style wide
 network-entity 50.0000.0000.0000.0004.00
 segment-routing mpls
 segment-routing global-block 16000 17999
#
interface Ethernet1/0/0
 undo shutdown
 ip address 10.1.234.4 255.255.255.0
 isis enable 10
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface Ethernet1/0/1
 undo shutdown
 ip address 10.1.45.4 255.255.255.0
 isis enable 10
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface LoopBack0
 ip address 4.4.4.4 255.255.255.255
 isis enable 10
 isis prefix-sid index 40
#

5. P4配置

#
sysname NE5
#
mpls lsr-id 5.5.5.5
#
mpls
#
segment-routing
#
isis 10
 is-level level-2
 cost-style wide
 network-entity 50.0000.0000.0000.0005.00
 segment-routing mpls
 segment-routing global-block 16000 17999
#
interface Ethernet1/0/0
 undo shutdown
 ip address 10.1.56.5 255.255.255.0
 isis enable 10
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface Ethernet1/0/1
 undo shutdown
 ip address 10.1.35.5 255.255.255.0
 isis enable 10
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface Ethernet1/0/2
 undo shutdown
 ip address 10.1.45.5 255.255.255.0
 isis enable 10
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn mode vlan
#
interface LoopBack0
 ip address 5.5.5.5 255.255.255.255
 isis enable 10
 isis prefix-sid index 50
#

6. PE2配置

#
sysname NE6
#
ip vpn-instance vpn1
 ipv4-family
  route-distinguisher 100:10
  vpn-target 100:10 export-extcommunity
  vpn-target 100:10 import-extcommunity
#
mpls lsr-id 6.6.6.6
#
mpls
#
segment-routing
#
isis 10
 is-level level-2
 cost-style wide
 network-entity 50.0000.0000.0000.0006.00
 segment-routing mpls
 segment-routing global-block 16000 17999
#
interface Ethernet1/0/0
 undo shutdown
 ip address 10.1.56.6 255.255.255.0
 isis enable 10
 isis circuit-type p2p
 isis circuit-level level-2
 undo dcn
 undo dcn mode vlan
#
interface Ethernet1/0/1
 undo shutdown
 ip binding vpn-instance vpn1
 ip address 100.1.1.5 255.255.255.252
 undo dcn
 undo dcn mode vlan
#
interface LoopBack0
 ip address 6.6.6.6 255.255.255.255
 isis enable 10
 isis prefix-sid index 60
#
interface NULL0
#
bgp 100
 router-id 6.6.6.6
 peer 1.1.1.1 as-number 100
 #
 ipv4-family unicast
  undo synchronization
  peer 1.1.1.1 enable
 #
 ipv4-family vpnv4
  policy vpn-target
  peer 1.1.1.1 enable
 #
 ipv4-family vpn-instance vpn1
  peer 100.1.1.6 as-number 65520
#

7. CE1配置

#
 sysname R1
#
interface GigabitEthernet0/0/0
 ip address 100.1.1.2 255.255.255.252 
#
interface LoopBack0
 ip address 11.11.11.11 255.255.255.255 
#
interface LoopBack192
 ip address 192.168.1.1 255.255.255.0 
#
bgp 65510
 router-id 11.11.11.11
 peer 100.1.1.1 as-number 100 
 #
 ipv4-family unicast
  undo synchronization
  network 192.168.1.0 
  peer 100.1.1.1 enable
#

8. CE2配置

#
 sysname R2
#
interface GigabitEthernet0/0/0
 ip address 100.1.1.6 255.255.255.252 
#
interface LoopBack0
 ip address 22.22.22.22 255.255.255.255 
#
interface LoopBack192
 ip address 192.168.2.1 255.255.255.0 
#
bgp 65520
 router-id 22.22.22.22
 peer 100.1.1.5 as-number 100 
 #
 ipv4-family unicast
  undo synchronization
  network 192.168.2.0 
  peer 100.1.1.5 enable
#

  • 配置完成后,在PE1设备上执行display tunnel-info all命令,可以看到SR LSP已建立,以PE1的显示为例。


  • 在PE1上使用Ping检测SR LSP连通性,例如:


  • 在PE1上使用display segment-routing prefix mpls forwarding命令来查看Segment Routing的标签转发表信息,以PE1的显示为例:


  • 在PE1上使用display segment-routing adjacency mpls forwarding命令来查看Segment Routing邻接标签转发表,以PE1的显示为例。


  • 在P1上使用display isis lsdb查看IS-IS链路状态数据库。


  • 在P1上使用display isis lsdb verbose 0000.0000.0001.00-00 查看LSP详细信息。


IS-IS for SR-MPLS
SR-MPLS使用IGP进行拓扑信息、前缀信息、SRGB和标签信息的通告。IGP为了完成上述功能,对于协议报文的TLV进行了一些扩展。IS-IS协议主要定义了针对SID和网元SR-MPLS能力的子TLV(Sub-TLV)。具体如图所示。


  • 在PE1设备上执行display bgp peer 或 display bgp vpnv4 all peer命令,可以看到PE之间的BGP对等体关系已建立,并达到Established状态,以PE1的显示为例。


  • 在PE1设备上执行display bgp vpnv4 vpn-instance vpn1 peer命令,可以看到PE1与CE1之间的BGP对等体关系已建立,并达到Established状态,以PE1与CE1的对等体关系为例:


  • 检查配置结果,在PE1设备上执行display ip routing-table vpn-instance vpn1查看vpn1的路由,以PE1的显示为例:


  • 同一VPN的CE能够相互Ping通,例如:CE1能够Ping通CE2。

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值