MPLS-VPN-扩展案例

实验需求

客户X有2个站点,现需要通过MPLS VPN实现站点之间的互联,对应VPNX,互联接口、AS号及IP地址信息如图。
客户X站点A与BRAS之间采用OSPF交互路由信息,客户X站点B与BRAS之间采用静态交互路由信息

组网图

数据规划

MPLS骨干网采用单区域OSPF实现路由互通,所有PE和P互联接口均使能MPLS LDP功能。 PE上的VPN相关配置如表格:

配置项描述
VPN名称BRAS1PE2
RDVPNXVPNX
IRT64640:17264640:172
ERT64640:17264640:172
接口G0/0/1G0/0/0
MP-BGP源接口:Loopback0源接口:Loopback0

配置思路

1. MPLS VPN骨干网配置

1.1 IGP配置,实现骨干网的IP连通性。

1.2 MPLS与MPLS LDP配置,建立MPLS LSP公网隧道,传输VPN数据。

1.3 MP-BGP配置(PE与P),建立后续传递VPNv4路由的MP-BGP对等体关系。

1.4 MP-BGP还应考虑MP-IBGP水平分割问题。

2. VPN用户接入配置

2.1 创建VPN实例并配置参数(RT、RD)

2.2 将接口加入VPN实例

2.3 配置PE与CE之间的路由交换

IGP配置

BRAS1

<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn BRAS1
[BRAS1]int  g0/0/1
[BRAS1-GigabitEthernet0/0/1]ip ad 10.1.12.1  30
[BRAS1-GigabitEthernet0/0/1]int loo0
[BRAS1-LoopBack0]ip ad 11.1.1.1  32
[BRAS1-LoopBack0]q

[BRAS1]ospf  100  router-id  11.1.1.1
[BRAS1-ospf-100]area 0
[BRAS1-ospf-100-area-0.0.0.0]net 11.1.1.1  0.0.0.0
[BRAS1-ospf-100-area-0.0.0.0]net 10.1.12.1  0.0.0.0
[BRAS1-ospf-100-area-0.0.0.0]q
[BRAS1-ospf-100]q

RT07

<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn RT07
[RT07]int g0/0/0
[RT07-GigabitEthernet0/0/0]ip ad 10.1.12.2  30
[RT07-GigabitEthernet0/0/0]int  g0/0/1
[RT07-GigabitEthernet0/0/1]ip ad 10.1.23.1  30
[RT07-GigabitEthernet0/0/1]int loo0
[RT07-LoopBack0]ip ad 22.1.1.1  32
[RT07-LoopBack0]q

[RT07]ospf  100  router-id  22.1.1.1
[RT07-ospf-100]area 0
[RT07-ospf-100-area-0.0.0.0]net 22.1.1.1  0.0.0.0
[RT07-ospf-100-area-0.0.0.0]net 10.1.12.2  0.0.0.0
[RT07-ospf-100-area-0.0.0.0]net 10.1.23.1  0.0.0.0
[RT07-ospf-100-area-0.0.0.0]q
[RT07-ospf-100]q

PE2

<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn PE
[PE]int g0/0/0
[PE-GigabitEthernet0/0/0]ip ad 10.1.23.2  30
[PE-GigabitEthernet0/0/0]int loo0
[PE-LoopBack0]ip ad 33.1.1.1  32
[PE-LoopBack0]q

[PE]ospf  100  router-id  33.1.1.1
[PE-ospf-100]area 0
[PE-ospf-100-area-0.0.0.0]net 33.1.1.1  0.0.0.0
[PE-ospf-100-area-0.0.0.0]net 10.1.23.2  0.0.0.0
[PE-ospf-100-area-0.0.0.0]q
[PE-ospf-100]q

MPLS与MPLS LDP配置

BRAS1

[BRAS1]mpls  lsr-id 11.1.1.1 
[BRAS1]mpls	
[BRAS1-mpls]q
[BRAS1]mpls  ldp
[BRAS1-mpls-ldp]q
[BRAS1]int g0/0/1
[BRAS1-GigabitEthernet0/0/1]mpls
[BRAS1-GigabitEthernet0/0/1]mpls ldp
[BRAS1-GigabitEthernet0/0/1]q

RT07

[RT07]mpls  lsr-id 22.1.1.1 	
[RT07]mpls 
[RT07-mpls]q
[RT07]mpls  ldp
[RT07-mpls-ldp]q
[RT07]int g0/0/1
[RT07-GigabitEthernet0/0/1]mpls
[RT07-GigabitEthernet0/0/1]mpls ldp
[RT07-GigabitEthernet0/0/1]int g0/0/0
[RT07-GigabitEthernet0/0/0]mpls
[RT07-GigabitEthernet0/0/0]mpls ldp
[RT07-GigabitEthernet0/0/0]q

PE2

[PE]mpls  lsr-id 33.1.1.1 
[PE]mpls	
[PE-mpls]q
[PE]mpls  ldp
[PE-mpls-ldp]q
[PE]int g0/0/1
[PE-GigabitEthernet0/0/1]mpls
[PE-GigabitEthernet0/0/1]mpls ldp
[PE-GigabitEthernet0/0/1]int g0/0/0
[PE-GigabitEthernet0/0/0]mpls
[PE-GigabitEthernet0/0/0]mpls ldp
[PE-GigabitEthernet0/0/0]q

MP-BGP配置

BRAS1

[BRAS1]bgp  64640 
[BRAS1-bgp]router-id  11.1.1.1
[BRAS1-bgp]peer  22.1.1.1  as-number 64640
[BRAS1-bgp]peer  22.1.1.1  connect-interface loo0
[BRAS1-bgp]ipv4-family  vpnv4   unicast
[BRAS1-bgp-af-vpnv4]peer  22.1.1.1  enable
[BRAS1-bgp-af-vpnv4]q
[BRAS1-bgp]q

RT07

[RT07]bgp  64640 
[RT07-bgp]router-id  22.1.1.1
[RT07-bgp]peer  11.1.1.1  as-number 64640
[RT07-bgp]peer  11.1.1.1  connect-interface loo0
[RT07-bgp]peer  33.1.1.1  as-number 64640
[RT07-bgp]peer  33.1.1.1  connect-interface loo0
[RT07-bgp]ipv4-family  vpnv4   unicast
[RT07-bgp-af-vpnv4]peer  11.1.1.1  enable
[RT07-bgp-af-vpnv4]peer  33.1.1.1  enable
[RT07-bgp-af-vpnv4]undo policy vpn-target
[RT07-bgp-af-vpnv4]q
[RT07-bgp]ipv4-family vpnv4
[RT07-bgp-af-vpnv4]peer 11.1.1.1 reflect-client
[RT07-bgp-af-vpnv4]peer 33.1.1.1 reflect-client
[RT07-bgp-af-vpnv4]q
[RT07-bgp]q

PE2

[PE]bgp  64640 
[PE-bgp]router-id  33.1.1.1
[PE-bgp]peer  22.1.1.1  as-number 64640
[PE-bgp]peer  22.1.1.1  connect-interface loo0
[PE-bgp]ipv4-family  vpnv4   unicast
[PE-bgp-af-vpnv4]peer  22.1.1.1  enable
[PE-bgp-af-vpnv4]q
[PE-bgp]q

创建VPN实例并配置参数

BRAS1

[BRAS1]ip vpn-instance VPNX
[BRAS1-vpn-instance-VPNX]route-distinguisher 64640:172
[BRAS1-vpn-instance-VPNX-af-ipv4]vpn-target 64640:172 both
[BRAS1-vpn-instance-VPNX-af-ipv4]q
[BRAS1-vpn-instance-VPNX]q

PE2

[PE]ip vpn-instance VPNX
[PE-vpn-instance-VPNX]route-distinguisher 64640:172
[PE-vpn-instance-VPNX-af-ipv4]vpn-target 64640:172 both
[PE-vpn-instance-VPNX-af-ipv4]q
[PE-vpn-instance-VPNX]q

将接口加入VPN实例

BRAS1

[BRAS1]interface GigabitEthernet 0/0/0
[BRAS1-GigabitEthernet0/0/0]ip binding vpn-instance VPNX
[BRAS1-GigabitEthernet0/0/0]ip ad 10.1.11.2  30
[BRAS1-GigabitEthernet0/0/0]q

PE2

[PE]interface GigabitEthernet 0/0/1
[PE-GigabitEthernet0/0/1]ip binding vpn-instance VPNX
[PE-GigabitEthernet0/0/1]ip ad  10.1.13.1  30
[PE-GigabitEthernet0/0/1]q

配置PE与CE之间的路由交换

BRAS1

//创建与实例绑定的OSPF进程
[BRAS1]ospf 2 vpn-instance  VPNX
[BRAS1-ospf-2]area 0
[BRAS1-ospf-2-area-0.0.0.0]net 10.1.11.2  0.0.0.0
[BRAS1-ospf-2-area-0.0.0.0]q
//配置OSPF进程与MP-BGP之间的路由双向引入
[BRAS1-ospf-2]import-route bgp
[BRAS1-ospf-2]q

[BRAS1]bgp 64640
[BRAS1-bgp]ipv4-family vpn-instance VPNX
[BRAS1-bgp-VPNX]import-route ospf 2
[BRAS1-bgp-VPNX]q
[BRAS1-bgp]q

PE2

//配置PE2上配置静态vpn回城路由
[PE]ip route-static vpn-instance VPNX 172.16.31.0 24 10.1.13.2

[PE]bgp 64640
[PE-bgp]ipv4-family vpn-instance VPNX
[PE-bgp-VPNX]network 172.16.31.0 24
[PE-bgp-VPNX]q
[PE-bgp]q

CE1

<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn CE1
[CE1]int g0/0/0
[CE1-GigabitEthernet0/0/0]ip ad 10.1.11.1  30
[CE1-GigabitEthernet0/0/0]int loo0
[CE1-LoopBack0]ip ad 172.16.30.1  24
[CE1-LoopBack0]q
[CE1]ospf 2  
[CE1-ospf-2]area 0
[CE1-ospf-2-area-0.0.0.0]net 10.1.11.1  0.0.0.0
[CE1-ospf-2-area-0.0.0.0]net 172.16.30.0  0.0.0.0
[CE1-ospf-2-area-0.0.0.0]q
[CE1-ospf-2]q

//如果172.16.30.0 网段引入失败则可以通过路由策略重新引入——骨干设备的bgp只学习到172.16.31.0网段,没有172.16.30.0网段,即可考虑是否是路由引入问题
[CE1]ip ip-prefix zhilian  permit  172.16.30.0  24
[CE1]route-policy  zhilian  permit node 10
[CE1-route-policy]if-match ip-prefix  zhilain 
[CE1-route-policy]ospf  2
[CE1-ospf-2]import-route  direct  route-policy  zhilian 
[CE1-ospf-2]q
[CE1]ping -a 172.16.30.1   172.16.31.1   //ping测是否通常

CE3

<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn CE3
[CE3]int g0/0/0
[CE3-GigabitEthernet0/0/0]ip ad 10.1.13.2  30
[CE3-GigabitEthernet0/0/0]int loo0
[CE3-LoopBack0]ip ad 172.16.31.1  24
[CE3-LoopBack0]q

[CE3]ip route-static 0.0.0.0 0.0.0.0 10.1.13.1

查看mpls 标签表

测试

至此实验完成

总配置

BRAS1
un ter mon
sys
un in en
sysn BRAS1
int  g0/0/1
ip ad 10.1.12.1  30
int loo0
ip ad 11.1.1.1  32
q



//IGP配置
ospf  100  router-id  11.1.1.1
area 0
net 11.1.1.1  0.0.0.0
net 10.1.12.2  0.0.0.0
q
q

//MP-BGP配置
bgp  64640 
router-id  11.1.1.1
peer  22.1.1.1  as-number 64640
peer  22.1.1.1  connect-interface loo0
ipv4-family  vpnv4   unicast
peer  22.1.1.1  enable
q
q


//MPLS与MPLS LDP配置
mpls  lsr-id 11.1.1.1 
mpls	
q
mpls  ldp
q
int g0/0/1
mpls
mpls ldp
q

//创建VPN实例并按照规划配置RD与RT参数
ip vpn-instance VPNX
route-distinguisher 64640:172
vpn-target 64640:172 both
q
q

//将接口绑定到VPN实例
interface GigabitEthernet 0/0/0
ip binding vpn-instance VPNX
ip ad 10.1.11.2  30
q

//创建与实例绑定的OSPF进程
ospf 2 vpn-instance  VPNX
area 0
net 10.1.11.2  0.0.0.0
q

//配置OSPF进程与MP-BGP之间的路由双向引入
ospf 2 vpn-instance VPNX
import-route bgp
q
bgp 64640
ipv4-family vpn-instance VPNX
import-route ospf 2
q
q



RT07
un ter mon
sys
un in en
sysn RT07
int g0/0/0
ip ad 10.1.12.2  30
int  g0/0/1
ip ad 10.1.23.1  30
int loo0
ip ad 22.1.1.1  32
q

//IGP配置
ospf  100  router-id  22.1.1.1
area 0
net 22.1.1.1  0.0.0.0
net 10.1.12.2  0.0.0.0
net 10.1.23.1  0.0.0.0
q
q

//MP-BGP配置
bgp  64640 
router-id  22.1.1.1
peer  11.1.1.1  as-number 64640
peer  11.1.1.1  connect-interface loo0
peer  33.1.1.1  as-number 64640
peer  33.1.1.1  connect-interface loo0
ipv4-family  vpnv4   unicast
peer  11.1.1.1  enable
peer  33.1.1.1  enable
undo policy vpn-target
q
ipv4-family vpnv4
peer 11.1.1.1 reflect-client
peer 33.1.1.1 reflect-client
q

//MPLS与MPLS LDP配置
mpls  lsr-id 22.1.1.1 
mpls	
q
mpls  ldp
q
int g0/0/1
mpls
mpls ldp
int g0/0/0
mpls
mpls ldp





PE
un ter mon
sys
un in en
sysn PE
int g0/0/0
ip ad 10.1.23.2  30
int loo0
ip ad 33.1.1.1  32
q

//IGP配置
ospf  100  router-id  33.1.1.1
area 0
net 33.1.1.1  0.0.0.0
net 10.1.23.2  0.0.0.0
q
q

//MP-BGP配置
bgp  64640 
router-id  33.1.1.1
peer  22.1.1.1  as-number 64640
peer  22.1.1.1  connect-interface loo0
ipv4-family  vpnv4   unicast
peer  22.1.1.1  enable
q
q

//MPLS与MPLS LDP配置
mpls  lsr-id 33.1.1.1 
mpls	
q
mpls  ldp
q
int g0/0/1
mpls
mpls ldp
int g0/0/0
mpls
mpls ldp
q

//创建VPN实例并按照规划配置RD与RT参数
ip vpn-instance VPNX
route-distinguisher 64640:172
vpn-target 64640:172 both
q
q

//将接口绑定到VPN实例
interface GigabitEthernet 0/0/1
ip binding vpn-instance VPNX
ip ad  10.1.13.1  30
q

//配置PE2上配置静态vpn回城路由
ip route-static vpn-instance VPNX 172.16.31.0 24 10.1.13.2
bgp 64640
ipv4-family vpn-instance VPNX
network 172.16.31.0 24
q
q




CE1
un ter mon
sys
un in en
sysn CE1
int g0/0/0
ip ad 10.1.11.1  30
int loo0
ip ad 172.16.30.1  24
q
ospf 2  
area 0
net 10.1.11.1  0.0.0.0
net 172.16.30.0  0.0.0.0
q
q


//172.16.30.0网段引入不成功
ip ip-prefix zhilian  permit  172.16.30.0  24
route-policy  zhilian  permit node 10
if-match ip-prefix  zhilain 
ospf  2
import-route  direct  route-policy  zhilian 
q

CE3
un ter mon
sys
un in en
sysn CE3
int g0/0/0
ip ad 10.1.13.2  30
int loo0
ip ad 172.16.31.1  24
q
使用静态
ip route-static 0.0.0.0 0.0.0.0 10.1.13.1

  • 11
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值