实验需求
客户X有2个站点,现需要通过MPLS VPN实现站点之间的互联,对应VPNX,互联接口、AS号及IP地址信息如图。
客户X站点A与BRAS之间采用OSPF交互路由信息,客户X站点B与BRAS之间采用静态交互路由信息
组网图
数据规划
MPLS骨干网采用单区域OSPF实现路由互通,所有PE和P互联接口均使能MPLS LDP功能。 PE上的VPN相关配置如表格:
配置项 | 描述 | |
VPN名称 | BRAS1 | PE2 |
RD | VPNX | VPNX |
IRT | 64640:172 | 64640:172 |
ERT | 64640:172 | 64640:172 |
接口 | G0/0/1 | G0/0/0 |
MP-BGP | 源接口:Loopback0 | 源接口:Loopback0 |
配置思路
1. MPLS VPN骨干网配置
1.1 IGP配置,实现骨干网的IP连通性。
1.2 MPLS与MPLS LDP配置,建立MPLS LSP公网隧道,传输VPN数据。
1.3 MP-BGP配置(PE与P),建立后续传递VPNv4路由的MP-BGP对等体关系。
1.4 MP-BGP还应考虑MP-IBGP水平分割问题。
2. VPN用户接入配置
2.1 创建VPN实例并配置参数(RT、RD)
2.2 将接口加入VPN实例
2.3 配置PE与CE之间的路由交换
IGP配置
BRAS1
<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn BRAS1
[BRAS1]int g0/0/1
[BRAS1-GigabitEthernet0/0/1]ip ad 10.1.12.1 30
[BRAS1-GigabitEthernet0/0/1]int loo0
[BRAS1-LoopBack0]ip ad 11.1.1.1 32
[BRAS1-LoopBack0]q
[BRAS1]ospf 100 router-id 11.1.1.1
[BRAS1-ospf-100]area 0
[BRAS1-ospf-100-area-0.0.0.0]net 11.1.1.1 0.0.0.0
[BRAS1-ospf-100-area-0.0.0.0]net 10.1.12.1 0.0.0.0
[BRAS1-ospf-100-area-0.0.0.0]q
[BRAS1-ospf-100]q
RT07
<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn RT07
[RT07]int g0/0/0
[RT07-GigabitEthernet0/0/0]ip ad 10.1.12.2 30
[RT07-GigabitEthernet0/0/0]int g0/0/1
[RT07-GigabitEthernet0/0/1]ip ad 10.1.23.1 30
[RT07-GigabitEthernet0/0/1]int loo0
[RT07-LoopBack0]ip ad 22.1.1.1 32
[RT07-LoopBack0]q
[RT07]ospf 100 router-id 22.1.1.1
[RT07-ospf-100]area 0
[RT07-ospf-100-area-0.0.0.0]net 22.1.1.1 0.0.0.0
[RT07-ospf-100-area-0.0.0.0]net 10.1.12.2 0.0.0.0
[RT07-ospf-100-area-0.0.0.0]net 10.1.23.1 0.0.0.0
[RT07-ospf-100-area-0.0.0.0]q
[RT07-ospf-100]q
PE2
<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn PE
[PE]int g0/0/0
[PE-GigabitEthernet0/0/0]ip ad 10.1.23.2 30
[PE-GigabitEthernet0/0/0]int loo0
[PE-LoopBack0]ip ad 33.1.1.1 32
[PE-LoopBack0]q
[PE]ospf 100 router-id 33.1.1.1
[PE-ospf-100]area 0
[PE-ospf-100-area-0.0.0.0]net 33.1.1.1 0.0.0.0
[PE-ospf-100-area-0.0.0.0]net 10.1.23.2 0.0.0.0
[PE-ospf-100-area-0.0.0.0]q
[PE-ospf-100]q
MPLS与MPLS LDP配置
BRAS1
[BRAS1]mpls lsr-id 11.1.1.1
[BRAS1]mpls
[BRAS1-mpls]q
[BRAS1]mpls ldp
[BRAS1-mpls-ldp]q
[BRAS1]int g0/0/1
[BRAS1-GigabitEthernet0/0/1]mpls
[BRAS1-GigabitEthernet0/0/1]mpls ldp
[BRAS1-GigabitEthernet0/0/1]q
RT07
[RT07]mpls lsr-id 22.1.1.1
[RT07]mpls
[RT07-mpls]q
[RT07]mpls ldp
[RT07-mpls-ldp]q
[RT07]int g0/0/1
[RT07-GigabitEthernet0/0/1]mpls
[RT07-GigabitEthernet0/0/1]mpls ldp
[RT07-GigabitEthernet0/0/1]int g0/0/0
[RT07-GigabitEthernet0/0/0]mpls
[RT07-GigabitEthernet0/0/0]mpls ldp
[RT07-GigabitEthernet0/0/0]q
PE2
[PE]mpls lsr-id 33.1.1.1
[PE]mpls
[PE-mpls]q
[PE]mpls ldp
[PE-mpls-ldp]q
[PE]int g0/0/1
[PE-GigabitEthernet0/0/1]mpls
[PE-GigabitEthernet0/0/1]mpls ldp
[PE-GigabitEthernet0/0/1]int g0/0/0
[PE-GigabitEthernet0/0/0]mpls
[PE-GigabitEthernet0/0/0]mpls ldp
[PE-GigabitEthernet0/0/0]q
MP-BGP配置
BRAS1
[BRAS1]bgp 64640
[BRAS1-bgp]router-id 11.1.1.1
[BRAS1-bgp]peer 22.1.1.1 as-number 64640
[BRAS1-bgp]peer 22.1.1.1 connect-interface loo0
[BRAS1-bgp]ipv4-family vpnv4 unicast
[BRAS1-bgp-af-vpnv4]peer 22.1.1.1 enable
[BRAS1-bgp-af-vpnv4]q
[BRAS1-bgp]q
RT07
[RT07]bgp 64640
[RT07-bgp]router-id 22.1.1.1
[RT07-bgp]peer 11.1.1.1 as-number 64640
[RT07-bgp]peer 11.1.1.1 connect-interface loo0
[RT07-bgp]peer 33.1.1.1 as-number 64640
[RT07-bgp]peer 33.1.1.1 connect-interface loo0
[RT07-bgp]ipv4-family vpnv4 unicast
[RT07-bgp-af-vpnv4]peer 11.1.1.1 enable
[RT07-bgp-af-vpnv4]peer 33.1.1.1 enable
[RT07-bgp-af-vpnv4]undo policy vpn-target
[RT07-bgp-af-vpnv4]q
[RT07-bgp]ipv4-family vpnv4
[RT07-bgp-af-vpnv4]peer 11.1.1.1 reflect-client
[RT07-bgp-af-vpnv4]peer 33.1.1.1 reflect-client
[RT07-bgp-af-vpnv4]q
[RT07-bgp]q
PE2
[PE]bgp 64640
[PE-bgp]router-id 33.1.1.1
[PE-bgp]peer 22.1.1.1 as-number 64640
[PE-bgp]peer 22.1.1.1 connect-interface loo0
[PE-bgp]ipv4-family vpnv4 unicast
[PE-bgp-af-vpnv4]peer 22.1.1.1 enable
[PE-bgp-af-vpnv4]q
[PE-bgp]q
创建VPN实例并配置参数
BRAS1
[BRAS1]ip vpn-instance VPNX
[BRAS1-vpn-instance-VPNX]route-distinguisher 64640:172
[BRAS1-vpn-instance-VPNX-af-ipv4]vpn-target 64640:172 both
[BRAS1-vpn-instance-VPNX-af-ipv4]q
[BRAS1-vpn-instance-VPNX]q
PE2
[PE]ip vpn-instance VPNX
[PE-vpn-instance-VPNX]route-distinguisher 64640:172
[PE-vpn-instance-VPNX-af-ipv4]vpn-target 64640:172 both
[PE-vpn-instance-VPNX-af-ipv4]q
[PE-vpn-instance-VPNX]q
将接口加入VPN实例
BRAS1
[BRAS1]interface GigabitEthernet 0/0/0
[BRAS1-GigabitEthernet0/0/0]ip binding vpn-instance VPNX
[BRAS1-GigabitEthernet0/0/0]ip ad 10.1.11.2 30
[BRAS1-GigabitEthernet0/0/0]q
PE2
[PE]interface GigabitEthernet 0/0/1
[PE-GigabitEthernet0/0/1]ip binding vpn-instance VPNX
[PE-GigabitEthernet0/0/1]ip ad 10.1.13.1 30
[PE-GigabitEthernet0/0/1]q
配置PE与CE之间的路由交换
BRAS1
//创建与实例绑定的OSPF进程
[BRAS1]ospf 2 vpn-instance VPNX
[BRAS1-ospf-2]area 0
[BRAS1-ospf-2-area-0.0.0.0]net 10.1.11.2 0.0.0.0
[BRAS1-ospf-2-area-0.0.0.0]q
//配置OSPF进程与MP-BGP之间的路由双向引入
[BRAS1-ospf-2]import-route bgp
[BRAS1-ospf-2]q
[BRAS1]bgp 64640
[BRAS1-bgp]ipv4-family vpn-instance VPNX
[BRAS1-bgp-VPNX]import-route ospf 2
[BRAS1-bgp-VPNX]q
[BRAS1-bgp]q
PE2
//配置PE2上配置静态vpn回城路由
[PE]ip route-static vpn-instance VPNX 172.16.31.0 24 10.1.13.2
[PE]bgp 64640
[PE-bgp]ipv4-family vpn-instance VPNX
[PE-bgp-VPNX]network 172.16.31.0 24
[PE-bgp-VPNX]q
[PE-bgp]q
CE1
<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn CE1
[CE1]int g0/0/0
[CE1-GigabitEthernet0/0/0]ip ad 10.1.11.1 30
[CE1-GigabitEthernet0/0/0]int loo0
[CE1-LoopBack0]ip ad 172.16.30.1 24
[CE1-LoopBack0]q
[CE1]ospf 2
[CE1-ospf-2]area 0
[CE1-ospf-2-area-0.0.0.0]net 10.1.11.1 0.0.0.0
[CE1-ospf-2-area-0.0.0.0]net 172.16.30.0 0.0.0.0
[CE1-ospf-2-area-0.0.0.0]q
[CE1-ospf-2]q
//如果172.16.30.0 网段引入失败则可以通过路由策略重新引入——骨干设备的bgp只学习到172.16.31.0网段,没有172.16.30.0网段,即可考虑是否是路由引入问题
[CE1]ip ip-prefix zhilian permit 172.16.30.0 24
[CE1]route-policy zhilian permit node 10
[CE1-route-policy]if-match ip-prefix zhilain
[CE1-route-policy]ospf 2
[CE1-ospf-2]import-route direct route-policy zhilian
[CE1-ospf-2]q
[CE1]ping -a 172.16.30.1 172.16.31.1 //ping测是否通常
CE3
<Huawei>un ter mon
<Huawei>sys
[Huawei]un in en
[Huawei]sysn CE3
[CE3]int g0/0/0
[CE3-GigabitEthernet0/0/0]ip ad 10.1.13.2 30
[CE3-GigabitEthernet0/0/0]int loo0
[CE3-LoopBack0]ip ad 172.16.31.1 24
[CE3-LoopBack0]q
[CE3]ip route-static 0.0.0.0 0.0.0.0 10.1.13.1
查看mpls 标签表
测试
至此实验完成
总配置
BRAS1
un ter mon
sys
un in en
sysn BRAS1
int g0/0/1
ip ad 10.1.12.1 30
int loo0
ip ad 11.1.1.1 32
q
//IGP配置
ospf 100 router-id 11.1.1.1
area 0
net 11.1.1.1 0.0.0.0
net 10.1.12.2 0.0.0.0
q
q
//MP-BGP配置
bgp 64640
router-id 11.1.1.1
peer 22.1.1.1 as-number 64640
peer 22.1.1.1 connect-interface loo0
ipv4-family vpnv4 unicast
peer 22.1.1.1 enable
q
q
//MPLS与MPLS LDP配置
mpls lsr-id 11.1.1.1
mpls
q
mpls ldp
q
int g0/0/1
mpls
mpls ldp
q
//创建VPN实例并按照规划配置RD与RT参数
ip vpn-instance VPNX
route-distinguisher 64640:172
vpn-target 64640:172 both
q
q
//将接口绑定到VPN实例
interface GigabitEthernet 0/0/0
ip binding vpn-instance VPNX
ip ad 10.1.11.2 30
q
//创建与实例绑定的OSPF进程
ospf 2 vpn-instance VPNX
area 0
net 10.1.11.2 0.0.0.0
q
//配置OSPF进程与MP-BGP之间的路由双向引入
ospf 2 vpn-instance VPNX
import-route bgp
q
bgp 64640
ipv4-family vpn-instance VPNX
import-route ospf 2
q
q
RT07
un ter mon
sys
un in en
sysn RT07
int g0/0/0
ip ad 10.1.12.2 30
int g0/0/1
ip ad 10.1.23.1 30
int loo0
ip ad 22.1.1.1 32
q
//IGP配置
ospf 100 router-id 22.1.1.1
area 0
net 22.1.1.1 0.0.0.0
net 10.1.12.2 0.0.0.0
net 10.1.23.1 0.0.0.0
q
q
//MP-BGP配置
bgp 64640
router-id 22.1.1.1
peer 11.1.1.1 as-number 64640
peer 11.1.1.1 connect-interface loo0
peer 33.1.1.1 as-number 64640
peer 33.1.1.1 connect-interface loo0
ipv4-family vpnv4 unicast
peer 11.1.1.1 enable
peer 33.1.1.1 enable
undo policy vpn-target
q
ipv4-family vpnv4
peer 11.1.1.1 reflect-client
peer 33.1.1.1 reflect-client
q
//MPLS与MPLS LDP配置
mpls lsr-id 22.1.1.1
mpls
q
mpls ldp
q
int g0/0/1
mpls
mpls ldp
int g0/0/0
mpls
mpls ldp
PE
un ter mon
sys
un in en
sysn PE
int g0/0/0
ip ad 10.1.23.2 30
int loo0
ip ad 33.1.1.1 32
q
//IGP配置
ospf 100 router-id 33.1.1.1
area 0
net 33.1.1.1 0.0.0.0
net 10.1.23.2 0.0.0.0
q
q
//MP-BGP配置
bgp 64640
router-id 33.1.1.1
peer 22.1.1.1 as-number 64640
peer 22.1.1.1 connect-interface loo0
ipv4-family vpnv4 unicast
peer 22.1.1.1 enable
q
q
//MPLS与MPLS LDP配置
mpls lsr-id 33.1.1.1
mpls
q
mpls ldp
q
int g0/0/1
mpls
mpls ldp
int g0/0/0
mpls
mpls ldp
q
//创建VPN实例并按照规划配置RD与RT参数
ip vpn-instance VPNX
route-distinguisher 64640:172
vpn-target 64640:172 both
q
q
//将接口绑定到VPN实例
interface GigabitEthernet 0/0/1
ip binding vpn-instance VPNX
ip ad 10.1.13.1 30
q
//配置PE2上配置静态vpn回城路由
ip route-static vpn-instance VPNX 172.16.31.0 24 10.1.13.2
bgp 64640
ipv4-family vpn-instance VPNX
network 172.16.31.0 24
q
q
CE1
un ter mon
sys
un in en
sysn CE1
int g0/0/0
ip ad 10.1.11.1 30
int loo0
ip ad 172.16.30.1 24
q
ospf 2
area 0
net 10.1.11.1 0.0.0.0
net 172.16.30.0 0.0.0.0
q
q
//172.16.30.0网段引入不成功
ip ip-prefix zhilian permit 172.16.30.0 24
route-policy zhilian permit node 10
if-match ip-prefix zhilain
ospf 2
import-route direct route-policy zhilian
q
CE3
un ter mon
sys
un in en
sysn CE3
int g0/0/0
ip ad 10.1.13.2 30
int loo0
ip ad 172.16.31.1 24
q
使用静态
ip route-static 0.0.0.0 0.0.0.0 10.1.13.1