MPLS VPN跨域Option A方案

目录

实验需求:使用mpls跨域option A组网,实现公司A互通、公司B互通。

1.配置IP地址

2.配置运营商网络的IGP协议

3.运营商网络之间配置MPLS,建立MPLS LSP隧道

4.配置PE设备上的VPN的实例,VPN A的RD值为100:1,RT值为100:1,VPN B的RD值为200:1,RT值为200:1。将接口加入对应的VPN实例。

5.配置PE设备和CE设备之间的协议,PE1和实例VPNB之间用的是OSPF协议,PE1和公司A之间用的是BGP的协议,PE2同理。

6.配置ASBR的VPN的实例,并绑定到子接口上。

7.配置ASBR之间的EBGP的路由

8.将PE的vpn实例B的ospf路由和BGP路由做双向引入

9.测试连通性

实验拓扑

实验需求:使用mpls跨域option A组网,实现公司A互通、公司B互通。

1.配置IP地址

2.配置运营商网络的IGP协议

[PE1-ospf-1]dis this

ospf 1

area 0.0.0.0

network 1.1.1.1 0.0.0.0

network 12.1.1.0 0.0.0.255

[P1-ospf-1]dis this

ospf 1

area 0.0.0.0

network 2.2.2.2 0.0.0.0

network 12.1.1.0 0.0.0.255

network 23.1.1.0 0.0.0.255

[ASBR1-ospf-1]dis this

ospf 1

area 0.0.0.0

network 3.3.3.3 0.0.0.0

network 23.1.1.0 0.0.0.255

[P2-ospf-1]dis this

ospf 1

area 0.0.0.0

network 5.5.5.5 0.0.0.0

network 45.1.1.0 0.0.0.255

network 56.1.1.0 0.0.0.255

[ASBR2-ospf-1]dis this

ospf 1

area 0.0.0.0

network 4.4.4.4 0.0.0.0

network 45.1.1.0 0.0.0.255

network 56.1.1.0 0.0.0.255

[P2-ospf-1]dis this

ospf 1

area 0.0.0.0

network 5.5.5.5 0.0.0.0

network 45.1.1.0 0.0.0.255

network 56.1.1.0 0.0.0.255

[PE2-ospf-1]dis this

ospf 1

area 0.0.0.0

network 6.6.6.6 0.0.0.0

network 56.1.1.0 0.0.0.255

查看ospf的邻居建立状态

3.运营商网络之间配置MPLS,建立MPLS LSP隧道

[PE1]mpls lsr-id 1.1.1.1

[PE1]mpls

[PE1-mpls]mpls ldp

[PE1]int g0/0/1

[PE1-GigabitEthernet0/0/1]mpls

[PE1-GigabitEthernet0/0/1]mpls ldp

[P1]mpls lsr-id 2.2.2.2

[P1]mpls

[P1-mpls]mpls ldp

[P1]int g0/0/0

[P1-GigabitEthernet0/0/0]mpls

[P1-GigabitEthernet0/0/0]mpls ldp

[P1-GigabitEthernet0/0/0]int g0/0/1

[P1-GigabitEthernet0/0/1]mpls

[P1-GigabitEthernet0/0/1]mpls ldp

[ASBR1]mpls lsr-id 3.3.3.3

[ASBR1]mpls

[ASBR1-mpls]mpls ldp

[ASBR1]int g0/0/0

[ASBR1-GigabitEthernet0/0/0]mpls

[ASBR1-GigabitEthernet0/0/0]mpls ldp

[ASBR2]mpls lsr-id 4.4.4.4

[ASBR2]mpls

[ASBR2-mpls]mpls ldp

[ASBR2-mpls-ldp]int g0/0/1

[ASBR2-GigabitEthernet0/0/1]mpls

[ASBR2-GigabitEthernet0/0/1]mpls ldp

[P2]mpls lsr-id 5.5.5.5

[P2]mpls

[P2-mpls]mpls ldp

[P2]int g0/0/0

[P2-GigabitEthernet0/0/0]mpls

[P2-GigabitEthernet0/0/0]mpls ldp

[P2-GigabitEthernet0/0/0]int g0/0/1

[P2-GigabitEthernet0/0/1]mpls

[P2-GigabitEthernet0/0/1]mpls ldp

[PE2]mpls lsr-id 6.6.6.6

[PE2]mpls

[PE2-mpls]mpls ldp

[PE2]int g0/0/0

[PE2-GigabitEthernet0/0/0]mpls

[PE2-GigabitEthernet0/0/0]mpls ldp

查看MPLS LSP隧道的建立情况

4.配置PE设备上的VPN的实例,VPN A的RD值为100:1,RT值为100:1,VPN B的RD值为200:1,RT值为200:1。将接口加入对应的VPN实例。

[PE1]dis current-configuration configuration vpn-instance

ip vpn-instance VPNA

ipv4-family

route-distinguisher 100:1

vpn-target 100:1 export-extcommunity

vpn-target 100:1 import-extcommunity

#

ip vpn-instance VPNB

ipv4-family

route-distinguisher 200:1

vpn-target 200:1 export-extcommunity

vpn-target 200:1 import-extcommunity

[PE2]dis current-configuration configuration vpn-instance

ip vpn-instance VPNA

ipv4-family

route-distinguisher 100:1

vpn-target 100:1 export-extcommunity

vpn-target 100:1 import-extcommunity

#

ip vpn-instance VPNB

ipv4-family

route-distinguisher 200:1

vpn-target 200:1 export-extcommunity

vpn-target 200:1 import-extcommunity

[PE1-GigabitEthernet0/0/2]dis this

interface GigabitEthernet0/0/2

ip binding vpn-instance VPNA

ip address 19.1.1.1 255.255.255.0

[PE1-GigabitEthernet0/0/0]dis this

interface GigabitEthernet0/0/0

ip binding vpn-instance VPNB

ip address 17.1.1.1 255.255.255.0

[PE2-GigabitEthernet0/0/2]dis this

interface GigabitEthernet0/0/2

ip binding vpn-instance VPNA

ip address 210.1.1.2 255.255.255.0

[PE2-GigabitEthernet0/0/1]dis this

interface GigabitEthernet0/0/1

ip binding vpn-instance VPNB

ip address 28.1.1.2 255.255.255.0

5.配置PE设备和CE设备之间的协议,PE1和实例VPNB之间用的是OSPF协议,PE1和公司A之间用的是BGP的协议,PE2同理。

[PE1-ospf-100]dis this

ospf 100 vpn-instance VPNB

area 0.0.0.0

network 17.1.1.0 0.0.0.255

[R7-ospf-1]dis this

ospf 1

area 0.0.0.0

network 17.1.1.0 0.0.0.255

network 7.7.7.7 0.0.0.0

[PE1-bgp]dis this

bgp 100

ipv4-family vpn-instance VPNA

peer 19.1.1.9 as-number 300

[R9-bgp]dis this

bgp 300

peer 19.1.1.1 as-number 100

network 9.9.9.9 255.255.255.255

[PE2-ospf-100]dis this

ospf 100 vpn-instance VPNB

area 0.0.0.0

network 28.1.1.0 0.0.0.255

[R8-ospf-1]dis this

ospf 1

area 0.0.0.0

network 28.1.1.0 0.0.0.255

network 8.8.8.8 0.0.0.0

[PE2-bgp-VPNA]dis this

ipv4-family vpn-instance VPNA

peer 210.1.1.10 as-number 400

[R10-bgp]dis this

bgp 400

peer 210.1.1.2 as-number 200

network 10.10.10.10 255.255.255.255

查看OSPF邻居关系的建立

查看BGP的邻居关系的建立

查看PE1的实例的VPNB的路由

可以看到PE1的实例B上学习到了AR7de 7.7.7.7/32的路由

查看PE2的实例VPNB的路由

可以看到PE2的实例B上学习到了AR8de 8.8.8.8/32的路由

6.配置ASBR的VPN的实例,并绑定到子接口上。

[ASBR1]dis current-configuration configuration vpn-instance

ip vpn-instance VPNA

ipv4-family

route-distinguisher 100:1

vpn-target 100:1 export-extcommunity

vpn-target 100:1 import-extcommunity

#

ip vpn-instance VPNB

ipv4-family

route-distinguisher 200:1

vpn-target 200:1 export-extcommunity

vpn-target 200:1 import-extcommunity

[ASBR2]dis current-configuration configuration vpn-instance

ip vpn-instance VPNA

ipv4-family

route-distinguisher 100:1

vpn-target 100:1 export-extcommunity

vpn-target 100:1 import-extcommunity

#

ip vpn-instance VPNB

ipv4-family

route-distinguisher 200:1

vpn-target 200:1 export-extcommunity

vpn-target 200:1 import-extcommunity

[ASBR1-GigabitEthernet0/0/1.1]dis this

interface GigabitEthernet0/0/1.1

dot1q termination vid 10

ip binding vpn-instance VPNA

ip address 34.1.1.1 255.255.255.0

arp broadcast enable

[ASBR1-GigabitEthernet0/0/1.2]dis this

interface GigabitEthernet0/0/1.2

dot1q termination vid 20

ip binding vpn-instance VPNB

ip address 43.1.1.1 255.255.255.0

arp broadcast enable

[ASBR2-GigabitEthernet0/0/0.1]dis this

interface GigabitEthernet0/0/0.1

dot1q termination vid 10

ip binding vpn-instance VPNA

ip address 34.1.1.2 255.255.255.0

arp broadcast enable

[ASBR2-GigabitEthernet0/0/0.2]dis this

interface GigabitEthernet0/0/0.2

dot1q termination vid 20

ip binding vpn-instance VPNB

ip address 43.1.1.2 255.255.255.0

arp broadcast enable

7.配置PE和ASBR之间MP-BGP协议,传递私网CE的路由

[ASBR1-bgp]dis this

bgp 100

peer 1.1.1.1 as-number 100

peer 1.1.1.1 connect-interface LoopBack0

ipv4-family vpnv4

peer 1.1.1.1 enable

[PE1-bgp]dis this

bgp 100

peer 3.3.3.3 as-number 100

peer 3.3.3.3 connect-interface LoopBack0

ipv4-family vpnv4

peer 3.3.3.3 enable

[ASBR2-bgp]dis this

bgp 200

peer 6.6.6.6 as-number 200

peer 6.6.6.6 connect-interface LoopBack0

ipv4-family vpnv4

peer 6.6.6.6 enable

[PE2-bgp]dis this

bgp 200

peer 4.4.4.4 as-number 200

peer 4.4.4.4 connect-interface LoopBack0

ipv4-family vpnv4

peer 4.4.4.4 enable

查看BGP的VPNV4的邻居关系

7.配置ASBR之间的EBGP的路由

[ASBR1-bgp-VPNA]dis this

ipv4-family vpn-instance VPNA

peer 34.1.1.2 as-number 200

[ASBR1-bgp-VPNB]dis this

ipv4-family vpn-instance VPNB

peer 43.1.1.2 as-number 200

[ASBR2-bgp-VPNA]dis this

ipv4-family vpn-instance VPNA

peer 34.1.1.1 as-number 100

[ASBR2-bgp-VPNB]dis this

ipv4-family vpn-instance VPNB

peer 43.1.1.1 as-number 100

查看EBGP的邻居建立的情况

可以看到EBGP的邻居关系已经建立

8.将PE的vpn实例B的ospf路由和BGP路由做双向引入

[PE1]ospf 100

[PE1-ospf-100]import-route bgp

[PE1]bgp 100

[PE1-bgp]ipv4-family vpn-instance VPNB

[PE1-bgp-VPNB]import-route ospf 100

[PE2]ospf 100

[PE2-ospf-100]import-route bgp

[PE2]bgp 200

[PE2-bgp]ipv4-family vpnv4

[PE2-bgp]ipv4-family vpn-instance VPNB

[PE2-bgp-VPNB]import-route ospf 100

9.测试连通性

  • 18
    点赞
  • 26
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值