Hub-spoke组网典型案例

本文详细描述了如何在多站点的HUB-Spoke网络架构中配置公网IGP和LDP,规划和配置VPNs,以及在AR路由器上设置MP-IBGP邻居关系,涉及AR1到AR5的具体配置步骤。
摘要由CSDN通过智能技术生成

HUB-Spoke组网
通过部署hub站点和多个spoke站点
要求:hub可以访问任意一个spoke
spoke可以访问hub
spoke可以通过 hub访问spoke

配置步骤
1、公网的IGP和LDP配置
2、连接站点的VPN实例规划
RD、RT值
VPN实例配置
接口绑定
站点路由协议(绑定VPN实例)
3、PE和RR建立MP-IBGP邻居关系

AR1:

bgp 65000
 peer 10.1.12.2 as-number 100
 peer 10.1.21.2 as-number 100
 #
 ipv4-family unicast
  undo synchronization
  peer 10.1.12.2 enable
  peer 10.1.21.2 enable
#

AR2:

#
sysname AR2
#
ip vpn-instance A_IN
 ipv4-family
  route-distinguisher 100:1
  vpn-target 2:2 3:2 import-extcommunity
#
ip vpn-instance A_OUT
 ipv4-family
  route-distinguisher 100:100
  vpn-target 2:1 3:1 export-extcommunity
#
mpls lsr-id 2.2.2.2
mpls
#
mpls ldp
#

#
isis 1
 is-level level-2
 cost-style wide
 network-entity 49.0001.0000.0000.0002.00
#
#
interface GigabitEthernet0/0/0
 ip binding vpn-instance A_OUT
 ip address 10.1.12.2 255.255.255.0
#
interface GigabitEthernet0/0/1
 ip address 10.1.23.2 255.255.255.0
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/2
 ip binding vpn-instance A_IN
 ip address 10.1.21.2 255.255.255.0
#

#
interface LoopBack0
 ip address 2.2.2.2 255.255.255.255
 isis enable 1
#
bgp 100
 peer 3.3.3.3 as-number 100
 peer 3.3.3.3 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 3.3.3.3 enable
 #
 ipv4-family vpnv4
  policy vpn-target
  peer 3.3.3.3 enable
 #
 ipv4-family vpn-instance A_IN
  peer 10.1.21.1 as-number 65000
 #
 ipv4-family vpn-instance A_OUT
  peer 10.1.12.1 as-number 65000
  peer 10.1.12.1 allow-as-loop
#

AR3:

#
sysname AR3
#
undo info-center enable
#
mpls lsr-id 3.3.3.3
mpls
#
mpls ldp
#

isis 1
 is-level level-2
 cost-style wide
 network-entity 49.0001.0000.0000.0003.00
#

interface GigabitEthernet0/0/0
 ip address 10.1.23.3 255.255.255.0
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip address 10.1.34.3 255.255.255.0
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/2
 ip address 10.1.35.3 255.255.255.0
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/3
#
wlan
#
#
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255
 isis enable 1
#
bgp 100
 peer 2.2.2.2 as-number 100
 peer 2.2.2.2 connect-interface LoopBack0
 peer 4.4.4.4 as-number 100
 peer 4.4.4.4 connect-interface LoopBack0
 peer 5.5.5.5 as-number 100
 peer 5.5.5.5 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 2.2.2.2 enable
  undo peer 4.4.4.4 enable
  undo peer 5.5.5.5 enable
 #
 ipv4-family vpnv4
  undo policy vpn-target
  peer 2.2.2.2 enable
  peer 2.2.2.2 reflect-client
  peer 4.4.4.4 enable
  peer 4.4.4.4 reflect-client
  peer 5.5.5.5 enable
  peer 5.5.5.5 reflect-client
#

AR4:

#
sysname AR4
#
undo info-center enable
#
ip vpn-instance B
 ipv4-family
  route-distinguisher 100:2
  vpn-target 2:2 export-extcommunity
  vpn-target 2:1 import-extcommunity
#
mpls lsr-id 4.4.4.4
mpls
#
mpls ldp
#
acl number 2000
 rule 5 permit source 100.6.6.6 0
#

isis 1
 is-level level-2
 cost-style wide
 network-entity 49.0001.0000.0000.0004.00

interface GigabitEthernet0/0/0
 ip address 10.1.34.4 255.255.255.0
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip binding vpn-instance B
 ip address 10.1.46.1 255.255.255.0
 ospf enable 1 area 0.0.0.0
#
#
interface LoopBack0
 ip address 4.4.4.4 255.255.255.255
 isis enable 1
#
bgp 100
 peer 3.3.3.3 as-number 100
 peer 3.3.3.3 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 3.3.3.3 enable
 #
 ipv4-family vpnv4
  policy vpn-target
  peer 3.3.3.3 enable
 #
 ipv4-family vpn-instance B
  import-route ospf 1 route-policy import_ospf
#
ospf 1 router-id 10.4.4.4 vpn-instance B
 import-route bgp
 area 0.0.0.0
#
route-policy import_ospf permit node 10
 if-match acl 2000
 

AR5:

#
sysname AR5
#
undo info-center enable
#
ip vpn-instance C
 ipv4-family
  route-distinguisher 100:3
  vpn-target 3:2 export-extcommunity
  vpn-target 3:1 import-extcommunity
#
mpls lsr-id 5.5.5.5
mpls
#
mpls ldp
#
#
acl number 2000
 rule 5 permit source 100.7.7.7 0

#
isis 1
 is-level level-2
 cost-style wide
 network-entity 49.0001.0000.0000.0005.00

#
interface GigabitEthernet0/0/0
 ip address 10.1.35.5 255.255.255.0
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip binding vpn-instance C
 ip address 10.1.57.5 255.255.255.0
 ospf enable 1 area 0.0.0.0
#

interface LoopBack0
 ip address 5.5.5.5 255.255.255.255
 isis enable 1
#
bgp 100
 peer 3.3.3.3 as-number 100
 peer 3.3.3.3 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 3.3.3.3 enable
 #
 ipv4-family vpnv4
  policy vpn-target
  peer 3.3.3.3 enable
 #
 ipv4-family vpn-instance C
  import-route ospf 1 route-policy import_ospf
#
ospf 1 router-id 10.5.5.5 vpn-instance C
 import-route bgp
 area 0.0.0.0
#
route-policy import_ospf permit node 10
 if-match acl 2000
#
 

  • 11
    点赞
  • 7
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值