MPLS的配置实验

MPLS VPN

1.CE将私有路由传递到PE端

2.PE端在收到不同CE发送过来的相同网段路由时,使用RD值进行区分:格式X:X 32位

3.PE端将附上RD的私有路由不能直接装载于本地公有路由表中,需要放置到对应的VRF(虚拟路由转发)空间内,之后再给路由赋RT值,用于传递到对端PE设备,对端区分信息。

VPNV4路由=普通IPV4路由+RD+RT

4.VPNV4路由需要MP-BGP来进行传递,对端基于RT值,将路由装载到对应的VRF空间内,再共享给对应的CE。

5.控制层面工作完成后,数据层面需要基于MPLS来工作,由于数据层面不能携带RD和RT值,故MPLS将在数据包中压入两层标签,外层标签用于穿越中间设备,打破BGP路由黑洞,内层标签用于对应VRF空间。

实验需求

1.R1与R5MPLS VPN。

2. R6与R7MPLS VPN。

3.R7可以访问R2、R3、R4的环回。

实验步骤

一、配置公网上的OSPF

[R2]int lo0
[R2-LoopBack0]ip a 2.2.2.2 24
[R2-LoopBack0]int g0/0/1
[R2-GigabitEthernet0/0/1]ip a 23.1.1.1 24
[R2-GigabitEthernet0/0/1]q
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]net 2.2.2.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]net 23.1.1.1 0.0.0.0

[R3]int lo0
[R3-LoopBack0]ip a 3.3.3.3 24
[R3-LoopBack0]int g0/0/0
[R3-GigabitEthernet0/0/0]ip a 23.1.1.2 24
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip a 43.1.1.2 24
[R3-GigabitEthernet0/0/1]q
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]net 3.3.3.3 0.0.0.0
[R3-ospf-1-area-0.0.0.0]net 23.1.1.2 0.0.0.0
[R3-ospf-1-area-0.0.0.0]net 43.1.1.2 0.0.0.0

[R4]int lo0
[R4-LoopBack0]ip a 4.4.4.4 24
[R4-LoopBack0]int g0/0/0
[R4-GigabitEthernet0/0/0]ip a 43.1.1.1 24
[R4-GigabitEthernet0/0/0]int g4/0/0
[R4-GigabitEthernet4/0/0]ip a 47.1.1.1 24
[R4-GigabitEthernet4/0/0]q
[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]net 43.1.1.1 0.0.0.0
[R4-ospf-1-area-0.0.0.0]net 4.4.4.4 0.0.0.0
[R4-ospf-1-area-0.0.0.0]net 47.1.1.1 0.0.0.0 
[R4-ospf-1-area-0.0.0.0]q
[R4-ospf-1]silent-interface g4/0/0        #因为R7有一条网线连到公网,只收不发
[R4-ospf-1]q
[R4]int g4/0/0
[R4-GigabitEthernet4/0/0]ospf authentication-mode md5 1 cipher 123456        #添加认证,更能保证R7只收不发

 二、配置MPLS

[R2]mpls lsr-id 2.2.2.2        #配置MPLS域
[R2]mpls
[R2-mpls]mpls ldp
[R2-mpls-ldp]q
[R2]int g0/0/1
[R2-GigabitEthernet0/0/1]mpls
[R2-GigabitEthernet0/0/1]mpls ldp
[R2-GigabitEthernet0/0/1]q
[R2]ip vpn-instance a1        #设置空间
[R2-vpn-instance-a1]ipv4-family 
[R2-vpn-instance-a1-af-ipv4]route-distinguisher 1:1
[R2-vpn-instance-a1-af-ipv4]vpn-target 1:1
[R2-vpn-instance-a1-af-ipv4]q
[R2-vpn-instance-a1]q
[R2]ip vpn-instance b1
[R2-vpn-instance-b1]ipv4-family
[R2-vpn-instance-b1-af-ipv4]route-distinguisher 2:2
[R2-vpn-instance-b1-af-ipv4]vpn-target 2:2
[R2-vpn-instance-b1-af-ipv4]q
[R2-vpn-instance-b1]q
[R2]int g0/0/0        #在接口上关联空间
[R2-GigabitEthernet0/0/0]ip binding vpn-instance a1
[R2-GigabitEthernet0/0/0]ip a 192.168.2.2 24
[R2-GigabitEthernet0/0/0]q
[R2]int g0/0/2
[R2-GigabitEthernet0/0/2]ip binding vpn-instance b1
[R2-GigabitEthernet0/0/2]ip a 192.168.2.2 24
[R2-GigabitEthernet0/0/2]q
[R2]bgp 1        #配置MP-BGP关系
[R2-bgp]router-id 2.2.2.2 
[R2-bgp]peer 4.4.4.4 as-number 1     
[R2-bgp]peer 4.4.4.4 connect-interface lo0
[R2-bgp]ipv4-family vpnv4
[R2-bgp-af-vpnv4]peer 4.4.4.4 enable
[R2-bgp-af-vpnv4]q

[R3]mpls lsr-id 3.3.3.3
[R3]mpls
[R3-mpls]mpls ldp
[R3-mpls-ldp]q
[R3]int g0/0/0
[R3-GigabitEthernet0/0/0]mpls
[R3-GigabitEthernet0/0/0]mpls ldp
[R3-GigabitEthernet0/0/0]q
[R3]int g0/0/1
[R3-GigabitEthernet0/0/1]mpls
[R3-GigabitEthernet0/0/1]mpls ldp

[R4]mpls lsr-id 4.4.4.4
[R4]mpls
[R4-mpls]mpls ldp
[R4-mpls-ldp]q
[R4]int g0/0/0
[R4-GigabitEthernet0/0/0]mpls
[R4-GigabitEthernet0/0/0]mpls ldp
[R4-GigabitEthernet0/0/0]q
[R4]ip vpn-instance a2
[R4-vpn-instance-a2]ipv4-family 
[R4-vpn-instance-a2-af-ipv4]route-distinguisher 1:1
[R4-vpn-instance-a2-af-ipv4]vpn-target 1:1
[R4-vpn-instance-a2-af-ipv4]q
[R4-vpn-instance-a2]q
[R4]ip vpn-instance b2
[R4-vpn-instance-b2]ipv4-family 
[R4-vpn-instance-b2-af-ipv4]route-distinguisher 2:2
[R4-vpn-instance-b2-af-ipv4]vpn-target 2:2
[R4-vpn-instance-b2-af-ipv4]q
[R4-vpn-instance-b2]q
[R4]int g0/0/2
[R4-GigabitEthernet0/0/2]ip binding vpn-instance b2
[R4-GigabitEthernet0/0/2]int g0/0/1
[R4-GigabitEthernet0/0/1]ip binding vpn-instance a2
[R4-GigabitEthernet0/0/1]ip a 192.168.3.2 24
[R4-GigabitEthernet0/0/1]int g0/0/2
[R4-GigabitEthernet0/0/2]ip a 192.168.3.2 24
[R4-GigabitEthernet0/0/2]q
[R4]bgp 1
[R4-bgp]router-id 4.4.4.4
[R4-bgp]peer 2.2.2.2 as-number 1
[R4-bgp]peer 2.2.2.2 connect-interface lo0
[R4-bgp]ipv4-family vpnv4       
[R4-bgp-af-vpnv4]peer 2.2.2.2 enable 
[R4-bgp-af-vpnv4]q

 三、配置a1、a2

[R1]int lo0  
[R1-LoopBack0]ip a 192.168.1.1 24
[R1-LoopBack0]int g0/0/0
[R1-GigabitEthernet0/0/0]ip a 192.168.2.1 24
[R1]ip route-static 192.168.3.0 24 192.168.2.2
[R1]ip route-static 192.168.4.0 24 192.168.2.2


[R2]ip route-static vpn-instance a1 192.168.1.0 24 192.168.2.1        #在空间上配置到R1环回的静态

[R2]bgp 1        #向a2重发布直连路由与静态
[R2-bgp]ipv4-family vpn-instance a1
[R2-bgp-a1]import-route direct
[R2-bgp-a1]import-route static


[R4]ip route-static vpn-instance a2 192.168.4.0 24 192.168.3.1

[R4]bgp 
[R4-bgp]ipv4 vpn-instance a2
[R4-bgp-a2]import-route direct  
[R4-bgp-a2]import-route static

[r5]int lo0
[r5-LoopBack0]ip a 192.168.4.1 24
[r5-LoopBack0]int g0/0/0
[r5-GigabitEthernet0/0/0]ip a 192.168.3.1 24
[r5]ip route-static 192.168.1.0 24 192.168.3.2
[r5]ip route-static 192.168.2.0 24 192.168.3.2

四、配置b1、b2

[R2]rip 1 vpn-instance b1
[R2-rip-1]ver 2
[R2-rip-1]net 192.168.2.0
[R2-rip-1]q
[R2]rip 1 vpn-instance b1        #将bgp重发布到rip
[R2-rip-1]import-route bgp
[R2-rip-1]q
[R2]bgp 1
[R2-bgp]ipv4-family vpn-instance b1        #将rip重发布到bgp
[R2-bgp-b1]import-route rip 1

[R4]ospf 2 vpn-instance b2
[R4-ospf-2]area 0
[R4-ospf-2-area-0.0.0.0]net 192.168.3.2 0.0.0.0
[R4-ospf-2-area-0.0.0.0]q
[R4-ospf-2]q
[R4]ospf 2 vpn-instance b2
[R4-ospf-2]import-route bgp
[R4-ospf-2]q
[R4]bgp 1
[R4-bgp]ipv4-family vpn-instance b2
[R4-bgp-b2]import-route ospf 2

实验测试

 

 

 

 

 

  • 1
    点赞
  • 16
    收藏
    觉得还不错? 一键收藏
  • 2
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值