MPLS VPN-跨域MPLS OptionC2(RR)

拓扑图

配置

配置接口IP地址

PE配置VPN-Instance,RD,RT

配置ISIS,引入BGP路由

配置MPLS,MPLS LDP,ASBR互联接口开启MPLS,ASBR配置BGP标签路由触发建立LSP

配置Route-policy,应用MPLS标签

ASBR建立BGP邻居关系,通告PE及RR的环回口地址,开启标签路由功能,邻居通告标签路由

RR间、RR与PE配置MP-BGP,PE作为RR客户端,RR间注意配置EBGP多跳,PE实例内通告路由,RR关闭RT过滤,RR配置对于邻居RR和PE下一跳不变

sysname AR1
#
ip vpn-instance BJ
 ipv4-family
  route-distinguisher 100:1
  vpn-target 100:1 export-extcommunity
  vpn-target 200:6 import-extcommunity
#
mpls lsr-id 1.1.1.1
mpls
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0001.00
#
interface GigabitEthernet0/0/0
 ip address 12.1.1.1 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip binding vpn-instance BJ
 ip address 10.0.1.254 255.255.255.0 
#
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255 
 isis enable 1
#
bgp 100
 undo default ipv4-unicast
 peer 7.7.7.7 as-number 100 
 peer 7.7.7.7 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 7.7.7.7 enable
 # 
 ipv4-family vpnv4
  policy vpn-target
  peer 7.7.7.7 enable
 #
 ipv4-family vpn-instance BJ 
  network 10.0.1.0 255.255.255.0 
#
sysname AR2
#
mpls lsr-id 2.2.2.2
mpls
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0002.00
#
interface GigabitEthernet0/0/1
 ip address 23.1.1.2 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/2
 ip address 27.1.1.2 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface LoopBack0
 ip address 2.2.2.2 255.255.255.255 
 isis enable 1
#
sysname AR3
#
mpls lsr-id 3.3.3.3
mpls
 lsp-trigger bgp-label-route
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0003.00
 import-route bgp 
#
interface GigabitEthernet0/0/0
 ip address 23.1.1.3 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip address 34.1.1.3 255.255.255.0 
 mpls
#
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255 
 isis enable 1
#
bgp 100
 peer 34.1.1.4 as-number 200 
 #
 ipv4-family unicast
  undo synchronization
  network 1.1.1.1 255.255.255.255 
  network 7.7.7.7 255.255.255.255 
  peer 34.1.1.4 enable
  peer 34.1.1.4 route-policy ASBR-Label export
  peer 34.1.1.4 label-route-capability
#
route-policy ASBR-Label permit node 10 
 apply mpls-label
#
sysname AR4
#
mpls lsr-id 4.4.4.4
mpls
 lsp-trigger bgp-label-route
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0004.00
 import-route bgp 
#
interface GigabitEthernet0/0/0
 ip address 34.1.1.4 255.255.255.0 
 mpls
#
interface GigabitEthernet0/0/1
 ip address 45.1.1.4 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface LoopBack0
 ip address 4.4.4.4 255.255.255.255 
 isis enable 1
#
bgp 200
 peer 34.1.1.3 as-number 100 
 #
 ipv4-family unicast
  undo synchronization
  network 6.6.6.6 255.255.255.255 
  network 8.8.8.8 255.255.255.255 
  peer 34.1.1.3 enable
  peer 34.1.1.3 route-policy ASBR-Label export
  peer 34.1.1.3 label-route-capability
#
route-policy ASBR-Label permit node 10 
 apply mpls-label
#
sysname AR5
#
mpls lsr-id 5.5.5.5
mpls
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0005.00
#
interface GigabitEthernet0/0/0
 ip address 45.1.1.5 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip address 56.1.1.5 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/2
 ip address 58.1.1.5 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface LoopBack0
 ip address 5.5.5.5 255.255.255.255 
 isis enable 1
#
sysname AR6
#
ip vpn-instance SH
 ipv4-family
  route-distinguisher 200:6
  vpn-target 200:6 export-extcommunity
  vpn-target 100:1 import-extcommunity
#
mpls lsr-id 6.6.6.6
mpls
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0006.00
#
interface GigabitEthernet0/0/0
 ip address 56.1.1.6 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip binding vpn-instance SH
 ip address 10.0.2.254 255.255.255.0 
#
interface LoopBack0
 ip address 6.6.6.6 255.255.255.255 
 isis enable 1
#
bgp 200
 undo default ipv4-unicast
 peer 8.8.8.8 as-number 200 
 peer 8.8.8.8 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 8.8.8.8 enable
 # 
 ipv4-family vpnv4
  policy vpn-target
  peer 8.8.8.8 enable
 #
 ipv4-family vpn-instance SH 
  network 10.0.2.0 255.255.255.0 
#
sysname AR7
#
mpls lsr-id 7.7.7.7
mpls
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0007.00
#
interface GigabitEthernet0/0/0
 ip address 27.1.1.7 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface LoopBack0
 ip address 7.7.7.7 255.255.255.255 
 isis enable 1
#
bgp 100
 undo default ipv4-unicast
 peer 1.1.1.1 as-number 100 
 peer 1.1.1.1 connect-interface LoopBack0
 peer 8.8.8.8 as-number 200 
 peer 8.8.8.8 ebgp-max-hop 255 
 peer 8.8.8.8 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 1.1.1.1 enable
  undo peer 8.8.8.8 enable
 # 
 ipv4-family vpnv4
  undo policy vpn-target
  peer 1.1.1.1 enable
  peer 1.1.1.1 reflect-client
  peer 1.1.1.1 next-hop-invariable 
  peer 8.8.8.8 enable
  peer 8.8.8.8 next-hop-invariable 
#
sysname AR8
#
mpls lsr-id 8.8.8.8
mpls
#
mpls ldp
#
isis 1
 is-level level-2
 network-entity 49.0000.0000.0000.0008.00
#
interface GigabitEthernet0/0/0
 ip address 58.1.1.8 255.255.255.0 
 isis enable 1
 mpls
 mpls ldp
#
interface LoopBack0
 ip address 8.8.8.8 255.255.255.255 
 isis enable 1
#
bgp 200
 undo default ipv4-unicast
 peer 6.6.6.6 as-number 200 
 peer 6.6.6.6 connect-interface LoopBack0
 peer 7.7.7.7 as-number 100 
 peer 7.7.7.7 ebgp-max-hop 255 
 peer 7.7.7.7 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  undo peer 6.6.6.6 enable
  undo peer 7.7.7.7 enable
 # 
 ipv4-family vpnv4
  undo policy vpn-target
  peer 6.6.6.6 enable
  peer 6.6.6.6 reflect-client
  peer 6.6.6.6 next-hop-invariable 
  peer 7.7.7.7 enable
  peer 7.7.7.7 next-hop-invariable 
#

查看BGP邻居关系

MP-BGP邻居关系

查看BGP路由

PC1访问PC2,查看路径

AR1访问AR2,查看标签转发路径

查看VPNv4标签

查看MPLS标签

华为ENSP (Enterprise Network Simulation Platform) 是一款网络模拟软件,主要用于华为产品的网络配置、故障排除和教学演示等场景。它提供了一个虚拟化的网络环境,帮助用户在安全的环境中学习和操作华为的网络设备。 IS-IS (Intermediate System to Intermediate System) 是一种链路状态路由协议,用于自治系统内的路由选择。在IS-IS网络中,路由器分为Level-1数据包,而Level-2路由器则发送Level-1和Level-2的数据包。 针对您提到的情况,如果有四台路由器AR1至AR4,其中只有AR1、AR2作为Level-1路由器(通常是骨干区域),并且要让所有设备开启快速扩散功能(即FastFlooding,快速传播),可以按照以下步骤实现: 1. **配置路由器角色**:在AR1和AR2上配置为Level-1路由器,其他路由器(AR3和AR4)配置为Level-2路由器。 ```sh [AR1/CLI] router isis 1 [AR2/CLI] router isis 1 [AR3/CLI] router isis 2 [AR4/CLI] router isis 2 ``` 2. **启用快速扩散**:在Level-1路由器上启用快速扩散特性。例如,在华为路由器上可能是通过`isis is-type level-1`命令,并指定`network-entity-extension`来启用。 ```sh [AR1/CLI] isis is-type level-1 network-entity-extension [AR2/CLI] isis is-type level-1 network-entity-extension ``` 3. **设置扩散策略**:确保Level-1路由器之间的通信策略允许快速扩散。这可能涉及到区域间的Hello时间间隔、CSNP周期等配置。 ```sh [AR1/CLI] isis circuit-type level-1-1 priority 10 interval 5 [AR2/CLI] isis circuit-type level-1-1 priority 10 interval 5 ``` 请注意,上述命令和配置仅供参考,实际操作时需要参考具体的华为设备型号和版本文档。同时,由于ENSP是一个模拟环境,可能需要在模拟器中设置相应的网络拓扑和协议选项来模拟这种配置效果。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值