9.跨域虚拟专用网 Option-B方案配置案例


一、拓扑

在这里插入图片描述
 
 

二、配置各接口IP地址

1.CE1配置

 sysname CE1 #修改主机名

interface GigabitEthernet0/0/1 
 ip address 10.1.1.1 255.255.255.252 

interface LoopBack0
 ip address 11.11.11.11 255.255.255.255 
#
bgp 65001  #配置PE1与CE1的BGP邻居关系
 peer 10.1.1.2 as-number 100 
 #
 ipv4-family unicast
  undo synchronization
  network 11.11.11.11 255.255.255.255 
  peer 10.1.1.2 enable

 

2.配置PE1

 sysname PE1 #配置主机名

ip vpn-instance huawei #创建VPN实例
 ipv4-family
  route-distinguisher 100:1  #配置RD属性
  vpn-target 100:1 export-extcommunity  #配置RT属性
  vpn-target 100:1 import-extcommunity
#
mpls lsr-id 1.1.1.1
mpls
mpls ldp    #使能MPLS和MPLS LDP                              
#
interface GigabitEthernet0/0/0
 ip address 12.12.12.1 255.255.255.252 
 mpls    #使能MPLS和MPLS LDP    
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip binding vpn-instance huawei #绑定VPN实例,注意绑定实例后接口配置全部消失
 ip address 10.1.1.2 255.255.255.252 

interface LoopBack0
 ip address 1.1.1.1 255.255.255.255 
#
bgp 100  
 peer 7.7.7.7 as-number 100  #配置PE1与RR1之间的IBGP邻居关系
 peer 7.7.7.7 connect-interface LoopBack0  #配置建立对等体的接口为LOOKBACK 0口
 #
 ipv4-family unicast
  undo synchronization
  peer 7.7.7.7 enable
 # 
 ipv4-family vpnv4  #进入BGP的VPNv4视图
  policy vpn-target
  peer 7.7.7.7 enable  #使能PE1与ASBR1的MP-IBGP邻居
 #
 ipv4-family vpn-instance huawei 
  peer 10.1.1.1 as-number 65001 
#
ospf 1 router-id 1.1.1.1   #底层通过OSPF互通
 area 0.0.0.0 
  network 1.1.1.1 0.0.0.0                 
  network 12.12.12.0 0.0.0.3 

 

3.配置P1

 sysname P1
#
mpls lsr-id 2.2.2.2
mpls
mpls ldp
#
interface GigabitEthernet0/0/0
 ip address 12.12.12.2 255.255.255.252 
 mpls
 mpls ldp  #使能MPLS和mpls ldp
#
interface GigabitEthernet0/0/1
 ip address 23.23.23.1 255.255.255.252 
 mpls
 mpls ldp #使能MPLS和mpls ldp
#
interface GigabitEthernet0/0/2
 ip address 72.72.72.2 255.255.255.252 

interface LoopBack0                       
 ip address 2.2.2.2 255.255.255.255 
#
ospf 1 router-id 2.2.2.2 #底层通过OSPF互通
 area 0.0.0.0 
  network 2.2.2.2 0.0.0.0 
  network 12.12.12.0 0.0.0.3 
  network 23.23.23.0 0.0.0.3 
  network 72.72.72.0 0.0.0.3 

 

4.RR1配置

 sysname RR1

interface GigabitEthernet0/0/2
 ip address 72.72.72.1 255.255.255.252 

interface LoopBack0
 ip address 7.7.7.7 255.255.255.255 
#
bgp 100
 peer 1.1.1.1 as-number 100 
 peer 1.1.1.1 connect-interface LoopBack0
 peer 3.3.3.3 as-number 100 
 peer 3.3.3.3 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  peer 1.1.1.1 enable
  peer 3.3.3.3 enable                     
 # 
 ipv4-family vpnv4
  undo policy vpn-target
  peer 1.1.1.1 enable
  peer 1.1.1.1 reflect-client
  peer 3.3.3.3 enable
  peer 3.3.3.3 reflect-client
#
ospf 1 router-id 7.7.7.7 #底层通过OSPF互通
 area 0.0.0.0 
  network 7.7.7.7 0.0.0.0 
  network 72.72.72.0 0.0.0.3 

 

5.ASBR1配置

 sysname ASBR1

mpls lsr-id 3.3.3.3
mpls
#
mpls ldp  
#
interface GigabitEthernet0/0/0
 ip address 34.34.34.1 255.255.255.252 
 mpls
#
interface GigabitEthernet0/0/1
 ip address 23.23.23.2 255.255.255.252 
 mpls
 mpls ldp #使能MPLS和MPLS ldp

interface LoopBack0
 ip address 3.3.3.3 255.255.255.255 
#                                         
bgp 100
 peer 7.7.7.7 as-number 100 
 peer 7.7.7.7 connect-interface LoopBack0
 peer 34.34.34.2 as-number 200 
 #
 ipv4-family unicast
  undo synchronization
  peer 7.7.7.7 enable
  peer 34.34.34.2 enable
 # 
 ipv4-family vpnv4
  undo policy vpn-target
  peer 7.7.7.7 enable
  peer 34.34.34.2 enable
#
ospf 1 router-id 3.3.3.3 
 area 0.0.0.0 
  network 3.3.3.3 0.0.0.0 
  network 23.23.23.0 0.0.0.3 

 

6.ASBR2配置

sysname ASBR2

mpls lsr-id 4.4.4.4
mpls
#
mpls ldp
#
interface GigabitEthernet0/0/0
 ip address 34.34.34.2 255.255.255.252 
 mpls
#
interface GigabitEthernet0/0/1
 ip address 45.45.45.1 255.255.255.252 
 mpls
 mpls ldp

interface LoopBack0
 ip address 4.4.4.4 255.255.255.255 
#                                         
bgp 200
 peer 8.8.8.8 as-number 200 
 peer 8.8.8.8 connect-interface LoopBack0
 peer 34.34.34.1 as-number 100 
 #
 ipv4-family unicast
  undo synchronization
  peer 8.8.8.8 enable
  peer 34.34.34.1 enable
 # 
 ipv4-family vpnv4
  undo policy vpn-target
  peer 8.8.8.8 enable
  peer 34.34.34.1 enable
#
ospf 1 router-id 4.4.4.4 
 area 0.0.0.0 
  network 4.4.4.4 0.0.0.0 
  network 45.45.45.0 0.0.0.3 

 

7.ASBR2配置

 sysname P2
mpls lsr-id 5.5.5.5
mpls
#
mpls ldp
#
interface GigabitEthernet0/0/0
 ip address 56.56.56.1 255.255.255.252 
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip address 45.45.45.2 255.255.255.252 
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/2
 ip address 58.58.58.1 255.255.255.252 

interface LoopBack0                       
 ip address 5.5.5.5 255.255.255.255 
#
ospf 1 router-id 5.5.5.5 
 area 0.0.0.0 
  network 5.5.5.5 0.0.0.0 
  network 45.45.45.0 0.0.0.3 
  network 56.56.56.0 0.0.0.3 
  network 58.58.58.0 0.0.0.3 

 

8.PE2配置

 sysname PE2
ip vpn-instance huawei
 ipv4-family
  route-distinguisher 100:1
  vpn-target 100:1 export-extcommunity
  vpn-target 100:1 import-extcommunity
#
mpls lsr-id 6.6.6.6
mpls
#
mpls ldp                                  
#
interface GigabitEthernet0/0/0
 ip address 56.56.56.2 255.255.255.252 
 mpls
 mpls ldp
#
interface GigabitEthernet0/0/1
 ip binding vpn-instance huawei
 ip address 20.1.1.1 255.255.255.252 
#
interface LoopBack0
 ip address 6.6.6.6 255.255.255.255 
#
bgp 200
 peer 8.8.8.8 as-number 200 
 peer 8.8.8.8 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  peer 8.8.8.8 enable
 # 
 ipv4-family vpnv4
  policy vpn-target
  peer 8.8.8.8 enable
 #
 ipv4-family vpn-instance huawei 
  peer 20.1.1.2 as-number 65002 
#
ospf 1 router-id 6.6.6.6 
 area 0.0.0.0 
  network 6.6.6.6 0.0.0.0                 
  network 56.56.56.0 0.0.0.3 

 

9.RR2配置


 sysname RR2

interface GigabitEthernet0/0/2
 ip address 58.58.58.2 255.255.255.252 
 
interface LoopBack0
 ip address 8.8.8.8 255.255.255.255 
#
bgp 200
 peer 4.4.4.4 as-number 200 
 peer 4.4.4.4 connect-interface LoopBack0
 peer 6.6.6.6 as-number 200 
 peer 6.6.6.6 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo synchronization
  peer 4.4.4.4 enable
  peer 6.6.6.6 enable                     
 # 
 ipv4-family vpnv4
  undo policy vpn-target
  peer 4.4.4.4 enable
  peer 4.4.4.4 reflect-client
  peer 6.6.6.6 enable
  peer 6.6.6.6 reflect-client
#
ospf 1 router-id 8.8.8.8 
 area 0.0.0.0 
  network 8.8.8.8 0.0.0.0 
  network 58.58.58.0 0.0.0.3 

 

10.CE2配置


 sysname CE2

interface GigabitEthernet0/0/1
 ip address 20.1.1.2 255.255.255.252 
#
interface LoopBack0
 ip address 22.22.22.22 255.255.255.255 
#
bgp 65002
 peer 20.1.1.1 as-number 200 
 #
 ipv4-family unicast
  undo synchronization
  network 22.22.22.22 255.255.255.255 
  peer 20.1.1.1 enable

配置验证

1.查看VPN实例邻居状态

在这里插入图片描述

2.查看RR上是否接收到正确的VPN路由

在这里插入图片描述

3.CE之间能够学到对方的接口路由

在这里插入图片描述

4.PING命令测试连通性

在这里插入图片描述

完成!

  • 1
    点赞
  • 8
    收藏
    觉得还不错? 一键收藏
  • 2
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 2
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值