VRF方式
允许PC1和PC2访问AR1
1、将SW下联PC接口与旁挂防火墙的下行口划分至VPN实例(LT),其中SW与FW创建链路聚合
2、SW配置去往Internet的VRF默认路由送达FW1
ip route-static vpn-instance LT 0.0.0.0 0 10.1.12.2
3、FW1收到报文配置默认路由从上行口送往SW
ip route-static 0.0.0.0 0 10.1.11.1
4、SW配置默认路由送往AR1(Internet)
5、AR1配置回程路由去往SW
6、SW配置回程路由去往PC送达上行口到FW
7、FW配置回程路由去往PC送达下行口到SW
8、PC收到回程报文
VRF+VFW方式
允许PC1和PC2通过FW访问AR1
允许PC1与PC2通过FW互访
0)SW按照要求创建VLAN和VLANIF,并将不同的PC分别划分进不同的VPN实例(LT / XC)。其中SW与FW创建链路聚合,同时FW按要求划分两个VFW(LT / XC)
[S1]display ip vpn-instance interface
Total VPN-Instances configured : 2
VPN-Instance Name and ID : LT, 1
Interface Number : 2
Interface list : Vlanif10,
Vlanif204
VPN-Instance Name and ID : XC, 2
Interface Number : 2
Interface list : Vlanif20,
Vlanif202
[S1]display eth-trunk 10
Eth-Trunk10's state information is:
Local:
LAG ID: 10 WorkingMode: STATIC
Preempt Delay: Disabled Hash arithmetic: According to SIP-XOR-DIP
System Priority: 32768 System ID: 4c1f-cca0-1725
Least Active-linknumber: 1 Max Active-linknumber: 8
Operate status: up Number Of Up Port In Trunk: 2
--------------------------------------------------------------------------------
ActorPortName Status PortType PortPri PortNo PortKey PortState Weight
GigabitEthernet0/0/3 Selected 1GE 32768 4 2609 10111100 1
GigabitEthernet0/0/4 Selected 1GE 32768 5 2609 10111100 1
[FW1]display ip vpn-instance interface
2024-01-08 06:59:12.250
Total VPN-Instances configured : 3
VPN-Instance Name and ID : LT, 1
Interface Number : 3
Interface list : Virtual-if1,
Vlanif203,
Vlanif204
VPN-Instance Name and ID : XC, 2
Interface Number : 3
Interface list : Vlanif201,
Virtual-if2,
Vlanif202
1)允许PC1与PC2通过FW互访
a.SW配置去往不同PC的VRF静态路由,将VPN流量送往FW1。
SW
ip route-static vpn-instance LT 10.1.2.0 255.255.255.0 10.1.204.2
ip route-static vpn-instance XC 10.1.1.0 255.255.255.0 10.1.202.2
b.由于FW1配置了两个VFW(LT / XC),不同的VFW接收VPN流量后,通过配置两个VRF静态路由使两个VFW可以直接互访;
FW-Public
ip route-static vpn-instance LT 10.1.2.0 255.255.255.0 vpn-instance XC
ip route-static vpn-instance XC 10.1.1.0 255.255.255.0 vpn-instance LT
c.VPN流量进入不同的VFW后,配置去往各自纳管PC的网段
FW-VFW-XC
ip route-static 10.1.2.0 255.255.255.0 10.1.202.1
FW-VFW-LT
ip route-static 10.1.1.0 255.255.255.0 10.1.204.1
d.PC互访的流量从VFW到达SW后通过各自的VRF表即可完成转发
2)允许PC1和PC2通过FW访问AR1
a.在第2步基础上,为SW中不同的VPN实例(LT / XC)配置不同的VRF默认路由,将去往Internet流量送往FW
SW
ip route-static vpn-instance LT 0.0.0.0 0.0.0.0 10.1.204.2
ip route-static vpn-instance XC 0.0.0.0 0.0.0.0 10.1.202.2
b.FW的VFW收到后,同样在不同的VFW上配置去往SW的默认路由
VFW-LT
ip route-static 0.0.0.0 0.0.0.0 Vlanif203 10.1.203.1
VFW-XC
ip route-static 0.0.0.0 0.0.0.0 Vlanif201 10.1.201.1
c.去往Internet的流量到达PC后,SW配置默认路由去往AR1,通过查找全局路由表达到AR1
SW
ip route-static 0.0.0.0 0.0.0.0 202.100.1.2
d.AR1配置回程路由
ip route-static 10.1.1.0 255.255.255.0 202.100.1.1
ip route-static 10.1.2.0 255.255.255.0 202.100.1.1
e.AR1的回程路由到达SW后,将回程流量送往不同的VPN实例
SW
ip route-static 10.1.1.0 255.255.255.0 vpn-instance LT 10.1.204.2
ip route-static 10.1.2.0 255.255.255.0 vpn-instance XC 10.1.202.2