1.VRF基本概念
(1)网络需求
(2)通过部署ACL实现
(3)通过增加核心交换机实现
(4)通过VRF技术实现
VRF的本质就是在一台物理设备上面虚拟出来多台虚拟路由器,并且物理设备路由表和虚拟出来的路由器路由表示相互隔离的。
(5)VRF的实现过程
⦁ 缺省时,一个网络设备的所有接口都属于同一个转发实例——设备的根实例。
(6)举例:部署VRF前
(7)举例:创建VPN实例
(8)举例:部署动态路由协议
(9)常见应用场景
2.VRF典型配置案例
(1)VRF基本配置命令(1)
(2)VRF基本配置命令(2)
(3)配置案例-背景介绍与需求分析
交换机上完成VLAN相关配置
[czySW1]vlan batch 10 20
[czySW1]inter g0/0/4
[czySW1-GigabitEthernet0/0/4]p l a
[czySW1-GigabitEthernet0/0/4]p d v 10
[czySW1-GigabitEthernet0/0/4]inter g0/0/5
[czySW1-GigabitEthernet0/0/5]p l a
[czySW1-GigabitEthernet0/0/5]p d v 20
[czySW1-GigabitEthernet0/0/5]inter g0/0/1
[czySW1-GigabitEthernet0/0/1]p l t
[czySW1-GigabitEthernet0/0/1]p t a v 10 20
路由器上完成配置子接口
[czyAR1]inter g0/0/0.10
[czyAR1-GigabitEthernet0/0/0.10]ip address 192.168.1.254 24
[czyAR1-GigabitEthernet0/0/0.10]dot1q termination vid 10
[czyAR1-GigabitEthernet0/0/0.10]arp broadcast enable
[czyAR1-GigabitEthernet0/0/0.10]inter g0/0/0.20
[czyAR1-GigabitEthernet0/0/0.20]ip address 192.168.2.254 24
[czyAR1-GigabitEthernet0/0/0.20]dot1q termination vid 20
[czyAR1-GigabitEthernet0/0/0.20]arp broadcast enable
测试主机是否ping通网关
创建生产与管理网络的VPC实力,并使能IPv4地址族
[czyAR1]ip vpn-instance production
[czyAR1-vpn-instance-production]ipv4-family
[czyAR1]ip vpn-instance management
[czyAR1-vpn-instance-management]ipv4-family
将接口绑定到实例
[czyAR1]inter g0/0/0.10
[czyAR1-GigabitEthernet0/0/0.10]ip binding vpn-instance production
[czyAR1-GigabitEthernet0/0/0.10]ip address 192.168.1.254 24
[czyAR1-GigabitEthernet0/0/0.10]inter g0/0/0.20
[czyAR1-GigabitEthernet0/0/0.20]ip binding vpn-instance management
[czyAR1-GigabitEthernet0/0/0.20]ip address 192.168.2.254 24
[czyAR1-GigabitEthernet0/0/1]ip binding vpn-instance production
[czyAR1-GigabitEthernet0/0/1]ip address 192.168.101.1 255.255.255.0
往实例中添加静态路由
[czyAR1]ip route-static vpn-instance production 192.168.100.0 24 192.168.101.254
[czyAR1]ip route-static vpn-instance management 192.168.200.0 24 192.168.102.254