MPLS VPN实验

要求

 拓扑搭建

首先配IP地址,这里没有要求,所以按照喜好配置就行

要让公网通是大前提,因此配置好后简单测试一下(用r3和r4即可)

 

 

 然后就是在公网上起协议

[r2]ospf 1 router-id 2.2.2.2
[r2-ospf-1]area 0
[r2-ospf-1-area-0.0.0.0]net 2.2.2.2 0.0.0.0
[r2-ospf-1-area-0.0.0.0]net 23.1.1.1 0.0.0.0

[r3]ospf 1 router-id 3.3.3.3
[r3-ospf-1]area 0
[r3-ospf-1-area-0.0.0.0]net 3.3.3.3 0.0.0.0
[r3-ospf-1-area-0.0.0.0]net 23.1.1.2 0.0.0.0
[r3-ospf-1-area-0.0.0.0]net 34.1.1.1 0.0.0.0
[r4]ospf 1 router-id 4.4.4.4
[r4-ospf-1]area 0
[r4-ospf-1-area-0.0.0.0]net 4.4.4.4 0.0.0.0
[r4-ospf-1-area-0.0.0.0]net 34.1.1.2 0.0.0.0
[r4-ospf-1-area-0.0.0.0]net 47.1.1.1 0.0.0.0

配好后记得检查

display ospf peer brief

此时把r7当成一个用户的化必须要沉默接口,做个认证会更安全 

[r4-ospf-1]silent-interface g0/0/2

[r4-GigabitEthernet0/0/2]ospf authentication-mode md5 1 cipher 12345

然后在r7上写一个缺省指向r4

[r7]ip route-static 0.0.0.0 0 47.1.1.1

此时r7可以上网了

现在起mpls协议

[r2]mpls lsr-id 2.2.2.2

[r2]mpls

[r2-mpls]mpls ldp

[r2-mpls-ldp]int g0/0/1
[r2-GigabitEthernet0/0/1]mpls
[r2-GigabitEthernet0/0/1]mpls ldp

 [r3]mpls lsr-id 3.3.3.3
[r3] mpls
[r3-mpls] mpls ldp
[r3-mpls-ldp]int g0/0/0
[r3-GigabitEthernet0/0/0] mpls
[r3-GigabitEthernet0/0/0] mpls ldp
[r3-GigabitEthernet0/0/0]int g0/0/1
[r3-GigabitEthernet0/0/1] mpls
[r3-GigabitEthernet0/0/1] mpls ldp

[r4]mpls lsr-id 4.4.4.4
[r4] mpls
[r4-mpls] mpls ldp
[r4-mpls-ldp]int g0/0/0
[r4-GigabitEthernet0/0/0] mpls
[r4-GigabitEthernet0/0/0] mpls ldp

这样就顺利完成mpls协议,同样不要忘记了检查

接下来调VPN,这里一步到位(r4同理)

[r2]ip vpn-instance a1
[r2-vpn-instance-a1]ipv4-family 
[r2-vpn-instance-a1-af-ipv4]route-distinguisher 2:2
[r2-vpn-instance-a1-af-ipv4]vpn-target 2:2
 IVT Assignment result: 
Info: VPN-Target assignment is successful.
 EVT Assignment result: 
Info: VPN-Target assignment is successful.

[r2]ip vpn-instance b1
[r2-vpn-instance-b1]ipv4-family 
[r2-vpn-instance-b1-af-ipv4]route-distinguisher 1:1
[r2-vpn-instance-b1-af-ipv4]vpn-target 1:1
 IVT Assignment result: 
Info: VPN-Target assignment is successful.
 EVT Assignment result: 
Info: VPN-Target assignment is successful.

[r2]int g0/0/0
[r2-GigabitEthernet0/0/0]ip binding vpn-instance b1
Info: All IPv4 related configurations on this interface are removed!
Info: All IPv6 related configurations on this interface are removed!
[r2-GigabitEthernet0/0/0]ip add 192.168.2.2 24

[r2-GigabitEthernet0/0/0]int g0/0/2
[r2-GigabitEthernet0/0/2]ip binding vpn-instance a1
Info: All IPv4 related configurations on this interface are removed!
Info: All IPv6 related configurations on this interface are removed!
[r2-GigabitEthernet0/0/2]ip add 192.168.2.2 24

然后建立bgp

[r2]bgp 1
[r2-bgp]router-id 2.2.2.2
[r2-bgp]peer 4.4.4.4 as-number 1
[r2-bgp]peer 4.4.4.4 connect-interface l0

[r2-bgp]ipv4-family vpnv4
[r2-bgp-af-vpnv4]peer 4.4.4.4 enable 

[r4]bgp 1
[r4-bgp]router-id 4.4.4.4
[r4-bgp]peer 2.2.2.2 as-number 1
[r4-bgp]peer 2.2.2.2 connect-interface l0
[r4-bgp]ipv4-family vpnv4
[r4-bgp-af-vpnv4]peer 2.2.2.2 enable 

接下来在用户之间建立协议(例如r6和2)

[r6]rip 1
[r6-rip-1]ver 2
[r6-rip-1]net 192.168.1.0
[r6-rip-1]net 192.168.2.0

[r2]rip 1 vpn-instance a1

[r2-rip-1]ver 2
[r2-rip-1]net 192.168.2.0

现在查看r2的a1路由表

r4和7

[r7]ospf 1 rou 7.7.7.7
[r7-ospf-1]area 0
[r7-ospf-1-area-0.0.0.0]net 192.168.3.2 0.0.0.0
[r7-ospf-1-area-0.0.0.0]net 192.168.4.2 0.0.0.0

[r4]ospf 2 vpn-instance a2
[r4-ospf-2]area 0
[r4-ospf-2-area-0.0.0.0]net 192.168.3.1 0.0.0.0

然后做双向重发布

[r2]bgp 1
[r2-bgp]ipv4-family vpn-instance a1
[r2-bgp-a1]import-route rip 1 、

[r4]ospf 2 vpn-instance a2
[r4-ospf-2]import-route bgp

[r4]bgp 1
[r4-bgp]ipv4-f vpnv4
[r4-bgp]ipv4-f vpn-instance a2
[r4-bgp-a2]import-route ospf 2 

 

[r2]rip 1 vpn-instance a1
[r2-rip-1]import-route bgp 

此时r6可以ping通r7

 

在r1、2上补静态

[r1]ip route-s 192.168.2.0 24 192.168.2.2
[r1]ip route-static 192.168.4.0 24 192.168.2.2 

[r2]ip route-static vpn-i b1 192.168.1.0 24 192.168.2.1

r4、5同理

[r5]ip route-s 192.168.1.0 24 192.168.3.1
[r5]ip route-s 192.168.2.0 24 192.168.3.1

[r4]ip route-s vpn-i b2 192.168.4.0 24 192.168.3.2

然后再r2和4上做重发布或者宣告,也可以一个宣告一个重发布

[r4]bgp 1
[r4-bgp]ipv4-f vpn-i b2
[r4-bgp-b2]import-route direct
[r4-bgp-b2]import-route static 

[r2]bgp 1
[r2-bgp]ipv4-f vpn-instance b1
[r2-bgp-b1]net 192.168.1.0 24
[r2-bgp-b1]net 192.168.2.0 24

最后拿r1ping通r5,实验就结束了

 

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 1
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值