- 积分
- 101
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 最后登录
- 1970-1-1
- 阅读权限
- 20
- 听众
- 收听
助理工程师
 
|
我有一条PPPOE的电信宽带和MPLS VPN海外专线
设备工程师帮我设置了,国内网站走PPPOE,国外网站(GMAIL GOOGLE等)走MPLS
它是怎么做到的呀,具体是哪些命令实现的?
下面是路由和ACL部份
router bgp 65000
bgp always-compare-med
bgp log-neighbor-changes
bgp dampening
neighbor RSVR peer-group
neighbor RSVR remote-as 65000
neighbor RSVR update-source Loopback0
neighbor RSVR soft-reconfiguration inbound
neighbor RSVR route-map bgp-from--RSVR in
neighbor 152.*.*.5 peer-group RSVR
neighbor 152.*.*.209 peer-group RSVR
maximum-paths 2
no auto-summary
!
ip local policy route-map Backup-Monitor
ip forward-protocol nd
no ip http server
no ip http secure-server
!
ip bgp-community new-format
!
ip nat inside source route-map nat--CN interface Dialer1 overload
ip route 0.0.0.0 0.0.0.0 10.205.20.149 track 2
ip route 0.0.0.0 0.0.0.0 10.201.73.141 111
ip route 1.1.1.1 255.255.255.255 Dialer1
ip route 124.*.*.169 255.255.255.255 Dialer1
ip route 125.*.*.7 255.255.255.255 Dialer1 name backup_tunnel
ip route 152.*.*.5 255.255.255.255 10.205.20.149 name bgp1 track 2
!
ip access-list extended Backup-Monitor
permit ip host 10.201.73.142 host 152.104.228.238
permit ip host 10.201.73.142 host 152.104.168.70
ip access-list extended al--Lan
deny ip 10.0.0.0 0.0.0.255 10.1.2.0 0.0.0.255
permit ip 10.0.0.0 0.0.0.255 any
ip access-list extended al-ERP
permit ip 10.0.0.0 0.0.0.255 host 10.1.2.2
permit ip 10.0.0.0 0.0.0.255 host 10.1.2.1
ip access-list extended al-VG
permit ip host 10.205.22.10 any
!
ip sla 2
icmp-echo 10.205.20.149 source-ip 10.205.20.150
tos 224
threshold 3000
timeout 3000
frequency 3
ip sla schedule 2 life forever start-time now
logging esm config
access-list 4 permit 0.0.0.0
access-list 4 deny any
access-list 5 remark SNMP Read-only Hosts
access-list 5 permit 202.*.67.10
access-list 5 permit 10.201.56.100
access-list 5 permit 202.*.86.248
access-list 5 permit 202.*.94.192 0.0.0.31
access-list 6 remark SNMP Read-Write Hosts
access-list 6 permit 202.*.67.4
access-list 6 permit 202.*.94.201
access-list 7 permit 202.*.64.0 0.0.0.255
access-list 7 permit 202.*.65.0 0.0.0.255
access-list 7 permit 202.*.67.0 0.0.0.255
access-list 7 permit 192.*.100.0 0.0.0.255
access-list 7 permit 202.*.94.0 0.0.0.255
access-list 7 permit 202.*.93.0 0.0.0.255
access-list 7 permit 10.201.56.0 0.0.0.255
access-list 7 deny any
access-list 110 permit ip 10.0.0.0 0.0.0.255 host 10.1.2.3
access-list 110 permit ip 10.0.0.0 0.0.0.255 host 10.1.2.2
access-list 110 permit ip 10.0.0.0 0.0.0.255 host 10.1.2.1
access-list 110 deny ip 10.0.0.0 0.0.0.255 10.1.2.0 0.0.0.255
access-list 110 deny ip 10.0.0.0 0.0.0.255 172.16.0.0 0.0.255.255
access-list 110 permit ip any any
!
!
!
!
route-map bgp-from--RSVR permit 100
match ip address 4
!
route-map bgp-from--RSVR permit 110
set ip next-hop 1.1.1.1
!
route-map Backup-Monitor permit 20
match ip address Backup-Monitor
set ip next-hop 10.201.73.141
!
route-map nat--CN permit 100
match ip address al--Lan
match interface Dialer1
!
!
tacacs-server host *
tacacs-server key *
!
!
control-plane
!
!
banner motd ^CC
|
|