3.R4和R6构成VPN-1,R5和R7构成VPN-2,不同VPN用户之间不能互相访问。VPN-1使用的RD为100:100,VPN-Target属性为100:1;VPN-2使用的RD为100:200,VPN-Target属性为100:2。 R1配置: [R1]ip vpn-instance vpn1 //创建vpn实例名称为vpn1 [R1-vpn-instance-vpn1]route-distinguisher 100:100 //RD值为100:100 [R1-vpn-instance-vpn1-af-ipv4]vpn-target 100:1 both //RT入和出值都为100:1 [R1]ip vpn-instance vpn2 [R1-vpn-instance-vpn2]route-distinguisher 100:200 [R1-vpn-instance-vpn2-af-ipv4]vpn-target 100:2 both R3配置: [R3]ip vpn-instance vpn1 [R3-vpn-instance-vpn1]route-distinguisher 100:100 [R3-vpn-instance-vpn1-af-ipv4]vpn-target 100:1 both [R3]ip vpn-instance vpn2 [R3-vpn-instance-vpn2]route-distinguisher 100:200 [R3-vpn-instance-vpn2-af-ipv4]vpn-target 100:2 both 检查现象:配置完成后在R1和R3上执行display ip vpn-instance verbose命令可以看到VPN实例的配置情况。 4.完成CE与PE之间的配置,PE连接CE的接口需要绑定VPN实例,注意接口绑定VPN实例后IP地址会失效,需要在绑定实例后再配置IP地址。CE和PE之间运行OSPF协议,将路由传给PE,CE对VPN实例是不感知的。接口地址如下表: 设备 | 接口 | 地址 | R1 | GigabitEthernet 0/0/1 | 10.1.14.1/24 | R1 | GigabitEthernet 0/0/2 | 10.1.15.1/24 | R3 | GigabitEthernet 0/0/1 | 10.1.36.3/24 | R3 | GigabitEthernet 0/0/2 | 10.1.37.3/24 | R4 | GigabitEthernet 0/0/0 | 10.1.14.4/24 | R4 | LoopBack 0 | 4.4.4.4/32 | R4 | LoopBack 1 | 10.10.10.10/32 | R5 | GigabitEthernet 0/0/0 | 10.1.15.5/24 | R5 | LoopBack 0 | 5.5.5.5/32 | R5 | LoopBack 1 | 10.10.10.10/32 | R6 | GigabitEthernet 0/0/0 | 10.1.36.6/24 | R6 | LoopBack 0 | 6.6.6.6/32 | R7 | GigabitEthernet 0/0/0 | 10.1.37.7/24 | R7 | LoopBack 0 | 7.7.7.7/32 |
R1配置: [R1]interface GigabitEthernet 0/0/1 [R1-GigabitEthernet0/0/1]ip binding vpn-instance vpn1 //接口绑定VPN实例 [R1-GigabitEthernet0/0/1]ip address 10.1.14.1 24 [R1]interface GigabitEthernet 0/0/2 [R1-GigabitEthernet0/0/2]ip binding vpn-instance vpn2 [R1-GigabitEthernet0/0/2]ip address 10.1.15.1 24 [R1]ospf 1 router-id 1.1.1.1 vpn-instance vpn1 //协议进程关联VPN实例 [R1-ospf-1]area 0 //进入OSPF区域0 [R1-ospf-1-area-0.0.0.0]network 10.1.14.1 0.0.0.0 //区域0下宣告地址 [R1]ospf 2 router-id 1.1.1.1 vpn-instance vpn2 [R1-ospf-2]area 0 [R1-ospf-2-area-0.0.0.0]network 10.1.15.1 0.0.0.0 R3配置: [R3]interface GigabitEthernet 0/0/1 [R3-GigabitEthernet0/0/1]ip binding vpn-instance vpn1 [R3-GigabitEthernet0/0/1]ip address 10.1.36.3 24 [R3]interface GigabitEthernet 0/0/2 [R3-GigabitEthernet0/0/2]ip binding vpn-instance vpn2 [R3-GigabitEthernet0/0/2]ip address 10.1.37.3 24 [R3]ospf 1 router-id 3.3.3.3 vpn-instance vpn1 [R3-ospf-1]area 0 [R3-ospf-1-area-0.0.0.0]network 10.1.36.3 0.0.0.0 [R3]ospf 2 router-id 3.3.3.3 vpn-instance vpn2 [R3-ospf-2]area 0 [R3-ospf-2-area-0.0.0.0]network 10.1.37.3 0.0.0.0 R4配置: system-view [Huawei]sysname R4 [R4]interface GigabitEthernet 0/0/0 [R4-GigabitEthernet0/0/0]ip address 10.1.14.4 24 [R4]interface LoopBack 0 [R4-LoopBack0]ip address 4.4.4.4 32 [R4]interface LoopBack 1 [R4-LoopBack1]ip address 10.10.10.10 32 [R4]ospf 1 router-id 4.4.4.4 [R4-ospf-1]area 0 [R4-ospf-1-area-0.0.0.0]network 10.1.14.4 0.0.0.0 [R4-ospf-1-area-0.0.0.0]network 4.4.4.4 0.0.0.0 [R4-ospf-1-area-0.0.0.0]network 10.10.10.10 0.0.0.0 R5配置: system-view [Huawei]sysname R5 [R5]interface GigabitEthernet 0/0/0 [R5-GigabitEthernet0/0/0]ip address 10.1.15.5 24 [R5]interface LoopBack 0 [R5-LoopBack0]ip address 5.5.5.5 32 [R5]interface LoopBack 1 [R5-LoopBack1]ip address 10.10.10.10 32 [R5]ospf 1 router-id 5.5.5.5 [R5-ospf-1]area 0 [R5-ospf-1-area-0.0.0.0]network 10.1.15.5 0.0.0.0 [R5-ospf-1-area-0.0.0.0]network 5.5.5.5 0.0.0.0 [R5-ospf-1-area-0.0.0.0]network 10.10.10.10 0.0.0.0 R6配置: system-view [Huawei]sysname R6 [R6]interface GigabitEthernet 0/0/0 [R6-GigabitEthernet0/0/0]ip address 10.1.36.6 24 [R6]interface LoopBack 0 [R6-LoopBack0]ip address 6.6.6.6 32 [R6]ospf 1 router-id 6.6.6.6 [R6-ospf-1]area 0 [R6-ospf-1-area-0.0.0.0]network 10.1.36.6 0.0.0.0 [R6-ospf-1-area-0.0.0.0]network 6.6.6.6 0.0.0.0 R7配置: system-view [Huawei]sysname R7 [R7]interface GigabitEthernet 0/0/0 [R7-GigabitEthernet0/0/0]ip address 10.1.37.7 24 [R7]interface LoopBack 0 [R7-LoopBack0]ip address 7.7.7.7 32 [R7]ospf 1 router-id 7.7.7.7 [R7-ospf-1]area 0 [R7-ospf-1-area-0.0.0.0]network 10.1.37.7 0.0.0.0 [R7-ospf-1-area-0.0.0.0]network 7.7.7.7 0.0.0.0 检查现象:配置完成后在R1和R3上查看是否学习到VPN实例路由,执行display ip routing-table vpn-instance xxx命令查看VPN实例路由。R1和R3通过ospf协议学习到实例路由,根据协议绑定的VPN实例决定放入那个VRF中。 下一节,我们将对MP-BGP邻居及VPN路由引入做配置讲解。 更多华为数通实验操作敬请关注:誉天教育 QQ:3200569443
|