华为路由器MPLSVPN配置示例Word格式文档下载.docx
- 文档编号:17326204
- 上传时间:2022-12-01
- 格式:DOCX
- 页数:17
- 大小:37.96KB
华为路由器MPLSVPN配置示例Word格式文档下载.docx
《华为路由器MPLSVPN配置示例Word格式文档下载.docx》由会员分享,可在线阅读,更多相关《华为路由器MPLSVPN配置示例Word格式文档下载.docx(17页珍藏版)》请在冰豆网上搜索。
[PE1-LoopBack1]
[PE1-LoopBack1]quit
[PE1]interfacegigabitethernet3/0/0
[PE1-GigabitEthernet3/0/0]
[PE1-GigabitEthernet3/0/0]quit
[PE1]ospf1
[PE1-ospf-1]area0
quit
[PE1-ospf-1]quit
#配置P。
[Huawei]sysnameP
[P]interfaceloopback1
[P-LoopBack1]
[P-LoopBack1]quit
[P]interfacegigabitethernet1/0/0
[P-GigabitEthernet1/0/0]
[P-GigabitEthernet1/0/0]quit
[P]interfacegigabitethernet2/0/0
[P-GigabitEthernet2/0/0]
[P-GigabitEthernet2/0/0]quit
[P]ospf
[P-ospf-1]area0
[P-ospf-1]quit
#配置PE2。
[Huawei]sysnamePE2
[PE2]interfaceloopback1
[PE2-LoopBack1]
[PE2-LoopBack1]quit
[PE2]interfacegigabitethernet3/0/0
[PE2-GigabitEthernet3/0/0]
[PE2-GigabitEthernet3/0/0]quit
[PE2]ospf
[PE2-ospf-1]area0
[PE2-ospf-1]quit
配置完成后,PE1、P、PE2之间应能建立OSPF邻居关系,执行displayospfpeer命令可以看到邻居状态为Full。
执行displayiprouting-table命令可以看到PE之间学习到对方的Loopback1路由。
以PE1的显示为例:
[PE1]displayiprouting-table
RouteFlags:
R-relay,
D-downloadtofib
------------------------------------------------------------------------------
RoutingTables:
Public
Destinations:
11Routes:
11
Destination/MaskProtoPreCostFlagsNextHopInterface
[PE1]displayospfpeer
Neighbors
State:
FullMode:
NbrisMasterPriority:
1
Deadtimerduein37sec
Retranstimerinterval:
5
Neighborisupfor00:
16:
21
AuthenticationSequence:
[0]
2.在MPLS骨干网上配置MPLS基本能力和MPLSLDP,建立LDPLSP
[PE1]
[PE1]mpls
[PE1-mpls]quit
[PE1]mplsldp
[PE1-mpls-ldp]quit
[PE1-GigabitEthernet3/0/0]mpls
[PE1-GigabitEthernet3/0/0]mplsldp
[P]
[P]mpls
[P-mpls]quit
[P]mplsldp
[P-mpls-ldp]quit
[P]interfacegigabitethernet1/0/0
[P-GigabitEthernet1/0/0]mpls
[P-GigabitEthernet1/0/0]mplsldp
[P-GigabitEthernet2/0/0]mpls
[P-GigabitEthernet2/0/0]mplsldp
[PE2]
[PE2]mpls
[PE2-mpls]quit
[PE2]mplsldp
[PE2-mpls-ldp]quit
[PE2]interfacegigabitethernet3/0/0
[PE2-GigabitEthernet3/0/0]mpls
[PE2-GigabitEthernet3/0/0]mplsldp
上述配置完成后,PE1与P、P与PE2之间应能建立LDP会话,执行displaymplsldpsession命令可以看到显示结果中Status项为“Operational”。
执行displaymplsldplsp命令,可以看到LDPLSP的建立情况。
[PE1]displaymplsldpsession
LDPSession(s)inPublicNetwork
Codes:
LAM(LabelAdvertisementMode),SsnAgeUnit(DDDD:
HH:
MM)
A'
*'
beforeasessionmeansthesessionisbeingdeleted.
------------------------------------------------------------------------------
PeerIDStatusLAMSsnRoleSsnAgeKASent/Rcv
OperationalDUActive0000:
00:
016/6
TOTAL:
1session(s)Found.
[PE1]displaymplsldplsp
LDPLSPInformation
-------------------------------------------------------------------------------
DestAddress/MaskIn/OutLabelUpstreamPeerNextHopOutInterface
5NormalLSP(s)Found.
1LiberalLSP(s)Found.
0FrrLSP(s)Found.
beforeanLSPmeanstheLSPisnotestablished
beforeaLabelmeanstheUSCBorDSCBisstale
beforeaUpstreamPeermeansthesessionisstale
beforeaDSmeansthesessionisstale
beforeaNextHopmeanstheLSPisFRRLSP
3.在PE设备上配置VPN实例,将CE接入PE
[PE1]ipvpn-instancevpna
[PE1-vpn-instance-vpna]ipv4-family
[PE1-vpn-instance-vpna-af-ipv4]route-distinguisher100:
1
[PE1-vpn-instance-vpna-af-ipv4]vpn-target111:
1both
[PE1-vpn-instance-vpna-af-ipv4]quit
[PE1-vpn-instance-vpna]quit
[PE1]ipvpn-instancevpnb
[PE1-vpn-instance-vpnb]ipv4-family
[PE1-vpn-instance-vpnb-af-ipv4]route-distinguisher100:
2
[PE1-vpn-instance-vpnb-af-ipv4]vpn-target222:
2both
[PE1-vpn-instance-vpnb]quit
[PE1]interfacegigabitethernet1/0/0
[PE1-GigabitEthernet1/0/0]ipbindingvpn-instancevpna
[PE1-GigabitEthernet1/0/0]
[PE1-GigabitEthernet1/0/0]quit
[PE1]interfacegigabitethernet2/0/0
[PE1-GigabitEthernet2/0/0]ipbindingvpn-instancevpnb
[PE1-GigabitEthernet2/0/0]
[PE1-GigabitEthernet2/0/0]quit
[PE2]ipvpn-instancevpna
[PE2-vpn-instance-vpna]ipv4-family
[PE2-vpn-instance-vpna-af-ipv4]route-distinguisher200:
[PE2-vpn-instance-vpna-af-ipv4]vpn-target111:
[PE2-vpn-instance-vpna-af-ipv4]quit
[PE2-vpn-instance-vpna]quit
[PE2]ipvpn-instancevpnb
[PE2-vpn-instance-vpnb]ipv4-family
[PE2-vpn-instance-vpnb-af-ipv4]route-distinguisher200:
[PE2-vpn-instance-vpnb-af-ipv4]vpn-target222:
[PE2-vpn-instance-vpnb-af-ipv4]quit
[PE2-vpn-instance-vpnb]quit
[PE2]interfacegigabitethernet1/0/0
[PE2-GigabitEthernet1/0/0]ipbindingvpn-instancevpna
[PE2-GigabitEthernet1/0/0]
[PE2-GigabitEthernet1/0/0]quit
[PE2]interfacegigabitethernet2/0/0
[PE2-GigabitEthernet2/0/0]ipbindingvpn-instancevpnb
[PE2-GigabitEthernet2/0/0]
[PE2-GigabitEthernet2/0/0]quit
#按配置各CE的接口IP地址。
#配置CE1。
CE2、CE3和CE4与CE1类似,不再赘述。
[Huawei]sysnameCE1
[CE1]interfacegigabitethernet1/0/0
[CE1-GigabitEthernet1/0/0]
[CE1-GigabitEthernet1/0/0]quit
配置完成后,在PE设备上执行displayipvpn-instanceverbose命令可以看到VPN实例的配置情况。
各PE能ping通自己接入的CE。
?
说明:
当PE上有多个接口绑定了同一个VPN,则使用ping-vpn-instance命令ping对端PE接入的CE时,要指定源IP地址,即要指定ping-vpn-instance?
vpn-instance-name?
-a?
source-ip-addressdest-ip-address命令中的参数-asource-ip-address,否则可能ping不通。
以PE1为例:
[PE1]displayipvpn-instanceverbose
TotalVPN-Instancesconfigured:
2
TotalIPv4VPN-Instancesconfigured:
TotalIPv6VPN-Instancesconfigured:
0
VPN-InstanceNameandID:
vpna,1
Interfaces:
GigabitEthernet1/0/0
Addressfamilyipv4
Createdate:
2012/07/2500:
58:
17
Uptime:
0days,22hours,24minutesand53seconds
RouteDistinguisher:
100:
ExportVPNTargets:
111:
ImportVPNTargets:
LabelPolicy:
labelperroute
LogInterval:
vpnb,2
GigabitEthernet2/0/0
222:
5packet(s)transmitted
5packet(s)received
%packetloss
round-tripmin/avg/max=3/6/16ms
4.在PE之间建立MP-IBGP对等体关系
[PE1]bgp100
[PE1-bgp]
[PE1-bgp]ipv4-familyvpnv4
[PE1-bgp-af-vpnv4]
[PE1-bgp-af-vpnv4]quit
[PE1-bgp]quit
[PE2]bgp100
[PE2-bgp]
[PE2-bgp]ipv4-familyvpnv4
[PE2-bgp-af-vpnv4]
[PE2-bgp-af-vpnv4]quit
[PE2-bgp]quit
配置完成后,在PE设备上执行displaybgppeer或displaybgpvpnv4allpeer命令,可以看到PE之间的BGP对等体关系已建立,并达到Established状态。
[PE1]displaybgppeer
LocalASnumber:
100
Totalnumberofpeers:
1Peersinestablishedstate:
PeerVASMsgRcvdMsgSentOutQUp/DownStatePrefRcv
Established0
[PE1]displaybgpvpnv4allpeer
5.在PE与CE之间建立EBGP对等体关系,引入VPN路由
[CE1]bgp65410
[CE1-bgp]
[CE1-bgp]import-routedirect
[CE1-bgp]quit
PE2的配置与PE1类似,不再赘述。
[PE1-bgp]ipv4-familyvpn-instancevpna
[PE1-bgp-vpna]
[PE1-bgp-vpna]import-routedirect
[PE1-bgp-vpna]quit
[PE1-bgp]ipv4-familyvpn-instancevpnb
[PE1-bgp-vpnb]
[PE1-bgp-vpnb]import-routedirect
[PE1-bgp-vpnb]quit
配置完成后,在PE设备上执行displaybgpvpnv4vpn-instancepeer命令,可以看到PE与CE之间的BGP对等体关系已建立,并达到Established状态。
以PE1与CE1的对等体关系为例:
[PE1]displaybgpvpnv4vpn-instancevpnapeer
100
1
Established4
6.验证配置结果
#在PE设备上执行displayiprouting-tablevpn-instance命令,可以看到去往对端CE的路由。
#以PE1的显示为例:
[PE1]displayiprouting-tablevpn-instancevpna
vpna
5Routes:
Destination/MaskProtoPreCostFlagsNextHopInterface
[PE1]displayiprouting-tablevpn-instancevpnb
vpnb
#同一VPN的CE能够相互Ping通,不同VPN的CE不能相互Ping通。
[CE1]
round-tripmin/avg/max=34/48/72ms
Requesttimeout
0packet(s)received
配置文件
∙PE1的配置文件
∙#
∙sysnamePE1
∙ip
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 华为 路由器 MPLSVPN 配置 示例