华为路由器mplsvpn配置示例Word文档格式.docx
- 文档编号:3666060
- 上传时间:2023-05-02
- 格式:DOCX
- 页数:24
- 大小:448.10KB
华为路由器mplsvpn配置示例Word文档格式.docx
《华为路由器mplsvpn配置示例Word文档格式.docx》由会员分享,可在线阅读,更多相关《华为路由器mplsvpn配置示例Word文档格式.docx(24页珍藏版)》请在冰点文库上搜索。
[P]interface
[P-GigabitEthernet1/0/0]ipaddress24
配置完成后,PE1、P、PE2之问应能建立OSPF邻居关系,执行displayospfpeer命令可以看到邻居状态为Fu11o执行displayiprouting-table命令可以看到PE之间学习到对方的Loopbackl路由。
以PE1的显示为例:
[PE1]displayiprouting-tabIe
RouteFlags:
R-relay,
D一downIoadtofib
RoutingTables:
PubIic
Destinations:
11
Routes:
Destination/Mask
ProtoPre
Cost
FlagsNextHop
Interface
/32Direct
00
D
LoopBack!
/32OSPF101
/32OSPF102
/8Direct00
/32Direct00
GigabitEthernet3/0/0
GigabitEthernet3/0/0
InLoopBackO
/32
Direct00
/24Direct00
/
32Direct00
/24OSPF102
1nLoopBackO
[PE1]
displayospfpeer
OSPFProcess1with
Router
ID
Neighbors
Area
interface(GigabitEthernet3/0/0)*s
neighbors
RouterID:
Address:
State:
FulIMode:
NbrisMaster
Priority:
1
DR:
BDR:
MTU:
0
Deadtimerduein37sec
Retranstimerinterval:
5
Neighborisupfor00:
16:
21
AuthenticationSequence:
[
0]
2.在MPLS骨干网上配置MPLS基本能力和MPLSLDP,建立LDPLSP
#配置PE1o
[PE1]mplsIsr-id
[PE1]mpls
[PE1-mpls]quit
[PE1]mplsIdp
[PE1-mpls-ldp]quit
[PE1]interfacegigabitethernet3/0/0
[PE1-GigabitEthernet3/0/0]mpls
[PE1-GigabitEthernet3/0/0]mplsIdp
[PE1-GigabitEthernet3/0/0]quit
[P]mplsIsr-id
[P]mpls
[P-mpIs]quit
[P]mplsIdp
[P-mpIs-ldp]quit
[P]interfacegigabitethernet1/0/0
[P-GigabitEthernet1/0/0]mpls
[P-GigabitEthernet1/0/0]mplsIdp
[P-GigabitEthernet1/0/0]quit
[P]interfacegigabitethernet2/0/0
[P-GigabitEthernet2/0/0]mpls
[P-GigabitEthernet2/0/0]mplsIdp
[P-GigabitEthernet2/0/0]quit
#配置PE2o
[PE2]mplsIsr-id
[PE2]mpls
[PE2-mpIs]quit
[PE2]mplsIdp
[PE2-mpls-ldp]quit
[PE2]interfacegigabitethernet3/0/0
[PE2-GigabitEthernet3/0/0]mpls
[PE2-GigabitEthernet3/0/0]mplsIdp
[PE2-GigabitEthernet3/0/0]quit
上述配置完成后,PE1与P、P与PE2之间应能建立LDP会话,执行displaymplsIdpsession命令可以看到显示结果中Status项为^Operational"
。
执行displaymplsIdpIsp命令,可以看到LDPLSP的建立情况。
[PE1]displaymplsIdpsession
LDPSession(s)inPubIicNetwork
Codes:
LAM(LabeIAdvertisementMode),SsnAgeUnit(DDDD:
HH:
MM)
A*beforeasessionmeansthesessionisbeingdeleted・
PeerIDStatusLAMSsnRoleSsnAgeKASent/Rcv
:
0OperationalDUActive0000:
00:
016/6
TOTAL:
1session(s)Found.
[PE1]displaymplsIdpIsp
LDPLSF
>
Information
DestAddress/MaskIn/OutLabelUpstreamPeerNextHopOutInterface
3/NULL
InLoopO
*/32
Libera1/1024
DS/
NULL/3-
GE3/0/0
1024/3
NULL/1025-
1025/1025
5NormalLSP(s)Found.
1LiberalLSP(s)Found・
0FrrLSP(s)Found・
A**•
beforeanLSPmeanstheLSPis
notestabIished
A
beforeaLabelmeanstheUSCBorDSCBisstale
beforeaUpstreamPeermeansthe
sessionisstale
A•**
beforeaDSmeansthesessioni
sstale
beforeaNextHopmeanstheLSP
isFRRLSP
3.在PE设备上配置VPN实例,将CE接入PE
[PE1]ipvpn-instancevpna
[PE1-vpn-instance-vpna]ipv4-famiIy
[PE1-vpn-instance-vpna-af-ipv4]route-distinguisher100:
1
[PE1-vpn-instance-vpna-af-ipv4]vpn-target111:
1both
[PE1-vpn-instance-vpna-af-ipv4]quit
[PE1-vpn-instance-vpna]quit
[PE1]ipvpn-instancovpnb
[PE1-vpn-instance-vpnb]ipv4-famiIy
[PE1-vpn-instance-vpnb-af-ipv4]
[PE1-vpn-instance-vpnb-af-ipv4]
route-distinguisher100:
2vpn-target222:
2both
[PE1-vpn-instance-vpna-af-ipv4]quit
[PE1-vpn-instance-vpnb]quit
[PE1]interfacegigabitethernet1/0/0
[PE1-GigabitEthernet1/O/O]ipbindingvpn-instancevpna
[PE1-GigabitEthernet1/0/0]ipaddress24
[PE1-GigabitEthernet1/O/O]quit
[PE1]interfacegigabitethernet2/0/0
[PE1-GigabitEthernet2/0/0]ipbindingvpn-instancevpnb
[PE1-GigabitEthernet2/0/0]ipaddress24
[PE1-GigabitEthernet2/0/0]quit
[PE2]ipvpn-instancevpna
[PE2-vpn-instance-vpna]ipv4-famiIy
[PE2-vpn-instance-vpna-af-ipv4]route-distinguishor200:
[PE2-vpn-instance-vpna-af-ipv4]vpn-target111:
1both[PE2-vpn-instance-vpna-af-ipv4]quit
[PE2-vpn-instance-vpna]quit[PE2]ipvpn-instancevpnb[PE2-vpn-instance-vpnb]ipv4-famiIy
[PE2-vpn-instance-vpnb-af-ipv4]route-distinguisher200:
2[PE2-vpn-instance-vpnb-af-ipv4]vpn-target222:
2both[PE2-vpn-instance-vpnb-af-ipv4]quit
[PE2-vpn-instance-vpnb]quit[PE2]interfacegigabitethernet1/0/0[PE2-GigabitEthernet1/0/0]ipbindingvpn-instancevpna[PE2-GigabitEthernet1/0/0]ipaddress24[PE2-GigabitEthernet1/0/0]quit
[PE2]interfacegigabitethernet2/0/0
[PE2-GigabitEthernet2/0/0]ipbindingvpn-instancevpnb[PE2-GigabitEthernet2/0/0]ipaddress24[PE2-GigabitEthernet2/0/0]quit
#按图1配置各CE的接口IP地址。
#配置CE1oCE2、CE3和CE4与CE1类似,不再赘述。
Huawei>
system-view
[Huawei]sysnameCE1
[CE1]interfacegigabitethernet1/0/0
[CE1-GigabitEthernet1/0/0]ipaddress24
[CE1-GigabitEthernet1/0/0]quit
配置完成后,在PE设备上执行displayipvpn-instanceverbose命令可以看到VPN
实例的配置情况。
各PE能ping通自己接入的CE。
当PE上有多个接口绑定了同一个VPN.则使用ping-vpn-instance命令ping对端
PE接入的CE时,要指定源IP地址,即要指定ping
-vpn-instaneevpn-instance-name一asource-ip-addressdest-ip-address令中的参数-asource-ip-address,否则可能ping不通<
以PE1为例:
[PE1]displayipvpn-instancoverbose
TotalVPN-1nstancesconfigured:
2
TotaIIPv4VPN-Instancesconfigured:
TotaIIPv6VPN-Instancesconfigured:
VPN-InstanceNameandID:
vpna,1
Interfaces:
GigabitEthernet1/0/0
Addressfamilyipv4
Createdate:
2012/07/2500:
58:
17
Uptime:
0days,22hours,24minutesand53seconds
RouteDistinguisher:
100:
ExportVPNTargets:
111:
ImportVPNTargets:
LabelPolicy:
labelperroute
LogInterval:
GigabitEthernet2/0/0
and53seconds
0days,22hours,24minutes
[PE1]ping-vpn-instancevpna
pingstatistics
5packet(s)transmitted
5packet(s)received
%packetloss
round-tripmin/avg/max=3/6/16ms
4.
在PE之间建立MP-IBGP对等体关系
[PE1]bgp100
[PE1-bgp]peeras-number100
[PE1-bgp]peerconnect-interfaceIoopback1
[PE1-bgp]ipv4-famiIyvpnv4
[PE1-bgp-af-vpnv4]peerenabIe
[PE1-bgp-af~vpnv4]quit
[PE1-bgp]quit
[PE2]bgp100
[PE2-bgp]peeras-number100
[PE2-bgp]peerconnect-irrterfaceIoopback1
[PE2-bgp]ipv4-famiIyvpnv4
[PE2-bgp-af-vpnv4]peerenable
[PE2-bgp-af-vpnv4]quit
[PE2-bgp]quit
配置完成后,在PE设备上执行displaybgppeer或displaybgpvpnv4alIpeer命令,可以看到PE之间的BGP对等体关系已建立,并达到Established状态。
[PE1]displaybgppeer
BGPlocalrouterID:
LocalASnumber:
100
Totalnumberofpeers:
1PeersinestabIishedstate:
PeerVASMsgRcvdMsgSentOutQUp/DownState
PrefRcv
4100126000:
02:
21Established
[PE1]displaybgpvpnv4alIpeer
Peer
ASMsgRcvdMsgSentOutQUp/DownState
5.
在PE与CE之间建立EBGP对等体关系,引入VPN路由
#配置CE1。
CE2、CE3和CE4与CE1类似,不再赘述。
[CE1]bgp65410
[CE1-bgp]peeras-number100
[CE1-bgp]import-routedirect
[CE1-bgp]quit
PE2的配置与PE1类似,不再赘述。
[PE1-bgp]ipv4-famiIyvpn-instancevpna
[PE1-bgp-vpna]peeras-number65410
[PE1-bgp-vpna]import-routedirect
[PE1-bgp-vpna]quit
[PE1-bgp]ipv4-famiIyvpn-instancevpnb
[PE1-bgp-vpnb]peeras-number65420
[PE1-bgp-vpnb]import-routedirect
[PE1-bgp-vpnb]quit
配置完成后,在PE设备上执行displaybgpvpnv4vpn-instancepeer命令,可以
看到PE与CE之间的BGP对等体关系已建立,并达到Established状态。
以PE1与CE1的对等体关系为例:
[PE1]displaybgpvpnv4vpn-instancevpnapeer
VPN-Instancevpna,RouterID:
Peersinestablishedstate:
465410
63000:
02Established4
6.验证配置结果
#在PE设备上执行displayiprouting-tablevpn-instance命令,可以看到去往对端CE的路由。
#以PE1的显示为例:
[PE1]displayiprouting-tabIevpn-instancevpna
R一relay,
D-downIoadtofib
RoutingTables:
vpna
Proto
PreCost
FlagsNextHopInterface
/24Direct
GigabitEthernet1/0/0
/32Direct0
GigabitEthernet1/0/0
/24IBGP
2550
RD
GigabitEthernet3/0/0
[PE1]displayiprouting-tablovpn-instancevpnb
vpnb
5Routes:
/24
Direct
GigabitEthernet2/0/0
GigabitEthernet2/0/0
Direct0
GigabitEthernet2/0/0
IBGP
255
#同一VPN的CE能够相互Ping通,不同VPN的CE不能相互Ping通。
#例如:
CE1能够Ping通CE30,但不能Ping通CE40。
[CE1]ping
PING:
56databytes,press
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 华为 路由器 mplsvpn 配置 示例