华为mpls vpn跨域方案A

跨域方案A原理(缺点是两个as如果有多个ce的话,要用多条的物理连接或子接口连接,不实用):

1、pe和P都和单域一样配置,只是asbr-pe配置不同

2、2个asbr-pe配置上面建立ip vpn-instance 实例

3、2个asbr-pe互联接口上一样要绑定vpn实例

3、2个asbr-pe在bgp的vpn实例中建立EBGP邻居

ipv4-fimary vpn-innstance a

peer XXX as //建立邻居

R1

ip vpn-instance a

ipv4-family

route-distinguisher 1:1

vpn-target 100:100 export-extcommunity

vpn-target 100:100 import-extcommunity

mpls lsr-id 1.1.1.1

mpls

mpls ldp

interface GigabitEthernet0/0/0

ip address 10.0.12.1 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/1

ip binding vpn-instance a

ip address 10.0.17.1 255.255.255.0

ospf enable 2 area 0.0.0.0

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0

ip address 1.1.1.1 255.255.255.255

bgp 100

peer 2.2.2.2 as-number 100

peer 2.2.2.2 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

peer 2.2.2.2 enable

ipv4-family vpnv4

policy vpn-target

peer 2.2.2.2 enable

ipv4-family vpn-instance a

import-route ospf 2

ospf 1

area 0.0.0.0

network 0.0.0.0 255.255.255.255

ospf 2 vpn-instance a

import-route bgp

area 0.0.0.0

R2

mpls lsr-id 2.2.2.2

mpls

mpls ldp

interface GigabitEthernet0/0/0

ip address 10.0.12.2 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/1

ip address 10.0.23.2 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0

ip address 2.2.2.2 255.255.255.255

bgp 100

peer 1.1.1.1 as-number 100

peer 1.1.1.1 connect-interface LoopBack0

peer 3.3.3.3 as-number 100

peer 3.3.3.3 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

peer 1.1.1.1 enable

peer 1.1.1.1 reflect-client

peer 3.3.3.3 enable

peer 3.3.3.3 reflect-client

ipv4-family vpnv4

undo policy vpn-target

peer 1.1.1.1 enable

peer 1.1.1.1 reflect-client

peer 3.3.3.3 enable

peer 3.3.3.3 reflect-client

ospf 1

area 0.0.0.0

network 0.0.0.0 255.255.255.255

R3:

ip vpn-instance a

ipv4-family

route-distinguisher 1:1

vpn-target 100:100 export-extcommunity

vpn-target 100:100 import-extcommunity

mpls lsr-id 3.3.3.3

mpls

mpls ldp

interface GigabitEthernet0/0/0

ip address 10.0.23.3 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/1

ip binding vpn-instance a

ip address 10.0.34.3 255.255.255.0

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0

ip address 3.3.3.3 255.255.255.255

bgp 100

peer 2.2.2.2 as-number 100

peer 2.2.2.2 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

peer 2.2.2.2 enable

ipv4-family vpnv4

policy vpn-target

peer 2.2.2.2 enable

ipv4-family vpn-instance a

peer 10.0.34.4 as-number 200

ospf 1

area 0.0.0.0

network 0.0.0.0 255.255.255.255

R4

ip vpn-instance a

ipv4-family

route-distinguisher 1:1

vpn-target 100:100 export-extcommunity

vpn-target 100:100 import-extcommunity

mpls lsr-id 4.4.4.4

mpls

mpls ldp

interface GigabitEthernet0/0/0

ip binding vpn-instance a

ip address 10.0.34.4 255.255.255.0

interface GigabitEthernet0/0/1

ip address 10.0.41.4 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0

ip address 4.4.4.4 255.255.255.255

bgp 200

peer 10.10.10.10 as-number 200

peer 10.10.10.10 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

peer 10.10.10.10 enable

ipv4-family vpnv4

policy vpn-target

peer 10.10.10.10 enable

ipv4-family vpn-instance a

peer 10.0.34.3 as-number 100

ospf 1

area 0.0.0.0

network 4.4.4.4 0.0.0.0

network 10.0.41.4 0.0.0.0

R7

router id 7.7.7.7

interface GigabitEthernet0/0/0

ip address 10.0.17.7 255.255.255.0

ospf enable 1 area 0.0.0.0

interface LoopBack0

ip address 7.7.7.7 255.255.255.255

ospf enable 1 area 0.0.0.0

ospf 1

area 0.0.0.0

R10

mpls lsr-id 10.10.10.10

mpls

mpls ldp

interface GigabitEthernet0/0/0

ip address 10.0.41.10 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/1

ip address 10.0.111.10 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0

ip address 10.10.10.10 255.255.255.255

bgp 200

peer 4.4.4.4 as-number 200

peer 4.4.4.4 connect-interface LoopBack0

peer 11.11.11.11 as-number 200

peer 11.11.11.11 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

peer 4.4.4.4 enable

peer 11.11.11.11 enable

ipv4-family vpnv4

undo policy vpn-target

peer 4.4.4.4 enable

peer 4.4.4.4 reflect-client

peer 11.11.11.11 enable

peer 11.11.11.11 reflect-client

ospf 1

area 0.0.0.0

network 10.0.41.10 0.0.0.0

network 10.0.111.10 0.0.0.0

network 10.10.10.10 0.0.0.0

R11

ip vpn-instance a

ipv4-family

route-distinguisher 1:1

vpn-target 100:100 export-extcommunity

vpn-target 100:100 import-extcommunity

mpls lsr-id 11.11.11.11

mpls

mpls ldp

interface GigabitEthernet0/0/0

ip address 10.0.111.11 255.255.255.0

mpls

mpls ldp

interface GigabitEthernet0/0/1

ip binding vpn-instance a

ip address 10.0.112.1 255.255.255.0

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0

ip address 11.11.11.11 255.255.255.255

bgp 200

peer 10.10.10.10 as-number 200

peer 10.10.10.10 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

peer 10.10.10.10 enable

ipv4-family vpnv4

policy vpn-target

peer 10.10.10.10 enable

ipv4-family vpn-instance a

import-route ospf 2

ospf 1

area 0.0.0.0

network 10.0.111.11 0.0.0.0

network 11.11.11.11 0.0.0.0

ospf 2 vpn-instance a

import-route bgp

area 0.0.0.0

network 10.0.112.1 0.0.0.0

R12

interface GigabitEthernet0/0/0

ip address 10.0.112.2 255.255.255.0

interface GigabitEthernet0/0/1

interface GigabitEthernet0/0/2

interface NULL0

interface LoopBack0

ip address 12.12.12.12 255.255.255.255

ospf 1

area 0.0.0.0

network 10.0.112.2 0.0.0.0

network 12.12.12.12 0.0.0.0

相关推荐
枷锁—sha34 分钟前
【SRC】SQL注入WAF 绕过应对策略(二)
网络·数据库·python·sql·安全·网络安全
Zach_yuan1 小时前
深入浅出 JSONCpp
linux·服务器·网络·c++
lbb 小魔仙2 小时前
【HarmonyOS实战】React Native 表单实战:在 OpenHarmony 上构建高性能表单
react native·华为·harmonyos
迎仔3 小时前
B-算力中心网络隔离的必要性:为什么必须隔离?
网络
野指针YZZ4 小时前
一键配置RK3588网络与SSH远程连接
网络·ssh·rk3588
迎仔4 小时前
10-网络安全监控与事件响应:数字世界的智能监控与应急系统
网络·安全·web安全
上海合宙LuatOS4 小时前
LuatOS核心库API——【audio 】
java·网络·单片机·嵌入式硬件·物联网·音视频·硬件工程
深圳市恒星物联科技有限公司5 小时前
水质流量监测仪:复合指标监测的管网智能感知设备
大数据·网络·人工智能
科技块儿6 小时前
2026年我会推荐哪些IP归属地查询网站?
网络·ip地址·ip归属地·运维工具·网络工具·实用网站·2026工具推荐
米羊1217 小时前
已有安全措施确认(中)
网络