华为L3VPNv4 over SRv6 BE配置案例

NE1

sysname pe1

ip vpn-instance vpn

ipv4-family

route-distinguisher 1:1

vpn-target 100:100 export-extcommunity

vpn-target 100:100 import-extcommunity

segment-routing ipv6 //建立srv6-BE路径

encapsulation source-address 2000::1 //用自己的回环口地址建立node sid

locator test ipv6-prefix 2000:1::1 64 static 32 //funcation用默认的动态自动生成

isis 1

is-level level-2

cost-style wide

network-entity 49.0001.0000.0000.0001.00

ipv6 enable topology ipv6

segment-routing ipv6 locator test //调用上面的名为test的locator,用isis扩散出去

interface Ethernet1/0/0

undo shutdown

ip binding vpn-instance vpn

ip address 192.168.0.1 255.255.255.0

undo dcn

undo dcn mode vlan

interface Ethernet1/0/1

undo shutdown

ipv6 enable

ipv6 address auto link-local

isis ipv6 enable 1

undo dcn

undo dcn mode vlan

interface LoopBack0

ipv6 enable

ipv6 address 2000::1/128

isis ipv6 enable 1

interface NULL0

bgp 100

router-id 1.1.1.1

peer 2000::3 as-number 100

peer 2000::3 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

ipv4-family vpnv4

policy vpn-target

peer 2000::3 enable

peer 2000::3 prefix-sid //段路由产生一个V标,私网路由携带SID

ipv4-family vpn-instance vpn

peer 192.168.0.2 as-number 65001

segment-routing ipv6 locator test //给vpn实例分配srv6标签,End.DT4

segment-routing ipv6 best-effort

undo dcn

NE2

isis 1

is-level level-2

cost-style wide

network-entity 49.0001.0000.0000.0002.00

ipv6 enable topology ipv6

interface Ethernet1/0/1

undo shutdown

ipv6 enable

ipv6 address auto link-local

isis ipv6 enable 1

undo dcn

undo dcn mode vlan

interface Ethernet1/0/2

undo shutdown

ipv6 enable

ipv6 address auto link-local

isis enable 1

isis ipv6 enable 1

undo dcn mode vlan

interface LoopBack0

ipv6 enable

ipv6 address 2000::2/128

isis ipv6 enable 1

undo dcn

NE3

ip vpn-instance vpn

ipv4-family

route-distinguisher 1:2

vpn-target 100:100 export-extcommunity

vpn-target 100:100 import-extcommunity

segment-routing ipv6

encapsulation source-address 2000::3

locator test ipv6-prefix 2000:3::3 64 static 32

isis 1

is-level level-2

cost-style wide

network-entity 49.0001.0000.0000.0003.00

ipv6 enable topology ipv6

segment-routing ipv6 locator test

interface Ethernet1/0/0

undo shutdown

ip binding vpn-instance vpn

ip address 192.168.1.1 255.255.255.0

undo dcn

undo dcn mode vlan

interface Ethernet1/0/1

undo shutdown

undo dcn

undo dcn mode vlan

interface Ethernet1/0/2

undo shutdown

ipv6 enable

ipv6 address auto link-local

isis ipv6 enable 1

undo dcn mode vlan

interface LoopBack0

ipv6 enable

ipv6 address 2000::3/128

isis ipv6 enable 1

interface NULL0

bgp 100

router-id 3.3.3.3

peer 2000::1 as-number 100

peer 2000::1 connect-interface LoopBack0

ipv4-family unicast

undo synchronization

ipv4-family vpnv4

policy vpn-target

peer 2000::1 enable

peer 2000::1 prefix-sid

ipv4-family vpn-instance vpn

peer 192.168.1.2 as-number 65002

segment-routing ipv6 locator test

segment-routing ipv6 best-effort

undo dcn

静态手动指定funcation

如果要用静态手动指定funcation就用以下配置替换上面的对应配,两边pe都要配:

isis 1

pe2-isis-1\]dis segment-routing ipv6 local-sid end forwarding //默认是动态,关掉它 segment-routing ipv6 locator test opcode ::111 end //手动指定end ### 查看 \[pe1\]dis segment-routing ipv6 local-sid end-dt4 forwarding ![在这里插入图片描述](https://file.jishuzhan.net/article/1783359243294871554/bb00ea898eb317ca3512115484773aa9.webp) \[pe1\]dis ip routing-table vpn-instance vpn 22.1.1.1 verbose ![在这里插入图片描述](https://file.jishuzhan.net/article/1783359243294871554/ab6aa31051337ce87ff7f14e95fa8902.webp) \[pe2\]dis segment-routing ipv6 local-sid end forwarding ![在这里插入图片描述](https://file.jishuzhan.net/article/1783359243294871554/d11bf6968fdb97c244a7f4c3ef57239e.webp)

相关推荐
遇到困难睡大觉哈哈1 小时前
HarmonyOS 公共事件机制介绍以及多进程之间的通信实现(9000字详解)
华为·harmonyos
Absinthe_苦艾酒2 小时前
计算机网络(三)传输层TCP
网络·tcp/ip·计算机网络
GLAB-Mary3 小时前
AI会取代网络工程师吗?理解AI在网络安全中的角色
网络·人工智能·web安全
敲敲敲-敲代码4 小时前
【ArcGIS10.2】网络数据集构建---最短路径分析
网络·arcgis
伍哥的传说5 小时前
鸿蒙系统(HarmonyOS)应用开发之实现电子签名效果
开发语言·前端·华为·harmonyos·鸿蒙·鸿蒙系统
cliffordl5 小时前
MCP 传输机制(Streamable HTTP)
网络·网络协议·http
晨曦丿6 小时前
双11服务器
linux·服务器·网络
galaxylove6 小时前
Gartner发布最新指南:企业要构建防御性强且敏捷的网络安全计划以平衡安全保障与业务运营
网络·安全·web安全
漫谈网络6 小时前
WebSocket扫盲
网络·websocket·网络协议
CH_Qing8 小时前
【udev】关于/dev 设备节点的生成 &udev
linux·前端·网络