当前位置:网站首页>Huawei equipment configures local virtual private network mutual access

Huawei equipment configures local virtual private network mutual access

2022-06-11 04:51:00 Tony_ long7483

 Insert picture description here

  1. To configure IP Address
    [PE1-GigabitEthernet0/0/0]ip add 12.1.1.1 24
    [PE1-GigabitEthernet0/0/1]ip add 10.1.1.1 24
    [PE1-GigabitEthernet0/0/2]ip add 20.1.1.1 24
    [CE1-GigabitEthernet0/0/0]ip add 10.1.1.10 24
    [PE1-LoopBack0]ip add 1.1.1.1 32
    [CE2-GigabitEthernet0/0/0]ip add 20.1.1.20 24
    [PE2-GigabitEthernet0/0/0]ip add 12.1.1.2 24
    [PE2-GigabitEthernet0/0/1]ip add 30.1.1.2 24
    [PE2-GigabitEthernet0/0/2]ip add 40.1.1.2 24
    [PE2-LoopBack0]ip add 2.2.2.2 32
    [CE3-GigabitEthernet0/0/0]ip add 30.1.1.30 24
    [CE4-GigabitEthernet0/0/0]ip add 40.1.1.40 24
  2. stay PE The device is configured with VPN example , take CE Access PE
    [PE1]ip vpn-instance vpna
    [PE1-vpn-instance-vpna]ipv4-family
    [PE1-vpn-instance-vpna-af-ipv4]route-distinguisher 100:1
    [PE1-vpn-instance-vpna-af-ipv4]vpn-target 111:1 export-extcommunity
    [PE1-vpn-instance-vpna-af-ipv4]vpn-target 111:1 222:2 import-extcommunity
    [PE1]ip vpn-instance vpnb
    [PE1-vpn-instance-vpnb]route-distinguisher 100:2
    [PE1-vpn-instance-vpnb-af-ipv4]vpn-target 222:2 export-extcommunity
    [PE1-vpn-instance-vpnb-af-ipv4]vpn-target 111:1 222:2 import-extcommunity
    [PE1-GigabitEthernet0/0/1]ip binding vpn-instance vpna
    [PE1-GigabitEthernet0/0/1]ip add 10.1.1.1 24
    [PE1-GigabitEthernet0/0/2]ip binding vpn-instance vpnb
    [PE1-GigabitEthernet0/0/2]ip add 20.1.1.1 24
     Insert picture description here

[PE2]ip vpn-instance vpna
[PE2-vpn-instance-vpna]ipv4-family
[PE2-vpn-instance-vpna]route-distinguisher 100:1
[PE2-vpn-instance-vpna-af-ipv4]vpn-target 111:1 both
[PE2]ip vpn-instance vpnb
[PE2-vpn-instance-vpnb]ipv4-family
[PE2-vpn-instance-vpnb-af-ipv4]route-distinguisher 100:2
[PE2-vpn-instance-vpnb-af-ipv4]vpn-target 222:2 both
[PE2-GigabitEthernet0/0/1]ip binding vpn-instance vpna
[PE2-GigabitEthernet0/0/1]ip add 30.1.1.2 24
[PE2-GigabitEthernet0/0/2]ip binding vpn-instance vpnb
[PE2-GigabitEthernet0/0/2]ip add 40.1.1.2 24
 Insert picture description here

  1. To configure BGP, To local CE The direct connection route of is introduced VPN Routing table
    [PE1]bgp 100
    [PE1-bgp]ipv4-family vpn-instance vpna
    [PE1-bgp-vpna]import-route direct
    [PE1-bgp]ipv4-family vpn-instance vpnb
    [PE1-bgp-vpnb]import-route direct
    [PE2]bgp 100
    [PE2-bgp]ipv4-family vpn-instance vpna
    [PE2-bgp-vpna]import-route direct
    [PE2-bgp]ipv4-family vpn-instance vpnb
    [PE2-bgp-vpnb]import-route direct
  2. To configure CE Static routing on
    [CE1]ip route-static 0.0.0.0 0.0.0.0 10.1.1.1
    [CE2]ip route-static 0.0.0.0 0.0.0.0 20.1.1.1
    [CE3]ip route-static 0.0.0.0 0.0.0.0 30.1.1.2
    [CE4]ip route-static 0.0.0.0 0.0.0.0 40.1.1.2
  3. To configure PE Between OSPF
    [PE1]ospf 1
    [PE1-ospf-1]area 0
    [PE1-ospf-1-area-0.0.0.0]network 12.1.1.0 0.0.0.255
    [PE1-ospf-1-area-0.0.0.0]network 10.1.1.0 0.0.0.255
    [PE1-ospf-1-area-0.0.0.0]network 20.1.1.0 0.0.0.255
    [PE1-ospf-1-area-0.0.0.0]network 1.1.1.1 0.0.0.0
    [PE2]ospf 1
    [PE2-ospf-1]area 0
    [PE2-ospf-1-area-0.0.0.0]network 30.1.1.0 0.0.0.255
    [PE2-ospf-1-area-0.0.0.0]network 40.1.1.0 0.0.0.255
    [PE2-ospf-1-area-0.0.0.0]network 12.1.1.0 0.0.0.255
    [PE2-ospf-1-area-0.0.0.0]network 2.2.2.2 0.0.0.0
  4. To configure PE Of MPLS Basic abilities and MPLS LDP, establish LDP LSP
    [PE1]mpls lsr-id 1.1.1.1
    [PE1]mpls
    [PE1]mpls ldp
    [PE1-GigabitEthernet0/0/0]mpls
    [PE1-GigabitEthernet0/0/0]mpls ldp
    [PE2]mpls lsr-id 2.2.2.2
    [PE2]mpls
    [PE2]mpls ldp
    [PE2-GigabitEthernet0/0/0]mpls
    [PE2-GigabitEthernet0/0/0]mpls ldp
  5. stay PE Establish between MP-IBGP Peer relationship
    [PE1]bgp 100
    [PE1-bgp]peer 2.2.2.2 as-number 100
    [PE1-bgp]peer 2.2.2.2 connect-interface LoopBack 0
    [PE1-bgp]ipv4-family vpnv4
    [PE1-bgp-af-vpnv4]peer 2.2.2.2 enable
    [PE2]bgp 100
    [PE2-bgp]peer 1.1.1.1 as-number 100
    [PE2-bgp]peer 1.1.1.1 connect-interface LoopBack 0
    [PE2-bgp]ipv4-family vpnv4
    [PE2-bgp-af-vpnv4]peer 1.1.1.1 enable
  6. Check the configuration
     Insert picture description here
     Insert picture description here
原网站

版权声明
本文为[Tony_ long7483]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/162/202206110443263554.html