华为BGPMPLSVPN多VPN配置实例.docx
《华为BGPMPLSVPN多VPN配置实例.docx》由会员分享,可在线阅读,更多相关《华为BGPMPLSVPN多VPN配置实例.docx(39页珍藏版)》请在冰豆网上搜索。
![华为BGPMPLSVPN多VPN配置实例.docx](https://file1.bdocx.com/fileroot1/2023-2/3/95c5647b-77c7-4680-b0a4-6995d7ea1563/95c5647b-77c7-4680-b0a4-6995d7ea15631.gif)
华为BGPMPLSVPN多VPN配置实例
华为BGP-MPLS-VPN多实例VPN配置实例
DISCU
#
sysnameR1
#
ipvpn-instanceTMIS
ipv4-family
route-distinguisher65107:
300001
vpn-target300:
300export-extcommunity
vpn-target300:
300import-extcommunity
#
mplslsr-id1.1.1.1
mpls
#
mplsldp
#
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher^HqTM5!
W[YjKUGU-KkpB=u/#
local-useradminservice-typehttp
#
isis1
is-levellevel-2
cost-stylewide
network-entity10.0000.0000.0000.0001.00
#
firewallzoneLocal
priority16
#
interfaceEthernet0/0/0
#
interfaceEthernet0/0/1
#
interfaceSerial0/0/0
link-protocolppp
#
interfaceSerial0/0/1
link-protocolppp
#
interfaceSerial0/0/2
link-protocolppp
#
interfaceSerial0/0/3
link-protocolppp
#
interfaceGigabitEthernet0/0/0
ipaddress10.220.12.1255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/1
ipaddress10.220.14.1255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/2
ipaddress10.220.19.1255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/3
ipbindingvpn-instanceTMIS
ipaddress10.220.101.1255.255.255.0
#
wlan
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress1.1.1.1255.255.255.255
isisenable1
#
interfaceLoopBack1
ipbindingvpn-instanceTMIS
ipaddress192.168.1.1255.255.255.0
#
bgp65107
groupVPNinternal
peerVPNconnect-interfaceLoopBack0
peer2.2.2.2as-number65107
peer2.2.2.2groupVPN
peer3.3.3.3as-number65107
peer3.3.3.3groupVPN
peer4.4.4.4as-number65107
peer4.4.4.4groupVPN
peer6.6.6.6as-number65107
peer6.6.6.6groupVPN
peer7.7.7.7as-number65107
peer7.7.7.7groupVPN
peer9.9.9.9as-number65107
peer9.9.9.9groupVPN
#
ipv4-familyunicast
undosynchronization
peerVPNenable
peerVPNreflect-client
peer2.2.2.2enable
peer2.2.2.2groupVPN
peer3.3.3.3enable
peer3.3.3.3groupVPN
peer4.4.4.4enable
peer4.4.4.4groupVPN
peer6.6.6.6enable
peer6.6.6.6groupVPN
peer7.7.7.7enable
peer7.7.7.7groupVPN
peer9.9.9.9enable
peer9.9.9.9groupVPN
#
ipv4-familyvpnv4
undopolicyvpn-target
peerVPNenable
peerVPNreflect-client
peer2.2.2.2enable
peer2.2.2.2groupVPN
peer3.3.3.3enable
peer3.3.3.3groupVPN
peer4.4.4.4enable
peer4.4.4.4groupVPN
peer6.6.6.6enable
peer6.6.6.6groupVPN
peer7.7.7.7enable
peer7.7.7.7groupVPN
#
ipv4-familyvpn-instanceTMIS
import-routedirect
import-routestatic
peer10.220.101.9as-number100
#
user-interfacecon0
user-interfacevty04
user-interfacevty1620
#
return
DISCU
#
sysnameR9
#
ipvpn-instanceIVMS
ipv4-family
route-distinguisher65107:
102
vpn-target102:
102export-extcommunity
vpn-target102:
102import-extcommunity
#
ipvpn-instanceTMIS
ipv4-family
route-distinguisher65107:
300009
vpn-target300:
300export-extcommunity
vpn-target300:
300import-extcommunity
#
mplslsr-id9.9.9.9
mpls
#
mplsldp
#
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher^HqTM5!
W[Y+/Y@:
Y>Lw(Yu^#
local-useradminservice-typehttp
#
isis1
is-levellevel-2
cost-stylewide
network-entity10.0000.0000.0000.0009.00
#
firewallzoneLocal
priority16
#
interfaceEthernet0/0/0
ipbindingvpn-instanceIVMS
ipaddress192.168.8.1255.255.255.0
#
interfaceEthernet0/0/1
#
interfaceSerial0/0/0
link-protocolppp
#
interfaceSerial0/0/1
link-protocolppp
#
interfaceSerial0/0/2
link-protocolppp
#
interfaceSerial0/0/3
link-protocolppp
#
interfaceGigabitEthernet0/0/0
ipaddress10.220.29.9255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/1
ipaddress10.220.49.9255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/2
ipaddress10.220.19.9255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/3
ipbindingvpn-instanceTMIS
ipaddress10.220.109.9255.255.255.0
#
wlan
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress9.9.9.9255.255.255.255
isisenable1
#
bgp65107
peer9.9.9.9as-number65107
groupVPNinternal
peerVPNconnect-interfaceLoopBack0
peer1.1.1.1as-number65107
peer1.1.1.1groupVPN
peer2.2.2.2as-number65107
peer2.2.2.2groupVPN
peer3.3.3.3as-number65107
peer3.3.3.3groupVPN
peer4.4.4.4as-number65107
peer4.4.4.4groupVPN
peer6.6.6.6as-number65107
peer6.6.6.6groupVPN
peer7.7.7.7as-number65107
peer7.7.7.7groupVPN
#
ipv4-familyunicast
undosynchronization
undopeer9.9.9.9enable
peerVPNenable
peerVPNreflect-client
peer1.1.1.1enable
peer1.1.1.1groupVPN
peer2.2.2.2enable
peer2.2.2.2groupVPN
peer3.3.3.3enable
peer3.3.3.3groupVPN
peer4.4.4.4enable
peer4.4.4.4groupVPN
peer6.6.6.6enable
peer6.6.6.6groupVPN
peer7.7.7.7enable
peer7.7.7.7groupVPN
#
ipv4-familyvpnv4
undopolicyvpn-target
peerVPNenable
peerVPNreflect-client
peer1.1.1.1enable
peer1.1.1.1groupVPN
peer2.2.2.2enable
peer2.2.2.2groupVPN
peer3.3.3.3enable
peer3.3.3.3groupVPN
peer4.4.4.4enable
peer4.4.4.4groupVPN
peer6.6.6.6enable
peer6.6.6.6groupVPN
peer7.7.7.7enable
peer7.7.7.7groupVPN
#
ipv4-familyvpn-instanceIVMS
import-routedirect
#
ipv4-familyvpn-instanceTMIS
import-routedirect
import-routestatic
peer10.220.109.1as-number100
#
user-interfacecon0
user-interfacevty04
user-interfacevty1620
#
return
DISCU
#
sysnameR2
#
routerid2.2.2.2
#
ipvpn-instanceTMIS
ipv4-family
route-distinguisher65107:
300002
vpn-target300:
300export-extcommunity
vpn-target300:
300import-extcommunity
#
mplslsr-id2.2.2.2
mpls
#
mplsldp
#
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordciphermdeIV<"F6,ZypQCee$t3i!
e#
local-useradminservice-typehttp
#
isis1
is-levellevel-2
cost-stylewide
network-entity10.0000.0102.2001.2002.00
#
firewallzoneLocal
priority16
#
interfaceEthernet0/0/0
#
interfaceEthernet0/0/1
#
interfaceSerial0/0/0
link-protocolppp
#
interfaceSerial0/0/1
link-protocolppp
#
interfaceSerial0/0/2
link-protocolppp
#
interfaceSerial0/0/3
link-protocolppp
#
interfaceGigabitEthernet0/0/0
ipaddress10.220.12.2255.255.255.0
isisenable1
isiscircuit-levellevel-2
mpls
mplsldp
#
interfaceGigabitEthernet0/0/1
ipaddress10.220.23.2255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/2
ipaddress10.220.26.2255.255.255.0
isisenable1
mpls
mplsldp
#
interfaceGigabitEthernet0/0/3
ipaddress10.220.39.3255.255.255.0
isisenable1
mpls
mplsldp
#
wlan
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress2.2.2.2255.255.255.255
isisenable1
#
interfaceLoopBack1
ipbindingvpn-instanceTMIS
ipaddress10.195.1.1255.255.255.255
#
bgp65107
groupVPNinternal
peerVPNconnect-interfaceLoopBack0
peer1.1.1.1as-number65107
peer1.1.1.1groupVPN
peer9.9.9.9as-number65107
peer9.9.9.9groupVPN
#
ipv4-familyunicast
undosynchronization
peerVPNenable
peer1.1.1.1enable
peer1.1.1.1groupVPN
peer9.9.9.9enable
peer9.9.9.9groupVPN
#
ipv4-familyvpnv4
undopolicyvpn-target
peerVPNenable
peer1.1.1.1enable
peer1.1.1.1groupVPN
peer9.9.9.9enable
peer9.9.9.9groupVPN
#
ipv4-familyvpn-instanceTMIS
import-routedirect
import-routestatic
#
user-interfacecon0
user-interfacevty04
user-interfacevty1620
#
return
DISCU
#
sysnameR10
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher'omy&03(mLECB7Ie7'/)G"W#
local-useradminservice-typehttp
#
firewallzoneLocal
priority16
#
interfaceEthernet0/0/0
#
interfaceEthernet0/0/1
#
interfaceSerial0/0/0
link-protocolppp
#
interfaceSerial0/0/1
link-protocolppp
#
interfaceSerial0/0/2
link-protocolppp
#
interfaceSerial0/0/3
link-protocolppp
#
interfaceGigabitEthernet0/0/0
ipaddress10.220.101.9255.255.255.0
#
interfaceGigabitEthernet0/0/1
ipaddress10.220.109.1255.255.255.0
#
interfaceGigabitEthernet0/0/2
ipaddress10.10.10.1255.255.255.0
#
interfaceGigabitEthernet0/0/3
#
wlan
#
interfaceNULL0
#
bgp100
peer10.220.101.1as-number65107
peer10.220.109.9as-number65107
#
ipv4-familyunicast
undosynchronization
import-routedirect
import-routestatic
peer10.220.101.1enable
peer10.220.109.9enable
#
iproute-static88.88.88.0255.255.255.010.10.10.2
#
user-interfacecon0
user-interfacevty04
user-interfacevty1620
#
Return
DISCU
#
sysnameR4
#
ipvpn-instanceIVMS
ipv4-family
route-distinguisher666:
888
vpn-target100:
100102:
102export-extcommunity
vpn-target100:
100102:
102import-extcommunity
#
ipvpn-instanceTMIS
ipv4-family
route-distinguisher65107:
300004
vpn-target300:
300export-extcommunity
vpn-target300:
300import-extcommunity
#
mplslsr-id4.4.4.4
mpls
#
mplsldp
#
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordciphergD/VGZfKq73@9_G-B0Y2b$5#
local-useradminservice-typehttp
#
isis1
is-levellevel-2
cost-stylewide
network-entity1