1、cisco路由器mpls vpn配置思路一、网络环境由5台CISCO7204组成的网络,一台为P路由器,两台PE路由器,两台CE路由器;二、网络描述在P和两台PE路由器这间通过OSPF动态路由协议完成MPLS网络的建立,两台PE路由器这间启用BGP路由协议,在PE路由器上向所属的CE路由器指VPN路由,在CE路由器中向PE路由器配置静态路由。配置思路:1、在P和两台PE路由器这间通过OSPF动态路由协议,在P和PE路由器两两互连的端口上启用MPLS,两台PE之间的路为备份路由,这属公网路由。2、两台PE路由器这间启用BGP路由协议,这使得属于VPN的IP地址能在两个网络(两台CE所属的网络)互
2、相发布,这属私网(VPN)路由。3、在PE路由器上向所属的CE路由器指VPN路由,这打通了两个网络(两台CE所属的网络)之间的路由。三、网络拓扑图四、P路由器配置p#SHOW RUNBuilding configuration.Current configuration : 1172 bytes!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname p!boot-start-markerboot-e
3、nd-marker!no aaa new-modelip subnet-zero!ip cefip audit po max-events 100!interface Loopback0 ip address 202.98.4.3 255.255.255.255!interface FastEthernet0/0 description to_r2 ip address 10.1.1.10 255.255.255.252 ip ospf cost 20 duplex full tag-switching mtu 1508 tag-switching ip!interface FastEther
4、net1/0 description to_r3 ip address 10.1.1.6 255.255.255.252 ip ospf cost 20 duplex full tag-switching mtu 1508 tag-switching ip!interface FastEthernet2/0 no ip address shutdown duplex half!interface FastEthernet3/0 no ip address shutdown duplex half!router ospf 100 log-adjacency-changes redistribut
5、e connected subnets redistribute static subnets network 10.1.1.6 0.0.0.0 area 0 network 10.1.1.10 0.0.0.0 area 0!ip classlessno ip http serverno ip http secure-server!gatekeeper shutdown!line con 0 exec-timeout 0 0 logging synchronous stopbits 1line aux 0 stopbits 1line vty 0 4 login!endp#五、PE1路由器配置
6、pe1#show runBuilding configuration.Current configuration : 1813 bytes!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname pe1!boot-start-markerboot-end-marker!no aaa new-modelip subnet-zero!ip vrf vpna rd 1:100 route-target ex
7、port 200:1 route-target import 200:1! ip cefip audit po max-events 100!interface Loopback0 ip address 202.98.4.1 255.255.255.255! interface FastEthernet0/0 description to_r5 ip vrf forwarding vpna ip address 172.16.1.1 255.255.255.252 duplex full tag-switching ip!interface FastEthernet1/0 descriptio
8、n to_r1 ip address 10.1.1.5 255.255.255.252 ip ospf cost 20 duplex full tag-switching mtu 1508 tag-switching ip!interface FastEthernet2/0 ip address 10.1.1.1 255.255.255.252 ip ospf cost 100 duplex full tag-switching mtu 1508 tag-switching ip!interface FastEthernet3/0 no ip address shutdown duplex h
9、alf!router ospf 100 log-adjacency-changes redistribute connected metric-type 1 subnets network 10.1.1.0 0.0.0.255 area 0 network 202.98.4.0 0.0.0.255 area 0!router bgp 100 no bgp default ipv4-unicast bgp log-neighbor-changes neighbor 202.98.4.2 remote-as 100 neighbor 202.98.4.2 update-source Loopbac
10、k0 neighbor 202.98.4.2 version 4 ! address-family vpnv4 neighbor 202.98.4.2 activate neighbor 202.98.4.2 send-community extended exit-address-family ! address-family ipv4 vrf vpna redistribute connected redistribute static no auto-summary no synchronization exit-address-family!ip classlessip route v
11、rf vpna 192.168.3.0 255.255.255.0 172.16.1.2no ip http serverno ip http secure-server!ip ospf name-lookup!gatekeeper shutdown! !line con 0 exec-timeout 0 0 logging synchronous stopbits 1line aux 0 stopbits 1line vty 0 4 login!endpe1# 六、PE2路由器配置pe2#show runBuilding configuration.Current configuration
12、 : 1725 bytes!version 12.3service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname pe2!boot-start-markerboot-end-marker!no aaa new-modelip subnet-zero!ip vrf vpna rd 1:100 route-target export 200:1 route-target import 200:1! ip cefip audit po
13、max-events 100!interface Loopback0 ip address 202.98.4.2 255.255.255.255! interface FastEthernet0/0 description to_r1 ip address 10.1.1.9 255.255.255.252 ip ospf cost 20 duplex full tag-switching ip!interface FastEthernet1/0 ip vrf forwarding vpna ip address 172.16.2.1 255.255.255.0 duplex full tag-
14、switching ip!interface FastEthernet2/0 ip address 10.1.1.2 255.255.255.252 ip ospf cost 100 duplex full tag-switching ip!interface FastEthernet3/0 no ip address shutdown duplex half!router ospf 100 log-adjacency-changes redistribute connected metric 1 subnets redistribute static metric-type 1 subnets network 10.1.1.0 0.0.0.255 area 0!router bgp 100 no bgp default ipv4-unicast bgp log-neighbor-changes neighbor 202.98.4.1 remote-as 100 neighbor 202.98.4.1 update-source Loopback0 neighbor 202.98.4.1 version 4 ! address-family vpnv4
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1