MPLS VPN 的基本配置,vpn,Cisco

时间:2013-08-09 00:00来源:网络整理 作者:采集侠 点击:


  Pomerol


  Current configuration:
  !
  version 12.0
  !
  hostname Pomerol
  !
  ip cef
  !
  interface Loopback0
  ip address 10.10.10.3 255.255.255.255
  ip router isis
  !
  interface Serial0/1
  no ip address
  no ip directed-broadcast
  encapsulation frame-relay
  random-detect
  !
  interface Serial0/1.1 point-to-point
  description link to Pauillac
  ip address 10.1.1.6 255.255.255.252
  no ip directed-broadcast
  ip router isis
  tag-switching mtu 1520

  tag-switching ip
  frame-relay interface-dlci 301
  !
  interface Serial0/1.2 point-to-point
  description link to Pulligny
  ip address 10.1.1.9 255.255.255.252
  no ip directed-broadcast
  ip router isis
  tag-switching ip
  frame-relay interface-dlci 303
  !
  interface Serial0/1.3 point-to-point
  description link to Pesaro
  ip address 10.1.1.21 255.255.255.252
  no ip directed-broadcast
  ip router isis
  tag-switching ip
  frame-relay interface-dlci 306
  !
  router isis
  net 49.0001.0000.0000.0003.00
  is-type level-1
  !
  ip classless
  !
  end

  Pulligny


  Current configuration:
  !
  version 12.1
  !
  hostname Pulligny
  !
  !
  ip cef
  !
  !
  interface Loopback0
  ip address 10.10.10.2 255.255.255.255
  !
  interface Serial0/1

  no ip address
  encapsulation frame-relay
  random-detect
  !
  interface Serial0/1.1 point-to-point
  description link to Pauillac
  ip address 10.1.1.2 255.255.255.252
  ip router isis
  tag-switching ip
  frame-relay interface-dlci 201
  !
  interface Serial0/1.2 point-to-point
  description link to Pomerol
  ip address 10.1.1.10 255.255.255.252
  ip router isis
  tag-switching ip
  frame-relay interface-dlci 203
  !
  router isis
  passive-interface Loopback0
  net 49.0001.0000.0000.0002.00
  is-type level-1
  !
  ip classless
  !
  end


  Pauillac


  version 12.1
  !
  hostname pauillac
  !
  ip cef
  !
  interface Loopback0
  ip address 10.10.10.1 255.255.255.255
  ip router isis
  !
  interface Serial0/0
  no ip address
  encapsulation frame-relay
  no ip mroute-cache

  tag-switching ip
  no fair-queue
  !
  interface Serial0/0.1 point-to-point
  description link to Pomerol
  bandwith 512
  ip address 10.1.1.1 255.255.255.252
  ip router isis
  tag-switching ip
  frame-relay interface-dlci 102
  !
  interface Serial0/0.2 point-to-point
  description link to Pulligny ip address 10.1.1.5 255.255.255.252
  ip router isis
  tag-switching ip
  frame-relay interface-dlci 103
  !
  interface Serial0/0.3 point-to-point
  description link to Pescara
  bandwidth 512
  ip address 10.1.1.13 255.255.255.252
  ip router isis
  tag-switching ip
  frame-relay interface-dlci 104
  !
  router isis
  net 49.0001.0000.0000.0001.00
  is-type level-1
  !
  ip classless
  !
  end

  检验
  本节讲述了如何检查你的配置是否工作正常.
  · show ip vrf - Verifies that the correct VRF exists.
  · show ip vrf interfaces - Verifies the activated interfaces.
  · show ip route vrf Customer_A - Verifies the routing information on the PE routers.
  · traceroute vrf Customer_A 200.0.6.1 - Verifies the routing information on the PE routers.
  · show ip bgp vpnv4 tag - Verifies the BGP.
  · show ip cef vrf Customer_A 200.0.6.1 detail - Verifies the routing information on the PE routers.

  更多的排错命令详见: MPLS VPN Solution Troubleshooting Guide.
  下面的输出是命令 show ip vrf 的结果 
     Pescara#show ip vrf 
     Name                         Default RD                             Interfaces 
     Customer_A                100:110                              Loopback101 
     Customer_B                100:120                              Loopback102

  下面的输出是命令show ip vrf interfaces 的结果.
  Pesaro#show ip vrf interfaces 
   Interface                  IP-Address              VRF               Protocol
  Loopback101             200.0.6.1         Customer_A            up
  Loopback111             200.1.6.1         Customer_A            up
   Loopback102            200.0.6.1         Customer_B            up


  下面的 show ip route vrf 命令的结果显示在2 个VPNl 里面都有相同的网段 200.0.6.0/24. 这是因为两个VPN客户 Customer_A 和Customer_B 使用了重叠的IP 地址.

  Pescara#show ip route vrf Customer_A
  Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
  D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
  N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
  E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
  i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
  * - candidate default, U - per-user static route, o - ODR

  Gateway of last resort is not set
  C 200.0.4.0/24 is directly connected, Loopback101
  B 200.0.6.0/24 [200/0] via 10.10.10.6, 05:10:11
  B 200.1.6.0/24 [200/0] via 10.10.10.6, 04:48:11

  Pescara#show ip route vrf Customer_B
  Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
  D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
  N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2

  E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
  i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
  * - candidate default, U - per-user static route, o - ODR
  P - periodic downloaded static route

  Gateway of last resort is not set
  C 200.0.4.0/24 is directly connected, Loopback102
  B 200.0.6.0/24 [200/0] via 10.10.10.6, 00:03:24

  在Customer_A 的2 个站点间使用Traceroute,可能可以看到MPLS 网络使用的label stack。
  (如果配置mpls ip ttl .)
  Pescara#traceroute vrf Customer_A 200.0.6.1
  Type escape sequence to abort. Tracing the route to 200.0.6.1
  1 10.1.1.13 [MPLS: Labels 20/26 Exp 0] 400 msec 276 msec 264 msec
  2 10.1.1.6 [MPLS: Labels 18/26 Exp 0] 224 msec 460 msec 344 msec
  3 200.0.6.1 108 msec * 100 msec
  Note: Exp 0 是QoS 使用的一个字段。

        

分享到: