MPLS-MCE

配置MCE示例
組網需求:
某公司需要通過MPLS ×××實現總部和分支間的互通,同時需要隔離兩種不同的業務。爲節省開支,希望分支通過一臺CE設備接入PE。
如圖1所示,按如下組網:
CE1、CE2連接企業總部,CE1屬於***a,CE2屬於***b
MCE連接企業分支,通過CE3和CE4分別連接***a和***b
要求屬於相同×××的用戶之間能互相訪問,但不同×××的用戶之間不能互相訪問,從而實現不同業務間隔離。
圖1 配置Muti-×××-Instance CE組網圖

配置思路
本例配置主要思路是:
1.PE與PE間配置OSPF協議,實現PE之間的互通;配置MP-IBGP交換×××路由信息。
2.PE上配置MPLS基本能力和MPLS LDP,建立LDP LSP。
3.PE和MCE上創建不同的×××實例(***a和***b),實現不同×××間的業務隔離。
4.PE1與相連的CE之間建立EBGP對等體,引入×××路由表中。
5.MCE與Site、MCE與PE2之間配置路由,引入×××路由信息。
操作步驟:
1.在骨幹網的PE上配置OSPF協議,實現PE之間的互通

配置PE1。

<Huawei> system-view
[Huawei] sysname PE1
[PE1] interface loopback 1
[PE1-LoopBack1] ip address 1.1.1.9 32
[PE1-LoopBack1] quit
[PE1] interface gigabitethernet 3/0/0
[PE1-GigabitEthernet3/0/0] ip address 172.1.1.1 24
[PE1-GigabitEthernet3/0/0] quit
[PE1] ospf
[PE1-ospf-1] area 0
[PE1-ospf-1-area-0.0.0.0] network 1.1.1.9 0.0.0.0
[PE1-ospf-1-area-0.0.0.0] network 172.1.1.0 0.0.0.255
[PE1-ospf-1-area-0.0.0.0] quit
[PE1-ospf-1] quit
PE2的配置過程與PE1類似,不再贅述(略)。
完成此步配置後,PE之間應能互相學習到對方的Loopback1的地址。
以PE2爲例:
[PE2] display ip routing-table
Route Flags: R - relay, D - download to fib

Routing Tables: Public
Destinations : 9 Routes : 9
Destination/Mask Proto Pre Cost Flags NextHop Interface
1.1.1.9/32 OSPF 10 1 D 172.1.1.1 GigabitEthernet1/0/0
2.2.2.9/32 Direct 0 0 D 127.0.0.1 LoopBack1
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
172.1.1.0/24 Direct 0 0 D 172.1.1.2 GigabitEthernet1/0/0
172.1.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet1/0/0
172.1.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet1/0/0
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
2.在骨幹網的PE上配置MPLS基本能力和MPLS LDP,PE之間建立LDP LSP

配置PE1。

[PE1] mpls lsr-id 1.1.1.9
[PE1] mpls
[PE1-mpls] quit
[PE1] mpls ldp
[PE1-mpls-ldp] quit
[PE1] interface gigabitethernet 3/0/0
[PE1-GigabitEthernet3/0/0] mpls
[PE1-GigabitEthernet3/0/0] mpls ldp
[PE1-GigabitEthernet3/0/0] quit
PE2的配置過程與PE1類似,不再贅述(略)。
完成此步配置後,在PE上執行命令display mpls ldp session,應能看見PE之間的MPLS LDP會話狀態爲“Operational”。
以PE2爲例:
[PE2] display mpls ldp session
LDP Session(s) in Public Network
Codes: LAM(Label Advertisement Mode), SsnAge Unit(DDDD:HH:MM)
A '*' before a session means the session is being deleted.

PeerID Status LAM SsnRole SsnAge KASent/Rcv


1.1.1.9:0 Operational DU Active 0000:00:04 17/17

TOTAL: 1 session(s) Found.
3.在PE設備上配置×××實例,將CE1、CE2接入PE1,將MCE接入PE2

配置PE1。

[PE1] ip ***-instance ***a
[PE1-***-instance-***a] ipv4-family
[PE1-***-instance-***a-af-ipv4] route-distinguisher 100:1
[PE1-***-instance-***a-af-ipv4] ***-target 111:1 both
[PE1-***-instance-***a-af-ipv4] quit
[PE1-***-instance-***a] quit
[PE1] ip ***-instance ***b
[PE1-***-instance-***b] ipv4-family
[PE1-***-instance-***b-af-ipv4] route-distinguisher 100:2
[PE1-***-instance-***b-af-ipv4] ***-target 222:2 both
[PE1-***-instance-***b-af-ipv4] quit
[PE1-***-instance-***b] quit
[PE1] interface gigabitethernet 1/0/0
[PE1-GigabitEthernet1/0/0] ip binding ***-instance ***a
[PE1-GigabitEthernet1/0/0] ip address 10.1.1.2 24
[PE1-GigabitEthernet1/0/0] quit
[PE1] interface gigabitethernet 2/0/0
[PE1-GigabitEthernet2/0/0] ip binding ***-instance ***b
[PE1-GigabitEthernet2/0/0] ip address 10.2.1.2 24
[PE1-GigabitEthernet2/0/0] quit

配置PE2。

[PE2] ip ***-instance ***a
[PE2-***-instance-***a] ipv4-family
[PE2-***-instance-***a-af-ipv4] route-distinguisher 200:1
[PE2-***-instance-***a-af-ipv4] ***-target 111:1 both
[PE2-***-instance-***a-af-ipv4] quit
[PE2-***-instance-***a] quit
[PE2] ip ***-instance ***b
[PE2-***-instance-***b] ipv4-family
[PE2-***-instance-***b-af-ipv4] route-distinguisher 200:2
[PE2-***-instance-***b-af-ipv4] ***-target 222:2 both
[PE2-***-instance-***b-af-ipv4] quit
[PE2-***-instance-***b] quit
[PE2] interface gigabitethernet 2/0/0.1
[PE2-GigabitEthernet2/0/0.1] dot1q termination vid 10
[PE2-GigabitEthernet2/0/0.1] ip binding ***-instance ***a
[PE2-GigabitEthernet2/0/0.1] ip address 192.1.1.1 24
[PE2-GigabitEthernet2/0/0.1] quit
[PE2] interface gigabitethernet 2/0/0.2
[PE2-GigabitEthernet2/0/0.2] dot1q termination vid 20
[PE2-GigabitEthernet2/0/0.2] ip binding ***-instance ***b
[PE2-GigabitEthernet2/0/0.2] ip address 192.2.1.1 24
[PE2-GigabitEthernet2/0/0.2] quit

4.在MCE設備上配置×××實例,將CE3、CE4及PE2接入MCE
<Huawei> system-view
[Huawei] sysname MCE
[MCE] ip ***-instance ***a
[MCE-***-instance-***a] ipv4-family
[MCE-***-instance-***a-af-ipv4] route-distinguisher 300:1
[MCE-***-instance-***a-af-ipv4] ***-target 111:1 both
[MCE-***-instance-***a-af-ipv4] quit
[MCE-***-instance-***a] quit
[MCE] ip ***-instance ***b
[MCE-***-instance-***b] ipv4-family
[MCE-***-instance-***b-af-ipv4] route-distinguisher 300:2
[MCE-***-instance-***b-af-ipv4] ***-target 222:2 both
[MCE-***-instance-***b-af-ipv4] quit
[MCE-***-instance-***b] quit
[MCE] interface gigabitethernet 3/0/0
[MCE-GigabitEthernet3/0/0] ip binding ***-instance ***a
[MCE-GigabitEthernet3/0/0] ip address 10.3.1.2 24
[MCE-GigabitEthernet3/0/0] quit
[MCE] interface gigabitethernet 4/0/0
[MCE-GigabitEthernet4/0/0] ip binding ***-instance ***b
[MCE-GigabitEthernet4/0/0] ip address 10.4.1.2 24
[MCE-GigabitEthernet4/0/0] quit
[MCE] interface gigabitethernet 1/0/0.1
[MCE-GigabitEthernet1/0/0.1] dot1q termination vid 10
[MCE-GigabitEthernet1/0/0.1] ip binding ***-instance ***a
[MCE-GigabitEthernet1/0/0.1] ip address 192.1.1.2 24
[MCE-GigabitEthernet1/0/0.1] quit
[MCE] interface gigabitethernet 1/0/0.2
[MCE-GigabitEthernet1/0/0.2] dot1q termination vid 20
[MCE-GigabitEthernet1/0/0.2] ip binding ***-instance ***b
[MCE-GigabitEthernet1/0/0.2] ip address 192.2.1.2 24
[MCE-GigabitEthernet1/0/0.2] quit
5.在PE之間建立MP-IBGP對等體,在PE1與CE1、CE2之間建立EBGP對等體

配置CE1。

<Huawei> system-view
[Huawei] sysname CE1
[CE1] bgp 65410
[CE1-bgp] peer 10.1.1.2 as-number 100
[CE1-bgp] ipv4-family unicast
[CE1-bgp-af-ipv4] import-route direct
[CE1-bgp-af-ipv4] quit
[CE1-bgp] quit
PE1和CE2的配置與CE1類似,不再贅述(略)。
完成此步配置後,在PE1上執行命令display bgp ***v4 all peer可以看見PE1與PE2的IBGP對等體關係及PE1與CE1、CE2之間建立EBGP對等體關係均爲“Established”。

[PE1] display bgp ***v4 all peer
BGP local router ID : 1.1.1.9
Local AS number : 100
Total number of peers : 3 Peers in established state : 3
Peer V AS MsgRcvd MsgSent OutQ Up/Down State PrefRcv
2.2.2.9 4 100 288 287 0 01:19:16 Established 4
Peer of IPv4-family for *** instance :
×××-Instance ***a, router ID 1.1.1.9:
10.1.1.1 4 65410 9 11 0 00:04:14 Established 4
×××-Instance ***b, router ID 1.1.1.9:
10.2.1.1 4 65420 9 12 0 00:04:09 Established 3

  1. 在PE2和MCE之間配置OSPF多實例

    配置PE2。

    [PE2] ospf 100 ***-instance ***a
    [PE2-ospf-100] area 0
    [PE2-ospf-100-area-0.0.0.0] network 192.1.1.0 0.0.0.255
    [PE2-ospf-100-area-0.0.0.0] quit
    [PE2-ospf-100] import-route bgp
    [PE2-ospf-100] quit
    [PE2] ospf 200 ***-instance ***b
    [PE2-ospf-200] area 0
    [PE2-ospf-200-area-0.0.0.0] network 192.2.1.0 0.0.0.255
    [PE2-ospf-200-area-0.0.0.0] quit
    [PE2-ospf-200] import-route bgp
    [PE2-ospf-200] quit
    [PE2] bgp 100
    [PE2-bgp] ipv4-family ***-instance ***a
    [PE2-bgp-***a] import-route ospf 100
    [PE2-bgp-***a] quit
    [PE2-bgp] ipv4-family ***-instance ***b
    [PE2-bgp-***b] import-route ospf 200
    [PE2-bgp-***b] quit
    [PE2-bgp] quit

    配置MCE。

    [MCE] ospf 100 ***-instance ***a
    [MCE-ospf-100] area 0
    [MCE-ospf-100-area-0.0.0.0] network 192.1.1.0 0.0.0.255
    [MCE-ospf-100-area-0.0.0.0] quit
    [MCE-ospf-100] quit
    [MCE] ospf 200 ***-instance ***b
    [MCE-ospf-200] area 0
    [MCE-ospf-200-area-0.0.0.0] network 192.2.1.0 0.0.0.255
    [MCE-ospf-200-area-0.0.0.0] quit
    [MCE-ospf-200] quit
    7.在MCE和CE3、CE4之間配置RIP-2

    配置MCE。

    [MCE] rip 100 ***-instance ***a
    [MCE-rip-100] version 2
    [MCE-rip-100] network 10.0.0.0
    [MCE-rip-100] import-route ospf 100
    [MCE-rip-100] quit
    [MCE] rip 200 ***-instance ***b
    [MCE-rip-200] version 2
    [MCE-rip-200] network 10.0.0.0
    [MCE-rip-200] import-route ospf 200
    [MCE-rip-200] quit

配置CE3。

<Huawei> system-view
[Huawei] sysname CE3
[CE3] rip 100
[CE3-rip-100] version 2
[CE3-rip-100] network 10.0.0.0
[CE3-rip-100] import-route direct

配置CE4。

<Huawei> system-view
[Huawei] sysname CE4
[CE4] rip 200
[CE4-rip-200] version 2
[CE4-rip-200] network 10.0.0.0
[CE4-rip-200] import-route direct

8.在MCE上配置不進行環路檢查,並引入RIP路由
[MCE] ospf 100 ***-instance ***a
[MCE-ospf-100] ***-instance-capability simple
[MCE-ospf-100] import-route rip 100
[MCE-ospf-100] quit
[MCE] ospf 200 ***-instance ***b
[MCE-ospf-200] ***-instance-capability simple
[MCE-ospf-200] import-route rip 200
[MCE-ospf-200] quit

9.檢查配置結果
完成上述配置後,在MCE設備上執行命令display ip routing-table ***-instance命令,可以看到去往對端CE的路由。
以***a爲例:
[MCE] display ip routing-table ***-instance ***a
Route Flags: R - relay, D - download to fib

Routing Tables: ***a
Destinations : 8 Routes : 8
Destination/Mask Proto Pre Cost Flags NextHop Interface
10.1.1.0/24 O_ASE 150 1 D 192.1.1.1 GigabitEthernet1/0/0.1
10.3.1.0/24 Direct 0 0 D 10.3.1.2 GigabitEthernet3/0/0
10.3.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet3/0/0
10.3.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet3/0/0
192.1.1.0/24 Direct 0 0 D 192.1.1.2 GigabitEthernet1/0/0.1
192.1.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet1/0/0.1
192.1.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet1/0/0.1
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
在PE上執行display ip routing-table ***-instance命令,可以看到去往對端CE的路由。
以PE1上的***a爲例:
[PE1] display ip routing-table ***-instance ***a
Route Flags: R - relay, D - download to fib

Routing Tables: ***a
Destinations : 6 Routes : 6
Destination/Mask Proto Pre Cost Flags NextHop Interface
10.1.1.0/24 Direct 0 0 D 10.1.1.2 GigabitEthernet1/0/0
10.1.1.2/32 Direct 0 0 D 127.0.0.1 GigabitEthernet1/0/0
10.1.1.255/32 Direct 0 0 D 127.0.0.1 GigabitEthernet1/0/0
10.3.1.0/24 IBGP 255 2 RD 2.2.2.9 GigabitEthernet3/0/0
192.1.1.0/24 IBGP 255 0 RD 2.2.2.9 GigabitEthernet3/0/0
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
CE1、CE3之間可以互通,CE2、CE4之間可以互通。
以CE1爲例:
[CE1] ping 10.3.1.1
PING 10.3.1.1: 56 data bytes, press CTRL_C to break
Reply from 10.3.1.1: bytes=56 Sequence=1 ttl=252 time=125 ms
Reply from 10.3.1.1: bytes=56 Sequence=2 ttl=252 time=125 ms
Reply from 10.3.1.1: bytes=56 Sequence=3 ttl=252 time=125 ms
Reply from 10.3.1.1: bytes=56 Sequence=4 ttl=252 time=125 ms
Reply from 10.3.1.1: bytes=56 Sequence=5 ttl=252 time=125 ms
--- 10.3.1.1 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 125/125/125 ms
CE1不能與CE2和CE4互通,CE3也不能與CE2和CE4互通。
以CE1上ping CE4的顯示爲例。
[CE1] ping 10.4.1.1
PING 10.4.1.1: 56 data bytes, press CTRL_C to break
Request time out
Request time out
Request time out
Request time out
Request time out

--- 10.4.1.1 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss

發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章