华为MPLS VPV配置_第1张图片

配置步骤

一、在PE路由器上配置VRF(虚拟路由转发),VRF将路由器的2个实例分割,实例之间不能直接通信。

二、在PE和P路由器上配置路由协议,互联网的内部路由器可以互通

三、在PE设备之间配置BGP协议,BGP协议支持标签转发

四、在PE和P路由器上配置MPLS协议,将端口设置允许MPLS协议

五、配置×××

六、配置VRF路由注入,让PE间设备能够学习到对方的路由协议

PE1配置

[PE1]displaycurrent-configuration
[V200R003C00]
#
sysnamePE1
#
snmp-agentlocal-engineid800007DB03000000000000
snmp-agent
#
clocktimezoneIndianStandardTimeminus05:13:20
clockdaylight-saving-timeDayLightSavingTimerepeating12:329-112:3211-2300:0020052005
#
dropillegal-macalarm
#
setcpu-usagethreshold80restore75
#
ip***-instance***a
ipv4-family
route-distinguisher100:1
***-target100:3export-extcommunity
***-target100:3import-extcommunity
#
ip***-instance***b
ipv4-family
route-distinguisher100:2
***-target100:4export-extcommunity
***-target100:4import-extcommunity
#
mplslsr-id3.3.3.3
mpls
lsp-triggerall
#
mplsldp
#
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-useradminservice-typehttp
#
firewallzoneLocal
priority15
#
interfaceGigabitEthernet0/0/0
ipaddress34.1.1.3255.255.255.0
mpls
mplsldp
#
interfaceGigabitEthernet0/0/1
ipbinding***-instance***b
ipaddress23.1.1.3255.255.255.0
#
interfaceGigabitEthernet0/0/2
ipbinding***-instance***a
ipaddress13.1.1.3255.255.255.0
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress3.3.3.3255.255.255.0
#
bgp100
peer5.5.5.5as-number100
peer5.5.5.5connect-interfaceLoopBack0
#
ipv4-familyunicast
undosynchronization
peer5.5.5.5enable
peer5.5.5.5next-hop-local
#
ipv4-family***v4
policy***-target
peer5.5.5.5enable
#
ipv4-family***-instance***a
import-routerip1
#
ipv4-family***-instance***b
import-routerip2
#
ospf1
area0.0.0.0
network3.3.3.00.0.0.255
network34.1.1.00.0.0.255
#
rip1***-instance***a
undosummary
version2
network13.0.0.0
import-routebgp
#
rip2***-instance***b
undosummary
version2
network23.0.0.0
network2.0.0.0
import-routebgp
#
user-interfacecon0
authentication-modepassword
user-interfacevty04
user-interfacevty1620
#
wlanac
#
return

PE2配置

[PE2]displaycurrent-configuration
[V200R003C00]
#
sysnamePE2
#
snmp-agentlocal-engineid800007DB03000000000000
snmp-agent
#
clocktimezoneIndianStandardTimeminus05:13:20
clockdaylight-saving-timeDayLightSavingTimerepeating12:329-112:3211-2300:0020052005
#
dropillegal-macalarm
#
setcpu-usagethreshold80restore75
#
ip***-instance***a
ipv4-family
route-distinguisher100:1
***-target100:3export-extcommunity
***-target100:3import-extcommunity
#
ip***-instance***b
ipv4-family
route-distinguisher100:2
***-target100:4export-extcommunity
***-target100:4import-extcommunity
#
mplslsr-id5.5.5.5
mpls
lsp-triggerall
#
mplsldp
#
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-useradminservice-typehttp
#
firewallzoneLocal
priority15
#
interfaceGigabitEthernet0/0/0
ipaddress45.1.1.5255.255.255.0
mpls
mplsldp
#
interfaceGigabitEthernet0/0/1
ipbinding***-instance***a
ipaddress76.1.1.6255.255.255.0
#
interfaceGigabitEthernet0/0/2
ipbinding***-instance***b
ipaddress86.1.1.6255.255.255.0
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress5.5.5.5255.255.255.0
#
bgp100
peer3.3.3.3as-number100
peer3.3.3.3connect-interfaceLoopBack0
#
ipv4-familyunicast
undosynchronization
peer3.3.3.3enable
peer3.3.3.3next-hop-local
#
ipv4-family***v4
policy***-target
peer3.3.3.3enable
#
ipv4-family***-instance***a
import-routerip1
#
ipv4-family***-instance***b
import-routerip2
#
ospf1
area0.0.0.0
network5.5.5.00.0.0.255
network45.1.1.00.0.0.255
#
rip1***-instance***a
undosummary
version2
network76.0.0.0
import-routebgp
#
rip2***-instance***b
undosummary
version2
network86.0.0.0
import-routebgp
#
user-interfacecon0
authentication-modepassword
user-interfacevty04
user-interfacevty1620
#
wlanac
#
return

P配置

[P]displaycurrent-configuration
[V200R003C00]
#
sysnameP
#
snmp-agentlocal-engineid800007DB03000000000000
snmp-agent
#
clocktimezoneIndianStandardTimeminus05:13:20
clockdaylight-saving-timeDayLightSavingTimerepeating12:329-112:3211-2300:0020052005
#
dropillegal-macalarm
#
setcpu-usagethreshold80restore75
#
mplslsr-id4.4.4.4
mpls
lsp-triggerall
#
mplsldp
#
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-useradminservice-typehttp
#
firewallzoneLocal
priority15
#
interfaceGigabitEthernet0/0/0
ipaddress34.1.1.4255.255.255.0
mpls
mplsldp
#
interfaceGigabitEthernet0/0/1
ipaddress45.1.1.4255.255.255.0
mpls
mplsldp
#
interfaceGigabitEthernet0/0/2
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress4.4.4.4255.255.255.0
#
ospf1
area0.0.0.0
network4.4.4.00.0.0.255
network34.1.1.00.0.0.255
network45.1.1.00.0.0.255
#
user-interfacecon0
authentication-modepassword
user-interfacevty04
user-interfacevty1620
#
wlanac
#
return

siteA1配置

[siteA-1]displaycurrent-configuration
[V200R003C00]
#
sysnamesiteA-1
#
snmp-agentlocal-engineid800007DB03000000000000
snmp-agent
#
clocktimezoneIndianStandardTimeminus05:13:20
clockdaylight-saving-timeDayLightSavingTimerepeating12:329-112:3211-2300:0020052005
#
dropillegal-macalarm
#
setcpu-usagethreshold80restore75
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-useradminservice-typehttp
#
firewallzoneLocal
priority15
#
interfaceGigabitEthernet0/0/0
ipaddress13.1.1.1255.255.255.0
#
interfaceGigabitEthernet0/0/1
#
interfaceGigabitEthernet0/0/2
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress1.1.1.1255.255.255.0
#
rip1
undosummary
version2
network1.0.0.0
network13.0.0.0
#
user-interfacecon0
authentication-modepassword
user-interfacevty04
user-interfacevty1620
#
wlanac
#
return

siteA2配置

[siteA-2]displaycurrent-configuration
[V200R003C00]
#
sysnamesiteA-2
#
snmp-agentlocal-engineid800007DB03000000000000
snmp-agent
#
clocktimezoneIndianStandardTimeminus05:13:20
clockdaylight-saving-timeDayLightSavingTimerepeating12:329-112:3211-2300:0020052005
#
dropillegal-macalarm
#
setcpu-usagethreshold80restore75
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-useradminservice-typehttp
#
firewallzoneLocal
priority15
#
interfaceGigabitEthernet0/0/0
ipaddress76.1.1.7255.255.255.0
#
interfaceGigabitEthernet0/0/1
#
interfaceGigabitEthernet0/0/2
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress6.6.6.6255.255.255.0
#
rip1
undosummary
version2
network6.0.0.0
network76.0.0.0
#
user-interfacecon0
authentication-modepassword
user-interfacevty04
user-interfacevty1620
#
wlanac
#
return

siteB1配置

[siteB-1]displaycurrent-configuration
[V200R003C00]
#
sysnamesiteB-1
#
snmp-agentlocal-engineid800007DB03000000000000
snmp-agent
#
clocktimezoneIndianStandardTimeminus05:13:20
clockdaylight-saving-timeDayLightSavingTimerepeating12:329-112:3211-2300:0020052005
#
dropillegal-macalarm
#
setcpu-usagethreshold80restore75
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-useradminservice-typehttp
#
firewallzoneLocal
priority15
#
interfaceGigabitEthernet0/0/0
ipaddress23.1.1.2255.255.255.0
#
interfaceGigabitEthernet0/0/1
#
interfaceGigabitEthernet0/0/2
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress2.2.2.2255.255.255.0
#
rip1
undosummary
version2
network2.0.0.0
network23.0.0.0
#
user-interfacecon0
authentication-modepassword
user-interfacevty04
user-interfacevty1620
#
wlanac
#
return

siteB2配置

[siteB-2]displaycurrent-configuration
[V200R003C00]
#
sysnamesiteB-2
#
snmp-agentlocal-engineid800007DB03000000000000
snmp-agent
#
clocktimezoneIndianStandardTimeminus05:13:20
clockdaylight-saving-timeDayLightSavingTimerepeating12:329-112:3211-2300:0020052005
#
dropillegal-macalarm
#
setcpu-usagethreshold80restore75
#
aaa
authentication-schemedefault
authorization-schemedefault
accounting-schemedefault
domaindefault
domaindefault_admin
local-useradminpasswordcipher%$%$K8m.Nt84DZ}e#<0`8bmE3Uw}%$%$
local-useradminservice-typehttp
#
firewallzoneLocal
priority15
#
interfaceGigabitEthernet0/0/0
ipaddress86.1.1.8255.255.255.0
#
interfaceGigabitEthernet0/0/1
#
interfaceGigabitEthernet0/0/2
#
interfaceNULL0
#
interfaceLoopBack0
ipaddress7.7.7.7255.255.255.0
#
rip1
undosummary
version2
network86.0.0.0
network7.0.0.0
#
user-interfacecon0
authentication-modepassword
user-interfacevty04
user-interfacevty1620
#
wlanac
#
return