拓扑图
一、实验目的
1.总部和分部之间使用MPLS/BGP 虚拟专用网络和OSPF通信
二、注意事项
1.PE-1上去往CE-5的NAT地址的静态路由的目的地址掩码可以不做限制
有去往CE-5的路由就可以了
2.配置DHCP时DHCP-relay的路由要通
三、简单的查询命令
1.display ip vpn-instance verbose 查看VPN实例是否正确
2.display current-configuration configuration bgp命令查看
BGP配置
3.display bgp vpnv4 all routing-table ipv4-address[
mask| mask-length] 命令查看目标路由确认VPNv4路由是否
可以迭代到隧道 显示信息中 Relay Tunnel Out-Interface
和Relay token字段不为空表示该路由可以迭代到隧道
4.display bgp vpnv4 all routing-table ipv4-address[
mask| mask-length]查看目标路由,确定该目标路由是否分到私网标签
5.dis bgp vpnv4 all routing-table label 查看BGP为私网分配的标签
6.dis mpls lsp verbose [ip addrss mask ] verbose详情
信息 下一跳标签转发表项(LFIB)
7.display current-configuration configuration [特定的协
议] 查看一些特定的协议的配置
8.display firewall session table 检查会话
四、简单配置
AR3
sysname AR3
#
interface Ethernet0/0/0
ip address 10.0.134.3 255.255.255.0
#
interface GigabitEthernet0/0/0
ip address 10.0.13.3 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 10.0.34.3 255.255.255.0
#
interface GigabitEthernet0/0/2
ip address 10.0.35.3 255.255.255.0
#
ospf 1
area 0.0.0.0
network 10.0.35.0 0.0.0.255
network 10.0.134.0 0.0.0.255
network 10.0.13.0 0.0.0.255
network 10.0.34.0 0.0.0.255
#
return
AR4
sysname AR4
#
interface Ethernet0/0/0
ip address 10.0.134.4 255.255.255.0
#
interface GigabitEthernet0/0/0
ip address 10.0.24.4 255.255.255.0
#
interface GigabitEthernet0/0/1
ip address 10.0.34.4 255.255.255.0
#
interface GigabitEthernet0/0/2
ip address 10.0.45.4 255.255.255.0
#
ospf 1
area 0.0.0.0
network 10.0.45.0 0.0.0.255
network 10.0.134.0 0.0.0.255
network 10.0.24.0 0.0.0.255
network 10.0.34.0 0.0.0.255
#
return
CE-5
sysname CE-5
interface GigabitEthernet1/0/0
ip address 10.0.45.5 255.255.255.0
interface GigabitEthernet1/0/1
ip address 10.0.35.5 255.255.255.0
interface GigabitEthernet1/0/2
ip address 10.0.15.5 255.255.255.0
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
add interface GigabitEthernet1/0/0
add interface GigabitEthernet1<