
Operation Manual – MPLS L3VPN
H3C S9500 Series Routing Switches
Chapter 1 MPLS L3VPN Configuration
1-7
4)
PE 2 searches VPN instance entries according to the inner label and destination
address of the packet to determine the outbound interface and then forwards the
packet out the interface to CE 2.
5)
CE 2 transmits the packet to the destination by IP forwarding.
1.1.4 MPLS L3VPN Networking Schemes
In MPLS L3VPNs, VPN target attributes are used to control the advertisement and
reception of VPN routes between sites. They work independently and can be
configured with multiple values to support flexible VPN access control and implement
multiple types of VPN networking schemes.
I. Basic VPN networking scheme
In the simplest case, all users in a VPN form a closed user group. They can forward
traffic to each other but cannot communicate with any user outside the VPN.
For this networking scheme, the basic VPN networking scheme, you need to assign a
VPN target to each VPN for identifying the export target attribute and import target
attribute of the VPN. Moreover, this VPN target cannot be used by any other VPNs.
Figure 1-4
Network diagram for basic VPN networking scheme
In
Figure 1-4
, for example, the VPN target for VPN 1 is 100:1 on the PEs, while that for
VPN 2 is 200:1. The two VPN 1 sites can communicate with each other, and the two
VPN 2 sites can communicate with each other. However, the VPN 1 sites cannot
communicate with the VPN 2 sites.
II. Hub and spoke networking scheme
For a VPN where a central access control device is required and all users must
communicate with each other through the access control device, the hub and spoke