1-5
An import routing policy can further filter the routes that can be advertised to a VPN instance by using
the VPN target attribute of import target attribute. It can reject the routes selected by the communities in
the import target attribute. An export routing policy can reject the routes selected by the communities in
the export target attribute.
After a VPN instance is created, you can configure import and/or export routing policies as needed.
Tunneling policy
A tunneling policy is used to select the tunnel for the packets of a specific VPN instance to use.
After a VPN instance is created, you can optionally configure a tunneling policy. By default, LSPs are
used as tunnels and no load balancing occurs (in other words, the number of tunnels for load balancing
is 1). In addition, a tunneling policy takes effect only within the local AS.
MPLS L3VPN Packet Forwarding
For basic MPLS L3VPN applications in a single AS, VPN packets are forwarded with two layers of
labels:
z
Layer 1 labels: Outer labels, used for label switching inside the backbone. They indicate LSPs from
the local PEs to the remote PEs. Based on layer 1 labels, VPN packets can be label switched along
the LSPs to the remote PEs.
z
Layer 2 labels: Inner labels, used for forwarding packets from the remote PEs to the CEs. An inner
label indicates to which site, or more precisely, to which CE the packet should be sent. A PE finds
the interface for forwarding a packet according to the inner label.
If two sites (CEs) belong to the same VPN and are connected to the same PE, each of them only needs
to know how to reach the remote CE.
The following takes
Figure 1-3
as an example to illustrate the VPN packet forwarding procedure.
Figure 1-3
VPN packet forwarding
1) Site 1 sends an IP packet with the destination address of 1.1.1.2. CE 1 transmits the packet to PE
1.
2) PE 1 searches VPN instance entries based on the inbound interface and destination address of the
packet. Once finding a matching entry, PE 1 labels the packet with both inner and outer labels and
forwards the packet out.
3) The MPLS backbone transmits the packet to PE 2 by outer label. Note that the outer label is
removed from the packet at the penultimate hop.
4) PE 2 searches VPN instance entries according to the inner label and destination address of the
packet to determine the outbound interface and then forwards the packet out the interface to CE 2.
Содержание S7902E
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45 ...
Страница 598: ...ii ...
Страница 1757: ...4 9 ...
Страница 1770: ...6 4 ...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface ...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20 ...