background image

VPN-IPv4 address 

Each VPN independently manages its address space. The address spaces of VPNs might overlap. 
For example, if both VPN 1 and VPN 2 use the addresses on subnet 10.110.10.0/24, address space 
overlapping occurs. 

Multiprotocol BGP (MP-BGP) can  solve this problem by advertising VPN-IPv4  addresses (also 
called VPNv4 addresses). 

As shown i

Figure 2

a VPN-IPv4 address consists of 12 bytes. The first eight bytes represent the 

RD, followed by a four-byte IPv4 prefix. The RD and the IPv4 prefix form a unique VPN-IPv4 prefix. 

Figure 2 VPN-IPv4 address structure 

 

 

An RD can be in one of the following formats: 

 

When the Type field is 0, the Administrator subfield occupies two bytes, the Assigned number 
subfield occupies four bytes, and the RD format is 

16-bit AS number

:

32-bit user-defined 

number

. For example, 100:1. 

 

When the Type field is 1, the Administrator subfield occupies four bytes, the Assigned number 
subfield occupies two bytes, and the RD format is 

32-bit IPv4 address

:

16-bit user-defined 

number

. For example, 172.1.1.1:1. 

 

When the Type field is 2, the Administrator subfield occupies four bytes, the Assigned number 
subfield occupies two bytes, and the RD format is 

32-bit AS number

:

16-bit user-defined number

where the minimum value of the AS number is 65536. For example, 65536:1. 

To guarantee global uniqueness for a VPN-IPv4 address, do not set the Administrator subfield to any 
private AS number or private IP address. 

Route target attribute 

MPLS L3VPN uses route target community attributes to control the advertisement of VPN routing 
information. A VPN instance on a PE supports the following types of route target attributes: 

 

Export target attribute

—A PE sets the export target attribute for VPN-IPv4 routes learned 

from directly connected sites before advertising them to other PEs. 

 

Import target attribute

—A PE checks the export target attribute of VPN-IPv4 routes received 

from other PEs. If the export target attribute matches the import target attribute of a VPN 
instance, the PE adds the routes to the routing table of the VPN instance. 

Route target attributes define which sites can receive VPN-IPv4 routes, and from which sites a PE 
can receive routes.  

Like RDs, route target attributes can be one of the following formats: 

 

16-bit AS number

:

32-bit user-defined number

. For example, 100:1. 

 

32-bit IPv4 address:16-bit user-defined number

. For example, 172.1.1.1:1. 

 

32-bit AS number

:

16-bit user-defined number

, where the minimum value of the AS number is 

65536. For example, 65536:1. 

MCE working mechanism 

As shown in

 Figure 3

, the MCE exchanges private routes with VPN sites and PE 1, and adds the 

private routes to the routing tables of corresponding VPN instances. 

    

Type

2 bytes

4 bytes

IPv4 address prefix

6 bytes

Route Distinguisher (8 bytes)

Assigned number subfield

Administrator subfield 

Содержание S5130S-HI Series

Страница 1: ... H3C S5130S SI switch series Release 6310 and later H3C S5120V2 SI switch series Release 6310 and later H3C S3100V3 EI switch series Release 6309P01 and later H3C E500C switch series Release 6309P01 and later H3C E500D switch series Release 6309P01 and later H3C E128C E152C switches Release 6310 and later New H3C Technologies Co Ltd http www h3c com Software version Release 63xx Document version 6...

Страница 2: ...w H3C Technologies Co Ltd any trademarks that may be mentioned in this document are the property of their respective owners Notice The information in this document is subject to change without notice All contents in this document including statements information and recommendations are believed to be accurate but they are presented without warranty of any kind express or implied H3C shall not be l...

Страница 3: ...s keywords or arguments that are optional x y Braces enclose a set of required syntax choices separated by vertical bars from which you select one x y Square brackets enclose a set of optional syntax choices separated by vertical bars from which you select one or none x y Asterisk marked braces enclose a set of required syntax choices separated by vertical bars from which you select a minimum of o...

Страница 4: ...a generic network device such as a router switch or firewall Represents a routing capable device such as a router or Layer 3 switch Represents a generic switch such as a Layer 2 or Layer 3 switch or a router that supports Layer 2 forwarding and other Layer 2 features Represents an access controller a unified wired WLAN module or the access controller engine on a unified wired WLAN switch Represent...

Страница 5: ...ocumentation To access the most up to date H3C product documentation go to the H3C website at http www h3c com hk To obtain information about installation configuration and maintenance click http www h3c com hk Technical_Documents To obtain software version information such as release notes click http www h3c com hk Software_Download Technical support service h3c com http www h3c com hk Documentat...

Страница 6: ... a PE 9 Display and maintenance commands for MCE 9 MCE configuration examples 10 Example Configuring the MCE that uses OSPF to advertise VPN routes to the PE 10 Configuring IPv6 MCE 15 About IPv6 MCE 15 Restrictions and guidelines IPv6 MCE configuration 15 IPv6 MCE tasks at a glance 15 Configuring VPN instances 15 Creating a VPN instance 15 Associating a VPN instance with a Layer 3 interface 16 Co...

Страница 7: ...devices Using a common CE for multiple VPNs cannot ensure data security because the VPNs use the same routing table The MCE feature offers balance between cost and security It creates multiple VPN instances on a CE to provide logically separated routing tables and address spaces for the VPNs so the VPNs can share the CE This CE is called the MCE device Basic MPLS L3VPN architecture A basic MPLS L3...

Страница 8: ...be classified into different sets by policies Only the sites in the same set can access each other through the provider network Such a set is called a VPN VPN instance VPN instances implement route isolation data independence and data security for VPNs A VPN instance has the following components A separate Label Forwarding Information Base LFIB An IP routing table Interfaces bound to the VPN insta...

Страница 9: ...ee global uniqueness for a VPN IPv4 address do not set the Administrator subfield to any private AS number or private IP address Route target attribute MPLS L3VPN uses route target community attributes to control the advertisement of VPN routing information A VPN instance on a PE supports the following types of route target attributes Export target attribute A PE sets the export target attribute f...

Страница 10: ...namic IP assignment for DHCP clients in private networks you can configure DHCP server or DHCP relay agent on the MCE When the MCE functions as the DHCP server the IP addresses assigned to different private networks cannot overlap Restrictions and guidelines MCE configuration On the PE disable routing loop detection to avoid route loss during route calculation and disable route redistribution betw...

Страница 11: ...instance 5 Optional Configure a VPN ID for the VPN instance vpn id vpn id By default no VPN ID is configured for a VPN instance Associating a VPN instance with a Layer 3 interface 1 Enter system view system view 2 Enter interface view interface interface type interface number This interface connects the device to the CE 3 Associate a VPN instance with the interface ip binding vpn instance vpn inst...

Страница 12: ...unity By default no route targets are configured 4 Set the maximum number of active routes routing table limit number warn threshold simply alert By default the number of active routes in a VPN instance is not limited Setting the maximum number of active routes for a VPN instance can prevent the device from learning too many routes 5 Apply an import routing policy import route policy route policy ...

Страница 13: ...ommon RIP process Procedure 1 Enter system view system view 2 Create a RIP process for a VPN instance and enter RIP view rip process id vpn instance vpn instance name A RIP process can belong to only one VPN instance 3 Enable RIP on the interface attached to the specified network network network address wildcard mask By default RIP is disabled on an interface 4 Redistribute remote site routes adve...

Страница 14: ...Enable OSPF on the interface attached to the specified network in the area network ip address wildcard mask By default an interface neither belongs to any area nor runs OSPF Configuring routing between an MCE and a PE About routing between an MCE and a PE MCE PE routing configuration includes these tasks Binding the MCE PE interfaces to VPN instances Performing route configurations Redistributing ...

Страница 15: ...ospf process id router id router id vpn instance vpn instance name 3 Disable routing loop detection vpn instance capability simple By default routing loop detection is enabled and the MCE does not receive OSPF routes from the PE 4 Redistribute the VPN routes import route protocol as number process id all processes allow direct cost cost value nssa only route policy route policy name tag tag type t...

Страница 16: ... Network diagram Procedure 1 Configure the VPN instances on the MCE and PE 1 On the MCE configure VPN instances vpn1 and vpn2 and specify an RD and route targets for each VPN instance MCE system view MCE ip vpn instance vpn1 MCE vpn instance vpn1 route distinguisher 10 1 MCE vpn instance vpn1 vpn target 10 1 MCE vpn instance vpn1 quit MCE ip vpn instance vpn2 MCE vpn instance vpn2 route distinguis...

Страница 17: ...ce vpn2 quit 2 Configure routing between the MCE and VPN sites The MCE is connected to VPN 1 directly and no routing protocol is enabled in VPN 1 Therefore you can configure static routes On VR 1 assign IP address 10 214 10 2 24 to the interface connected to MCE and 192 168 0 1 24 to the interface connected to VPN 1 Add ports to VLANs correctly Details not shown On VR 1 configure a default route w...

Страница 18: ...ystem view VR2 ospf 2 VR2 ospf 2 area 0 VR2 ospf 2 area 0 0 0 0 network 192 168 10 0 0 0 0 255 VR2 ospf 2 area 0 0 0 0 network 10 214 20 0 0 0 0 255 VR2 ospf 2 area 0 0 0 0 quit VR2 ospf 2 quit On the MCE display the routing information maintained for VPN instance vpn2 MCE display ip routing table vpn instance vpn2 Destinations 13 Routes 13 Destination Mask Proto Pre Cost NextHop Interface 0 0 0 0...

Страница 19: ...interface40 ip binding vpn instance vpn2 PE1 Vlan interface40 ip address 40 1 1 2 24 PE1 Vlan interface40 quit Configure the IP address of the interface Loopback 0 as 101 101 10 1 for the MCE and as 100 100 10 1 for PE 1 Specify the loopback interface address as the router ID for the MCE and PE 1 Details not shown Enable OSPF process 10 on the MCE and bind the process to VPN instance vpn1 MCE ospf...

Страница 20: ...Vlan30 224 0 0 0 4 Direct 0 0 0 0 0 0 NULL0 224 0 0 0 24 Direct 0 0 0 0 0 0 NULL0 255 255 255 255 32 Direct 0 0 127 0 0 1 InLoop0 Verify that PE 1 has learned the routes of OSPF process 20 in VPN 2 through OSPF PE1 display ip routing table vpn instance vpn2 Destinations 13 Routes 13 Destination Mask Proto Pre Cost NextHop Interface 0 0 0 0 32 Direct 0 0 127 0 0 1 InLoop0 40 1 1 0 24 Direct 0 0 40 ...

Страница 21: ...n routing protocols to save system resources IPv6 MCE tasks at a glance To configure IPv6 MCE perform the following tasks 1 Configuring VPN instances Perform the following VPN instance tasks on PEs and MCEs a Creating a VPN instance b Associating a VPN instance with a Layer 3 interface c Optional Configuring route related attributes for a VPN instance 2 Configuring routing between an MCE and a VPN...

Страница 22: ...ce with an interface or disassociating a VPN instance from an interface will clear the IP address and routing protocol settings of the interface Configuration of this command deletes the IPv6 address of the current interface You must reconfigure an IPv6 address for the interface after configuring the command Configuring route related attributes for a VPN instance Restrictions and guidelines If you...

Страница 23: ...n MCE and a VPN site About IPv6 static routing between an MCE and a VPN site An MCE can reach a VPN site through an IPv6 static route IPv6 static routing on a traditional CE is globally effective and does not support address overlapping among VPNs An MCE supports binding an IPv6 static route with an IPv6 VPN instance so that the IPv6 static routes of different IPv6 VPN instances can be isolated fr...

Страница 24: ...re redistributed into RIPng 4 Return to system view quit 5 Enter interface view interface interface type interface number 6 Enable RIPng on the interface ripng process id enable By default RIPng is disabled Configuring OSPFv3 between an MCE and a VPN site About OSPFv3 between an MCE and a VPN site By configuring OSPFv3 process to IPv6 VPN instance bindings on a MCE you allow routes of different IP...

Страница 25: ...ing configurations on the MCE For information about configuring the PE see the documentation for the PE Configuring IPv6 static routing between an MCE and a PE 1 Enter system view system view 2 Configure an IPv6 static route for an IPv6 VPN instance ipv6 route static vpn instance s vpn instance name ipv6 address prefix length interface type interface number next hop address nexthop address public ...

Страница 26: ... receive OSPFv3 routes from the PE 5 Redistribute VPN routes import route protocol as number process id all processes allow direct cost cost value nssa only route policy route policy name tag tag type type By default no routes are redistributed into OSPFv3 6 Return to system view quit 7 Enter interface view interface interface type interface number 8 Enable the OSPFv3 process on the interface ospf...

Страница 27: ...PN instances vpn1 and vpn2 and specify an RD and route targets for each VPN instance MCE system view MCE ip vpn instance vpn1 MCE vpn instance vpn1 route distinguisher 10 1 MCE vpn instance vpn1 vpn target 10 1 MCE vpn instance vpn1 quit MCE ip vpn instance vpn2 MCE vpn instance vpn2 route distinguisher 20 1 CE VPN 1 Site 2 CE VPN 2 Site 1 PE 1 PE 3 PE 2 VPN 2 2012 64 VR 2 VPN 1 2012 1 64 VR 1 MCE...

Страница 28: ...VPN sites The MCE is connected to VPN 1 directly and no routing protocol is enabled in VPN 1 Therefore you can configure IPv6 static routes On VR 1 assign IPv6 address 2001 1 2 64 to the interface connected to the MCE and 2012 1 2 64 to the interface connected to VPN 1 Add ports to VLANs Details not shown On VR 1 configure a default route with the next hop being 2001 1 1 VR1 system view VR1 ipv6 r...

Страница 29: ...nce 0 Interface Vlan10 Cost 0 Destination 2001 1 1 128 Protocol Direct NextHop 1 Preference 0 Interface InLoop0 Cost 0 Destination 2012 1 64 Protocol Static NextHop 2001 1 2 Preference 60 Interface Vlan10 Cost 0 Destination FE80 10 Protocol Direct NextHop Preference 0 Interface NULL0 Cost 0 Destination FF00 8 Protocol Direct NextHop Preference 0 Interface NULL0 Cost 0 MCE display ipv6 routing tabl...

Страница 30: ...nterface MCE interface vlan interface 40 MCE Vlan interface40 ip binding vpn instance vpn2 MCE Vlan interface40 ipv6 address 40 1 64 MCE Vlan interface40 quit On PE 1 bind VLAN interface 30 to VPN instance vpn1 and configure an IPv6 address for the VLAN interface PE1 interface vlan interface 30 PE1 Vlan interface30 ip binding vpn instance vpn1 PE1 Vlan interface30 ipv6 address 30 2 64 PE1 Vlan int...

Страница 31: ...etails not shown Verifying the configuration Verify that PE 1 has learned the private route of VPN 1 through OSPFv3 PE1 display ipv6 routing table vpn instance vpn1 Destinations 6 Routes 6 Destination 1 128 Protocol Direct NextHop 1 Preference 0 Interface InLoop0 Cost 0 Destination 30 64 Protocol Direct NextHop Preference 0 Interface Vlan30 Cost 0 Destination 30 2 128 Protocol Direct NextHop 1 Pre...

Страница 32: ...rotocol Direct NextHop 1 Preference 0 Interface InLoop0 Cost 0 Destination 2012 64 Protocol O_ASE2 NextHop FE80 200 FF FE0F 5 Preference 150 Interface Vlan40 Cost 1 Destination FE80 10 Protocol Direct NextHop Preference 0 Interface NULL0 Cost 0 Destination FF00 8 Protocol Direct NextHop Preference 0 Interface NULL0 Cost 0 The routing information for the two VPNs has been added into the routing tab...

Отзывы: