399
connected with multiple sites in the same VPN, you can configure the MCE as a route reflector (RR) and
configure the egress routers of the sites as clients, making the MCE reflect routing information between
the sites. This eliminates the necessity for BGP connections between sites, reducing the number of BGP
connections and simplifying network configuration.
eBGP
To use eBGP for exchanging routing information between an MCE and VPN sites, you must configure a
BGP peer for each VPN instance on the MCE, and redistribute the IGP routes of each VPN instance on
the VPN sites. You also can configure filtering policies to filter the received routes and the routes to be
advertised.
Route exchange between an MCE and a PE
Routing information entries are bound to specific VPN instances on an MCE device, and packets of each
VPN instance are forwarded between MCE and PE according to interface. As a result, VPN routing
information can be transmitted by performing relatively simple configurations between MCE and PE,
such as importing the VPN routing entries on MCE devices to the routing table of the routing protocol
running between MCE and PEs.
The following routing protocols can be used between MCE and PE devices for routing formation
exchange:
•
Static route
•
RIP
•
OSPF
•
IS-IS
•
iBGP
•
eBGP
For information about routing protocol configuration and route import, see
Layer 3—IP Routing
Configuration Guide
.
Configuring an MCE
Configuring VPN instances
Configuring VPN instances is required in all MCE networking schemes.
By configuring VPN instances on a PE, you isolate not only VPN routes from public network routes, but
also routes of a VPN from those of another VPN. This feature allows VPN instances to be used in
networking scenarios besides MCE.
Creating a VPN Instance
A VPN instance is associated with a site. It is a collection of the VPN membership and routing rules of its
associated site. A VPN instance does not necessarily correspond to one VPN.
A VPN instance takes effect only after you configure an RD for it. Before configuring an RD for a VPN
instance, you can configure no other parameters for the instance but a description.
You can configure a description for a VPN instance to record its related information, such as its
relationship with a certain VPN.