233
Configuring nested VPN
Network requirements
The service provider provides nested VPN services for users, as shown in
•
PE 1 and PE 2 are PE devices on the service provider backbone. Both of them support the
nested VPN function.
•
CE 1 and CE 2 are connected to the service provider backbone. Both of them support VPNv4
routes.
•
PE 3 and PE 4 are PE devices of the customer VPN. Both of them support MPLS L3VPN.
•
CE 3 through CE 6 are CE devices of the sub-VPNs for the customer VPN.
The key of nested VPN configuration is to understand the processing of routes of sub-VPNs on the
service provider PEs:
•
When receiving a VPNv4 route from a CE (CE 1 or CE 2 in this example), a service provider PE
a.
Replaces the RD of the VPNv4 route with the RD of the MPLS VPN on the service provider
network where the CE resides.
b.
Adds the export target attribute of the MPLS VPN on the service provider network to the
extended community attribute list.
c.
Forwards the VPNv4 route.
•
To implement exchange of sub-VPN routes between customer PEs and service provider PEs,
MP-EBGP peers must be established between service provider PEs and customer CEs.
Figure 68 Network diagram
Table 18 Interface and IP address assignment
Device
Interface
IP address
Device
Interface
IP address
CE 1
Loop0
2.2.2.9/32
CE 2
Loop0
5.5.5.9/32
Vlan-int2
10.1.1.2/24
Vlan-int1
21.1.1.2/24
Vlan-int1
11.1.1.1/24
Vlan-int2
20.1.1.1/24
CE 3
Vlan-int1
100.1.1.1/24
CE 4
Vlan-int1
120.1.1.1/24
CE 5
Vlan-int3
110.1.1.1/24
CE 6
Vlan-int3
130.1.1.1/24
PE 1
CE 3
AS 65410
SUB_VPN 1
PE 2
Customer VPN
PE 3
CE 6
AS 65421
SUB_VPN 2
PE 4
Vlan-int2
Carrier VPN
Customer VPN
Loop0
Loop0
Vlan-int1
Loop
0
CE 1
CE 2
Loop
0
Vlan-int2
Vlan-int2
Vlan-int1
Vlan-int1
Vlan-int3
Vlan-int3
Vlan-int2
Vlan-int2
AS 100
AS 200
VPN 1
AS 200
VPN 1
Vlan-int2
Vlan-int1
Vlan-int1
Vlan-int1
Loop
0
CE 5
AS 65411
SUB_VPN 2
Vlan-int3
Vlan-int3
Loop
0
CE 4
AS 65420
SUB_VPN 1
Vlan-int1
Vlan-int1
Содержание FlexNetwork 5510 HI Series
Страница 9: ...vii Remote support 460 Documentation feedback 460 Index 462 ...
Страница 318: ...309 Request list 0 Retransmit list 0 ...
Страница 363: ...354 Verify that CE 1 and CE 2 can ping each other Details not shown ...
Страница 446: ...437 The MCE has redistributed the OSPF routes of the two VPN instances into the EBGP routing tables of PE 1 ...