实验题目如下:
实验拓扑如下:
实验要求如下:
【1】R1与R5MPLS VPN
【2】R6与R7MPLS VPN
【3】R7可以访问R2/3/4的环回
实验思路如下:
(1)合理的IP配置
(2)R2、R3、R4的 IGP 配置
(3)R2、R3、R4的 MPLS 配置
(4)R2、R3、R4的 MPLS VPN配置
(5)R2、R4的 BGP 配置
(6)内网宣告R1/5使用静态路由配置,R6/7使用动态路由配置
(7)R7的缺省路由配置,NAT配置
实验步骤如下:
1、合理的IP配置
指令如下:
R1:
[R1-LoopBack0]ip add 192.168.1.1 24
[R1-LoopBack0]int g0/0/1
[R1-GigabitEthernet0/0/1]ip add 192.168.2.1 24
R2:
[R2]int g0/0/2
[R2-GigabitEthernet0/0/2]ip add 23.1.1.1 24
[R2-GigabitEthernet0/0/2]int l0
[R2-LoopBack0]ip add 2.2.2.2 24
R3:
[R3-LoopBack0]ip add 3.3.3.3 24
[R3-LoopBack0]int g0/0/0
[R3-GigabitEthernet0/0/0]ip add 23.1.1.2 24
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]ip add 34.1.1.1 24
R4:
[R4-LoopBack0]ip add 4.4.4.4 24
[R4-LoopBack0]int g0/0/0
[R4-GigabitEthernet0/0/0]ip add 34.1.1.2 24
[R4-GigabitEthernet0/0/0]int g0/0/1
[R4-GigabitEthernet0/0/1]ip add 47.1.1.2 24
R5:
[R5-LoopBack0]ip add 192.168.4.1 24
[R5-LoopBack0]int g0/0/0
[R5-GigabitEthernet0/0/0]ip add 192.168.3.1 24
R6:
[R6-LoopBack0]ip add 192.168.1.1 24
[R6-LoopBack0]int g0/0/1
[R6-GigabitEthernet0/0/1]ip add 192.168.2.1 24
R7:
[R7]int l0
[R7-LoopBack0]ip add 7.7.7.7 24
[R7-LoopBack0]int l1
[R7-LoopBack1]ip add 192.168.4.2 24
[R7-LoopBack0]int g0/0/1
[R7-GigabitEthernet0/0/1]ip add 192.168.3.1 24
[R7-GigabitEthernet0/0/1]int g0/0/0
[R7-GigabitEthernet0/0/0]ip add 47.1.1.1 24
2、R2、R3、R4的 IGP 配置
指令如下:
R2:
OSPF配置:
[R2]ospf 1 router-id 2.2.2.2
[R2-ospf-1]area 0
[R2-ospf-1-area-0.0.0.0]network 2.2.2.2 0.0.0.0
[R2-ospf-1-area-0.0.0.0]network 23.1.1.1 0.0.0.0
R3:
OSPF配置:
[R3]ospf 1 router-id 3.3.3.3
[R3-ospf-1]area 0
[R3-ospf-1-area-0.0.0.0]network 3.3.3.3 0.0.0.0
[R3-ospf-1-area-0.0.0.0]network 34.1.1.1 0.0.0.0
[R3-ospf-1-area-0.0.0.0]network 23.1.1.2 0.0.0.0
R4:
OSPF配置:
[R4]ospf 1 router-id 4.4.4.4
[R4-ospf-1]area 0
[R4-ospf-1-area-0.0.0.0]network 4.4.4.4 0.0.0.0
[R4-ospf-1-area-0.0.0.0]network 47.1.1.2 0.0.0.0
[R4-ospf-1-area-0.0.0.0]network 34.1.1.2 0.0.0.0
3、R2、R3、R4 的 MPLS 配置
指令如下:
R2:
[R2]mpls lsr-id 2.2.2.2
[R2]mpls
[R2-mpls]mpls ldp
[R2-mpls-ldp]int g0/0/2
[R2-GigabitEthernet0/0/2]mpls
[R2-GigabitEthernet0/0/2]mpls ldp
R3:
[R3]mpls lsr-id 3.3.3.3
[R3]mpls
[R3-mpls]mpls ldp
[R3-mpls-ldp]int g0/0/0
[R3-GigabitEthernet0/0/0]mpls
[R3-GigabitEthernet0/0/0]mpls ldp
[R3-GigabitEthernet0/0/0]int g0/0/1
[R3-GigabitEthernet0/0/1]mpls
[R3-GigabitEthernet0/0/1]mpls ldp
R4:
[R4]mpls lsr-id 4.4.4.4
[R4]mpls
[R4-mpls]mpls ldp
[R4-mpls-ldp]int g0/0/0
[R4-GigabitEthernet0/0/0]mpls
[R4-GigabitEthernet0/0/0]mpls ldp
[R4-GigabitEthernet0/0/0]int g0/0/1
[R4-GigabitEthernet0/0/1]mpls
[R4-GigabitEthernet0/0/1]mpls ldp
4、R2、R3、R4 的 MPLS VPN 配置
指令如下:
R2:
[R2]ip vpn-instance A1
[R2-vpn-instance-A1]ipv4-family
[R2-vpn-instance-A1-af-ipv4]route-distinguisher 1:1
[R2-vpn-instance-A1-af-ipv4]vpn-target 1:1
[R2-vpn-instance-A1-af-ipv4]int g0/0/1
[R2-GigabitEthernet0/0/1]ip binding vpn-instance A1
[R2-GigabitEthernet0/0/1]ip add 192.168.2.2 24
[R2]ip vpn-instance B1
[R2-vpn-instance-B1]ipv4-family
[R2-vpn-instance-B1-af-ipv4]route-distinguisher 2:2
[R2-vpn-instance-B1-af-ipv4]vpn-target 2:2
[R2-vpn-instance-B1-af-ipv4]int g0/0/0
[R2-GigabitEthernet0/0/0]ip binding vpn-instance B1
[R2-GigabitEthernet0/0/0]ip add 192.168.2.2 24
R4:
[R4]ip vpn-instance B2
[R4-vpn-instance-B2]ipv4-family
[R4-vpn-instance-B2-af-ipv4]route-distinguisher 2:2
[R4-vpn-instance-B2-af-ipv4]vpn-target 2:2
[R4-vpn-instance-B2-af-ipv4]int g4/0/0
[R4-GigabitEthernet4/0/0]ip binding vpn-instance B2
[R4-GigabitEthernet4/0/0]ip add 192.168.3.2 24
[R4]ip vpn-instance A2
[R4-vpn-instance-A2]ipv4-family
[R4-vpn-instance-A2-af-ipv4]route-distinguisher 1:1
[R4-vpn-instance-A2-af-ipv4]vpn-target 1:1
[R4-vpn-instance-A2-af-ipv4]int g0/0/2
[R4-GigabitEthernet0/0/2]ip binding vpn-instance A2
[R4-GigabitEthernet0/0/2]ip add 192.168.3.2 24
5、R2、R4的 BGP 宣告
指令如下:
R2:
BGP 配置 内网静态宣告:
[R2]bgp 2
[R2-bgp]router-id 2.2.2.2
[R2-bgp]peer 4.4.4.4 as-number 2
[R2-bgp]peer 4.4.4.4 connect-interface LoopBack 0
[R2-bgp]peer 4.4.4.4 next-hop-local
[R2-bgp]ipv4-family vpnv4
[R2-bgp-af-vpnv4]peer 4.4.4.4 enable
[R2]ip route-static vpn-instance B1 192.168.1.0 24 192.168.2.1
[R2]bgp 2
[R2-bgp]ipv4 vpn-instance B1
[R2-bgp-B1]import-route direct
[R2-bgp-B1]import-route static
R4:
BGP 配置 内网静态宣告:
[R4]bgp 2
[R4-bgp]router-id 4.4.4.4
[R4-bgp]peer 2.2.2.2 as-number 2
[R4-bgp]peer 2.2.2.2 connect-interface LoopBack 0
[R4-bgp]peer 2.2.2.2 next-hop-local
[R4-bgp]ipv4-family vpnv4
[R4-bgp-af-vpnv4]peer 2.2.2.2 enable
[R4]ip route-static vpn-instance B2 192.168.4.0 24 192.168.3.1
[R4]bgp 2
[R4-bgp]ipv4 vpn-instance B2
[R4-bgp-B2]import-route direct
[R4-bgp-B2]import-route static
6、内网宣告R1/5使用静态路由配置,R6/7使用动态路由配置
指令如下:
R1:
[R1]ip route-static 0.0.0.0 0 192.168.2.2
R5:
[R5]ip route-static 0.0.0.0 0 192.168.3.2
R6:
RIP配置:
[R6]rip 1
[R6-rip-1]ver 2
[R6-rip-1]network 192.168.2.0
[R6-rip-1]network 192.168.1.0
7、R7的缺省路由配置,NAT配置
指令如下:
R7:
缺省路由:
[R7]ip route-static 0.0.0.0 0 47.1.1.2
NAT配置:
[R7]acl 2000
[R7-acl-basic-2000]rule permit source 192.168.4.2 0.0.0.0
[R7-acl-basic-2000]int g0/0/0
[R7-GigabitEthernet0/0/0]nat outbound 2000
8、测试如下:
R1:
R2:
R4:
R6:
R7: