ãããããããŸã§ã®ãšãããå®ç掻ã§ã®ã¢ããªã±ãŒã·ã§ã³ã®ã¿ã幜éã®ããã«æãããŠããŸãã ãããŠããã¯æªãã§ãã
ãã®èšäºã§ã¯ãç¶æ³ã®ä¿®æ£ãéå§ããŸãã äžè¬ã«ãèªè ã«ã¯L3VPNãL2VPNãTraffic Engineeringãšããäžé£ã®3ã€ã®èšäºãåŸ ã£ãŠããŸããããã§ã¯ãå®éã«MPLSãäœã®ããã«ããã®ããå®å šã«èª¬æããããšããŸãã
ãããã£ãŠãlinkmeupã¯ãã¯ã倧èŠæš¡ãªããããå¯äžã®äŒç€ŸããµããŒãããããã®ã¢ãŠããœãŒã·ã³ã°ã§ã¯ãªãããããã€ããŒã§ãã ç§ãã¡ã®å åŠç³»ã¯åœã®ãã¹ãŠã®éšåã«éããŠããã®ã§ãé£éŠæ¿åºã®ãããã€ããŒãšèšãããšããã§ããŸãã ãããŠãå€ãã®ã客æ§ã¯ãã¯ãé«éã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæãã§ããããVPNãæ±ããŠããŸãã
ä»æ¥ããããã®èªç±ãªæ¬²æ±ãæºããããã«ããããã¯ãŒã¯ïŒMPLSãæ¢ã«ã»ããã¢ãããããŠããïŒã§äœãããå¿ èŠãããããèããŸãã

ãªãªãŒã¹ã³ã³ãã³ã
- VRFãVPNã€ã³ã¹ã¿ã³ã¹ãã«ãŒãã£ã³ã°ã€ã³ã¹ã¿ã³ã¹
- >>> VRF-Lite
- MPLS L3VPN
- >>> ããŒã¿ãã¬ãŒã³ãŸãã¯ãŠãŒã¶ãŒããŒã¿è»¢é
- >>>>>> MPLSã¿ã°ã®åœ¹å²
- >>>>>>>>> 茞éã©ãã«
- >>>>>>>>> ãµãŒãã¹ã¿ã°
- >>> çšèª
- >>> ã³ã³ãããŒã«ãã¬ãŒã³ãŸãã¯ãµãŒãã¹ïŒã«ãŒãã£ã³ã°ïŒæ å ±ã®éä¿¡
- >>>>>> ã«ãŒãã£ã³ã°ãããã³ã«
- >>>>>>>>> MBGP
- >>>>>>>>>>>> ã«ãŒãèå¥
- >>>>>>>>>>>> ã«ãŒãã¿ãŒã²ãã
- ç·Žç¿ãã
- >>> VRF-Lite
- >>> MPLS L3VPN
- >>>>>> VPNéã®çžäºäœçš
- MPLS L3VPNã®ãã¬ãŒã¹
- QïŒA
- 䟿å©ãªãªã³ã¯
åŸæ¥ã®ãããªïŒ
ã€ã³ã¿ãŒãããäžã®2ã€ã®ãªã¢ãŒããµã€ãã®çžäºäœçšãæŽçããæ¹æ³ ãããªãã¯ã¢ãã¬ã¹ãããå Žåã¯éåžžã«ç°¡åã§ã-ãã®ããã«IPãèæ¡ãããŸããã 圌ãã¯çŽæ¥éä¿¡ã§ããŸãã ãããã«ãããã€ã³ã¿ãŒãããäžã®2ã€ã®ãã€ã³ããæ¥ç¶ããã«ã¯ã2ã€ã®ãããªãã¯ã¢ãã¬ã¹ãå¿ èŠã§ã-äž¡åŽã«1ã€ã ãŸãããã©ã€ããŒãã¢ãã¬ã¹ïŒ10 / 8ã172.16 / 20ã192.168 / 16ïŒãããå Žåã¯ã©ããªããŸããïŒ
ãããã圌ãã¯äžæ¹ã§ãã€ãŸãããããããŠä»æ¹ã§ãåºããã ãããŠãNATã¯å€§äºãªãã®ã§ãã
ãããã£ãŠãVPNããããŸãã ä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ã¯ãå€éšãããã¯ãŒã¯ãç¹ã«ã€ã³ã¿ãŒããããä»ããŠãã©ã€ããŒããããã¯ãŒã¯ã«äœããæ¥ç¶ã§ããããã«ããäžé£ã®ãã¯ãããžãšãããã³ã«ã§ãã
ããšãã°ãlinkmeupã®Tomskãã©ã³ãã¯ãVPNã®åé¡ã§è¡ã£ãããã«ãã€ã³ã¿ãŒãããäžã®VPNã䜿çšããŠã¢ã¹ã¯ã¯ã®æ¬ç€Ÿã«æ¥ç¶ã§ããŸã ã
ã€ãŸããVPNãä»ããŠä»ã®ãã©ã³ããé£ã®éšå±ã«ããããã«èŠããã³ãŒããã¹ã€ããããŸãã¯ã«ãŒã¿ãŒãä»ããŠãããã«æ¥ç¶ãããŸãã ãããã£ãŠãããŒãã¯ãããªãã¯ã¢ãã¬ã¹ã§ã¯ãªããã©ã€ããŒãã¢ãã¬ã¹ã§éä¿¡ã§ããŸãã
ãã®å Žåããã©ã€ããŒãã¢ãã¬ã¹ãæã€å人ããŒã¿ã¯ããããªãã¯ã¢ãã¬ã¹ãæã€ãã±ããã«ããã±ãŒãžåãããã€ã³ã¿ãŒãããããã³ãã«ã§é£è¡ããŸãã
ããã¯ãã¯ã©ã€ã¢ã³ãèªäœããã®æ§æãšææ Œãæžå¿µããããã ã¯ã©ã€ã¢ã³ãVPNãšåŒã°ããŸã ã ãã®å¯äžã®ä»²ä»è ã¯ã€ã³ã¿ãŒãããã§ãã
ç§ãã¡ã¯ç¬¬7å·ã§ãããäœããŸããããããŠããã«ã€ããŠlinkmeupããã°ã§ç§ãã¡ã®èªè ã«ãã巚倧ãªèšäºããããŸã-Vadim Semenovã
å¥ã®å¯èœãªãªãã·ã§ã³ã¯ãããã€ããŒVPNã§ãã ãã®å Žåããããã€ããŒã¯ã¯ã©ã€ã¢ã³ãã«è€æ°ã®æ¥ç¶ãã€ã³ããæäŸãããããã¯ãŒã¯å ã§ãããã®éã«ãã£ãã«ãæ§ç¯ããŸãã
ãã®åŸãã¯ã©ã€ã¢ã³ãã¯ãããã€ããŒã«ãã®ãã£ãã«ãæ¯æãã ãã§æžã¿ãŸãã
ãããã€ããŒVPNã¯ãã¯ã©ã€ã¢ã³ãVPNãšã¯ç°ãªããç¹å®ã®ãµãŒãã¹å質ãæäŸã§ããŸãã éåžžãå¥çŽã®ç· çµæã«SLAã眲åãããé 延ã¬ãã«ããžãã¿ãŒããã±ããæ倱ã®å²åããµãŒãã¹ãå©çšã§ããªãæ倧æéãªã©ãèŠå®ãããŸãã ãŸããã¯ã©ã€ã¢ã³ãVPNã§ãã€ã³ã¿ãŒãããäžã§ãã¹ãŠãèœã¡çããŠããŠãããŒã¿ãå®å šãªé åºã§å°çããããšãæãã°ããããã€ããŒã«å°ãã人ãããŸãã
ä»åã¯ãããã€ããŒVPNã«çŠç¹ãåœãŠãŸãã
ãããã¯ãŒã¯ãã©ãã£ãã¯ã®ã«ãŒãã£ã³ã°ã確ä¿ããå¿ èŠãããå Žåã第3ã¬ãã«ã®VPN-L3VPNã«ã€ããŠè©±ããŸãã L2VPNã¯æ¬¡ã®ãªãªãŒã¹ã®ãããã¯ã§ãã
VRFãVPNã€ã³ã¹ã¿ã³ã¹ãã«ãŒãã£ã³ã°ã€ã³ã¹ã¿ã³ã¹
VPNã«é¢ããŠã¯ããã©ãã£ãã¯ã®åé¢ã®åé¡ãçºçããŸãã ä»ã®äººã¯ãããåä¿¡ããŠââã¯ãªãããããªãã®ãã©ã€ããŒãã¢ãã¬ã¹ã¯ã圌ããæå³ãããŠããªãå Žæãã€ãŸãã€ã³ã¿ãŒãããäžãç§ãã¡ã®ãããã€ããŒã®ãããã¯ãŒã¯å ãããã³ä»ã®ã¯ã©ã€ã¢ã³ãã®VPNäžã«çŸããŠã¯ãããŸããã
ã€ã³ã¿ãŒãããïŒãŸãã¯å¥œã¿ã«å¿ããŠOpenVPNïŒãä»ããŠGREãã³ãã«ãèšå®ãããšãããŒã¿ã¯èªåçã«åé¢ãããŸã-ã€ã³ã¿ãŒãããäžã®ãã©ã€ããŒãã¢ãã¬ã¹ã¯èª°ã«ãèŠããããã©ãã£ãã¯ã¯ééã£ãæã«æž¡ããŸããïŒæšçåæ»æã®åé¡ãæèµ·ããªãéãïŒã
ã€ãŸãã2ã€ã®ãããªãã¯ã¢ãã¬ã¹éã«ç¹å®ã®ãã³ãã«ãããããããã€ããŒãŸãã¯ä»ã®äžç¶ãã³ãã«ãšã¯æ±ºããŠæ¥ç¶ãããŠããŸããã 2ã€ã®ç°ãªãVPN-2ã€ã®å®å šã«ç°ãªããã³ãã«-ããã³ãã©ãã£ãã¯ã®ã¿ããã³ãã«ãééããŸãã
質åã¯ãããã€ããŒVPNã§ã¯ç°ãªããŸã-åãããã¯ããŒã³ãããã¯ãŒã¯ã¯æ°çŸã®ã¯ã©ã€ã¢ã³ãã®ããŒã¿ãäŒéããå¿ èŠããããŸãã ããã«ããæ¹æ³ã¯ïŒ
ãããããã¡ãããããã§ã¯GREãOpenVPNãL2TPãªã©ã䜿çšã§ããŸãããéçšãšã³ãžãã¢ãè¡ãããšã¯ããã³ãã«ãèšå®ããæ°çŸäžæ¬ã®æ§æã©ã€ã³ãã·ã£ãã«ããã ãã§ãã
ããããåé¡ã¯ããæ·±ãã§ã-ãã®ãããªãŠãããŒãµã«ãã£ãã«ããã¹ãŠã®äººã®ããã«ç·šæãããšããåé¡ã¯äºæ¬¡çãªåé¡ã§ããäž»ãªããšã¯ãåãã«ãŒã¿ã«æ¥ç¶ããã2ã€ã®ã¯ã©ã€ã¢ã³ããåé¢ããæ¹æ³ã§ãã ããšãã°ãäž¡æ¹ã10.0.0.0/8ãããã¯ãŒã¯ã䜿çšããŠããå Žåããããã®éã§ãã©ãã£ãã¯ãã«ãŒãã£ã³ã°ãããªãããã«ããã«ã¯ã©ãããã°ããã§ããïŒ
ããã§ã VRF-ä»®æ³ã«ãŒãã£ã³ã°ããã³è»¢éã€ã³ã¹ã¿ã³ã¹ã®æŠå¿µã«é²ã¿ãŸãã ããã§ã®çšèªã¯ç¢ºç«ãããŠããŸãããã·ã¹ã³ã§ã¯-ããã¯VRFãHuaweiã§ã¯-VPNã€ã³ã¹ã¿ã³ã¹ãJuniperã§ã¯-ã«ãŒãã£ã³ã°ã€ã³ã¹ã¿ã³ã¹ã§ãã ãã¹ãŠã®ååã«ã¯çåœæš©ããããŸãããæ¬è³ªã¯åãã§ã-ä»®æ³ã«ãŒã¿ãŒã ããã¯ãäžéšã®VirtualBoxã®ä»®æ³ãã·ã³ã®ãããªãã®ã§ãã1ã€ã®ç©çãµãŒããŒäžã§å®è¡ãããŠããä»®æ³ãµãŒããŒãå€æ°ããã1ã€ã®ç©çã«ãŒã¿ãŒäžã«å€æ°ã®ä»®æ³ã«ãŒã¿ãŒããããŸãã
ãã®ãããªåä»®æ³ããŒã·ã£ã©ã€ã¶ãŒã¯ãæ¬è³ªçã«å¥åã®VPNã§ãã ã«ãŒãã£ã³ã°ããŒãã«ãFIBãã€ã³ã¿ãŒãã§ã€ã¹ã®ãªã¹ããããã³ãã®ä»ã®ãã©ã¡ãŒã¿ãŒã¯éè€ããŠããŸãã-å³å¯ã«åå¥ã§éé¢ãããŠããŸãã ãŸã£ããåãæ¹æ³ã§ãç©çã«ãŒã¿ãŒèªäœããéé¢ãããŸãã ãã ããä»®æ³ãµãŒããŒãšåæ§ã«ãä»®æ³ãµãŒããŒéã§éä¿¡ãå¯èœã§ãã
VRF-ã«ãŒã¿ãŒã«å¯ŸããŠå³å¯ã«ããŒã«ã«ã§ã-VRFã¯å€éšã«ååšããŸããã ãããã£ãŠãäžæ¹ã®ã«ãŒã¿ã®VRFã¯ãããäžæ¹ã®ã«ãŒã¿ã®VRFãšã¯ãŸã£ããæ¥ç¶ãããŠããŸããã
ã·ã¹ã³ã®æ©åšã«é¢ãããã¹ãŠã®äŸãæ€èšããŠããããããããã®çšèªãé å®ããŸãã
VRF Lite
ããã¯ãMPLSãªãã§ãããã€ããŒVPNãäœæããååã§ãã
ããã§ã¯ãããšãã°ãåãã«ãŒã¿ãŒå ã§VPNãæ§æã§ããŸãã

ããã«ã¯ãTARã®RoboticsãšC3PO Electronicã®2ã€ã®ã¯ã©ã€ã¢ã³ãããããŸãã
ã€ã³ã¿ãŒãã§ã€ã¹FE0 / 0ããã³FE0 / 1ã¯VPN C3PO Electronicã«å±ããã€ã³ã¿ãŒãã§ã€ã¹FE1 / 0ããã³FE1 / 1ã¯VPN TARã®Roboticsã«å±ããŸãã åäžã®VPNå ã§ã¯ãããŒãã¯äºãã«åé¡ãªãéä¿¡ããŸã-äœãéä¿¡ããŸããã

ããã¯ããããã€ããŒã®ã«ãŒã¿ãŒäžã§ã®ã«ãŒãã£ã³ã°ããŒãã«ã®å€èŠ³ã§ãã


C3POé»åã«ãŒãã¯TARS 'Roboticsãããã¯ãŒã¯ã«å ¥ããããã®éãåæ§ã§ãã
ããã®ã¯ã©ã€ã¢ã³ãã€ã³ã¿ãŒãã§ã€ã¹ã¯ãç¹å®ã®VRFã«é¢é£ä»ããããŠããŸãã
1ã€ã®ã€ã³ã¿ãŒãã§ã€ã¹ã2ã€ã®VRFã®ã¡ã³ããŒãŸãã¯VRFãšã°ããŒãã«ã«ãŒãã£ã³ã°ããŒãã«ã®äž¡æ¹ã®ã¡ã³ããŒã«ããããšã¯ã§ããŸããã
VRF Liteã䜿çšãããšããããã¯ãŒã¯ã®ç°ãªããšã³ãéã§VPNãç°¡åã«è»¢éã§ããŸãã ãããè¡ãã«ã¯ããã¹ãŠã®äžéããŒãã§åãVRFãæ§æããããããã€ã³ã¿ãŒãã§ã€ã¹ã«æ£ãããã€ã³ãããå¿ èŠããããŸãã

ã€ãŸããR1ãšR2ã¯ãã°ããŒãã«ã«ãŒãã£ã³ã°ããŒãã«ã®1çµã®ã€ã³ã¿ãŒãã§ã€ã¹ãVRF TARS 'Roboticsã®å¥ã®ãã¢ãããã³VRF C3PO Electronicã®3çªç®ã®ãã¢ãä»ããŠäºãã«éä¿¡ããŸãã ãã¡ããããããã¯ãµãã€ã³ã¿ãŒãã§ã€ã¹ã«ããããšãã§ããŸãã
åæ§ã«R2-R3ã®éã
ãããã£ãŠãäºãã«äº€å·®ããªã2ã€ã®ä»®æ³ãããã¯ãŒã¯ãååŸãããŸãã ãã®äºå®ãèãããšããã®ãããªåãããã¯ãŒã¯ã§ã¯ãæ¥ç¶ã確ä¿ããããã«IGPããã»ã¹ãäžããå¿ èŠããããŸãã
ãã®å Žåãç©çã«ãŒã¿ãŒãTARS 'RoboticsãC3PO Electricã®ããããã«1ã€ã®ããã»ã¹ããããŸãã ãããã£ãŠããããã®ããããã¯ãç¬èªã®ã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠä»ãšã¯å¥åã«éç¥ãããŸãã
ããŒã¿è»¢éã«ã€ããŠèª¬æãããšãå ¥åã€ã³ã¿ãŒãã§ã€ã¹R1ããã®ã¡ã³ããŒã§ãããããTARSã®ãããã£ã¯ã¹ãããã¯ãŒã¯ã®ããŒãããå°çãããã±ããã¯ãããã«å¯Ÿå¿ããVRFã«å ¥ããŸãã ãã®VRFã®FIBã«ããã°ãåºåã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠR2ã«ã«ãŒãã£ã³ã°ãããŸãã R1ãšR2ã®éã®ã»ã¯ã·ã§ã³ã§ã¯ãæãäžè¬çãªIPãã±ãããéä¿¡ãããŸããããããã¯ç°ãªãVPNã«å±ããŠãããšã¯æãããŸããã å¯äžã®éãã¯ãç°ãªãç©çã€ã³ã¿ãŒãã§ã€ã¹ãééãããã802.1qããããŒã§ç°ãªãã¿ã°ãéã¶ããšã§ãã R2ã¯ãTARSã®Robotics VRFã®ã¡ã³ããŒã§ãããã€ã³ã¿ãŒãã§ã€ã¹ã§ãã®ããã±ãŒãžãåãå ¥ããŸãã
R2ã¯ãç®çã®FIBã§ãã±ãããã¯ãã¯ããIGPã«åŸã£ãŠããã«éä¿¡ããŸãã ãããŠããã±ããããããã¯ãŒã¯ã®å察åŽã«å°çãããŸã§ç¶ããŸãã
ãã¹ãã¯ãåä¿¡ãããã±ãããç¹å®ã®VPNã«å±ããŠããããšãã©ã®ããã«å€æããŸããïŒ éåžžã«ç°¡åïŒãã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯ç¹å®ã®VRFã«çµã³ä»ããããŠããŸãïŒããã€ã³ããïŒã
æ¢ã«ãæ°ã¥ããããããŸãããããããã®ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¯ãå³ã®å¯Ÿå¿ããè²ã®ãªã³ã°ãä»ããŠããŸãã
å°ãæ³ååãã€ããŠãã ããïŒ
ããã°ãç°è²ã®ãªã³ã°ãééãã
åæ§ã«ããã±ããããŽãŒã«ããªã³ã°ãééãããšããé«è²Žãªéã¡ããã§èŠããããŽãŒã«ãã«ãŒãã£ã³ã°ããŒãã«ã«å¯ŸããŠãã§ãã¯ãããŸãã
åæ§ã«ãåºåã€ã³ã¿ãŒãã§ã€ã¹ã¯VPNã«é¢é£ä»ããããŠããã察å¿ããã«ãŒãã£ã³ã°ããŒãã«ã¯ãããã®èåŸã«ãããããã¯ãŒã¯ãèªèããŠããŸãã
ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ããŠèª¬æããããšã¯ãã¹ãŠFIBã«é©çšãããããšã«æ³šæããŠãã ãããåVPNã«ã¯ç¬èªã®FIBããããŸãã
ã«ãŒã¿éã§ã¯ãã±ããã¯ãã€ã³ããããŸãã ã ããŸããŸãªVPNã®ãã±ããã¯ãç°ãªãç©çã€ã³ã¿ãŒãã§ã€ã¹ãŸãã¯äžåºŠã«1ã€ãã€éä¿¡ããããããæ··åšããŸããããç°ãªãVLANã¿ã°ãæã¡ãŸãïŒåVRFã«ã¯ç¬èªã®åºåãµãã€ã³ã¿ãŒãã§ã€ã¹ããããŸãïŒã
ããã§ã¯ãã·ã³ãã«ã§ééçãªVPNã§ããã¯ã©ã€ã¢ã³ãã«å¯ŸããŠæããã©ã€ããŒããªãããã¯ãŒã¯ã圢æãããŠããŸãã

ãã ãã2ã3åã®ã¯ã©ã€ã¢ã³ããš2ã3åã®ã«ãŒã¿ãŒãããéãããã®æ¹æ³ã¯äŸ¿å©ã§ãã 1ã€ã®æ°ããVPNã¯ãåããŒãã®æ°ããVRFãæ°ããã€ã³ã¿ãŒãã§ã€ã¹ããªã³ã¯IPã¢ãã¬ã¹ã®æ°ããããŒã«ãæ°ããIGP / BGPããã»ã¹ãæå³ããããããŸã£ããã¹ã±ãŒãªã³ã°ããŸããã
æ¥ç¶ãã€ã³ãã2ã3ã§ã¯ãªã10ã§ãããããã«åé·æ§ãå¿ èŠãªå Žåãã¯ã©ã€ã¢ã³ãã§IGPãäžããŠãåããŒãã§ã«ãŒããæäŸããã®ã¯ã©ã®ãããªãã®ã§ããã
ãããŠãããã§MPLS VPNã«è¡ããŸãã
MPLS L3VPN
MPLS VPNã䜿çšãããšã次ã®äžå¿«ãªæé ãåãé€ãããšãã§ããŸãã
1ïŒæ¥ç¶ãã€ã³ãéã®åããŒãã§VRFãæ§æããŸã
2ïŒåããŒãã®åVRFã«åå¥ã®ã€ã³ã¿ãŒãã§ã€ã¹ãèšå®ããŸãã
3ïŒåããŒãã®åVRFã«åå¥ã®IGPããã»ã¹ãèšå®ããŸãã
4ïŒåããŒãã®åVRFã®ã«ãŒãã£ã³ã°ããŒãã«ãç¶æããå¿ èŠæ§ã
ã©ãããŠïŒ
ãã®ãããªãããã¯ãŒã¯ã®äŸãšããŠMPLS L3VPNãäœã§ããããæ€èšããŠãã ããã

ãããã£ãŠããããã¯ç§ãã¡ã®TARS 'Roboticsã¯ã©ã€ã¢ã³ãã®3ã€ã®ãã©ã³ãã§ããã¢ã¹ã¯ã¯ã®æ¬ç€Ÿãšããã·ãã«ã¹ã¯ãšã¯ã©ã¹ãã€ã«ã¹ã¯ã®ãªãã£ã¹ã¯ããã¡ã€ããŒã«éåžžã«é¢ããŠããŸãã ãããŠããã§ã«ãã£ã³ãã«ããããŸãã
äžå€®ã®ã¯ã©ãŠãã¯ç§ãã¡-linkmeup-L3VPNãµãŒãã¹ãæäŸãããããã€ããŒã§ãã
äžè¬çã«èšãã°ã顧客ãšããŠã®TARS Roboticsã¯ãL3VPNã®ç·šææ¹æ³ã«éãã¯ãããŸãããããšãå°ãªããšãSLAã«é©åããããã«ããã±ãŒãžãé»è»ã§éãã ãšããŠãã§ãã ãã ãããã®èšäºã®æ çµã¿ã®äžã§ããã¡ãããMPLSã¯ãããã¯ãŒã¯å ã§æ©èœããŸãã
ããŒã¿ãã¬ãŒã³ãŸãã¯ãŠãŒã¶ãŒããŒã¿è»¢é
ãŸããMPLS VPN VRFã§ã¯ãã¯ã©ã€ã¢ã³ããããã¯ãŒã¯ãæ¥ç¶ãããŠããã«ãŒã¿ãŒäžã§ã®ã¿äœæããããšèšããªããã°ãªããŸããã ãã®äŸã§ã¯ããããã¯R1ãšR3ã§ãã äžéãã¹ãã¯ãVPNã«ã€ããŠäœãç¥ãå¿ èŠã¯ãããŸããã
ãããŠããããã®éã§äœããã®åœ¢ã§ç°ãªãVPNã®ãã±ããã®åé¢ãããéä¿¡ãæäŸããå¿ èŠããããŸãã
MPLS VPNãæäŸããã¢ãããŒãã¯æ¬¡ã®ãšããã§ãã åã®èšäºã§èª¬æããããã«ãMPLSã©ãã«ã«åŸã£ãŠããã¯ããŒã³ãããã¯ãŒã¯å ã®ã¹ã€ããã³ã°ãå®è¡ãããç¹å®ã®VPNã«å±ãããã©ããã¯å¥ã®ã©ãã«ïŒè¿œå ã©ãã«ïŒã«ãã£ãŠæ±ºãŸããŸãã
詳现ïŒ
1ïŒããã§ãã¯ã©ã€ã¢ã³ãã¯ãããã¯ãŒã¯172.16.0.0/24ãããããã¯ãŒã¯172.16.1.0/24ã«ãã±ãããéä¿¡ããŸãã
2ïŒãã©ã³ãïŒã¯ã©ã€ã¢ã³ããããã¯ãŒã¯ïŒå ã移åããŸãããæãäžè¬çãªIPãã±ããã§ããããœãŒã¹IPã¯172.16.0.2ãå®å IPã¯172.16.1.2ã§ãã
3ïŒãã©ã³ããããã¯ãŒã¯ã¯ããããã€ããŒã®ãããã¯ãŒã¯ãä»ããŠ172.16.1.0/24ã«å°éã§ããããšãèªèããŠããŸãã
ããã¯ãæãäžè¬çãªãã±ããã§ãããžã£ã³ã¯ã·ã§ã³ã¯ããã©ã€ããŒãã¢ãã¬ã¹ãæã€ã¯ãªãŒã³ãªIPãçµç±ããããã§ãã
4ïŒæ¬¡ã«ãR1ïŒãããã€ããŒã®ã«ãŒã¿ãŒïŒã¯ãã®ãã±ãããåä¿¡ããç¹å®ã®VRFã«å±ããŠããããšãèªèãïŒã€ã³ã¿ãŒãã§ã€ã¹ã¯VRF TARSã«é¢é£ä»ããããŠããŸãïŒããã®VRFã®ã«ãŒãã£ã³ã°ããŒãã«ã確èªããŸãïŒãã±ããã®éä¿¡å ã®ãã©ã³ãïŒããããMPLSãã±ããã«ã«ãã»ã«åããŸãã
ãã®ãã±ããã®MPLSã©ãã«ã¯ãç¹å®ã®VPNã«å±ããŠããããšãæå³ããŸãã ããã¯ãµãŒãã¹ã¿ã°ãšåŒã°ããŸãã
5ïŒæ¬¡ã«ãã«ãŒã¿ãŒã¯R3ã«ãã±ãããéä¿¡ããå¿ èŠããããŸãããã®èåŸã«ã¯ç®çã®ã¯ã©ã€ã¢ã³ããªãã£ã¹ããããŸãã åœç¶ãMPLSã«ãããšã ãããè¡ãã«ã¯ãR1ãçµäºãããšãã«MPLSãã©ã³ã¹ããŒãã©ãã«ããã³ã°ããŸãã ã€ãŸããçŸæç¹ã§ã¯ããã±ããã«2ã€ã®ã©ãã«ããããŸãã
åºæ¬çãªMPLSãªãªãŒã¹ã§èª¬æãããããã«MPLSãã±ããã¯ãŸãã«é²ãéãæããŸãã ç¹ã«ããã©ã³ã¹ããŒãã©ãã«-SWAPã©ãã«ã¯R2ã«çœ®ãæããããŸãã
6ïŒçµæãšããŠãR3ã¯ãã±ãããåä¿¡ãã ãã©ã³ã¹ããŒãã©ãã«ãç Žæ£ãã ãµãŒãã¹äžã§ãããTARS 'Robotics VPNã«å±ããŠããããšãç解ããŸãã
7ïŒãã¹ãŠã®MPLSããããŒãåé€ãããã±ãããæåã«R1ã«å°éãããšãã«ã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ããŸãã

MPLSã®å©ç¹ãèŠããŠããŸããïŒ ã©ãã«ã®äžã«ãããã®ã誰ãæ°ã«ããªããšããäºå®ã ãããã£ãŠãããã¯ããŒã³ãããã¯ãŒã¯å ã§ã¯ãã¯ã©ã€ã¢ã³ããã©ã®ã¢ãã¬ã¹ã¹ããŒã¹ãæã£ãŠããããã€ãŸããã©ã®IPãã±ãããMPLSããããŒã®äžã«ãããã¯é¢ä¿ãããŸããã
ãã±ããã¯ã©ãã«ã«ãã£ãŠã¹ã€ããã³ã°ãããIPã¢ãã¬ã¹ã«ãã£ãŠã«ãŒãã£ã³ã°ãããªããããäžéããŒãã§VPNã«ãŒãã£ã³ã°ããŒãã«ãç¶æããå¿ èŠã¯ãããŸããã
ã€ãŸãããã®ãããªäŸ¿å©ãªMPLSãã³ãã«ãååŸããŸããããã¯ãåŸã§èª¬æããããã«ãèªåçã«éç¥ãããŸãã
ãã®ãããR1ãšR3ã®éïŒã€ãŸããMPLSã¯ã©ãŠãå ïŒã§ãVPNãäœã§ãããã誰ãç解ããŠããŸãããVPNãã±ããã¯ã©ãã«ã«æ²¿ã£ãŠå®å ã«ç§»åããŸãã ããã«ãããåããŒãã§VRFãäžããå¿ èŠããªããªããããã«å¿ããŠãã«ãŒãã£ã³ã°ããŒãã«ãFIBãã€ã³ã¿ãŒãã§ã€ã¹ã®ãªã¹ããªã©ãç¶æã§ããŸãã
ãã±ããã®è¿œå ã®ãã¹å šäœãæåã®MPLSã«ãŒã¿ãŒïŒR1ïŒã§æ±ºå®ãããããšãèæ ®ãããšãåVPNã«åå¥ã®ã«ãŒãã£ã³ã°ãããã³ã«ã¯å¿ èŠãããŸããããåºåã«ãŒã¿ãŒãèŠã€ããæ¹æ³ã«ã€ããŠã¯çåãæ®ããŸãã

ãã©ãã£ãã¯ã®éä¿¡æ¹æ³ãããããç解ããã«ã¯ããã±ããå ã®ã©ãã«ã®æå³ã調ã¹ãå¿ èŠããããŸãã
MPLSã©ãã«ã®åœ¹å²
VRF-Liteã䜿çšããŠå ã®ã¹ããŒã ã«æ»ããšãåé¡ã¯IPãã±ããïŒTARS 'Robotics VPNã¡ã³ããŒã·ããã€ã³ãžã±ãŒã¿ãŒïŒã®ç°è²ããã¹ãå ã«ã®ã¿ååšããå¥ã®ãã¹ãã«è»¢éããããšããã®æ å ±ãVLANã¿ã°ã§è»¢éãããããšã§ãã ãããŠãäžéããŒãã§sinterfaceãæåŠãããšããridgeãå§ãŸããŸãã ãããŠãããã¯ãã¹ãŠã®åã®ããã«è¡ãããªããã°ãªããŸããã
ãããMPLSã·ããªãªã§çºçããã®ãé²ãããã«ãã€ã³ã°ã¬ã¹LSR ã¯ç¹å¥ãªMPLSã©ãã«ããã±ããã«ä»ããŸã- ãµãŒãã¹ -ããã¯VPNèå¥åã§ãã ãã®ã©ãã«ã«ããåºåLSRïŒæåŸã®ã«ãŒã¿ãŒã¯R3ïŒã¯ãIPãã±ãããTARSã®Robotics VPNã«å±ããŠããããšãç解ãã察å¿ããFIBã調ã¹ãŸãã
ã€ãŸããVLANã«éåžžã«äŒŒãŠããŸãããæåã®ã«ãŒã¿ãŒã ãããããåŠçããå¿ èŠããããšããéãããããŸãã
ãããããµãŒãã¹ã¿ã°ã«åºã¥ããŠãMPLSãããã¯ãŒã¯ã§ãã±ãããåãæ¿ããããšã¯ã§ããŸããããã±ãããã©ããã§å€æŽãããšãEgress LSRã¯ã©ã®VPNã«å±ããŠããããèªèã§ããªããªããŸãã
ãããŠããã«ã¿ã°ã¹ã¿ãã¯ããããŸãããååã®å·ã§éåžžã«æ éã«é¿ããŸããã
ãµãŒãã¹ã©ãã«ã¯å éš-ã¹ã¿ãã¯ã®æåã®ã©ãã«ã§ããããã©ã³ã¹ããŒãã©ãã«ã¯ãŸã ãã®äžã«ãã³ã°ããŠããŸãã
ã€ãŸãããã±ããã¯ã2ã€ã®ã©ãã«ïŒäžéšã®ãã©ã³ã¹ããŒããšäžéšã®ãµãŒãã¹ïŒã§MPLSãããã¯ãŒã¯äžã移åããŸãïŒã
2ã€ã®ã¿ã°ãå¿ èŠãªçç±ã1ã€ã®ãµãŒãã¹ã§ã§ããªãã®ã¯ãªãã§ããïŒ ããšãã°ãIngress LSRã®1ã€ã®ã©ãã«ã§1ã€ã®VPNãèšå®ããå¥ã®ã©ãã«ã§å¥ã®VPNãèšå®ããŸãã ãããã£ãŠãéäžã§ããã«åãæ¿ããããåºåLSRã¯ãã±ãããéä¿¡ããVRFãæ£ç¢ºã«èªèããŸãã
äžè¬çã«èšãã°ãããããããšã¯å¯èœã§ãããåäœããŸãããåVPNã®ãã©ã³ã¯ãããã¯ãŒã¯ã§ã¯åå¥ã®LSPã«ãªããŸãã ãŸããããšãã°ãR1ããR3ãŸã§ã®20åã®VPNã®ãã³ãã«ãããå Žåã20åã®LSPãäœæããå¿ èŠããããŸãã ãããŠãç¶æããã®ãããé£ãããã©ãã«ãããµããŠãããããã¯ãã©ã³ãžããLSRã«äœåãªè² è·ããããŸãã ãããŠãå³å¯ã«èšãã°ããããæã ãããããéããããšããŠããããšã§ãã
ããã«ãåãVPNã®ç°ãªããã¬ãã£ãã¯ã¹ã«å¯ŸããŠãç°ãªãã©ãã«ãååšããå ŽåããããŸããããã«ãããLSPã®æ°ãå€§å¹ ã«å¢å ããŸãã
20åãã¹ãŠã®VPNãäžåºŠã«ãã³ããªã³ã°ãã1ã€ã®LSPãäœæããæ¹ãç°¡åã§ããïŒ
茞éã©ãã«
ãããã£ãŠããã©ã³ã¹ããŒãã©ãã«ãå¿ èŠã§ãã 圌女ã¯ã¹ã¿ãã¯ã®ãããã§ãã

LSPãå®çŸ©ããåããŒãã§å€æŽããŸãã
è¿œå ïŒPUSHïŒå ¥åLSRããã³åé€ïŒPOPïŒåºåLSRïŒãŸãã¯PHPã®å Žåã¯æåŸãã2çªç®ã®LSRïŒãè¿œå ãããŸãã ãã¹ãŠã®äžéããŒãã§ãããããŒãããå¥ã®ããŒãïŒSWAPïŒã«å€ãããŸãã
LDPãšRSVP-TEã¯ããã©ã³ã¹ããŒãã©ãã«ã®é åžã«é¢äžããŠããŸãã ãŸããååã®èšäºã§ããã«ã€ããŠéåžžã«ãã話ããŸããããä»ã¯ãããŸããã
äžè¬ã«ããã©ã³ã¹ããŒãã©ãã«ã¯ãFECãšãã1ã€ã®è©³çŽ°ãé€ããŠããã¹ãŠãæ確ã§ãããããã»ãšãã©é¢å¿ããããŸããã
ããã§ã®FECã¯ããã±ããã®å®å ãããã¯ãŒã¯ïŒã¯ã©ã€ã¢ã³ãã®ãã©ã€ããŒãã¢ãã¬ã¹ïŒã§ã¯ãªããã¯ã©ã€ã¢ã³ããæ¥ç¶ãããŠããMPLSãããã¯ãŒã¯å ã®æåŸã®LSRã®ã¢ãã¬ã¹ã§ãã
ããã¯éåžžã«éèŠã§ããLSPã¯ããã«ããããããçš®é¡ã®VPNãèªèããŠããªãããããã©ã€ããŒãã«ãŒã/ãã¬ãã£ãã¯ã¹ã«ã€ããŠäœãç¥ããªãããã§ãã ãããã圌ã¯ãã¹ãŠã®LSRã®ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¢ãã¬ã¹ãããç¥ã£ãŠããŸãã ãããã£ãŠããã®ã¯ã©ã€ã¢ã³ããã¬ãã£ãã¯ã¹ãã©ã®LSRã«æ¥ç¶ãããŠãããã¯ãBGPããéç¥ãããŸããããããã©ã³ã¹ããŒãã©ãã«ã®FECã«ãªããŸãã
ãã®äŸã§ã¯ãR1ã¯ã¯ã©ã€ã¢ã³ããã±ããã®å®å ã¢ãã¬ã¹ã«åºã¥ããŠãR3ã«ã€ãªããLSPãéžæããå¿ èŠãããããšãç解ããå¿ èŠããããŸãã
å°ãåŸã§ãã®åé¡ã«æ»ããŸãã
ãµãŒãã¹ããŒã¯

ã¹ã¿ãã¯ã®äžçªäžã®ã©ãã«ã¯ãµãŒãã¹ã§ãã ããã¯ãç¹å®ã®VPNã®ãã¬ãã£ãã¯ã¹ã®äžæã®èå¥åã§ãã
ããã¯Ingress LSRã«ãã£ãŠè¿œå ãããEgress LSRèªäœãæçµçã«åé€ãããŸã§ã©ãã§ãå€æŽãããŸããã
ãµãŒãã¹ã¿ã°ã®FECã¯ãVPNã®ãã¬ãã£ãã¯ã¹ããŸãã¯å€§ãŸãã«èšã£ãŠãå ã®ãã±ããã®å®å ãµããããã§ãã 次ã®äŸã§ã¯ãFECã¯VRF C3POã®å Žåã¯192.168.1.0/24ãVRF TARSã®å Žåã¯172.16.1.0/24ã§ãã
ã€ãŸããã€ã³ã°ã¬ã¹LSRã¯ããã®VPNã«ã©ã®ã©ãã«ãå²ãåœãŠãããŠããããç¥ãå¿ èŠããããŸãã ãããã©ã®ããã«èµ·ãããã¯ãç§ãã¡ã®ãããªãç 究ã®äž»é¡ã§ãã
ããã¯ãç°ãªãVPNã§ãã±ãããéä¿¡ããããã»ã¹å šäœãã©ã®ããã«èŠãããã§ãã

2ã€ã®ç°ãªãVPNã®å ŽåããµãŒãã¹ããŒã¯ã¯ç°ãªãããšã«æ³šæããŠãã ãã-ãããã«å¿ããŠãåºåã«ãŒã¿ãŒã¯ãã±ãããéä¿¡ããVRFãèŠã€ããŸãã
ãã®å Žåã®ãã©ã³ã¹ããŒãã¯ã1ã€ã®LSP-R1R2R3ã䜿çšãããããäž¡æ¹ã®VRFãã±ããã§åãã§ãã
çšèª
è¡ãéãããŸã§ãçšèªã玹ä»ããå¿ èŠããããŸãã
MPLS VPNã«é¢ããŠã¯ãããã€ãã®æ°ããçšèªãç»å ŽããŸããããããã¯éåžžã«æçœã§ãã
CE- ã«ã¹ã¿ããŒãšããžã«ãŒã¿ãŒ -ãããã€ããŒã®ãããã¯ãŒã¯ã«æ¥ç¶ãããŠããã¯ã©ã€ã¢ã³ããšããžã«ãŒã¿ãŒã
PE- ãããã€ããŒãšããžã«ãŒã¿ãŒ - ãããã€ããŒãšããžã«ãŒã¿ãŒã å®éãCEã¯ããã«æ¥ç¶ãããŠããŸãã VPNã¯PEã§å§ãŸããPEã§çµãããŸãã ãã®äžã«ãVPNã«é¢é£ä»ããããã€ã³ã¿ãŒãã§ã€ã¹ãé 眮ãããŸãã ãµãŒãã¹ããŒã¯ã®å²ãåœãŠãšåé€ãè¡ãã®ã¯PEã§ãã PEã¯ãå ¥åLSRããã³åºåLSRã§ãã
PEã¯ãåVPNã®ã«ãŒãã£ã³ã°ããŒãã«ãç¥ã£ãŠããå¿ èŠããããŸããããã¯ããããã€ããŒãããã¯ãŒã¯å ãšã¯ã©ã€ã¢ã³ãã€ã³ã¿ãŒãã§ã€ã¹ã®äž¡æ¹ã§ããã±ããã®éä¿¡å ã決å®ããã®ã¯åœŒãã§ããããã§ãã
P- ãããã€ããŒã«ãŒã¿ãŒ -æ¥ç¶ãã€ã³ãã§ã¯ãªãäžç¶ã«ãŒã¿ãŒ-VPNãã±ããã¯ãè¿œå ã®åŠçãªãã§ééããŸããã€ãŸãããã©ã³ã¹ããŒãã©ãã«ã«åŸã£ãŠåçŽã«åãæ¿ãããŸãã P VPNã«ãŒãã£ã³ã°ããŒãã«ããµãŒãã¹ã©ãã«ãç¥ãå¿ èŠã¯ãããŸããã Pã«ã¯VPNã«ãã€ã³ããããã€ã³ã¿ãŒãã§ã€ã¹ã¯ãããŸããã
å®éãP-PEã®åœ¹å²ã¯VPNããšã«ç°ãªããŸãã 1ã€ã®VPNã§R1ãšR3ãPEã§ãããR2ãPã§ããå Žåãå¥ã®VPNã§ã¯åœ¹å²ãå€æŽã§ããŸãã
ããšãã°ã次ã®å³ã§ã¯ãéã®ã«ãŒã¿ãŒã®åœ¹å²ã¯ç·ã®ã¯ã©ã€ã¢ã³ããšçŽ«ã®ã¯ã©ã€ã¢ã³ãã§ç°ãªããŸãã

ã©ãã«ã¹ã¿ã㯠-1ã€ã®ãã±ããã«ãã³ã°ã¢ããããMPLSããããŒã®ã»ããããããããäœããã®åœ¹å²ãæãããŸããçŸå®ã«ã¯ãã¹ã¿ãã¯äžã§6ã€ä»¥äžã®ã¿ã°ããµããŒãããŠãããã³ããŒã¯ã»ãšãã©ãããŸããã
å€ãã®çšèªããããŸããããããã玹ä»ããã«ã¯ææå°æ©ã§ãã
äžè¬ã«ãããŒã¿ã®éä¿¡æ¹æ³ãã€ãŸãForwading Planeã®ä»çµã¿ã«ãªããŸããã
èŠçŽãããšã
PEã«ãŒã¿ãŒã¯2ã€ã®ã©ãã«ãã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ã«æããŸã-å éšãµãŒãã¹ã®ã©ãã«ã¯ãæ è¡ã®æåŸãŸã§å€åãããæåŸã®PEã¯ãã±ãããå±ããVRFãç解ããå€éšãã©ã³ã¹ããŒãã¯ãã±ããããããã€ããŒã®ãããã¯ãŒã¯ãä»ããŠéä¿¡ããã-ãã®ã©ãã«ã¯åPã«ãŒã¿ãŒã¯ãæåŸã®PEãŸãã¯æåŸãã2çªç®ã®Pã§åé€ãããŸãã
ãµãŒãã¹ã¿ã°ãšVRFã®ååšã«ãããç°ãªãVPNã®ãã©ãã£ãã¯ã¯ãã«ãŒã¿ãŒå ãšãã£ãã«ã®äž¡æ¹ã§äºãã«åé¢ãããŸãã
ãããŠå®éãä»ãç§ãã¡ã¯å€ãã®äžç©ãªè³ªåãçå®ããããšãã§ããŸãïŒ
1ïŒMPLSã©ãã«ã¯ã©ã®ããã«é åžãããŸããïŒ
2ïŒVPNããšã«ã«ãŒãã£ã³ã°æ å ±ã¯ã©ã®ããã«é ä¿¡ãããŸããïŒ
3ïŒç°ãªãVPNã®ã«ãŒãã¯ã©ã®ããã«çžäºã«åé¢ãããæ··åãããŠããŸãããïŒ
ãããã®è³ªåããã®ä»ã®è³ªåã«ä»¥äžã§åçããŸãã
ã³ã³ãããŒã«ãã¬ãŒã³ãŸãã¯ãµãŒãã¹ïŒã«ãŒãã£ã³ã°ïŒæ å ±ã®éä¿¡
ãããã«çããŠãããŒã¿ãã±ãããæ£åžžã«éä¿¡ãããç°å¢å šäœãã©ã®ããã«æºåãããŠãããã«ã€ããŠèª¬æããŸãã
ã«ãŒãã£ã³ã°ãããã³ã«
ãããã£ãŠã2çš®é¡ã®ãããã¯ãŒã¯ãšãããã®éã®ãžã§ã€ã³ãããããŸãã
- ã¯ã©ã€ã¢ã³ãIPãããã¯ãŒã¯ã
- MPLSãå®è¡ãããŠãããããã€ããŒããã¯ããŒã³ãããã¯ãŒã¯ã
ãããã®ãããã¯ãŒã¯ã®å¢çã¯PEäžã«ãããŸããã€ãŸããååã¯ãã§ã«ã¯ã©ã€ã¢ã³ãã§ãããããååã¯ãããã€ããŒã§ããæ°è¡ã®ç¥æµãååšããããšã¯äœããããŸãããPEãã©ã®ããã«èª¿æŽããŠããããã¯é¡§å®¢ãèŠãŸãã
MPLSã¯ããã©ã³ã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§ã®ã¿èšå®ãããŸãã

L3VPNã«ã€ããŠè©±ããŠããããšãæãåºããŠãã ããããããŠãããã§IPæ¥ç¶ã®äžè©±ãããå¿ èŠããããŸãããããŠä»ãç§ãã¡ã«ã¯å€ãã®å¶éããããŸããã©ã®é åã®ã©ã®ãããã³ã«ãæçšã§ããããç解ããŸãã
ãŸãããããã€ããŒã®ããã¯ããŒã³ãããã¯ãŒã¯å ã§åºæ¬çãªIPæ¥ç¶ãæäŸããå¿ èŠããããŸãããã®ããããã¹ãŠã®ã«ãŒãããã¯ã¢ãã¬ã¹ããªã³ã¯ãããã¯ãŒã¯ããµãŒãã¹ãã¬ãã£ãã¯ã¹ãããã³å Žåã«ãã£ãŠã¯å€éšã®ããã€ãã®åºå£ãèªèãããŸãã
ãããè¡ãã«ã¯ãIGPïŒISISãOSPFïŒãéå§ããŸãã
ãã§ã«æ¥ç¶ããããããã¯ãŒã¯ã®æäžéšã§MPLSãäžæããŠããŸãã
ãããã£ãŠãç§ãã¡ã¯ããã¯ããŒã³ãããã¯ãŒã¯ã®æçšæ§ã確å®ã«ããŸããã
第äºã«ããã©ã³ãå ã®ã¯ã©ã€ã¢ã³ãã«ã¯ã«ãŒã¿ãŒã1ã€ã§ã¯ãªãããããã¯ãŒã¯ãããå ŽåããããŸãããããã®ãããã¯ãŒã¯ã¯ãå°ãªããšããããèªäœã®å éšã§ã«ãŒãã£ã³ã°ããå¿ èŠããããŸãã
æããã«ãèªåã®ãããã¯ãŒã¯å ã§ãã¯ã©ã€ã¢ã³ãã¯å¥œããªããã«ã«ãŒãã£ã³ã°æ å ±ãèªç±ã«é åžã§ããŸãããããã€ããŒãšããŠãããã«åœ±é¿ãäžããããšã¯ã§ããŸããã
ããã«ããã顧客ãããã¯ãŒã¯å ã®ã«ãŒãã®è»¢éãä¿èšŒãããŸãã
第äžã«ãã¯ã©ã€ã¢ã³ãã¯äœããã®æ¹æ³ã§ãããã€ããŒã«ã«ãŒããäŒããå¿ èŠããããŸãã CE-PEã®ãžã£ã³ã¯ã·ã§ã³ã§ã¯ãã¯ã©ã€ã¢ã³ããšãããã€ããŒã¯ã䜿çšãããããã³ã«ã«ã€ããŠåæããå¿ èŠããããŸãã
ãã ããã¯ã©ã€ã¢ã³ãã«ã¯ç¬èªã®IGPãããã³ã«ã¯ã»ãšãã©ãããŸããã確ãã«ããã¯OSPF / ISIS / RIPã§ãããããã£ãŠãéåžžããããã€ããŒã¯å ã«é²ã¿ãã¯ã©ã€ã¢ã³ãã«ãšã£ãŠäŸ¿å©ãªãã®ãéžæããŸãã
ããã§ã¯ããã®ã¯ã©ã€ã¢ã³ã察話ãããã³ã«ãVPNã§æ©èœãããããã€ããŒã®IGPãšäº€å·®ããªãããšãç解ããå¿ èŠããããŸãããããã¯ç°ãªãç¬ç«ããããã»ã¹ã§ãã
å€ãã®å ŽåãBGPã¯ãã®ãžã£ã³ã¯ã·ã§ã³ã§æ©èœããŸããããŸããŸãªå±æ§ã«ãã£ãŠãã¬ãã£ãã¯ã¹ãæè»ã«ãã£ã«ã¿ãªã³ã°ã§ããããã§ãã
ãããã£ãŠããããã€ããŒã¯é¡§å®¢ã«ãŒããåãåããŸãã
ãããŸã§ã®ãšããããã¹ãŠãæ確ã«ãªã£ãŠããŸãã
ããšãããã§ãªããŠã
4çªç®ãããã¯æãèå³æ·±ã-ãã©ã³ã¯ãããã¯ãŒã¯ãä»ããŠ1ã€ã®ãã©ã³ãã®ã«ãŒããå¥ã®ãã©ã³ãã«è»¢éããããšã§ããåæã«ã圌ãã¯éã«æ²¿ã£ãŠå€±ãããŠã¯ãªãããèŠç¥ãã¬äººãšæ··åããããå®å šã§å¥å šã«å±ããããªããã°ãªããŸãããããã§ãBGPãããã³ã«ã®æ¡åŒµ-MBGP- ãã«ããããã³ã«BGPïŒMP-BGPãšåŒã°ããããšãå€ãïŒã圹ç«ã¡ãŸããä»ãã圌ã«ã€ããŠè©±ããŸãã
ãããããŸããäœãã©ãã§æ©èœãããã確èªããŠãã ããã

, .
, .
1) , (IGP ).
2) , (IGP/BGP ).
3) , ( ). (VPN).
4) , â (BGP), ( â PUSH Label â )
, . , â . , .
5) , . , . . ( â SWAP Label). â - .
6) (POP Label) â ( VPN).
7) (IGP/BGP ).
8) , (IGP ).
, â PE/Ingress LSR, â PE/Egress LSR, â P/Intermediate LSR.
PHP .
MBGP
ããã§2ã€ã®è³ªåã«çããŸãã1ã€ã®PEããå¥ã®PEãžã®ãããã€ããŒãããã¯ãŒã¯ã§ã®ã«ãŒãã®éä¿¡æ¹æ³ãšãåé¢ã®ä¿èšŒæ¹æ³ã§ãã
äžè¬ã«ããããŸã§ã®ãšãããã«ãŒãããªã¢ãŒãããŒãã«è»¢éããããã«BGPã»ã©åªãããã®ã¯çºæãããŠããŸãããã«ãŒãèªäœã転éããæè»æ§ãã«ãŒãéžæã«åœ±é¿ãäžããããŒã«ã®å€§èŠæš¡ããããã³ã«ãŒããšã³ãã¥ããã£ãéåä¿¡ããããã®ããªã·ãŒãã°ã«ãŒãã¢ã¯ã·ã§ã³ãå€§å¹ ã«ç°¡çŽ åããŸãã«ãŒãäžã
çªç¶å¿ããŠããŸã£ãå Žåãããã¯éåžžã®BGPæŽæ°ã¡ãã»ãŒãžã§ããNLRI

ã»ã¯ã·ã§ã³ã§ã¯ããã¬ãã£ãã¯ã¹èªäœãäŒéããŸããä»ã®ã»ã¯ã·ã§ã³ã§ã¯ããã®ãã©ã¡ãŒã¿ã®è³ªéã
ãŸããMPLS L3VPNãå®è£ ãããšãã«åœŒã®å©ãã«é ŒããŸãããããã£ãŠããã®ããã«ããŒã ã¯MPLS BGP VPNã§ãã
ãããã©ã®ããã«èµ·ãããèŠããŠããŸããïŒ BGPã¯ãTCPçµç±ã§ããŒã179ãžã®ãã€ããŒãšã®ã»ãã·ã§ã³ã確ç«ããŸããããã«ãããçŽæ¥æ¥ç¶ãããã«ãŒã¿ãŒã§ã¯ãªããããã€ãã®åžæãããã«ãŒã¿ãŒããã€ããŒãšããŠéžæã§ããŸãããããIBGPã®ä»çµã¿ã§ããããã¯ããŒã³ãããã¯ãŒã¯å ã§ã1察1ãæ¥ç¶ãæ³å®ãããŸãã
åããããã¯ãŒã¯ã«ã€ãªããè€æ°ã®ã«ãŒãããã¹ãã«å°çãããšãBGPã¯åã«ãããããæé©ãªã«ãŒããéžæããã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
ã€ãŸããäžè¬ã«ãVPNã«ãŒãããããã¯ãŒã¯çµç±ã§ããäžæ¹ã®ç«¯ã«è»¢éããã®ã«è²»çšã¯ããããŸããã
BGPã¯ã1ã€ã®ããŒãäžã®VRFããã«ãŒããååŸããããããå¥ã®ããŒãã«é ä¿¡ããããã§æ£ããVRFã«ãšã¯ã¹ããŒãããå¿ èŠããããŸãã
å¯äžã®èœãšãç©Žã¯ãBGPãåœåãäžçäžã§äžæã§ãããšæ³å®ãããŠãããããªãã¯ã¢ãã¬ã¹ã§ã®äœæ¥ãæåããŠããããšã§ãããããŠãäžæ£ã¯ã©ã€ã¢ã³ãã¯éåžžãã«ãŒãããã©ã€ããŒããããã¯ãŒã¯ïŒRFC1918ïŒã«è»¢éãããã®ã§ãéãè¯ããã°ãä»ã®VPNã®ãããã¯ãŒã¯ãšãããã€ããŒèªäœã®å éšã¢ãã¬ã¹ã¹ããŒã¹ã®äž¡æ¹ãç°¡åã«äº€å·®ã§ããŸãã
ã€ãŸããããšãã°ãR3ã10.10.10.10/32ã®ãããã¯ãŒã¯ãžã®2ã€ã®ã«ãŒãïŒTARSã®RoboticsãããC3PO ElectronicããïŒãåä¿¡ããå Žåãæšæºã§èŠå®ãããŠããããã«æé«ã®ããã©ãŒãã³ã¹ã§1ã€ã ããéžæããŸããåããããã¯ãŒã¯ã«ã

åœç¶ãããã¯ç§ãã¡ã«é©ããŠããŸããã次ã®2ã€ã®æ¡ä»¶ãæºããããå¿ èŠããããŸã
ã1ïŒç°ãªãVPNã®ã«ãŒãã¯äžæã§ãããPEéã®éä¿¡äžã«æ··åšããŸããã§ããã
2ïŒãšã³ããã€ã³ãã§ã®ã«ãŒãã¯ãæ£ããVRFã«éä¿¡ããå¿ èŠããããŸãã
ãããã®åé¡ã«å¯Ÿãããšã¬ã¬ã³ããªè§£æ±ºçãèŠã€ãããŸããããã€ã³ã1ããå§ããŸããã-ã«ãŒãã®äžææ§ã
ãã®äŸã§ã¯ãTARSã®Roboticsã®10.10.10.10/32ã¯ãC3PO Electronicã®10.10.10.10/32ãšã¯ç°ãªããã®ã§ãªããã°ãªããŸããã
BGPã¯éåžžã«æè»ãªãããã³ã«ã§ãïŒæ£åœãªçç±ã«ãããBGPã¯å¯äžã®å€éšã²ãŒããŠã§ã€ãããã³ã«ã«ãªã£ãŠããŸãïŒãç°¡åã«æ¡åŒµã§ããããããã¢ãã¬ã¹ãã¡ããªã®å©ããåããŠãIPv4ã ãã§ãªããIPv6ãšIPXã«ãã«ãŒãã転éã§ããŸãïŒãã ããå¿ èŠãªã®ã¯ã ããïŒãäœãæ°ãããã®ãäŒãããå Žåã¯ãã¢ãã¬ã¹ãã¡ããª
ãçšæããŠãã ãããIETFãæ°ããã¢ãã¬ã¹ãã¡ããªãäœæããŸããããããŠåœŒã¯åœŒã«ååVPNv4ïŒãŸãã¯VPN-IPv4ïŒãäžããŸããã
ã«ãŒãèå¥å
ç°ãªãVPNã«ãŒããåºå¥ããããã«ãéåžžã®IPv4ãã¬ãã£ãã¯ã¹ã¯ãé·ã8ãã€ãã®ç¹å¥ãªãã¬ãã£ãã¯ã¹-RD- Route Distinguisherã«ãã£ãŠè£å®ãããŸãã
C3POããã®ã«ãŒãã¯æ¬¡ã®ããã«ãªããŸãïŒ64500ïŒ100ïŒ 10.10.10.10/32ãããã³TARSããã®ã«ãŒãïŒ64500ïŒ200ïŒ 10.10.10.10/32ãããŠä»ããããã¯å®å šã«ç°ãªããã®ã§ãããBGPããã»ã¹ãäºãã«åºå¥ããããšãã§ããŸãã
RDãšã¯äœããã©ã®ããã«å®çŸ©ããããèŠãŠã¿ãŸãããã
RDã«ã¯3ã€ã®ã¿ã€ãããããŸãïŒ

Inspiredã
æåã®éšåã¯ã¿ã€ãèªäœïŒ0ã1ããŸãã¯2ïŒã§ãã
第äºéš-管çè ãã£ãŒã«ãã¯åžžã«ãããªãã¯ãã©ã¡ãŒã¿ã§ã-ãããªãã¯IPã¢ãã¬ã¹ãŸãã¯ãããªãã¯ASçªå·ã RDããããã¯ãŒã¯å ã ãã§ãªããææå ã§ãäžæã«ãªãããã«ããå¿ èŠããããŸãã
ã€ãŸãã管çéšåã§ã¯ãIPã¢ãã¬ã¹172.16.127.2ãŸãã¯AS 65001ã誀ã£ãŠè¡šç€ºãããããšã¯ãããŸãããããã¯ãVPNãå¥ã®ãããã€ããŒã®ãããã¯ãŒã¯ã«è»¢éããå¿ èŠãããå Žåã«äŸ¿å©ã§ã-AS VPNïŒã
3çªç®ã®éšå -å²ãåœãŠãããçªå·-ããã¯ããªããå²ãåœãŠããã®ã§ãããã®éšåã«ãããRDã¯ãããã¯ãŒã¯å ã§äžæã«ãªããå®éã«ã¯VPNãå®çŸ©ã§ããŸãã
ã芧ã®ãšãããRDã¯ææå ã§äžæã§ãã
次ã«ãéåžžã®IPv4ãã¬ãã£ãã¯ã¹10.10.10.10/32ãVPNv4ã«å€æãã2ã€ã®äŸã瀺ããŸãã
0:64500:100:10.10.10.10/32
ãŸãã¯
1:100.0.0.1:100:10.10.10.10/32.
ãããã¯ãŒã¯å ã§äž¡æ¹ã®ã¢ãããŒããåæã«äœ¿çšããå Žåã§ããã©ã¡ããéžæããŠãããŸããŸããã ç°ãªãã«ãŒã¿ãŒäžã®1ã€ã®VRFã§ãã RDã®äž»ãªã¿ã¹ã¯ã¯ããã¬ãã£ãã¯ã¹ãåé¢ããããšã§ãã
ã€ãŸããéåžžã«åçŽãªèšèªã®å ŽåïŒèšå®ããå 容ã¯ãŸã£ããåé¡ã§ã¯ãããŸãããäž»ãªããšã¯ãBGPãç°ãªãVPNã®ã«ãŒããæ··åããªãããšã§ãã
äœç³»åã¯èª°ãæ°ã«ããŸããã§ãããã
éåžžãã¿ã€ã0ã䜿çšãã管çãã£ãŒã«ãã¯ãããã€ããŒã®ASçªå·ã§ããããŠãŒã¶ãŒã¯èªåã§å°çšã®çªå·ãéžæããŸãã RDãã»ããã¢ãããããšããæåã®ã0ïŒããŸãã¯ã1ïŒãïŒã¿ã€ãRDïŒã¯ççž®ããã 64500ïŒ100ããã³100.0.0.1:100ã®ããã«ãªããŸã ã
ã·ã¹ã³ã§ã¯ãã¿ã€ã0ããã³1ã®äœ¿çšãèš±å¯ããŠããŸãã
ã¯ããRDã¯æåã§ã»ããã¢ãããããã®ç¬èªæ§ã«æ³šæããå¿ èŠããããŸãã ãã ããä»ã®RDããã§ã«ãã®ãããªRDãæã£ãŠãããã©ãããã«ãŒã¿ãŒèªäœã远跡ããããšã¯ã§ããŸããã ãããããªããããã¯åãVPNã§ã¯ãããŸãããïŒ
ãããŠãç§ãã¡ã¯äœãåŸãŸããïŒ
1ïŒæ°ãããããã¯ãŒã¯ã®CEã¢ããŠã³ã¹ããååŸã åæãããšããã10.10.10.10 / 32ãšããŸãã PEã¯ããã®ã«ãŒããç¹å®ã®VRFã®ã«ãŒãã£ã³ã°ããŒãã«ã«è¿œå ããŸãã éåžžã®IPv4ã«ãŒãã¯ã«ãŒãã£ã³ã°ããŒãã«ã«ä¿åãããããšã«æ³šæããŠãã ãããVPNv4ã¯ãããŸããã ããã¯å¿ èŠãããŸãããåè¿°ããããã«ãVRFã¯çžäºã«åé¢ãããŠããŸããããã¯ä»®æ³ã«ãŒã¿ãŒã§ã¯ãããŸãããå¥åã®ãã®ã§ãã
2ïŒ BGPã¯ãæ°ããVPNãã¬ãã£ãã¯ã¹ãçŸããããšã«æ°ä»ããŸããã VRFæ§æããã䜿çšããRDã確èªããŸãã RDããã³æ°ããIPv4ãã¬ãã£ãã¯ã¹ãVPNv4ãã¬ãã£ãã¯ã¹ããã³ã³ãã€ã«ããŸãã 次ã®ããã«ãªããŸãã
C3POïŒ64500ïŒ100ïŒ10.10.10.10/32
ãŸãã¯ïŒ
TARSïŒ64500ïŒ200ïŒ10.10.10.10/32
3ïŒ BGPã¢ããããŒãã®äœææã«ãã«ãŒã¿ãŒã¯åä¿¡ããVPNv4ãã¬ãã£ãã¯ã¹ã次ãããã¢ãã¬ã¹ãããã³ãã®ä»ã®BGPå±æ§ãããã«æ¿å ¥ããŸãã ãããããšãããã ã©ãã«æ å ±ãNLRIãã£ãŒã«ãã«è¿œå ããŸãã ãã®ã©ãã«ã¯ã«ãŒãã«ãã€ã³ããããŸããããæ£ç¢ºã«ã¯ãVPNv4ãã¬ãã£ãã¯ã¹ã¯FECã§ããããã®FECãšã©ãã«ã®æãNLRIã«æž¡ãããŸãã
è±èªã§ã¯ãããã¯ã©ãã«ä»ãã«ãŒããšåŒã°ããŸãããã·ã¢èªã§ã¯ãããããã©ãã«ã§ããŒã¯ãããã«ãŒãã§ã ã ãã®ããããã®PEã¯ããã®ãããã¯ãŒã¯äžã®CEããIPãã±ãããåä¿¡ããå Žåããã®ãããªãµãŒãã¹ã©ãã«ãå²ãåœãŠãå¿ èŠãããããšãè¿é£ã«éç¥ããŸãã

ãã¯ã¹ããããã¢ãã¬ã¹ã«ã泚æããŠãã ãããããã¯ã«ãŒãããã¯PEã§ãã ããã¯éåžžã«çå®ã§ããå ¥åPEã¯ãåä¿¡ããããŒã¿ãã±ãããéä¿¡ããããã«å¿ èŠãªåºåPEãç¥ãå¿ èŠããããŸããã€ãŸããã«ãŒãããã¯ãšå°ãªããšããã©ãããç¥ãå¿ èŠããããŸãã
4ïŒæ¬¡ã«ãVPNv4ãã¡ããªã»ã¯ã·ã§ã³ã§èšå®ããããã¹ãŠã®ãã€ããŒã«BGPã¢ããããŒããæž¡ãããŸãã
5ïŒãªã¢ãŒãPEã¯ãã®ã¢ããããŒããåä¿¡ããNLRIã§ãããéåžžã®IPv4ã«ãŒãã§ã¯ãªããVPNv4ã§ããããšã確èªããŸãã ã¯ããèŠããŠãããŠãã ããã2ã€ã®ã«ãŒããç°ãªãã¯ã©ã€ã¢ã³ãããåããããã¯ãŒã¯ã«æ¥ãå Žåããããã¯ç°ãªãRDãæã£ãŠããããæ··åãããŸããã 次ã«ãåºåPEã¯ã ãã®ã«ãŒãããšã¯ã¹ããŒãããVRFã決å®ã ãå®éã«ãããå®è¡ããŸãã ãã®ãããã«ãŒãã¯ç®çã®VRFã®ã«ãŒãã£ã³ã°ããŒãã«ãšFIBã«è¡šç€ºãããããããã¯ã©ã€ã¢ã³ãã®ãããã¯ãŒã¯ã«æ®ããŸãã
çŸåšãPEã¯10.10.10.10/32ã®ãããã¯ãŒã¯ã«åããããŒã¿ãã±ãããCEããåä¿¡ãããšããã®VPNã®FIBã§ãµãŒãã¹ã©ãã«ïŒ22ïŒãšãã¯ã¹ããããïŒ1.1.1.1ïŒãèŠã€ããŸãã IPãMPLSã«ã«ãã»ã«åããŠããã次ã®ãããã®ãã©ã³ã¹ããŒãã©ãã«ãæ¢ãããã«æ¢ã«ã°ããŒãã«ãªFIBã調ã¹ãŸãã
ãã©ã³ã¹ããŒãã©ãã«èªäœã¯ã以åãšåæ§ã«ãLDPãŸãã¯RSVP-TEãããã³ã«ã«ãã£ãŠé ä¿¡ããããµãŒãã¹ã©ãã«ã¯MBGPã«ãã£ãŠé ä¿¡ãããŸãã
éåžžã®BGPãšMP-BGPã®NLRIãã£ãŒã«ããæ¯èŒããŸãã


ã«ãŒãã¿ãŒã²ãã
5çªç®ã®æ®µèœã§ãã€ã¿ãªãã¯äœã§ããã®ã«ãŒãããšã¯ã¹ããŒãããVRFã決å®ããããšãããã¬ãŒãºãéžæããã®ã¯ç¡é§ã§ã¯ãããŸããã ãã®åçŽãã®åŸãã«ããäžã€ã®ãã®ããããŸã-RT- ã«ãŒãã¿ãŒã²ãã ã
å®éãRDã®å¯äžã®åœ¹å²ã¯ãBGPã®å¯¿åœãå€æ§åããããšãã€ãŸãã«ãŒããäžæã«ããããšã§ãã VRFçšã«èšå®ãããŠãããšããäºå®ã«ãããããããããã¯äžæã®èå¥åã§ã¯ãªãããã¹ãŠã®æ¥ç¶ãã€ã³ãã§ãã®å€ã¯ç°ãªãå ŽåãããããŸãã ãããã£ãŠãPEã¯ã©ã®VRFã§RDããŒã¹ã®ã«ãŒããåºå®ãããã決å®ã§ããŸããã
ã¯ããããã¯å®å šã«BGPã®äŒçµ±ã§ã¯ãããŸãã-éä¿¡ãããã¢ãã¬ã¹ã解æããã«ã¯ãã©ããã§çºè¡šããåã«ãããåæããŸãã ãããã®ç®çã®ããã«ãããªã·ãŒããããŸãã
ã€ãŸããåŸæ¥ã®BGPã§ã¯ãã«ãŒããããããåå¥ã«VRFã«ãšã¯ã¹ããŒãããããã®ããªã·ãŒãåæããå¿ èŠããããŸãã ãããŠãåã«ãŒããæ¥ç¶ããå Žæãæåã§ãã£ã«ã¿ãªã³ã°ããŸãã
ç°¡çŽ åãžã®ç¬¬äžæ©ã¯ãã³ãã¥ããã£ã®äœ¿çšã§ãã ããPEããå¥ã®PEã«ã«ãŒããéä¿¡ããå Žåãç¹å®ã®ã³ãã¥ããã£ãèšå®ã§ããŸããVRFããšã«ç¬èªã®ã³ãã¥ããã£ãèšå®ãããªã¢ãŒãã³ãã¥ããã£ã®å¯Ÿå¿ããVRFã«æ¢ã«ãšã¯ã¹ããŒãã§ããŸãã ãã§ã«å¿«é©ã§èª¬åŸåããããŸãã
MBGPã¯ããã«é²ãã§ããŸã-ã³ãã¥ããã£ã®ã¢ã€ãã¢ã¯ãã«ãŒãã¿ãŒã²ããã®æŠå¿µã«åãããŠéçºãããŸããã å®éãããã¯åãã³ãã¥ããã£ã§ã-RTã¯æ¡åŒµã³ãã¥ããã£å±æ§ã§ãæž¡ããããã¹ãŠã®ããªã·ãŒã®ã¿ãèªåçã«æ©èœããŸãã
RT圢åŒã¯ãéåžžã®æ¡åŒµã³ãã¥ããã£ãšãŸã£ããåãã§ãã äŸïŒ
64500ïŒ100
ã€ãŸããRDã®æåã®ã¿ã€ãã«äŒŒãŠããŸãã ããã¯ãRDãšRTãé »ç¹ã«æ··åãããçç±ã®äžéšã§ãã
VRFã®çåŽã§ã¯ãRTãã«ãŒãããšã¯ã¹ããŒãããããã«æ§æãããŠããŸããããã¯ããªã¢ãŒãPEã«ç§»åããRTã§ãã äžæ¹ãã€ã³ããŒãããããã«èšå®ãããŠããã®ã¯åãRTå€ã§ãã ãããŠãã®éã
éåžžãã¿ã¹ã¯ã1ã€ã®ã¯ã©ã€ã¢ã³ãã®VPNãµãŒãã¹ãåçŽââã«ç·šæããããšã§ããå Žåããšã¯ã¹ããŒããšã€ã³ããŒãã®RTã¯ãã¹ãŠã®æ¥ç¶ãã€ã³ãã§äžèŽããŸãã
äŸã«æ»ããŸãã
R1ã¯R3ã«ãããã¯ãŒã¯10.10.10.10/32ïŒTARS 'RoboticsïŒãžã®ã«ãŒããéä¿¡ããã©ãã«ãšä»ã®ãã¹ãŠã®ãã©ã¡ãŒã¿ãŒã瀺ããŸããç¹ã«ãRTãæ¡åŒµã³ãã¥ããã£å±æ§ã«æžã蟌ã¿ããã®VRFïŒ64500ïŒ200ã«èšå®ãããã«ãŒãããšã¯ã¹ããŒãããŸãã
R3ã¯ãã®ã¢ããŠã³ã¹ã¡ã³ããåä¿¡ããã³ãã¥ããã£ããã§ãã¯ãã64500ïŒ200ã確èªããèšå®ããããã®RTãæã€ã«ãŒããVRF TARSã«ã€ã³ããŒãããå¿ èŠãããããšãç¥ã£ãŠããŸãã

ãããã§ããïŒ ãšã¬ã¬ã³ãïŒ ããããããã ãã§ã¯ãããŸããã ããã§ãBGPã®æè»æ§ãæããã§ãã RTã¡ã«ããºã ã䜿çšãããšãåãVPNå ããã³ç°ãªãVPNéã®äž¡æ¹ã§ãå¿ èŠã«å¿ããŠã«ãŒããã€ã³ããŒãã§ããŸãã
以äžã«2ã€ã®ã·ããªãªã瀺ããŸãã
1ïŒã¯ã©ã€ã¢ã³ãã¯ãããããã®ã¹ã¿ãŒããããžã§ã¯ãªããã¹ã¿ãŒããããžãæŽçããããšèããŠããŸãã ã€ãŸããäžå€®ãã€ã³ãã¯ãã¹ãŠã®æ¥ç¶ãã€ã³ããžã®ã«ãŒããç¥ã£ãŠããå¿ èŠããããŸããããããã¯ã»ã³ã¿ãŒãžã®ã«ãŒãã®ã¿ãç¥ã£ãŠããå¿ èŠããããŸãã ãããã£ãŠãåå²ãããã¯ã©ã€ã¢ã³ããããã¯ãŒã¯éã®çžäºäœçšã¯ãã»ã³ãã©ã«ããŒããä»ããŠå®è¡ãããŸãã ã¯ã©ã€ã¢ã³ãåŽã§äœãããããšãªã䟿å©ã§ãïŒ
解決çïŒåãã©ã³ãã«ã¯ããšã¯ã¹ããŒãçšã®ç¬èªã®RTããããŸãã ãã©ã³ãã§ã¯ãã€ã³ããŒãçšã®RTã¯ãã»ã³ãã©ã«ããŒãã§èšå®ããããšã¯ã¹ããŒãçšã®RTã§ããã€ãŸããã»ã³ã¿ãŒããã«ãŒããåä¿¡ã§ããŸãã åæã«ãã€ã³ããŒãããä»ã®ãã©ã³ãã®RTã¯ãããŸããããããã£ãŠã圌ãã¯ã«ãŒããçŽæ¥ç¢ºèªããŸããã ããããäžå€®ã§ã¯ãRTã¯ãã¹ãŠã®ãã©ã³ãã®ã€ã³ããŒãçšã«æ§æãããŠããŸããã€ãŸãããã¹ãŠããã¹ãŠåä¿¡ããŸãã
2ïŒ2ã€ã®VPNã«å ããŠã3çªç®ã®R2D2ãç»å ŽãããšããŸãã 圌ã«ã¯ããã€ãã®ã¿ã¹ã¯ããããŸãããC3PO Electronicã«å¿ èŠãªãã€ã¯ãããã»ããµãŒããã³ãã¬ãŒããè¿œå ã¢ãžã¥ãŒã«ãªã©ã®ãã¡ãŒã ãŠã§ã¢ãåãããµãŒããŒããµããŒãããŠããŸãã åæã«ã圌ã¯èªåã®ãµãŒããŒã§äžçã«èŒãããã¯ãããŸããããã¯ã©ã€ã¢ã³ãããããã€ããŒã®ãããã¯ãŒã¯ãä»ããŠã¢ã¯ã»ã¹ãæäŸããããšãæãã§ããŸãã
ãããŠãRTã䜿çšããŠãç°ãªãVPNéã®çžäºéçšæ§ãæäŸã§ããŸãã ãããè¡ãã«ã¯ãC3PO Electronicã§ããã®ãããªRTãã€ã³ããŒãçšã«æ§æããŸããããã¯ãVPN R2D2ã§ãšã¯ã¹ããŒãçšã«æå®ããããã®ã§ãã ãããŠãããã«å¿ããŠãéãåæ§ã§ãã
確ãã«ããã®å Žåã䜿çšããããµããããã亀差ãããã©ãããç£èŠããå¿ èŠããããŸãã å®éããã¹ãŠã®RDããã³RTã«ãããããããBGPã¯VRFã®åãµãããããžã®ã«ãŒãã1ã€ã ãéžæããŸãã

以äžãšã®éã§ã«ãŒãã転éããããã»ã¹ã確èªããå¿ èŠããããŸãã


ç·Žç¿ãã
äŒçµ±çã«ãå®éã«ã¯ããããŸã§ã®çè«ã®ãã¹ãŠãç¹°ãè¿ããŸãã
VRF-Lite
ããã§ã¯ãåçŽãªãã®ããè€éãªãã®ã«ç§»ããŸãããã 1ã€ã®ã¯ã©ã€ã¢ã³ãã1ã€ã®ã«ãŒã¿ãŒã«2ã€ã®æ¥ç¶ãæã£ãŠããç¶æ³ããå§ããŸãããã

æåã«ã以åãšåãããã«ãã¹ãŠãèšå®ããŠã¿ãŸãããã
LinkmeupïŒ
Linkmeup(config)# interface FastEthernet0/0 Linkmeup(config-if)# description To C3PO_1 Linkmeup(config-if)# ip address 192.168.0.1 255.255.255.0 Linkmeup(config)# interface FastEthernet0/1 Linkmeup(config-if)# description To C3PO_2 Linkmeup(config-if)# ip address 192.168.1.1 255.255.255.0
C3PO_1ïŒ
C3PO_1(config)# interface FastEthernet0/0 C3PO_1(config-if)# description To Linkmeup C3PO_1(config-if)# ip address 192.168.0.2 255.255.255.0 C3PO_1(config)#ip route 0.0.0.0 0.0.0.0 192.168.0.1
C3PO_2ïŒ
C3PO_2(config)# interface FastEthernet0/0 C3PO_2(config-if)# description To Linkmeup C3PO_2(config-if)# ip address 192.168.1.2 255.255.255.0 C3PO_2(config)# ip route 0.0.0.0 0.0.0.0 192.168.1.1
ãã©ã³ãéã®Pingã衚瀺ãããŸã-圌ãã¯ãäºããèŠãŸãã

ãã ããåæã«ãããšãã°ãã«ãŒãããã¯R1ã¢ãã¬ã¹ã衚瀺ãããŸãã

ãããã£ãŠã圌ãã¯ãããã€ããŒã®ãããã¯ãŒã¯å šäœãèŠãä»ã®ã¯ã©ã€ã¢ã³ãã®ãããã¯ãŒã¯ãèŠãŸãã
ãããã£ãŠãVRFãèšå®ããŸãã
Linkmeup(config)#ip vrf C3O
ãã®VRFã«ã¯ã©ã€ã¢ã³ããé 眮ããã«ã¯ãã€ã³ã¿ãŒãã§ãŒã¹ãVRFã«ãã€ã³ãããå¿ èŠããããŸãã
Linkmeup(config)# interface FastEthernet0/0 Linkmeup(config-if)# ip vrf forwarding C3PO % Interface FastEthernet0/0 IP address 192.168.0.1 removed due to enabling VRF C3PO
ip vrf forwarding C3POã³ãã³ããå®è¡ããåŸãIOSã¯ã€ã³ã¿ãŒãã§ã€ã¹ããIPã¢ãã¬ã¹ãåé€ãããããåæ§æããå¿ èŠãããããšã«æ³šæããŠãã ããã ããã¯ãã°ããŒãã«ã«ãŒãã£ã³ã°ããŒãã«ããæå®ããããµãããããåé€ããããã«çºçããŸããã
Linkmeup(config)# interface FastEthernet0/0 Linkmeup(config-if)# ip address 192.168.0.1 255.255.255.0 Linkmeup(config-if)#interface FastEthernet0/1 Linkmeup(config-if)# ip vrf forwarding C3PO % Interface FastEthernet0/0 IP address 192.168.1.1 removed due to enabling VRF C3PO Linkmeup(config-if)# ip address 192.168.1.1 255.255.255.0
ã¢ãã¬ã¹ãåæ§æãããšããããã®ãµããããã¯ãã§ã«VRFã«ãŒãã£ã³ã°ããŒãã«ã«è¡šç€ºãããŸãã

pingãããäžåºŠç¢ºèªããŸãã

ãã ãããããã€ããŒã¯å éšã¢ãã¬ã¹ã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã

åæ§ã®èšå®ãTARSã¯ã©ã€ã¢ã³ãã«å¯ŸããŠè¡ãå¿ èŠããããŸãã
Linkmeup(config)# ip vrf TARS Linkmeup(config-if)# interface FastEthernet1/0 Linkmeup(config-if)# ip vrf forwarding TARS Linkmeup(config-if)# ip address 100.0.0.1 255.255.255.252 Linkmeup(config-if)#interface FastEthernet1/1 Linkmeup(config-if)# ip vrf forwarding TARS Linkmeup(config-if)# ip address 100.0.1.1 255.255.255.252
ããã VRF TARSãšC3POã¯ããããã€ããŒã®ãããã¯ãŒã¯ããã³çžäºããå®å šã«åé¢ãããŠããŸãã



次ã«ãlinkmeupãããã¯ãŒã¯ã®åã³ãåºããŸãã

æåã®èšå®æé ã¯ãR1ããR3ãŸã§ã®åããŒãã§VRFãäœæããããšã§ãã
Linkmeup_R1(config)#ip vrf C3PO Linkmeup_R1(config)#ip vrf TARS
Linkmeup_R2(config)#ip vrf C3PO Linkmeup_R2(config)#ip vrf TARS
Linkmeup_R3(config)#ip vrf C3PO Linkmeup_R3(config)#ip vrf TARS
* VRFã¯ãµã€ãã®å³å¯ãªããŒã«ã«ã³ã³ã»ããã§ããããšãç解ããŠãã ããã ç°ãªãã«ãŒã¿ãŒã«ç°ãªãVRFåãèšå®ããããšãã§ããŸãã
2çªç®ã®ã¹ãããã¯ããã¹ãŠã®ããŒãéã«ãªã³ã¯ãããã¯ãŒã¯ã®ãã§ãŒã³ãäœæãã ã€ã³ã¿ãŒãã§ã€ã¹ã®åãã¢ãç®çã®VRFã«ãã€ã³ãããããšã§ãã
å³ãç ©éã«ãªããªãããã«ããªã³ã¯ã¢ãã¬ã¹ãå³ã«ç€ºããŠããŸããã 泚æã«ã¯ããããã€ããŒã®ãããã¯ãŒã¯èªäœïŒVLAN1ïŒã«10.0 / 16ãã¬ãã£ãã¯ã¹ãC3PO ElectronicïŒVlan 2ïŒã«192.168 / 16ãTARS 'RoboticsïŒVlan 3ïŒã«100.0 / 16ãéžæããŸãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#interface FastEthernet0/0 Linkmeup_R1(config-if)#description To C3PO_Electronic_1 Linkmeup_R1(config-if)#ip vrf forwarding C3PO Linkmeup_R1(config-if)#ip address 192.168.0.1 255.255.255.0 Linkmeup_R1(config)#interface FastEthernet0/1 Linkmeup_R1(config-if)#description To Linkmeup_R2 Linkmeup_R1(config-if)#ip address 10.0.12.1 255.255.255.0 Linkmeup_R1(config)#interface FastEthernet0/1.2 Linkmeup_R1(config-subif)#description to Linkmeup_R2_vrf_C3PO Linkmeup_R1(config-subif)#encapsulation dot1Q 2 Linkmeup_R1(config-subif)#ip vrf forwarding C3PO Linkmeup_R1(config-subif)#ip address 192.168.12.1 255.255.255.0 Linkmeup_R1(config)#interface FastEthernet0/1.3 Linkmeup_R1(config-subif)#description To Linkmeup_R2_in_TARS Linkmeup_R1(config-subif)#encapsulation dot1Q 3 Linkmeup_R1(config-subif)#ip vrf forwarding TARS Linkmeup_R1(config-subif)#ip address 100.0.12.1 255.255.255.0 Linkmeup_R1(config)#interface FastEthernet1/0 Linkmeup_R1(config-if)#description To TARS_1 Linkmeup_R1(config-if)#ip vrf forwarding TARS Linkmeup_R1(config-if)#ip address 100.0.0.1 255.255.255.0
ãã®ä»ã®ããŒãæ§æ
Linkmeup_R2ïŒ
Linkmeup_R3ïŒ
Linkmeup_R2(config)#interface FastEthernet0/0 Linkmeup_R2(config-if)#description To Linkmeup_R1 Linkmeup_R2(config-if)#ip address 10.0.12.2 255.255.255.0 Linkmeup_R2(config)#interface FastEthernet0/0.2 Linkmeup_R2(config-subif)#description To Linkmeup_R1_vrf_C3PO Linkmeup_R2(config-subif)#encapsulation dot1Q 2 Linkmeup_R2(config-subif)#ip vrf forwarding C3PO Linkmeup_R2(config-subif)#ip address 192.168.12.2 255.255.255.0 Linkmeup_R2(config)#interface FastEthernet0/0.3 Linkmeup_R2(config-subif)#description To Linkmeup_R1_vrf_TARS Linkmeup_R2(config-subif)#encapsulation dot1Q 3 Linkmeup_R2(config-subif)#ip vrf forwarding TARS Linkmeup_R2(config-subif)#ip address 100.0.12.2 255.255.255.0 Linkmeup_R2(config)#interface FastEthernet0/1 Linkmeup_R2(config-if)#description To Linkmeup_R3 Linkmeup_R2(config-if)#ip address 10.0.23.2 255.255.255.0 Linkmeup_R2(config)#interface FastEthernet0/1.2 Linkmeup_R2(config-subif)#description To Linkmeup_R3_vrf_C3PO Linkmeup_R2(config-subif)#encapsulation dot1Q 2 Linkmeup_R2(config-subif)#ip vrf forwarding C3PO Linkmeup_R2(config-subif)#ip address 192.168.23.2 255.255.255.0 Linkmeup_R2(config)#interface FastEthernet0/1.3 Linkmeup_R2(config-subif)#description To Linkmeup_R3_vrf_TARS Linkmeup_R2(config-subif)#encapsulation dot1Q 3 Linkmeup_R2(config-subif)#ip vrf forwarding TARS Linkmeup_R2(config-subif)#ip address 100.0.23.2 255.255.255.0
Linkmeup_R3ïŒ
Linkmeup_R3(config)#interface FastEthernet0/0 Linkmeup_R3(config-if)#description To Linkmeup_R2 Linkmeup_R3(config-if)#ip address 10.0.23.3 255.255.255.0 Linkmeup_R3(config)#interface FastEthernet0/0.2 Linkmeup_R3(config-subif)#description To Linkmeup_R2_vrf_C3PO Linkmeup_R3(config-subif)#encapsulation dot1Q 2 Linkmeup_R3(config-subif)#ip vrf forwarding C3PO Linkmeup_R3(config-subif)#ip address 192.168.23.3 255.255.255.0 Linkmeup_R3(config)#interface FastEthernet0/0.3 Linkmeup_R3(config-subif)#description To Linkmeup_R2_vrf_TARS Linkmeup_R3(config-subif)#encapsulation dot1Q 3 Linkmeup_R3(config-subif)#ip vrf forwarding TARS Linkmeup_R3(config-subif)#ip address 100.0.23.3 255.255.255.0 Linkmeup_R3(config)#interface FastEthernet0/1 Linkmeup_R3(config-if)#description To C3PO_2 Linkmeup_R3(config-if)#ip vrf forwarding C3PO Linkmeup_R3(config-if)#ip address 192.168.1.1 255.255.255.0 Linkmeup_R3(config)#interface FastEthernet1/0 Linkmeup_R3(config-if)#description To TARS_2 Linkmeup_R3(config-if)#ip vrf forwarding TARS Linkmeup_R3(config-if)#ip address 100.0.1.1 255.255.255.0
3çªç®ã¯ãVRFã§IGPãäžããããšã§ãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#router ospf 2 vrf C3PO Linkmeup_R1(config-router)#network 192.168.0.0 0.0.255.255 area 0 Linkmeup_R1(config)#router ospf 3 vrf TARS Linkmeup_R1(config-router)#network 100.0.0.0 0.0.255.255 area 0 Linkmeup_R1(config)#router isis 1 Linkmeup_R1(config-router)#net 10.0000.0000.0001.00 Linkmeup_R1(config)#interface FastEthernet0/1 Linkmeup_R1(config-if)#ip router isis 1
ãã®ä»ã®ããŒãæ§æ
Linkmeup_R2 ïŒ
Linkmeup_R3 ïŒ
Linkmeup_R2(config)#router ospf 2 vrf C3PO Linkmeup_R2(config-router)#network 192.168.0.0 0.0.255.255 area 0 Linkmeup_R2(config)#router ospf 3 vrf TARS Linkmeup_R2(config-router)#network 100.0.0.0 0.0.255.255 area 0 Linkmeup_R2(config)#router isis 1 Linkmeup_R2(config-router)#net 10.0000.0000.0001.00 Linkmeup_R2(config)#interface FastEthernet0/0 Linkmeup_R2(config-if)#ip router isis 1 Linkmeup_R2(config)#interface FastEthernet0/1 Linkmeup_R2(config-if)#ip router isis 1
Linkmeup_R3 ïŒ
Linkmeup_R3(config)#router ospf 2 vrf C3PO Linkmeup_R3(config-router)#network 192.168.0.0 0.0.255.255 area 0 Linkmeup_R3(config)#router ospf 3 vrf TARS Linkmeup_R3(config-router)#network 100.0.0.0 0.0.255.255 area 0 Linkmeup_R3(config)#router isis 1 Linkmeup_R3(config-router)#net 10.0000.0000.0001.00 Linkmeup_R3(config)#interface FastEthernet0/0 Linkmeup_R3(config-if)#ip router isis 1
ãããã€ããŒã®å éšãããã¯ãŒã¯æ¥ç¶çšã®ISISãVPNçšã®OSPFã
OSPFãã¯ã©ã€ã¢ã³ããšãšãã«äžæãããããã¯ã©ã€ã¢ã³ãã¯ã«ãŒããåçã«åŠç¿ããŸãã ãããã£ãŠã次ã®ãããªãã¶ã€ã³ã«ããå¿ èŠããããŸãã
C3PO_1(config)# router ospf 1 C3PO_1(config-router)# network 192.168.0.0 0.0.255.255 area 0
å®éã«ã¯ãã¹ãŠã ããã§ãåãããã¯ãŒã¯ã¯ãã®ã«ãŒããèªèããŸãã


ååãšããŠã1ã€ã®ç©çãããã¯ãŒã¯ã«åºã¥ããŠã3ã€ã®å®å šã«ç¬ç«ããä»®æ³ãããã¯ãŒã¯ãäœæããŸããããã®å éšã§ã¯ãå°ãªããšãäœã§ãMPLSãäžããããšãã§ããŸãã
ãã ããåè¿°ããããã«ãããã¯éåžžã«äžæŽ»æ§ãªãœãªã¥ãŒã·ã§ã³ãªã®ã§ãMPLS BGP VPNã«é²ã¿ãŸãããã
MPLS L3VPN
ä»åã¯ããã¹ãŠãäºåã«æ§æãããŠããæ¢è£œã®ãããã¯ãŒã¯ã䜿çšããªãããšããå§ãããŸãã ãã€ã«ã¹ããŒã³ã ãã§ã詳现ã«å ¥ããã«ãã®æ¹æ³ã§ãŒãããå§ããæ¹ãããèå³æ·±ãã§ãããã
ãã®ãããåããããã¯ãŒã¯ãèŠãããŠããŸããã1ã€ã®ãã©ã³ããåé€ããããšã§åçŽåããŸãã

1ã€ã®ã¯ã©ã€ã¢ã³ããš2ã€ã®æ¥ç¶ãã€ã³ãããå§ããŸãããã
ã¯ã©ã€ã¢ã³ãã«ãŒã¿ãŒã®æ§æã¯éåžžã«åçŽã§ãã
C3PO_1ïŒ
C3PO_1(config)# interface Loopback0 C3PO_1(config-if)# ip address 192.168.255.1 255.255.255.255 C3PO_1(config)# interface FastEthernet0/0 C3PO_1(config-f)# description To Linkmeup C3PO_1(config-if)# ip address 192.168.0.2 255.255.255.0 C3PO_1(config)# router ospf 1 C3PO_1(config-router)# network 192.168.0.0 0.0.255.255 area 0
C3PO_2ïŒ
C3PO_1(config)# interface Loopback0 C3PO_1(config-if)# ip address 192.168.255.2 255.255.255.255 C3PO_1(config)# interface FastEthernet0/0 C3PO_1(config-f)# description To Linkmeup C3PO_1(config-if)# ip address 192.168.1.2 255.255.255.0 C3PO_1(config)# router ospf 1 C3PO_1(config-router)# network 192.168.0.0 0.0.255.255 area 0
ã¯ã©ã€ã¢ã³ãããŒãã§ã¯ããããã€ããŒããã³ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ãšã®ãªã³ã¯ã¢ãã¬ã¹ãæ§æãããŸãïŒä»¥åãšåæ§ããã®ã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠãã«ãŒã¿ãŒãäœæããªãããã«ãããã¯ãŒã¯ãã·ãã¥ã¬ãŒãããŸãïŒã ã€ãŸãã C3PO_2ã§ãããã¯ãŒã¯192.168.255.1/32ã衚瀺ãããå Žåãããã¯ãããã¯ãŒã¯å šäœã衚瀺ãããããšãæå³ããŸãã
OSPFã¯ãããŒã«ã«ã®åçã«ãŒãã£ã³ã°ãããã³ã«ãšããŠäœ¿çšãããŸãã å®éãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®ã¢ãã¬ã¹ãé¢ä¿è ã«ç¥ãããã®ã¯åœŒã§ãã
ãããã¯ãŒã¯ãããã€ããŒã«ã€ããŠã¯ã
ãŸããçãã»ããã¢ããæé ã瀺ãã次ã«äŸã瀺ããŸãã
- ãã©ã³ã¯ãããã¯ãŒã¯ã®åºæ¬çãªæ¥ç¶ã®æ§æïŒIPã¢ãã¬ã¹ãIGPã
- MPLSããã³LDPãæå¹ã«ãã
- VRFãäœæããã€ã³ã¿ãŒãã§ã€ã¹ã«ãã€ã³ãããŸãã
- CEã§ã«ãŒãã£ã³ã°ãããã³ã«ãæ§æããŸãã
- BGPãšMBGPãæ§æãã
1ïŒ IPã¢ãã¬ã¹ãæ§æããŸãïŒãªã³ã¯ãšã«ãŒãããã¯ã ã¯ã©ã€ã¢ã³ãã«ã¯ãŸã 觊ããŠããŸããã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#interface Loopback0 Linkmeup_R1(config-if)#ip address 1.1.1.1 255.255.255.255 Linkmeup_R1(config)#interface FastEthernet0/1 Linkmeup_R1(config-if)#description To Linkmeup_R2 Linkmeup_R1(config-if)#ip address 10.0.12.1 255.255.255.0
Linkmeup_R2 ïŒ
Linkmeup_R2(config)#interface Loopback0 Linkmeup_R2(config-if)#ip address 2.2.2.2 255.255.255.255 Linkmeup_R2(config)#interface FastEthernet0/0 Linkmeup_R2(config-if)#description To Linkmeup_R1 Linkmeup_R2(config-if)#ip address 10.0.12.2 255.255.255.0 Linkmeup_R2(config)#interface FastEthernet0/1 Linkmeup_R2(config-if)#description To <i>Linkmeup_R3</i> Linkmeup_R2(config-if)#ip address 10.0.23.2 255.255.255.0
Linkmeup_R3 ïŒ
Linkmeup_R3(config)#interface Loopback0 Linkmeup_R3(config-if)#ip address 3.3.3.3 255.255.255.255 Linkmeup_R3(config)#interface FastEthernet0/0 Linkmeup_R3(config-if)#description To Linkmeup_R2 Linkmeup_R3(config-if)#ip address 10.0.23.3 255.255.255.0
åææ§æãã¡ã€ã«ã
2ïŒ ISISãIGPãšããŠæèµ·ããŸãããªã³ã¯ããã³ã«ãŒãããã¯ã¢ãã¬ã¹ã«é¢ããã«ãŒãã£ã³ã°æ å ±ãé åžããããšã«ãããlinkmeupãããã¯ãŒã¯å šäœãæ¥ç¶ããŸãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#router isis 1 Linkmeup_R1(config-router)#net 10.0000.0000.0001.00 Linkmeup_R1(config)#interface FastEthernet 0/1 Linkmeup_R1(config-if)#ip router isis 1
Linkmeup_R2 ïŒ
Linkmeup_R2(config)#router isis 1 Linkmeup_R2(config-router)#net 10.0000.0000.0002.00 Linkmeup_R2(config)#interface FastEthernet 0/0 Linkmeup_R2(config-if)#ip router isis 1 Linkmeup_R2(config)#interface FastEthernet 0/1 Linkmeup_R2(config-if)#ip router isis 1
Linkmeup_R3 ïŒ
Linkmeup_R3(config)#router isis 1 Linkmeup_R3(config-router)#net 10.0000.0000.0002.00 Linkmeup_R3(config)#interface FastEthernet 0/0 Linkmeup_R3(config-if)#ip router isis 1
ãã®ã¹ãããã§ã次ã®ã¹ãããã«å¿ èŠãªãã©ãããã©ãŒã ã§ããã°ããŒãã«ã«ãŒãã£ã³ã°ããŒãã«ãååŸããŸããã

3ïŒ MPLSããã³LDPããªã³ã«ããŸãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#mpls ip Linkmeup_R1(config)#interface FastEthernet 0/1 Linkmeup_R1(config-if)#mpls ip
Linkmeup_R2 ïŒ
Linkmeup_R2(config)#mpls ip Linkmeup_R2(config)#interface FastEthernet 0/0 Linkmeup_R2(config-if)#mpls ip Linkmeup_R2(config)#interface FastEthernet 0/1 Linkmeup_R2(config-if)#mpls ip
Linkmeup_R3 ïŒ
Linkmeup_R3(config)#mpls ip Linkmeup_R3(config)#interface FastEthernet 0/0 Linkmeup_R3(config-if)#mpls ip
ãã®ã¹ãããã§ã¯ããã¹ãŠã®LSRãã¢éã«LSPãæ§ç¯ããŸããã

* Linkmeup_R1ã®ããŒã¯å²ãåœãŠã®äŸã
ãããVPNã®åºç€ã§ãã ãããã®LSPã¯ããã©ã³ã¹ããŒãã©ãã«ã®ã»ããã§ãã
ããã§ã¯ãæ§æãè€éã«ããªãããã«LDPãéžæããŸããã ãŸãããã©ãã£ãã¯ãšã³ãžãã¢ãªã³ã°ã«é¢ããèšäºã§RSVP-TEãæ±ã£ãŠããŸãã
4ïŒ 2ã€ã®ããŒãLinkmeup_R1ããã³Linkmeup_R3㧠VRFãäœæããŸãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#ip vrf C3PO Linkmeup_R1(config-vrf)# rd 64500:100 Linkmeup_R1(config-vrf)# route-target both 64500:100
Linkmeup_R3 ïŒ
Linkmeup_R3(config)#ip vrf C3PO Linkmeup_R3(config-vrf)# rd 64500:100 Linkmeup_R3(config-vrf)# route-target both 64500:100
ããã«ãããããã¯ã©ã€ã¢ã³ãã®ãã¹ãŠã®ããŒã¿ããä»ã®ã¯ã©ã€ã¢ã³ãããããã€ããŒã®ãããã¯ãŒã¯ããåé¢ã§ããŸãã
ããã§ã¯ãRDãšRTã瀺ããŸãã ã¿ã¹ã¯ã¯åçŽãªã®ã§ãC3PO Electronicã®ãã¹ãŠã®ãã©ã³ããæ¥ç¶ãããããRDãšRTãåãã«ããŸãã ããã«ãã€ã³ããŒãæã®RTãšãšã¯ã¹ããŒãæã®RTãåãã«ãªããŸãã ããã¯äžè¬çãªæ £è¡ã§ãããããç¹å¥ãªãã£ã¬ã¯ãã£ããããããŸã- äž¡æ¹ -ãããŠãäž¡æ¹ã®RTã¯ããã«åãããã«äœæãããŸãã
第8å·ã§ã¯ãlinkmeupãããã¯ãŒã¯ã®ASçªå·64500ãéžæããŸãããããã¯ã管çãã£ãŒã«ããšããŠã䜿çšãããŸãã
å²ãåœãŠãããçªå·ã¯ä»»æã«éžæãããŸããããã§ã«äœ¿çšãããŠããå¥ã®çªå·ãšäžèŽããªãããã«ç£èŠãããŸãã
5ïŒã€ã³ã¿ãŒãã§ã€ã¹ãVRFã«ãã€ã³ããããããã®IPã¢ãã¬ã¹ãæå®ããŸãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#interface FastEthernet0/0 Linkmeup_R1(config-if)# description To C3PO_Electronic_1 Linkmeup_R1(config-if)# ip vrf forwarding C3PO Linkmeup_R1(config-if)#ip address 192.168.0.1 255.255.255.0
Linkmeup_R3 ïŒ
Linkmeup_R3(config)#interface FastEthernet0/1 Linkmeup_R3(config-if)# description To C3PO_Electronic_2 Linkmeup_R3(config-if)# ip vrf forwarding C3PO Linkmeup_R3(config-if)#ip address 192.168.1.1 255.255.255.0
VRF C3POã«ãŒãã£ã³ã°ããŒãã«ã§ã¯ãèšå®ããããããã¯ãŒã¯ã¯çŽæ¥æ¥ç¶ãããŠããããã«èŠããã¯ãã§ãã


6ïŒã¯ã©ã€ã¢ã³ãã§ã«ãŒãã£ã³ã°ãããã³ã«ãäžããå¿ èŠããããŸãã ç§ãã¡ã®å Žåãããã¯OSPFã«ãªããŸãããåæ§ã«æåããå Žåã¯ISISãŸãã¯EBGPã«ãªããŸãã ãã®ããã»ã¹ã¯ã°ããŒãã«ã«ãŒãã£ã³ã°ããŒãã«ãšéè€ããªãããã«ãããããVRFã«é 眮ããŸãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#router ospf 2 vrf C3PO Linkmeup_R1(config-router)# network 192.168.0.0 0.0.255.255 area 0
Linkmeup_R3 ïŒ
Linkmeup_R3(config)#router ospf 2 vrf C3PO Linkmeup_R3(config-router)# network 192.168.0.0 0.0.255.255 area 0
OSPFã¯ã©ã€ã¢ã³ããæ¢ã«æ§æãããŠããããšãèæ ®ãããšãã«ãŒãã£ã³ã°ããŒãã«ã«ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã¢ãã¬ã¹ã衚瀺ãããã¯ãã§ãã


ã芧ã®ãšããã Linkmeup_R1ã«ã¯192.168.255.1ã衚瀺ãããŸããããªã¢ãŒãã«ãŒãããã¯-192.168.255.2ã¯è¡šç€ºãããŸããã åæ§ã«ã Linkmeup_R3ã¯ãäžéšã®ã«ãŒãã®ã¿ãèªèããŸãã ããã¯ãã¯ã©ã€ã¢ã³ãã®ã«ãŒãããŸã ãããã€ããŒã®ãããã¯ãŒã¯ãä»ããŠéä¿¡ãããŠããªãããã§ãã
7ïŒããã§ãMBGPã®æãæ¥ãŸããã
ååã®ãªãªãŒã¹ã§BGP Free Coreã«ã€ããŠè©±ããããšãèŠããŠããŸããïŒ ããã§ãã®ææ³ãããŸã䜿çšã§ããŸãã Linkmeup_R2㧠BGPã¯å¿ èŠãããŸãã-ããã§äžããããšã¯ãããŸããã
æåã®éšåã¯ãiBGPãã€ããŒã®åºæ¬èšå®ã§ãã
Linkmeup_R1 ïŒ
Linkmeup_R1(config)#router bgp 64500 Linkmeup_R1(config-router)# neighbor 3.3.3.3 remote-as 64500 Linkmeup_R1(config-router)# neighbor 3.3.3.3 update-source Loopback0
Linkmeup_R3ïŒ
Linkmeup_R3(config)#router bgp 64500 Linkmeup_R3(config-router)# neighbor 1.1.1.1 remote-as 64500 Linkmeup_R3(config-router)# neighbor 1.1.1.1 update-source Loopback0
ã¢ãã¬ã¹ãã¡ããªVPNv4ãèšå®ãã2çªç®ã®éšåã¯ãLinkmeup_R1ããLinkmeup_R3ãžã®ã¯ã©ã€ã¢ã³ãã«ãŒããèš±å¯ãããã®ã§ãããã®å±æ§ã¯RTã«ãã£ãŠäœ¿çšããããããã³ãã¥ããã£è»¢éãã¢ã¯ãã£ãã«ããŠããããšã«æ³šæããŠãã ããã
Linkmeup_R1ïŒ
Linkmeup_R1(config-router)# address-family vpnv4 Linkmeup_R1(config-router-af)# neighbor 3.3.3.3 activate Linkmeup_R1(config-router-af)# neighbor 3.3.3.3 send-community both
Linkmeup_R3ïŒ
Linkmeup_R3(config-router)# address-family vpnv4 Linkmeup_R3(config-router-af)# neighbor 1.1.1.1 activate Linkmeup_R3(config-router-af)# neighbor 1.1.1.1 send-community both
3çªç®ã®éšåã¯ããã®ç¹å®ã®VRFã®ã¢ãã¬ã¹ãã¡ããªã§ããéåžžã®IPv4ãã¬ãã£ãã¯ã¹ã§åäœããŸãããVRF C3PO Electronicããã§ããMBGPãšOSPFã®éã§ã«ãŒãã転éããããã«å¿ èŠã§ãã
Linkmeup_R1ïŒ
Linkmeup_R1(config-router)# address-family ipv4 vrf C3PO Linkmeup_R1(config-router-af)# redistribute connected Linkmeup_R1(config-router-af)# redistribute ospf 2 vrf C3PO
Linkmeup_R3ïŒ
Linkmeup_R3(config-router)# address-family ipv4 vrf C3PO Linkmeup_R3(config-router-af)# redistribute connected Linkmeup_R3(config-router-af)# redistribute ospf 2 vrf C3PO
ã芧ã®ãšãããOSPFããã»ã¹ããã®ã«ãŒã2ã®
ã€ã³ããŒãã¯ããã§èšå®ãããŠãããããBGPããOSPFãžã®ã«ãŒãã®ã€ã³ããŒããèšå®ããå¿ èŠããããŸãïŒ
Linkmeup_R1ïŒ
Linkmeup_R1(config)#router ospf 2 Linkmeup_R1(config-router)# redistribute bgp 64500 subnets
Linkmeup_R3ïŒ
Linkmeup_R3(config)#router ospf 2 Linkmeup_R3(config-router)# redistribute bgp 64500 subnets
ãããŠä»ããã¹ãŠãå転ããŸãã
PEäžã®ã«ãŒãïŒ


CEäžã®ã«ãŒãïŒ

ã¯ã©ã€ã¢ã³ããããã¯ãŒã¯éã®

PingïŒãããã€ããŒãããã¯ãŒã¯ãžã®Pingã®è©Šè¡ïŒ

ããã¯è¯ãããšã§ãã
BGP
ãä»ããã¯ã©ã€ã¢ã³ãã®æ¥ç¶æ¬¡ã«ãTAR'S Roboticsã¯ã©ã€ã¢ã³ããæ¥ç¶ããŸããCEãšPEéã®ã«ãŒãã¯ãBGPãä»ããŠéä¿¡ãããŸããã€ãŸããã¯ã©ã€ã¢ã³ãã«ãŒã¿ãŒã§EBGPãäžããŸãã
ã¹ããã4ãš5ã«éãã¯ãããŸãããçåŽã®ã¿ã®æ§æã¯æ¬¡ã®ãšããã§ãã
Linkmeup_R1(config)#ip vrf TARS Linkmeup_R1(config-vrf)#rd 64500:200 Linkmeup_R1(config-vrf)#route-target export 64500:200 Linkmeup_R1(config-vrf)#route-target import 64500:200 Linkmeup_R1(config)#interface FastEthernet1/0 Linkmeup_R1(config-if)#description To TARS_1 Linkmeup_R1(config-if)#ip vrf forwarding TARS Linkmeup_R1(config-if)#ip address 100.0.0.1 255.255.255.0
6ïŒ CEã§ã¯ãEBGPã¯æãäžè¬çãªæ¹æ³ã§æ§æãããŸãã
TARS_1ïŒ
TARS_1(config)#router bgp 64510 TARS_1(config-router)#network 172.16.255.1 mask 255.255.255.255 TARS_1(config-router)#neighbor 100.0.0.1 remote-as 64500
TARS 'Roboticsã¯172.16.255.1/32ãããã¯ãŒã¯ãçºè¡šãããšè¿°ã¹ãŠããŸãã
OSPFã¯ãŸã å¿ èŠãããããŸãããããã®ãã©ã³ãå ãªã©ã§ã®ã«ãŒãã£ã³ã°ã«æ¢ã«äœ¿çšãããŠããŸãã
PEã§ã¯ãã¹ãŠãåãã§ãããæ°ããOSPFããã»ã¹ã¯ãªãïŒã¯ã©ã€ã¢ã³ããOSPFã®ä»£ããã«EBGPã䜿çšããŠããããïŒãã¢ãã¬ã¹ãã¡ããªipv4 vrf TARSïŒ
Linkmeup_R1ãå€æŽãããŸãã
Linkmeup_R1(config-router)#address-family ipv4 vrf TARS Linkmeup_R1(config-router-af)#redistribute connected Linkmeup_R1(config-router-af)#neighbor 100.0.0.2 remote-as 64510 Linkmeup_R1(config-router-af)#neighbor 100.0.0.2 activate
ä»Linkmeup_R1ã¯ã BGP-é£äººã§ããTARS_1ïŒ

ã¯ã©ã€ã¢ã³ãã®ãããã¯ãŒã¯ã¯ããããCEæŽæ°ã¡ãã»ãŒãžããåä¿¡ããŸãã
7ïŒ MBGPã®ãã¹ãŠã¯åãã§ããã¯ã©ã€ã¢ã³ããšã®çžäºäœçšã®ãããã³ã«ãå€æŽãããšããäºå®ããããã®äžã§äœãéããŸã«ãªãããšã¯ãããŸããã
ã€ãŸãããã¹ãŠãåäœããã¯ãã§ãïŒãã¡ããã2çªç®ã®åŽãæ§æãããŠããå ŽåïŒïŒã³ã¡ã³ãä»ãããã³ã³ã¡ã³ããªã



ã§ãã¹ãŠã®ããŒãã®æ§æãå®äºããŸãã
ç§ãã¡ã¯äœãããŸãããïŒ
ããã§ã¯ãã¿ã°ã®ååžãè¿œã£ãŠã¿ãŸãããã
ããã¯äžãããã®ã Linkmeup_R1ã¯ãããŒãLinkmeup_R3ãã

ããã§ã¯ãFEC 192.168.255.1ã®ã©ãã«22ãšNext Hop 1.1.1.1ã®ã¢ãã¬ã¹ã衚瀺ãããŸãã
ã«ãŒã¿ãŒã¯ã©ã®ããã«ãããç解ããŸããïŒ
VRF C3PO TMã§ã¯ã次ã®ãããã«é¢ããæ å ±ãå ¥åããŸãïŒ

ååž°çã«å©çšå¯èœãªæ¹æ³ãèšç®ããŸã

1.1.1.1ïŒVRF C3POã®BGPããŒãã«ã§ãµãŒãã¹ã¿ã°ã確èªã§ããŸãïŒ

ãšããã§ã次ã®ããããããã«è¡šç€ºãããŸãã
ïŒãã©ã³ã¹ããŒãFEC 1.1.1.1ã®ã©ãã«

ã®éåžžã®FIBã¯ãTMãžã®è€æ°ã®åŒã³åºãããã«ãã¹ãŠã®é¢é£æ å ±ãå«ãŸããŠãããšããŠã§ã¯ãªããïŒ

FIBã¯ããšè¢ãããã¯ããããã«ç§ãã¡ã«èªã£ãŠããDIP192.168.255.1ãã©ãã«ã¹ã¿ãã¯{17ã22}ã«éä¿¡ããFE0 / 0ã€ã³ã¿ãŒãã§ã€ã¹ã®ãµã€ã10.0.23.2ã«éä¿¡ããŸãã
ããã«ãããã®ã¯ãã¹ãŠéåžžã«æ確ã§æ±ºãŸã£ãŠããŸãã
äžè¬ããç¹å®ãžã®æ£ããé åºã§L3VPNãæåããèšå®ããæé ãèŠçŽããŸãããã
- ãããã€ããŒã®IPã¢ãã¬ã¹ãæ§æããŸãïŒãªã³ã¯ãšã«ãŒãããã¯ããã¹ãŠã®ããŒããæ§æãããå¿ããŠããŸããã
- ãããã€ããŒã®ãããã¯ãŒã¯ã§IGPãæ§æããŠãå éšæ¥ç¶ãæäŸããŸãããã¹ãŠã®ããŒããæ§æãããå¿ããŠããŸããã
- MPLS + LDPïŒãŸãã¯å¿ èŠã«å¿ããŠRSVP TEïŒãæ§æããŸãããã¹ãŠã®ããŒããæ§æãããå¿ããŠããŸããã
- ãããã€ããŒã®ãããã¯ãŒã¯å ã§MBGPãæ§æããŸããã¯ã©ã€ã¢ã³ããæã€PEã®ã¿ãæ§æãããå¿ããããŸãã
- ã¯ã©ã€ã¢ã³ãVRFãæ§æããRDãRTãå²ãåœãŠãŸããã¯ã©ã€ã¢ã³ãããããããã®PEã ããããããã«åå¥ã«æ§æãããŸãã
- ã¯ã©ã€ã¢ã³ãã€ã³ã¿ãŒãã§ã€ã¹ãVRFã«è¿œå ããIPã¢ãã¬ã¹ãæ§æããŸããã¯ã©ã€ã¢ã³ãããããããã®PEã ããããããã«åå¥ã«æ§æãããŸãã
- å¿ èŠã«å¿ããŠãã¯ã©ã€ã¢ã³ããšIGP / BGPãäžããŠã«ãŒãã亀æããŸããã¯ã©ã€ã¢ã³ãããããããã®PEã ããããããã«åå¥ã«æ§æãããŸãã
- å®äº
ãããã¯ãããŒã¹L3VPNãæ§æããããã«å¿ èŠãã€ååãªæé ã§ããã
ããŠãå®éã®æåŸã®ã·ããªãªã¯
VPNçžäºéçšæ§
ããã®ã©ãã-ã¯ããäž-C3POã®ããã€ãã®ãã¥ãŒãæã€3çªç®ã®ã¯ã©ã€ã¢ã³ãR2D2ã®ååšãæ³å®ããŸãããå ·äœçã«ã¯ãç°ãªãVPNã«ããéã«ã«ãŒãã亀æããå¿ èŠããããŸãã
ã¹ããŒã ã¯æ¬¡ã®ãšããã§ããããã§RTã䜿çšããŸããVPNC3POããã®ã«ãŒãããBGPãããã³ã«ã䜿çšããŠR2D2ã«è»¢éããŸããããŠããããŠæ»ã-ãããªãã§ã©ãã«ïŒR2D2ã«ãŒã¿ãŒã®æ§æïŒ

R2D2(config)#interface Loopback0 R2D2(config-if)#ip address 10.22.22.22 255.255.255.255 R2D2(config)#interface FastEthernet0/0 R2D2(config-if)#description To Linkmeup R2D2(config-if)#ip address 10.22.22.2 255.255.255.252 R2D2(config)#router ospf 1 R2D2(config-router)#network 10.22.22.0 0.0.0.255 area 0
Linkmeup_R3ã® VRFã»ããã¢ããïŒ
Linkmeup_R3(config)#ip vrf R2D2 Linkmeup_R3(config-vrf)#rd 64500:300 Linkmeup_R3(config-vrf)#route-target both 64500:300 Linkmeup_R3(config-vrf)#route-target import 64500:100 Linkmeup_R3(config-router)#interface FastEthernet1/1 Linkmeup_R3(config-if)#ip vrf forwarding R2D2 Linkmeup_R3(config-if)#ip address 10.22.22.1 255.255.255.252 Linkmeup_R3(config-vrf)#router ospf 3 vrf R2D2 Linkmeup_R3(config-router)#redistribute bgp 64500 subnets Linkmeup_R3(config-router)#network 10.22.22.0 0.0.0.3 a 0 Linkmeup_R3(config)#router bgp 64500 Linkmeup_R3(config-router)#address-family ipv4 vrf R2D2 Linkmeup_R3(config-router-af)#redistribute ospf 3
å®éãVRFã§route-targetãèšå®ããããšãé€ããŠãããã«ã¯æ°ãããã®ã¯ãããŸããã
ã芧ã®ãšãããéåžžã®ãroute-target both 64500ïŒ300ãã³ãã³ãã«å ããŠããroute-target import 64500ïŒ100ããæå®ããŸãããã€ãŸããVRFã§ã¯ãRT 645500ïŒ100ã®ã«ãŒããã€ã³ããŒãããå¿ èŠããããŸããã€ãŸããVPN C3POããå¿ èŠã«å¿ããŠã€ã³ããŒãããå¿ èŠããããŸãã
ãã®çŽåŸã«ã«ãŒããäžã«è¡šç€ºããR2D2ïŒ

ïŒãã®åŸãpingã192.168.255.2ã«æž¡ã

ãããªããã¢ãã¬ã¹192.168.255.1ãžã®pingãå®è¡ããå Žåãããã¯åäœããŸããããããããªãã§ïŒ

楜ãã¿ã®ããã«ãã¢ãã¬ã¹10.20.22.22/32 ã§TARS_2 Loopback 1ãè¿œå ã§ããŸããããã¯Loopback 0 R2D2ãšåãã§ãäœãèµ·ãããã確èªã§ããŸãã
VPNéã®çžäºäœçšã®ã·ããªãªã®ãã¹ãŠã®ããŒãã®å®å šãªæ§æã
VPNããã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹
ãããã€ããŒãåãVPNãžã®ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹ãæäŸããŠããããšãå€æããå ŽåããããŸããVPNå ã«ãããåå¥ã®ã±ãŒãã«ã§ããåå¥ã®VLANã§ããããŸãããã€ãŸããåãæ¥ç¶ãåãã¢ãã¬ã¹ãä»ããã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ã§ãããŸãã顧客ã®æ°ãŸãããããããŸããã
ãã®ãããã¯ã¯èå³æ·±ããã倧èŠæš¡ãªã®ã§ãå°ãåŸã§å¥ã®ãã€ã¯ãã€ã·ã¥ãŒã§å ¬éããŸãã
MPLS L3VPNã®ãã¬ãŒã¹
çŽ1幎åãç§ã¯ã¡ãã£ãšãã質åã®ããå°ããªèšäºãæžããŸããã
ãã®äžã ã£ã1ãç§ãã¡ã«ãšã£ãŠéåžžã«å±æã
ãããæ¹åããæãæ¥ãŸããã
çªç¶ãéåžžã®ãã¬ãŒã¹ãã©ã®ããã«æ©èœããããç¥ããªãã£ãå Žåã¯ãç°¡åã«
TTLå€ãåŸã ã«å¢ãããŠãåä¿¡è ã«ãã±ãããéä¿¡ããŸããéåžžã¯UDPã§ãããICMPãTCPã§ãããŸããŸããã
æåã¯1ã§ãããã±ããã¯ãçŽæ¥æ¥ç¶ãããã«ãŒã¿ãŒã«å°éããTTLãæžãããçŸåšãŒãã«ãªã£ãŠããããšã確èªããŠãã転éäžã®æéè¶ éãã¡ãã»ãŒãžãçæããè¿ä¿¡ããŸãããããã£ãŠãéä¿¡è ã®ã¢ãã¬ã¹ã§ã¯ãæåã®ããããããããŸãã
ãã®åŸãããã¯2ã§ãããã±ããã¯2çªç®ã®ã«ãŒã¿ãŒã«å°éããŸããåãããšãèµ·ããã®ã§ã次ã®ããããèªèããŸãã
...
æåŸã«ãTTLãNã«å°éãããšãå®å ããŒãã¯ãã±ãããåä¿¡ããããããã±ããã§ããããšã確èªããïŒãããã³ã«ã«åŸã£ãŠïŒå¿çã圢æããŸããããã«ããããã¹ãŠãçµäºããããšãããããã³ã³ãœãŒã«ã§çµäºããŸãã
ããã«ãå埩ããšã«1ã€ã§ã¯ãªãè€æ°ã®ãã±ããïŒéåžžã¯3ã€ïŒãéä¿¡ã§ããŸãã
L3VPNãä»ãããã¬ãŒã¹ã®ç¹ç°æ§ã¯äœã§ããïŒ
ãã±ããã¯ã©ãã«ã«ãã£ãŠã¹ã€ããã³ã°ãããŸãããMPLSãããæ·±ãããããŒã®ãã£ãŒã«ãã®å€ã«ã¯æå³ããããŸãããTTLãå«ããã«ãŒã¿ãŒã¯ãMPLSããããŒã®TTLãã¿ãŒã²ããã«ããŸãã
PEãCEãããã±ãããåä¿¡ãããšãã2ã€ã®ãªãã·ã§ã³ããããŸãïŒ
- TTLå€ãIPããããŒããMPLSã«ã³ããŒããŸãïŒããã¯åäžã¢ãŒãã§ãïŒã
- TTL MPLSããããã£ãŒã«ã255ïŒãã®ã¢ãŒããžã®ã©ã€ããã€ãåã¯ã·ã§ãŒããã€ãïŒã
æåã®ã·ããªãªã§ã¯ãåä¿¡è ã«åããéäžã§åã«ãŒã¿ãŒãèŠãããšãã§ããŸãããã¬ãŒã¹ã®çµæã¯

次ã®ããã«ãªããŸããã¡ã«ããºã ã¯æ¬¡ã®ãšããã§ãã
- æåã®ã¹ãããã§ã¯ãäœãå€ãããŸãããTARS_1ã¯ãTTL = 1ã®ICMPèŠæ±ãéä¿¡ããŸããR1ã¯ãããåä¿¡ããTTLããŒãã«æžãããŠãTARS_1 ãéä¿¡äžã®æéè¶ éãã«éä¿¡ããŸããæåã®ãããïŒR1ïŒã®æºåãã§ããŸããã
- TARS_1ã¯ãTTL = 2ã®ICMPèŠæ±ãéä¿¡ããŸãã
- TARS_1ã¯ãTTL = 3ã®ICMPèŠæ±ãéä¿¡ããŸããR3ã«å°éããçŸåš1ã«çããMPLS TTLå€ã確èªããŠ0ã«æžãããã転éäžã®æéè¶ éããè¿ããŸãã
- TARS_1ã¯ãTTL = 4ã®ICMPèŠæ±ãéä¿¡ããŸããR3ã¯MPLS TTLã1ã«æžãããã©ãã«ãåé€ããMPLS TTLå€ãIP TTLã«ã³ããŒããŸãããããŠããã±ããã¯å®å šã«TARS_2ã«å°éããæ£åžžã«å®äºãããšå¿çãéä¿¡ããŸãããã¬ãŒã¹ãçµäºããŸããã
ããããã¯ã©ã€ã¢ã³ããèªåã®ãã¬ãŒã¹ã§ãããã¯ãŒã¯ããããžã衚瀺ããªãããã«èªç¶ãªæ¬²æ±ãããå Žåã¯ã©ãã§ãããããããªãã¯èšããçŠæ¢ãããŠããå¿ èŠããããŸãã2æ³ã®åšã®ç¶èŠªãšããŠãç§ã¯ããªãã«èšããŸãïŒçŠæ¢ããå¿ èŠã¯ãããŸãããããªãããŒã«ããããšã¯å¯èœã§ãããå¿ èŠã§ãããããã¯ãŒã¯å ã§TTL MPLSããŒãã«æžããã€ããã¯ãããŸããã
ãã®ããã«ã2çªç®ã®ã·ããªãªã䜿çšãããŸã-TTL MPLSã255ã«èšå®ããŸãããã®å ŽåãTARS_1ã§ãã¬ãŒã¹ãããšã次ã®ãã¹ã衚瀺ãããŸãïŒR1R3TARS_2ã

- TARS_1 ICMP- TTL=1. R1 , TTL TARS_1 «time exceeded in transit» . (R1) .
- TARS_1 ICMP- TTL=2.
- TARS_1 ICMP- TTL=3. TARS_2, . .
ãŸããã©ã®ãããã®æ°ã®ãã©ã³ãžããPã«ãŒã¿ãŒããã£ãŠããTARS_1ããTARS_2ã«ãã¬ãŒã¹ãããšãã¯ãTTL = 3ã§åžžã«ååã§ãã
ããã©ã«ãã®åäœã¯ãã³ããŒã«ãã£ãŠç°ãªããŸãã
Tsiskaã¯ããšã³ãžãã¢ãèªåãäœãããŠãããåã¢ã¯ã·ã§ã³ã圌ãè ãããã®ãç¥ã£ãŠãããšèããŠãããããæåã®éãéžæããŸããããšãã°ãHuaweiã¯å®å šã«ãã¬ã€ããããšã奜ã¿ãŸã-ããŸããããªãããã«ãæåã«çŠæ¢ããã»ããããã®ã§ããšã³ãžãã¢ã¯å¿ èŠã«å¿ããŠèš±å¯ããŸã
å Žåã«ãã£ãŠã¯ãã¢ãŒãã¯ãã€ã§ãå€æŽã§ããŸãããã®å Žåãã°ããŒãã«ã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãã§ã¯ããã®ããã«ã³ãã³ããno mpls ip propagate-ttlããæå®ããå¿ èŠããããŸããnano.orgã®çŽ æŽããã53ããŒãžã®
ãã¬ãŒã¹ããã¥ã¡ã³ãããšããã§ãMPLSã«ã¯ç¹å¥ãªpingããã³ãã¬ãŒã¹ãŠãŒãã£ãªãã£ããããŸãã
QïŒA
ãã°ãããç« ã®è³ªåãšåçãã¡ã€ã³èšäºã§ååã§ã¯ãªãã£ããã¹ãŠãããã«çœ®ãããšãã§ããã®ã§ãæ¬åœã«æ°ã«å ¥ã£ãŠããŸãã
Q1ïŒ Pã¯äžéLSRã§ãããPEã¯LERã§ãããšèšããŸããïŒ
å³å¯ã«èšãã°ãããããå°ãªããšããLERãLSRã®æŠå¿µã¯åºæ¬çãªMPLSã§ãããLSPãããã³PãPEãCEã«é¢é£ããŠãããããVPNã®ã¿ã§ãã
ãã¡ãããéåžžãã¯ã©ã€ã¢ã³ããæ¥ç¶ãããŠããããŒãã¯ãMPLSã®Ingress / Egress LSRã®åœ¹å²ãšVPNã®PEã®åœ¹å²ã®äž¡æ¹ãå®è¡ããŸãã
Q2ïŒãªãMBGPã¯ãã«ããããã³ã«BGPã§ãããããšãã°MPLS BGPã§ã¯ãªãã®ã§ããïŒãã«ããããã³ã«ãšã¯äœã§ããïŒ
BGPã®ç®æšã¯ãã«ãŒããã«ãŒãã£ã³ã°ããããšã§ããæŽå²çããã³å€å žçã«ãããã¯IPv4ã§ãããã ããéåžžã®ãã¬ãã£ãã¯ã¹ã«å ããŠãBGPã¯IPv6ãIPXããã«ããã£ã¹ããVPNãªã©ã®ä»ã®ãã¹ããéä¿¡ã§ããŸããåã¿ã€ãã®ãã¬ãã£ãã¯ã¹ã¯ãåå¥ã®ã¢ãã¬ã¹ãã¡ããªãã€ãŸãåãã¿ã€ãã®ã¢ãã¬ã¹ã®ã°ã«ãŒããšããŠæ§æãããŸããå®éãç°ãªããããã³ã«ã®ã«ãŒãã£ã³ã°ããŒã¿ããã®ãããªBGPã«è»¢éãããã®æ©èœã®ããã«ãMBGPãšããååãåãåããŸããã
Q3ïŒ MBGPã§éä¿¡ãããã«ãŒããRDãããã³ãããã®å±æ§ã¯ã©ãã«ãããŸããïŒ
RDã¯VPNv4ã«ãŒãã®äžéšã§ãããNLRI-Network Layer Reachability Informationã»ã¯ã·ã§ã³ã§äžç·ã«æž¡ãããŸãã
RTã¯ãæ¬è³ªçã«ã¯æ¡åŒµã³ãã¥ããã£ã»ã¯ã·ã§ã³ã§éä¿¡ãããŸãã
äžè¬ã«ãBGPæŽæ°ã¡ãã»ãŒãžã®VPNã«ãŒãã®å€ãã®å±æ§ã¯ãç¹å¥ãªã»ã¯ã·ã§ã³MP_REACH_NLRIã«é 眮ãããŸããMP_REACH_NLRIã®äžéšã¯ãéåžžã®NLRIãšãã¯ã¹ããããã§ãã
Q4ïŒã§ã¯ãRDãšRTã®éãã¯äœã§ããïŒãã®ãã¡ã®1ã€ã ãã§ã¯ååã§ã¯ãªãã®ã¯ãªãã§ããïŒãããŠãç§ã¯æ£ããç解ããŸããïŒRDã¯RTã®ãããªVPNèå¥åã§ã¯ãããŸãããïŒ
, RD, RT VPN. VPN RD/RT, RD/RT.
:
RD â Route Distinguisher â â , MBGP â VPN . RD PE, / .
RT â Route Target. VPN, VRF, . VRF VRF . Extended Community.
PEã¯ã«ãŒããé©åã«ç®¡çããæ¹æ³ãç¥ããªããããRDã ãã§ã¯äžååã§ãã
ãŸããéä¿¡äžã«ã«ãŒããæ··åšãã1ã€ãé€ããã¹ãŠã倱ãããããã1ã€ã®RTã§ã¯äžååã§ãã
ããšãã°ãRDã®ã¿ãæ®ããŠããã®ããŒã¹ã«åºã¥ããŠã«ãŒãã転éããå Žæã決å®ããããšã¯å¯èœã§ãããããã¯æè»æ§ããªããBGPã®ååã«åããŸãã
Q5ïŒè¥ãç·ãç§ãã¡ã¯äž»èŠãªãªãã¬ãŒã¿ãŒã§ãããçå£ã«åãçµãã§ããŸããAdnvancedLTEãæ§ç¯ããŠããŸããã2GããµããŒãããŠããŸãããVPNãå¿ èŠãšããã¯ã©ã€ã¢ã³ãã¯ããŸããã
. â .
, 2G, 3G, 4G 5G, Mobile Backhaul ( MBH ) 5 VPN: . , , . Traffic EngineeringâŠ
VPN MBH â Core Network: 2G BSC, 3G â RNC, 4G â MME. .
: MVNO â Mobile Virtual Network Operator â MBH ..
, , MPLS VPN â - .
Q6ïŒããããŸããã1ã€ã®ã©ãã«ã®ãã±ãããåä¿¡ããEgress PEãã€ãŸãPHPãçºçããå Žåããã®VPNã©ãã«ã¯ãã©ã³ã¹ããŒãã©ãã«ã§ã¯ãªããšå€æãããããã£ãŠãã©ãã«ããšã«VRFã«æž¡ãå¿ èŠããããããã«äœãïŒ
ãã¹ãŠãéåžžã«åçŽã§ã-VPNãLSPãããããçš®é¡ã®FRRããã³CSCã®ã©ãã«ã¹ããŒã¹ã¯äžè¬çã§ããVPNãšLSPã«åãã©ãã«ãå²ãåœãŠãããŠããããšã¯ã§ããŸãããããŠãäœæãããåã©ãã«ã«ã¯ãåä¿¡æã«ãã®ããŒã«ãšã¢ã¯ã·ã§ã³ãå²ãåœãŠãããŸãã
䟿å©ãªãªã³ã¯
ãã®èšäºã§äœ¿çšãããŠãããã¹ãŠã®çšèªãšç¥èªã¯ãlookmeupçšèªéã§èŠã€ããããšãã§ãããšèšã£ãŠé£œããããšã¯ãããŸãããããŠãç§ã¯cã ïŒãã¹ãŠã§ã¯ãªãã倧å€æ°ã®ã¿
ç§ã®æãããžã§ãã»ãã€ã«ïŒ2ã€ã®éšåãããªãVPNïŒããŒãIãããŒãIIã
RDãšRTã®éãã¯ãJeremy Stretchã«ãã£ãŠèšè¿°ãããŠããŸãïŒRoute DistinguishersãšRoute Targetsã
ãæ°ã¥ããããããŸããããL3VPNã®äœæã¯å€ãã®æäœæ¥ã§ãããŸããVPNéã®ããåããæŽçããå¿ èŠãããå Žåã¯ãæãæ£ç¢ºã§çŸããæ¹æ³ã§ããã1ã€ã®ã€ã³ã¿ãŒãããã²ãŒããŠã§ã€ã ãã§ãªããã¯ã©ã€ã¢ã³ãPEãæ§æããå¿ èŠããããŸãã
ãããããã®äœæ¥ã¯ãã¹ãŠå¿ èŠã§ãããåé·æ§ã¯ãããŸãããå¯Ÿç §çã«ãGREãŸãã¯VRF-Liteã䜿çšããŠVPNãæ§æããããšãèŠããŠãããŠãã ããã
ãŸããPã«ãŒã¿ãŒïŒLinkmeup_R2ïŒã¯ãMPLSãæåã«çµã¿èŸŒãŸããŠããæ§æã®ãã¹ãŠã®æ®µéã§ãŸã£ããå€æŽãããŠããªãããšã«æ³šæããŠãã ãããããããããªãïŒ
ããã¯ãL3VPNå šäœããã®å°ããªèšäºã§ã«ããŒãããšããããšã§ã¯ãããŸãããç¹ã«ã3ã€ã®ã¿ã€ãã®Inter-AS VPNãCSCïŒCarrier Support CarrierïŒãªã©ã®èå³æ·±ããã®ãäžè¬çãªå³å€ã«æ®ã£ãŠããŸããããããããããã®2ã€ã®ã¡ã«ããºã ã«ã€ããŠå ·äœçã«å¥ã®èšäºãæžããããšæã£ãŠããŸãã
L3VPNã¯æçãããææ ®æ·±ããæšæºåããããã®ã§ãããã¹ãŠã®ã¡ãŒã«ãŒã«ãšã£ãŠããã©ã¹/ãã€ãã¹ã®åãåããããŸãã
ãŸããAToMãVLLãPWE3ãVPLSãå«ãL2VPNã«é¢ããèšäºããŸã ãããŸãããã®äžã§ããã®åéã®çºå±ã«ãããŠã·ã¹ã³ãšãžã¥ãããŒãæããã圹å²ãCESãEoMPLSãªã©ã®ãµãŒãã¹ãç§ãã¡ã®ç掻ã«ããããåã³ãåŠã³ãŸããææ ¢ããŠãã ãã-ä»å¹Žã¯ããŒã¹ãäžããå¢ããå¢ããã¹ãã³ã¢ããããå¹çãäžããããšããŸãã
ãããªã¯ãããã»ãŒãé³æ¥œã䜿çšããŠããŸã
ãããžã§ã¯ãã€ã©ã¹ãã¬ãŒã¿ãŒã¯ã¢ãã¹ã¿ã·ã¢ã¡ããã©ãŒã§ããJDima
ã«æè¬ããŸãã
é£çµ¡ãåãåããŸãããã
ãã¹ãŠã®åé¡