ãã®èšäºã§ã¯ã次ã®ãããã¯ãæ€èšããŸãã
-BGP Inter-ASãªãã·ã§ã³A
-BGP Inter-ASãªãã·ã§ã³B
-BGP Inter-ASãªãã·ã§ã³C
-JunOSã§ãããã®ãªãã·ã§ã³ãèšå®ããæ©èœ
ãã®èšäºã¯ãCisco CLIãšJuniperããã®å€ãã®çµè«ã«ãªããŸãã mplsã®åºæ¬ãbgpã©ãã«ä»ããŠããã£ã¹ããšvpnv4ãŠããã£ã¹ãã®éããããããªãå Žåããã®èšäºãèªãã®ã¯æå³ããããŸããã ãããã®æŠå¿µãããªãã¿ã®å Žåã¯ãç«ããé¡ãããŸãã
泚ïŒäžã®å³ã§ã¯ãå·ŠåŽã®éšåã¯ãCisco IOS15ã®å³åŽã«ããJunOSïŒCEãé€ãïŒãå®è¡ããŠããã«ãŒã¿ãŒã§æ§æãããŠããŸãã
ããã§ã¯ãæãäžè¬çãªãªãã·ã§ã³Aããå§ããŸãããã
ãã®ãªãã·ã§ã³ã®æå³ã¯ãASBRã§åVPNã«å¯ŸããŠVRFãäœæãããé£æ¥ASããã®åå¥ã®ãµãã€ã³ã¿ãŒãã§ã€ã¹ãçæãããããšã§ãã ãã®ããã«ããŠãASBRã¯CE-PEã«ãŒã¿ãŒãšããŠçžäºäœçšããçŽç²ãªIPã«ãŒãã亀æããŸãã ãã®ãªãã·ã§ã³ã§ã¯ãASBRéã«MPLSã¯ãããŸãã-çŽç²ãªIPãã©ãã£ãã¯ã®ã¿ïŒ
ã³ã³ãããŒã«ãã¬ãŒã³ãã©ã®ããã«æ©èœãããã詳ãã調ã¹ãŠã¿ãŸãããã
1. PE1ã¯vpnv4ã«ãŒããçæããMP-BGPçµç±ã§ã«ãŒã¿ãŒïŒRR1ïŒã«éä¿¡ããŸãã
2. routreflectorã«ã¯ASBR1ãšã®vpnv4ã»ãã·ã§ã³ãããããã®äžã§PE1 vpnv4ããåä¿¡ããã«ãŒããæäŸããŸãã
3. VRFã¯ASBR1ïŒããããžãASBR1 CE1ãšCE3ãããã³ASBR2-CE2ãšCE4ïŒã§ãäœæããããããã«ãŒããåãå ¥ãã察å¿ããvrfã®ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
4. ASBR1ã¯ãæ¢ã«ã¯ãªãŒã³ãªIPã«ãŒããASBR2ã«è»¢éããŸãïŒã«ãŒãã£ã³ã°ãããã³ã«ã¯ãRIPããBGPãžã®ä»»æã®ãã®ã§ãïŒã ããã¯ãCEããPEãžã®çžäºäœçšãæ©èœããå Žæã§ããASBR1ã¯IPãã¬ãã£ãã¯ã¹ãæäŸããã«ãŒã¿ãŒCEãšããŠæ©èœããASBR2ã¯ã«ãŒã¿ãŒã®PEãšãªãããã¬ãã£ãã¯ã¹ãåä¿¡ããŠââASã®vpnv4ãã¬ãã£ãã¯ã¹ãçæããŸãã ïŒã«ãŒãã¯äž¡åŽããéä¿¡ããããããASBRã¯ã«ãŒã¿ãŒã®CEãšPEã®äž¡æ¹ãšããŠæ©èœããŸãïŒã
5. IPãã¬ãã£ãã¯ã¹ãåä¿¡ããASBR2ã¯ãvpnv4ãã¬ãã£ãã¯ã¹ãçæããã«ãŒã¿ãŒïŒRR2ïŒã«éä¿¡ããŸãã
6. PE2ã¯ãvpnv4ã»ãã·ã§ã³ã®ã«ãŒã¿ãŒãããã®ãã¬ãã£ãã¯ã¹ãåä¿¡ããvrf-importã«ãŒã¿ãŒã§æ§æãããã«ãŒãã§ãã¯ã¹ããããã®å°éå¯èœæ§ãšrtã®äžèŽã確èªããåŸã察å¿ããvrfã®ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
ããã§ã¯ãããŒã¿ãã¬ãŒã³ã«ç§»ããŸãããã
1. PE1ã¯ãCE1ãããã±ãããåä¿¡ããASBR1ããåä¿¡ããã©ãã«ïŒvrfã©ãã«ïŒãASBR1ãžã®ãã©ã³ã¹ããŒãã©ãã«ïŒldpçµç±ã§åä¿¡ïŒããã³ã°ã¢ããããã察å¿ããã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ããŸãã
2. 2-xã¿ã°ã®ã¹ã¿ãã¯ã§PE1ãããã±ãããåä¿¡ããP1ã¯ãäžäœãã©ã³ã¹ããŒãã©ãã«ïŒphpïŒãåé€ãããã±ãããASBR1ã«éä¿¡ããŸãã
3. ASBR1ã¯1ã€ã®ã©ãã«ïŒvrfã©ãã«ïŒãæã€ãã±ãããåä¿¡ããã¯ã©ã€ã¢ã³ãCEã«ãŒã¿ãŒãçµäºããéåžžã®PEã«ãŒã¿ãŒãšããŠæ©èœããŸã-ã©ãã«ãåé€ããé©åãªã€ã³ã¿ãŒãã§ãŒã¹ã«ãã±ãããéä¿¡ããŸãASBR2ãšã®ãžã§ã€ã³ãã«éä¿¡ãããŸãã
4. ASBR2ã¯ãã®ãã±ãããåä¿¡ããéåžžã®PEã«ãŒã¿ãŒã®ããã«æ©èœããŸããvrfã©ãã«ïŒPE2ããåä¿¡ïŒããã©ã³ã¹ããŒãã©ãã«ãPE2ïŒldpããåä¿¡ïŒã«è¿œå ããé©åãªã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ããŸãã
5. P2ã¯ããã©ã³ã¹ããŒãã©ãã«ïŒphpïŒãåé€ããŸãã
6. PE2ã¯ã1ã€ã®ã©ãã«ïŒããèªäœãçæããVRFã©ãã«ïŒãæã€ãã±ãããåä¿¡ãããããåé€ããIPã«ãã¯ã¢ãããè¡ãã察å¿ããVRFã®ã«ãŒãã£ã³ã°ããŒãã«ã«åŸã£ãŠãã±ãããéä¿¡ããŸãã
次ã«ãå®éã«ã¿ã°ã䜿çšããŠå®è¡ãããæäœãèŠãŠã¿ãŸãããã
ASBRã®BGPèšå®ã¯æ¬¡ã®ãšããã§ãã
bormoglotx@ASBR1> show configuration routing-instances CE1 instance-type vrf; interface ge-0/0/3.0; route-distinguisher 1:2; vrf-target { import target:1:100; export target:1:100; } vrf-table-label; protocols { bgp { group AS64999 { type external; local-address 10.2.0.1; peer-as 64999; local-as 65000; neighbor 10.2.0.2; } } }
ASBR2#sh configuration | b ip vrf ip vrf CE2 rd 2:2 route-target export 2:100 route-target import 2:100 ASBR2#sh configuration | b address-family ipv4 address-family ipv4 vrf CE2 no synchronization neighbor 10.2.0.1 remote-as 65000 neighbor 10.2.0.1 local-as 64999 neighbor 10.2.0.1 activate exit-address-family
ã芧ã®ãšãããéåžžã®PEã«ãŒã¿ãŒã®ããã«ããã¹ãŠãç¯çœªã§ã¯ãããŸããã
泚ïŒã«ãŒãã£ã³ã°ãããã³ã«ã«é¢ããŠã¯ããã€ãã®ãã¥ã¢ã³ã¹ããããŸãã BGPã䜿çšããå Žåã2ã€ã®ã¯ã©ã€ã¢ã³ããµã€ããåãèªåŸã·ã¹ãã çªå·ã§ãªã³ã¯ããå Žåãããšãã°OSPFãã©ãã«ã§ãããå Žåã¯ãDNããããå¿ããªãã§ãã ãããloops2ã³ãã³ãã䜿çšããå¿ èŠããããŸãã åã ã®ã±ãŒã¹ã¯åå¥ã«æ€èšããå¿ èŠããããŸãã
ãããã£ãŠãå³ã«ç€ºãããã«ãPE1ãšASBR1ã«vrf CE1ããPE2ãšASBR2ã«vrf CE2ãäœæããŸããã vpnv4ã«ãŒãã®ãšã¯ã¹ããŒããšã€ã³ããŒãã¯ãèªåŸã·ã¹ãã å ã®VRFããŒã¿éã§ã®ã¿å¯èœã§ãã èªåŸã·ã¹ãã éã§ã¯ãASBRïŒããã³ipv4ãŠããã£ã¹ãããïŒã®ã¿ãã«ãŒãã亀æããŸãã CE1ãšCE2ã¯ã©ã€ã¢ã³ãã«ãŒã¿ãŒéã®æ¥ç¶ã確èªããŸãã
R5#ping 10.0.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.0.1.2, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 60/70/84 ms
ãã¹ãŠãé 調ã§ãæ¥ç¶æ§ããããŸãã 次ã«ãããã±ãŒãžã®é²è¡ã«äŒŽã£ãŠã©ãã«ã䜿çšããæäœãã©ã®ããã«ãªãããæ€èšããŸãã
ããã§ã¯ãPE1ã®ã«ãŒããèŠãŠã¿ãŸãããã
bormoglotx@PE1> show route table CE1.inet.0 10.0.1.0/24 CE1.inet.0: 7 destinations, 7 routes (7 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.0.1.0/24 *[BGP/170] 00:03:29, localpref 100, from 10.0.10.10 AS path: 65000 64999 2 ? > to 10.0.2.2 via ge-0/0/0.0, Push 16, Push 299824(top)
PE1ã¯2ã€ã®ã¿ã°ããã³ã°ã¢ããããŸãã
16-ASBR1ããRR1ãä»ããŠåä¿¡ããVRFã¿ã°
299824-ldpãããã³ã«ãä»ããŠåä¿¡ãããã©ã³ã¹ããŒãã©ãã«
ãã±ãããP-0ã«åããŠge-0 / 0 / 0.0ã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ããŸãã
P1ã¯mpls.0ããŒãã«ã«åŸã£ãŠïŒäžç¶ã«ãŒã¿ãŒã§ããããïŒããããããŒã¯ãåé€ãïŒPHPã¡ã«ããºã ãå®è¡ïŒããã®ãã±ãããASBR1ã«éä¿¡ããŸãïŒ
bormoglotx@P1> show route table mpls.0 label 299824 mpls.0: 9 destinations, 9 routes (9 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 299824 *[LDP/9] 00:41:16, metric 1 > to 10.0.3.1 via ge-0/0/1.0, Pop 299824(S=0) *[LDP/9] 00:41:16, metric 1 > to 10.0.3.1 via ge-0/0/1.0, Pop
ASBR1ã¯vrfã©ãã«ãåé€ããCE1.inet.0ããŒãã«ã§IPã«ãã¯ã¢ãããè¡ããŸãïŒJunOSã§vrf-table-labelã³ãã³ããå¿ããªãã§ãã ããïŒïŒ
bormoglotx@ASBR1> show route table mpls.0 label 16 mpls.0: 10 destinations, 10 routes (10 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 16 *[VPN/0] 00:35:23 to table CE1.inet.0, Pop bormoglotx@ASBR1> show route table CE1.inet.0 10.0.1.0/24 CE1.inet.0: 7 destinations, 7 routes (7 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.0.1.0/24 *[BGP/170] 00:05:41, localpref 100 AS path: 64999 2 ? > to 10.2.0.2 via ge-0/0/3.0
ASBR1ããã®ãã±ããã¯ãge-0 / 0/3ã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠmplsããããŒãªãã§ASBR2ã«éä¿¡ãããŸã-çŽç²ãªipãã©ãã£ãã¯ã®ã¿ïŒéåžžã¯ã¿ã°ä»ãããã®å Žåã¯vrfã®ã¿ã§ããè€æ°ã®vrfãããå Žåããµãã€ã³ã¿ãŒãã§ãŒã¹ãå®è¡ããŸããã§ããã vpnããšã«åå¥ã®ãµãã€ã³ã¿ãŒãã§ã€ã¹ãäœæããvrfèšå®ã§æå®ããŸãïŒã
IPãã±ãããåä¿¡ããASBR2ã¯ãvrf CE2ã«ãŒãã£ã³ã°ããŒãã«ã§ã«ãŒããæ¢ããŸãã
ASBR2#show ip route vrf CE2 10.0.1.0 Routing Table: CE2 Routing entry for 10.0.1.0/24 Known via "bgp 2", distance 200, metric 0, type internal Last update from 10.1.10.1 00:20:49 ago Routing Descriptor Blocks: * 10.1.10.1 (default), from 10.1.10.10, 00:20:49 ago Route metric is 0, traffic share count is 1 AS Hops 0 MPLS label: 22 MPLS Flags: MPLS Required
ASBR2#sh mpls forwarding-table 10.1.10.1 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 21 18 10.1.10.1/32 0 Gi1/0 10.1.0.2 17 10.1.10.1/32 0 Gi2/0 10.1.2.2
ã«ãŒãã«åŸã£ãŠãASBR2ã¯ãPE2ããbgp vpnv4ããåä¿¡ããvrfïŒ22ïŒã©ãã«ããã³ã°ãããPE2ïŒ10.1.10.1ïŒäžã®lspã«éä¿¡ããŸãã ã«ãŒãã®æ¬¡ã®ãããã¯P2ãŸãã¯RR2ã§ãïŒãã®å Žåããªãã¬ã¯ã¿ãŒã¯Pã«ãŒã¿ãŒã®ããã«æ©èœããŸãïŒã ãã©ãã£ãã¯ãP2ãééãããšæ³å®ããã©ãã«ã®ä»ããæäœãç£èŠããŸãã P2ã¯2ã€ã®ã©ãã«22ããã³17ã®ãã±ãããåä¿¡ããmpls転éããŒãã«ãæ€çŽ¢ããŸãã
P1#sh mpls forwarding-table labels 17 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 17 Pop Label 10.1.10.1/32 18542 Gi1/0 10.1.3.1
mpls転éããŒãã«ã«ãããšãP2ã¯ãããããŒã¯ãåé€ãïŒåã³phpïŒããã±ãããPE2ã«éä¿¡ããŸãã
PE2ã¯ããã®ã©ãã«ãvrf CE2ãæããŠããããšã確èªããvrf CE2ããŒãã«ã§IPã«ãã¯ã¢ãããå®è¡ããã¯ã©ã€ã¢ã³ãã«ã¯ãªãŒã³ãªIPãã±ãããéä¿¡ããŸãã
PE2#sh mpls forwarding-table labels 22 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 22 No Label 10.0.1.0/24[V] 14450 aggregate/CE2 PE2#sh ip rou vrf CE2 10.0.1.0 Routing Table: CE2 Routing entry for 10.0.1.0/24 Known via "connected", distance 0, metric 0 (connected, via interface) Redistributing via bgp 2 Advertised by bgp 2 Routing Descriptor Blocks: * directly connected, via GigabitEthernet3/0.10 Route metric is 0, traffic share count is 1
ãã®ãœãªã¥ãŒã·ã§ã³ãéåžžã«é£ããããšã¯æããã§ãã æ°ããã¯ã©ã€ã¢ã³ããæ¥ç¶ããå Žåããã®ã¯ã©ã€ã¢ã³ããçµäºããPEã«ãŒã¿ãŒã ãã§ãªããASBRã§ãvrfãäœæããå¿ èŠããããŸãïŒå察åŽãããåãããšãããå¿ èŠããããŸãïŒã åœç¶ããã®ãœãªã¥ãŒã·ã§ã³ã¯éä¿¡äºæ¥è ã®ä»æ¥ã®èŠæ±ãæºãããŠããªããããããã«èå³æ·±ããœãªã¥ãŒã·ã§ã³ã§ãããªãã·ã§ã³Bããã³Cãæ€èšããŸãã
ãªãã·ã§ã³B
ASBRã®éã§vpnv4ã»ãã·ã§ã³ãçºçãããã®äžã§vpnv4ã«ãŒãã亀æãããŸãïŒãã¡ãããäœåãªãã®ãäžãããäžãããããªãããã«ãæå®ããããã¬ãã£ãã¯ã¹ãšåä¿¡ããããã¬ãã£ãã¯ã¹ã®ASBRã§ãã£ã«ã¿ãªã³ã°ãæ§æããå¿ èŠããããŸãïŒã ãã ãããããã®ã«ãŒãã®å®å ãšãªãVRFããªãå ŽåïŒã€ã³ããŒãæã«vrfsã§NLRIã§æå®ãããã«ãŒãã¿ãŒã²ãããèŠã€ãããªãå ŽåïŒãã«ãŒã¿ãŒã¯vpnv4ã«ãŒããç Žæ£ããŸãïŒJuniperã«ãŒã¿ãŒãé€ãïŒã ãã®ããã©ã«ãã®åäœãASBRã«å€æŽããã«ã¯ããã¹ãŠã®vpnv4ã«ãŒããæå¹ã«ããå¿ èŠããããŸãïŒãã¹ãŠä¿æ-ãžã¥ãããŒãbgpããã©ã«ãã«ãŒãã¿ãŒã²ãããã£ã«ã¿ãŒãªã-IOSãã«ãŒãã¿ãŒã²ãããã¹ãŠãä¿æ-IOS XRãå ã®ããªã·ãŒvpn-ã¿ãŒã²ãã-HuaweiïŒã
泚ïŒJuniperã«ãŒã¿ãŒã§ã¯ãeBGP vpnv4ã»ãã·ã§ã³ãæ§æãããšãã«ããªãã·ã§ã³Bã®ASBR-romãšèŠãªããããããvpnv4ãã¢ããåä¿¡ãããã¹ãŠã®ã«ãŒããåãå ¥ããŠbgp.l3vpn.0ããŒãã«ã«è»¢éãããããkeep allã³ãã³ãã¯äžèŠã§ãããã¢ãžã®ã«ãŒããæå®ããŸãã
ããã§ã¯ãã³ã³ãããŒã«ãã¬ãŒã³ããå§ããŸãããã
1. PE2ã¯vpnv4ã«ãŒããçæããRR2ã«ãŒã¿ãŒã«éä¿¡ããŸãã
2. RR2 Routreflectorã¯ããã®ã«ãŒãããã¹ãŠã®é¡§å®¢ã«è»¢éããŸãã
3.ã«ãŒããªãã¬ã¯ã¿ã®ã¯ã©ã€ã¢ã³ãã§ããASBR2ã¯ãçæãããPE2 vpnv4ã«ãŒããåä¿¡ããŸãã ãªãã·ã§ã³no bgp default route-target filterãæå¹ã«ãªã£ãŠãããããASBR2ã¯åä¿¡ããã«ãŒããã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
4. ASBR2ã¯ãã«ãŒã¿ãŒãåä¿¡ãããã¯ã¹ããããã«ãŒããå€æŽããæ°ããã©ãã«ãçæãïŒã©ãã«å€ã¯å€æŽãããªãå¯èœæ§ããããŸãïŒãebgp vpnv4ã»ãã·ã§ã³ã«ãã£ãŠãã®ã«ãŒããASBR1ã«éä¿¡ããŸãã
5. ASBR1ã¯ASBR2ããvpnv4ã«ãŒããåä¿¡ããã«ãŒãã£ã³ã°ããŒãã«bgp.l3vpn.0ã«ã€ã³ã¹ããŒã«ããŸãã
6. ASBR1ã¯ãASBR2ããåä¿¡ãããã¯ã¹ããããã«ãŒããèªèº«ã«å€æŽããæ°ããmplsã©ãã«ãçæããŠãæå®ãããã«ãŒããRR1ã«éä¿¡ããŸãã
7.ãã®ã«ãŒããåä¿¡ããRR1ã¯ããã¯ã¹ãããããas-pathïŒæé©ãªbgpã«ãŒããéžæããããã®æšæºã¡ã«ããºã ïŒã®å¯çšæ§ã確èªãããã®ã«ãŒããã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
8. RR1ã¯ãASBR1ããåä¿¡ããã«ãŒããPE1ã«éä¿¡ããŸãã
9. vpnv4ã«ãŒã¿ãŒããã«ãŒããåä¿¡ããPE1ã¯ããã¯ã¹ããããã®å¯çšæ§ã確èªããåä¿¡ããã«ãŒãã®extcommunityïŒrtïŒãã«ãŒã¿ãŒã«èšå®ãããvrf-importãšäžèŽãããã©ããã確èªãã察å¿ããvrfã®ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
ASå ã®ASBRãžã®ãã©ã³ã¹ããŒãã©ãã«ã¯ãæšæºçãªæ¹æ³ïŒLDPãŸãã¯RSVP-TEïŒã§é åžãããŸãã
次ã«ãäŸãæããŠäžèšãæ€èšããŸãã
PE2 vrf CE2ã§çµäºããã¯ã©ã€ã¢ã³ããã¬ãã£ãã¯ã¹10.0.1.0/24ã®ã©ãã«ä»ããã©ã®ããã«çºçããããèããŠã¿ãŸãããã
PE2#sh ip route vrf CE2 10.0.1.0 Routing Table: CE2 Routing entry for 10.0.1.0/24 Known via "connected", distance 0, metric 0 (connected, via interface) Redistributing via bgp 2 Advertised by bgp 2 Routing Descriptor Blocks: * directly connected, via GigabitEthernet3/0.10 Route metric is 0, traffic share count is 1
PE2ã¯vpnv4ã«ãŒããçæããiBGPãä»ããŠRR2ã«ãŒããªãã¬ã¯ã¿ãŒã«éä¿¡ããŸãã
PE2#sh ip bgp vpnv4 rd 2:1 10.0.1.0/24 BGP routing table entry for 2:1:10.0.1.0/24, version 2 Paths: (1 available, best #1, table CE2) Advertised to update-groups: 1 Local 0.0.0.0 from 0.0.0.0 (10.1.10.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best Extended Community: RT:1:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 mpls labels in/out 17/nolabel(CE2)
äžèšã®çµè«ã«ããã°ããã®ãã¬ãã£ãã¯ã¹ã«å¯ŸããŠã©ãã«17ãçæãããŸãããmplslabels in / out 17 / nolabelïŒCE2ïŒ
次ã«ãPE2ã¯vpnv4ã«ãŒããã«ãŒã¿ãŒã«éä¿¡ããŸãã 1ã€ã¯PE2ãšCE2ã®éã®ãããã¯ãŒã¯ã§ããã2ã€ç®ã¯CE2ã¯ã©ã€ã¢ã³ãã«ãŒã¿ã®ã«ãŒãããã¯ã§ããããã2ã€ã®ã«ãŒãããããŸãã
PE2#sh ip bgp vpnv4 all neighbors 10.1.10.10 advertised-routes BGP table version is 39, local router ID is 10.1.10.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 2:1 (default for vrf CE1) *> 10.0.1.0/24 0.0.0.0 0 32768 ? *> 10.1.1.2/32 10.0.1.2 2 32768 ? Total number of prefixes 2
RR2ã«ãŒã¿ãŒã¯ãPE2 vpnv4ããåä¿¡ããASBR2ãªã©ã®ã¯ã©ã€ã¢ã³ããžã®ã«ãŒããåæ ããŸãã
RR2#sh ip bgp vpnv4 rd 2:1 neighbors 10.1.10.3 advertised-routes BGP table version is 21, local router ID is 10.1.10.10 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 2:1 *>i10.0.1.0/24 10.1.10.1 0 100 0 ? *>i10.1.1.2/32 10.1.10.1 2 100 0 ? Total number of prefixes 2
ASBR2ã¯ãã®ã«ãŒããåãå ¥ããã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
ASBR2#sh ip bgp vpnv4 rd 2:1 10.0.1.0/24 BGP routing table entry for 2:1:10.0.1.0/24, version 4 Paths: (1 available, best #1, no table) Advertised to update-groups: 1 Local 10.1.10.1 (metric 3) from 10.1.10.10 (10.1.10.10) Origin incomplete, metric 0, localpref 100, valid, internal, best Extended Community: RT:1:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 Originator: 10.1.10.1, Cluster list: 10.1.10.10 mpls labels in/out 26/17
ãmpls labels in / out 26/17ããšããè¡ã«æ³šç®ããŸãã ASBR2ã¯in-26ã§æ°ããã©ãã«ãçæããææãããã¹ãŠã®vpnv4ã«ãŒãïŒãã£ã«ã¿ãªã³ã°ãoutã«èšå®ãããŠããå Žåã¯ãã¹ãŠã§ã¯ãªãïŒãASBR1äžã®é£æ¥ASã«éä¿¡ããŸãã
ASBR2#sh ip bgp vpnv4 rd 2:1 neighbors 10.2.0.1 advertised-routes BGP table version is 13, local router ID is 10.1.10.3 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 2:1 *>i10.0.1.0/24 10.1.10.1 0 100 0 ? *>i10.1.1.2/32 10.1.10.1 2 100 0 ? Total number of prefixes 2
ASBR1ã¯ãããã®ã«ãŒããåãå ¥ããã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
bormoglotx@ASBR1> show route receive-protocol bgp 10.2.0.2 10.0.1.0/24 10.0.1.0/24 detail inet.0: 13 destinations, 13 routes (13 active, 0 holddown, 0 hidden) bgp.l3vpn.0: 4 destinations, 4 routes (4 active, 0 holddown, 0 hidden) * 2:1:10.0.1.0/24 (1 entry, 1 announced) Accepted Route Distinguisher: 2:1 VPN Label: 26 Nexthop: 10.2.0.2 AS path: 2 ? Communities: target:1:100 domain-id:0:131584 route-type-vendor:0.0.0.0:2:0 router-id-vendor:10.0.1.1:0
æ°ããã©ãã«ã®çæã«å ããŠãASBR2ã¯ãã¯ã¹ãããããããèªäœã«å€æŽããŸããïŒãã¯ã¹ããããïŒ10.2.0.2ïŒã
ASBR1ã¯ããã¬ãã£ãã¯ã¹10.0.1.0/24ã®åã«æ°ããã©ãã«ïŒVPNã©ãã«ïŒ299888ïŒãçæãããã¯ã¹ãããããããèªäœïŒãã¯ã¹ããããïŒã»ã«ãïŒã«å€æŽããRR1ã«ãŒã¿ãŒãžã®ã«ãŒããæäŸããŸã
bormoglotx@ASBR1> show route advertising-protocol bgp 10.0.10.10 10.0.1.0/24 detail bgp.l3vpn.0: 4 destinations, 4 routes (4 active, 0 holddown, 0 hidden) * 2:1:10.0.1.0/24 (1 entry, 1 announced) BGP group RR type Internal Route Distinguisher: 2:1 VPN Label: 299888 Nexthop: Self Flags: Nexthop Change Localpref: 100 AS path: [1] 2 ? Communities: target:1:100 domain-id:0:131584 route-type-vendor:0.0.0.0:2:0 router-id-vendor:10.0.1.1:0
RR1 Routreflectorã¯ãPE1ãå«ã顧客ã«ã«ãŒããæäŸããŸãã
bormoglotx@PE1> show route receive-protocol bgp 10.0.10.10 10.0.1.0/24 detail inet.0: 11 destinations, 11 routes (11 active, 0 holddown, 0 hidden) CE1.inet.0: 6 destinations, 6 routes (6 active, 0 holddown, 0 hidden) * 10.0.1.0/24 (1 entry, 1 announced) Import Accepted Route Distinguisher: 2:1 VPN Label: 299888 Nexthop: 10.0.10.3 Localpref: 100 AS path: 2 ? (Originator) Cluster list: 10.0.10.10 AS path: Originator ID: 10.0.10.3 Communities: target:1:100 domain-id:0:131584 route-type-vendor:0.0.0.0:2:0 router-id-vendor:10.0.1.1:0 bgp.l3vpn.0: 2 destinations, 2 routes (2 active, 0 holddown, 0 hidden) * 2:1:10.0.1.0/24 (1 entry, 0 announced) Import Accepted Route Distinguisher: 2:1 VPN Label: 299888 Nexthop: 10.0.10.3 Localpref: 100 AS path: 2 ? (Originator) Cluster list: 10.0.10.10 AS path: Originator ID: 10.0.10.3 Communities: target:1:100 domain-id:0:131584 route-type-vendor:0.0.0.0:2:0 router-id-vendor:10.0.1.1:0
ã«ãŒãã¯ãvrfããŒãã«CE1.inet.0ãšbgpããŒãã«vpnv4ã«ãŒãbgp.l3vpn.0ã®2ã€ã®ããŒãã«ã«è¡šç€ºãããŸãã
JunOSã¯vpnv4ã«ãŒããåä¿¡ãããã®é©åæ§ïŒAS-PATHããã¯ã¹ããããã®å¯çšæ§ïŒãã€ã³ããŒãçšã®ã«ãŒãã£ã³ã°ã€ã³ã¹ã¿ã³ã¹æ§æã®vpnv4ã§æå®ããããšã¯ã¹ã³ãã¥ããã£ããããã©ãããããã³ã«ãŒããæ€èšŒããŒã¿ãééããéåžžã®bgpæé©ãã¹éžæã¢ã«ãŽãªãºã ã«åŸã£ãŠæé©ãšããŠéžæãããŠãããã©ããããã§ãã¯ããŸããbgp.l3vpn.0ããŒãã«ã«ã€ã³ã¹ããŒã«ãããŸãã ãããŠããã§ã«ãã®IPããŒãã«ããããã¬ãã£ãã¯ã¹ã¯vrfããŒãã«ïŒãã®å Žåã¯CE1.inet.0ïŒã«è»¢éãããŸãã
ããŒã¿ãã¬ãŒã³ïŒ
ã¢ã©ãŒã ããŒãã³ã°ã䜿çšããŠãç§ãã¡ã¯ææ¡ããŸããã 次ã«ãããŒã¿ãã¬ãŒã³ãã€ãŸãããã±ããããmplsã¯ã©ãŠãããä»ããŠCE1ïŒ10.0.0.2ããïŒããCE2ïŒ10.0.1.2ïŒã«è»¢éãããæ¹æ³ãæ€èšããŸãã
æåã«ãCEã«ãŒã¿ãŒéã®pingãéå§ãããã¹ãéã«æ¥ç¶ãããããšã確èªããŸãã
CE1#ping 10.0.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.1.1.2, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 52/91/132 ms
ãã¬ãŒã¹ãäœæããŸãããïŒ
R5#traceroute 10.0.1.2 numeric timeout 1 Type escape sequence to abort. Tracing the route to 10.0.1.2 1 10.0.0.1 32 msec 4 msec 12 msec 2 10.0.2.2 [MPLS: Labels 299792/299888 Exp 0] 48 msec 68 msec 52 msec 3 10.0.3.1 [MPLS: Label 299888 Exp 0] 48 msec 60 msec 52 msec 4 10.2.0.2 [MPLS: Label 26 Exp 0] 64 msec 52 msec 52 msec 5 10.1.0.2 [MPLS: Labels 19/17 Exp 0] 48 msec 60 msec 52 msec 6 10.0.1.1 52 msec 52 msec 56 msec 7 10.0.1.2 48 msec 64 msec 108 msec
ã¿ã°ã®æ倧æ°ã¯2ã§ããããšãããããŸãã
泚ïŒtraffic-engineerengã䜿çšããå Žåãããã«å€ãã®å¯èœæ§ããããŸãã ãã®å Žåãldpã®ã¿ãã©ãã«ãé åžããŸãã
次ã«ããã±ããããããã¯ãŒã¯äžã移åãããšãã®ã©ãã«æäœãæ±ããŸãã
ã¯ãªãŒã³ãªIPãã±ããã¯ãCE1ã¯ã©ã€ã¢ã³ãã«ãŒã¿ããPE1ã«å°çããŸãïŒãã®äŸã§ã¯vlanã¿ã°10ã䜿çšããŠããŸãããl3vpnã§ãããã¿ã°ãåé€ãããŠãããããåé¡ã§ã¯ãããŸããïŒã PE1ã®ã«ãŒãã¯ããã±ãããmplsãã³ãã«ã«éä¿¡ããå¿ èŠãããããšã瀺ããŠããŸãã PE1ã¯2ã€ã®ã©ãã«ããã³ã°ãããŸãïŒvrfã©ãã«ã¯299888ïŒASBR1ããåãåã£ãïŒã§ãããASBR1ãžã®ãã©ã³ã¹ããŒãã©ãã«ã¯299792ã§ãïŒldpãããã³ã«ã«ãã£ãŠåãåã£ãïŒïŒ
bormoglotx@PE1> show route table CE1.inet.0 10.0.1.2 CE1.inet.0: 6 destinations, 6 routes (6 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.0.1.0/24 *[BGP/170] 00:15:32, localpref 100, from 10.0.10.10 AS path: 2 ? to 10.0.2.2 via ge-0/0/0.0, Push 299888, Push 299792(top) > to 10.0.0.2 via ge-0/0/1.0, Push 299888, Push 299792(top)
bormoglotx@PE1> show interfaces descriptions Interface Admin Link Description ge-0/0/0 up up to P1 ge-0/0/1 up up to RR1 ge-0/0/3 up up to SW1 lo0 up up router-id
PE1ã¯ããã®ãã±ãããRR1ã®æ¹åã§ge-0 / 0/1ã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ããŸãïŒãã®å Žåãã«ãŒã¿ãŒãªãã¬ã¯ã¿ãŒã¯Pã«ãŒã¿ãŒãšããŠãæ©èœããŸãïŒã
RR1ã¯ã©ãã«ã¹ã¿ãã¯ã®ãããã±ãããåä¿¡ãããããã©ãã«299792ã解æããŸãã
bormoglotx@RR1> show route table mpls.0 label 299792 mpls.0: 9 destinations, 9 routes (9 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 299792 *[LDP/9] 01:19:34, metric 1 > to 10.0.1.1 via ge-0/0/0.0, Pop 299792(S=0) *[LDP/9] 01:19:34, metric 1 > to 10.0.1.1 via ge-0/0/0.0, Pop
mpls.0ããŒãã«ã«ãããšãRR1ã¯ã©ãã«ïŒphpïŒãåé€ããASBR2ã«åããŠge-0 / 0 / 0.0ã€ã³ã¿ãŒãã§ã€ã¹ã«ãã±ãããéä¿¡ããŸãã
ASBR2ã¯ã299888ãšããã©ãã«ã1ã€ã ãä»ããããããåãåããŸããäœããã¹ãããèŠãŠãããŸãã
bormoglotx@ASBR1> show route table mpls.0 label 299888 mpls.0: 12 destinations, 12 routes (12 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 299888 *[VPN/170] 00:17:02 > to 10.2.0.2 via ge-0/0/3.0, Swap 26
ASBR1ã¯ã©ãã«299888ãã©ãã«26ã«ã¹ã¯ãããããžã§ã€ã³ããä»ããŠAS2ããASBR2ã«ãã±ãããéä¿¡ããŸãã
次ã«ãASBR2ã¯ã©ãã«26ãã©ãã«17ã«ã¹ã¯ããããŸãïŒPE2ããåãåã£ãïŒã
ASBR2#show ip bgp vpnv4 rd 2:1 10.0.1.0/24 BGP routing table entry for 2:1:10.0.1.0/24, version 4 Paths: (1 available, best #1, no table) Advertised to update-groups: 1 Local 10.1.10.1 (metric 3) from 10.1.10.10 (10.1.10.10) Origin incomplete, metric 0, localpref 100, valid, internal, best Extended Community: RT:1:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 Originator: 10.1.10.1, Cluster list: 10.1.10.10 mpls labels in/out 26/17
ãããã£ãŠããã¯ã¹ããããã«ãŒãã¯10.1.10.1ã§ãããããASBR2ã¯ãã©ã³ã¹ããŒãã©ãã«ïŒ19ïŒãPE2ã«è¿œå ããå¿ èŠããããŸãã
ASBR2#sh mpls forwarding-table 10.1.10.1 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 23 19 10.1.10.1/32 0 Gi1/0 10.1.0.2 19 10.1.10.1/32 0 Gi2/0 10.1.2.2
ãã¹ã¯åçã§ããããããã±ããã¯RR2ãŸãã¯P2ã«éä¿¡ãããŸããP2ããã®ãã±ããã§äœãè¡ãããèŠãŠã¿ãŸãããã
P1#sh mpls forwarding-table labels 19 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 19 Pop Label 10.1.10.1/32 1180 Gi1/0 10.1.3.1
P2ã¯ã¿ã°ãåé€ããåäžã¿ã°ã®ãã±ãããPE2ã«éä¿¡ããŸãã
PE2ã¯ãVRFã©ãã«ã§ããåäžã®ã©ãã«17ãæã€ãã±ãããåä¿¡ããŸãã ãã®å Žåããã¬ãã£ãã¯ã¹ã®ã©ãã«ã®é åžã䜿çšãããŸãïŒ1ã€ã®ã©ãã«-1ã€ã®ã¯ã©ã€ã¢ã³ããã¬ãã£ãã¯ã¹ïŒãããã¯å®éã«ã¯ç¡é§ã§ãããããã©ãã«é åžã¢ãŒãã-vrfïŒvrfã®1ã€ã®ã©ãã«ïŒã«åãæ¿ããå¿ èŠããããŸãã Ciscoãšã¯ç°ãªããJunOSã§ã¯ãããã©ã«ãã®ã©ãã«é åžã¡ã«ããºã ã¯ãã¯ã¹ããããããšã§ãã ã¯ã©ã€ã¢ã³ãã«ã€ãŒãµããããªã³ã¯ããããããã倧éšåã®å Žåã«èªç¶ã«çºçããå Žåã¯ãvrf-table-labelã³ãã³ãã§VRFããšã®ã©ãã«çæãæå¹ã«ããå¿ èŠããããŸãã ãã®å Žåã®ããã±ãŒãžã®åŠçã®ååã¯å€æŽãããŠãããå¥ã®èšäºã«å€ããŸãã
PE2#show mpls forwarding-table labels 17 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 17 No Label 10.0.1.0/24[V] 0 aggregate/CE1 PE2#sh ip bgp vpnv4 rd 2:1 10.0.1.0/24 BGP routing table entry for 2:1:10.0.1.0/24, version 2 Paths: (1 available, best #1, table CE1) Advertised to update-groups: 1 Local 0.0.0.0 from 0.0.0.0 (10.1.10.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best Extended Community: RT:1:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 mpls labels in/out 17/nolabel(CE1)
äžèšã®æ å ±ã«åŸã£ãŠãPE2ã¯ã©ãã«17ãåé€ããvrfããŒãã«CE1ã§ipã«ãã¯ã¢ãããè¡ãããã±ãããã¯ã©ã€ã¢ã³ãã«éä¿¡ããŸãã
ASBRã®æ§æïŒ
bormoglotx@ASBR1# show keep all; group RR { type internal; local-address 10.0.10.3; family inet-vpn { unicast; } export NHS; neighbor 10.0.10.10; } group ASBR-AS2 { type external; local-address 10.2.0.1; family inet-vpn { unicast; } peer-as 2; neighbor 10.2.0.2; }
ASBR2#sh configuration | b router bgp router bgp 2 no synchronization no bgp default route-target filter bgp log-neighbor-changes neighbor 10.1.10.10 remote-as 2 neighbor 10.1.10.10 description RR2 neighbor 10.1.10.10 update-source Loopback0 neighbor 10.2.0.1 remote-as 1 neighbor 10.2.0.1 description ASBR1 | AS2 neighbor 10.2.0.1 update-source GigabitEthernet3/0 no auto-summary ! address-family vpnv4 neighbor 10.1.10.10 activate neighbor 10.1.10.10 send-community extended neighbor 10.1.10.10 next-hop-self neighbor 10.2.0.1 activate neighbor 10.2.0.1 send-community extended exit-address-family ASBR2#sh run int gi3/0 Building configuration... Current configuration : 143 bytes ! interface GigabitEthernet3/0 description to ASBR1 | AS1 ip address 10.2.0.2 255.255.255.252 negotiation auto mpls bgp forwarding ! end
ãªãã·ã§ã³Bã«ã¯2ã€ã®ã¿ã€ããããããšãä»ãå ããŸããæåã®æ¹æ³-æãäžè¬çãªæ¹æ³-ãæ€èšããŸãããASBRã¯ãèªåŸã·ã¹ãã å ã§ã«ãŒãã転éãããšãïŒã«ãŒãããªãã¬ã¯ã¿ãŒã«è»¢éãããšãïŒã«ãã¯ã¹ããããã眮ãæããŸãã 2çªç®ã®æ¹æ³ã¯ããªãã¬ã¯ã¿ãŒãžã®ã«ãŒããã¢ããŠã³ã¹ãããšãã«ASBRãibgpã»ãã·ã§ã³ã®ã¯ããªã®ã§ããã¯ã¹ããããããã®ã¢ãã¬ã¹ã«çœ®ãæããªãã£ãããšã§ãã ãã ããASBRéã®ãããã¯ãŒã¯ã¯IGPã§ã¢ããŠã³ã¹ããå¿ èŠããããŸãïŒASBRéã®ãªã³ã¯ãããã·ãã«ããããASBRã«ã¹ã¿ãã£ãã¯ãç»é²ããŠIGPã§åé åžã§ããŸãïŒã ããã¯ãPEã«ãŒã¿ãŒãããŒãã«ãžã®BGPã«ãŒããèšå®ãïŒãã¯ã¹ããããã®å¯çšæ§ãã§ãã¯ïŒãldpããã®ãã¬ãã£ãã¯ã¹ã«ã©ãã«ãçæããããã«å¿ èŠã§ãã
ãªãã·ã§ã³Bã§æŽçããããšæããŸãã ãªãã·ã§ã³Cã«é²ã¿ãŸãããã
ãªãã·ã§ã³c
vpnv4ã«ãŒãã®äº€æã¯ãç°ãªãASã®ã«ãŒããªãã¬ã¯ã¿ãŒéã§ebgp-multihopã»ãã·ã§ã³ã«ãã£ãŠçŽæ¥å®è¡ãããŸããASBR-riesã¯ãmplsã©ãã«ãæã€ã«ãŒãããã«ãŒããªãã¬ã¯ã¿ãŒã®ã«ãŒãããã¯ããã³é£æ¥ããèªåŸã·ã¹ãã ã®PEã«ãŒã¿ãŒã«é åžããã¿ã¹ã¯ãæã£ãŠããŸãã
ã³ã³ãããŒã«ãã¬ãŒã³ã®ä»çµã¿ãèŠãŠã¿ãŸãããã
ã©ãã«é åžïŒ
1. ldpãä»ããASBR2ã¯ãPE2ã®ãã€ããŒããã©ãã«ãåä¿¡ããŸãã
2.èšå®ãããããªã·ãŒã«åŸã£ãŠãASBR2ã¯èªåŸã·ã¹ãã ã®æœ€æ»æ²¹ãžã®ã©ãã«ä»ãã®ã«ãŒããçæããbgpã©ãã«ä»ããŠããã£ã¹ããä»ããŠãããã®ã«ãŒããASBR1ã«è»¢éãããã¯ã¹ããããã«ãŒãã«èªèº«ã瀺ããŸãã
3. ASBR1ã¯ãASBR2ããã®ã©ãã«ä»ããŠããã£ã¹ãã«ãŒããåãå ¥ããmpls転éããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
4. ASBR1ã¯ãASBR2ããåä¿¡ããã«ãŒãã®ã©ãã«ãçæãããã¯ã¹ããããèªäœã瀺ããRR1ãžã®ã«ãŒããæäŸããŸãã
5.ãããã®ã«ãŒããåä¿¡ããRR1ã¯ãã«ãŒãã®æå¹æ§ã確èªããã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŠãä»ã®ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã«éä¿¡ããŸãã
6. PE1ã¯ãã©ãã«ä»ããŠããã£ã¹ãã«ãŒã¿ãŒããã«ãŒããåä¿¡ããæ€èšŒããŠãã«ãŒãã£ã³ã°ããŒãã«ã«ã«ãŒããã€ã³ã¹ããŒã«ããŸãã
VRFã¿ã°ã®é åžïŒ
1. PE2ã¯vpnv4ã«ãŒããçæããRR2ã«ãŒã¿ãŒã«éä¿¡ããŸãã
2. RR2ã«ãŒãã£ã³ã°ãªãã¬ã¯ã¿ãŒã¯ããã¯ã¹ãããããšã©ãã«ã®å€ãå€æŽããã«ãeBGPãã«ããããã»ãã·ã§ã³ãä»ããŠãã®ã«ãŒãããã¹ãŠã®ã¯ã©ã€ã¢ã³ããšRR1ã«è»¢éããŸãã
3. RR1ã¯ãRR2ããåä¿¡ããã«ãŒãããPE1ãå«ããã¹ãŠã®ã¯ã©ã€ã¢ã³ãã«è»¢éããŸãã
4. PE1ã¯ãã«ãŒãã®é©åæ§ã確èªãã察å¿ããVRFãã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
Vrfã¿ã°ãšãã©ã³ã¹ããŒãã¿ã°ãé åžãããŸãã
次ã«ãå®éã«ã©ã®ããã«æ©èœããããèŠãŠã¿ãŸãããã ãŸããèªåŸã·ã¹ãã éã§ã«ãŒãããã¯ã«ãŒããé åžããå¿ èŠããããŸããããã¯ããªã¢ãŒãã«ãŒããªãã¬ã¯ã¿ãŒãžã®ã«ãŒãããªããããã«ãŒããªãã¬ã¯ã¿ãŒéã®vpnv4ã»ãã·ã§ã³ãå¢å ããªãããã§ãã èªåŸã·ã¹ãã éã§ã©ãã«ä»ãã®ã«ãŒããããã«é åžãããããASBRéã®ã©ãã«ä»ããŠããã£ã¹ãã»ãã·ã§ã³ã®ã¿ãååšããŸãïŒã©ãã«ã®ãªãipv4ãã¬ãã£ãã¯ã¹ã¯äžèŠã§ãïŒããã ããäž¡æ¹ã®ã¢ãã¬ã¹ãã¡ããªãå¿ èŠãªå Žåã¯ãã©ãã«ä»ããŠããã£ã¹ãã«ãŒããinet.3ã«ã€ã³ã¹ããŒã«ããå¿ èŠãããããšãæå®ããå¿ èŠããããŸãïŒãã以å€ã®å ŽåãJunOSã§ã¯ãåãã»ãã·ã§ã³ã§2ã€ã®ipv4ããã³ipv4ã©ãã«ä»ããŠããã£ã¹ãã¢ãã¬ã¹ãã¡ããªãçºçãããŸããïŒã
ASBR1ã§ã®Bgpèšå®ïŒASBR2ãšã®ã»ãã·ã§ã³ïŒïŒ
bormoglotx@ASBR1> show configuration protocols bgp group ASBR-AS2 type external; local-address 10.2.0.1; family inet { labeled-unicast; } export Lo-export; peer-as 2; neighbor 10.2.0.2;
bormoglotx@ASBR1> show configuration policy-options policy-statement Lo-export term 1 { from { protocol isis; route-filter 10.0.10.0/24 prefix-length-range /32-/32; } then accept; } term 2 { then reject;
ããŒãã³ã°ã·ã¹ãã ãPE2ã«ãŒãããã¯ãŸã§ã©ã®ããã«æ©èœããããèŠãŠã¿ãŸãããã
ãã®ãããèªåŸã·ã¹ãã å ã§ã¯ãã«ãŒãããã¯ãASå šäœã«èªåçã«åæ£ãããåã«ãldpãå®è¡ãããã©ãã«ããããŸããåœç¶ãASBR2ã«ã¯ããã¹ãŠã®AS2ã«ãŒã¿ãŒã®ã«ãŒãããã¯ãŸã§ã®ã©ãã«ããããŸããããã§ãASBR2ã¯ASã®ã«ãŒãããã¯ãžã®ã©ãã«ä»ãã®ã«ãŒããçæããASBR1ã«è»¢éããå¿ èŠããããŸããèŠãŠã¿ãŸãããïŒ
ASBR2#sh ip bgp 10.1.10.1/32 BGP routing table entry for 10.1.10.1/32, version 2 Paths: (1 available, best #1, table default) Advertised to update-groups: 1 2 Local 10.1.0.2 from 0.0.0.0 (10.1.10.3) Origin incomplete, metric 3, localpref 100, weight 32768, valid, sourced, best mpls labels in/out 22/nolabel
åºåãããããããã«ãASBR2ã¯22ã«çãããã¬ãã£ãã¯ã¹10.1.10.1ããinã®åã«ã©ãã«ãçæã
ãŸãããASBR1ã§ãã®ã«ãŒããèŠãŠã¿ãŸãããã
bormoglotx@ASBR1> show route receive-protocol bgp 10.2.0.2 10.1.10.1/32 detail inet.0: 17 destinations, 20 routes (17 active, 0 holddown, 0 hidden) * 10.1.10.1/32 (1 entry, 1 announced) Accepted Route Label: 22 Nexthop: 10.2.0.2 MED: 3 AS path: 2 ?
åºåã©ãã«ïŒ22ããã³next-hopïŒ10.2.0.2ïŒASBR2ã€ã³ã¿ãŒãã§ãŒã¹ã®ã¢ãã¬ã¹ïŒã«é¢å¿ããããŸããããã§ãASBR1ã¯PE2ã«å°éããæ¹æ³ãèªèããŸããã
ããã«ããã®ã«ãŒãã¯ãã©ãã«ä»ããŠããã£ã¹ãã»ãã·ã§ã³ãä»ããŠãªãã¬ã¯ã¿ã«éä¿¡ãããããããPEã«ãŒã¿éã®èªåŸã·ã¹ãã å ã«é ä¿¡ãããŸãããã ããããã«1ã€ã®ããšããããŸããASBR1ãASBR2ããåä¿¡ããã®ãšåã圢åŒã§ã«ãŒããæž¡ãå ŽåãèªåŸã·ã¹ãã å ã®ãããã¯ãŒã¯10.2.0.0/30ïŒASBRéã®ãããã¯ãŒã¯ïŒãžã®ã«ãŒãããªããããæ©èœããŸããããããã£ãŠãASBR1ã¯ãã¯ã¹ãããããããèªäœã«å€æŽããæ°ããã©ãã«ãçæããŸãã
bormoglotx@ASBR1> show route advertising-protocol bgp 10.0.10.10 10.1.10.1/32 detail inet.0: 17 destinations, 20 routes (17 active, 0 holddown, 0 hidden) * 10.1.10.1/32 (1 entry, 1 announced) BGP group RR type Internal Route Label: 299920 Nexthop: Self Flags: Nexthop Change MED: 3 Localpref: 100 AS path: [1] 2 ?
次ã«ãPE1ã§ãã®ã«ãŒããèŠãŠã¿ãŸãããã
bormoglotx@PE1> show route protocol bgp 10.1.10.1/32 inet.0: 15 destinations, 15 routes (15 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.1.10.1/32 *[BGP/170] 00:26:35, MED 3, localpref 100, from 10.0.10.10 AS path: 2 ? > to 10.0.2.2 via ge-0/0/0.0, Push 299920, Push 299776(top) to 10.0.0.2 via ge-0/0/1.0, Push 299920, Push 299776(top) inet.3: 7 destinations, 7 routes (7 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.1.10.1/32 *[BGP/170] 00:26:35, MED 3, localpref 100, from 10.0.10.10 AS path: 2 ? > to 10.0.2.2 via ge-0/0/0.0, Push 299920, Push 299776(top) to 10.0.0.2 via ge-0/0/1.0, Push 299920, Push 299776(top)
ããã§ããã©ãã«299920ã¯PE2ã«å°éããããã«äœ¿çšãããŸããåºåã«ã¯ãå¥ã®ã©ãã«299776ã衚瀺ãããŸããã€ãŸããã©ãã«ã®ã¹ã¿ãã¯ããããŸãã2çªç®ïŒ299776ïŒã®ä»»åœã¯ä»¥äžã«èšèŒãããŸãïŒã
OKãPE1ãšPE2ã®éã«ãšã³ãããŒãšã³ãã®lspãã§ããŸãããå®éã«ã¯ãRR1ãšRR2ãžã®ã«ãŒãã«ãã©ãã«ãä»ããããŠããããããªãã¬ã¯ã¿ãŒéã«ã¯lspããããŸããèªåŸã·ã¹ãã éã§ã«ãŒãããã¯ã«ãŒããé åžããåŸãã«ãŒããªãã¬ã¯ã¿ãŒéã§è¿é£ãäžæããŸãã
bormoglotx@RR1> show bgp neighbor 10.1.10.10 Peer: 10.1.10.10+34875 AS 2 Local: 10.0.10.10+179 AS 1 Type: External State: Established Flags: <Sync> Last State: OpenConfirm Last Event: RecvKeepAlive Last Error: None Options: <Multihop NoNextHopChange Preference LocalAddress Ttl AddressFamily PeerAS Rib-group Refresh> Address families configured: inet-vpn-unicast Local Address: 10.0.10.10 Holdtime: 90 Preference: 170 Number of flaps: 0 Peer ID: 10.1.10.10 Local ID: 10.0.10.10 Active Holdtime: 90 Keepalive Interval: 30 Peer index: 0 BFD: disabled, down NLRI for restart configured on peer: inet-vpn-unicast NLRI advertised by peer: inet-unicast inet-vpn-unicast NLRI for this session: inet-vpn-unicast Peer supports Refresh capability (2) Stale routes from peer are kept for: 300 Peer does not support Restarter functionality Peer does not support Receiver functionality Peer supports 4 byte AS extension (peer-as 2) Peer does not support Addpath Table bgp.l3vpn.0 Bit: 20001 RIB State: BGP restart is complete RIB State: VPN restart is complete Send state: in sync Active prefixes: 2 Received prefixes: 2 Accepted prefixes: 2 Suppressed due to damping: 0 Advertised prefixes: 2 Last traffic (seconds): Received 20 Sent 13 Checked 68 Input messages: Total 210 Updates 3 Refreshes 0 Octets 4222 Output messages: Total 212 Updates 2 Refreshes 0 Octets 4205 Output Queue[1]: 0
Vpnv4ã«ãŒãã¯ããªãã¬ã¯ã¿ãŒéã§é åžãããŸãããã®ã»ãã·ã§ã³ã®NLRIïŒinet-vpn-unicastã
è¿é£ãã2ã€ã®ãã¬ãã£ãã¯ã¹ãåãå ¥ããŸãïŒåãå ¥ãããããã¬ãã£ãã¯ã¹ïŒ2
ãããŠãåãéãäžããŸãïŒåºåããããã¬ãã£ãã¯ã¹ïŒ2
ããã¯ç解ã§ãããšæããŸãã
ãªãã¬ã¯ã¿ãŒèšå®ïŒ
bormoglotx@RR1# show protocols bgp group RR-AS2 type external; multihop { ttl 5; no-nexthop-change; } local-address 10.0.10.10; family inet-vpn { unicast; } peer-as 2; neighbor 10.1.10.10;
RR2#sh configuration | b router bgp router bgp 2 bgp log-neighbor-changes neighbor 10.0.10.10 remote-as 1 neighbor 10.0.10.10 ebgp-multihop 5 neighbor 10.0.10.10 update-source Loopback0 ! address-family vpnv4 neighbor 10.0.10.10 activate neighbor 10.0.10.10 send-community extended neighbor 10.0.10.10 next-hop-unchanged exit-address-family
泚ïŒRR2æ§æïŒCisco IOS15ïŒã§ã¯ãåºåãµã€ãºãåæžããããã«ã10.0.10.10以å€ã®è¡ãåé€ãããŸãã
ããã§ãvrfã©ãã«é åžã®ä»çµã¿ã確èªã§ããŸã
ãPE2ã¯10.0.1.0/24ãããã¯ãŒã¯ãžã®ã«ãŒããçæããvrf CE1ã§çµç«¯ããŸã
PE2#sh ip bgp vpnv4 rd 2:1 10.0.1.0/24 BGP routing table entry for 2:1:10.0.1.0/24, version 2 Paths: (1 available, best #1, table CE1) Advertised to update-groups: 1 Local 0.0.0.0 from 0.0.0.0 (10.1.10.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best Extended Community: RT:1:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 mpls labels in/out 22/nolabel(CE1)
ã芧ã®ãšãããã©ãã«22ãçæãããŸããã
次ã«ãã«ãŒããRR2ã«äžããããŸãã
PE2#sh ip bgp vpnv4 all neighbors 10.1.10.10 advertised-routes BGP table version is 7, local router ID is 10.1.10.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 2:1 (default for vrf CE1) *> 10.0.1.0/24 0.0.0.0 0 32768 ? *> 10.1.1.2/32 10.0.1.2 2 32768 ? Total number of prefixes 2
ã«ãŒããªãã¬ã¯ã¿ã¯ãRR1ã ãã§ãªãããã¹ãŠã®é¡§å®¢ã«ãã®ã«ãŒããæäŸããŸãã
RR2#sh ip bgp vpnv4 rd 2:1 neighbors 10.0.10.10 advertised-routes BGP table version is 5, local router ID is 10.1.10.10 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 2:1 *>i10.0.1.0/24 10.1.10.1 0 100 0 ? *>i10.1.1.2/32 10.1.10.1 2 100 0 ? Total number of prefixes 2
RR1ã§åä¿¡ããã«ãŒããèŠãŠã¿ãŸãããã
bormoglotx@RR1> show route table bgp.l3vpn.0 10.0.1.0/24 bgp.l3vpn.0: 4 destinations, 4 routes (2 active, 0 holddown, 2 hidden)
ã«ãŒãã¯é衚瀺ã«ãªããé åžãããªããªããŸããã質åã¯-ãªãã§ããïŒïŒããã«ãã·ã¹ã³ã«ã¯ãã®ãããªçœå®³ã¯ãããŸããïŒ
bormoglotx@RR1> show route table bgp.l3vpn.0 10.0.1.0/24 hidden bgp.l3vpn.0: 4 destinations, 4 routes (2 active, 0 holddown, 2 hidden) + = Active Route, - = Last Active, * = Both 2:1:10.0.1.0/24 [BGP/170] 00:29:12, localpref 100, from 10.1.10.10 AS path: 2 ? Unusable
ãã®çç±ãèŠãŠã¿ãŸãããïŒ
bormoglotx@RR1> show route table bgp.l3vpn.0 10.0.1.0/24 hidden detail bgp.l3vpn.0: 4 destinations, 4 routes (2 active, 0 holddown, 2 hidden) 2:1:10.0.1.0/24 (1 entry, 0 announced) BGP Preference: 170/-101 Route Distinguisher: 2:1 Next hop type: Unusable Address: 0x8f3c5a4 Next-hop reference count: 2 State: <Hidden Ext> Local AS: 1 Peer AS: 2 Age: 31:00 Task: BGP_2.10.1.10.10+34875 AS path: 2 ? Communities: target:1:100 domain-id:0:131584 route-type-vendor:0.0.0.0:2:0 router-id-vendor:10.0.1.1:0 Accepted VPN Label: 22 Localpref: 100 Router ID: 10.1.10.10
Next hop typeã®å察åŽã®åºåã¯Unusableã§ããã«ãŒããªãã¬ã¯ã¿ãŒã¯ããã¯ã¹ããããã®å¯çšæ§ã«ã€ããŠã«ãŒãããã§ãã¯ããŸããããã«ãŒãã£ã³ã°ããŒãã«ã§æå®ããããã¯ã¹ãããããžã®ã«ãŒããèŠã€ãããŸããã§ããã
ã«ãŒãã£ã³ã°ããŒãã«ãèŠãŠã¿ãŸãããã
bormoglotx@RR1> show route 10.1.10.1/32 inet.0: 15 destinations, 15 routes (15 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.1.10.1/32 *[BGP/170] 00:33:04, MED 3, localpref 100, from 10.0.10.3 AS path: 2 ? > to 10.0.1.1 via ge-0/0/0.0, Push 299920
ã©ãã«ããã£ãŠãã«ãŒãããããŸãïŒè«ççã«ã¯ãASBR1ããã©ãã«ä»ããŠããã£ã¹ãã«é åžããŸããïŒãå®éãJunOSã«ã¯ïŒä»ã®ãã³ããŒãšã¯ç°ãªãïŒããã€ãã®ã«ãŒãã£ã³ã°ããŒãã«ããããŸããããã§ãããŒãã«inet.0ããã³inet.3ã«æ³šç®ããŸãã
inet.0ã¯ãipv4ãŠããã£ã¹ãã«ãŒããä¿åãããã«ãŒãã£ã³ã°ããŒãã«ã§ãã
inet.3-ipv4 mplsã«ãŒããä¿åãããã«ãŒãã£ã³ã°ããŒãã«ãã«ãŒã¿ã¯ãå ¥åLSRã§ããå Žåããã®ããŒãã«ã䜿çšããŸãã
vpnv4ã«ãŒããåä¿¡ããBGPã¯ãinet.3ããŒãã«ã®ãã¯ã¹ããããã®è§£æ±ºãè©Šã¿ãŸããããã©ã«ãã§ã¯ãbgpã©ãã«ä»ããŠããã£ã¹ãã«ãŒãã¯inet.0ããŒãã«ã«ã€ã³ã¹ããŒã«ãããinet.3ã«ã¯åé¡ãããŸãããã€ãŸããã«ãŒããªãã¬ã¯ã¿ã¯vpnv4ã«ãŒããåä¿¡ãããã¯ã¹ããããã解決ããããšããŸãããinet.3ããŒãã«ã§ãã®ã«ãŒããžã®ã«ãŒããèŠã€ããããã䜿çšã§ããªããã¯ã¹ããããã«ããvpnv4ã«ãŒããé衚瀺ãšããŠããŒã¯ããŸãã
ãã®åäœãå€æŽããå¿ èŠããããŸãã圌ã®ããã«ããã€ãã®ã¬ããŒããããŸãã
RESOLVE-VPN㯠-ãã®ã³ãã³ãã¯ãJUNOSæšèããŠããã£ã¹ãã«ãŒãã£ã³ã°ããŒãã«å ã®ã«ãŒããèšçœ®ã«é¢ããããã©ã«ãã®åäœãå€æŽããŸããããã§ãJunOSã¯bgpã©ãã«ä»ããŠããã£ã¹ãã«ãŒããinet.0ããŒãã«ãšinet.3ããŒãã«ã®äž¡æ¹ã«ã€ã³ã¹ããŒã«ããŸãã
ãªãã°ã«ãŒã-éåžžã«æè»ãªã¡ã«ããºã ã§ãããªã·ãŒã䜿çšããŠç¹å®ã®ã«ãŒãïŒèã®äžã®/ 32ãã¬ãã£ãã¯ã¹ïŒãããã«ãŒãã£ã³ã°ããŒãã«ããå¥ã®ã«ãŒãã£ã³ã°ããŒãã«ïŒãã®å Žåãinet.0ããinet.3ïŒã«ãã©ãã°ã§ããŸããããªãã°ã«ãŒãã«ã¯æ³šæããå¿ èŠããããŸããäœãããŠããã®ããæ確ã«ç解ããããšãªãfireãå£ãããšãã§ããŸãïŒrib骚ã°ã«ãŒãã®å¯èœæ§ã¯éåžžã«å€§ããã§ãïŒã
resolution rib bgp.l3vpn.0 resolution-ribs inet.0-ãã®ã³ãã³ãã䜿çšãããšãã©ãã«ãäœã転éã§ããŸããããinet.0ããŒãã«å ã®vpnv4ã«ãŒãã®ã¿ãã«ãŒã¿ãŒã«åŒ·å¶çã«è§£æ±ºãããŸãã
ã«ãŒã¿ã§ã¯ãã³ãã³ã解決ãªããæå®ããPEã«ãŒã¿ã§ã¯resolve-vpnãæå®ããŸãã
bormoglotx@RR1# show routing-options router-id 10.0.10.10; autonomous-system 1; resolution { rib bgp.l3vpn.0 { resolution-ribs inet.0; } }
ããã§ããªãã¬ã¯ã¿ãŒäžã®ã«ãŒãã衚瀺ãããèªåŸã·ã¹ãã å ã§é åžã§ããŸãã
bormoglotx@RR1> show route receive-protocol bgp 10.1.10.10 inet.0: 15 destinations, 15 routes (15 active, 0 holddown, 0 hidden) inet.3: 3 destinations, 3 routes (3 active, 0 holddown, 0 hidden) iso.0: 1 destinations, 1 routes (1 active, 0 holddown, 0 hidden) mpls.0: 9 destinations, 9 routes (9 active, 0 holddown, 0 hidden) bgp.l3vpn.0: 4 destinations, 4 routes (4 active, 0 holddown, 0 hidden) Prefix Nexthop MED Lclpref AS path 2:1:10.0.1.0/24 * 10.1.10.1 2 ? 2:1:10.1.1.2/32 * 10.1.10.1 2 ?
詳现ãšãšãã«ã«ãŒãèªäœãèŠãŠã¿ãŸãããïŒ
bormoglotx@RR1> show route protocol bgp rd-prefix 2:1:10.0.1.0/24 detail bgp.l3vpn.0: 4 destinations, 4 routes (4 active, 0 holddown, 0 hidden) 2:1:10.0.1.0/24 (1 entry, 1 announced) *BGP Preference: 170/-101 Route Distinguisher: 2:1 Next hop type: Indirect Address: 0x934d6d8 Next-hop reference count: 1 Source: 10.1.10.10 Protocol next hop: 10.1.10.1 Push 22 Indirect next hop: 2 no-forward State: <Active Ext> Local AS: 1 Peer AS: 2 Age: 11:55 Metric2: 1 Task: BGP_2.10.1.10.10+34875 Announcement bits (1): 0-BGP_RT_Background AS path: 2 ? Communities: target:1:100 domain-id:0:131584 route-type-vendor:0.0.0.0:2:0 router-id-vendor:10.0.1.1:0 Accepted VPN Label: 22 Localpref: 100 Router ID: 10.1.10.10
çµè«ã¯ãèªåŸã·ã¹ãã ã®å¢çãè¶ããŠããã¯ã¹ãããããå€åããªãããšã瀺ããŠããŸããããã¯ebgpã«ã¯äžè¬çã§ã¯ãããŸãããå®éã«ã¯ãæ§æïŒäžèšïŒã«ã¯no-nexthop-changeã³ãã³ãããããŸã-JunOSãnext-hop-unchanged-Ciscoãebgpã®æšæºåäœãå€æŽããèªåŸã·ã¹ãã ã®å¢çãè¶ãããšãã®ãã¯ã¹ããããã®å€æŽãèš±å¯ããŸãããããã¯äœã®ããã§ããïŒãã®ã³ãã³ããæå®ããªãå Žåããã¹ãŠã®vpnv4ã«ãŒãã§ã«ãŒã¿ãŒã¯æ¬¡ã®ãããã«é²ã¿ãŸããã€ãŸãããã¹ãŠã®vpnãã©ãã£ãã¯ãã«ãŒã¿ãŒãééããŸãããããã¯äººçã§ããã»ã©çããªãã§ããçŸåšãå€æ°ã®ã«ãŒããæ¶åããããšã«å ããŠïŒç¹ã«FVãããå ŽåïŒãèšå€§ãªéã®ãã©ãã£ãã¯ãåŠçããå¿ èŠããããŸããå®éã«ã¯ãçµããã¯åžžã«1ã€ã§ãããã®åè·¯ã¯ããã¹ãŠã®çµæã䌎ãã«ãŒã¿ãŒã®èœäžã«å€±æããŸããããã«ã2ã€ã®åé·ãªãã¬ã¯ã¿ãŒãååšããŠãã圹ã«ç«ã¡ãŸããããã ããããããžã«æ»ããPE1ã§vpnv4ã«ãŒãã確èªããŸãïŒresolve-vpnã³ãã³ããæ¢ã«äžããããšãå¿ããªãã§ãã ãããããããªããšãã«ãŒããé衚瀺ã«ãªããŸãïŒã
bormoglotx@PE1> show configuration protocols bgp group RR type internal; local-address 10.0.10.1; family inet { labeled-unicast { resolve-vpn; } } family inet-vpn { unicast; } neighbor 10.0.10.10;
bormoglotx@PE1> show route table CE1.inet.0 10.0.1.0/24 detail CE1.inet.0: 6 destinations, 6 routes (6 active, 0 holddown, 0 hidden) 10.0.1.0/24 (1 entry, 1 announced) *BGP Preference: 170/-101 Route Distinguisher: 2:1 Next hop type: Indirect Address: 0x934d2e8 Next-hop reference count: 3 Source: 10.0.10.10 Next hop type: Router, Next hop index: 608 Next hop: 10.0.2.2 via ge-0/0/0.0, selected Label operation: Push 22, Push 299920, Push 299776(top) Label TTL action: prop-ttl, prop-ttl, prop-ttl(top) Protocol next hop: 10.1.10.1 Push 22 Indirect next hop: 94a0658 262151 State: <Secondary Active Int Ext> Local AS: 1 Peer AS: 1 Age: 39:28 Metric2: 1 Task: BGP_1.10.0.10.10+179 Announcement bits (2): 0-CE1-OSPF 1-KRT AS path: 2 ? Communities: target:1:100 domain-id:0:131584 route-type-vendor:0.0.0.0:2:0 router-id-vendor:10.0.1.1:0 Import Accepted VPN Label: 22 Localpref: 100 Router ID: 10.0.10.10 Primary Routing Table bgp.l3vpn.0
次ã®è¡ã«é¢å¿ããããŸãã
ãããã³ã«ãã¯ã¹ããããïŒ10.1.10.1
ããã·ã¥22
VPNã©ãã«ïŒ22
ã¢ã©ãŒã ãæ©èœããŸãããPEã«ãŒã¿ãŒãšvrfã¿ã°ã®éã«lspãã§ããŸããã
ããŒã¿ãã¬ãŒã³ïŒ
次ã«ãä¿¡å·çµè·¯ã«æ²¿ã£ãŠãã©ãã£ãã¯ãã©ã®ããã«éä¿¡ãããããèŠãŠã¿ãŸãããã
ãŸããCEéã®æ¥ç¶ã確èªããŸãã
CE1#ping 10.0.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.0.1.2, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 48/57/68 ms
çŽ æŽãããã ããã§ãã¬ãŒã¹ãäœæã§ããŸãã
R5#traceroute 10.0.1.2 Type escape sequence to abort. Tracing the route to 10.0.1.2 1 10.0.0.1 4 msec 4 msec 8 msec 2 10.0.2.2 [MPLS: Labels 299776/299920/22 Exp 0] 48 msec 48 msec 12 msec 3 10.0.3.1 [MPLS: Labels 299920/22 Exp 0] 76 msec 56 msec 36 msec 4 10.2.0.2 [MPLS: Labels 22/22 Exp 0] 48 msec 12 msec 76 msec 5 10.1.2.2 [MPLS: Labels 17/22 Exp 0] 40 msec 52 msec 44 msec 6 10.0.1.1 44 msec 60 msec 48 msec 7 10.0.1.2 44 msec 56 msec 56 msec
3ã€ã®ã¿ã°ã®ã¹ã¿ãã¯ã衚瀺ãããŸãã
ããã§ãPE1äžã®ã¯ã©ã€ã¢ã³ããã¬ãã£ãã¯ã¹10.0.1.0/24ãžã®ã«ãŒããèŠãŠã¿ãŸãããã
bormoglotx@PE1> show route table CE1.inet.0 10.0.1.0/24 CE1.inet.0: 6 destinations, 6 routes (6 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.0.1.0/24 *[BGP/170] 00:39:25, localpref 100, from 10.0.10.10 AS path: 2 ? > to 10.0.2.2 via ge-0/0/0.0, Push 22, Push 299920, Push 299776(top)
PE1ã¯3ã€ã®ã©ãã«ããã³ã°ãããŸãïŒ
22-PE2
299920 ãããªãã¬ã¯ã¿ãŒ
ãä»ããŠåä¿¡ããVRFã©ãã«-ASBR1 299776 ããã«ãŒãã£ã³ã°ãªãã¬ã¯ã¿ãŒãä»ããŠåä¿¡ããPE2ã«ãŒãããã¯ãžã®ã©ãã«-LDPãä»ããŠåä¿¡ããASBR1ãžã®ã©ãã«
ã 2.2 ge-0 / 0çµç±/ 0.0
bormoglotx@PE1> show interfaces descriptions Interface Admin Link Description ge-0/0/0 up up to P1 ge-0/0/1 up up to RR1 ge-0/0/3 up up to SW1 lo0 up up router-id
泚ïŒlabeled-unicastã«ãã£ãŠã©ãã«ãPE2ã«é åžãããããP1ã«ã¯PE2ã«å¯Ÿããã©ãã«ããããŸããã2ã€ã®ã¿ã°ãå«ããã±ãããéä¿¡ãããšãP1ã¯ãã®ã¿ã°ãã©ãããããç¥ããŸããããããã£ãŠãASBR1ã«ãã1ã€ã®ã©ãã«ãè¿œå ããå¿ èŠããããŸããP1ã¯ãé£æ¥ASãžã®ãã©ãã£ãã¯ã§ãããšçããã«ãã®ãã©ãã£ãã¯ãåŠçããŸãïŒãããã©ãã«ã§ã®ã¿åäœããŸãïŒãã€ãŸããASBR1ãPE2ã«ã€ããŠlspããã³ããªã³ã°ããåã«lspã«ããŸãã
P1ãåä¿¡ãããã±ãããã©ãåŠçããããèŠãŠã¿ãŸãããã
bormoglotx@P1> show route table mpls.0 label 299776 mpls.0: 9 destinations, 9 routes (9 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 299776 *[LDP/9] 01:13:09, metric 1 > to 10.0.3.1 via ge-0/0/1.0, Pop 299776(S=0) *[LDP/9] 01:13:09, metric 1 > to 10.0.3.1 via ge-0/0/1.0, Pop
ãã¹ãŠãè«ççã§ãP1ã¯ãããã©ãã«ãåé€ãïŒphpã¡ã«ããºã ïŒã2ã€ã®ã©ãã«ã®ã¹ã¿ãã¯ãæã€ãã±ãããASBR1ã«æ¢ã«éä¿¡ããŸãã
ASBR1ã¯ããããã©ãã«ïŒPE2ã®åã®ã©ãã«ïŒãASBR2ããéç¥ãããã©ãã«ã«äº€æããŸãã
bormoglotx@ASBR1> show route table mpls.0 label 299920 mpls.0: 19 destinations, 19 routes (19 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 299920 *[VPN/170] 01:13:51 > to 10.2.0.2 via ge-0/0/3.0, Swap 22
泚ïŒéåžžã«æ確ã«å€æ-ã©ãã«22ã¯AS2ã«ãã£ãŠçæãããPE2ãéæãããŸããããã©ãã«22ã¯PE2ãVRFã©ãã«ãšããŠçæãããŸããããããã£ãŠãASBR1ãšASBR2ã®éã«ã¯ã2ã€ã®åäžã®ã©ãã«22/22ã®ã¹ã¿ãã¯ã§éä¿¡ããããã±ããããããŸããå®éã«ã¯ããããã¯2ã€ã®ç°ãªãã©ãã«ïŒæå³ãããšããïŒã§ããããã®å Žåã«åãã§ãããšããäºå®ã¯å¶ç¶ã§ãã
ãã®åŸããã±ããã¯ASBR2ã«éãããŸãã
ASBR2#sh mpls forwarding-table labels 22 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 22 18 10.1.10.1/32 0 Gi1/0 10.1.0.2 17 10.1.10.1/32 13378 Gi2/0 10.1.2.2
ASBR2ã¯ãã¹ã¿ãã¯ã®ãããã©ãã«ãã©ãã«18ãŸãã¯17ã«äº€æããŸãïŒåçã®ãã¹ããããŸãïŒã圌ã¯ãããã®ã©ãã«ãldpãããã³ã«ããååŸããŸããã
ASBR2#show mpls ldp bindings 10.1.10.1 32 lib entry: 10.1.10.1/32, rev 18 local binding: label: 22 remote binding: lsr: 10.1.10.2:0, label: 17 remote binding: lsr: 10.1.10.10:0, label: 18
ãã±ãããP2ã«éãããASBR2ããããã©ãã«ãã©ãã«17ã«ã¹ã¯ãããããšããŸããP2ã
äœãããããèŠãŠã¿ãŸãããã
P1#sh mpls forwarding-table labels 17 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 17 Pop Label 10.1.10.1/32 12936 Gi1/0 10.1.3.1
P2ã¯ã©ãã«ãåé€ããåäžã©ãã«ïŒvrfã©ãã«ïŒãæã€ãã±ãããPE2ã«éä¿¡ããŸãã
PE2ãã©ãã«22ã®ãã±ããã§äœãè¡ããã確èªããã ãã§ã
ãPE1ã¯MPLS転éããŒãã«ã調ã¹ãã©ãã«ãåé€ããCE1ããŒãã«ã§IPã«ãã¯ã¢ãããè¡ããGigabitEthernet3 / 0.10ã€ã³ã¿ãŒãã§ã€ã¹ã«ãã±ãããéä¿¡ããŸãã CE2ïŒ
PE2#sh mpls forwarding-table labels 22 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 22 No Label 10.0.1.0/24[V] 3296 aggregate/CE1
PE2#sh ip route vrf CE1 10.0.1.0 Routing Table: CE1 Routing entry for 10.0.1.0/24 Known via "connected", distance 0, metric 0 (connected, via interface) Redistributing via bgp 2 Advertised by bgp 2 Routing Descriptor Blocks: * directly connected, via GigabitEthernet3/0.10 Route metric is 0, traffic share count is 1
ãã®äŸã§ã¯ã3ã€ã®ã©ãã«ã®ã¹ã¿ãã¯ãæã€ã¹ããŒã ã䜿çšããŸããã 2ã€ã®ã¿ã°ã®ã¹ã¿ãã¯ã䜿çšãããªãã·ã§ã³ããããŸããéãã¯ãASBRãåä¿¡ããã«ãŒããIGPã«åé åžããå¿ èŠãããããšã§ãããã®åŸãldpã¯ã©ãã«ãè¿é£ã®èªåŸã·ã¹ãã ã®ã«ãŒãããã¯ã«é åžãå§ããŸãããå°ãªããšãbgpã«ãŒããigpã«å ¥ãããããç§ã¯å人çã«ãã®ãªãã·ã§ã³ã奜ãã§ã¯ãããŸããããã以å€ã®å Žåããã¹ãŠã¯äžèšã®ãã®ãšåæ§ã§ãã
ãããã®ãªãã·ã§ã³ã®åäœåçãèªè ã«äŒãããã®èšäºãl3vpnã®åé¡ã蚺æããéã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãããã®èšäºã¯éåžžã«å€§ããã1æ¥ä»¥äžæžãããŠããŸããã誰ããäœããè¿œå ãããããŸãã¯äœããã®æ¬ é¥ã«æ°ã¥ãããïŒçµå±ç§ã¯äººã§ãïŒãPMã«æžããŠãã ãããä¿®æ£ããŠè¿œå ããŸããã質åãããå Žåã¯ãã³ã¡ã³ããèšå ¥ããŠãã ãããå¯èœãªå Žåã¯ãçãããŸãããæž èŽããããšãããããŸããïŒ
AllTheThingsUndone.