ãªãã·ã§ã³A
ãã®ãªãã·ã§ã³ã®æå³ã¯ãASBRã§ã¯åã¯ã©ã€ã¢ã³ãvpnã«å¯ŸããŠåå¥ã®vrfsãçºçããçŽç²ãªipã«ãŒãã亀æããããµãã€ã³ã¿ãŒãã§ãŒã¹ãäœæãããåããµãã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ã転éãããããšã§ãã ASBRéã«mplsã¯ãããŸããã PEãšCEã«ãŒã¿ãŒéãªã©ãASBRéã®ã€ã³ã¿ãŒã¯ãŒãã³ã°ãçºçããŸãã
ãã®ãªãã·ã§ã³ã®æ¬ ç¹ã¯æããã§ãã
-PEã«ãŒã¿ã§VRFãäœæããããšã«å ããŠãASBRã§VRFãäœæããå¿ èŠããããŸãã
-ASBRéã§ã«ãŒãã亀æããã«ã¯ãåvrfã§ã«ãŒãã£ã³ã°ãããã³ã«ãäžããå¿ èŠããããŸããåœç¶ãããšãã°bgp-sessionsã®ããã«ãã«ãŒã¿ãŒã®ããã©ãŒãã³ã¹ã«å€§ããªåœ±é¿ãäžããŸããã
ããããé©ãããšã§ã¯ãããŸãããããã®ã¹ããŒã ã«ã¯æ¬¡ã®ãããªå©ç¹ããããŸãã
+ ASBRéã«ã¯MPLSãªãã®çŽç²ãªIPãã©ãã£ãã¯ããããããIPããããŒã«åºã¥ããŠQoSãšãã£ã«ã¿ãªã³ã°ãå®è£ ã§ããŸãã
+顧客ã®ãã©ãã£ãã¯ã¯æ確ã«åãããŠããŸãã
+ãã®ãªãã·ã§ã³ã¯æãå®å šã§ãïŒããšãã°ãä»ã®äººã®ã«ãŒããèªåŸã·ã¹ãã ã«æ³šå ¥ããããªãå Žåã«ãç°ãªããããã€ããŒéã§ãã®ãªãã·ã§ã³ãäžããããšãã§ããå ŽåïŒã
ãããããã¹ãŠåãã§ããããã®å Žåã®çæã¯é·æãäžåããŸãïŒ50-60 vpn-sãããŒã«ããå¿ èŠããããšæ³åããŠãã ãã-ãªãã·ã§ã³Aã䜿çšããããšãã欲æ±ã¯ããã«æ¶ããŸãïŒã ãããã£ãŠã圌ã®é ã®äžã§ã¯ãäžéšã®ãšã³ãžãã¢ããªãã·ã§ã³Aãäžããããšã¯æããªãã§ãããã
ãªãã·ã§ã³B
ãã®ãªãã·ã§ã³ã®æå³ã¯ãASBRãvpnv4ã«ãŒãã亀æããããšã§ãã é£æ¥ASããvpnv4ã«ãŒããåä¿¡ãããšãASBRã¯æ°ããã©ãã«ãçæãããã¯ã¹ããããïŒãªãã·ã§ã³BaïŒãšããŠèªèº«ãèšå®ãããããã¯ã¹ãããããå€æŽããïŒãªãã·ã§ã³BbïŒãã«ãŒãããªãã¬ã¯ã¿ãŒïŒãŸãã¯ããããžã«å¿ããŠPEã«ãŒã¿ãŒã«çŽã¡ã«è»¢éïŒã«è»¢éããŸãããã®åŸããã¹ãŠã®PEã«ãŒã¿ãŒã«å¿ èŠãªvpnv4ã«ãŒãããããŸãã
ãã®ã¢ãããŒãã®å©ç¹ïŒ
+èªåŸã·ã¹ãã éã§ã«ãŒãã転éããããã«å¿ èŠãªBGP vpnv4ã»ãã·ã§ã³ã¯1ã€ã ãã§ãASBRã«ã¯vrfã®ã«ãŒãã£ã³ã°ãããã³ã«ãããŒããããŠããŸããã
+ãã¹ãŠã®ãã¬ãã£ãã¯ã¹ã1ã€ã®ã»ãã·ã§ã³å ã§éä¿¡ãããããããã®ã¢ãããŒãã¯åªããã¹ã±ãŒã©ããªãã£ãåããŠããŸãïŒãªãã·ã§ã³Aãšæ¯èŒããŠïŒã
+æ°ããã¯ã©ã€ã¢ã³ãã®é»æºãå ¥ãããšãèšå®ãASBRã«å€æŽããå¿ èŠã¯ãããŸããïŒåœç¶ã®ããšãªããããã£ã«ã¿ãŒã¯äŸå€ã§ãïŒã
çæïŒ
-ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ã¯ãmplsã©ãã«ä»ãã®å ±éã¹ããªãŒã ã§éä¿¡ãããipããããŒã«åºã¥ããŠqosãŸãã¯ãã£ã«ã¿ãªã³ã°ãé©çšããããšã¯ã§ããŸããã
-ASBRã¯ããã©ãã£ãã¯è»¢éã«å ããŠããŒããããå€æ°ã®vpnv4ã«ãŒããæ¶åããŸãã
ãªãã·ã§ã³C
ãã®ãªãã·ã§ã³ã®æå³ã¯ãebgp-multihopã»ãã·ã§ã³ã®ç°ãªãèªåŸã·ã¹ãã ã®ã«ãŒããªãã¬ã¯ã¿ãŒéã§vpnv4ã«ãŒãã®äº€æãçºçããããšã§ãã 次ã«ãASBRã¯ã¿ã°ä»ãã«ãŒãïŒbgpã©ãã«ä»ããŠããã£ã¹ãïŒãè¿é£ã®èªåŸã·ã¹ãã ã«ã«ãŒãããã¯ã«ãŒã¿ãŒãšPEã«ãŒã¿ãŒã«éä¿¡ããŸãã ãã®çµæãASBRããåä¿¡ããã©ãã«ã䜿çšããŠãPEã«ãŒã¿ãŒã¯ãšã³ãããŒãšã³ãã®lspãæ§ç¯ã§ãããã¹ãŠã®PEã«ãŒã¿ãŒéã®vrfã©ãã«ã¯ã«ãŒãã£ã³ã°ãªãã¬ã¯ã¿ãŒã䜿çšããŠé åžãããŸãã
ãã®ãªãã·ã§ã³ã®ãã©ã¹ïŒ
+éåžžã«é«ãã¹ã±ãŒã©ããªãã£
+ ASBRã«äžå¿ èŠãªäœæ¥ãè² è·ããŸããïŒä»ã®ãªãã·ã§ã³ãšæ¯èŒããŠïŒ
ããããæ¬ ç¹ããããŸãïŒ
-ãªãã·ã§ã³Bãšåæ§ã«ãASBRéã®ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ã¯äžè¬çãªãããŒã«å ¥ããŸããããã§ã«2ã€ã®mplsã©ãã«ããããIPããããŒã«åºã¥ããŠASBRéã®QoSããã³ãã£ã«ã¿ãªã³ã°ãââã©ãã£ãã¯ãèš±å¯ããŸããã
ãã£ã«ã¿ãŒ/ QoSã1ã€ã®ã¢ãããŒãã§é©çšãããšåæã«ãå€æ°ã®bgpïŒospfãisisãripïŒãã€ããŒãç¶æããããã®äžèŠãªäœæ¥ã§ASBRã«è² æ ãããããASBRã®è€éãªæ§æãããšã³ãžãã¢ãæãå¯èœæ§ãçµã¿åãããæ¹æ³ã¯ïŒ
ãããã£ãŠãæ¬æ¥ã¯ã ASéãªãã·ã§ã³ABïŒDïŒã«ã€ããŠèª¬æããŸãã
ãã®ãªãã·ã§ã³ã¯ããªãã·ã§ã³Aãšåæ§ã«ãvpnããšã«ASBRã«åå¥ã®vrfãäœæããããšãããã³ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ãéä¿¡ããããã«äœ¿çšãããåvrfã«åå¥ã®ãµãã€ã³ã¿ãŒãã§ã€ã¹ãäœæããããšãæå³ããŸãã ãããŸã§ã®ãšããããã¹ãŠã¯æšæºãªãã·ã§ã³Aãšåãã§ããéèŠãªéãã¯ãvrfïŒASBRäžïŒã®ã«ãŒãã£ã³ã°ãããã³ã«ã¯èµ·åããããäœæããããµãã€ã³ã¿ãŒãã§ã€ã¹ã¯ãã©ãã£ãã¯è»¢éã«ã®ã¿äœ¿çšãããããšã§ãã ã«ãŒãã¯ã©ã®ããã«äº€æãããŸããïŒ ãã®ç®çã®ããã«ããªãã·ã§ã³Bãšåæ§ã«ãASBRéã«åäžã®vpnv4ã»ãã·ã§ã³ãäœæããããããä»ããŠvpnv4ã«ãŒããéä¿¡ãããŸãã å®éã2ã€ã®ASBRã®éã§ãªãã·ã§ã³Aãšãªãã·ã§ã³Bã®äž¡æ¹ãåæã«ç解ããŠãããšèšããŸãã 次ã«ãã³ã³ãããŒã«ãã¬ãŒã³ã®è©³çŽ°ãªèª¬æã«ç§»ãããã¹ãŠãé©åã«é 眮ãããããã«ããŸãã
1. PE2ã¯vpnv4ã«ãŒããçæããRR2ã«ãŒã¿ãŒã«éä¿¡ããŸãã
2.ã«ãŒãã¬ãã¬ã¯ã¿ãŒã¯åä¿¡ããã«ãŒããæ€èšŒãã顧客ã«æž¡ããŸãã ç§ãã¡ã®å ŽåãASBR2ã§ã
3. ASBR2ã¯vpnv4ã«ãŒããåä¿¡ããèšå®ãããã«ãŒãã¿ãŒã²ããã€ã³ããŒãã«åŸã£ãŠã察å¿ããVRFããã®å ŽåVRF VPN1-ASBR2ã®ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
4. ASBR2ã¯æ°ããvpnv4ã«ãŒããçæãããã®äžã§excommunityïŒã«ãŒãã¿ãŒã²ããïŒããã³ã°ãããŸããããã¯ãvrf VPN1-ASBR2ãžã®ãšã¯ã¹ããŒãçšã«ç€ºãããASBR1ã«ã«ãŒãã転éããŸãã 次ã®ãããã§ã¯ãéåžžã®ãªãã·ã§ã³Bãšåæ§ã«ãASBR2ã«ãŒã¿ãŒã®ã¢ãã¬ã¹ãèšå®ãããŸãïŒãã®vpnv4ã»ãã·ã§ã³ã®ãœãŒã¹ã§ããã€ã³ã¿ãŒãã§ãŒã¹ã®ã¢ãã¬ã¹ïŒã
5. ASBR1ã¯ãã®ã«ãŒããåãå ¥ããã«ãŒãã¿ãŒã²ããã€ã³ããŒãã«åŸã£ãŠããã®ã«ãŒãã察å¿ããvrfã®ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãããã®å Žåãvrf VPN1-ASBR1ã¯ãvrf VPN1-ASBR1ïŒinter-as hybrid next -hopïŒã ã¢ãã¬ã¹ASBR2ã«çœ®ãæããããŸãïŒçµåASBR2ïŒvrf VPN1-ASBR2ïŒ==> ASBR1ïŒvrf VPN1-ASBR1ïŒïŒã
6. ASBR1ã¯æ°ããvpnv4ã«ãŒããçæããexcommunityïŒã«ãŒãã¿ãŒã²ããïŒã§ãã³ã°ã¢ããããŸããããã¯vrf VPN1-ASBR1ã«ãšã¯ã¹ããŒããããRR1ã«ãŒã¿ãŒã«ã«ãŒããéä¿¡ããŸãïŒãã¯ã¹ãããã-ASBR1ã«ãŒãããã¯ïŒ
7. RR1ã¯PE1ã§ã«ãŒããã¢ããŠã³ã¹ããŸãã
8. RR1ããã«ãŒããåä¿¡ããPE1ã¯ã察å¿ããvrfã®ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ã¹ããŒã«ããŸãã
ãã®ãªãã·ã§ã³ã®äž»ãªãã®ã¯ãASBRãžã®vpnv4ã«ãŒããæåã«vrfã«åé¡ããããã®vrfããããã«ã¢ããŠã³ã¹ãããããšã§ããããã«ããšã¯ã¹ããŒãã®ããã«vrfã§æå®ãããexcommunityã§ã¢ããŠã³ã¹ãããŸããçºè¡šïŒã æŠç¥çã«ã¯ã次ã®ããã«ãªããŸãã
ã€ãŸããvpnv4ã«ãŒãã¯æ¬¡ã®é åºã§1ã€ã®ASããå¥ã®ASã«è»¢éãããŸããPE2==> RR2 ==> ASBR2 ==> ASBR2ïŒvrf VPN1-ASBR2ïŒ==> ASBR1 ==> ASBR1ïŒvrf VPN1-ASBR1ïŒ== > RR1 ==> PE1ã
ãããã£ãŠãäžèšã®ãã¹ãŠãäŸã§æ€èšããŸãã
2ã€ã®VRFãPE2ã«äœæãããŸãã
ip vrf VPN1-CE2 rd 2:1 route-target export 2:100 route-target import 1:100 route-target import 2:100 ! ip vrf VPN2-CE2 rd 2:2 route-target export 2:200 route-target import 1:200 route-target import 2:200
VRF VPN1-CE2ããã®10.0.1.0/24ã«ãŒãã·ã°ããªã³ã°ãæ€èšããŸãã
以äžã¯ãPE2ã«ãã£ãŠçæãããã«ãŒãã§ããvpnv4ã§ãã
PE2#sh ip bgp vpnv4 rd 2:1 10.0.1.0/24 BGP routing table entry for 2:1:10.0.1.0/24, version 2 Paths: (1 available, best #1, table VPN1-CE2) Advertised to update-groups: 3 Local 0.0.0.0 from 0.0.0.0 (10.1.10.1) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best Extended Community: RT:2:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 mpls labels in/out IPv4 VRF Aggr:22/nolabel(VPN1-CE2)
PE2ã§ã¯ã«ãŒããããŒã«ã«ã§ããããã®ãã¬ãã£ãã¯ã¹ã§ã¯çæãããã©ãã«22ã§ããããšãããããŸãã
ããã§ãPE2ã¯ãã®ã«ãŒããã«ãŒã¿ãŒã«éä¿¡ããå¿ èŠããããŸãã ãã§ãã¯ïŒ
PE2#show ip bgp vpnv4 rd 2:1 neighbors 10.1.10.10 advertised-routes BGP table version is 13, local router ID is 10.1.10.1 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 2:1 (default for vrf VPN1-CE2) *> 10.0.1.0/24 0.0.0.0 0 32768 ? *> 10.1.1.2/32 10.0.1.2 2 32768 ? Total number of prefixes 2
2ã€ã®ã«ãŒããçºè¡šããŠããŸãïŒ10.1.1.2ã¯ãospfãä»ããŠåä¿¡ããVPN1-CE2ã«ãŒã¿ãŒã®ã«ãŒãããã¯ã§ãïŒã ããã«ãã«ãŒãã¯ASBR2ã«è»¢éãããŸãã
RR2#sh ip bgp vpnv4 rd 2:1 neighbors 10.1.10.3 advertised-routes | i 10. BGP table version is 37, local router ID is 10.1.10.10 *>i10.0.1.0/24 10.1.10.1 0 100 0 ? *>i10.1.1.2/32 10.1.10.1 2 100 0 ?
ASBR2#sh ip bgp vpnv4 rd 2:1 10.0.1.0/24 BGP routing table entry for 2:1:10.0.1.0/24, version 100 Paths: (1 available, best #1, no table) Not advertised to any peer Local 10.1.10.1 (metric 3) from 10.1.10.10 (10.1.10.10) Origin incomplete, metric 0, localpref 100, valid, internal, best Extended Community: RT:2:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 Originator: 10.1.10.1, Cluster list: 10.1.10.10 mpls labels in/out nolabel/22
ãªãã·ã§ã³no bgp default route-target filterã¯æå¹ã«ããŠããŸããããASBR2ã«vrfãäœæãããŠããŸãã
ip vrf VPN1-ASBR2 rd 2:10001 route-target export 2:100 route-target import 1:100 route-target import 2:100 inter-as-hybrid next-hop 10.1.0.1 ! ip vrf VPN2-ASBR2 rd 2:10002 route-target export 2:200 route-target import 1:200 route-target import 2:200 inter-as-hybrid next-hop 20.1.0.1
ã«ãŒãã¿ãŒã²ããã€ã³ããŒã2ïŒ100ã«ãããšãã«ãŒãã¯vrf VPN1-ASBR2ã«åé¡ãããŸãã
泚ïŒvrfæ§æã«ã¯ãinter-as-hybrid next-hopãšããæ°ããã³ãã³ããè¿œå ãããŸããã 圌女ã®ä»»åœã«ã€ããŠã¯åŸã§èª¬æããŸãã
ãããã¯ãŒã¯10.0.1.0/24ãžã®ã«ãŒããã«ãŒãã£ã³ã°ããŒãã«vrf VPN1-ASBR2ã«èšå®ãããŠãããã©ããã確èªããŸãã
ASBR2#sh ip route vrf VPN1-ASBR2 10.0.1.0 Routing Table: VPN1-ASBR2 Routing entry for 10.0.1.0/24 Known via "bgp 2", distance 200, metric 0, type internal Last update from 10.1.10.1 00:50:46 ago Routing Descriptor Blocks: * 10.1.10.1 (default), from 10.1.10.10, 00:50:46 ago Route metric is 0, traffic share count is 1 AS Hops 0 MPLS label: 22 MPLS Flags: MPLS Required
çŽ æŽããããã«ãŒãããããŸãã ãããŸã§ã®ãšããããã¹ãŠã¯ãªãã·ã§ã³Aãšåãã§ãããã ãããªãã·ã§ã³Aã§ã¯ãvrfã§ç¹å¥ã«èµ·åãããã«ãŒãã£ã³ã°ãããã³ã«ã䜿çšããŠãããvrfããå¥ã®vrfãžã®çŽç²ãªipã«ãŒããã¢ããŠã³ã¹ããå¿ èŠããããŸãã ãã ãããªãã·ã§ã³ABã§ã¯ãASBRéã®ã«ãŒãã¯ãASBRéã®bgp vpnv4ã»ãã·ã§ã³ãä»ããŠéä¿¡ãããŸãã ASBRéã®bgpã»ãã·ã§ã³ã§ASBR1ã§çºè¡šããå 容ãèŠãŠã¿ãŸãããã
ASBR2#sh ip bgp vpnv4 all neighbors 10.2.0.1 advertised-routes BGP table version is 109, local router ID is 10.1.10.3 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 2:10001 (default for vrf VPN1-ASBR2) *>i10.0.1.0/24 10.1.10.1 0 100 0 ? *>i10.1.1.2/32 10.1.10.1 2 100 0 ? Route Distinguisher: 2:10002 (default for vrf VPN2-ASBR2) *>i20.0.1.0/24 10.1.10.1 0 100 0 ? *>i20.1.1.2/32 10.1.10.1 2 100 0 ? Total number of prefixes 4
4ã€ã®ã«ãŒããçºè¡šããŠããŸããããããã«ã¯å ã®rdã¯ãããŸããã PE1ã§ã®ã¢ããŠã³ã¹ã¯rd 2ïŒ1ã§è¡ãããçŸåšã¯rd 2ïŒ10001ã§ã«ãŒããçºè¡šããŠããŸãã ã€ãŸããASBR2ã§ã«ãŒããåçæãããŸããã ãããæ©èœããã«ã¯ãASBRéã®bgpã»ãã·ã§ã³ã®èšå®ã§ã³ãã³ãinter-as-hybridãæå®ããå¿ èŠããããŸãã ãã®ã³ãã³ãã¯ããã®ã»ãã·ã§ã³ããªãã·ã§ã³ABã®vpnv4ã«ãŒãã転éããããšãæå³ããŠããããšã瀺ããŸãïŒCiscoã®èŠ³ç¹ã§ã¯ãASBR vrfã§äœæããããã®ã¯ãªãã·ã§ã³AB vrfãšåŒã°ããŸãïŒã
ASBR2#sh configuration | b address-family vpnv4 address-family vpnv4 neighbor 10.1.10.10 activate neighbor 10.1.10.10 send-community extended neighbor 10.2.0.1 activate neighbor 10.2.0.1 send-community extended neighbor 10.2.0.1 inter-as-hybrid exit-address-family
ç¶ããŸãããã ASBR1äžã®ãããã¯ãŒã¯10.0.1.0/24ãžã®ã«ãŒãã確èªããŸãã
ASBR1#sh ip bgp vpnv4 all 10.0.1.0/24 BGP routing table entry for 1:10001:10.0.1.0/24, version 98 Paths: (1 available, best #1, table VPN1-ASBR1) Advertised to update-groups: 1 2, imported path from 2:10001:10.0.1.0/24 10.1.0.2 (via VPN1-ASBR1) from 10.2.0.2 (10.1.10.3) Origin incomplete, localpref 100, valid, external, best Extended Community: RT:2:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 mpls labels in/out 31/19 BGP routing table entry for 2:10001:10.0.1.0/24, version 94 Paths: (1 available, best #1, no table) Not advertised to any peer 2 10.2.0.2 from 10.2.0.2 (10.1.10.3) Origin incomplete, localpref 100, valid, external, best Extended Community: RT:2:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 mpls labels in/out nolabel/19
åºåã«ã¯2ã€ã®ã«ãŒããããããã¯ã¹ãããã10.2.0.2ã®ã«ãŒãã¯ASBR2ããåä¿¡ããå ã®vpnv4ã«ãŒãã§ãã 2çªç®ã¯ãã¯ã¹ãããã10.1.0.2ïŒVPN1-ASBR1çµç±ïŒ-ãã©ãã£ãã¯ã®è»¢éã«äœ¿çšãããã«ãŒãã£ã³ã°ããŒãã«VPN1-ASBR1ã«ã€ã³ã¹ããŒã«ãããæ¢ã«å€æŽãããã«ãŒãã§ãã
ãªãã·ã§ã³Bã®ASBR-ruã«ãµããããASBR2ãã©ãã«ãçæããããšã«æ³šæããŠãã ãããASBR1ãžã®ã«ãŒãã«ã¯ããmpls labels in / out 31/19ããšããã©ãã«ããããŸãã ãã ãããã®ã¿ã°ã¯ãã©ãã£ãã¯ã®éä¿¡ã«ã¯äœ¿çšãããŸããã ããã¯ãvrf VPN1-ASBR1ã«ãŒãã£ã³ã°ããŒãã«ã«ã€ã³ããŒããããã«ãŒãããèŠãããšãã§ããŸããmplsã«ãŒãã«ã¯ã©ãã«ããããŸããïŒãMPLSã©ãã«ïŒãªããïŒä»¥äžã®åºåãåç §ïŒïŒ
ASBR1#sh ip rou vrf VPN1-ASBR1 10.0.1.0 Routing Table: VPN1-ASBR1 Routing entry for 10.0.1.0/24 Known via "bgp 1", distance 20, metric 0 Tag 2, type external Last update from 10.1.0.2 on GigabitEthernet3/0.10, 01:14:18 ago Routing Descriptor Blocks: * 10.1.0.2, from 10.2.0.2, 01:14:18 ago, via GigabitEthernet3/0.10 Route metric is 0, traffic share count is 1 AS Hops 1 Route tag 2 MPLS label: none
ASBR1ã®inter-as-hybrid next-hopã³ãã³ãã®ãããã§ããã¯ã¹ãããã眮æãè¡ãããŸããã
ip vrf VPN1-ASBR1 rd 1:10001 route-target export 1:100 route-target import 1:100 route-target import 2:100 inter-as-hybrid next-hop 10.1.0.2
ãã®ã³ãã³ããæå®ãããŠããªãå ŽåãASBR2ããåä¿¡ããvpnv4ã«ãŒãããã®å ã®ãã¯ã¹ãããããæã€ã«ãŒããvrfã«ã€ã³ããŒããããŸãïŒã€ãŸãããã¯ã¹ããããã¯ãéåžžã®ãªãã·ã§ã³Bã®ããã«eBGPã»ãã·ã§ã³ã®sorsãšããŠäœ¿çšãããã¢ãã¬ã¹ASBR2ã«ãªããŸãïŒ ãã®å ŽåãASBR1ã«ã¯æ¬¡ã®ã€ã³ã¿ãŒãã§ã€ã¹ããããŸãã
ASBR1#sh int description | i Gi3 Gi3/0 up up "to ASBR2 | AS2" Gi3/0.2 up up "to ASBR2 | vpnv4 routes only" Gi3/0.10 up up "for VPN1 only" Gi3/0.20 up up "for VPN2 only" ASBR1#sh ip int brief | i 3/0 GigabitEthernet3/0 unassigned YES NVRAM up up GigabitEthernet3/0.2 10.2.0.1 YES NVRAM up up GigabitEthernet3/0.10 10.1.0.1 YES NVRAM up up GigabitEthernet3/0.20 20.1.0.1 YES NVRAM up up
GigabitEthernet3 / 0.10ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠè»¢éããvpn1ãã©ãã£ãã¯ãå¿ èŠã§ãïŒãããããvpn2ããGigabitEthernet3 / 0.20ïŒã ãããã£ãŠã次ãããã®vrfèšå®ã§ã¯ãã¢ãã¬ã¹10.1.0.2ã瀺ãããŠããŸã-ASBR2ã®GigabitEthernet3 / 0.10ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãvrf VPN1-ASBR2ã«ãããŸãã
ASBR2#sh run int gigabitEthernet 3/0.10 Building configuration... Current configuration : 165 bytes ! interface GigabitEthernet3/0.10 description "for VPN1 forwarding" encapsulation dot1Q 10 ip vrf forwarding VPN1-ASBR2 ip address 10.1.0.2 255.255.255.252 end
å ã«é²ã¿ãŸãã vrf VPN1-ASBR1ããããã®ã«ãŒããã«ãŒã¿ãŒã«ã¢ããŠã³ã¹ããå¿ èŠããããŸãã
ASBR1#sh ip bgp vpnv4 all neighbors 10.0.10.10 advertised-routes BGP table version is 101, local router ID is 10.0.10.3 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 1:10001 (default for vrf VPN1-ASBR1) *> 10.0.1.0/24 10.1.0.2 0 2 ? *> 10.1.1.2/32 10.1.0.2 0 2 ? Route Distinguisher: 1:10002 (default for vrf VPN2-ASBR1) *> 20.0.1.0/24 20.1.0.2 0 2 ? *> 20.1.1.2/32 20.1.0.2 0 2 ? Total number of prefixes 4
ASBR1ãåä¿¡ããã«ãŒããããããïŒããã¯rdã«æ³šæãæãïŒããããASBR1ã«ãã£ãŠçæãããæ°ããã«ãŒãã§ããããšã«ãã§ã«æ°ã¥ãããšæããŸãã
Route Distinguisher: 2:10001 (default for vrf VPN1-ASBR2) *>i10.0.1.0/24 10.1.10.1 0 100 0 ? *>i10.1.1.2/32 10.1.10.1 2 100 0 ?
ASBR1ã§çºè¡šãããã«ãŒãã¯æ¬¡ã®ãšããã§ãã
Route Distinguisher: 1:10001 (default for vrf VPN1-ASBR1) *> 10.0.1.0/24 10.1.0.2 0 2 ? *> 10.1.1.2/32 10.1.0.2 0 2 ?
rdã«æ³šæããŠãã ããïŒ2ïŒ10001ãä»ã§ã¯1ïŒ10001ã ASBR1ã§ã©ã®vrfsãæ§æãããŠããããèŠãŠã¿ãŸãããã
ip vrf VPN1-ASBR1 rd 1:10001 route-target export 1:100 route-target import 1:100 route-target import 2:100 inter-as-hybrid next-hop 10.1.0.2 ! ip vrf VPN2-ASBR1 rd 1:10002 route-target export 1:200 route-target import 1:200 route-target import 2:200 inter-as-hybrid next-hop 20.1.0.2
ã«ãŒããASBR1ã«ãã£ãŠçæãããããšãæããã«ãªã£ããšæããŸãã
ASBR1ã¯ããã®ãã¬ãã£ãã¯ã¹ã«å¯ŸããŠã©ãã«31ãçæããŸããã
RR1#sh ip bgp vpnv4 all 10.0.1.0/24 BGP routing table entry for 1:10001:10.0.1.0/24, version 38 Paths: (1 available, best #1, no table) Advertised to update-groups: 1 2, (Received from a RR-client) 10.0.10.3 (metric 20) from 10.0.10.3 (10.0.10.3) Origin incomplete, metric 0, localpref 100, valid, internal, best Extended Community: RT:1:100 OSPF DOMAIN ID:0x0005:0x000000020200 OSPF RT:0.0.0.0:2:0 OSPF ROUTER ID:10.0.1.1:0 mpls labels in/out nolabel/31
ããã«ããã¹ãŠãæšæºã§ãã ã«ãŒãã¯RR1ããPE1ã«éä¿¡ãããŸãã
RR1#sh ip bgp vpnv4 rd 1:10001 neighbors 10.0.10.1 advertised-routes BGP table version is 41, local router ID is 10.0.10.10 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Originating default network 0.0.0.0 Network Next Hop Metric LocPrf Weight Path Route Distinguisher: 1:10001 *>i10.0.1.0/24 10.0.10.3 0 100 0 2 ? *>i10.1.1.2/32 10.0.10.3 0 100 0 2 ? Total number of prefixes 2
PE1ã¯ã察å¿ããVRFã®ã«ãŒãã£ã³ã°ããŒãã«ãã€ã³ã¹ããŒã«ããŸãã
PE1#sh ip route vrf VPN1-CE1 10.0.1.0 Routing Table: VPN1-CE1 Routing entry for 10.0.1.0/24 Known via "bgp 1", distance 200, metric 0 Tag 2, type internal Redistributing via ospf 1 Advertised by ospf 1 subnets Last update from 10.0.10.3 01:45:25 ago Routing Descriptor Blocks: * 10.0.10.3 (default), from 10.0.10.10, 01:45:25 ago Route metric is 0, traffic share count is 1 AS Hops 1 Route tag 2 MPLS label: 31 MPLS Flags: MPLS Required
次ã®å³ã¯ãVPNã¿ã°ã·ã°ããªã³ã°ããã»ã¹ã瀺ããŠããŸãã
ããã§ã¯ã ããŒã¿ãã¬ãŒã³ã«é²ã¿ãŸãããã CEã«ãŒã¿ãŒéã®ãã¬ãŒã¹ãäœæããŠã¿ãŸãããã
CE1-VPN1#ping 10.0.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.0.1.2, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 72/101/144 ms CE1-VPN1#traceroute 10.0.1.2 Type escape sequence to abort. Tracing the route to 10.0.1.2 1 10.0.0.1 32 msec 12 msec 8 msec 2 10.0.2.2 [MPLS: Labels 17/31 Exp 0] 48 msec 44 msec 48 msec 3 10.1.0.1 [MPLS: Label 31 Exp 0] 44 msec 40 msec 12 msec 4 10.1.0.2 60 msec 48 msec 44 msec 5 10.1.0.2 [MPLS: Labels 17/22 Exp 0] 72 msec 88 msec 68 msec 6 10.0.1.1 80 msec 40 msec 56 msec 7 10.0.1.2 100 msec 84 msec 80 msec
ãããŠvpn2ã§ãåãã§ãïŒ
VPN2-CE1#ping 20.0.1.2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 20.0.1.2, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 92/120/144 ms VPN2-CE1#traceroute 20.0.1.2 Type escape sequence to abort. Tracing the route to 20.0.1.2 1 20.0.0.1 64 msec 16 msec 16 msec 2 10.0.0.2 [MPLS: Labels 16/32 Exp 0] 44 msec 40 msec 40 msec 3 20.1.0.1 [MPLS: Label 32 Exp 0] 12 msec 28 msec 24 msec 4 20.1.0.2 52 msec 44 msec 40 msec 5 10.1.0.2 [MPLS: Labels 17/23 Exp 0] 40 msec 48 msec 64 msec 6 20.0.1.1 60 msec 48 msec 84 msec 7 20.0.1.2 76 msec 72 msec 76 msec
PE1ã¯ã¯ã©ã€ã¢ã³ãã«ãŒã¿ããIPãã±ãããåä¿¡ããã«ãŒãã£ã³ã°ããŒãã«ã«åŸã£ãŠã31ïŒvrfã©ãã«ïŒãš17ãŸãã¯16ïŒPE1ããã©ãã£ãã¯ãåæ£ããæ¹æ³ã«å¿ããŠASBR1ãžã®ãã©ã³ã¹ããŒãã©ãã«ïŒã®2ã€ã®ã©ãã«ãåæããŸãã
PE1#sh ip route vrf VPN1-CE1 10.0.1.0 Routing Table: VPN1-CE1 Routing entry for 10.0.1.0/24 Known via "bgp 1", distance 200, metric 0 Tag 2, type internal Redistributing via ospf 1 Advertised by ospf 1 subnets Last update from 10.0.10.3 01:45:25 ago Routing Descriptor Blocks: * 10.0.10.3 (default), from 10.0.10.10, 01:45:25 ago Route metric is 0, traffic share count is 1 AS Hops 1 Route tag 2 MPLS label: 31 MPLS Flags: MPLS Required PE1#sh mpls forwarding-table 10.0.10.3 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 18 16 10.0.10.3/32 0 Gi1/0 10.0.0.2 17 10.0.10.3/32 0 Gi2/0 10.0.2.2
äžèšã®ãã¬ãŒã¹ããå€æãããšãPE1ã¯P1ãéãã«ãŒããéžæããŸãã
ã¿ã°17ã®ãã±ãããåä¿¡ããP1ã¯ããã®ïŒäžéšïŒã¿ã°ãåé€ããGi1 / 0ã€ã³ã¿ãŒãã§ã€ã¹ïŒASBR1ãžã®ãªã³ã¯ïŒã«ãã±ãããéä¿¡ããŸãã
P1#sh mpls forwarding-table labels 17 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 17 Pop Label 10.0.10.3/32 11590 Gi1/0 10.0.3.1
ASBR1ã¯ãã±ãããéåžžã®PEã«ãŒã¿ãŒãšããŠåŠçããŸã-ã©ãã«ãåé€ããã¯ãªãŒã³ãªIPãã±ãããGi3 / 0.10ã€ã³ã¿ãŒãã§ã€ã¹ã«éä¿¡ããŸãã
ASBR1#sh mpls forwarding-table labels 31 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 31 No Label 10.0.1.0/24[V] 1712 Gi3/0.10 10.1.0.2
ãã®ãã±ãããåä¿¡ãããšãASBR2ã¯PEã«ãŒã¿ãŒãšããŠåäœããã¯ã©ã€ã¢ã³ãCEã«ãŒã¿ãŒãããã±ãããåä¿¡ããŸã-vrfïŒ22ïŒãšãã©ã³ã¹ããŒãã©ãã«ããã³ã°ãããŸãïŒ17ãŸãã¯19ã¯åã³åçã®ãã¹ã§ããããã¬ãŒã¹ã«ãã£ãŠå€æãããšããã±ããã¯RR2ã«éãããŸãïŒã
ASBR2# sh ip route vrf VPN1-ASBR2 10.0.1.0 Routing Table: VPN1-ASBR2 Routing entry for 10.0.1.0/24 Known via "bgp 2", distance 200, metric 0, type internal Last update from 10.1.10.1 01:51:32 ago Routing Descriptor Blocks: * 10.1.10.1 (default), from 10.1.10.10, 01:51:32 ago Route metric is 0, traffic share count is 1 AS Hops 0 MPLS label: 22 MPLS Flags: MPLS Required ASBR2#sh mpls forwarding-table 10.1.10.1 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 23 17 10.1.10.1/32 0 Gi1/0 10.1.0.2 19 10.1.10.1/32 0 Gi2/0 10.1.2.2
RR2ã¯ãæåŸãã2çªç®ã®ãããã®mplsäžç¶ã«ãŒã¿ãŒã«é©ããŠããããããããããŒã¯ãåé€ãããã±ãããPE2ã«éä¿¡ããŸãã
RR2#sh mpls forwarding-table labels 17 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 17 Pop Label 10.1.10.1/32 7242 Gi2/0 10.1.1.1
PE2ã¯ãã©ãã«22ãvrf VPN1-CE2ã§IPã«ãã¯ã¢ãããå®è¡ããå¿ èŠãããããšã瀺ããŠããããšãç¥ã£ãŠããŸãã
PE2#show mpls forwarding-table labels 22 Local Outgoing Prefix Bytes Label Outgoing Next Hop Label Label or Tunnel Id Switched interface 22 Pop Label IPv4 VRF[V] 8150 aggregate/VPN1-CE2
次ã«ããã±ããã¯ã¯ã©ã€ã¢ã³ãCEã«ãŒã¿ãŒã«éãããŸãã 以äžã®å³ã«ããã¹ãŠã®ã©ãã«ãšãããã®æäœã瀺ããŸãã
ãã®çµæããªãã·ã§ã³AãšBã®ãã€ããªãããåŸãããããã§ã¯qosã䜿çšããŠããªãã·ã§ã³Aã®ããã«ASBRéã®ã¯ã©ã€ã¢ã³ããã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ã§ããŸãããåæã«ãASBRã®åvpnã«vrfãæ§æããåå¥ã®ãžã§ã€ã³ããäœæããå¿ èŠããããŸãããåvrfã«åå¥ã®ã«ãŒãã£ã³ã°ãããã³ã«ããã»ã¹ã¯å¿ èŠãããŸãããããã«ããããªãã·ã§ã³Bã®ããã«ãé£æ¥ASBRãšã®vpnv4ã»ãã·ã§ã³ã1ã€ã ããµããŒãããASBRã®è² è·ãèªç¶ã«æžå°ããŸãã
æåŸã«ã2ã€ã®éèŠãªããŒã ã«çŠç¹ãåœãŠãããšæããŸãã
ip vrféå±€ã®inter-as-hybridãã¯ã¹ãããã-ãã¯ã¹ããããã眮ãæããããã«ãã®ã³ãã³ããå¿ èŠã§ããæå®ããªãå Žåããã¯ã¹ãããããããªãã·ã§ã³Bãå®è¡ãããŠãããžã§ã€ã³ããŸã§ã®ã«ãŒããvrfã«ã€ã³ããŒããããŸãã
neighbor 10.2.0.1 inter-as-hybrid-ãã®ã³ãã³ãã¯ãInter-AS Option ABã®vpnv4ã«ãŒãã亀æããããã«ãã¢éã§bgpã»ãã·ã§ã³ã確ç«ãããããšã瀺ããŸãã ãã®ã³ãã³ãã䜿çšãããšãæåã«ã«ãŒããvrfã«ã€ã³ããŒããã次ã«ãã®vrfããã«ãŒããããã«ãšã¯ã¹ããŒãã§ããŸãïŒrdããã³å¿ èŠã«å¿ããŠã³ãã¥ããã£ãå€æŽããŸãïŒã
ãããã®ãªãã·ã§ã³ã®äž¡æ¹ãæå¹ã«ããå¿ èŠããããŸããæå¹ã«ããªããšãäœãåŸãããªãããåäœããŸãããåäœæ¹æ³ã¯åäœããŸããã
çŸåšãABãªãã·ã§ã³ã«é¢ããRFCãã©ããã®ã¿ããããŸãã ãã®èšäºã§ã¯ãã·ã¹ã³ã«ããå®è£ ã®äŸã«é¢ãããªãã·ã§ã³ABã«äŒããŸããã æ¬ ç¹ãèŠã€ããããäœããè£è¶³/説æããå¿ èŠããããšæãå Žåã¯ãPMã«é£çµ¡ããŠãã ããã
ãæž èŽããããšãããããŸããïŒ