SW1:
<H3C>sys
System View: return to User View with Ctrl+Z.
[H3C]sysname SW1
#创建VPN实例,指定RD值、RT值
[SW1]ip vpn-instance vpn-rt
[SW1-vpn-instance-vpn-rt]route-distinguisher 100:1
[SW1-vpn-instance-vpn-rt]vpn-target 100:1
[SW1-vpn-instance-vpn-rt]quit
[SW1]ip vpn-instance vpn-nrt
[SW1-vpn-instance-vpn-nrt]route-distinguisher 200:1
[SW1-vpn-instance-vpn-nrt]vpn-target 200:1
[SW1-vpn-instance-vpn-nrt]quit
[SW1]vlan 400
[SW1-vlan400]quit
[SW1]vlan 500
[SW1-vlan500]quit
[SW1]int vlan 400
[SW1-Vlan-interface400]ip binding vpn-instance vpn-rt //将VLAN绑定到VPN实例
Some configurations on the interface are removed.
[SW1-Vlan-interface400]des <connect to SW2_vpn-rt>
[SW1-Vlan-interface400]ipv6 address 1::1 64
[SW1-Vlan-interface400]quit
[SW1]int vlan 500
[SW1-Vlan-interface500]ip binding vpn-instance vpn-nrt
Some configurations on the interface are removed.
[SW1-Vlan-interface500]des <connect to SW2_vpn-nrt>
[SW1-Vlan-interface500]ipv6 address 1::1 64
[SW1-Vlan-interface500]quit
[SW1]int gi 1/0/1
[SW1-GigabitEthernet1/0/1]des <connect to SW2>
[SW1-GigabitEthernet1/0/1]port link-type trunk
[SW1-GigabitEthernet1/0/1]undo port trunk permit vlan 1
[SW1-GigabitEthernet1/0/1]port trunk permit vlan 400 500
[SW1-GigabitEthernet1/0/1]quit
[SW1]int loopback 10
[SW1-LoopBack10]ip binding vpn-instance vpn-rt
Some configurations on the interface are removed.
[SW1-LoopBack10]ipv6 address 2::1 64
[SW1-LoopBack10]quit
[SW1]int loopback 20
[SW1-LoopBack20]ip binding vpn-instance vpn-nrt
Some configurations on the interface are removed.
[SW1-LoopBack20]ipv6 address 3::1 64
[SW1-LoopBack20]quit
[SW1]int loopback 0
[SW1-LoopBack0]ip binding vpn-instance vpn-rt
Some configurations on the interface are removed.
[SW1-LoopBack0]ip address 1.1.1.1 32
[SW1-LoopBack0]quit
[SW1]int loopback 1
[SW1-LoopBack1]ip binding vpn-instance vpn-nrt
Some configurations on the interface are removed.
[SW1-LoopBack1]ip address 2.2.2.2 32
[SW1-LoopBack1]quit
[SW1]ipv6 route-static vpn-instance vpn-rt 4:: 64 1::2 //将静态路由绑定到VPN实例
[SW1]ipv6 route-static vpn-instance vpn-nrt 5:: 64 1::2
SW2:
<H3C>sys
System View: return to User View with Ctrl+Z.
[H3C]sysname SW2
[SW2]ip vpn-instance vpn-rt
[SW2-vpn-instance-vpn-rt]route-distinguisher 100:1
[SW2-vpn-instance-vpn-rt]vpn-target 100:1
[SW2-vpn-instance-vpn-rt]quit
[SW2]ip vpn-instance vpn-nrt
[SW2-vpn-instance-vpn-nrt]route-distinguisher 200:1
[SW2-vpn-instance-vpn-nrt]vpn-target 200:1
[SW2-vpn-instance-vpn-nrt]quit
[SW2]vlan 400
[SW2-vlan400]quit
[SW2]vlan 500
[SW2-vlan500]quit
[SW2]int vlan 400
[SW2-Vlan-interface400]ip binding vpn-instance vpn-rt
Some configurations on the interface are removed.
[SW2-Vlan-interface400]des <connect to SW1_vpn-rt>
[SW2-Vlan-interface400]ipv6 address 1::2 64
[SW2-Vlan-interface400]quit
[SW2]int vlan 500
[SW2-Vlan-interface500]ip binding vpn-instance vpn-nrt
Some configurations on the interface are removed.
[SW2-Vlan-interface500]des <connect to SW1_vpn-nrt>
[SW2-Vlan-interface500]ipv6 address 1::2 64
[SW2-Vlan-interface500]quit
[SW2]int LoopBack 10
[SW2-LoopBack10]ip binding vpn-instance vpn-rt
Some configurations on the interface are removed.
[SW2-LoopBack10]ipv6 address 4::1 64
[SW2-LoopBack10]quit
[SW2]int loopback 20
[SW2-LoopBack20]ip binding vpn-instance vpn-nrt
Some configurations on the interface are removed.
[SW2-LoopBack20]ipv6 address 5::1 64
[SW2-LoopBack20]quit
[SW2]int loopback 0
[SW2-LoopBack0]ip binding vpn-instance vpn-rt
Some configurations on the interface are removed.
[SW2-LoopBack0]ip address 3.3.3.3 32
[SW2-LoopBack0]quit
[SW2]int loopback 1
[SW2-LoopBack1]ip binding vpn-instance vpn-nrt
Some configurations on the interface are removed.
[SW2-LoopBack1]ip address 4.4.4.4 32
[SW2-LoopBack1]quit
[SW2]int gi 1/0/1
[SW2-GigabitEthernet1/0/1]port link-mode bridge
[SW2-GigabitEthernet1/0/1]des <connect to SW1>
[SW2-GigabitEthernet1/0/1]port link-type trunk
[SW2-GigabitEthernet1/0/1]undo port trunk permit vlan 1
[SW2-GigabitEthernet1/0/1]port trunk permit vlan 400 500
[SW2-GigabitEthernet1/0/1]quit
[SW2]ipv6 route-static vpn-instance vpn-rt 2:: 64 1::1
[SW2]ipv6 route-static vpn-instance vpn-nrt 3:: 64 1::1
测试:
在SW1使用loopback 10作为源,带VPN能PING通FW2的loopback 10,PING不通FW2的loopback 20:


在SW1使用loopback 20作为源,带VPN能PING通FW2的loopback20,PING不通FW2的loopback 10:


在SW2使用loopback 10作为源,带VPN能PING通FW1的loopback 10,PING不通FW1的loopback 20:


在SW2使用loopback 20作为源,带VPN能PING通FW1的loopback20,PING不通FW1的loopback 10:


根据测试结果得知,相同VPN实例内的业务可以互通,不同VPN实例内的业务不能互通,达到了隔离的效果。
查看SW1 IPV6 VPN实例的路由表:


查看SW2 IPV6 VPN实例的路由表:


至此,S5820 IPV6多VPN实例静态路由典型组网配置案例已完成!