MSR2600中GRE绑定vpn-instance后tunnel状态无法UP,同样的配置,我将vpn-instance去掉后,tunnel状态up,请高手看是我的配置问题,还是本身就不支持?
<H3C>disp version
H3C Comware Software, Version 7.1.064, Release 6749P33
Copyright (c) 2004-2024 New H3C Technologies Co., Ltd. All rights reserved.
H3C MSR2600 uptime is 2 weeks, 5 days, 15 hours, 45 minutes
Last reboot reason : Power on
Boot image: flash:/msr26x1a-cmw710-boot-r6749p33.bin
Boot image version: 7.1.064P80, Release 6749P33
Compiled Dec 13 2024 15:00:00
System image: flash:/msr26x1a-cmw710-system-r6749p33.bin
System image version: 7.1.064, Release 6749P33
Compiled Dec 13 2024 15:00:00
Feature image(s) list:
flash:/msr26x1a-cmw710-security-r6749p33.bin, version: 7.1.064
Compiled Dec 13 2024 15:00:00
flash:/msr26x1a-cmw710-voice-r6749p33.bin, version: 7.1.064
Compiled Dec 13 2024 15:00:00
flash:/msr26x1a-cmw710-data-r6749p33.bin, version: 7.1.064
Compiled Dec 13 2024 15:00:00
[H3C] disp cur
#
version 7.1.064, Release 6749P33
#
sysname H3C
#
ip vpn-instance boshun-jiaxiao
#
ip vpn-instance manage
#
wlan global-configuration
#
telnet server enable
#
security-zone intra-zone default permit
#
dhcp enable
#
dns proxy enable
#
system-working-mode standard
password-recovery enable
#
vlan 1
#
dhcp server ip-pool lan1
gateway-list 192.168.0.1
network 192.168.0.0 mask 255.255.254.0
address range 192.168.1.2 192.168.1.254
dns-list 192.168.0.1
#
interface NULL0
#
interface LoopBack0
ip binding vpn-instance boshun-jiaxiao
ip address 100.127.2.26 255.255.255.255
#
interface LoopBack1
ip binding vpn-instance boshun-jiaxiao
ip address 100.127.2.28 255.255.255.255
#
interface Vlan-interface1
description LAN-interface
ip address 192.168.0.1 255.255.254.0
tcp mss 1280
#
interface GigabitEthernet0/0
port link-mode route
#
interface GigabitEthernet0/1
port link-mode route
#
interface GigabitEthernet0/2
port link-mode route
#
interface GigabitEthernet0/3
port link-mode route
#
interface GigabitEthernet0/4
port link-mode route
#
interface GigabitEthernet0/11
port link-mode route
ip binding vpn-instance manage
ip address 172.17.122.237 255.255.255.0
#
interface GigabitEthernet0/13
port link-mode route
#
interface GigabitEthernet0/13.1025
ip binding vpn-instance boshun-jiaxiao
ip address 100.125.2.98 255.255.255.252
vlan-type dot1q vid 1025
#
interface GigabitEthernet0/13.1026
ip binding vpn-instance boshun-jiaxiao
ip address 100.125.2.102 255.255.255.252
vlan-type dot1q vid 1026
#
interface GigabitEthernet0/13.1027
ip binding vpn-instance boshun-jiaxiao
ip address 100.125.2.106 255.255.255.252
vlan-type dot1q vid 1027
#
interface GigabitEthernet0/13.1028
ip binding vpn-instance boshun-jiaxiao
ip address 100.125.2.110 255.255.255.252
vlan-type dot1q vid 1028
#
interface GigabitEthernet0/14
port link-mode route
#
interface GigabitEthernet0/5
port link-mode bridge
#
interface GigabitEthernet0/6
port link-mode bridge
#
interface GigabitEthernet0/7
port link-mode bridge
#
interface GigabitEthernet0/8
port link-mode bridge
#
interface GigabitEthernet0/9
port link-mode bridge
#
interface GigabitEthernet0/10
port link-mode bridge
#
interface GigabitEthernet0/12
port link-mode bridge
#
interface Tunnel0 mode gre
ip binding vpn-instance boshun-jiaxiao
ip address 100.126.2.50 255.255.255.252
source 100.127.2.26
destination 100.127.2.25
keepalive 5 3
#
interface Tunnel1 mode gre
ip binding vpn-instance boshun-jiaxiao
ip address 100.126.2.54 255.255.255.252
source 100.127.2.28
destination 100.127.2.27
keepalive 5 3
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class tty
user-role network-operator
#
line class vty
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 4
authentication-mode scheme
user-role network-admin
user-role network-operator
#
line vty 5 63
authentication-mode scheme
user-role network-operator
#
ip route-static vpn-instance manage 0.0.0.0 0 172.17.122.1
ip route-static vpn-instance boshun-jiaxiao 100.127.2.25 32 GigabitEthernet0/13.1025 100.125.2.97
ip route-static vpn-instance boshun-jiaxiao 100.127.2.25 32 GigabitEthernet0/13.1026 100.125.2.101 preference 120
ip route-static vpn-instance boshun-jiaxiao 100.127.2.27 32 GigabitEthernet0/13.1027 100.125.2.105
ip route-static vpn-instance boshun-jiaxiao 100.127.2.27 32 GigabitEthernet0/13.1028 100.125.2.109 preference 120
#
performance-management
#
password-control enable
undo password-control aging enable
undo password-control history enable
password-control length 6
password-control login-attempt 3 exceed lock-time 10
password-control update-interval 0
password-control login idle-time 0
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
service-type telnet http
authorization-attribute user-role network-admin
#
local-user hello class manage
service-type ssh telnet terminal http
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
local-user huawei class network
password cipher $c$3$WmTpwz7aQh8Jt413b8yplhUPKpi5V8Tmyl8L
service-type ppp
authorization-attribute user-role network-operator
#
security-enhanced level 1
#
ssl version gm-tls1.1 disable
undo ssl renegotiation disable
undo ssl version ssl3.0 disable
undo ssl version tls1.0 disable
undo ssl version tls1.1 disable
undo ssl version tls1.2 disable
undo ssl version tls1.3 disable
#
ip http enable
web new-style
#
smartmc tc enable
#
wlan ap-group default-group
vlan 1
radio 2.4g
radio 5g
#
return
[H3C]
您好,你的 MSR2600 配置中GRE Tunnel 绑定 vpn-instance 后无法 UP,是配置逻辑问题(隧道源地址的路由可达性缺失),并非设备不支持。MSR2600 Comware 7 是支持 GRE 绑定 VPN 实例的,问题出在隧道源地址的路由未正确关联 VPN 实例,具体分析和修正步骤如下:
Tunnel0源地址是100.127.2.26(绑定在boshun-jiaxiao VPN 实例的 LoopBack0),但 GRE 隧道建立的前提是源地址到目的地址的路由必须在对应 VPN 实例内可达,而你的配置中存在两个关键缺失:boshun-jiaxiao VPN 实例内无出接口路由:100.127.2.26是 VPN 实例内的地址,但你未配置 “100.127.2.26对应的出接口路由”(仅配置了目的地址100.127.2.25的路由),导致设备在boshun-jiaxiao实例内无法找到100.127.2.26的出接口,GRE 隧道无法发起建连请求。boshun-jiaxiao VPN 实例内,为100.127.2.26(LoopBack0)和100.127.2.28(LoopBack1)配置出接口路由(指向对应的子接口):system-view
# 为Tunnel0的源地址100.127.2.26配置出接口路由
ip route-static vpn-instance boshun-jiaxiao 100.127.2.26 32 GigabitEthernet0/13.1025 100.125.2.97
# 为Tunnel1的源地址100.127.2.28配置出接口路由
ip route-static vpn-instance boshun-jiaxiao 100.127.2.28 32 GigabitEthernet0/13.1027 100.125.2.105
boshun-jiaxiao实例内100.127.2.26到100.127.2.25的路由可达:display ip routing-table vpn-instance boshun-jiaxiao 100.127.2.25
display ip routing-table vpn-instance boshun-jiaxiao 100.127.2.26
若输出中包含对应的出接口(如 GigabitEthernet0/13.1025),则路由可达;若仍不可达,检查子接口GigabitEthernet0/13.1025是否绑定boshun-jiaxiao实例(你的配置中已绑定,可忽略)。interface Tunnel0
shutdown
undo shutdown
quit
interface Tunnel1
shutdown
undo shutdown
quit
ip binding vpn-instance xxx;
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论