本案例采用ENSP模拟器的华为交换机部署多VPN实例ISIS典型案例,为了实现业务的相互隔离,拟采用多VPN实例的方式来满足需求,全网采用多VPN实例ISIS实现互通。
1、按照网络拓扑图配置IP地址。
2、配置多VPN实例ISIS。
LSW1:
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>u t d
Info: Current terminal debugging is off.
<Huawei>system
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname LSW1
[LSW1]vlan 10
[LSW1-vlan10]quit
[LSW1]vlan 20
[LSW1-vlan20]quit
[LSW1]vlan 100
[LSW1-vlan100]quit
[LSW1]vlan 200
[LSW1-vlan200]quit
[LSW1]int gi 0/0/2
[LSW1-GigabitEthernet0/0/2]po li acc
[LSW1-GigabitEthernet0/0/2]po de vlan 10
[LSW1-GigabitEthernet0/0/2]quit
[LSW1]int gi 0/0/3
[LSW1-GigabitEthernet0/0/3]po li acc
[LSW1-GigabitEthernet0/0/3]po de vlan 20
[LSW1-GigabitEthernet0/0/3]quit
[LSW1]int gi 0/0/1
[LSW1-GigabitEthernet0/0/1]po li tr
[LSW1-GigabitEthernet0/0/1]undo po tr all vlan 1
[LSW1-GigabitEthernet0/0/1]po tr all vlan 100 200
[LSW1-GigabitEthernet0/0/1]quit
配置多VPN实例相关部署
[LSW1]ip vpn-instance vpn-rt
[LSW1-vpn-instance-vpn-rt]route-distinguisher 100:1
[LSW1-vpn-instance-vpn-rt-af-ipv4]vpn-target 100:1 both
[LSW1-vpn-instance-vpn-rt-af-ipv4]quit
[LSW1-vpn-instance-vpn-rt]quit
[LSW1]ip vpn-instance vpn-nrt
[LSW1-vpn-instance-vpn-nrt]route-distinguisher 200:1
[LSW1-vpn-instance-vpn-nrt-af-ipv4]vpn-target 200:1 both
[LSW1-vpn-instance-vpn-nrt-af-ipv4]quit
[LSW1-vpn-instance-vpn-nrt]quit
[LSW1]isis 1 vpn-instance vpn-rt
[LSW1-isis-1]is-level level-1-2
[LSW1-isis-1]network-entity 10.0000.0000.0001.00
[LSW1-isis-1]quit
[LSW1]isis 2 vpn-instance vpn-nrt
[LSW1-isis-2]is-level level-1-2
[LSW1-isis-2]network-entity 10.0000.0000.0001.00
[LSW1-isis-2]quit
[LSW1]int vlan 10
[LSW1-Vlanif10]ip binding vpn-instance vpn-rt
[LSW1-Vlanif10]ip address 192.168.1.1 24
[LSW1-Vlanif10]isis enable 1
[LSW1-Vlanif10]quit
[LSW1]int vlan 20
[LSW1-Vlanif20]ip binding vpn-instance vpn-nrt
[LSW1-Vlanif20]ip address 192.168.2.1 24
[LSW1-Vlanif20]isis enable 2
[LSW1-Vlanif20]quit
[LSW1]int vlan 100
[LSW1-Vlanif100]ip binding vpn-instance vpn-rt
[LSW1-Vlanif100]ip address 10.0.0.1 30
[LSW1-Vlanif100]isis enable 1
[LSW1-Vlanif100]quit
[LSW1]int vlan 200
[LSW1-Vlanif200]ip binding vpn-instance vpn-nrt
[LSW1-Vlanif200]ip address 10.0.0.1 30
[LSW1-Vlanif200]isis enable 2
[LSW1-Vlanif200]quit
LSW2:
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>u t d
Info: Current terminal debugging is off.
<Huawei>system
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname LSW2
[LSW2]vlan 100
[LSW2-vlan100]quit
[LSW2]vlan 200
[LSW2-vlan200]quit
[LSW2]vlan 10
[LSW2-vlan10]quit
[LSW2]vlan 20
[LSW2-vlan20]quit
[LSW2]int gi 0/0/2
[LSW2-GigabitEthernet0/0/2]po li acc
[LSW2-GigabitEthernet0/0/2]po de vlan 10
[LSW2-GigabitEthernet0/0/2]quit
[LSW2]int gi 0/0/3
[LSW2-GigabitEthernet0/0/3]po li acc
[LSW2-GigabitEthernet0/0/3]po de vlan 20
[LSW2-GigabitEthernet0/0/3]quit
[LSW2]int gi 0/0/1
[LSW2-GigabitEthernet0/0/1]po li tr
[LSW2-GigabitEthernet0/0/1]undo po tr all vlan 1
[LSW2-GigabitEthernet0/0/1]po tr all vlan 100 200
[LSW2-GigabitEthernet0/0/1]quit
多VPN实例相关配置
[LSW2]ip vpn-instance vpn-rt
[LSW2-vpn-instance-vpn-rt]route-distinguisher 100:1
[LSW2-vpn-instance-vpn-rt-af-ipv4]vpn-target 100:1 both
[LSW2-vpn-instance-vpn-rt-af-ipv4]quit
[LSW2-vpn-instance-vpn-rt]quit
[LSW2]ip vpn-instance vpn-nrt
[LSW2-vpn-instance-vpn-nrt]route-distinguisher 200:1
[LSW2-vpn-instance-vpn-nrt-af-ipv4]vpn-target 200:1 both
[LSW2-vpn-instance-vpn-nrt-af-ipv4]quit
[LSW2-vpn-instance-vpn-nrt]quit
[LSW2]isis 1 vpn-instance vpn-rt
[LSW2-isis-1]is-level level-1-2
[LSW2-isis-1]network-entity 10.0000.0000.0002.00
[LSW2-isis-1]quit
[LSW2]isis 2 vpn-instance vpn-nrt
[LSW2-isis-2]is-level level-1-2
[LSW2-isis-2]network-entity 10.0000.0000.0002.00
[LSW2-isis-2]quit
[LSW2]int vlan 10
[LSW2-Vlanif10]ip binding vpn-instance vpn-rt
[LSW2-Vlanif10]ip address 172.16.1.1 24
[LSW2-Vlanif10]isis enable 1
[LSW2-Vlanif10]quit
[LSW2]int vlan 20
[LSW2-Vlanif20]ip binding vpn-instance vpn-nrt
[LSW2-Vlanif20]ip address 172.16.2.1 24
[LSW2-Vlanif20]isis enable 2
[LSW2-Vlanif20]quit
[LSW2]int vlan 100
[LSW2-Vlanif100]ip binding vpn-instance vpn-rt
[LSW2-Vlanif100]ip address 10.0.0.2 30
[LSW2-Vlanif100]isis enable 1
[LSW2-Vlanif100]quit
[LSW2]int vlan 200
[LSW2-Vlanif200]ip binding vpn-instance vpn-nrt
[LSW2-Vlanif200]ip address 10.0.0.2 30
[LSW2-Vlanif200]isis enable 2
[LSW2-Vlanif200]quit
使用dis isis peer vpn-instance vpn-rt和dis isis peer vpn-instance vpn-nrt命令分别查看LSW1和LSW2的isis邻居建立的情况,已完成建立。
分别查看LSW1和LSW2的路由表,携带vpn实例的参数,已能学习到对端传递过来相应VPN实例的路由。
PC分别填写IP地址,相同VPN实例的业务能PING通,不同VPN实例的业务不能互通。
至此,华为交换机多VPN实例ISIS典型组网配置案例已完成!
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作