华为ne40e路由器实验配置示例|配置evdpdndl3vdpdndv4oversrv6be网络切片(代码片段)

COCOgsta COCOgsta     2023-03-09     319

关键词:

组网需求

图1所示:PE1、P和PE2属于同一自治系统,要求它们之间通过IS-IS协议达到IPv6网络互连的目的。在PE1和PE2之间通过建立双向SRv6 BE承载EVPN L3VPNv4业务。此外,为了满足保障CE1和CE2之间VPN实例vpn1的业务SLA,可以在公网上创建网络切片20,专门承载vpn1的业务;为了满足保障CE3和CE4之间VPN实例vpn2的业务SLA,可以在公网上创建网络切片30,专门承载vpn2的业务。

图1 配置EVPN L3VPNv4 over SRv6 BE网络切片组网图

配置思路 

  1. 使能PE1、P和PE2各接口的IPv6转发能力,配置各接口的IPv6地址。

  2. 在PE1、P和PE2上使能IS-IS,配置Level级别,指定网络实体。

  3. 在PE1、P和PE2上创建网络切片实例,并指定基础接口和创建网络切片接口。
  4. 在PE设备上配置IPv4 L3VPN实例并将IPv4 L3VPN实例绑定到接入侧接口。

  5. 在PE和CE之间建立EBGP对等体关系。

  6. 在PE设备之间建立BGP EVPN对等体关系。

  7. 在PE设备上配置SRv6 BE。配置IS-IS的SRv6能力。
  8. 在PE1和PE2上配置Route-Policy,为VPN实例路由染色。

  9. 配置SRv6 BE路由颜色(Color)与Slice ID的映射关系。

操作步骤

1. 使能各接口的IPv6转发能力,配置各接口的IPv6地址

# 配置PE1。P和PE2的配置过程与PE1类似,不再赘述,详情可参考配置文件。

<HUAWEI> system-view
[~HUAWEI] sysname PE1
[*HUAWEI] commit
[~PE1] interface gigabitethernet 1/0/0
[~PE1-GigabitEthernet1/0/0] ipv6 enable
[*PE1-GigabitEthernet1/0/0] ipv6 address 2001:DB8:10::1 64
[*PE1-GigabitEthernet1/0/0] quit
[*PE1] interface LoopBack 1
[*PE1-LoopBack1] ipv6 enable
[*PE1-LoopBack1] ipv6 address 2001:DB8:1::1 128
[*PE1-LoopBack1] quit
[*PE1] commit

2. 配置IS-IS

# 配置PE1。

[~PE1] isis 1
[*PE1-isis-1] is-level level-1
[*PE1-isis-1] cost-style wide
[*PE1-isis-1] network-entity 10.0000.0000.0001.00
[*PE1-isis-1] ipv6 enable topology ipv6
[*PE1-isis-1] quit
[*PE1] interface gigabitethernet 1/0/0
[*PE1-GigabitEthernet1/0/0] isis ipv6 enable 1
[*PE1-GigabitEthernet1/0/0] quit
[*PE1] interface loopback1
[*PE1-LoopBack1] isis ipv6 enable 1
[*PE1-LoopBack1] quit
[*PE1] commit

# 配置P。

[~P] isis 1 
[*P-isis-1] is-level level-1
[*P-isis-1] cost-style wide
[*P-isis-1] network-entity 10.0000.0000.0002.00
[*P-isis-1] ipv6 enable topology ipv6
[*P-isis-1] quit
[*P] interface gigabitethernet 1/0/0
[*P-GigabitEthernet1/0/0] isis ipv6 enable 1
[*P-GigabitEthernet1/0/0] quit
[*P] interface gigabitethernet 2/0/0
[*P-GigabitEthernet2/0/0] isis ipv6 enable 1
[*P-GigabitEthernet2/0/0] quit
[*P] commit

# 配置PE2。

[~PE2] isis 1
[*PE2-isis-1] is-level level-1
[*PE2-isis-1] cost-style wide
[*PE2-isis-1] network-entity 10.0000.0000.0003.00
[*PE2-isis-1] ipv6 enable topology ipv6
[*PE2-isis-1] quit
[*PE2] interface gigabitethernet 1/0/0
[*PE2-GigabitEthernet1/0/0] isis ipv6 enable 1
[*PE2-GigabitEthernet1/0/0] quit
[*PE2] interface loopback1
[*PE2-LoopBack1] isis ipv6 enable 1
[*PE2-LoopBack1] quit
[*PE2] commit

配置完成后,可按如下指导检查IS-IS是否配置成功。

# 显示IS-IS邻居信息。以PE1为例。

[~PE1] display isis peer
                          Peer information for ISIS(1)
                         
  System Id     Interface         Circuit Id        State HoldTime Type     PRI
--------------------------------------------------------------------------------
0000.0000.0002* GE1/0/0           0000.0000.0002.01  Up   8s       L1       64 

Total Peer(s): 1

3. 在PE1、P和PE2上创建网络切片实例,并指定基础接口和创建网络切片接口

# 配置PE1。

[~PE1] network-slice instance 10
[*PE1-network-slice-instance-10] description Basic
[*PE1-network-slice-instance-10] quit
[*PE1] network-slice instance 20
[*PE1-network-slice-instance-20] description vpn1
[*PE1-network-slice-instance-20] quit
[*PE1] network-slice instance 30
[*PE1-network-slice-instance-30] description vpn2
[*PE1-network-slice-instance-30] quit
[*PE1] interface gigabitethernet 1/0/0
[*PE1-GigabitEthernet1/0/0] network-slice 10 data-plane
[*PE1-GigabitEthernet1/0/0] quit
[*PE1] interface gigabitethernet 1/0/0.1
[*PE1-GigabitEthernet1/0/0.1] vlan-type dot1q 11
[*PE1-GigabitEthernet1/0/0.1] ipv6 enable
[*PE1-GigabitEthernet1/0/0.1] ipv6 address auto link-local
[*PE1-GigabitEthernet1/0/0.1] mode channel enable 
[*PE1-GigabitEthernet1/0/0.1] mode channel bandwidth 500 
[*PE1-GigabitEthernet1/0/0.1] basic-slice 10 
[*PE1-GigabitEthernet1/0/0.1] network-slice 20 data-plane 
[*PE1-GigabitEthernet1/0/0.1] quit
[*PE1] interface gigabitethernet 1/0/0.2
[*PE1-GigabitEthernet1/0/0.2] vlan-type dot1q 22
[*PE1-GigabitEthernet1/0/0.2] ipv6 enable
[*PE1-GigabitEthernet1/0/0.2] ipv6 address auto link-local
[*PE1-GigabitEthernet1/0/0.2] mode channel enable 
[*PE1-GigabitEthernet1/0/0.2] mode channel bandwidth 500 
[*PE1-GigabitEthernet1/0/0.2] basic-slice 10 
[*PE1-GigabitEthernet1/0/0.2] network-slice 30 data-plane 
[*PE1-GigabitEthernet1/0/0.2] quit
[*PE1] commit

# 配置P。

[~P] network-slice instance 10
[*P-network-slice-instance-10] description Basic
[*P-network-slice-instance-10] quit
[*P] network-slice instance 20
[*P-network-slice-instance-20] description vpn1
[*P-network-slice-instance-20] quit
[*P] network-slice instance 30
[*P-network-slice-instance-30] description vpn2
[*P-network-slice-instance-30] quit
[*P] interface gigabitethernet 1/0/0
[*P-GigabitEthernet1/0/0] network-slice 10 data-plane
[*P-GigabitEthernet1/0/0] quit
[*P] interface gigabitethernet 1/0/0.1
[*P-GigabitEthernet1/0/0.1] vlan-type dot1q 11
[*P-GigabitEthernet1/0/0.1] ipv6 enable
[*P-GigabitEthernet1/0/0.1] ipv6 address auto link-local
[*P-GigabitEthernet1/0/0.1] mode channel enable 
[*P-GigabitEthernet1/0/0.1] mode channel bandwidth 500 
[*P-GigabitEthernet1/0/0.1] basic-slice 10 
[*P-GigabitEthernet1/0/0.1] network-slice 20 data-plane 
[*P-GigabitEthernet1/0/0.1] quit
[*P] interface gigabitethernet 1/0/0.2
[*P-GigabitEthernet1/0/0.2] vlan-type dot1q 22
[*P-GigabitEthernet1/0/0.2] ipv6 enable
[*P-GigabitEthernet1/0/0.2] ipv6 address auto link-local
[*P-GigabitEthernet1/0/0.2] mode channel enable 
[*P-GigabitEthernet1/0/0.2] mode channel bandwidth 500 
[*P-GigabitEthernet1/0/0.2] basic-slice 10 
[*P-GigabitEthernet1/0/0.2] network-slice 30 data-plane 
[*P-GigabitEthernet1/0/0.2] quit
[*P] interface gigabitethernet 2/0/0
[*P-GigabitEthernet2/0/0] network-slice 10 data-plane
[*P-GigabitEthernet2/0/0] quit
[*P] interface gigabitethernet 2/0/0.1
[*P-GigabitEthernet2/0/0.1] vlan-type dot1q 11
[*P-GigabitEthernet2/0/0.1] ipv6 enable
[*P-GigabitEthernet2/0/0.1] ipv6 address auto link-local
[*P-GigabitEthernet2/0/0.1] mode channel enable 
[*P-GigabitEthernet2/0/0.1] mode channel bandwidth 500 
[*P-GigabitEthernet2/0/0.1] basic-slice 10 
[*P-GigabitEthernet2/0/0.1] network-slice 20 data-plane 
[*P-GigabitEthernet2/0/0.1] quit
[*P] interface gigabitethernet 2/0/0.2
[*P-GigabitEthernet2/0/0.2] vlan-type dot1q 22
[*P-GigabitEthernet2/0/0.2] ipv6 enable
[*P-GigabitEthernet2/0/0.2] ipv6 address auto link-local
[*P-GigabitEthernet2/0/0.1] mode channel enable 
[*P-GigabitEthernet2/0/0.1] mode channel bandwidth 500 
[*P-GigabitEthernet2/0/0.2] basic-slice 10 
[*P-GigabitEthernet2/0/0.2] network-slice 30 data-plane 
[*P-GigabitEthernet2/0/0.2] quit
[*P] commit

# 配置PE2。

[~PE2] network-slice instance 10
[*PE2-network-slice-instance-10] description Basic
[*PE2-network-slice-instance-10] quit
[*PE2] network-slice instance 20
[*PE2-network-slice-instance-20] description vpn1
[*PE2-network-slice-instance-20] quit
[*PE2] network-slice instance 30
[*PE2-network-slice-instance-30] description vpn2
[*PE2-network-slice-instance-30] quit
[*PE2] interface gigabitethernet 1/0/0
[*PE2-GigabitEthernet1/0/0] network-slice 10 data-plane
[*PE2-GigabitEthernet1/0/0] quit
[*PE2] interface gigabitethernet 1/0/0.1
[*PE2-GigabitEthernet1/0/0.1] vlan-type dot1q 11
[*PE2-GigabitEthernet1/0/0.1] ipv6 enable
[*PE2-GigabitEthernet1/0/0.1] ipv6 address auto link-local
[*PE2-GigabitEthernet1/0/0.1] mode channel enable 
[*PE2-GigabitEthernet1/0/0.1] mode channel bandwidth 500
[*PE2-GigabitEthernet1/0/0.1] basic-slice 10 
[*PE2-GigabitEthernet1/0/0.1] network-slice 20 data-plane 
[*PE2-GigabitEthernet1/0/0.1] quit
[*PE2] interface gigabitethernet 1/0/0.2
[*PE2-GigabitEthernet1/0/0.2] vlan-type dot1q 22
[*PE2-GigabitEthernet1/0/0.2] ipv6 enable
[*PE2-GigabitEthernet1/0/0.2] ipv6 address auto link-local
[*PE2-GigabitEthernet1/0/0.2] mode channel enable 
[*PE2-GigabitEthernet1/0/0.2] mode channel bandwidth 500
[*PE2-GigabitEthernet1/0/0.2] basic-slice 10 
[*PE2-GigabitEthernet1/0/0.2] network-slice 30 data-plane 
[*PE2-GigabitEthernet1/0/0.2] quit
[*PE2] commit

配置完成后,可按如下指导查看切片实例下基础接口与切片接口绑定关系。以PE1的显示为例:

[~PE1] display network-slice 10 binding-list 
        Slice-ID            Basic-Interface          Slicing-Interface 
        10                  GigabitEthernet1/0/0     GigabitEthernet1/0/0.1
                                                     GigabitEthernet1/0/0.2

4. 在PE设备上配置IPv4 L3VPN实例并将IPv4 L3VPN实例绑定到接入侧接口

# 配置PE1。

[~PE1] ip vpn-instance vpn1
[*PE1-vpn-instance-vpn1] ipv4-family
[*PE1-vpn-instance-vpn1-af-ipv4] route-distinguisher 100:1
[*PE1-vpn-instance-vpn1-af-ipv4] vpn-target 1:1 evpn
[*PE1-vpn-instance-vpn1-af-ipv4] quit
[*PE1-vpn-instance-vpn1] quit
[*PE1] interface gigabitethernet2/0/0
[*PE1-GigabitEthernet2/0/0] ip binding vpn-instance vpn1
[*PE1-GigabitEthernet2/0/0] ip address 10.11.1.1 24
[*PE1-GigabitEthernet2/0/0] quit
[*PE1] ip vpn-instance vpn2
[*PE1-vpn-instance-vpn2] ipv4-family
[*PE1-vpn-instance-vpn2-af-ipv4] route-distinguisher 100:2
[*PE1-vpn-instance-vpn2-af-ipv4] vpn-target 2:2 evpn
[*PE1-vpn-instance-vpn2-af-ipv4] quit
[*PE1-vpn-instance-vpn2] quit
[*PE1] interface gigabitethernet3/0/0
[*PE1-GigabitEthernet3/0/0] ip binding vpn-instance vpn2
[*PE1-GigabitEthernet3/0/0] ip address 10.33.1.1 24
[*PE1-GigabitEthernet3/0/0] quit
[*PE1] commit

# 配置PE2。

[~PE2] ip vpn-instance vpn1
[*PE2-vpn-instance-vpn1] ipv4-family
[*PE2-vpn-instance-vpn1-af-ipv4] route-distinguisher 200:1
[*PE2-vpn-instance-vpn1-af-ipv4] vpn-target 1:1 evpn
[*PE2-vpn-instance-vpn1-af-ipv4] quit
[*PE2-vpn-instance-vpn1] quit
[*PE2] interface gigabitethernet2/0/0
[*PE2-GigabitEthernet2/0/0] ip binding vpn-instance vpn1
[*PE2-GigabitEthernet2/0/0] ip address 10.22.1.1 24
[*PE2-GigabitEthernet2/0/0] quit
[*PE2] ip vpn-instance vpn2
[*PE2-vpn-instance-vpn2] ipv4-family
[*PE2-vpn-instance-vpn2-af-ipv4] route-distinguisher 200:2
[*PE2-vpn-instance-vpn2-af-ipv4] vpn-target 2:2 evpn
[*PE2-vpn-instance-vpn2-af-ipv4] quit
[*PE2-vpn-instance-vpn2] quit
[*PE2] interface gigabitethernet3/0/0
[*PE2-GigabitEthernet3/0/0] ip binding vpn-instance vpn2
[*PE2-GigabitEthernet3/0/0] ip address 10.44.1.1 24
[*PE2-GigabitEthernet3/0/0] quit
[*PE2] commit

5. 在PE与CE之间建立EBGP对等体关系

# 配置CE1。

[~CE1] interface loopback 1
[*CE1-LoopBack1] ip address 11.1.1.1 32
[*CE1-LoopBack1] quit
[*CE1] bgp 65410
[*CE1-bgp] router-id 11.1.1.1
[*CE1-bgp] peer 10.11.1.1 as-number 100
[*CE1-bgp] import-route direct
[*CE1-bgp] quit
[*CE1] commit

# 配置CE3。

[~CE3] interface loopback 1
[*CE3-LoopBack1] ip address 33.3.3.3 32
[*CE3-LoopBack1] quit
[*CE3] bgp 65430
[*CE3-bgp] router-id 33.3.3.3
[*CE3-bgp] peer 10.33.1.1 as-number 100
[*CE3-bgp] import-route direct
[*CE3-bgp] quit
[*CE3] commit

# 配置PE1。

[~PE1] bgp 100
[~PE1-bgp] router-id 1.1.1.1
[*PE1-bgp] ipv4-family vpn-instance vpn1
[*PE1-bgp-vpn1] peer 10.11.1.2 as-number 65410
[*PE1-bgp-vpn1] import-route direct
[*PE1-bgp-vpn1] advertise l2vpn evpn
[*PE1-bgp-vpn1] quit
[*PE1-bgp] ipv4-family vpn-instance vpn2
[*PE1-bgp-vpn2] peer 10.33.1.2 as-number 65430
[*PE1-bgp-vpn2] import-route direct
[*PE1-bgp-vpn2] advertise l2vpn evpn
[*PE1-bgp-vpn2] quit
[*PE1-bgp] quit
[*PE1] commit

# 配置CE2。

[~CE2] interface loopback 1
[*CE2-LoopBack1] ip address 22.2.2.2 32
[*CE2-LoopBack1] quit
[*CE2] bgp 65420
[*CE2-bgp] router-id 22.2.2.2
[*CE2-bgp] peer 10.22.1.1 as-number 100
[*CE2-bgp] import-route direct
[*CE2-bgp] quit
[*CE2] commit

# 配置CE4。

[~CE4] interface loopback 1
[*CE4-LoopBack1] ip address 44.4.4.4 32
[*CE4-LoopBack1] quit
[*CE4] bgp 65440
[*CE4-bgp] router-id 44.4.4.4
[*CE4-bgp] peer 10.44.1.1 as-number 100
[*CE4-bgp] import-route direct
[*CE4-bgp] quit
[*CE4] commit

# 配置PE2。

[~PE2] bgp 100
[~PE2-bgp] router-id 3.3.3.3
[*PE2-bgp] ipv4-family vpn-instance vpn1
[*PE2-bgp-vpn1] peer 10.22.1.2 as-number 65420
[*PE2-bgp-vpn1] import-route direct
[*PE2-bgp-vpn1] advertise l2vpn evpn
[*PE2-bgp-vpn1] quit
[*PE2-bgp] ipv4-family vpn-instance vpn2
[*PE2-bgp-vpn2] peer 10.44.1.2 as-number 65440
[*PE2-bgp-vpn2] import-route direct
[*PE2-bgp-vpn2] advertise l2vpn evpn
[*PE2-bgp-vpn2] quit
[*PE2-bgp] quit
[*PE2] commit

配置完成后,在PE设备上执行display bgp vpnv4 vpn-instance peer命令,可以看到PE与CE之间的BGP对等体关系已建立,并达到Established状态。

以PE1与CE1的对等体关系为例:

[~PE1] display bgp vpnv4 vpn-instance vpn1 peer

 BGP local router ID : 1.1.1.1                               
 Local AS number : 100                             

 VPN-Instance vpn1, Router ID 1.1.1.1:                       
 Total number of peers : 1                 Peers in established state : 1                   

  Peer                             V          AS  MsgRcvd  MsgSent  OutQ  Up/Down       State  PrefRcv 
  10.11.1.2                        4       65410       16       19     0 00:10:44 Established        2 

6. 在PE设备之间建立BGP EVPN对等体关系

# 配置PE1。

[~PE1] bgp 100
[~PE1-bgp] peer 2001:DB8:3::3 as-number 100
[*PE1-bgp] peer 2001:DB8:3::3 connect-interface loopback 1
[*PE1-bgp] l2vpn-family evpn
[*PE1-bgp-af-evpn] peer 2001:DB8:3::3 enable
[*PE1-bgp-af-evpn] quit
[*PE1-bgp] quit
[*PE1] commit

# 配置PE2。

[~PE2] bgp 100
[~PE2-bgp] peer 2001:DB8:1::1 as-number 100
[*PE2-bgp] peer 2001:DB8:1::1 connect-interface loopback 1
[*PE2-bgp] l2vpn-family evpn
[*PE2-bgp-af-evpn] peer 2001:DB8:1::1 enable
[*PE2-bgp-af-evpn] quit
[*PE2-bgp] quit
[*PE2] commit

配置完成后,在PE设备上执行display bgp evpn peer命令,可以看到PE之间的BGP EVPN对等体关系已建立,并达到Established状态。

以PE1的显示为例:

[~PE1] display bgp evpn peer

 BGP local router ID : 1.1.1.1
 Local AS number : 100
 Total number of peers : 1                 Peers in established state : 1

  Peer                             V          AS  MsgRcvd  MsgSent  OutQ  Up/Down       State  PrefRcv
  2001:DB8:3::3                    4         100       49       49     0 00:30:41 Established        2

7. 在PE之间建立SRv6 BE路径

# 配置PE1。

[~PE1] segment-routing ipv6
[*PE1-segment-routing-ipv6] encapsulation source-address 2001:DB8:1::1
[*PE1-segment-routing-ipv6] locator PE1 ipv6-prefix 2001:DB8:100:: 64 static 32
[*PE1-segment-routing-ipv6-locator] quit
[*PE1-segment-routing-ipv6] quit
[*PE1] bgp 100
[*PE1-bgp] l2vpn-family evpn
[*PE1-bgp-af-evpn] peer 2001:DB8:3::3 advertise encap-type srv6
[*PE1-bgp-af-evpn] quit
[*PE1-bgp] ipv4-family vpn-instance vpn1
[*PE1-bgp-vpn1] segment-routing ipv6 best-effort evpn
[*PE1-bgp-vpn1] segment-routing ipv6 locator PE1 evpn
[*PE1-bgp-vpn1] quit
[*PE1-bgp] ipv4-family vpn-instance vpn2
[*PE1-bgp-vpn2] segment-routing ipv6 best-effort evpn
[*PE1-bgp-vpn2] segment-routing ipv6 locator PE1 evpn
[*PE1-bgp-vpn2] quit
[*PE1-bgp] quit
[*PE1] isis 1
[*PE1-isis-1] segment-routing ipv6 locator PE1
[*PE1-isis-1] commit
[~PE1-isis-1] quit

# 配置PE2。

[~PE2] segment-routing ipv6
[*PE2-segment-routing-ipv6] encapsulation source-address 2001:DB8:3::3
[*PE2-segment-routing-ipv6] locator PE2 ipv6-prefix 2001:DB8:130:: 64 static 32
[*PE2-segment-routing-ipv6-locator] quit
[*PE2-segment-routing-ipv6] quit
[*PE2] bgp 100
[*PE2-bgp] l2vpn-family evpn
[*PE2-bgp-af-evpn] peer 2001:DB8:1::1 advertise encap-type srv6
[*PE2-bgp-af-evpn] quit
[*PE2-bgp] ipv4-family vpn-instance vpn1
[*PE2-bgp-vpn1] segment-routing ipv6 best-effort evpn
[*PE2-bgp-vpn1] segment-routing ipv6 locator PE2 evpn
[*PE2-bgp-vpn1] quit
[*PE2-bgp] ipv4-family vpn-instance vpn2
[*PE2-bgp-vpn2] segment-routing ipv6 best-effort evpn
[*PE2-bgp-vpn2] segment-routing ipv6 locator PE2 evpn
[*PE2-bgp-vpn2] quit
[*PE2-bgp] quit
[*PE2] isis 1
[*PE2-isis-1] segment-routing ipv6 locator PE2
[*PE2-isis-1] commit
[~PE2-isis-1] quit

8. 配置Route-Policy,为VPN实例路由染色

# 配置PE1。

[~PE1] route-policy rp11 permit node 10
[*PE1-route-policy] apply extcommunity color 0:101
[*PE1-route-policy] quit
[*PE1] route-policy rp11 permit node 20
[*PE1-route-policy] quit
[*PE1] route-policy rp22 permit node 10
[*PE1-route-policy] apply extcommunity color 0:202
[*PE1-route-policy] quit
[*PE1] route-policy rp22 permit node 20
[*PE1-route-policy] quit
[*PE1] ip vpn-instance vpn1
[*PE1-vpn-instance-vpn1] ipv4-family
[*PE1-vpn-instance-vpn1-af-ipv4] import route-policy rp11
[*PE1-vpn-instance-vpn1-af-ipv4] quit
[*PE1-vpn-instance-vpn1] quit
[*PE1] ip vpn-instance vpn2
[*PE1-vpn-instance-vpn2] ipv4-family
[*PE1-vpn-instance-vpn2-af-ipv4] import route-policy rp22
[*PE1-vpn-instance-vpn2-af-ipv4] quit
[*PE1-vpn-instance-vpn2] quit
[*PE1] commit

# 配置PE2。

[~PE2] route-policy rp11 permit node 10
[*PE2-route-policy] apply extcommunity color 0:101
[*PE2-route-policy] quit
[*PE2] route-policy rp11 permit node 20
[*PE2-route-policy] quit
[*PE2] route-policy rp22 permit node 10
[*PE2-route-policy] apply extcommunity color 0:202
[*PE2-route-policy] quit
[*PE2] route-policy rp22 permit node 20
[*PE2-route-policy] quit
[*PE2] ip vpn-instance vpn1
[*PE2-vpn-instance-vpn1] ipv4-family
[*PE2-vpn-instance-vpn1-af-ipv4] import route-policy rp11
[*PE2-vpn-instance-vpn1-af-ipv4] quit
[*PE2-vpn-instance-vpn1] quit
[*PE2] ip vpn-instance vpn2
[*PE2-vpn-instance-vpn2] ipv4-family
[*PE2-vpn-instance-vpn2-af-ipv4] import route-policy rp22
[*PE2-vpn-instance-vpn2-af-ipv4] quit
[*PE2-vpn-instance-vpn2] quit
[*PE2] commit

9. 配置SRv6 BE路由颜色(Color)与Slice ID的映射关系。

# 配置PE1。

[~PE1] network-slice color-mapping
[*PE1-network-slice-color-mapping] color 101 network-slice 20
[*PE1-network-slice-color-mapping] color 202 network-slice 30
[*PE1-network-slice-color-mapping] quit
[*PE1-route-policy] commit

# 配置PE2。

[~PE2] network-slice color-mapping
[*PE2-network-slice-color-mapping] color 101 network-slice 20
[*PE2-network-slice-color-mapping] color 202 network-slice 30
[*PE2-network-slice-color-mapping] quit
[*PE2-route-policy] commit

10. 检查配置结果

同一VPN的CE能够相互Ping通,例如:

[~CE1] ping -a 11.1.1.1 22.2.2.2                                                 
  PING 22.2.2.2: 56  data bytes, press CTRL_C to break                          
    Reply from 22.2.2.2: bytes=56 Sequence=1 ttl=253 time=7 ms                       
    Reply from 22.2.2.2: bytes=56 Sequence=2 ttl=253 time=4 ms                     
    Reply from 22.2.2.2: bytes=56 Sequence=3 ttl=253 time=3 ms                       
    Reply from 22.2.2.2: bytes=56 Sequence=4 ttl=253 time=4 ms                    
    Reply from 22.2.2.2: bytes=56 Sequence=5 ttl=253 time=3 ms                    

  --- 22.2.2.2 ping statistics ---                                        
    5 packet(s) transmitted                                                 
    5 packet(s) received                                                  
    0.00% packet loss                                            
    round-trip min/avg/max = 3/4/7 ms
[~CE3] ping -a 33.3.3.3 44.4.4.4                                                 
  PING 44.4.4.4: 56  data bytes, press CTRL_C to break                          
    Reply from 44.4.4.4: bytes=56 Sequence=1 ttl=253 time=9 ms                       
    Reply from 44.4.4.4: bytes=56 Sequence=2 ttl=253 time=5 ms                     
    Reply from 44.4.4.4: bytes=56 Sequence=3 ttl=253 time=4 ms                       
    Reply from 44.4.4.4: bytes=56 Sequence=4 ttl=253 time=5 ms                    
    Reply from 44.4.4.4: bytes=56 Sequence=5 ttl=253 time=4 ms                    

  --- 44.4.4.4 ping statistics ---                                        
    5 packet(s) transmitted                                                 
    5 packet(s) received                                                  
    0.00% packet loss                                            
    round-trip min/avg/max = 4/5/9 ms

华为ne40e路由器实验配置示例|配置非标签公网bgp路由迭代sr-mplsbe隧道(代码片段)

组网需求当用户通过运营商网络访问互联网时,如果报文采用IP转发的话,则从用户到互联网路径上的运营商核心设备都需要学习到大量的互联网路由,这给运营商的核心设备带来了很大的负担,影响核心设备的... 查看详情

华为ne40e路由器实验配置示例|配置evdpdndl3vdpdndv6oversrv6be(代码片段)

组网需求如图1所示:PE1、P和PE2属于同一自治系统,要求它们之间通过IS-IS协议达到IPv6网络互连的目的。在PE1和PE2之间通过建立双向SRv6BE承载EVPNL3VPNv6业务。图1 配置EVPNL3VPNv6overSRv6BE组网图配置思路使能PE1、P和PE2各接口的... 查看详情

华为ne40e路由器实验配置示例|配置evdpdndl3vdpdndv4oversrv6beflex-algo(代码片段)

组网需求如图1所示:路由器PE1、P和PE2属于同一自治系统,要求它们之间通过IS-IS协议达到IPv6网络互连的目的。PE1、P和PE2属于IS-IS进程1,都是Level-1设备。要求在PE1和PE2之间建立双向SRv6BE路径,承载EVPNL3VPNv4业务。... 查看详情

华为ne40e路由器实验配置示例|配置evdpdndl3vdpdndv4oversrv6be网络切片(代码片段)

组网需求如图1所示:PE1、P和PE2属于同一自治系统,要求它们之间通过IS-IS协议达到IPv6网络互连的目的。在PE1和PE2之间通过建立双向SRv6BE承载EVPNL3VPNv4业务。此外,为了满足保障CE1和CE2之间VPN实例vpn1的业务SLA,可... 查看详情

华为ne16ex路由器清除密码步骤

在BootLoader下配置跳过Console口密码启动后,修改Console口密码设备的BootLoader提供了配置跳过Console口密码启动的功能,可以在用户使用Console口登录的时候跳过密码检查。这样系统启动后除了不需要输入Console密码外,与正常启动相... 查看详情

简单的单臂路由的配置实验(华为)(代码片段)

实验名称:简单的单臂路由的配置实验(华为)实验拓扑:实验需要:1、按图中所示配置设网络备vlan,IP地址2、能够使各pc互相ping通。实验步骤:1、配置终端设备:pc1-pc5按照拓扑图中所示配置各个pc的ip地址。网关配置为192.168... 查看详情

华为配置rip实现全网互通

...置RIP实现全网互通实验拓扑:实验需求:两台PC机,四台路由器实验步骤:配置pc机配置路由器接口IPR1:<Huawei>sysEntersystemview,returnuserviewwithCtrl+Z.[Huawei]sysnameR1[R1]interfaceGigabitEthernet0/0/0[R1-GigabitEthe 查看详情

华为---单臂路由配置

...260)实验步骤:首先,来了解一下,单臂路由:性质:在路由器的一个接口上配置子接口目的:实现原来不同VLAN之间的互联互通优点:实现不同vlan之间的通信缺点:容易成为网络单点故障作用:单臂路由(router-on-a-stick)是指... 查看详情

微型企业默认路由使用及配置实验—华为

...环境软件eNSP1.2.00.500虚拟设备PC:PC1–PC2交换机:SW1、SW2路由器:R1–R3三、实验拓扑四、实验步骤手动配置PC1、PC2的IP、子网掩码、网关,过程不进行叙述和展示。R1:<Huawei>sys#进入视图模式[Huawei]sysR1#修改设备名称为R1[R1]intg... 查看详情

华为交换机rip配置实验

给上图四台路由器分别配置接口IP地址;分别用版本2,开启summary,配置自己的两个直连网段给其他路由器学习。 水平分割机制:在一个端口上收到的路由不会再从这个端口发出去。验证命令查看当前路由协议R1#showiproute ... 查看详情

简单的三层交换配置路由实验(华为)(代码片段)

实验名称:简单的三层交换配置路由实验拓扑:实验需要:1、按图中所示配置设网络备vlan,IP地址2、能够使各pc互相ping通。实验步骤:1、配置终端设备:pc1-pc5按照拓扑图中所示配置各个pc的ip地址。网关配置为192.168.x.254pc6配置... 查看详情

华为网络设备介绍及基础配置命令(代码片段)

一、华为产品分类:.目前华为网络产品有路由器、交换机、防火墙。.1、路由器路由器主要分为AR系列和NE系列:AR系列路由器:AR系列是华为推出的新一代网络产品,主要面向企业及分支机构。AR系列集成路由、交换、3G、语音和... 查看详情

小型企业默认路由使用及配置实验—华为

目的:通过静态路由和默认路由来实现全网互通。拓扑图:步骤及配置:手动配置PC1,PC2的ip地址,子网掩码和网关。AR1:[Huawei]sysR1#修改设备名称为R1[R1]intgi0/0/0#进入0端口[R1-GigabitEthernet0/0/0]undoshutdown#启用端口[R1-GigabitEthernet0/0/0]ipa... 查看详情

默认路由配置实现全网互通。(华为)

...互通。实验步骤:1.先给PC配置不同网段的IP地址;2.配置路由器实现全网互通;配置命令:路由器AR1:<Huawei>system-view进入特权[Huawei]interfaceGigabitEthernet0/0/0进入端口[Huawei-GigabitEthernet0/0/0]ipaddress192.168.1 查看详情

华为路由器ospf虚链路配置(代码片段)

...OSPF虚链路配置命令。实验配置如下图:实验说明如下:1.路由器R1、R2在0区域,路由器R2、R3、R4在234区域,路由器R4、R5在45区域。2.45区域没有与骨干区域直接相连,因此在不引入外部路由的情况下,需要在路由R2、R4上配置虚链... 查看详情

华为设备-配置默认路由

...通。方案使用eNSP搭建实验环境,如图所示。分别为PC机和路由器1-2-3的各接口配置好IP地址,方便做实验。PC1:ip地址:192.168.1.1255.255.255.0PC2:ip地址:192.168.4.1255.255.255.0R1:GE0/0/0192.168.1.254255.255.255.0R1:GE0/0 查看详情

玩转华为ensp模拟器系列|配置lldp基本功能示例(代码片段)

素材来源:华为路由器配置指南一边学习一边整理试验笔记,并与大家分享,侵权即删,谢谢支持!附上汇总贴:玩转华为ENSP模拟器系列|合集_COCOgsta的博客-CSDN博客_华为模拟器实验目标本举例介绍通过配... 查看详情

玩转华为ensp模拟器系列|配置igmp基本功能示例(代码片段)

素材来源:华为路由器配置指南一边学习一边整理试验笔记,并与大家分享,侵权即删,谢谢支持!附上汇总贴:玩转华为ENSP模拟器系列|合集_COCOgsta的博客-CSDN博客_华为模拟器实验目标在组播网络中部署I... 查看详情