實踐gobgp作為mpls l3vpn的vpnv4反射器

Linux-PE-RR

os:ubuntu-17.10

zebra的ospfd用于Lo(5.5.5.5)和其他PE的Lo可達

gobgp用于Lo和其他PE的Lo建立MP-IBGP鄰居


root@ubuntu:~# cat /etc/apt/sources.list

deb http://mirrors.163.com/ubuntu/ artful main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-security main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-updates main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-proposed main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-backports main restricted universe multiverse


root@ubuntu:~# apt update

root@ubuntu:~# apt install gobgpd? -y

root@ubuntu:~# apt install quagga -y

root@ubuntu:~# touch /etc/quagga/ospfd.conf

root@ubuntu:~# touch /etc/quagga/zebra.conf

root@ubuntu:~# chown quagga.quagga /etc/quagga/*.conf

root@ubuntu:~# cat /etc/quagga/ospfd.conf

router ospf

ospf router-id 5.5.5.5

network 5.5.5.5/32 area 0.0.0.0

network 10.0.5.0/24 area 0.0.0.0


root@ubuntu:~# ip add li ens4 | grep inet

inet 10.0.5.1/24 scope global ens4

root@ubuntu:~# ip add li lo | grep inet

inet 127.0.0.1/8 scope host lo

inet 5.5.5.5/32 scope global lo


編輯gobgpd.conf配置文件

root@ubuntu:~# cat /etc/gobgp/gobgpd.conf

[global]

[global.config]

as = 65000

router-id = "5.5.5.5"

[[neighbors]]

[neighbors.config]

neighbor-address = "1.1.1.1"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

[[neighbors]]

[neighbors.config]

neighbor-address = "2.2.2.2"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

[[neighbors]]

[neighbors.config]

neighbor-address = "3.3.3.3"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

[[neighbors]]

[neighbors.config]

neighbor-address = "4.4.4.4"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

啟動ospfd和gobgpd

root@ubuntu:~# gobgpd -f /etc/gobgp/gobgpd.conf &

root@ubuntu:~# systemctl start ospfd

root@ubuntu:~# systemctl? start zebra


#########VMX-P的配置###############

set version 14.1R4.8

set system root-authentication encrypted-password "$1$gQsE5emV$YKl79HDHgraX5dofhGZj8."

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.1.254/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 10.0.2.254/24

set interfaces ge-0/0/1 unit 0 family mpls

set interfaces ge-0/0/2 unit 0 family inet address 10.0.3.254/24

set interfaces ge-0/0/2 unit 0 family mpls

set interfaces ge-0/0/3 unit 0 family inet address 10.0.4.254/24

set interfaces ge-0/0/3 unit 0 family mpls

set interfaces ge-0/0/4 unit 0 family inet address 10.0.5.254/24

set interfaces ge-0/0/4 unit 0 family mpls

set interfaces lo0 unit 0 family inet address 10.10.10.10/32

set routing-options router-id 10.10.10.10

set protocols mpls interface ge-0/0/0.0

set protocols mpls interface ge-0/0/1.0

set protocols mpls interface ge-0/0/2.0

set protocols mpls interface ge-0/0/3.0

set protocols mpls interface ge-0/0/4.0

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface ge-0/0/1.0

set protocols ospf area 0.0.0.0 interface ge-0/0/2.0

set protocols ospf area 0.0.0.0 interface ge-0/0/3.0

set protocols ospf area 0.0.0.0 interface ge-0/0/4.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set protocols ldp interface ge-0/0/1.0

set protocols ldp interface ge-0/0/2.0

set protocols ldp interface ge-0/0/3.0

set protocols ldp interface ge-0/0/4.0

#######VMX-PE1的配置######################

set version 14.1R4.8

set system host-name VMX-PE1

set system root-authentication encrypted-password "$1$PDALzLQM$7sa4xnKY/CG9Z4gGDRooI0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.1.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.1.254/24

set interfaces lo0 unit 0 family inet address 1.1.1.1/32

set routing-options router-id 1.1.1.1

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 1.1.1.1

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 1.1.1.1:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.1.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.1.1 peer-as 65001

########VMX-PE2的配置#####################

set version 14.1R4.8

set system host-name VMX-PE2

set system root-authentication encrypted-password "$1$CT8eKT4/$6KoQkGBVblWjaXduDGCTO0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.2.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.2.254/24

set interfaces lo0 unit 0 family inet address 2.2.2.2/32

set routing-options router-id 2.2.2.2

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 2.2.2.2

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 2.2.2.2:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.2.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.2.1 peer-as 65002

##############VMX-PE3的配置################

set version 14.1R4.8

set system host-name VMX-PE3

set system root-authentication encrypted-password "$1$ci.Wd2VV$Mi.R0/P7Sa3JcJkrm2Vuv0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.3.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.3.254/24

set interfaces lo0 unit 0 family inet address 3.3.3.3/32

set routing-options router-id 3.3.3.3

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 3.3.3.3

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 3.3.3.3:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.3.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.3.1 peer-as 65003

#############VMX-PE4的配置#################

set version 14.1R4.8

set system host-name VMX-PE4

set system root-authentication encrypted-password "$1$TuNrotp/$/3NLB7HAPp2qTksnJAHTy0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.4.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.4.254/24

set interfaces lo0 unit 0 family inet address 4.4.4.4/32

set routing-options router-id 4.4.4.4

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 4.4.4.4

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 4.4.4.4:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.4.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.4.1 peer-as 65004

###########VMX-CE1####################

set version 14.1R4.8

set system host-name VMX-CE1

set system root-authentication encrypted-password "$1$1006jy5.$8/66Q0JBoXlGtAktmGNka1"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.1.1/24

set interfaces lo0 unit 0 family inet address 11.11.11.11/32

set routing-options router-id 11.11.11.11

set routing-options autonomous-system 65001

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.1.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.1.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

##########VMX-CE2###########################

set version 14.1R4.8

set system host-name VMX-CE2

set system root-authentication encrypted-password "$1$0qSqG.Fl$qU3qxR7eosVTyj65jNxVV1"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.2.1/24

set interfaces lo0 unit 0 family inet address 22.22.22.22/32

set routing-options router-id 22.22.22.22

set routing-options autonomous-system 65002

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.2.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.2.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

###########VMX-CE3#################

set version 14.1R4.8

set system host-name VMX-CE3

set system root-authentication encrypted-password "$1$X1Ybl/Jd$eC4M5uKC6Num6F2vb/EP1."

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.3.1/24

set interfaces lo0 unit 0 family inet address 33.33.33.33/32

set routing-options router-id 33.33.33.33

set routing-options autonomous-system 65003

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.3.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.3.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

################VMX-CE4############################

set version 14.1R4.8

set system host-name VMX-CE4

set system root-authentication encrypted-password "$1$l/p/KeA6$CQ6qWqkWaM7P2MbUGN4RI0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.4.1/24

set interfaces lo0 unit 0 family inet address 44.44.44.44/32

set routing-options router-id 44.44.44.44

set routing-options autonomous-system 65004

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.4.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.4.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

驗證

root@VMX-CE1> show bgp neighbor 192.168.1.254 | match State

Type: External? ? State: Established? ? Flags:

Last State: OpenConfirm? Last Event: RecvKeepAlive

RIB State: BGP restart is complete

Send state: in sync

學習到了22.22.22.22,33.33.33.33,44.44.44.44路由

root@VMX-CE1> show route protocol bgp

inet.0: 9 destinations, 9 routes (9 active, 0 holddown, 0 hidden)

+ = Active Route, - = Last Active, * = Both

22.22.22.22/32? ? *[BGP/170] 00:20:12, localpref 100

AS path: 65000 65002 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

33.33.33.33/32? ? *[BGP/170] 00:23:56, localpref 100

AS path: 65000 65003 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

44.44.44.44/32? ? *[BGP/170] 00:23:43, localpref 100

AS path: 65000 65004 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

192.168.2.0/24? ? *[BGP/170] 00:20:12, localpref 100

AS path: 65000 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

192.168.3.0/24? ? *[BGP/170] 00:23:56, localpref 100

AS path: 65000 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

192.168.4.0/24? ? *[BGP/170] 00:23:43, localpref 100

AS path: 65000 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

root@ubuntu:~# gobgp nei

Peer? ? ? AS? Up/Down State? ? ? |#Received? Accepted

1.1.1.1 65000 00:26:29 Establ? ? ? |? ? ? ? 2? ? ? ? 2

2.2.2.2 65000 00:22:45 Establ? ? ? |? ? ? ? 2? ? ? ? 2

3.3.3.3 65000 00:26:54 Establ? ? ? |? ? ? ? 2? ? ? ? 2

4.4.4.4 65000 00:26:15 Establ? ? ? |? ? ? ? 2? ? ? ? 2

root@VMX-CE1> ping source 11.11.11.11 22.22.22.22

PING 22.22.22.22 (22.22.22.22): 56 data bytes

64 bytes from 22.22.22.22: icmp_seq=0 ttl=61 time=7.720 ms

64 bytes from 22.22.22.22: icmp_seq=1 ttl=61 time=5.759 ms

64 bytes from 22.22.22.22: icmp_seq=2 ttl=61 time=8.294 ms

雙層標簽截獲的包


VPNV4的基礎學習請參考

http://blog.sina.com.cn/s/blog_3e15c5360101bovk.html

?著作權歸作者所有,轉載或內容合作請聯系作者
平臺聲明:文章內容(如有圖片或視頻亦包括在內)由作者上傳并發布,文章內容僅代表作者本人觀點,簡書系信息發布平臺,僅提供信息存儲服務。
  • 序言:七十年代末,一起剝皮案震驚了整個濱河市,隨后出現的幾起案子,更是在濱河造成了極大的恐慌,老刑警劉巖,帶你破解...
    沈念sama閱讀 230,048評論 6 542
  • 序言:濱河連續發生了三起死亡事件,死亡現場離奇詭異,居然都是意外死亡,警方通過查閱死者的電腦和手機,發現死者居然都...
    沈念sama閱讀 99,414評論 3 429
  • 文/潘曉璐 我一進店門,熙熙樓的掌柜王于貴愁眉苦臉地迎上來,“玉大人,你說我怎么就攤上這事。” “怎么了?”我有些...
    開封第一講書人閱讀 178,169評論 0 383
  • 文/不壞的土叔 我叫張陵,是天一觀的道長。 經常有香客問我,道長,這世上最難降的妖魔是什么? 我笑而不...
    開封第一講書人閱讀 63,722評論 1 317
  • 正文 為了忘掉前任,我火速辦了婚禮,結果婚禮上,老公的妹妹穿的比我還像新娘。我一直安慰自己,他們只是感情好,可當我...
    茶點故事閱讀 72,465評論 6 412
  • 文/花漫 我一把揭開白布。 她就那樣靜靜地躺著,像睡著了一般。 火紅的嫁衣襯著肌膚如雪。 梳的紋絲不亂的頭發上,一...
    開封第一講書人閱讀 55,823評論 1 328
  • 那天,我揣著相機與錄音,去河邊找鬼。 笑死,一個胖子當著我的面吹牛,可吹牛的內容都是我干的。 我是一名探鬼主播,決...
    沈念sama閱讀 43,813評論 3 446
  • 文/蒼蘭香墨 我猛地睜開眼,長吁一口氣:“原來是場噩夢啊……” “哼!你這毒婦竟也來了?” 一聲冷哼從身側響起,我...
    開封第一講書人閱讀 43,000評論 0 290
  • 序言:老撾萬榮一對情侶失蹤,失蹤者是張志新(化名)和其女友劉穎,沒想到半個月后,有當地人在樹林里發現了一具尸體,經...
    沈念sama閱讀 49,554評論 1 335
  • 正文 獨居荒郊野嶺守林人離奇死亡,尸身上長有42處帶血的膿包…… 初始之章·張勛 以下內容為張勛視角 年9月15日...
    茶點故事閱讀 41,295評論 3 358
  • 正文 我和宋清朗相戀三年,在試婚紗的時候發現自己被綠了。 大學時的朋友給我發了我未婚夫和他白月光在一起吃飯的照片。...
    茶點故事閱讀 43,513評論 1 374
  • 序言:一個原本活蹦亂跳的男人離奇死亡,死狀恐怖,靈堂內的尸體忽然破棺而出,到底是詐尸還是另有隱情,我是刑警寧澤,帶...
    沈念sama閱讀 39,035評論 5 363
  • 正文 年R本政府宣布,位于F島的核電站,受9級特大地震影響,放射性物質發生泄漏。R本人自食惡果不足惜,卻給世界環境...
    茶點故事閱讀 44,722評論 3 348
  • 文/蒙蒙 一、第九天 我趴在偏房一處隱蔽的房頂上張望。 院中可真熱鬧,春花似錦、人聲如沸。這莊子的主人今日做“春日...
    開封第一講書人閱讀 35,125評論 0 28
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽。三九已至,卻和暖如春,著一層夾襖步出監牢的瞬間,已是汗流浹背。 一陣腳步聲響...
    開封第一講書人閱讀 36,430評論 1 295
  • 我被黑心中介騙來泰國打工, 沒想到剛下飛機就差點兒被人妖公主榨干…… 1. 我叫王不留,地道東北人。 一個月前我還...
    沈念sama閱讀 52,237評論 3 398
  • 正文 我出身青樓,卻偏偏與公主長得像,于是被迫代替她去往敵國和親。 傳聞我的和親對象是個殘疾皇子,可洞房花燭夜當晚...
    茶點故事閱讀 48,482評論 2 379

推薦閱讀更多精彩內容