Configuring nested vpn, Network requirements – H3C Technologies H3C SR8800 User Manual

Page 335

Advertising
background image

324

--- 120.1.1.1 ping statistics ---

5 packet(s) transmitted

5 packet(s) received

0.00% packet loss

round-trip min/avg/max = 69/90/105 ms

Configuring nested VPN

Network requirements

The service provider provides nested VPN services for users, as shown in

Figure 81

, where:

PE 1 and PE 2 are PE devices on the service provider backbone. Both of them support the nested
VPN function.

CE 1 and CE 2 are connected to the service provider backbone. Both of them support VPNv4

routes.

PE 3 and PE 4 are PE devices of the customer VPN. Both of them support MPLS L3VPN.

CE 3 through CE 6 are CE devices of sub-VPNs for the customer VPN.

The key of nested VPN configuration is to understand the processing of routes of sub-VPNs on the service

provider PEs, which is described as follows:

When receiving a VPNv4 route from a CE (CE 1 or CE 2 in this example), a service provider PE
replaces the RD of the VPNv4 route with the RD of the MPLS VPN on the service provider network

where the CE resides, adds the export target attribute of the MPLS VPN on the service provider

network to the extended community attribute list, and then forwards the VPNv4 route as usual.

To implement exchange of sub-VPN routes between customer PEs and service provider PEs,
MP-EBGP peers should be established between service provider PEs and customer CEs.

Figure 81 Network diagram

Device Interface IP

address

Device

Interface

IP address

CE 1

Loop0

2.2.2.9/32

CE 2

Loop0

5.5.5.9/32

POS5/1/1 10.1.1.2/24

POS5/1/1 21.1.1.2/24

POS5/1/2 11.1.1.1/24

POS5/1/2 20.1.1.1/24

Advertising