No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

NE40E V800R010C10SPC500 Configuration Guide - User Access 01

This is NE40E V800R010C10SPC500 Configuration Guide - User Access
Rate and give feedback :
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Example for Configuring vCPE

Example for Configuring vCPE

This section provides an example to describe how to configure vCPE. The example provides the networking requirements, configuration roadmap, configuration procedure, and configuration files.

Networking Requirements

In this networking, user terminals connect to an L2CPE, and the BRAS connects to a NAT device. To allow the L2CPE to perform only Layer 2 functions and the user terminals to apply for IP addresses directly from carrier devices, such as the BRAS, DHCP server, and RADIUS server, configure vCPE on the BRAS for address assignment and translation.In vCPE networking, vCPE home users and the VSP(Value-Added Service Platform) are in the same Layer 2 network and a same VSI.

Figure 9-6 Networking for configuring vCPE

Configuration Roadmap

The configuration roadmap is as follows:
  1. Configure basic BAS functions.

  2. Configure a GRE tunnel.

  3. Configure a session group template.

  4. Configure the vCPE mode for the GRE tunnel interface.

  5. Configure a GRE tunnel group.

  6. Configure a user address pool.

  7. Configure a vsi.

  8. Binding the VSI to the interface is used for user access and the interface connected to the VSP

  9. Configure vCPE for the BAS interface.

  10. Configure an uplink interface.

Data Preparation

To complete the configuration, you need the following data:
  • RADIUS server group name and IP addresses and port numbers of the RADIUS authentication server and accounting server

  • Authentication template name and authentication mode

  • Accounting template name and accounting mode

  • Address pool name

  • Domain name

  • GRE tunnel group name

  • Session group template name

Procedure

  1. Configure AAA schemes.

    # Configure an authentication scheme.

    <HUAWEI> system-view
    [~HUAWEI] aaa
    [~HUAWEI-aaa] authentication-scheme auth2
    [*HUAWEI-aaa-authen-auth2] authentication-mode radius
    [*HUAWEI-aaa-authen-auth2] quit
    [*HUAWEI-aaa] commit

    # Configure an accounting scheme.

    [~HUAWEI-aaa] accounting-scheme acct2
    [*HUAWEI-aaa-accounting-acct2] accounting-mode radius
    [*HUAWEI-aaa-accounting-acct2] quit
    [*HUAWEI-aaa] quit
    [*HUAWEI] commit

  2. Configure a RADIUS server group.

    [~HUAWEI] radius-server group rd2
    [*HUAWEI-radius-rd2] radius-server authentication 192.168.8.249 1812
    [*HUAWEI-radius-rd2] radius-server accounting 192.168.8.249 1813
    [*HUAWEI-radius-rd2] radius-server shared-key-cipher %#%#nxI_5dBV`1c>#OFGFh{MNjbcXl$10Ya1/CDk48B-%#% 
    [*HUAWEI-radius-rd2] quit
    [*HUAWEI] commit

  3. Configure a DHCPv4 server group.

    [~HUAWEI] dhcp-server group group1
    [*HUAWEI-dhcp-server-group-group1] dhcp-server 10.1.1.1
    [*HUAWEI-dhcp-server-group-group1] quit
    [*HUAWEI] commit
    NOTE:

    If the DHCP reply packets from the DHCP server carry the gateway address as the destination IP address, a loopback interface must be configured, with the IP address of 192.168.1.1 and the mask of 255.255.255.255..

  4. Configure an address pool.

    [~HUAWEI] ip pool pool2 bas remote overlap
    [*HUAWEI-ip-pool-pool2] dhcp-server group group1
    [*HUAWEI-ip-pool-pool2] quit
    [*HUAWEI-ip-pool-pool2] commit

  5. Configure a session group template.

    [~HUAWEI] access session-group template tp1
    [*HUAWEI-session-group-tp1] grouping-identifier include pevlan cevlan
    [*HUAWEI-session-group-tp1] service-mode vcpe
    [*HUAWEI-session-group-tp1] quit
    [*HUAWEI-session-group-tp1] commit

  6. Configure a GRE tunnel.

    Configure a GRE tunnel interface and the vCPE mode for the tunnel interface for address translation.

    A GRE tunnel interface also needs to be configured on a CGN device for the GRE tunnel to be established.
    [~HUAWEI] interface tunnel 1
    [*HUAWEI-Tunnel1] tunnel-protocol gre
    [*HUAWEI-Tunnel1] ip address 40.1.1.2 255.255.255.0
    [*HUAWEI-Tunnel1] source 30.1.1.2
    [*HUAWEI-Tunnel1] destination 20.1.1.1
    [*HUAWEI-Tunnel1] gre mode vcpe
    [*HUAWEI-Tunnel1] quit
    [*HUAWEI] commit

  7. Configure a GRE tunnel group.

    [~HUAWEI]  gre-group group1 mode vcpe
    [*HUAWEI-gre-group-group1] interface tunnel 1 master
    [*HUAWEI-gre-group-group1]  quit
    [*HUAWEI]  commit

  8. Configure a domain.

    [~HUAWEI] aaa
    [~HUAWEI-aaa] domain isp2
    [*HUAWEI-aaa-domain-isp2] authentication-scheme auth2
    [*HUAWEI-aaa-domain-isp2] accounting-scheme acct2
    [*HUAWEI-aaa-domain-isp2] radius-server group rd2
    [*HUAWEI-aaa-domain-isp2] quit
    [*HUAWEI-aaa] quit
    [*HUAWEI] commit

  9. Creating a VSI

    [~HUAWEI] mpls lsr-id 1.1.1.1
    [*HUAWEI] mpls
    [*HUAWEI-mpls] quit
    [*HUAWEI] mpls l2vpn
    [*HUAWEI-l2vpn] commit
    [~HUAWEI-l2vpn] quit
    [*HUAWEI] vsi v1 vcpe-mode
    [*HUAWEI-vsi-v1] commit
    [~HUAWEI-vsi-v1] quit

  10. Configure a BAS interface.

    # Configure a BAS interface for vCPE family with value-added services.

    [~HUAWEI] interface GigabitEthernet1/0/0.1
    [*HUAWEI-GigabitEthernet1/0/0.1] user-vlan 10 qinq 20
    [*HUAWEI-GigabitEthernet1/0/0.1-vlan-10-10-QinQ-20-20] bas
    [*HUAWEI-GigabitEthernet1/0/0.1-bas] access-type layer2-subscriber default-domain authentication isp2
    [*HUAWEI-GigabitEthernet1/0/0.1-bas] access session-group-template tp1
    [*HUAWEI-GigabitEthernet1/0/0.1-bas] basinfo-insert vcpe version1
    [*HUAWEI-GigabitEthernet1/0/0.1-bas] quit
    [*HUAWEI-GigabitEthernet1/0/0.1] l2 binding vsi v1
    [*HUAWEI-GigabitEthernet1/0/0.1] quit
    [*HUAWEI] commit

    # Configure a BAS interface for vCPE family without value-added services.

    [~HUAWEI] interface GigabitEthernet1/0/0.2
    [*HUAWEI-GigabitEthernet1/0/0.2] user-vlan any-other
    [*HUAWEI-GigabitEthernet1/0/0.2] bas
    [*HUAWEI-GigabitEthernet1/0/0.2-bas] access-type layer2-subscriber default-domain authentication isp2
    [*HUAWEI-GigabitEthernet1/0/0.2-bas] access session-group-template tp1
    [*HUAWEI-GigabitEthernet1/0/0.2-bas] basinfo-insert vcpe version1
    [*HUAWEI-GigabitEthernet1/0/0.2-bas] quit
    [*HUAWEI-GigabitEthernet1/0/0.2] l2 binding vsi v1
    [*HUAWEI-GigabitEthernet1/0/0.2] quit
    [*HUAWEI] commit

  11. Configure an uplink interface and qinq vlan tag termination.

    [~HUAWEI] interface GigabitEthernet2/0/0.1
    [*HUAWEI-GigabitEthernet2/0/0.1] encapsulation qinq-termination
    [*HUAWEI-GigabitEthernet2/0/0.1] qinq termination l2 transparent
    [*HUAWEI-GigabitEthernet2/0/0.1] qinq termination pe-vid 10 ce-vid any 
    [*HUAWEI-GigabitEthernet2/0/0.1] l2 binding vsi v1 

  12. (Optional)Configure a diagnostic interface

    [~HUAWEI] interface GigabitEthernet2/0/1.1
    [*HUAWEI-GigabitEthernet2/0/1.1] user-vlan 10 qinq 20
    [*HUAWEI-GigabitEthernet2/0/1.1-vlan-10-10-QinQ-20-20] bas
    [*HUAWEI-GigabitEthernet2/0/1.1-bas] access-type layer2-subscriber default-domain authentication isp2
    [*HUAWEI-GigabitEthernet2/0/1.1-bas] access session-group-template tp1
    [*HUAWEI-GigabitEthernet2/0/1.1-bas] basinfo-insert vcpe version1
    [*HUAWEI-GigabitEthernet2/0/1.1-bas] trouble-shooting enable
    [*HUAWEI-GigabitEthernet2/0/1.1-bas] quit
    [*HUAWEI-GigabitEthernet2/0/1.1] l2 binding vsi v1
    [*HUAWEI-GigabitEthernet2/0/1.1] commit

Configuration Files

  • Configuration file of router

    #
     sysname HUAWEI
    
    #
    dhcp-server group group1
     dhcp-server 10.1.1.1
    #
    ip pool pool2 bas remote overlap
      dhcp-server group group1
    #
    access session-group-template tp1
     grouping-identifier include pevlan cevlan
     service-mode vcpe
    #
    aaa
     authentication-scheme auth2
     #
     accounting-scheme acct2
     #
    domain isp2
     authentication-scheme default0
     accounting-scheme default0
     ip-pool pool2
     radius-server group rd2
     #
    interface GigabitEthernet1/0/0.1
     undo shutdown
     user-vlan 10 qinq 20
     l2 binding vsi v1
     bas
     #
      access-type layer2-subscriber default-domain authentication isp2
      access session-group-template tp1
      basinfo-insert vcpe version1
     #
    interface GigabitEthernet1/0/0.2
     undo shutdown
     user-vlan any-other
     l2 binding vsi v1
     bas
     #
      access-type layer2-subscriber default-domain authentication isp2
      access session-group-template tp1
      basinfo-insert vcpe version1
     #
    interface GigabitEthernet2/0/1.1
     undo shutdown
     user-vlan 10 qinq 20
     l2 binding vsi v1
     bas
     #
      access-type layer2-subscriber default-domain authentication isp2
      access session-group-template tp1
      basinfo-insert vcpe version1
      trouble-shooting enable
    #
    interface Tunnel1
     ip address 40.1.1.1 255.255.255.0
     tunnel-protocol gre
     source 20.1.1.1
     destination 30.1.1.2
     gre mode vcpe
    #
    interface GigabitEthernet2/0/0.1
     encapsulation qinq-termination
     qinq termination l2 transparent
     qinq termination pe-vid 10 ce-vid any 
     l2 binding vsi v1
    
    #
    gre-group group1 mode vcpe
     interface tunnel1 master
    #
    interface LoopBack1
     ip address 192.168.1.1 255.255.255.255
    #
    return
Translation
Download
Updated: 2019-01-03

Document ID: EDOC1100055031

Views: 17335

Downloads: 70

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next