No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


Configuration Guide - VPN 01

NE05E and NE08E V300R003C10SPC500

This is NE05E and NE08E V300R003C10SPC500 Configuration Guide - VPN
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Configuring Hub & Spoke

Configuring Hub & Spoke

In hub and spoke networking, an access control device is specified in the VPN, and users communicate with each other through the access control device.

Usage Scenario

If it is required that an access control device be specified in the VPN and all the users access the VPN through this access control device, you can deploy the hub & spoke networking so that all the data exchanged between spoke sites flow through the hub site.

Hub & Spoke supports the following networking schemes:
  • The Hub-CE accesses the Hub-PE through dual links. On the network shown in Figure 5-5, traffic between Site 1 and Site 2 of VPN1 needs to pass through Site 3. The Hub-PE and the Hub-CE are connected through two links. The Hub-PE has two VPN instances configured, vpn_in and vpn_out, which are bound to the corresponding AC interfaces. vpn-in receives and maintains all the VPNv4 routes advertised by the Spoke-PEs. vpn-out maintains routes from the hub site and all the spoke sites and advertises them to all the Spoke-PEs.

    Figure 5-5 Hub-CE accessing Hub-PE through dual links
  • The Hub-CE accesses the Hub-PE through a single link. On the network shown in Figure 5-6, traffic between Site 1 and Site 2 of VPN1 needs to pass through Site 3. The Hub-PE and the Hub-CE are connected through a single link. The Hub-PE has only one VPN instance configured, vpnhub, which is bound to the AC interface connecting to the Hub-CE. Additionally, the apply-label per-route pop-go command needs to be run in the VPN instance view to configure the Hub-PE to directly search the label mapping table for the outbound interface for forwarding after receiving data packets from the Spoke-PEs.

    Figure 5-6 Hub-CE accessing Hub-PE through a single link

Pre-configuration Tasks

Before configuring hub & spoke, complete the following tasks:

  • Configure an IGP on the MPLS backbone network to ensure IP connectivity on the backbone network.

  • Configure MPLS both globally and per interface on each node of the backbone network and establish an LDP LSP between PEs.

  • Configure an IP address for the interface connecting a CE to a PE.

Configuration Procedures

Figure 5-7 Flowchart for configuring hub & spoke
Updated: 2019-01-14

Document ID: EDOC1100058925

Views: 36846

Downloads: 61

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Previous Next