配置CCC VC和LDP VC互保护示例(非双归2PE场景)
部署CCC VC和LDP VC,在PE设备上使用主从模式,指定主备,可以实现CCC VC和LDP VC互保护。
组网需求
如图9-17所示,CE3通过PE1访问CE1,当CE1侧AC故障或者CE1故障时候,CE3无法通过认证。解决方法是部署CE2与CE1形成保护关系。正常情况下,CE3通过CE1进行认证,当CE1侧AC故障或者CE1故障后,CE3切换到CE2进行认证,保证通过CE3接入的用户业务正常。
操作步骤
- 配置CE
# 配置CE1。
<HUAWEI> system-view
[~HUAWEI] sysname CE1
[*CE1] interface gigabitethernet1/0/0.100
[*CE1-GigabitEthernet1/0/0.100] undo shutdown
[*CE1-GigabitEthernet1/0/0.100] vlan-type dot1q 100
[*CE1-GigabitEthernet1/0/0.100] ip address 10.1.1.1 255.255.255.0
[*CE1-GigabitEthernet1/0/0.100] quit
[*CE1] commit
# 配置CE2。
<HUAWEI> system-view
[~HUAWEI] sysname CE2
[*CE2] interface gigabitethernet1/0/0.100
[*CE2-GigabitEthernet1/0/0.100] undo shutdown
[*CE2-GigabitEthernet1/0/0.100] vlan-type dot1q 100
[*CE2-GigabitEthernet1/0/0.100] ip address 10.1.1.2 255.255.255.0
[*CE2-GigabitEthernet1/0/0.100] quit
[*CE2] commit
# 配置CE3。
<HUAWEI> system-view
[~HUAWEI] sysname CE3
[*CE3] interface gigabitethernet1/0/0.100
[*CE3-GigabitEthernet1/0/0.100] undo shutdown
[*CE3-GigabitEthernet1/0/0.100] vlan-type dot1q 100
[*CE3-GigabitEthernet1/0/0.100] ip address 10.1.1.3 255.255.255.0
[*CE3-GigabitEthernet1/0/0.100] quit
[*CE3] commit
- 配置骨干网设备各接口的IP地址
# 配置PE1。
<HUAWEI> system-view
[~HUAWEI] sysname PE1
[*PE1] interface loopback 1
[*PE1-LoopBack1] ip address 1.1.1.1 32
[*PE1-LoopBack1] quit
[*PE1] interface gigabitethernet1/0/0
[*PE1-GigabitEthernet1/0/0] undo shutdown
[*PE1-GigabitEthernet1/0/0] ip address 192.168.1.1 24
[*PE1-GigabitEthernet1/0/0] quit
[*PE1] commit
# 配置PE2。
<HUAWEI> system-view
[~HUAWEI] sysname PE2
[*PE2] interface loopback 1
[*PE2-LoopBack1] ip address 2.2.2.2 32
[*PE2-LoopBack1] quit
[*PE2] interface gigabitethernet1/0/0
[*PE2-GigabitEthernet1/0/0] undo shutdown
[*PE2-GigabitEthernet1/0/0] ip address 192.168.1.2 24
[*PE2-GigabitEthernet1/0/0] quit
[*PE2] commit
- 使能MPLS,建立LSP隧道。
# 配置PE1。
[~PE1] mpls lsr-id 1.1.1.1
[*PE1] mpls
[*PE1-mpls] quit
[*PE1] mpls ldp
[*PE1-mpls-ldp] quit
[*PE1] interface gigabitethernet1/0/0
[*PE1-GigabitEthernet1/0/0] mpls
[*PE1-GigabitEthernet1/0/0] mpls ldp
[*PE1-GigabitEthernet1/0/0] quit
[*PE1] commit
# 配置PE2。
[~PE2] mpls lsr-id 2.2.2.2
[*PE2] mpls
[*PE2-mpls] quit
[*PE2] mpls ldp
[*PE2-mpls-ldp] quit
[*PE2] interface gigabitethernet1/0/0
[*PE2-GigabitEthernet1/0/0] mpls
[*PE2-GigabitEthernet1/0/0] mpls ldp
[*PE2-GigabitEthernet1/0/0] quit
[*PE2] commit
- 配置IGP,本示例使用OSPF
# 配置PE1。
[~PE1] ospf 1
[*PE1-ospf-1] area 0.0.0.0
[*PE1-ospf-1-area-0.0.0.0] network 1.1.1.1 0.0.0.0
[*PE1-ospf-1-area-0.0.0.0] network 192.168.1.1 0.0.0.255
[*PE1-ospf-1-area-0.0.0.0] quit
[*PE1-ospf-1] quit
[*PE1] commit
# 配置PE2。
[~PE2] ospf 1
[*PE2-ospf-1] area 0.0.0.0
[*PE2-ospf-1-area-0.0.0.0] network 2.2.2.2 0.0.0.0
[*PE2-ospf-1-area-0.0.0.0] network 192.168.1.2 0.0.0.255
[*PE2-ospf-1-area-0.0.0.0] quit
[*PE2-ospf-1] quit
[*PE2] commit
- 在PE上使能MPLS L2VPN
# 配置PE1。
[~PE1] mpls l2vpn
[*PE1-l2vpn] quit
[*PE1] commit
# 配置PE2。
[~PE2] mpls l2vpn
[*PE2-l2vpn] quit
[*PE2] commit
- 在PE上创建CCC VC和LDP VC业务
# 配置PE1。
[~PE1] interface gigabitethernet1/0/2.100
[*PE1-GigabitEthernet1/0/2.100] vlan-type dot1q 100
[*PE1-GigabitEthernet1/0/2.100] mpls ccc out-interface gigabitethernet1/0/1.100
[*PE1-GigabitEthernet1/0/2.100] mpls l2vc 2.2.2.2 100 secondary
[*PE1-GigabitEthernet1/0/2.100] mpls l2vpn redundancy master
[*PE1-GigabitEthernet1/0/2] quit
[*PE1] interface gigabitethernet 1/0/1.100
[*PE1-GigabitEthernet1/0/1.100] vlan-type dot1q 100
[*PE1-GigabitEthernet1/0/1.100] mpls ccc out-interface gigabitethernet1/0/2.100
[*PE1-GigabitEthernet1/0/1] quit
[*PE1] commit
# 配置PE2。
[~PE2] interface gigabitethernet 1/0/1.100
[*PE2-GigabitEthernet1/0/1.100] vlan-type dot1q 100
[*PE2-GigabitEthernet1/0/1.100] mpls l2vc 1.1.1.1 100
[*PE2-GigabitEthernet1/0/1] quit
[*PE2] commit
- 验证配置结果
配置完成后,在PE1上查看VPWS状态信息,可以看到建立了CCC VC和LDP VC,状态为UP。CCC VC的角色为主,LDP VC的角色为secondary。
[PE1]display mpls l2vpn vpws
Pri : Primary Sec : Secondary Byp : Bypass PWb : PW-bypass ACb : AC-bypass Access Circuit Virtual Circuit States Active Role GE1/0/2.100 GE1/0/1.100 Up Active Pri 2.2.2.2:2 Up Inactive Sec GE1/0/1.100 GE1/0/2.100 Up Active Pri
配置文件
CE1的配置文件
# sysname CE1 # interface GigabitEthernet1/0/0.100 undo shutdown ip address 10.1.1.1 255.255.255.0 vlan-type dot1q 100 # return
CE2的配置文件
# sysname CE2 # interface GigabitEthernet1/0/0.100 undo shutdown ip address 10.1.1.2 255.255.255.0 vlan-type dot1q 100 # return
CE3的配置文件
# sysname CE3 # interface GigabitEthernet1/0/0.100 undo shutdown ip address 10.1.1.3 255.255.255.0 vlan-type dot1q 100 # return
PE1的配置文件
# sysname PE1 # mpls lsr-id 1.1.1.1 # mpls mpls ldp # mpls l2vpn # interface GigabitEthernet1/0/2.100 undo shutdown vlan-type dot1q 100 mpls ccc out-interface GigabitEthernet1/0/1.100 mpls l2vc 2.2.2.2 100 secondary mpls l2vpn redundancy master # interface GigabitEthernet1/0/1.100 vlan-type dot1q 100 mpls ccc out-interface GigabitEthernet1/0/2.100 # interface GigabitEthernet1/0/0 undo shutdown ip address 192.168.1.1 255.255.255.0 mpls mpls ldp # interface LoopBack1 ip address 1.1.1.1 255.255.255.255 # ospf 1 area 0.0.0.0 network 1.1.1.1 0.0.0.0 network 192.168.1.1 0.0.0.255 # return
PE2的配置文件
# sysname PE2 # mpls lsr-id 2.2.2.2 # mpls mpls ldp # mpls l2vpn # interface GigabitEthernet1/0/0 undo shutdown ip address 192.168.1.2 255.255.255.0 mpls mpls ldp # #interface GigabitEthernet1/0/1.100 undo shutdown vlan-type dot1q 100 mpls l2vc 1.1.1.1 100 # interface LoopBack1 ip address 2.2.2.2 255.255.255.255 # ospf 1 area 0.0.0.0 network 2.2.2.2 0.0.0.0 network 192.168.1.2 0.0.0.255 # # return