实践gobgp作为mpls l3vpn的vpnv4反射器

Linux-PE-RR

os:ubuntu-17.10

zebra的ospfd用于Lo(5.5.5.5)和其他PE的Lo可达

gobgp用于Lo和其他PE的Lo建立MP-IBGP邻居


root@ubuntu:~# cat /etc/apt/sources.list

deb http://mirrors.163.com/ubuntu/ artful main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-security main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-updates main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-proposed main restricted universe multiverse

deb http://mirrors.163.com/ubuntu/ artful-backports main restricted universe multiverse


root@ubuntu:~# apt update

root@ubuntu:~# apt install gobgpd  -y

root@ubuntu:~# apt install quagga -y

root@ubuntu:~# touch /etc/quagga/ospfd.conf

root@ubuntu:~# touch /etc/quagga/zebra.conf

root@ubuntu:~# chown quagga.quagga /etc/quagga/*.conf

root@ubuntu:~# cat /etc/quagga/ospfd.conf

router ospf

ospf router-id 5.5.5.5

network 5.5.5.5/32 area 0.0.0.0

network 10.0.5.0/24 area 0.0.0.0


root@ubuntu:~# ip add li ens4 | grep inet

inet 10.0.5.1/24 scope global ens4

root@ubuntu:~# ip add li lo | grep inet

inet 127.0.0.1/8 scope host lo

inet 5.5.5.5/32 scope global lo


编辑gobgpd.conf配置文件

root@ubuntu:~# cat /etc/gobgp/gobgpd.conf

[global]

[global.config]

as = 65000

router-id = "5.5.5.5"

[[neighbors]]

[neighbors.config]

neighbor-address = "1.1.1.1"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

[[neighbors]]

[neighbors.config]

neighbor-address = "2.2.2.2"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

[[neighbors]]

[neighbors.config]

neighbor-address = "3.3.3.3"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

[[neighbors]]

[neighbors.config]

neighbor-address = "4.4.4.4"

peer-as = 65000

[neighbors.route-reflector.config]

route-reflector-client = true

route-reflector-cluster-id = "5.5.5.5"

[[neighbors.afi-safis]]

[neighbors.afi-safis.config]

afi-safi-name = "l3vpn-ipv4-unicast"

启动ospfd和gobgpd

root@ubuntu:~# gobgpd -f /etc/gobgp/gobgpd.conf &

root@ubuntu:~# systemctl start ospfd

root@ubuntu:~# systemctl  start zebra


#########VMX-P的配置###############

set version 14.1R4.8

set system root-authentication encrypted-password "$1$gQsE5emV$YKl79HDHgraX5dofhGZj8."

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.1.254/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 10.0.2.254/24

set interfaces ge-0/0/1 unit 0 family mpls

set interfaces ge-0/0/2 unit 0 family inet address 10.0.3.254/24

set interfaces ge-0/0/2 unit 0 family mpls

set interfaces ge-0/0/3 unit 0 family inet address 10.0.4.254/24

set interfaces ge-0/0/3 unit 0 family mpls

set interfaces ge-0/0/4 unit 0 family inet address 10.0.5.254/24

set interfaces ge-0/0/4 unit 0 family mpls

set interfaces lo0 unit 0 family inet address 10.10.10.10/32

set routing-options router-id 10.10.10.10

set protocols mpls interface ge-0/0/0.0

set protocols mpls interface ge-0/0/1.0

set protocols mpls interface ge-0/0/2.0

set protocols mpls interface ge-0/0/3.0

set protocols mpls interface ge-0/0/4.0

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface ge-0/0/1.0

set protocols ospf area 0.0.0.0 interface ge-0/0/2.0

set protocols ospf area 0.0.0.0 interface ge-0/0/3.0

set protocols ospf area 0.0.0.0 interface ge-0/0/4.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set protocols ldp interface ge-0/0/1.0

set protocols ldp interface ge-0/0/2.0

set protocols ldp interface ge-0/0/3.0

set protocols ldp interface ge-0/0/4.0

#######VMX-PE1的配置######################

set version 14.1R4.8

set system host-name VMX-PE1

set system root-authentication encrypted-password "$1$PDALzLQM$7sa4xnKY/CG9Z4gGDRooI0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.1.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.1.254/24

set interfaces lo0 unit 0 family inet address 1.1.1.1/32

set routing-options router-id 1.1.1.1

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 1.1.1.1

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 1.1.1.1:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.1.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.1.1 peer-as 65001

########VMX-PE2的配置#####################

set version 14.1R4.8

set system host-name VMX-PE2

set system root-authentication encrypted-password "$1$CT8eKT4/$6KoQkGBVblWjaXduDGCTO0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.2.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.2.254/24

set interfaces lo0 unit 0 family inet address 2.2.2.2/32

set routing-options router-id 2.2.2.2

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 2.2.2.2

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 2.2.2.2:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.2.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.2.1 peer-as 65002

##############VMX-PE3的配置################

set version 14.1R4.8

set system host-name VMX-PE3

set system root-authentication encrypted-password "$1$ci.Wd2VV$Mi.R0/P7Sa3JcJkrm2Vuv0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.3.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.3.254/24

set interfaces lo0 unit 0 family inet address 3.3.3.3/32

set routing-options router-id 3.3.3.3

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 3.3.3.3

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 3.3.3.3:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.3.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.3.1 peer-as 65003

#############VMX-PE4的配置#################

set version 14.1R4.8

set system host-name VMX-PE4

set system root-authentication encrypted-password "$1$TuNrotp/$/3NLB7HAPp2qTksnJAHTy0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/0 unit 0 family inet address 10.0.4.1/24

set interfaces ge-0/0/0 unit 0 family mpls

set interfaces ge-0/0/1 unit 0 family inet address 192.168.4.254/24

set interfaces lo0 unit 0 family inet address 4.4.4.4/32

set routing-options router-id 4.4.4.4

set routing-options autonomous-system 65000

set protocols mpls interface ge-0/0/0.0

set protocols bgp group PE-PE type internal

set protocols bgp group PE-PE local-address 4.4.4.4

set protocols bgp group PE-PE family inet-vpn unicast

set protocols bgp group PE-PE neighbor 5.5.5.5

set protocols ospf area 0.0.0.0 interface ge-0/0/0.0

set protocols ospf area 0.0.0.0 interface lo0.0 passive

set protocols ldp interface ge-0/0/0.0

set routing-instances VRF1 instance-type vrf

set routing-instances VRF1 interface ge-0/0/1.0

set routing-instances VRF1 route-distinguisher 4.4.4.4:1

set routing-instances VRF1 vrf-target target:65000:1

set routing-instances VRF1 protocols bgp group PE-CE type external

set routing-instances VRF1 protocols bgp group PE-CE local-address 192.168.4.254

set routing-instances VRF1 protocols bgp group PE-CE neighbor 192.168.4.1 peer-as 65004

###########VMX-CE1####################

set version 14.1R4.8

set system host-name VMX-CE1

set system root-authentication encrypted-password "$1$1006jy5.$8/66Q0JBoXlGtAktmGNka1"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.1.1/24

set interfaces lo0 unit 0 family inet address 11.11.11.11/32

set routing-options router-id 11.11.11.11

set routing-options autonomous-system 65001

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.1.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.1.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

##########VMX-CE2###########################

set version 14.1R4.8

set system host-name VMX-CE2

set system root-authentication encrypted-password "$1$0qSqG.Fl$qU3qxR7eosVTyj65jNxVV1"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.2.1/24

set interfaces lo0 unit 0 family inet address 22.22.22.22/32

set routing-options router-id 22.22.22.22

set routing-options autonomous-system 65002

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.2.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.2.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

###########VMX-CE3#################

set version 14.1R4.8

set system host-name VMX-CE3

set system root-authentication encrypted-password "$1$X1Ybl/Jd$eC4M5uKC6Num6F2vb/EP1."

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.3.1/24

set interfaces lo0 unit 0 family inet address 33.33.33.33/32

set routing-options router-id 33.33.33.33

set routing-options autonomous-system 65003

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.3.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.3.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

################VMX-CE4############################

set version 14.1R4.8

set system host-name VMX-CE4

set system root-authentication encrypted-password "$1$l/p/KeA6$CQ6qWqkWaM7P2MbUGN4RI0"

set system syslog user * any emergency

set system syslog file messages any notice

set system syslog file messages authorization info

set system syslog file interactive-commands interactive-commands any

set interfaces ge-0/0/1 unit 0 family inet address 192.168.4.1/24

set interfaces lo0 unit 0 family inet address 44.44.44.44/32

set routing-options router-id 44.44.44.44

set routing-options autonomous-system 65004

set protocols bgp group CE-PE type external

set protocols bgp group CE-PE local-address 192.168.4.1

set protocols bgp group CE-PE export POLICY_EXPORT_LO0

set protocols bgp group CE-PE neighbor 192.168.4.254 peer-as 65000

set policy-options policy-statement POLICY_EXPORT_LO0 from family inet

set policy-options policy-statement POLICY_EXPORT_LO0 from protocol direct

set policy-options policy-statement POLICY_EXPORT_LO0 from route-filter 0.0.0.0/0 prefix-length-range /32-/32

set policy-options policy-statement POLICY_EXPORT_LO0 then accept

验证

root@VMX-CE1> show bgp neighbor 192.168.1.254 | match State

Type: External    State: Established    Flags:

Last State: OpenConfirm  Last Event: RecvKeepAlive

RIB State: BGP restart is complete

Send state: in sync

学习到了22.22.22.22,33.33.33.33,44.44.44.44路由

root@VMX-CE1> show route protocol bgp

inet.0: 9 destinations, 9 routes (9 active, 0 holddown, 0 hidden)

+ = Active Route, - = Last Active, * = Both

22.22.22.22/32    *[BGP/170] 00:20:12, localpref 100

AS path: 65000 65002 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

33.33.33.33/32    *[BGP/170] 00:23:56, localpref 100

AS path: 65000 65003 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

44.44.44.44/32    *[BGP/170] 00:23:43, localpref 100

AS path: 65000 65004 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

192.168.2.0/24    *[BGP/170] 00:20:12, localpref 100

AS path: 65000 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

192.168.3.0/24    *[BGP/170] 00:23:56, localpref 100

AS path: 65000 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

192.168.4.0/24    *[BGP/170] 00:23:43, localpref 100

AS path: 65000 I, validation-state: unverified

> to 192.168.1.254 via ge-0/0/1.0

root@ubuntu:~# gobgp nei

Peer      AS  Up/Down State      |#Received  Accepted

1.1.1.1 65000 00:26:29 Establ      |        2        2

2.2.2.2 65000 00:22:45 Establ      |        2        2

3.3.3.3 65000 00:26:54 Establ      |        2        2

4.4.4.4 65000 00:26:15 Establ      |        2        2

root@VMX-CE1> ping source 11.11.11.11 22.22.22.22

PING 22.22.22.22 (22.22.22.22): 56 data bytes

64 bytes from 22.22.22.22: icmp_seq=0 ttl=61 time=7.720 ms

64 bytes from 22.22.22.22: icmp_seq=1 ttl=61 time=5.759 ms

64 bytes from 22.22.22.22: icmp_seq=2 ttl=61 time=8.294 ms

双层标签截获的包


VPNV4的基础学习请参考

http://blog.sina.com.cn/s/blog_3e15c5360101bovk.html

©著作权归作者所有,转载或内容合作请联系作者
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 194,242评论 5 459
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 81,769评论 2 371
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 141,484评论 0 319
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 52,133评论 1 263
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 61,007评论 4 355
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 46,080评论 1 272
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 36,496评论 3 381
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 35,190评论 0 253
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 39,464评论 1 290
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 34,549评论 2 309
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 36,330评论 1 326
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 32,205评论 3 312
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 37,567评论 3 298
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 28,889评论 0 17
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 30,160评论 1 250
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 41,475评论 2 341
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 40,650评论 2 335

推荐阅读更多精彩内容