#
ipv4-family unicast
undo synchronization
peer 2.2.2.9 enable
#
ipv4-family vpnv4
policy vpn-target
peer 2.2.2.9 enable
#
ipv4-family vpn-instance vpna
peer 10.2.1.1 as-number 65420
import-route direct
#
ospf 1
area 0.0.0.0
network 3.3.3.9 0.0.0.0
network 172.2.1.0 0.0.0.255
#
return
l Configuration file of CE2
#
sysname CE2
#
interface GigabitEthernet1/0/0
ip address 10.2.1.1 255.255.255.0
#
bgp 65420
peer 10.2.1.2 as-number 100
#
ipv4-family unicast
undo synchronization
import-route direct
peer 10.2.1.2 enable
#
return
3.18.9 Example for Configuring Multi-VPN-Instance CE
By using OSPF multi-instance on CEs, you can implement service isolation on the LAN.
Networking Requirements
As shown in Figure 3-10, the networking requirements are as follows:
l CE1 and CE2 belong to the same LAN, and MCE, CE3, and CE4 belong to the same LAN.
l An MCE is used by the client to exchange routes between multiple VPN instances.
l CE1 and CE3 belong to vpna, while CE2 and CE4 belong to vpnb.
l vpna and vpnb use different VPN targets.
The users residing in the same VPN can mutually access, but those in different VPNs cannot
mutually access. So, the services of different VPNs in LAN are isolated from each other.
Huawei AR1200 Series Enterprise Routers
Configuration Guide - VPN 3 BGP MPLS IP VPN Configuration
Issue 01 (2012-04-20) Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
216