HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 3 - IP Routing Confi - Page 289

Configuring IBGP beween MCE and VPN site

Page 289 highlights

Configuring IBGP beween MCE and VPN site If IBGP is used for exchanging routing information between an MCE and VPN sites, you must configure a BGP peer for each VPN instance respectively, and redistribute the IGP routes of each VPN instance on the VPN sites. 1. Configure the MCE: Step Command Remarks 1. Enter system view. system-view N/A 2. Enter BGP view. bgp as-number N/A 3. Enter BGP-VPN instance view. ipv4-family vpn-instance vpn-instance-name N/A 4. Configure an IBGP peer. peer { group-name | ip-address } as-number as-number N/A 5. Configure the system to be the RR and specify the peer as the client of the RR. peer { group-name | ip-address } reflect-client Optional. By default, no RR or RR client is configured. 6. Redistribute remote site routes advertised by the PE. import-route protocol [ process-id | all-processes ] [ med med-value | route-policy route-policy-name ] * By default, no route redistribution is configured. 7. Configure a filtering policy to filter the routes to be advertised. filter-policy { acl-number | ip-prefix ip-prefix-name } export [ direct | ospf process-id | rip process-id | static ] Optional. By default, BGP does not filter the routes to be advertised. 8. Configure a filtering policy to filter-policy { acl-number | filter the received routes. ip-prefix ip-prefix-name } import Optional. By default, BGP does not filter the received routes. NOTE: After you configure a VPN site as an IBGP peer of the MCE, the MCE does not advertise the BGP routes learned from the VPN site to other IBGP peers, including VPNv4 peers. Only when you configure the VPN site as a client of the RR (the MCE), does the MCE advertise routes learned from it to other IBGP peers. 2. Configure a VPN site: Step 1. Enter system view. 2. Enter BGP view. 3. Configure the MCE as the IBGP peer. 4. Redistribute the IGP routes of the VPN. Command Remarks system-view N/A bgp as-number N/A peer { group-name | ip-address } as-number as-number N/A import-route protocol [ process-id ] [ med med-value | route-policy route-policy-name ] * Optional. A VPN site must advertise the VPN network addresses it can reach to the connected MCE. 279

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312

279
Configuring IBGP beween MCE and VPN site
If IBGP is used for exchanging routing information between an MCE and VPN sites, you must configure
a BGP peer for each VPN instance respectively, and redistribute the IGP routes of each VPN instance on
the VPN sites.
1.
Configure the MCE:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter BGP view.
bgp
as-number
N/A
3.
Enter BGP-VPN instance view.
ipv4-family vpn-instance
vpn-instance-name
N/A
4.
Configure an IBGP peer.
peer
{
group-name
|
ip-address
}
as-number
as-number
N/A
5.
Configure the system to be the
RR and specify the peer as the
client of the RR.
peer
{
group-name
|
ip-address
}
reflect-client
Optional.
By default, no RR or RR client is
configured.
6.
Redistribute remote site routes
advertised by the PE.
import-route
protocol
[
process-id
|
all-processes
] [
med
med-value
|
route-policy
route-policy-name
] *
By default, no route redistribution
is configured.
7.
Configure a filtering policy to
filter the routes to be
advertised.
filter-policy
{
acl-number
|
ip-prefix
ip-prefix-name
}
export
[
direct
|
ospf
process-id
|
rip
process-id
|
static
]
Optional.
By default, BGP does not filter the
routes to be advertised.
8.
Configure a filtering policy to
filter the received routes.
filter-policy
{
acl-number
|
ip-prefix
ip-prefix-name
}
import
Optional.
By default, BGP does not filter the
received routes.
NOTE:
After you configure a VPN site as an IBGP peer of the MCE, the MCE does not advertise the BGP routes
learned from the VPN site to other IBGP peers, including VPNv4 peers. Only when you configure the VPN
site as a client of the RR (the MCE), does the MCE advertise routes learned from it to other IBGP peers.
2.
Configure a VPN site:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter BGP view.
bgp
as-number
N/A
3.
Configure the MCE as the
IBGP peer.
peer
{
group-name
|
ip-address
}
as-number
as-number
N/A
4.
Redistribute the IGP routes of
the VPN.
import-route
protocol
[
process-id
]
[
med
med-value
|
route-policy
route-policy-name
] *
Optional.
A VPN site must advertise the VPN
network addresses it can reach to
the connected MCE.