HP 6125XLG R2306-HP 6125XLG Blade Switch MCE Configuration Guide - Page 12

Configuring IS-IS between an MCE and a VPN site

Page 12 highlights

Step Command Remarks The defaults are as follows: 4. (Optional.) Configure the type codes of OSPF extended community attributes. ext-community-type { domain-id type-code1 | router-id type-code2 | route-type type-code3 } • 0x0005 for Domain ID. • 0x0107 for Router ID. • 0x0306 for Route Type. 5. (Optional.) Configure the external route tag for imported VPN routes. route-tag tag-value By default, no route tag is configured. In some networks, a VPN might be connected to multiple MCEs. When one MCE advertise the routes learned from BGP to the VPN, the other MCEs might learn the routes, resulting in routing loops. To avoid such routing loops, you can configure route tags for VPN instances on an MCE. H3C recommends configuring the same route tag for the same VPN on the MCEs. import-route protocol [ process-id 6. Redistribute remote site routes | allow-ibgp ] [ cost cost | type advertised by the PE. type | tag tag | route-policy route-policy-name ] * By default, OSPF does not redistribute routes from any other routing protocol. 7. (Optional.) Configure OSPF to redistribute the default route. default-route-advertise summary cost cost By default, OSPF does not redistribute the default route. This command redistributes the default route in a Type-3 LSA. The MCE advertises the default route to the site. 8. Create an OSPF area and enter OSPF area view. area area-id By default, no OSPF area is created. 9. Enable OSPF on the interface attached to the specified network in the area. network ip-address wildcard-mask By default, an interface does not run OSPF. Configuring IS-IS between an MCE and a VPN site An IS-IS process belongs to the public network or a single VPN instance. If you create an IS-IS process without binding it to a VPN instance, the process belongs to the public network. Binding IS-IS processes to VPN instances can isolate routes of different VPNs. To configure IS-IS between an MCE and a VPN site: Step 1. Enter system view. 2. Create an IS-IS process for a VPN instance and enter IS-IS view. 3. Configure a network entity title. Command system-view isis [ process-id ] vpn-instance vpn-instance-name network-entity net 9 Remarks N/A Perform this configuration on the MCE. On the VPN site, configure a normal IS-IS process. By default, no NET is configured.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52

9
Step
Command
Remarks
4.
(Optional.) Configure the type
codes of OSPF extended
community attributes.
ext-community-type
{
domain-id
type-code1
|
router-id
type-code2
|
route-type
type-code3
}
The defaults are as follows:
0x0005 for Domain ID.
0x0107 for Router ID.
0x0306 for Route Type.
5.
(Optional.) Configure the
external route tag for
imported VPN routes.
route-tag
tag-value
By default, no route tag is
configured.
In some networks, a VPN might be
connected to multiple MCEs.
When one MCE advertise the
routes learned from BGP to the
VPN, the other MCEs might learn
the routes, resulting in routing
loops. To avoid such routing loops,
you can configure route tags for
VPN instances on an MCE. H3C
recommends configuring the same
route tag for the same VPN on the
MCEs.
6.
Redistribute remote site routes
advertised by the PE.
import-route
protocol
[
process-id
|
allow-ibgp
] [
cost
cost
|
type
type
|
tag
tag
|
route-policy
route-policy-name
] *
By default, OSPF does not
redistribute routes from any other
routing protocol.
7.
(Optional.) Configure OSPF
to redistribute the default
route.
default-route-advertise summary
cost
cost
By default, OSPF does not
redistribute the default route.
This command redistributes the
default route in a Type-3 LSA. The
MCE advertises the default route to
the site.
8.
Create an OSPF area and
enter OSPF area view.
area
area-id
By default, no OSPF area is
created.
9.
Enable OSPF on the interface
attached to the specified
network in the area.
network
ip-address wildcard-mask
By default, an interface does not
run OSPF.
Configuring IS-IS between an MCE and a VPN site
An IS-IS process belongs to the public network or a single VPN instance. If you create an IS-IS process
without binding it to a VPN instance, the process belongs to the public network.
Binding IS-IS processes to VPN instances can isolate routes of different VPNs.
To configure IS-IS between an MCE and a VPN site:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an IS-IS process for a
VPN instance and enter IS-IS
view.
isis
[
process-id
]
vpn-instance
vpn-instance-name
Perform this configuration on the
MCE. On the VPN site, configure a
normal IS-IS process.
3.
Configure a network entity
title.
network-entity
net
By default, no NET is configured.