Mpls L3Vpn Networking Schemes - HP HPE FlexNetwork MSR Router Series Configuration Manual

Table of Contents

Advertisement

MPLS L3VPN networking schemes

In MPLS L3VPNs, route target attributes are used to control the advertisement and reception of VPN
routes between sites. They work independently and can be configured with multiple values to
support flexible VPN access control and implement multiple types of VPN networking schemes.
Basic VPN networking scheme
In the simplest case, all users in a VPN form a closed user group. They can forward traffic to each
other but cannot communicate with any user outside the VPN.
For the basic VPN networking scheme, you must assign a route target to each VPN for identifying
the export target attribute and import target attribute of the VPN. Moreover, this route target cannot
be used by any other VPNs.
Figure 49 Network diagram for basic VPN networking scheme
VPN 1
Site 1
CE
CE
Site 2
VPN 2
As shown in
VPN 1 sites can communicate with each other, and the two VPN 2 sites can communicate with each
other. However, the VPN 1 sites cannot communicate with the VPN 2 sites.
Hub and spoke networking scheme
The hub and spoke networking scheme is suitable for a VPN where all users must communicate with
each other through an access control device.
In a hub and spoke network as shown in
On spoke PEs (PEs connected to spoke sites), set the export target to Spoke and the import
target to Hub.
On the hub PE (PE connected to the hub site), use two interfaces or subinterfaces that each
belong to a different VPN instance to connect the hub CE. One VPN instance receives routes
from spoke PEs and has the import target set to Spoke. The other VPN instance advertises
routes to spoke PEs and has the export target set to Hub.
These route targets rules produce the following results:
The hub PE can receive all VPN-IPv4 routes from spoke PEs.
All spoke PEs can receive VPN-IPv4 routes advertised by the hub PE.
The hub PE advertises the routes learned from a spoke PE to the other spoke PEs so the spoke
sites can communicate with each other through the hub site.
VPN 1:
Import: 100:1
Export: 100:1
PE
VPN 2:
Import: 200:1
Export: 200:1
Figure
49, the route target for VPN 1 is 100:1, while that for VPN 2 is 200:1. The two
VPN 2:
Import: 200:1
Export: 200:1
P
PE
VPN 1:
Import: 100:1
Export: 100:1
Figure
50, configure route targets as follows:
192
VPN 2
Site 3
CE
CE
Site 4
VPN 1

Advertisement

Table of Contents
loading

Table of Contents