GRE Tunnel with VRF Configuration

R3-PE Configuration :
ip vrf blue
rd 1:1
route-target export 301:301
route-target import 401:401
!
ip vrf green
rd 2:2
route-target export 302:302
route-target import 402:402
!
!- If the import and export lists are identical, use the both keyword to define both lists simultaneously.
!- You can add only one route target to a list at a time.
!
ip cef
!
interfave tunnel 0
ip vrf forwarding green
ip address 1.1.1.1 255.255.255.0
tunnel source Ethernet0/0
tunnel destination 10.10.10.1
tunnel vrf blue
!-Tunnel 0 is part of VRF GREEN; but it uses the tunnel destination and source addresses from the routing
table of VRF BLUE, because of this tunnel vrf blue command.
!
interface Ethernet0/0
ip vrf forwarding blue
address 20.20.20.3 255.255.255.0
!— Connection to the VRF BLUE network and the VRF GREEN network using the GRE tunnel.
!
interface Ethernet0/1
ip address 30.30.30.3 255.255.255.0
tag-switching ip (replaces IP MPLS command)
!
router bgp 1
no bgp default ipv4-unicast
bgp log-neighbor-changes (allow those routers to log their BGP neighbors resets).
neighbor 30.30.30.4 remote-as 1
!
address-family vpnv4 (This command replaces the match nlri and set nlri commands).
(Use to configure the router to exchange IPv4 addresses in VPN mode).
neighbor 30.30.30.4 activate (Specify peer or peer group with routes of current address family exchanged).
neighbor 30.30.30.4 send-community extend (Enables BGP speaker to send community attribute to peer).
exit-address-family (Exit Address Family Configuration mode and access Router Configuration mode).
!
address-family ipv4 vrf green
redistribute connected
no auto-summary
no synchronization ( Tells routers shouldn’t wait for synchronization, just go ahead use the iBGP routes).
exit-address-family
!
address-family ipv4 vrf blue
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
ip classless
ip route vrf blue 10.10.10.1 255.255.255.255 20.20.20.2
!
end

R4-PE Configuration :
ip vrf blue
rd 1:1
route-target export 401:401
route-target import 301:301
!
ip vrf green
rd 2:2
route-target export 402:402
route-target import 302:302
!
ip cef
!
interface Ethernet0/0
ip address 30.30.30.4 255.255.255.0
tag-switching ip (replaces IP MPLS command)
!
interface Ethernet 0/1
ip vrf forwarding green
ip address 100.100.100.4 255.255.255.0
!
interface Ethernet0/2
ip vrf forwarding blue
ip address 40.40.40.4 255.255.255.0
!
router bgp 1
no bgp default ipv4-unicast
bgp log-neighbor-changes
neighbor 30.30.30.3 remote-as 1
!
address-family vpnv4
neighbor 30.30.30.3 activate
neighbor 30.30.30.3 send-community extend
exit-address-family
!
address-family ipv4 vrf green
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
address-family ipv4 vrf blue
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
ip classless
!
end

R1-PE Configuration :ip cef
!
interface Tunnel 0
ip address 200.200.200.1 255.255.255.0
tunnel source Ethernet0/0
tunnel destination 20.20.20.3
!- Both the tunnel source and destination address are in the VRF BLUE,
to provide transport for the VRF GREEN network.
!
interface Ethernet0/0
description Connection to R2-CE router
ip address 10.10.10.1 255.255.255.0
ip access-group 100 in
ip access-group 100 out
!- Access-group to allow only GRE packets through theR2-CE network.
However, R1-CE networks data is in the GRE packet.
!
ip route 0.0.0.0 0.0.0.0 Tunnel0
ip route 20.20.20.3 255.255.255.255 10.10.10.2
!
access-list 100 permit gre host 10.10.10.1 host 20.20.20.3
access-list 100 permit gre host 20.20.20.3 host 10.10.10.1
!- Permits only GRE packets between the endpoints.
!
end

R2-CE#ip cef
!
interface Ethernet0/0
description Connection to R1-CE router
ip address 10.10.10.2 255.255.255.0
ip access-group 100 in
ip access-group 100 out
!
interface Ethernet1/0
ip address 20.20.20.2 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 20.20.20.3
!
access-list 100 permit gre host 10.10.10.1 host 20.20.20.3
access-list 100 permit gre host 20.20.20.3 host 10.10.10.1
!- Permits only GRE packets between the endpoints.
!
end

R5-CE#
interface Ethernet0/0
ip address 100.100.100.5 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 100.100.100.4
!
end

R6-CE
!
interface Ethernet0/0
ip address 40.40.40.6 255.255.255.0
!
ip route 0.0.0.0 0.0.0.0 40.40.40.4
!
end