CISCO MPLS VPN – VRF

PE Routers
(PE1)
PE Router configuration is the beefiest part of the lab.
hostname PE_1
!
ip vrf ClientA
rd 999:1
route-target export 64999:1
route-target import 64999:1
!
ip vrf ClientB
rd 999:2
route-target export 64999:2
route-target import 64999:2
!
!
interface Loopback0
ip address 172.16.1.1 255.255.255.255
!
interface FastEthernet0/0
ip vrf forwarding ClientA
ip address 10.1.1.2 255.255.255.252
speed 100
full-duplex
!
interface FastEthernet0/1
ip vrf forwarding ClientB
ip address 10.1.1.2 255.255.255.252
duplex auto
speed auto
!
interface FastEthernet1/0
ip address 192.168.1.1 255.255.255.252
speed 100
full-duplex
mpls ip
!
router ospf 100
log-adjacency-changes
network 172.16.0.0 0.0.255.255 area 0
network 192.168.1.0 0.0.0.255 area 0
!
router rip
version 2
!
address-family ipv4 vrf ClientB
redistribute bgp 64999 metric 1
network 10.0.0.0
no auto-summary
version 2
exit-address-family
!
address-family ipv4 vrf ClientA
redistribute bgp 64999 metric 1
network 10.0.0.0
no auto-summary
version 2
exit-address-family
!
router bgp 64999
no bgp default ipv4-unicast
bgp log-neighbor-changes
neighbor 172.16.1.3 remote-as 64999
neighbor 172.16.1.3 update-source Loopback0
!
address-family vpnv4
neighbor 172.16.1.3 activate
neighbor 172.16.1.3 send-community extended
neighbor 172.16.1.3 next-hop-self
exit-address-family
!
address-family ipv4 vrf ClientB
redistribute rip metric 1
no synchronization
exit-address-family
!
address-family ipv4 vrf ClientA
redistribute rip metric 1
no synchronization
exit-address-family
!
!
PE2
hostname PE_2
!
ip vrf ClientA
rd 999:1
route-target export 64999:1
route-target import 64999:1
!
ip vrf ClientB
rd 999:2
route-target export 64999:2
route-target import 64999:2
!
!
interface Loopback0
ip address 172.16.1.3 255.255.255.255
!
interface FastEthernet0/0
ip vrf forwarding ClientA
ip address 10.1.1.6 255.255.255.252
speed 100
full-duplex
!
interface FastEthernet0/1
ip vrf forwarding ClientB
ip address 10.1.1.6 255.255.255.252
speed 100
full-duplex
!
interface FastEthernet1/0
ip address 192.168.1.5 255.255.255.252
speed 100
full-duplex
mpls ip
!
!
router ospf 100
log-adjacency-changes
network 172.16.0.0 0.0.255.255 area 0
network 192.168.1.0 0.0.0.255 area 0
!
interface Loopback0
ip address 172.16.1.3 255.255.255.255
!
interface FastEthernet0/0
ip vrf forwarding ClientA
ip address 10.1.1.6 255.255.255.252
speed 100
full-duplex
!
interface FastEthernet0/1
ip vrf forwarding ClientB
ip address 10.1.1.6 255.255.255.252
speed 100
full-duplex
!
interface FastEthernet1/0
ip address 192.168.1.5 255.255.255.252
speed 100
full-duplex
mpls ip
!
router ospf 100
log-adjacency-changes
network 172.16.0.0 0.0.255.255 area 0
network 192.168.1.0 0.0.0.255 area 0
!
router rip
version 2
!
address-family ipv4 vrf ClientB
redistribute bgp 64999 metric 1
network 10.0.0.0
no auto-summary
version 2
exit-address-family
!
address-family ipv4 vrf ClientA
redistribute bgp 64999 metric 1
network 10.0.0.0
no auto-summary
version 2
exit-address-family
!
router bgp 64999
no bgp default ipv4-unicast
bgp log-neighbor-changes
neighbor 172.16.1.1 remote-as 64999
neighbor 172.16.1.1 update-source Loopback0
!
address-family vpnv4
neighbor 172.16.1.1 activate
neighbor 172.16.1.1 send-community extended
neighbor 172.16.1.1 next-hop-self
exit-address-family
!
address-family ipv4 vrf ClientB
redistribute rip metric 1
no synchronization
exit-address-family
!
address-family ipv4 vrf ClientA
redistribute rip metric 1
no synchronization
exit-address-family
!
!
P Router (MPLS)
The P router is a very simple configuration, not caring about VRFs or anything, only making label
switching decisions based on the top label.
ip cef
mpls label protocol ldp
!
!
interface Loopback0
ip address 172.16.1.2 255.255.255.255
!
interface FastEthernet0/0
ip address 192.168.1.2 255.255.255.252
speed 100
full-duplex
mpls ip
!
interface FastEthernet0/1
ip address 192.168.1.6 255.255.255.252
speed 100
full-duplex
mpls ip
!
router ospf 100
log-adjacency-changes
network 172.16.0.0 0.0.255.255 area 0
network 192.168.1.0 0.0.0.255 area 0
!
!
CE Routers
CE routers are a very basic config. They are completely unaware that MPLS/VPN is going on.
All they really know is that their full mesh WAN is costing them a whole lot less then it used to 😉
I am only including the configuration for one CE router in an effort to keep this short.
All four are configured in a similar way.
hostname CE_A1
!
interface FastEthernet0/0
ip address 10.1.1.1 255.255.255.252
speed 100
full-duplex
!
router rip
version 2
network 10.0.0.0
no auto-summary
!
!
hostname CE_A2
!
interface FastEthernet0/0
ip address 10.1.1.5 255.255.255.252
speed 100
full-duplex
!
router rip
version 2
network 10.0.0.0
no auto-summary
!
!
hostname CE_B1
!
interface FastEthernet0/0
ip address 10.1.1.1 255.255.255.252
speed 100
full-duplex
!
router rip
version 2
network 10.0.0.0
no auto-summary
!
!
hostname CE_B2
!
interface FastEthernet0/0
ip address 10.1.1.5 255.255.255.252
speed 100
full-duplex
!
router rip
version 2
network 10.0.0.0
no auto-summary
!
!