交换机如何利用VRF做旁挂引流
如图所示,要求PC1和PC2访问PC3的流量按红色路线走!
SW1的配置:
#
vlan batch 2 to 3 100 200
#
stp disable
#
ip vpn-instance 1
ipv4-family
route-distinguisher 1:1
#
ip vpn-instance 2
ipv4-family
route-distinguisher 2:1
#
ip vpn-instance 3
ipv4-family
route-distinguisher 3:1
#
interface Vlanif1
ip binding vpn-instance 1
ip address 1.1.1.1 255.255.255.0
#
interface Vlanif2
ip binding vpn-instance 2
ip address 2.2.2.1 255.255.255.0
#
interface Vlanif3
ip binding vpn-instance 3
ip address 3.3.3.1 255.255.255.0
#
interface Vlanif100
ip address 100.1.1.1 255.255.255.0
#
interface Vlanif200
ip binding vpn-instance 3
ip address 200.1.1.1 255.255.255.0
#
interface GigabitEthernet0/0/1
port link-type access
#
interface GigabitEthernet0/0/2
port link-type access
port default vlan 2
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 3
#
interface GigabitEthernet0/0/23
port link-type access
port default vlan 200
stp disable
#
interface GigabitEthernet0/0/24
port link-type access
port default vlan 100
stp disable
#
ip route-static 0.0.0.0 0.0.0.0 100.1.1.2
ip route-static 1.1.1.0 255.255.255.0 vpn-instance 1 1.1.1.2
ip route-static 2.2.2.0 255.255.255.0 vpn-instance 2 2.2.2.2
ip route-static vpn-instance 1 4.4.4.0 255.255.255.0 100.1.1.2 public
ip route-static vpn-instance 2 4.4.4.0 255.255.255.0 100.1.1.2 public
ip route-static vpn-instance 3 0.0.0.0 0.0.0.0 200.1.1.2
ip route-static vpn-instance 3 4.4.4.0 255.255.255.0 3.3.3.2
#
SW2的配置:
#
vlan batch 3
#
interface Vlanif3
ip address 3.3.3.2 255.255.255.0
#
interface GigabitEthernet0/0/3
port link-type access
port default vlan 3
#
interface Vlanif4
ip address 4.4.4.1 255.255.255.0
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 4
#
ip route-static 0.0.0.0 0.0.0.0 3.3.3.1
#
SW3的配置:
#
vlan batch 100 200
#
stp disable
#
interface Vlanif100
ip address 100.1.1.2 255.255.255.0
#
interface Vlanif200
ip address 200.1.1.2 255.255.255.0
#
interface GigabitEthernet0/0/23
port link-type access
port default vlan 200
stp disable
#
interface GigabitEthernet0/0/24
port link-type access
port default vlan 100
stp disable
#
ip route-static 1.1.1.0 255.255.255.0 100.1.1.1
ip route-static 2.2.2.0 255.255.255.0 100.1.1.1
ip route-static 4.4.4.0 255.255.255.0 200.1.1.1
#
实验效果:
(ICMP), press Ctrl+C to stop
1 1.1.1.1 <1 ms 31 ms 31 ms
2 100.1.1.2 63 ms 94 ms 93 ms
3 200.1.1.1 110 ms 125 ms 125 ms
4 3.3.3.2 203 ms 219 ms 203 ms
5 4.4.4.2 203 ms 219 ms 234 ms
(ICMP), press Ctrl+C to stop
1 2.2.2.1 15 ms 32 ms 31 ms
2 100.1.1.2 94 ms 78 ms 94 ms
3 200.1.1.1 156 ms 140 ms 125 ms
4 3.3.3.2 157 ms 109 ms 188 ms
5 4.4.4.2 234 ms 250 ms 234 ms
PC 3>tracert 1.1.1.2
(ICMP), press Ctrl+C to stop
1 4.4.4.1 16 ms 16 ms 31 ms
2 3.3.3.1 94 ms 62 ms 94 ms
3 200.1.1.2 140 ms 141 ms 156 ms
4 100.1.1.1 203 ms 219 ms 203 ms
5 1.1.1.2 219 ms 172 ms 250 ms
(ICMP), press Ctrl+C to stop
1 4.4.4.1 47 ms 31 ms 32 ms
2 3.3.3.1 62 ms 47 ms 63 ms
3 200.1.1.2 93 ms 94 ms 78 ms
4 100.1.1.1 125 ms 125 ms 125 ms
5 2.2.2.2 141 ms 156 ms 141 ms