Professional Documents
Culture Documents
: NG NH THNG
: 05110139
: 05110119
MSSV:05110139
H tn SV: L Din Tm
MSSV:05110119
(K v ghi r h tn)
(K v ghi r h tn)
ii
iii
LI CM N
iv
LI CM N
MC LC
MC LC
NHN XT CA GIO VIN HNG DN ........................................................ I
NHN XT CA GIO VIN PHN BIN .......................................................... II
NHN XT CA HI NG PHN BIN ..........................................................III
LI CM N .......................................................................................................... IV
DANH MC HNH MINH HA .......................................................................... VIII
DANH SCH T VIT TT ................................................................................. XI
PHN M U .................................................................................................... - 1 1. Tnh cp thit ca ti .................................................................................. - 2 2. Mc tiu ca ti .......................................................................................... - 3 3. i tng nghin cu ..................................................................................... - 3 4. Phng php nghin cu ................................................................................ - 3 5. Phm vi nghin cu ........................................................................................ - 3 6. ngha thc tin ca ti ............................................................................ - 3 PHN NI DUNG ................................................................................................ - 4 CHNG 1. GII THIU V CNG NGH VPN ............................................ - 5 1.1 VPN l g? ..................................................................................................... - 5 1.2 Phn loi VPN .............................................................................................. - 6 1.2.1 VPN cho cc nh doanh nghip ............................................................. - 6 1.2.1.1 Remote access VPN ......................................................................... - 6 1.2.1.2 Sitetosite VPN .............................................................................. - 7 1.2.2 VPN i vi cc nh cung cp dch v .................................................. - 8 1.2.2.1 M hnh overlay VPN ...................................................................... - 8 1.2.2.2 M hnh Peer-to-peer VPN .............................................................. - 9 1.3 Tng kt chng ......................................................................................... - 11 CHNG 2. CHUYN MCH NHN A GIAO THC MPLS ................. - 12 2.1 S lc v cng ngh IP v cng ngh ATM............................................. - 12 -
MC LC
vi
2.1.1 Cng ngh IP ........................................................................................ - 12 2.1.2 Cng ngh ATM ................................................................................... - 12 2.2 Khi nim c bn v MPLS ........................................................................ - 14 2.2.1 Li ch ca MPLS ................................................................................ - 14 2.2.2 Mt s ng dng ca MPLS................................................................. - 15 2.3 Cc thnh phn trong MPLS....................................................................... - 16 2.3.1 Nhn ..................................................................................................... - 16 2.3.2 Ngn xp nhn ...................................................................................... - 17 2.3.3 Lp chuyn tip tng ng FEC ...................................................... - 18 2.3.4 ng chuyn mch nhn LSP ............................................................ - 18 2.3.5 C s d liu nhn LIB ........................................................................ - 19 2.3.6 Topo mng MPLS ................................................................................ - 19 2.3.7 Thnh phn c bn ca MPLS ............................................................. - 20 2.3.7.1 Thit b LSR ................................................................................... - 20 2.3.7.2 Thit b LER .................................................................................. - 20 2.4 Giao thc phn phi nhn LDP .................................................................. - 20 2.4.1 Qu trnh khm ph lng ging LSR .................................................... - 21 2.4.2 Cc kiu phn phi nhn ...................................................................... - 22 2.5 Cu trc MPLS ........................................................................................... - 23 2.5.1 Mt phng iu khin ........................................................................... - 25 2.5.2 Mt phng d liu................................................................................. - 26 2.5.3 Cc thnh phn bn trong mt phng iu khin v mt phng d liu- 26
2.6 Cc giao thc nh tuyn ............................................................................ - 28 2.6.1 Giao thc nh tuyn OSPF.................................................................. - 28 2.6.2 Giao thc nh tuyn EIGRP................................................................ - 29 2.6.3 Giao thc nh tuyn BGP ................................................................... - 29 2.7 Phng thc hot ng ca MPLS ............................................................. - 30 2.8 Tng kt chng ......................................................................................... - 37 -
MC LC
vii
CHNG 3. MPLS VPN .................................................................................... - 38 3.1 MPLS VPN l g? ....................................................................................... - 38 3.2 Li ch ca MPLS VPN .............................................................................. - 39 3.3 Cc thnh phn trong MPLS VPN.............................................................. - 40 3.3.1 Virtual Routing and Forwarding Table (VRF) ..................................... - 40 3.3.2 Multiprotocol BGP (MP-BGP) ............................................................ - 41 3.3.3 Route Distinguisher (RD) ..................................................................... - 41 3.3.4 Route Targets (RT) ............................................................................... - 43 3.4 Cch hot ng MPLS VPN ....................................................................... - 44 3.5 Hot ng ca mt phng iu khin MPLS VPN ..................................... - 45 3.6 Hot ng ca mt phng d liu MPLS VPN........................................... - 47 3.7 So snh VPN truyn thng v MPLS VPN ................................................ - 48 3.7.1 VPN truyn thng ................................................................................. - 48 3.7.2 MPLS VPN........................................................................................... - 50 3.8 Tng kt chng ......................................................................................... - 51 CHNG 4. THC NGHIM ........................................................................... - 52 4.1 Cu hnh ...................................................................................................... - 53 4.2 Thng tin nh tuyn ................................................................................... - 63 4.3 Kim tra ...................................................................................................... - 66 PHN KT LUN .............................................................................................. - 71 TI LIU THAM KHO .................................................................................... - 74 -
viii
Hnh 1.1 M hnh remote access VPN ................................................................... - 6 Hnh 1.2 M hnh Site-to-site VPN ....................................................................... - 7 Hnh 1.3 M hnh overlay VPN ............................................................................. - 8 Hnh 1.4 M hnh peer-to-peer VPN ..................................................................... - 9 Hnh 1.5 M hnh shared-router v dedicated-router ........................................... - 11 Hnh 2.1 M hnh chuyn tip gi tin trong IP .................................................... - 12 Hnh 2.2 M hnh ATM ....................................................................................... - 13 Hnh 2.3 Khi nim v MPLS .............................................................................. - 14 Hnh 2.4 Cu trc mo u MPLS ....................................................................... - 16 Hnh 2.5 Nhn MPLS ........................................................................................... - 16 Hnh 2.6 Nhn ca stack ...................................................................................... - 18 Hnh 2.7 Topo mng MPLS ................................................................................. - 19 Hnh 2.8 Qu trnh khm ph lng ging bng LDP ............................................ - 22 Hnh 2.9 Qu trnh trao i thng tin nhn trong LDP ........................................ - 22 Hnh 2.10 Mt phng iu khin v mt phng d liu ....................................... - 24 Hnh 2.11 Cc modul iu khin MPLS .............................................................. - 25 Hnh 2.12 Cc thnh phn MPLS trong mt phng iu khin v mt phng d liu.
.............................................................................................................................. - 28 Hnh 2.13 nh tuyn, chuyn mch, chuyn tip ............................................... - 31 Hnh 2.14 Mng MPLS ........................................................................................ - 32 Hnh 2.15 Qu trnh xy dng bng routing table ............................................... - 33 Hnh 2.16 Qu trnh gn nhn ca router B ......................................................... - 33 Hnh 2.17 Qu trnh phn phi nhn ca router B ............................................... - 34 Hnh 2.18 Qu trnh to bng LIB ....................................................................... - 34 Hnh 2.19 Qu trnh phn phi nhn ca router C ............................................... - 35 Hnh 2.20 Qu trnh to bng LFIB ..................................................................... - 35 -
ix
Hnh 2.21 Qu trnh kim gn nhn ti ingress LSR ........................................... - 36 Hnh 2.22 Qu trnh hon i nhn ...................................................................... - 36 Hnh 2.23 Qu trnh tho nhn ti egress LSR .................................................... - 37 Hnh 3.1 M hnh MPLS VPN ............................................................................. - 38 Hnh 3.2 Bng VRF.............................................................................................. - 40 Hnh 3.3 Gi tr RD .............................................................................................. - 41 Hnh 3.4 Qu trnh gn RD .................................................................................. - 42 Hnh 3.5 Qu trnh tho RD ................................................................................. - 42 Hnh 3.6 Hot ng ca MPLS lp 3 ................................................................... - 44 Hnh 3.7 Hot ng ca MPLS lp 2 ................................................................... - 45 Hnh 3.8 Mt phng iu khin MPLS VPN ....................................................... - 45 Hnh 3.9 Mt phng d liu MPLS VPN ............................................................. - 47 Hnh 3.10 M hnh VPN truyn thng ................................................................. - 48 Hnh 3.11 MPLS VPN ......................................................................................... - 50 Hnh 4.1 M hnh thc nghim MPLS VPN ....................................................... - 52 Hnh 4.2 Thng tin nh tuyn ca A1 ................................................................. - 63 Hnh 4.3 Thng tin nh tuyn ca A2 ................................................................. - 63 Hnh 4.4 Thng tin nh tuyn ca B1 ................................................................. - 64 Hnh 4.5 Thng tin nh tuyn ca B2 ................................................................. - 64 Hnh 4.6 Thng tin nh tuyn ca PE01 ............................................................. - 65 Hnh 4.7 Thng tin nh tuyn ca PE02 ............................................................. - 65 Hnh 4.8 Thng tin nh tuyn ca P ................................................................... - 66 Hnh 4.9 show mpls ldp bindings PE01 ............................................................... - 66 Hnh 4.10 show mpls ldp bindings P ................................................................... - 67 Hnh 4.11 show mpls ldp bindings PE02 ............................................................. - 67 Hnh 4.12 bng LFIB trn PE01 .......................................................................... - 67 Hnh 4.13 bng LFIB trn P ................................................................................. - 68 Hnh 4.14 bng LFIB trn PE02 .......................................................................... - 68 Hnh 4.15 bng nh tuyn vrf A1 trn PE01 ...................................................... - 68 -
Hnh 4.16 bng nh tuyn vrf A2 trn PE02 ..................................................... - 69 Hnh 4.17 bng nh tuyn vrf B1 trn PE01 ...................................................... - 69 Hnh 4.18 bng nh tuyn vrf B2 trn PE02 ...................................................... - 70 Hnh 4.19 A1 ping A2 .......................................................................................... - 70 Hnh 4.20 B1 ping B2 .......................................................................................... - 70 Hnh 4.21 A1 ping B2 .......................................................................................... - 70 -
T ting Anh
AS
Autonomous system
ATM
BGP
B-ISDN
CE
customer edge
CEF
CIDR
CLP
CPE
CSR
DLCI
DoS
Denial of Service
eBGP
EGP
EIGRP
FEC
FIB
xi
FR
Frame Relay
GFC
HDLC
HEC
iBGP
ICMP
IGP
IP
Internet Protocol
IPSec
IPv4
Internet protocol v4
ISDN
ISP
LDP
LERs
LFIB
LIB
LSP
LSRs
MED
xii
MP-BGP
Multiprotocol BGP
MPLS
MTU
NBMA
NGN
OSI
OSPF
PE
provider edge
PPP
PT
Payload Type
PVC
QoS
Quality of service
RD
Route Distinguisher
RIB
RT
Route Targets
SP
Service Provider
SDN
SVC
TCP
xiii
TTL
Time To Live
UDP
VC
Virtual channel
VCI
VLSM
VPI
VPDN
VPN
VRF
WAN
xiv
-1-
A
PHN M U
Phn m u
-2-
1. Tnh cp thit ca ti
Hin nay vi tc pht trin chng mt ca Internet v li ch to ln do vic
p dng cng ngh thng tin vo mi lnh vc, c bit l trong lnh vc vn phng,
qun l th mng ring o dng nh l th khng th thiu i vi cc cng ty.
T nhu cu truy cp d liu ca cng ty t xa, n vic to mi quan h vi khch
hng, gip h c th khai thc mt phn ngun ti nguyn ca mnh m vn m
bo tnh bo mt cn thit cho thng tin.
VPN truyn thng da trn cng ngh ATM, Frame Relay v IP gp khng it
nh c i m nh kh nng qun l, tnh bo mt, cht lng dch v. H u qua la co
th m t lu l ng, m t k t n i , th m chi giam c tinh cua ma ng . Ngoi ra cn phi
k n cac chi ph khng nho dnh cho vic thu dch v vin thng kt ni
mng.
Gn y, Cng ngh chuyn mch nhn a giao thc - MPLS c cc hng
cung cp dch v quan tm c bit bi kh nng vt tri trong vic cung cp dch
v cht lng cao qua mng IP, bi tnh n gin, hiu qu v quan trng nht l
kh nng trin khai VPN.
Vi u im chuy n ti p lu l ng nhanh , kh nng linh hot , n gian , i u
khi n phn lu ng v phu c vu linh hoa t cac dich
vu inh
tuy n , t n du ng c ng
truy n giup giam chi phi . Cng ngh MPLS ang dn thay th cc cng ngh truyn
thng khc nh IP v ATM.
MPLS VPN gii quyt c nhng hn ch ca cc mng VPN truyn thng
da trn cng ngh ATM, Frame Relay v IP nh tit kim thi gian, gim chi ph
lp t v c bo mt cao cho doanh nghip. Do vy vic tm hiu v ng dng
VPN trn nn MPLS c xem la v n cp thit gip doanh nghip c th d
dng tip cn vi cng ngh mi ny v t c th ng dng vo vic pht trin
ca doanh nghip mnh cng vi s i ln ca ngnh mng vin thng quc t.
Phn m u
-3-
2. Mc tiu ca ti
Mc tiu ca ti l:
Tm hiu v MPLS VPN v p dng MPLS VPN ci t thc nghim.
Gip cho ngi c c nhng khi nim c bn v MPLS v t c th
xy dng mt mng MPLS VPN n gin.
3. i tng nghin cu
Tm hiu v trin khai MPLS VPN.
4. Phng php nghin cu
Khi thc hin ti ny, nhm nghin cu dng cc phng php sau:
Phng php phn tch ti liu: dng tm hiu thng tin v ngha ca
cc khi nim lin quan n MPLS v VPN. Thng qua phng tin l
Internet tm ti liu phc v cho ti.
Phng php thc nghim: da trn m hnh trin khai thc nghim,
nhm thc hnh cu hnh MPLS VPN. Qua b sung kin thc l
thuyt cho tng phn.
5. Phm vi nghin cu
Do tnh cht ca ti v iu kin thc t nn nhm nghin cu ch tin
hnh nghin cu cc vn lin quan n VPN trong MPLS v trin khai trn
m hnh thc nghim.
6. ngha thc tin ca ti
Vic tm hiu v MPLS VPN gip cho cc nh cung cp dch v c th
trin khai v ng dng trong thc t ng thi khc phc c nhng nhc
im ca cc mng VPN truyn thng.
-4-
B
PHN NI DUNG
-5-
1.1 VPN l g?
VPN l cng ngh cho php kt ni cc thnh phn ca mt mng ring
(private network) thng qua h tng mng cng cng (Internet). VPN hot ng
da trn k thut tunneling: gi tin trc khi c chuyn i trn VPN s c
m ha v c t bn trong mt gi tin c th chuyn i c trn mng cng
cng. Gi tin c truyn i n u bn kia ca kt ni VPN. Ti im n
bn kia ca kt ni VPN, gi tin b m ha s c ly ra t trong gi tin
ca mng cng cng v c gii m.
Cc giai on pht trin ca VPN:
Th h VPN th nht do AT&T pht trin c tn l SDN.
Th h th 2 l ISND v X25.
Th h th 3 l Frame relay v ATM.
V th h hin nay, th h th 4 l VPN trn nn mng IP.
Th h tip theo s l VPN trn nn mng MPLS.
VPN gm cc vng sau:
Mng khch hng (Customer network): gm cc router ti cc site khch
hng khc nhau. Cc router kt ni cc site c nhn vi mng ca nh
cung cp c gi l cc router bin pha khch hng CE.
Mng nh cung cp (Provider network): c dng cung cp cc kt
ni point-to-point qua h tng mng ca nh cung cp dch v. Cc thit
b ca nh cung cp dch v m ni trc tip vi CE router c gi l
router bin pha nh cung cp PE. Mng ca nh cung cp cn c cc
thit b dng chuyn tip d liu trong mng trc (SP backbone) c
gi l cc router nh cung cp (P- provider).
-6-
-7-
-8-
Khi Frame relay v ATM cung cp cho khch hng cc mng ring,
nh cung cp khng th tham gia vo vic nh tuyn khch hng. Cc
nh cung cp dch v ch vn chuyn d liu qua cc kt ni o. Nh
vy, nh cung cp ch cung cp cho khch hng kt ni o ti lp 2.
l m hnh Overlay.
Nu mch o l c nh, sn sng cho khch hng s dng mi lc
th c gi l mch o c nh PVC. Nu mch o c thit lp theo
yu cu (on-demand) th c gi l mch o chuyn i SVC.
Hn ch chnh ca m hnh Overlay l cc mch o ca cc site
khch hng kt ni dng full mesh. Nu c N site khch hng th tng
s lng mch o cn thit N(N-1)/2.
-9-
- 10 -
Vic pht hin cc thng tin nh tuyn ring ca khch hng bng
cch thc hin lc gi (packet) ti cc router kt ni vi mng khch
hng.
Peer-to-peer VPN chia lm 2 loi:
Shared-router
Router dng chung, tc l khch hng VPN chia s cng router bin
mng nh cung cp PE. phng php ny, nhiu khch hng c th
kt ni n cng router PE.
Trn router PE phi cu hnh access-list cho mi interface PE-CE
m bo chc chn s cch ly gia cc khch hng VPN, ngn
chn VPN ca khch hng ny thc hin cc tn cng t chi dch v
DoS vo VPN ca khch hng khc. Nh cung cp dch v chia mi
phn trong khng gian a ch ca n cho khch hng v qun l vic
lc gi tin trn Router PE.
Dedicated-router
L phng php m khch hng VPN c router PE dnh ring. Trong
phng php ny, mi khch hng VPN phi c router PE dnh ring
v do ch truy cp n cc nh tuyn trong bng nh tuyn ca
router PE . M hnh Dedicated-router s dng cc giao thc nh
tuyn to ra bng nh tuyn trn mt VPN trn Router PE. Bng
nh tuyn ch c cc nh tuyn c qung b bi khch hng VPN
kt ni n chng, kt qu l to ra s cch ly gia cc VPN.
- 11 -
- 12 -
- 13 -
- 14 -
2.2.1 Li ch ca MPLS
MPLS l phng php ci tin cho vic chuyn tip cc gi tin IP trn
mng bng cch thm vo nhn (label). MPLS kt hp cc u im ca k
thut chuyn mch (switching) ca lp 2 v k thut nh tuyn (routing)
lp 3. Do s dng nhn quyt nh chng tip theo trong mng nn router
t lm vic hn v hot ng gn ging nh switch.
MPLS h tr mi giao thc lp 2, trin khai hiu qu cc dch v IP
trn mt mng chuyn mch IP. MPLS h tr vic to ra cc tuyn khc
nhau gia ngun v ch trn mt ng trc Internet. Bng vic tch hp
MPLS vo kin trc mng, cc ISP c th gim chi ph, tng li nhun,
cung cp nhiu hiu qu khc nhau v t c hiu qu cnh tranh cao.
- 15 -
- 16 -
Nhn (20)
Mo u
IP
m
MPLS
COS(3)
S(1)
Mo u lp
2
TTL(8)
- 17 -
- 18 -
- 19 -
- 20 -
- 21 -
C 4 loi bn tin:
Bn tin Discovery: thng bo v duy tr s c mt ca mt
LSR trong mng.
Bn tin Adjency: c nhim v khi to, duy tr v kt thc
nhng phin kt ni gia cc LSR.
Bn tin Label advertisement: thc hin vic thng bo, a ra
yu cu, hy bo v gii phng thng tin nhn.
Bn tin Notification: c s dng thng bo li.
Thit lp kt ni TCP trao i cc bn tin (ngoi tr bn tin
Discovery).
Cc bn tin l tp hp nhng thnh phn c cu trc < type, length,
value>.
2.4.1 Qu trnh khm ph lng ging LSR
Giao thc ny hot ng trn kt ni UDP v c th c xem l giai
on nhn bit nhau ca hai LSR trc khi chng thit lp kt ni TCP.
Mt LSR s qung b bn tin hello ti tt c LSR kt ni trc tip vi n
trn mt cng UDP mc nh theo mt chu k nht nh. Tt c cc LSR
u lng nghe bn tin hello ny trn cng UDP. Nh LSR bit c a
ch ca tt c cc LSR kt ni trc tip vi n. Sau khi bit c a ch ca
mt LSR no , mt kt ni TCP s c thit lp gia hai LSR ny. Ngay
c khi khng kt ni trc tip vi nhau th LSR vn c th gi nh k bn
tin hello n cng UDP mc nh ca mt a ch IP xc nh. V LSR nhn
cng c th gi li bn tin hello cho LSR gi thit lp kt ni TCP.
- 22 -
- 23 -
- 24 -
Trong :
GFC : iu khin lung chung.
VPI : nhn dng ng o.
VCI : nhn dng knh o.
PT : ch th kiu trng tin.
CLP : chc nng ch th u tin hu bo t bo.
HEC : kim tra li tiu .
MPLS chia thnh 2 mt phng: mt phng iu khin MPLS ( Control plane )
v mt phng chuyn tip MPLS hay cn gi l mt phng d liu (Data plane).
- 25 -
- 26 -
- 27 -
2.5.3.3 C s thng tin nhn LIB v c s thng tin chuyn tip nhn
LFIB
Ngoi FIB cn c hai cu trc khc c xy dng trn router,
l LIB v LFIB.
Cc giao thc phn phi c s dng gia cc router lng ging
trong min MPLS nhm p ng cho vic to ra cc mc trong LIB v
LFIB:
LIB nm trong mt phng iu khin v thng c dng bi
giao thc phn phi nhn. Cc nhn hop k c nhn t cc
Downstream, cn cc nhn cc b c to ra bi giao thc
phn phi nhn.
LFIB nm trong mt phng d liu, cha mt nh x t nhn
cc b n nhn hop k.
2.5.3.4 C s thng tin nh tuyn RIB
Thng tin v cc mng ch c kh nng i n c ly t cc
giao thc nh tuyn cha trong c s thng tin nh tuyn RIB hoc
bng nh tuyn. Bng nh tuyn cung cp thng tin cho mt FIB. LIB
s dng thng tin t giao thc phn phi nhn, v khi LIB kt hp cng
vi cc thng tin ly t FIB s to ra c s thng tin chuyn tip nhn
LFIB.
- 28 -
Hnh 2.12 Cc thnh phn MPLS trong mt phng iu khin v mt phng d liu.
- 29 -
- 30 -
Cu hnh BGP
Router(config)#router bgp as-number
Router(config-router)#neighbor {ip address/peer-group-name} remoteas as-number
Router(config-router)#neighbor {ip address/peer-group-name} updatesource interface-type interface-number
Router(config-router)#address-family vpnv4
Router(config-router-af)#neighbor {ip address/peer-group-name}
activate
Router(config-router)# neighbor {ip address/peer-group-name} sendcommunity {extended/both}
Router(config-router)# neighbor {ip address/peer-group-name} nexthop-self
2.7 Phng thc hot ng ca MPLS
Khi mt gi tin vo mng MPLS, cc b nh tuyn chuyn mch nhn
khng thc hin chuyn tip theo tng gi m thc hin phn loi gi tin vo
trong cc lp tng ng chuyn tip FEC, sau cc nhn c nh x vo
trong cc FEC. Mt giao thc phn b nhn LDP c xc nh v chc nng
ca n l n nh v phn b cc rng buc FEC/nhn cho cc b nh tuyn
chuyn mch nhn LSR. Khi LDP hon thnh nhim v ca n, mt ng dn
chuyn mch nhn LSP c xy dng t ng vo ti ng ra. Khi cc gi vo
mng, LSR ng vo kim tra nhiu trng trong tiu gi xc nh xem gi
thuc v FEC no. Nu c mt rng buc nhn/FEC th LSR ng vo gn
nhn cho gi v chuyn tip n ti ng ra tng ng. Sau gi c hon i
nhn qua mng cho n khi n n LSR ng ra, lc nhn b loi bo v gi
c x l ti lp 3. V vy qu trnh chuyn tip gi tin din ra nhanh hn so
vi vic chuyn tip da vo nh tuyn IP.
- 31 -
Mt phng iu
khin
Mt phng
chuyn tip
Duy tr tuyn
nh tuyn
La chn cng ra
Nhn gi u vo
Chuyn mch
Nhn gi u ra
Cc cng u vo
Cc cng u ra
Lin mng
- 32 -
- 33 -
Sau khi bng routing table hnh thnh, cc router s gn nhn cho cc
ch n m c trong bng routing table ca n, v d y router B s gn
nhn bng 25 cho mng X, ngha l nhng nhn vo c gi tr 25 router B s
chuyn n n mng X.
- 34 -
- 35 -
- 36 -
- 37 -
- 38 -
- 39 -
- 40 -
- 41 -
Hnh 3.3 Gi tr RD
- 42 -
- 43 -
- 44 -
- 45 -
- 46 -
- 47 -
- 48 -
nhn trong. Nhn trong (6) cho router bit giao tip no n s chuyn tip gi ra.
Gi sau c chuyn ti CE2.
- 49 -
m, hai hot ng ny tip tc lm tr gi tin trong mng. Cui cng, CPEB s chuyn tip gi tin n my tnh B.
Thi gian tr trong mng s ph thuc vo phc tp v tc x l
ca cc CPE. Cc thit b CPE cht lng thp thng phi thc hin hu
ht cc chc nng IPSec bng phn mm khin tr trong mng ln. Cc thit
b CPE vi kh nng thc hin cc chc nng IPSec bng phn cng c th
tng tc x l gi tin ln rt nhiu nhng chi ph cho cc thit b ny l
rt t. iu ny dn n chi ph trin khai mt mng IPSec VPN l rt tn
km.
Cc cng ngh IP VPN khc hin c, nh IPSec, L2TP, L2F v GRE
tt c u hot ng tt vi cu hnh mng sao (hubandspoke). Tuy
nhin, mng ngy nay cn lin lc nhiu chiu (anytoany). h tr iu
ny s dng Frame relay hay giao thc ng hm th cn phi c cu hnh
dng kt ni y (full mesh) cc PVC hay ng hm gia cc vng l
thnh vin. Mng khng th cung cp v qun l mt cu hnh y (full
mesh topology) s dng cc cng ngh truyn thng vi hng ngn hay
chc ngn VPN.
Mt im chng ta cn phi cn nhc khi trin khai cc mng VPN
l cc thit b CPE. Mi nh cung cp cn phi chc chn rng tt c cc
CPE s hot ng tng thch vi nhau. Gii php n gin v hiu qu
nht l s dng cng mt loi CPE trong mi vng, tuy nhin, iu ny
khng phi bao gi cng thc hin c do nhiu yu t khc nhau. Tuy
ngy nay s tng thch khng phi l mt vn ln nhng n vn cn
phi c quan tm khi hoch nh mt gii php mng IPSec VPN.
- 50 -
- 51 -
- 52 -
4.1 Cu hnh
4.1.1 Cu hnh router A1:
hostname A1
!
ip cef
ip audit po max-events 100
!
interface Loopback0
ip address 10.10.10.10 255.255.255.0
!
interface Serial1/0
ip address 192.168.1.2 255.255.255.0
serial restart-delay 0
!
router rip
version 2
network 10.0.0.0
network 192.168.1.0
no auto-summary
!
End
4.1.2 Cu hnh router B1:
hostname B1
!
ip cef
ip audit po max-events 100
!
interface Loopback0
- 53 -
- 54 -
!
interface Loopback0
ip address 1.1.1.1 255.255.255.0
!
interface Serial1/0
ip vrf forwarding A1
ip address 192.168.1.1 255.255.255.0
serial restart-delay 0
!
interface Serial1/1
ip vrf forwarding B1
ip address 192.168.2.1 255.255.255.0
serial restart-delay 0
!
interface Serial1/2
ip address 192.168.3.1 255.255.255.0
mpls label protocol ldp
tag-switching ip
serial restart-delay 0
!
router eigrp 100
network 1.0.0.0
network 192.168.3.0
no auto-summary
!
router rip
version 2
!
address-family ipv4 vrf B1
- 55 -
- 56 -
!
address-family ipv4 vrf A1
redistribute rip
no auto-summary
no synchronization
exit-address-family
!
End
4.1.4 Cu hnh router P:
hostname P
!
ip cef
ip audit po max-events 100
!
interface Loopback0
ip address 3.3.3.3 255.255.255.0
!
interface Serial1/0
ip address 192.168.3.2 255.255.255.0
mpls label protocol ldp
tag-switching ip
serial restart-delay 0
!
interface Serial1/1
ip address 192.168.4.1 255.255.255.0
mpls label protocol ldp
tag-switching ip
serial restart-delay 0
- 57 -
!
router eigrp 100
network 3.0.0.0
network 192.168.3.0
network 192.168.4.0
no auto-summary
!
End
4.1.5 Cu hnh router PE02:
hostname PE02
!
ip vrf A2
rd 1:100
route-target export 1:100
route-target import 1:100
!
ip vrf B2
rd 1:200
route-target export 1:200
route-target import 1:200
!
ip cef
ip audit po max-events 100
!
interface Loopback0
ip address 2.2.2.2 255.255.255.0
!
interface Serial1/0
- 58 -
- 59 -
- 60 -
exit-address-family
!
End
4.1.6 Cu hnh router A2:
hostname A2
!
ip cef
ip audit po max-events 100
!
interface Loopback0
ip address 30.30.30.30 255.255.255.0
!
interface Serial1/0
ip address 192.168.5.2 255.255.255.0
serial restart-delay 0
!
router rip
version 2
network 30.0.0.0
network 192.168.5.0
no auto-summary
!
End
- 61 -
- 62 -
- 63 -
- 64 -
- 65 -
- 66 -
- 67 -
Bng LFIB
- 68 -
- 69 -
- 70 -
- 71 -
C
PHN KT LUN
Phn kt lun
- 72 -
Phn kt lun
- 73 -
[1]. TS.Trn Cng Hng, chuyn mch nhn a giao thc MPLS, nh xut bn
thng tin v truyn thng, 7/2009
[2]. Brian Morgan v Neil Lovering, CCNP ISCW Ofcial Exam Certication
Guide, Cisco Press
[3]. Jim CCIE #2069 Guichard v Ivan CCIE #1354 Pepelnjak, MPLS and VPN
Architectures, Cisco Press
[4]. Dng Vn Ton, MPLS Lab Guide Version 1.0 (MPLS - Multiprotocol Label
Switching), vnexperts, 9/2008
[5]. ng Quang Minh, CCNA labpro, nh xut bn tr, 2008
[6]. Munther Louis Antoun, mpls vpn configuration and design guide
[7]. Trn Th T Quyn, Chuyn mch nhn a giao thc
[9]. http://www.vnpro.org/forum
[10]. http://my.opera.com/huyhung.hanu/blog/
[11].http://ties.itu.int/ftp/public/itut/ahtmpls/readandwrite/doc_exchange/0802_gene
va/wd16-mpls-data-and-control-plane.txt
[12]. http://www.tapchibcvt.gov.vn
- 74 -