3Com Switch 8800 Family Configuration Guide

Typical BGP/MPLS VPN Configuration Example 557
[PE3-bgp-af-vpn] peer 202.100.1.1 group 202
[PE3-bgp-af-vpn] quit
5 Configure PE2 and PE4
The configuration of PE2 and PE4 is similar to that of PE1 and PE3. The details are
omitted here.
Extranet Configuration
Example
Network requirements
Company A and Company B are located at City A and City B respectively. Their
headquarters is located at City C. They respectively own VPN1 and VPN2.
In this case, VPN function is provided by MPLS. There are some shared resources at
the City C for the two VPNs. All subscribers in both VPNs can access the shared
resources, but VPN subscribers in City A and City B cannot access each other.
The two companies cannot use identical IP addresses, for they share the same
VPN-instance at PE-C.
n
In the case the configuration is focused on controlling access authority of VPN
subscribers at different cities by configuring different VPN-target attributes at
different PEs.
Network diagram
Figure 135 Network diagram for Extranet
PC
CE-B
PCPC
CE-C
PCPC
CE-A
PCPC PC
CE-B
PCPC
CE-C
PCPC
CE-A
PCPC
VPN 1
VPN 2
PE-A
10.1.1.1
PE-B
30.1.1.1
PE-C
20.1.1.1
City A
City C City B
10.11.1.0/24 10.12.1.0/24
VLAN301
172.15.0.1/16
VLAN201
172.15.1.1/16
VLAN301
172.16.0.1/16
VLAN201
172.16.1.1/16
172.17.0.1/16
VLAN201
172.17.1.1/16
AS100
AS65011 AS65012 AS65013
VLAN301
SP network
VPN 1
VPN 2
PE-A
10.1.1.1
PE-B
30.1.1.1
PE-C
20.1.1.1
City A
City C City B
10.11.1.0/24 10.12.1.0/24
VLAN301
172.15.0.1/16
VLAN201
172.15.1.1/16
VLAN301
172.16.0.1/16
VLAN201
172.16.1.1/16
172.17.0.1/16
VLAN201
172.17.1.1/16
AS100
AS65011 AS65012 AS65013
VLAN301
SP network
PC
CE-B
PCPC
CE-C
PCPC
CE-A
PCPC
VPN 1
VPN 2
PE-A
10.1.1.1
PE-B
30.1.1.1
PE-C
20.1.1.1
City A
City C City B
10.11.1.0/24 10.12.1.0/24
VLAN301
172.15.0.1/16
VLAN201
172.15.1.1/16
VLAN301
172.16.0.1/16
VLAN201
172.16.1.1/16
172.17.0.1/16
VLAN201
172.17.1.1/16
AS100
AS65011 AS65012 AS65013
VLAN301