MPLS L3VPN Deep-Dive

CCIE Enterprise Infrastructure EVE-NG / GNS3

مقصدObjectiveObjective

اس سبق کے بعد آپ MPLS L3VPN کا مکمل خاکہ سمجھ جائیں گے: VRF، Route Distinguisher، Route Target، اور MP-BGP VPNv4 کی عملی configuration کر سکیں گے۔Is lesson ke baad aap MPLS L3VPN ka mukammal khaaka samajh jayenge: VRF, Route Distinguisher, Route Target, aur MP-BGP VPNv4 ki practical configuration kar sakenge.After this lesson you will understand the full MPLS L3VPN picture: VRF, Route Distinguisher, Route Target, and practical MP-BGP VPNv4 configuration.

آسان مثالSimple AnalogySimple Analogy

MPLS L3VPN ایسا ہے جیسے ایک ہی عمارت میں کئی کمپنیوں کے الگ الگ دفاتر — ایک ہی provider نیٹ ورک، لیکن ہر customer کا ٹریفک VRF کے ذریعے مکمل الگ۔ RD ہر دفتر کا منفرد پتہ ہے، RT دروازے کی چابی۔MPLS L3VPN aisa hai jaise ek hi building mein kai companies ke alag alag offices — ek hi provider network, lekin har customer ka traffic VRF ke zariye mukammal alag. RD har office ka unique pata hai, RT darwaze ki chaabi.MPLS L3VPN is like several companies sharing one building with separate offices — one provider network, but each customer's traffic fully isolated via VRF. RD is each office's unique address; RT is the door key.

سیٹ اپLab SetupLab Setup

دو PE روٹرز، ایک P روٹر، اور دو CE روٹرز (دو customers) لیں۔ کور میں OSPF چلائیں۔ ہر PE پر دو VRFs بنائیں (CUST-A، CUST-B)۔Do PE routers, ek P router, aur do CE routers (do customers) lein. Core mein OSPF chalayein. Har PE par do VRFs banayein (CUST-A, CUST-B).Use two PE routers, one P router, and two CE routers (two customers). Run OSPF in the core. Create two VRFs (CUST-A, CUST-B) on each PE.

اقداماتStepsSteps

Step 1

کور میں MPLS فعال کریں: ہر کور انٹرفیس پر LDP چلائیں۔ پہلے IGP (OSPF) پوری طرح converge ہونا چاہیے۔Core mein MPLS active karein: har core interface par LDP chalayein. Pehle IGP (OSPF) poori tarah converge hona chahiye.Enable MPLS in the core: run LDP on every core interface. The IGP (OSPF) must be fully converged first.

mpls ip
interface GigabitEthernet0/0
mpls ip
show mpls ldp neighbor

Step 2

VRF بنائیں۔ RD ہر VRF prefix کو منفرد بناتا ہے (اوور لیپنگ IPs کی اجازت دیتا ہے)۔ RT کنٹرول کرتا ہے کون سی VRF کون سے routes import/export کرے۔VRF banayein. RD har VRF prefix ko unique banata hai (overlapping IPs ki ijazat deta hai). RT control karta hai kaun si VRF kaun se routes import/export kare.Create the VRFs. RD makes each VRF prefix unique (allowing overlapping IPs). RT controls which VRF imports/exports which routes.

ip vrf CUST-A
rd 65000:1
route-target export 65000:1
route-target import 65000:1

Step 3

VRF کو customer-facing انٹرفیس سے جوڑیں۔ نوٹ: انٹرفیس پر پہلے سے موجود IP مٹ جائے گا، اس لیے IP دوبارہ لگائیں۔VRF ko customer-facing interface se jorein. Note: interface par pehle se maujood IP mit jayega, is liye IP dobara lagayein.Bind the VRF to the customer-facing interface. Note: the interface's existing IP is removed, so re-apply it.

interface GigabitEthernet0/1
ip vrf forwarding CUST-A
ip address 192.168.10.1 255.255.255.0

Step 4

PE-CE routing چلائیں — یہاں eBGP استعمال کریں۔ CE کے روٹس VRF routing table میں آئیں گے۔PE-CE routing chalayein — yahan eBGP use karein. CE ke routes VRF routing table mein aayenge.Run PE-CE routing — use eBGP here. CE routes will land in the VRF routing table.

router bgp 65000
address-family ipv4 vrf CUST-A
neighbor 192.168.10.2 remote-as 65001
redistribute connected

Step 5

PEs کے درمیان MP-BGP VPNv4 session بنائیں۔ یہ VPNv4 prefixes (RD + IPv4) ایک PE سے دوسرے PE تک لے جاتا ہے۔PEs ke darmiyan MP-BGP VPNv4 session banayein. Ye VPNv4 prefixes (RD + IPv4) ek PE se doosre PE tak le jata hai.Build the MP-BGP VPNv4 session between PEs. It carries VPNv4 prefixes (RD + IPv4) from one PE to the other.

router bgp 65000
neighbor 10.0.0.2 remote-as 65000
neighbor 10.0.0.2 update-source Loopback0
address-family vpnv4
neighbor 10.0.0.2 activate
neighbor 10.0.0.2 send-community extended

Step 6

VRF روٹس کو MP-BGP میں redistribute کریں تاکہ وہ VPNv4 کے طور پر دوسرے PE تک پہنچیں۔VRF routes ko MP-BGP mein redistribute karein taake wo VPNv4 ke tor par doosre PE tak pohnchen.Redistribute VRF routes into MP-BGP so they reach the other PE as VPNv4.

address-family ipv4 vrf CUST-A
redistribute bgp 65001

Step 7

آخر سے آخر تک connectivity ٹیسٹ کریں: CE-A1 سے CE-A2 تک ping۔ پھر CUST-B کے CE سے ping کر کے دیکھیں کہ ٹریفک الگ ہے (fail ہونا چاہیے)۔End-to-end connectivity test karein: CE-A1 se CE-A2 tak ping. Phir CUST-B ke CE se ping kar ke dekhen ke traffic alag hai (fail hona chahiye).Test end-to-end connectivity: ping from CE-A1 to CE-A2. Then ping from CUST-B's CE to confirm isolation (it should fail).

ping vrf CUST-A 192.168.20.2
show ip route vrf CUST-A

تصدیقVerifyVerify

یقین کریں کہ LDP neighbors up ہیں، ہر VRF میں CE روٹس موجود ہیں، VPNv4 prefixes دوسرے PE پر نظر آ رہے ہیں، اور customers آپس میں isolated ہیں۔Yaqeen karein ke LDP neighbors up hain, har VRF mein CE routes maujood hain, VPNv4 prefixes doosre PE par nazar aa rahe hain, aur customers aapas mein isolated hain.Confirm LDP neighbors are up, each VRF holds CE routes, VPNv4 prefixes appear on the remote PE, and customers are isolated from each other.

show mpls forwarding-table
show ip bgp vpnv4 all summary
show ip route vrf CUST-A
ping vrf CUST-A 192.168.20.2

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ VPNv4 prefixes دوسرے PE پر نظر نہیں آ رہے۔VPNv4 prefixes doosre PE par nazar nahi aa rahe.VPNv4 prefixes not visible on the remote PE.

✅ چیک کریں: address-family vpnv4 میں neighbor activate ہے؟ send-community extended لگا ہے؟ VRF address-family میں redistribute ہوا ہے؟Check karein: address-family vpnv4 mein neighbor activate hai? send-community extended laga hai? VRF address-family mein redistribute hua hai?Check: is the neighbor activated under address-family vpnv4? Is send-community extended set? Are routes redistributed under the VRF address-family?

⚠️ CE سے PE تک ping کامیاب ہے لیکن CE-to-CE fail ہے۔CE se PE tak ping kamyab hai lekin CE-to-CE fail hai.CE-to-PE ping works but CE-to-CE fails.

✅ RT import/export match کریں دونوں PEs پر، اور یقین کریں MP-BGP session up ہے۔ اکثر RT mismatch ہوتا ہے۔RT import/export match karein dono PEs par, aur yaqeen karein MP-BGP session up hai. Aksar RT mismatch hota hai.Match RT import/export on both PEs and confirm the MP-BGP session is up. RT mismatch is the usual culprit.

⚠️ LDP neighbor نہیں بن رہا۔LDP neighbor nahi ban raha.LDP neighbor not forming.

✅ IGP reachability چیک کریں (loopbacks ping ہونی چاہئیں)، پھر ہر کور انٹرفیس پر 'mpls ip' لگا ہے یا نہیں دیکھیں۔IGP reachability check karein (loopbacks ping honi chahiyein), phir har core interface par 'mpls ip' laga hai ya nahi dekhen.Verify IGP reachability (loopbacks must ping), then confirm 'mpls ip' is on every core interface.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ RD اور RT میں کیا فرق ہے؟RD aur RT mein kya farq hai?What is the difference between RD and RT?

RD ہر VPNv4 prefix کو منفرد بناتا ہے تاکہ اوور لیپنگ customer IPs ایک ساتھ رہ سکیں۔ RT ایک extended community ہے جو کنٹرول کرتی ہے کون سا route کون سی VRF میں import ہو۔RD har VPNv4 prefix ko unique banata hai taake overlapping customer IPs ek saath reh sakein. RT ek extended community hai jo control karti hai kaun sa route kaun si VRF mein import ho.RD makes each VPNv4 prefix unique so overlapping customer IPs can coexist. RT is an extended community controlling which routes get imported into which VRF.

❓ P روٹر کو VRFs یا BGP کیوں نہیں چاہیے؟P router ko VRFs ya BGP kyun nahi chahiye?Why doesn't the P router need VRFs or BGP?

P روٹر صرف labeled packets سوئچ کرتا ہے — اسے customer routes دیکھنے کی ضرورت نہیں۔ صرف PE روٹرز VRF اور MP-BGP چلاتے ہیں۔P router sirf labeled packets switch karta hai — use customer routes dekhne ki zaroorat nahi. Sirf PE routers VRF aur MP-BGP chalate hain.The P router only label-switches packets — it never needs customer routes. Only PE routers run VRF and MP-BGP.