3Com Switch 8800 Configuration Guide Chapter 37 BGP/MPLS VPN Configuration

37-9

interface, routing table, and sends VPN routing information over MPLS network using

BGP/OSPF interaction.

If supporting OSPF multi-instance, one router can run multiple OSPF procedures,

which can be bound to different VPN instances. In practice, you can create one OSPF

instance for each service type. OSPF multi-instance can fully isolate different services

in transmission, which can solve security problems with low cost to meet the needs of

customers. Generally, OSPF multi-instance is run on PEs; The CE running OSPF

multi-instance in the LAN is called multi-VPN-instance CE. At present, isolation of LAN

services implements by VLAN function of the switch. OSPF Multi-VPN-Instance CE

provides schemes of services isolation implemented on routers.

MPLS VPN Backbone
VPN-RED
Site1
OSPF Area0
VPN-GREEN
Si t e1
OSPF Ar ea1
VPN-GREEN
Si t e2
OSPF Ar e a 2
VPN-RED
Si t e2
OSPF Ar e a 1
Area 2
OSPF 100 VPN-GREEN
Area 0
OSPF 100 VPN-RED
OSPF 200 VPN-GREEN
Area 1
CE11
CE12
CE31
CE21
CE22
PE1
PE2
PE3
Area 0
OSPF 100 VPN-RED
OSPF 200 VPN-GREEN
Area 1
MPLS VPN Backbone
VPN-RED
Site1
OSPF Area0
VPN-GREEN
Si t e1
OSPF Ar ea1
VPN-GREEN
Si t e2
OSPF Ar e a 2
VPN-RED
Si t e2
OSPF Ar e a 1
Area 2
OSPF 100 VPN-GREEN
Area 0
OSPF 100 VPN-RED
OSPF 200 VPN-GREEN
Area 1
CE11
CE12
CE31
CE21
CE22
PE1
PE2
PE3
Area 0
OSPF 100 VPN-RED
OSPF 200 VPN-GREEN
Area 1

Figure 37-6 OSPF multi-instance application in MPLS/BGP VPN PE

MPLS Network
PE
R&D
Finances
Engineering
Multi-VPN-Instance CE
ospf100
opsf200
vpn-rd
ospf300
vpn-finances
ospf100
vpn-engineering
ospf300
vpn-finances
opsf200
vpn-rd
vpn-engineering
MPLS Network
PE
R&D
Finances
Engineering
Multi-VPN-Instance CE
ospf100
opsf200
vpn-rd
ospf300
vpn-finances
ospf100
vpn-engineering
ospf300
vpn-finances
opsf200
vpn-rd
vpn-engineering

Figure 37-7 Multi-VPN-instance CE application in conventional LAN

37.1.6 Introduction to Multi-Role Host

The VPN attribute of the packets from a CE to its PE lies on the VPN bound with the

ingress interface. This, in fact determines that all the CEs forwarded by the PE through

the same ingress interface belong to the same VPN; but in actual network

environments, a CE may need to access multiple VPNs through one physical interface.

Though you can configure different logical interfaces to meet this need, this