Skip Headers
Oracle® Communications IP Service Activator VPN User's Guide
Release 7.2

E47719-01
Go to Documentation Home
Home
Go to Table of Contents
Contents
Go to Feedback page
Contact Us

Go to previous page
Previous
PDF · Mobi · ePub

A Setting Up Management and Customer VPNs

This appendix outlines the high-level steps you need to follow in order to set up management and customer VPNs on Oracle Communications IP Service Activator.

Introduction

In the following example, three VPNs are created:

  • A management VPN is set up comprising the Management site and all other sites in all VPNs managed by IP Service Activator. With IP Service Activator running at the management site, all CE routers can be managed. The management site is a hub site; all other sites are spoke sites.

  • Customer VPN 1 comprises sites 1, 2 and 4.

  • Customer VPN 2 comprises sites 1, 3 and 5.

VPN 1 and 2 are both fully-meshed. The network layout and routing protocols are shown in Figure A-1.

Figure A-1 Network and Routing Protocols for Management and Customer VPNs

Description of Figure A-1 follows
Description of "Figure A-1 Network and Routing Protocols for Management and Customer VPNs"

Between the management site and the core network, two links are required, one to provide VPN connectivity and one to provide routes to the Service Provider backbone IGP. These links are illustrated in Figure A-2.

Figure A-2 Links Between Management Site and Core Network

Description of Figure A-2 follows
Description of "Figure A-2 Links Between Management Site and Core Network"

Configuring the VPNs

The following steps explain the sequence of operations required to set up a management VPN, enabling access to the CE routers, followed by customer VPNs. For full details, see the detailed explanation in "Setting Up MPLS VPNs".

Configuring VPNs involves:

  1. Setting Up the Domain

  2. Setting Up the Core Network ASN

  3. Discovering the Network and Assigning Roles

  4. Disabling Interfaces on CE-PE Link

  5. Setting Devices to Managed

  6. Setting Up Customers and Sites

  7. Linking Physical Network Components with Sites

  8. Setting the VPN Routing Parameters

  9. Creating the Management VPN

  10. Implementing the Management VPN

  11. Setting Up the CE Devices

  12. Setting Up the Customer VPNs

  13. Implementing the Customer VPNs

Setting Up the Domain

To set up the domain:

  1. On the Domain page of the Domain dialog box:

    • Set the Type to MPLS VPN.

    • Select the PE to CE Addresses option.

  2. Set the required parameters on the VPN BGP page and the VPN MPLS page.

    See "Setting Up Domain Parameters" for more details.

Setting Up the Core Network ASN

To set up the core network ASN:

  1. On the ASN page of the Domain dialog box, set the internal BGP ASN to 1.

    See "Setting Up the Provider Core ASN for the Domain" for more details.

Discovering the Network and Assigning Roles

To discover the network and assign roles to devices and interfaces:

  1. Run a device discovery to discover the PE devices (PE1 and PE2) and the CE device at the management site (MgmtCE).

    Devices can be discovered using their IP addresses or DNS names.

  2. Assign the correct system-defined roles to devices. Routers must be assigned the Gateway role and the CE router must be assigned the Access role.

    Appropriate interfaces on the devices also need to be assigned Local or Access roles.

  3. Assign roles manually for each device.

    For more information, see IP Service Activator User's Guide.

Disabling Interfaces on CE-PE Link

To prevent interfaces on a CE-PE link from being configured into a VPN, disable them.

To disable interfaces:

  1. Assign the role of Disabled to the interfaces at both ends of the Serial 0.1 link between PE1 and MgmtCE (the link that is not to be used for the VPN connection).

Note:

The Access Point (interface or sub-interface) that is in the Management VPN and thus provides routes to the CE must be passive. This is so that routes from the customer networks are not leaked into the Service Provider backbone, and vice versa

Setting Devices to Managed

Set all discovered devices to Managed so that IP Service Activator can configure them.

Setting Up Customers and Sites

To set up customers and sites:

  1. On the Service tab, set up the appropriate customers:

    • Create a dummy customer, such as Management for the management VPN

    • Create dummy customers, Customer 1 and Customer 2, for the customer VPNs

  2. Create site objects for the management site and each of the customers sites and give them identifying names.

Linking Physical Network Components with Sites

For each site, link the appropriate access interface on the PE router to the site by dragging and dropping.

Setting the VPN Routing Parameters

To set up VPN routing parameters for each site:

  1. On the Site property page, set the appropriate routing type and relevant parameters (EBGP, RIP, OSPF, EIGRP, EBGP & OSPF, EBGP & RIP, EBGP & EIGRP and/or static routing).

  2. On the Addressing page of the Site dialog box, set up private addresses (used with the VPN) and public addresses (used outside the VPN).

Note:

In this example, it is assumed that the settings on the Advanced VPN page are left as defaults.

Creating the Management VPN

To create the management VPN:

  1. Under the Management customer object, create a VPN object to represent the management VPN.

  2. Link all the sites (Management site, Site 1, Site 2, Site 3, Site 4, and Site 5) to the VPN by dragging and dropping.

  3. On the Connectivity page of the VPN properties, set the Connectivity to Management.

  4. Ensure that the management site is selected as the hub site.

Implementing the Management VPN

To implement the management VPN:

  1. Save the changes to the database.

  2. Commit the transaction.

Setting Up the CE Devices

To set up the CE devices:

  1. Discover the CE devices using their defined loopback addresses.

  2. Link the CE devices to the appropriate sites by dragging and dropping.

    An error is flagged if the devices are not linked.

Setting Up the Customer VPNs

To set up the customer VPNs:

  1. On the Service tab, create to VPN objects to represent the two customer VPNs.

  2. Link the customer sites to the appropriate VPN objects by dragging and dropping:

    • Link Customer VPN 1 to Site 1, Site 2, and Site 4.

    • Link Customer VPN 2 to Site 1, Site 3, and Site 5.

Implementing the Customer VPNs

To implement the customer VPNs:

  1. Save the changes to the database.

  2. Commit the transaction.

Note:

For example VPN configurations, see the Device Driver guide appropriate for your installation.