本文說明了使用 Azure ExpressRoute 時,Cisco IOS-XE、Juniper MX 系列及 Arista 路由器的介面與路由設定範例。
重要
本文中的範例僅供參考。 請與廠商的銷售/技術小組和網路小組合作,尋找適當的設定以符合您的需求。 Microsoft不支援與此頁面所列的設定相關的問題。 如有支援問題,請聯絡您的裝置廠商。
路由器介面上的 MTU 和 TCP MSS 設定
ExpressRoute 介面的傳輸單元最大值 (MTU) 是 1500,這是路由器上乙太網路介面的典型預設 MTU。 除非您的路由器預設有不同的 MTU,否則沒有必要在路由器介面上指定值。
與 Azure VPN 閘道不同,ExpressRoute 電路不需要指定 TCP 最大區段大小(MSS)。
本文所列的路由器組態範例適用於所有對等互連類型。 如需路由的詳細資訊,請檢閱 ExpressRoute 對等互連和 ExpressRoute 路由需求。
您連接到 Microsoft 的每一台路由器,都需要為每個對等互連設定一個子介面。 透過 VLAN ID 或一對堆疊的 VLAN ID 以及 IP 位址來識別子介面。
本節中的範例適用於任何執行 IOS-XE 作業系統系列的路由器。
Dot1Q 介面定義
此範例定義了一個具有單一 VLAN ID 的子介面。 在每個對等互連中 VLAN ID 都是唯一的。 IPv4 位址的最後一個八位元一律是奇數。
interface GigabitEthernet<Interface_Number>.<Number>
encapsulation dot1Q <VLAN_ID>
ip address <IPv4_Address><Subnet_Mask>
QinQ 介面定義
此範例定義了一個具有兩個 VLAN ID 的子介面。 外層 VLAN ID(s-tag)若有使用,在所有對等互連中皆保持相同。 對於每個對等互連,內部 VLAN ID(c-tag)都是唯一的。 IPv4 位址的最後一個八位元一律是奇數。
interface GigabitEthernet<Interface_Number>.<Number>
encapsulation dot1Q <s-tag> second-dot1Q <c-tag>
ip address <IPv4_Address><Subnet_Mask>
本節的範例適用於任何 Arista 路由器。
Dot1Q 介面定義
此範例定義了一個具有單一 VLAN ID 的子介面。 在每個對等互連中 VLAN ID 都是唯一的。 IPv4 位址的最後一個八位元一律是奇數。
interface Ethernet<Interface_Number>.<Number>
encapsulation dot1Q vlan <VLAN_ID>
ip address <IPv4_Address>/<Subnet_Mask_Length>
QinQ 介面定義
此範例定義了一個具有兩個 VLAN ID 的子介面。 外層 VLAN ID(s-tag)若有使用,在所有對等互連中皆保持相同。 對於每個對等互連,內部 VLAN ID(c-tag)都是唯一的。 IPv4 位址的最後一個八位元一律是奇數。
interface Ethernet<Interface_Number>.<Number>
encapsulation dot1Q vlan <s-tag> inner <c-tag>
ip address <IPv4_Address>/<Subnet_Mask_Length>
本節中的範例適用於所有的 Juniper MX 系列路由器。
Dot1Q 介面定義
此範例定義了一個具有單一 VLAN ID 的子介面。 在每個對等互連中 VLAN ID 都是唯一的。 IPv4 位址的最後一個八位元一律是奇數。
interfaces {
vlan-tagging;
<Interface_Number> {
unit <Number> {
vlan-id <VLAN_ID>;
family inet {
address <IPv4_Address/Subnet_Mask>;
}
}
}
}
QinQ 介面定義
此範例定義了一個具有兩個 VLAN ID 的子介面。 外層 VLAN ID(s-tag)若有使用,在所有對等互連中皆保持相同。 對於每個對等互連,內部 VLAN ID(c-tag)都是唯一的。 IPv4 位址的最後一個八位元一律是奇數。
interfaces {
<Interface_Number> {
flexible-vlan-tagging;
unit <Number> {
vlan-tags outer <S-tag> inner <C-tag>;
family inet {
address <IPv4_Address/Subnet_Mask>;
}
}
}
}
設定 eBGP 工作階段
您必須針對每個對等互連,與 Microsoft 建立 BGP 工作階段。 使用以下範例建立 BGP 工作階段。 如果你用來做子介面的 IPv4 位址是 a.b.c.d,那麼 BGP 鄰居(Microsoft)的 IP 位址就是 a.b.c.d+1。 BGP 芳鄰的 IPv4 位址的最後一個八位元一律為偶數。
router bgp <Customer_ASN>
bgp log-neighbor-changes
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
neighbor <IP#2_used_by_Azure> activate
exit-address-family
!
router bgp <Customer_ASN>
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
neighbor <IP#2_used_by_Azure> activate
!
routing-options {
autonomous-system <Customer_ASN>;
}
protocols {
bgp {
group <Group_Name> {
peer-as 12076;
neighbor <IP#2_used_by_Azure>;
}
}
}
將前置詞設定為透過 BGP 工作階段公告
請使用下列範例,設定路由器將選取的前置詞公告給 Microsoft。
router bgp <Customer_ASN>
bgp log-neighbor-changes
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
network <Prefix_to_be_advertised> mask <Subnet_mask>
neighbor <IP#2_used_by_Azure> activate
exit-address-family
!
router bgp <Customer_ASN>
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
network <Prefix_to_be_advertised>/<Subnet_mask_length>
neighbor <IP#2_used_by_Azure> activate
!
policy-options {
policy-statement <Policy_Name> {
term 1 {
from protocol OSPF;
route-filter;
<Prefix_to_be_advertised/Subnet_Mask> exact;
then {
accept;
}
}
}
}
protocols {
bgp {
group <Group_Name> {
export <Policy_Name>;
peer-as 12076;
neighbor <IP#2_used_by_Azure>;
}
}
}
路線圖
請使用路由映射和前綴清單,篩選傳播到您的網路中的前綴。 請參考以下範例,並確保你已設定適當的前綴列表。
router bgp <Customer_ASN>
bgp log-neighbor-changes
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
network <Prefix_to_be_advertised> mask <Subnet_mask>
neighbor <IP#2_used_by_Azure> activate
neighbor <IP#2_used_by_Azure> route-map <MS_Prefixes_Inbound> in
exit-address-family
!
route-map <MS_Prefixes_Inbound> permit 10
match ip address prefix-list <MS_Prefixes>
!
router bgp <Customer_ASN>
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
network <Prefix_to_be_advertised>/<Subnet_mask_length>
neighbor <IP#2_used_by_Azure> activate
neighbor <IP#2_used_by_Azure> route-map <MS_Prefixes_Inbound> in
!
route-map <MS_Prefixes_Inbound> permit 10
match ip address prefix-list <MS_Prefixes>
!
policy-options {
prefix-list MS_Prefixes {
<IP_Prefix_1/Subnet_Mask>;
<IP_Prefix_2/Subnet_Mask>;
}
policy-statement <MS_Prefixes_Inbound> {
term 1 {
from {
prefix-list MS_Prefixes;
}
then {
accept;
}
}
}
}
protocols {
bgp {
group <Group_Name> {
export <Policy_Name>;
import <MS_Prefixes_Inbound>;
peer-as 12076;
neighbor <IP#2_used_by_Azure>;
}
}
}
您會在兩處設定 BFD:一個在介面層級,另一個在 BGP 層級。 此範例使用 QinQ 介面。
interface GigabitEthernet<Interface_Number>.<Number>
bfd interval 300 min_rx 300 multiplier 3
encapsulation dot1Q <s-tag> second-dot1Q <c-tag>
ip address <IPv4_Address><Subnet_Mask>
router bgp <Customer_ASN>
bgp log-neighbor-changes
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
neighbor <IP#2_used_by_Azure> activate
neighbor <IP#2_used_by_Azure> fall-over bfd
exit-address-family
!
您會在兩處設定 BFD:一個在介面層級,另一個在 BGP 層級。 此範例使用 QinQ 介面。
interface Ethernet<Interface_Number>.<Number>
bfd interval 300 min-rx 300 multiplier 3
encapsulation dot1Q vlan <s-tag> inner <c-tag>
ip address <IPv4_Address>/<Subnet_Mask_Length>
router bgp <Customer_ASN>
neighbor <IP#2_used_by_Azure> remote-as 12076
!
address-family ipv4
network <Prefix_to_be_advertised>/<Subnet_mask_length>
neighbor <IP#2_used_by_Azure> activate
neighbor <IP#2_used_by_Azure> bfd
!
僅在通訊協定 BGP 區段下設定 BFD。
protocols {
bgp {
group <Group_Name> {
peer-as 12076;
neighbor <IP#2_used_by_Azure>;
bfd-liveness-detection {
minimum-interval 300;
multiplier 3;
}
}
}
}
針對 MACSec 設定,連線關聯金鑰 (CAK) 和連線關聯金鑰名稱 (CKN) 必須與透過 PowerShell 命令設定的值相符。
本文未包含 Cisco IOS-XE 的 MACSec 範例。 請參閱 Cisco 關於 IOS-XE 路由器 MACSec 設定的文件。
mac security
profile <Profile_Name>
cipher <Cipher_Name E.g. aes256-gcm>
key <Connectivity_Association_Key_Name> 7 <Connectivity_Association_Key>
key derivation padding append
sci
!
!
interface Ethernet<Interface_Number>
mac security profile <Profile_Name>
security {
macsec {
connectivity-association <Connectivity_Association_Name> {
cipher-suite gcm-aes-xpn-128;
security-mode static-cak;
pre-shared-key {
ckn <Connectivity_Association_Key_Name>;
cak <Connectivity_Association_Key>; ## SECRET-DATA
}
}
interfaces {
<Interface_Number> {
connectivity-association <Connectivity_Association_Name>;
}
}
}
}
下一步