Ejercicio: Virtualización de Red
Novena parte de la serie. La red del edificio tiene monitoreo y troubleshooting. Ahora aplicas virtualización de red para segmentar el tráfico de Ventas e IT con VRF, y conectas una red remota con un túnel GRE.
graph LR
subgraph VRF_VENTAS["VRF: Ventas"]
PC1[PC Ventas<br>192.168.10.10]
end
subgraph VRF_IT["VRF: IT"]
PC2[PC IT<br>10.0.0.10]
end
R1[R1<br>dos VRFs] --> PC1
R1 --> PC2
R1 ===|"GRE Tunnel<br>172.16.0.1 ↔ 172.16.0.2"| RREMOTE[R Remoto]
RREMOTE --- LANREMOTA[LAN Remota<br>10.10.10.0/24]
Requisitos
Section titled “Requisitos”- Red completa del ejercicio anterior.
- Un segundo router (RREMOTE) con enlace hacia R1.
Objetivos
Section titled “Objetivos”- Configurar VRF en R1 para separar Ventas e IT.
- Mover las subinterfaces de Ventas e IT a sus VRFs.
- Configurar un túnel GRE entre R1 y RREMOTE.
- Verificar que las VRFs están aisladas y el túnel funciona.
1. Crear las VRFs en R1
Section titled “1. Crear las VRFs en R1”R1(config)# vrf definition VENTASR1(config-vrf)# rd 65000:10R1(config-vrf)# address-family ipv4R1(config-vrf-af)# route-target export 65000:10R1(config-vrf-af)# route-target import 65000:10R1(config-vrf-af)# exitR1(config-vrf)# exit
R1(config)# vrf definition ITR1(config-vrf)# rd 65000:20R1(config-vrf)# address-family ipv4R1(config-vrf-af)# route-target export 65000:20R1(config-vrf-af)# route-target import 65000:20R1(config-vrf-af)# exitR1(config-vrf)# exit2. Asignar interfaces a las VRFs
Section titled “2. Asignar interfaces a las VRFs”R1(config)# interface GigabitEthernet0/0.10R1(config-subif)# vrf forwarding VENTASR1(config-subif)# ip address 192.168.10.1 255.255.255.0
R1(config)# interface GigabitEthernet0/0.20R1(config-subif)# vrf forwarding ITR1(config-subif)# ip address 10.0.0.1 255.255.255.0Nota: al asignar una interfaz a una VRF, se borra la IP previa. Reasignar la IP después del comando
vrf forwarding.
3. Crear VRF para voz (opcional, separada)
Section titled “3. Crear VRF para voz (opcional, separada)”R1(config)# vrf definition VOZR1(config-vrf)# rd 65000:30R1(config-vrf)# address-family ipv4R1(config-vrf-af)# exit
R1(config)# interface GigabitEthernet0/0.30R1(config-subif)# vrf forwarding VOZR1(config-subif)# ip address 192.168.30.1 255.255.255.04. Verificar aislamiento VRF
Section titled “4. Verificar aislamiento VRF”R1# show vrfR1# show ip route vrf VENTASR1# show ip route vrf ITR1# ping vrf VENTAS 192.168.10.10R1# ping vrf IT 10.0.0.10Las PCs de Ventas no deben poder hacer ping a PCs de IT (aislamiento).
5. Configurar túnel GRE entre R1 y RREMOTE
Section titled “5. Configurar túnel GRE entre R1 y RREMOTE”En R1:
R1(config)# interface Tunnel0R1(config-if)# ip address 172.16.0.1 255.255.255.252R1(config-if)# tunnel source 200.200.200.1R1(config-if)# tunnel destination 200.200.200.2R1(config-if)# tunnel mode gre ipR1(config-if)# exit
R1(config)# ip route 10.10.10.0 255.255.255.0 172.16.0.2En RREMOTE:
RREMOTE(config)# interface Tunnel0RREMOTE(config-if)# ip address 172.16.0.2 255.255.255.252RREMOTE(config-if)# tunnel source 200.200.200.2RREMOTE(config-if)# tunnel destination 200.200.200.1RREMOTE(config-if)# tunnel mode gre ipRREMOTE(config-if)# exit
RREMOTE(config)# ip route 192.168.10.0 255.255.255.0 172.16.0.1RREMOTE(config)# ip route 10.0.0.0 255.255.255.0 172.16.0.16. Verificar túnel GRE
Section titled “6. Verificar túnel GRE”R1# show interface Tunnel0 # Estado up/upR1# show tunnel interface Tunnel0 # Detalle del túnelR1# ping 10.10.10.10 # Ping a LAN remotaR1# traceroute 10.10.10.10 # Ver hops a través del túnel7. Verificación de extremo a extremo
Section titled “7. Verificación de extremo a extremo”R1# show vrf # 3 VRFs activasR1# show ip route vrf VENTAS # Rutas de VentasR1# show ip route vrf IT # Rutas de ITR1# ping vrf VENTAS 192.168.10.10 # Ping dentro de VRFR1# show interface Tunnel0 # Túnel GRE activoR1# ping 10.10.10.10 # LAN remota accesibleResultado esperado
Section titled “Resultado esperado”Al completar este ejercicio:
- Ventas e IT están aisladas en VRFs separadas (no pueden comunicarse).
- El túnel GRE conecta la red del edificio con la LAN remota.
- La voz y datos siguen funcionando dentro de sus VRFs.
- La red del edificio ahora soporta virtualización y conectividad remota.