Multi-VPN-instance can be configured for routing protocols on a CE to isolate different types of services on a LAN.
VPN services are becoming increasingly refined and the demand for VPN service security is growing. Carriers must isolate different types of VPN services on networks to meet this demand. The traditional BGP/MPLS VPN technology isolates VPN services by deploying one CE for each VPN, which is expensive and complicates network deployment. If multiple VPNs use the same CE to access upper-layer devices, these VPNs share the same routing and forwarding table, and data security for these VPNs cannot be ensured. The MCE technology addresses the conflict between network costs and data security problems caused by multiple VPNs sharing the same CE.
Before configuring an MCE, complete the following tasks:
Configure a VPN instance for each service on the MCE and the PE to which the MCE is connected (for details, see Configuring a VPN Instance)
Configure link and network layer protocols for LAN interfaces, and connect the LAN interface for each type of service to the MCE.
Bind the MCE's interfaces and the PE's interfaces connecting to the MCE to VPN instances (for details, see Binding Interfaces to a VPN Instance), and configure IP addresses for these interfaces.