3Com Switch 8800 Configuration Guide Chapter 37 BGP/MPLS VPN Configuration37-237.1.1 BGP/MPLS VPN ModelI. BGP/MPLS VPN modelsite 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1CEsite 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1CEsite 2VPN 2CEPEPPEPPPEPEBackbone network ofthe service providersite 1CEsite 2CEVPN1site 3CEVPN2site 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1CEsite 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1CEsite 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1CEsite 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1VPN1site 2VPN 2CEPEPPEPPPEPEsite 1CEsite 2CEVPN1site 3CEVPN2site 1VPN1CEsite 2VPN 2CEPEPPEPPPEPEBackbone network ofthe service providersite 1CEsite 2CEVPN1site 3CEVPN2Figure 37-1 MPLS VPN modelAs shown in Figure 37-1, MPLS VPN model contains three parts: CE, PE and P.z CE (Customer Edge) device: It is a composing part of the customer network, whichis usually connected with the service provider directly through an interface. It maybe a router or a switch which cannot sense the existence of VPN.z PE (Provider Edge) router: It is the Provider Edge router, namely the edge deviceof the provider network, which connects with your CE directly. In MPLS network,PE router processes all the operations for VPN.PE needs to possess MPLS basicforwarding capability.z P (Provider) router: It is the backbone router in the provider network, which is notconnected with CE directly. P router needs to possess MPLS basic forwardingcapability.The classification of CE and PE mainly depends on the range for the management ofthe provider and the customer, and CE and PE are the edges of the managementranges.II. Nested BGP/MPLS VPN modelIn a basic BGP/MPLS VPN model, the PEs are in the network of the service providerand are managed by the service provider.When a VPN user wants to subdivide the VPN into multiple VPNs, the traditionalsolution is to configure these VPNs directly on the PEs of the service provider. Thissolution is easy to implement, but has the following disadvantages: the number of theVPNs carried on PEs may increase rapidly; the operator may have to perform moreoperations when required by a user to adjust the relation between the user's internal