Monday, October 18, 2010

INE Vol 1 - Lab 14 - Inter AS Back to Back VRFs

Re-doing this lab, I used different RDs and Route-Targets in the 2 different ASes and I wasn't able to get connectivity. My thoughts were that the ASes were independent of each other being that they are doing the PE-CE transition into IP routing to exchange routes.

When I reconfigured the VRFs to be uniform through out the 2 the ASes, everything worked.


Tuesday, September 7, 2010

OL - MPLS Label filtering

Notes:

Atleast 2 ways to accomplish label filtering, meaning appending label to prefix. Outbound filtering and Inbound filtering.

Configs:
Outbound Filtering
no mpls ldp advertise-labels
mpls ldp advertise-labels for 51 to 50

Access List 51 is ACL for the prefixes and ACL 50 is the ACL for the LDP neighbor

Inbound Filtering
mpls ldp neighbor 1.1.1.1 labels accept 99

Access List 99 is the ACL for the prefixes

Thursday, September 2, 2010

OL - L2TPv3

Notes:

The difference between AToM and L2TP is that AToM is over an MPLS network whereas L2TP is over straight IP.

The concepts are very similar. The CE facing interfaces on the PEs need to create a VC across IP (for L2TP or MPLS for AToM). This requires pseudowires to make that connection.

With both AToM, the use of LDP neighbor/peer of the remote PE is used but in L2TP, under the pseudowire-class, you need to define a ip local inteface loop 0. And then use the peer's loopback as the xconnect's peer.

Config:

R3 - PE
l2tp-class L2TP
authentication
password 7 047822352C0E
!
pseudowire-class L2TP
encapsulation l2tpv3
protocol l2tpv3 L2TP
ip local interface Loopback0
!
!
interface FastEthernet1/1
no ip address
duplex auto
speed auto
no cdp enable
no clns route-cache
xconnect 4.4.4.4 12 pw-class L2TP

OL - ATOM

Notes:

I've created my own lab to test out the different types of Layer 2 protocols I can transport over MPLS.

There are, at a basic level, 2 parts to enabling AToM. First, create a pseudowire-class and second, create the VC via an xconnect statement under the CE facing interface on the PE.

Of course, the prerequisite for this to work is that MPLS is enabled throughout the core network.

Also, note that to make life easier use 'mpls ldp router-id loop 0 force'. You have to designate the other PE as peer in xconnect which will be the ldp router id.

Layer 2 protocols that can be transported are EoMPLS, FRoMPLS, PPPoMPLS, HDLCoMPLS, and ATMoMPLS (can't emulate in dynamips, as the PA-A1 doesn't support it).

Config:

R3 - PE
mpls ldp router-id Loopback0 force
mpls label protocol ldp
pseudowire-class EOMPLS
encapsulation mpls
!
interface Loopback0
ip address 3.3.3.3 255.255.255.255
no clns route-cache
!
interface FastEthernet1/0
ip address 150.1.35.3 255.255.255.0
duplex auto
speed auto
mpls ip
no clns route-cache
!
interface FastEthernet1/1.100
description EoMPLS
encapsulation dot1Q 100
no cdp enable
xconnect 4.4.4.4 100 pw-class EOMPLS
!
interface Serial2/0
description HDLCoMPLS
no ip address
serial restart-delay 0
no cdp enable
no clns route-cache
xconnect 4.4.4.4 67 pw-class EOMPLS
!
interface Serial2/1
description FRoMPLS
no ip address
serial restart-delay 0
no cdp enable
no clns route-cache
xconnect 4.4.4.4 607 pw-class EOMPLS
!
interface FastEthernet3/0
ip address 150.1.34.3 255.255.255.0
shutdown
duplex auto
speed auto
mpls ip
no clns route-cache
!

CE config
The CE's are generally configured like back to back CE to CE connections with nothing but a pseudo wire connecting the two. * Remember for FRoMPLS though, you'll want once side to act as Frame switch and that interface to be DCE.

Thursday, August 26, 2010

OL - ISIS

Notes:

I've been working through ISIS since I'm not very familiar with it. ISIS by default creates Level 1 (intra area) and Level 2 (inter area) adjacencies with other ISIS routers. You can limit the type on a per interface level ['isis circuit-type'] or on a per process level ['is-type']. Same with authentication, you can do on s per link or on a per process level and authentication supports clear text as well as MD5 hash.

Level 2 is considered the 'backbone' area as all other level1 router need to connect and transit a level 2 area to get to another level 1 router. Level 1-2 routers automatically redistribute level1 prefixes into level 2. In order to redistribute Level 2 into Level 1 you need to configure 'redistribute isis ip level-2 into level-1 route-map/distribute-list'. The route-map doesn't need to contain any entries, it just needs to exist.

Default-information originate by default will originate only a L2 default, in order to generate and L1 default create a route-map, set level level-1 and then append the route map to the default-information originate.

Metrics, without metric-style wide configured, isis defaults to max metric of 63, enabling wide metrics lets you go far beyond that. The default metric of any interface is 10 and can be changed.

Priority, the default priority is 64 with the max being 127. Priority is used to determine who will be the DIS on a multi access segment like ethernet.

Summary-address, can summarize groups of addresses for a given level. The metric used to advertise the summary is the smallest metric of all the more specific routes.



Monday, August 23, 2010

OL - PPPoE

Notes:

PPPoE can be configured in a many different ways. One of the simplest is demonstrated here. R1 is the client and R2 is the server.

Summary Steps:
Order of Operation is important!

For the client:
1. under the FastE interface, enable pppoe 'pppoe-enable'
2. create a dialer interface, assign an IP, encaps PPP, and associate the this interface to a dialer pool
3. under the FastE interface, associate this interface to the dialer pool

For the server:
1. enable vpdn 'vpdn enable', create a vpdn-group 'vpdn-group CISCO', under the group 'accept-dailin' to make it a server, designate a virtual-template 'virtual-template 1' and configure the protocol to pppoe 'protocol pppoe'
2. configure the virtual-template with an IP (note the default encaps for the Virtual template is ppp)
3. under the FastE interface, enable pppoe.
Config:
R1
interface FastEthernet1/0
no ip address
duplex auto
speed auto
pppoe enable group global
pppoe-client dial-pool-number 1
!
interface Dialer1
ip address 150.1.12.1 255.255.255.0
encapsulation ppp
dialer pool 1
dialer idle-timeout 0
dialer persistent

R2
vpdn enable
!
vpdn-group CISCO
! Default L2TP VPDN group
accept-dialin
protocol pppoe
virtual-template 1
!
interface FastEthernet1/0
no ip address
duplex auto
speed auto
pppoe enable group global
!
interface Virtual-Template1
ip address 150.1.12.2 255.255.255.0
!

For DocCD reference, under 12.2 configuration guides, Wide-Area Networking, Configuring Broadband Access... [DocCD Ref]

Sunday, August 22, 2010

INE Vol 1 multicast - Lab 12 - Multicast BGP

Notes:

Nothing really to difficult here. This lab uses AFI and SAFI for ipv4 multicast.

Some things to note:
1. On the router connecting to the receiver, disable ip mroute-cache.
2. Disabling Fast Switching via the "no ip route-cache" command helps ensure that the packets are process switched.