Showing posts with label Data Center. Show all posts
Showing posts with label Data Center. Show all posts

Monday, September 11, 2023

The Data Centre Networking (DCN) Ref. Frame - Expanding MONAF Part 1

Your Data Centre Network (DCN) essentially is a stretch that cuts across SaaS, PaaS, Public Clouds, Hybrid Clouds & the Modern Day Multi-Cloud.

If You look underneath, it's essentially a set of technical capabilities, combined together to deliver business outcomes.

But what should be Your starting point to have a well structured conversation with business as well as the technical folks around DCN ?

Well, if we expand the DCN frame under the MONAF umbrella, it exactly does that to offer You are a very detailed and a firm structure by segmenting those capabilities into well defined and structured layered approach. (Essentially following the famous MECE consulting approach).

Let me know if there is any questions that comes in your mind around DCN that this frame couldn't fit into one of it's layers.


HTH...

A Tech Artist ðŸŽ¨

Tuesday, August 13, 2019

Important Considerations To Get Your Zero Trust/MicroSegmentation Project Right ... A Network Artist's Perspective


Recently came across an interesting blog talking about When & How " Zero Trust " idea surfaced almost a decade ago and some really good approach author has put together when it comes to approach a Zero Trust project.

While the approach seems to be good for most part, I found few small gaps and some additional consideration those needs to well thought through in order to get it right in real world.

So here is quick summary - Feel free to add and correct. Again it's my personal perspective and nothing against the original blog author. 


1. By implementing Zero Trust, you just increased the Network Complexity in significant manner (I'll save P vs. NP analysis for later :)  ) and more importantly Operational Complexity. So Author sort of didn't touch on those important topics I guess. You don't want to end up increasing MTTR and MTTI.


2. It would require a big Cultural Change in the organization to be successful. Similar to NetDevOPS and other fancy stuff.



3. The point 2 and 3 seems to be going opposite to each other. You want every communication to be encrypted/Secure and you want to inspect every thing too. Probably no easy way to do that in real life.



4. Every encrypted communication will add into performance degradation probably. Even considering CPU and Memory are not issues any longer. You run into other fancy issues such as MTU, MSS. Having multiple hops involved for encryption/decryption for Inspection would add significant delay, Expose it to man in middle attack and breaks end to end communication flow. And never underestimate the madness things like NAT can add into this.



5. Convergence becomes a challenge. (Networking Convergence is not = Application Convergence)



6. How this model map to Overlay Networking is interesting area to get head around and think through. (Stitching those policies across Campus, WAN and DCs needs to considered too as most vendor solutions in these spaces are pretty much black boxes)



7. Is your NMS ready to Monitor such Network and Network Constructs ?



8. How do you map this model to Telco Services and SLAs will be worth taking a look



9. For application dependency mappings you need to invest into APMs. A pretty big investment usually I guess and takes good amount of time to not only deploy it but getting it right.



10. My Fav One - Are you solving the right problem to begin with. It's not only about doing right things but more importantly doing things right. :)

11. Impact on Customer Experience. Most organisations don't even want you to touch that area in case there is any impact....even if it's little.



It goes back to basic principle of Computer Science around State, Surface & Optimization. The Author seems to be more focussed on only single dimension of Surface (Though Surface itself has many micro areas to touch upon)



Maybe good time to look at OODA loop for Cyber Security ?



What would the governance model , business case to get funds will look like and how you would measure the success of such project ?


And never underestimate RFC 1925 rule 8 :)

HTH...
Deepak Arora
Evil CCIE

Thursday, November 19, 2015

Finally CCIE Data Centre 2.0 Is Here

Finally Cisco is Bringing ACI into CCIE Data Centre Ver 2.0 Exam. While this will simplify learning curve for ACI Fans, it's good way of indirect marketing as well from Cisco :) ... More ACI trained people should provide enough thrust to ACI market (or so called SDN in some way ) and also should help customers gain confidence from operational standpoint.




http://www.cisco.com/web/learning/certifications/shared/docs/ccie-datacenter-comparison.pdf


HTH...
Deepak Arora
Evil CCIE

Sunday, July 13, 2014

OTV Unicast-Mode Configuration Example Using OTV On Stick Design - OTV Series Part 2

Note: DC1-N7K-2 Is Playing Role Of OTV Unicast Adj. Server


Configuration Template Used In Demo:

Getting Infrastructure Ready
############################

DC1-N7K-1
+++++++++

!
en
!
conf t
!
feature interface-vlan
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
int vlan 200
 ip add 200.0.0.1/24
 no sh
 exit
!
int e1/5
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
int e1/7
 ip add 1.1.1.1/24
 < Enable Routing Of Your Choice >
 no sh
 exit
!
int e1/1
 ip add 10.1.13.3/24
 < Enable Routing Of Your Choice >
 no sh
 exit
!

DC2-N7K-1
+++++++++

!
en
!
conf t
!
feature interface-vlan
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
int vlan 200
 ip add 200.0.0.2/24
 no sh
 exit
!
int e1/12
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
int e1/14
 ip add 2.2.2.1/24
 < Enable Routing Of Your Choice >
 no sh
 exit
!
int e1/10
 ip add 10.1.23.3/24
 < Enable Routing Of Your Choice >
 no sh
 exit
!


DC1-N7K-2
+++++++++

!
en
!
conf t
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
int e1/9
 des "OTV-INTERNAL-INTERFACE"
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
int e1/11
 des "OTV-JOIN-INTERFACE"
 ip add 1.1.1.2/24
 < Enable Routing Of Your Choice >
 no sh
 exit
!


DC2-N7K-2
+++++++++

!
en
!
conf t
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
int e1/18
 des "OTV-INTERNAL-INTERFACE"
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
int e1/11
 des "OTV-JOIN-INTERFACE"
 ip add 2.2.2.2/24
 < Enable Routing Of Your Choice >
 no sh
 exit
!

****************************************

OTV Configurations
##################


DC1-N7K-2
+++++++++

!
en
!
conf t
!
feature otv
!
otv site-vlan 100
 exit
!
otv site-identifier 0x01
!
int overlay 1
 otv join-interface e1/11
 otv adjacency-server unicast-only
 otv extend-vlan 200
 no sh
 exit
!


DC2-N7K-2
+++++++++

!
en
!
conf t
!
feature otv
!
otv site-vlan 100
 exit
!
otv site-identifier 0x02
!
int overlay 1
 otv join-interface e1/20
 otv use-adjacency-server 1.1.1.2 unicast-only
 otv extend-vlan 200
 no sh
 exit
!


Further Readings:

http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/DCI/whitepaper/DCI3_OTV_Intro_WP.pdf

HTH...
Deepak Arora
Evil CCIE

Saturday, July 12, 2014

OTV Unicast-Mode Configuration Example Using OTV In Path Design - OTV Series Part 1

Note:- 100.100.100.100 is Redundant Unicast Adjacency Server In This Configuration Example & DC1-N7K-1 Is Primary Unicast Adj. Server In This Configuration Example.




Configuration Template Used In Demo:

DC1-N7K-2
+++++++++

!
en
!
conf t
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
int e1/9
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
feature interface-vlan
!
int vlan 200
 ip add 200.0.0.1/24
 no sh
 exit
!
end
!


DC2-N7K-2
+++++++++

!
en
!
conf t
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
int e1/18
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
feature interface-vlan
!
int vlan 200
 ip add 200.0.0.2/24
 no sh
 exit
!
end
!


DC1-N7K-1
+++++++++

!
en
!
conf t
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
system jumbo 9216
!
feature otv
!
int e1/5
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
otv site-identifier 0x01
!
otv site-vlan 100
 exit
!
interface overlay 1
 otv join-interface e1/1
 otv adjacency-server unicast-only
 otv use-adjacency-server 10.1.13.3 100.100.100.100 unicast-only
 otv extend-vlan 200
 no sh
 exit
!


DC2-N7K-1
+++++++++

!
en
!
conf t
!
vlan 100
 name OTV-SITE-VLAN
 exit
!
vlan 200
 name OTV-EXTEND-VLAN
 exit
!
system jumbo 9216
!
feature otv
!
int e1/12
 switchport
 switchport mode trunk
 switchport trunk allowed vlan 100,200
 no sh
 exit
!
otv site-identifier 0x02
!
otv site-vlan 100
 exit
!
interface overlay 1
 otv join-interface e1/10
 otv use-adjacency-server 10.1.13.3 100.100.100.100 unicast-only
 otv extend-vlan 200
 no sh
 exit
!


Further Readings:

http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/wan_otv/configuration/xe-3s/wan-otv-xe-3s-book/wan-otv-adj-server.html

http://www.cisco.com/c/en/us/products/collateral/switches/nexus-7000-series-switches/white_paper_c11-644634.html

http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/DCI/5.0/OTVunicast.pdf

https://supportforums.cisco.com/document/64881/troubleshooting-arp-issues-across-otv

https://supportforums.cisco.com/document/65531/otv-silent-host-connectivity-problem

HTH...
Deepak Arora
Evil CCIE

Tuesday, September 17, 2013

Free CCNA Data Center Video Training - @ Cisco Learning Network

In case you guys haven't noticed this. Cisco Learning Network is offering CCNA Data Center Video Training in free. Most of the sessions were ran by Robert Burns which is CCIE Data Center. Below are access details:







https://learningnetwork.cisco.com/docs/DOC-17214

https://learningnetwork.cisco.com/community/learning_center/recorded_tech_seminars

HTH...
Deepak Arora
Evil CCIE

Tuesday, September 10, 2013

Cisco Catalyst 6500/6800 Instant Access - Answer To Cisco Nexus 2000 AKA FEX For Enterprise ?

As Cisco Launched its Next Gen Catalyst 6000 Series as Catalyst 6800 based on One of it's most successful Enterprise switch product Cat 6500's DNA at recent Cisco Live Event At Orlando, There was an advantage that competing Nexus Series had even as solution to Enterprise market was Nexus 2000 AKA FEX, which was offering lots of benefits.

While the roadmap/investment protection of Nexus Family is yet to be clarified by Cisco as they keep coming with newer versions and flavors, the Cat 6500 always seen as very mature platform for Enterprise solutions.

Even to compete further with Nexus family, Cisco Catalyst team came up with a latest solution recently as INSTANT ACCESS (IA).

The benefits Cisco IA offers are some what similar to Nexus 2000/FEX. Though there are few hard requirements like :

> SUP 2T
> VSS CODE
> Switches To be configured in VSS Mode even if it's a standalone chassis
> 6904 10/40Gig line cards to be operated in 10Gig mode only

Further Readings:









HTH...
Deepak Arora
Evil CCIE

Tuesday, July 9, 2013

NPV & NPIV - (Storage Series Part-9)


Node Port Virtualization & Node Port ID Virtualization (NPV & NPIV)
+++++++++++++++++++++++++++++++++++++++++++++++++

- FCID is a 3 byte field with Domain ID as first byte

- Fibre Channel forwarding is based on FCID

- Domain ID is used to identify the Switch in the Fabric's SPT

- It implies that hard limit of switches per fabric is 256

- Some IDs are reserved so only 239 are usable but Qualified limit by OSMs 
   (Original Storage Manufacturer) is approx 50

- NPV fixes the Domain ID problem by removing the need for a switch to participate in Fabric Services
  
  > I.e. no FSPF, FCNS, Zoning etc

- Switches running NPV appears to the rest of the fabric as an end host I.e. a Node Port (N_Port)

- Upstream facing link on the NPV switch is called NP_Port AKA Proxy Node Port


FC Switch/NPV Core Swith (F_Port)----------(NP_Port) NPV Switch (F_Port)----------(N_Port) Initiator


- Switch upstream of NPV switch is the NPV core switch

- NPV Core switch runs NPIV

- NPIV allows multiple FLOGIs and FCID assignments on its F Port facing downstream

======================================================


NPV/NPIV Configuration
+++++++++++++++++++++++

- Enable NPV on NPV Switch (Downstream Switch)

 > feature fcoe
 > feature npv

# After enabling feature NPV,Switch would require reload. Also most of older config 
   including Data Plane will be erased

# On 5500 UP, reallocate ports as FC after first reload which would again require second reload

- Now configure NP Ports on NPV Switch

 > switchport mode np

- Configure F Ports on NPV Switch (Facing Initiator) / NPIV Switch (Facing NPV Switch)

 > switchport mode f

- ENable NPIV on the Core Swith

 > feature npiv

# sh npv flogi-table ( To check Initiators flogi on NPV Switch )

# sh npv external-interface-usage (To check F port to NP Port Mapping on NPV SW to 
   verify static pinning distribution)

- Zoning to be configured on NPIV Switch

HTH...
Deepak Arora
Evil CCIE

Sunday, July 7, 2013

FCIP - (Storage Series Part-8)


Fiber Channel Over IP (FCIP)
++++++++++++++++++++++++++++

- SCSI over FCP over TCP over IP

- Same protocol stack as fiber channel

- Initiator and Targets are still Native FC (or FCOE)

- Used for FC SAN Extension like SAN replication over DCI (Data Center Interconnect), 
   for example running FCIP over OTV will be - SCSI over FCP over TCP over IP over 
   Ethernet over MPLS over GRE over IP over Ethernet

===============================================================

MDS FCIP Gateway Configuration
+++++++++++++++++++++++++++++++

- Configure normal FC to initiators & targets

- Configure IP Connectivity between MDSes

- Configure FCIP Tunnel

- FCIP tunnel now counts as a TE port

_ Normal FC Switching design now applies

- FCIP only supported on MDS

================================================================
FCIP Configuration Example
++++++++++++++++++++++++++

!
feature fcip
!
fcip profile 10
 ip add 1.1.1.1
 exit
!
inteface fcip 12
 use-profile 10
 peer-info ipadd 1.1.1.2
 no shut
 exit
!


sh fcip summary

sh int fcip 12 brief

sh int fcip12 trunk vsan

sh fcip profile

HTH...
Deepak Arora
Evil CCIE

iSCSI - (Storage Series Part-7)


+ iSCSI ( Internet Small Computer System Interface )
####################################################

- Completely separate protocol stack from Fibre channel

- Typically used in small to mid range SANs

- No dedicated SAN switches required which implies no SAN switching knowledge required

- 1/10 GigE iSCSI hardware offload cards available

- End host/Storage Array just runs IP

- Transport supports IP and can be of any IP Transport type like Ethernet, Frame Relay or Token Ring

- MDS is an iSCSI to FC Gateway, so MDS is a translational bridge for Fiber Channel & iSCSI

=====================================

+ iSCSI Gateway Operation
########################

- FC Targets FLOGI to FC Fabric

- iSCSI initiators send Discovery to MDS using Ethernet for example

- MDS applies zoning/Access Lists

- iSCSI initiator things FC target is iSCSI target 

- FC Target thinks iSCSI initiator is a FC initiator

=====================================

+ MDS iSCSI Gateway Configuration Steps
#######################################

- Configure FC to Targets

- Configure IP to Initiators

- Enable iSCSI

- Configure ZONING/ Access Control

- Point Server at MDS's IP Address

=====================================

+ Access Control in iSCSI
##########################

- Access Control can be enforced as Zoning based upon :

> pwwn, fcid, alias

> Initiator's IP Address

> Initiator's iSCSI qualified name (IQN),IQNs are generated automatically by initiator
    but can be configured manually.

> iSCI based virtual target to present LUN based on IQN or IP Address/Subnet

=====================================

sh int fc1/20 trunk vsan

feature iscsi
iscsi enable module 1

int iscsi 1/1
 no sh
inc iscsi 1/2
 no sh

iscsi import target fc

sh iscsi global

sh iscsi initiator

HTH...
Deepak Arora
Evil CCIE

Saturday, June 22, 2013

San Port Channels & Order Of Operation - (Storage Series Part-4)


Sample SAN Port Channel Config
==============================

interface san-port-channel 1 >> In Nexus # in MDS >> interface port-channel
 channel mode active
 switchport mode E
 swithcport trunk allowed vsan 1
 switchport trunk allowed vsan add 10
 switchport speed 4000


!
int x/x
 channel-group 1 > Static port channel
 channel-group 1 foce > To add any link later into functional San Port Channel
 channel-mode active > To enable port channel protocol



Verification
============


sh port-channel summary

sh san-port-channel summary

sh port-channel internal info interface po1

sh interface san-port-channel 1 trunk vsan


=============================================================================


This is order of operations for E/TE:

1. Go to the MDS physical interfaces, shut them down
2. Need to ensure the individual ports are dedicated - 'switchport rate mode dedicated' 

    otherwise will error out on port-channel configuration. Can also configure 
    'switchport mode e'
3. Add ports to port-channel - 'channel-group X'
4. Go to the port-channel, apply the configuration ('switchport mode e' and 

    'switchport rate mode dedicated'.
5. If required, restrict the port-channel with the only the necessary VSANs
6. Add the port-channel to the VSAN database (optional - again depends on requirements)
7. No shut the port-channel and then physical ports

* Make use of 'show interface fc x/y' and verify config - look at: Admin port mode, 

    trunk mode, port mode, port vsan, VSANs allowed (if trunking).
* Ensure that these settings match on both sides (either MDS to N5K or UCS)

For F/TF port-channel, steps that are slightly different from above:

1. Enable MDS features (such as npiv / fport-channel-trunk - if making a TF port-channel)
2. For F ports, can leave in either shared or dedicated mode. Additionally, configure the 

    physical interfaces as 'switchport mode f', otherwise will error out as generally 
    they default to FX ports
3. Instead of 'switchport mode e' on the port-channel, obviously make it an F port

If link fails to come up and using NPV-NPiV, useful to make use of 'show npv status', 

 will also identify if you've forgotten to enable NPiV upstream, etc.

HTH...
Deepak Arora

Evil CCIE

Friday, June 14, 2013

Fiber Channel Fabric Services - (Storage Series Part-3)






Principle Switch (PS) Election
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

# Election starts when E port between two or more switches comes up

# Assign Domain IDs automatically but can be assigned manually as well 

   with - ( fcdomain domain 0x51 vsan )

- Preferred > Switch asks principal switch if it can use static domain id, if PS 

   says "Yes" than fine, If "NO" it uses Domain ID given by PS

- Static > Same theory as above but if PS says NO, the switch gets isolated from the FC network

Election based on
++++++++++++

- Lowest priority ( fcdomain priority 1 vsan 1)
- Lowest WWN ( sh wwn switch)

* sh fcdomain (vsan)
* sh fcdomain domain-list (vsan)


FC Domain Services Restart
+++++++++++++++++++

- Graceful - fcdomain restart vsan 1

- Forced - fcdomain restart disruptive vsan 1 < Hidden command

Everytime we make changes into FC Services, the services must be restarted

==============================================================

# Note: One copy of FC services runs on per VSAN basis which means One

  domain id can be used for multiple VSANs but it doesn't affect the design. 
  It's more like using one OSPF router id for multiple ospf processes. But each 
  process populates a separate Datbase which is completely unrelated from each other.

==============================================================

Fabric Shortest Path First (FSPF)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

- Used to build an SPT through the fabric

- Domain ID is the Node ID in the SPT calculation

- FSPF runs automatically on per VSAN basis

- FSPF perameters can be manually modified in global config mode with 

   "fspf config vsan 1" or on interface level like
   " fspf [cost|dead-interval|hello-interval|passive|retransmit-interval]


Verification
++++++++++++

- sh fspf [database|interface] [vsan]

- sh fcroute unicast vsan

 
==============================================================


Fabric Login (FLOGI)
^^^^^^^^^^^^^^^^^^^^

- All initiators and targets must FLOGI before sending any data into the fabric

- Verification - sh flogi database vsan

- No configuration required

- No FLOGI indicates a basic link-level negotiation problem

- The FLOGI database is local to switch which means only directly connected devices 

    will show up, It's FCNS job to   progpogate this information to entire fabric


==============================================================

 
Fiber Channel Name Services
^^^^^^^^^^^^^^^^^^^^^^^^^^^

- FCNS (AKA Directory Services) keeps a mapping of FCIDs to WWPNs

- Analogous to IP ARP Cache in ethernet

- End devices register with the FCNS after FLOGI

- sh fcns database

- If Node did FLOGI but is not in everyone's FCNS, it indicates the Fabric is broken

> E.g. VSAN is isolated, EISL allowed list is wrong etc

Wednesday, March 20, 2013

MPLS L2 VPN - Ethernet To Ethernet/PPP To PPP ATOM: It's All About Pseudo-Wires






pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls <
Choosing MPLS Here Basically Suggests that we are using AToM Not L2TPv3
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 2.2.2.2 12 pw-class ATOM_ETH_TO_ETH
!


R2's XCONNECT Configuration

pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls

!

interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 1.1.1.1 12 pw-class ATOM_ETH_TO_ETH

!

Verification











PPP To PPP Variation







R1
===
!
!
! Last configuration change at 17:46:55 UTC Wed Mar 20 2013
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
!
hostname R1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip source-route
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
no ipv6 cef
!
!
multilink bundle-name authenticated
mpls label protocol ldp
!
!
!
!
ip tcp synwait-time 5
pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls
!
!
!
!
!
!
!
interface Loopback0
 ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet0/0
 no ip address
 shutdown
 duplex half
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 2.2.2.2 12 pw-class ATOM_ETH_TO_ETH
!
interface FastEthernet1/1
 ip address 13.0.0.1 255.255.255.0
 ip router isis 1
 speed auto
 duplex auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0001.00
 is-type level-2-only
 passive-interface Loopback0
!
no ip http server
no ip http secure-server
!
!
!
no cdp run
!
!
!
control-plane
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line vty 0 4
 login
!
end
 
R2
==

!
!
! Last configuration change at 17:48:05 UTC Wed Mar 20 2013
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
!
hostname R2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip source-route
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
no ipv6 cef
!
!
multilink bundle-name authenticated
mpls label protocol ldp
!
!
!
!
ip tcp synwait-time 5
pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls
!
!
!
!
!
!
!
interface Loopback0
 ip address 2.2.2.2 255.255.255.255
!
interface FastEthernet0/0
 no ip address
 shutdown
 duplex half
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 1.1.1.1 12 pw-class ATOM_ETH_TO_ETH
!
interface FastEthernet1/1
 ip address 24.0.0.2 255.255.255.0
 ip router isis 1
 speed auto
 duplex auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0002.00
 is-type level-2-only
 passive-interface Loopback0
!
no ip http server
no ip http secure-server
!
!
!
no cdp run
!
!
!
control-plane
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line vty 0 4
 login
!
end
 

R3
==
 !
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R3
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 3.3.3.3 255.255.255.255
 ip router isis 1
!
interface FastEthernet0/0
 ip address 34.0.0.3 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 13.0.0.3 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0003.00
 is-type level-2-only
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 
R4
==
 !
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R4
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 4.4.4.4 255.255.255.255
!
interface FastEthernet0/0
 ip address 24.0.0.4 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 34.0.0.4 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0004.00
 is-type level-2-only
 passive-interface Loopback0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 
R5
==

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R5
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 5.5.5.5 255.255.255.255
!
interface FastEthernet0/0
 ip address 150.0.0.5 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 5.5.5.5 0.0.0.0 area 0
 network 150.0.0.5 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 

R6
==

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R6
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 6.6.6.6 255.255.255.255
!
interface FastEthernet0/0
 ip address 150.0.0.6 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 6.6.6.6 0.0.0.0 area 0
 network 150.0.0.6 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 

HTH...
Deepak Arora
Evil CCIE