Showing posts with label Ethernet. Show all posts
Showing posts with label Ethernet. Show all posts

Wednesday, March 20, 2013

MPLS L2 VPN - Ethernet To Ethernet/PPP To PPP ATOM: It's All About Pseudo-Wires






pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls <
Choosing MPLS Here Basically Suggests that we are using AToM Not L2TPv3
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 2.2.2.2 12 pw-class ATOM_ETH_TO_ETH
!


R2's XCONNECT Configuration

pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls

!

interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 1.1.1.1 12 pw-class ATOM_ETH_TO_ETH

!

Verification











PPP To PPP Variation







R1
===
!
!
! Last configuration change at 17:46:55 UTC Wed Mar 20 2013
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
!
hostname R1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip source-route
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
no ipv6 cef
!
!
multilink bundle-name authenticated
mpls label protocol ldp
!
!
!
!
ip tcp synwait-time 5
pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls
!
!
!
!
!
!
!
interface Loopback0
 ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet0/0
 no ip address
 shutdown
 duplex half
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 2.2.2.2 12 pw-class ATOM_ETH_TO_ETH
!
interface FastEthernet1/1
 ip address 13.0.0.1 255.255.255.0
 ip router isis 1
 speed auto
 duplex auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0001.00
 is-type level-2-only
 passive-interface Loopback0
!
no ip http server
no ip http secure-server
!
!
!
no cdp run
!
!
!
control-plane
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line vty 0 4
 login
!
end
 
R2
==

!
!
! Last configuration change at 17:48:05 UTC Wed Mar 20 2013
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
!
hostname R2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip source-route
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
no ipv6 cef
!
!
multilink bundle-name authenticated
mpls label protocol ldp
!
!
!
!
ip tcp synwait-time 5
pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls
!
!
!
!
!
!
!
interface Loopback0
 ip address 2.2.2.2 255.255.255.255
!
interface FastEthernet0/0
 no ip address
 shutdown
 duplex half
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 1.1.1.1 12 pw-class ATOM_ETH_TO_ETH
!
interface FastEthernet1/1
 ip address 24.0.0.2 255.255.255.0
 ip router isis 1
 speed auto
 duplex auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0002.00
 is-type level-2-only
 passive-interface Loopback0
!
no ip http server
no ip http secure-server
!
!
!
no cdp run
!
!
!
control-plane
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line vty 0 4
 login
!
end
 

R3
==
 !
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R3
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 3.3.3.3 255.255.255.255
 ip router isis 1
!
interface FastEthernet0/0
 ip address 34.0.0.3 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 13.0.0.3 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0003.00
 is-type level-2-only
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 
R4
==
 !
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R4
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 4.4.4.4 255.255.255.255
!
interface FastEthernet0/0
 ip address 24.0.0.4 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 34.0.0.4 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0004.00
 is-type level-2-only
 passive-interface Loopback0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 
R5
==

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R5
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 5.5.5.5 255.255.255.255
!
interface FastEthernet0/0
 ip address 150.0.0.5 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 5.5.5.5 0.0.0.0 area 0
 network 150.0.0.5 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 

R6
==

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R6
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 6.6.6.6 255.255.255.255
!
interface FastEthernet0/0
 ip address 150.0.0.6 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 6.6.6.6 0.0.0.0 area 0
 network 150.0.0.6 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 

HTH...
Deepak Arora
Evil CCIE

Monday, October 29, 2012

Address Resolution Protocol - ARP







Often I have seen CCNA Candidates struggling with understanding ARP & Proxy ARP. So I always recommend such guys two things :

1. Read through the following document:

http://www.cisco.com/en/US/docs/ios/ipaddr/configuration/guide/iad_cfg_arp_ps6350_TSD_Products_Configuration_Guide_Chapter.html

2. Lab up ARP and Inverse ARP on real equipments and verify the operation using debugs.


HTH...
Deepak Arora
Evil CCIE

Friday, December 10, 2010

Native VLAN Horror - Can you solve the puzzle ?

Around 2 years back there was section called "Resources" on NMC Website. Actually plenty of good documents were out there on different R&S blueprint topics. Some of them were my favorite one. They created some scenarios based on few simple things like "Native VLAN", "SPAN/RSPAN" etc which most of you might be thinking about...ehhh...that's easy stuff and I can do even in sleep :-)


But there is always major difference between "knowing about things" Vs "Knowing things inside out". Though it's quite a lot of hard work one needs to do to achieve "Perfection" but still it's doable.


Without saying anything further let me share on of those interesting scenarios to challenge your understandings :-)


Or what Scott Morris call is "abusing people technically and in exiting new ways" hehehe :-)


Here you go:



HTH...
Deepak Arora
CCIE - 0::0/0 Null0

Tuesday, November 16, 2010

Auto-Negotiation ON vs OFF - Welcome Back To Ethernet World

Auto negotiation is one of those thing which comes back to every network engineer at some point. There is always so much talk about idea  that - if we should keep auto-negotiation "ON" or should we turn it "OFF" and hard-cord the "Duplex" & "Speed" settings.

There are always two schools of thoughts about this and you may choose which one you like more. 


So idea boils down to which school you prefer. 

But...

Here are some of drawbacks or I should say list of things which you won't be able to figure out easily or will not work at all if you turn off auto-negotiation over interface:

1. Performance Issue
2.
Link failures
3. 
Pause Frames or Flow Control
4.
Bad Cable Problem
5.
Link Partner Capabilities
6. Auto-MDIX will not work

For more:

http://en.wikipedia.org/wiki/Autonegotiation 

http://etherealmind.com/ethernet-autonegotiation-works-why-how-standard-should-be-set/

http://www.sun.com/blueprints/0704/817-7526.pdf

http://www.cisco.com/en/US/docs/internetworking/troubleshooting/guide/tr1923.html

http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00800a7af0.shtml 

http://blog.ine.com/2008/07/08/802-3x-flow-control/ 
 
HTH...
Deepak  Arora

Friday, October 16, 2009

PROXY ARP - In General

The command no ip proxy-arp was one of those things which I saw in IOS configs and wasn’t to sure what proxy arp is used for or why it exists. Proxy ARP is where a router will respond on behalf of another device, it was used heavily in networks before the days of DHCP & default gateways where a host would ARP for an address that wasn’t on its subnet (modern networks just send the packets to the default gateway instead of arping for the address), the router on the local network would then act as a “proxy” and respond on behalf of the device outside of the subnet.

Proxy ARP isn’t used if hosts are set with default gateways or have routing intelligence, setting a default gateway instead of using proxy ARP is a much better option. Using Proxy ARP instead of a default gateway results in higher ARP traffic & the ARP tables of the hosts get very large as they maintain an IP/MAC binding for every single address the communicate with.

Monday, May 18, 2009

Some more ARP detials

Gratituos arp is nothing but a arp packets which checks and validates the ip address given to the system is not given for any other system . this is done by sending a arp packet which contains its own ip address , so if a duplicate system is present it responds to it so that it can be corrected

Proxy arp if we know about router converting or routing different netwoks its the same , the router gives its own mac address of the interface without forewarding the broadcast as arp is based on broadcast

arp headers dosent contain any info on protocols such as tcp udp and ip headers so it basically cannot be read by devices which looks for ip headers

Tuesday, February 24, 2009

Local Proxy ARP - hmmm it's not ordinary ip proxy ARP

The local proxy ARP feature allows the Multilayer Switching Feature Card (MSFC) to respond to ARP requests for IP addresses within a subnet where normally no routing is required. With the local proxy ARP feature enabled, the MSFC responds to all ARP requests for IP addresses within the subnet and forwards all traffic between hosts in the subnet. Use this feature only on subnets where hosts are intentionally prevented from communicating directly to the Catalyst 6500 series switch on which they are connected.
Before the local proxy ARP feature can be used, the IP proxy ARP feature must be enabled. The IP proxy ARP feature is enabled by default.
Internet Control Message Protocol (ICMP) redirects are disabled on interfaces where the local proxy ARP feature is enabled.
Examples
The following example shows how to enable the local proxy ARP feature:
Router(config-if)# ip local-proxy-arp

Best Regards,
Deepak Arora

Saturday, December 27, 2008

Few words about ip directed broadcast :-)

An IP directed broadcast is an IP packet whose destination address is a valid broadcast address for some IP subnet, but which originates from a node that is not itself part of that destination subnet.

A router that is not directly connected to its destination subnet forwards an IP directed broadcast in the same way it would forward unicast IP packets destined to a host on that subnet. When a directed broadcast packet reaches a router that is directly connected to its destination subnet, that packet is "exploded" as a broadcast on the destination subnet. The destination address in the IP header of the packet is rewritten to the configured IP broadcast address for the subnet, and the packet is sent as a link-layer broadcast.

The ip directed-broadcast interface command controls the explosion of directed broadcasts when they reach their target subnets. The command affects only the final transmission of the directed broadcast on its ultimate destination subnet. It does not affect the transit unicast routing of IP directed broadcasts.

If directed broadcast is enabled for an interface, incoming IP packets whose addresses identify them as directed broadcasts intended for the subnet to which that interface is attached will be exploded as broadcasts on that subnet. If an access list has been configured with the ip directed-broadcast command, only directed broadcasts that are permitted by the access list in question will be forwarded; all other directed broadcasts destined for the interface subnet will be dropped.

If the no ip directed-broadcast command has been configured for an interface, directed broadcasts destined for the subnet to which that interface is attached will be dropped, rather than being broadcast.

Taken from Cisco's site:
http://www.cisco.com/en/US/docs/ios/12_3/ipaddr/command/reference/ip1_i1g.html#wp1081245

Best Regards,
Deepak Arora

Monday, December 22, 2008

Prefix Notations - For CCNA

When you're preparing to pass the CCNA exam and earn this coveted
Cisco certification, you've got to be totally prepared for the many
kinds of binary and subnetting questions Cisco may throw at you.
You also have to be familiar with the different manners in which a
subnet mask can be expressed, and that’s where your knowledge
of prefix notation comes in.


Prefix notation is an alternate way to express the value of a subnet
mask, as opposed to the more familiar dotted decimal format. Not
only will you see prefix notation in Cisco documentation, but you’ll
probably see it on your CCNA exam. Consider the following two values:


255.255.255.0

or

/24

Believe it or not, those two values are exactly the same. The first
mask is written out in the more familiar dotted decimal format, and
you know by looking at those first three octets that every bit is set
to "1", since the maximum value of such an octet is 255:


11111111 11111111 11111111 00000000
The second value represents the exact same mask, only this value
is expressed in prefix notation. This particular value would be
pronounced "slash twenty-four", and the 24 represents the number
of consecutive ones that are set at the beginning of the subnet mask.


Those of us who hate to type numbers are particularly appreciative
of this, since it means you'll have to type a lot less numbers to
represent a subnet mask. In addition, it's a lot easier to discuss
masks in prefix notation than dotted decimal. ("I thought about
using a two-fifty-five two-fifty-five two-fifty-five zero mask ,
but then decided to use a two-fifty-five two-fifty-five two-fifty
-five one-twenty-eight mask...")


Be sure you're comfortable with prefix notation before taking your
CCNA exam. As with Cisco documentation, you'll most likely see masks
expressed in both dotted decimal and prefix notation, and you've got
to be ready to use the both as well!

Best Regards,
Deepak Arora

Broadcasts, Multicasts, And Unicasts - For CCNA

A broadcast is a data signal that is intended for everyone. A network
broadcast is much like a radio broadcast. A commercial radio
station's tower isn't sending a signal to one particular destination
- it's sending its signal out in all directions in hopes that everyone
who can listen to it will do so. A network broadcast is very similar
in that it's given a destination address that every host on the
network will listen to. Two important broadcast addresses for you
to know for the CCNA certification exams:


Data Link layer (Layer 2) broadcast frames have a destination MAC
address of ff-ff-ff-ff-ff-ff (also expressed as FF-FF-FF-FF-FF-FF,
the case doesn't matter)
Network layer (Layer 3) broadcast packets
have a destination IP address of 255.255.255.255

By default, switches will forward all broadcast frames out every
port except the one that originally received the broadcast. Also by
default, routers accept broadcasts but do not forward them.


A unicast has a much simpler definition - it's simply data that has
a single destination.


Broadcasts go to everyone, unicasts go to only one -- sounds like
we need a middle ground! Luckily, we do, with multicasts. A multicast
is destined for members of a multicast group. Later on in your CCNP
studies you'll learn much more about multicasting, but there are
several multicast addresses you should know for the CCNA
certification exam:


EIGRP updates are destined for 224.0.0.10
OSPF routers listen to 224.0.0.5 for updates
RIP version 2 uses 224.0.0.9 as a destination IP address
I'm sure you notice a pattern there! The entire range of addresses
from 224.0.0.0 - 239.255.255.255 is reserved for multicasting. This
is the Class D address range. As with broadcast packets, these
multicast packets are not forwarded by routers.


It's important to know the differences between multicasts,
broadcasts, and unicasts as part of your CCNA test prep,
but this knowledge goes far beyond passing a certification exam.
Knowing how to limit broadcasts helps to improve your network.

Best Regards,
Deepak Arora