Showing posts with label IS-IS. Show all posts
Showing posts with label IS-IS. Show all posts

Wednesday, July 22, 2015

CCDE IGP Study Plan Part 1 - IS-IS

Finally I found some time recently to study and move on with CCDE plan. The idea is to take CCDE written in next 6 months at max. Since I have been doing on and off study for quite a while, I decided to gear up this time and work based on attack plan I had per technology duing my CCIE R&S couple of years back since the approach did well for me. The plan is more likely to work since to me CCDE is just a getting into mindset of a Network Designer but otherwise it's just a vast collection of exam topics that carefully needs to be examined and prepared for.

So to start with I picked up one of my fav routing protocol (IGP) which is yet not very well known - Integrated IS-IS or IS-IS for IP or IS-IS in general.

There are many personal reasons that I would pick it as protocol of choice if I have to pick for an ISP Network Design over more popular OSPF. But let's not get into IS-IS vs OSPF discussion yet.

Below is the study plan I used so far and I am quite happy about with progress.

1. Routing TCP/IP, Volume 1 (2nd Edition) - Jeff Doyle - Cisco Press
2. Optimal Routing Design  - Russ White - Cisco Press
3. IS-IS Network Design Solutions  - Abe Martey - Cisco Press > Two 
    Design Chapters
4. INE CCIE SP ATC IS-IS Section
5. SPF calculation in OSPF and IS-IS
6. ISIS Link-Group
7. Using BFD to Detect WAN Forwarding Errors
8. IS-IS+MPLS TE+Native IPv6=FAIL
9. Do not EVER run OSPF or IS-IS with your Internet customers
10. Missing routes when running IS-IS over Frame Relay
11. Cisco Live 365 - BRKRST-2335 - IS-IS Network Design and Deployment  
     (2012 San Diego)
12. Cisco Live 365 - BRKRST-2327 - ISIS Fundamentals and Troubleshooting
     (2013 Orlando)
13. Cisco Live 365 - BRKRST-2338 - ISIS Deployment in Modern Networks
     (2014 San Francisco) 
14. Packet Pushers - Show 89 – OSPF vs IS-IS Smackdown – Where You Can  
     Watch Their Eyes Reload
15. ISIS Authentication types
16. IS-IS Notes
17. IS-IS Study Guide Cisco IOS,IOS-XR 
18. IS-IS Routing Protocol FAQ

Under point '3' I chose Cisco Press IS-IS Network Design Solutions while there were some other good options too suggested by many CCIE and CCDE friends. But after carefully examining the contents through quick review I preferred Cisco Press book. But other books are no less either if you pick one of those like:

The Complete IS-IS Routing Protocol

OSPF and IS-IS: Choosing an IGP for Large-Scale Networks

IS-IS: Deployment in IP Networks

With that being said, hope to come up with IS-IS design articles and possibly a short IS-IS CCDE type case study in coming month.

HTH...
Deepak Arora
Evil CCIE

Tuesday, May 14, 2013

ISIS Route-Leaking On IOS - Tricky Part


Task - Leak The L-2 Routes into ISIS Level-1 Domain with minimal commands.

Initial Configuration
=============


R1
===

!
en
!
conf t
!
no ip do lo
!
line con 0
 no exec-time
 logging syn
 exit
!
ho R1
!
int lo1
 ip add 1.1.1.1 255.255.255.255
 exit
!
int p1/0
 ip add 12.0.0.1 255.255.255.0
 no sh
 exit
!
int p2/0
 ip add 13.0.0.1 255.255.255.0
 no sh
 exit
!
ipv6 unicast-routing
!
router isis
 net 49.0111.0000.0000.1111.00
 metric-style wide
 add ipv6
 multi
 exit
exit
!
int lo1
 ip router isis
 isis circuit-type level-2
 exit
!
int p1/0
 ip router isis
 isis circuit-type level-2
 exit
!
int p2/0
 ip router isis
 isis circuit-type level-2
 exit
!
end
!
wr
!
=============================

R2
===

!
en
!
conf t
!
no ip do lo
!
line con 0
 no exec-time
 logging syn
 exit
!
ho R2
!
int lo2
 ip add 2.2.2.2 255.255.255.255
 exit
!
int p1/0
 ip add 12.0.0.2 255.255.255.0
 no sh
 exit
!
int p2/0
 ip add 24.0.0.2 255.255.255.0
 no sh
 exit
!
ipv6 unicast-routing
!
router isis
 net 49.0122.0000.0000.2222.00
 metric-style wide
 add ipv6
 multi
 exit
exit
!
int lo2
 ip router isis
 isis circuit-type level-2
 exit
!
int p1/0
 ip router isis
 isis circuit-type level-2
 exit
!
int p2/0
 ip router isis
 isis circuit-type level-2
 exit
!
end
!
wr
!

=============================

R3
===

!
en
!
conf t
!
no ip do lo
!
line con 0
 no exec-time
 logging syn
 exit
!
ho R3
!
int lo3
 ip add 3.3.3.3 255.255.255.255
 exit
!
int p1/0
 ip add 34.0.0.3 255.255.255.0
 no sh
 exit
!
int p2/0
 ip add 13.0.0.3 255.255.255.0
 no sh
 exit
!
int p3/0
 ip add 35.0.0.3 255.255.255.0
 no sh
 exit
!
ipv6 unicast-routing
!
router isis
 net 49.0133.0000.0000.3333.00
 metric-style wide
 add ipv6
 multi
 exit
exit
!
int lo3
 ip router isis
 isis circuit-type level-2
 exit
!
int p1/0
 ip router isis
 isis circuit-type level-2
 exit
!
int p2/0
 ip router isis
 isis circuit-type level-2
 exit
!
int p3/0
 ip router isis
 isis circuit-type level-1
 exit
!
end
!
wr
!

=============================

R4
===

!
en
!
conf t
!
no ip do lo
!
line con 0
 no exec-time
 logging syn
 exit
!
ho R4
!
int lo4
 ip add 4.4.4.4 255.255.255.255
 exit
!
int p1/0
 ip add 34.0.0.4 255.255.255.0
 no sh
 exit
!
int p2/0
 ip add 24.0.0.4 255.255.255.0
 no sh
 exit
!
ipv6 unicast-routing
!
router isis
 net 49.0144.0000.0000.4444.00
 metric-style wide
 add ipv6
 multi
 exit
exit
!
int lo4
 ip router isis
 isis circuit-type level-2
 exit
!
int p1/0
 ip router isis
 isis circuit-type level-2
 exit
!
int p2/0
 ip router isis
 isis circuit-type level-2
 exit
!
end
!
wr
!


=============================

R5
===

!
en
!
conf t
!
no ip do lo
!
line con 0
 no exec-time
 logging syn
 exit
!
ho R5
!
int lo5
 ip add 5.5.5.5 255.255.255.255
 exit
!
int p3/0
 ip add 35.0.0.5 255.255.255.0
 no sh
 exit
!
ipv6 unicast-routing
!
router isis
 net 49.0133.0000.0000.5555.00
 metric-style wide
 add ipv6
 multi
 exit
exit
!
int lo5
 ip router isis
 isis circuit-type level-1
 exit
!
int p3/0
 ip router isis
 isis circuit-type level-1
 exit
!
end
!
wr
!


Simple Trick
=========


Earlier on R5
=========





On R3
=====

Redistribute level-2 into level-1 with a Dummy Access list that doesn't exist.




Later on R5
========




HTH...
Deepak Arora
Evil CCIE


Wednesday, May 1, 2013

MPLS Traffic Engineering Using ISIS - Explicit Path



R3#sh run | s mpls|FastEthernet0/0.34|FastEthernet0/0.36|Loopback33|router isis|Tunnel
mpls traffic-eng tunnels
mpls label protocol ldp
 ip router isis
interface Loopback33
 ip address 33.33.33.33 255.255.255.255
interface Tunnel319
 ip unnumbered Loopback0
 tunnel mode mpls traffic-eng
 tunnel destination 19.19.19.19
 tunnel mpls traffic-eng priority 7 7
 tunnel mpls traffic-eng bandwidth 2000
 tunnel mpls traffic-eng path-option 1 explicit name TE
interface FastEthernet0/0.34
 encapsulation dot1Q 34
 ip address 20.3.4.3 255.255.255.0
 ip router isis
 ipv6 address 2001:20:3:4::3/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.36
 encapsulation dot1Q 36
 ip address 20.3.6.3 255.255.255.0
 ip router isis
 ipv6 address 2001:20:3:6::3/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
router isis
 net 11.0703.0000.0000.0000.3333.00
 metric-style wide
 !
 address-family ipv6
  multi-topology
 exit-address-family
 mpls ldp autoconfig level-2
 mpls traffic-eng router-id Loopback0
 mpls traffic-eng level-2
ip route 199.199.199.199 255.255.255.255 Tunnel319
mpls ldp router-id Loopback0 force



ip route 199.199.199.199 255.255.255.255 Tunnel319
==================================================================================================


R4#sh run | s mpls|FastEthernet0/0.34|FastEthernet0/0.45|FastEthernet0/0.46|router isis
mpls traffic-eng tunnels
mpls label protocol ldp
interface FastEthernet0/0.34
 encapsulation dot1Q 34
 ip address 20.3.4.4 255.255.255.0
 ip router isis
 ipv6 address 2001:20:3:4::4/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.45
 encapsulation dot1Q 45
 ip address 20.4.5.4 255.255.255.0
 ip router isis
 ipv6 address 2001:20:4:5::4/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.46
 encapsulation dot1Q 46
 ip address 20.4.6.4 255.255.255.0
 ip router isis
 ipv6 address 2001:20:4:6::4/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
 mpls ldp autoconfig level-2
 mpls traffic-eng router-id Loopback0
 mpls traffic-eng level-2
mpls ldp router-id Loopback0 force
router isis
 net 11.0744.0000.0000.0000.4444.00
 metric-style wide
 !
 address-family ipv6
  multi-topology
 exit-address-family
 mpls ldp autoconfig level-2
 mpls traffic-eng router-id Loopback0
 mpls traffic-eng level-2



==================================================================================================


R5#sh run | s mpls|FastEthernet0/0.45|FastEthernet0/0.56|FastEthernet0/0.519|router isis
mpls traffic-eng tunnels
mpls label protocol ldp
 ip router isis
interface FastEthernet0/0.45
 encapsulation dot1Q 45
 ip address 20.4.5.5 255.255.255.0
 ip router isis
 ipv6 address 2001:20:4:5::5/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.56
 encapsulation dot1Q 56
 ip address 20.5.6.5 255.255.255.0
 ip router isis
 ipv6 address 2001:20:5:6::5/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.519
 encapsulation dot1Q 519
 ip address 20.5.19.5 255.255.255.0
 ip router isis
router isis
 net 11.0755.0000.0000.5555.00
 metric-style wide
 !
 address-family ipv6
  multi-topology
 exit-address-family
 mpls ldp autoconfig level-2
 mpls traffic-eng router-id Loopback0
 mpls traffic-eng level-2

==================================================================================================

R6#sh run | s mpls|FastEthernet0/0.36|FastEthernet0/0.46|FastEthernet0/0.56|FastEthernet0/0.619|router isis
mpls traffic-eng tunnels
mpls label protocol ldp
 ip router isis
 ipv6 router isis
interface FastEthernet0/0.36
 encapsulation dot1Q 36
 ip address 20.3.6.6 255.255.255.0
 ip router isis
 ipv6 address 2001:20:3:6::6/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.46
 encapsulation dot1Q 46
 ip address 20.4.6.6 255.255.255.0
 ip router isis
 ipv6 address 2001:20:4:6::6/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.56
 encapsulation dot1Q 56
 ip address 20.5.6.6 255.255.255.0
 ip router isis
 ipv6 address 2001:20:5:6::6/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
interface FastEthernet0/0.619
 encapsulation dot1Q 619
 ip address 20.6.19.6 255.255.255.0
 ip router isis
 ipv6 address 2001:20:6:19::6/64
 mpls traffic-eng tunnels
 isis circuit-type level-2-only
 ip rsvp bandwidth 2000
router isis
 net 11.0766.0000.0000.0066.6600
 metric-style wide
 !
 address-family ipv6
  multi-topology
 exit-address-family
 mpls ldp autoconfig level-2
 mpls traffic-eng router-id Loopback0
 mpls traffic-eng level-2
mpls ldp router-id Loopback0 force



==================================================================================================

XR1
===

explicit-path name TE
 index 1 next-address strict ipv4 unicast 20.5.19.5
 index 2 next-address strict ipv4 unicast 20.4.5.4
 index 3 next-address strict ipv4 unicast 20.3.4.3

!
interface tunnel-te193
 ipv4 unnumbered Loopback0
 signalled-bandwidth 2000
 destination 3.3.3.3
 path-option 1 explicit name TE
!

!
router static
 address-family ipv4 unicast
  33.33.33.33/32 tunnel-te193
 !

!
router isis abcd
 net 11.0719.0000.0000.1919.00
 address-family ipv4 unicast
  metric-style wide
  mpls traffic-eng level-2-only
  mpls traffic-eng router-id Loopback0
 !
 address-family ipv6 unicast
  metric-style wide
 !
 interface Loopback0
  circuit-type level-2-only
  address-family ipv4 unicast
  !
 !
 interface GigabitEthernet0/1/0/0.519
  circuit-type level-2-only
  address-family ipv4 unicast
  !
 !
 interface GigabitEthernet0/1/0/0.619
  circuit-type level-2-only
  address-family ipv4 unicast
  !


!
rsvp
 interface GigabitEthernet0/1/0/0.519
  bandwidth 2000
 !
 interface GigabitEthernet0/1/0/0.619
  bandwidth 2000
 !


!
mpls traffic-eng
 interface GigabitEthernet0/1/0/0.519
 !
 interface GigabitEthernet0/1/0/0.619
 !



!
mpls ldp
 router-id 19.19.19.19
 interface GigabitEthernet0/1/0/0.519
 !
 interface GigabitEthernet0/1/0/0.619
 !
==================================================================================================

R3#traceroute 199.199.199.199 source lo33

Type escape sequence to abort.
Tracing the route to 199.199.199.199

  1 20.3.6.6 [MPLS: Label 16 Exp 0] 4 msec 0 msec 4 msec
  2 20.5.6.5 [MPLS: Label 16 Exp 0] 0 msec 4 msec 0 msec
  3 20.5.19.19 4 msec *  4 msec



RP/0/0/CPU0:XR1#traceroute 33.33.33.33 so 199.199.199.199
Wed May  1 02:09:04.449 UTC

Type escape sequence to abort.
Tracing the route to 33.33.33.33

 1  20.5.19.5 [MPLS: Label 27 Exp 0] 4 msec  4 msec  3 msec
 2  20.4.5.4 [MPLS: Label 26 Exp 0] 4 msec  3 msec  3 msec
 3  20.3.4.3 2 msec  *  3 msec


HTH...
Deepak Arora
Evil CCIE

Wednesday, March 20, 2013

MPLS L2 VPN - Ethernet To Ethernet/PPP To PPP ATOM: It's All About Pseudo-Wires






pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls <
Choosing MPLS Here Basically Suggests that we are using AToM Not L2TPv3
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 2.2.2.2 12 pw-class ATOM_ETH_TO_ETH
!


R2's XCONNECT Configuration

pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls

!

interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 1.1.1.1 12 pw-class ATOM_ETH_TO_ETH

!

Verification











PPP To PPP Variation







R1
===
!
!
! Last configuration change at 17:46:55 UTC Wed Mar 20 2013
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
!
hostname R1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip source-route
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
no ipv6 cef
!
!
multilink bundle-name authenticated
mpls label protocol ldp
!
!
!
!
ip tcp synwait-time 5
pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls
!
!
!
!
!
!
!
interface Loopback0
 ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet0/0
 no ip address
 shutdown
 duplex half
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 2.2.2.2 12 pw-class ATOM_ETH_TO_ETH
!
interface FastEthernet1/1
 ip address 13.0.0.1 255.255.255.0
 ip router isis 1
 speed auto
 duplex auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0001.00
 is-type level-2-only
 passive-interface Loopback0
!
no ip http server
no ip http secure-server
!
!
!
no cdp run
!
!
!
control-plane
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line vty 0 4
 login
!
end
 
R2
==

!
!
! Last configuration change at 17:48:05 UTC Wed Mar 20 2013
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
!
hostname R2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
ip source-route
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
no ipv6 cef
!
!
multilink bundle-name authenticated
mpls label protocol ldp
!
!
!
!
ip tcp synwait-time 5
pseudowire-class ATOM_ETH_TO_ETH
 encapsulation mpls
!
!
!
!
!
!
!
interface Loopback0
 ip address 2.2.2.2 255.255.255.255
!
interface FastEthernet0/0
 no ip address
 shutdown
 duplex half
!
interface FastEthernet1/0
 no ip address
 speed auto
 duplex auto
 no keepalive
 xconnect 1.1.1.1 12 pw-class ATOM_ETH_TO_ETH
!
interface FastEthernet1/1
 ip address 24.0.0.2 255.255.255.0
 ip router isis 1
 speed auto
 duplex auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0002.00
 is-type level-2-only
 passive-interface Loopback0
!
no ip http server
no ip http secure-server
!
!
!
no cdp run
!
!
!
control-plane
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
 stopbits 1
line vty 0 4
 login
!
end
 

R3
==
 !
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R3
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 3.3.3.3 255.255.255.255
 ip router isis 1
!
interface FastEthernet0/0
 ip address 34.0.0.3 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 13.0.0.3 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0003.00
 is-type level-2-only
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 
R4
==
 !
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R4
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 4.4.4.4 255.255.255.255
!
interface FastEthernet0/0
 ip address 24.0.0.4 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 34.0.0.4 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
router isis 1
 net 49.1234.0000.0000.0004.00
 is-type level-2-only
 passive-interface Loopback0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 
R5
==

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R5
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 5.5.5.5 255.255.255.255
!
interface FastEthernet0/0
 ip address 150.0.0.5 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 5.5.5.5 0.0.0.0 area 0
 network 150.0.0.5 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 

R6
==

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R6
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 6.6.6.6 255.255.255.255
!
interface FastEthernet0/0
 ip address 150.0.0.6 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 6.6.6.6 0.0.0.0 area 0
 network 150.0.0.6 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end
 

HTH...
Deepak Arora
Evil CCIE

Thursday, March 14, 2013

MPLS Inter AS VPN Option B AKA Option 2








R1 Final Configuration

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
ip vrf A
 rd 100:1
 route-target export 1:1
 route-target import 1:1
!
ip vrf B
 rd 100:2
 route-target export 2:2
 route-target import 2:2
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet0/0
 ip address 14.0.0.1 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip vrf forwarding A
 ip address 12.0.0.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet1/0
 ip vrf forwarding B
 ip address 13.0.0.1 255.255.255.0
 duplex auto
 speed auto
!
router eigrp 1
 auto-summary
 !
 address-family ipv4 vrf A
  redistribute bgp 100 metric 1 1 1 1 1
  network 12.0.0.1 0.0.0.0
  no auto-summary
  autonomous-system 100
 exit-address-family
!
router ospf 1 vrf B
 log-adjacency-changes
 redistribute bgp 100 subnets
 network 13.0.0.1 0.0.0.0 area 0
!
router isis 1
 net 49.1456.0000.0000.0001.00
 is-type level-2-only
 passive-interface Loopback0
!
router bgp 100
 no synchronization
 bgp log-neighbor-changes
 neighbor 4.4.4.4 remote-as 100
 neighbor 4.4.4.4 update-source Loopback0
 no auto-summary
 !
 address-family vpnv4
  neighbor 4.4.4.4 activate
  neighbor 4.4.4.4 send-community extended
 exit-address-family
 !
 address-family ipv4 vrf B
  redistribute ospf 1 vrf B match internal external 1 external 2
  no synchronization
 exit-address-family
 !
 address-family ipv4 vrf A
  redistribute eigrp 100
  no synchronization
 exit-address-family
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

R2 Final Configuration 

 !
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 2.2.2.2 255.255.255.255
!
interface FastEthernet0/0
 ip address 12.0.0.2 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router eigrp 100
 network 2.2.2.2 0.0.0.0
 network 12.0.0.2 0.0.0.0
 no auto-summary
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

R3 Final Configuration

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R3
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 3.3.3.3 255.255.255.255
!
interface FastEthernet0/0
 ip address 13.0.0.3 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 3.3.3.3 0.0.0.0 area 0
 network 13.0.0.3 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end


R4 Final Configuration

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R4
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 4.4.4.4 255.255.255.255
!
interface FastEthernet0/0
 ip address 14.0.0.4 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 45.0.0.4 255.255.255.0
 duplex auto
 speed auto
!
router isis 1
 net 49.1456.0000.0000.0004.00
 is-type level-2-only
 passive-interface Loopback0
!
router bgp 100
 no synchronization
 no bgp default route-target filter
 bgp log-neighbor-changes
 neighbor 1.1.1.1 remote-as 100
 neighbor 1.1.1.1 update-source Loopback0
 neighbor 45.0.0.5 remote-as 200
 no auto-summary
 !
 address-family vpnv4
  neighbor 1.1.1.1 activate
  neighbor 1.1.1.1 send-community extended
  neighbor 1.1.1.1 next-hop-self
  neighbor 45.0.0.5 activate
  neighbor 45.0.0.5 send-community extended
 exit-address-family
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end


R5 Final Configuration

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R5
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 5.5.5.5 255.255.255.255
!
interface FastEthernet0/0
 ip address 56.0.0.5 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip address 45.0.0.5 255.255.255.0
 duplex auto
 speed auto
!
router isis 1
 net 49.1456.0000.0000.0005.00
 is-type level-2-only
 passive-interface Loopback0
!
router bgp 200
 no synchronization
 no bgp default route-target filter
 bgp log-neighbor-changes
 neighbor 6.6.6.6 remote-as 200
 neighbor 6.6.6.6 update-source Loopback0
 neighbor 45.0.0.4 remote-as 100
 no auto-summary
 !
 address-family vpnv4
  neighbor 6.6.6.6 activate
  neighbor 6.6.6.6 send-community extended
  neighbor 6.6.6.6 next-hop-self
  neighbor 45.0.0.4 activate
  neighbor 45.0.0.4 send-community extended
 exit-address-family
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

R6 Final Configuration

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R6
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
ip vrf A
 rd 200:1
 route-target export 1:1
 route-target import 1:1
!
ip vrf B
 rd 200:2
 route-target export 2:2
 route-target import 2:2
!
no ip domain lookup
mpls label protocol ldp
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 6.6.6.6 255.255.255.255
!
interface FastEthernet0/0
 ip address 56.0.0.6 255.255.255.0
 ip router isis 1
 duplex auto
 speed auto
 mpls ip
!
interface FastEthernet0/1
 ip vrf forwarding A
 ip address 67.0.0.6 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet1/0
 ip vrf forwarding B
 ip address 68.0.0.6 255.255.255.0
 duplex auto
 speed auto
!
router eigrp 1
 auto-summary
 !
 address-family ipv4 vrf A
  redistribute bgp 200 metric 1 1 1 1 1
  network 67.0.0.6 0.0.0.0
  no auto-summary
  autonomous-system 100
 exit-address-family
!
router ospf 1 vrf B
 log-adjacency-changes
 redistribute bgp 200 subnets
 network 68.0.0.6 0.0.0.0 area 0
!
router isis 1
 net 49.1456.0000.0000.0006.00
 is-type level-2-only
 passive-interface Loopback0
!
router bgp 200
 no synchronization
 bgp log-neighbor-changes
 neighbor 5.5.5.5 remote-as 200
 neighbor 5.5.5.5 update-source Loopback0
 no auto-summary
 !
 address-family vpnv4
  neighbor 5.5.5.5 activate
  neighbor 5.5.5.5 send-community extended
 exit-address-family
 !
 address-family ipv4 vrf B
  redistribute ospf 1 vrf B match internal external 1 external 2
  no synchronization
 exit-address-family
 !
 address-family ipv4 vrf A
  redistribute eigrp 100
  no synchronization
 exit-address-family
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

R7 Final Configuration

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R7
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 7.7.7.7 255.255.255.255
!
interface FastEthernet0/0
 ip address 67.0.0.7 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router eigrp 100
 network 7.7.7.7 0.0.0.0
 network 67.0.0.7 0.0.0.0
 no auto-summary
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

R8 Final Configuration

!
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R8
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
memory-size iomem 5
no ip icmp rate-limit unreachable
ip cef
!
!
!
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
ip tcp synwait-time 5
!
!
!
interface Loopback0
 ip address 8.8.8.8 255.255.255.255
!
interface FastEthernet0/0
 ip address 68.0.0.8 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1
 no ip address
 shutdown
 duplex auto
 speed auto
!
router ospf 1
 log-adjacency-changes
 network 8.8.8.8 0.0.0.0 area 0
 network 68.0.0.8 0.0.0.0 area 0
!
ip forward-protocol nd
!
!
no ip http server
no ip http secure-server
!
no cdp run
!
!
control-plane
!
!
!
!
!
!
!
!
!
line con 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line aux 0
 exec-timeout 0 0
 privilege level 15
 logging synchronous
line vty 0 4
 login
!
!
end

Further Readings:







Deepak Arora
Evil CCIE

Monday, March 11, 2013

ISIS Route Leaking In IOS-XR... Coming Soon



RP/0/0/CPU0:XR1#sh route isis | i 3.3.3.3
i L2 3.3.3.3/32 [115/30] via 20.6.19.6, 00:29:27, GigabitEthernet0/1/0/0.619
RP/0/0/CPU0:XR1#sh route isis | i 4.4.4.4
i L2 4.4.4.4/32 [115/20] via 20.6.19.6, 00:29:36, GigabitEthernet0/1/0/0.619

Step 1: Create Route Policy
=====================

RP/0/0/CPU0:XR1#sh run route-policy ISIS
route-policy ISIS
  if destination in (3.3.3.3/32, 4.4.4.4/32) then
    pass
  endif
end-policy

!

Step 2: Map The Policy To ISIS Process
==============================

RP/0/0/CPU0:XR1#sh run router isis
router isis 1
 net 49.1920.0000.0000.0019.00
 address-family ipv4 unicast
  propagate level 2 into level 1 route-policy ISIS
 !
 interface Loopback0
  passive
  circuit-type level-2-only
  address-family ipv4 unicast
  !
 !
 interface GigabitEthernet0/1/0/0.519
  circuit-type level-2-only
  address-family ipv4 unicast
  !
 !
 interface GigabitEthernet0/1/0/0.619
  circuit-type level-2-only
  address-family ipv4 unicast
  !
 !
 interface POS0/6/0/0
  circuit-type level-1
  address-family ipv4 unicast
  !
 !
!


Verification
=========

Before on XR2
===========
RP/0/3/CPU0:XR2#sh ip route isis

i*L1 0.0.0.0/0 [115/10] via 10.19.20.19, 00:23:22, POS0/7/0/0


After on XR2
==========

RP/0/3/CPU0:XR2#sh ip route isis


i*L1 0.0.0.0/0 [115/10] via 10.19.20.19, 00:23:46, POS0/7/0/0
i ia 3.3.3.3/32 [115/40] via 10.19.20.19, 00:00:05, POS0/7/0/0
i ia 4.4.4.4/32 [115/30] via 10.19.20.19, 00:00:05, POS0/7/0/0

 

Other Relevant Configuration
======================

RP/0/3/CPU0:XR2#sh run router isis

router isis 1
 is-type level-1
 net 49.1920.0000.0000.0020.00
 interface Loopback0
  passive
  address-family ipv4 unicast
  !
 !
 interface POS0/7/0/0
  address-family ipv4 unicast
  !
 !
!
  
Deepak Arora
Evil CCIE