Sunday, January 4, 2009

OSPF Summerization Issue - Real World Case Study

Hello Friends,

Hope you are enjoying my blog and its helping you out in few weird situations.

Lets talk about a weird OSPF scenario that I came across few days back.

I was just doing some of my own designed ospf scenarios when I saw this issue occurring.

Lets talk about the issue now. In my scenario (which is mentioned in above diagram); I established a virtual-link between R2 & R3 to get R4's routes to area 0 as Area 2 was not directly connected to area 0. After that I setup some loop back interfaces on R4 and advertised them in area 2. I also configured ospf network type point-to-point for these loopback interfaces (I hope you got the reason why I changed the network type on loopback interfaces). After that I summarized these networks using area 2 range command on R3 and summarized these loopback networks into one summary route.


Upto this point things were working fine as per my expectations. After that I thought lets do one more summarization :-)

So I created some more loopback interfaces on R3 this time and did the same steps which I performed on R4 earlier ( but advertised loopback interfaces in area 1). But this time even after issuing area 1 range command on R2 you know what I saw in R1 routing table ? :-O

I saw on R1 that It's not only getting summarized route for R3 loopback addresses but also getting loopback network addresses of R3's loopback interfaces with their correct mask and subnets. Means I got summary route as well as normal prefix subnet routes for same addresses in R1's routing table.

e.g.

R1# sh ip rou ospf
2.0.0.0/30 is subnetted, 1 subnets
O IA 2.2.2.0 [110/128] via 1.1.1.2, 00:00:00, Serial0/0
3.0.0.0/30 is subnetted, 1 subnets
O IA 3.3.3.0 [110/192] via 1.1.1.2, 00:00:00, Serial0/0
O IA 192.168.8.0/24 [110/129] via 1.1.1.2, 00:00:00, Serial0/0 ---> Route with accurate prefix (from R3)
O IA 192.168.9.0/24 [110/129] via 1.1.1.2, 00:00:00, Serial0/0
---> Route with accurate prefix (from R3)
O IA 20.0.0.0/8 [110/74] via 1.1.1.2, 00:00:00, Serial0/0
O IA 192.168.10.0/24 [110/129] via 1.1.1.2, 00:00:00, Serial0/0
---> Route with accurate prefix (from R3)
172.16.0.0/22 is subnetted, 1 subnets
O IA 172.16.8.0 [110/193] via 1.1.1.2, 00:00:00, Serial0/0
O IA 192.168.11.0/24 [110/129] via 1.1.1.2, 00:00:00, Serial0/0
---> Route with accurate prefix (from R3)
O IA 40.0.0.0/8 [110/202] via 1.1.1.2, 00:00:00, Serial0/0
O IA 30.0.0.0/8 [110/138] via 1.1.1.2, 00:00:00, Serial0/0
O IA 192.168.8.0/22 [110/129] via 1.1.1.2, 00:00:00, Serial0/0 ---> Huh..and summary route as well :-)

I beat my head against the wall for quite some time and finally I tried one thing which worked for me...yyoohhhooo :-)

I configured the same area 1 range command on R3 as well and summarization issue got fixed.

R1#sh ip route ospf
2.0.0.0/30 is subnetted, 1 subnets
O IA 2.2.2.0 [110/128] via 1.1.1.2, 00:00:10, Serial0/0
3.0.0.0/30 is subnetted, 1 subnets
O IA 3.3.3.0 [110/192] via 1.1.1.2, 00:00:10, Serial0/0
O IA 20.0.0.0/8 [110/74] via 1.1.1.2, 00:00:10, Serial0/0
172.16.0.0/22 is subnetted, 1 subnets
O IA 172.16.8.0 [110/193] via 1.1.1.2, 00:00:10, Serial0/0
O IA 40.0.0.0/8 [110/202] via 1.1.1.2, 00:00:10, Serial0/0
O IA 30.0.0.0/8 [110/138] via 1.1.1.2, 00:00:10, Serial0/0
O IA 192.168.8.0/22 [110/129] via 1.1.1.2, 00:00:10, Serial0/0

Below is the config for all four routers for your further reference. Drop me an email to me at deepakarora.1984@gmail.com incase you face any issue or have some doubt or suggestions on this :-)
-------------------------------------------------------------------------------------------
R1#sh run
Building configuration...

Current configuration : 804 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
resource policy
!
memory-size iomem 5
ip cef
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 10.0.0.1 255.0.0.0
duplex auto
speed auto
!
interface Serial0/0
ip address 1.1.1.1 255.255.255.252
clock rate 2000000
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0/1
no ip address
shutdown
clock rate 2000000
!
router ospf 1
router-id 25.25.25.25
log-adjacency-changes
network 1.1.1.1 0.0.0.0 area 0
network 10.0.0.1 0.0.0.0 area 0
!
!
ip http server
no ip http secure-server
!
!
control-plane
!
!
line con 0
line aux 0
line vty 0 4
!
!
end

--------------------------------------------------------------------------------------------


R2#sh run
Building configuration...

Current configuration : 1054 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
resource policy
!
memory-size iomem 5
ip cef
!
!
!
!
!
!
!
!
!
!
!
interface FastEthernet0/0
ip address 20.0.0.1 255.0.0.0
duplex auto
speed auto
!
interface Serial0/0
ip address 1.1.1.2 255.255.255.252
clock rate 2000000
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0/1
ip address 2.2.2.1 255.255.255.252
clock rate 2000000
!
interface Serial0/2
no ip address
shutdown
clock rate 2000000
!
interface Serial0/3
no ip address
shutdown
clock rate 2000000
!
router ospf 1
router-id 50.50.50.50
log-adjacency-changes
area 1 range 192.168.8.0 255.255.252.0
area 1 virtual-link 75.75.75.75
network 1.1.1.2 0.0.0.0 area 0
network 2.2.2.1 0.0.0.0 area 1
network 20.0.0.1 0.0.0.0 area 1
!
!
ip http server
no ip http secure-server
!
!
control-plane
!
!
line con 0
line aux 0
line vty 0 4
!
!
end

------------------------------------------------------------------------------------------

R3#sh run
Building configuration...

Current configuration : 1572 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R3
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
resource policy
!
memory-size iomem 5
ip cef
!
!
!
!
!
!
!
!
!
!
!
interface Loopback0
ip address 192.168.8.1 255.255.255.0
ip ospf network point-to-point
ip ospf 1 area 1
!
interface Loopback1
ip address 192.168.9.1 255.255.255.0
ip ospf network point-to-point
ip ospf 1 area 1
!
interface Loopback2
ip address 192.168.10.1 255.255.255.0
ip ospf network point-to-point
ip ospf 1 area 1
!
interface Loopback3
ip address 192.168.11.1 255.255.255.0
ip ospf network point-to-point
ip ospf 1 area 1
!
interface Loopback4
no ip address
!
interface FastEthernet0/0
ip address 30.0.0.1 255.0.0.0
duplex auto
speed auto
!
interface Serial0/0
ip address 2.2.2.2 255.255.255.252
clock rate 2000000
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0/1
ip address 3.3.3.1 255.255.255.252
clock rate 2000000
!
interface Serial0/2
no ip address
shutdown
clock rate 2000000
!
interface Serial0/3
no ip address
shutdown
clock rate 2000000
!
router ospf 1
router-id 75.75.75.75
log-adjacency-changes
area 1 range 192.168.8.0 255.255.252.0
area 1 virtual-link 50.50.50.50
area 2 range 172.16.8.0 255.255.252.0
network 2.2.2.2 0.0.0.0 area 1
network 3.3.3.1 0.0.0.0 area 2
network 30.0.0.1 0.0.0.0 area 2
!
!
ip http server
no ip http secure-server
!
!
control-plane
!
!
line con 0
line aux 0
line vty 0 4
!
!
end

------------------------------------------------------------------------------------------------


R4#sh run
Building configuration...

Current configuration : 1316 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R4
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
resource policy
!
memory-size iomem 5
ip cef
!
!
!
!
!
!
!
!
!
!
!
interface Loopback0
ip address 172.16.8.1 255.255.255.0
ip ospf network point-to-point
!
interface Loopback1
ip address 172.16.9.1 255.255.255.0
ip ospf network point-to-point
!
interface Loopback2
ip address 172.16.10.1 255.255.255.0
ip ospf network point-to-point
!
interface Loopback3
ip address 172.16.11.1 255.255.255.0
ip ospf network point-to-point
!
interface FastEthernet0/0
ip address 40.0.0.1 255.0.0.0
duplex auto
speed auto
!
interface Serial0/0
ip address 3.3.3.2 255.255.255.252
clock rate 2000000
!
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
!
interface Serial0/1
no ip address
shutdown
clock rate 2000000
!
router ospf 1
router-id 100.100.100.100
log-adjacency-changes
network 3.3.3.2 0.0.0.0 area 2
network 40.0.0.1 0.0.0.0 area 2
network 172.16.8.1 0.0.0.0 area 2
network 172.16.9.1 0.0.0.0 area 2
network 172.16.10.1 0.0.0.0 area 2
network 172.16.11.1 0.0.0.0 area 2
!
!
ip http server
no ip http secure-server
!
!
control-plane
!
!
line con 0
line aux 0
line vty 0 4
!
!
end


Best Regards,
Deepak Arora





Tuesday, December 30, 2008

PPP Peer Neighbor Route Feature

Have you ever come across an issue where you have got two Cisco routers, connected through back to back serial cable and are configured with two different IP subnets over the WAN link.

Lets take an example:

R1 is connected to R2 through back to back DCE/DTE cable. On R1's Serial0/0 we have ip address configured as 1.1.1.1 255.255.255.252; on R2's Serial0/0 we have configured ip address as 2.2.2.2 255.255.255.252. Now what you think ....will R1 be able to ping R2 address ?

Weird Situation :-O

Lets fix it using PPP peer neighbor route feature...trust me...not many people know this cool ppp feature :-)

PPP peer neighbor route feature discover the peer router's ip address and install a /32 host route for that address. Below is the sample config.
----------------------------------------------------------------------------------------
R1(config)#do sh ip int brief
Interface IP-Address OK? Method Status Protocol

FastEthernet0/0 unassigned YES unset administratively down down

Serial0/0 1.1.1.1 YES manual up up

-----------------------------------------------------------------------------------------
R2(config)#do sh ip int brief
Interface IP-Address OK? Method Status Protocol

FastEthernet0/0 unassigned YES unset administratively down down

Serial0/0 2.2.2.2 YES manual up up

-------------------------------------------------------------------------------------------
R1(config)#do ping 2.2.2.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
-------------------------------------------------------------------------------------------
R1(config)#int s0/0
R1(config-if)#encapsulation ppp
R1(config-if)#exit
-------------------------------------------------------------------------------------------
R2(config)#int s0/0
R2(config-if)#encapsulation ppp
R2(config-if)#exit
-------------------------------------------------------------------------------------------
R1(config)#do ping 2.2.2.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 12/47/112 ms
--------------------------------------------------------------------------------------------
R1(config)#do sh ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route

Gateway of last resort is not set

1.0.0.0/30 is subnetted, 1 subnets
C 1.1.1.0 is directly connected, Serial0/0
2.0.0.0/32 is subnetted, 1 subnets
C 2.2.2.2 is directly connected, Serial0/0
--------------------------------------------------------------------------------------------

Enjoy...

Best Regards,
Deepak Arora

Monday, December 29, 2008

Storm Control Feature On 3560 Catalyst Switches

1. Storm control is supported in physical interfaces .It can be applied also on etherchannel.

2.When storm control feature is applied to etherchannel the storm control settings propagate to the physical interfaces.

3.The rising threshold level can be specified in percentage level ( 0.00 to 100.00 ) , bps or pps

4.storm-control action shutdown command will error-disable the port during a storm.

5.storm-control action trap command will generate an snmp trap during a storm.

6. When the rate of multicast threshold exceeds the value all incoming tarffic is blocked untill the level falls below the value & only STP packets are forwarded.


Unicast storm control example:

SWITCH#configure terminal
SWITCH(config)#int fa 0/7
SWITCH(config-if)#storm-control unicast level 75 65

In this example 75 percent is the rising threshold & 65 percent is the falling threshold.

Verification:
SWITCH# show storm-control fa 0/7 unicast

Best Regards,
Deepak Arora

Sunday, December 28, 2008

How to get all interfaces summary quickly

To quickly get a summary of interfaces and addressing information from IOS you could use one of the following:
Router#sh run | include interface|ip address
interface Loopback0
ip address 10.200.200.11 255.255.255.255
interface FastEthernet0/0
ip address 10.1.1.1 255.255.255.0
interface BRI0/0
no ip address
interface Serial1/0
no ip address
interface Serial1/0.1 multipoint
ip address 172.31.1.1 255.255.255.0
interface Serial1/0.2 multipoint
ip address 172.31.11.1 255.255.255.0
interface Serial1/1
[...]


Best Regards,
Deepak Arora

Oops I added some config to router which I don't need :-O

I'm sure you know about the "copy running-config startup-config" command used to save your configuration. However, not too many people know about the command to restore your configuration back to the startup configuration after the router is running. No, the "copy start run" command won't do it. That just merges the startup configuration with the running configuration.

Since IOS 12.3(7)T, a new command has been implemented into the IOS: the "configure replace" command. This command will allow you to truly replace the running configuration with the startup configuration, just as if you had rebooted the router.

There are many variations of this command, but my favorite is the "configure replace nvram:startup-config list" command. This will replace your current running configuration with the startup-config file located in NVRAM and list the commands that were removed/changed.

Hope this will help :-)

Best Regards,
Deepak Arora