Sie sind auf Seite 1von 331
JUnIPer d > JUNOS SERVICE 5 5 PROVIDER SWITCHING Junos Service Provider Switching 10.a Student Guide JUNIPEr NETWORKS Worletwida Education Sarvlons £1194 North Mathida Avenue Sunnyvale, A 94089 USA 408-748-2000 ‘wi juniper net ‘Course Number: EDUJUNISEX Chapter 1: Chapter 2: Chapter 3: Chapter 4: Chapter 5: Chapter 6: Ethormet Standards Organizations coon ‘310 MxSeries Layer 2 Fstures 2 : Ch 229 themet Switching and Vitual LANS «+. heme LANE ove onto raging Cconiguring and Montoring VUNG «- ‘conrgiing ard Montorng RE ayer 2 Access Leaning and Forwarding COI ae {ayer 2 Froval Fitoring CII aa {ab L Eterna Stoning and VANS SII! gr Virtual Switches pr At Routing instances Overview 43 ‘contigiring end monitoring Vist Switches : CON Inerconnacing Routing instances CEES IDs ab 2: Vital Stes enero nsoose a6 Provider Bridging .. peered “5A Expaning the aridged Network . 53 Provider Bridging. 53 ‘contigirng ond Montaring Prowse Bridging 519 Provider Gabon Bring 2 sss ‘contigaing and Mentoring Proido Backtone Bridging 43 Lab 3: Prove Bragg 550 ‘Spanning-Tree Protocols. a coer ed voniow of STP : 63 ‘vorow of STP oe 638 vonnow oF STP cuiuni &a ‘vontow of STP : Sess ‘onfigating ana Moniorng Spanning Trea Pretocois : a3 Understanding SPOU, Lop, ara Rot Protest on eas Lab STP SE ees, Juniper Tomo Course Overview ee en Objectives JUMIPeF SSS ‘This to day course dosed to provide students wth nena switching knowledge ‘and configuration sxamples The course Incudes on oversaw of vtehng conceonts suc as, Layer odes lerring bridging, virtual LANS (VANS), solr brine, rower ‘bacbone biging, VLAN tarsltion sanningtree protacoe, and Eternst Oparetion ‘Admins, aa Waintranoe ON, This eoues alee covers unos ooertng ‘stam epncrimplaentatens of integrated Routing and siging (RO) eros, outing Instances, viral switches, lose balancing and part mire Thi ours bed onthe ures 05 Release 10.0R2.10. ‘Tnough demonstrations and hands-on abe, student wl gin experienc in conguring and rmontring te nos OS and in device operation, arte uocessulycomsseting ths cours, You shouldbe abl to + esate care there + Describe te arteren treme stanaars ogaations + Desrbe th Layor2seevess that aa srallabie onthe MX Seles 30 Ethernet Universal Edge Routers, + Deserve the funtion ofan there LAN Deserve earning and forwardingin a bring ronment + Deserise Etnernet ame fitaan. + Inplement VLAN aging + mplement RB + implement Layee 2 few fir + Deserbe the usage of routing stance + ert the function of vital over + esc tne unction of vital swe + Implement vitual swteh, + esrb intrconnacting outing nstancas, + Deserbe she sterent ntti of laces and Electronics Enneers IEE) WLAN ‘sacking modes + anise he components of rover bridging + conigre ana monitor provider bridging. + Describe te components of provider backbone bldg + Configure arc monitor provider backbone bring. + ipiain the purpose a he Sanning Tee Proton (ST + bescbe tne basic operation ofthe STP the Rad Spanning Preocol (AST, the Multiple Spanning Tee Prtool (USIP), andthe VAN Spanning Tee Protocol sre) + Configure and monte the STP, the RSTR tne MSTA, nd the VSTP. 1]? Course Agenda Day 4. Day2 ‘hapar 4:Couse invoastion ‘hapter2:Caror themes ‘apar3Eterrt Switching an Val LANS Lab 1 ethene Sitening and VLAN ‘aper 4vieual Switches Lab 2:Virual tenes choper 5: Prowler Siding Lab 8 Proaer Sing ‘chapter 6:SpanningTree Protcols Lab AST ‘nape 7 Ethernet OAM Lab 5 Ether O8M ‘nape & Eterna ing Potacion Lab 6: Ethernet Ring Protection JUMIPer Cours iganda» ~ Defined and Undefined Syntax Variables Fal this course cstingushes betwen regular text and ta ible. and algo ‘singulsnesbatvan stax aisles whore thevalueis aed sesened(dehred verleles) an sna erables where you must assign the valu undid variables Note that these ‘syjescan be combined wth the nat she 38 wel, sye Desciton cr TTatohare vavabiavalis waveady Varsabte — aeslned Variable ae “Tat where the variables value e [EndeEinad — theeers decrton and tet where cor thevarable's value oe shown nthe BE cag i guide igh afer fom the BadEtined othe user mustinaut Usage Example pelley my-peore (lek on my-poarain the dag. ‘pe wee policy policy-nane. ing 20.0.2 Seectite > gave, andiype JUMIPeEr ‘Document Conventions» JUNIPer NETWORKS Junos Service Provider Switching r Chapter 1: Course Introduction unos Service Provider Sitting Chapter Objectives “After successfully completing this chapter, yot will be able to: + Getto know one another + Identity the objectives, prerequisites, facities, and ‘materials used during this course + Identify additional Juniper Networks courses + Describe the Juniper Networks Technical Certification Progam ‘This Chapter Discusses: + objectives snd course contentinformatin: + Aiona Juniner Neto, ne courses an + Juniper Network Tchnicsl Cenifeaton Program UNTEM, ve unos Seniee Provider Switching Introductions = Before we get started + Whatis your name? + where do you work? ‘= Whatis your primary role in your organization? + What kind of network experience do you have? + Whatis the most important thing for you to learn in this training session? Introductions Those asks several question or you to anewor during os inodtctions, JUNIPer air neon» Gracie -3 unos Service Provide Sithing Gourse Contents = Contents: ‘Chapter 4: Course introduction * Chapter 2: Carrier Ethernet, ‘Chapter 3: Ethernet Switching and Virtual LANS + Chapter 4: Virtual Switones + Chapter 5: Provider Bridging ‘Chapter 6: Spanning:Tree Protocols, ‘+ Chapter 7: Ethernet OAM + Chapter 8: Ethemet Ring Protection (course Contents ‘The slide Its the topics we cscus inthis couse, pe unos Serva Prov cer Swiching Prerequisites "The prerequisites for this course are the following: + Knowledge of the Open Systems Interconnection model + Experience with TCP/IP protocols + Junos 0S configuration experience—the Intreduction to| Junos Software (US) course or equivalent + Routing knowledge~the Junos Routing Essentials (JRE) ‘course or equivalent Prerequisites “The side its the prerequises for this couse JUNIPEr tiene com {unos Serve # Prova Shing Course Administration "The basics: + Signin sheet + Schedule + Class times, + Breaks + Lunet + Break and restroom faciities + Fire and safety procedures + Communications + Telephonesand wireless vices + Intemetaccess General Course Administration The sie documents goneral aspects of classroom atministation, Sasi 8 + Coane elon JUnIPer ve Nee un Service rovicler Sutin Education Materials = Available materials: + Inclass: + Lecture material + Lab ice + Labequipment + online: + eLearning courses Training and Study Materials “Te side dass Education Servoes rates tht are avaiable for eference both Inne classroom ard one ‘ours nvoduetion » Chester 7 JUNIper unas Seve Provider Shing Additional Resources ‘For those who want more: “Juniper Networks Technical Assistance Center JTAC) + hitp//w Juniper net/suppert/requestingsuppor tr ‘Juniper Networks books = Coura toaucton JUNIPer Janes Serve Pouce Switching Satisfaction Feedback F *To receive your certificate, you must complete the survey + Either you will receive a survey to complete at the end of class, or we will e-mail it to you within two weeks + Completed surveys help us serve you better! —— Satisfaction Feedback Suniger Networt usas an electron survey gystamta collet and ane your “ommerts and feedback Depending on the class ou are taking please completa the Shreya the end of te chee or be sve t oo foran emai about tro weeks rom ‘Sass Compliion tat reste jou complete an oine survey form. sure that you provide ds lth your cunt evra address) _Sbmining your eee enetas you oa cotta class completion, We thank you in advance for taka the te one Us impo our educational offerings. v- : C C ours nvoulon » Gheplor 1-9 SUNS Janos Sevic# Prviter Shing Juniper Networks Education Services Curriculum = Formats: + Classroom-based instructor-led technical courses + Online instructor-led technical courses + Hardware installation eLesrning courses as well as technical eLearningcourses = Complete list of courses: ‘http://w juniper net/training/technical_education/ Juniper Networks Education Services Curriculum niger Networks Eduoston Services can help encure that yu hav the knowlodga and shal oly and manta costatectv, nigh gerermanos networ for bath mtrpise and service rovider environment. Wo have een tain stat wth dsp ‘echnical nd industry knowtede, roving you with nstUcoriedhancean courses inte assroom and onine, as wo ab convient, ot paca elseming courses, Course List Yu can ocess te ltest Education Services alferngs covering wide range ot Platoon tsy/wwm unioernetUsning/technes eyxton, a Se (Csanter 0 + Coume nvoduaton JUNPEE unos Serve rovielar Switching Technical Certification Programs "Demonstrate competence with Juniper Networks technology + Multiple tracks + Multiple certification levels + virtten proficlency exams. + Hands-on configuration and troubleshootingexems, + For more information and detalls on how to prepare for the exams + http//wuneunipernet/training/certieaton/ aNToP “The Junper Network YotncalCartifcaton Program UNTCP) consis of Datiormapectig, mulered acre that onasie pripats to demarstate though ‘combination of writen poficency exams and Randy configrtion snd ‘uleshooting mama, competence wth Juries Raters tecoiogy. Suocesstl ‘candidates demonstat thorough understanding of itenet and security| {echolages and Juniper Networks platform congraton end rubleshooting skis. ‘ou ean asm more infomation abou the JNTOP at ito /amaunipecnet/vaining carseat. te JUNIPER msn Gm Junoa Sani rover Staring Juniper Networks Certification Path *Up to four levels of certification for each track Certification Levels, {cen INTOP rk ns on to four certo ols. Juniper Netw Cert !nteme Associate UNCI and Juniper Networs Coitiedintmet Speciast NCIS) ‘tems ore computer-based exams composed af multe chloe questions These ‘computer sabe eras are sominatrad a roti testing enters Work have nopreequlsto ceteation requernats Juniper Networks Cord intomet Profesional UNCP) and niger Netoris Ceri internet Exoert UNCE) exams are composed nants on io exer tat are acminstere a soc Juniper stworks testing centers Professnetievel ana Exgertevt exams requis tat you fest obtain these lower ootieationin the Wack. Paso atthe INTCP Web ste at tp unis net/raiing/ereatir/ freeads information, exam prong and exam oatration, JUNI aS Se snes Service Provicer Switching Certification Preparation = How to prepare: *Trainingand study resources “INTER Web ste py /wr juniper net/tranirg/certicaton/ + EducatonSarvoes valning lasses Iepy//wivw juniper ne taining/teahnical_sducsion/ + JuniperNetworks documentation and whitepapers htp,//won Juniper net/teenpubs/ + Practical exams: lots of hands-on practice + onthejob experience + EeusationSenices tralningc'sses + Equpmentaccess Prepping and Stuaying ‘The side sts same options for hse interested in peprngor nip Networks caneation. ‘ours ivodieuon » Grapler 3 Juniper unos sevice Provider Sting Questions Oo ‘Any Questions? you have any question or concerns about the dass you a attending we suegest ‘hat you vole them now so hat your nto can best eds you needs ding ier Gaus rican JUNIREL JunIPe IPEr Junos Service Provider Switching Chapter 2: Carrier Ethernet C P C unas Senice Poser Swtcirg Shapter Objectives * After successfully completing this chapter, you will be able to: * Describe carrier Ethernet + Deseribe the aitterent Ethernet standards organizations + Describe the Layer 2 services that are available on the Juniper Networks MX Series 3D Universal Edge Routers ‘This Chapter Discusses: + camer eiemet: + Diferoe teenet tensa orgeizstons ane + Layer 2 sev that ar avaable on the Jarier Networks NKSeries 3 Univorsl Edge Routers JUMIPEr ar ae ‘ i Jutos Saie Provider Switching Agenda: Carrier Ethernet Ethernet in the WAN * Ethernet Standards Organizations. = MX Series Layer 2 Features Ethernet in the WAN ‘The slid its th topes we cover inthis chapter. i tous the hight topke first UNPep SSS TS Jutos Seni Provider Sthing Networking Terms = LAN: + Anetwork that is usually Iocated ata single customer site + Connects devices that are very close to one another = MAN: + Anetworicthat is located within a metropolitan area (city or town) + Connects devices that are within a few miles of each other = WAN: ‘Anetwork that can extend far beyond the MAN + Connects devices that can be hundreds and thousands of miles away from each other Local Area Nework ‘ALAN s usualy a network of thera switches and bide tat proves connectivity ‘etwwen end ston that in general are vory ose together Ia mt cates, the nd ations and switches ae wus the same bung “Metropolitan area Network | stopaltan Ave Network (MAN) is ocated within the corns of ey or town ‘here a service prover might havea fiber inratucure ora cable inrasuctre. A a provides te aby to connect customer sites tat ae stad rea each ler, Wide Area Network AVN alos fer sannecivty that extends far beyond he MAN. A WAN tylcaly ‘connects doles tat are hundreds ang thousands mesa fom each oe, ‘Sher JUMIPEF unos Seniee rover Swtehing Service Providers = Service providers (in most cases a phone or cable company) typically own and operate MANs and WANs: + Service providers usually sell the MAN and WAN service to ‘their customers for a monthly fee ‘In general, MAN and WAN networks are mads up of vast underground, underwater, and overhead networks of fiber = Acustomer gains access to the MAN or WAN through a local loop Service Providers When a business doxestoltrconnect wo orare sos hat ae not physialy ‘oar each othe, service provider usualy proweasbAl or WAN connect between those ses tape. Aerie ponder (cable conaany or oc) has tho facies ‘siov ae the milas endl ofbe-tat are necessary to Vanefer dota around he ‘worl A estore fe sere provider gansaccss tthe NAN or WAN tough 2 Teel loop of access ciel thet the sencs provide delves to each ste a Carter Sherset » Chapter 2-5 Juniper unos Sensce Provider Suithing End-to-End Connectivity = Several options exist to provide connectivity between customer sites: + Private line (DSO, T2, E4, or T3) +ATM Frame Relay + Ethernet "The customer must purchase and maintain ‘equipment that can support the Layer 4 and Layer 2 interfaces SitetD Site Connectivity Options ‘customers have eotons when tcomesto dering sendos frm te service provider It ‘he eusiomer sts ae relate) cons to each ater, the eure can purchase 2 Dateline sence Ton tha sance rove. Aptos pine Dot Cree ‘hat customers can order at varying speeds (050, T1,€3, 73, and more}. A the stance between ses rons, so dea thei fr te katona eve, Oar ‘options forststoste connectivity nude Ayrehvonou rast Moda (RTM), ram ely and now ememet Equipment and Expertise ‘Tosupgort the stent connesty, the oustomer must phase the corset auipment and have the expertise tobe abe te support he ew cats, The {ustomer wi eed ethemet exerts forthe LAN, sn the cate of ATM WAN onnectvy, thy wi need ATM experts 3 wel ‘haptare 7 Carer Barat Juniper ve unas Serves Prov der Switching Ethernet as a MAN and WAN Solution * Bandwidth needs from the MAN and WAN + As the bandwidth usage of the customers has increased, ATM and Frame Relay port speeds have not kept uo + Privateline prices have become far too high "Ethernet becomes the MAN or WAN solution: + Ethernet speeds have increased over time + 10 bps, 100 Mbps, 1 bps. and 10 Gbps + Ethernetis a technology that the customer understands, + CustomerIT groups are generally Ethernet exports ‘Allows the customer to have a single interface to the service provider + Intemst access and ste tote connectivity avera engl interface + Lower-cost customer premise equipment + HlghcpeedaTa equipmentsigriicartlyhighercost than Ethernet Bandwidth Becomes a Factor ‘er the last 20 years the noes fr high peat ances tothe Internet as wel as for ‘stotoete connectity has skyrecete. ith moreard mere vdeo, woes, and eter bandwitsroggganpieations bing places on the network ATM and Frame Relay etwas have ot boon acl to Keep up wth the dear Ethernet Is the Solution nem interfaces fasts £0 Gps are aaa. Soon speeds wll excood that lit as wl An Bernat souion in the WAN Denes aot he sence prover ant th customer in many ways Using Ethernet athe WAN sltlon the eto longer needs Ethernet and ATM experts ora te network, Service providers canoer ‘lle services using singe interface to the cusomer, hos of Sonat can eo JUMIper ae Juros Service Provider Swtehing initial Ethernet Challenges * Scalability: * Milions of customer end stations +The service provider envitonmentiearns a large numberof MAC addresses + Redundant connections between the service provider and the customers for resiliency + Spanningtiee protocols simply cannot scale SLAs: + Native Ethernet frames do not provide quality of service + Best effort had heen generally accepted in LAN network = OAM: + Fault management and performance monitoring + Monitoring and troubleshooting Ethemet access lirks + Circuit protection ‘Scalability ‘Aowing an Etorest Wl o ste hae avons posed a chalange tothesevce provider. or instance, fran Eternet sth to ornard Ethene ames must ear the MAG adres ofeach of tne end sation onthe customer nator Fora serves provider sarang thousands fcustarer, thie need mint ean hat eevee rorder-onned swtzres must tela lea milons of WC adress, iso, when Fedundant Irs ext betwoen the series provdar ands eatomars fr eliency Duoses, the question arses, “How can you prevest slong” Tre spanning tse oto of today snp cant sale o prevent he loops of thousancs of customer Service-Lovel Agreements Usaty whens customer purchases WAN sence, sevice ie aereements(SL4s) are Inplce to ensure tat he service provi prvides a goodserie to he cteme Common SLAs would cover rae delay end rare sa, CContrved on nest page hoot Juniper Jones Sere Provicer Seng Operation, Administration, and Maintenance “Te ably ora servos provider to provide and prove the sam lve of service with Etneret that customer eoul gat rom AM, rae Relay, and pristine sored ‘ended toe dovologed. Ethernet was also lacing Operation, Adminstration, ana Malterance (ORM) fetus. For examen te casa of AT, OXM feats would ‘tow administrator to very the stats of ATM perranert tual ecu (PVCS) This Sate capably was necessary fr Ether tual connectors (VCs). iw rat Juniper oe unos Senice Provider Switching Agenda: Carrier Ethemet *Ethemet in the WAN > £themet Standards Organizations “MX Series Layer 2 Features Ethernet Standards Organizations “Tho sl ghights th ole we cscuse net Juniper S JUNIPer nos Sen Provider Swiching Internet Standards Organizations * Ethernet standards organizations are developing standards for Ethernet services, architecture, OAM, and interfaces: * Metro Ethernet Forum + Institute of Electrioal and Electronics Engineers + International Telecommunication Union Ethernet Standards Organizations Several orgonizstons have been working sls te problems that Eherat poses in {he WAN. The tveo primary oanzatons tht are hing ta anabs Ethernet WAN ‘serves ae the Metro Ethernet Forum (MEF) th tuts ofCleces! ond Electonics Engneers (EEE. and the Iterations! elconnunation Union (71, Carer Sern Chapter unos Service Provider Swthing ‘Metro Ethernet Forum = Nonprofit international industry consortium dedicated to accelerating worldwide adoption of carrier Ethernet networks and services + Defines carrier Ethernet (also referred to as Metro Ethernet) a5 2 ubiquitous, standardized, carrier-class service defined by five attributes that distinguish carrier Ethernet from LAN- based Etnernet Metro Ethemet Forum “The MEF, asthe cefnng boty of cartier Emorat,' obaalion organo including Serve providers cat multe sera operators NSOS), network equipment manufetrer, sofre manveetirers sarnconditr Vena Sn testing organizations. Tne goa 9th HEF to acca i carer Shemet networks and sores. The ME Ubigous, standardizes, err cane gore defines ty fe tees irate on the ie) that lsinguien cra Eterot rom LAN based Ehomet, An obectve ct the MEF sto bul» consensus and unite sevice ponders savpment vendors ard ‘stoners an Ethernet sorvceSefntans tannal pactietons sna Intropercbiy ‘Shanta 2-12 + Carte Earns JUNIPEr peo Ju108 Sie Provider Switching Metro Ethernet Forum Attributes (4 of 2) "MEF attributes: . + Standardized services: a . + Eline. ELAN, and Tree : + Requieno changeto customer UN equipment + Suited for corvergedvoles, ideo ‘ahddata networking + Wide choice o aranutarty of bancwicth and quality o service options + Scalability + The ably for millons of eustomersto use the exvioe + Spans access, metropoitan,natonal. anc globe networks wth a wide variety of physical infrastructutesand service provers MEF Attributes: Part 2. Te side csbusses the datnons ofthe Standsréued Services and Soa JunIper unos Service Provider Sting | Metro Ethernet Forum Attributes (2 of 2) = MEF attributes (contd,): Reliability + Rap recovery time + Thanetoork shouldbe able to detect ‘ndrecove from outages without impacting users + Quality of Service + Many bancivcth and quay of service options + StAstor endto-endperformanceaasedon commited formation tat frame os. delay. and delay vrtion + Service Management + Abityto manitor. diagnose, ana centrally manage tener using stancarde-based mplementalions + carter cis OAM MEF Attbutes: Part 2 Tho sto dscusses te datntons of the Reality, Quay Service, end Service bo” MEF Standards (1 of 2) "Carrier Ethernet technical specifications: unos Senoe Provider Swiching Saaeeen errr eens anriate ‘Technical Specifications: Part 4 ‘These shows the MEF doveloped arer Enero eerie spetcatins, Juniper ‘carer Ethernet » Chapter 3-25 Janos Service Provider Sitting MEF Standards (2 of 2) Cartier Ethernet technical specifications (contd,) +All specifications are avallable for download at http://metroethernetforum.ore/ [rea eisar hetero f | k [irae forenoon Technical Specifications: Part 2 “Tho sideshows the cortnuation ofthe MEF dvelopd carrer theme echnical specteatons (ab, "Ghepter2-L6 + Carr Eterat JUNIP' O bo 108 Sei Provider Sutching ‘MEF Equipment and Service Provider Certification ‘= MEF launched a certification program in 2008 to verify compliance of vendor equipment and service-provider services to MEF technical specifications + Eliminates the need for expensive and comrlex testing between equipment vendors + Establishes a solid foundation for carrier Ethernet interoperability + Provides for a single, universally recognized test and certification process + Accelerates cartier Ethernet deployment at reduced costs + Eases making informed decisions about equipment vendors MEF Certification Program “Tonep ints obec wo promote ntroperabity bxween servos providers and ‘eaipment vendors the MEF inveduced now craton pra in 2008, The orifeaton apples to bath saves pevaers and equipment vendo Having 3 ‘Standardized oortfcaton ai but simnats the nee for expensive and corp Intereperabiny tots. unos Sorc Provider Switching Four MEF Certifications “MEF 9 (User-to-network interface capabilities) ‘Juniper Networks-certfied equipment + MxSenies devices ‘*MEF 14 (Frame delay, loss, and jitter): ‘Juniper Networks-certfied equipment + MxSeries devices “MEF 18 (CESOETH): ‘No Juniper Networks-certified equipment, = MEF 21 (Link OAM): “Juniper Networks-certfied equipment + IWxSeries devices + MiSeries Mulservce Edge Routers + T Series Core Routers MEF 9 Certification The MEF 9 coteation tests for compliance wth MEF 6.39, ap 11. This tast lenaures the meeting ofa requremonts tte aero newark neace (UN) Some ofthe tetsu + Nomooping ame dlr: + Single copy brosdcast ana mutsest delivery aad +Customer VLAN (ALAN) 1D preservation MEF 14 Certification ‘The MEF 34 corteatin tet or cumplance wih MEF 9 ara 10. Tis est snsuros + Frame delay svc performance: + Frame deayvadaton senoe pertormance and + Frame as ation sore patrmance Continued on net page Juniper JUnIper Jur0s Soviee Provider Switching MEF 18 Certification ‘Tho MEF 18 oarifiation ets for compton with MEF, Ths cortation ensures ‘he meeting of al quremants for relate anspor of tme-Svslon mui plein (TDN chcuts. Tis certienten icles some othe flowing tests + Encapsulation jes + Payload format: and + betes MEF 21 Cortitication ‘The MEF 21 certification tests or compliance wth WEF 20. The cartfoation ensures ‘he moog ofall equrements for UNI Toe 2andling OAM Features. Carier Ethernet » Chapter 525 unas Service Pevider Stehing Carrier Ethernet Terminology (1 of 2) = Carrier Ethernet terms: UN +A physical interface or port that isthe demarcation betweon the txlstomer andthe eervice provider + UNIType 4: Compliant with MEF 43 and manus coniguable + UNI Type 2: Automate service discover though EtnernetL.ocal Managementinterface: supports OAM + UNI Type 8: Povidesfor dynamic EVC setup + Anthernetntetace operating at 40 Mbps, 100 Mbps, 1 Gbps, (F 10 ops or +Customer equipment Carrier Ethernet Terms: Part 4 “The slit sts some ofthe common terms found a aca Ethernet net "Ghapter2-20 + Carter Ethernet JUNI f fo a sures Serica Provide Switching Garrier Ethernet Terminology (2 of 2) = Carrier Ethernet terms (contd,): + Network-to-network interface «+ Aphysicalintartace or port that isthe demarcation between stint cartier Ethernet networks, operated by one or more servic rovers + Carrier Ethernet network : + Anaccess, metropolitan, national. o lobalEthemet transport etnorkconnecting user endpoints Carrier Ethernet Terms: Part 2 “These oisausses some ofthe common ts ound in a caer Ethernet network per unos Service Provider String Ethernet Virtual Connection EVE: + Connects two or more customer sites or UNIS + Prevents data transfer between sites that are not cart of the same EVC ‘Defined in MEF 6.1. and 10.2 + Pointto-point + Muitipointto-mutipont + Rooted multipoint Ethernet Virtual Connection ‘An (EV0} carrer Etat seni offre by a sonics provider It connect two oF ore sites, Aoqurement ofan EVC isto provert data vancerbetwoon UN that are ot part of he some EVE. Three pes of EVOs ess porto poi, ‘ultipinttomulspont, and rots mulpaint ‘hanter 2-22 + Carier Ethernet Juniper po Janes Service Provider Switching = Eine service EVCs + Two types! + EthernetPriate Line (port based) + Virtual Private Line (VLAN-based) + Allow for communication between only two UNIS Eine Service EVE Apointso point EVs refered to 08 an theme ino (Lie) ENG provides Connect bexwoen an two UNE Wo yes of Eine EVEs et An Ethemet ‘Private Lino EVE ls ort based, where each ofthe UN is ddiated por to customer Al vitulLANS (VLAN) forte UNI can tore the EVE. Vital Prats Une EVCis WAN-bsed, such hat it lows forte napping individual VLAN tothe VG. This mappings the serve prover to maltpien multiple customers Ushi single access port JUAIREE on TT unas Service Provider Saleing Muitipoint-to-Multipoint EV¢ "ELAN service EVCs ‘+ Two types: + Ethernet Private LAN (port-based) + Viral Private LAN VLAN-Dased) + Allows for communication between two oF more UNIs + Ingress broadcastor multicast frames at one UNI are frwardetto allotier UN ELAN Service Eves ‘Mutipone:o Caer Cenet Jun ¥ 3 a yw unas Seniee Poviger Swing Rooted Multipoint EV¢ = E'Tree service EVCs + Two types: + EthernetPivate Toe Port based) + Virtual Private Tree VLAN-based) + Aroot UNI can send ingress frames to one or all leaf UNIS. “+ Aleaf UNI can exchange data only with the reat UNI += Useful for multicast video applications. Tree Service EVES Rooted multipoint EY are refered a8 Eee Es. The side describes the ‘orwaidng properdes ofan Eres EV. Eee EVCScome inthe form af ster an _Envenet ate Tro or Virtual Private Te, sms the Eine EV jUNIer anes Serve Provider Switching MEF Layered Approach = Threedayer model: + Application Layer + Encsuser applications carried by the Etnernet Services Layer + Ethernet Services Layer + Eves ‘Transport Services Layer + Variousnetworkingand macia types that delve the Ethemetservioes MEF's Three-Layer Mode! ‘The MEF nas dered a twee eer model or eatrar Ethernet neces. The -Aepleation Sarvicas Layer supports ender appleaions. The Ethernet Serices Layer carte the applesions sae the main oeus of te MEF. Carer Ethernet reas onthe diame Sances Layer To dalver the hers sarees the rans Servioas Layer uses various networting and medi types. Ts ayer neice technologies ke provider backaone bedgng tl pvte LAN sare (VPLS) acd 'SONET.As showman haste, each ayer othe MEF model ass nda, contol, and management panes. Sie F5S > Croat JUAIPEr arayeye vO" unos Senioe Provider Swtching JEEE Ethernet Standards The IEEE Ethernet standards fall into the 802 category: + IEEE 8023-Physical Layer and Data Link MAC sublayer for wired Ethernet + IEEE 802.4~Bridging and management + 802.10/802.19:Bridgesand VIAN + 802 1nd Provderbidging + 802. 1ah Provider backbonebriaing + 802.tag Connscty fault management + Many more IEEE Standards The tides some ofthe important IEEE Etherntstancars. JUNIPer See aera unos Senice Prove Suhching ITU-T Recommendations "ITU-T is the ITU's telecommunication standardization sector: *G series—Transmission systems and media, digital systems, and networks + 6.8040: ArentectureoF Etnernet Layer networks, + G-8011.1: EthernetPrvate Line Service + 6.80442: Ethernet Virtual Privat Line Service + 6.8032" Ethernet Ring Protection +Y series—Global information infrastructure, IP aspects, and next generation networks + ¥:1730-EthemetOAM requements + ¥732:04M mechanisms ITU-T Recommendations Tne slde shows some othe tamales! Telacommuneatin ion TelecommuniostonStandarizaton (MT) Eterntrecommendatns. Cot JUNIRE® yo Janos Seniee Provider Switching Agenda: Carvier Ethernet * Ethernet in the WAN * Ethemet Standards Organizations MK Series Layer 2 Features MX Serles Layer 2 Features ‘Tha slide els tne topie we dscuss net. JUMIPEr ‘anierEhemet » Chapter 2-29 unos Sanice rover Shing MX Series Highlights * MX Series highlights: + Designed for next-generation services at the Ethernet edge + Functonas Layer 2 switches, Layer 3 routers, or both + Piovideredge for Layee 3 VPN, pesaaaeraa Set + Fullyredundent design + Distibuted packet formaraing + Fullset of Junes 0 routing capabilies + MX240and Mx480 + Mlcange patos + Optmizedfor sites with space and power restrictions Mx Series Highlights “These shows som ofthe gas xSeries dovees. “Fear 30 > Coie re —: JURIPEE bo” unos Senioe Provicer Switching MX Series Layer 2 Features "MX Series devices support: EEE siut + 902.40: Brcging + ¥.4734:CFWand Frame Delay + 802.10: VLAN tage Meaauement + 202.194: Provierbridging _-—*-G.8032:EthernetRing Protection + 8021ah'Provigerbackbone * intefnet Engineering Task Drtaging Force + 802 19g cFW + RFCAT6::VPLS usingBGP + 302.3 clause 57:LFM + RFO4762:4PLS usingLOP Layer 2 Features The sideshows some ofthe Layer2 features supra on Mees devices. JUNIPEFSOS~SOSOSOSC TT unas Servic ® Prove Sithing Summary In this chapter, we: + Described oarrier Ethernet + Described the different Etnemet standards organizations * Described the Layer 2 services that are available on the MX Series devices ‘This Chapter Discussed: + cone there: + diferent Ethene tensors organization: anc + Layer 2 sero hat are smiabie on MKS “ae ae BEL 08 Sone Provider Switching Review Questions 4. List two properties that make carrier Ethernet more desirable than older WAN methods like Frame Relay and ATM. List the three prominent Ethemet standards organizations. . List three Layer 2 services that an MX Series device : can provide. JUNIPEF iriiana Baa unos Service Provide Senin ‘Suis s Gremae BE JUNIP: Junos Service Provider Switching Ne Per Chapter 3: Ethernet Switching and Virtual LANs unas Service Provider Suitehing Chapter Objectives "After successfully completing this chapter, you will be able to: + Describe the functions of an Ethernet LAN + Describe learning and forwarding in a bridging envronment + lmplermant VLAN tagging, + Implement IRB + Implement Layer 2 address learning and forwarding ‘Implement Layer 2 firewall fiters ‘This Chapter Discusses: Te funtion ot an Ethernet LAN: Learning a forwarding bridging environmant: Implementation of vets LAN (LAN) ten Inplementaton of integrated routing an ridge RG Implementation of Layer 2 ars learning and forwarding ond Implementation of Layer 2frewatters. ne ‘hapiar 3-2» EthametSwcing and Vial Ane JUNIPer unos Serie Provider Sutching Agenda: Ethermet Switching and Virtual LANs > Ethemet LANs "Bridging * Configuring and Monitoring VLANs = Configuring and Monitoring IRB * Layer 2 Address Learning and Forwarding * Layer 2 Firewall Filtering Ethernet LANS ‘These ists th apes we ow in this chap. We cuss the highgnted took tit unas Service Poder Steing Overview of Ethernet Ethernet defined: +Family of LAN specifications, standardized in IEEE 802.3 + 108ase-T(802 si)—10 Mbps + 1008a8e-7K(802.9u)~100 Mops + 10008ase-T(802.2ab)~1000Mops + Uses Data Link Layer technology to create LANS, + Shared mecium-asingle broadcastand olision comin + Uniquely cenities all noes.on the LAN with a 48.bit MAC adress. + Uses CSMAVCD to avoid and manage frame collisions. Ethernet Defined Ethernet safely f LAN spestcatios detnedin the institute of lacie! and lecrnics Engineers (IE) 802.3 standard. The sido es some common examales, Including the 803.1, 802.31, and 802.30 spocteatons. Een Ethomet implementation uses unique wringand sighaingstandera-pealy a copperbased rad or fbr epi‘ the Physica aye Atough the arlous mporantations ‘oF Ethernet can use various wring and signaling andar, ney alse a caren etressng format. theme is Data Link Layer etnology, s tne ty Layer 2 ofthe Open Systems. Intreannection (0! model of conenunstions, An Eheret LAW conats ca shared ‘aaium tat encompanes a ingle caaeast and calision domain Network devices, ‘afro as nodea onthe Cternet AN ran cata Innes hat are general Feteed to as rames, Each node on @ LAN hes a ungue deri so that os be Unambiguous ected onthe retwors Ethernet uss the Layer 2 mea acess antl (MAC) adress forts purpose. MAG asaresses are set Neaware ‘urease progronmed nto the Ethernet processor ef ech ode ethernet uses the caie-sense muti aoees wh clisen detection (OSMA/CO) proteol to avid ane manage rae cline, Geer a4 Ghana Scingommearats INP unos Sane Provider Switching Ethernet LANs (4 of 2) "Characteristics: Shared medium + Single collision domain + Nodes can transmit simultaneously Ethernet LANs: Part 4 "Ethernet LAs const of shared mosium that defn a singe colsion doar As ‘breviovs mentoned,Etnernet uss tre CSMAYCD protocol tohelp avo and manage ‘eam clison. The eae topology on a ada sews everes of rade connected ‘rough hub using a copper based physical medun. This ype oF mplmentation atone only a singla seam of data ata tine. Al noes patirpating itis shares Etieret LAN stn o vr that the ie sie bate arsmiting Ite tne sil, the nodes begin vansiting da ames muttpe odes listen anadetoet ha the Snes ide and then begin anemitng data ramas imustaneouyocalision osc. x When colisions our, an ors generated ana taut tthe Wansmiting ‘doves. when a noe raeles elisionentx message, stops tnemiting Immediately an wat fora period oF me before tring 6 senda fame again. the node coanues to detect colisions, ogressiveyncveases the time between ‘onthe LAN. The node ses backat algorithm to cscs tha reesing ‘aransmsion te intervals When anode does sceosfulytanem ethat tinficrepstes out a ports onthe rub ad al oer noses on tha shared theme ‘segment eee his aff fooding approach, coupled with ollains consumes pwr al» Grape JUnIper unos Service Prove String Bthernet LANs (2 of 2) *As the network grows, the likelihood of collisions increases: +s collisions increase. overall LAN efficiency decreases. Ethernet LANs: Part 2 thermot LANs ware egal implemented for smal, simple networ. Overtime, sis hae bozome age ard more compes. Asan EtternetLAN grows, teken003 ‘of collsions on tat LAN ako ows. As re usar in a shared Ethernet segment, ‘Seon patspatng node racsves an inva fail th papain odes for wai ts nat te actual destination. Tis unvants consumption of rework esouroas, long with an nereseg of cllsion,nevabiy decreases the ‘veal efency ont LAN, aerS-6 + Enenetsutounganavewatiate IO f O 2 unos Senee Provider Switching Agenda: Ethomet Switching and Virtual LANs + Ethemet LANs Bridging * Configuring and Monitoring VLANs + Configuring and Monitoring IRB + Layer 2 Address Learning and Forwarding + Layer 2 Firewall Filtering Bridging Tho side hilt the topic we seuss noe. JUMIPEF STINTS OST unos Service Provide Sting Overview of Bridging * Bridging: + Defined in the IEEE 802,10-2004 standara + Segments single collision domain + Isolates the Physical Layer + Learns and maintains a forwarding table (bridge table} + Performs inteligent forwarding decisions based on the bridge table ‘Bridging Defined Define inthe IEE 802.40:2004standara,rdgng addrooes some oft inherent problems orgs shared Ethornet LANs. Bagngusesmieseogmenatonto vice 'Sgecolision domi into mutp, smal, dgedcolisin domain, Reduclng the ‘Sz of cation domain eectvaly roducs te halo thet cols. maha Ths approse alco enhances parformance by allowing mult teams of data to fw trough te sah within a commen LAW or troadeastfomaln, rgngalons a mised colton of interface types and speeds tobe lacy ‘cuped within te same briaged LAN The abit to lgieally rou sina inrfacesin a trdge LAN envionment provides cesign Max not found na ‘shared Etharat LAN environment Srgng buds and mainais forwarding tabla, known 69 brig ade fora estnatins within th rida LAN Tho Widget bane ante ares NAC ‘sdrestes foal devices partspatngin he brig LAN Too bi alo can ei in intesigent orwaraing decisions This porcach reduces unnecessary tafficon he Sar tamioaevee "pee bem unos Service Prov der Swing Bridging: How Does it Work? ‘Transparent bridging builds and maintains bridge tables using the following mechanisms: Leeming + Leams MAC addresses and associates ports + Forwarding + Fornards packets out the proper egress interacetoward the ‘seston + Flooding + Repleates packets aut other pots for unknowndlstination MAC Adtesses: also used when passing multicast and breadcasttratic + Fltering + Units traffic tots associated network segment aging + Ensures brdgetable enties arecurrent Bridging Mechanics “Te wansparent bridge protocol allows a switch clan infomation about al nodes ‘ontno LAN, The sites utes hes ntrmation to reste te acess oop tables Foferad to a gga tbls, hat 'cansuts When fewaraing Uso (or two) ‘fstnaton an the LAN nen a sith feat connects to an Ethernet LAN VLAN, thas n information aout ner nodes o te retwork. Learning. recess sth uses to obtain the MAC faeeses of lthenades on the network stores nese ascrecsos na rig abe. Tleam MAC aaaresss, te such rad al ames that Seect onthe LAN orn the acl VLAN, toning Tor MAG adereses of sending nodes places these ‘ease itis brige tale slong we 9 othe pooas of iotmation fea wee reosiog ante meshed the “Tho wich uses the forwarding mechanism to dether vate, passing from an Incoming itrfae oan outgoing interace tot ese oor over) th Sactinaton. To foraas rams, he such consults the bldg ale determine wheter the abe ‘contains the MAC address caresponding ote destination oft rames. the ‘ig bi cortains an erty forthe casived detation aden, the witch sands ‘he ffs out the rteracesscocinnd withthe MAC arose. The sie lea consults ‘he beget. in he same way when oramiting ems tht originate on devices connect coat te sath, Cantnved an nee pg JUNIPer ernet Sching nd tual UNS » Chapter 3-9 unos Seevice Powe Seine ‘Bridging Mechanies (conta.) Flooding varsparent mechanian vee to deter packets to unknown NAC ‘acess, hein table has no ert fr a paul destination WAC adress, Crit he paca recived isa roadcoe or mules paca, he ch foots the ‘raicoutal interfaces excep the nteace on which twas canna tree oFgiates onthe sec, the sch lode that afi outalintertaces,) Wen tho \ntnown destnation host respands tafe it has boon Fooded though a Switch, ‘he stan learns the MAC address ofthat rode and updates ibid abe with the source MAG adres ofthe ost and ingress pot. “he ftering mechani nts vate ts essoites nett eagmentar YAN. AS th numberof ens In thei abe gone, the suo loss gether an Increasingly compet plete othe inal never segments the pte caries rich nodes belong to which network, The sien soos ts information oe trate. tering prevents te swch om forwarding ua am onenetwork Seger to Fry the site uses aging to ensure that nly aetve NAC adress erties rein the bilge table For each MAC ates nthe ble abe the se reco 2 ‘timestamp of when earned te ifort about the retvork nade Each tne the ‘shch detects rae tom @ MAG saree, updates the Smear. ion the ‘swith periodical checks the inestamp; he timestamp solder tan he iobai-nac-table-aging-tine value (cussed ate ins capt, the _Swch removes the rode's HAC adress from the ridge ate ? unas Seales Ponder Switching MAC Address Learning en MAC Address Learning. Theslieitstates a basiovew of te MAC adres laring proces. ln this example, eaen ach port connects @ hub and he aaa nubs have mute connestog fades, A each nade snd taf toward ta ther odes onthe ria LAN, the ‘ch eviews hatred rants 8 MAG ada tab (abridge ae) base On| ‘he soues adress ofthe sender slong wt he sen porton when racehea the ‘tf inthis example, we soe thatthe MAC adoses fo Ai and AZ are associated wn or g@0/0/0,wheross the MAC edérosses 0°62 ana B2 ae associated wth ort 70/2 unos Srvc Prva Sting Forwarding Known Unicast Frames (4 of 2) [Sete cman | ean en Forwarding Known Unicast Frames: Part 1. Inthe example onesie, At sends a ramet 82. The frame i rapested out al ors onthe attached ub, whi eels in ames travengto bath A2 as wall the “ch shown inte mid ofthe trustation. a2 recsves fe rome and detects that ‘the desthtlon WAC aderass dons not toh He onn MAC aresoy ot whch tn 2 ‘dscarsthe frame. Te wich rcoes the frame, checks th MAC address tabla fro Iathing ent, and towards tho fame out the assocted fort bared onthe loko. ‘sults, Uta, 82 reeves and procasesthe ame whe Bl rece and ‘scars thea ‘apie 3-12» Ethernat Suing an Vital ie JUNIPE be Forwarding Known Unicast Frames (2 of 2) Juniper ures Series Provider Switching Forwarding Known Unicast Frames: Part 2 inthis example, A sends tame oA2. The attactes hub ecb the frome and sends oval ports, vn esis in auplste Fames sent to Aza wll as tothe Swen 2 rece the rome snd tans that the seattion MAC addrene motores [own MAC adress at which te A2 processes be fame. The sth race the ‘fame and chooks the MAC adress tale fora mating ene. The etry in tne MAC ‘ress tabi shove the egress pt, whieh, in hs exams the same port on ‘neh tne snitch reosNed the ram Because te egress porn te WAC adress {eal the same port on whos the rae wos rece the sth tors the fame. ‘there Swishingand Waal LANs + Cnaplr 3-13 unos Sanice Prova Sting Flooding Broadeast, Multicast, or Unknown Unicast Frames Flooding Frames, Flooding i used len 8 NAC adores nt recorded inthe vide table This ‘mechanism salsa used when sendingbrandeast and mery cases, mutteast frames. The exarplon te sie shows Ai sending a trade ame with ‘ostnaton MAC adaess of FFFEFFFE.FFFF tthe LAN. The allachec hub sens the frame out al ars The sich Foods te eoadeas frame oi al ports ateoclated ‘wn te LAN, except forthe port on wich reenact eee The soca shows het, Umass at nodes ante LAN receive the ame, oe sues Senco Provider Switching Viewing the MAG Address Table Use the show bridge mac-table command to view MAC address table entries Sorntisaanecies b gearonco | Viewing the MAC Address Table Use tne show briage:mac-table command ovew alent win the MAC ‘ataress abo. This commana generaas esto leamed WAC saaeases alongwith {ha coraponding VLANs and ntraoes lenge are oraned based on thse ‘ssociated WANS unas Senice® rover Siting ‘Glearing the MAC Address Table "Use the clear bridge mac-table command to clear the MAC address table contents evo boning demain, o¢ "on ise doce ares cntce fab for Sacliie sntertace Clearing MAC Address Table Entries Use the clear Bridge mac-tabe commando clearal entries yin the MAC ‘res tae. Optonly you can us he Inter #acm opion tear ol those MAC {ate entries eared ough the specie terfee, Te following ene Mahan house of tia Enter zace option lserdewitchs show bridge mac-tabte Whe Flags (5 “static WAC, 9 -dynanie Mac, SE “Statistics enabled, 1 -Won configured MAC) outing instance + defau2e-switch Bridging domain : vian_i00, VtAN : 100 wae wae | Logical addzees flags interface Corsisssimpsearys & 70/00 Doraisss:abiea:99 B 0-1/0/3.0, Routing instance : dafaslt-aviten Bridging domain : vian_200, Vian Nac Rac’ togseal Gor21:S9:abiea:97 9 a oor21:59:ab:6a:99 5 a6-1/0/3.0, Continued on nex page pe unos Sonice Povicer Snitching Clearing MAC Address Table Entries (contd! user@awitel> clear bridge mac-teble interface go-1/0/3.0 usee@mvitch> show bridge mao-table wie flags {S -static Ac, D ~dynamic HAC, ‘SE “Statistics enabled, aM -sion configured snc} Routing instance + degault-aviten ‘Bridging dessin | vien 100, VLAN ; 100 uae mac’ ” togicat address flags interface Doratss9-apsRas95 | D 50-1/0/0.0, sac flags (5 -atatic wAc, D ~dynanic mac, ‘SE “Statistics enabled, 1 -Non configured HAC) Routing inatance + defautenawieen Bridging sanain vian_200, VIAN : 200 uae Bac | Legteat address flags interface Boralss9sabiaa97 | 8 geni/o/2-0 5 Swicing an Virtual [ANS » Chapter a7 JUNBEL unas Service Provide Sitting Agend: Ethemet Switching and Virtual LANs = Ethernet LANs * Bridging Configuring and Monitoring VLANs * Configuring and Monitoring IRB * Layer 2 Address Leaming and Forwarding * Layer 2 Firewall Filtering Configuring and Monitoring VLANS ‘The slid Mgnt the tpl we dacs ne. eR eisanraewe Ber pw unos Soni Provider Seitching Overview of VLANs = VLANs: + Segmenta single broadcast domain into mutiple broadcast domains + Allow for grouping users based on business needs, regardless of physical location VLANs Defined _AVLAN sa coletion f network codes that te logealysrouped together to fom Soparate broadcast danas. AVIAN hes the same gonerlatriotes a pte UU, out ows at neses ora pertoulr VIAN to be rousadtogetnerrogardless ot pnsialacauen. One advantage fusing VLAN i eson fey. VAN alow [gouningofiaidual users besed on busines neo. You can eetatish and Fraimainconnectvy win a VLAN cough softws oniguation, wich makes uate such a ajnairic and exe oon nodeysnetwortng emironmonts JUMIPEE RnR csr ao ons Serve Provider Switching ‘Switch Port Modes = Switch ports operate in either access or trunk mode + Aovess mode: + Connectsto network dices (desktops. |P phones. pines and so forts) + Typleaty transmit untagged Etnemet ames fora single VLAN *Trunk mode: + Connectstocthersuitshesora router + Typical transmits tagged Etnernetrrames for multiple VLANS—the exceptions are winen the nathe VLAN option is configured or when contaltratic is sent Switch Port Modes ‘Swit ports eperatain thar aocess mode or turk pode. ‘An acess por connects to nator devices such as destop compte, phones, ‘rns or eserves. Access pots Yoiealy belong to a srg VLAN ar uansmit ‘and recche umagged Eteret ames. ‘trunk port peal connects to another switch orto a cusbmereoge rue Inertaces conigired for rank mde handle wae fer mutsie VLAN, musing ‘he wafer al conigured VLANs over the same piysicaleeneclon, and separating ‘he vac by agar with he aporoprite VIAN. Turk ors can aka carry niague rari when configured wn ine naeive-van-ia sistement. Furthermore turk ports send eonvl Waffle untagges. SSewrs20 + eestoataingertveate IUIPEE re unos Soviee Provider Switching 302,10—Ethemet Frame += 4-byte tag inserted into the Ethernet frame (max 1522 bytes) + Tag Protocol Identifier: 16 bits, default 0x8190 + Priority: 3 bits, 802.4p canonical Format Indicator: 4 bit. default 0 + Unique VLAN identifier: 12 bits 802.19—Ethernet Frame To consistent acsecite trac wth a parteular VAN the india tames must be ‘eaged 9 they pas tought network. These sstrtes on 802.0 eagsee Ethemet ame elong with tekey components Othe tg-, + Tag Protea! enti (PID, + Pri + Canonical Format inceatr (FI and + Unga VLAN eniter() JUAIPGF Senses ra pera at Janes Seno Provide Senin 302.1Q—Trunk Links *Atrunk is a single Ethernet link that can carry traffic for multiple VLANs 802.19 Trunk Links _Arunk i singe Ethernet ink used to cary wae for mute VLAN. Ato ink ‘ypealy interconnects mats switches ora sich wih acstomer edge outer As ‘shown on te se, interorae configured a ru prt hana ae fr mute ‘YLANG, muleioang raf oral configired VLAN ovr = sing sys ‘connection ratner then using separate pysical inks for eae contig VLAN, Sanaa EnaaaaeaTaNE per yer unos Senio Provider Switching Access Port Configuration (1 of 3} "Define the bridge domains (broadcast domains) and VLANs to be used for switching Define a Bridge Domain “oallow an NX Series 30 Etnemet Unreal Ede Foutetoact asa ston and build «2 MAG adres abe you must rst pect ine porteular VLAN Ds tat it il for the pepoee of switching, Te do so, spect the spretateVLAR I as part ots normed big domain, Ts meted request you configure enen VLAN aa part of singe bridge domain On afolowing side we cover now we can spac eavra VLAN within single orogecomain using the vian-id-1se¢ tatoment JUNIPEr ‘ihren Sishngand tial LANs» Grape 2-23 Jones Senice Provider Switching Access Port Configuration (2 of 3) "Assign the interface to the bridge domain andset the interface mode to access [Tie riao- i sot pase oe | Ses] ‘Assign an Interface to Bridge Domain Toatlow an interac to act as an acess port for a prtclar VLAN ou must sect Itsintertace mode es access and you rust sot) the VLAN to which lblores. Far ‘2ezes5 pots you ust ube othe unt nomber. ‘amie 2a» heat Sang and Wal ANS JUNIPer pe sures Servee Provider Switching Access Port Configuration (3 of 3) = The following method is another way to add an access port to a bridge domain: + Acoomplishes the same objective as the process on the previous two slides asic) Another Method ‘The aide shows 2 secondary (rigs! at) metnodio aocomossh adéng the 151/0/0 interisee as an aozees porta VLAN 100. ihe metho is arceptabe, but te recommend hat yu choesa are method green sowusion However You can JUMIPCF CSCS ev totinc oar a = Cir Janes Service Powe Siting 802.19 Trunk Example (4 of 2) or MAES T So"260 210 sap £802.49 Trunk Configuration Example: Part Tesi tustrates an 802.19 trunk congwation expla. tis case telneriace Iscontigured ase wn pot ands assoit wth the van 100 and via. 200 Oke domain. The parting ten vould have» sel congivation or the nerace funeoning as ti The side aso ust the usage ofthe nat ive-vLen-i statement. Ms enfigrationstaiemant does wo thing, Ft, fierce gp-2/0/3reoowes ary Uitaged amas, asscltes those reas a VLAN 100, Secon, Fnerfacs £6:1/0/3 ansmts any outgoing ames tat associate wiAVLAN 200, thay transmit Sseuntagges ames, Notice the visn-a-List statement it specifies the VLANs to which te ntertace ‘wil bea mame The folowingsiatements ar examples oftow you can use the + vaaneld-1iee {100]:VLAN L00ni + vaancid-1ise (100-200); WANs beeen 100 ard 200, + vaan-id-1iee (200-109 212-200): Ar LANs between 109 ane 200, except VAN 130; or + vaancid-1ist (200-109 112 113-2001:A LANsbetwoen 190 and 200, except VLAN 120 ar 112 a. Jones Seniee Providor Switching 302.10 Trunk Example (2 of 2) aun ‘espace vaa-aieper £802.10 Trunk Configuration Example: Part 2 The site shows. secondary (gal sive) methato accomplish adding the 12-1/0/3 intace asa trunk portusng VAN ID 100 and VLAN 10200. Either ‘methods acceptable, but we rocommend that youhoose ane matod to prevent [onfsion Hower yu can use both maths sataneoucy, unas Serce Provider Sching Dealing with Large Numbers of VLANs Service providers typically deal with thousands of bridge domains and VLANs for each switch: “Use a single statement to create multiple bridge domains, + Brig domain names take the fom prafixe-v1 an-nunber Sec eto etapeamine ASSSig arcana "Sage domain vow retectace Dealing with Many VLANs ‘As oposed to configuring invizual ridge domains for eachVLAN used for sting, ‘be hos operating jtam allows forthe coniguaton of mary VLANs within a ingle ‘ridge comin. Th se shows that Instead of ung the vast_2astaternn you ‘would use the vian-{c-1.gt statement The usage ofthis statements sma to ‘Be usage dostibad onthe previous page. When using the vian-ia-List statement the swich automaticaly configures the appropri bridge domain, wien have names tat ak the form preix-vien-nunber were te prefix tthe configures bridge domainname unos Sovice Provider Svtching Monitoring VLAN Assignments Monitoring VLAN Assignments, ‘The sid shows some tay commands used ta montor WAN assignments ntis ramp, tne ge/0/3 terface belongs to te briage aomein named van. 109, ‘heh hea an 802.19 tof 200. Because tis neface's configured asian access or recs and transmits ony uragied frames. fa Wonk ort wore ale ‘configured to pass traf fx the van_200 Bdge dann, would add and rene ‘a 802.10 tg vale of 100 fora trafic for tne van. 00 bridge domain We ook {329 Wank part cantaration ana mentoring example at. ‘chapter JUNIREL unos Servic Prosder Swthing Monitoring 302.1 Trunks (4 of 2) “Use the show interfaces command to determine the interface mode Sa ees Ae rs ae Erie Set ena oer iii SSE en a Se we Tig: trtrpeneteee eapeiaion etcenecacape steel sete, or 1514 igs fentieae Monitoring 802.49 Trunks: Part 1 ‘he show interfaces commana shows thi the ge/0/ ntertace ie cnt ured fortran mode, meaning wil wars VAAN ies peo Juros Seniee Provider Switching Monitoring $02.4Q Trunks (2 of 2) Use the show bridge domain command to determine the interface VLAN assignments ES ‘Monitoring 802.40 Trunks: Part 2 The show bridge domain command shows thelntertaoes and tr VLAN assignments. JUNIPEF SCSI RSTRNT + Gar {oa Seni Provider Switching Monitoring Bridge Statistics ‘eoadeast pockets " SS ‘Monitor Bridge Statistics The show bridge stattetios command displns tafe ststetes end MAC ‘unt internation related to each eg iterface of the ste, (Chapter 3-32 + Bharat Sching and Wu JUMIPEr pe unas Senive Provider Switching Agenda: Ethernet Switching and Virtual LANs * Ethemet LANs * Bridging = Configuring and Monitoring VLAN Configuring and Monitoring IRB * Layer 2 Address Learning and Forwarding "Layer 2 Firewall Filtering ef eet configuring and Monitoring IRB “The ss hignghtsthe tole we cuss net. Jone Serie Provider Suteing IRB Interface IRB allows for both Layer 2 bridging and Layer 3 routing in a bridge domain ‘An IRB interface Is an IP gateway for the hosts of abridge domain IRB Allows for Bridging and Routing Ifyou use Layer 2.only Ethernet itch ro Layer’ funeral, hen you must add 2 separate route to your envrenmant te prodde routing teen the subnet ow ‘nt sce However an WX Serie routr ean act a Dt aay 2 Etemet Swen {nd a outer atthe ean tins. An Inrfaco slog! Layer ineriace vad as ‘an gxtznay foe VAN. Te allowing sos provide come aton and mentoring, ‘ramps fren I intetoe, 8 ‘hepter3“Ba" + Ethernet Swching ond Vtual UNS JUAIP be unos See Providar Switching IRB Configuration Example en iy tee ¢ ee RB Configuration Example The sie provides a configuration exami fran FB aria. In his exams, the ston performs Layer 3 lookup when reels ttf witha destination MAC eas that sto on MC address ortho sian parfor nl outing "poration th attached devices must have configured gateway adresses that match the arose associated wth the coresporng near, JUNIPEr Rares ose unos Sanice Provide Snitching Monitoring an IRB Interface Use the show interfaces command to verify the status of an IRB interface op inne rraazezanae a) | SSS (ere rrr eee rR amo Dour] Monitoring IRB “Tha side Ista kay command used montor an IRBintrece,andshows the outout ‘rom tie show intereacee terse comand. This comand shone te sate and |P adress informatien fron IR interlace. As nested onthe se, toast one _actve port must ssodate wt the bie domain for thar rts to be ‘eminiseatwoy up. rat Swtching and WaT JUnIper ye unos Sevice Provider Switching Verifying Routing "Use the show route command to verify the router's. ability to route between the appropriate subnets ear cas Verifying Routing ‘As with any roster, wen yu configure an Padres for an interac cn that ou routes are utero aeded tothe routing tae. nthe Junos OS, fr each ‘onfigred IP intorfaoo, vo route are edo tothe routing tase One rout ie host route (32 mask thats used to forward Wa tathe Routing Engine (RE) wen locally destined packets ere. ha ther ruta ate othe network subnet ‘wie that earface beers. This outa atows the ute to route pacotsto other hosts on hat same subnet. Tha side snows mat ou routes Were added 9 the nat.O ‘abla. recut of contgung two IRD itaraces JUAIPEF RNS STOUT cree unas Sonic Provider Switching Agenda: Ethernet Switching and Virtual LANs Ethernet LANs * Bridging Configuring and Monitoring VLANs = Configuring and Monitoring IRB ‘D Layer 2 Address Learning and Forwarding = Layer 2 Firewall Filtering Layer 2 Address Learning and Forwarding The site hight the opie we acuss nex. Jur0s Sane Provider Switching MAG Address Learning and Forwarding = Aswitch learns the source MAC addresses from. incoming frames and learns destination MAC addresses as a result of the flooding provesses: + By default, the Junos 0S performs MAC learring, butt allows for you to change the default Layer 2 earning, properties globally, per virtual switch, per bridge domain, and per interface level + Timeout interval for MAC entries (efatt is 3005) + MAC statsties detautiseisabled) + Maximum numberof MAC adress learned defautie 393,235) + Turnoff MAC fearing [MAG Address Learning and Forwarding ‘awe discusses prevousiy inthis chap, sch eams MAC addresses from Incoming ames es we as om ine flooding proces. The Junos 0S alows You > rte the dete VAC earning behovie: Te sets the things that you can ‘change as wi as wnere te changes can app to asmten. The folomngist aroces ‘irae values foreach of the MAC leaning properties: “+ Ac timeout intent 105-10000008 3005s the detau ‘Mpc statisti an be enabled (aeble by fou) Global ac um: 20-s048875 (393235 ne cera + Swit Mac it: 16-104887S (61206 the default . + Brige domain MAC iit 61048575 (5120's re default and + Interface MAC: £-131074 (1028s the defau p@. “oview NAC station once you enable te feature ane the ahew eke Juros Senice rover Sitting Global and Switch Address Settings * Global level (all virtual switches and bridge domains) (lobl-mac-stetiotsce “matie whe mice atistic at svetan seed SSESCTESES Sti the spon eel wad tas splay ine Her n00008 [Bieme-taiog oie dante 8c asses etcng ot ston * Switch level (all bridge domains for the virtual switch) $j tiptigesupeenspe ante neni soaeigueetion dn flonan aap 2 EEEESTT" cua or sopuing tame apo Global Level Settings loa evel etings apy mat virtual switches (cussed 9 ator capt and al edge domains. Switch Level Settings ‘wc level setings apply tal bridge domains assosatd ith avituel seh, ‘chapter3-26 tos Sania Paver Switching ‘Bridge Domain and Interface Address Settings += Bridge domain (all associated logical interfaces) uy groupeeacagt Sue statse Snciquntion sate fee ste atop roSnateiarning Gustnie Syncs te sosast ara + Interface level (single interface) + appay-aroupe ‘Scoupe trom sich Co Soheeit contigeation data Bridge Domain Level Settings Setngs a this evel aot interincas asociatd hte Bdge domain. Interface Level Sotngs at this ove atfoct any the ierace specie inthe conga unos Senco Provider Switching MAG Table Size Example "Specify the mac-table-size number option to limit the number of learned MAC addresses for the bridge domain: ah Layer 2 Learning Example The eamle onthe side shows atthe MAC table sl forthe bridge domain changed fom te cefault oF 5120 ts 4000. By deat. wen the aig dosaln MAC ‘caring iit ie resced, te device doesnot an ary more MA addres ut ‘onwards o floods wae inthe oaee of rsmown desta, The ake shows that {hs default behavior was everden oo tat Enemet frames win unkown ‘estinaons wil drop whon the congue it is reschee, (Ren AE Gratsuiangenrwmarans IU IPEL unos Sonioe Prorder Svtohing Monitor Layer 2 Information "Use show 12-learning commands to view Layer 2 ‘ante at tation mil information Ea Layer 2 Learning and Forwarding Status These shows some othe commands thatyeu can usa to view the Layer 2 earning and forwarding satus forthe ste, unos Senos Provider Switching Agenda: Sthernet Switching and Virtual LANs ® Ethernet LANs = Bridging = Configuring and Monitoring VLANs * Configuring and Monitoring IRB * Layer 2 Address Learning and Forwarding PLayer 2 Firewall Filtering Layer 2 Firewall Fitering ‘The sie highs the tpiowe dacs nex. ‘raptor 3a + Beret Swiching ae Vital AN JUnIPer oe Junas Seni Provider Switching Layer 2 Firewall Filters + Filter frames based on their contents and perform an action on frames that match the filter, ‘Filters can accept or discard packets based on: + Address fields + Protocoltype +YLANID +802 .1p bits +P address of the packet carried within an Ethernet rame ‘+ Many more factors Actions You can use fits to control ne fames destined othe RE 98 wo as cota ames psssng tough ta route. ‘Acceptor Discard You can cee input tors thatatfetonlyintourd wae and output ers that affect ‘only cutbound vat. Fits ean ascent or sar Tamas based onthe contents of the ame’ adds feds, prosecel ype, VLAN ID, ven the 02 3p Bt fel inthe frame teaser unas Senice Provide Staring Layer 2 Firewall Filter Syntax + Syntaxis similar to that for policy statements "Defined under the [edit oor etch) any bese firewall family bridge] cn ne ( hierarchy level ‘came! "Named filters, one or more terms ‘iterustson ‘Terms process sequentially at + Al frames match a term when ‘ction a from condition Is not specified slcemaiens + An implott discard all exists for ‘en eine) ‘ramesthat do not match any term * Actions: Accept or discard 7 + Modifiers: count, galice, and so on -AJunos 0S itr consis of ne oF more nated terms, slat ply statement, ath cern haba sto maton condtons procededby the keyword from, anda set of tons or acton mods prosedod bythe Keyed than. Hierarchy Level Layer2trowalftrs are defined underthe [edit ficewsl family BeLagel section ofthe contiguration het. (One or More Terms, re teem at ant ona tre neem) A ena sas 9 Erameondon fs pesort then al rams mach ifr ras match on tom tho default acon’ to cars th frame sendy Toke caret ensure at wanted ames arenoliscardea. Ue the commansine nace (CL) Sager, copy, and rename funcions to assist inte managemontof your mutter feral ites continued on net page. SRR ES* GratSetangmrvmmtatsIIPEE wo Jos Service Paver Sutehing Actions and Mosifiers ‘After can arcos fame fr normal warding oacarda tame siemty, You can ‘mod these acions by apping« mar. For exo, you can soni the eeu Inoaiertinvement unter We daciae oer modes onthe sowing ses, JUnIper ‘Beret Sucing snd ual LAN + Chapter 3-47 unos Sanice Provider Sting Applying Layer 2 Firewall Filters You can apply Layer 2 firewall filters to either an individual interface, a bridge domain, or to both + Interface level + Youcan apply a single ter for each interface (input. crput. or both) + Appiya chain ofits using the inpmt~Liat or ontpat=1iet statgments + Bridge domain level + Youcan apply a single iter for eschbrgedoman int only) + Interface and bridge domain at the same time (input only) * Tsinaace tris processed tt ftowesty he ree domain al Applying Layer 2 Firewall Fitters ‘ones you congue a renal er, you must appt itt one er mare trees. You face intesface interface-nane unit suber Tanliy beidga esieer! lvl of the coniiaton heey o acpi aftr to lintrfacas that belong to pater Sige domain, youzan apa eval tor atthe [edit bridgerdenain nama forearding-oyelons. flee] lev ‘ofthe configuration ere. eave ers are apled aint ers ta the Intorfaoe and brdge-domain evel, the Junos Olga eongatonates the bide omalniovel ite tothe end ofthe rtrface evel ite, ‘te that you cannot we bse domain-ve ira when re wlan-ta-2hee ‘Satoment was sod to coate th dee domain. ve unos Sonic Provider Stehing How Filters Are Evaluated + Single-term filters’ + Ifthe frame matches all the conditions. the device takes the action in the then statement + ifthe frame does not match all the conditions, the device discards it * Multiple-term filters (terms evaluated sequentially): +The Junos OS sequentially evaluates the traine against the conditions in each term's from statement. beginning with the first term “Ie rare matches, the device takes the action nthe ehen statement +a frame passes throughallthe terme inthe ier without rmatehingary of them the device dscardsit * Filter lists (chains) are concatenated logically into a single filter Single Terms. When areal ite: consis of sng te, he er vlusted as oon tthe ‘nome matches al ts condos, mn cevcs aka he acton Inthe enon statement ‘tno trome docs not match al the canons, the aves scogsi Muttpte Terms, ‘nen a fre fitar consists of more than ane tern the iter sealant sequentially Fist tho frame i otauatoc agit te condtions inthe From Satemeont inte fist nr ithe fare matchos Ye deve takes th action inthe ‘chon statement it does not maton, ts vaste again he condtons the Fromstatamant Inthe second tr. Ths process cansnues url ater he fame maton the Eran condton inane ofthe subsequent terms o uni na mare terms Ira tame passes trough athe torms in he fier nhout matching ay of thr, the ‘device dca Ira tem does not contain a fom sttement, the fame considered match, and the dele tae ta action heteum's then latament Ita ten doos nt contain a then statement, rif) do rt configure an ston in the then statomert hat ste fama ust coursed), and fe Frame matches the conations inthe tarn’s €zamtatarant the davies acopis the rama Continued on next page. Juroe Series Provider Senin Fiter Lists Instead of appyings singe te to an interface using er np oF Reroute, you can apply ist of up to 16 ters You paocn this ston wh the Lape “Lis ard oeepue “list kenords. JUnNIPer ve unos Senlee Provider Switching Firewall Filter Match Conditions (1 of 2) TSB eccot Set Belts satin use tm pane cope to nt sath forecting hare beeen Ease ‘Match Conditions: Part 1. ‘hese shows some of the ary match contr that ou can use ina Layer 2 fava tr JUAIPEG ee ITEM epora oT Jungs Sanvi® Provider Switching Firewall Filter Match Conditions (2 of 2) Match Conditions: Part 2 ‘Tesi shows come ofthe many match conctons that ou can use ina Layer 2 ye unos Serie Provider Sutching Firewall Filter Match Actions = Match actions determine what happens to frames ‘once a match occurs: 1+ Besides accept and discard for actions, you can apply ‘modifiers to frames like setting the forwarding class, andl sganunon eet eseeusl fany args Eltee nampa Geen 30 then oe eae cece Match Actions accept and discardare the actors that you car apy to ame, However you ‘an aap medifers tone amas a5 wel + coune: Ths modifier counts the number of matches hat occur to 3 harmed counter. See te curent aaa saung the show Lowel. commend, + roxwaraing-ciass! thsi sed for mts clasication for cies of serve (655) Essonay, ths satin seas the quoue In whch tis treme should be pace, + 1o2s-orlority: Tia mast lows ou to chang the packet ass pron ofthe IP pack inthe payed ofthe hore acne + nee: Tn mii liu the rome abe eae bythe not tor It there, + noxt-Rop-group: The mor species which nexthop goup wil be ‘poles. + policar: This maser pps a rtokmling pacer to the matching frames. + pore-niezos: Tis moder als cpiasf tha tame tobe sent to an {utbounaltrfece for ara, The orginal fae ova es nora JUAIPEF NTE Cr J Senice Provider Swtcing Firewall—Family Bridge Example "Configure, apply, and view the effects of a firewall tees twats) Example Fiter ‘The slide shows an eam of configuring, apphing. anc vewing he efecto Trew iter To Gea the courers, use te eter ekrevatl command Gaeir34 + Eom Geiongouenatine IEE ae uno Senice Provider Switching Summary In this chapter, we: + Described the functions of Ethernet LANS + Described learning and forwarding in a bridging environment + Discussed implementing VLAN tagging + Discussed implementing IRS + Discussed implementing Layer 2 address learning and forwarding. + Discussed implementing Layer 2 firewall fiters ‘This Chapter Discussed: +The functions of an thames LAN, + Learning and orvarding in a ridng erionment + tlomentaen of WAN tagging + plementation of 86: + implementation of Layer 2aderss teaming and ferwaring: and + implementation of Layer 2 trowel tes unos Service Provider Sting Review Questions Whats the purpose of a bridge domain on an MX Series router? . How does a bridge handle multicast Etherne: frames? What is the purpose of an IRB interface? Which match condition is used in a Layer 2 frewall filter to match on 802.4p priority bits? Review Questions ‘Ghaoter3-86. + Btharat Switcingand Viale “JUNIPer pw unos Sane Provider Switching Lab 4: thernet Switching and VLANs * Configure a bridge domain. *" Configure a Layer 2 interface. "Use operational mode commands to verify the status of a Layer 2 interface. Lab 4: Ethernet Switching and VLANS “The slide provides the obectes fr this a, unas Service Provider Satcing JUNIPEr NerwORKs Junos Service Provider Switching Chapter 4: Virtual Switches Juno Senice Provo Stching Chapter Objectives ‘After successfully completing this chapter, you will be able to: + Describe the use of a routinginstance + Desoribe the function of a virtual router + Deseribe the function ofa virtual switch ‘implementa virtual switch + Interconnectiocal routing instances This Chapter Discusses: + The us ofa routing intone: + Tmefunetion of virtua outer + Tho retion of @vtua stn; + mplomemtion of» vei ste, ana + Interconnection aoe roti instances, {nos Serie ro er Sutohing Agenda: Virtual Switches Routing Instances Overview = Configuring and Monitoring Virtual Switches " Interconnecting Routing Instances ae ES z Routing Instances Overview ‘hes sts th topes we ever in ths chapter. We lcuss the higahted ope ts Js Service Provider Saltching Routing Instances = Several different types of routing s instance existe, ad + Virtualrouter routing instances allow for cl your single chassis to appear as multiple | routers to the outside world | | + Each with ther own separate outing tables, protocols nk state databases, and 20 0n + Detaurtinstance is named default. + Virtual-switch routing instances allow for your single chassis to appear as multiple ‘switches to the outside world + Each has its own MAC abies, VANID epee, and spanningt comaine + Thedefaultinstanceis named defaul t-evi teh Routing Instance Types ‘The Jinos operating sytem provides several iferentoutnginsance types with whieh two In ths couse we wore wth wo pes of outhginstance=" ‘istual-router andvictuel-ewitch, Carentan wo ratinginstance types afow your singe chassis apacar as ethormere tan ane router or ore than ‘ne switen respacaa) Each etl reuter des asa stardsone rte. For exam e2ch tual outer hess own routing table, outa eotecs,rteraces, ana isk bout evethngshat encompasses thetic things Vat crmprae a rowtar inlay, teach confgurod tual ewtch has sawn MAC tbls, vit LAN (AN) T9 spe, lridge domains, panningee domsins, and o forty & June Networks NK Series 3 Univeral Edge Router uses two deft routing instances, or outing uses the ‘Sofaul virtual roulr ft Rs outing table Fer swing uses the ‘Soave switch val ewtan, Vital Swit JUNIPer be JUNIE unos Sais Provider Switching A Simplistic View of Routing Instances = Interface to table default assignment: + Layer 3 interfaces associate with inet..0 + Layer 2 interfaces associate with the default-switch virtual swviten j O lomgaiuraecry ayes to Routing instance and Interface Default Relationship “Tha sida shons avery split vow ofthe deteutlationshio of intraces tothe routing ane MAC tables ofan NX Sere outer, Keen mind tht we have ie ot dsovssen ofthe Packet Forwercing enghe (PFE) ad the assole forwarcing ‘ables. Whon Zoublshaotng val outers and auch, you general can spend your im focuseal on the Routing Enge’s (RES) oxy ofthe rutng an MG abs, ‘nl trusting that equllent opis appear as fruaring odes inthe PFES of your ‘Swit. To view the PFE forwarding tates, beth or eutng and such use the Show route forwarding-eable conmant Ina outngonty enronment, contgued interfaces andthe associate lcel and ‘Sect routes appear inthe daft viel outers tng able, eto, ined Layer a Layer 3 endronment, Layer 3 interfaces orsnua to Wok a secerbed, hares Layor 2 ntaraces, Pawns been asociated fh a ge dora at th {eae bridge- domaine) Morro associate wih te cefautvitol ow tes Mao tabes, Because RB ntaroces se Layer 3 traces tet associated ocala ‘rect ovtes apearinsnet a8 wel [ Vitwal Swishos Grapter 4-5 unos Senice Povicer Steing Routing Instances—Virtual Router *You must assign interfaces. toa virtual router + Place routes associated with those interfaces only in that. virtual router's routing table ‘Assign Interfaces toa Virtual Router 2 detaut, once you configure an itertace wih properts atthe (edi: interfaces interface-nans unit umber family it! lvl ofthe ‘ervey, hat ieaca's ocala der routes are placed nthe net. ovtag table ‘Tooverie that beh, yu simply Ist the nertace ho teace reuting-instances Jnstance-nase! lve ofthe Naren, the joc ang Grectrowtes now appear inthe instance-name. inet routing abe Val ‘outs’ routing abe) > wit Sane JUNIRES io: unos Seni Provider Sitching Routing Instances—Virtual Switeh * Each virtual-switch routing instance operates independently of the other virtual switches: + Routes assisted th RB rteraces are lad in inst. 0 regress he ian i ey belong mama Virtual Switch These shows the routng.nd WAC tbl elaionshps when using virtual svtehes {sen vitual sth, incuang te dtaut wich, nas inert asia for bridging ‘iso youcen cofiguentegratod routing and ig) nteroces or sac it ‘ich he bel an aie routes for al RG ntatsces nal tal sches ae ‘aoe in ine, ty defaut. Hone you can 380 lace them avitual router's ‘outing table by iting te RB Interfaces at he [aes routing instance inetance-nane] tel ha Neary Te folowing slides ove the process of enfauenga wal sith unos Senice Provide String Agenda: Virtual Switches * Routing Instances Overview > Configuring and Monitoring Virtual Switches + Interconnecting Routing Instances Configuring and Monitoring Virtual Switches The side gigs the topie we discuss na. ‘Ghonter 4-8 + Wal Swchos JUNIREr pe unas Sonica Provider Swiching Sonfigure a Routing Instance = Configure a base virtual-switch routing instance: + Define the bridge domains and VLAN IDs that the ewitch will use Virtual Switch Routing instance The oarguration onesie erates avis tual-2v-1 out stance and atows for VIAN Ids 200 ana 200 o be used forthe purpose of Layer 2 eting WAG edie {or those nw bridge domams wl ot 0 wood fr lesrng and forwarding unl you aSSgn atleast ane interact the wrt etn unas Serice Provider Suteing Configuring an Access Port "Configure an interface that acts as an access port for the virtual switch: + Specify he correct vlan=id so that this interfaces ‘associated with the correct bridge domrain Setbutcom su sntectaces e/0/5 co". == > naming utc tee tad cama ‘Virtual Switch Access Port ‘You cortgue te ntartace properties or an socess port ug the exact some process as when defining forthe deat seh fect, ou were to corm the ‘onfguation, ego /0/'5.0 ntertace would be paced te deft ute Be arf notte commit the cantguaton a5 sands,becaus you might ois @ Toop nto our sted network One o te folowing sis shows how to place the Intrtacein tho wrtual sen. Weg esormena tatu perform that step tors ‘commiting tre cantare, ‘Chapter 2.6 > vit Sees JUNIPer unos Seniee Prov dar Switching Configuring a Trunk Port = Configure an interface that acts as a trunk port for the virtual switch: + Specify the correct vLan-id=11 st so that zis interface Is associated with the correct bridge domains Sebevieon at sntctaces ow weet Configure a Trunk Port You configure the itrface properties ora trunk pet usingthe exact same roca a5 when dating or he aaa sri In tu wor to comm te aniguttion on he slide, the go-s/3/.8.0 erfoce wuld be led nthe default Sto. Bo cart not te cam the configuration a estan, eau you mint Inreduce op i your suited network. One ofthe following tee shows New aoe the interface nthe vrtual ston We hgh esonmende thet you pero that stop before comming ne configuration eo Juniper Seer eee Janos Srvc Prove Sitchin Configuring a Virtual-Switch IRB Interface Configure an IRB interface that acts as the IP gateway for a bridge domain within the virtual switch ctolespeice “ou foe aH Configure an IRB Interface You congue the inrtace properties fran I irtertace ung the exst came process as when defining or he deat ewan infaet, #ou wee to comet the {orfguation onthe slid, ter. terface wou be plod inte dato, Be {arf otto cormit the canfaraton ae sands, boonies you mgt isveduoe &| loon into our sted network. Thefoloingstce shows aw to placate interface Inthe wreua ster We recommends that you perform Pt step before contin g ‘he contiguraton Sea meee Ber uns Sendoe Provtder Switching Bind the Interfaces to the Virtual Switch * Specify the interfaces that belong to the virtual switch: + List the trunk and access ports as member interfaces of the viral switen + Ust the IRB as the routinginterface for the Seztoutay soe covttn-sneancer appropriate bridge domain“ [iseseartyereI-aTET within the virtual switch Hntaetaer-ge-17178 ‘Add the interfaces tothe Virtual Switch ‘Aer configuing te asess and wunk prt as shown on the previous slides, you ‘Simpl noes tote intarfaceat the (adit routing-snstances Anetance:nane} lev! f te terarchy. The {2b 1 triacs should be tisted as ‘pe routings Lntortace forthe appropri bige domain ye Juniper Vinal Sones » Grape &-53 ures Senjce Provider Sutehing ‘VWerlfy That Ports Belong to the Virtual Switch "Use the show bridge domain command to ‘ensure that the configuration setting accomplished your goal Te Noes Verify Setings Lookingat the output onthe ste, you can soethat the ge//40 nefac is now bound tothe vizuai~ew-1 outing interes atthe bie dorbains van 109 {nd vlan. 200. lee, ge-2/0/5.0 shoundto te sopra routing tance and beige data. ‘Chapter 4a + Vital Switches JUNIREF unas Seaee Powder Switching Yorify Routing = Ensure that the appropriate routes appear in the inet.0 routing table IRB Routes ‘The local and dec routes nat associate wth ho If iterface shouldbe nthe propery Chapter a8 JUNIPER mons SE Jura Service Powe Stoning Agenda: Virtual Switches = Routing Instances Overview = Configuring and Monitoring Virtual Switches interconnecting Routing Instances Interconnecting Routing Instances The sie his the tpi we sss net. ‘Chapter @-26 + wauat Swiches JUMIPEF wo unos See ProtiderSyitcing Interconnection Methods = Supported methods: + Internal, logical tunnel interface {Layer 3 ony] ‘+ Two extemal, physically looped interfaces (1. cable) ‘Supported Methods of interconnecting Routing Instances ‘As mentioned previously, tothe ouside no virtual routers and virtual switches ‘sppest as inaivaual routers ad switches. Aso sont you might want > Inreannact the vital outers and vt otehosthat are oral to single chassis, Foy vtua rota you can aesomainh thi tk sig ater aoa nal nara ‘ory loplng wo lerfaes together witha sng abo. For vitual switches, is process wars on using the exeral cable metfod The reason wy spanning se tots donot tuneton propery betwoon virtua ewienos s because al vita Stones use te same MAC addres os partf tel once D Inthe Ss protocol os (POLS). Untortunatly, you anne change arta sts MA adress, JUNIPer pone eweet unas Sensc® Prove Sithing Enabling Tunnel Support "You must enable tunneling on the PFE of MX Series routers, ESSE" MMMARSETES nase saceh sate Tunnel Services ‘Ante you nee toute tye tunneling, you must enable unre sevens onthe NK ‘Sees outer. Fo expe, you must enable tne! saris ar 9 gener outing ‘encapsulation (GRE) tunnel an IP ovr P (PAP) Lanne, Pyscel terface Module (Fi enesosulaton or deapsuiton of repster massages, an or urcae, ing loge! tunel interfaces, Each Dense Pore Concertvta (DPC) ona sah has ether 40Gb Eieret pores (10 ports per PFE) or 4 20-Ggab thereto (2 pot pe PFE, Each PTE onan MX Sees DPC can provide unraing services bu yeu must {enable These shows howto enabla tunnel serves on heat rE (gervng '6:1/0/0 through g6-4/0/9) on the 40 .GigatitEiernet 2° in ot ruber 1. One You enable his eae, yu wl notice that you have soverl unre! ype ntefacea, that become avaiable fr your use. Nee that he tune! eaces Use te loge Pic port numberof 10 (rermaly PC prt numbers stop at) When enabling tne ‘anim nna BFF af por 9 BigantEternet OF the Era nr fr that FE is removed om service an ino longa visti nthe eammardinn inerace, a, JUNIPer unos Serve Provider Switching Layer 3 Logical Tunnel interface Configuration *= Configure and assign the logical tunnel interfaces to the appropriate Sap ae inmati ivayoaa virtual routers att Configure and Assign Logical Tunnel Intertaces You congue te fogs tune! intercessor tohow you woul ory other Layer terface You configure each gies tunel ye 3 interface a a toga ui. Tomap one loge unto ance, use te peer-uat seman de ea - tunnel ntaraces oe paced inthe default tl rete Ta places loge tunnel Inaracain aru outer ape he loge! tunel interface athe Cade routing instence instance-nama) lee! ofthe Neary Juniper VitialSwiches > Chapter 9 unos Senice Provide Sitching Layer 2 Physical Loop * Configure and assign the physical interfaces to the appropriate virtual switch Sine ee san Configure and Assign Physical interfaces ‘The sid shows howto conigure and assign Layor 2 Intro t vital wtohes. re unos Service Provider Switching Vorify Switch Settings *Use the show bridge domain command to verify settings... Verity Settings {Looking the outpton hase you can se that he ge-1/1/4.0 interface snow ‘ound to tne virtual -aw-1 ovtg instance anc tne bidge daring van 100 And ian. 200, wreas go-1/ 0/40 belongs tothe deat etch JUNIPer Vian Swiaies » Capi FE unos Sanice Provider Sitting Summary ‘In this chapter, we: + Described the use of a routinginstance + Described the function ofa virtual router + Described the function of a virtual switch + Implemented a virtual switch + Interconnected local routinginstances ‘This Chapter Discussed: "chapter @-22 © Vinal Swans ‘ne use ofa outing Ista: The funtion of vetue outer: ‘Tne funtion a tun ewer nplementation ofa vital nite ne Irtorconneeon ofa outriginstances. JUNIPEr pe unos Serie Provicer Switching Review Questions 1. How can you make your MX Series router appear as multiple routers to other devices? How can you make it appear as multiple switches? 2. After configuring an interface under [edit interfaces], which step do you perform next to ensure that the interface appears as part of the v1 virtual switch? 3. After configuring an IRB interface as part of the vs virtual switch, in which routing table will you find its, associated routes? jUnpep ST unos Service Provider Sting Lab 2: Virtual Switches = Configure virtual-switch routing instances. = Configure bridge domains for the virtual switches, * Create a virtual-switched network by configuring. virtual-switch routing instances, IEDR nil nt Lab 2: Virtual Switches The sie provides the obec fortis, ‘cnanar 4-24 + Val Sots Juniper pe JUNIPE neve i Junos Service Provider Switching Chapter 5: Provider Bridging unos Senice Provide Switching Shapter Objectives ‘After successfully completing this chapter, you will be able to: + Describe the different IEEE VLAN stacking models + Describe the components of provider bridging + Configure and monitor provider bridging + Describe the components of provider backbone bridging + Configure and monitor provider backbone bridging ‘This Chapter Discusses: ‘Ghaple'S-2 > Provider Brdsing Insite of Becca and Bectronies Engineers (EEE) tl LAN VLAN} sacking modes; ‘The components of provider bang Configuration of prove dene ‘Te componans ofa provider backbone ries network PBBN) ane ‘Contiguraton of prover backoone ridelng. JUNIPEr wo unos Serve ProH\Gor Switching Agenda: Provider Bridging Expanding the Bridged Network = Provider Bridging * Configuring and Monitoring Provider Bridging = Provider Backbone Bridging * Configuring and Monitoring Provider Backbone Bridging [es Expanding the Bridged Network ‘The ld atthe topes we ever ths chap e lscuss te hight tops first Juniper Peeves Baagng » Chanter 6-2 Janos Service rover Shing Customer Bridged Network = IEEE 802.10 VLANs allow the customer's local bridged networks to scale: + VLAN tags allow for up 4004 separate broadcast domains, = Service provider scaling issues (for Ethemet virtual connections): + Service provider network needs to be aware of customer's bridging {spanning tree) and VLAN administration + Problem of overlapping VLAN IDs between service provider ‘customers + Service provider bridges leam and store customer MAC eacldresses ‘Scaling Customer Bridged Networks IESE 802.19 VLAN tgung males it possible for a customers brigad naterkto ‘szalenstoed of neesing to add more brig equipment toa growing etwas, VLAN ‘Babin allows for te ogi! soparation ofa raged netnor no many boast ‘domains (or WANS. tha 12. ang VAN ID, 4094 VL are vate for use ‘ona sige ays ethemot neta Ethernet from Service Providers ‘Because os simple nature, serves prover customers ately understan _EermatFora longtime, cores prdershave seared to nay te dlr Chernot iu Greuts (E¥0s tothe customer premises. To acustan, an EC Between vo sites shoud pear asa impo Ethernet nk or VLAN tah the sevice proves ewor ett 802.20 VLAN tagging doesnt prvi the scaly in Ne serves rover network for asec rower to clver hat ype erie Continued on nes page, pe JUNIE Oo i 4up08 Saree Provider Seitching Ethernet from Service Providers (contd) From the serdoe provides pnt of ew, elon isl of om ofthe seating ieee hat mig aie ‘ecause anyone VLAN tag ed enssin an 802.19 fama, customers fd the service provider need to cotanate the uso! WAN ID space Consiserrg tht» series provider might have thocsands of custome ‘is cooration woul be an over eareme efor. ‘Topass Ethernet ames between customer ses, the serlee provider twigs must lear customer WC adessas, “To prvi redundant inks between customers and the eve provider, ruminga orn of he Spanning Tee Peacal (STP) which s generally ot ‘Saale solo, might ke necessary. he SPs of today cannot scale to “support al sevice provider and customer beages of te word na sng eannon tee domain Provider Bing > Caapter SS uns Serie Provider Swing Provider Bridged Network ‘= IEEE 802.1ad provides the standard for stacking VLAN tags: ‘Allows the service provider to provide LAN service through the service provider network + Ezohoutertag(S.VLAN tag) represents a customer(409¢ possile) + Inner tag (C-VLAN ag represents any ofa customer's 4094 VLAN +The service ptewider and the customer use uniquespannagres omains + Alls for VLAN translation between sence proider bridged eters ™ Service provider scaling issues: * Servie provider bridges learn and store customer NAC addresses _< —( eel) ——E a Feb IEEE 802.120 EEE 802.tahas standardized the matodology of tacllng VAN tags The slide ‘ows thotrame lormat hat the tancerd odio. Te tana ave a naw name ‘0 the 802.19 VIAN tg the Customer VLAN (CLAN) ag (CTAB also invades aw tag named the Serves VLAN (SAN) tg (STAG) 8 acting he STA tho "ram, uch less coorination i necessary becwean he customer andthe service rover. A the customer it, the cust’ oan continue o use 802-20 tagging Using (CALAN Ds hat are reevant ony tothatnetwerk (tthe sevice povcers networ ‘3802 @teggos ames ore at the edge of the service poets bred network, ‘he provider ig ras (PEB) eds an STAG 0 tne ame The STAG, sig anal 'SMLAN ID, can cary ry or all ofthe 4094 CALAN tat ee posi in use bythe "customer. Inte simplest caso, a sarc provider can aod single SVLAN ID to ‘presen each of sindvdia customer, whic alows tne serves provide to ‘tently spot nt 4084 cstomers IEEE 002-404 sien lowe fon he ‘ranslbing ots WAN Ds at he ecgo of a sarice powdered network, wich hepsi the coorinaton of VLAN ID usage between service prone, CContnved on net page. Frovderaidane JUNIPer unos Service Provider Switching Scaling issues _Mtnough IEEE 802.106 habs to sve the issue ote ited VLAN 10 Space that we dacussed in relation to IEEE 80219 taggng, it doesnot ove the MAC learning probien, Thats fo femes tbe forwarded atveen bridge inthe service proves ‘network, te bridges each must eam and soe MAC atest laznet fom the cstomer networks. service powder can help lloiate tis roam by Hfng the umber of eamed MN adresses or cholate estar more" the EVE serves fina excead the MAC adores wo JUIPEr Provider Bing » Chapter 7 unos Service Peoider Stclng Provider Backbone Bridged Network = IEEE 802.1ah solves the service provider scaling issues: + Specifies a frame format with two new tag types + Alowsfor neany 16.8 millon EVCS (customers) + Senvice provider backvone bridges co not earn and storecustomers [MACadaressesercept atthe edge ofthe BBN (ELAN only) + Outer WACaddresses ext ont within the PBBN + IEEESO2 tad STAG VLAN IDs ranstat into the TAG Backbone Service Instance D as frames entsr the PBEN IEEE 802.1ah: Provider Backbone Bridging ‘The IEEE 802.2ah standard atts to sole all the EVO soxing sues. Customers ‘an contoue to uve IEEE 802.10 VAN aang ther naval sites sing LAN IDs that ae relevant oly to ther bred network, The eres rower can corti > tse IEE 802 1ad VLAN aggngto provide EVE soviet ts customers (ypicaly at the edge ofthe network) IEEE 802. allows the provider bud out scalable “backbone” network of rdges-thecevter network onthe dide-to prove ‘connec between ts customer o Is nd IEE 802d idee networ, ‘Tha slid shows tho 802.1ah Eten tame format. Notoothat anew set of source ‘ad destinaon MAC adresses a TAG and an HAG noansulat the orignal Citomorrame. The comsination cf the AG and he LAC aows an vil provider to support upto 168 rllon cstamers Ab, because forwarding ofthe ‘ame across te service provider ocurs using the new sous and dstnaton MAC aaaresces tho WAU aacrosos ar local o ue rage ns backbone exwar), te backbone ges ned not eam the customers Mac addressee eal for etnemet Line (@ Lin) EV0s. For hornet LAN (LAN) EVES, only brs at tho ogo of no baokbone lnm customer MAC addresses, We dees Une and ELAN EVES Io more lz iatrin tis chapter Grane + Provaer order Juniper pe’ Janos Senoe Proviser Switching Agenda: Provider Bridging + Expanding the Bridged Network Provider Bridging ™ Configuring and Monitoring Provider Bridging * Provider Backbone Bridging * Configuring and Monitoring Provider 8ackbone Bridging Provider Bridging “The side hig ne topic we cscuss net. unos Service Provider Steins What Is Provider Bridging? = Defined by the IEEE 802.4ad standard: + Allows for service providers to offer the equivalent of separate Ethernet LANs to their customers *+ Easy forthe customarto understang(ethemet) + Easy forthe serie provider to provision (1 VLAN equals customer) + Requires the use of 2 stacked VLAN tags + CMLAN-typicaly contotedty the customer + SVLAN-contrlledby the service provider fe = a ime] om cs "a" | & Provider Bridging Proviso bigngs defined under IEEE 802:Lad twas devopes to alow a servico rover to provide a mere scalable EVC serve tots cusoners A yp prover ‘gd meter (PBN) proves for CLAN tnggngand forvarng atthe eg of tho ‘network sn the ports that face the customer Fora pits tat face the creo he PN, the saver brges forward based ony onthe SVAN ag oaeo meee CIO unos Serve Proce Stohing ‘JAG Formats «Tag formats: svat ag "Tatler Aa dott 86A8 “py tt 802 tp “Dre Ege neat: dott “tinge VAN £2 soutaiag ee Taglar 1 tet 8100 “prety 3 8023p + Carer Fomet ctr 4 dtat 0 * uo VLA eter 12s EEE 802-1ad TAG Formats The side shows he SAG and CTAG formats defi urder EEE 602-104, Note that {he CTAG remains erica tothe IEEE 802.10 VUM tag Te STAG similar buta few fos me ben edeine. For examine, becave the canonical ormat ndiato (Cfo in tho CRG israrly ues or eo oan rng networks. Rhos boon ‘redefined inthe 1X6 to representa rama"s esto be soppes. The Dron Engi rear (OM ve or lato erie, whien we do Nt dscuse nhs ours. Ao, EEE 802.180 as reserved a Tag Potcn Menier (PID) of OxBBAS Tor {he 5186, nowever the unos operating stem deu Behair 19 se the TPO ‘salto Oxa00. juniper ever idee unos Sewice Provide Sitehing Provider Bridging Terms "Each device performs a specific task in a PBN PEN Terms The folowing terms are ued in @ PBN network: ‘aoter SAAB > Provider Bridang PN network of provider bigest provide for ransoarent EVE ‘servoe tthe sence provider's stoners Provider Gri: Abie in the sevice prover’ net that performs | IEEE 802.1d VLAN tagging and forwarding. These rages eam and ‘Sore the MAC acareses of he sonics proves customers, Provider Ee ro (PE): Accepts ana forwards IEEE 802.20 rames to and tram eatoners. PES also encapsulate the reed customer ‘Tames using the IEEE 802. 1ad formato forwad custome mes S:7LAW rie: nanodge provider bls the orvessrames based contyon tne SVAN tag Prov Network Port &porton a provcor ba tat ova rms sed on tne SLAW tage Customer Edge Por: Aprt on 8 PED that const ta ouster ‘esuipmant hat races ad vanes CVLAN ag rates. Customer Network Port A porton a PES thet eseves an transis ‘SLAN tage ames. JUNIBer wo unos Sonioe Pro ider Sucking YLAN Tag Operations = Provider bridges make several different types of adjustments to the VLAN stack: + These options can be configured explicitly manually intensive) or using shortcut (implicit) methods that require minimal configuration + push: Adda outer tag + pop: Remove the outer tag + sup Snap the outer tag witha new one + poppop: Removethe outerand immer tags + push-push Add two tags + staap~swap: Swap the inner and outer tags with new ones + pop-swap: Pop te outer tag and sia the nner tag, + swep-push: Swap the ner tag and add an our tag + ronrite vlan and tag-pratecol-1d EE VLAN Tag Operations ‘The side shows. of te posible operations that prvi biige can perf on (Ctaggeatvames ond Stage rames hata pot eosves and Wanersts unos Senice Provider Sitshing Frame Processing Example (4 of 5) * Service provider provides an EVC to the customer: * Customer uses 802,1@-tagged frames (C-VLAN 100) to connectto the remote site while the service provider network is transparent + SVLAN tagging of toa customer frames duringtranemission across {theservce provider network provides taneparency ‘Service Provider Provides EVC Service to the Customer Inthe exams, the service provide divers an Etemet cet peach of the customer premises, fo prove connoctybetneen Customer Badge 1 and Customer ‘Bridge 2, the customer mus rable a IEE 202.10 VAN ing VIAN © 100 onthe ‘senvoe provider facing pots, The ervice provdorhasalooeaa an SVAN tog 9 200 ‘0 ranspareiy forwar the customer's ames across the FAN. Tis aoston erormec by conguring a begs domain on eacn prover brige specie forthe ‘customer speciyng an SALAN ID of 200, and by onfigungal possible inbound and ‘outbound interfaces to spor the approprato VIAN aggro he customers ike domain Far example, on Brigo 8 th sare provide woul ned to corte 1 Bridge Comin that aczepts Ctaggs frames onthe custanerfacng interface and ‘Stagg Tames (VLA I0 200} on the core facing inertanes pe sures Senvce Provider Swing Frame Processing Example (2 of 3) ‘Frames with a single C-VLAN tag with VLAN ID 100 arrive at Bridge A: “Bridge A performs a MAC lookup to determine the outgoing logical interface ra PEB Processing of Incoming Frames ines CLAW tagged frames anv at Brg (a PES), rgeAperforms a MAC table Toop based on te customers anda domain. I eid Aas previously leaened the

Das könnte Ihnen auch gefallen