Beruflich Dokumente
Kultur Dokumente
BRKRST-2310
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 2
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 3
Market Segments
Market Segments
a) Service Providers
b) Enterprise
Manufacturing
Retail
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 4
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 5
Enterprise Retails
IGP scalability requirements
on retail side is on the Hub
and Spoke
OSPF were designed keeping
the Service Provider
infrastructure in mind
Lacks clear vision towards hub
and spoke architecture
Acquisitions brings more
topological restrictions
Distance Vector are better
choice for e.g., EIGRP,
RIPv2, ODR
BGP?
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 6
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 7
Service Providers
Deployments
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 8
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 9
SP Architecture
Major routing information is
~250K via BGP POP POP
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 10
PE
PE PE
CE CE CE
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 11
SP Architecture
The link between PE-CE Regional
needs to be known for Core
management purpose
NMS
BGP next-hop-self should be done on
all access routers—unless PE-CE are
BGP
on shared media (rare case)
RR WAN
This will cut down the size
of the IGP
For PE-CE link do redistributed
connected in BGP Access
These connected subnets should
ONLY be sent through RR to NMS for
management purpose; this can be
done through BGP communities
Link Suppression can be done in PE
OSPF via OSPF prefix PE PE
suppression feature
CE CE CE
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 12
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 13
Router Mode
[no] prefix-suppression
Suppress all prefixes except loopbacks and passive interfaces
Interface Mode
[no] ip ospf prefix-suppression [disable]
Suppress all prefixes on interface
Loopbacks and passive interfaces are included
Takes precedence over router-mode command
Disable keyword makes OSPF advertise the interface
ip prefix, regardless of router mode configuration
Available 12.4(15)T
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 14
PE
PE PE
CE CE CE
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 15
SP Architecture
Physical address between ABR and
PE should be in a contiguous blocks Regional
Core
These physical links should be filtered NMS
via Type 3 filtering from area 0 into
other areas or suppressed via prefix
suppression feature Area 0
Why? To reduce the size of the routing
table within each pop WAN
ABR
Every area will carry only loopback
addresses for all routers Access
Only NMS station will keep track of
Area 1
those physical links
These links can be advertised in BGP
via redistribute connected
PE
PE device will not carry other Pop’s PE PE
PE’s physical address in the
routing table CE CE CE
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 16
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 17
Don’t do it!
If you’re an SP you shouldn’t be carrying external
information in your IGP
Let BGP take care of external reachability
Use OSPF or to carry only next-hop
information—i.e., loopbacks
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 18
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 19
Enterprise Retail
OSPF is not a very good
choice for hub and spokes
Enhancements are being
made in IETF to make OSPF
more robust on hub and spoke
EIGRP, ODR, RIPv2 and
BGP are better choices at
the moment
Enterprise BGP is
not complicated
You do not need to play with
lot of attributes
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 20
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 21
Area 1
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 22
100 A
Area 1
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 23
Enterprise Retail
Summarization of areas will
require specific routing information
between the ABR’s
This is to avoid suboptimal routing
The link between 2 hub routers
should be equal to the number
of areas
As you grow the number of areas,
you will grow the number of
VLAN/PVC’s–scalability issue
Possible solution is to have a
single link with adjacencies in
multiple areas (draft-ietf-ospf-
multi-area-adj-07.txt)
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 25
This isn’t a
Static Routes Here
common configuration
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 26
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 27
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 28
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 29
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 30
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 31
Manual Configuration
of Each Spoke with the Correct
Single Interface Single IP Subnet
OSPF Priority
at the Hub Treated as an OSPF Fewer Host Routes
Broadcast or NBMA Network No Reachability Between
in Routing Table
Spokes or Labor-Intensive Layer
2 Configuration
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 32
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 33
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 34
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 35
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 36
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 37
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 38
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 39
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 40
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 41
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 42
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 43
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 44
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 45
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 46
Backbone 3.3.1.0
1.1.1.0 Area 0 3.3.2.0
1.1.2.0 3.3.3.0
1.1.3.0 3.3.4.0
1.1.4.0
2.2.1.0
2.2.2.0 3.3.1.0 3.3.4.0
1.1.1.0 1.1.4.0 2.2.3.0
2.2.1.0 3.3.4.0
1.1.2.0 1.1.3.0 3.3.3.0
2.2.3.0
2.2.2.0
Only summary LSA advertised out
Link-state changes do not propagate
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 47
Backbone
1.0.0.0 Area #0 3.0.0.0
2.0.0.0
2.2.1.0 3.3.4.0
1.1.2.0 1.1.3.0 3.3.3.0
2.2.3.0
2.2.2.0
Only summary LSA advertised out
Link-state changes do not propagate
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 48
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 50
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 51
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 52
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 53
! Point-to-Point
interface serial 1/0
ip ospf database-filter all out
....
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 56
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 57
Fast Convergence
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 58
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 61
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 62
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 63
Graceful Restart
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 64
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 65
Graceful Restart
Router A loses its control
plane for some period
of time A Control Data
B Control Data
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 66
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 67
Graceful Restart
If A is NSF capable, the No Reset
control plane will not reset the
data plane when it restarts A Control Data
Mark Forwarding
Information as Stale
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 68
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 69
Graceful Restart
NSF is a protection scheme
NSF and fast hellos/BFD do A Control Data
not go well and should
be avoided
NSF makes more sense in a
singly homed edge devices
Multihomed edge devices
should go on restoration
scheme instead and switch
over to the alternate path
B Control Data
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 70
GR Signaling Resynchronization
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 71
OSPF as PE-CE
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 72
In service provider networks, the OSPF process id should match, otherwise external type-5 routes
are generated
Site 2 expects Type-3 inter-area routes from Site1 via PE2 but instead receives external type-5
OSPF process-ID is usually locally significant. In MPLS VPN, consider service provider cloud acting as a single
router from OSPF perspective
Instead of removing and reconfiguring the OSPF process, service provider may configure same domain-id on
both ingress and egress PEs to solve the problem
Mismatch ospf process id
VPN-IPv4 Update router ospf 1 vrf <name>
router ospf 2 vrf <name> RD:Net-1, Next-hop=PE-1 domain-id 99
RT=xxx:xxx
domain-id 99 OSPF-Route-Type= 1:2:0
OSPF-Domain: xxx
OSPF-RID= PE-1:0
Provider Edge Router
PE-1 MPLS-VPN Backbone
(PE) PE-2
Type-3 (Summary-LSA)
Type-5 (External-LSA) Link-State-ID: C-1
Link-State-ID: Net-1 Link-ID: Net-1
Type-1 (Router-LSA)
Adv. Router: PE-2 Adv. Router: PE-2
Link-State-ID: C-1
Metric : 20
Link-ID: Net-1
Area: 1
Adv. Router: C-1
CE-1 CE-2 Site2 - Area 2
Net-1
Site1 - Area 1
BRKRST-2310
C-1
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 73
Customer wants to send a summary route to all other sites from site1 (area 1)
Summarization not possible since ABR does not exist in site1
Provider can summarize in BGP and advertise a aggregate block to all other sites
router bgp 1
…
address-family ipv4 vrf <name>
aggregate-address 30.1.0.0 255.255.0.0 summary-only
VPN-IPv4 Update
RD:30.1.0.0, Next-hop=PE-1
RT=xxx:xxx
atomic-aggregate
BGP
BGP
PE-3
PE-1 PE-2
OSPF Type-5 (External-LSA) OSPF
Link-State-ID: 30.1.0.0
Adv. Router: PE-2
Site1/Area 1 Metric : 20
CE-1 CE-3
CE-2
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 74
x
OSPF-Domain:xxx
PE-3
PE-1
PE-2
OSPF
30.0.0.0/8 summary route Type-5 (External-LSA)
Link-State-ID: 30.0.0.0
Area 1 Adv. Router: PE-3
Area 2 Area 3
Metric : 58
30.1.1.0 - 30.1.255.0 30.2.1.0 - 30.2.255.0
router ospf 1 vrf <name>
CE-1 summary-address 30.0.0.0
CE-3
CE-2 255.0.0.0
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 76
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 77
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 78
Type 1 or Type2 LSA converted into summary LSA by the Customer ABR
Local PE receives a Type-3 LSA and remote PE forwards the same Type LSA towards the remote CE
VPN-IPv4 Update
RD:Net-1, Next-hop=PE-1
RT=xxx:xxx
MED: 6
OSPF-Route-Type= 0:3:0
OSPF-Domain:xxx MPLS-VPN Backbone
PE-1
Type-3 (Summary-LSA) PE-2
Down Bit Is NOT Set Type-3 (Summary-LSA)
Link-State-ID: Net-1 Down Bit Is Set
Adv. Router: CE-1 Link-State-ID: Net-1
Metric: 6 Area 0 Area 0 Adv. Router: PE-2
Metric: 6
CE-1
Type-1 Router-LSA Link-ID: CE-2
Net-1
Adv. Router: x.x.x.x
Type-3 (Summary-LSA)
Area 1
Area 2 Down Bit Is Ignored
Type-2 Network-LSA Link- Network = Net-1 Link-State-ID: Net-1
or State-ID: Net-1 Adv. Router: CE-2
Adv. Router: x.x.x.x Metric: 6
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 79
All VPN sites belong to same OSPF area (area 1 in the example)
Service provider PEs acts as OSPF ABR routers
Type1 or 2 LSA are always converted into Type 3
Remote Site receives a summary LSA
Not an issue if the topology for simple topologies
VPN-IPv4 Update
RD:Net-1, Next-hop=PE-1
RT=xxx:xxx Type-3 LSA created even though
MED: 6 local area number is same
OSPF-Route-Type= 1:2:0
OSPF-Domain:xxx
MPLS-VPN Backbone
OSPF-RID= PE-1:0
PE-1 PE-2
CE-1 CE-2
Network = Net-1
Site1 Site2
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 81
Customers Sites are in the same area and there is a backdoor link
Route is advertised to MPLS VPN backbone
Same prefix is learnt as intra-area route via backdoor link
PE2 does not generate Type3 LSA once type-1 LSA is received from the site
Traffic is sent over backdoor link instead of MPLS VPN cloud
VPN-IPv4 Update
RD:Net-1, Next-hop=PE-1
RT=xxx:xxx No LSA Type 3 created
OSPF-Route-Type= 1:2:0 MPLS VPN Backbone Not used
OSPF-Domain: xxx
OSPF-RID= PE-1:0 MPLS-VPN Backbone
PE-1 PE-2
Type-1 (Router-LSA)
Type-1 (Router-LSA)
Link-State-ID: C-1
Link-State-ID: C-1
Link-ID: Net-1
Link-ID: Net-1
Area: 1
Area: 1
Adv. Router: C-1
Adv. Router: C-1 CE-1/CE-2 link
Area 1
Some OSPF sites entirely belong to area 0 and some other sites can belong to non area 0
Some sites may consist of hierarchical OSPF topology consisting of area 0 as well as
non-zero areas
Both scenarios are valid
PE-1
PE-2
VPN red
VPN red
area 0
area 1
CE-1
area 2
Site1 Site2
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 84
As before some sites may consist of hierarchical OSPF topology consisting of area 0 as well as non-zero areas.
If site contains area 0, it must touch provider PE router
OSPF RULE: Summary LSAs from non-zero area’s are not injected into backbone area 0
Inter-area routes will not show up unless a Virtual link is created
LSA Type 3
xPE-1
PE-2
LSA Type 1 or 2
VPN red
VPN red
virtual-link
area 0 LSA Type 3
area 1
CE-1
LSA Type 3
area 2 x LSA type 3
Summary routes is NOT advertised into area 0
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 85
RR
CE
MPLS PE
VPN CE
CE
CE
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 88
Router mode
max-lsa <max> [<threshold> [warning-only]
[ignore-time <value>]
[ignore-count <value>
[reset-time <value>]]
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 89
Availability
12.0(25)S, 12.3(2)T, 12.2(18)S
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 90
RR
CE
iBGP OSPF
MPLS
VPN CE
PE CE
CE
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 91
Summary
What We Learned?
Deployment issues in Service Providers and
Enterprise Networks
Dialup deployments techniques
Design Best Practices
Understand OSPF fast convergence and
resiliency techniques
OSPF deployments techniques in MPLS environment
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 92
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 93
Recommended Reading
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 95
BRKRST-2310
14445_04_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 96