Beruflich Dokumente
Kultur Dokumente
Things to go wrong
Wrong cable types (Cross vs. Straight) L2 settings & negotiation (half / full & speed) Bad Location (relative to MPLS, IPsec-VPN, NAT, L7-FW) Limited IP connectivity (VLANS / transfer segments / Firewalls) LAN / WAN ports swapped (no opt. in one direction) Packet Rikochet (WAN link more data than LAN) Forwarding Asymmetry (VRRP vs. WAN / forgotten links) NAT between the Steelheads (no opt. / broken sessions)
straight
cross
cross (mostly)
Limited IP connectivity (VLANS / transfer segments / Firewalls) InPathIP addresses must be able to communicate with each other This could be limited due to A) VLAN Trunk -> set the right VLAN number on the InPathInterface B) InPath is sitting on a non-routed transfer network -> use FT (or FT/reset) in all InPath-Rules AND use OOB-Transparency C) Firewall blocks TCP sessions between the Steelheads -> Open TCP Port 7800 in- and outgoing to and from all InPathIPs In a combined situation (where more than one of the above applies), FT/reset in all InPathRules and <in-path peering oobtransparency mode "full> is your best shot check InPath- with Connectivity <ping I inpath0_0 10.17.0.23> to adjacent routers as well as to remote InPathIPs
10
11
Thank You !
Questions ?