设为首页收藏本站language 语言切换
查看: 7708|回复: 21
收起左侧

[LAB战报] CCIE SP V4.0 最新LAB 我刚考完 pass了

  [复制链接]
发表于 2013-6-11 18:20:18 | 显示全部楼层 |阅读模式
lab2.jpg
- ]9 c: z( M' i, C* mSection 1:; K0 ]9 f" |# s* o! a" K
SECTION 1:- e7 t; q. m2 o% V( a7 j
0 T2 e# c3 l' S# Z% ?" V& ?7 t& |
1.1 OSPFv2 IPv4 troubleshooting7 s0 K3 ^9 d+ R5 B5 A
5 y% W) T/ ~. Q% N* A
OSPF for IPV4 routing on routers in AS9 has been configured for the interconnect and Loopback 0 interfaces (table will be given there in the lab ) , all interfaces are in area 0.: O  |" x9 A- O, i/ Y; L/ ^
There are some problems in the topology find out and fix them. loopback2 on R2 and R6 should not be advertised in OSPF (shown in table)  _" @* R' Y$ c8 z

6 e4 f6 |$ t. ~& P: O0 `& g8 \' p Fault#1
: d& R/ O2 l5 M2 } OSPF neighbor ship is down b/w R3-R4 due to mismatch hello interval
6 N# b! E0 S9 Z5 Z1 {1 ~' i Note: R1, R2, R3 and R4 are XR R3:" `; G9 M( I1 c" H8 ^
To check this fault you should do( {+ u5 ]: D" a9 S
Sh run router ospf- g+ ~1 _/ X2 \% w, P
router ospf 9 area 0. U+ I! x# H$ o9 `
int GigabitEthernet0/0.34) b$ s7 G: H6 R  I3 A8 t
no ip ospf hello-interval 20
7 t5 d# b, D2 u3 w !4 @1 o+ A( i5 A
clear ip ospf process show ospf neighbor* Q% l, D7 i  `1 \7 Q

0 ]5 I, ~$ G6 T8 [- Q Fault#2' K: K: X# P/ p& f" R& g

) a% V2 N) h7 `  c2 ?8 i OSPF neighbor ship is down b/w R7-R4 due to mismatch MTU, neighbor-ship is stuck in EXTRACT state.7 D" n4 Q  \2 Z! `. T
R7% ]( h7 X! t- A  \
Sh run int fa0/0.475 ?) O3 X* R2 F( ]
interface FastEthernet0/0.47 no ip mtu 1300
& d; K5 @9 o( J* f  [ or
: u) U9 R% \9 |, r' B5 K ignore mtu3 _  ?* q$ E$ F  B  l4 S8 P  V6 p

5 u" {+ \/ ?- U% H0 g# K8 R" \ Fault#3$ l1 N0 Q7 K5 h
) n" @& D+ F! P7 B8 z" X( H
OSPF Neighbor ship is established between R5-R6 , but one side is configured as        “point-to-point” , for other side of the link network type is still “broadcast” . In this case both routers will not exchange the DATABASE.
5 k7 q+ {8 M2 h% B7 u0 \: d; Y) ~) k* g. |/ K
You can capture these faults if you look at the “show ip ospf neighbor”9 |7 j8 R( G( Y( N& R- B
output and see there is no DR/BDR election on this link from R6 perspective
' Q. k7 e' m" p: a; N3 r$ C8 k8 f  s- J" r6 l
R6#show ip ospf neighbor& R' A' q3 S8 E% J5 E( G
2 B, a  g& r$ d5 F1 u" H) q5 g  Q, R
Neighbor        ID        Pri        State        Dead Time        Address        Interface: G8 L2 B% X9 V" Y( B: p
9.9.0.5                0        FULL/        -        00:00:37        9.9.56.5        FastEthernet0/0.56
$ Z0 E# q5 B) ?) O0 O+ H* L) I 9.9.0.4                1        FULL/DR        00:00:37        9.9.46.4        FastEthernet0/0.46; ]0 l9 J3 i5 m. C  K( P
R6#                                                * @- I2 k+ C& ^* l) P5 S7 [
( Y" {, k) T" @: x
ON R6% _+ w$ ]! Q7 ?+ R9 s

4 A! _$ R/ u5 f/ b, A+ f interface FastEthernet0/0.56  r2 T( I4 K7 T
no ip ospf network point-to-point# H6 L0 o4 X5 n5 a' e/ r

  E9 Q, g$ t0 l, H) n OR on R5 : make it also as point-to-point3 K% T- e- T/ d0 I

6 y8 ^: }! f5 M( P5 P& z  Q  } interface FastEthernet0/0.561 ^" _4 f2 O& ~3 {
ip ospf network point-to-point
5 Y3 ?3 G5 n" s1 ^/ o; F) O' A+ I4 I( k7 w& b! j" ?
*** IP OSPF COST Question 1.5 will only meet the requirement if R6 and R5 are properly exchanging the database if they ask to change the cost for ipv4$ N; ~! v( C9 [0 z  v
otherwise normally they ask ipv6***
+ m9 M" `) R5 z' ]1 S! r/ y+ {, X* W2 d# t% |4 u; i1 x
OTHER POTENTIAL FAULTS:' m4 u9 g4 c% A) C8 L
4 z# j/ }9 R: A/ p( j
a. Interfaces is not advertised in OSPF Process IPv4/IPv6 b. IP Address and Wrong Mask2 E0 d  K; N  h' ]- q
c. OSPF Network Type should be compatible on both sides of the link. d. MD5 Authentication4 v5 ?2 v+ }' }
e. One router is configured as STUB, T-STUB, NSSA, T-NSSA
( m4 }* f( `0 N0 U3 U* |1 M$ r2 J  L1 y: D
ROUTER-ID:
, \9 F- ^! \- A. m. G+ e& q1 t9 X* U# K! Z) h* t  v# B. s9 q9 B
router-id for IPv4 and IPv6 OSPF process in AS9 will be: f2 {% @" H" o7 d
172.9.0.X , its betters to hardcode them to 9.9.0.X for both1 D! I9 L* U+ ?' c
IPv4 and IPv6 OSPF process . ( Altough Not required )7 S" i* w- K3 s1 K, N* F% X4 Q
" J9 {7 I' ?. g5 Z  L
1.2: OSPFv3 troubleshooting:
  i4 I3 n2 O1 j) a, \; [* Q7 N% r9 j3 X+ `$ E5 I2 l- G
OSPF for IPV6 routing on routers in AS9 have been configured for the interconnect and Loopback 0 interfaces (table will be given there).0 @- F& N% g6 r5 u
R2,R7,R3,R4        interconnect links and lo0 are in area 0
* z8 r# X% L& d6 X5 f1 K R3-R5 link , R4-R6 link and R5 /R6 lo0 are in area 1, q/ K4 J' X3 u1 f
There are some problems in the topology find out and fix them.3 w, T3 W1 _- Y8 m' |, r& u

+ x4 e- C& A5 s8 ~ IPv6 OSPF neighbor-ship is down b/w R4-R6 due to mismatch area/ W* |% V5 T: I, Z9 ]
7 l9 s! z! }1 v1 @% ]
On R4  ]0 g: T+ H% R9 c( z- s# @8 S
6 Y/ s/ P- [: q' ], g
router ospfv3 9 no area 10
$ |3 Y0 ^: {% m2 S# m% p area 1
; e8 z" M" k1 m( d8 [ interface GigabitEthernet0/9/0/0.46/ @/ E& r3 k) w6 v9 N- q, i
!
: t. T3 g- f1 G6 O7 l !
& r7 F+ U0 O& d; K& {" N
: W' A: A9 z* ?4 [! r8 J# k ** Actual Interfaces in the Lab will be different **
1 N1 o( D) R" E+ W0 U  E) U
& n2 J( X2 [9 D. z1 m 1.3: ISIS IPv4/IPv62 \; M5 {: q8 w* O

0 v. b: X  _4 X" g! c" a; U ISIS for IPV4/,IPv6 has been configured in AS1009, configure
1 T  Z* M% M$ i8 }. A( e+ O ISIS as point to point between R1 R8.
/ c: v+ }$ z& U1 @. @4 b7 g There are some problems in the topology find out and fix them.Solution:( r6 N: L8 K) @7 f2 x- H# A
R1        R80 h1 e( ^/ z. g2 n# a; U
router isis abc3 c0 V+ _. W2 ]2 D/ [( w
interface Gig0/2/1/0.18 point-to-point        interface fastethernet0/0.18
/ J& t" X5 Y/ b* o# v isis network point-to-point
  m- ?; g. l4 P$ Z$ X+ K0 Z( o# |/ P$ I) a6 @9 G( U0 R2 {% G: n! d6 Y
FAULT#1:! \5 d* }; ]8 J4 d

# a) c4 r' O5 o9 P R9:5 Q) c: W" R. X" b& m) F0 I# z

. K7 J1 J: Y& p* O( r router isis! |5 J, }& [% c5 L3 B+ D" u* _& c
net 47.0109.0000.0000.0109.00 no is-type level-1
, o7 d, b5 m% R/ ^# d5 v: @ metric-style wide" b/ j2 A0 H6 B1 c/ Q  L

) Y6 s. g: z  K* M NOTE: R9 should        be Level-1/Level-2 router , as it has level-1 neighbour-ship with R20 later in the exam.+ C! r; I) |" ]1 j2 p  q
7 |& F% H; d4 `- |! z
FAULT#2:  v3 C  {" D9 }
# I  T5 I! i: V. U# v7 w
R10 - R1 isis for ipv6 is not enable8 U: s  h+ l+ b2 a+ j& R+ H

& g" L: l9 z, \2 }& N& v R1#sh isis neighbor detail2 y" f: O# n4 t/ E2 n' e5 W2 N* Z+ ]

/ v8 B4 w: @! }  n/ q7 _# { System Id        Type Interface  IP Address        State Holdtime Circuit Id7 H! m3 N& Q* n$ D9 U  U! n4 `+ M
R10        L2  Gi0/0.101  9.9.101.10        UP        8        R10.020 d5 Y" V. x# P  q1 ]& B6 }+ ~* D  S
Area Address(es): 47.0110
/ W6 c: L6 `/ i: q" J3 l4 Z2 m" A SNPA: ca09.0bc0.0008" ?  x- l2 e# b. @7 X
State Changed: 00:45:13    IPv6 Address FE80 is not shown
1 I, u5 a( N! W" G! m7 x LAN Priority: 64
$ Z& E7 Q6 L  o; z$ X- Z Format: Phase V Remote TID: 0
. t: ]& ^+ A8 G. ?) _9 {2 n Local TID: 0, 2) j0 G+ A( n8 E5 H8 |8 z4 q2 j2 M6 R
Interface name: GigabitEthernet0/0.101  a& o. J8 t; [' e2 m* B
R8        L2  Gi0/0.18        9.9.18.8        UP        9        R8.02( c. I% L2 h: f+ X1 @, H( w- T+ s  ^
Area Address(es): 47.0108; k7 w/ m2 V4 o
SNPA: ca07.0bc0.0008
! @  f9 A; O  x" a$ n! C& q9 _ IPv6 Address(es): FE80::C807:BFF:FEC0:8
* F/ [7 L; b6 A# x& D State Changed: 00:45:12. M! e; U5 K! P
LAN Priority: 64
- b: M+ `0 z8 |1 o& l$ o Format: Phase V Remote TID: 0, 2
& [( t8 f! K2 T% z Local TID: 0, 2
( Q7 L  ~1 v+ e8 ~6 r& t Interface name: GigabitEthernet0/0.18$ t' D: V0 V3 i; l9 H
R10:int FastEthernet0/0.101 ipv6 router isis% i  b& T) a! T& c. j6 p& S6 Y
6 w6 k) v6 s4 |) |
R1#sh isis neighbor detail
5 O: p4 s' Z5 f5 b. c5 Y: N5 R8 e
System Id        Type Interface  IP Address        State Holdtime Circuit Id
1 v/ T0 `3 s) K R10        L2  Gi0/0.101  9.9.101.10        UP        8        R10.02
7 z: U: I$ K$ ^0 w7 E% T  Z% K# k% Q) Q Area Address(es): 47.0110
2 U9 L; P: s+ z' Z5 W/ R& P SNPA: ca09.0bc0.00083 Y' g2 B7 D8 o0 O
IPv6 Address(es): FE80::C809:BFF:FEC0:8
: p* M1 q& g. n0 P State Changed: 00:47:16
5 g  B( |. J* y. A& }! t* e' E LAN Priority: 64/ e( E) W8 O& b% N, M& m* U/ T
Format: Phase V Remote TID: 0, 2
1 m7 e+ b, J) c: a! {: { Local TID: 0, 2% p' N- E% O0 `6 |  g9 l) {7 B, d
Interface name: GigabitEthernet0/0.101. }' p& b% l) m6 Z; v" ?; J
R8        L2  Gi0/0.18        9.9.18.8        UP        9        R8.02: ~* h9 q9 v+ h4 ]9 p& u
Area Address(es): 47.0108
: {' T9 X* @& g9 h& c SNPA: ca07.0bc0.0008
/ L8 f1 C8 R9 X IPv6 Address(es): FE80::C807:BFF:FEC0:8
8 p' r, V- K8 x State Changed: 00:47:140 N) a* S7 d* k) V+ Q
LAN Priority: 64
" g3 G2 X9 r: v4 y! t0 b0 _3 H Format: Phase V Remote TID: 0, 2
* D/ _+ d2 {& ^/ V8 [! j' [ Local TID: 0, 2
0 a9 m* u) P& v0 B$ y' ?1 w$ u Interface name: GigabitEthernet0/0.18& h2 w9 y$ u  q' L
' L0 ^% o4 K1 k4 m. d! J( @. B( J

! g. Y9 @! r- E# H7 B2 M$ L) q Fault#3 ISIS( H. y  Q5 ^9 Z- ~
configure AS 1009 as multi-topology: ASR:R1:        IOS: R9,R10,R89 G" ^5 W+ T9 R
router isis abcaddress-family ipv6 unicast no single-topology        router isis  s/ P9 E( J: g+ |# e
address-family ipv6 unicast multi-topology9 @- K# U( k! U/ z0 O  T

( e) p' ?. A1 b( P* H NOTE: if IOS-XR is running single-topology , then we don’t need to change it to MULTI-TOPOLOGY on both IOS /IOS-XR , Our goal is to just match the topology mode.
, g/ X! @1 ~+ ]6 ~- L" e5 D* |' r8 ]: L* R8 @
Fault#4 ISIS NET ID is wrong on R8!& A' j. X" C3 M% k+ s
router isis
2 Z( q$ X$ n: k2 w* a7 [( { no network 47.0109.0000.0000.8888.00 network 47.0108.0000.0000.8888.00. g( Y% X, s- {8 e8 z& P# X
!1 m* y% `9 g" Z3 W, P" F/ a  x
Fault#5 IP Address is not configured on the interface but neighbor is UP. NOTE: Need to check if the        IP addresses and subnet masks are correct? It is4 d& T: A* c) V- s8 G
very important to check these in an Integrated IS-IS environment because a misconfigured IP address will not prevent an IS-IS adjacency from being partially established
) e3 h& U, }* `# V, L( O3 |, _6 X- F" s9 M- t+ l
R10#show isis neighbors
7 K0 c% Z- ~9 S% X, X( x( O8 e; i, e' s/ c/ H" T, o+ T
System        Id        Type        Interface        IP Address        State        Holdtime        Circuit Id5 b& ~+ V* P9 D( @4 U+ }' \! p
R9                L2        Fa0/0.109        MISSING        UP        28        R10.031 J. p- `/ _/ m  }
R1
8 Q- E6 L' v2 F: A. l R10#                L2        Fa0/0.101        9.9.101.1        UP        22        R10.02
$ V! l" {/ H+ v+ n# j6 y9 }$ l% p on R9configure the IPv4 Address on R9 interface connecting R10.
4 V$ M+ i$ G4 F1 Q, {0 R4 m9 y !, Y, S$ F4 _  \6 ?8 T
interface FastEthernet0/0.109 encapsulation dot1Q 109
$ U( P  ]2 w# u- L) Z5 g ip address 9.9.109.9 255.255.255.0endR10#show isis neighborsSystem Id        Type Interface        IP Address        State Holdtime Circuit Id  P# i3 d# z  h% N# E
R9        L2        Fa0/0.109        9.9.109.9        UP        22        R10.03
8 m! p" q4 k6 t8 g7 e R1        L2        Fa0/0.101        9.9.101.1        UP        24        R10.02
/ S& W2 Q9 K/ q4 t3 ^ R10#NOTE: If the IPv4 Address is not configured , your PIM and LDP
' i9 O( v. }& U& l neighbors will also be down.With Faults like these it is very important to verify whether
) T8 R- t* ~2 C$ z: {7 t IPv4 and IPv6 address are configured.AS#9        : At minimum check for IPv6 Address, as version 6 protocol        run on link local address which are automatically        assigned when you enable IPv6 support on any interface.AS1009 : check for both IPv4 and IPv6 AddressAS109        Site 1: At minimum check for IPv6 Address
+ j% I, O0 z+ y0 K8 z0 E- |5 X AS109        Site 2: At minimum check for IPv6 Address8 @$ ~; \. |# _3 G# k9 ?
AS1109 Site 3: IPv6 Protocol in BGPv6 , peering are on physical address so you will find it out when peering wont come up 4 J% G3 H$ l+ z! ]7 b
( O! H+ A1 ?, \3 \
1.4: Bidirectional Forwarding Detection5 g/ ~! K4 \" B5 w9 F" _

: ~% d' y+ F' y) G$ s& F/ y  s Configure BFD between R5 and R6
- H  Q+ G0 Y# N, y( q( }" g% A R5:int Fa0/0.56 ip ospf bfd8 _7 U! k8 n  H8 p
bfd interval 100 min_rx 100 multiplier 3R6:int Fa0/0.56 ip ospf bfd
5 ^! [) l, J4 I; Q" t bfd interval 100 min_rx 100 multiplier 3: J* v( ^. e1 _% z
show bfd neighbor
, v' ~3 W* F# X! i9 v7 D8 f7 J ** NOTE : DON’T TEST ON DYNAMIPS, ROUTERS MIGHT CRASH , it will work on if you are practicing on IOU/Gigavelociy Rack-Rental and2 A" e6 V: X) O- M' V! ~
offcource in actual lab ;)
: }: h- J! v* _$ ]5 ?
. E  w: U- r' d1 a- f) U) C 12
; n; r! Q  I6 n7 E* A% q" I, [" t4 @' M+ x; v/ H
1.5: IPv6 OSPF Cost0 f+ \6 U+ J' G
2 E, M, B5 |/ E9 w, s. G5 T* ^! p, |
R7 is getting R5 Loopback IPv6 via two paths R4-R6-R5 and from R2-R3-R5 configure R3 such that it should prefer the path first one as primary.5 W7 W$ }; I" z3 i% }  a+ H( i# j
R3 IOS-XR:
8 `. a# j. {- X5 i# y router ospfv3 9( d: H2 U1 t$ F+ }
address-family ipv6 unicast
( u" b# K2 [+ R  ^ !
( \. z2 e- Y  T4 R0 g: b: d" ` area 14 k% C2 o, v. j2 m+ Q7 _9 A2 _3 z& N
int GigabitEthernet0/7/0/0.35 cost 30" f: C, ]1 K; P' `4 m
!2 w" L$ m* E- j+ |6 R. m
!Check on R7 if it is getting the route loopback of R5 from R4 ONLY
& {% x3 v3 e2 r( M
5 k, @- N8 y# r1 y 132 [1 x. g. m" B7 l; O) a9 T
9 T2 N; |, E2 L2 B  G
1.6: IPV4 BGP unicast troubleshooting
" Q4 O$ @7 {& S- D; m- J# }% h0 y( o$ Z  L/ k: @7 Z
R2 R3 R4 R5 R7 R6 have been preconfigured to belong to AS9. R1 R8 R9 R10 have been preconfigured to belong to AS1009./ U' m1 }" H1 ?  f
R2 and R7 act as the route reflector for IBGP IPV4 unicast within AS9. An I-BGP ipv4 session should not be established between R3 R4 R5 R6.$ N- q4 n" i$ n- p
R1 , R8 act as route reflector for IBGP ipv4 unicast within
4 Z" F0 _. J6 R# l AS1009. An IBGP IPV4 session should not establish between R9
* j0 v/ [7 v- C- k! G, c2 K R10." o: w# E2 S5 Q1 x2 [
There are some problems in BGP IPV4 unicast find out and fix them.
6 G% s' X; p2 n5 B: H$ P1 K ON IOS-XR! k6 h; s# p2 R
show running router bgp | in “neighbor|address-family|route-reflector-client”  t! c  q3 Q/ }( b
show bgp ipv4 unicast summaryON IOS
3 _5 T5 w8 W7 i8 Y7 Z) e show running router bgp | in address-family|route-reflector-client show bgp ipv4 unicast summary8 L, ^3 C8 X% }4 r8 H, m4 ~

) B7 S9 O3 _5 b0 @8 _ R5 is not configured as RR client on R2
* h6 N% K5 v  p8 ~ R2:4 p; s! N, d/ y$ f3 q; H* F
router bgp 9 neighbor 9.9.0.5
3 y8 L1 H0 Z2 m7 U! \ address-family ipv44 k) h8 u7 I6 r  B( e
route-reflector-client: B: K6 }$ |& J  a/ o+ X8 I
!
  G# ], A: P" d$ Q1 Q8 S2 T+ O+ M !) {- I; ~( h1 R
145 A% h3 j+ b" E& R* X

' k: b6 C3 X, {9 x, Z  ^. h 1.7 : IPV6 BGP unicast troubleshooting  \1 x$ Y7 A9 I" \+ d; S

) L7 G! [' a( Q. v* ~1 J R2 R3 R4 R5 R7 R6 have been preconfigured to belong to AS9. R1 R8 R9 R10 have been preconfigured to belong to AS1009.
2 S  \% h; H/ B& E R2 act as the route reflector for IBGP IPV6 unicast within AS9. An iBGP IPv6 session should not be
  ?$ x9 `5 F" u/ j established between R3 R4 R5 R6 R7.% L- B: P3 e) }% ^0 Z* S- q
R1 act as route reflector for iBGP IPv6 unicast within AS1009. An IBGP IPV6 session should not establish between R6 R9 R10. There are some problems in BGP IPV6 unicast find out and fix them.
& P/ z9 C/ E/ Q/ u2 s* \ R2-R6: IPV6 Neighbor-ship is down due to AS number changed on R6R6router bgp 90 ]8 y5 ^2 J& d0 j2 _
no neighbor 2002:9:9::2 remote-as 109 neighbor 2002:9:9::2 remote-as 9( W! Z( ^0 l! `: x4 N2 F, a! P
neighbor 2002:9:9::2 update-source loopback0address-family ipv6 unicast neighbor 2002:9:9::2 activate3 ?0 S8 W% [& g
R2:R2 is not configured as RR for R6.router bgp 9neighbor 2002:9:9::6 address-family ipv65 U! K* E0 ^" |
route-reflector-client
' X0 Y; w0 r0 O !( D  d3 c/ V0 u. m4 R. h
!
$ x7 ^( V3 G8 s$ L2 i; M R9:Update source loopback 0 is missing on R9 towards R1.
4 q3 O; @5 u2 k1 S5 I. [. @) J" w
15
) w1 u$ `% J- f9 O
- W1 f1 W' H( e
( a: b; o0 y0 S. {' m* r: ], } router bgp 1009; F1 u$ j; f: @6 V# f. E% a" I
neighbor 2002:9:9::1 remote-as 1009 --> Missing neighbor 2002:9:9::1 update-source Loopback0
3 Y8 a; V& p# L% m0 h2 _/ A! j !
: n1 p& k) Q- Q+ m) C. X address-family ipv6 no synchronization network 2002:9:9::9/128
* [+ m$ s$ N8 y- T* y* b3 m7 V neighbor 2002:9:9::1 activate
! X6 H, ^- c. G4 d1 e3 f exit-address-family
) W! T6 d9 ~( P0 u3 W' ?4 \$ ~ !
+ i- R8 `5 Z1 T* z+ ^$ s: |3 a 1.8a: E-BGP IPv4 and IPv6 Peerings
9 W, q" e6 _4 z0 l/ f4 H+ y" I
. V: n7 q- k: Q Configure a E-BGP IPv4        unicast session between R1 and R28 e8 o  R' N7 y7 M/ v& R, u7 H
Configure a E-BGP IPv4        unicast session between R7 and R81 U$ L( u7 p0 y7 h$ N' k
Lo0 for all the Routers should be visible in both AS 9 and AS1009, no other routes are allowed to be redistributed between AS9 and AS1009.9 N; f; W7 P; d! C* y+ T
point to point connected subnets between R1 and R2        / R7 & R84 J/ _  X% \( _% Y0 C# t; W  S
are NOT ALLOWED to be advertised/redistribute in the respective2 C% y4 I- r; @9 |* ^# p
IGPs
3 }2 t; h. p" C$ F+ F On all IOS-XR routers R1, R2, R3, R4!5 c. y& L4 ~, R! C1 E4 X; R
route-policy PASS
4 f- d) b6 l- T4 o/ J! s" d pass end
" u4 b* N$ K. ]' i. a5 _# F !*** AT THIS POINT WE WILL NO ONLY CONFIGIRE IPv4 E-BGP Peering , but also
6 R4 |- b4 ^' W: L9 j3 l, V IPv6 , VPNv6 and NEXT-HOP-SELF , POP Labels for VPNv6 transport Address.! l$ e# M8 ^4 m2 q7 P" I
***R2        R1
9 |; t% F! A. P% q* n router bgp 9
$ l, U! X8 m  {- K9 b7 a) o# y neighbor 9.9.12.1 remote 10091 v# w9 u. D" |9 j
address-family ipv4 unicast route-policy PASS in
$ N, F3 j8 P) ^9 z- Q' m; l route-policy PASS out
, J) K" u$ F- K6 P( o# R) S address-family vpnv6 unicast route-policy PASS in9 T2 h) r( ^2 V: B7 P
route-policy PASS outneighbor 2002:9:9:12::1 remote-as 1009$ }2 a% z8 p% X
address-family ipv6 unicast  g* P' ~* D( }* K( _% ?; B- b
route-policy PASS in        router bgp 10090 N  O6 b# }- E1 a8 w/ D, q' i# e
neighbor 9.9.12.2 remote 9. u, V; U; e9 J
address-family ipv4 unicast route-policy PASS in$ s# u1 O! ~1 |4 B* F
route-policy PASS out, a, ?! W6 E3 N5 A, [9 N# h
address-family vpnv6 unicast route-policy PASS in
9 z0 U. ]% l. I$ V& ^1 j. {1 n route-policy PASS outneighbor 2002:9:9:12::2 remote-as 9
" [; c' R" H& b# K+ p address-family ipv6 unicast
8 _' S+ Q/ r2 j/ T4 P- l9 g/ | route-policy PASS in) s: o% P- M$ |4 k
   
7 N9 \( Z: s9 H8 ~+ j route-policy PASS out!
1 r8 Z+ U5 x* v+ s router static
7 Q8 U% p* {" T5 `9 W5 _; @$ y7 Y( }0 b address-family ipv4 unicast, ]& h! `5 C  \4 B* a; b
9.9.12.1/32 POS0/5/0/0# Q/ V% v( h8 m& u) [  H0 }
!
; ]' q. A5 {) ~" s0 h1 I. c !$ z" ^3 I" l( [
verify the Pop Label# d. P- V9 g( P) e

' w# t5 A! ]2 u route-policy PASS out!
4 L6 x$ t3 A( G- @1 L' G( b router static/ ]( a7 p) T( @
address-family ipv4 unicast
* N1 R9 }  r# j# W( v/ s1 D7 {: L: s 9.9.12.2/32 POS0/2/0/0
! c. G9 a( _/ {5 t. c% F' [ !8 o. P- A3 y% x3 q4 d
!8 ?2 H9 P+ G, B0 i& `
verify the Pop Label
. j" z* u8 k; x* s NEXT-HOP-SELF ON IOS-XR
/ m# v- t- @! N: f+ o show running route bgp | in “neighbor|address-family|route-reflector-client”
5 G/ ^1 `  B% p5 xshow bgp ipv4 unicast summary
* U7 m1 |* X, S: ~9 [# J R2        R1
, V- i1 X* ]. u !
/ t+ ]* G0 ]9 U6 t! @8 X8 q, c router bgp 9. s% t6 Z  {. n! V; j! {

/ Z8 H8 R5 X" n- _0 L& U# I+ o4 d: L neighbor 9.9.0.3
) k: m  K& z6 `# y5 m( L$ E+ F) ~ address-family ipv4 unicast next-hop-self1 ]  j. A; d3 `# `1 p( `  {& ^
!: O. R, i. h" u4 c3 [
address-family vpnv6 unicast next-hop-self9 v* N7 j8 v8 }9 Z& ]3 m8 t
!
5 w$ U5 y  P; l3 G !3 ?1 W. i; k: ^5 c3 o
neighbor 9.9.0.4
/ b3 c1 ?# H: L address-family ipv4 unicast next-hop-self$ m6 J, M+ g9 x& C4 v- D0 j

1 q2 a* j* \* ^ neighbor 9.9.0.50 ^+ f+ Z3 I. D4 l; D  z& j
adddress-family ipv4 unicast next-hop-self
' {' S" O. a/ m9 g4 f. i! v. Q
1 \$ ?( D5 N) C neighbor 9.9.0.7
6 n' y' R! F4 `/ K address-family ipv4 unicast next-hop-self0 }% F9 R! _  D; G
!
# P; ]7 Z( u1 O$ p& \  Q6 I& |& _( s% n) T
!        !6 S3 b- @) ]- D- U: |8 B. d
router bgp 1009" {$ C- w$ G( ~* I
# Q5 {' ~! Z4 D6 e" h1 n; @
neighbor 9.9.0.8* B6 b0 C: Q) r3 ]1 O0 `! \
address-family ipv4 unicast next-hop-self/ Y1 l% V. K% h, I

0 ^9 P9 a4 z% c- ~" n' d& A neighbor 9.9.0.9
- y' Y+ J" s- D5 ~( w9 e address-family ipv4 unicast next-hop-self
0 G, t2 a4 `! i6 d- g2 E8 R; D0 P  P0 A8 K: A* J
neighbor 9.9.0.10
, M" z/ _, w4 E8 r/ u" x address-family ipv4 unicast next-hop-self
; I! p7 q" P5 U7 x: s2 O/ Z: Q7 q7 m% Q  ^, ]5 L# q
address-family vpnv6 unicast next-hop-self8 n1 s+ o6 j8 \: y, E: {' v' T

% X* E4 t' i; i !
  [# o2 C% F+ j7 N0 F !) b  S, E. F  ?  U0 Q/ ^) X9 _
   
, k% a. B- `+ `( w !! k. j/ K1 ?! q$ A
neighbor 9.9.0.6
) S1 H& ]. a0 O4 j address-family ipv4 unicast next-hop-self
4 V5 X9 i. Q1 k6 x2 g: H+ F5 w
2 U: o/ O3 G! |  a address-family vpnv6 unicast next-hop-self  {6 ]* _, t- U$ m# i2 W
!
+ s# y, n6 ]& F8 A. f !
, R: f; ~3 v2 m* x3 m  Z, |9 O neighbor 2002:9:9::5
  |, r* V+ `5 B0 d, ^ address-family ipv6 unicast next-hop-self
/ ]% J/ Z% R2 C9 M0 m neighbor 2002:9:9::8
5 ^7 z+ i4 a, ?
1 A+ {1 C% {  g( I, @% @; ` address-family ipv6 unicast next-hop-self
6 Y6 J7 O' i7 Z" [, C  d
& j1 x; v. F) d: y( N# @( m8 x !
' }( @$ \- }. F9 B5 P3 c  f) Z !
, U/ J" a% v; K) A8 i. r neighbor 2002:9:9::9# u4 t. }1 _6 b* ~; ~; d! e
% Y7 l) d( G! K7 b& I. ^7 j
address-family ipv6 unicast next-hop-self
; D$ _# P  I- {1 A$ E8 k+ F. W3 }2 C3 E* M1 N1 p
!1 ~. o, a! I' F
!        !) |; H& u, F2 ]9 N6 u6 H& c! I
neighbor 2002:9:9::6        !) ?% {2 P) R, L# a7 n' b! |
. f0 o! `+ R& A3 e
address-family ipv6 unicast next-hop-self
+ U4 w' x/ Z! s6 P  | !
' l7 ]- i; O1 s4 K6 D! U2 m& \' A# P !
" i6 S9 a5 d2 X$ E* l/ a) [ neighbor 2002:9:9::35 [6 J. Z* E* Z! m& U, k& t
address-family ipv6 unicast
0 i% V3 ]. H# |4 O3 j: \6 X/ V, V next-hop-self
. \, r2 d" c* B" [7 v
5 A6 r: d, m# U$ @9 {* F9 I4 d neighbor 2002:9:9::101 V% ^" L" t9 S' W2 a* c+ [' N( z
address-family ipv6 unicast next-hop-self
* Q1 v- p" h& x; _ !( W: v* L/ v6 p' l4 `" o; f
!$ f; L; t, g- r  j, I7 [9 s
neighbor 2002:9:9::4* f% o) f( F4 j9 W+ q
address-family ipv6 unicast  n3 U/ }$ g/ ~# ~
!. m: b  |  P2 S, X
neighbor 2002:9:9::7
* s- [+ L( h0 a9 h& t address-family ipv6 unicast
' }0 Q7 m+ l6 O- ?- ?, _* n !
& t, b* j: a* E2 c ** IPv4 BGP Peering between R7 and R8 will be done later with: f# m: p1 @) |0 |3 E
Local Prefernce Task.
: j/ A9 `8 u; V' l+ i 1.8b: E-BGP IPv4 and IPv6 Peering6 v, n3 T- `" N. {
' a5 E; m# L+ Y% S  k' M5 V7 x) v
Configure a E-BGP IPv6        unicast session between R1 and R28 ?  `# H  X1 G, X: Y8 H5 S
Lo0 for all the Routers should be visible in both AS 9 and AS1009, no other routes are allowed to be redistributed between AS9 and AS10094 L, {, S* R4 b7 C- A/ @
point to point connected subnets between R1 & R2 are NOT ALLOWED
  e! N5 `9 B# K to be advertised/redistribute in the respective IGPs; G4 Z/ s  |5 \% I
ALREADY TAKEN CARE OF
. v& \3 o- T; J0 K5 _ 1.8c: BGP IPV4 Unicast Path selection
( o- {) ]" i+ w+ H" F- O! I( `; y. Y( R0 T5 T3 V
Configure R7 to ensure that ipv4 traffic from AS9 destined to AS1009 chooses R7 as primary exit point and R2 as backup exit point.
/ C: a7 Q$ ?0 Q& ]. a Configure R8 to ensure that ipv4 traffic from AS1009 destined to
9 q" I* G# p6 S5 s8 a: Y% J7 B5 b AS9 chooses R8 as primary exit point and R1 as backup exit point.!5 V! \$ R* o" ?! T  R7 I
route-map LP permit 10
& ^) w6 G/ g7 u9 ?8 K3 s$ y/ j' W set local-preference 200
' r( z3 g, d6 E, j- K2 x6 j0 R !2 v. a( h3 [3 W' u
R7        R8
/ K5 P: o/ W/ _9 L! Y* e& Z router bgp 9
% e- v1 Y) U* E0 ^7 F  D neighbor 9.9.78.8 remote-as 1009address-family ipv4 unicast neighbor 9.9.78.8 activate. Q- U; m8 ~1 M$ ^: W& l, S
neighbor 9.9.78.8 send-community both neighbor 9.9.78.8 route-map LP in% S3 u2 E4 s2 {. p, T

, ^! B0 m2 @0 \" a! j address-family vpnv4 unicast neighbor 9.9.78.8 activate4 L  x# ]0 L9 ~
neighbor 9.9.78.8 send-community both        router bgp 1009  l$ M# R+ j( Z( g, o
neighbor 9.9.78.7 remote-as 9address-family ipv4 unicast neighbor 9.9.78.7 activate
9 J( D" _5 G- ^+ H# U neighbor 9.9.78.7 send-community both neighbor 9.9.78.7 route-map LP in
( W% L4 b; r! i- W' K
! X3 ~" d* g. \+ F9 h, V1 E$ ]& _ address-family vpnv4 unicast neighbor 9.9.78.7 activate5 }: P* e- W+ W: ~6 m- o/ V
neighbor 9.9.78.7 send-community both
: `/ }3 K6 o# t clear ip bgp * on both R7,R8 to have LP get take effect.
9 u4 p# [$ S4 L; g0 H0 k3 }' E8 d ON IOS
8 }! S$ r" x6 ?/ Z) F show running | in address-family|route-reflector-client show bgp ipv4 unicast summaryR7        R8
1 v: {+ ?- `: D2 P) f! ^
& q% H" S. ~6 S3 x; M2 @' r9 k router bgp 9
! \2 z4 ?! e5 v- Z2 ^+ N8 \& F  g4 h address-family ipv40 F8 p: M9 ?2 P, r% |* B
neighbor 9.9.0.2 next-hop-self neighbor 9.9.0.3 next-hop-self neighbor 9.9.0.4 next-hop-self neighbor 9.9.0.5 next-hop-self neighbor 9.9.0.6 next-hop-self address-family vpnv43 H+ X; _2 L2 Y/ F8 w- R5 h$ C" i% d
neighbor 9.9.0.2 next-hop-self
$ i: o. t) E! s6 e% k' R neighbor 9.9.0.3 next-hop-self neighbor 9.9.0.4 next-hop-self neighbor 9.9.0.5 next-hop-self neighbor 9.9.0.6 next-hop-self address-family ipv6
# \$ l8 c3 Y# \3 V8 t, Q, R end4 J) B5 u$ U  D+ u9 q# r7 m2 h( x
wr        ) F# S% X9 \5 g( Q) Q) Z
router bgp 1009 address-family ipv4
" r1 B! E' |& D9 s neighbor 9.9.0.1 next-hop-self neighbor 9.9.0.9 next-hop-self neighbor 9.9.0.10 next-hop-self address-family vpnv4
9 H  `- a8 l4 q! f1 W+ Q neighbor 9.9.0.1 next-hop-self neighbor 9.9.0.9 next-hop-self neighbor 9.9.0.10 next-hop-self address-family ipv6" f  E  P1 A3 ], @, @* n! g% q1 j2 `
end
/ Z, g6 u; k9 k6 k wr. `5 U( x0 l3 z; m$ M: x, L

评分

参与人数 3鸿鹄币 +20 收起 理由
s07yyz + 5 赞一个!
Mansilence + 10 赞一个!
beir + 5 很给力!

查看全部评分

发表于 2013-6-11 22:09:32 | 显示全部楼层
沙发 2013-6-11 22:09:32 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-6-11 22:13:37 | 显示全部楼层
板凳 2013-6-11 22:13:37 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-6-11 22:45:16 | 显示全部楼层
地板 2013-6-11 22:45:16 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-6-12 03:24:24 | 显示全部楼层
谢谢 谢谢分享。。。。。 9 C, o5 ]; f6 V" r& ^+ M$ Z
5# 2013-6-12 03:24:24 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-6-17 15:33:53 | 显示全部楼层
6# 2013-6-17 15:33:53 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-6-27 14:17:14 | 显示全部楼层
7# 2013-6-27 14:17:14 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-7-1 16:35:42 | 显示全部楼层
啥也不说了,楼主就是给力!
8# 2013-7-1 16:35:42 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-7-17 22:28:48 | 显示全部楼层
膜拜中啊。。。。。向大神看齐。。。加油加油。。。。
9# 2013-7-17 22:28:48 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-7-31 08:14:44 | 显示全部楼层
10# 2013-7-31 08:14:44 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-7-31 08:16:54 | 显示全部楼层
膜拜神贴,后面的请保持队形~
11# 2013-7-31 08:16:54 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-8-19 22:48:07 | 显示全部楼层
不错,谢谢分享!!!!!!!!!!!!!!!!!!!1
12# 2013-8-19 22:48:07 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-11-1 02:31:56 | 显示全部楼层
13# 2013-11-1 02:31:56 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2013-11-1 10:39:35 | 显示全部楼层
很不错的战报,感谢LZ
14# 2013-11-1 10:39:35 回复 收起回复
回复 支持 反对

使用道具 举报

发表于 2014-5-30 22:20:17 | 显示全部楼层
我也打算考,刚开始学。。。
15# 2014-5-30 22:20:17 回复 收起回复
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2025-5-8 12:37 , Processed in 0.475509 second(s), 25 queries , Redis On.  

  Powered by Discuz!

  © 2001-2025 HH010.COM

快速回复 返回顶部 返回列表