Module Self Check
Use the questions here to review what you learned in this module. The correct answers and solutions are found in the Module Self-Check Answer Key. Q1) Why do you need a selective VRF import command (Source Using Advanced VRF Import and Export Features) Q2) How does the import route map affect the VRF import process (Source Using Advanced VRF Import and Export Features) Q3) Why do you need a selective VRF export command (Source Using Advanced VRF Import and Export Features) Q4) How does the...
Steps for Configuring a Central Services VPN
Separate VRF per client site Separate VRF per client site A unique RD on each client site Import and export routes with an RT that is the same value as the RD for each client site (VPN of client) Export routes with an RT (clients-to-server) associated with the server site Import routes with the RT (server-to-clients) into client VRFs 2004 Cisco Systems, Inc. All rights reserved. MPLS v2.1 6-6 To configure a central services VPN, you need to address the following requirements You need a...
Module Self Check Answer
Q2) Because with routing protocols such as RIP and BGP, only a single copy of the protocol may be running in the router. Q4) False. Interfaces are assigned to a VRF. Q5) D Q6) VPNv4 routers are redistributed from the global BGP table to the per-instance BGP table and then to the per-instance RIP, which is propagated to the CE router. Q12) EBGP is used to carry routing updates between the PE router and the CE router. IBGP (VNPv4) is used to carry VPN route updates between PE routers. Note IBGP...
Monitoring VRF Routing
This topic describes how to monitor VRF routing. This topic describes how to monitor VRF routing. Displays the routing protocols configured in a VRF. Displays per-VRF BGP parameters. Cisco Systems, Inc. All rights reserved. MPLS v2.1 The following three commands can be used to monitor VRF routing The show ip protocols vrf command displays the summary information about routing protocols running in a VRF. The show ip route vrf command displays the VRF routing table. The show ip bgp vpnv4 vrf...
- A company with several securityconscious departments that exchange data between their servers
- A route map can be configured in a VRF to make the route import more specific
- A separate link for Internet access is a perfect match for this customer type
- Adding flexibility to client service selection
- Address families routing protocol contexts are used to configure these three tasks in the same BGP process
- Addressfamily
- Addressfamily ipv4
- Advanced VRF Features
- After this operation the provider AS number is prepended to the AS path
- All Internet routes are carried as VPN routes full Internet routing cannot be implemented because of scalability problems
- All nonBGP perVRF routes have to be redistributed into perVrf Bgp context to be propagated by MPBGP to other PE routers
- Allowasin The Issue
- Allowasin The Issue Cont
- Alternatively only the internal OSPF routes can be redistributed into MPBGP on the PE routers
- Are CE routes received by the PE router
- Are large labeled packets propagated across the MPLS backbone maximum transmission unit issues
- Are routes redistributed into MPBGP with proper extended communities
- Are VPNv4 routes inserted into VRFs on PE2
- Are VPNv4 routes propagated to other CE routers
- Are VPNv4 routes propagated to other PE routers
- Are VPNv4 routes redistributed from BGP into the PECE routing protocol
- AS pathbased BGP loop prevention is bypassed with the ASoverride and allowasin features
- ASOverride ASPath Prepending
- ASOverride The Issue
- Assign interfaces to VRFs
- Assigning an Interface to a VRF Table
- Benefits
- Benefits and Limitations of Separate Internet Access
- Can support all customer requirements including a BGP session with the customer accomplished through advanced BGP setup
- CE routers run standard OSPF software
- Central Firewall Service Addressing
- Central Services VPN
- Central Services VPN and Simple VPN Requirements
- Central Services VPN and Simple VPN Requirements Cont
- Central Services VPN Data Flow Model
- Central Services VPN Routing
- Classical Internet Access for a VPN Customer - 2
- Command Modes
- Conclusion Mpls Vpn must extend the classic Ospfbgp routing model
- Configuration of Mpibgp sessions
- Configure redistribution of OSPF into MPBGP
- Configuring a PerVrf Bgp Routing Context
- Configuring MPIBGP
- Configuring RDs in a Central Services and Simple VPN
- Configuring Route Targets
- Configuring RTs in a Central Services and Simple VPN
- Configuring Selective VRF Export Cont
- Configuring Selective VRF Import Cont
- Configuring VRFs in a Central Services and Simple VPN
- Data Mdt Mdt group created on demand for mVPN SG pairsusually highbandwidth traffic
- Defaults - 2 3 4 5 6 7 8
- DHCP Relay Corporate DHCP Server
- DHCP Relay Shared DHCP Server
- Disabling IPv4 Route Exchange
- Displays labels allocated by an Mpls Vpn for routes in the specified VRF
- Each interface assignable to only one VRF
- Every CE router needs two links or subinterfaces to its PE router
- Every customer that needs Internet access is assigned to the same VPN as the Internet gateway
- Example ASOverride
- Example BGP Route Propagation Outbound - 2
- Example Central Services VPN Routing
- Example Configuring a Central Services VPN
- Example Configuring a Default RD for Two VRFs
- Example Configuring Overlapping Vpn Vrfs
- Example Configuring perVrf Bgp Routing Context
- Example Configuring VRFs
- Example Configuring VRFs in a Central Services and Simple VPN
- Example DHCP Relay Configuration
- Example DHCP Relay Corporate DHCP Server
- Example DHCP Relay Shared DHCP Server
- Example Disabling IPv4 Route Exchange
- Example Limiting the Total Number of VRF Routes
- Example Mpls Vpn Network
- Example NAT Implementation with Multiple NAT Pools
- Example Network Address Translation
- Example Optimizing of Packet Forwarding
- Example OSPF Down - 2
- Example OSPF Superbackbone Implementation
- Example OSPF Tag Field
- Example OSPF Tag Field Routing Loop Prevention
- Example Overlapping VPN Routing
- Example Overlapping VPNsConfiguration Tasks
- Example Sample Sham Link Configuration
- Example Sham Link
- Export map
- Fast Switching and IP Multicast
- For other routing protocols the SOO attribute can be applied to routes learned through a particular VRF interface during the redistribution into BGP
- Here ACentral talks to BCentral
- High Bandwidth BGP Backbone
- Independent perinstance router variables for each instance
- Internet access as a separate VPN
- Internet Access as a Separate VPN Cont
- Internet Access from Every Customer Site
- Internet access is implemented via separate interfaces that are not placed in any VRF traditional Internet access setup
- Internet Access Through a Central Firewall Service
- Internet Access Through a Dedicated Subinterface Traffic Flow
- Internet Access Through Central Firewall Service
- Ip route vrf
- Ip vrf sitemap
- Is the CEF entry correct on the ingress PE router
- Is the LFIB entry on the egress PE router correct
- It can limit the total number of routes in a VRF
- Limiting the Total Number of VRF Routes Cont
- LSA flooding occurs across the sham link
- Managed CE Routers
- Managed Services Overview
- Maximum design flexibility Internet access totally independent from Mpls Vpns
- Maximum routes
- Module Objectives - 2
- Module Self Check
- Module Summary - 2
- Module Summary Cont
- Monitoring an Mpbgp Vpnv4 Table
- Monitoring an Mpbgp Vpnv4 Table show ip bgp vpnv4 rd routedistinguisher
- Monitoring an Mpbgp Vpnv4 Table show ip bgp vpnv4 vrfname
- Monitoring Labels Associated with VPNv4 Routes
- Monitoring Mpbgp Sessions
- Monitoring Mpbgp Sessions show ip bgp neighbors
- Monitoring Mpbgp Sessions show ip bgp neighbors Cont
- Monitoring perVrf Cef and LFIB Structures Cont
- Monitoring VRF Routing show ip bgp vpnv4 vrf neighbors
- Monitoring VRF Routing show ip protocols vrf
- Monitoring VRFs
- Multicast VPNs
- Multicast VPNs Today Data MDT
- Multicast VPNs Today Default MDT
- Multicast VPNs Today Solution Concept
- Must be advertised by BGP
- Need for Routing Protocol Contexts
- Neighbor allowasin
- Neighbor asoverride
- Neighbor maximumprefix
- Neighbor nexthopself
- Neighbor remoteas
- Neighbor routemap
- Neighbor sendcommunity
- Neighbor updatesource
- Network Address Translation Implentation
- Network Address Translation Today
- No other set operations can be performed by this route map
- NonBGP Route Propagation Outbound
- Note Because of current limitations with route redistribution backdoor links are not supported
- Objectives - 2 3 4 5 6 7 8 9
- OnDemand Address Pools Address Pool Management
- OnDemand Address Pools IP Address Management Today
- OnDemand Address Pools VRF Pool Example
- Only RIPv2 is supported
- Optimizing of Packet Forwarding Across the Mpls Vpn Backbone Cont
- OSPF cost is copied into MED attribute
- OSPF Hierarchical Model
- OSPF in an Mpls Vpn Routing Model
- OSPF Superbackbone Ospfbgp Hierarchy Issue
- Overview - 2 3 4 5 6 7 8 9 10 11 12 13 14
- PE Router
- PE routers filter external OSPF routes to MPBGP with OSPF tag field AS numbers matching Bgp As numbers
- PE routers never redistribute OSPF routes with the down bit set into MPBGP
- Performs VRFbased traceroute
- Pim
- Prerequisites
- Rd
- Redundant Internet Access
- Redundant Internet Access Cont
- References
- Requires separate physical links or WAN encapsulation that supports subinterfaces
- Route Propagation Inbound
- Route Propagation Inbound Cont
- Router ospf
- Routes from Area 0 at one site appear as interarea routes in Area 0 at another site
- Sample router configuration for simple customer VPN
- Set extcommunity - 2
- Set of import and export route targets
- Show cef interface
- Show ip bgp neighbors
- Show ip bgp vpnv4
- Show ip bgp vpnv4 rd routedistinguisher
- Show ip bgp vpnv4 vrf
- Show ip bgp vpnv4 vrf neighbors
- Show ip cef vrf
- Show ip protocols vrf
- Show ip route vrf
- Show ip vrf
- Show mpls forwarding vrf
- Simple setup using overlapping VPNs
- Some customers would like to optimize traffic flow and gain access to the Internet from every site
- Specify additional parameters for VPNv4 route exchange filters next hops and so on
- Specifying Export and Import RTs
- Student Guide
- Summary - 2 3
- Summary Cont - 2 3 4 5 6 4 5 6 7 8 9 10 11 12 13 14 15
- Syntax Description - 2
- The Cisco IOS software can be configured to reject routes optional
- The forwarding information from the MPBGP route is used
- The overall number of routing processes per router is limited to 32 of which only 28 are available for VRF assignment
- The PE router will reject the update only if its AS number appears in the AS path more often than the configured limit
- The same AS number may be used for all sites
- These routes do not enter the IP routing table even when they are selected as the best routes using the SPF algorithm
- This setup could lead to security leaks because global packets could end up in VPN space
- To propagate standard BGP communities between MPBGP neighbors use the both option
- Two addressing options
- Usage Guidelines - 2 3 4 5 6
- Validating CEF Status
- Validating the Endto End Label Switched Path
- Verifying the Routing Information Flow
- Volume
- VRF Creation and RD Overview
- VRFspecific EBGP neighbors are configured under corresponding address families
- What Is DHCP Relay
- When the SPF algorithm is executed the sham link will have the specified cost
- Wholesale Internet Access - 2
- With MPLS managed services ISPs can provide additional centralized services that are integrated with existing VPN service to customers
- Without the OSPF match keyword specified only internal OSPF routes are redistributed into OSPF

