Mpls Network
Load Balancing in CEF
CEF allows for load balancing or load sharing of traffic among multiple outgoing links. CEF needs multiple outgoing links as next hops in the routing table to perform load balancing. The command maximum-paths specifies how many paths or next hops are allowed per prefix in the routing table for the specific routing protocol. For instance, if you configure maximum-path 2 under the routing protocol Open Shortest Path First (OSPF), only two OSPF paths per prefix are allowed in the routing table....
Mpls Ldp Session Protection
A common problem in networks is flapping links. The flapping of links can have several causes, but it is not the goal of this book to look deeper into this. Flapping links do have an important impact on the convergence of the network. Because the IGP adjacency and the LDP session are running across the link, they go down when the link goes down. This is unfortunate, especially because the link is usually not down for long. The impact is pretty severe though, because the routing protocol and LDP...
Forwarding Equivalence Class
A Forwarding Equivalence Class (FEC) is a group or flow of packets that are forwarded along the same path and are treated the same with regard to the forwarding treatment. All packets belonging to the same FEC have the same label. However, not all packets that have the same label belong to the same FEC, because their EXP values might differ the forwarding treatment could be different, and they could belong to a different FEC. The router that decides which packets belong to which FEC is the...
Frame Relay
Frame Relay can be carried across the MPLS network in two fashions DLCI-to-DLCI or port-toport. In the DLCI-to-DLCI method, one VC is carried over one pseudowire. In the port-to-port method, all VCs on one port are carried over one pseudowire. You can use both the Frame Relay encapsulation types of Cisco or the IETF (RFC 1490) for the DLCI-to-DLCI and the port-to-port methods. In the DLCI-to-DLCI method, each VC is carried across the MPLS network over one pseudowire. Frame Relay VCs to...
ATM Cell Relay
With ATM cell relay, ATM cells are labeled and transported across the MPLS network. Every single cell is transported across the network, including the OAM cells. With ATM cell relay, you have two options single cell relay mode and packed cell relay mode as you learn about in the next sections. With single cell relay, each ATM cell is separately labeled and carried across the MPLS network. The disadvantage of single cell relay is the created overhead of adding two MPLS labels, a control word...
What Are the Components of CEF
CEF has two main data structures the Forwarding Information Base (FIB) and the adjacency table. The FIB is also referred to as just the CEF table. Look at Figure 6-2 to see an overview of CEF and its components. The adjacency table is the CEF component that is responsible for the MAC or Layer 2 rewrite. When routers and hosts are adjacent, they learn about each other by some means. They can discover each other dynamically or by means of configuration. If routers are adjacent across a...
Ospf Route Type Extended Community
OSPF can be the routing protocol on the PE-CE link. To propagate the customer routes from PE to PE, OSPF is redistributed into iBGP and vice versa on the PE routers. The down side of this is that all OSPF routes become external routes on the remote PE when the routes are redistributed back into OSPF. The result of this would be that all OSPF routes that transverse the MPLS VPN backbone would be less preferable than the routes that did not transverse the backbone but were sent via an intersite...
Path MTU Discovery
One method to avoid fragmentation is Path MTU Discovery, which most modern IP hosts perform automatically. In that case, the IP packets sent out have the Don't Fragment (DF) bit set. When a packet encounters a router that cannot forward the packet without fragmenting it, the router notices that the DF bit is set, drops the packet, and sends an ICMP error message Fragmentation needed and do not fragment bit set (ICMP type 3, code 4) to the originator of the IP packet. The originator of the IP...
IP Service Level Agreement
The Cisco IP Service Level Agreement (IP SLA) is a network performance measurement tool that is embedded in Cisco IOS. IP SLA allows the network operator to monitor the network performance-wise and see if the SLAs are adhered to. The network characteristics that you can monitor include jitter, one-way delay, RTT, and packet loss. These measurements can be done per class-of-service. IP SLA measures the network by sending periodic probes. The probes can be various protocol packets, such as ICMP,...
Internet Access Through the Global Routing Table with Static Routes
You can provide Internet access to the VPN customers by forwarding their traffic to the Internet gateway of the service provider. The Internet gateway is known to all P routers in the MPLS VPN network because the gateway IP address is known in the global routing table of the service provider. It surely is running eBGP with a router of an Internet provider. The PE routers are already running BGP, so they can provide MPLS VPN services. The PE routers can also run an iBGP peering session for IPv4...
Targeted LDP Session
Normally, LDP sessions are set up between directly connected LSRs. In a network in which the IGP routes need to be labeled, this is sufficient, because the label switching of packets is hop per hop. Therefore, if the label bindings are advertised hop per hop for the IGP routes, the LSPs are set up. However, in some cases, a remote or targeted LDP session is needed. This is an LDP session between LSRs that are not directly connected. Examples in which the targeted LDP session is needed are AToM...
Giant and Baby Giant Frames
When a packet becomes labeled, the size increases slightly. If the IP packet was already at the maximum size possible for a certain data link (full MTU), it becomes too big to be sent on that data link because of the added labels. Therefore, the frame at Layer 2 becomes a giant frame. Because the frame is only slightly bigger than the maximum allowed, it is called a baby giant frame. Take the example of Ethernet The payload can be a maximum of 1500 bytes. However, if the packet is a maximum...
Overview of the IPv6 Protocol
The biggest changes in IPv6 compared to IPv4 are the bigger addresses and the simplified header. The next sections explain the new IPv6 header and how it is different from the IPv4 header. You can see the header of the IPv4 protocol in Figure 9-1. Compare that to the IPv6 header in Figure 9-2. The obvious change is the length of the addresses. The source and destination address are four times bigger in the IPv6 header. Also, the header is simplified because certain fields have been omitted. For...
Dot1q Tunneling QinQ over AToM
Dotlq tunneling, or QinQ, refers to a technique whereby Ethernet frames are double tagged that is, the Ethernet frames have two 802.1Q tags. This is done by configuring the interface in dotlqtunnel mode with an access VLAN instead of the normal access VLAN mode or trunk mode. The received frames on the interface that is configured for dot1qtunnel are left intact and another 802.1Q tag is put onto the frame. This 802.1Q tag refers to the VLAN number that is configured on the dot1qtunnel...
VRFAware IP SLA
This means that it can run inside a VRF on PE routers. Therefore, you can use IP SLA to measure the network performance inside the VPN from the PE routers. IP SLA can, for instance, measure the RTT between PE routers inside the customer VRF. From the PE router, the IP SLA probes are forwarded using the VRF routing table. Equally, the IP SLA can run on multi-VRF CE routers. To make IP SLA run over MPLS VPN, you must put the rtr probe into the correct VRF. Look at...
Overview of IPv6 Unicast Routing in Cisco IOS
So that you can better understand how to transport IPv6 over MPLS, this section offers a brief overview of the IPv6 unicast routing protocols. Not that much has changed. The IP routing protocols have just been adapted to work for IPv6. Open Shortest Path First (OSPF) for IPv6 (OSPFv3) has changed more than any of the other protocols, but it is still similar to OSPFv2. The most significant change in configuring the IPv6 routing protocols in Cisco IOS is the change to enabling the routing...
What Is Rd In Mpls
The VPN prefixes are propagated across the MPLS VPN network by Multiprotocol BGP (MP-BGP). The problem is that when BGP carries these IPv4 prefixes across the service provider network, they must be unique. If the customers had overlapping IP addressing, the routing would be wrong. To solve this problem, the concept of RDs was conceived to make IPv4 prefixes unique. The basic idea is that each prefix from each customer receives a unique identifier (the RD) to distinguish the same prefix from...
HVPLS with Dot1q Tunneling QinQ in the Access Layer
As in the case of EoMPLS, dot1q tunneling (QinQ) is possible with VPLS. This means that the customer VLANs can be encapsulated into another VLAN (the provider VLAN, or P-VLAN), allowing a multi-VLAN switched customer network to be transparently transported between multiple sites connected to an MPLS network. This P-VLAN is mapped to one VFI on the N-PE router. If the CE equipment is a router, you can configure the Ethernet interface toward the PE router as a trunk interface by configuring...
Label Distribution Protocol
The fundamental story on MPLS is that packets are labeled, and each label switching router (LSR) must perform label swapping to forward the packet. This means that in all cases, labels need to be distributed. You can achieve this in two ways piggyback the labels on an existing routing protocol, or develop a new protocol to do just that. If you want to adjust the Interior Gateway Protocol (IGP) such as Open Shortest Path First (OSPF), Intermediate System-to-Intermediate System (IS-IS), Enhanced...
Advertising of Label Mappings
Advertising label mappings or label bindings is the main purpose of LDP. Chapter 2 explains the three different modes in which the LSRs can behave advertisement, label retention, and LSP control mode. Each of the three modes has two possibilities, which leads to the following six modes Unsolicited Downstream (UD) versus Downstream-on-Demand (DoD) advertisement mode Liberal Label Retention (LLR) versus Conservative Label Retention (CLR) mode Independent LSP Control versus Ordered LSP Control...
BGP Multiprotocol Extensions and Capabilities
BGP-4 is described in RFC 1771, but that RFC describes only the use of BGP to carry IPv4 prefixes. BGP can do much more than carry IPv4 prefixes. RFC 2858, Multiprotocol Extensions for BGP-4, was written to extend BGP as being able to carry other routing information than IPv4. For instance, BGP-4 can carry IPv6 prefixes and thus provide interdomain routing for IPv6. A BGP speaker lets its peers know that multiprotocol extensions for BGP-4 is supported by using capabilities advertisement. BGP...
OSPF Extensions for TE
RFC 2370 describes an extension to the OSPF protocol whereby three new link-state advertisements (LSAs) are defined and are called opaque LSAs. These three new LSAs give OPSF a generalized mechanism to extend OSPF. They can carry information to be used by OSPF or directly by any application. These LSAs are exactly what MPLS TE needs to put its information into OSPF. OSPF can then flood this information throughout the network. Three types of opaque LSAs exist, differing only in the flooding...
BGP Extended Community RT
The draft ietf-idr-bgp-ext-communities defines the extended community attribute. The community attribute is an optional transitive attribute that is described in RFC 1997. The extended community is also a transitive optional BGP attribute. It came into existence to extend the range of communities and has an enhanced structure over the BGP community attribute. Several BGP extended community attributes are defined, but only one is required for MPLS VPN the RT extended community. It indicates to...
VPLS Architecture
A VPLS service emulates a LAN or the functionality of an Ethernet switch. An Ethernet switch has the following characteristics Forwarding of Ethernet frames Forwarding of unicast frames with an unknown destination MAC address Replication of broadcast and multicast frames to more than one port Dynamic learning of MAC addresses VPLS should also have these characteristics. Ethernet frames receive two MPLS labels before they are forwarded across the MPLS backbone. This forwarding of Ethernet frames...
Cisco Eigrp In Mpls Network
EIGRP can be the PE-CE routing protocol. The usual disadvantage of the redistribution between iBGP and the routing protocol between the PE and CE router is present here, too. This means that redistributing the routes from BGP into EIGRP makes all the routes external EIGRP routes. However, as much EIGRP information as possible is coded in new BGP extended communities to alleviate the problem. This enables the remote PE router to reconstruct the EIGRP route with all its characteristics, including...
The Discovery of LSRs That Are Running LDP
LSRs that are running LDP send LDP Hello messages on all links that are LDP enabled. These are all the interfaces with mpls ip configured on them. First, however, you must enable CEF with the global ip cef command. Then you must enable LDP globally with the mpls ip command. Example 4-1 shows you the basic global and interface commands to enable LDP. Example 4-1 Basic MPLS LDP Configuration interface Loopback0 ip address 10.200.254.2 255.255.255.255 ip address 10.200.210.2 255.255.255.0 mpls ip...
BGP Route Selection
Different BGP speakers can advertise the vpnv4 route when, for instance, a customer site is dual homed to two PE routers. The receiving BGP speaker must then choose one BGP route as the best one. The process for selecting the best vpnv4 route is the same as the one for regular IPv4 BGP routes. The only difference is that now the BGP routes are not 32-bit IPv4 prefixes but 96-bit vpnv4 prefixes. Therefore, if a customer site is dual homed to two PE routers, the ingress PE router receives the...
RIP Version
Routing Information Protocol (RIP) is a simple distance vector routing protocol. It is limited in its use and is not a routing protocol that is suited for large networks because of its slowness in converging. However, it is still used often in small networks as a quick-and-dirty routing protocol that gets the job done with respect to basic routing functionality. RIP version 2 (RIPv2) has seen some improvements over the first RIP specification, but it is still a limited routing protocol....
Mpls To External As Number
EBGP can be the PE-CE routing protocol. Under the address family ipv4 vrf of the router bgp process on the PE, you need to configure the CE router as the eBGP neighbor and activate it. In Example 7-35, the eBGP neighbor 10.20.2.1 (the CE router) in the autonomous system 65001 in VRF cust-one is configured. Example 7-35 Basic BGP Configuration as PE-CE Routing Protocol neighbor 10.200.254.5 remote-as 1 neighbor 10.200.254.5 update-source Loopback0 neighbor 10.200.254.5 send-community extended...
CE Management
Often, the service provider, not the customer, owns and manages the CE router. In that situation, the service provider wants management access to the CE router from a central management server. You can do this by having the PE router advertise one prefix from the managed CE router with one RT that is imported into the management VRF by the PE router connected to the management VRF. You can limit the number of prefixes advertised with this management RT by configuring an export map on each VRF...
Verifying 6VPE Operation
Figure 9-10 depicts the distribution of a vpnv6 prefix and label by MP-iBGP in a 6VPE network. Figure 9-10 Distribution of vpnv6 Prefixes and Labels 2001 0DB8 1 2 1 128 RD Next-hop 10.200.254.4 Label 21 Figure 9-11 shows the same network depicting the packet forwarding of an IPv6 packet through the 6VPE network. Figure 9-11 Packet Forwarding Through the 6VPE Network Example 9-33 shows how to check which IPv6 VRFs are running on the PE router. Example 9-33 Verifying IPv6 VRFs VRF cust-one...
LDP Autoconfiguration
LDP is enabled on an interface by configuring the interface command mpls ip. On an LSR, LDP is usually enabled on all the interfaces on which the IGP is enabled. Much easier than configuring mpls ip on every interface separately is enabling LDP Autoconfiguration for the IGP. Every interface on which the IGP is running then has LDP enabled. The OSPF router command to enable LDP Autoconfiguration is this As you can see, it can be enabled for just a specific OSPF area. You can also disable it from...
LDP for LCATM
This section covers some specifics on LDP when running on an LC-ATM interface. Per-interface label space is used for LC-ATM interfaces. As you can see in Example 5-12, it means that the peer LDP is not identified with router-id 0 as in the non-LC-ATM case. The number following the peer LDP router Identifier is now non-zero. If you have multiple links between a pair of ATM LSRs, multiple label spaces will exist between them. Look at Example 5-12 to see that the ATM LSRs washington-atm and...
Debugging Load Balancing of Labeled Packets
The algorithm for load balancing labeled packets is as follows If the MPLS payload is an IPv4 packet, the load balancing is done by hashing the source and destination IP address of the IPv4 header. If the MPLS payload is an IPv6 packet, the load balancing is done by hashing the source and destination IP address of the IPv6 header. If the MPLS payload is not an IPv4 or IPv6 packet, the load balancing is done by load balancing the MPLS packets based on the value of the bottom label. The hashing...
MPLSAware Netflow
Useful on certain occasions is the MPLS-aware Netflow feature. MPLS-aware Netflow collects statistics for labeled packets and can report them on a label position in the label stack. You can specify up to three label positions in the label stack to keep track of. The command to enable MPLS-aware Netflow globally is this ip flow-cache mpls label-positions label-position-1 label-position-2 label-position-3 mpls-length no-ip-fields You can specify up to the sixth label in the label stack. A...
Debug MPLS Packets
You can debug the forwarding of MPLS packets, just as you can debug the forwarding of IP packets. The command is debug mpls packets. However, if you turn on this debug command without further specifying anything, it returns debug output for all label switched packets. This is something that is probably fine in a lab environment, but not in a production network. Fortunately, you can specify an access list that limits the output to certain labeled packets. WARNING Debugging the forwarding of...
IP Lookup Versus Label Lookup
When a router receives an IP packet, the lookup done is an IP lookup. In Cisco IOS, this means that the packet is looked up in the CEF table. When a router receives a labeled packet, the lookup is done in the LFIB of the router. The router knows that it receives a labeled packet or an IP packet by looking at the protocol field in the Layer 2 header. If a packet is forwarded by either Cisco Express Forwarding (CEF) (IP lookup) or by LFIB (label lookup), the packet can leave the router either...
Mpls Ldp Inbound Label Binding Filtering
You can filter out incoming label bindings from an LDP neighbor. In effect, this is the opposite of the feature that prevents the advertising of label bindings. You can use the inbound label binding filtering on the receiving LDP peer if you cannot apply the outbound filtering of label bindings, as described in the previous section. This feature can limit the number of label bindings stored in the MPLS LDP Inbound Label Binding Filtering 91 LIB of the router. For instance, you can filter out...
BGP Carrying the Label
BGP advertises the vpnv4 prefixes in the MPLS VPN network. This is not enough to be able to forward the VPN traffic correctly. For the egress PE router to be able to forward the VPN traffic correctly to the CE router, it must forward the packet based on a label. The egress PE router can map such a label to the vpnv4 prefix, it is called the VPN label. The egress PE router must advertise the label along with the vpnv4 prefix to the possible ingress PE routers. The encoding of the label with the...
TE Tunnel with P Router as Tail End Router
When a P router is the tail end router of the tunnel instead of the provider edge (PE) router, you need to ensure that two things are present LDP is enabled on all links. An LDP session exists between the head end and tail end router of the TE tunnel LSP. The first requirement should be clear. If a TE tunnel terminates at a P router instead of the PE router, the packets still need to be label-switched up to the PE router. Otherwise, the packets become unlabeled and the IGP label and the VPN...
ToM Tunnel Selection
The AToM Tunnel Selection feature enables you to steer the AToM traffic through the MPLS network over a path that you specify. For this to work, you need to set up an MPLS TE tunnel from the PE to the PE router and then specify that the AToM traffic should take the TE tunnel instead of the default shortest labeled path. In addition, you can specify whether fallback to the default path is desirable when the TE tunnel fails. Figure 10-21 shows an MPLS network with MPLS VPN and AToM customers. The...
Moving MPLS QoS from the PE to the CE Router
These DiffServ Tunneling models are popular for MPLS VPN networks. However, the PE routers have some work to do, including running BGP, labeling packets, running LDP, running routing protocols over the virtual routing forwarding (VRF) interfaces to the customer CE routers, and so on. If the MPLS VPN network also does one of the DiffServ models, the PE must have some MQC configuration. To make matters worse, the DiffServ models are configurable per interface hence, per customer connecting to the...
Problems with Tracerouting in MPLS Networks
Tracerouting in an MPLS network is similar to tracerouting in an IP network. However, the path that the ICMP messages take is not the same in an MPLS network as in an IP network. All ICMP messages are forwarded to the egress router on the LSP. The result of this behavior is that tracerouting becomes less efficient. Take the example of the link between the two P routers in the previous network, when it is no longer forwarding labeled packets. For example, LDP is failing between the two P...
VPNv4 Route Propagation in the Mpls Vpn Network
The VRF separates the customer routes on the PE routers, but how are the prefixes transported across the service provider network Because, potentially, numerous routes perhaps hundred of thousands could be transported, BGP is the ideal candidate because it is a proven and stable routing protocol for carrying that many routes. Just realize that BGP is the standard routing protocol for carrying the complete Internet routing table. Because the customer VPN routes are made unique by adding the RD...
Packet Forwarding in an Mpls Vpn Network
As explained in the previous section, the packets cannot be forwarded as pure IP packets between sites. The P routers cannot forward them because they do not have the VRF information from each site. MPLS can solve this problem by labeling the packets. The P routers must then have only the correct forwarding information for the label to forward the packets. The most common way is to configure Label Distribution Protocol (LDP) between all P and PE routers so that all IP traffic is label-switched...
MultiVRF CE
The Multi-VRF CE feature also known as VRF-Lite is a feature whereby the VPN functionality is extended to the CE router in a cheap way. Assume that you have a company with a large main site and some smaller sites that are interconnected across an MPLS VPN network. The main site of the company is rather large and has several departments that need to be separated from each other for privacy reasons. These departments (finance, human resources, engineering, and so on) then connect to their...
Operation of 6PE
In the 6PE solution, the PE routers are dual-stack, which means they run IPv4 and IPv6. The CE routers that are running IPv6 are connected to the PE router via a normal interface the interface is not part of a VRF for IPv6 even though the same interface might be in a VRF for IPv4. The IPv6 routing distribution between the PE routers is done via MP-iBGP. At the same time, MP-iBGP distributes the label to be used for the specific IPv6 prefixes. This BGP label identifies or tags the IPv6 packet at...
Policy Based Routing
Policy-based routing (PBR) uses a configured policy on the incoming interface to send traffic to a specific next hop. When using PBR, you can route traffic on criteria that differ from the usual routing based solely on the destination IP address. For instance, you can route traffic based on the source IP address or the protocol type. Example 8-23 shows PBR with a TE tunnel as the outgoing interface. The route map pbr is used to switch traffic with source IP address 10.200.254.1 and destination...
Overview of Cisco IOS Switching Methods
The basic function of a router is to move packets through the network. For a router to forward packets, it needs to look up the destination address of the packet in a table and decide which route to use to switch or forward the packet. Each protocol that the router can forward packets for must have a separate forwarding table. Such protocols might include DECnet, Internetwork Packet Exchange IPX , AppleTalk, IP, and MPLS. Packets can be forwarded through the router in three basic ways process...
Troubleshooting CEF
Packets dropped by CEF IP CEF table events IP CEF fragmentation IP CEF hash events IP CEF IPC events Packets seen by IP CEF IP-prefixes related IPC Packets received by IP CEF IP CEF subblock events IP CEF table changes All CEF events CEF assert events CEF background events Example 6-13 debug ip cef and debug cef (Continued) consistency-check CEF consistency checker events hardware CEF hardware api debugging high-availability CEF high availability events Example 6-14 shows the interesting...
Virtual Routing Forwarding
A virtual routing forwarding (VRF) is a VPN routing and forwarding instance. It is the name for the combination of the VPN routing table, the VRF Cisco Express Forwarding (CEF) table, and the associated IP routing protocols on the PE router. A PE router has a VRF instance for each attached VPN. Look at Figure 7-3 to see that a PE router holds the global IP routing table, but also a VRF routing table per VPN connected to the PE. Because the routing should be separate and private for each...
Context Based Access for SNMP over Mpls Vpn
So far, SNMP access to devices has been global, meaning that the SNMP access has been for the whole device. However, with the introduction of MPLS VPN, you see the concept of VPNs and VRFs on the PE routers. The VPN provides a VRF routing table, VRF CEF table, and VRF interfaces on the PE routers. The VRF is not part of the global context of the PE router, but rather the VRF context. The problem is when the SNMP traffic comes into the PE router via the VRF interfaces or when traps leave the PE...
The Basic VPLS Configuration
The configuration for VPLS is simple. First, you must configure a VPLS instance with the global 12 vfi command. The VFI needs to have a unique name on the PE router. Then you need to specify a unique VPN ID number for that VFI. Configure as neighbors all the egress PE routers of the full mesh of that VPLS. Router(config-vfi) neighbor remote-router-id encapsulation mpls After you define the VFI, associate the VLAN interfaces belonging to that VFI with the VFI. You do this with the interface...
Better IP over ATM Integration
In the previous decade, IP won the battle over all other networking Layer 3 protocols, such as AppleTalk, Internetwork Packet Exchange (IPX), and DECnet. IP is relatively simple and omnipresent. A much-hyped Layer 2 protocol at the time was ATM. Although ATM as an end-to-end protocol or desktop-to-desktop protocol as some predicted, never happened, ATM did have plenty of success, but the success was limited to its use as a WAN protocol in the core of service provider networks. Many of these...
Signaling the Pseudowire
A targeted LDP session between the PE routers signals the pseudowires. In essence, the signaling protocol LDP sets up and maintains the pseudowires between the PE routers, as shown in Figure 10-4. LDP has been extended with new Type Length Value fields (TLVs) to perform this job. The main purpose of this LDP session between the PE routers is to advertise the VC label that is associated with the pseudowire. This label is advertised in a Label Mapping message using the downstream unsolicited...
Overview of the Operation of Mpls Te
Following is what MPLS TE needs to make it work. These are the building blocks of MPLS TE Link constraints (how much traffic each link can support and which TE tunnel can use the link) Overview of the Operation of MPLS TE 253 TE information distribution (by the MPLS TE-enabled link-state routing protocol) An algorithm (path calculation PCALC ) to calculate the best path from the head end LSR to the tail end LSR A signaling protocol (Resource Reservation Protocol RSVP ) to signal the TE tunnel...
Mpls Ldpigp Synchronization Configuration
MPLS LDP-IGP Synchronization is enabled for the IGP process. This means that it is configured for an IGP, and it applies to all the interfaces on which the IGP is running. The command to enable it for the IGP is mpls ldp sync, and it is configured under the router process. You can disable MPLS LDP-IGP Synchronization on one particular interface with the command no mpls ldp igp sync. By default, if synchronization is not achieved, the IGP waits indefinitely to bring up the adjacency. You can...
Peerto Peer VPN Model Versus Overlay VPN Model
A VPN is a network that emulates a private network over a common infrastructure. The private network requires all customer sites to be able to interconnect and be completely separate from other VPNs. The VPN usually belongs to one company and has several sites interconnected across the common service provider infrastructure. Service providers can deploy two major VPN models to provide VPN services to their customers In the overlay model, the service provider supplies a service of point-to-point...
TTL Expiration
When a labeled packet is received with a TTL of 1, the receiving LSR drops the packet and sends an ICMP message time exceeded (type 11, code 0) to the originator of the IP packet. This is the same behavior that a router would exhibit with an IP packet that had an expiring TTL. However, the ICMP message is not immediately sent back to the originator of the packet because an interim LSR might not have an IP path toward the source of the packet. The ICMP message is forwarded along the LSP the...
Uniform Model
The Uniform model is quite different from the Pipe or Short Pipe model. In the Uniform model, the following rules apply The LSP DiffServ information must be derived from the Tunneled DiffServ information on the ingress LSR. On an intermediate LSR (a P router), the LSP DiffServ information of the outgoing label is derived from the LSP DiffServ information of the incoming label. On the egress LSR, the LSP DiffServ information must be propagated to the Tunneled DiffServ information. Notice the...
How This Book Is Organized
This book has 15 chapters and one appendix and is organized in two parts. Also available are online supplemental materials that you can find on the website, including an appendix on static MPLS labels. Although each chapter has its own topic and stands alone, it is best to read this book in sequential order. Only if you are an MPLS-experienced reader will you be able to jump to any chapter from Part II without problem. Even if you fit into that category, you might want to browse through the...
OAM Protocols
BFD is a new, lightweight, media independent protocol that detects faults in the data plane between two devices. It has been specifically developed to be routing protocol and media independent and to quickly detect data communication failures. The quickly stands for subsecond detection. SONET has alarms that can detect and notify problems quickly. Most media, however, have no such fast detection mechanisms. BFD quickly detects all failures between routers instead of relying on the hello...
Mpls ip ttlexpiration pop Command
One command can improve the use of the traceroute tool, at least in some cases. The command mpls ip ttl-expiration pop labels can make a difference. The value of labels is between 1 and 6. This command lets you control the behavior when an ICMP TTL expired message is generated. The default behaviour is to forward the ICMP message along the original LSP. With this command, you can specify the behavior when the TTL of a labeled packet expires, according to the number of labels in the label stack....
Multi Virtual Circuit Tagged Bit Rate
With Multi-Virtual Circuit Tagged Bit Rate (Multi-VC TBR), multiple VCs are set up for the same destination to provide different class of service (CoS). Up to four parallel LVCs can go toward the same destination. The switches can then treat the cells differently based on which LVC they are on. The incoming IP packets are mapped with their IP precedence DiffServ bits to the corresponding outgoing LVC. The labeled packets are mapped based on the EXP bits value of the top label onto the...
LSP Verification
LSP verification (LSPV) is the Cisco IOS subsystem that is responsible for anything related to MPLS LSP ping and traceroute. The duties of LSPV include these Encoding and decoding of MPLS echo requests and MPLS echo replies Maintaining a database of outstanding MPLS echo requests Providing the command-line interface (CLI) for MPLS LSP ping and traceroute Interfacing with IP, MPLS, and AToM on the LSR to send and receive the echo requests and replies Handling packets with MPLS TTL expiring and...
Transporting Layer 2 Frames
Two solutions are available for transporting Layer 2 frames across a packet-switched network (PSN) Carry the traffic across an MPLS backbone, which is the AToM solution. Carry the traffic across an IP backbone, which is the Layer 2 Tunneling Protocol version 3 (L2TPv3) solution. NOTE Both solutions are implemented in Cisco IOS, but because this book focuses on MPLS, only the AToM solution is explained here. L2TPv3 is the Layer 2 transport service over an IP network. The Layer 2 frames are...
The Basic AToM Configuration
The basic configuration for AToM is pretty straightforward. You must first select the encapsulation type of the customer-facing (CE-facing) interface on the PE with the following command Router(config-if) encapsulation encapsulation-type Then you enable AToM by specifying the xconnect command on the CE-facing interface, as follows Router(config-if) xconnect peer-router-id vcid encapsulation mpls The peer-router-id is the LDP router ID of the remote PE router. The vcid is the identifier that you...
Virtual Private LAN Service
Virtual Private LAN Service (VPLS) emulates a LAN segment across the MPLS backbone across pseudowires or virtual circuits. VPLS creates one or more LANs for each customer who is using the service from the service provider. Each LAN, of course, is completely separate from the other emulated LAN segments hence the P for Private in VPLS. When the customer with different Ethernet sites connects to an MPLS backbone where VPLS is deployed, it appears as if all the sites are interconnected through a...
OAM Message Mapping
OAM Message Mapping is important in the case of AToM. In AToM networks, pseudowires or VCs transport Layer 2 frames across the MPLS cloud. Toward the native Layer 2 clouds on either side of the MPLS network are ACs with the particular Layer 2 encapsulation. One important aspect when managing this service is the mapping of the OAM messages of the ACs onto newly defined pseudowire OAM messages on the pseudowires and vice versa. Specific alarm indications can be transported between the PE routers,...
MPLS Control Word
The control word (the MPLS header) is used today in AToM networks to carry protocol control information across the MPLS network to support the correct operation of pseudowires. Networks can also use the MPLS control word for the fragmentation of AToM traffic. Another use of the control word is as Pseudowire Associated Channel Header. This stems from the fact that MPLS has no protocol identifier field to indicate the payload type. The Pseudowire Associated Channel Header indicates that the MPLS...
Load Balancing Labeled Packets
If multiple equal-cost paths exist for an IPv4 prefix, the Cisco IOS can load-balance labeled packets, as illustrated in the Cisco IOS output of Example 3-6. You can see that the incoming local labels 17 and 18 have two outgoing interfaces. If labeled packets are load-balanced, they can have the same outgoing labels, but they can also be different. The outgoing labels are the same if the two links are between a pair of routers and both links belong to the platform label space. If multiple...
The Use of MPLS QoS for Ethernet over MPLS
So far in this chapter, the packet for which the QoS was set was an IP packet or a labeled packet. However, in the case of Ethernet over MPLS (EoMPLS), the forwarded packet is actually an Ethernet frame. If the frame is a non-VLAN Ethernet frame, it does not have QoS information embedded. If the frame is an 802.1Q frame, though, the Priority bits (P bits) in the 802.1Q header designate a QoS value. If a service provider carries the 802.1Q Ethernet frames over an MPLS network as in the case of...
Default MPLS QoS Behavior in Cisco IOS
In Cisco IOS, the default behavior when imposing one or more labels on an IP packet is to copy the precedence value to the EXP bits of all imposed labels. This is called TOS reflection, because nothing regarding QoS changes by default. If, however, the six bits of the DSCP field are used, only the first three bits of DSCP are copied to the EXP bits of the labels. This leads to the first MPLS QoS rule. MPLS QoS Rule 1 By default, in Cisco IOS, the precedence bits or the first three bits of the...
TE Tunnel Path Calculation
The way that the TE tunnel is laid out through the network depends on several factors Attribute flags and affinity bits You can configure the path option on the tunnel configuration on the head end router. You can set up a tunnel in two ways explicitly or dynamically. In the explicit way, you must specify every router that the TE tunnel must be routed on, up to and including the tail end router. You can either specify the TE router ID or the link IP address of the intermediate routers. In the...
RSVP and Labels
RSVP signals the path for the TE tunnel, but it is also its task to carry the MPLS label so that the packets can be label-switched along the path of the TE tunnel. Look at Figure 8-9 to see the RSVP messages sent for the TE tunnel signaling. The PATH messages carry a Label Request object. When the tail end router receives this Label Request object, it assigns a label to this TE tunnel LSP and advertises it to the upstream router (the penultimate hop router) in a Label object in the RESV...
Chapter Review Questions Ubc
You can find answers to the following questions in Appendix A, Answers to the Chapter Review Questions. 1. What is a route distinguisher 2. How is a packet that is coming from the CE router identified as to which VRF it belongs 5. What is the BGP neighbor command with as-override used for 6. When would you use different route distinguishers for routes of the same VPN 7. What command should you configure on a Multi-VRF CE router that is running OSPF 8. What three characteristics does an OSPF...
FRRNode Protection
With FRR for Node Protection, you are not trying to protect only one link, but rather a whole router. Node protection works by creating a next-next-hop (NNHOP) backup tunnel. An NNHOP backup tunnel is not a tunnel to the next-hop router of the PLR, but to the router that is one hop behind the protected router. Therefore, in the case of node protection, the NNHOP router is the MP router. When you configure the command tunnel mpls traffic-eng fast-reroute node-protect on the head end of the TE...
The Use of One Unified Network Infrastructure
With MPLS, the idea is to label ingress packets based on their destination address or other preconfigured criteria and switch all the traffic over a common infrastructure. This is the great advantage of MPLS. One of the reasons that IP became the only protocol to dominate the networking world is because many technologies can be transported over it. Not only is data transported over IP, but also telephony. By using MPLS with IP, you can extend the possibilities of what you can transport. Adding...
Class Based Tunnel Selection
Class-based tunnel selection (CBTS) is a TE feature whereby you can forward different class of service (CoS) traffic onto different TE tunnels. These TE tunnels can be global pool tunnels or subpool tunnels, but all the TE tunnels must be between the same head end and tail end routers. Furthermore, when you want to route CoS traffic onto these tunnels for one destination, you must route all the traffic for this destination onto these tunnels. In other words, if you have traffic for a...
ISIS Extensions for TE
RFC 3784 describes the extensions made to IS-IS that enable it to carry the MPLS TE information. Two new IS-IS TLVs have been defined. They allow the MPLS TE information to be carried by IS-IS. However, at the same time, some other changes were made regarding these TLVs, such as extending the link metric from a maximum of 63 to a new maximum of 224-1, the usage of sub-TLVs, and the introduction of the down bit. The first new TLV is the extended IS Reachability TLV, or TLV type 22. It is the...
Requirements for the IGP
The Interior Gateway Protocol (IGP) needs to be capable of sending all the topology information (the state of the links) to all routers in the area in which TE has been enabled. Only a link state protocol can perform this task because it floods the state of all links of a router to all the routers in one area. Therefore, every router in the area knows all alternative paths to get to the destination. A distance vector routing protocol cannot perform this task. It is designed only to forward the...
Huband Spoke
Often, customers do not want their sites to have full interconnectivity. This means they do not want or need the sites to be fully meshed. A typical scenario involves one main site at a company with many remote sites. The remote sites or spokes need connectivity to the main or hub site, but they do not need to communicate between them directly. Perhaps the connectivity is possible but not wanted for security reasons. This scenario is commonly referred to as the hub-and-spoke scenario. It can...
Label Retention Modes
Two label retention modes are possible Liberal Label Retention (LLR) mode Conservative Label Retention (CLR) mode In LLR mode, an LSR keeps all received remote bindings in the LIB. One of these bindings is the remote binding received from the downstream or next hop for that FEC. The label from that remote binding is used in the LFIB, but none of the labels from the other remote bindings are put in the LFIB therefore, not all are used to forward packets. Why keep the labels around that are not...
Router Alert Option and Router Alert Label
IP packets can have a Router Alert option appended to the IP header. This option is an IP option indicating that the router should inspect the packet further when forwarding the packet, even though the packet is not directly addressed to that router. The transit router for the packet should not just forward the packet by doing an IP lookup, but the router should inspect it further before forwarding it. What this inspection means is not defined and is up to the software implementation on the...
Configuration of 6PE
The 6PE solution is simple and straightforward to configure. This section shows you that you only need to enable the iBGP neighbor under the IPv6 address family of BGP and add one extra keyword (iBGP neighbor command with the send-label keyword). Of course, you need to configure an IGP for IPv6 on the link between the PE and CE router. Alternatively, you can configure eBGP between the PE and CE or even static routing for IPv6. Only two 6PE-specific commands exist neighbor ip-address send-label...
Encoding of MPLS
Where does this label stack reside The label stack sits in front of the Layer 3 packet that is, before the header of the transported protocol, but after the Layer 2 header. Often, the MPLS label stack is called the shim header because of its placement. Figure 2-3 shows you the placement of the label stack for labeled packets. Figure 2-3 Encapsulation for Labeled Packet The Layer 2 encapsulation of the link can be almost any encapsulation that Cisco IOS supports PPP, High-Level Data Link Control...
Cost Calculation of IGP Routes over TE Tunnels
Knowing the metric for prefixes with TE tunnels as next hop might not be as straightforward as you think. This section explains how to calculate the cost of the prefixes with TE tunnels as the next hop, each time with autoroute announce enabled on the tunnel interface. When you are using autoroute announce, the cost of the TE tunnel as used by the IGP for the prefixes with the TE tunnel as next hop is always the lowest IGP total cost of the path. This cost is the path weight you see under...
Tunneling Cisco Discovery Protocol
Example 11-7 shows the output of show cdp neighbor on CE1 when VPLS-PE-1 is not configured for tunneling CDP for VPLS instance cust-one. The router CE1 sees the PE router VPLS-PE-1 as a CDP neighbor. Example 11-7 CDP Neighbors on CE1 Without Tunneling CDP Example 11-8 shows the output of the CDP command on router CE1 after enabling tunneling CDP on all physical ports that are associated with VPLS instance cust-one on the PE routers. Now VPLS and Tunneling Layer 2 Protocols 447 router CE1 sees...
Tag Switching to MPLS
Cisco Systems started off with putting labels on top of IP packets in what was then called tag switching. The first implementation was released in Cisco IOS 11.1(17)CT in 1998. A tag was the name for what is now known as a label. This implementation could assign tags to networks from the routing table and put those tags on top of the packet that was destined for that network. Tag switching built a Tag Forwarding Information Base (TFIB), which is, in essence, a table that stores input-to-output...
Internet Access Through a Central VRF Site
Instead of traffic from each VPN site being forwarded directly to the Internet gateway router, it is possible to forward all the Internet traffic from the VRF sites to the CE router(s) of a central VRF site in a VPN. The advantage is that security features such as firewall services or other services such as Network Address Translation (NAT) are implemented only once and centrally in the central VRF site. The Internet traffic between the VRF sites and the VRF central site is then forwarded...
Mpls Lsp Ping
MPLS LSP ping is the name for an MPLS echo request and MPLS echo reply. Ping is a well-known troubleshooting tool for IP networks that is used to figure out if the object is there. If it is, you see an echo. It is like using SONAR on a submarine. Ping uses ICMP, which was designed to augment the IP protocol because it can signal error conditions (destination unreachable, time exceeded, and so on) and send informational advertisements (redirect, address mask, and so on). Ping uses ICMP to carry...
Controlling the Advertisement of Labels via LDP
LDP lets you control the advertisement of labels. You can configure LDP to advertise or not to advertise certain labels to certain LDP peers. You can then use the locally assigned labels that are advertised to the LDP peers as outgoing label on those LSRs. The syntax for this command is as follows mpls ldp advertise-labels vrf vpn-name interface interface for prefix-access-list to peer-access-list The prefix-access-list is a standard numbered access list 1-99 or named access list that lets you...
VPNv4 Routes
The 64-bit field of the RD and the 32-bit IPv4 prefix make up the vpnv4 prefix, which is 96 bits long. MP-iBGP advertises these prefixes between the PE routers. You can see the vpnv4 prefixes that BGP carries with the following command show ip bgp vpnv4 all rd route-distinguisher vrf vrf-name rib-failure ip-prefix length longer-prefixes output-modifiers network-address mask longer-prefixes labels The all keyword for this command shows all vnpv4 routes, or all the routes for all RDs. With the rd...
Non MPLSAware ATM Switches
In the example network, the ATM LSR denver-atm is now non-MPLS-aware. Figure 5-14 shows the VP tunnel across the LSR denver-atm. Figure 5-14 VP Tunnels Across denver-atm Figure 5-14 VP Tunnels Across denver-atm A VP tunnel is created from the LSR washington-atm to the LSR brussels-atm that carries the LVCs across the non-MPLS-aware ATM switch. Look at Example 5-21 to see the configuration needed on the LSRs. An ATM subinterface is created for the VP tunnel. Example 5-21 Configuration for MPLS...
Definition of MPLS
The MPLS labels are advertised between routers so that they can build a label-to-label mapping. These labels are attached to the IP packets, enabling the routers to forward the traffic by looking at the label and not the destination IP address. The packets are forwarded by label switching instead of by IP switching. The label switching technique is not new. Frame Relay and ATM use it to move frames or cells throughout a network. In Frame Relay, the frame can be any length, whereas in ATM, a...
Tunneling Spanning Tree Protocol
By default, VFI does not forward the STP BPDUs on the PE routers. As such, the STP tree in the metro Ethernet site stops at the PE router. The data frames are forwarded across the MPLS network. The frames cannot loop, however, because of the Layer 2 split-horizon rule imposed by the PE routers, which do not forward frames onto the pseudowires if the frames were received from the pseudowires. Because of this split-horizon rule, all PE routers must be in a full mesh for each particular VPLS...
The Table Map Feature
The table-map is a conversion table between the different types of QoS that a packet can have. It allows you to map IP precedence, DSCP, MPLS EXP bits, qos-group, and Layer 2 cos information (the 802.1Q priority bits) via an MQC command. For example, you can map the IP precedence in the incoming IP packet to the EXP bits value of the outgoing labeled packet by using this table instead of specifying an MQC command for each value to be mapped. Table 12-5 shows the categories of QoS information...
MPLS and the OSI Reference Model
The OSI reference model consists of seven layers. Refer to Figure 2-4 for the OSI reference model. Figure 2-4 OSI Reference Model Application Presentation Session Transport Network Data Link Physical The bottom layer is Layer 1, or the physical layer, and the top layer is Layer 7, or the application layer. Whereas the physical layer concerns the cabling, mechanical, and electrical characteristics, Layer 2, the data link layer, is concerned with the formatting of the frames. Examples of the data...
Explicit NULL Label
The use of implicit NULL adds efficiency when forwarding packets. However, it has one downside The packet is forwarded with one label less than it was received by the penultimate LSR or unlabeled if it was received with only one label. Besides the label value, the label also holds the Experimental (EXP) bits. When a label is removed, the EXP bits are also removed. Because the EXP bits are exclusively used for quality of service (QoS), the QoS part of the packet is lost when the top label is...
Piggyback the Labels on an Existing IP Routing Protocol
The first method has the advantage that a new protocol is not needed to run on the LSRs, but every existing IP routing protocol needs to be extended to carry the labels. This is not always an easy thing to do. The big advantage of having the routing protocol carry the labels is that the routing and label distribution are always in sync, which means that you cannot have a label if the prefix is missing or vice versa. It also eliminates the need of another protocol running on the LSR to do the...
Link TE Attributes
Every link in the MPLS network enabled for TE can have characteristics that need to be flooded so that the head end router can figure out whether the TE tunnel can use a particular link. A link that is enabled for TE can have the following characteristics configured for TE Maximum reservable bandwidth Maximum reservable sub-pool bandwidth You configure the maximum reservable bandwidth on the interface by configuring ip rsvp bandwidth interface-kbps. It is configured in kpbs. This is the maximum...
Reducing the Number of LVCs
You can take the following actions to decrease the number of LVCs Reduce the number of IP prefixes Disable head end VCs on an LSC Block Label Request messages for IP prefixes You can reduce the number of IP prefixes by using a loopback IP address for the IGP and LDP. Configure all links as IP unnumbered to the loopback interface IP address. Note that IP prefixes that are not configured on the ATM LSR but are still in the same routing domain cause LVCs to be set up. You can also reduce these IP...
MPLS Traceroute in Cisco IOS
Example 14-6 shows an MPLS traceroute example for the IPv4 prefix 10.200.254.4 32, which is three hops away from the router new-york. ipv4 Target specified as an IPv4 address traffic-eng Target specified as TE tunnel interface lt cr gt Example 14-6 MPLS LSP Traceroute Continued new-york traceroute mpls ipv4 A.B.C.D nn A.B.C.D Target FEC address with mask new-york traceroute mpls ipv4 10.200.254.4 32 Destination address or address range EXP bits in mpls header Flag options force-explicit-null...
Label Switch Router
A label switch router (LSR) is a router that supports MPLS. It is capable of understanding MPLS labels and of receiving and transmitting a labeled packet on a data link. Three kinds of LSRs exist in an MPLS network Ingress LSRs Ingress LSRs receive a packet that is not labeled yet, insert a label (stack) in front of the packet, and send it on a data link. Egress LSRs Egress LSRs receive labeled packets, remove the label(s), and send them on a data link. Ingress and egress LSRs are edge LSRs....
Internet Access Through the Global Routing Table
An easy way to provide Internet access to CE routers is to have an interface from the PE to the CE router that is in the global routing space. The PE router has a VRF interface toward the CE router, but you can have a second interface that is not in a VRF toward the CE router. The routing on the CE router should then take care of sending the VPN traffic to the VRF interface and the Internet traffic to the interface in the global routing space on the PE router. The obvious disadvantage is that...
SRLG Used by Backup Tunnels
You should use SRLG when a backup tunnel can potentially be routed across a link that is on the same fiber or conduit as the protected link. If you configure the protected link and all other links that share the same fiber or conduit with the same SRLG identifier, the backup tunnel avoids those links. NOTE Backup auto tunnels, which routers automatically create, can use the SRLG of protected links to ensure that they are not routed across them. Refer to the section titled Backup Auto Tunnels in...
Router Alert Label
The Router Alert label has a value of 1, and it can be present anywhere in the label stack except at the bottom. When an LSR receives a packet with label 1 as the top label, it knows that it must further examine the packet. Therefore, the LSR removes label 1 and examines the packet. The LSR then looks at the exposed new top label in the label stack and makes a forwarding decision by looking up this label in the LFIB. This forwarding decision makes the LSR perform a swap, pop, or push operation...
OAM Alert Label
In Chapter 3, Forwarding Labeled Packets, you saw a specific MPLS label called the Operation and Maintenance Alert label that has a value of 14. This label is specified by the ITU-T Recommendation Y.1711 and RFC 3429. You insert this OAM Alert label in the label stack just below the label(s) of the LSP under test. Cisco IOS does not use this special MPLS label anywhere. That is because the introduction of a special label in the label stack can influence the treatment of the packet when being...
Label Encoding
ATM switches that are running MPLS are still switching ATM cells. As such, they cannot forward labeled frames. Because the MPLS labels are mapped to VCs in the ATM cloud, the MPLS label value is mapped to the VPI VCI pair. If the labeled packet has a label stack with more than one label, only the value of the top label is mapped to the VPI VCI fields. Figure 5-4 shows the MPLS label mapped to the VPI VCI values. When the edge ATM LSR receives a frame, the frame is chopped up into cells. Only...




































