Multigroup Hsrp With Secondary Ip

Figure 9-4 HSRP

172.16.1.100 HSRP grp 1:172.16.1.201 HSRP grp 1: priority 120

172.16.1.101

HSRP grp 1:172.16.1.201

Wks1

Default route 172.16.1.201

Wks1

Default route 172.16.1.201

Router Monet is configured with an interface IP address 172.16.1.100 and an HSRP group 1 IP address 172.16.1.201. Router Monet advertises an HSRP priority, for HSRP group 1, as 120. This is higher than the default priority of Picasso. Monet, therefore, is the active router for group 1. When Wks 1 wants to send a packet toward its default gateway, it ARPs for the HSRP group 1 address. Monet responds with the HSRP group 1 MAC address. Wksl then sends its packets to the HSRP group 1 MAC address, which Monet accepts.

The routers in an HSRP group exchange multicasAello packets, advertising priorities. The hello messages are exchanged over the link for which the HSRP group is configured. The routers send hello messages, by default, every 3 seconds. If the active router fails to send a hello within a configurable period of time, called the holdtime (the default holdtime is every 10 seconds), the standby router with the highest priority becomes active and begins accepting the packets destined to the group's MAC address.

Multigroup HSRP (MHSRP) enables an interface to be configured with multiple HSRP groups. You use MHSRP when you want to distribute the active router functionality among multiple routers on the same LAN. Some end nodes default route to the IP address of one group; other nodes default route to the IP address of a second group. If either default router fails, the other resumes the packet forwarding. MHSRP is not supported on Ethernet interfaces that are not allowed to be associated with multiple MAC addresses. (Those routers that use Lance Ethernet hardware [1000, 2500, 3000, and 4000] do not support multiple groups on a single Ethernet.) Ethernet and FDDI support up to 255 MHSRP groups. Token Ring supports up to three groups (group numbers 0, 1, 2). MHSRP is supported over Inter-Switch Link (ISL) encapsulation. Figure 9-5 illustrates MHSRP

Figure 9-5 MHSRP Groups Can Be Configured on Router Interfaces to Balance Load

Multigroup HSRP

Figure 9-5 MHSRP Groups Can Be Configured on Router Interfaces to Balance Load

172.16.1.100

172.16.1 101

HSRP grp 1: 172.16.1.201 HSRP grp 2: 172.16.1.202 HSRP grp 2: priority 110

172.16.1.100

172.16.1 101

HSRP grp 1:172.16.1.201 HSRP grp 1: priority 110 HSRP grp 2:172.16.1.1.202

HSRP grp 1: 172.16.1.201 HSRP grp 2: 172.16.1.202 HSRP grp 2: priority 110

Wks1

Default route 172.16.1.201

Wks2

Default route 172.16.1.202

Wks1

Default route 172.16.1.201

Wks2

Default route 172.16.1.202

In Figure 9 5 Monet is the active router for group 1 Picasso is the active router for group 2 Wksl defaults to 172 16 1 201 group 1 Wks2 defaults to 172 16 1 202 group 2 If Monet stops receiving the HSRP hello messages for group 2 Monet becomes the active router for group 2 in addition to group 1

Configuring HSRP

To enable HSRP enter the following interface subcommand standby [group number] ip [ip address [secondary]]

You must specify the IP address on at least one router in the HSRP group If you do not specify the IP address on a router the address is learned via HSRP hello messages

The following commands affect how the router participates in HSRP

standby [group number] timers hellotime holdtime standby [group number] priority priority [preempt [delay delay]]

standby [group number] [priority priority] preempt [delay delay]

standby [group number] track type number [interface priority]

standby [group number] authentication string standby use bia [scope interface]

The timers command modifies the time between hello packets and the maximum elapsed time before a standby router considers the active router dead The default hello time is 3 seconds The default holdtime is 10 seconds

The priority and preempt command modifies the HSRP router s priority preempt enables the router with the highest priority to take over the active role even if the current active router is not having problems The delay option causes the router to postpone preempting the active role for the specified number of seconds before becoming active The range is from 0 to 3600 seconds The default is 0

A router s LAN interface may be active and the router itself is operating fine but the interfaces used to forward packets out of the router may have failed In this case packets forwarded to the router have to be redirected back to the other router as illustrated in Figure 9 6

The workstation sends a packet toward its default gateway which is the active router Monet Monet s outbound interfaces have both failed Monet consults its routing table and forwards the packets back onto the Ethernet and to Picasso for further forwarding

Figure 9 6 HSRP Without Interface Tracking

Monet

172 16 1 100 172 16 1 201

HSRP grp 1 HSRP grp 1: priority 120

Monet

172 16 1 100 172 16 1 201

HSRP grp 1 HSRP grp 1: priority 120

Hsrp Secondary

Picasso

172 16 1 101

HSRP grp 1 172 16 1 201

Picasso

172 16 1 101

HSRP grp 1 172 16 1 201

Wks1

Default route 172 16 1 201

Wks1

Default route 172 16 1 201

The track command enables HSRP to track the state of outbound interfaces causing the router to lower its priority and possibly transition out of its active state if the interface fails When the tracked interface fails the router changes the priority it is advertising If the new priority is lower than a standby router s priority and the standby router is configured to preempt an active router with a lower priority the standby router becomes active for the group The router s priority for the group is decremented by the amount specified in the interface priority field The default value is 10 Multiple interfaces can be tracked If more than one interface is tracked and each is configured with an interface priority value when more than one interface fails the decremented priority amount is cumulative If no interface priority value is set on tracked interfaces and more than one goes down the priority value is decremented by the default 10 but is not cumulative

The authentication command enables the routers to include an authentication string in the HSRP messages You must configure all routers in a group with the same authentication string or no string at all The first router enabled with HSRP becomes active If the authentication strings on subsequently activated routers do not match the newly activated routers remain in a learning state No router becomes the standby router

Example 9 48 shows the HSRP configurations from routers Monet and Picasso illustrated in Figure 9 7 (single group HSRP)

Example 9-48 HSRP Configurations for Routers Monet and Picasso in Figure 9-7

Router Monet interface Ethernet 1 lp address 172.16.1 100 255.255.255.0 standby 1 priority 120 preempt delay 10 standby 1 authentication secret standby 1 lp 172.16.1.201

Router Picasso interface Ethernet 0 lp address 172.16.1 101 255.255.255.0 standby 1 authentication secret standby 1 lp

Figure 9-7 Network Illustrating Single-Group HSRP

Monet

172.16.1.100 HSRP grp 1:172.16.1.201 HSRP grp 1: priority 120

Monet

Picasso

172.16.1.101

HSRP grp 1:172.16.1.201

Wks1

Default route 172.16.1.201

Wks1

Default route 172.16.1.201

Picasso learns the IP address and timers from the HSRP function.

The output from the show standby command on Picasso m Example 9-49 shows the learned information.

Notice that Picasso s state is Standby, with priority 100. The active router address is 172.16.1.100, Monet. The HSRP address is 172.16.1.201. The HSRP MAC address that is associated with this address is 0000.0c07.ac01.

Example 9 49 show standby Command Output Shows the IP Address and Timer Information Picasso Learns from the HSRP Function

Picasso#show standby Ethernet© Group 1 local state is Standby, priority 100 Hellotime 3 holdtime 10 Next hello sent in 00:00:00 340 Hot standby IP address is 172 16 1 201 % Active router is 172.16.1.100 expires in 00:00:1« Standby router is local

Standby virtual mac address is 0000.0c07.ac01 4 state changes last state change 00:02:57

Pings to the HSRP address from a workstation in Example 9 50 illustrate the failure of the active router and lecovery by the standby router

Example 9 50 Pings to the HSRP Address Indicate Active Router Failure and Standby Router Recovery

ObiWan: # ping 172 16 1 201

PING 172 16 1 201 (172 16 1 201): 56 data bytes

64 bytes from 172 16 1 201: icmp_seq 0 ttl 255 time 5 7 ms

64 bytes from 172 16 1 201: icmp_seq 1 ttl 255 time 3 5 ms

64 bytes from 172 16 1 201: icmp_seq 2 ttl 255 time 3 5 ms

64 bytes from 172 16 1 201: icmp_seq 3 ttl 255 time 3 5 ms

64 bytes from 172 16 1 201: icmp_seq 4 ttl 255 time 3 5 ms

64 bytes from 172 16 1 201: icmp_seq 5 ttl 255 time 3 4 ms

64 bytes from 172 16 1 201: icmp_seq 6 ttl 255 time 3 5 ms

64 bytes from 172.16.1.201: icmpj*eq«17 ttl*255 tims*3.5 ms

64 bytes from 172 16 1 201: icmp_seq 18 ttl 255 time 3 5ms

64 bytes from 172 16 1 201: icmp_seq 19 ttl 255 time 3 5 ms

64 bytes from 172 16 1 201: icmp_seq 20 ttl 255 time 3 4 ms

64 bytes from 172 16 1 201: icmp_seq 21 ttl 255 time 3 4 ms

The workstation is sending pings every second Packets 1-6 succeeded Packets 7-16 failed As you can see it took 10-11 seconds for the standby router to begin accepting packets for the HSRP MAC address The standby router stopped receiving hello messages from the active router when its LAN interface failed It waits for its hold period of 10 seconds and then begins accepting packets

The additions to the configuration illustrated in Example 9 51 enable HSRP interface tracking on Monet Figure 9 8 illustrates the benefits of HSRP interface tracking Monet s Serial 1 and Ethernet 0 lead to remote resources which are also accessible via Picasso The design goal is to allow workstations on the LAN to default route to Monet as long as one or more outbound interfaces (Serial 1 and Ethernet 0) are up If both fail the workstations default to Picasso instead

Example 9 51 Enabling HSRP Interface Tracking on Router Monet

Monet interface Ethernetl standby 1 track EthernetO 15 standby 1 track Seriall 15

Picasso interface EthernetO standby 1 priority 100 preempt delay 10

Figure 9 8 Network Illustrating HSRP Interface Tracking

Monet

172 16 1 100 HSRP grp 1:172 16 1 201 HSRP grp 1: priority 120

Monet

Picasso

Picasso

172 16 1 101

HSRP grp 1:172 16 1 201

Wks1

Default route 172 16 1 201

Wks1

Default route 172 16 1 201

Note that Monet is tracking both Serial 1 and Ethernet 0 If only one tracked interface goes down Monet s priority is 105 still higher than Picasso s so Monet continues to be active If both interfaces fail Monet begins advertising its priority as 90 rather than 120 After waiting the preempt delay time Picasso sends an HSRP coup message indicating to Monet that it is taking over as the active router Monet resigns as active router and listens for other HSRP messages to determine whether it is to become the standby router You must add the preempt statement to Picasso s HSRP configuration to enable the takeover When one of Monet s interfaces becomes active again its priority rises to 105 Monet has preempt and delay configured so Monet waits 10 seconds before taking over as the active router for group 1

Configuring MHSRP

Figure 9 9 illustrates Multigroup HSRP

Figure 9 9 Network Illustrating MHSRP

172 16 1 100 HSRP grp 1:172 16 1 201 HSRP grp 1 priority 110 HSRP grp 2:172 16 1 1 202

Wks1

Default route 172 16 1 201

Wks1

Default route 172 16 1 201

172 16 1 101

HSRP grp 1:172 16 1 201 HSRP grp 2:172 16 1 202 HSRP grp 2: priority 110

Wks2

Default route 172 16 1 202

Wks2

Default route 172 16 1 202

The configurations in Example 9 52 are for MHSRP on routers Monet and Picasso Example 9 52 Configuring MHSRP on Routers Monet and Picasso

Router Monet interface Ethernet 1 ip address 172 16 1 100 255 255 255 0 standby 1 priority 120 preempt delay 10 standby 1 authentication secret standby 1 ip 172 16 1 201 standby 2 authentication secret standby 2 ip

Router Picasso interface Ethernet 0 ip address 172 16 1 101 255 255 255 0 standby 1 authenticationsecret standby 1 ip "

standby 2 priority 120 preempt delay 10 standby 2 authentication secret standby 2 ip 172 16 1 202

Monet is the active router for group 1 with HSRP IP address 172 16 1 201; Picasso is the active router for group 2 with HSRP IP address 172 16 1 202 To achieve load balancing configure half the workstations on the LAN with default gateway 172 16 1 201 and the other half with default gateway 172 16 1 202

A network lab provides a platform on which to test new configurations IOS versions and features

Because a lab s purpose is to test anything new before implementing it in the live network the lab s construction reflects the live network An effective lab does not have to be a full scale reproduction of the live network but it is composed of the same type of routers interfaces and Cisco IOS Software It runs the same routing protocols and routing features Anything that is implemented in the live network can be reproduced in the lab

The lab is isolated from the production network but those who need to use it can easily access it One way to keep the functionality of the lab isolated from the production network while still enabling access to the lab from the network is to use a terminal server The terminal server s LAN interface connects to the production network Its asynchronous ports connect to the console ports of the lab routers Most terminal servers allow reverse Telnet connections to devices connected to their asynchronous ports Each async port is associated with a protocol port number If you Telnet to the IP address of the TS and specify the appropriate protocol port for the desired async port you connect to the async device connected to that port Figure 9 10 illustrates the interconnection of the production and lab networks using a terminal server

Figure 9 10 Terminal Server Provides Access to an Isolated Lab from the Production Network

The information in Figure 9 10 shows that by Telneting to 172 16 1 254 port 2001 from the production network the terminal server connects you to the device connected to async port 1 router R1

A configuration entry on the terminal server associates host R1 to IP address and port number 172 16 1 254 2001 A Telnet session initiated from the terminal server to R1 connects to router R1 via async port 1

A lab is used to test all network designs and changes taking place in the network including configuration changes router additions IOS upgrades and new feature additions Lab testing is an integral part of a good change policy A successful test ensures that the network

Production network

TS Ethernet: 172 16 1 254 Async 1: port 2001 £ host R1=172 16 1 254 2001

Production network change will be successful and will not present any negative surprises The test assures business units that due diligence is being performed by the network engineers and every effort is being made to keep the network running optimally

It is particularly important to thoroughly test new designs feature additions and Cisco IOS Software upgrades These are considered major upgrades to any network

Tests may not work out as expected and the results may not be valid if you do not have a good test plan A test plan describes the item to be tested and defines how it will be tested Writing a clear test plan before beginning the test saves you time You clarify exactly what needs to be tested as well as define the steps necessary to perform the test Very precisely define the steps In fact the plan should be so well defined that anyone can follow it and that any two people following the plan perform the exact same steps and get the same

Labs also provide an area of the network where you can just play around with the commands testing the effect of misconfigurations and practicing troubleshooting The lab can be used in this way for training and CCIE preparation Only with a lab can you thoroughly experiment with configurations break things to see what happens and determine what symptoms identify misconfigurations The depth of knowledge you need in the CCIE lab test requires that you have this kind of experience with Cisco IOS Software

Marshal T Rose The Simple Book An Introduction to Networking Management Revised Second Edition (New York NY Simon & Schuster Trade 1995) This book thoroughly explains SNMP

Randal L Schwartz Tom Christiansen Steve Talbot (Editor) Learning Perl Second Edition (O Reilly & Associates Inc July 1997)

Larry Wall Jon Orwant Tom Christiansen Programming PERL (O Reilly & Associates Inc July 2000)

*J Case et al RFC 1157: A Simple Network Management Protocol (SNMP) (Work in Progress)

2 J Case et al RFC 1901: Introduction to Community based SNMPv2 (Work in Progress)

3K McCloghrie and M Rose RFC 1213: Management Information Base for Network Man agement of TCP/IP based internets: MIB II (Work in Progress) 4S Waldbusser RFC 2819: Remote Network Monitoring Management Information Base (Work in Progress)

results

Continue reading here: Answers to Chapter 1 Review Questions

Was this article helpful?

0 0