Showing posts with label Networking. Show all posts
Showing posts with label Networking. Show all posts

Tuesday, July 13, 2010

Blogs for Network Geeks

AGGREGATORS / LISTS



GENERAL NETWORKING



CERTIFICATION / STUDY


Vendor Blogs, Feeds, and Tweets for Network Geeks

This is a list of vendors who service the networking industry in areas of wireless, routing, switching, VoIP, security, or management.

Sunday, May 23, 2010

Layer by Layer Troubleshooting with a Cisco Router

Every network admin is going to have trouble with network links on a Cisco router, at one point or another. The best way to troubleshoot any networking issues is to use the OSI model and go layer by layer. In my article How to use the OSI Model to Troubleshoot Networks, we talked about the different troubleshooting approaches and how to use them to troubleshoot your network, in general. In this article, you will find out how to use the OSI model to troubleshoot, bottom up, using a Cisco router.


OSI Model - Bottom Up Troubleshooting


If you will recall, the OSI model starts with the physical layer (layer 1) and goes up to layer 7 (application). When troubleshooting with a Cisco router, much of your time will be spent working in layers 1-3. They are:



  • Layer 3 - Network

  • Layer 2 - Data Link

  • Layer 1 - Physical


Because these layers build on each other, Layer 1 is most critical, without layer 1, layer 2 will not function. Without layer 1 & 2, layer 3 will not function, and so on. For this reason, I start troubleshooting at layer 1, physical, and move on up from there.


Router Troubleshooting at OSI Layer 1 & 2 - Physical & Data link


Remember, if Layer 1 isn't up, nothing else will work so make sure you start here. Examples of layer 1 are your T1 circuit or your Ethernet cable - physical connectivity. I usually troubleshoot layer 1 and layer 2 in union because they are so closely paired. Examples of layer 2 - data link - are your line protocol (such as Ethernet, ATM, 802.11, PPP, frame-relay, HDLC, or PPP).


To troubleshoot at these layers, the first thing I would do on your router is a show interface. Here is an example of a LAN Gigabit Ethernet circuit:


Router# show interface
GigabitEthernet0/0 is up, line protocol is up
Hardware is BCM1125 Internal MAC, address is 0015.2b46.5000 (bia 0015.2b46.5000)
Description: LAN Connection to Data center
Internet address is 10.20.100.1/16
MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 1000Mb/s, link type is autonegotiation, media type is RJ45
output flow-control is XON, input flow-control is XON
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: weighted fair
Output queue: 0/1000/64/0 (size/max total/threshold/drops)
Conversations 0/2/256 (active/max active/max total)
Reserved Conversations 0/0 (allocated/max allocated)
Available Bandwidth 750000 kilobits/sec
5 minute input rate 3218000 bits/sec, 1715 packets/sec
5 minute output rate 1390000 bits/sec, 2129 packets/sec
1416888620 packets input, 15402720 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 1556005 multicast, 0 pause input
0 input packets with dribble condition detected
1666663097 packets output, 573841802 bytes, 0 underruns
19 output errors, 0 collisions, 3 interface resets
0 babbles, 0 late collision, 0 deferred
19 lost carrier, 0 no carrier, 0 pause output
0 output buffer failures, 0 output buffers swapped out

Here is what a WAN T1or T3 circuit might look like:


Routerl# show interface serial 3/0
Serial3/0 is up, line protocol is up
Hardware is DSXPNM Serial
Description: Sprint T3
Internet address is 10.2.100.2/30
MTU 4470 bytes, BW 9000 Kbit, DLY 200 usec,
reliability 255/255, txload 77/255, rxload 26/255
Encapsulation HDLC, crc 16, loopback not set
Keepalive set (10 sec)
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 18394
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 927000 bits/sec, 1914 packets/sec
5 minute output rate 2752000 bits/sec, 1504 packets/sec
1560997932 packets input, 3254680247 bytes, 0 no buffer
Received 255480 broadcasts, 1 runts, 1 giants, 0 throttles
1567 input errors, 1567 CRC, 976 frame, 496 overrun, 0 ignored, 908 abort
1303636803 packets output, 3737276508 bytes, 0 underruns
0 output errors, 0 collisions, 3 interface resets
0 output buffer failures, 0 output buffers swapped out
1 carrier transitions
DSU mode 1, bandwidth 9000, real bandwidth 9000, scramble 0

Here is the quick version:


Router# show ip interface brief
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 10.20.100.1 YES NVRAM up up
Serial3/0 10.2.100.2 YES NVRAM up up

Here is what you look for:



  • Is the interface UP?

  • Is the line protocol UP?

  • If both the interface and line protocol are NOT up, your connection is never going to work.

  • To resolve a line down, I look at the cable or the keepalives

  • To resolve a line protocol down, check to make sure that the protocols match on each side of the connection(notice the "line protocol" on each of the interfaces above).

  • Are you taking input, CRC, framing, or other errors on the line (notice how the serial interface above does show errors)? If so, check your cable or contact your provider.


In general, verify that you have a good cable on each side, verify that line protocols match, and that clocking settings are correct.


If this is an Ethernet connection, is there a link light on the switch?


If this is a serial connection, do you have an external CSU/DSU? If it is an external CSU, check that the Carrier Detect (CD) light & data terminal ready (DTR) lights are on. If not, contact your provider. This also applies if you have an internal Cisco WIC CSU card. If that is the case, take a look at this Cisco link on understanding the lights on that card.


You can, of course, use the Cisco IOS test commands to test your network interfaces with internal staff and with your telecommunications providers.


Do not proceed to upper level layers until your Physical interface on the router shows as being UP and your line protocol is UP. Until then, don't worry about IP addressing, pinging, access-lists or anything like that.


Router Troubleshooting at OSI Layer 3 - Network


Once you have Layers 1 & 2 working (your show interface command shows the line is "UP & UP", it is time to move on to layer 3 - the OSI Network layer. The easiest thing to do here to see if layer 3 is working is to ping the remote side of the LAN or WAN link from this router. Make sure you ping as close as possible to the router you are trying to communication with - from one side across to the other side.


Here are examples of successful & failed pings:


Router# ping 10.2.100.2

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.2.100.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms
Router#
Router#
Router#
Router#
Router# ping 1.1.1.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
Router#

The easiest way to check the status of Layer 3 - the network layer - is to do a show ip interface brief, as I did above. Here is an example:


Router# show ip interface brief
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 10.20.100.1 YES NVRAM up up
Serial3/0 10.2.100.2 YES NVRAM up up

Notice the IP addressing on each of these interface. Also do a show running-config, like this (you can even specify an interface, like this):


Router# show running-config int serial3/0
Building configuration...

Current configuration : 225 bytes
!
interface Serial3/0
description Sprint T3
bandwidth 9000
ip address 10.2.100.2 255.255.255.252
no ip proxy-arp
no ip mroute-cache
dsu mode 1
dsu bandwidth 9000
no cdp enable
end

Router#

I would recommend taking this interface configuration and comparing it, side by side, with the remote WAN connection to ensure they are the same. Ask yourself questions like:



  • Are these interfaces on the same IP network?

  • Do these interfaces have the same subnet mask?

  • Are there any access-lists (ACL) that are blocking your traffic?

  • Can you remove all optional IP features to make sure that the basic configuration works before adding additional features that could be causing trouble?


Here is an example. Look at the two interfaces below. What is the real problem, causing these two to not communicate?


Router 1


interface Serial3/0 description Sprint T3 - TO ROUTER 2 bandwidth 9000 ip address 10.2.100.2 255.255.255.252


Router 2


interface Serial3/0 description Sprint T3 - TO ROUTER 1 bandwidth 1500 ip address 10.2.100.5 255.255.255.252


No, there is no problem with the bandwidth statement. Bandwidth statements are only used as comments and by routing protocols to select the best route. The real problem here is that the second router's serial interface is not on the same IP subnet as router #1. Even though they have the same subnet, the 10.2.100.5 IP address will never be able to communicate to the 10.2.100.2 IP address because they are on different networks but directly connected.


Let's say that you are now able to ping across the link, from one side to another. While that is a great sign, it doesn't always mean that everything is "fixed". You still may not be able to communicate from a client on the LAN of one router, to a client on the LAN of another router, due to things like improperly configured IP routing protocols.


For one LAN to communicate to another LAN, through routers (through a WAN, usually), you MUST have either static routes or dynamic routes configured. To ensure you have a route configured for the network you are trying to reach, do:


Router# show ip routes


and look at


Router# show ip protocols


For troubleshooting layers 3, all the way up, look at the output of this command:


Router# show ip interfaces

GigabitEthernet0/0 is up, line protocol is up
Internet address is 10.20.100.1/16
Broadcast address is 255.255.255.255
Address determined by non-volatile memory
MTU is 1500 bytes
Helper address is not set
Directed broadcast forwarding is disabled
Multicast reserved groups joined: 224.0.0.10
Outgoing access list is not set
Inbound access list is not set
Proxy ARP is disabled
Local Proxy ARP is disabled
Security level is default
Split horizon is enabled
ICMP redirects are always sent
ICMP unreachables are always sent
ICMP mask replies are never sent
IP fast switching is enabled
IP fast switching on the same interface is disabled
IP Flow switching is enabled
IP CEF switching is enabled
IP CEF Flow Fast switching turbo vector
IP multicast fast switching is disabled
IP multicast distributed fast switching is disabled
IP route-cache flags are Fast, Flow cache, CEF, Subint Flow
Router Discovery is disabled
IP output packet accounting is disabled
IP access violation accounting is disabled
TCP/IP header compression is disabled
RTP/IP header compression is disabled
Policy routing is disabled
Network address translation is enabled, interface in domain inside
WCCP Redirect outbound is disabled
WCCP Redirect inbound is disabled
WCCP Redirect exclude is disabled
BGP Policy Mapping is disabled

Router Troubleshooting at OSI Layers 4 - 7


Now, let's say that you have made it to the point where you can ping from LAN to LAN, through your WAN. Congratulations - that is a very good sign. If you are still having trouble, it must be in OSI Layers4-7. Here are those layers listed out and possible issues you might experience in each layer:



  • Layer 4 - Transport - in the transport layer are TCP and UDP - you could be have an ACL or QoS feature blocking or slowing this traffic. Your TCP traffic could also be fragmented to the point that it could not be reassembled. Another option is that you may not be receiving an ACK back from your traffic that was successfully sent.

  • Layer 5 - Session - in the session layer are protocols like SQL, NFS, SMB, or RPC - you could be taking errors on any one of these session protocols. I would recommend using a protocol analyzer like Wireshark to analyze your session data.

  • Layer 6 - Presentation - in the Presentation layer are data encryption, compression, and formatting - your VPN tunnel could be failing or perhaps you are sending one type of data (like a MPEG) and the receiver is trying to view it as a WMV file.

  • Layer 7 - Application - in the Application layer are, of course, your applications like FTP, HTTP, SCP, TFTP, TELNET, SSH, and more - you could be trying to connect to a telnet server with the SSH protocol, for example.

  • Layer 8 - End User - the standing joke is that "Layer 8" is the user - the user could be just mistyping their username or password or you, the network admin, could have been troubleshooting the wrong IP address all along.


Summary


In summary, using the OSI model to troubleshoot connectivity issues is the fastest and most efficient way to troubleshoot any network issue. Even if someone calls you to work on a Windows share problem, all of the same principles in this article apply to that troublesooting process. So remember, the next time you work on a network issue - remember the OSI model and how to use the bottom-up approach to troubleshooting! It could same you a while lot of time!

Monday, May 17, 2010

HOWTO: Setting up QEMU on Ubuntu with TUN/TAP and NAT

Step 1) Compile and setup of Qemu and KQemu
Step 2) Installation of GuestOS [ Windows 98se in this example ]
Step 3) Setup of Tun/Tap network interface on host and guest OS.
Step 4) NAT setup to allow guestOS access to the internet.

*note: KQEMU is the QEMU Accelorator

Brief Description:
QEMU is an Open-Source Emulator that emulates x86 arch as well as several others.... allowing for guestOS's to be installed inside the host OS.
QEMU is available for Linux, Mac, and Windows. We'll be covering the Linux Package in this HowTo.
For more information on QEMU visit the projectpage @ http://fabrice.bellard.free.fr/qemu/

What you'll need:
+ QEMU source tarball from http://fabrice.bellard.free.fr/qemu/
+ KQEMU binary tarball from http://fabrice.bellard.free.fr/qemu/
+ linux-headers package
+ IPTables ( should already be installed ) package
+ libsdl1.2-dev package
+ Tun/Tap package
+ uml-utilities package
+ windows98 install cd and valid windows98 serial.
+ GCC-3.4 package

Ok, so this is the first HowTo i've wrote in quite a long time. First for ubuntu, and Qemu..


################################################## ##############
[ Step 1 ] - Compilation and Installation of KQEMU and QEMU

Outlined here is the steps taken to compile and setup Qemu and Kernel Module KQemu

A) Download the latest source tarball of QEMU from http://fabrice.bellard.free.fr/qemu/download.html current version is 0.8.1
B) Download the latest binary of KQEMU from http://fabrice.bellard.free.fr/qemu/qemu-accel.html

C) Move the tarballs to your /usr/local/src directory and deflate
#> sudo mv qemu-version.tar.gz /usr/local/src/
#> sudo mv kqemu-version.tar.gz /usr/local/src/

deflate...
#> sudo gunzip qemu-version.tar.gz; sudo tar -xvf qemu-version.tar
#> sudo gunzip kqemu-version.tar.gz; sudo tar -xvf kqemu-version.tar

D) Install linux-headers for your current kernel version.
If you don't know your current kernel version you can do `uname -r` at the shell to find out...

#> sudo apt-get install linux-headers-`uname -r`

E) Install GCC-3.4 [ qemu complains on GCC-4 ] and libsdl1.2-dev

#> sudo apt-get install gcc-3.4 libsdl1.2-dev

locate the installed gcc-3.4 binary using whereis
#> whereis gcc-3.4

it should be located in /usr/bin/ if not found at all installation failed. repeat step E.
make a note of it's location. you're going to need it in step F

F) Configure and Compile QEMU and KQEMU

change directories to your qemu-source you deflated in step C
#> cd /usr/local/src/qemu-version
#> sudo ./configure --cc=/usr/bin/gcc-3.4 [ remember the location of it from step E? ]

once configuration is completed run make and make install to compile and install... do so as follows

#> sudo make
#> sudo make install

verify that QEMU installed correctly...
#> whereis qemu

change directories to your kqemu-source you deflated in step C, and configure make and make install

#> cd /usr/local/src/kqemu-version
#> sudo ./configure
#> sudo make
#> sudo make install

verify that device node /dev/kqemu exists
if not...execute following commands

#> sudo mknod /dev/kqemu c 250 0
#> sudo chmod 666 /dev/kqemu

Active module KQEMU
#> sudo modprobe kqemu
Verify that it loaded properly
#> lsmod | grep kqemu
If it failed to show up. issue a dmesg | tail to see what the error was
#> dmesg | tail
Anyway... continuing...

[ Step 1 Completed ]
################################################## ################


[ Step 2 ] Installing Guest OS
*notes: you can use either the actual install CD or an ISO made from the original install disk, I used an iso.
you can also use the dd command with the seek option to create your hard disk image file, in place of qemu-img create
for convenience we're going to use the qemu-img binary installed with QEMU

*help: Run qemu/qemu-img without any arguements to view it's help

A) Create the Hard Drive Image File to use as HDA
choose the directory you wish to store your disk images you can use mkdir to create a new one. I use ~/qemu
#> cd ~/qemu
A brief rundown of what we're executing here....
qemu-img create [filename] [-f format( raw, vvfat, cloop,... )] [size G(gigs), M(megs) ]
#> qemu-img create win98.img -f raw 2G
Ok, we've created the 2G image file to install windows98se into....now we load QEMU to boot from the cdrom/iso file specified to start installation

#> qemu -hda win98.img -cdrom /dev/cdrom -boot d -localtime -net nic -net tap
Now QEMU should boot from CD, just follow the steps to complete the installation...

Once installation has completed now we can move onto Step 3
[ Step 2 Complete ]
################################################## ################

[ Step 3 ] Setting up TUN/TAP network interface on HostOS and GuestOS

A) Install uml-utilities via apt
#> sudo apt-get install uml-utilities
B) Load kernel module tun
#> sudo modprobe tun66.202.65.50
C) Create the /dev/net/tun device node
#> mkdir /dev/net
#> mknod /dev/net/tun c 10 200
D) Setup the tap0 interface, with an ip address i use 192.168.100.1 for this.
Create the tap0 interface using tunctl
#> sudo tunctl

Give it an IP-Address
#> sudo ifconfig tap0 192.168.100.1 up
Make sure it was configured properly...
#> ifconfig

You should see tap0 with an inet addr: 192.168.100.1 and a Mask: 255.255.255.0
If there is no mask set...sometimes this happens don't know why but it's happend....do this
#> sudo ifconfig tap0 192.168.100.1 netmask 255.255.255.0 up


Ok, we're done with the HOST side of this

E) Setting up the GuestOS's network configuration

If you don't have QEMU booted into windows already then do so by this command...
#> qemu -hda win98.img -boot c -net nic -net tap &

Once windows has loaded goto your Control panel and open Network Settings
At the configuration tab Select TCP/IP and click properties

In the Properties window
- Select the IP Address Tab
select specify an IP address
enter 192.168.100.2 as your ip address
enter 255.255.255.0 as your subnet mask
- Select the Gateway Tab
add a new gateway as 192.168.100.1
- Select Ok
Select Ok
Now you will be promted for a restart....restart and you should be able to ping the guestOS from the hostOS

F) Testing the network connection
from a terminal
#> ping 192.168.100.2 -c 4
You should reach 192.168.100.2 if not, verify you followed every step.

Make sure you can Ping the Host from the guest

on Windows from a dosprmpt
#> ping 192.168.100.1 -n 4
You should reach 192.168.100.1 if not, verify you followed every step correctly.

[ Step 3 Complete ]
################################################## ###############

[ Step 4 Setting up NAT to allow GuestOS access to the internet ]
*note: i'm going to go ahead and assume you have iptables already installed.

A) Load Required Kernel Modules
#> sudo modprobe ip_tables
#> sudo modprobe iptable_nat
#> sudo modprobe ip_nat_ftp
#> sudo modprobe ip_nat_irc

B) Enable IP-Forwarding
as root run
#> echo "1" > /proc/sys/net/ipv4/ip_forward

If you get your IP Address Dynamically e.g. PPP0 (Dial-up)
as root run
#> echo "1" > /proc/sys/net/ipv4/ip_dynaddr

Enable SNAT (MASQUERADE) functionality on eth0/ppp0
*note: replace eth0 with ppp0 for dialup

#> sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE

C) Setup DNS on guestOS
*note: this is for windows98se, methods aren't listed for other OS's

You can retrieve your DNS Server Ip's from your /etc/resolv.conf file after connected to the internet.

#> sudo cat /etc/resolv.conf

In windows, goto control panel -> networking -> TCP/IP Properties -> DNS Configuration
Select Enable DNS

Set Host to your gateway address, i set mine to 192.168.100.1 for my gateway
Set Domain to your Domain i just set it to one of the DNS servers IP Address's
Add your ISP DNS Servers to the DNS List..

Ok, reboot! everything should work fine now..
[ Step 4 Complete ]

After following these steps you should have a working Qemu using the KQEMU accelerator as well as Tun/Tap Virtual Network forwarding Requests from the guest to the internet.
If something isn't working, double check to make sure you set it up correctly.

Saturday, April 10, 2010

Interview with 6x CCIE Roman Rodichev!!!!

It is my pleasure and honor to introduce Roman Rodichev 6x CCIE #7927 ( yes six ). Roman is the first person in the world to hold all 6 active CCIE certifications!!! He is also the instructor, content developer, and owner of ieMentor

Larry: Thanks for taking the time to participate in this interview.

Roman: Thank you, Larry. It’s great to see a new online resource dedicated to the CCIE training industry. Thank you for spending time on doing this! A lot of folks who are going for a CCIE appreciate this too.

Larry: Thanks. I am hoping that the blog will become a valuable resource. The first thing I have to ask about is – 6 CCIE certifications!!! What drove you to want to go that far?

Roman: I’m not even sure what exactly drove me to this. I definitely like being challenged, I like taking tests. There is no one common reason for each of the CCIEs though.
R&S was my first and it took a couple of years to prepare for, finally passing it in August 2001 on second attempt. I just got out of college, not yet legal to drink or to rent a car. Clearly that was the most exciting CCIE to get, far more exciting compared to the last one I got this year. What an experience that was, so much inspiration, drive, fear, stress, so little sleep! First attempt was a disaster, out of excitement I threw away one of the provided pieces of paper into trash, and Kathy, my favorite proctor, wouldn’t let me continue on my second day, even though I passed the first day. She said “You are lucky we are not putting you on a black list”. I would have had to wait for almost 6 months to get another seat.
Fortunately, past programming skills helped me develop a quick script that checked Cisco’s CCIE scheduling site for available dates and grabbed a date if it became available. I was back in a month and paid more attention that time. The big driver for R&S was career advancement and desire to get through that magic $100K/year salary barrier. But more importantly, I really liked what I was doing and was fortunate enough to become inspired by a couple of CCIE Cisco folks I met around that time. One of them, Dmitry Bokotey, 5xCCIE#4460, became a very good friend of mine and was the main point of inspiration for getting drunk on Cisco Kool-Aid.
I got Security CCIE six months later on first attempt. Playing with PIXs and VPNs at that time helped out a lot. The other factor was the young age of the Security CCIE track. I always recommend students to take the CCIE lab when it just comes out and not wait for the second version of the blueprint. I realize, of course, that not everyone gets a chance to do that. The first version of the Security lab was a little raw and wasn’t as advanced as the latest blueprint. It didn’t require as much effort. I’m not saying it was easy, but definitely easier than what other folks have to go through now to achieve Security CCIE.
If Cisco could take my Security track away and let me retake the new lab, I’d like to do that. I don’t think they allow this, though.
I remember asking them the same about my Storage CCIE so that I could go and try the new second version of the lab. They wouldn’t let me.
During those two years in 2002 and 2003, I was heavily involved in some voice deployments with CallManager, Unity, IPCC, and other Cisco voice offerings. This helped me gain enough interest and knowledgebase for attempting Voice track. My sheer interest for UC (or IPT back then) held me hostage and begged me to try it. I studied for a couple of months, went and failed. I have to thank proctor Ben Ng for creating a very challenging lab. He was the most helpful proctor of all!
I haven’t seen the new security lab, but based on the six labs I took, in my opinion, Voice was the hardest.
After failing, I studied each night after work for a month, and then went back and was lucky enough to pass it.
This is where the story stops for about three years. During that time I got a chance to do a consulting gig in Europe for about a year, got married, bought a home, those dollars had to go somewhere!!
I forgot about CCIEs for a while. Finally in 2005, around the same time Storage track was coming out, I got involved with ieMentor. It was more of a hobby than a business. I wanted to do something fun and take advantage of all the knowledge CCIEs gave me and pass this knowledge on to other people. Our CCIE Service Provider, CCIE Voice and CCIE Storage workbooks came out around the same time, followed by the CCIE Service Provider and CCIE Storage bootcamps.
Writing a CCIE Storage workbook drove me to take the CCIE Storage lab. Developing labs and questions is the best way to study for the lab. Of course, not everyone would decide to use this wacky approach, but it certainly helped me pass the Storage lab on first attempt in March of 2006 and then release the workbook a month after that. In the summer of 2006, I started delivering the CCIE Service Provider bootcamps without actually having the cert.
CCIE Service Provider is my favorite track. No other track has such a collection of interconnected technologies that allows you to achieve the result only if you get every little piece right. Doing that successful final ping between two CEs is more exciting to me than making a successful phone call between two IP phones. Discovering a failed ping between two CEs is more stressful for me than discovering a broken VPN session. I don’t know, maybe it’s just me, but Service Provider technologies are just a lot of fun to work with! Obviously, I couldn’t teach the class for too long without having the certification. I went and passed it in November of 2006.
Finally, in 2008, a rumor spread that a CCIE wireless track was on the horizon. My brain was refusing to even think about it, while my heart was telling me “Just one more, and that’s it”. Also, the word “sextuple” had something sexy about it. Probably the only sexy thing ever associated with a CCIE. I locked myself in the room for two months studying controllers, access points, authentication, security, WCS, roaming, wireless voice, all the fun stuff you have to know for this great track. I took the lab in San Jose in May of 2009 and it kicked my butt.
Past experience taking these labs taught me a lesson:
1. Document the entire lab even if you think you passed it. This takes about 3 days. Don’t be lazy!!
2. Practice your lab at home and research every topic even if you believe you will get a different lab next time
3. Don’t wait after failing, schedule the lab for the soonest date possible. The most studying you will do is between the attempts.
After coming back from the wireless lab, I locked myself in a room for a month again, went back in July and was lucky to pass it. It was a very nostalgic experience coming to San Jose for the last CCIE, the same location I went to get my first one eight years ago.
In conclusion, what helped me get six CCIEs? A different thing each time:
1. R&S = lots of studying for about two years, a true CCIE preparation experience that most go through
2. Security = experience with PIXes and IOS security + luck
3. Voice = experience with IPT + two months of non-stop studying
4. Storage = writing a workbook
5. SP = teaching a bootcamp
6. Wireless = two months of non-stop studying
Some people who don’t know me think I have no life and that all I do is study. I would say that studying for CCIE R&S was really like that, no partying, lots of lab hours, lots of sleepless nights. Other tracks involved short but intense study methods. I would simply lock myself in a room with equipment and books for a couple of months. Another thing that helps me a lot is that I enjoy reading technical literature, Cisco Press books, but mostly Cisco’s documentation. The problem is that 90% of reading I do is in my car. I certainly don’t recommend it! At any point in time, you will find around ten 20-30 page Cisco website print-outs on my passenger’s seat. I don’t know why, but it helps me better digest and remember the information.
I don’t like long and boring tasks that don’t require some knowledge transfer, like driving, running on treadmill, waiting at the doctor’s office. I can’t just sit and stare at something, I need to read. Yes, reading while driving is not a good idea, but I never had an accident because of it, I usually feel more distracted talking on the phone while driving.
Larry: Wow – that’s quite a story . I think that all of us that have passed, taken or are preparing for a lab can relate in some way. As an instructor, how do you keep up to date on all of the tracks and the changes to the labs?

Roman : Various sources can help. I currently teach SP track and since the blueprint hasn’t changed for a long time, it doesn’t require too many changes to the curriculum. I make sure that I cover all topics on the blueprint. I also monitor IOS release notes to be aware of any changes or new features introduced. I listen to what students are saying or what they hear about from other people preparing for SP. I myself learn something new in each class.

Larry: That is definitely something to remember. We can always learn something new!!
Do you have a favorite technology area? One that really interests you more than the others?

Roman: I enjoy working with Data Center, Virtualization, Unified Communications and Wireless. I like them all equally as long as the project is challenging.

Larry: There are a lot of folks that are currently studying for their first CCIE. They have problems balancing work, studying and family. Do you have any advice for them?

Roman: First of all, I need to mention that my wife and I don’t have kids yet, so I’m absolutely in no position to make recommendation of how to balance your time between kids and studying. For my situation, my success at getting CCIE and how quickly I can achieve it depends entirely on how much I am interested in the technology. If configuring MPLS VPNs is more interesting than watching TV, I will pass the lab quickly.
Find time to read. Print out a 10-20 page section of a configuration guide or a tech note and read it the same day. Do this every day. There are plenty of moments in your day, wherever you are, when you are idling and could spend that time reading.
Finally, again, it’s all about INTEREST and ENJOYMENT. If you are truly interested in the technology, if you are really enjoying studying, you will find time how to balance work, wife (can’t speak for kids) and studying. People who “can’t find time for studying”, don’t actually enjoy studying that technology.

Larry: That is an important item to consider. Having a passion for what you are studying makes it more bearable. What is your reaction to the major changes to the R&S lab structure? Do you have any advice for folks that are studying for this “new breed” of lab?

Roman: I’m not very familiar with it. I’ve heard about new troubleshooting section, but can’t speak much to it. I live in the SP and Storage world.

Larry: One question that I get quite often from people is - Should I go for a professional level certification before moving to the CCIE? What is your advice on that?

Roman: If you are going to do CCIE, why waste time on CCNP? If you are ready for CCIE, you can go and take all CCNP tests in one day, and you’ll pass them. Getting CCNP might get you a $10-20K salary increase, but probably only if you switch jobs. If you think that CCIE is your ultimate goal, go for CCIE, don’t think about CCNP. These two certifications require a different approach in studying. Some people choose to study with pass4sure and pass the CCNP within a week. I would rather prepare first for a CCIE, and then take CCNP tests without preparation a week before the CCIE lab.

Larry: Thanks again for taking the time for this out of your busy schedule. One last closing question – If Cisco brings out another CCIE track will you go for it?

Roman: Well, it’s kind of obvious that Data Center CCIE will be the next track. It would be interesting to see if Cisco keeps Storage CCIE alive or if it decides to merge them. I love Data Center technologies and therefore will do this track. Now, if Cisco decides to make a track on TelePresence, that’s a different story!

Tuesday, March 2, 2010

MIKROTIK: How to apply different limits for Local/Overseas traffic

Introduction

Let's consider the scenario, when you want to apply different limit to Local and Oversea traffic. Oversea traffic - traffic that doesn't belong to the Local country traffic. To distinguish oversea traffic from Local country traffic, we will use 'mangle marks' and 'address-list' features. It will place appropriate marks to the packets to/from the Local country and Oversea networks. Note, 'address-list' entries should be replaced with respective addresses, if your router isn't located in Latvia. To find the actual list of network numbers belonging to your country, use Google or any other resources. Simple queues will limit data rate for the Local country traffic and Oversea traffic.

Address-list

First we create Local country address-list, where are placed list of network numbers belonging to ISPs in Latvia (any other country network addresses can be used instead). Full address-list configuration is not included (too many address-list entries), but address-list idea is clear. Networks added to the list 'Latvia':

/ ip firewall address-list
add list=Latvia address=159.148.0.0/16 comment="" disabled=no
add list=Latvia address=193.41.195.0/24 comment="" disabled=no
add list=Latvia address=193.41.33.0/24 comment="" disabled=no
add list=Latvia address=193.41.45.0/24 comment="" disabled=no
add list=Latvia address=193.68.64.0/19 comment="" disabled=no
add list=Latvia address=193.108.29.0/24 comment="" disabled=no
add list=Latvia address=193.108.144.0/22 comment="" disabled=no
add list=Latvia address=193.108.185.0/24 comment="" disabled=no
add list=Latvia address=193.109.211.0/24 comment="" disabled=no
add list=Latvia address=193.109.85.0/24 comment="" disabled=no
add list=Latvia address=193.110.8.0/23 comment="" disabled=no
add list=Latvia address=193.110.164.0/23 comment="" disabled=no
...
add list=Latvia address=193.111.244.0/22 comment="" disabled=no

Mangle

First we add rule to mark connections that belong to local router's subnet (192.168.100.0/24). Second rule marks connections between local subnet and overseas networks. Third rule marks oversea packets and exclude them from mangle table (passtrough=no). Finally, the last rule places packet mark on all packets that belong to Local country traffic.

/ ip firewall mangle
add chain=prerouting src-address=192.168.100.0/24 action=mark-connection \
new-connection-mark="Con Entire Traffic" passthrough=yes \
comment="Mark-connection All Traffic" disabled=no
add chain=prerouting src-address=192.168.100.0/24 connection-mark="Con Entire \
Traffic" dst-address-list=!Latvia action=mark-connection \
new-connection-mark="Con Oversea" passthrough=yes comment="Mark-connection \
Oversea Traffic" disabled=no
add chain=prerouting connection-mark="Con Oversea" action=mark-packet \
new-packet-mark="Oversea traffic" passthrough=no comment="Mark-packet \
Oversea Traffic" disabled=no
add chain=prerouting action=mark-packet new-packet-mark="Local Country Traffic" \
passthrough=no comment="Mark-packet Local Country Traffic" disabled=no

Simple Queue

Queue configuration is quite simple in the particular case. 192.168.100.254 is the local network host. First rule sets limit 256k/256k to Oversea traffic for the particular host. Respectively second simple queue set limit 1M/1M for Local country traffic.
/ queue simple
add name="Oversea" target-addresses=192.168.100.254/32 dst-address=0.0.0.0/0 \
interface=all parent=none packet-marks="Oversea traffic" direction=both \
priority=8 queue=default-small/default-small limit-at=0/0 \
max-limit=256000/256000 total-queue=default-small disabled=no
add name="Local Country" target-addresses=192.168.100.254/32 dst-address=0.0.0.0/0 \
interface=all parent=none packet-marks="Local Country Traffic" direction=both \
priority=8 queue=default-small/default-small limit-at=0/0 \
max-limit=1024000/1024000 total-queue=default-small disabled=no

Monday, December 21, 2009

MPLS Topics

MPLS Concepts

* Introducing Basic MPLS Concepts
* Introducing MPLS Labels and Label Stacks
* Identifying MPLS Applications


Label Assignment and Distribution

* Discovering LDP Neighbors
* Introducing Typical Label Distribution in Frame-Mode MPLS
* Introducing Convergence in Frame-Mode MPLS
* Introducing MPLS Label Allocation, Distribution, and Retention Modes


Frame-Mode MPLS Implementation on Cisco IOS Platforms

* Introducing CEF Switching
* Configuring Frame-Mode MPLS on Cisco IOS Platforms
* Monitoring Frame-Mode MPLS on Cisco IOS Platforms
* Troubleshooting Frame-Mode MPLS on Cisco IOS Platforms


MPLS VPN Technology

* Introducing VPNs
* Categorizing VPNs
* Introducing MPLS VPN Architecture
* Introducing the MPLS VPN Routing Model
* Forwarding MPLS VPN Packets


MPLS VPN Implementation

* Using MPLS VPN Mechanisms on Cisco IOS Platforms
* Configuring VRF Tables
* Configuring an MP-BGP Session Between PE Routers
* Configuring Small-Scale Routing Protocols Between PE and CE Routers
* Monitoring MPLS VPN Operations
* Configuring OSPF as the Routing Protocol Between PE and CE routers
* Configuring BGP as the Routing Protocol Between PE and CE routers
* Troubleshooting MPLS VPNs


Complex MPLS VPNs

* Using Advanced VRF Import and Export Features
* Introducing Overlapping VPNs
* Introducing Central Services VPNs
* Introducing the Managed CE Routers Service


Internet Access and MPLS VPNs

* Introducing VPN Internet Access Topologies
* Implementing Separate Internet Access and VPN Services
* Implementing Internet Access as a Separate VPN


MPLS TE Overview

* Introducing the TE Concept
* Understanding MPLS TE Components
* Configuring MPLS TE on Cisco IOS Platforms
* Monitoring Basic MPLS TE on Cisco IOS Platforms

Sunday, November 1, 2009

Inter-Switch Link



Cisco Inter-Switch Link (ISL) is a Cisco Systems proprietary protocol that maintains VLAN information as traffic flows between switches and routers, or switches and switches.ISL is Cisco's VLAN encapsulation method and supported only on Cisco's equipment through Fast and Gigabit Ethernet links. The size of an Ethernet encapsulated ISL frame can be expected to start from 94 bytes and increase up to 1548 bytes due to the overhead (additional fields) the protocol creates via encapsulation. ISL adds a 26-byte header (containing a 15-bit VLAN identifier) and a 4-byte CRC trailer to the frame. ISL functions at the Data-Link layer of the OSI model. ISL is used to maintain redundant links.

ISL is a Cisco proprietary protocol for the interconnection of multiple switches and maintenance of VLAN information as traffic goes between switches. ISL provides VLAN trunking capabilities while it maintains full wire-speed performance on Ethernet links in full-duplex or half-duplex mode. ISL operates in a point-to-point environment and can support up to 1000 VLANs. In ISL, the original frame is encapsulated and an additional header is added before the frame is carried over a trunk link. At the receiving end, the header is removed and the frame is forwarded to the assigned VLAN. ISL uses Per VLAN Spanning Tree (PVST), which runs one instance of Spanning Tree Protocol (STP) per VLAN. PVST allows the optimization of root switch placement for each VLAN and supports the load balancing of VLANs over multiple trunk links. ISL Frame- The ISL frame consists of three primary fields: the encapsulation frame (original frame), which is encapsulated by the ISL header, and the FCS at the end.

This section provides detailed descriptions of the ISL frame fields:

The DA field of the ISL packet is a 40-bit destination address. This address is a multicast address and is set at "0x01-00-0C-00-00" or "0x03-00-0c-00-00". The first 40 bits of the DA field signal the receiver that the packet is in ISL format.

The TYPE field consists of a 4-bit code. The TYPE field indicates the type of frame that is encapsulated and can be used in the future to indicate alternative encapsulations. This table provides definitions of different TYPE codes:

The USER field consists of a 4-bit code. The USER bits are used to extend the meaning of the TYPE field. The default USER field value is "0000". For Ethernet frames, the USER field bits "0" and "1" indicate the priority of the packet as it passes through the switch. Whenever traffic can be handled in a manner that allows it to be forwarded more quickly, the packets with this bit set should take advantage of the quick path. It is not required that such paths be provided.

The SA field is the source address field of the ISL packet. The field should be set to the "802.3" MAC address of the switch port that transmits the frame. It is a 48-bit value. The receiving device may ignore the SA field of the frame.

The LEN field stores the actual packet size of the original packet as a 16-bit value. The LEN field represents the length of the packet in bytes, with the exclusion of the DA, TYPE, USER, SA, LEN, and FCS fields. The total length of the excluded fields is 18 bytes, so the LEN field represents the total length minus 18 bytes.

AAAA03 (SNAP)—Subnetwork Access Protocol (SNAP) and Logical Link Control (LLC).The AAAA03 SNAP field is a 24-bit constant value of "0xAAAA03".

HSA—High Bits of Source Address.The HSA field is a 24-bit value. This field represents the upper 3 bytes (the manufacturer ID portion) of the SA field. The field must contain the value "0x00-00-0C".

VLAN—Destination Virtual LAN ID. The VLAN field is the VLAN ID of the packet. It is a 15-bit value that is used to distinguish frames on different VLANs. This field is often referred to as the "color" of the frame.

BPDU—Bridge Protocol Data Unit (BPDU) and Cisco Discovery Protocol (CDP) Indicator.
The bit in the BPDU field is set for all BPDU packets that are encapsulated by the ISL frame. The BPDUs are used by the spanning tree algorithm in order to determine information about the topology of the network. This bit is also set for CDP and VLAN Trunk Protocol (VTP) frames that are encapsulated.

The INDX field indicates the port index of the source of the packet as it exits the switch. This field is used for diagnostic purposes only, and may be set to any value by other devices. It is a 16-bit value and is ignored in received packets.
RES—Reserved for Token Ring and FDDI

The RES field is a 16-bit value. This field is used when Token Ring or FDDI packets are encapsulated with an ISL frame. In the case of Token Ring frames, the Access Control (AC) and Frame Control (FC) fields are placed here. In the case of FDDI, the FC field is placed in the Least Significant Byte (LSB) of this field. For example, an FC of "0x12" has a RES field of "0x0012". For Ethernet packets, the RES field should be set to all zeros.

The ENCAP FRAME field is the encapsulated data packet, which includes its own cyclic redundancy check (CRC) value, completely unmodified. The internal frame must have a CRC value that is valid after the ISL encapsulation fields are removed. The length of this field can be from 1 to 24,575 bytes in order to accommodate Ethernet, Token Ring, and FDDI frames. A receiving switch may strip off the ISL encapsulation fields and use this ENCAP FRAME field as the frame is received (associating the appropriate VLAN and other values with the received frame as indicated for switching purposes).
FCS—Frame Check Sequence

The FCS field consists of 4 bytes. This sequence contains a 32-bit CRC value, which is created by the sending MAC and is recalculated by the receiving MAC in order to check for damaged frames. The FCS is generated over the DA, SA, Length/Type, and Data fields. When an ISL header is attached, a new FCS is calculated over the entire ISL packet and added to the end of the frame.

The ISL frame encapsulation is 30 bytes, and the minimum FDDI packet is 17 bytes. Therefore, the minimum ISL encapsulated packet for FDDI is 47 bytes. The maximum Token Ring packet is 18,000 bytes. Therefore, the maximum ISL packet is 18,000 plus 30 bytes of ISL header, for a total of 18,030 bytes. If only Ethernet packets are encapsulated, the range of ISL frame sizes is from 94 to 1548 bytes.The biggest implication for systems that use ISL encapsulation is that the encapsulation is a total of 30 bytes, and fragmentation is not required. Therefore, if the encapsulated packet is 1518 bytes long, the ISL packet is 1548 bytes long for Ethernet. Additionally, if packets other than Ethernet packets are encapsulated, the maximum length can be greatly increased. You must consider this length change when you evaluate whether a topology can support ISL packets size.

Note: The addition of the new FCS does not alter the original FCS that is contained within the encapsulated frame.

VLAN Trunking Protocol (VTP)





Cisco Devices, VTP (VLAN Trunking Protocol) maintains VLAN configuration consistency across the entire network. VTP uses Layer 2 trunk frames to manage the addition, deletion, and renaming of VLANs on a network-wide basis from a centralized switch in the VTP server mode. VTP is responsible for synchronizing VLAN information within a VTP domain and reduces the need to configure the same VLAN information on each switch.

VTP minimizes the possible configuration inconsistencies that arise when changes are made. These inconsistencies can result in security violations, because VLANs can crossconnect when duplicate names are used. They also could become internally disconnected when they are mapped from one LAN type to another, for example, Ethernet to ATM LANE ELANs or FDDI 802.10 VLANs. VTP provides a mapping scheme that enables seamless trunking within a network employing mixed-media technologies.

VTP provides the following benefits:

* VLAN configuration consistency across the network
* Mapping scheme that allows a VLAN to be trunked over mixed media
* Accurate tracking and monitoring of VLANs
* Dynamic reporting of added VLANs across the network
* Plug-and-play configuration when adding new VLANs

As beneficial as VTP can be, it does have disadvantages that are normally related to the Spanning Tree Protocol (STP) as a bridging loop propagating throughout the network can occur. Cisco switches run an instance of STP for each VLAN, and since VTP propagates VLANs across the campus LAN, VTP effectively creates more opportunities for a bridging loop to occur.

Before creating VLANs on the switch that will be propagated via VTP, a VTP domain must first be set up. A VTP domain for a network is a set of all contiguously trunked switches with the same VTP domain name. All switches in the same management domain share their VLAN information with each other, and a switch can participate in only one VTP management domain. Switches in different domains do not share VTP information.

Using VTP, each Catalyst Family Switch advertises the following on its trunk ports:

* Management domain
* Configuration revision number
* Known VLANs and their specific parameters

There are three version of VTP so far. VTP Version 2 (V2) is not much different than VTP Version 1 (V1). The major difference is that VTP V2 introduces the support for Token Ring VLANs. If you are using Token Ring VLANs, you need to enable VTP V2. Otherwise, there is no reason to use VTP V2. VTP version 3 differs from earlier VTP versions in that it does not directly handle VLANs. VTP version 3 is a protocol that is only responsible for distributing a list of opaque databases over an administrative domain. When enabled, VTP version 3 provides the following enhancements to previous VTP versions:

* Support for extended VLANs.
* Support for the creation and advertising of private VLANs.
* Improved server authentication.
* Protection from the "wrong" database accidentally being inserted into a VTP domain.
* Interaction with VTP version 1 and VTP version 2.
* Provides the ability to be configured on a per-port basis.
* Provides the ability to propagate the VLAN database andother databases.

Virtual LAN



VLANs are created to provide the segmentation services traditionally provided by routers in LAN configurations. VLANs address issues such as scalability, security, and network management. Routers in VLAN topologies provide broadcast filtering, security, address summarization, and traffic flow management. By definition, switches may not bridge IP traffic between VLANs as it would violate the integrity of the VLAN broadcast domain. Virtual LANs are essentially Layer 2 constructs, compared with IP subnets which are Layer 3 constructs. In an environment employing VLANs, a one-to-one relationship often exists between VLANs and IP subnets, although it is possible to have multiple subnets on one VLAN or have one subnet spread across multiple VLANs. Virtual LANs and IP subnets provide independent Layer 2 and Layer 3 constructs that map to one another and this correspondence is useful during the network design process. By using VLANs, one can control traffic patterns and react quickly to relocations. VLANs provide the flexibility to adapt to changes in network requirements and allow for simplified administration.



The protocol most commonly used today in configuring virtual LANs is IEEE 802.1Q. The IEEE committee defined this method of multiplexing VLANs in an effort to provide multivendor VLAN support. Prior to the introduction of the 802.1Q standard, several proprietary protocols existed, such as Cisco's ISL (Inter-Switch Link, a variant of IEEE 802.10) and 3Com's VLT (Virtual LAN Trunk). Both ISL and IEEE 802.1Q tagging perform "explicit tagging" - the frame itself is tagged with VLAN information. ISL uses an external tagging process that does not modify the existing Ethernet frame, while 802.1Q uses a frame-internal field for tagging, and so does modify the Ethernet frame. This internal tagging is what allows IEEE 802.1Q to work on both access and trunk links: frames are standard Ethernet, and so can be handled by commodity hardware.

The IEEE 802.1Q header contains a 4-byte tag header containing a 2-byte tag protocol identifier (TPID) and a 2-byte tag control information (TCI). The TPID has a fixed value of 0x8100 that indicates that the frame carries the 802.1Q/802.1p tag information. The TCI contains the following elements:

* Three-bit user priority
* One-bit canonical format indicator (CFI)
* Twelve-bit VLAN identifier (VID)-Uniquely identifies the VLAN to which the frame belongs

The 802.1Q standard can create an interesting scenario on the network. Recalling that the maximum size for an Ethernet frame as specified by IEEE 802.3 is 1518 bytes, this means that if a maximum-sized Ethernet frame gets tagged, the frame size will be 1522 bytes, a number that violates the IEEE 802.3 standard. To resolve this issue, the 802.3 committee created a subgroup called 802.3ac to extend the maximum Ethernet size to 1522 bytes. Network devices that do not support a larger frame size will process the frame successfully but may report these anomalies as a "baby giant". Inter-Switch Link (ISL) is a Cisco proprietary protocol used to interconnect multiple switches and maintain VLAN information as traffic travels between switches on trunk links. This technology provides one method for multiplexing bridge groups (VLANs) over a high-speed backbone. It is defined for Fast Ethernet and Gigabit Ethernet, as is IEEE 802.1Q. ISL has been available on Cisco routers since Cisco IOS Software Release 11.1.

With ISL, an Ethernet frame is encapsulated with a header that transports VLAN IDs between switches and routers. ISL does add overhead to the packet as a 26-byte header containing a 10-bit VLAN ID. In addition, a 4-byte CRC is appended to the end of each frame. This CRC is in addition to any frame checking that the Ethernet frame requires. The fields in an ISL header identify the frame as belonging to a particular VLAN. A VLAN ID is added only if the frame is forwarded out a port configured as a trunk link. If the frame is to be forwarded out a port configured as an access link, the ISL encapsulation is removed.

Thursday, October 22, 2009

Static Routing

Objective:

Design & develop a computer network between 3 routers in three buildings, using static routing.

Setup:

I have taken several steps to establish static routing between routers A, B, C are given below:

Router A: Network address 192.168.1.0 is used for hosts of the router A. PC 0 and PC 1 are connected through a switch ip configuration of 192.168.1.2 and subnet mask is 255.255.255.0 and 192.168.1.3 and subnet mask is 255.255.255.0. For the cable which connects router A with router B is configured with the ip address 192.168.4.1 and subnet mask is 255.255.255.0. Gateway address used for hosts of router A network is 192.168.1.1 and subnet mask is 255.255.255.0.

Router B: Network address 192.168.2.0 is used for hosts of the router B. PC 2 and PC 3 are connected through a switch ip configuration of 192.168.2.2 and subnet mask is 255.255.255.0 and 192.168.2.3 and subnet mask is 255.255.255.0. For the cable which connects router B with router A is configured with the ip address 192.168.4.2 and subnet mask is 255.255.255.0 and for the cable which connects router B with router C is configured with the ip address 192.168.5.1 and subnet mask is 255.255.255.0. Gateway address used for hosts of router B network is 192.168.2.1 and subnet mask is 255.255.255.0.

Router C: Network address 192.168.3.0 is used for hosts of the router A. PC 4 and PC 5 are connected through a switch ip configuration of 192.168.3.2 and subnet mask is 255.255.255.0 and 192.168.3.3 and subnet mask is 255.255.255.0. For the cable which connects router C with router B is configured with the ip address 192.168.5.2 and subnet mask is 255.255.255.0. Gateway address used for hosts of router C network is 192.168.3.1 and subnet mask is 255.255.255.0.

Network Diagram:

Image and video hosting by TinyPic

Commands in the routers:

Defining Routes:

Router A:

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.4.2

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.4.2

Router B:

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.4.1

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.5.2

Router C:

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.5.1

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.5.1


Objective:

Design & develop a computer network between 4 routers situated in different places, using static routing with redundancy.

Setup:

I have taken several steps to establish static routing between routers A, B, C, D are given below:

Router A: Network address 192.168.1.0 is used for hosts of the router A. PC 1 is connected through a switch ip configuration of 192.168.1.2 and subnet mask is 255.255.255.0. For the cable which connects router A with router B is configured with the ip address 192.168.5.1 and subnet mask is 255.255.255.0 and router C is configured with the ip address 192.168.6.2 and subnet mask is 255.255.255.0.There is another router D and For the cable which connects router A with router D is configured with the ip address 192.168.10.1 and subnet mask is 255.255.255.0 and the gateway address used for hosts of router A network is 192.168.1.1 and subnet mask is 255.255.255.0.

Router B: Network address 192.168.3.0 is used for hosts of the router B. PC 2 is connected through a switch ip configuration of 192.168.3.2 and subnet mask is 255.255.255.0. For the cable which connects router B with router A is configured with the ip address 192.168.5.2 and subnet mask is 255.255.255.0 and router C is configured with the ip address 192.168.9.2 and subnet mask is 255.255.255.0.There is another router D and For the cable which connects router A with router D is configured with the ip address 192.168.8.1 and subnet mask is 255.255.255.0 and the gateway address used for hosts of router B network is 192.168.3.1 and subnet mask is 255.255.255.0.

Router C: Network address 192.168.2.0 is used for hosts of the router C. PC 3 is connected through a switch ip configuration of 192.168.2.2 and subnet mask is 255.255.255.0. For the cable which connects router C with router B is configured with the ip address 192.168.9.1 and subnet mask is 255.255.255.0 and router A is configured with the ip address 192.168.6.1 and subnet mask is 255.255.255.0.There is another router D and For the cable which connects router A with router D is configured with the ip address 192.168.7.2 and subnet mask is 255.255.255.0 and the gateway address used for hosts of router A network is 192.168.2.1 and subnet mask is 255.255.255.0.

Router D: Network address 192.168.4.0 is used for hosts of the router D. PC 4 is connected through a switch ip configuration of 192.168.4.2 and subnet mask is 255.255.255.0. For the cable which connects router D with router B is configured with the ip address 192.168.8.2 and subnet mask is 255.255.255.0 and router C is configured with the ip address 192.168.7.2 and subnet mask is 255.255.255.0.There is another router A and For the cable which connects router D with router A is configured with the ip address 192.168.10.2 and subnet mask is 255.255.255.0 and the gateway address used for hosts of router A network is 192.168.4.1 and subnet mask is 255.255.255.0.

Network Diagram:

Image and video hosting by TinyPic

Commands in the routers:

Defining Routes:

Router A:

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.6.1 10

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.10.2 11

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.5.2 12

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.5.2 13

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.10.2 14

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.6.1 15

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.10.2 16

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.5.2 17

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.6.1 18

Router B

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.8.2 10

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.9.1 11

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.5.1 12

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.5.1 13

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.9.1 14

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.8.2 15

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.9.1 16

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.8.2 17

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.5.1 18

Router C

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.6.2 10

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.9.2 11

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.7.1 12

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.7.1 13

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.9.2 14

Router(config)#ip route 192.168.4.0 255.255.255.0 192.168.6.2 15

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.9.2 16

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.7.1 17

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.6.2 18

Router D

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.7.2 10

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.10.1 11

Router(config)#ip route 192.168.2.0 255.255.255.0 192.168.8.1 12

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.8.1 13

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.10.1 14

Router(config)#ip route 192.168.3.0 255.255.255.0 192.168.7.2 15

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.10.1 16

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.7.2 17

Router(config)#ip route 192.168.1.0 255.255.255.0 192.168.8.1 18

Tuesday, October 20, 2009

IPLC

An IPLC (international private leased circuit) is a point-to-point private line used by an organization to communicate between offices that are geographically dispersed throughout the world. An IPLC can be used for Internet access, business data exchange, video conferencing, and any other form of telecommunication.


Thursday, October 15, 2009

Virtual private LAN service

Virtual private LAN service (VPLS) is a way to provide Ethernet based multipoint to multipoint communication over IP/MPLS networks. It allows geographically dispersed sites to share an Ethernet broadcast domain by connecting sites through pseudo-wires. The technologies that can be used as pseudo-wire can be Ethernet over MPLS, L2TPv3 or even GRE. There are two IETF standards track RFCs (RFC 4761 and RFC 4762) describing VPLS establishment.VPLS is a virtual private network (VPN) technology. In contrast to L2TPv3, which allows only point-to-point layer 2 tunnels, VPLS allows any-to-any (multipoint) connectivity. In a VPLS, the local area network (LAN) at each site is extended to the edge of the provider network. The provider network then emulates a switch or bridge to connect all of the customer LANs to create a single bridged LAN. Since VPLS emulates a LAN, full mesh connectivity is required. There are two methods for full mesh establishment for VPLS: using BGP and using Label Distribution Protocol (LDP). The "control plane" is the means by which provider edge (PE) routers communicate for auto-discovery and signaling. Auto-discovery refers to the process of finding other PE routers participating in the same VPN or VPLS. Signaling is the process of establishing pseudo-wires (PW). The PWs constitute the "data plane", whereby PEs send customer VPN/VPLS traffic to other PEs.

With BGP, one has auto-discovery as well as signaling. The mechanisms used are very similar to those used in establishing Layer-3 MPLS VPNs. Each PE is configured to participate in a given VPLS. The PE, through the use of BGP, simultaneously discovers all other PEs in the same VPLS, and establishes a full mesh of pseudo-wires to those PEs. With LDP, each PE router must be configured to participate in a given VPLS, and, in addition, be given the addresses of other PEs participating in the same VPLS. A full mesh of LDP sessions is then established between these PEs. LDP is then used to create an equivalent mesh of PWs between those PEs. An advantage to using PWs as the underlying technology for the data plane is that in case of failure, traffic will automatically be routed along available backup paths in the service provider's network. Failover will be much faster than could be achieved with e.g. Spanning Tree Protocol (STP). VPLS is thus a more reliable solution for linking together Ethernet networks in different locations than simply connecting a WAN link to Ethernet switches in both locations.

VPLS has significant advantages for both service providers and customers. Service providers benefit because they can generate additional revenues by offering a new Ethernet service with flexible bandwidth and sophisticated service level agreements (SLAs). VPLS is also simpler and more cost effective to operate than a traditional service. Customers benefit because they can connect all of their sites to an Ethernet VPN that provides a secure, high speed and homogenous network. Moreover, VPLS provides a logical next step in the continuing evolution of Ethernet from a 10 Mbps shared LAN protocol to a multi-Gbps global service. VPLS MPLS packets have a two-label stack. The outer label is used for normal MPLS forwarding in the service provider's network. If BGP is used to establish the VPLS, the inner label is allocated by a PE as part of a label block. If LDP is used, the inner label is a virtual circuit ID assigned by LDP when it first established a mesh between the participating PEs. Every PE keeps track of assigned inner label, and associates these with the VPLS instance.

PEs participating in a VPLS-based VPN must appear as an Ethernet bridge to connected customer edge (CE) devices. Received Ethernet frames must be treated in such a way as to ensure CEs can be simple Ethernet devices.When a PE receives a frame from a CE, it inspects the frame and learns the CE's MAC address, storing it locally along with LSP routing information. It then checks the frame's destination MAC address. If it is a broadcast frame, or the MAC address is not known to the PE, it floods the frame to all PEs in the mesh. Ethernet does not have a time to live (TTL) field in its frame header, so loop avoidance must be arranged by other means. In regular Ethernet deployments, Spanning Tree Protocol is used for this. In VPLS, loop avoidance is arranged by the following rule: A PE never forwards a frame received from a PE, to another PE. The use of a full mesh combined with split horizon forwarding guarantees a loop-free broadcast domain.VPLS is typically used to link a large number of sites together. Scalability is therefore an important issue that needs addressing.

Split horizon route advertisement

In computer networks, distance-vector routing protocols employ the split horizon route advertisement rule which prohibits a router from advertising a route back out the interface from which it was learned. Split horizon is one of the methods used to prevent routing loops due to the slow convergence times of distance-vector routing protocols.

In this example A uses B to reach C.

A-B-C.svg

A will not advertise its route for C (A to B to C) back to B. On the surface, this seems redundant since B will never use A's route because it costs more than B's route to C. However, if B's route to C goes down, B could end up using A's route, which goes through B; A would send the packet right back to B, creating a loop. With split horizon, this particular loop scenario cannot happen which improves convergence time in complex, highly-redundant environments.

An additional variation of split horizon does advertise the route back to the router that is used to reach the destination, but marks the advertisement as unreachable. This is called split horizon with poison reverse.

With poison reverse, when a routing update indicates that a network is unreachable, routes are immediately removed from the routing table. This breaks erroneous, looping routes before they can propagate through the network. This approach differs from the basic split horizon rule where routes are eliminated through timeouts. Poison reverse has no benefit in networks with no redundancy (single path networks). One disadvantage to poison reverse is that it might significantly increase the size of routing announcements exchanged between neighbors. This is because all routes in the distance vector table are included in each announcement. Although this is generally not an issue on local area networks, it can cause periods of increased utilization on lower-capacity WAN connections.

Protocols using split horizon