Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Elements
Configuration
R1
interface Loopback0
ip address 1.1.1.1 255.255.255.255
interface FastEthernet0/0
ip address 192.168.12.1 255.255.255.0
speed 100
full-duplex
interface FastEthernet0/1
ip address 192.168.13.1 255.255.255.0
speed 100
full-duplex
interface Serial0/0
ip address 192.168.14.1 255.255.255.0
encapsulation ppp
router ospf 1
router-id 1.1.1.1
log-adjacency-changes
redistribute bgp 1 subnets
network 192.168.12.1 0.0.0.0 area 0
router eigrp 1
network 1.1.1.1 0.0.0.0
network 192.168.13.1 0.0.0.0
no auto-summary
router bgp 1
neighbor 3.3.3.3 remote-as 1
neighbor 3.3.3.3 update-source Loopback0
neighbor 192.168.14.4 remote-as 4
no auto-summary
R2
interface Loopback0
ip address 2.2.2.2 255.255.255.255
interface FastEthernet0/0
ip address 192.168.12.2 255.255.255.0
speed 100
full-duplex
router ospf 1
router-id 2.2.2.2
log-adjacency-changes
network 2.2.2.2 0.0.0.0 area 0
network 192.168.12.2 0.0.0.0 area 0
R3
interface Loopback0
ip address 3.3.3.3 255.255.255.255
interface Loopback1
ip address 13.13.13.13 255.255.255.255
interface FastEthernet0/0
ip address 192.168.13.3 255.255.255.0
speed 100
full-duplex
router bgp 1
network 3.3.3.3 mask 255.255.255.255
network 13.13.13.13 mask 255.255.255.255
neighbor 1.1.1.1 remote-as 1
neighbor 1.1.1.1 update-source Loopback0
no auto-summary
R4
interface Loopback0
ip address 4.4.4.4 255.255.255.255
interface Serial0/0
ip address 192.168.14.4 255.255.255.0
encapsulation ppp
clock rate 2000000
router bgp 4
network 4.4.4.4 mask 255.255.255.255
neighbor 192.168.14.1 remote-as 1
no auto-summary
Verification
Now let us check basic relations and route advertisements before we do the
redistribution
R1#sh ip ospf neighbor
R1#sh ip bgp
BGP table version is 5, local router ID is 1.1.1.1
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete
So , all is functioning normal , now let us do one way redistribution from BGP into OSPF
on R1 , R2 should according to the rule we mentioned above receive only 4.4.4.4/32
(which is the prefix learned via eBGP)
R1(config)#router ospf 1
R1(config-router)#redistribute bgp 1 subnets
R2#sh ip route ospf
4.0.0.0/32 is subnetted, 1 subnets
O E2 4.4.4.4 [110/1] via 192.168.12.1, 00:00:10, FastEthernet0/0
Which is true, we cannot see the 13.13.13.13/32 prefix which is learned via iBGP, now
let us add the hidden command
R1(config-router)#router bgp 1
R1(config-router)#bgp redistribute-internal
R2#sh ip route ospf
4.0.0.0/32 is subnetted, 1 subnets
O E2 4.4.4.4 [110/1] via 192.168.12.1, 00:00:51, FastEthernet0/0
13.0.0.0/32 is subnetted, 1 subnets
O E2 13.13.13.13 [110/1] via 192.168.12.1, 00:00:03, FastEthernet0/0
And yes, this command also takes the iBGP learned routes and redistributes them
And we can see the command as well in the show running configuration
R1#sh run | sec router bgp
router bgp 1
no synchronization
bgp log-neighbor-changes
bgp redistribute-internal
neighbor 3.3.3.3 remote-as 1
neighbor 3.3.3.3 update-source Loopback0
neighbor 192.168.14.4 remote-as 4
no auto-summary
Elements
We are going to configure DMVPN with EIGRP as the connecting routing protocol
between the hub and the spokes
Our Hub will R1 and the spokes will be R2 and R3
Configuration
R1
interface Loopback0
ip address 192.168.1.1 255.255.255.0
interface FastEthernet0/0
ip address 212.118.14.1 255.255.255.0
speed 100
full-duplex
IKE Phase I
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
Authentication-key configuration
crypto isakmp key cisco address 0.0.0.0 0.0.0.0
IKE Phase II
crypto ipsec transform-set SET esp-aes esp-sha-hmac
Tunnel Interface
interface Tunnel0
bandwidth 1000 (Not to overwhelm EIGRP bandwidth)
ip address 10.1.123.1 255.255.255.0
no ip redirects
ip mtu 1400 (it’s better to do so because of the IPSEC and GRE headers)
no ip next-hop-self eigrp 1 (the spokes are going to communicate)
ip nhrp authentication cisco
ip nhrp map multicast dynamic
ip nhrp network-id 5
ip tcp adjust-mss 1360
no ip split-horizon eigrp 1
tunnel source FastEthernet0/0
tunnel mode gre multipoint
tunnel key 6
tunnel protection ipsec profile PROFILE
Routing
router eigrp 1
network 10.1.123.1 0.0.0.0
network 192.168.1.1 0.0.0.0
no auto-summary
R2
interface Loopback0
ip address 192.168.2.1 255.255.255.0
interface FastEthernet0/0
ip address 62.215.1.2 255.255.255.0
speed 100
full-duplex
IKE Phase I
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
Authentication-key configuration
crypto isakmp key cisco address 0.0.0.0 0.0.0.0
IKE Phase II
crypto ipsec transform-set SET esp-aes esp-sha-hmac
Tunnel Interface
interface Tunnel0
bandwidth 1000
ip address 10.1.123.2 255.255.255.0
no ip redirects
ip mtu 1400
ip nhrp authentication cisco
ip nhrp map multicast 212.118.14.1
ip nhrp map 10.1.123.1 212.118.14.1
ip nhrp network-id 5
ip nhrp nhs 10.1.123.1
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0
tunnel mode gre multipoint
tunnel key 6
tunnel protection ipsec profile PROFILE
Routing
router eigrp 1
network 10.0.0.0
network 192.168.2.1 0.0.0.0
no auto-summary
R3
interface Loopback0
ip address 192.168.3.1 255.255.255.0
interface FastEthernet0/0
ip address 62.215.1.3 255.255.255.0
speed 100
full-duplex
IKE Phase I
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
Authentication-key configuration
crypto isakmp key cisco address 0.0.0.0 0.0.0.0
IKE Phase II
crypto ipsec transform-set SET esp-aes esp-sha-hmac
Tunnel Interface
interface Tunnel0
bandwidth 1000
ip address 10.1.123.3 255.255.255.0
no ip redirects
ip mtu 1400
ip nhrp authentication cisco
ip nhrp map multicast 212.118.14.1
ip nhrp map 10.1.123.1 212.118.14.1
ip nhrp network-id 5
ip nhrp nhs 10.1.123.1
ip tcp adjust-mss 1360
tunnel source FastEthernet0/0
tunnel mode gre multipoint
tunnel key 6
tunnel protection ipsec profile PROFILE
Routing
router eigrp 1
network 10.1.123.3 0.0.0.0
network 192.168.3.1 0.0.0.0
no auto-summary
R4
interface FastEthernet0/0
ip address 62.215.1.4 255.255.255.0
speed 100
full-duplex
interface FastEthernet0/1
ip address 212.118.14.4 255.255.255.0
speed 100
full-duplex
Verification
interface: Tunnel0
Crypto map tag: Tunnel0-head-0, local addr 62.215.1.3
inbound ah sas:
outbound ah sas:
interface: Tunnel0
Crypto map tag: Tunnel0-head-0, local addr 62.215.1.3
inbound ah sas:
outbound ah sas:
inbound ah sas:
outbound ah sas:
In this example we will configure MPLS L3VPN between two sites but, one of the CEs is
connected via normal Ethernet connection and the other one is connected via PPPoE
OSPF will be the PE-CE routing protocol and ISIS level-2 will be the operating IGP inside the
MPLS backbone, area 49.0001 is in use
MPLS backbone will be located in AS 100
Configuration
R1
interface Loopback0
ip address 1.1.1.1 255.255.255.255
interface FastEthernet0/0
no ip address
speed 100
full-duplex
pppoe enable group global
pppoe-client dial-pool-number 1
interface Dialer1
mtu 1492
ip address dhcp
encapsulation ppp
dialer pool 1
R2
interface Loopback0
ip address 2.2.2.2 255.255.255.255
ip router isis 1
interface FastEthernet0/0
ip address 192.168.23.2 255.255.255.0
ip router isis 1
speed 100
full-duplex
mpls ip
interface FastEthernet0/1
no ip address
speed 100
full-duplex
pppoe enable group PPPOE
interface Virtual-Template1
ip vrf forwarding MSSK
ip address 192.168.12.2 255.255.255.0
ip vrf MSSK
rd 100:1
route-target export 100:1
route-target import 100:1
router isis 1
net 49.0001.0000.0000.0002.00
is-type level-2-only
interface FastEthernet0/0
ip address 192.168.23.3 255.255.255.0
ip router isis 1
speed 100
full-duplex
mpls ip
interface FastEthernet0/1
ip address 192.168.34.3 255.255.255.0
ip router isis 1
speed 100
full-duplex
mpls ip
router isis 1
net 49.0001.0000.0000.0003.00
is-type level-2-only
R4
interface Loopback0
ip address 4.4.4.4 255.255.255.255
ip router isis 1
interface FastEthernet0/0
ip address 192.168.34.4 255.255.255.0
ip router isis 1
speed 100
full-duplex
mpls ip
interface FastEthernet0/1
ip vrf forwarding MSSK
ip address 192.168.45.4 255.255.255.0
ip ospf network point-to-point
speed 100
full-duplex
ip vrf MSSK
rd 100:1
route-target export 100:1
route-target import 100:1
mpls label protocol ldp
mpls ldp router-id Loopback0 force
router isis 1
net 49.0001.0000.0000.0004.00
is-type level-2-only
R5
interface Loopback0
ip address 5.5.5.5 255.255.255.255
interface FastEthernet0/0
ip address 192.168.45.5 255.255.255.0
ip ospf network point-to-point
speed 100
full-duplex
Verifications