Professional Documents
Culture Documents
EB EB
Shared Service in
Data Center
Host 2
Fabric Site 1
FE FE
Host 1
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 419
SD-Access Transit
Route-Maps
1. permit-all-eids (Applied to LISP Map-Cache – Border Nodes) 4. site-local-eids (Applied against LISP Database import – External Border)
▪ Matches and PERMITS IP Community value 655370 and 655371 ▪ Matches and DENIES IP Community value 655371
▪ Denies the default route ▪ Denies the default route
▪ Permits everything else ▪ Permits everything else
▪ Configured on Border Nodes ▪ Configured on Border Nodes connected to SDA Transit
2. deny-all-eids (Applied against LISP Database import – Internal Border) 5. tag_transit_eids (Applied to EBGP Neighbors – Transit Control Plane Node)
▪ Matches and DENIES IP Community value 655370 and 655371 ▪ Applies IP Community value 655371
▪ Denies the L3 IP Handoff Prefixes ▪ Configured on Transit Control Plane Nodes
▪ Denies the default route
6. deny_all (Applied to EBGP Neighbors – Transit Control Plane Node)
▪ Permits everything else
▪ Denies everything
▪ Configured on Internal-Only Border Nodes
▪ Configured on Transit Control Plane Nodes
3. tag_local_eids (Applied to IBGP Neighbors – Borders and Site-Local Control Plane Nodes)
▪ Applies IP Community Value 655370
▪ Configured on Border Nodes and Site-Local Control Plane Nodes
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 420
SD-Access Transit
Route-Map 1: permit-all-eids (Applied to Map-Cache on Border Nodes)
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 421
SD-Access Transit
Route-Map 2: deny-all-eids (Applied Against LISP Database Import –
Internal Borders)
Route-Map Route-Map in Configuration Context
route-map deny-all-eids deny 10
match ip address prefix-list l3handoff-prefixes
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 422
SD-Access Transit
Route-Map 3: tag_local_eids (Applied to IBGP Neighbors – Borders and
Site-Local Control Plane Nodes)
Route-Map Route-Map in Configuration Context
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 423
SD-Access Transit
Route-Map 4: site-local-eids (Applied against LISP Database Import –
External Border)
Route-Map Route-Map in Configuration Context
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 424
SD-Access Transit
Route-Map 5: tag_transit_eids (Applied to EBGP Neighbors – Transit Control
Plane Nodes)
Route-Map Route-Map in Configuration Context
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 425
SD-Access Transit
Route-Map 6: deny-all (Applied to EBGP Neighbors – Transit Control Plane
Nodes)
Route-Map Route-Map in Configuration Context
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 426
SD-Access Transit
Route-Maps
Internet
DHCP, DNS, AD
198.51.100.30/24 TC
TC CP
EB EB
Shared Service in route-map deny_all
Data Center
route-map tag_transit_eids
route-map tag_local_eids
Host 1
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 428
SD-Access Transit – Route Maps
Internal Borders
deny-all-eids
Deny L3 Handoff Prefixes
Internet
DHCP, DNS, AD Deny 655370 deny-all-eids
198.51.100.30/24 Deny 655371 Result: Only prefixes learned from External Peer
Deny Default Route TC
are imported into the LISP Database CP
Permit Everything Else
TC
tag_local_eids
tag_local_eids
Result: Prefixes learned from External Peer are advertised
EB
Shared Service in
Apply 655370
to Site-Local Control Plane Node with Community Value EB655370
Data Center permit-all-eids
Permit 655370 permit-all-eids
Permit 655371 Result: Prefixes learned and reflected by Site-Local
Deny Default Route
Control Plane Node are imported into map-cache
Permit Everything Else
CP
Fabric Site 2
FE FE
IB EB SD-Access Transit
Host 2
Fabric Site 1
FE FE
Host 1
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 429
SD-Access Transit – Route Maps
Site-Local Control Plane Nodes
Internet
DHCP, DNS, AD
198.51.100.30/24 TC
TC CP
EB EB
Shared Service in
Data Center
• Prefixes learned via External Border and route-reflected to the Internal Border
tag_local_eids • (Tagged with IP Community 655370 tag_local_eids on by the External Border)
Apply 655370
Host 2
• Prefixes learned via the Internal Border and route-reflected to the External Border
Fabric Site 1 • (Tagged with IP Community 655370 tag_local_eids by the Internal Border)
FE FE Prefixes cannot be modified when traversing a BGP route reflector
•
tag_local_eids
Result: Tag site registrations learned from Edge Nodes and advertise to Border Nodes.
Site registrations from Internal Border and External Border Nodes are route-reflected and already tagged.
Host 1
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 430
SD-Access Transit – Route Maps
External Borders
Internet
DHCP, DNS, AD
198.51.100.30/24 TC
TC CP
EB EB
Shared Service in
Data Center
tag_local_eids
tag_local_eids
Apply 655370
Result: Prefixes learned from External Peer (if any) areHost 2
advertised
to Site-Local Control Plane Node with Community Value 655370
Fabric Site 1 site-local-eids site-local-eids
Deny 655371
FE FE Deny Default Route
Result #1: Only prefixes with IP Community Value 655370
Permit Everything Else are imported into LISP Database.
These are proxy registered to the Transit Control Plane Nodes.
Result #2: The site-local control plane node is used for map-
requests with prefixes with IP Community Value 655370.
Host 1
The Transit Control Plane Node is used for map-requests for all
other prefixes, which include those with IP Community Value
655371 (other Fabric Sites) and those without (Internet).
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 431
SD-Access Transit – Route Maps
Transit Control Plane Nodes
Internet
DHCP, DNS, AD
198.51.100.30/24 TC
TC CP
• Aggregate prefixes are registered by the Site Borders
that are connected to the SDA Transit (Site registrations)
• EB are exported to the RIB withEB
Site registrations an
Shared Service in tag_transit_eids Administrative Distance (AD) of 250
Data Center Apply 655371
tag_transit_eids
deny_all
Deny Everything Result #1: Prefixes proxy-registered via LISP to the Transit Control Plane
Nodes are advertised to all Site Borders that are connected to the
All site registrations that the Transit Control Plane Nodes learn
are advertised to the all border nodes connected to the SDA Transit.
Host 2
Border Nodes receive their own prefixes back from the Transit Control Plane
Nodes.
Fabric Site 1
FE FE However, site-local-eids on the border nodes prevents the
prefixes advertised by the Transit Control Plane Nodes (which are tagged
with 655371 from being imported into the LISP database and
thus re-registered, creating an infinite mutual redistribution loop.
deny_all
Host 1 Result: Applied inbound to all IPv4 and VPVv4 neighbors, this route-map
ensures prefixes are learned via LISP registration and subsequent
export to the RIB. If prefixes are learned via BGP, its default
AD of 20 would be preferred over the LISP AD of 240.
TECCRS-3810 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 432