Professional Documents
Culture Documents
0 workshop
New VPRN and VPRN-related features
April 2010
VPRN topics
3. GRT leaking
4. NAT
5. Load balancing in the MPLS core
6. MVPN
7. Miscellaneous: auto-bind, eiBGP, PE-CE
8. VPRN on 7705
1
Network Time Protocol in VPRN
Provide time/frequency reference to customer
Alcatel-Lucent – Internal
3 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Providing time reference to customer
Release 8.0 introduces the possibility of acting as an NTP server inside a VPRN.
The CE and other customer equipment will be able to use the PE as a time
reference.
There is only one instance of NTP: the VPRN will not provide a different timing
than the global one.
Alcatel-Lucent – Internal
4 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Configuration steps
CE1
PE3
PE5
PE6
PE4
PE2
Alcatel-Lucent – Internal
5 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Configuration steps
CE1
PE3
PE5
PE6
PE4
PE2
Alcatel-Lucent – Internal
6 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Configuration steps
CE1
PE3
PE5
PE6
PE4
PE2
Alcatel-Lucent – Internal
7 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Configuration steps
CE1
PE3
PE5
A:CE1# configure system time ntp
A:CE1>config>system>time>ntp# server 192.168.0.3
A:CE1>config>system>time>ntp# no shutdown
PE6
PE4
PE2
Alcatel-Lucent – Internal
8 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Configuration steps
NTP server
PE6
PE4
PE2
Alcatel-Lucent – Internal
9 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Configuration steps
The server periodically sends time announcements and the client is configured
to process these broadcast messages.
A:CE9>config>system>ntp# broadcastclient interface to-PE3
CE1
PE3
PE5
PE6
PE4
PE2
Alcatel-Lucent – Internal
10 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Caveat
Please note: the NTP process always checks out-of-band routing table first,
even when replying to VPRN clients.
CE1
PE3
PE5
PE6
PE4
PE2
Alcatel-Lucent – Internal
11 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Caveat
Please note: the NTP process in VPRN always generates packets from:
- the lowest numbered loopback IP address;
- if there is no loopback, the lowest numbered IP address
Alcatel-Lucent – Internal
12 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
NTP within VPRN
Extended show
NTP show command has been extended to list the NTP clients.
A:PE3# show system ntp all
===============================================================================
NTP Status
===============================================================================
Configured : Yes Stratum : 5
Admin Status : up Oper Status : up
Server Enabled : Yes Server Authenticate : No
Clock Source : 138.203.19.128 Auth Check : Yes
Current Date & Time: 2010/04/18 08:13:44 UTC
===============================================================================
===============================================================================
NTP Active Associations
===============================================================================
State Remote Reference ID St Type A Poll Reach Offset(ms)
-------------------------------------------------------------------------------
chosen 138.203.19.128 135.3.41.146 4 srvr - 1024 YYYYYYYY 2.433
===============================================================================
===============================================================================
NTP Clients
===============================================================================
vRouter Address Time Last Request Rx
-------------------------------------------------------------------------------
Base 10.0.0.4 04/18/2010 09:59:18
vprn100 138.203.18.140 04/16/2010 16:45:18
vprn100 192.168.0.1 04/18/2010 10:00:05
===============================================================================
Alcatel-Lucent – Internal
15 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
IP pseudowire temination
IPv6 over Ethernet pseudowire
Alcatel-Lucent – Internal
16 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
IP pseudowire termination
Configuration steps
IPIPE
192.168.101.7 192.168.101.6
CE PE5 PE6
Alcatel-Lucent – Internal
17 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
IPv6 pseudowire termination
Configuration steps
IOM2 or better is required (including 7710 and 7450-mixed), any chassis mode
*A:PE5# configure service epipe 102 A:PE6# configure service vprn 100
service-mtu 1514 interface "to-Epipe-IPv6" create
sap 1/1/4:102 create ipv6 address 2000::102:7/112
exit ip-mtu 1500
spoke-sdp 56:102 create spoke-sdp 65:102 create
exit exit
no shutdown exit
EPIPE
2000::102:7/112 2000::102:6/112
CE PE5 PE6
Alcatel-Lucent – Internal
18 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Pseudowire termination in L3 interface
Active/standby signalling
Alcatel-Lucent – Internal
19 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Before 8.0
Both PE’s would see the interface “up”, leading to an inoperable situation
PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE
192.168.103.9
PE3
A:PE6# show router 100 route-table
-------------------------------------
192.168.103.0/24
10.0.0.2 (tunneled)
192.168.103.0/24
10.0.0.3 (tunneled)
Alcatel-Lucent – Internal
20 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Description
In Release 8.0 the PE processes the TLDP signalling so that the interface
connected to the standby SDP is brought down; correspondingly, the
route/routes are withdrawn
PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE
192.168.103.9
PE3
A:PE6# show router 100 route-table
-------------------------------------
192.168.103.0/24
10.0.0.2 (tunneled)
Alcatel-Lucent – Internal
21 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Configuration
192.168.0.103/32
EPIPE
192.168.103.9
Alcatel-Lucent – Internal
22 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance
Let’s see what happens when PW redundancy is triggered; for example, when PE2 is
rebooted.
1) PE4 needs to be know that the SDP to PE2 is not available anymore; this is usually
triggered by the LSP failing (LDP or RSVP); or BFD may be used on the TLDP session
2) PE4 signals to PE3 that the SDP is becoming active
typ < 1 sec
3) PE3 switches “up” the L3 interface
1) PE3 sends a gratuitous ARP CE9 updates its ARP table
2) PE3 starts announcing the routes through the interface
4) MPBGP propagates the routes from PE3 …wait… …wait… 10-30 sec!
5) In the meanwhile, the remote PE’s detect that PE2 is unreachable and disable the
routes having PE2 as next-hop PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE TLDP
192.168.103.9
Alcatel-Lucent – Internal
23 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning
It would be desirable to have a “cold” route pointing to PE3, ready to kick in when the
route to PE2 is invalidated (because PE2 becomes unreachable) – without waiting for BGP
to propagate the new route.
This can be achieved with a trick: PE3 announces a route to a wider subnet, including all
the networks behind the CE, while PE2 announces specific routes.
This way, PE6 can use the specific routes (to PE2) as far as PE2 is available, and switch to
the generic route (to PE3) when PE2 becomes unreachable.
By removing BGP from the convergence mechanism, the overall convergence time can
easily be brought under 1 second.
PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE
192.168.103.9
PE3 RR9
192.168.0.102/31
(black hole)
Alcatel-Lucent – Internal
24 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: configuration
PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE
192.168.103.9
PE3 RR9
192.168.0.102/31
(black hole)
Alcatel-Lucent – Internal
25 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: routing before failure
interface "to-Epipe-red" create
address 192.168.103.2/24
Routing at PE2 192.168.0.102/31 Remote BGP VPN ip-mtu 1500
10.0.0.3 (tunneled) spoke-sdp 24:103 create
192.168.0.103/32 Remote Static exit
192.168.103.9 exit
static-route 192.168.0.103/32 next-hop 192.168.103.9
PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE
192.168.103.9
PE3 RR9
192.168.0.102/31
(black hole)
Alcatel-Lucent – Internal
26 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: routing shortly after PE failure
interface "to-Epipe-red" create
address 192.168.103.2/24
Routing at PE2 192.168.0.102/31 Remote BGP VPN ip-mtu 1500
10.0.0.3 (tunneled) spoke-sdp 24:103 create
192.168.0.103/32 Remote Static exit
192.168.103.9 exit
static-route 192.168.0.103/32 next-hop 192.168.103.9
PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE
192.168.103.9
Alcatel-Lucent – Internal
27 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: routing after BGP propagation
interface "to-Epipe-red" create
address 192.168.103.2/24
Routing at PE2 192.168.0.102/31 Remote BGP VPN ip-mtu 1500
10.0.0.3 (tunneled) spoke-sdp 24:103 create
192.168.0.103/32 Remote Static exit
192.168.103.9 exit
static-route 192.168.0.103/32 next-hop 192.168.103.9
PE2
192.168.103.2
UP
192.168.0.103/32
EPIPE
192.168.103.9
PE3 RR9
192.168.0.102/31
(black hole)
Alcatel-Lucent – Internal
28 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: routing shortly after SDP failure
interface "to-Epipe-red" create
address 192.168.103.2/24
Routing at PE2 192.168.0.102/31 Remote BGP VPN ip-mtu 1500
10.0.0.3 (tunneled) spoke-sdp 24:103 create
192.168.0.103/32 Remote Static exit
192.168.103.9 exit
static-route 192.168.0.103/32 next-hop 192.168.103.9
PE2
U-turn
192.168.103.2
DN
192.168.0.103/32
EPIPE
192.168.103.9
PE3 RR9
192.168.0.102/31
(black hole)
Alcatel-Lucent – Internal
29 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: after BGP propagation (SDP failure)
interface "to-Epipe-red" create
address 192.168.103.2/24
Routing at PE2 192.168.0.102/31 Remote BGP VPN ip-mtu 1500
10.0.0.3 (tunneled) spoke-sdp 24:103 create
192.168.0.103/32 Remote BGP VPN exit
10.0.0.3 (tunneled) exit
static-route 192.168.0.103/32 next-hop 192.168.103.9
PE2
192.168.103.2
DN
192.168.0.103/32
EPIPE
192.168.103.9
PE3 RR9
192.168.0.102/31
(black hole)
Alcatel-Lucent – Internal
30 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: revert to PE2
What happens when switching from PE3 to PE2 (either because the endpoint
configuration in PE4 is revertive, or because PE3 fails)?
PE2
192.168.103.2
UP
192.168.0.103/32
BGP
EPIPE
192.168.103.9
PE3 RR9
192.168.0.102/31
(black hole) Traffic is blackholed until BGP
propagates to PE3 and/or PE6
In order to avoid BGP convergence times, PE2 should be configured in a similar way to
PE3 (black-hole route to wider subnet).
PE6 must have both BGP routes available different route-distinguisher must be used on
PE2 and PE3.
Alcatel-Lucent – Internal
31 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Active/standby signalling for redundant PW termination
Performance tuning: configuration
A:PE2>config>service>vprn#
route-distinguisher 999:102
A:PE3>config>service>vprn#
interface "to-Epipe-red" create
route-distinguisher 999:103
address 192.168.103.2/24
interface "to-Epipe-red" create
ip-mtu 1500
address 192.168.103.2/24
spoke-sdp 24:103 create
ip-mtu 1500
exit
spoke-sdp 34:103 create
exit
exit
static-route 192.168.0.102/31 black-hole
exit
static-route 192.168.0.103/32 next-hop 192.168.103.9
static-route 192.168.0.102/31 black-hole
static-route 192.168.0.103/32 next-hop 192.168.103.9
Alcatel-Lucent – Internal
32 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Lab practice
Alcatel-Lucent – Internal
33 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
IP PW + active/standby
Group G = ……
Lab practice
PE5
192.168.117.56
VPRN
i/f
1G00
192.168.0.7/32 SDP 35 / 53
l.b 192.168.28.2
1/1/1:1G10 1/2/1 IPIPE VPRN
i/f i/f i/f
1G01 1G00 192.168.28.8
192.168.117.7 SDP 36 / 63
VPRN 1G00 is already created on PE2, PE5, PE6; CE7 and CE8 are configured as well
• Use customer id G
• Complete IPipe 1G01 on PE3 with active/standby spoke-sdp to PE5 and PE6; make PE5 primary and revertive
• Complete the interfaces on PE5 and PE6
• Verify that CE7 can ping PE5 (or PE6) and v.v.
• Check ARP and routing tables on CE7, PE5, PE6 Router Management System
• whose MAC addresses do they list? PE2 138.203.19.105 10.0.0.2
PE3 138.203.19.67 10.0.0.3
• Static route towards 192.168.0.7/32 is configured on PE5 and PE6 PE5 138.203.18.156 10.0.0.5
• Check routing on PE2, PE5 and PE6 PE6 138.203.18.187 10.0.0.6
• Verify that 192.168.0.7 is reachable from CE8 CE7 138.203.18.83
• Do not attempt to optimize convergence time yet CE8 138.203.18.155
Alcatel-Lucent – Internal
34 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
3
Leaking to Global Routing Table
Alcatel-Lucent – Internal
35 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Description
It has always been possible to route between one VPRN and another, creating
things like “extranet”, “hub and spoke” etc., by operating on the vrf-import
and vrf-export policies; this is easily possible because all VPRNs distribute their
routes with the same protocol and address family (BGP / vpn-ipv4).
It’s not possible to do the same for the global routing table.
However, Release 8.0 introduces tools to allow routing between a VPRN and
the GRT.
The approach is different in the two directions, as shown in the next slides.
Alcatel-Lucent – Internal
36 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
To allow data flowing from VPRN to base routing space, routing information
must be made available for lookup in the VPRN.
As usual, the flow of the routing information (control plane) is in the opposite
direction than the flow of the user packets (data plane).
In this case the routing information for the
Control plane
GRT is already available in the router, and it
Data plane only needs to be made available to the VPRN.
The approach chosen is to perform a double
VRF GRT lookup:
1) in the VRF table
2) in the global table
Alcatel-Lucent – Internal
37 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
grt-lookup
enable-grt Double lookup and selection of VRF/GRT route:
exit
exit
destination IP is 40.1.1.1
VRF GRT
A:PE5# show router 100 route-table A:PE5# show router route-table
=========================================== ===========================================
Dest Prefix Type Proto Dest Prefix Type Proto
Next Hop[Interface Name] Next Hop[Interface Name]
------------------------------------------- -------------------------------------------
40.1.1.1/32 Remote BGP VPN 40.2.2.2/32 Remote OSPF
10.0.0.6 (tunneled) 10.3.5.3
40.3.3.3/32 Remote BGP VPN 40.3.3.3/32 Remote OSPF
10.0.0.2 (tunneled) 10.3.5.3
=========================================== ===========================================
Alcatel-Lucent – Internal
39 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
grt-lookup
enable-grt Double lookup and selection of VRF/GRT route:
exit
exit
destination IP is 40.2.2.2
VRF GRT
A:PE5# show router 100 route-table A:PE5# show router route-table
=========================================== ===========================================
Dest Prefix Type Proto Dest Prefix Type Proto
Next Hop[Interface Name] Next Hop[Interface Name]
------------------------------------------- -------------------------------------------
40.1.1.1/32 Remote BGP VPN 40.2.2.2/32 Remote OSPF
10.0.0.6 (tunneled) 10.3.5.3
40.3.3.3/32 Remote BGP VPN 40.3.3.3/32 Remote OSPF
10.0.0.2 (tunneled) 10.3.5.3
=========================================== ===========================================
Result: nh = 10.3.5.3
Alcatel-Lucent – Internal
40 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
grt-lookup
enable-grt Double lookup and selection of VRF/GRT route:
exit
exit
destination IP is 40.3.3.3
VRF GRT
A:PE5# show router 100 route-table A:PE5# show router route-table
=========================================== ===========================================
Dest Prefix Type Proto Dest Prefix Type Proto
Next Hop[Interface Name] Next Hop[Interface Name]
------------------------------------------- -------------------------------------------
40.1.1.1/32 Remote BGP VPN 40.2.2.2/32 Remote OSPF
10.0.0.6 (tunneled) 10.3.5.3
40.3.3.3/32 Remote BGP VPN 40.3.3.3/32 Remote OSPF
10.0.0.2 (tunneled) 10.3.5.3
=========================================== ===========================================
Alcatel-Lucent – Internal
41 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
Since a VRF match is preferred to GRT, if the VRF has default routes or
comprehensive routes then the GRT will never be used.
- more specific routes (e.g. 40.1.2.3/24) in the VRF are still preferred
*A:PE5# show router 100 route-table A:PE2# show router 100 route-table
--------------------------------------- ---------------------------------------
10.0.0.0/8 Remote Static 10.0.0.0/8 Remote BGP VPN
Black Hole 10.0.0.5 (tunneled)
Alcatel-Lucent – Internal
42 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
grt-lookup
enable-grt Double lookup and selection of VRF/GRT route:
static-route 40.0.0.0/8 grt
exit destination IP is 40.1.1.1
exit
VRF GRT
A:PE5# show router 100 route-table A:PE5# show router route-table
=========================================== ===========================================
Dest Prefix Type Proto Dest Prefix Type Proto
Next Hop[Interface Name] Next Hop[Interface Name]
------------------------------------------- -------------------------------------------
0.0.0.0/0 Remote BGP VPN 40.2.2.2/32 Remote OSPF
10.0.0.6 (tunneled) 10.3.5.3
40.0.0.0/8 Remote Static 40.3.3.3/32 Remote OSPF
Black Hole 10.3.5.3
40.1.1.1/32 Remote BGP VPN ===========================================
10.0.0.6 (tunneled)
40.3.3.3/32 Remote BGP VPN
10.0.0.2 (tunneled)
===========================================
No result in GRT
Alcatel-Lucent – Internal
43 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
grt-lookup
enable-grt Double lookup and selection of VRF/GRT route:
static-route 40.0.0.0/8 grt
exit destination IP is 40.2.2.2
exit
VRF GRT
A:PE5# show router 100 route-table A:PE5# show router route-table
=========================================== ===========================================
Dest Prefix Type Proto Dest Prefix Type Proto
Next Hop[Interface Name] Next Hop[Interface Name]
------------------------------------------- -------------------------------------------
0.0.0.0/0 Remote BGP VPN 40.2.2.2/32 Remote OSPF
10.0.0.6 (tunneled) 10.3.5.3
40.0.0.0/8 Remote Static 40.3.3.3/32 Remote OSPF
Black Hole 10.3.5.3
40.1.1.1/32 Remote BGP VPN ===========================================
10.0.0.6 (tunneled)
40.3.3.3/32 Remote BGP VPN
10.0.0.2 (tunneled)
===========================================
Result in GRT: nh = 10.3.5.3
Alcatel-Lucent – Internal
44 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
grt-lookup
enable-grt Double lookup and selection of VRF/GRT route:
static-route 40.0.0.0/8 grt
exit destination IP is 40.3.3.3
exit
VRF GRT
A:PE5# show router 100 route-table A:PE5# show router route-table
=========================================== ===========================================
Dest Prefix Type Proto Dest Prefix Type Proto
Next Hop[Interface Name] Next Hop[Interface Name]
------------------------------------------- -------------------------------------------
0.0.0.0/0 Remote BGP VPN 40.2.2.2/32 Remote OSPF
10.0.0.6 (tunneled) 10.3.5.3
40.0.0.0/8 Remote Static 40.3.3.3/32 Remote OSPF
Black Hole 10.3.5.3
40.1.1.1/32 Remote BGP VPN ===========================================
10.0.0.6 (tunneled)
40.3.3.3/32 Remote BGP VPN
10.0.0.2 (tunneled)
===========================================
Result in GRT: nh = 10.3.5.3
Alcatel-Lucent – Internal
45 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from VPRN to base routing
- second lookup in GRT is still performed, with VRF result taking precedence
Alcatel-Lucent – Internal
46 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from base routing to VPRN
To allow data flowing from base routing context to VPRN, routing information
must be made available into the GRT.
As usual, the flow of the routing information (control plane) is in the opposite
direction than the flow of the user packets (data plane).
A new protocol is introduced to export routes from VPRN into GRT: vpn-leak.
*A:PE5# configure router
The vpn-lean “protocol” may be used in the policy-options
begin
routing policies in GRT to inject routes policy-statement "export-vpn"
exported from the VPRN. entry 10
from
protocol vpn-leak
exit
Control plane action accept
exit
exit
Data plane exit
commit
exit
ospf
VRF GRT asbr
export "export-vpn"
exit
Alcatel-Lucent – Internal
48 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from base routing to VPRN
Alcatel-Lucent – Internal
49 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Allowing data from base routing to VPRN
The routes are now available in the global routing table; they are recognizable
as leaked in the injecting router.
*A:PE5# show router route-table
===============================================================================
Route Table (Router: Base)
===============================================================================
Of course the addresses exported to GRT must be globally unique, i.e. they
can’t be used in the GRT (or be leaked to the GRT by another VPRN).
The default preference for vpn-leak protocol is 180, worse than any normal GRT routing protocol; so,
in case of conflict between a GRT-originated route and a VRF-leaked route, the GRT would win.
Even so, a more spcific route would still be preferred over a more general route (e.g. a /32 vs a /24).
Alcatel-Lucent – Internal
50 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Identifying the origin VPRN of a leaked route
There is no easy command to identify the VPRN a route was leaked from.
===============================================================================
Route Table (Router: Base)
===============================================================================
Dest Prefix Type Proto Age Pref
Next Hop[Interface Name] Metric
-------------------------------------------------------------------------------
20.3.10.10/32 Remote VPN Leak 00h19m14s 180
10.0.0.6 (tunneled) 0
20.4.10.10/32 Remote VPN Leak 00h00m16s 180
10.0.0.6 (tunneled) 0
20.5.10.10/32 Remote VPN Leak 00h11m27s 180
10.0.0.6 (tunneled) 0
20.6.10.10/32 Remote VPN Leak 00h27m25s 180
10.0.0.6 (tunneled) 0
20.9.10.10/32 Remote VPN Leak 00h13m03s 180
Offending 10.0.0.6
routes: (tunneled)
(but no clue where they come from) 0
172.16.0.10/32 Remote VPN Leak 00h00m16s 180
10.0.0.6 (tunneled) 0
172.16.60.0/24 Remote VPN Leak 00h00m16s 180
10.0.0.6 (tunneled) 0
-------------------------------------------------------------------------------
No. of Routes: 7
===============================================================================
Alcatel-Lucent – Internal
51 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Identifying the origin VPRN of a leaked route
===============================================================================
FIB Display
===============================================================================
Prefix Protocol
NextHop
-------------------------------------------------------------------------------
172.16.0.10/32 VPN_LEAK
10.0.0.6 (VPRN Label:131059 Transport:LDP)
172.16.60.0/24 VPN_LEAK
10.0.0.6 (VPRN Label:131059 Transport:LDP)
A:PE5# show router bgp routes vpn-ipv4 172.16.0.10/24
-------------------------------------------------------------------------------
===============================================================================
Total Entries : 2 BGP Router ID:10.0.0.5 AS:999 Local AS:999
-------------------------------------------------------------------------------
===============================================================================
===============================================================================
Legend -
Status codes : u - used, s - suppressed, h - history, d - decayed, * - valid
Origin codes : i - IGP, e - EGP, ? - incomplete, > - best
===============================================================================
BGP VPN-IPv4 Routes
===============================================================================
Flag Network LocalPref MED
Nexthop VPNLabel
As-Path
-------------------------------------------------------------------------------
...
u*>i 999:2400:172.16.0.10/24 100 None
10.0.0.6 131059
No As-Path
...
Alcatel-Lucent – Internal
52 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Leaking to Global Routing Table (GRT)
Summary
Examples of application:
No IPv6 (yet)
URPF is mutually exclusive to GRT leaking (they share the “second lookup”
resource)
Alcatel-Lucent – Internal
53 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
4
Network Address Translation
Another approach to GRT
Alcatel-Lucent – Internal
54 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Network Address Translation
Description
If the VPRN wants to grant access to the Internet to all its hosts, including
those without a globally routable IP address, NAT is necessary.
On the SR platform, MS-ISA MDA is necessary to perform NAT; the ISA MDA
must be equipped in an IOM3 to enable the NAT functionality.
Alcatel-Lucent – Internal
55 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Large Scale NAT
Configuration
===============================================================================
MDA Summary
===============================================================================
Slot Mda Provisioned Equipped Admin Operational
Mda-type Mda-type State State
-------------------------------------------------------------------------------
1 1 m5-1gb-sfp-b m5-1gb-sfp-b up up
2 isa-bb isa-ms up up
===============================================================================
Alcatel-Lucent – Internal
56 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Large Scale NAT
Configuration
• NAT group: one or more ISA MDA’s form a load-balancing resilient group
*A:PE5# configure isa
*A:PE5>config>isa# info
----------------------------------------------
nat-group 1 create
active-mda-limit 1
mda 1/2
no shutdown
exit
• Outside: configure the public address pool in the GRT; IP addresses used to
NAT the private hosts will come from the address ranges defined inside the
pool *A:PE5# configure router nat
*A:PE5>config>router>nat# info
----------------------------------------------
outside
pool "public-1" nat-group 1 type large-scale create
address-range 20.20.20.0 20.20.20.39 create
exit
address-range 20.20.20.100 20.20.20.103 create
exit
no shutdown
exit
exit
----------------------------------------------
Alcatel-Lucent – Internal
57 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Large Scale NAT
Configuration
===============================================================================
Route Table (Router: Base)
===============================================================================
Dest Prefix Type Proto Age Pref
Next Hop[Interface Name] Metric
-------------------------------------------------------------------------------
...
10.5.9.0/24 Local Local 04d02h40m 0
to-RR9 0
20.20.20.0/27 Remote Static 00h02m56s 5
NAT outside: group 1 member 1 1
20.20.20.32/29 Remote Static 00h02m56s 5
NAT outside: group 1 member 1 1
20.20.20.100/30 Remote Static 00h02m56s 5
NAT outside: group 1 member 1 1
192.168.0.1/32 Remote VPN Leak 04h21m05s 180
10.0.0.6 (tunneled) 0
...
-------------------------------------------------------------------------------
No. of Routes: 23
===============================================================================
The address ranges are automatically summarized to the largest possible subnets
Alcatel-Lucent – Internal
58 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Large Scale NAT
Configuration
• NAT policy: points to the pool and optionally defines limits, parameters etc.
*A:PE5# configure service nat
*A:PE5>config>service>nat# info
----------------------------------------------
nat-policy "policy-1" create
pool "public-1" router Base
exit
----------------------------------------------
• Inside: point to the policy and define the destination addresses that will
trigger NAT (if destination is not found in VRF table); this is similar to
“static-route grt” in GRT leaking
*A:PE5# configure service vprn 100
nat
inside
nat-policy "policy-1"
destination-prefix 0.0.0.0/0
exit
exit
Alcatel-Lucent – Internal
59 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Large Scale NAT
Configuration
===============================================================================
Route Table (Service: 100)
===============================================================================
Dest Prefix Type Proto Age Pref
Next Hop[Interface Name] Metric
-------------------------------------------------------------------------------
0.0.0.0/0 Remote Static 00h03m26s 5
NAT inside 1
...
* (of course this very brief overview skips 95% of the NAT features…)
Alcatel-Lucent – Internal
60 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
GRT leaking vs NAT
Comparison
Requires globally unique addresses inside the VPRN Allows private/non-unique addresses in the VPRN
Allows bidirectional communication GRT VPRN Only allows communication VPRN GRT (session
initiation)
Requires IOM3/IMM Requires IOM3 and MS-ISA
(with two extranets you could deploy GRT leaking and LS-NAT at the same time)
No IPv6 No IPv6
Alcatel-Lucent – Internal
61 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Lab practice
Alcatel-Lucent – Internal
62 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
GRT leaking and NAT
Group G = ……
Lab practice
10.0.0.9
172.16.0.10/32
PE5 GRT sys
l.b
CE10 VPRN GRT
i/f l.b
(VPRN 2G10) 172.16.60.10 2G00 VPRN
l.b 30.30.30.9
2G00
20.G.10.10 PE6 RR9
Alcatel-Lucent – Internal
63 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
5
Load balancing in the MPLS core
“Entropy” label, hashing on IP
Alcatel-Lucent – Internal
64 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Load balancing in the MPLS core
Load balancing VPRN traffic at the LSR
Since 7750 allocates VPRN service labels on a per-service basis (rather than
per-destination or per next-hop), hashing on the label stack at the LSR does not
provide efficient load balancing.
Two approaches are available in Release 8.0 to obtain more granular traffic
distribution:
hashing on IP header rather than (or in addition to) the label stack; this is an
extension to functionality introduced in Release 7.0.R4
configuration at system and router level; nothing to configure in VPRN
Alcatel-Lucent – Internal
65 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
SR1 7710 SRc-NG SR7/12 IOM1 IOM2 A/B
Load balancing at LSR 8.0.R1 C
ESS7/12
Hash label for “entropy” 7705 ESS1 ESS7/12
mixed-mode
IOM3 IMM D
CE CE
PE PE
LSR LSR
Alcatel-Lucent – Internal
73 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
SR1 7710 SRc-NG SR7/12 IOM1 IOM2 A/B
Load balancing at LSR 8.0.R1 C
ESS7/12
Hash label for “entropy” 7705 ESS1 ESS7/12
mixed-mode
IOM3 IMM D
IP header
As far as the ingress PE is 7x50, this range is distinct
hash
from all the service, transport and special labels. label
used for service
hashing label
Interop test shows that 7705 R3.0 accepts incoming transport
label
packets with 3 label stack (ignoring the hash label).
LSR LSR
Case-by case interop testing
may be required with other
vendors.
CE CE
PE PE
LSR LSR
Alcatel-Lucent – Internal
74 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
SR1 7710 SRc-NG SR7/12 IOM1 IOM2 A/B
Load balancing at LSR 8.0.R1 C
ESS7/12
Configuration 7705 ESS1 ESS7/12
mixed-mode
IOM3 IMM D
Alcatel-Lucent – Internal
75 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
SR1 7710 SRc-NG SR7/12 IOM1 IOM2 A/B
Load balancing at LSR 8.0.R1 C
ESS7/12
Configuration 7705 ESS1 ESS7/12
mixed-mode
IOM3 IMM D
“show service … base” command can be used to check if the hash label is
enabled on the VPRN service level:
A:PE6# show service id 100 base
...
Ignore NH Metric : Disabled
Hash Label : Enabled
Vrf Target : target:999:100
...
Alcatel-Lucent – Internal
76 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
6
MVPN
Alcatel-Lucent – Internal
77 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
MVPN 8.0.R4 or later
Preview
New MVPN features are expected for minor Release 8.0.R4 (or possibly later):
Alcatel-Lucent – Internal
78 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
MVPN 9.0 or later
Preview
• Aggregated PMSI
Alcatel-Lucent – Internal
79 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
MVPN 8.0.R4 or later
As usual with p2mp LSP, chassis mode C is required and IOM3 is preferred (better
performance).
Only automatic creation of p2mp LSP based on a template will be possible in the first
release, for both the inclusive and the selective PMSIs. Manual p2mp provisioning might
become available in a later release.
Sample configuration (based on 8.0 BETA, CLI details may differ in final release):
*A:sim3# configure service vprn 9999
mvpn
auto-discovery
c-mcast-signaling bgp
provider-tunnel
*A:sim3# configure router mpls
inclusive
path "loose"
rsvp
no shutdown
lsp-template mc-lsp
exit
no shutdown
lsp-template "mc-lsp" p2mp
exit
default-path "loose"
exit
no shutdown
selective
exit
rsvp
lsp-template mc-lsp
no shutdown
exit
exit
exit
exit
Alcatel-Lucent – Internal
80 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
MVPN 8.0.R4 or later
===============================================================================
MVPN 9999 configuration data
===============================================================================
signaling : Bgp auto-discovery : Enabled
UMH Selection : Hash-based intersite-shared : Disabled
vrf-import : N/A
vrf-export : N/A
vrf-target : N/A
C-Mcast Import RT : N/A
===============================================================================
Alcatel-Lucent – Internal
81 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
7
Miscellaneous
Auto-bind MPLS, eiBGP, GR helper at PE-CE, BFD at PE-CE for
OPSF
Alcatel-Lucent – Internal
82 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Miscellaneous
Auto-bind MPLS, eiBGP, GR helper and BFD at PE-CE
• eiBGP
• PE-CE adjacency
• Graceful Restart helper for OSPF and BGP when used as PE-CE protocols (GR helper
was already available in base router)
• BFD support for OSPF PE-CE adjacencies (already available for BGP and PIM)
• BGP next hop indirection
Alcatel-Lucent – Internal
83 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Auto-bind MPLS
Alcatel-Lucent – Internal
84 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Miscellaneous
Auto-bind MPLS
Auto-bind now has four options for automatic selection of the tunnel to BGP next-hop:
• auto-bind gre use automatic GRE tunnels
• auto-bind ldp use automatic LDP LSP to next-hop
• auto-bind rsvp-te choose automatically an existing TE LSP
• auto-bind mpls this was new in 7.0R3: choose an existing TE LSP if available,
otherwise use LDP
In all cases, if an explicit spoke-sdp is specified in the VPRN, it is always preferred over
automatically selected tunnels (even if the SDP is down the route becomes
inactive, there is no fallback to the automatic selection).
Alcatel-Lucent – Internal
85 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Miscellaneous
Auto-bind MPLS: configuration
*A:PE2>config>service>vprn# info
----------------------------------------------
route-distinguisher 999:102
auto-bind mpls
vrf-target target:999:100
interface "loopback" create
address 192.168.0.2/32
loopback
exit
interface "to-Epipe-red" create
address 192.168.103.2/24
ip-mtu 1500
spoke-sdp 24:103 create
exit
exit
static-route 192.168.0.102/31 black-hole
static-route 192.168.0.103/32 next-hop 192.168.103.9
spoke-sdp 25 create
shutdown
exit
spoke-sdp 26 create
exit
no shutdown
Alcatel-Lucent – Internal
86 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Miscellaneous
Auto-bind MPLS: checking
===============================================================================
Route Table (Service: 100)
===============================================================================
Dest Prefix Type Proto Age Pref
Next Hop[Interface Name] Metric
-------------------------------------------------------------------------------
192.168.0.1/32 this is via a specific Remote
SDP BGP VPN 00h05m02s 170
10.0.0.6 (tunneled) 0
(we know because we
192.168.0.2/32 Local Local 03d19h48m 0
loopback configured it!) 0
192.168.0.3/32 Remote BGP VPN 00h07m35s 170
10.0.0.3 (tunneled:RSVP:1) this is via 0
192.168.0.102/31 auto-boundRemote Static 21h12m54s 5
Black Hole 1
RSVP-TE LSP
192.168.0.103/32 Remote Static 00h26m35s 5
192.168.103.9 (tunnel id 1) 1
192.168.16.0/24 Remote BGP VPN 00h05m02s 170 Note that there is no active
10.0.0.6 (tunneled) 0 route to 10.0.0.5, because
192.168.101.0/24 Remote BGP VPN 00h05m02s 170
the spoke-sdp is down and
10.0.0.6 (tunneled) 0
192.168.103.0/24 Local Local 00h26m35s 0 there is no fallback to auto-
to-Epipe-red 0 selection
192.168.253.0/24 Remote BGP VPN 00h06m17s 170
10.0.0.4 (tunneled) this is via auto-bound 0
192.168.254.0/24 LDP LSP (we knowRemote BGP VPN 00h06m17s 170
10.0.0.4 (tunneled) because there is no SDP 0
-------------------------------------------------------------------------------
configured)
No. of Routes: 10
===============================================================================
Alcatel-Lucent – Internal
87 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Miscellaneous
Auto-bind MPLS: checking
Alcatel-Lucent – Internal
88 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Miscellaneous
Auto-bind MPLS: checking
show router tunnel-table can be useful to obtain information about the various
tunnels (LDP, RSVP, SDP) available for selection:
*A:PE2# show router tunnel-table
===============================================================================
Tunnel Table (Router: Base)
===============================================================================
Destination Owner Encap TunnelId Pref Nexthop Metric
-------------------------------------------------------------------------------
10.0.0.3/32 rsvp MPLS 1 7 10.2.3.3 100
10.0.0.3/32 ldp MPLS - 9 10.2.3.3 100
10.0.0.4/32 sdp MPLS 24 5 10.0.0.4 0
10.0.0.4/32 ldp MPLS - 9 10.2.4.4 100
10.0.0.5/32 sdp MPLS 25 5 10.0.0.5 0
10.0.0.5/32 ldp MPLS - 9 10.2.3.3 200
10.0.0.5/32 ldp MPLS - 9 10.2.4.4 200
10.0.0.6/32 sdp MPLS 26 5 10.0.0.6 0
10.0.0.6/32 ldp MPLS - 9 10.2.6.6 100
===============================================================================
Note how “Preference” and “Metric” are used for best tunnel selection:
* SDP has lowest (best) preference, followed by RSVP then by LDP
* if preference is the same, lowest metric is selected (ECMP is possible with LDP)
Alcatel-Lucent – Internal
89 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
eiBGP
Alcatel-Lucent – Internal
90 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
eiBGP
Description
In the situation below, while traffic from Bob to Alice can be balanced on both
links to PE2 and PE3, traffic from Alice to Bob will only use the PE3-CE7 link and
will never use the PE2-CE8 link, because the BGP-VPN route has a worse
preference than the eBGP route to CE8.
192.168.1.1
CE5
192.168.2.1
PE2 CE7
Bob
Alcatel-Lucent – Internal
91 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
eiBGP 7.0.R4
Description
When enabled, the VPRN PE disregards the different preference between eBGP
ipv4 and iBGP vpn-ipv4, obtraining routes with equal cost that can be both
active, therefore obtaining load balancing.
CE5
Alice
PE3
MPLS VPRN
PE2 CE8
Bob
Alcatel-Lucent – Internal
93 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
eiBGP 7.0.R4
Configuration
In order to achieve the desired behaviour, a few thing must be configured in the
VPRN service on the PE:
- different route-distinguisher must be used on PE2 and PE3, otherwise the
alternate BGP-VPN route via PE2 might be suppressed by BGP selection
- ECMP must be enabled
- eiBGP special treatment must be enabled
A:PE3# configure service vprn 100
ecmp 4
autonomous-system 999
route-distinguisher 999:103
auto-bind ldp
vrf-target target:999:100
...
bgp
eibgp-loadbalance
group "Customer"
type external
export "export-vpn"
neighbor 192.168.37.7
peer-as 65100
exit
exit
exit
Alcatel-Lucent – Internal
94 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
eiBGP 7.0.R4
Description
Result is that now there are two next-hops for the “Bob” subnet in PE3, one
directly to CE7 and one tunneled to PE2.
In order to avoid loops, the tunneled destination is not used for traffic coming
from a network tunnel, but only from a SAP or interface-terminated spoke SDP.
192.168.1.1
CE5
A:PE3# show router 100 route-table 192.168.2.0/24
----------------------------------------------------
Alice 192.168.2.0/24 Remote BGP VPN
10.0.0.2 (tunneled)
192.168.2.0/24 Remote BGP
192.168.37.7
PE3
MPLS VPRN
192.168.2.1
PE2 CE8
Bob
Alcatel-Lucent – Internal
95 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
eiBGP
Description
It works for traffic coming into a VPRN interface, either from a SAP or from a
spoke-SDP.
Instead, traffic coming from a VPRN peer is not forwarded to another VPRN peer
(to avoid loops).
CE5
Alice
PE3
MPLS VPRN
EPIPE
R4
spoke-SDP
PE2 CE8
Bob
Charlie
Alcatel-Lucent – Internal
96 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Graceful Restart helper on PE-CE link
Alcatel-Lucent – Internal
97 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Miscellaneous
PE-CE GR helper
Alcatel-Lucent – Internal
98 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
BFD for PE-CE OSPF adjacency
Alcatel-Lucent – Internal
99 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
BFD on PE-CE OSPF adjacency
Configuration
...
---------------------------------------------------------------
State
---------------------------------------------------------------
...
Oper Metric : 100 Bfd Enabled : Yes
...
Alcatel-Lucent – Internal
100 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
Next hop indirection on PE-CE
(thanks to Gilles and Dominique)
Alcatel-Lucent – Internal
101 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
BGP Fast NextHop Resolution
IGP NH1
PE CE (BGP NH)
IGP NH2
In Forwarding Plane
180K BGP Single Msg to NP to update mapping
Routes 180K routes re-converge in 200~300 ms
Pre-R8.0, not available for PE-CE routing. No CLI required (enabled by default).
Alcatel-Lucent – Internal
102 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
8
VPRN on 7705
Alcatel-Lucent – Internal
105 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
VPRN on 7705 SAR
Features
VPRN on 7705 will (of course) interop with 7750 and it should seamlessly
interop with other vendors’ IP-VPN as well.
Alcatel-Lucent – Internal
106 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
VPRN on 7705 SAR
Limitations
Alcatel-Lucent – Internal
108 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
VPRN on 7705 SAR
Configuration (BGP)
===============================================================================
BGP Summary
===============================================================================
Neighbor
AS PktRcvd InQ Up/Down State|Rcv/Act/Sent (Addr Family)
PktSent OutQ
-------------------------------------------------------------------------------
10.0.0.9
999 11073 0 16h26m30s 9/9/2 (VpnIPv4)
10996 0
===============================================================================
Alcatel-Lucent – Internal
109 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
VPRN on 7705 SAR
Scalability
VPRN services per node 16 yes MINOR: SVCMGR #1210 Reached the maximum
BGP RIB 32K no Can process at least 60K vpn-ipv4 routes in one VPRN
Data throughput ?
Alcatel-Lucent – Internal
110 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.
www.alcatel-lucent.com
www.alcatel-lucent.com
Alcatel-Lucent – Internal
111 | R8.0 VPRN features | April 2010 Proprietary – Use pursuant to Company instruction.