Documentos de Académico
Documentos de Profesional
Documentos de Cultura
BRKDCT-2840
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 2
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 3
Session Agenda
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 4
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 5
Layer 2 / 3 Clusters
Intra-Cluster node communications
Flow Types
Traditionally Layer2
Communications on Private and/or Public interfaces
IPv4 and/or IPv6 possible depending on clustering package used
Ability to prioritize interfaces
Client Access to Cluster
DNS/Active Directory resolution by clients
Shared Virtual IP for service discovery
Caching issues can inhibit Layer3 clustering
Client application can have logic to re-establish connections
Quorum considerations to avoid split-brain
Additional cluster nodes at alternate sites to achieve a majority node set (MNS)
Possible extensions such as ping-groups (Linux-HA) to have a quorum mechanism without
a member node
Shoot The Other Node In The Head topologies to resolve conflicts (STONITH)
Mechanisms to facilitate service restoration in another location
VMware Site Recovery Manager (SRM) is one example
Microsoft Server 2008 Layer 3 Clustering is another
BRKDCT-2840
Remapping of service to new IP/DNS entry
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 6
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 7
Layer 2 Risks
Session Agenda
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 10
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 11
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 12
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 13
L2TPv3 View
3 point to point links shown in 3 site solution
In layer2 environment, BPDUs must cross links and are used for loop
detection
In layer3 environment, point to point nature ideal for /30 subnets
Data plane rate limiting in L2 still needs protection
STP domains are shared between sites
L2TPv3 point to point tunnels
PE PE
CE CE
IP
CE
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 14
2.2.2.2 3.3.3.3
PE1 IP PE2
CE1 IPCore
Core CE2
gi8/1 gi8/1
gi9/3/1 192.168.3.2 gi9/3/1
VLAN50 gi8/1 gi8/2 VLAN50
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 15
* Example with SIP400 with SPA 2x1GE supported (12.2.33SRC IOS software)
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 16
IPSec
Edge Transport L2TPv3 Total
Header
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 17
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 18
VSS
VSS VSS
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 19
L2 Local Fiber
All links are port channels to Central VSS
BPDU Filtering
VSS VSS
VSS
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 20
EoMPLS is a pseudo-wire
PE PE
CE CE
MPLS
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 21
PE PE
CE CE
MPLS
CE
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 22
CE router CE router
CE switch CE switch
MPLS
Core
Yellow VFI
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 25
1.1.1.1 2.2.2.2
PE1 PE2
CE1 pos4/1
CE2
Self-Managed pos4/3
Self-Managed
gi3/0 MPLS
MPLSCore
Core gi4/4
VLAN100 pos3/0 pos3/1 VLAN100
PE3
gi4/2
3.3.3.3 CE2
VLAN100
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 26
CE1 CE2
Subnet
VLAN100 192.168.20.0/24 VLAN100
1.1.1.1 2.2.2.2
PE1 MPLS PE2
CE1 MPLSCore
Core CE2
pos4/1 pos4/3
gi3/0 gi4/4
VLAN100 pos3/0 pos3/1 VLAN100
PE3
gi4/2
3.3.3.3 CE2
VLAN100
l2 vfi VPLS-A manual
Create the Pseudo vpn id 56
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 29
MPLS MPLS
Edge Transport Total
Stack Header
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 30
Layer 3 Core
Intranet
WCore1 WCore2 ECore1 ECore2
WMC1 EMC1
DC Core Ten3/0/0 Ten3/0/0 DC Core
Po1
Po1
WAgg1 EAgg2
Po4 Ten4/0/0 Ten4/0/0 Po2 Po4
Po2
VPLS / EoMPLS
Po3 Po3 Po4 Domain Po4 Po3 Po3
Po2 Po2
Ten4/0/0 Ten4/0/0
Agg WAgg2 EAgg1 Agg
Po1 Ten3/0/0 Ten3/0/0
Po1
WMC2 EMC2
Access Access
Loss of Link/Node
Server Farm Server Farm
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 31
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 32
Layer 3
Layer 3 connections from DC Enterprise Core
Core to Enterprise Core
Aggregation switch L3
connected to DC Core
Hanging L3 links in diagram,
are to Metro Core switches DC Core
which are Ethernet over
MPLS links
Hanging L3 links are for
peering the DC Cores in Agg
each location in a point-to-
point scenario
Bidirectional forwarding detection (bfd)
interval 100 min_rx 100 multiplier 3
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 33
Ten3/0/0 Ten3/0/0
Ten4/0/0
Ten4/0/0 IGP Routing Process
connecting
MPLS PE’s
Ten4/0/0
Ten4/0/0
Ten3/0/0 Ten3/0/0
Metro Core Metro Core
L3 Links (10GE)
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 35
!
interface TenGigabitEthernet4/0/0
description MPLS Interface to local peer N-PE
mtu 1522
ip address 192.168.1.9 255.255.255.252
ip hello-interval eigrp 5 1
ip hold-time eigrp 5 3
ip authentication mode eigrp 5 md5
ip authentication key-chain eigrp 5 password
logging event link-status
load-interval 30
udld port disable
mls qos trust dscp
mpls ip
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 37
!
interface TenGigabitEthernet3/0/0
description MPLS Interface to peer N-PE in DC #2
mtu 1522
ip address 192.168.1.1 255.255.255.252
ip ospf network point-to-point
logging event link-status
load-interval 30
udld port disable
mls qos trust dscp
mpls ip
router ospf 1
log-adjacency-changes
nsf cisco
timers throttle spf 50 100 5000
timers lsa arrival 0
timers pacing flood 15
network 192.168.0.0 0.0.255.255 area 0
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 38
!
interface TenGigabitEthernet4/0/0
description MPLS Interface to local peer N-PE
mtu 1522
ip address 192.168.1.9 255.255.255.252
ip ospf network point-to-point
logging event link-status
load-interval 30
udld port disable
mls qos trust dscp
mpls ip
router ospf 1
log-adjacency-changes
nsf cisco
timers throttle spf 50 100 5000
timers lsa arrival 0
timers pacing flood 15
network 192.168.0.0 0.0.255.255 area 0
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 39
WestMetroCore2
Loopback0 IP Address = 192.168.255.251/32
Interface Te3/0/0 IP Address = 192.168.1.5/30
Interface Te4/0/0 IP Address = 192.168.1.10/30
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 40
EastMetroCore1
Loopback0 IP Address = 192.168.255.252/32
Interface Te3/0/0 IP Address = 192.168.1.2/30
Interface Te4/0/0 IP Address = 192.168.1.13/30
EastMetroCore2
Loopback0 IP Address = 192.168.255.253/32
Interface Te3/0/0 IP Address = 192.168.1.6/30
Interface Te4/0/0 IP Address = 192.168.1.14/30
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 41
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 42
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 43
Layer 3 Core
Intranet
DC Core
METRO CORE DC Core
PW – Pseudo Wires
Agg Agg
EoMPLS
Access Access
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 44
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 45
WestMetroCore1
!
interface Loopback0
description Loopback interface for PW peering
ip address 192.168.255.250 255.255.255.255
!
interface GigabitEthernet1/1
description WESTCORE:1/1 - EASTCORE:9/1
xconnect 192.168.255.252 250252 encapsulation mpls
!
interface GigabitEthernet2/1
description WESTCORE:1/2 - EASTCORE:8/1
xconnect 192.168.255.252 252250 encapsulation mpls
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 46
Layer 3 Core
Intranet
DC Core
METRO CORE DC Core
VFI
Agg Agg
PW – Pseudo Wires
Metro Core Metro Core
Access Access
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 47
DC Core
METRO CORE DC Core
Agg Agg
PW – Pseudo Wires
Metro Core Metro Core
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 48
DC Core
METRO CORE DC Core
VLAN
3700 Agg
Agg
PW – Pseudo Wires
Metro Core Metro Core
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 49
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 50
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 51
DC Core DC Core
VPLS / EoMPLS
Domain
Agg Agg
RSTP RSTP
X X X X
Metro Core Metro Core
Access Access
Without layer 2 link between Metro Switches there is a
loop. Each side has a “U” shape with Metro and Agg
switches. Broadcast storms.
L2 Links (GE or 10GE)
Server Farm Server Farm
L3 Links (GE or 10GE)
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 52
DC Core DC Core
Single L2
Single L2
MST Bridge
MST Bridge
VPLS / EoMPLS
MST Domain MST
Agg Agg
RSTP RSTP
Metro Core Metro Core
Access Access
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 53
Spanning-Tree
MST (802.1s) chosen to present Metro Cores as single
bridge
Red Layer 2 link is access port channel with a VLAN that
represents the MST0 instance to make the MST group
MST bridge priority set to 0 (Metro Core will be root of
Inter-DC VLANs)
Spanning tree root-guard enabled on Metro Cores toward
aggregation switches (protects in case the red MST link
fails)
Only inter-DC VLANs allowed on trunks to/from
aggregation switches Single L2
MST Bridge
Set spanning-tree vlan cost to set the priorities on the agg
switches links to metro core – will allow us to put some
VLANs on upper Metro Core, some on Lower by default
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 54
DC Core DC Core
Single L2
Single L2
MST Bridge
MST Bridge X
X VPLS / EoMPLS
MST Domain MST
X X
Agg Agg
X RSTP X X
RSTP X
X X X X
Metro Core Metro Core
Access Access
interface Port-channel4
description Port Channel to WestMetroCore2
spanning-tree vlan 3700,3704,3712,3716 cost 8
Server Farm Server Farm
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 55
MST Configuration
Configuration on Primary N-PE (root of Inter-DC
VLANs):
spanning-tree mode mst
spanning-tree extend system-id
!
spanning-tree mst configuration
name WESTDC
revision 50
!
spanning-tree mst 0 priority 0
!
interface Port-channel5
description port-channel to westagg1
switchport
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 3700
switchport mode trunk
storm-control broadcast level 1.00
storm-control multicast level 1.00
spanning-tree guard root
!
interface Port-channel6
description port-channel to peer N-PE
switchport
switchport mode access
BRKDCT-2840 !
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 56
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 57
Storm Control
Traffic storms when packets flood the LAN
Traffic storm control feature prevents LAN ports from being
disrupted by broadcast or multicast flooding
Rate limiting for unknown unicast (UU) must be handled at Data
Center aggregation; unknown unicast flood rate-limiting (UUFRL):
mls rate-limit layer2 unknown rate-in-pps [burst-size]
Storm Control is configured as a percentage of the link that storm
traffic is allowed to use.
storm-control broadcast level 1.00 (% of b/w may vary – need to
baseline)
storm-control multicast level 1.00 (% of b/w may vary – need to
baseline)
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 58
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 59
Server Farm
Server Farm
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 62
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 63
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 64
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 65
VLAN A VLAN A
10.1.1.1 HSRP Group 1 10.1.1.1 HSRP Group 1
Priority 140 and 130 Priority 120 and 110
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 67
VLAN A VLAN A
10.1.1.1 HSRP Group 1 10.1.1.1 HSRP Group 1
Priority 140 and 130 Priority 120 and 110
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 69
DNS:
www-hr.acme.com -> 10.1.1.100
www-news.acme.com -> 10.1.2.100
VLAN A VLAN A
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 71
DNS:
www-hr.acme.com -> 10.1.1.100
10.1.2.100
VLAN A VLAN A
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 73
CPOC Tested
Failover Numbers
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 74
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 75
xx
Vertical Rail Pull 0 0
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 76
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 77
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 79
Core-MC Shut 0 0
Core-Core with 0 0
Core-MC Shut
Core Sup Pull 734mSec 0
Core Reload 0 0
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 80
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 81
Recommendations
Recommended Reading:
MPLS and VPN Architectures, Volume II
by Jim Guichard
Network Virtualization by Victor Moreno
Check the Recommended Reading flyer
for suggested books
Related technology breakouts:
BRKAGG-2000 Implementation and
utilization of Layer 2 VPN technologies
TECAGG-2003 Layer 2 Virtual Private
Networks – Converged IP/MPLS Network
NSITE is compiling test results for both
the MST N-PE and EEM Solution
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 83
BRKDCT-2840
14688_05_2008_c1 © 2008 Cisco Systems, Inc. All rights reserved. Cisco Public 84