© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 MPLS VPN Implementation Troubleshooting MPLS VPNs.

Slides:



Advertisements
Similar presentations
MPLS VPN.
Advertisements

Identifying MPLS Applications
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v MPLS TE Overview Configuring MPLS TE on Cisco IOS Platforms.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v Frame-Mode MPLS Implementation on Cisco IOS Platforms Troubleshooting Frame-Mode MPLS on Cisco.
Release 5.1, Revision 0 Copyright © 2001, Juniper Networks, Inc. Advanced Juniper Networks Routing Module 9: Static Routes & Routing Table Groups.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v MPLS VPN Technology Introducing the MPLS VPN Routing Model.
BGP Overview Processing BGP Routes.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 MPLS VPN Implementation Configuring BGP as the Routing Protocol Between PE and CE Routers.
1 IP Forwarding Relates to Lab 3. Covers the principles of end-to-end datagram delivery in IP networks.
IP Forwarding Relates to Lab 3.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—8-1 MPLS TE Overview Understanding MPLS TE Components.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 Module Summary The VRF table is a virtual routing and forwarding instance separating sites.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 MPLS VPN Implementation Configuring VRF Tables.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—2-1 Label Assignment and Distribution Introducing Convergence in Frame-Mode MPLS.
Basic IP Traffic Management with Access Lists
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—3-1 Frame-Mode MPLS Implementation on Cisco IOS Platforms Introducing CEF Switching.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—2-1 BGP Transit Autonomous Systems Monitoring and Troubleshooting IBGP in a Transit AS.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—2-1 Label Assignment and Distribution Introducing Typical Label Distribution in Frame-Mode MPLS.
111 © 2003 Cisco Systems, Inc. All rights reserved. Half Duplex VRFs, 12/03 HALF DUPLEX VRFs: A SCALABLE HUB & SPOKE IMPLEMENTATION DECEMBER 2003.
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—4-1 Managing IP Traffic with ACLs Configuring IP ACLs.
Introducing MPLS Labels and Label Stacks
CS Summer 2003 Lecture 14. CS Summer 2003 MPLS VPN Architecture MPLS VPN is a collection of sites interconnected over MPLS core network. MPLS.
MPLS and Traffic Engineering
© 2006 Cisco Systems, Inc. All rights reserved. Implementing Secure Converged Wide Area Networks (ISCW) Module 4: Frame Mode MPLS Implementation.
© 2006 Cisco Systems, Inc. All rights reserved. Implementing Secure Converged Wide Area Networks (ISCW) Module 4: Frame Mode MPLS Implementation.
© 2009 Cisco Systems, Inc. All rights reserved. ROUTE v1.0—5-1 Implementing Path Control Lab 5-1 Debrief.
MPLS L3 and L2 VPNs Virtual Private Network –Connect sites of a customer over a public infrastructure Requires: –Isolation of traffic Terminology –PE,
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—7-1 MPLS Traffic Engineering Monitoring Basic MPLS TE on Cisco IOS.
© 2006 Cisco Systems, Inc. All rights reserved. ICND v2.3—3-1 Determining IP Routes Enabling RIP.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5#-1 MPLS VPN Implementation Configuring OSPF as the Routing Protocol Between PE and CE Routers.
1 IP Forwarding Relates to Lab 3. Covers the principles of end-to-end datagram delivery in IP networks.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—7-1 Integrating Internet Access with MPLS VPNs Implementing Internet Access as a Separate VPN.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 MPLS VPN Implementation Configuring Small-Scale Routing Protocols Between PE and CE Routers.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—4-1 MPLS VPN Technology Forwarding MPLS VPN Packets.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 MPLS VPN Implementation Using MPLS VPN Mechanisms of Cisco IOS Platforms.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—3-1 Frame-Mode MPLS Implementation on Cisco IOS Platforms Configuring Frame-Mode MPLS on Cisco.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—3-1 Frame-Mode MPLS Implementation on Cisco IOS Platforms Monitoring Frame-Mode MPLS on Cisco.
1 © 2003 Cisco Systems, Inc. All rights reserved. MPLS VPN Inter-AS, 12/03 INTER-AUTONOMOUS SYSTEM MPLS VPN December 2003.
Connecting Networks © 2004 Cisco Systems, Inc. All rights reserved. Defining the IP Packet Delivery Process INTRO v2.0—4-1.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—1-1 MPLS Concepts Introducing Basic MPLS Concepts.
Lab MPLS Basic Configuration Last Update Copyright 2011 Kenneth M. Chipps Ph.D. 1.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA 2 Module 9 Basic Router Troubleshooting.
Chapter 9. Implementing Scalability Features in Your Internetwork.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—6-1 Complex MPLS VPNs Introducing Overlapping VPNs.
1 What Are Access Lists? –Standard –Checks Source address –Generally permits or denies entire protocol suite –Extended –Checks Source and Destination address.
© 2006 Cisco Systems, Inc. All rights reserved. FRAME MODE MPLS IMPLEMENTATION.
1MPLS QOS 10/00 © 2000, Cisco Systems, Inc. rfc2547bis VPN Alvaro Retana Alvaro Retana
© 2002, Cisco Systems, Inc. All rights reserved. 1 Routing Overview.
MPLS VPNs by Richard Bannister. The Topology The next two slides display both the physical and logical topology of our simple example network –Please.
MPLS Concepts Introducing Basic MPLS Concepts. Outline Overview What Are the Foundations of Traditional IP Routing? Basic MPLS Features Benefits of MPLS.
Support for RSVP in Layer 3 VPNs draft-davie-tsvwg-rsvp-l3vpn-01.txt Bruce Davie François le Faucheur Ashok Narayanan Cisco Systems.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 6: Static Routing Routing and Switching Essentials.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—6-1 Scaling Service Provider Networks Scaling IGP and BGP in Service Provider Networks.
 RIP — A distance vector interior routing protocol  IGRP — The Cisco distance vector interior routing protocol (not used nowadays)  OSPF — A link-state.
+ Routing Concepts 1 st semester Objectives  Describe the primary functions and features of a router.  Explain how routers use information.
Route Selection Using Policy Controls
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—5-1 Customer-to-Provider Connectivity with BGP Connecting a Multihomed Customer to a Single Service.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—2-1 BGP Transit Autonomous Systems Forwarding Packets in a Transit AS.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—1-1 BGP Overview Understanding BGP Path Attributes.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—1-1 BGP Overview Monitoring and Troubleshooting BGP.
BGP Transit Autonomous System
© 2006 Cisco Systems, Inc. All rights reserved. Implementing Secure Converged Wide Area Networks (ISCW) Module 4: Frame Mode MPLS Implementation.
IP Forwarding Covers the principles of end-to-end datagram delivery in IP networks.
Chapter 2: Static Routing
IP Forwarding Relates to Lab 3.
Chapter 2: Static Routing
IP Forwarding Relates to Lab 3.
IP Forwarding Relates to Lab 3.
Networking and Network Protocols (Part2)
IP Forwarding Relates to Lab 3.
Presentation transcript:

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 MPLS VPN Implementation Troubleshooting MPLS VPNs

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-2 Overview Identifying Preliminary Steps in MPLS VPN Troubleshooting Verifying the Routing Information Flow Validating CE-to-PE Routing Information Flow Validating PE-to-PE Routing Information Flow Validating PE-to-CE Routing Information Flow Identifying the Issues When Verifying the Data Flow Validating CEF Status Validating the End-to-End LSP Validating the LFIB status Summary Outline

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-3 Preliminary Steps in MPLS VPN Troubleshooting Perform basic MPLS troubleshooting: Is CEF enabled? Are labels for IGP routes generated and propagated? Are large labeled packets propagated across the MPLS backbone (maximum transmission unit issues)?

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-4 Verifying the Routing Information Flow Verify the routing information flow: Are CE routes received by a PE router? Are routes redistributed into MP-BGP with proper extended communities? Are VPNv4 routes propagated to other PE routers? Is the BGP route selection process working correctly? Are VPNv4 routes inserted into VRFs on other PE routers? Are VPNv4 routes redistributed from BGP into the PE-CE routing protocol? Are IPv4 routes propagated to other CE routers?

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-5 Are CE routes received by the PE router? Verify with the show ip route vrf vrf-name command on PE-1. Perform traditional routing protocol troubleshooting if needed. Validating CE-to-PE Routing Information Flow

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-6 Are routes redistributed into MP-BGP with proper extended communities? Verify with the show ip bgp vpnv4 vrf vrf-name ip-prefix command on PE-1. Troubleshoot with debug ip bgp commands. Validating PE-to-PE Routing Information Flow

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-7 Are VPNv4 routes propagated to other PE routers? Verify with the show ip bgp vpnv4 all ip-prefix/length command. Troubleshoot PE-to-PE connectivity with traditional BGP troubleshooting tools. Validating PE-to-PE Routing Information Flow (Cont.)

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-8 Is the BGP route selection process working correctly on PE-2? Verify with the show ip bgp vpnv4 vrf vrf-name ip-prefix command. Change local preference or weight settings if needed. Do not change MED if you are using IGP-BGP redistribution on PE-2. Validating PE-to-PE Routing Information Flow (Cont.)

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-9 Are VPNv4 routes inserted into VRFs on PE-2? Verify with the show ip route vrf command. Troubleshoot with the show ip bgp ip-prefix and show ip vrf detail command. Perform additional BGP troubleshooting if needed. Validating PE-to-PE Routing Information Flow (Cont.)

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-10 Are VPNv4 routes redistributed from BGP into the PE-CE routing protocol? Verify redistribution configuration—is the IGP metric specified? Perform traditional routing protocol troubleshooting. Validating PE-to-PE Routing Information Flow (Cont.)

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-11 Are VPNv4 routes propagated to other CE routers? Verify with the show ip route command on CE-Spoke. Alternatively, do CE-Spokes have a default route toward PE-2? Perform traditional routing protocol troubleshooting if needed. Validating PE-to-CE Routing Information Flow

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-12 Verifying the Data Flow Verify proper data flow: Is CEF enabled on the ingress PE router interface? Is the CEF entry correct on the ingress PE router? Is there an end-to-end label switched path tunnel (LSP tunnel) between PE routers? Is the LFIB entry on the egress PE router correct?

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-13 Is CEF enabled on the ingress PE router interface? Verify with the show cef interface command. MPLS VPN needs CEF enabled on the ingress PE router interface for proper operation. CEF might become disabled because of additional features deployed on the interface. Validating CEF Status

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-14 Router#show cef interface serial 1/0.20 Serial1/0.20 is up (if_number 18) Internet address is /30 ICMP redirects are always sent Per packet loadbalancing is disabled IP unicast RPF check is disabled Inbound access list is not set Outbound access list is not set IP policy routing is disabled Interface is marked as point to point interface Hardware idb is Serial1/0 Fast switching type 5, interface type 64 IP CEF switching enabled IP CEF VPN Fast switching turbo vector VPN Forwarding table "SiteA2" Input fast flags 0x1000, Output fast flags 0x0 ifindex 3(3) Slot 1 Slot unit 0 VC -1 Transmit limit accumulator 0x0 (0x0) IP MTU 1500 Validating CEF Status: show cef interface

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-15 Is the CEF entry correct on the ingress PE router? Display the CEF entry with the show ip cef vrf vrf-name ip-prefix/length detail command. Verify the label stack in the CEF entry. Validating CEF Status

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-16 Is there an end-to-end LSP tunnel between PE routers? Check summarization issues—BGP next hop should be reachable as host route. Quick check—if TTL propagation is disabled, the trace from PE-2 to PE-1 should contain only one hop. If needed, check LFIB values hop by hop. Check for MTU issues on the path—MPLS VPN requires a larger label header than pure MPLS. Validating the End-to-End Label Switched Path

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-17 Is the LFIB entry on the egress PE router correct? Find out the second label in the label stack on PE-2 with the show ip cef vrf vrf-name ip-prefix detail command. Verify correctness of LFIB entry on PE-1 with the show mpls forwarding vrf vrf-name value detail command. Validating the LFIB Status

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-18 Summary Divide MPLS troubleshooting into two main steps: –Verify routing information flow. –Verify proper data flow. Validate CE-to-PE routing information flow by checking the routing information exchange from CE routers to PE routers. Use the show ip bgp vpnv4 vrf vrf-name ip-prefix command to validate PE-to-PE routing information flow. Verify that routes are redistributed back into the CE routing protocol on the PE route and propagated toward CE routers to validate PE-to-CE routing information flow.

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-19 Summary (Cont.) Verify data flow systematically, starting at the ingress CE router and moving to the egress CE router. Verify that CEF and LSP switching are operational. Use the show cef interface command to verify the CEF status. When validating the end-to-end LSP, verify that there is an end-to-end LSP tunnel between PE routers. To validate the LFIB status, review the contents of the LFIB on the egress PE router in comparison to the second label in the label stack on the ingress PE router.

© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-20