jueves, 5 de mayo de 2016

DMVPN


R1
interface Tunnel0
 ip address 192.168.0.1 255.255.255.0
 ip mtu 1400
 ip nhrp authentication cisco
 ip nhrp map multicast 203.0.0.2
 ip nhrp map 192.168.0.3 203.0.0.2
 ip nhrp network-id 100
 ip nhrp nhs 192.168.0.3
 ip tcp adjust-mss 1360
 ip ospf network broadcast
 ip ospf priority 0
 tunnel source Serial2/0
 tunnel mode gre multipoint

router ospf 1
 network 1.1.1.0 0.0.0.255 area 0
 network 192.168.0.0 0.0.0.255 area 0


R3
interface Tunnel0
 ip address 192.168.0.3 255.255.255.0
 no ip redirects
 ip mtu 1400
 ip nhrp authentication cisco
 ip nhrp map multicast dynamic
 ip nhrp network-id 100
 ip tcp adjust-mss 1360
 ip ospf network broadcast
 ip ospf priority 5
 tunnel source Serial2/0
 tunnel mode gre multipoint

end

router ospf 1
 network 3.3.3.0 0.0.0.255 area 0
 network 192.168.0.0 0.0.0.255 area 0


R1#show ip nhrp  
192.168.0.1/32 via 192.168.0.1
   Tunnel0 created 00:00:38, expire 01:59:21
   Type: dynamic, Flags: router unique local
   NBMA address: 201.0.0.1
    (no-socket)
192.168.0.2/32 via 192.168.0.2
   Tunnel0 created 00:00:38, expire 01:59:21
   Type: dynamic, Flags: router used nhop
   NBMA address: 202.0.0.2
192.168.0.3/32 via 192.168.0.3
   Tunnel0 created 00:14:58, never expire
   Type: static, Flags: used
   NBMA address: 203.0.0.2

R1#show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
       a - application route
       + - replicated route, % - next hop override

Gateway of last resort is 201.0.0.2 to network 0.0.0.0

S*    0.0.0.0/0 [1/0] via 201.0.0.2
      1.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
C        1.1.1.0/24 is directly connected, Loopback0
L        1.1.1.1/32 is directly connected, Loopback0
      2.0.0.0/32 is subnetted, 1 subnets
O        2.2.2.2 [110/1001] via 192.168.0.2, 00:15:02, Tunnel0
      3.0.0.0/32 is subnetted, 1 subnets
O        3.3.3.3 [110/1001] via 192.168.0.3, 00:15:12, Tunnel0
      192.168.0.0/24 is variably subnetted, 2 subnets, 2 masks
C        192.168.0.0/24 is directly connected, Tunnel0
L        192.168.0.1/32 is directly connected, Tunnel0
      201.0.0.0/24 is variably subnetted, 2 subnets, 2 masks
C        201.0.0.0/30 is directly connected, Serial2/0
L        201.0.0.1/32 is directly connected, Serial2/0

viernes, 12 de junio de 2015

PPPoE

!
! Cliente1
hostname Cust1
interface Ethernet0/0
pppoe enable group global
pppoe-client dial-pool-number 1
no shut
interface Dialer1
mtu 1492
ip address negotiated
encapsulation ppp
dialer pool 1
ppp authentication chap callin
ppp chap hostname Cust1
ppp chap password 0 ciscopppoe
ip route 0.0.0.0 0.0.0.0 Dialer1

!Server
hostname ISP
username Cust1 password 0 ciscopppoe
bba-group pppoe global
virtual-template 1
interface Ethernet0/0
pppoe enable group global
no shut
interface Virtual-Template1
ip address 10.0.0.254 255.255.255.0
mtu 1492
peer default ip address pool PPPoEPOOL
ppp authentication chap callin
ip local pool PPPoEPOOL 10.0.0.1 10.0.0.10
ip forward-protocol nd

Cust1#sh ip int br | se up
Ethernet0/0                   unassigned      YES NVRAM  up                    up    
Dialer1                         10.0.0.1           YES IPCP         up                    up    
Virtual-Access1            unassigned      YES unset         up                    up    
Virtual-Access2            unassigned      YES unset         up                    up    


Cust1#sh interfaces dialer 1
Dialer1 is up, line protocol is up (spoofing)
  Hardware is Unknown
  Internet address is 10.0.0.1/32
  MTU 1492 bytes, BW 56 Kbit/sec, DLY 20000 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation PPP, LCP Closed, loopback not set


Cust1#show pppoe session
     1 client session

Uniq ID  PPPoE  RemMAC          Port                    VT  VA         State
                    SID  LocMAC                                      VA-st      Type
    N/A           55  aabb.cc00.0200  Et0/0                   Di1 Vi2        UP    
                            aabb.cc00.0100                              UP  



jueves, 30 de abril de 2015

IP SLA


IP SLA



Se va a hacer un tracking del router R4 al ip 5.5.5.5 ( loopback R5) aplicada a la ruta estática a la 3.3.3.0

hostname R4
track 2 ip sla 2 reachability
interface Loopback0
 ip address 4.4.4.4 255.255.255.0
!
interface FastEthernet0/0
 ip address 192.168.2.4 255.255.255.0
 duplex full
!
interface Serial1/0
 ip address 192.168.4.4 255.255.255.0
 serial restart-delay 0
ip route 3.3.3.0 255.255.255.0 192.168.4.5 track 2
ip route 3.3.3.0 255.255.255.0 192.168.2.3 10
ip route 5.5.5.0 255.255.255.0 192.168.4.5

ip sla 2
 icmp-echo 5.5.5.5
 frequency 10
ip sla schedule 2 life forever start-time now

miércoles, 29 de abril de 2015

PPPoE Multilink

PPPoe  Multilink







hostname R1
interface Loopback0
 ip address 1.1.1.1 255.255.255.0
!
interface FastEthernet0/0
 no ip address
 pppoe enable group global
 pppoe-client dial-pool-number 1
!
interface Dialer1
 ip address negotiated
 ip mtu 1454
 encapsulation ppp
 dialer pool 1
 dialer-group 1
 ppp authentication chap callin
 ppp chap hostname cisco
 ppp chap password 0 cisco
!
router ospf 1
 network 1.1.1.0 0.0.0.255 area 0
 network 192.168.1.0 0.0.0.255 area 0


hostname R2
!
username cisco password 0 cisco

bba-group pppoe global
 virtual-template 1
!
bba-group pppoe test
 virtual-template 1
!
interface Loopback0
 ip address 2.2.2.2 255.255.255.0
!
interface Multilink1
 ip address 172.19.11.2 255.255.255.0
 ppp multilink
 ppp multilink group 1
!
interface FastEthernet0/0
 no ip address
 pppoe enable group test
!
interface Serial1/0
 no ip address
 encapsulation ppp
 ppp multilink
 ppp multilink group 1
!
interface Serial1/1
 no ip address
 encapsulation ppp
 ppp multilink
 ppp multilink group 1
!
interface Serial1/2
 no ip address
 encapsulation ppp
 ppp multilink
 ppp multilink group 1
!
interface Serial1/3
 no ip address
 encapsulation ppp
 ppp multilink
 ppp multilink group 1
!
interface Virtual-Template1
 mtu 1454
 ip address 192.168.1.2 255.255.255.0
 peer default ip address pool test1
 ppp authentication chap
!
router ospf 1
 log-adjacency-changes
 network 0.0.0.0 255.255.255.255 area 0
!
ip local pool test1 192.168.1.10 192.168.1.19



hostname R3
!
interface Loopback0
 ip address 3.3.3.3 255.255.255.0
!
interface Multilink1
 ip address 172.19.11.3 255.255.255.0
 ppp multilink
 ppp multilink group 1
!
interface FastEthernet0/0
 ip address 192.168.2.3 255.255.255.0
!
interface FastEthernet0/1
 no ip address
 shutdown
!
interface Serial1/0
 no ip address
 encapsulation ppp
 serial restart-delay 0
 ppp multilink
 ppp multilink group 1
!
interface Serial1/1
 no ip address
 encapsulation ppp
 ppp multilink
 ppp multilink group 1
!
interface Serial1/2
 no ip address
 encapsulation ppp
 ppp multilink
 ppp multilink group 1
!
interface Serial1/3
 no ip address
 encapsulation ppp
 ppp multilink
 ppp multilink group 1
!
interface Group-Async1
 physical-layer async
 no ip address
 encapsulation ppp
 ppp multilink
!
router ospf 1
 network 0.0.0.0 255.255.255.255 area 0
!

domingo, 28 de diciembre de 2014

DMVPN VRF









    DMVPN :
Generic Routing Encapsulation GRE
Next-Hop Resolution Protocol NHRP
Dynamic routing protocols
IPsec encryption protocols

R1:
!
ip vrf voice
 rd 1:1
 route-target export 1:1
 route-target import 1:1

crypto isakmp policy 10
 hash md5
 authentication pre-share
crypto isakmp key cisco123 address 0.0.0.0 0.0.0.0
crypto ipsec transform-set strong esp-3des esp-md5-hmac
crypto ipsec profile cisco
 set security-association lifetime seconds 120
 set transform-set strong

interface Tunnel0
 ip address 172.16.0.1 255.255.255.0 ip mtu 1440
 no ip next-hop-self eigrp 90
 ip nhrp authentication cisco123
 ip nhrp map multicast dynamic
 ip nhrp network-id 1
 no ip split-horizon eigrp 90
 tunnel source FastEthernet0/0
 tunnel mode gre multipoint
 tunnel key 0
 tunnel protection ipsec profile cisco shared
end

interface Tunnel1
 ip vrf forwarding voice
 ip address 172.16.1.1 255.255.255.0 ip mtu 1440
 no ip next-hop-self eigrp 90
 ip nhrp authentication cisco123
 ip nhrp map multicast dynamic
 ip nhrp network-id 2
 no ip split-horizon eigrp 90
 tunnel source FastEthernet0/0
 tunnel mode gre multipoint
 tunnel key 1
 tunnel protection ipsec profile cisco shared
end


router eigrp 90
 network 10.0.1.0 0.0.0.255
 network 172.16.0.0 0.0.0.255
 no auto-summary
 !
 address-family ipv4 vrf voice
  network 10.1.1.0 0.0.0.255
  network 172.16.1.0 0.0.0.255
  no auto-summary
  autonomous-system 90
 exit-address-family
!



verificacion:

R1#sh dmvpn
Legend: Attrb --> S - Static, D - Dynamic, I - Incompletea
        N - NATed, L - Local, X - No Socket
        # Ent --> Number of NHRP entries with same NBMA peer

Tunnel0, Type:Hub, NHRP Peers:2,
 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1      10.10.10.2      172.16.0.2    UP    never D
     1      10.10.10.3      172.16.0.3    UP    never D

Tunnel1, Type:Hub, NHRP Peers:2,
 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1      10.10.10.2      172.16.1.2    UP    never D
     1      10.10.10.3      172.16.1.3    UP    never D



R1#sh crypto isakmp sa
IPv4 Crypto ISAKMP SA
dst             src             state          conn-id slot status
10.10.10.1      10.10.10.3      QM_IDLE           1002    0 ACTIVE
10.10.10.1      10.10.10.2      QM_IDLE           1001    0 ACTIVE

IPv6 Crypto ISAKMP SA




sábado, 27 de diciembre de 2014

DMVPN

R1#sh dmvpn
Legend: Attrb --> S - Static, D - Dynamic, I - Incompletea
        N - NATed, L - Local, X - No Socket
        # Ent --> Number of NHRP entries with same NBMA peer

Tunnel0, Type:Hub/Spoke, NHRP Peers:4,
 # Ent  Peer NBMA Addr Peer Tunnel Add State  UpDn Tm Attrb
 ----- --------------- --------------- ----- -------- -----
     1      10.10.10.1     172.19.11.1  NHRP    never S
     1      10.10.10.5     172.19.11.3    UP    never D
     1     10.10.10.14     172.19.11.4    UP    never D
     1     10.10.10.10     172.19.11.5    UP    never D

miércoles, 24 de diciembre de 2014

VRF LITE


ip vrf rojo
 rd 10:10
!
ip vrf verde
 rd 20:20
!
interface FastEthernet0/0
no shutdown

interface FastEthernet0/0.10
 encapsulation dot1Q 10
 ip vrf forwarding rojo
 ip address 10.10.10.1 255.255.255.252
!
interface FastEthernet0/0.20
 encapsulation dot1Q 20
 ip vrf forwarding verde
 ip address 10.10.11.1 255.255.255.252


ip route vrf rojo 20.20.20.0 255.255.255.0 10.10.10.2
ip route vrf verde 20.20.21.0 255.255.255.0 10.10.11.2