Montag, 9. August 2010

IPv6 - Implementing QoS

IntServ (RFC 1633) - braucht Signaling Protocol a la RSVP (Resource Reservation), DiffServ (RFC2475) - Policies auf den Netzwerkgeräten


Classification and Marking -> Traffic conditioning (policing and shaping) -> congestion avoidance -> congestion  management


NBAR-Marking (Network based Application Regocnition) (ging in 12.4er-IOS) und GTS-Shaping (Generic traffic shaping), PQ (Priority Queueing (ging in 12.4(IOS)), CQ (Custom Queueing) noch nicht IPv6-fähig,
DOCSIS-L2-QoS nicht IPv6-fähig, cRTP (Compressed Real Time Protocol) noch nicht IPv6-fähig.


Layer-3-QoS IPv6 - anhand von 8bit Traffic Class (analog IPv4 ToS Field),Protocol Type, Flow label oder Extension Headers


Layer 2-Switches welche Classification durchführen sollten bei die IP-Protokoll unterscheiden können. (L2-QoS dependency on L3-Information)


Link-Efficency Mechanisms
cRTP (currently not supported for IPv6)
LFI (link fragmentation and interleave - L2 fragmentation - works with IPv6)

IPv6 QoS funktioniert nur mit eingeschaltetem CEF (Cisco Express Forwarding)

Queueing wird genauso konfiguriert wie bei IPv4 (FIFO,FB-WFQ,CB-WFQ,LLQ,MDRR), Congestion Avoidance (WRED) ebenso.


IPv6 classification
!
class-map match-all IPV6-WITH-ACL
 match access-group name IPV6
 match  dscp ef
class-map match-all IPV6
 match protocol ipv6
 match  dscp ef
class-map match-all IPV4                 <---- IPv4 Classification
 match  dscp ef
!      
ipv6 access-list IPV6
 permit ipv6 any any
!


IPv6 policy map
!        
policy-map IPV6
 class IPV6-WITH-ACL
    priority 10
!        
interface FastEthernet0/1
 no ip address
 duplex auto
 speed auto
 ipv6 enable
 service-policy output IPV6           <--- das Buch ist von 2004, in 12.4-IOS scheint         end                                        man PQ-IPv6 schon nutzen zu können

 
IPv6 NBAR

!
class-map match-all IPV6-NBAR
 match protocol ipv6
 match protocol citrix
!
policy-map IPV6-NBAR
 class IPV6-NBAR
    priority 20
!
interface FastEthernet0/0
 service-policy output IPV6           <--- auch NBAR scheint mittlerweile zu tun
!


Show Policy
Rack1R5#show policy-map int fa 0/1
 FastEthernet0/1

  Service-policy output: IPV6-NBAR

    queue stats for all priority classes:
     
      queue limit 64 packets
      (queue depth/total drops/no-buffer drops) 0/0/0
      (pkts output/bytes output) 0/0

    Class-map: IPV6-NBAR (match-all)
      0 packets, 0 bytes
      5 minute offered rate 0 bps, drop rate 0 bps
      Match: protocol ipv6
      Match: protocol citrix
      Priority: 20 kbps, burst bytes 1500, b/w exceed drops: 0
     

    Class-map: class-default (match-any)
      17 packets, 1742 bytes
      5 minute offered rate 0 bps, drop rate 0 bps
      Match: any
     
      queue limit 64 packets
      (queue depth/total drops/no-buffer drops) 0/0/0
      (pkts output/bytes output) 17/1742
Rack1R5#



QoS for IPv6 over MPLS (S.190)
DiffServ (RFC2474,RFC2475) still apply in the MPLS environment (RFC 3270).
6PE (IPv4-core und LSP) unterscheidet sich nicht von LDP IPv6, oder reinem IPv6
RVSP für MPLS-TE-Tunnels über einen MPLS Core (IPv4 oder IPv6). Da 6PEs einen IPv4-LSP nutzen, kann mit IPv4-RVSP-TE gearbeitet werden.

DSCP 6bits -> Class-Selector bits -> MPLS EXP (3 bits), am (6)PE Classification anhand DSCP,
In Service Provider-Netzen ist dies ausreichend, da der CE die DSCP anpasst.

IPv6 6PE RVSP MPLS-TE (S.195) - denke ich nicht Lab-Relevant.



Samstag, 7. August 2010

IPv6 - Routing Protocols

Zusammenfassung Chapter 4 Deploying IPv6 Networks - IPv6 Routing Protocols

Refresher
Distance Vector - RIP, EIGRP - Route Selection anhand der Metric, Bandbreite....
Link-State Protocols - OSPF, IS-IS - komplette Sicht der Links, Rout Selection anhand von Dijkstra Algo
Path Vector Protocols - BGP - Route Selection anhand des kompletten Wegs (Paths) einer Route

RIPng
Hopcount 15 wie IPv4, split-horizon und poison-reverse wie IPv4.
RIPng announced eigenes Subnetz auf Interface
Da es im IPv6 keinen Broadcast gibt wird link-local-all-Router-Multicast verwednet (FF02::9)
RIPng Security via ESP,AH
Mehre RIPng Prozesse auf einem Interface müssen mit unterschiedlichem UDP-Port gefahren werden, es gibt keine Prozess-ID oder ähnliches
Rack1R5(config)#ipv6 router rip SHIT
Rack1R5(config-rtr)#port 5000 multicast-group ff02::9
Rack1R5#sh ipv6 rip | incl port
RIP process "SHIT", port 5000, multicast-group FF02::9, pid 277
Config 
Rack1R5(config)#ipv6 unicast-routing
Rack1R5(config)#int fa 0/0
Rack1R5(config-if)#ipv6 address 2001:200::1/64
Rack1R5(config-if)#ipv6 rip SHIT enable


Show-Commands
Rack1R5#sh ipv6 rip
RIP process "SHIT", port 521, multicast-group FF02::9, pid 277
     Administrative distance is 120. Maximum paths is 16
     Updates every 30 seconds, expire after 180
     Holddown lasts 0 seconds, garbage collect after 120
     Split horizon is on; poison reverse is off
     Default routes are not generated
     Periodic updates 1, trigger updates 0
  Interfaces:
    FastEthernet0/0
  Redistribution:
    None
Rack1R5#

Metric und Summary-Infos per Interface, Redistribution etc. im router-Sub-Config-Mode
RIP-Database


Rack1R5#sh ipv6 rip database
RIP process "SHIT", local RIB
 2001:100::/64, metric 2, installed
     FastEthernet0/0/FE80::221:D8FF:FE39:41EE, expires in 179 secs
Rack1R5#


RIP-Routing-Table
Rack1R4#sh ipv6 route rip
IPv6 Routing Table - Default - 4 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
       B - BGP, M - MIPv6, R - RIP, I1 - ISIS L1
       I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary, D - EIGRP
       EX - EIGRP external
       O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
R   2001:200::/64 [120/2]
     via FE80::21A:2FFF:FE87:5C62, FastEthernet0/0
Rack1R4#



EIGRP
DUAL-Algorithmus -  Loop-free und alternative Pfade, Active Query, Reliable Transport, Hellos für schnellere Konvergenz
Support for Appletalk, IPX, neue Protokollerweiterung (TLV)
Source Address EIGRP Hello = link-local-Adress
Destination Address EIGRP Hello  = FF00::A (all EIGRP routers, link-scope)
EIGRP Process ID muss manuell konfiguriert werden wenn keine IPv4-Adresse vorhanden ist (sonst startet der Daemon nicht)
IPv6-EIGRP neighbors for process 1
% EIGRP 1 is in SHUTDOWN
Rack1R4#sh ip int brief
Interface                  IP-Address      OK? Method Status                Protocol
FastEthernet0/0            unassigned      YES TFTP   up                    up     
FastEthernet0/1            unassigned      YES TFTP   up                    down   
SSLVPN-VIF0                unassigned      NO  unset  up                    up     
Loopback0                  unassigned      YES TFTP   up                    up     
Rack1R4#
Rack1R4(config-rtr)#eigrp router-id 1.1.1.1
Rack1R4(config-rtr)#shutdown
Rack1R4(config-rtr)#no shutdown
Aug  7 19:30:05.535: %DUAL-5-NBRCHANGE: IPv6-EIGRP(0) 1: Neighbor FE80::21A:2FFF:FE87:5C62 (FastEthernet0/0) is up: new adjacency

EIGRP IPv4 benutzt MD5, EIGRP v6 soll IPSec unterstützen.
Auto-Summary in IPv6 disabled, auch Split-Horizon (da es mehere Prefixe auf einem Interface geben kann)

Config
Rack1R5(config)#int fa 0/1
Rack1R5(config-if)#ipv6 enable
Rack1R5(config-if)#ipv6 eigrp 1


OSPFv3 (RFC2740) - S.154
 Link-state-Protocol, no backward compaibility to OSPFv2 (Authentication),v1, Router und Network LSA enthalten keine Prefixe mehr, Inter-area prefix ersetzt Network Summary (Typ3 LSA), Inter-Area Router ersetzt ASBR summary LSA (Typ 4), OSPFv3 on a "per link" Basis, Source Adresse = link-local-Address. Security wieder über AH und ESP, Instance ID ermöglicht mehere Instanzen auf dem selben Link (Unterscheidung durch Instance ID im LSA)


Config (Unified mit Adress Family lt.Buch - hat auf c1841 / 12.4(24)T IOS nicht funktioniert)
 Rack1R4(config-if)#ospfv3 2 area 0 instance 64 address-family ipv4
 Rack1R4(config-if)#ospfv3 instance 64 cost 32


Config
Rack1R5(config-if)#ipv6 ospf 1 area 0
 

Router-ID weiterhin 32Bit (verfügbare IPv4-Adresse, wenn nicht startet der Prozess nicht)
Rack1R4(config-if)#ipv6 ospf 1 area 0
Aug  8 07:56:21.251: %OSPFv3-4-NORTRID: OSPFv3 process 1 could not pick a router-id,

Rack1R4(config)#ipv6 router ospf 1
Rack1R4(config-rtr)#router-id 1.1.1.4
Aug  8 08:01:16.291: %OSPFv3-5-ADJCHG: Process 1, Nbr 150.1.5.5 on FastEthernet0/0 from LOADING to FULL, Loading Done



Config (Back-to-Back-Encap-Frame-Relay)
Rack1R5#
!
interface Serial0/1/0
 no ip address
 encapsulation frame-relay
 no keepalive
 clock rate 2000000
!
interface Serial0/1/0.1 point-to-point
 ipv6 enable
 ipv6 ospf 1 area
 frame-relay interface-dlci 101  
!
Rack1R1#
!
interface Serial0/0
 no ip address
 encapsulation frame-relay
 no keepalive
!
interface Serial0/0.1 point-to-point
 ipv6 enable
 ipv6 ospf 1 area 0
 frame-relay interface-dlci 101  
!

Rack1R1#sh ipv6 ospf nei

Neighbor ID     Pri   State           Dead Time   Interface ID    Interface
150.1.5.5         1   FULL/  -        00:00:32    17              Serial0/0.1
Rack1R1#
 



Config (NBMA Frame-Relay)
Rack1R5#
!
interface Serial0/0/0
 no ip address
 encapsulation frame-relay
!
interface Serial0/0/0.1 multipoint
 ipv6 enable
 ipv6 ospf neighbor FE80::20B:FDFF:FEBA:6A40
 ipv6 ospf 1 area 0
 frame-relay map ipv6 FE80::20B:FDFF:FEBA:6A40 501
 frame-relay interface-dlci 501
!
ipv6 router ospf 1
 router-id 0.0.0.5
 log-adjacency-changes
!

Rack1R1#
!
interface Serial0/1
 no ip address
 encapsulation frame-relay
!
interface Serial0/1.1 multipoint
 ipv6 enable
 ipv6 ospf neighbor FE80::21A:2FFF:FE87:5C62
 ipv6 ospf 1 area 0
 frame-relay map ipv6 FE80::21A:2FFF:FE87:5C62 105
 frame-relay interface-dlci 105
!
ipv6 router ospf 1
 router-id 0.0.0.1
 log-adjacency-changes
!
Rack1R5#
*Aug  8 10:21:29.375: %OSPFv3-5-ADJCHG: Process 1, Nbr 0.0.0.1 on Serial0/0/0.1 from LOADING to FULL, Loading Done
Rack1R1#
*Mar  1 01:32:00.313: %OSPFv3-5-ADJCHG: Process 1, Nbr 0.0.0.5 on Serial0/1.1 from LOADING to FULL, Loading Done
Rack1R1#

Rack1R5#sh ipv6 ospf nei

Neighbor ID     Pri   State           Dead Time   Interface ID    Interface
0.0.0.1           1   FULL/DR         00:01:39    13              Serial0/0/0.1
Rack1R5#

Rack1R5#sh ipv6 ospf interface ser0/0/0.1
Serial0/0/0.1 is up, line protocol is up
  Link Local Address FE80::21A:2FFF:FE87:5C62, Interface ID 18
  Area 0, Process ID 1, Instance ID 0, Router ID 0.0.0.5
  Network Type NON_BROADCAST, Cost: 64
  Transmit Delay is 1 sec, State BDR, Priority 1
  Designated Router (ID) 0.0.0.1, local address FE80::20B:FDFF:FEBA:6A40
  Backup Designated router (ID) 0.0.0.5, local address FE80::21A:2FFF:FE87:5C62
  Timer intervals configured, Hello 30, Dead 120, Wait 120, Retransmit 5
    Hello due in 00:00:06
  Index 1/1/1, flood queue length 0
  Next 0x0(0)/0x0(0)/0x0(0)
  Last flood scan length is 1, maximum is 3
  Last flood scan time is 0 msec, maximum is 0 msec
  Neighbor Count is 1, Adjacent neighbor count is 1
    Adjacent with neighbor 0.0.0.1  (Designated Router)
  Suppress hello for 0 neighbor(s)
Rack1R5#

#Q# : Slow Neighbor adjacency ? why ?



Config OSPF IPSec Auth Option 

Rack1R1(config-rtr)#area 0 authentication ipsec spi 256 md5
Rack1R5#
*Aug  8 10:30:22.747: %OSPFv3-5-ADJCHG: Process 1, Nbr 0.0.0.1 on Serial0/0/0.1 from FULL to DOWN, Neighbor Down: Dead timer expired
Rack1R5(config-rtr)#area 0 authentication ipsec spi 256 md5 FC488E222896E0.......

#Q# : OSPFv3 IPSec funktioniert nicht in NBMA-Netzen ? auf Ethernet (Broadcast) zwischen 1841 und 2611XM auch nicht !?! IOS-Bug ??

IS-IS
OSI Protocol, aufgrund TLV (Type Length Value) leicht erweiterbar, IS-IS LSP (Link-State-Packets) arbeiten auf L2, OSPF DR = IS-IS DIS (designated Intermediate System), kein direkter NBMA Support,
Neue Protokoll-ID IPv6 -> 0x8E -> neue TLVs ->IPv6 Reachability (0XEC)
                                                                   ->IPv6 Interface Address (0XE8) 
Link-Local Address als LSP Source-Adresse
Gleiche Topology für IPv4 und IPv6 im single-topology-Mode (gleiche Metrik, Authentication etc.)
Multitopology (eigene Metrik, Authentication für IPv6 - in Transition-Phase IPv4->IPv6 nutzbar)


Config
Rack1R5#
!
interface FastEthernet0/1
 ipv6 enable
 ipv6 router isis SHIT
!
router isis SHIT
 net 49.0000.0000.0000.0005.00
!

 
Rack1R1#

!
interface FastEthernet0/0
 ipv6 enable
 ipv6 router isis SHIT

!
router isis SHIT
 net 49.0000.0000.0000.0001.00
!
 

Config (Multitopology)
Rack1R1#
!
router isis SHIT
 net 49.0000.0000.0000.0001.00
 metric-style wide transition
 !
 address-family ipv6
 multi-topology
 exit-address-family
!
Rack1R1#show isis database detail | incl Topo
  Topology:     IPv6 (0x2)
  Topology:     IPv6 (0x2)
Rack1R1#                         
!Rack1R1 sendet nun die Multitopology TLVs
Rack1R5#show clns is-neighbors detail | incl Topo
  Topology: IPv6
Rack1R5#

BGP - S.165
Path Vector Protocol, Attribute z.B. AS_PATH, NEXT_HOP
MP-BGP Extension for IPv6 (RFC2858)
-> neue Attribute MP_REACH_NLRI, MP_UNREACH_NLRI
->Attribute fangen mit AFI (16Bit) und SAFI (8Bit) an um das L3-Protokoll zu kennzeichnen
  • AFI:1=IPv4
  • AFI:2=IPv6
  • SAFI:128=MPLS VPN (#F# Fehler im Buch dort steht SAFI 127 = VPN)
  • SAFI:1=unicast
  • SAFI:2=multicast
  • SAFI:4=labeled 
MP-BGP-Capability negotiation via OPEN message
Bei BGP-Peering via IPv4 und Austausch von IPv6-Routen muss per Route-map der Next-hop angepasst werden. Da im IPv6-Prefix der IPv4-Next-Hop gesetzt wird.

Multihoming - mehrere IPv6 Adressen pro Host (von jedem Provider eine)
                   - multihoming in IPv6 würde die aggregation vom ISP zerhauen
                   - keine Lösung derzeit (verschiedene Drafts existieren)


 
Config (Peering with Link-Local-Addresses)
Rack1R1# (Cisco 2611XM)
router bgp 65000
 no synchronization
 bgp router-id 1.0.0.1
 bgp log-neighbor-changes
 neighbor FE80::21A:2FFF:FE87:5C63 remote-as 65000
 no auto-summar
!

Rack1R5# (Cisco 1841)
router bgp 65000
 no synchronization
 bgp router-id 1.0.0.5
 bgp log-neighbor-changes
 neighbor FE80::20B:FDFF:FEBA:6A40 remote-as 65000
 no auto-summary
!
Rack1R1#sh ip bgp summary                    

BGP router identifier 1.0.0.1, local AS number 65000
BGP table version is 1, main routing table version 1

Neighbor        V    AS MsgRcvd MsgSent   TblVer  InQ OutQ Up/Down  State/PfxRcd
FE80::21A:2FFF:FE87:5C63
                4 65000       0       0        0    0    0 never    Active
Rack1R1#
 
no Peering :( Note: Link-Local-Adressen auf einem Router müssen NICHT einzigartig sein !! Sollte die Link-Local-Adresse eines Interfaces außerhalb des selben Interface-Contextes auftauchen, muss beim Peering das Interface mit angegeben werden (Siehe Cisco BGP Peering with Link-Local-Address)
Nachdem auf Rack1R5 das Neighbor-Statement mit Interface angegeben wird, kommt das Peering hoch. !?!
Rack1R5(config)#router bgp 65000
Rack1R5(config-router)#no neighbor FE80::20B:FDFF:FEBA:6A40 remote-as 65000
Rack1R5(config-router)#neighbor FE80::20B:FDFF:FEBA:6A40%FastEthernet0/1 remot$
Rack1R5(config-router)#
Rack1R5#sh run | incl
*Aug  8 14:52:05.203: %SYS-5-CONFIG_I: Configured from console by console
Rack1R5#sh run | incl neigh
 bgp log-neighbor-changes
 neighbor FE80::20B:FDFF:FEBA:6A40%FastEthernet0/1 remote-as 65000
Rack1R5#
*Aug  8 14:52:11.323: %BGP-5-ADJCHANGE: neighbor FE80::20B:FDFF:FEBA:6A40%FastEthernet0/1 Up

Rack1R5#sh ipv6 int brief | incl up
FastEthernet0/1            [up/up]
SSLVPN-VIF0                [up/up]
Loopback0                  [up/up]
Rack1R5#
#Q# : Woran liegt das !?!


Config (IPv6 Peering with Loopbacks, Static Routes)
Rack1R1#
!
ipv6 unicast-routing
!
interface Loopback0
 no ip address
 ipv6 address 2001:5::1/64
 ipv6 enable
!
router bgp 65000
 no synchronization
 bgp router-id 1.0.0.5
 bgp log-neighbor-changes
 neighbor 2001:1::1 remote-as 65000
 neighbor 2001:1::1 update-source Loopback0
 no auto-summary
!
ipv6 route 2001:1::1/128 FastEthernet0/1 FE80::20B:FDFF:FEBA:6A40
!


Rack1R5#
!        
interface Loopback0
 no ip address
 ipv6 address 2001:1::1/64
 ipv6 enable
!
router bgp 65000
 no synchronization
 bgp router-id 1.0.0.1
 bgp log-neighbor-changes
 neighbor 2001:5::1 remote-as 65000
 neighbor 2001:5::1 update-source Loopback0
 no auto-summary

!
ipv6 route 2001:5::1/128 FastEthernet0/0 FE80::21A:2FFF:FE87:5C63
!


Ihr habe ich einen mal einen blöden Fehler drin gehabt.
Rack1R1 fa0/0---------- Rack1R5 fa0/1
Auf R1 war router bgp 65000 und auf R5 router bgp 6500 konfiguriert. Auf den ersten Blick sieht man das nicht.
Es kam natürlich kein Peering zu stande, es kam auch keine Fehlermeldung, da für R5 das neighbor-statement zu R1 eine eBGP-Session darstellt, der TTL auf 1 ist und somit nicht am R1 ankommt. Mit einem neighbor ebgp-multhop hätte man den Fehler am R5 leicht erkannt. Fürs Troubleshooting hilfreich ->
R1#telnet 2001:5::1 179 /ipv6 /source-interface lo0
Trying 2001:5::1, 179 ...
% Connection refused by remote host

 Bzw.
Rack1R5(config)#ipv6 access-list TEST
Rack1R5(config-ipv6-acl)#per
Rack1R5(config-ipv6-acl)#permit tc
Rack1R5(config-ipv6-acl)#permit tcp any any eq bgp
Rack1R5#debug ipv6 packet ac TEST
  IPv6 unicast packet debugging is on for access list TEST
Rack1R5#








 

IPv6 - Delivering IPv6 Unicast Services

Zusammenfassung des Chapter 3 - Deploying IPv6 Networks - Delivering IPv6 unicast Services.

Stateless autoconfiguration
works with NDP (Neighbor Discovery Protocol), Prefix im RA enthalten + EUI/64 ergibt IPv6-Adresse
Autoconfiguration abschalten

Router(config-if)#ipv6 nd suppress-ra
  • nicht pratikabel, keine Router-Discovery mehr
  • keine Router-RAs -> keine Autoconfiguratio
IPv6 Adress renumbering
Automatisches Renumbering mit Hilfe von Konfiguration für Prefix-Gültigkeit (S.92)
Router(config-if)# ipv6 nd prefix 2003::/64 at 31 Dec 2012 23:59 31 Dec 2012 12:15
                                          expire Valid Lifetime / expire Preferred Lifetime
ACHTUNG : NTP (kann weiterhin von IPv4-Source kommen)

Stateful DHCPv6
Nicht mit IOS, Cisco Network Registrar (CNR) Software für Solaris,Linux,Windows (S.93)
Wenn der DHCPv6-Server nicht im selben L2-Netz ist, benötigt mal DHCPv6 Relay (analog IPv4)
Router(config-if)# ipv6 dhcp relay destination 2003::1 

Damit Router keine Autoconfiguration durchführen und sich die IP vom DHCP ziehen
Rack1R5(config-if)#ipv6 nd managed-config-flag  (Hosts should use DHCP for address config)
#Q# Was passeirt wenn kein DHCP da ist, zieht dann wieder Autoconfiguration !?!
#A#

#Q# Was ist der unterschied von manage-config-flag zu other-config-flag !?!
#A# Combining the values of the M and O flags can yield the following:
Both M and O Flags are Set to 0. This combination corresponds to a network
without a DHCPv6 infrastructure. Hosts use router advertisements for
non-link-local addresses and other methods (such as manual configuration)
to configure other settings.
Both M and O Flags are Set to 1. DHCPv6 is used for both addresses and
other configuration settings. This combination is known as DHCPv6 stateful,
in which DHCPv6 is assigning stateful addresses to IPv6 hosts.
The M Flag is Set to 0 and the O Flag is Set to 1. DHCPv6 is not used to
assign addresses, only to assign other configuration settings. Neighboring
routers are configured to advertise non-link-local address prefixes from
which IPv6 hosts derive stateless addresses. This combination is known as
DHCPv6 stateless: DHCPv6 is not assigning stateful addresses to IPv6 hosts,
but stateless configuration settings.
The M Flag is Set to 1 and the O Flag is Set to 0. In this combination,
DHCPv6 is used for address configuration but not for other settings.
Because IPv6 hosts typically need to be configured with other settings,
such as the IPv6 addresses of Domain Name System (DNS) servers, this is an
unlikely combination.
Prefix Delegation (RFC 3633) - S.96
Prefixe vom Provider per DHCPv6 vom Provider Router (auch Delegating Router - DR) genannt. CE = RR (Requesting Router). Auch hier wird bei non-directly connected PE-CE ein DHCPv6 Relay benötigt.
DUID= DHCPv6 Unique Identifier
DR-Config
!        
ipv6 dhcp pool foo
 prefix-delegation 2001:7:7::/48 01
!       
Rack1R5(config-if)#ipv6 address foo 0:0:0::1/64
                                                   Die ersten 48Bit werden durch 2001:7:7 ersetzt
RR-Config
Rack1R5(config-if)#ipv6 dhcp client pd foo   (Downstream-Interfaces)
Rack1R5(config-if)#ipv6 address autoconfig default (Interface zum DR, generiert Def.Route)
Achtung ! Prefix-Delegation löst nicht das IGP ab, Prefix propagation via IGP wird immer noch benötigt !


Stateless DHCP (RFC3315)

Informationen über DNS, Hostname, etc.

Rack1R5(config-if)#ipv6 nd other-config-flag 
nd-mit other config flag zeigt das Hosts stateful DHCP nutzen sollen !?!

DNS
DNS Replay mit IPv4 und IPv6 Adressen gleichzeitig möglich
IPv6 DNS Records können über IPv4 transportiert werden und IPv4 DNS Records können über IPv6 transportiert werden
Am besten Dual-Stack DNS Server



Access Layer
Cable modems - haben bislang kein IPv6 support, IGMP snooping verhindert NDP (Neighbor Discovery Protocol)

Access over tunnels 
  • MCT (manually configured tunnel) S.121 (Achtung! RA ist auf Tunnel-Interfaces disabled im IOS)
  • Tunnel broker - tunnel Server (scale MCTs) kein IOS Feature
  • Teredo - IPv6 tunneling over IPv4 UDP (Port 3544) meines Wissens kein IOS Feature
  • ISATAP (RFC 4214) - S.123 - encap IPv6 in IPv4 (Protokoll Nr.41) - IPv4 als Link-Layer, FE80::5EFE::/64 + EUI/64 als link-local , es darf kein NAT verwendet werden wg. ProtokollNr.
  • IPv6 over GRE (MCT)
  • 6to4 tunnels (automatic) - S.129 - Tunnel Destination muss nicht angegeben werden, each site 2002:V4ADDR::/48 - Tunnel Endpunkte anhand der IPv4-Adresse, Probleme gibt es wenn ein Host  mehreren Adressen hat. 
  • IPv6 MPLS - braucht einen LSP für IPv6 und für IPv6, (LDPv6 gibt es derzeit noch nicht), IPv4 Peering kann für IPv6 Prefix Propagation genutzt werden (adress-family ipv6)
  • IPv6 over L2 circuit (EoMPLS) S.133
  • IPv6 tunnels over IPv4 over MPLS S.135
  • IPv6 MPPLS with IPv4 core (6PE) S.137 - bei PHP gibt es Probleme da kein IPv6-Informationen vorhanden sind darum muss in der IPv6-Adress-Family neighbor x.x.x.x send-label genutzt werden,M-BGP SAFI (Subsequent Adress Family) Label , P-Router müssen kein IPv6 sprechen, Problem ICMPv6 bei traceroute über MPLS Domain (no mpls ip propagate-ttl

Translation Mechanism (NAT-PT) (RFC 2765,2766) - S.140
Konfiguration NAT-PT - S.142

interface Ethernet3/1 
ipv6 address 2001:0db8:bbbb:1::9/64 
ipv6 enable 
ipv6 nat 
! 
interface Ethernet3/3 
ip address 192.168.30.9 255.255.255.0 
ipv6 nat 
! 
ipv6 nat v4v6 source 192.168.30.1 2001:0db8:0::2 
ipv6 nat v6v4 source list pt-list1 pool v4pool 
ipv6 nat v6v4 pool v4pool 10.21.8.1 10.21.8.10 prefix-length 24 
ipv6 nat translation udp-timeout 600
ipv6 nat prefix 2001:0db8:1::/96 
! 
ipv6 access-list pt-list1 
permit ipv6 2001:0db8:bbbb:1::/64 any
!








Eigenes Lab

Um nach dem Written Exam auch was zum üben hab, habe ich mir schonmal Teile des IN_E Racks angeschafft. Die teuren Geschichten fehlen noch (3560) für die IPv6-Labs.
Bereits vorhanden Devices Modules Modell IOS File Preis Gekauft bei
X R1 2x WIC-1T(1 vorhanden) 2611XM - c2600-adventerprisek9-mz.124-10a.bin 65,00 Ebay
X R2 2x WIC-1T(1 vorhanden) 2611XM - c2600-adventerprisek9-mz.124-10a.bin 65,00 Ebay
X R3 1x NM-4AS 2611XM - c2600-adventerprisek9-mz.124-10a.bin 69,03 Ebay
X R4 2x WIC-1T 1841 - c1841-adventerprisek9-mz.124-24.T.bin 289,03 Ebay
X R5 2x WIC-1T 1841 - c1841-adventerprisek9-mz.124-24.T.bin 206,90 Ebay
R6 2x WIC-1T 1841 - - 300,00 Ebay
- SW1 WS-C3550 - c3550-ipservicesk9-mz.122-25.sec2.bin 225,00 Ebay
- SW2 WS-C3550 - c3550-ipservicesk9-mz.122-25.sec2.bin 225,00 Ebay
X SW3 WS-C3550 - c3550-ipservicesk9-mz.122-25.sec2.bin 300,00 Ebay
X SW4 WS-C3560 - c3550-ipservicesk9-mz.122-25.sec2.bin 230,00 Ebay
X BB1Fr 2610 - c2600-i-mz.120-28.bin 100,00 Ebay
- BB2 2501 - c2500 - Ebay
X BB3 2501 - c2500 30,00 Ebay
X ACS 2511RJ - c2500 139,00 Ebay
R1
-

R2
System image file is "flash:c2600-adventerprisek9-mz.124-10a.bin"
Cisco 2611XM (MPC860P) processor (revision 1.0) with 127308K/3764K bytes of memory.
Processor board ID JAD070509XX
M860 processor: part number 5, mask 2
2 FastEthernet interfaces
1 Serial interface

R3
System image file is "flash:c2600-adventerprisek9-mz.124-10a.bin"
Cisco 2611XM (MPC860P) processor (revision 2.0) with 188416K/8192K bytes of memory.
Processor board ID JAE07510LXX
M860 processor: part number 5, mask 2
2 FastEthernet interfaces
4 Low-speed serial(sync/async) interfaces
32K bytes of NVRAM.
32768K bytes of processor board System flash (Read/Write)


R4
System image file is "flash:c1841-adventerprisek9-mz.124-24.T.bin"
Cisco 1841 (revision 7.0) with 333824K/59392K bytes of memory.
Processor board ID FHK122427XX
2 FastEthernet interfaces
1 Virtual Private Network (VPN) Module
DRAM configuration is 64 bits wide with parity disabled.
191K bytes of NVRAM.
1000440K bytes of ATA CompactFlash (Read/Write)

R5
System image file is "flash:c1841-adventerprisek9-mz.124-24.T.bin"
Cisco 1841 (revision 6.0) with 239616K/22528K bytes of memory.
Processor board ID FCZ104871XX
2 FastEthernet interfaces
2 Serial(sync/async) interfaces
1 Virtual Private Network (VPN) Module
DRAM configuration is 64 bits wide with parity disabled.
191K bytes of NVRAM.
62720K bytes of ATA CompactFlash (Read/Write)


R6
noch nicht vorhanden


SW1
System image file is "flash:/c3550-ipservicesk9-mz.122-25.sec2.bin"
24 FastEthernet interfaces
2 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.
384K bytes of flash-simulated NVRAM.
Base ethernet MAC Address: 00:0B:5F:70:05:XX
Motherboard assembly number: 73-5700-09
Power supply part number: 34-0966-02
Motherboard serial number: CAT064502XX
Power supply serial number: DCA06421EXX
Model revision number: G0
Motherboard revision number: A0
Model number: WS-C3550-24-SMI
System serial number: CAT0645Z1XX
Configuration register is 0x10F

SW2
nicht vorhanden

SW3
System image file is "flash:c3550-ipservicesk9-mz.122-25.sec2.bin"
384K bytes of flash-simulated NVRAM.
Base ethernet MAC Address: 00:0D:29:83:B7:XX
Motherboard assembly number: 73-8100-07
Power supply part number: 341-0029-02
Motherboard serial number: CAT07240GXX
Power supply serial number: DTH072213XX
Model revision number: D0
Motherboard revision number: A0
Model number: WS-C3550-24PWR-SMI
System serial number: CAT0725Y2XX
Configuration register is 0x10F


SW4
noch nicht vorhanden

BB1Fr
System image file is "flash:c2600-i-mz.120-28.bin"
cisco 2610 (MPC860) processor (revision 0x202) with 13312K/3072K bytes of memory.
Processor board ID JAB023501XX (25674104XX)
M860 processor: part number 0, mask 49
Bridging software.
X.25 software, Version 3.0.0.
1 Ethernet/IEEE 802.3 interface(s)
8 Low-speed serial(sync/async) network interface(s)
32K bytes of non-volatile configuration memory.
4096K bytes of processor board System flash (Read/Write)

BB2
nicht vorhanden

BB3


ACS
System image file is "flash:c2500-i-l.121-27b.bin"
cisco AS2511-RJ (68030) processor (revision E) with 6144K/2048K bytes of memory.
Processor board ID 14514580, with hardware revision 00000000
Bridging software.
X.25 software, Version 3.0.0.
1 Ethernet/IEEE 802.3 interface(s)
1 Serial network interface(s)
16 terminal line(s)
32K bytes of non-volatile configuration memory.
8192K bytes of processor board System flash (Read ONLY)

Patchkabel haben auch nochmal 85 Euronen gekostet, DB60 Kabel auch nochmal fast 150 Euro.
Eine IP-Steckdosenleiste von Conrad (249 Euro) hab ich mir noch zugelegt umd das Lab auch unterwegs rebooten zu können. Spart auch Strom in der Nacht. wenn ich das Lab remote ausknipsen kann.

So siehts derzeit aus :


Uploaded with ImageShack.us

Starting study for CCIE R&S

Nachdem ich im Jahr 2008 den CCNP/CCIP abgeschlossen habe und am 9.9.2010 die CCIE R&S Written v4 Beta Test mit 693 (Passing 790) ohne jegliche Vorbereitung verpasst hatte, habe ich mich danach etwas der Security gewidmet. (CCSA,CCSE im Feb2010). Nach etwas Pause habe ich im Mai 2010 endgültig beschlossen mit den Vorbereitungen zum CCIE R&S anzufangen.

- Angefangen hab ich mit dem CCIE Routing and Swichting Exam Certification Guide, Third Edition - ISBN-13: 978-1-58720-196-7, dummerweise gibt es schon den 4th Edition, habe mein Buch schon im September 2009 gekauft habe.
 Erwartet von diesem Buch nicht zu viel, die Themen werden nur angerissen, für IPv6, BGP und MPLS braucht man zwingend weitere Bücher, Docs etc.
- Danach Internet Routing Architectures - Sam Halabi -  (best BGP book)-(2nd Edition) (ISBN 9781578702336) - das BGP Buch, wenn man das durch hat, hat man es verstanden
-  Deploying IPv6 Networks - ISBN 1-58705-210-5 - IPv6 bis ins letzte Detail, dieses Buch ist keine leichte Kost, denn es erzählt nicht wie alle anderen Bücher und was euch Consultants über IPv6 sagen "IPv6 hat einen größeren Adressbereich..das wars" sondern erklärt IPv6 ins letze Detail (Adressresolution mit ICMPv6, Autoconfiguration, MobileIPv6, 6PE, und und und und) auch mögliche Implementierungen werden angesprochen. Zusätzlich empfiehlt es sich jedoch auch die aufgeführten RFCs zu lesen.

Danach werde ich mir nochmals folgende Bücher geben
- Routing TCP/IP Vol1 and Vol2 as refresher
- MPLS VPN Architectures - Peplnjak

Written Exam Date Thu,26.8.2010

Um meine Fortschritte, Rückschläge und sonstige Probleme zu dokumentieren hab ich den Blog gestartet.