<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Daniels quest for CCIE</title>
	<atom:link href="http://lostintransit.se/feed/" rel="self" type="application/rss+xml" />
	<link>http://lostintransit.se</link>
	<description>Going for that CCIE</description>
	<lastBuildDate>Fri, 24 Feb 2012 19:39:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='lostintransit.se' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Daniels quest for CCIE</title>
		<link>http://lostintransit.se</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://lostintransit.se/osd.xml" title="Daniels quest for CCIE" />
	<atom:link rel='hub' href='http://lostintransit.se/?pushpress=hub'/>
		<item>
		<title>Final mock &#8211; 71/100</title>
		<link>http://lostintransit.se/2012/02/24/final-mock-71100/</link>
		<comments>http://lostintransit.se/2012/02/24/final-mock-71100/#comments</comments>
		<pubDate>Fri, 24 Feb 2012 19:39:19 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[CCIE]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1099</guid>
		<description><![CDATA[Did a final mock before lab and barely failed. I got 71/100. To my defence I did loose at least 3 points due to a bug. I had BGP configured correctly but session would not come up, BB was expecting other AS then the one I was coming from but SG had the same solution. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1099&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Did a final mock before lab and barely failed. I got 71/100. To my defence I did loose at least 3 points due to a bug. I had BGP configured correctly but session would not come up, BB was expecting other AS then the one I was coming from but SG had the same solution.</p>
<p>The TS section had some very stupid tasks. I hope I don&#8217;t have to see anything like that on the lab.</p>
<p>The config section went pretty well but lost some few points due to bug and a few points from reading the tasks wrong. I need to cut down on those definately. Everything has to be taken literally. If it says that put interface x in OSPF with /64 mask for IPv6. Then you need to see it as /64 so if it is a loopback you need to announce it as point-to-point.</p>
<p>Good news is I pretty much nailed IGP and redistribution went according to plans. Full reachability! I was also able to finish all tasks on time so I&#8217;m at least on the right path.</p>
<p>I&#8217;ll post more next week.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1099/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1099/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1099/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1099/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1099/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1099/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1099/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1099/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1099/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1099/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1099/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1099/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1099/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1099/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1099&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/24/final-mock-71100/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>
	</item>
		<item>
		<title>Quick notes on Zone Based Policy Firewall (ZBFW)</title>
		<link>http://lostintransit.se/2012/02/15/quick-notes-on-zone-based-policy-firewall-zbfw/</link>
		<comments>http://lostintransit.se/2012/02/15/quick-notes-on-zone-based-policy-firewall-zbfw/#comments</comments>
		<pubDate>Tue, 14 Feb 2012 22:12:32 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[ZBFW]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1095</guid>
		<description><![CDATA[Continuing to check things off from the blueprint. Did some ZBFW labbing today. Here are some important stuff to be aware of. ZBFW is basically a wrapper for CBAC. We create policys between zones and assign interfaces to zones instead of applying CBAC rules to interfaces. By default all traffic to the self zone will [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1095&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Continuing to check things off from the blueprint. Did some ZBFW labbing today. Here are some important stuff to be aware of.</p>
<p>ZBFW is basically a wrapper for CBAC. We create policys between zones and assign interfaces to zones instead of applying CBAC rules to interfaces.</p>
<p>By default all traffic to the self zone will be allowed (router from and to router itself). If we apply policys to self zone then everything is dropped except for the traffic that is explicitly permitted. We need to be aware of this to not mess with the routing if we get such a task at the lab.</p>
<p>The self zone can only inspect TCP, UDP and ICMP but not protocols like telnet and SSH. To work around this we can do a class-map matching an ACL AND the protocol TCP if we are matching telnet traffic.</p>
<p>It&#8217;s not very intuitive to see which traffic is dropped. We can turn on logging with ip inspect log drop-pkt. This helps a lot to see which traffic is being dropped.</p>
<p>ZBFW is massive in configuration, you will be typing a lot. It is easy to get confused and mix things. Name things intuitively, name class-maps CM_INSIDE_PROTOCOLS, name policy-maps PM_INSIDE_TO_OUTSIDE or names similar to that. If you don&#8217;t you will easily get lost after a while due to the massive config.</p>
<p>Packet counters for ZBFW can&#8217;t be trusted, this seems to be due to a bug. Verify by pinging or telneting to create traffic.</p>
<p>Use Notepad when creating the config, it is faster and less prone to errors.</p>
<p>All traffic flows are unidirectional so we need to create zone pairs for both directions depending if we want traffic to flow both ways.</p>
<p>We can have three different actions for traffic in the policy-maps.</p>
<p>Pass &#8211; Traffic gets through but not return traffic is permitted. Useful for &#8220;stateless&#8221; protocols like RIP<br />
Inspect &#8211; Allow traffic through and also allow the return traffic back.<br />
Drop &#8211; Drop the traffic</p>
<p>If we have a policy-map that allows some traffic through, the rest of the traffic not matching any class will be implicitly dropped, this is even if we don&#8217;t specify a class class-default.</p>
<p>That are the most important things you need to be aware of when configuring this feature.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1095/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1095/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1095/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1095/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1095/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1095/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1095/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1095/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1095/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1095/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1095/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1095/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1095/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1095/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1095&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/15/quick-notes-on-zone-based-policy-firewall-zbfw/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>
	</item>
		<item>
		<title>AAA new-model &#8211; What does it do?</title>
		<link>http://lostintransit.se/2012/02/13/aaa-new-model-what-does-it-do/</link>
		<comments>http://lostintransit.se/2012/02/13/aaa-new-model-what-does-it-do/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 13:04:56 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AAA]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1093</guid>
		<description><![CDATA[To enable AAA we need the AAA new-model command but what does it really do? Many of us makes assumptions about this command. By default if we have an empty config then we will be able to use the console and get straight into enable mode (priv15). If we try to telnet in (VTY) then [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1093&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>To enable AAA we need the AAA new-model command but what does it really do? Many of us makes assumptions about this command.</p>
<p>By default if we have an empty config then we will be able to use the console and get straight into enable mode (priv15). If we try to telnet in (VTY) then we can&#8217;t login since no password has been set. If we set a password then we can login to priv 1 but we won&#8217;t be able to enable since no enable password has been set.</p>
<p>When configuring AAA we use method lists. We can use the list called &#8216;default&#8217; or create our own. The sneaky thing about aaa new-model is that when we enable this the &#8216;default&#8217; list goes active which is applied to the VTY. What surprised me is that this is not applied to the console. Someone had a theory that Cisco wanted to apply it to both console and VTY but too many users got locked out of their routers so they had to back on this implementation, true or not, I don&#8217;t know.</p>
<p>When aaa new-model has been enabled the device will ask for local authentication. If we haven&#8217;t defined any users then no access for you (VTY-nazi). Console will still work though, we will have to enable to enter priv 15 as usual.<br />
Now if we define a user we will be able to login remotely as well, we do need to configure an enable password to get into priv 15 though.</p>
<p>For the lab I have seen that if people get a task with AAA they will create a new method list with no authentication and no authorization and apply it to the console and VTY. As I pointed out we should not have to enable this to the console but better safe than sorry I guess. This can be configured in the following way:</p>
<p>aaa new-model<br />
aaa authentication login VTY none<br />
aaa authorization exec VTY non<br />
line con 0<br />
login authentication VTY<br />
authorization exec VTY<br />
line vty 0 4<br />
line authentication VTY<br />
authorization exec VTY</p>
<p>How would you configure this, what do you do in real life? Post in comments.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1093/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1093/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1093/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1093/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1093/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1093/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1093/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1093/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1093/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1093/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1093/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1093/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1093/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1093/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1093&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/13/aaa-new-model-what-does-it-do/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>
	</item>
		<item>
		<title>Quick post on IP applications</title>
		<link>http://lostintransit.se/2012/02/11/quick-post-on-ip-applications/</link>
		<comments>http://lostintransit.se/2012/02/11/quick-post-on-ip-applications/#comments</comments>
		<pubDate>Sat, 11 Feb 2012 10:30:59 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ACL]]></category>
		<category><![CDATA[IP accounting]]></category>
		<category><![CDATA[Port 33435]]></category>
		<category><![CDATA[Traceroute]]></category>
		<category><![CDATA[UDP]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1080</guid>
		<description><![CDATA[I&#8217;m going through the blueprint and now I checked off IP accounting. The feature is very simple, it lets us see which source destination pairs that are sending traffic to each other. We can also configure to look what precedence values that are in the packets. There is also an option to look at the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1080&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m going through the blueprint and now I checked off IP accounting. The feature is very simple, it lets us see which source destination pairs that are sending traffic to each other. We can also configure to look what precedence values that are in the packets. There is also an option to look at the MAC-addresses of the packets passing through and also packets that are being denied by an access-list. The topology is dead simple, see below.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/ip_accounting.png"><img src="http://reaper81.files.wordpress.com/2012/02/ip_accounting.png?w=600" alt="" title="IP_accounting"   class="alignnone size-full wp-image-1081" /></a></p>
<p>Configure your routing protocol of choice to get reachability. I&#8217;m using OSPF, it does not matter at all as long as you have connectivity. Now lets say that we are interested in which source and destination pairs that are sending traffic THROUGH the router (transit). Packets destined TO the router will not be seen in the accounting. I&#8217;ll configure accounting on R2&#8242;s interface to R1 and then initiate a ping from R1 to R3. I&#8217;ll send traffic both to the loopback and R3&#8242;s FastEthernet interface to see two different source/destination pairs.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_output_packets.png"><img src="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_output_packets.png?w=600&#038;h=89" alt="" title="R2_IP_accounting_output_packets" width="600" height="89" class="alignnone size-full wp-image-1082" /></a></p>
<p>OK, lets ping.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_ping_1.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_ping_1.png?w=600&#038;h=194" alt="" title="R1_ping_1" width="600" height="194" class="alignnone size-full wp-image-1083" /></a></p>
<p>Now we will check the accounting database with the show ip accounting command.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r2_show_ip_accounting_1.png"><img src="http://reaper81.files.wordpress.com/2012/02/r2_show_ip_accounting_1.png?w=600" alt="" title="R2_show_ip_accounting_1"   class="alignnone size-full wp-image-1084" /></a></p>
<p>So that shows us what sources/destinations are sending traffic to each other, interesting! We can also see the number of packets and number of bytes. If we want to check statistics for only certain hosts we can use the global ip accounting-list command to define what hosts we are interested in. We define hosts/networks as in ACL with network/wilcard combination. </p>
<p>Storing entries in the IP accounting database requires some memory, there could be a risk of exhaustion if we have too many entries but the default is set to max 512 entries. We can define this with the global ip accounting-threshold command.</p>
<p>So now we want to check what IP precedence values pass through our interfaces and also what MAC addresses that are sending/receiving traffic. Lets configure this.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_prec_and_mac.png"><img src="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_prec_and_mac.png?w=600" alt="" title="R2_IP_accounting_prec_and_mac"   class="alignnone size-full wp-image-1085" /></a></p>
<p>Then we send some pings from R1, I will send with a ToS of 128, what IP precedence/DSCP is that? Think quick.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_ping_2.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_ping_2.png?w=600" alt="" title="R1_ping_2"   class="alignnone size-full wp-image-1086" /></a></p>
<p>Lets verify at R2 if we see anything, the command to use is show interface precedence.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r2_sh_int_prec.png"><img src="http://reaper81.files.wordpress.com/2012/02/r2_sh_int_prec.png?w=600" alt="" title="R2_sh_int_prec"   class="alignnone size-full wp-image-1087" /></a></p>
<p>So a ToS of 128 was a IP prec of 4 but you already figured that, right? <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  What is that traffic with IP prec 6? Mysterious&#8230;We are running routing so that is OSPF which is marked with an IP precedence of 6 automatically by the router itself. We can also check what MAC addresses have been learned.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r2_show_int_mac.png"><img src="http://reaper81.files.wordpress.com/2012/02/r2_show_int_mac.png?w=600" alt="" title="R2_show_int_mac"   class="alignnone size-full wp-image-1089" /></a></p>
<p>Here we also see OSPF represented by the MAC address 01-00-5E-00-00-05. We can also see when the last packet was sent which is quite handy. Now we will turn on accounting for access-lists as well, first we will define an ACL denying ICMP to 3.3.3.3 which is the loopback of R3. Note that we need the log keyword in the ACL.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_access_violations1.png"><img src="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_access_violations1.png?w=600" alt="" title="R2_IP_accounting_access_violations"   class="alignnone size-full wp-image-1091" /></a></p>
<p>Now we send traffic from R1 to 3.3.3.3.</p>
<p>For some reason I don&#8217;t see anything with the show ip accounting access-violations. Maybe this is a software issue? I tried turning off CEF as well. If any of my readers get this working I would be interested.</p>
<p>Lastly lets have a brief look at how traceroute works in IOS. Cisco devices uses UDP traceroute compared to ICMP used by Windows. The router sends packets with TTL of 1 and then N+1 the further away the probe goes. Traceroute sends three packets for every hop. The first hop will have a destination port of 33435, the second one will have 33436 and so on. If we want a router to not respond to traceroute we can turn off IP unreachables. Note that this will not hinder traceroute for which this router is not the final destination. Only the final device will send an ICMP unreachable (port unreachable) which is ICMP code 3. The other routers will send time exceeded which is ICMP code 11.</p>
<p>If we did want to block traceroute going through the router we could block this with an ACL denying packets that have ttl-exceeded or all packets lower than a certain TTL. If we need to find ICMP codes we can reference the ASA library. This should be available at the lab. You can find the reference by following this path.</p>
<p>Products &gt; Security &gt; Firewalls &gt; Firewall Appliances &gt; Cisco ASA 5500 Series Adaptive Security Appliances &gt; Configure &gt; Configuration Guides &gt; Cisco ASA 5500 Series Configuration Guide using the CLI, 8.4 &gt; Reference &gt; Addresses, Protocols, and Ports &gt; ICMP types</p>
<p>So this is just another feature that is handy to have.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1080/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1080/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1080/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1080&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/11/quick-post-on-ip-applications/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/ip_accounting.png" medium="image">
			<media:title type="html">IP_accounting</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_output_packets.png" medium="image">
			<media:title type="html">R2_IP_accounting_output_packets</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_ping_1.png" medium="image">
			<media:title type="html">R1_ping_1</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r2_show_ip_accounting_1.png" medium="image">
			<media:title type="html">R2_show_ip_accounting_1</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_prec_and_mac.png" medium="image">
			<media:title type="html">R2_IP_accounting_prec_and_mac</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_ping_2.png" medium="image">
			<media:title type="html">R1_ping_2</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r2_sh_int_prec.png" medium="image">
			<media:title type="html">R2_sh_int_prec</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r2_show_int_mac.png" medium="image">
			<media:title type="html">R2_show_int_mac</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r2_ip_accounting_access_violations1.png" medium="image">
			<media:title type="html">R2_IP_accounting_access_violations</media:title>
		</media:content>
	</item>
		<item>
		<title>Final stretch</title>
		<link>http://lostintransit.se/2012/02/10/final-stretch/</link>
		<comments>http://lostintransit.se/2012/02/10/final-stretch/#comments</comments>
		<pubDate>Fri, 10 Feb 2012 18:21:06 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[CCIE]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1078</guid>
		<description><![CDATA[Lab is coming up real fast now. I am checking off boxes in the blueprint for the stuff I feel comfortable with. I have maybe 70% checked but some of the stuff I want to revisit is QoS, multicast and a few filtering scenarios for routing and also NAT. There are also a few services [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1078&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Lab is coming up real fast now. I am checking off boxes in the blueprint for the stuff I feel comfortable with. I have maybe 70% checked but some of the stuff I want to revisit is QoS, multicast and a few filtering scenarios for routing and also NAT. There are also a few services that I want to check briefly in case I get them at the lab.</p>
<p>I don&#8217;t feel 100% prepared but I do feel that I do have a chance if everything goes well. All I can do is my best. I will also review a few labs down the final stretch. The last few days I will try to keep my brain fresh instead of cramming by only doing light review and by visiting the gym.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1078/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1078/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1078/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1078&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/10/final-stretch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>
	</item>
		<item>
		<title>Frame-relay multilink (MFR) and MLPPPoFR</title>
		<link>http://lostintransit.se/2012/02/09/frame-relay-multilink-mfr-and-mlpppofr/</link>
		<comments>http://lostintransit.se/2012/02/09/frame-relay-multilink-mfr-and-mlpppofr/#comments</comments>
		<pubDate>Thu, 09 Feb 2012 09:35:56 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Frame relay]]></category>
		<category><![CDATA[PPP]]></category>
		<category><![CDATA[Frame-relay]]></category>
		<category><![CDATA[FRF.16.1]]></category>
		<category><![CDATA[MFR]]></category>
		<category><![CDATA[MLPPPoFR]]></category>
		<category><![CDATA[PPPoFR]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1065</guid>
		<description><![CDATA[These topics are probably not very likely to appear at lab but it still good to at least have seen them once so you don&#8217;t get stumped if you should get a task like that at the lab. Frame relay multilink (MFR) is defined in FRF.16.1 as defined by The Frame Relay Forum. See this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1065&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>These topics are probably not very likely to appear at lab but it still good to at least have seen them once so you don&#8217;t get stumped if you should get a task like that at the lab.</p>
<p>Frame relay multilink (MFR) is defined in FRF.16.1 as defined by The Frame Relay Forum. See this <a href="http://www.broadband-forum.org/technical/download/FRF.16/frf16.1.pdf" title="FRF.16.1" target="_blank">URL</a> for complete specification.</p>
<p>The basic idea is to take several frame-relay interfaces with the same DLCI and bundle them into one logical interface. Kind of like an Etherchannel. The reason I write this post is that the DOCCD isn&#8217;t really intuitive for this topic and there does not seem to be a lot of documentation how to configure this rather simple feature.</p>
<p>I will be using a simple topology where router R1 is dually connected to R2 and R3 is also dually connected to R2. R2 will be acting as the frame switch, we could have used a separate frame switch in Dynamips but this is a bit more fun and shows how to configure the SP side as well.</p>
<p>The configuration on the customer side is rather simple. First we create the logical interface which is named mfr and then a number. We will use number 1. All configuration like IP address and access-lists or anything like that goes to this interface.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_mfr_conf.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_mfr_conf.png?w=600" alt="" title="R1_MFR_conf"   class="alignnone size-full wp-image-1066" /></a></p>
<p>Then we have to define which interfaces are part of the bundle. This is done with the encapsulation frame-relay mfr command.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_mfr_conf_2.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_mfr_conf_2.png?w=600&#038;h=208" alt="" title="R1_MFR_conf_2" width="600" height="208" class="alignnone size-full wp-image-1067" /></a></p>
<p>Then we do the same thing on the other side but with a different IP address of course. Then we can verify that the link is up with show frame-relay multilink. We verify with a ping.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_show_frame_multi.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_show_frame_multi.png?w=600&#038;h=202" alt="" title="R1_show_frame_multi" width="600" height="202" class="alignnone size-full wp-image-1068" /></a></p>
<p>If you want to check that both links are being used then you can clear the counters and then do a ping. The number of packets should be equal or close to.</p>
<p>This is how a show frame pvc looks.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_show_frame_pvc.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_show_frame_pvc.png?w=600" alt="" title="R1_show_frame_pvc"   class="alignnone size-full wp-image-1069" /></a></p>
<p>Note that the multilink interface is shown here instead of the physical interfaces. The MFR interface works the same way as a regular frame relay interface. Since I&#8217;m using a physical interface all DLCI&#8217;s will be mapped to it automatically and inverse ARP is used to resolve the remote layer 3 address to the local DLCI.</p>
<p>We also have the option of running the MFR interface on a subinterface, both as multipoint or point-to-point. Multipoint does not really make sense in this case but it can be done. The regular rules apply, if using multipoint we can either use a frame map statement or the frame-relay interface-dlci and rely on inverse ARP. For point-to-point interfaces we just use the frame-relay interface-dlci command as usual.</p>
<p>Now to the configuration of the FR switch. We enable frame-relay switching as usual. The configuration for the MFR is the same as for the customer side but we need to define that this interface is DCE and then we have the frame-relay route statements which map to the MFR interfaces instead of physical interfaces.</p>
<p>This is the configuration of R2.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r2_mfr_conf.png"><img src="http://reaper81.files.wordpress.com/2012/02/r2_mfr_conf.png?w=600&#038;h=236" alt="" title="R2_MFR_conf" width="600" height="236" class="alignnone size-full wp-image-1070" /></a></p>
<p>Now we will look at MLPPPoFR which is another way of doing bundling of links by using PPP. First we start with the basic configuration. We bind the DLCI&#8217;s to the virtual template.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_mlpppofr_1.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_mlpppofr_1.png?w=600" alt="" title="R1_MLPPPoFR_1"   class="alignnone size-full wp-image-1071" /></a></p>
<p>We do the same configuration on R2 and then we will configure the virtual-template to use multilink functionality. </p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_mlpppofr_2.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_mlpppofr_2.png?w=600&#038;h=91" alt="" title="R1_MLPPPoFR_2" width="600" height="91" class="alignnone size-full wp-image-1072" /></a></p>
<p>You will see that several virtual-access have been created. We can verify with show ppp multilink command.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/02/r1_show_ppp_multi1.png"><img src="http://reaper81.files.wordpress.com/2012/02/r1_show_ppp_multi1.png?w=600&#038;h=250" alt="" title="R1_show_ppp_multi" width="600" height="250" class="alignnone size-full wp-image-1075" /></a></p>
<p>That is basically it. Now you know how to configure FRF.16 and MLPPPoFR.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1065/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1065/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1065/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1065&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/09/frame-relay-multilink-mfr-and-mlpppofr/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_mfr_conf.png" medium="image">
			<media:title type="html">R1_MFR_conf</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_mfr_conf_2.png" medium="image">
			<media:title type="html">R1_MFR_conf_2</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_show_frame_multi.png" medium="image">
			<media:title type="html">R1_show_frame_multi</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_show_frame_pvc.png" medium="image">
			<media:title type="html">R1_show_frame_pvc</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r2_mfr_conf.png" medium="image">
			<media:title type="html">R2_MFR_conf</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_mlpppofr_1.png" medium="image">
			<media:title type="html">R1_MLPPPoFR_1</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_mlpppofr_2.png" medium="image">
			<media:title type="html">R1_MLPPPoFR_2</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/02/r1_show_ppp_multi1.png" medium="image">
			<media:title type="html">R1_show_ppp_multi</media:title>
		</media:content>
	</item>
		<item>
		<title>Blueprint &#8211; sample frame-relay task</title>
		<link>http://lostintransit.se/2012/02/07/blueprint-sample-frame-relay-task/</link>
		<comments>http://lostintransit.se/2012/02/07/blueprint-sample-frame-relay-task/#comments</comments>
		<pubDate>Tue, 07 Feb 2012 07:14:47 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Frame relay]]></category>
		<category><![CDATA[Frame-relay]]></category>
		<category><![CDATA[Sample Task]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1062</guid>
		<description><![CDATA[So I&#8217;m going through the blueprint checking off everything before the lab. I know FR pretty well by now but there are always some details you forget. As I was going through FR again I thought about possible failure scenarios and restrictions that could be used at the lab. Here is a sample task I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1062&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So I&#8217;m going through the blueprint checking off everything before the lab. I know FR pretty well by now but there are always some details you forget. As I was going through FR again I thought about possible failure scenarios and restrictions that could be used at the lab. Here is a sample task I thought of.</p>
<p>Router R1 is running frame-relay on interface serial0/0. Via LMI 4 PVC&#8217;s have been learned, DLCI 102, 103, 104 and 105. Disable inverse ARP for all DCLI&#8217;s except 102. Do not use the no frame-relay inverse arp command. For this task you are allowed to create an additional interface.</p>
<p>Post solution in comments.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1062/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1062/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1062/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1062&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/07/blueprint-sample-frame-relay-task/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>
	</item>
		<item>
		<title>Blueprint &#8211; Working on my weak areas</title>
		<link>http://lostintransit.se/2012/02/05/blueprint-working-on-my-weak-areas/</link>
		<comments>http://lostintransit.se/2012/02/05/blueprint-working-on-my-weak-areas/#comments</comments>
		<pubDate>Sun, 05 Feb 2012 19:52:08 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Blueprint]]></category>

		<guid isPermaLink="false">http://reaper81.wordpress.com/?p=1060</guid>
		<description><![CDATA[So lab is now only some weeks away. This is what I&#8217;m up against, the blueprint. The final weeks I will try to go through this list and work on my weaker areas.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1060&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So lab is now only some weeks away. This is what I&#8217;m up against, the <a href="https://learningnetwork.cisco.com/docs/DOC-6864" title="Cisco CCIE RS blueprint" target="_blank">blueprint</a>.</p>
<p>The final weeks I will try to go through this list and work on my weaker areas. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1060/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1060/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1060/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1060&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/02/05/blueprint-working-on-my-weak-areas/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>
	</item>
		<item>
		<title>Route redistribution &#8211; filtering and mitigating loops</title>
		<link>http://lostintransit.se/2012/01/30/route-redistribution-filtering-and-mitigating-loops/</link>
		<comments>http://lostintransit.se/2012/01/30/route-redistribution-filtering-and-mitigating-loops/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 13:47:13 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[Routing]]></category>
		<category><![CDATA[Distribute-list]]></category>
		<category><![CDATA[Loops]]></category>
		<category><![CDATA[OSPF]]></category>
		<category><![CDATA[Redistribution]]></category>
		<category><![CDATA[RIP]]></category>
		<category><![CDATA[Route feedback]]></category>
		<category><![CDATA[Route-map]]></category>
		<category><![CDATA[Tagging]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1041</guid>
		<description><![CDATA[This post is about route redistribution and the different filtering techniques we have available in our toolbelt. This post requires that you have a basic understanding of route redistribution. For some good posts look at Petr Lapukhovs posts at INE. First lets define what is route redistribution? Generally we will use route redistribution when multiple [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1041&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This post is about route redistribution and the different filtering techniques<br />
we have available in our toolbelt. This post requires that you have a basic<br />
understanding of route redistribution. For some good posts look at Petr<br />
Lapukhovs posts at INE.</p>
<p>First lets define what is route redistribution? Generally we will use route<br />
redistribution when multiple routing protocols are running in the network or<br />
multiple instances of the same routing protocol is running. This can be due<br />
to mergers, acquisitions or a fork lift upgrade. Maybe network is running<br />
OSPF but is migrating to EIGRP or vice versa. We can also have redistribution<br />
of connected and static routes.</p>
<p>What are some of the issues we can run into with route redistribution? We can<br />
have routing loops in the network. These may not always be visible right away.<br />
We can see them when doing a traceroute or when using debug ip routing.</p>
<p>We can also have issues with route feedback. Route feedback is when a redistributed<br />
route gets redistributed back into the same protocol from which it originated. This<br />
can lead to suboptimal routing or routing loops.</p>
<p>How do we define how &#8220;believable&#8221; a prefix is? First we must know that only the<br />
same prefixes will be compared. 162.14.1.0/24 and 162.14.1.0/25 are not the same<br />
prefixes. Longer match always wins! If we are comparing the two same prefixes<br />
from different routing protocols then the AD will determine which one is the<br />
best. Lower AD wins. If the AD for some reason is the same then the default AD<br />
is the tie breaker.</p>
<p>Routes that are external should be less trusted than internal routes. EIGRP does<br />
this by default by setting AD to 170 for external routes but 90 for internal. If<br />
the other protocols did the same then we would not have issues with routing loops<br />
at all. OSPF uses the same AD for internal and external prefixes (110) but we<br />
can modify the AD for external routes if we want to. RIP does not have this<br />
possibility.</p>
<p>Routing loops generally occur when we have redistribution between a protocol with<br />
higher AD to a protocol with lower AD. This means that RIP is most often involved<br />
in loops since it has the highest AD and we can&#8217;t define an external AD.</p>
<p>Lets look at a topology where loops can occur. This image is hand drawn and something<br />
I do when doing labs to try to spot potential issues. I use a different color for<br />
different protocols and draw arrows where redistribution occurs.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/rip_and_ospf1.png"><img src="http://reaper81.files.wordpress.com/2012/01/rip_and_ospf1.png?w=600" alt="" title="RIP_and_OSPF"   class="alignnone size-full wp-image-1043" /></a></p>
<p>We are doing mutual redistribution on R1 and R2. The issue here is that we will<br />
have suboptimal routing. You can download topology and configs <a href="http://www.reaper.nu/RIP_and_OSPF.zip" title="Redistribution lab #1" target="_blank">here</a>.</p>
<p>Look at the show ip route and traceroute from R1 to R2&#8242;s loopback.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_traceroute.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_traceroute.png?w=600&#038;h=286" alt="" title="R1_show_ip_route_traceroute" width="600" height="286" class="alignnone size-full wp-image-1044" /></a></p>
<p>R1 is going the whole way round even though it has a direct route via RIP to<br />
R2. This is of course due to RIP having a higher AD than OSPF. Lets look at<br />
a few different ways of fixing this. If this was the CCIE lab you would do nothing<br />
unless it was asked of you to provide optimal routing. We don&#8217;t have a loop so it&#8217;s<br />
not really a big issue at the moment. The issue here is that OSPF is not setting<br />
a higher AD on it&#8217;s external prefixes. So we will have to do this manually.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_distance_ospf_external.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_distance_ospf_external.png?w=600&#038;h=331" alt="" title="R1_distance_ospf_external" width="600" height="331" class="alignnone size-full wp-image-1045" /></a></p>
<p>So we set the AD to something higher than RIP, 121 in this case. Now we take<br />
the direct path. Remember that AD is a local setting so this would have to be done<br />
on all routers choosing suboptimal path.</p>
<p>We could also lower the AD of RIP. Either we do it for all routes or for a selection<br />
of routes. Here we will select the routes with an ACL. We can set the distance for<br />
all route sources or for a specific one based on the IP. Here we only have one so<br />
we don&#8217;t really care, we will match on 0.0.0.0 255.255.255.255.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_lower_distance_on_rip.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_lower_distance_on_rip.png?w=600" alt="" title="r1_lower_distance_on_rip"   class="alignnone size-full wp-image-1046" /></a></p>
<p>So now the AD is 109 for the RIP route which beats OSPF of 110. This would of course<br />
also be have to be done on all routers with suboptimal path.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_distance_255.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_distance_255.png?w=600&#038;h=346" alt="" title="R1_distance_255" width="600" height="346" class="alignnone size-full wp-image-1047" /></a></p>
<p>This is another way of doing it. We are setting a distance of 255 for the RIP routes<br />
when they are entering as OSPF routes. 255 is not a valid distance for installing to<br />
RIB so RIP routes will be preferred.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_distribute_list_in.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_distribute_list_in.png?w=600&#038;h=312" alt="" title="R1_distribute_list_in" width="600" height="312" class="alignnone size-full wp-image-1048" /></a></p>
<p>We can also use a distribute-list to control what routes get installed via OSPF.<br />
Since OSPF is a link state protocl the LSA will of course propagate to other<br />
routers.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_data1.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_data1.png?w=600" alt="" title="R1_show_ip_ospf_data"   class="alignnone size-full wp-image-1049" /></a></p>
<p>As you can see the route is still present in the OSPF database but it does not<br />
get installed into the RIB.</p>
<p>There is also a more fancy way of using distribute-lists. We can tie them to<br />
a routing-protocol and define what is allowed to go out from that protocol<br />
into the routing protocol that we are currently configuring. We will configure<br />
R2 so that RIP routes are not allowed to be redistributed into OSPF. This will<br />
kill any redundancy in the network.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r2_distribute_list_rip1.png"><img src="http://reaper81.files.wordpress.com/2012/01/r2_distribute_list_rip1.png?w=600" alt="" title="R2_distribute_list_rip"   class="alignnone size-full wp-image-1051" /></a></p>
<p>So we go to the config mode of the routing protocol we are redistributing into.<br />
Then we define with the distribute-list what is allowed to go out from other<br />
protocols into the one we are now configuring. This is an effective way of<br />
filtering when we have a lot of redistribution going on. In a small scenario<br />
like this it does not make much sense but it&#8217;s very handy in large scenarios.</p>
<p>There is still one tool left and that is the route-map. The route-map is the<br />
most flexible and scalable solution of all. We can choose what prefixes get<br />
redistributed with an access-list or prefix-list. Lets try that first.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r2_redistribute_route-map.png"><img src="http://reaper81.files.wordpress.com/2012/01/r2_redistribute_route-map.png?w=600" alt="" title="r2_redistribute_route-map"   class="alignnone size-full wp-image-1052" /></a></p>
<p>Here we matched prefixes with a prefix-list. The prefix-list has a deny for the<br />
loopback of R2 and permits anything else. The route-map only has a permit statement,<br />
deny in prefix-list and permit in route-map means that the prefix does not match<br />
and moves to the next statement which is an implicit deny. The permit matches the<br />
permit of the route-map and allows anything else.</p>
<p>This is an example of route feedback.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/route_feedback.png"><img src="http://reaper81.files.wordpress.com/2012/01/route_feedback.png?w=600" alt="" title="Route_feedback"   class="alignnone size-full wp-image-1053" /></a></p>
<p>R5 is the only redistribution point. The issue here is that the routes that R3<br />
learns from R1 and R2 via RIP will arrive at R5. R5 then redistributes into<br />
OSPF. R3 will receive these LSA&#8217;s and find that this path is better due to a<br />
lower AD. R3 will then install this route. R3 stops announcing that route via<br />
RIP. R5 looses its route via RIP and can&#8217;t redistribute it into OSPF, so it<br />
stops announcing it via OSPF. R3 installs the RIP route again and the fun<br />
has just begun. Debug ip routing will show this procedure repeat over and over.</p>
<p>For our final tool we need a more complicated scenario to make full use of it.<br />
First lets take a look at the topology. Download configs and topology <a href="http://www.reaper.nu/RIP_and_OSPF_2.zip" title="Redistribution lab #2" target="_blank">here</a>.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/rip_and_ospf_2.png"><img src="http://reaper81.files.wordpress.com/2012/01/rip_and_ospf_2.png?w=600" alt="" title="RIP_and_OSPF_2"   class="alignnone size-full wp-image-1054" /></a></p>
<p>We have mutual redistribution on R3 and R5. The issue here is that we are<br />
redistributing into RIP with a seed metric of 1. R3 sees R1&#8242;s loopback via<br />
RIP with a metric of 2. R3 redistributes this information into OSPF. R5 learns<br />
this information via OSPF and then redistributes into RIP with a metric of 1.<br />
R3 now has two possible paths to R1 loopback. One with a metric of 1 and one<br />
with a metric of two. Of course the lower metric wins. This means that R5<br />
points towards R3 via R4 and R3 points to R5. Ladies and gentlemen, we have<br />
a routing loop. There is definately a risk of loops when doing mutual redistribution.<br />
When I redistribute something into RIP I usually set a quite high seed metric like 7.<br />
This lowers the risk of loops because the RIP metric internally should be lower unless<br />
it&#8217;s a very large network.</p>
<p>The probably best way to filter redistribution is to use route tagging. We set<br />
a tag in a route-map and then base our filters on this. Sometimes it can be difficult<br />
knowing where a route originated and from which protocol it came. If we set good tags<br />
we can see both just by looking at the tag. I usually set a tag like 390, that means<br />
that router 3 originated the route and it came from EIGRP. A tag of 4120 would mean<br />
that it was a RIP route from R4 to begin with. Now lets try this technique as well.</p>
<p>We will set a tag of 3120 on R3 and also deny routes with a tag of 5110 on R3. This<br />
is used to prevent R3 from taking OSPF routes from R5 received over RIP and then<br />
redistributing them back into OSPF.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r3_route_map.png"><img src="http://reaper81.files.wordpress.com/2012/01/r3_route_map.png?w=600&#038;h=123" alt="" title="r3_route_map" width="600" height="123" class="alignnone size-full wp-image-1055" /></a></p>
<p>This is what the filtering looks like on R5.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r5_route_map.png"><img src="http://reaper81.files.wordpress.com/2012/01/r5_route_map.png?w=600" alt="" title="r5_route_map"   class="alignnone size-full wp-image-1056" /></a></p>
<p>Here we deny routes with a tag of 3120 and set our own tag of 5110.</p>
<p>Note that there is a risk that the loop still remains. R3 is announcing<br />
routes via RIP natively to R5. We have a chicken and egg problem here.<br />
This is the scenario before tagging. R3 redistributes RIP into OSPF. R5 receives<br />
the routes and install them via OSPF since AD is lower than RIP. R5 then redistributes<br />
these back into RIP. R3 sees the lower metric via R5 and installs this route in the<br />
RIB. We now have a loop. </p>
<p>We start implementing tagging. R3 tags RIP routes going into OSPF<br />
and denies any prefixes that R5 has already redistributed from OSPF to RIP.<br />
R5 denies routes from R3 with a tag of 3120 from going back into RIP and sets<br />
its own tag of 5110. There is a risk that R5 sees the best path via RIP to R3<br />
and then announces an OSPF route which R3 installs. We need to make sure that<br />
R5 sees the best path via OSPF to have a stable network. This can be done by<br />
clearing routing table and shutting down links. To make sure this does not<br />
happen we should also tag RIP routes going into OSPF on R5.</p>
<p>So you see that redistribution can be very complicated and there are a lot of<br />
tools available. Try to check what routes are native to which routing protocol<br />
and make sure that these are preferred in that domain. You can use distance<br />
or other tools to make sure this happens.</p>
<p>In the real lab there could be hidden bombs that you need to detect to have a stable<br />
topology. Probably you won&#8217;t be that restricted what you could do but there could<br />
be some restrictions. So it&#8217;s good to have as many tools as possible. If all else<br />
fails, do what it takes to get connectivity. Use distribute-lists or whatever<br />
to have a stable topology. Yes, you will loose points but you can definately<br />
not finish the lab if you don&#8217;t have a stable topology.</p>
<p>I hope this post has been informative and if you want to give med feedback<br />
post in the comments section.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1041/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1041/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1041/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1041&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/01/30/route-redistribution-filtering-and-mitigating-loops/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/rip_and_ospf1.png" medium="image">
			<media:title type="html">RIP_and_OSPF</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_traceroute.png" medium="image">
			<media:title type="html">R1_show_ip_route_traceroute</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_distance_ospf_external.png" medium="image">
			<media:title type="html">R1_distance_ospf_external</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_lower_distance_on_rip.png" medium="image">
			<media:title type="html">r1_lower_distance_on_rip</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_distance_255.png" medium="image">
			<media:title type="html">R1_distance_255</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_distribute_list_in.png" medium="image">
			<media:title type="html">R1_distribute_list_in</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_data1.png" medium="image">
			<media:title type="html">R1_show_ip_ospf_data</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r2_distribute_list_rip1.png" medium="image">
			<media:title type="html">R2_distribute_list_rip</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r2_redistribute_route-map.png" medium="image">
			<media:title type="html">r2_redistribute_route-map</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/route_feedback.png" medium="image">
			<media:title type="html">Route_feedback</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/rip_and_ospf_2.png" medium="image">
			<media:title type="html">RIP_and_OSPF_2</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r3_route_map.png" medium="image">
			<media:title type="html">r3_route_map</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r5_route_map.png" medium="image">
			<media:title type="html">r5_route_map</media:title>
		</media:content>
	</item>
		<item>
		<title>OSPF magic &#8211; Make interarea routes become intraarea</title>
		<link>http://lostintransit.se/2012/01/26/ospf-magic-make-interarea-routes-become-intraarea/</link>
		<comments>http://lostintransit.se/2012/01/26/ospf-magic-make-interarea-routes-become-intraarea/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 07:36:56 +0000</pubDate>
		<dc:creator>reaper81</dc:creator>
				<category><![CDATA[CCIE]]></category>
		<category><![CDATA[OSPF]]></category>
		<category><![CDATA[Discontigous]]></category>
		<category><![CDATA[GRE]]></category>
		<category><![CDATA[IP unnumbered]]></category>
		<category><![CDATA[Tunnel]]></category>

		<guid isPermaLink="false">http://lostintransit.se/?p=1032</guid>
		<description><![CDATA[This is a follow up post to my last OSPF post about repairing area 0. In the comments section Ray asked me what we can do if we have a scenario where we have another area that is discontigous. In this example we are using area 1. Area 1 is used everywhere but between R1 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1032&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This is a follow up post to my last OSPF post about repairing area 0.<br />
In the comments section Ray asked me what we can do if we have a<br />
scenario where we have another area that is discontigous. In this<br />
example we are using area 1. Area 1 is used everywhere but between<br />
R1 and R4 is the backbone area. The routes will therefore be<br />
interarea. What if we were told to make these routes appear as<br />
intra area? First look at the topology. Download .net file and<br />
initial and final configs <a href="http://www.reaper.nu/Area1.zip" title="Discontigous area 1 scenario" target="_blank">here</a>.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/area1_discontigous.png"><img src="http://reaper81.files.wordpress.com/2012/01/area1_discontigous.png?w=600&#038;h=369" alt="" title="Area1_discontigous" width="600" height="369" class="alignnone size-full wp-image-1033" /></a></p>
<p>First we start by confirming that routes received on R1<br />
are coming in as interarea routes.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_ospf_1.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_ospf_1.png?w=600&#038;h=109" alt="" title="R1_show_ip_route_ospf_1" width="600" height="109" class="alignnone size-full wp-image-1034" /></a></p>
<p>Yes they are. This is expected behaviour. So what can we do to<br />
make them appear as intraarea? Using a virtual link does not help<br />
since it always belongs to area 0. We could use the tunnel technique<br />
that was used in the previous post. Let&#8217;s try that. Same procedure as<br />
last time. Source tunnel from physical interface. Use IP unnumbered<br />
from an interface in area 1.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/area1_tunnel.png"><img src="http://reaper81.files.wordpress.com/2012/01/area1_tunnel.png?w=600&#038;h=246" alt="" title="Area1_tunnel" width="600" height="246" class="alignnone size-full wp-image-1035" /></a></p>
<p>The tunnel is up and we have a new adjacency.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_int_brief.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_int_brief.png?w=600&#038;h=194" alt="" title="R1_show_ip_ospf_int_brief" width="600" height="194" class="alignnone size-full wp-image-1036" /></a></p>
<p>The IP address is 0.0.0.0/0 and located in area 1. Lets look at the<br />
router LSA for area 1.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_data.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_data.png?w=600" alt="" title="R1_show_ip_ospf_data"   class="alignnone size-full wp-image-1037" /></a></p>
<p>The address is 0.0.0.16 just as the last time. This should be 10 according<br />
to the SNMP MIB but as one of my friends Patrick pointed out 16 in decimal<br />
is 0&#215;10 in hex. Maybe it is encoded in hex?</p>
<p>So now lets check the routing table.</p>
<p><a href="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_ospf_2.png"><img src="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_ospf_2.png?w=600" alt="" title="R1_show_ip_route_ospf_2"   class="alignnone size-full wp-image-1038" /></a></p>
<p>Problem solved. Routes are now received as intraarea. So there you have it,<br />
another OSPF problem solved.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reaper81.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reaper81.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reaper81.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reaper81.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reaper81.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reaper81.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reaper81.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reaper81.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reaper81.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reaper81.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reaper81.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reaper81.wordpress.com/1032/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reaper81.wordpress.com/1032/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reaper81.wordpress.com/1032/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=lostintransit.se&amp;blog=14928697&amp;post=1032&amp;subd=reaper81&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://lostintransit.se/2012/01/26/ospf-magic-make-interarea-routes-become-intraarea/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/fa9e672ca444eb4c9378feec578ca1df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reaper81</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/area1_discontigous.png" medium="image">
			<media:title type="html">Area1_discontigous</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_ospf_1.png" medium="image">
			<media:title type="html">R1_show_ip_route_ospf_1</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/area1_tunnel.png" medium="image">
			<media:title type="html">Area1_tunnel</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_int_brief.png" medium="image">
			<media:title type="html">R1_show_ip_ospf_int_brief</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_ospf_data.png" medium="image">
			<media:title type="html">R1_show_ip_ospf_data</media:title>
		</media:content>

		<media:content url="http://reaper81.files.wordpress.com/2012/01/r1_show_ip_route_ospf_2.png" medium="image">
			<media:title type="html">R1_show_ip_route_ospf_2</media:title>
		</media:content>
	</item>
	</channel>
</rss>
