Page 1
Ethernet Routing Switch 8600 Engineering IP-VPN (MPLS) for ERS 8600 Technical Configuration Guide Avaya Data Solutions Document Date: July 2010 Document Number: NN48500-569 Document Version: 1.1...
Page 2
Avaya Support Web site: http://www.avaya.com/support Please note that if you acquired the product from an authorized reseller, the warranty is provided to you by said reseller and not by Avaya. Licenses THE SOFTWARE LICENSE TERMS AVAILABLE ON THE AVAYA WEBSITE, HTTP://SUPPORT.AVAYA.COM/LICENSEINFO/...
Page 3
Abstract This Technical Configuration Guide covers IP-VPN (MPLS) for the Ethernet Routing Switch 8600 (ERS 8600). IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Customer Service ..........................52 Getting technical documentation ....................52 Getting product training ....................... 52 Getting help from a distributor or reseller ..................52 Getting technical support from the Avaya Web site ..............52 IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Italic text in a Courier New font indicates text the user must enter or select in a menu item, button or command: ERS5520-48T# show running-config Output examples from Avaya devices are displayed in a Lucinda Console font: ERS5520-48T# show running-config ! Embedded ASCII Configuration Generator Script ! Model = Ethernet Routing Switch 5520-24T-PWR ! Software version = v5.0.0.011...
ERS8600 – please note that RFC 4364 obsoletes RFC 2547. This allows customer edge routers (CE routers) connect to an ERS 8600 acting as an MPLS PE (Provider Edge) router to send their routes via a MPLS backbone to other CE routers at different sites. There is no requirement for the CE routers at different sites to peer with each other or knowledge of IP Virtual Private Networks (VPNs) across the service provider‘s backbone.
4 byte ASN provider Both configured as IP-address:nn IP address Defined if backbone uses private AS IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide number Mandatory format on ERS8600 July 2010 when doing IPVPN-Lite...
IGP protocol to determine the path between the various nodes in the network. Hence, LDP uses the same path as that selected by the IGP protocol used. The ERS8600 uses LDP for VPN-IPv4. VPN Packet Forwarding IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Static Route Entries 2,000 per VRF, 10,000 per system OSPF instances supported 12 system RIP instances supported 48 system OSPF area per switch 5 per VRF and 24 per system IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 12
80, 200 per system Traffic Classification Traffic classification is supported via port, VLAN, IPv4 parameters, or VRF MPLS MPLS LDP sessions MPLS LDP LSPs MPLS RSVP static LSPs Tunnels 2500 IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
2. Configuration Example 2.1 IP-VPN Configuration In this configuration example, we will configure the following PE routers 8600-1, 8600-2, and 8600-3 with the following: Routing protocol between CE and PE routers OSPF Protocol between PE and P routers OSPF ...
8600-3 (PE3) Subnet Zone 10.91.x.y 10.92.x.y 10.93.x.y VLAN & IP VLAN 1000 VLAN 1010 VLAN 1020 (10.91.100.2/30) (10.92.101.2/30) (10.93.102.0/30) VLAN 1010 (10.91.100.6/30) IGP Protocol OSPF OSPF OSPF 10.91.1.1/32 10.92.1.1/32 10.93.1.1/32 CLIP IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 15
Enabled per VRF Enabled per VRF Enabled per VRF *OSPF ASBR instance instance instance *Route re- BGP into OSPF BGP into OSPF BGP into OSPF distribution Note 2 VPN Configuration See IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 16
use a common method throughout the network to help in configuration and troubleshooting. As suggested above, the Autonomous System Number used to derive both the RD and RT values. IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 17
2.2.1 ERS8600 – Base Configuration For this configuration example, we will use ACLI on 8600-1 and PPCLI on 8600-2 and 8600-3. 2.2.1.1 Create VLANs to MPLS Core ERS8600-1 Step 1 – Create VLAN 1000 plus VLAN 1010 and add port members...
Page 18
ERS8600-3: Step 1 – Disable STP on port 3/27 and disable/re-enable port 3/27 ERS8600-3:5# config ethernet 3/27 stg 1 stp disable ERS8600-3:5# config ethernet 3/27 state disable ERS8600-3:5# config ethernet 3/27 state enable IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 19
ERS8600-2: Step 2 – Enable OSPF globally ERS8600-2:6# config ip ospf router-id 10.92.1.1 ERS8600-2:5# config ip ospf enable ERS8600-3: Step 2 – Enable OSPF globally ERS8600-3:5# config ip ospf router-id 10.93.1.1 ERS8600-3:5# config ip ospf enable IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 21
ERS8600-2: Step 2 – Use the CLIP address as the MPLS router-id ERS8600-2:5# config mpls router-id 10.92.1.1 ERS8600-3: Step 2 – Use the CLIP address as the MPLS router-id ERS8600-3:5# config mpls router-id 10.93.1.1 IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 22
On each ERS8600 in the switch cluster verify the following information: Option Verify State Verify that the LDP state is Enabled. 2.2.4.2 Verify LDP ID Step 1 – Verify LDP Id ERS8600-1:5# show mpls ldp summary IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 23
On each ERS8600 in the switch cluster verify the following information: Option Verify Local Ldp Id Verify that the LDP is the CLIP address configured on the switch. For the 8600-1 switch, the LDP ID should be displayed as 10.91.1.1. 2.2.4.3 Verify LDP Interface, Session, Discovery, and Neighbors Step 1 –...
Page 24
Option Verify Local Ldp Id Verify that the Local LDP ID is the CLIP address configured on the switch. For the 8600- 1 switch, the LDP ID should be displayed as 10.91.1.1. IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide...
Page 25
Peer LDP ID & Verify the Peer LDP ID is that for the direct neighbors. In the case of 8600-1 which is Interface & connected to MPLS P router P1 and P2, the Peer LDP ID should show up as State 10.100.100.1 via interface VLAN 1000 and 10.100.100.3 via interface VLAN 1010.
Page 27
MPLS Labels – End to End 2.2.4.5 Assuming you wish to see the labels used for the CLIP address of 10.92.1.1/32 from 8600-1 to 8600-2. The normal path is via P2 and P3 where P2 is a Juniper router and P3 is a Cisco router.
Page 28
10.91.1.1:0 remote binding: tsr: 10.100.100.1:0, tag: 100032 remote binding: tsr: 10.100.100.2:0, tag: 100000 8600-1 – Verify that the LDP labels used for path 10.92.1.1/32 by issuing the following command: ERS8600-1:5# show mpls ldp bindings 10.92.1.1/32 Result: Fec : 10.92.1.1/32 Local Binding : Label:23 Remote Binding : 10.100.100.3:0...
Page 29
ERS8600-3:5# config ip vrf blue create id 10 ERS8600-3:5# config ip vrf red create id 11 ERS8600-1 Step 2 – Add OSPF to VRF instances ERS8600-1:5(config)# router vrf blue ERS8600-1:5(router-vrf)# ip ospf ERS8600-1:5(router-vrf)# exit IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 30
ERS8600-1:5(config)# vlan members add 3001 3/26 ERS8600-1:5(config)# interface vlan 3001 ERS8600-1:5(config-if)# vrf red ERS8600-1:5(config-if)# exit ERS8600-1:5(config)# vlan create 3002 name green type port 1 ERS8600-1:5(config)# vlan members add 3002 3/27 ERS8600-1:5(config)# interface vlan 3002 IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 31
ERS8600-1 Step 2 – Add IP address and enable OSPF on each VRF ERS8600-1:5(config)# interface vlan 3000 ERS8600-1:5(config-if)# ip address 10.91.10.1 255.255.255.0 ERS8600-1:5(config-if)# ip ospf enable ERS8600-1:5(config-if)# exit ERS8600-1:5(config)# interface vlan 3001 ERS8600-1:5(config-if)# ip address 10.91.10.1 255.255.255.0 ERS8600-1:5(config-if)# ip ospf enable IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 32
ERS8600-2:5# config ip vrf red ospf enable ERS8600-2:5# config ip vrf green ospf enable ERS8600-3 Step 3 – Enable OSPF globally for VRF 10 and 11 ERS8600-3:5# config ip vrf blue ospf enable IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Create BGP Neighbours and enabled PE-PE MP-BGP Please note that MP-BGP must be enabled by using the neighbour command ―address-family vpnv4 enable‖ and ―update-source‖ using the local CLIP address. ERS8600-1 Step 1 – Configure BGP neighbours 8600-2 and 8600-3 ERS8600-1:5(config)# router bgp ERS8600-1:5(router-bgp)# neighbor 10.92.1.1 ERS8600-1:5(router-bgp)# neighbor 10.92.1.1 remote-as 3030...
Page 35
ERS8600-3:5# config ip vrf blue bgp enable ERS8600-3:5# config ip vrf red bgp create ERS8600-3:5# config ip vrf red bgp auto-summary disable ERS8600-3:5# config ip vrf red bgp synchronization disable IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 36
ERS8600-2:5# config ip vrf red ipvpn rt add both 3030:11 ERS8600-2:5# config ip vrf red ipvpn enable ERS8600-2:5# config ip vrf green ipvpn create ERS8600-2:5# config ip vrf green ipvpn rd 3030:212 IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 37
ERS8600-1:5(router-vrf)# ip ospf redistribute bgp enable ERS8600-1:5(router-vrf)# exit ERS8600-1:5(config)# router vrf green ERS8600-1:5(router-vrf)# ip ospf as-boundary-router enable ERS8600-1:5(router-vrf)# ip ospf redistribute bgp ERS8600-1:5(router-vrf)# ip ospf redistribute bgp enable ERS8600-1:5(router-vrf)# exit IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 38
ERS8600-3:5# config ip vrf blue ospf redistribute bgp create ERS8600-3:5# config ip vrf blue ospf redistribute bgp enable ERS8600-3:5# config ip vrf red ospf redistribute bgp create ERS8600-3:5# config ip vrf red ospf redistribute bgp enable IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 39
BGP AS number and the ERS8600 number plus VRF number. The IPVPN Route Target is equal to the BGP AS number and the VRF id. IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 40
1010 10.93.100.0 255.255.255.0 10.93.1.1 Glob~ 0 1010 192.2.1.0 255.255.255.0 10.91.1.1 Glob~ 0 1010 7 out of 7 Total Num of Route Entries, 7 Total Num of Dest Networks displayed. -------------------------------------------------------------------------------- IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 41
Option Verify NH VRF All local routes learned, in this case by 8600-2, via the locally attached CE router with display a ―NH VRF‖ value of blue via VLAN 3000 using a protocol of OSPF. All external INTERFACE routes from ERS8600-1 and ERS8600-3 are learned via BGP via VLAN 1010.
Page 42
PEER REM ADDR Please note that the BGP Peer and Next-hop address from ERS8600-2 perspective is either the circuitless IP (CLIP) address from 8600-1 or 8600-3. The CLIP was NEXTHOP configured as the source IP address using the ―update-source-interface‖ when the BGP neighbors where configured.
Page 45
Out Label : 100640 ; Out Port : Vlan 1010 ; Next-Hop : 10.92.101.1 Type : ldp-dynamic Dest/Mask : 10.100.100.1/255.255.255.255 Out Label : 100560 ; Out Port : Vlan 1010 ; Next-Hop : 10.92.101.1 Type : ldp-dynamic IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 46
ERS8600-2:5# show mpls ilm info NNCLI command: ERS8600:5# show mpls ilm Result: In Label : 16 ; Out Label : N/A Next-Hop : Interface : N/A ; Address : N/A IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 47
Packet Capture Examples As shown via the packet capture below taken via port 4/19 on ERS8600-2, note the ―In label‖ of 16 for the packet destined to the CE router attached to 8600-2 and the out label of 100688. ...
Page 48
1 out of 1 Total number of ILM entries. IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
Page 49
Show below is a packet capture displaying a BGP update from ERS8600-2 for VRF 10 – the blue VRF. IV-VPN (MPLS) for ERS 8600 Technical Configuration Guide July 2010...
5. Customer Service Visit the Avaya Web site to access the complete range of services and support that Avaya provides. Go www.avaya.com or go to one of the pages listed in the following sections. 5.1 Getting technical documentation To download and print selected technical publications and release notes directly from the Internet,go to www.avaya.com/support.
Need help?
Do you have a question about the 8600 and is the answer not in the manual?
Questions and answers