Ospfv2 Sham Link Support For Mpls Vpn - Cisco ASR 9000 Series Configuration Manual

Aggregation services router
Hide thumbs Also See for ASR 9000 Series:
Table of Contents

Advertisement

Implementing OSPF

OSPFv2 Sham Link Support for MPLS VPN

It is recommended to use passive configuration on interfaces that are connecting LAN segments with hosts
to the rest of the network, but are not meant to be transit links between routers.
OSPFv2 Sham Link Support for MPLS VPN
In an MPLS VPN environment, several VPN client sites can be connected in the same OSPF area. If these
sites are connected over a backdoor link (intra-area link) and connected over the VPN backbone, all traffic
passes over the backdoor link instead of over the VPN backbone, because provider edge routers advertise
OSPF routes learned over the VPN backbone as inter-area or external routes that are less preferred than
intra-area routes advertised over backdoor links.
To correct this default OSPF behavior in an MPLS VPN, configure a sham link between two provider edge
(PE) routers to connect the sites through the MPLS VPN backbone. A sham link represents an intra-area
(unnumbered point-to-point) connection between PE routers. All other routers in the area see the sham link
and use it to calculate intra-area shortest path first (SPF) routes to the remote site. A cost must be configured
with each sham link to determine whether traffic is sent over the backdoor link or sham link.
Configured source and destination addresses serve as the endpoints of the sham link. The source and destination
IP addresses must belong to the VRF and must be advertised by Border Gateway Protocol (BGP) as host
routes to remote PE routers. The sham-link endpoint addresses should not be advertised by OSPF.
Figure 18: Backdoor Paths Between OSPF Client Sites
For example,
Figure 18: Backdoor Paths Between OSPF Client Sites , on page 344
shows three client sites,
each with backdoor links. Because each site runs OSPF within Area 1 configuration, all routing between the
sites follows the intra-area path across the backdoor links instead of over the MPLS VPN backbone.
If the backdoor links between the sites are used only for backup purposes, default route selection over the
backbone link is not acceptable as it creates undesirable traffic flow. To establish the desired path selection
Cisco ASR 9000 Series Aggregation Services Router Routing Configuration Guide, Release 5.1.x
344
OL-30423-03

Advertisement

Table of Contents
loading

Table of Contents