Show card X icmpI think is the command you want. Chris O'Shea 2011/9/16 Mariano Juliá <mjuliaq at gmail.com> > Yes, there is a hard coded policer for locally bound ICMP packets. > > As a matter of fact, ICMP packets destined to any local IP address never > reach the XCRP, they are always handled by the input traffic card regardless > of whether the interface belong to that card or not. So it does for most > protocol keepalives although those are not ratelimited. > > I took notes of the ICMP rate limit values, some are in bytes others in > packets per second, unfortunately I didn't write down which ones are which. > > ICMP echo request 1000,1500 > ICMP echo reply 1000,1500 > Net Unreach 10,20 > Host Unreach 10,20 > port unreach 10,20 > DF unreach 1000,2000 > admin prohibited 10,20 > TTL exceed 100,200 > Net Redirect 10,20 > host redirect 10,20 > Parameter problem 10,20 > > If I recall correctly, one of the commands under "show card" has counters > for traffic dropped by this policer but I don't have access to a Redback any > more so I can't be more precise. > > Regards, > > Mariano > > > On 14/09/2011 14:08, Jim Tyrrell wrote: > >> Does SEOS have some sort of control plane policing that will drop ICMP >> packets in an MPLS environment? I have configured a vpn context but when >> testing I'm getting packetloss when pinging the SE600 from our Cisco >> routers. I have the following setup: >> >> R1 -> R2 -> SE600 -> DSL line (L2TP session) >> >> R1 & R2 can ping each other fine, and they can also ping the DSL line >> with 0 packetloss, but when I ping between the Cisco and SE600 I'm >> getting packetloss: >> >> >> ping vrf test 172.16.10.3 repeat 100 >> Sending 100, 100-byte ICMP Echos to 172.16.10.3, timeout is 2 seconds: >> !!!!!!!!!!.!!!!!!!!!!.!!!!!!!!**!!.!!!!!!!!!!.!!!!!!!!!!.!!!!!** >> !!!!!.!!!!!!!!!!.!!!!!!!!!!.!!**!!!!!!!!.! >> >> Success rate is 91 percent (91/100), round-trip min/avg/max = 1/1/4 ms >> >> It seems to be quite regular, and doesnt happen when pinging through the >> SE600 to the DSL line so I'm thinking there is some kind of ratelimiting >> on the SE600 itself? >> >> Thanks. >> >> Jim.
13 janv. 2012
[rbak-nsp] Internal icmp ratelimiting?
12 janv. 2012
PTA
lac:
client:
hostname R1
!
no ip domain lookup
!
ip cef
vpdn enable
!
vpdn-group pppoetest
accept-dialin
protocol pppoe
virtual-template 1
!
interface Loopback0
ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet0/0
ip address 10.10.10.1 255.255.255.0
pppoe enable
!
interface Virtual-Template1
mtu 1492
ip unnumbered FastEthernet0/0
peer default ip address pool pppoepool
!
ip local pool pppoepool 10.10.10.2 10.10.10.100
client:
hostname R2
!
no ip domain lookup
!
ip cef
!
interface FastEthernet0/0
no ip address
pppoe enable
pppoe-client dial-pool-number 1
!
interface Dialer1
mtu 1492
ip address negotiated
encapsulation ppp
dialer pool 1
dialer-group 1
no peer neighbor-route
!
ip route 0.0.0.0 0.0.0.0 Dialer1
!
dialer-list 1 protocol ip permit
LAC - LNS - PPP, PPPoE, L2TP
LNS:
To take traces:
!
hostname LNS
!
vpdn enable
vpdn multihop
!
vpdn-group L2TP-LNS
accept-dialin
protocol l2tp
virtual-template 1
terminate-from hostname LAC
local name LNS
no l2tp tunnel authentication
relay pppoe bba-group PPPoE
!
bba-group pppoe PPPoE
virtual-template 1
!
interface Loopback0
ip address 10.0.0.3 255.255.255.255
!
no ip address
no shutdown
duplex auto
speed auto
no keepalive
!
interface Loopback999
description for_tests
description for_tests
ip address 1.1.1.1 255.255.255.255
!
interface FastEthernet1/0!
no ip address
no shutdown
duplex auto
speed auto
no keepalive
!
interface FastEthernet1/0.203
encapsulation dot1q 203
encapsulation dot1q 203
ip address 192.168.23.3 255.255.255.0
!
interface Virtual-Template1
ip unnumbered Loopback0
peer default ip address pool PPP_Pool
keepalive 240
keepalive 240
!
ip local pool PPP_Pool 210.1.1.1 210.1.1.254
ip route 10.0.0.2 255.255.255.255 192.168.23.2 name LNS-to-LAC
!
no cdp run
!
no cdp run
!
LAC:
hostname LAC
!
subscriber profile PPPoE_Profile
service relay pppoe vpdn group L2TP-LAC
!
vpdn enable
vpdn source-ip 10.0.0.2
!
vpdn-group L2TP-LAC
request-dialin
protocol l2tp
domain test.com
initiate-to ip 10.0.0.3
local name LAC
no l2tp tunnel authentication
l2tp tunnel receive-window 1
!
bba-group pppoe PPPoE
virtual-template 1
service profile PPPoE_Profile
!
!
interface Loopback0
ip address 10.0.0.2 255.255.255.255
!
interface FastEthernet1/0
no ip address
no shutdown
duplex auto
speed auto
no keepalive
!
interface FastEthernet1/0
no ip address
no shutdown
duplex auto
speed auto
no keepalive
!
interface FastEthernet1/0.102
encapsulation dot1q 102
encapsulation dot1q 102
no ip address
pppoe enable group PPPoE
!
interface FastEthernet1/0.203
encapsulation dot1q 203
encapsulation dot1q 203
ip address 192.168.23.2 255.255.255.0
!
interface Virtual-Template1
ip unnumbered Loopback0
!
ip route 10.0.0.3 255.255.255.255 192.168.23.3 name LAC-to-LNS
!
no cdp run
!
no cdp run
!
CPE:
!
hostname CPE
!
interface Loopback0
ip address 123.123.123.123 255.255.255.255
!
interface FastEthernet1/0
no ip address
no shutdown
duplex auto
speed auto
no keepalive
!
interface FastEthernet1/0
no ip address
no shutdown
duplex auto
speed auto
no keepalive
!
interface FastEthernet1/0.102
encapsulation dot1q 102
pppoe enable group global
pppoe-client dial-pool-number 1
!
interface Dialer1
ip address negotiated
encapsulation ppp
dialer pool 1
dialer idle-timeout 0
dialer-group 1
ppp ipcp route default
ppp ipcp route default
!
no cdp run
!
To take traces:
- no cdp run
- no keepalive on interfaces
- change keepalive (240s) on interface Dialer 1 (CPE) and interface Virtual-Template (LNS).
15 déc. 2011
Frame relay and inverse-arp
no frame-relay inverse arp says that I shall not ask the other end what his IP address is.
no arp frame-relay means that if the other end asks me my IP address, I shall not answer him.
29 nov. 2011
Create ACL on eXtreme Network Switches...
vi no67udp.pol
(use a pol extension)
(ls command will list the files/configs on the XOS switch...linux) The following is needed in the policy (I add count so I can see the number of packet hits...it's not required):
entry drop1 {
if match all {
protocol udp;
source-port 67;
} then {
deny;
count drop1;
}
}
entry drop2{
if match all {
protocol udp;
destination-port 67;
} then {
deny;
count drop2;
}
}
After you've wq that (if you're doing vi) then you're ready to apply the policy/access-list. Enter the following commands:
check policy no67udp
(to make sure there are no errors and don't use .pol extension)
Next, apply to the ports:
configure access-list no67udp port 1-11,13-24 (or 26)
(it should respond with done!)
You can then show access-list or show access-list counter to see
if there are any hits.
To remove the access-list enter:
unconfigure access-list no67udp
You can edit the access-list while it's running and then after the
check policy command you will need to enter:
refresh policy no67udp
to make the changes take affect. I think that's all you need.
There's probably a better way and someone
with more experience than me might know. But
this should deny all 67 udp packets from all ports but 12.
27 nov. 2011
OSPF Authentication #1
Three authentication modes:
r1(config)#interface s1/0
r1(config-if)#ip ospf authentication ?
MD5 Authentication:
If "ip ospf authentication message-digest", then:
r1(config-if)#ip ospf message-digest-key 1 md5 ccie_lab
If you just entered "ip ospf authentication", it is clear-text authentication, then:
r1(config-if)#ip ospf authentication-key joe
Bad configuration #1:
There is no authentication here, but it works. Check with show ip ospf interface.
interface Serial1/1
ip ospf authentication message-digest
ip ospf authentication-key joe
Don't forget to use the same key id on both sides, else it won't work. Multiple key numbers can exist on the same interface.
Area Authentication
Authentication can be configured for the whole area (md5 or plain-text).
On each router:
router ospf 1
area 0 authentication message-digest
And on all interface configured with area 0:
interface Serial1/0
ip ospf message-digest-key 1 md5 CCIE_LAB
Note that here, there is no need to configure "ip ospf authentication message-digest" on the interface.
If using a Virtual_Link (which belong to area 0), configure on each router (even if no interfaces belongs to area 0):
Troubleshooting
Always look at "show ip ospf interface (intf)" and see what's happening. If you see "key 0" is used in MD5, then you will NOT be getting credit for that section where they likely tell you to use "cisco" as the password!
To check authentication problems:
r1#debug ip ospf adj
00:39:54: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication type. Input packet specified type 2, we use type 0
00:40:04: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication type. Input packet specified type 2, we use type 1
00:51:54: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication Key - No message digest key 0 on interface
- 0 - null, no authentication
- 1 - clear-text
- 2 - md5
r1(config)#interface s1/0
r1(config-if)#ip ospf authentication ?
message-digest Use message-digest authentication
null Use no authentication
MD5 Authentication:
If "ip ospf authentication message-digest", then:
r1(config-if)#ip ospf message-digest-key 1 md5 ccie_lab
If you just entered "ip ospf authentication", it is clear-text authentication, then:
r1(config-if)#ip ospf authentication-key joe
Bad configuration #1:
interface Serial1/1
ip address 13.0.0.1 255.255.255.0
ip ospf authentication-key joe
There is no authentication here, but it works. Check with show ip ospf interface.
Bad configuration #2:
interface Serial1/1
ip ospf authentication message-digest
ip ospf authentication-key joe
There is md5 authentication here, but there is no md5 password specified, it works:
r1#show ip ospf interface Serial1/1
Serial1/1 is up, line protocol is up
[...]
Message digest authentication enabled
No key configured, using default key id 0
Don't forget to use the same key id on both sides, else it won't work. Multiple key numbers can exist on the same interface.
Area Authentication
Authentication can be configured for the whole area (md5 or plain-text).
On each router:
router ospf 1
area 0 authentication message-digest
And on all interface configured with area 0:
interface Serial1/0
ip ospf message-digest-key 1 md5 CCIE_LAB
Note that here, there is no need to configure "ip ospf authentication message-digest" on the interface.
If using a Virtual_Link (which belong to area 0), configure on each router (even if no interfaces belongs to area 0):
router ospf 1
area 0 authentication message-digest
message-digest-key 1 md5 CCIE_LAB
area 234 virtual-link 2.2.2.2 authentication
Troubleshooting
Always look at "show ip ospf interface (intf)" and see what's happening. If you see "key 0" is used in MD5, then you will NOT be getting credit for that section where they likely tell you to use "cisco" as the password!
To check authentication problems:
r1#debug ip ospf adj
00:39:54: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication type. Input packet specified type 2, we use type 0
00:40:04: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication type. Input packet specified type 2, we use type 1
00:51:54: OSPF: Rcv pkt from 13.0.0.3, Serial1/1 : Mismatch Authentication Key - No message digest key 0 on interface
OSPF Virtual links
OSPF Virtual links are mainly used to avoid partitionned areas.
r1 and r2 belongs to area 0.
r1 and r3 to area 13, r3's loopback0 belongs to area 13.
r2, r3 and r4 to area 234.
If the link between r1 and r3 goes down, r3's loopback 0 becomes unreachable because area 13 has no connectivity with area 0 to reach other areas.
To avoid this, a virtual-link is established betwen the ABR, r3 and r2. This virtual-link belong to area 0.
Configuration:
r1:
!
interface Loopback0
ip address 1.1.1.1 255.255.255.0
ip ospf network point-to-point
!
!
interface Serial1/0
ip address 12.0.0.1 255.255.255.0
!
interface Serial1/1
ip address 13.0.0.1 255.255.255.0
!
router ospf 1
router-id 1.1.1.1
log-adjacency-changes
redistribute connected subnets
network 12.0.0.1 0.0.0.0 area 0
network 13.0.0.1 0.0.0.0 area 13
!
On r2:
interface Loopback0
ip address 2.2.2.2 255.255.255.0
ip ospf network point-to-point
!
interface Serial1/0
ip address 12.0.0.2 255.255.255.0
!
interface Serial1/1
ip address 24.0.0.2 255.255.255.0
!
!
router ospf 1
router-id 2.2.2.2
log-adjacency-changes
redistribute connected subnets
network 12.0.0.2 0.0.0.0 area 0
network 24.0.0.2 0.0.0.0 area 234
!
On r3:
!
interface Loopback0
ip address 3.3.3.3 255.255.255.0
ip ospf network point-to-point
!
interface Serial1/0
ip address 34.0.0.3 255.255.255.0
! interface Serial1/1
ip address 13.0.0.3 255.255.255.0!
router ospf 1
router-id 3.3.3.3
log-adjacency-changes
redistribute connected subnets
network 3.3.3.3 0.0.0.0 area 13
network 13.0.0.3 0.0.0.0 area 13
network 34.0.0.3 0.0.0.0 area 234
!
r4:
!
interface Loopback0
ip address 4.4.4.4
ip ospf network point-to-point
!
interface Serial1/0
ip address 24.0.0.4 255.255.255.0
!
interface Serial1/1
ip address 34.0.0.4 255.255.255.0
!
router ospf 1
router-id 4.4.4.4
log-adjacency-changes
redistribute connected subnets
network 24.0.0.4 0.0.0.0 area 234
network 34.0.0.4 0.0.0.0 area 234
!
To create the virtual-link through area 234 (using OSPF router-id), configure the ABR:
On r2:
!
router ospf 1
area 234 virtual-link 3.3.3.3
!
On r3:
!
r3#show ip ospf neighbor
r1 and r2 belongs to area 0.
r1 and r3 to area 13, r3's loopback0 belongs to area 13.
r2, r3 and r4 to area 234.
If the link between r1 and r3 goes down, r3's loopback 0 becomes unreachable because area 13 has no connectivity with area 0 to reach other areas.
To avoid this, a virtual-link is established betwen the ABR, r3 and r2. This virtual-link belong to area 0.
Configuration:
r1:
!
interface Loopback0
ip address 1.1.1.1 255.255.255.0
ip ospf network point-to-point
!
!
interface Serial1/0
ip address 12.0.0.1 255.255.255.0
!
interface Serial1/1
ip address 13.0.0.1 255.255.255.0
!
router ospf 1
router-id 1.1.1.1
log-adjacency-changes
redistribute connected subnets
network 12.0.0.1 0.0.0.0 area 0
network 13.0.0.1 0.0.0.0 area 13
!
On r2:
interface Loopback0
ip address 2.2.2.2 255.255.255.0
ip ospf network point-to-point
!
interface Serial1/0
ip address 12.0.0.2 255.255.255.0
!
interface Serial1/1
ip address 24.0.0.2 255.255.255.0
!
!
router ospf 1
router-id 2.2.2.2
log-adjacency-changes
redistribute connected subnets
network 12.0.0.2 0.0.0.0 area 0
network 24.0.0.2 0.0.0.0 area 234
!
On r3:
!
interface Loopback0
ip address 3.3.3.3 255.255.255.0
ip ospf network point-to-point
!
interface Serial1/0
ip address 34.0.0.3 255.255.255.0
! interface Serial1/1
ip address 13.0.0.3 255.255.255.0!
router ospf 1
router-id 3.3.3.3
log-adjacency-changes
redistribute connected subnets
network 3.3.3.3 0.0.0.0 area 13
network 13.0.0.3 0.0.0.0 area 13
network 34.0.0.3 0.0.0.0 area 234
!
r4:
!
interface Loopback0
ip address 4.4.4.4
ip ospf network point-to-point
!
interface Serial1/0
ip address 24.0.0.4 255.255.255.0
!
interface Serial1/1
ip address 34.0.0.4 255.255.255.0
!
router ospf 1
router-id 4.4.4.4
log-adjacency-changes
redistribute connected subnets
network 24.0.0.4 0.0.0.0 area 234
network 34.0.0.4 0.0.0.0 area 234
!
To create the virtual-link through area 234 (using OSPF router-id), configure the ABR:
On r2:
!
router ospf 1
area 234 virtual-link 3.3.3.3
!
On r3:
!
router ospf 1
area 234 virtual-link 2.2.2.2
!
Neighbor ID Pri State Dead Time Address Interface
2.2.2.2 0 FULL/ - - 24.0.0.2 OSPF_VL1
1.1.1.1 0 FULL/ - 00:00:33 13.0.0.1 Serial1/1
4.4.4.4 0 FULL/ - 00:00:38 34.0.0.4 Serial1/0
r3#show ip ospf interface brief
Interface PID Area IP Address/Mask Cost State Nbrs F/C
Vl1 1 0 34.0.0.3/24 128 P2P 1/1
Lo0 1 13 3.3.3.3/24 1 P2P 0/0
Se1/1 1 13 13.0.0.3/24 64 P2P 1/1
Se1/0 1 234 34.0.0.3/24 64 P2P 1/1
Inscription à :
Articles (Atom)
NTP - ACL
NTP - Network Time Protocol Packet types: - Control messages : don't bother with this. - NTP request/update messages: used for time sy...
-
Small Python Client/Server Application Client #!/usr/bin/env python import socket TCP_IP = '10.0.0.10' TCP_PORT = 21 ...
-
NTP - Network Time Protocol Packet types: - Control messages : don't bother with this. - NTP request/update messages: used for time sy...
-
Synchronization Before the discussion of synchronization, look at this scenario. RTC in AS300 sends updates about 170.10.0.0. RTA an...