Overview
Join Knox Hutchinson as he works through a CCIE Enterprise BGP assessment.
BGP Assessment
Knox Hutchinson works through the CCIE Enterprise assessment beginning with manipulating BGP for the internet backbone.
Knowledge Check
To configure bgp confederation using an autonomous system (AS) number of 400, which of the following would be used?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
BGP Assessment
0:00OK, here we go with our first major task in this journey
0:03into the CCIE practice exam.
0:05Our first task is going to be all about bringing up
0:08the internet backbone.
0:10There's seven routers that we need
0:11to work with in the internet backbone.
0:14They're all labeled starting with ISP hyphen, something.
0:17So that's what we're going to be focusing in this video.
0:19This is going to be a major BGP assessment.
0:22So get ready.
0:23Let's get started with task number
0:25one, the internet network.
0:26All right, so without further ado,
0:28let's have some fun here and start
0:29bringing this lab to life.
0:31So what I'm going to focus on first
0:32is the internet section here.
0:34This is going to be ISPs 100, ISP 200, 300, 400-1, 2, 3,
0:40and 4.
0:41Those are the ones that we want to bring to life first.
0:43So that way when we bring all of our branches to life,
0:46all of them will have connectivity over the internet
0:48and that simulates that way.
0:50As a quick refresher, this traffic
0:52will be sent outbound towards this NAT-out router, which
0:55if you've got it set up right in your environment,
0:57this will actually send it outbound
0:59toward the actual internet.
1:00So our LAN devices will actually be
1:02able to simulate the internet when the time comes.
1:04So let's take a look at these lab tests
1:06here, if I jump over to the left-hand side
1:07and choose lab test.
1:09I'm focused on the internet network section first.
1:12And here's also what I'm going to do.
1:14I'm going to bring the consoles of these devices
1:16up by using secure CRT.
1:18So when I give them a click here and launch secure CRT,
1:21and I'm going to do a little split screen action like this.
1:25Here we go.
1:26So I'll choose ISP 200, 300--
1:30come on 300, there we go--
1:31400-1 2, 3, and 4.
1:38Cool, so all of my consoles are up here.
1:40Let's start by just getting a little lay of the land.
1:42I'll do ISP 100, show IP interface brief.
1:45In fact, let's clean this up a little bit.
1:47I've got a little quick shortcut item here.
1:49So this is show IP interface brief,
1:51exclude unassigned and administratively down.
1:53So this just shows me all of the IP addresses
1:55that are assigned currently.
1:57The layout is like this, the 192.168s typically are going
2:03to be used for anything outside of the internet.
2:06So this is how our customers connect into the internet.
2:08It's also how we connect to the NAT outbound router two.
2:12The 172.30s are going to be BGP neighbors
2:16if they're in a different autonomous system.
2:18So if we look at the topology here,
2:20let me move things around just a little bit
2:22so we can work with this a little bit better.
2:24Hit over a couple times, great.
2:26So ISP 100 is going to have only eBGP neighbor relationships--
2:31so we think.
2:31We'll see what the tasks have in store for us.
2:34Same thing's going to be for ISP 200 because there's only--
2:38let's just say show IP-- actually, you know what?
2:41I've got that quick button here at the bottom.
2:42Let's just do that.
2:42So that way it's nice and easy and clean.
2:44There we go.
2:44So, again, we've got the 172.30s.
2:47So I see there's going to be three 172.30s, and then,
2:50of course, a loopback.
2:51Same thing with ISP 300.
2:53Let's get into enable privilege mode.
2:56It takes the lay of the land there, OK?
2:59Let's do this one, the 400s.
3:01Just doing the lay of the land, get our feet a little
3:05settled here.
3:06Take a look at the IP addresses, cool.
3:09Now, notice here in the ISP 400s,
3:12we're going to be doing some iBGP
3:14relationships and some more configurations beyond that.
3:17So those internal BGPs are going to be 172.31.
3:24If I was to jump back to ISP 400-1,
3:27I see I've got the 192.168s.
3:29Again, that's so it can connect, too.
3:31It looks like it's got two outbound connections
3:33to R9 and R8.
3:34So that's going to be customer one and customer two's routers.
3:38All right, let's take a look at ISP 400-3.
3:43Cool, there we go.
3:45I also see some outbound connections here for customer
3:49one and customer two, and then the internal 172.31s.
3:55And let's give this one a run.
3:57OK, so now we've got a lay of the land.
3:59We've seen all of the IP addresses.
4:01Why wait any longer?
4:02Let's just start from the top.
4:04Configure BGP on all routers in the ISP network
4:06according to the following.
4:08So this task, so this internet network task
4:11is going to be almost exclusively BGP.
4:13But that does not mean this is the only place that we will see
4:16BGP throughout this journey.
4:17We will absolutely see BGP again.
4:19It's just that the internet network section is going
4:21to be heavily focused on BGP.
4:23So let's get to it.
4:25ISP 100 should operate in ASN 100.
4:28So let's do router BGP 100.
4:30There we go.
4:31So that's operating in AS 100.
4:32200 operates in 200.
4:34300 operates in 300.
4:36So let's get that done, conf t router BGP 200, cool.
4:40ISP 300.
4:42Config t router BGP 300, cool.
4:45Now, ISP 400s should all operate in AS 400, but like so.
4:50ISP 400-1 and ISP 400-2 should participate
4:54in a confederation, ASN 65005, and use authentication Cisco.
4:58Now, I believe that's 400-1 and 400-2 should authenticate
5:02to each other.
5:03400-3 and 400-4 should participate in a confederation,
5:07the same confederation.
5:08But ASN 65006 can use authentication CISCO1.
5:13All right, so we're doing a confederation here.
5:16Let's get it going.
5:17This is going to be router BGP for 400-1.
5:21We said that's 65005.
5:25So they're going to be participating
5:27in the local autonomous system of 65005,
5:31representing ASN400 as part of the confederation.
5:35So let's say BGP confederation identifier is going to be 400.
5:39And BGP confederation peers, we're
5:42expecting to be 65006, OK?
5:46Same thing is going to be on ISP 400-2.
5:50So I'm going to give this a do show run, section BGP, and just
5:55copy and paste--
5:57very cool.
5:58Here we go.
5:59Config t, paste it in.
6:01There we go.
6:01So now my confederation is set up for 65005.
6:05We also need to configure the neighbor
6:07relationship between these two, such that it
6:10uses authentication.
6:12So let's say neighbor, this was going to be--
6:17do we want to do this by loopbacks?
6:19We probably do want to do this by loopbacks, don't we?
6:21OK, so the loopback address on 400-2 is 142.142.142.142.
6:29And the issue that I have here, just looking at this,
6:32is that these don't have-- nope.
6:36Do show IP route.
6:38These don't have routes to each other.
6:41So let's do this in order to make this happen.
6:44Let's just make this come to life
6:45real quick by saying router OSPF1.
6:48Let's just run OSPF between all of the devices in ISP 400.
6:54So I'm going to say router OSPF 1 network.
6:57We need to turn the network on for one of these commands.
7:01Let's do 172.31.41.0.
7:06These are all 24-bit masks in this area, or in this topology.
7:14And this was 43, cool.
7:19If I jump back over here, we'll back out
7:22of BGP configuration real quick, OSPF 1 network 172.31.41.0.
7:31So it's area 0.
7:32That'll bring that to life real quick.
7:34And 24, that'll bring that to life real quick.
7:40Let's bring these to life with the OSPF real quick--
7:45network 172.31.34.0 area 0 and 43, cool.
7:59Router OSPF 1 network 172.31.34.0 area
8:060 and 24 right here.
8:11OK, so if I give this a do show IP OSPF interface brief,
8:16let's verify that those are participating here.
8:19And do show IP OSPF neighbors.
8:23We're in a DROTHER state, which means
8:26it might be coming to life.
8:27Looks like I'm getting some full adjacencies over here.
8:30Now we need to get those loopbacks into OSPF
8:33so that we can make our BGP neighbor relationships based
8:37on the loopback addresses.
8:39So let's get those loopbacks in.
8:42And I'm going to do a network statement instead
8:44of a redistributor connected because--
8:46actually, you know what?
8:48Yeah, I'm going to do it that way.
8:49OK, 141.
8:52Let's do 0.0.0.0 area 0.
8:56Over here, I'm going to do network 142.142.142.142
9:060.0.0.0, area 0.
9:09Let's jump over here, network 143--
9:13ah, hit Enter too many times--
9:15143.143.143.143 0.0.0.0, area 0.
9:22Why can't I type?
9:23There we go.
9:24And ISP 400, network 144.144.144.144 0.0.0.0--
9:33I always forget that wildcard mask.
9:35All right, so at this point, let's do
9:37a do show IP route OSPF.
9:41Cool, I'm starting to see--
9:42OK, I got all the loopbacks in.
9:44So at this point, I can start building my BGP relationships.
9:47So I'll go back into BGP.
9:50This is 65005 on ISP 400-1.
9:55Just making sure you all can see me OK.
9:56Yeah, OK, we're good.
9:59And I'm going to say neighbor is going to be--
10:02we were going to do authentication
10:04between ISP 400-1 and ISP 400-2, and a different password
10:12between 400-3 and 400-4.
10:14So I'll say 142.142.142.142.
10:20Remote AS is going to be 65005.
10:22We're going to do update so that it's peered
10:25based on the loopback address.
10:27And let's throw in that password, shall we?
10:30Password was all caps, CISCO.
10:33Let's bring this BGP relationship to life over here.
10:37And we're going to say new--
10:39nope, nope, nope, got to be in BGP--
10:4265005.
10:45And we've got our neighbor statement, 141.141.141.141.
10:51Remote AS 65005, update source loopback.
10:59OK, and lastly, the password.
11:03Let's let it sit for a second and just verify
11:06that this comes to life.
11:09Come on, baby.
11:11Give me a BGP relationship.
11:13Do a debug BGP IPv4 unicast.
11:17Is that it?
11:25All right, I think that's a good sign.
11:28Do show BGP IPv4 unicast summary.
11:33OK, we've got an up.
11:34No prefixes received because we're not
11:36advertising any prefixes into BGP at this time.
11:39But it looks like everything is doing good.
11:41Do undebug all-- oops, all-- there we go.
11:44Cool, debugging is turned off.
11:46So the relationship between 400-1 and 400-2
11:50is brought to life.
11:50So we've got that one checked off.
11:52Let's bring up 400-3 and 400-4.
11:55So let's exit out of this-- router BGP-- this is 65006.
12:01And this is now going to be our neighbor
12:03statement of 144.144.144.144.
12:07Remote AS is going to be our remote AS because this
12:11is an internal BGP session.
12:13We're going to do the update source loopback.
12:18And we need to do a password.
12:21This was password CISCO1.
12:24Cool, all right, let's do this guy
12:27over here, which is going to be ISP 400-4, router BGP 65006,
12:34neighbor 143.143.143.143.
12:40Remote AS is our AS because it's internal.
12:45Update source loopback and password is CISCO1.
12:51Let's do do debug BGP IPv4 unicast, watch it come to life.
13:00Come on, baby.
13:08Cool, looking good, adjacency is up.
13:11We've got the little ADJ change neighbor status of up.
13:15Give me one second so I can mute this.
13:16This keeps going off.
13:18All right, there we go-- silent mode.
13:20Sorry about that.
13:21OK, now we've got the BGP relationship between 400--
13:26within the local autonomous system.
13:27Now we need to get that outside of local autonomous system,
13:30but still within the confederation.
13:32So this is going to be peers between 65005 and 65006.
13:39So this is going to be ISP 400-1 over here to 400-3,
13:44and ISP 400-2 to ISP 400-4.
13:47So on the side, we're going to say neighbor 143.143.143.143.
13:55remote autonomous system, 65006 update source, loopback 0.
14:03There's no authentication requirement here.
14:06So I'm not worried about it.
14:08Let me do a do undebug all here.
14:09There we go, OK?
14:12Neighbor 141, which is the loopback address of 400-1,
14:18remote autonomous system, 65005.
14:21Update source-- entered too many times there.
14:26Update source, loopback 0.
14:28OK, so that should bring that relationship to life.
14:30Let's do 400-2 and 400-4.
14:36There we go.
14:36So neighbor statement here, autonomous system 65006.
14:43Update source, loopback 0, cool.
14:47And in the other direction, neighbor 142.142.142.142,
14:56remote autonomous system--
14:58nope, there's 65005.
15:00And update source, loopback 0, OK?
15:08Just let everything come to life-- do.
15:12Active open failed.
15:13No route to peer.
15:15No route?
15:16Do show IP route OSPF.
15:18What's up with that?
15:21You definitely have a route to peer, buddy.
15:28No route to peer?
15:31Do ping, 142.142.142.142 source loopback 0, OK?
15:39Well, we definitely have connectivity.
15:42Oh, OK, do show run section BGP.
15:47Where did I go wrong?
16:03Do show BGP IPv4 unicast--
16:08nope, summary.
16:12We definitely have not established
16:14a connection for 142.
16:17Oh, I didn't configure the confederation--
16:20duh.
16:20OK, BGP confederation identifier 400,
16:27BGP confederation peers 65005.
16:32And did I do the same thing here?
16:35Do show run-- bet I didn't--
16:39section BGP, y'all.
16:42BGP confederation identifier 400,
16:45BGP confederation peers 65005.
16:52Still says no route to peer, ugh.
16:57Do show run section BGP, OK?
17:07I did type this right.
17:10And it does have a route because I can ping it.
17:19Do show run section BGP, do show IP route, OK?
17:30So not only does router three here
17:32see the route to router two through one and three--
17:35so this is some tomfoolery here.
17:38Do show IP route.
17:45It learns the route via OSPF.
17:52OK.
17:56active open field.
17:57OK, let's see.
17:58What's going on over here?
17:59Do show run section BGP.
18:1165006 update source loopback 0.
18:15Do show run section BGP 65005.
18:24Update source loopback 0.
18:27Show IP route.
18:36Do ping 144.144.144.144 source from loopback 0.
18:44Roundtrip traffic, but this guy says there is no route for 142.
18:53OK, let's do this.
18:54No, just wipe these out real quick.
19:10Try it again.
19:18Make sure I'm into BGP configuration, yeah, OK.
19:22Neighbor is 142.142.142.142.
19:26The remote autonomous system is 65005.
19:30Neighbor, 142.142.142.142.
19:36Update source, loopback 0.
19:43Oh, do I not have a loopback?
19:47Do I have a loopback?
19:53Active open failed, no route to peer.
20:08Why do you think you have no route to peer?
20:15Let's try this because this is going from-- even though this
20:19is part of the confederation, this is going from loopback
20:23to loopback.
20:24So it could behave like an eBGP.
20:26So let's do this.
20:27Let's do eBGP-- nope, that's not it.
20:31It is the eBGP multihop.
20:36Let's do neighbor 142.142.142.142, eBGP multihop.
20:46Let's give it a 5.
20:48And let's do the same thing on the other direction, neighbor
20:51144.144.144.144, eBGP multihop.
20:56Give it a 5.
20:58Let's see what happens.
20:59Ah, look at that.
21:00Yep, OK, so because we are peering between autonomous
21:03systems, even though they're within the same confederation,
21:09it still behaves like an eBGP relationship.
21:11So we have to have multihop.
21:12So that means the same thing is going
21:13to be true over here between one and three.
21:16And I see that relationship never came up either.
21:18So 143.143.143.143-- nope, 3.
21:22EBGP multihop 5.
21:25Just give myself some padding.
21:27It doesn't specify anything like that.
21:28Neighbor 141.140-- nope, this is 2.
21:32Do that in 2.
21:33We'll do this on 3.
21:36Neighbor 141.141.141.141, eBGP multihop 5.
21:43And let's give it a second.
21:51There we go.
21:53Neighbor adjacency is up.
21:54OK, so now I have my adjacency for autonomous system 400 up.
21:58Next step is step five, form eBGP relationships
22:01between directly connected neighbors
22:03in different autonomous systems.
22:05So eBGP relationships are going to be from 400 to 200,
22:09400-2 to 300, 400-4 to 200, 400-4 to 300, 300 to 100,
22:14and 200 to 100.
22:15So let's actually start from 100 and work our way out.
22:19So we're going to go into router BGP 100.
22:23Neighbor is going to be-- in this case,
22:25we actually can see what our IP addresses are.
22:27Do show IP interface brief.
22:30OK, our first neighbor adjacency is going to be 172.30.
22:35200 is going to be for autonomous system 200.
22:38You remember autonomous system is going to be 200.
22:41Neighbor adjacency here for the 103
22:44is going to be between 100 and 300.
22:46So I just used 103 right there.
22:48103.30, I think is what I set him at?
22:53We'll verify that.
22:55OK, so that's going to be ISP 100's neighbor adjacency
23:00statements.
23:02Let's do ISP 200, BGP 200.
23:07Let's bring up 100 first, 172.30.200.100.
23:11Remote autonomous system is 100.
23:13Let's bring up-- now we're connecting to 400-2 and 400-4.
23:18I have no idea what those IP addresses are.
23:21OK, 172.30.42.something.
23:29Hiccups-- got to look.
23:31Let's see.
23:36So we've got 172.30.42, is going to be 400-2, OK?
23:4442 is 400-2, which is .20 Autonomous system is 400.
23:54Uh-oh.
23:59Cannot configure the local system as neighbor because I am
24:02looking at the wrong IP address.
24:04So this is 400-2, 24--
24:08oh, 42-40.
24:09I was looking at the 31s, of course.
24:14Yeah, I did that on purpose.
24:15I'm tricking myself up.
24:16I even said, like, I'm going to do this to trick myself.
24:19And that is exactly what happened.
24:20So if that one--
24:24and this one is going to be 24.40, OK?
24:28So then on this side, I will say neighbor 172.30.42.20.
24:35Autonomous system is 200.
24:38And over here, we'll say neighbor--
24:42let's do do show IP interface brief.
24:43Do show IP interface brief.
24:45So I'll take a look.
24:46OK, neighbor is 172.30.24.20.
24:50Autonomous system is going to be 200.
24:53So this should bring my eBGP relationships up.
24:55There they go.
24:56They came up to life right there.
24:57And from ISP 200's perspective, do
25:00show BGP IPv4 unicast summary because we don't have
25:05any prefixes advertised yet.
25:07OK, I see my three eBGP relationships for ISP 200
25:12are now brought to life.
25:14Everything shows in the upstate with the timer kicking there.
25:16So let's move on to ISP 300.
25:19Let's give it a show IP interface brief
25:21because I can already tell I'm going to need it.
25:23Router BGP 300.
25:25Neighbor, let's bring up the relationship to ISP 100
25:29first, .100.
25:33Remote autonomous system 100, neighbor 172.30.43.40,
25:44and then 34.40, cool.
25:49So from 400-2, neighbor 172.30.43.30.
25:58Remote autonomous system, 300.
26:00And from 400-4, do show--
26:03OK, let's just do undebug all.
26:05Do undebug all, OK?
26:07Do show IP interface brief.
26:09Neighbor is going to be 172.30.34.30.
26:13Remote autonomous system is 300, OK?
26:20Do show BGP IPv4 unicast summary.
26:23And I see all my relationships are alive here--
26:29cool, cool, cool, cool, cool.
26:30All right, so step 5 is done, form eBGP relationships
26:33between all directly connected neighbors
26:35in different autonomous systems on ISP 300.
26:38Should check that neighbors are only one hop away.
26:42So that's going to be the TTL statements.
26:46Let's see.
26:48Is this is a neighbor statement?
26:49I believe it is.
26:51Neighbor, 172.30.103.100.
26:56TTL Security, hops-- let's just say--
27:02you know what?
27:03I know it says one hop away.
27:05I feel like I should say it needs to just--
27:08OK.
27:09Fine, fine, fine, fine.
27:11You win, one hop.
27:14One hop away, 30.43 and 40 and 34.
27:24So we're checking the TTL on these
27:26that we should be receiving, that they
27:29are only one hop away.
27:32So this is checking that the TTL on these that comes in
27:36is going to be one hop away.
27:40Cool, advertise all loopbacks into BGP.
27:44All right, so let's do this.
27:45It doesn't say how.
27:46We could do a redistribute connected.
27:48We could also do network statements.
27:52In fact, I am-- you know what?
27:53Just to make things easy on me since it doesn't specify,
27:56I am going to do redistribute connected
27:58on any of the ISPs that have my endpoints, my customer
28:04endpoints connected to them.
28:06So that way it also brings in those.
28:08And I don't have to do so many network statements here.
28:10And then it gets really clustered.
28:12So let's do-- should I go into IP address family redistribute
28:17connected?
28:19Cool, so we're bringing in the connected routes
28:23into the IPv4 unicast address family on 400-1.
28:26I also see 400-3 is going to do some redistribution because I
28:31have the customer addresses here, redistribute connected.
28:36And then I have ISP 100, which also has some customer routes
28:44that I'm going to bring in, redistribute connected.
28:47Now, something that I'm expecting
28:48to have a problem with here is the confederation items here.
28:51There's probably going to need to be some next hop self.
28:55Otherwise, some routes are not going to be resolvable.
28:58But I also need to do network statements on ISP 200, 300,
29:01402, and 404.
29:03So let's do network-- what is the loopback here?
29:07130?
29:07OK, network 130.130.130.130 mask 255.255-- this is on ISP 300.
29:18Cool, looking good there.
29:20200, we need to do the same thing.
29:23This is 140-- nope, this is 400-2.
29:26We need to go to ISP 200.
29:28Do show IP interface brief network statement
29:32120.120.120.120 mask 255.
29:39Cool, and then we had 400-2 and 400-4.
29:45OK, so I was on the right one after all, 142.142.142.142,
29:49mask 255.255.255.255 and 400-4, 144.144.144.144 mask
30:01255.255.255.255.
30:04And my hunch, like I said, was that we're
30:06going to have some next hop self problems for routes.
30:10So in this case, I'm looking at, like, ISP 300.
30:13It's going to be advertising its loopback over here
30:15to 400-2 and 400-4.
30:17My expectation is that 400-3 won't know how to reach that.
30:23So let's just check it out.
30:25Oh, look at that.
30:26Something just changed there.
30:28Aha, 30 went down, probably because of the TTL, didn't it?
30:34Probably because of the TTL--
30:43let's fix that.
30:46We probably needed that TTL statement
30:48to go in two directions, don't you think?
30:50So let's say 172.30.34.30 TTL security hops 1 and neighbor
31:05172.30.43.30 TTL security hops 1.
31:15And here come the relationships one more time.
31:17Let's fix ISP 102.172.30.103.30 TTL--
31:25oops, I'm in the address family.
31:27So the issue here is that the TTL security
31:30has to be in two directions.
31:33The hold timer on BGP was three minutes.
31:35So three minutes just passed.
31:37And they probably dropped out because the hold timer
31:42was not--
31:43because the TTL security, the hops
31:45were not matching on both sides.
31:47We hadn't agreed on that security feature yet.
31:49But the relationships are coming back now that I've set it up
31:52to be in two directions.
31:53So like I was saying, I'm expecting ISP 300
31:55to advertise its loopback into ISP 400.
31:58But the distant routers won't be able to receive it.
32:01So let's verify that real quick.
32:03I'm going to look at do show BGP IPv4 unicast.
32:07And let's see.
32:09So that was 130.130.130.130.
32:12And sure enough, I don't know how
32:14to get there because this next hop is the path to ISP 300.
32:20And I haven't learned about that route via OSPF or via BGP.
32:27So I can either advertise this in to BGP,
32:30or which-- you know what?
32:31I probably should just advertise all of these links into BGP.
32:35I probably should just do redistribute connected
32:37everywhere, actually.
32:38That way every router knows about every path
32:40within the environment.
32:42Let me look ahead and make sure I don't have any--
32:45oh, look at that.
32:46I do have something, advertise all routes into BGP.
32:49Well, there you go.
32:50ASN 400 should show--
32:54ASN 400 router should show incomplete.
32:55So there's redistribution.
32:56All of the routes should show an origination of I.
33:00So should have done network statements on ISP 100.
33:08And redistribute connected is what
33:10we need to do on all of the items in ISP 400.
33:15So without further ado, let's just get that going--
33:17IPv4 just redistribute connected, cool.
33:22And let's do this on two, address family IPv4 unicast,
33:27redistribute connected-- cool.
33:31Now that that's done I can go over here now to 400-3,
33:36press up.
33:37And sure enough, now I can actually get to the 130.
33:40I now actually have a little carat here showing
33:43that I have a best path forward.
33:45And it does show as originating internally.
33:48Now, this one is showing-- this is ISP 100's loopback.
33:52It's showing as incomplete.
33:53We do need to fix that because it says all other routes should
33:56show an origination of I. So let's do this,
34:00do show run section BGP.
34:04And let's wipe out my address family IPv4
34:08unicast and no redistribute connected, exit.
34:13Now we have to take it through all these network statements.
34:16Man, why did I do this to myself?
34:17OK, OK, lots of network statements.
34:24Oops, got to go network statements are in IPv4 unicast.
34:27There we go, network.
34:29All right, 192.168.198.0 mask 255.
34:36They're all 24-bit masks.
34:38So keep it easy, at least in that regard.
34:41Seven-- now, jumping ahead, I see I've got one in 10 and 11.
34:48So 10, 11.
34:56Now let's do the 172.30s.
35:01172.30.103.0 200.
35:09And lastly, the loopback.
35:14100.100.100.100.
35:18Wipe out this guy here--
35:21cool.
35:22So if I now jump back, let's see what we got.
35:33Looking a lot better.
35:35I think we have now accomplished our goal.
35:37All right, cool.
35:38So that knocks out seven and eight.
35:40ISP 400-1's loopback should not be
35:43advertised outside of ASN 400.
35:45So there's a few ways you could do that.
35:47You could do a route map that filters it out.
35:50Or the easier way is actually going to be BGP communities.
35:54So let's do this.
35:57Let's say-- time to start sending some communities,
36:00do show run section BGP--
36:05cool.
36:06Tackle my first neighbor, 142.142.142.142,
36:11send community, both, and 143.
36:22Cool, let's do-- got to forward these communities
36:24on throughout the topology, section BGP.
36:31Neighbor 144.144.144.144, send community--
36:40was that an address family when you do that?
36:42Must be.
36:45Neighbor, 144.144.144.144 send community, yep, both, cool.
36:52We'll send it back to 141 just for good measure
36:57and for cleanliness sake.
37:00400-3 show run section BGP, neighbor 141.141.141.141
37:10send community both and 144.
37:20And lastly, we're going to do this coming
37:25back this way, 143.143.143.143, send community both, and 142.
37:36That's what we needed.
37:41Cool, so now we're sending the communities.
37:44Now we actually need to set a community.
37:45So let's do a route map, a prefix list and a route map.
37:49OK, IP prefix list.
37:52What am I going to call this prefix list?
37:53Let's call this 400-1 loop sequence 5 permit.
38:00And the prefix is 141.141.141.141/32.
38:07Let's make a route map that matches it.
38:09Route map-- what's a clever name to call this?
38:17Loop com for community string?
38:20I don't know.
38:21I'm not good at names, guys.
38:22I'm sorry.
38:24Match IP address prefix.
38:28And let's just grab this right here--
38:33cool.
38:34Set community.
38:37OK, let's take a look at our options so we can see.
38:39We want to do no export, do not export to the next autonomous
38:43system because we do want to keep it within advertise.
38:46We do want it to go outside of this autonomous system.
38:49So we're going to export it out of our autonomous system
38:52and into the confederation peer system.
38:57But it won't go outside of that.
38:59So let's do no export.
39:01And now we're going to set our new neighbor statements,
39:05router BGP 65005.
39:13And now our neighbor statement 143.143.143.143 route map.
39:18Nope, not remote.
39:22Is that in the address family?
39:27For unicast neighbor 143.143.143.143 route map.
39:35And what do we call that route map?
39:36Loop com.
39:41Nope, out.
39:43You know what I did?
39:45That route map has an implicit deny all.
39:51So we need to fix that, don't we?
39:54Route map, loop com, sequence 20--
40:03ick-- permit 20.
40:09There we go.
40:11Show route map.
40:15OK, so at this point, let's see.
40:21Do show BGP IPv4 unicast.
40:24OK, we still are receiving 141.141.141.141, which is cool.
40:35But now if I do show BG-- actually, let's
40:39just do show IP route BGP, still have 141 there.
40:45Let's do clear BGP IPv4 unicast, star.
40:52Let's just bounce them all.
41:03Actually, I wonder if that--
41:13I think it might actually be that we didn't
41:15want that sequence twinning.
41:18No route map loop com permit 20.
41:29Do show route map.
41:35Do clear BGP IPv4 unicast.
41:38Oh, not parentheses.
41:41Bounce them all again.
41:45OK, OK, still receiving it here from ISP 200's perspective.
42:09Let's bounce this.
42:11Do clear BGP IPv4 unicast star and do clear BGP IPv4
42:22unicast star because I just don't want to wait.
42:31Still sending it outbound.
42:49Hmm.
42:52Let's do show BGP IPv4 unicast 141.141.141.141.
43:03I don't see the community being set here.
43:13Is this because we redistributed this?
43:26Yeah, actually, BGP 65005 address family IPv4 unicast
43:37network 141.141.141.141, mask 255.255.255.255.
43:45I am going to set that route map back
43:48to have a permit statement map.
43:52There's a loop-comm 20, show route-map, OK, exit, exit.
44:02Show BGP IPv4 unicast.
44:06141.141.141.141.
44:35Might be something wrong with our prefix list?
44:41Access-list standard.
44:45Loop ACL permit host.
44:57Exit.
44:58Show route map.
45:00Loop-comm permit 10 match IP access prefix list.
45:10Grr, I can never remember what I type.
45:18No.
45:29And this loop, ACL is what I named this.
45:51Bounce the neighbors.
45:58Ah, well, it's looking better and not advertised to any peer.
46:09Unicast 142.142.142.142.
46:13Not advertised with any peer.
46:15No best path available, though.
46:17That is peculiar.
46:19Show BGP IPv4-- you know why?
46:41I think we're looking good.
46:48Cool, let's now check over here.
46:53No, still got it.
47:17OK, so here we've got the community of no exports set.
47:23Here we've got the community not set, learn from router two.
47:33So let's do, do clear BGP IPv4 unicast all.
47:36Let's bounce the session.
47:40Back on, looking better.
47:44OK, cool.
47:47Now, from this point of view, if I
47:49do do clear BGP IPv4 unicast star,
47:53bounce the session, no more 141.
48:14But no more 140s anyways.
48:42Show route map.
49:07There we go.
49:08It just took a moment.
49:09Just took a moment to resync.
49:10Everything's OK.
49:12Just took a moment to resync.
49:13And we're all good here.
49:14It almost had me freaking out.
49:15OK, all right, should not be advertised outside.
49:18OK, so 9 is done.
49:19Configure ISP 300 to only advertise its loopback
49:23to ISP 400-4.
49:26So we want ISP 300 to only send its loopback outbound
49:31towards 400-4.
49:32We're not going to send it towards ISP 100.
49:34And we're not going to send it outbound towards ISP 400-2.
49:39Well, that's pretty simple to do.
49:41There's no really struggle here.
49:43We can just use a route map that stops the advertisement
49:46in that direction.
49:47So let's do configure.
49:48Let's do IP access list standard.
49:52Let's call this loop something simple like that.
49:56Permit post and our loopback was--
50:02do show IP interface brief permit 130.130.130.130.
50:13Let's create the route map, route map.
50:15When in doubt, make a route map.
50:17Let's call it stop loop.
50:19Permit 10, match-- no, no, no, not permit 10, deny 10.
50:29Match IP address, what do we call that?
50:32Loop.
50:34And then we'll do route map stop loop permit 20.
50:40So if I do, do show route map, I see
50:43that my first set is going to stop the advertisement
50:46of the loopback.
50:47The second one is going to permit the advertisement
50:49of everything else.
50:50So I did a route map config, a router of BGP 300.
50:56My neighbor towards 400-2, what is neighbor towards 400-2?
51:01Do show IP interface brief, 43.
51:07So come on, mouse.
51:13Address family IPv4 unicast.
51:15My neighbor statement is 172.30.43.40.
51:21Route map was stop loop.
51:25Route out.
51:27And the same thing was 103.100, OK?
51:35Do clear BGP IP list-- because I'm just bouncing them.
51:38I'm just clearing them at this point.
51:41I want to wait for all these things to sync up.
51:43So we're just going to reset them all.
51:46So at this point, I stopped the advertisement towards IS--
51:49let's just see on ISP 100.
51:52Show BGP IPv4 unicast.
51:56So that was 130.
51:58We're are learning 130 via 200, which is probably good
52:04because it learned it from 400, who relayed it to 200,
52:07and so on.
52:08So if I acutally check out 200--
52:11show BGP IPv4 unicast--
52:15I'm learning I don't even have 130.
52:17So we're just waiting for it to expire
52:19at this point on 100's point of view.
52:21Cool, so that looks good.
52:23All right, moving on.
52:40So 300 advertises its loopback to only 400-4.
52:44The next step is configure BGP, such
52:46that ISP 400-4 does not advertise that loopback outside
52:49of the local autonomous system.
52:51So let's do that.
52:53Exit.
52:54Exit.
52:55We're going to create an access list.
52:57Standard-- let's call it 300 loop, something like that.
53:05Invalid access list name.
53:06300 loop, maybe?
53:07No.
53:08OK, because it wants me to loop 300--
53:12cool.
53:13All right, permit post 130.130.130.130.
53:24Route map, it's called just loop 300 again, permit 10,
53:30match IP address, loop 300, set community.
53:37This is going to be no advertise.
53:39Just don't advertise it outside of our local autonomous system.
53:44Cool, and then we're going to say everything else goes.
53:49So route map loop 300, permit 20-- cool.
53:58And now we're going to go back into router BGP 65006.
54:02My neighbor over here is 143--
54:06nope.
54:06This guy has to be done-- route maps have to be done
54:09in the address family mode.
54:11OK, route map-- nope, not route map.
54:17It's getting towards the end.
54:18Hang in there.
54:20143.143.143.143, route map.
54:22And what was that called?
54:23Loop 300?
54:25Cool-- nope, out--
54:27OK.
54:28All right, so now we get fun.
54:30Configure ISP 100 to propagate a default route.
54:34Does ISP 100 have a default route ISP?
54:40It does have a default route.
54:41Can I ping the internet and such?
54:43Sure can.
54:45So let's propagate this default route.
54:48OK, there's two ways to do this.
54:50You have to have a couple of commands to make this happen.
54:52BGP 100, first, is a default information--
54:59is that in address family mode?
55:05Information originate.
55:08Second is a redistribute static.
55:14OK, that should do the trick.
55:17We have default information originate as well as
55:19redistribute static.
55:20It is a static default route.
55:22So that should do the trick.
55:24In just a moment, I should start seeing--
55:27there it is.
55:28Default route is being learned this way.
55:31Can I ping?
55:33There we go.
55:34So ISP 200 can now reach the internet,
55:36thanks to that default route.
55:37Configure ASN 400 such that traffic entering ASN 400
55:42will enter through ASN 400-4.
55:45So we need to make 400-2 look less attractive
55:49somehow, maybe by prepending an additional autonomous system
55:54hop to the end of it.
55:56So let's do routes that we're advertising destined
55:59this way should be coming out of 400-2
56:02should have extra autonomous system hops.
56:04So to do that, we need to do an AS path ACL.
56:08And I always forget this part.
56:10Let's just give it a number, permit,
56:14and our regional exposure.
56:15So routes that originate from us--
56:17carat, dollar sign-- that's how we do that.
56:20And we are going to be using a route
56:22map to append autonomous system hops to the end of that.
56:27So route map, we'll call this prepend not append.
56:30That's what I should have said, prepend, permit.
56:36And we will say match AS path 1.
56:42That's it.
56:42Match AS path 1.
56:44And then we will say set, and that's
56:46going to be AS path, right?
56:47AS path, prepend, and then however many autonomous
56:51systems.
56:52Let's just three or something like that.
56:55Let's now do the rest of them.
56:56We're going to do a route map.
56:59We called this prepend, right?
57:01Permit 20, OK?
57:04All good there.
57:05Now we need to advertise those additional hops
57:07to ISP 200 and 300.
57:10So let's go back and do config t router BGP 65005,
57:14address family IPv4 unicast.
57:19Neighbors this direction was 200.
57:23Shoot, I'll never remember that.
57:25Do show IP interface brief.
57:29OK, neighbor 172.30.42.20 route map, prepend.
57:40Out.
57:41Out.
57:41I always forget the out, always forget the out.
57:45This is going to be 43.30 prepend out.
57:51So now the routes originating from 400-2
57:53will look like it has to go through 400 three times.
57:57OK, configure ASN 200 and 300 to summarize ASN 400's loopbacks
58:03as they are advertised to ASN 100.
58:06So that's the 141s through 144s.
58:15So we're trying to do the aggregate address command,
58:17but not on ISP 100 knocks.
58:19We're doing it on 200 and 300.
58:21We'll do to router of BGP 200, address family IPv4
58:27unicast, the aggregate address command.
58:29And it wants to know what the address is.
58:31So let's say I did 128.0.0.0.
58:36What would the mask be that would encompass 144?
58:40Actually, we could do something more specific than that.
58:46Let's think.
58:46Think, think, think, think.
58:47128, 32, 38 plus 8.
58:54So 138.0.0.0 and then an 8-bit block size
58:59would put me up to 146.
59:01So that would be 54, 52, 40--
59:13no.
59:15254, 252-- 248, right?
59:32248, yeah, I think this is it.
59:39I don't have any other parameters at this one.
59:43Well, that's not going to work, is it?
59:44OK, it doesn't like that.
59:46OK, think.
59:49OK, because it's 8-bit block size.
59:50So math-- 128, 136.
1:00:06Nope, that wouldn't work because that would go up to 144.
1:00:11So it's got to be 128.
1:00:22And that would need to be a 32-bit size
1:00:25to reach over 144 because the 16-bit size would stop at 144.
1:00:31So the 32-bit size--
1:00:338, 40, 224, OK.
1:00:38And this is what also needs to be on ISP 300.
1:00:52So we should, after a while, start filtering those out
1:00:56into the summary addresses.
1:01:14Let's just bounce it, let it all sync up.
1:01:32While it's thinking about that, we'll come back to this.
1:01:35Create the summary such that ISP 400-2's loopback
1:01:39is accessed through ISP 300.
1:01:42So ISP 300 is going to have to leak ISP 400-2's
1:01:47loopback, which is 142.142.142.
1:01:50So let's look at ISP 300 here for a second.
1:01:52Do I have a route?
1:01:55Yep, I have a specific route to 142.142.142.
1:01:59So I can create a route map that leaks that out.
1:02:02Let's do this, IP access list standard.
1:02:07It's actually an unsuppress, I keep saying.
1:02:09So let's just call it unsuppress.
1:02:11I'm not even sure if I'm spelling unsuppress right.
1:02:13And I don't care.
1:02:14They're not going to judge me for spelling on the exam,
1:02:17I hope.
1:02:18142.142.142.142, cool, exit, route map.
1:02:25Unsuppress-- I'm never going to spell it right.
1:02:28Match IP address unsuppress.
1:02:36Yup, that's really all we need to do on that case.
1:02:42Router BGP 300, router BGP 300.
1:02:50This is going to go into address.
1:02:51I'm pretty sure you have to do the unsuppressed map
1:02:53on the neighbor statement?
1:02:59Ah, yes!
1:03:02OK, so now ISP 300 should be advertising 142.142.142.142
1:03:08outbound.
1:03:09Perform a soft reset outbound from 300 to 100.
1:03:15Clear BGP IPv4 unicast 172.30.103.100 soft outbound.
1:03:27That should do the trick.
1:03:42Cool, cool, cool, cool, cool, cool, cool, cool, cool.
1:03:51All right, I think we've just about accomplished
1:03:54all of our goals here.
1:03:56There's a lot of goals.
1:03:57We did a lot of good work today, a lot of fun.
1:04:06I'm just curious about this aggregate address.
1:04:24Oh, you know what I did?
1:04:26The aggregate address, that's not going to work.
1:04:29Summary only.
1:04:35Ah!
1:04:38There we go.
1:04:39I knew I was missing something.
1:04:40It was still sending those more specific prefixes.
1:04:44Router BGP 300, address family IPv4 unicast.
1:04:53Where is that aggregate address command?
1:04:55There you are-- there.
1:05:05OK, bounce them all one more time.
1:05:14Now, yeah, all right.
1:05:20Let's let it sync up, find its feet.
1:05:28There we go.
1:05:31I love it.
1:05:32There's the summary address.
1:05:33There's the more specific prefix coming in.
1:05:38I love it.
1:05:39This makes me happy.
1:05:42This is great.
1:05:44Cool, so that's it.
1:05:45That summarizes our first task there,
1:05:48bringing the internet network to life--
1:05:49really took our BGP skills up a notch.
1:05:53So that's it.
1:05:53That's it for the first one.
1:05:54In the next one, what we are going to work on
1:05:56is the MPLS network.
1:05:58We're not going to bring layer 3 VPN to life.
1:06:00We're just going to bring the network to life.
1:06:02And then we're going to bring the customer sites to life.
1:06:05And then we'll bring the MPLS layer 3 VPN and DMVPN to life
1:06:08after that.
1:06:09So that's it.
1:06:10That's it for me.
1:06:10That's it for the first task here,
1:06:12bringing the internet network to life.
1:06:13Thanks for stopping by, y'all.
1:06:14See you in the next one.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year