Huawei AR Series Access Routers
Book information
Description
About This Document Contents 1 L2TP Configuration 1.1 Overview of L2TP 1.2 Understanding L2TP 1.2.1 Concepts 1.2.2 L2TP Implementation 1.2.3 Working Procedure 1.3 Application Scenarios for L2TP 1.3.1 Client-Initiated L2TP Connection 1.3.2 LAC-Initiated L2TP Connection upon Receiving a Call ConnectionRequest 1.3.3 LAC-Initiated L2TP Connection upon Receiving a Call from aPPPoE User 1.3.4 L2TP Client-Initiated L2TP Connection 1.3.5 LAC-Initiated L2TP Connection When Users from Multiple DomainsAre Connected 1.3.6 Authenticating VPDN Users Using the RADIUS Server 1.3.7 Allocating the Frame-IP and Frame-Route Attributes and theSpecified Address Pool Name to L2TP Users by the RADIUS Server 1.3.8 Setting Up a Secure Tunnel Connection Using L2TP over IPSecEncapsulation 1.3.9 Setting Up a Secure Tunnel Connection Using IPSec over L2TPEncapsulation 1.4 Licensing Requirements and Limitations for L2TP 1.5 Default Settings for L2TP 1.6 Configuring L2TP 1.6.1 Configuring the LAC to Initiate Call-Triggered L2TP Connections 1.6.1.1 Configuring AAA Authentication and Accounting 1.6.1.2 Configuring the LAC to Accept Dial-Up Calls and Initiate L2TPConnections 1.6.1.3 Configuring the LNS to Respond to the L2TP Connection Request 1.6.2 Configuring L2TP Client-Initiated L2TP Connections 1.6.2.1 Configuring AAA Authentication and Accounting 1.6.2.2 Configuring the L2TP Client to Dial Up and Initiate L2TP Connections 1.6.2.3 Configuring the LNS to Respond to the L2TP Connection Request 1.6.3 Configuring Other L2TP Functions 1.6.3.1 Configuring LCP Renegotiation 1.6.3.2 Configuring CHAP Mandatory Authentication 1.6.3.3 Configuring Primary and Secondary LNSs 1.6.3.4 Configuring AVP Parameter Encryption 1.6.3.5 Configuring L2TP Tunnel Authentication 1.6.3.6 Configuring L2TP Tunnel Connectivity 1.6.4 Verifying the L2TP Configuration 1.7 Maintaining L2TP 1.7.1 Disconnecting an L2TP Tunnel Manually 1.7.2 Monitoring the Running Status of L2TP 1.7.3 Collecting L2TP Packet Statistics 1.8 Configuration Examples for L2TP 1.8.1 Example for Configuring Client-Initiated L2TP Connections 1.8.2 Example for Configuring the LAC to Initiate Call-TriggeredL2TP Connections (Dial-Up Users) 1.8.3 Example for Configuring the LAC to Initiate Call-Triggered L2TP Connections (PPPoE Users) 1.8.4 Example for Configuring an L2TP Client-Initiated L2TP Connection 1.8.5 Example for Configuring L2TP Client-Initiated L2TP Connections 1.8.6 Example for Configuring L2TP Client-Initiated L2TP Connections Using the 3G Interface 1.9 Troubleshooting L2TP 1.9.1 User Failed to Dial Up to the LNS 1.9.2 Data Transmission Fails After L2TP Connections Are Established 1.10 FAQ About L2TP 1.10.1 Starting from Which Version Does the device Support NAT Traversalin L2TP? 1.10.2 L2TP Dialup Is Successful After Dozens of Attempts and Error691 Is Displayed. Why? 1.10.3 How Can I Quickly Locate Why the LAC Cannot Set Up an L2TPTunnel with the LNS? 1.10.4 How Do I Configure the LNS That Trusts the LAC Not to PerformSecond Authentication on Remote Users? 1.10.5 What Can I Do If a PC Running the Windows 7 or XP OperatingSystem Fails to Establish an L2TP over IPSec Tunnel with the Device? 2 L2TPv3 Configuration 2.1 Overview of L2TPv3 2.2 Understanding L2TPv3 2.3 Application Scenarios for L2TPv3 2.4 Licensing Requirements and Limitations for L2TPv3 2.5 Configuring L2TPv3 2.5.1 Configuring a Static L2TPv3 Tunnel 2.5.2 Verifying the L2TPv3 Configuration 2.6 Monitoring the L2TPv3 Tunnel Running Status 2.7 Configuration Examples for L2TPv3 2.7.1 Example for Establishing a Static L2TPv3 Tunnel 2.7.2 Example for Configuring L2TPv3 over IPSec to Implement Secure Communication Between Branches 3 GRE Configuration 3.1 Overview of GRE 3.2 Understanding GRE 3.2.1 Basic Concepts 3.2.2 GRE Security Mechanisms 3.2.3 Keepalive Detection 3.2.4 Ethernet over GRE 3.2.5 Ethernet over mGRE 3.3 Application Scenarios for GRE 3.3.1 Transmitting Data of Multi-Protocol Local Networks Througha GRE Tunnel 3.3.2 Enlarging the Operation Scope of a Network with a Hop Limit 3.3.3 Combining GRE with IPSec to Protect Multicast Data 3.3.4 Setting Up an L2VPN and an L3VPN Using a GRE Tunnel 3.3.5 Connecting CE Devices to an MPLS VPN Network 3.3.6 Ethernet over GRE Application 3.3.7 Ethernet over mGRE Application 3.4 Licensing Requirements and Limitations for GRE 3.5 Default Settings for GRE 3.6 Configuring a GRE Tunnel 3.6.1 Configuring a Tunnel Interface 3.6.2 Configuring a Route on a Tunnel Interface 3.6.3 (Optional) Configuring the Link Bridge Function 3.6.4 (Optional) Configuring a Security Mechanism for GRE 3.6.5 (Optional) Enabling the Keepalive Detection Function for GRE 3.6.6 (Optional) Configuring Ethernet over GRE 3.6.7 (Optional) Configuring Ethernet over mGRE 3.6.8 (Optional) Configuring the DF Flag Bit for GRE Packets 3.6.9 Verifying the GRE Tunnel Configuration 3.7 Maintaining the GRE Tunnel 3.7.1 Collecting and Viewing Statistics on Tunnel Interfaces 3.7.2 Monitoring the GRE Running Status 3.7.3 Resetting the Keepalive Packet Statistics on a Tunnel Interface 3.8 Configuration Examples for GRE 3.8.1 Example for Configuring a Static Route for GRE to ImplementInterworking Between IPv4 Networks 3.8.2 Example for Configuring OSPF for GRE to Implement InterworkingBetween IPv4 Networks 3.8.3 Example for Configuring a GRE Tunnel to Implement InterworkingBetween IPv6 Networks 3.8.4 Example for Enlarging the Operation Scope of a Network witha Hop Limit 3.8.5 Example for Configuring BGP/MPLS IP VPN to Use a GRE Tunnel 3.8.6 Example for Configuring VLL to Use a GRE Tunnel 3.8.7 Example for Connecting a CE to a VPN Through a GRE Tunnel overa Public Network 3.8.8 Example for Connecting a CE to a VPN Through a GRE Tunnel overa VPN 3.8.9 Example for Configuring GRE to Implement Communication BetweenFR Networks 3.8.10 Example for Configuring an Ethernet over GRE Tunnel 3.8.11 Example for Configuring an Ethernet over mGRE Tunnel 3.9 Troubleshooting GRE 3.9.1 Failed to Ping the IP Address of the Remote Tunnel Interface 3.9.2 Tunnel Interface Alternates Between Up and Down States 3.10 FAQ About GRE 3.10.1 Can the MTU of the GRE Tunnel Interface Take Effect? 3.10.2 What Is QoS Information in an Outer IP Header During GRE Encapsulation? 4 DSVPN Configuration 4.1 Overview of DSVPN 4.2 Understanding DSVPN 4.2.1 Basic Concepts 4.2.2 Implementation 4.2.3 DSVPN NAT Traversal 4.2.4 DSVPN Protected by IPSec 4.2.5 DSVPN Reliability 4.2.5.1 Dual Hubs in Active/Standby Mode 4.2.5.2 Dual Hubs in Load Balancing Mode 4.3 Application Scenarios for DSVPN 4.3.1 DSVPN Deployment on a Small- or Medium-sized Network 4.3.2 DSVPN Deployment on a Large-sized Network 4.3.3 Deploying DSVPN in Hierarchical Hub Networking 4.4 Licensing Requirements and Limitations for DSVPN 4.5 Default Settings for DSVPN 4.6 Configuring DSVPN 4.6.1 Configuring mGRE 4.6.2 Configuring Routes 4.6.3 Configuring NHRP 4.6.4 (Optional) Configuring an IPSec Profile 4.6.5 Verifying the DSVPN Configuration 4.7 Maintaining DSVPN 4.7.1 Clearing DSVPN Running Statistics 4.7.2 Monitoring DSVPN Running Statistics 4.8 Configuration Examples for DSVPN 4.8.1 Example for Configuring Non-Shortcut Scenario of DSVPN (Static Route) 4.8.2 Example for Configuring Non-Shortcut Scenario of DSVPN (RIP) 4.8.3 Example for Configuring Non-Shortcut Scenario of DSVPN (OSPF) 4.8.4 Example for Configuring Non-ShortcutScenario of DSVPN (BGP) 4.8.5 Example for Configuring Shortcut Scenario of DSVPN (RIP) 4.8.6 Example for Configuring Shortcut Scenario of DSVPN (OSPF) 4.8.7 Example for Configuring Shortcut Scenario of DSVPN (BGP) 4.8.8 Example for Configuring DSVPN NAT traversal 4.8.9 Example for Configuring Dual Hubs in Active/Standby Mode 4.8.10 Example for Configuring DSVPN Protected by IPSec 4.8.11 Example for Configuring aDual-Hub DSVPN Protected by IPSec 4.8.12 Example for Configuring a DSVPN Based on the LTE Dialup Status 4.9 Troubleshooting DSVPN 4.9.1 Spoke Fails to Register with a Hub 4.9.2 Subnets Between Spokes Cannot Communicate Directly in Non-Shortcut Mode 4.9.3 Subnets Between Spokes Cannot Communicate Directly in Shortcut Mode 4.9.4 Backup Hub Only Forwards Data After the Master Hub Fails 5 IPSec Configuration 5.1 Overview of IPSec 5.2 Understanding IPSec 5.2.1 IPSec Framework 5.2.1.1 Security Association 5.2.1.2 Security Protocols 5.2.1.3 Encapsulation Modes 5.2.1.4 Encryption and Authentication 5.2.1.5 Key Exchange 5.2.2 IPSec Working Mechanisms 5.2.2.1 Defining IPSec-Protected Data Flows 5.2.2.2 Establishing SAs Through IKEv1 Negotiation 5.2.2.3 Establishing SAs Through IKEv2 Negotiation 5.2.3 IPSec Enhancements 5.2.3.1 L2TP over IPSec 5.2.3.2 GRE over IPSec 5.2.3.3 IPSec Multi-instance 5.2.3.4 Efficient VPN 5.2.4 IPSec Reliability 5.2.4.1 Link Redundancy 5.3 Application Scenarios for IPSec 5.3.1 Using IPSec VPN to Implement Secure Interconnection Between LANs 5.3.2 Using IPSec VPN to Provide Secure Remote Access for Mobile Users 5.3.3 Secure LAN Interconnection Through Efficient VPN 5.4 Summary of IPSec Configuration Tasks 5.5 Licensing Requirements and Limitations for IPSec 5.6 Default Settings for IPSec 5.7 Using an ACL to Establish an IPSec Tunnel 5.7.1 Defining Data Flows to Be Protected 5.7.2 Configuring an IPSec Proposal 5.7.3 Configuring an IPSec Policy 5.7.3.1 Configuring an IPSec Policy in Manual Mode 5.7.3.2 Configuring an IPSec Policy in ISAKMP Mode 5.7.3.3 Configuring an IPSec Policy Using an IPSec Policy Template 5.7.4 (Optional) Setting the IPSec SA Lifetime 5.7.5 (Optional) Enabling the Anti-replay Function 5.7.6 (Optional) Configuring IPSec Fragmentation Before Encryption 5.7.7 (Optional) Configuring Route Injection 5.7.8 (Optional) Configuring IPSec Check 5.7.9 (Optional) Enabling the QoS Function for IPSec Packets 5.7.10 (Optional) Configuring IPSec VPN Multi-instance 5.7.11 (Optional) Allowing New Users with the Same Traffic Rule as Original Branch Users to Access the Headquarters Network 5.7.12 (Optional) Configuring a Multi-link Shared IPSec Policy Group 5.7.13 (Optional) Configuring Redundancy Control of IPSec Tunnels 5.7.14 (Optional) Configuring IPSec Mask Filtering 5.7.15 Applying an IPSec Policy Group to an Interface 5.7.16 Verifying the Configuration of IPSec Tunnel Establishment 5.8 Using a Virtual Tunnel Interface to Establish an IPSec Tunnel 5.8.1 Configuring an IPSec Proposal 5.8.2 Configuring an IPSec Profile 5.8.3 (Optional) Setting the SA Lifetime 5.8.4 (Optional) Enabling the Anti-replay Function 5.8.5 (Optional) Configuring IPSec Fragmentation Before Encryption 5.8.6 (Optional) Configuring IPSec Check 5.8.7 (Optional) Enabling the QoS Function for IPSec Packets 5.8.8 (Optional) Configuring Requesting, Sending or Accepting of Subnet Route Information 5.8.9 Configuring a Tunnel Interface or a Tunnel Template Interface 5.8.10 Verifying the Configuration of IPSec Tunnel Establishment Using a Virtual Tunnel Interface 5.9 Establishing an IPSec Tunnel Using an Efficient VPN Policy 5.9.1 Configuring the Remote Device 5.9.2 Configuring the Efficient VPN Server 5.9.3 Verifying the Efficient VPN Configuration 5.10 Configuring IKE 5.10.1 Configuring an IKE Proposal 5.10.2 Configuring an IKE Peer 5.10.3 (Optional) Setting the IKE SA Lifetime 5.10.4 (Optional) Configuring IKE Peer Status Detection 5.10.4.1 (Optional) Configuring Heartbeat Detection 5.10.4.2 (Optional) Configuring DPD 5.10.5 (Optional) Configuring an Identity Filter Set 5.10.6 (Optional) Configuring DSCP Priority for IKE Packets 5.10.7 (Optional) Configuring NAT Traversal 5.10.8 (Optional) Configuring IPSec VPN Multi-instance 5.10.9 (Optional) Configuring Network Resource Delivery 5.10.10 (Optional) Configuring ACL Delivery 5.10.11 (Optional) Enabling Dependency Between IPSec SA and IKE SA During IKEv1 Negotiation 5.10.12 (Optional) Configuring Rapid Switchover and Revertive Switching of an IKE Peer 5.10.13 (Optional) Disabling Validity Verification on Certificates 5.10.14 Verifying the IKE Configuration 5.11 Configuring IPSec for OSPFv3 Data Encryption 5.11.1 Before You Start 5.11.2 Configuring a Security Proposal 5.11.3 Configuring an SA 5.11.4 Checking the Configuration 5.12 Maintaining IPSec 5.12.1 Monitoring the IPSec Running Status 5.12.2 Clearing IPSec Statistics 5.12.3 Clearing Statistics on IPSec-encrypted OSPFv3 Packets 5.13 Configuration Examples for IPSec 5.13.1 Example for Manually Establishing an IPSec Tunnel 5.13.2 Example for Establishing an IPSec Tunnel in IKE Negotiation Mode Using Default Settings 5.13.3 Example for Establishing an IPSec Tunnel Between the Enterprise Headquarters and Branch Using an IPSec Policy Template 5.13.4 Example for Establishing Multiple IPSec Tunnels Between the Enterprise Headquarters and Branches Using IPSec Policy Groups 5.13.5 Example for Establishing IPSec Tunnels for Branch Access to the Headquarters Using Different Pre-shared Keys 5.13.6 Example for Establishing an IPSec Tunnel Between the Branch and Headquarters with a Redundant Gateway 5.13.7 Example for Establishing an IPSec Tunnel Between the Enterprise Headquarters and Branch Using a Multi-Link Shared IPSec Policy Group 5.13.8 Example for Establishing an IPSec Tunnel Between the Enterprise Headquarters and Branch Through PPPoE 5.13.9 Example for Establishing an IPSec Tunnel Through NAT Traversal 5.13.10 Example for Establishing an IPSec Tunnel in IKE Negotiation Mode by Specifying DNs 5.13.11 Example for Establishing an IPSec Tunnel Through Negotiation Initiated by the Branch User That Dynamically Obtains an IP Address 5.13.12 Example for Establishing an IPSec Tunnel Using a Tunnel Interface 5.13.13 Example for Establishing GRE over IPSec Tunnel Using a Tunnel Interface 5.13.14 Example for Establishing IPSec over GRE Tunnel Using a Tunnel Interface 5.13.15 Example for Establishing an IPSec over GRE Tunnel Between the Headquarters and Branch (Based on ACL) 5.13.16 Example for Establishing IPSec over DSVPN Tunnels Between Hub and Spokes (Based on ACL) 5.13.17 Example for Configuring L2TP Over IPSec to Implement SecureCommunication Between the Headquarters and Branch 5.13.18 Example for Configuring a Tunnel Template Interface for IPSec Tunnel Setup 5.13.19 Example for Establishing an IPSec Tunnel Using an Efficient VPN Policy in Client Mode 5.13.20 Example for Configuring an IPSec Tunnel Using an Efficient VPN Policy in Network Mode 5.13.21 Example for Configuring an IPSec Tunnel Using an Efficient VPN Policy in Network-Plus Mode 5.13.22 Example for Configuring Efficient VPN in Network-auto-cfg Mode to Establish an IPSec Tunnel 5.13.23 Example for Configuring Automatic Upgrade of the Efficient VPN Remote Device 5.13.24 Example for Configuring Rapid Switchover and Revertive Switching 5.13.25 Example for Configuring Redundancy Control of IPSec Tunnels 5.13.26 Example for Configuring IPSec for OSPFv3 5.14 Troubleshooting IPSec 5.14.1 IKE SA Negotiation Failed 5.14.2 IPSec SA Negotiation Failed 5.14.3 Services Are Interrupted After an IPSec Tunnel Is Established 5.15 FAQ About IPSec 5.15.1 Private Network Communication Fails After IPSec Is Configured. What Are the Causes? 5.15.2 How Do I Rectify the Failure to View SA Information by Runningthe display ipsec sa Command After IPSec Is Configured? 5.15.3 Does the Interface with a Dynamic IP Address Support IPSec? 5.15.4 IPSec Does Not Take Effect When Both IPSec and NAT Are Configuredon a Device Interface. How This Problem Is Solved? 5.15.5 Why Cannot an IPSec Tunnel Be Established Until It Is Restarted? 6 A2A VPN Configuration 6.1 Overview of A2A VPN 6.2 Understanding A2A VPN 6.2.1 Basic Networking 6.2.2 Implementation 6.2.2.1 GM Registering with the KS 6.2.2.2 GM Data Protection 6.2.2.3 Rekey 6.3 Application Scenarios for A2A VPN 6.3.1 Typical A2A VPN Networking 6.3.2 A2A VPN Redundancy 6.4 Licensing Requirements and Limitations for A2A VPN 6.5 Default Settings for A2A VPN 6.6 Configuring A2A VPN 6.6.1 Configuring a KS 6.6.1.1 Defining the Data Flows to Be Protected by A2A VPN 6.6.1.2 Configuring IKE 6.6.1.3 Configuring an IPSec Proposal 6.6.1.4 Configuring a GDOI Group 6.6.1.5 (Optional) Configuring the SA Mode 6.6.1.6 (Optional) Configuring the Group SA Lifetime 6.6.1.7 (Optional) Configuring the Time-based Anti-Replay Function 6.6.1.8 Verifying the KS Configuration 6.6.2 Configuring a GM 6.6.2.1 Configuring IKE 6.6.2.2 (Optional) Defining Data Flows Not to Be Protected 6.6.2.3 Configuring a GDOI Policy 6.6.2.4 Configuring an IP Address for Multicast Rekey Messages 6.6.2.5 (Optional) Configuring the Receive_Option Mode 6.6.2.6 (Optional) Configuring the QoS Function for A2A VPN 6.6.2.7 (Optional) Configuring A2A VPN Multi-Link Sharing 6.6.2.8 (Optional) Configuring Fragmentation Before Encryption 6.6.2.9 Applying a GDOI Policy Group to an Interface 6.6.2.10 Verifying the GM Configuration 6.7 Maintaining A2A VPN 6.7.1 Monitoring the A2A VPN Status 6.7.2 Clearing A2A VPN Statistics 6.8 Configuration Examples for A2A VPN 6.8.1 Example for Configuring Services to be Protected by A2A VPNBetween a Branch and the Headquarters 6.8.2 Example for Configuring the MPLS VPN Protected by the A2A VPN 6.8.3 Example for Configuring GM Link Redundancy 6.9 Troubleshooting A2A VPN 6.9.1 GM Fails to Register with the KS 6.10 A2A VPN FAQ 6.10.1 Why Some Service Packets Are Lost After A2A VPN Is Deployed? 7 BGP/MPLS IP VPN Configuration 7.1 Overview of BGP/MPLS IP VPN 7.2 Understanding BGP/MPLS IP VPN 7.2.1 Concepts 7.2.2 Implementation 7.2.3 Basic Networking 7.2.4 Inter-AS VPN 7.2.5 MCE 7.2.6 HoVPN 7.2.7 VPN FRR 7.2.8 VPN GR 7.2.9 VPN NSR 7.2.10 VPN Tunnel Policy 7.3 Application Scenarios for BGP/MPLS IP VPN 7.3.1 BGP/MPLS IP VPN Application 7.3.2 Hub and Spoke Networking Application 7.3.3 Interconnection Between VPNs and the Internet 7.4 Summary of BGP/MPLS IP VPN Configuration Tasks 7.5 Licensing Requirements and Limitations for BGP/MPLS IP VPN 7.6 Default Settings for BGP/MPLS IP VPN 7.7 Configuring BGP/MPLS IP VPN 7.7.1 Configuring Basic BGP/MPLS IP VPN Functions 7.7.1.1 Configuration Tasks 7.7.1.2 Establishing MP-IBGP Peer Relationships Between PE Devices 7.7.1.3 Configuring a VPN Instance on a PE Device 7.7.1.4 Binding a VPN Instance to an Interface 7.7.1.5 Configuring Route Exchange Between PE and CE Devices 7.7.1.6 Verifying the Configuration of Basic BGP/MPLS IP VPN Functions 7.7.2 Configuring Hub and Spoke 7.7.2.1 Configuring MP-IBGP Between Hub-PE and Spoke-PE 7.7.2.2 Configuring VPN Instances on PE Devices 7.7.2.3 Binding a VPN Instance to an Interface 7.7.2.4 Configuring Route Exchange Between PE device and CE Devices 7.7.2.5 Verifying the Hub and Spoke Configuration 7.7.3 Configuring Inter-AS VPN Option A 7.7.4 Configuring Inter-AS VPN Option B 7.7.4.1 Configuring MP-IBGP Between PE and ASBR in the Same AS 7.7.4.2 Configuring MP-EBGP Between ASBRs in Different ASs 7.7.4.3 Disabling an ASBR from Filtering VPNv4 Routes by VPN Targets 7.7.4.4 (Optional) Configuring Routing Policies to Control VPN RouteAdvertisement and Acceptance 7.7.4.5 (Optional) Enabling Next-Hop-based Label Allocation on theASBR 7.7.4.6 Verifying the Inter-AS VPN Option B Configuration 7.7.5 Configuring Inter-AS VPN Option C (Solution 1) 7.7.5.1 Enabling the Labeled IPv4 Route Exchange 7.7.5.2 Configuring a Routing Policy to Control Label Distribution 7.7.5.3 Establishing an MP-EBGP Peer Relationship Between PE Devices 7.7.5.4 Verifying the Inter-AS VPN Option C Configuration (Solution 1) 7.7.6 Configuring Inter-AS VPN Option C (Solution 2) 7.7.6.1 Establishing the EBGP Peer Relationship Between ASBRs 7.7.6.2 Advertising the Routes of the PE in the Local AS to the RemotePE 7.7.6.3 Enabling the Capability of Exchanging Labeled IPv4 Routes 7.7.6.4 Establishing an LDP LSP for the Labeled BGP Routes of the PublicNetwork 7.7.6.5 Establishing the MP-EBGP Peer Relationship Between PEs 7.7.6.6 Verifying the Inter-AS VPN Option C Configuration (Solution 2) 7.7.7 Configuring an MCE Device 7.7.7.1 Configure Route Exchange Between an MCE Device and VPN Sites 7.7.7.2 Configure Route Exchange Between an MCE Device and a PE Device 7.7.7.3 Verifying the MCE Configuration 7.7.8 Configuring HoVPN 7.7.9 Configuring PBR to an LSP for VPN Packets 7.7.10 Configuring an OSPF Sham Link 7.7.11 Configuring Route Reflection to Optimize the VPN Backbone Layer 7.7.11.1 Configuring the Client PEs to Establish MP IBGP Connectionswith the RR 7.7.11.2 Configuring the RR to Establish MP IBGP Connections with theClient PEs 7.7.11.3 Configuring Route Reflection for BGP IPv4 VPN Routes 7.7.11.4 Verifying the Configuration of Route Reflection to Optimize the VPN Backbone Layer 7.7.12 Configuring IP FRR for VPN Routes 7.7.13 Configuring VPN FRR 7.7.14 Configuring VPN GR 7.7.15 Configuring Tunnel Policies 7.7.15.1 Configuring and Applying a Tunnel Policy 7.7.15.2 Configuring and Applying a Tunnel Selector 7.7.16 Connecting a VPN to the Internet 7.8 Maintaining BGP/MPLS IP VPN 7.8.1 Collecting Statistics About L3VPN Traffic 7.8.2 Checking L3VPN Traffic 7.8.3 Clearing L3VPN Traffic 7.8.4 Displaying BGP/MPLS IP VPN Information 7.8.5 Checking Network Connectivity and Reachability 7.8.6 Viewing the Integrated Route Statistics of IPv4 VPN Instances 7.8.7 Resetting BGP Statistics of a VPN Instance IPv4 Address Family 7.8.8 Resetting BGP Connections 7.8.9 Monitoring the Running Status of VPN Tunnels 7.9 Configuration Examples for BGP/MPLS IP VPN 7.9.1 Example for Configuring BGP/MPLS IP VPN 7.9.2 Example for Configuring BGP/MPLS IP VPNs with Overlapping AddressSpaces 7.9.3 Example for Configuring Communication Between Local VPNs 7.9.4 Example for Configuring Hub and Spoke 7.9.5 Example for Configuring Inter-AS VPN Option A 7.9.6 Example for Configuring Inter-AS VPN Option B 7.9.7 Example for Configuring Inter-AS VPN Option C (Solution 1) 7.9.8 Example for Configuring Inter-AS VPN Option C (Solution 2) 7.9.9 Example for Configuring MCE 7.9.10 Example for Configuring PBR to an LSP for VPN Packets 7.9.11 Example for Configuring HoVPN 7.9.12 Example for Configuring an OSPF Sham Link 7.9.13 Example for Configuring BGP AS Number Substitution 7.9.14 Example for Configuring the BGP SoO Attribute 7.9.15 Example for Configuring CE Dual-homing 7.9.16 Example for Configuring VPN FRR 7.9.17 Example for Configuring IP FRR for VPN Routes 7.9.18 Example for Configuring VPN GR 7.9.19 Example for Configuring Double RRs to Optimize the VPN BackboneLayer 7.9.20 Example for Connecting a VPN to the Internet 7.9.21 Example for Configuring BGP/MPLS IP VPN to Use a GRE Tunnel 7.9.22 Example for Configuring L3VPN Using LDP Signaling over GRE 7.9.23 Example for Configuring L3VPN with LDP Signals Carried by DSVPN 7.9.24 Example for Configuring L3VPN with LDP Signals Carried by DSVPNand Protected by IPSec 7.9.25 Example for Configuring a Tunnel Policy for an L3VPN 7.10 FAQ About BGP/MPLS IP VPN 7.10.1 Why Routes Cannot Be Imported When AS Numbers on the BGP/MPLS IP VPN Are the Same? 8 MCE IPv6 Configuration 8.1 Overview of MCE IPv6 8.2 Licensing Requirements and Limitations for MCE IPv6. 8.3 Configuring an MCE Device 8.3.1 Configuring a VPN Instance 8.3.2 Configure Route Exchange Between an MCE Device and VPN Sites 8.3.3 Configure Route Exchange Between an MCE Device and a PE Device 8.3.4 Verifying the MCE Configuration 8.4 Configuration Examples for MCE IPv6 8.4.1 Example for Configuring an MCE IPv6 Device 9 EVPN Configuration 9.1 Overview of EVPN 9.2 Understanding EVPN 9.2.1 Implementation 9.3 Application Scenarios for EVPN 9.3.1 EVPN Applications 9.4 Licensing Requirements and Limitations for EVPN 9.5 Configuring EVPN Functions 9.5.1 Before You Start 9.5.2 Configuring a VPN Instance 9.5.3 Binding an Interface to a VPN Instance 9.5.4 Configuring an EVPN BGP Peer Relationship 9.5.5 Verifying the EVPN Configuration 9.6 Maintaining EVPN 9.6.1 Configuring EVPN BGP Soft Reset 9.6.2 Resetting EVPN BGP Connections 9.7 Configuration Examples for EVPN 9.7.1 Example for Dynamically Establishing a VXLAN Tunnel in BGP EVPN Mode to Implement Communication Between Users in Different Network Segments 9.8 References for EVPN 10 VLL Configuration 10.1 Overview of VLL 10.2 Understanding VLL 10.2.1 Implementation 10.2.2 VLL Modes 10.2.2.1 VLL in CCC Mode 10.2.2.2 VLL in Martini Mode 10.2.2.3 VLL in SVC Mode 10.2.2.4 Comparison of VLL Modes 10.2.3 Inter-AS VLL 10.2.4 VLL FRR 10.3 Application Scenarios for VLL 10.3.1 Point-to-Point Layer 2 Connection Between Sites in DifferentCities 10.3.2 Multi-service Transparent Transmission over PWs on a MAN 10.4 Summary of VLL Configuration Tasks 10.5 Licensing Requirements and Limitations for VLL 10.6 Default Settings for VLL 10.7 Configuring VLL 10.7.1 Configuring the CCC VLL 10.7.2 Configuring the Martini VLL 10.7.3 Configuring the SVC VLL 10.7.4 Configuring Inter-AS VLL 10.7.5 Configuring VLL FRR 10.7.5.1 Configuring Primary and Secondary PWs 10.7.5.2 (Optional) Configuring Fast Fault Notification - OAM Mapping 10.7.5.3 (Optional) Configuring BFD for PW 10.7.5.4 (Optional) Configuring a Revertive Switchover Policy 10.7.5.5 Verifying the VLL FRR Configuration 10.7.6 Configuring the Access of VLL to L3VPN 10.7.6.1 Before You Start 10.7.6.2 Creating an L2VE Interface 10.7.6.3 Creating an L3VE Interface 10.7.6.4 Associating the L2VE Interface with a VLL 10.7.6.5 Configuring the Access of a User to L3VPN 10.7.6.6 Verifying the configuration of Martini VLL to Access L3VPN 10.7.7 Configuring and Applying a Tunnel Policy 10.7.8 Configuring the Alarm Report Function 10.8 Maintaining VLL 10.8.1 Monitoring the Running Status of VLL 10.8.2 Checking Connectivity of the VLL Network 10.9 Configuration Examples for VLL 10.9.1 Example for Configuring a Local CCC Connection 10.9.2 Example for Configuring a VLL Connection in SVC Mode 10.9.3 Example for Configuring a VLL Connection in Martini Mode 10.9.4 Example for Configuring Inter-AS Martini VLL (Option A) 10.9.5 Example for Configuring Martini VLL FRR (Asymmetrically Connected CEs) 10.9.6 Example for Configuring VLL to Use a GRE Tunnel 10.9.7 Example for Configuring a VLL Using an MPLS TE Tunnel 10.10 Troubleshooting VLL 10.10.1 The VC of a Martini VLL Connection Cannot Go Up 11 PWE3 Configuration 11.1 Overview of PWE3 11.2 Relationship Between PWE3 and L2VPN 11.2.1 Extensions to the Control Plane 11.2.2 Extensions at the Data Plane 11.3 Understanding PWE3 11.3.1 Implementation 11.3.2 Control Word 11.3.3 VCCV 11.3.4 PWE3 FRR 11.3.5 Inter-AS Technology 11.4 Application Scenarios for PWE3 11.4.1 PWE3 Carrying Enterprise Leased Line Services on a MAN 11.5 Summary of PWE3 Configuration Tasks 11.6 Licensing Requirements and Limitations for PWE3 11.7 Default Settings for PWE3 11.8 Configuring PWE3 11.8.1 Configuring a Static PW 11.8.1.1 Enabling MPLS L2VPN 11.8.1.2 (Optional) Creating a PW Template and Setting Attributes forthe PW Template 11.8.1.3 Creating a Static PW 11.8.1.4 Verifying the Static PW Configuration 11.8.2 Configuring a Dynamic PW 11.8.2.1 Enabling MPLS L2VPN 11.8.2.2 (Optional) Creating a PW Template and Setting Attributes forthe PW Template 11.8.2.3 Creating a Dynamic PW 11.8.2.4 Verifying the Dynamic PW Configuration 11.8.3 Configuring PW Switching 11.8.4 Configuring TDM PWE3 11.8.4.1 Configuring an AC Interface to Transparently Transmit TDM Cells 11.8.4.2 (Optional) Creating a PW Template and Setting Attributes forthe PW Template 11.8.4.3 Configuring PW 11.8.4.4 Verifying the TDM PWE3 Configuration 11.8.5 Configuring Static BFD for PWs 11.8.5.1 Enabling BFD Globally 11.8.5.2 Configuring BFD for PWs 11.8.5.3 Verifying the Configuration of Static BFD for PWs 11.8.6 Configuring PWE3 FRR 11.8.6.1 Configuring Primary and Secondary PWs 11.8.6.2 (Optional) Configuring Fast Fault Notification - OAM Mapping 11.8.6.3 (Optional) Configuring BFD for PW 11.8.6.4 (Optional) Configuring a Revertive Switchover Policy 11.8.6.5 Verifying the PWE3 FRR Configuration 11.8.7 Configuring Inter-AS PWE3 11.8.8 Configuring and Applying a Tunnel Policy 11.9 Maintaining PWE3 11.9.1 Verifying Connectivity of a PW 11.9.2 Locating a Fault on a PW 11.10 Configuration Examples for PWE3 11.10.1 Example for Configuring a Dynamic Single-Segment PW 11.10.2 Example for Configuring a Static Multi-Segment PW 11.10.3 Example for Configuring a Dynamic Multi-Segment PW 11.10.4 Example for Configuring a Mixed Multi-Segment PW 11.10.5 Example for Configuring Inter-AS PWE3 Option A 11.10.6 Example for Configuring TDM PWE3 (Using the 8E1T1-M InterfaceCard) 11.10.7 Example for Configuring TDM PWE3 (Using the 8SA interface card) 12 VPLS Configuration 12.1 Overview of VPLS 12.2 Understanding VPLS 12.2.1 Implementation 12.2.2 PW Signaling Protocols 12.2.3 Packet Encapsulation 12.2.4 MAC Address Management 12.2.5 Loop Prevention 12.2.6 Inter-AS VPLS 12.3 Application Scenarios for VPLS 12.3.1 VPLS Application in Individual Services 12.3.2 VPLS Application in Enterprise Services 12.4 Licensing Requirements and Limitations for VPLS 12.5 Default Settings for VPLS 12.6 Configuring Martini VPLS 12.6.1 Creating a VSI and Configuring LDP Signaling 12.6.2 Binding VSIs to AC Interfaces 12.6.3 Verifying the Martini VPLS Configuration 12.7 (Optional) Configuring Inter-AS Martini VPLS 12.7.1 Configuring Inter-AS Martini VPLS in OptionA Mode 12.7.2 Configuring Inter-AS Martini VPLS in OptionC Mode 12.8 (Optional) Setting Related Parameters for a VSI 12.8.1 Configuring a PE to Send MAC Withdraw Messages to Remove MACAddress Entries 12.8.2 Configuring MAC Withdraw Loop Detection 12.8.3 Configuring MAC Address Learning 12.8.4 Configuring a VSI to Ignore the AC Status 12.9 Maintaining VPLS 12.9.1 Collecting Traffic Statistics on a VPLS PW 12.9.2 Clearing the Traffic Statistics 12.9.3 Checking Traffic Statistics on a VPLS PW 12.9.4 Enabling or Disabling VSI 12.9.5 Clearing MAC Address Entries 12.9.6 Checking Connectivity of the VPLS Network 12.9.7 Configuring the Upper and Lower Alarm Thresholds for VPLS VCs 12.9.8 Checking MPLS L2VPN Usage Information 12.10 Configuration Examples for VPLS 12.10.1 Example for Configuring Martini VPLS 12.10.2 Example for Configuring Inter-AS Martini VPLS in OptionA Mode 12.11 Troubleshooting VPLS 12.11.1 VSI Cannot Go Up in Martini VPLS Mode 13 VXLAN Configuration 13.1 Overview of VXLANs 13.2 Understanding VXLANs 13.2.1 VXLAN Network Architecture 13.2.2 Packet Encapsulation Format 13.2.3 VXLAN Implementation 13.2.3.1 Packet Identification 13.2.3.2 Tunnel Establishment 13.2.3.3 Packet Forwarding 13.3 Application Scenario 13.4 Licensing Requirements and Limitations for VXLAN 13.5 Configuring VXLAN (in Static Mode) 13.5.1 Configuring Deployment Mode for VXLAN Access Service 13.5.2 Configuring a VXLAN Tunnel 13.5.3 Configuring a Layer 3 VXLAN Gateway 13.5.4 (Optional) Configuring Static ARP Entries 13.5.5 (Optional) Configuring a Static MAC Address Entry 13.5.6 Verifying the VXLAN Configuration in Centralized Gateway Mode Using Static Mode 13.6 Configuring VXLAN (in BGP EVPN Mode) 13.6.1 Configuring Deployment Mode for VXLAN Access Service 13.6.2 Configuring a VXLAN Tunnel 13.6.3 Configuring a Layer 3 VXLAN Gateway 13.6.4 Checking the Configuration 13.7 Configuration Examples for VXLANs 13.7.1 Example for Configuring Communication Within a Network Segment Through a VXLAN Tunnel 13.7.2 Example for Configuring a Layer 3 VXLAN Gateway to Enable CommunicationBetween Users in Different Network Segments 13.7.3 Example for Dynamically Establishing a VXLAN Tunnel in BGP EVPN Mode to Implement Communication Between Users in Different Network Segments 13.7.4 Example for Configuring the Headquarters and Branch to CommunicateUsing VXLAN over IPSec Tunnels 13.8 Further Reading 13.8.1 Server Virtualization 13.8.2 Large Layer 2 Network
Similar books
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF
The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians
1809 · PDF
Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix
2008 · PDF