<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Understanding Technology One at a Time!!!</title>
	<atom:link href="http://www.cciematrix.com/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.cciematrix.com</link>
	<description>Rakesh CCIE Blog</description>
	<lastBuildDate>Sat, 03 Jul 2010 20:27:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>GNS 3 AND AN IDEA !!! THRILLING ONE PER SE</title>
		<link>http://www.cciematrix.com/?p=346</link>
		<comments>http://www.cciematrix.com/?p=346#comments</comments>
		<pubDate>Sat, 03 Jul 2010 20:27:39 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://www.cciematrix.com/?p=346</guid>
		<description><![CDATA[Hello all , Today i was working on a ticket which was based on an interface down alert and was observing all the details what Network management system has thrown on my face &#8230; i was seeing it and was impressed with amazing details it was showing all of the values &#8230; quickly my brain [...]]]></description>
			<content:encoded><![CDATA[<div class='images'><a href='http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif'><img src="http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?fltr=usm&src=//wp-includes/images/smilies/icon_smile.gif&w=400" /></a></div><p>Hello all ,</p>
<p>Today i was working on a ticket which was based on an interface down alert and was observing all the details what Network management system has thrown on my face &#8230; i was seeing it and was impressed with amazing details it was showing all of the values &#8230; quickly my brain recalled that it was from snmp and i was very happy for my memory power <!-- IMAGE REMOVED BY wp-image-resizer HERE -->  haha</p>
<p>as i was thinking about the monitoring system and wanted to set it up so that i could gain some experience on it i went to solar winds website and was happy to see that they are offering a free trial of all of their products ..</p>
<p>the point is how do i have such  a huge equipment stance as a Data center ..and quickly i thought about a wild guess of associating the trial Network management system With Gns3 .. i quickly downloaded their Network monitoring software which allowed me to see only one product ..nevertheless i installed it and was thinking how could i associate it with my GNS3 &#8230; i did it finally and was seeing all the results and snmp world as iam unware of snmp stuff as such ..still i dont know how it happens as my goal from tomorrow would be precisely that ! .. i got some results and would show that to you &#8230;</p>
<p>This is still in Idea phase hope it grows more and gives all of us a huge familiarity of all the technologies with a open source software such as gns3 .. thank you guys @ gns3 who made it possible</p>
<p>Regards</p>
<p>Rakesh</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=346" target="_blank" title="Share on Facebook">Share on Facebook</a></p><div class='presskit'><h3>High Resolution Press Images:</h3>[+] <a href='http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?src=http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif&down=true'>icon_smile.gif</a><br /></div>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=346</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Radix Tree ! now i get how x.x.x.x/y works</title>
		<link>http://www.cciematrix.com/?p=344</link>
		<comments>http://www.cciematrix.com/?p=344#comments</comments>
		<pubDate>Mon, 28 Jun 2010 18:35:53 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://www.cciematrix.com/?p=344</guid>
		<description><![CDATA[Well i was studying about Routing policy and their implementation and their power in filtering out and filtering in updates &#8230; i knew this before as many access lists , distribute lists and other do the same filtering .. but was studying an interesting thing called Radix tree which showed a very basic way in [...]]]></description>
			<content:encoded><![CDATA[<div class='images'></div><p>Well i was studying about Routing policy and their implementation and their power in filtering out and filtering in updates &#8230; i knew this before as many access lists , distribute lists and other do the same filtering .. but was studying an interesting thing called Radix tree which showed a very basic way in which &#8217;1&#8242; or &#8217;0&#8242; would change the ip address / subnet &#8230; i wish i could have showed the same but instead of me telling i would advice you to do some search and feel good after reading !</p>
<p>In the mean while iam working on Quality of service and may be going with some internetwork expert work books &#8230; trying to attend Narbik bootcamp in a near by location .. had a chat wid Narbik and waiting for his email for other details</p>
<p>i will post you updated about the ccie and status &#8230;. i would be attempting lab some where soon and dnt know how that goes ! iam working with Junipers Adaptive threat Management and Data center architecture   &#8230;. some unified solutions</p>
<p>Keep Rocking</p>
<p>Rakesh</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=344" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=344</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Juniper m/mx overview continued</title>
		<link>http://www.cciematrix.com/?p=340</link>
		<comments>http://www.cciematrix.com/?p=340#comments</comments>
		<pubDate>Wed, 02 Jun 2010 17:30:15 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=340</guid>
		<description><![CDATA[M and MX series overiew &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; juniper is #2 with 48% market share consolidation , complexity , reliability , security&#38;compliance is evolution reduce tco, increase roi , profitability Advance Routing and sofware &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; two tiered collapsed architechture virtualisation , low latency , carrier class reliablity , qos , security one operating system , one single [...]]]></description>
			<content:encoded><![CDATA[<div class='images'></div><p>M and MX series overiew<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>juniper is #2 with 48% market share</p>
<p>consolidation , complexity , reliability , security&amp;compliance is evolution</p>
<p>reduce tco, increase roi , profitability</p>
<p>Advance Routing and sofware<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>two tiered collapsed architechture</p>
<p>virtualisation , low latency , carrier class reliablity , qos , security</p>
<p>one operating system , one single software release , one common architechture</p>
<p>junos trio chipset</p>
<p>mx 3d industry leader</p>
<p>carrier class reliability,reduced network complexity , sustainablity and operational efficiency , improved end user exp and app perf , improved network flexibility</p>
<p>mcast distribution tree &#8211; spt or source tree / shared tree</p>
<p>forwarding delay &#8211; advance asic<br />
transmission &#8211; user higher port speeds<br />
propagation &#8211; reduce distance between source and recievers<br />
end-to-end latency &#8211; implement all of them</p>
<p>forwarding path is full of asic based providing low latency</p>
<p>optimized hardware</p>
<p>i-chip asic for intensive services , pfe , redundancy</p>
<p>nsr &#8211; non stop routing , issu in-service software upgrade</p>
<p>graceful routing engine switchover<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>backup routing states are maintained with keepalive mechanism</p>
<p>Nonstop Active Routing<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>maintains all the state routing engines , hence no routing latency in switchover</p>
<p>Unified in-service software upgrade<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>can be installed with new versions without<br />
reloading the device by installing it in the standby routing engine</p>
<p>quality of service<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>standard 8 hardware ques with over 1000 to choose from (mcli)</p>
<p>acl and policers<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>m/mx/t have the most flexible and sophisticated policers in the industry</p>
<p>memory allocation &#8211; dynamic (mad)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>provides right amount of bandwidth to queues</p>
<p>rewrites / marking<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>ingress dscp rewrite / egress rewrite<br />
802.1p ieee bits</p>
<p>mpls network virtualisation<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>support network segmentation and privacy<br />
improve network security<br />
scales for future growth</p>
<p>enterprise routing portifolio<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>mx &#8211; optimized for wan gw , campus , dc aggr and core</p>
<p>m &#8211; application at campus backbone , wan edge</p>
<p>t &#8211; carrier class multi-service routing system,high perf</p>
<p>mx80 , mx240 , mx480 , mx960</p>
<p>ise &#8211; intelligent services edge<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>not a product , its a service which enables high performance and scale , service flexibility and operational efficiency</p>
<p>mx 3d aggregation<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>16x10gbe ports , 120 gbps (mx 240 mx 480 mx 960)</p>
<p>eantc -  european advanced networking test center</p>
<p>mx 3d 100gb3 line card &#8211; line rate 100mb</p>
<p>16port ge line card &#8211; regional high speed metro network,suitable for large data center</p>
<p>mx80 3d ethernet services router &#8211; worlds most powerful 3.5 inch router</p>
<p>mx80 &#8211; any where dc</p>
<p>junos space simplicty , reliability ,scalability</p>
<p>mx960 ethernet services router<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>14 slot chassis , 172 ports , front to back cooling</p>
<p>dpc &#8211; dense port concentrators</p>
<p>re is the daughter card for scb (switch control board)</p>
<p>mx480 ethernet services router<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>smaller firm factor than mx960 and offers<br />
half capacity than mx960</p>
<p>8 slot chassis cards (6+2)</p>
<p>side to side cooling</p>
<p>mx240 ethernet services router<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>half of mx480 performance</p>
<p>4 slot chassis (2+2 or 3+1)</p>
<p>mx fpc carrier cards (non ethernet intf)</p>
<p>mx architecture<br />
&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>2-3 switch control boards(scb&#8217;s)<br />
scb&#8217;s fully redundant<br />
packet order maintained<br />
qos maintained</p>
<p>mx fpc architecture<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>pics are hot swappable and support oir<br />
l3 ichip and l2 ese npu as the dpc&#8217;s<br />
fpc supports l2 and l3</p>
<p>dpc-r(switching and routing) , dpc-x(scaled-down switching routing) , dpc-q (queing)</p>
<p>mx family has fuller and richer capabilities over ex</p>
<p>M-series<br />
&#8212;&#8212;&#8211;</p>
<p>m7i , m10i , m120 , m320</p>
<p>m7i multiservice edge router<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>1 fixed ge or 2 fixed fe ports</p>
<p>16mpps lookup perf</p>
<p>m7i components<br />
&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>4 pic slots , fic 2 fixed fe , side to side cooling , redundant ac or dc pwr supplies,20 g harddrive , pcmcia , 2 serial aux , ethernet card intf, 850 mbps(tunnel services)</p>
<p>m10i multiservice edge router<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>most compact m series w/ fully redundant common hardware</p>
<p>m10i components<br />
&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>8 slots for hot-swappable and exchanble with m5/m7i/m10i pics , redundant re and fe , redundant pwr ac / dc</p>
<p>m120 multiservice edge router<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>120 gigs throughput , 90mpps lookup , 8 queues per intf</p>
<p>m120 arch<br />
&#8212;&#8212;&#8212;</p>
<p>4+2 fpc slots,one pfe per feb , 10gbps full duplex per slot , 15mpps per feb</p>
<p>m120 10gig capable high-end enterprise router</p>
<p>type 1 : 4pics / fpc 1gig/sec<br />
type 2 : 4pics / fpc 2.5gig/sec<br />
type 3 : 1 pic /fpc 10 gig/sec</p>
<p>two cfpcs for wan intf 10ge or option for no cfpcs</p>
<p>front to back cooled system</p>
<p>routing engineris a daughter card for scb</p>
<p>m120 ip services pic<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>provides hw accel<br />
encryption servies pic &#8211; ipsec<br />
monitoring services pic &#8211; j-flow<br />
tunnel services &#8211; gre ipinip<br />
multi-services nat<br />
linkservices &#8211; mlppp , mlfr</p>
<p>m320 multiservice edge router<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>same arch as 120 and mx offer with diff type of form factor</p>
<p>8fpc slots , 20gbps full dup , 40mpps per fpc</p>
<p>4 scbs</p>
<p>e3 fpc overview<br />
&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>type 1(4) , 2(4) , 3(2 &#8211; 10gigs each),<br />
redundant power supplies</p>
<p>non &#8211; ethernet intfs &#8211; then m-series</p>
<p>only ethernet intfs &#8211; them mx but you have an option for non-intfs</p>
<p>m-series offer with l3 where as mx can as work as l2</p>
<p>partner solution development platform</p>
<p>customers<br />
&#8212;&#8212;&#8212;</p>
<p>nyse &#8211; new york stock exchange<br />
doe  &#8211; department of energy<br />
laboratory of neuro imaging</p>
<p>Regards</p>
<p>Rakesh</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=340" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=340</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Overview of Juniper srx series in Brief</title>
		<link>http://www.cciematrix.com/?p=338</link>
		<comments>http://www.cciematrix.com/?p=338#comments</comments>
		<pubDate>Wed, 02 Jun 2010 17:28:32 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=338</guid>
		<description><![CDATA[upgrade path &#8212;&#8212;&#8212;&#8212;- cisco vs juniper 1600 series vs srx 100 1600-&#62;1700-&#62;1800 to ssg20, srx210 2500-&#62;2600-&#62;2800 to srx140,srx240,j2320,j2350,j4350 3600-&#62;3700-&#62;3800 to srx650,j4350,j6350 7200-&#62;7600-&#62;M7i srx3000 or srx5000(worlds fastest fw) 7500-&#62;7600-&#62; m series or srx3000/srx5000 &#8212;&#8212;&#8212;&#8212;- srx and j-series features &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- best in class routing with bgp , rip , ospf , mcst , isis rich set of [...]]]></description>
			<content:encoded><![CDATA[<div class='images'></div><p>upgrade path<br />
&#8212;&#8212;&#8212;&#8212;-</p>
<p>cisco vs juniper</p>
<p>1600 series vs srx 100</p>
<p>1600-&gt;1700-&gt;1800 to ssg20, srx210</p>
<p>2500-&gt;2600-&gt;2800 to srx140,srx240,j2320,j2350,j4350</p>
<p>3600-&gt;3700-&gt;3800 to srx650,j4350,j6350</p>
<p>7200-&gt;7600-&gt;M7i srx3000 or srx5000(worlds fastest fw)</p>
<p>7500-&gt;7600-&gt; m series or srx3000/srx5000</p>
<p>&#8212;&#8212;&#8212;&#8212;-</p>
<p>srx and j-series features<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>best in class routing with bgp , rip , ospf , mcst , isis</p>
<p>rich set of wan and lan intf</p>
<p>quality of service</p>
<p>support acl , stateful fw inspect , ipsec , ddos screeing , ids ips , webfilt ,</p>
<p>mpls ce pe and ipv6 routing</p>
<p>fw , nat ,ipsec etc</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>power of junos<br />
&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>one os(branch and core)  , one release , one architechture</p>
<p>quaterly release process</p>
<p>stand-alone modules and seperation of control and packet forwarding planes</p>
<p>NextGen data plane (alg for instance)</p>
<p>NextGen software is based on screen os<br />
(junos smp kernel with embedded junos features)</p>
<p>firewall processing has been enhanced with best of netscreen and junos with a single lookup and also policy implementation</p>
<p>fw processing  also has DOS and ACL filter with special hardware</p>
<p>session-aware processing avoids policy-matching</p>
<p>SRX series : zones and policies (simplify management)</p>
<p>NEXTGEN NAT : zone based security policy which seperates nat from security policy and no need for loopback-grps or dummy static routes</p>
<p>security policies and NAT are independent</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>UNIFIED THREAT MANAGEMENT : UTM<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>antivirus &#8211; kaspersky<br />
webfiltering &#8211; websense / surfcontrol<br />
content filtering<br />
antispan &#8211; symantec</p>
<p>url whitelists can be used to bypass scanning of traffic from some sites</p>
<p>mime lists can be set up to bypass scanning of some traffic</p>
<p>webfiltering<br />
&#8212;&#8212;&#8212;&#8211;</p>
<p>Integrated (surfcontrol) and redirect(websense)</p>
<p>a global whitelist/blacklist can be configred</p>
<p>redirect solution</p>
<p>Juniper networks-websense WF soultions<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Integrated webfiltering and location is in cloud</p>
<p>redirect webfilter is located in same network</p>
<p>ease-of-use is good for integrated webfiltering</p>
<p>latency is good for redirect web filtering</p>
<p>what to use depends on needs of requirement and latency issues</p>
<p>Content Filtering<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>control traffic based on MIME type , file extention , protocol commands</p>
<p>ANTISPAM<br />
&#8212;&#8212;&#8211;</p>
<p>ip address recognition based on symantec database provider (SPM RBL)</p>
<p>DYNAMIC VPN SERVICE &#8212; Access Manager Client<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>supported on srx100 , srx210 , srx240 not on srx650</p>
<p>layer 3 ipsec client that is automatically downloaded from a junos device<br />
ssl fallback for tcp traversal</p>
<p>will replace NS-REMOTE which was on screen os and NS-REMOTE on srx</p>
<p>SRX FOR THE BRANCH OVERVIEW<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>srx100<br />
srx210<br />
srx240<br />
srx650</p>
<p>srx series offers routing and security</p>
<p>all srx will have<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>routing and switching<br />
firewall and vpn<br />
utm<br />
ids and ips<br />
uac &#8211; unified access control<br />
voice services<br />
power over ethernet 802.3at(30watt/port) versus 802.3af (15.4watt/port)</p>
<p>Antivirus</p>
<p>two av engines</p>
<p>full av kaspersky<br />
express av &#8211; packet / content security accelarator</p>
<p>full av is high detection and express av is high performance</p>
<p>performance , coverage , memory utilsation</p>
<p>in express av the packet is sent as is and there is no huge av db<br />
in full av the packet is reconstructed as is upto 20 mb and hence more cpu</p>
<p>When performance and memory utilization is a concern , use Express AV</p>
<p>when coverage rate is a concern use fULL av</p>
<p>&#8212;&#8212;&#8212;&#8212;-</p>
<p>srx100(small)<br />
&#8212;&#8212;</p>
<p>8xfe , 1 usb , fw 175mbps , vpn 75 mbps , idp 50 mbps , no poe , no voi port , a/a or a/p conn (active , passive) , full utm features</p>
<p>srx210(small)<br />
&#8212;&#8212;</p>
<p>2xge+6 fe , 1 mini pim , 3g slot , usb 2 , voice ports optional 2xfxs 2xfxo or mini-pim , fw perf 250Mbps , vpn 85Mbps , idp 80Mbps , a/a , a/p<br />
4 poe ports (50w total),full utm features</p>
<p>low mem 512mb ram / 1gb flash<br />
high mem 1gb ram / 1 gb flash(comes with regex accelaration for av and idp)</p>
<p>srx240(small to medium)<br />
&#8212;&#8212;</p>
<p>16xge , mini pim 4 , 3g wireless , usb 2 , poe 16ports (150w) , optional 2xfxs , fw 500mbps , vpn 200mbps , idp 250 mbps , a/a a.p (smb) , full  utm</p>
<p>srx650(medium)<br />
&#8212;&#8212;</p>
<p>4xge , gpim 8 , usb 2 per processor,poe upto 48 ports (250w or 500w) , pstn voice ports 8 analog , 2 t1/e1 per gpim , fw 2.5gbps , vpn 1.5 gbps,idp 900mpbs , a/a or a.p or dual power , full utm</p>
<p>2 process module slots (sre services and routing enginer backup sre , application co processor engine ACE card)</p>
<p>uac l3 enforcement points</p>
<p>Mid-plane design and modular ,  8 gpim slots not hot-swap as of now</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>Wireless<br />
&#8212;&#8212;&#8211;</p>
<p>ax411 blend high perf 802.11n with srx</p>
<p>rapid setup and centralized monitoring of remote sites</p>
<p>integrated</p>
<p>802.11n client adapter choosing should be good</p>
<p>ax411 is 180mbps peak throughput</p>
<p>oversubscription rates 4:1 or 8:1</p>
<p>provisioning model<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>ap request an ip address using DHCP</p>
<p>DHCP should be configured on SRX gateways</p>
<p>you cannot plug ap into first port of gig eth as it is dhcp client</p>
<p>zero config<br />
&#8212;&#8212;&#8212;&#8211;</p>
<p>except first port of gig e all others are in default-vlan and are in trust zone</p>
<p>plug ap into any of the other ports its as simple as that</p>
<p>L2 Management Mode<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>in l2 mode all ports are conn to intf in switching mode</p>
<p>all aps belong to same l3 network</p>
<p>roaming is supported and tranparent to srx series</p>
<p>L3 Management Mode<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>In l3 mode all ap ports are connected to intf in routing mode</p>
<p>each ap&#8217;s belong to diff l3 network</p>
<p>in this mode roaming is not supported</p>
<p>client isolation can be enforced</p>
<p>authentication<br />
&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>local and radius mac</p>
<p>802.1x</p>
<p>wep , wpa , wpa2 with eap based protocols</p>
<p>at srx series gateways<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>fw auth with local redirect for local auth</p>
<p>utm,idp,uac,wan accl,ip sec</p>
<p>Junipers Networks 3G Networks<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Bridge or Integrated with SRX210 integrated 3G</p>
<p>deployment options</p>
<p>on-demand dialing<br />
backup interface<br />
prefix monitoring</p>
<p>rpm monitoring scripts cab be used for failover</p>
<p>Dialer interfaces<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>dialer intf are pseudo intfs</p>
<p>J-Series overview<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>juniper networks with avaya voip solution with cme configured at remote end</p>
<p>wxc ism200 application accelaration for j2320 , j2350 , j4350 , j6350</p>
<p>unmatched performance when services are turned on</p>
<p>j2320<br />
&#8212;&#8211;</p>
<p>4ports ge , 3 pims , internal and external c-flash , optional encry card ,supports avaya ip telephony module</p>
<p>j2350<br />
&#8212;&#8212;</p>
<p>5 pim slots , 4 ge , nebs and dc pwr , optional encryp and supports avaya telephony module</p>
<p>j4350<br />
&#8212;&#8212;</p>
<p>4 ge ports , 4pims , 2 epims , supoprts avaya media gateway , dc version available, low mem ver 256mb flash or high end 1gb , optional encryp</p>
<p>j6350<br />
&#8212;&#8212;</p>
<p>4fixed ge lan ports , 2pim slots and 4 epim slots , supports avaya media gateway , dc version available , hardware encryp standard , 1gb dram max 2gb , nebs compliant</p>
<p>pims , enchance pim , universal pim</p>
<p>double the speed whn services when compared with CISCO ISR</p>
<p>30% lower than cisco isr products</p>
<p>Enterprise routing portifolio<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>srx 240 &#8211; srx 650 with j-series in between</p>
<p>greenfield acounts &#8211; lead with srx series</p>
<p>screen os installed base &#8211; go ahead with ssg</p>
<p>existing junos cust &#8211; introude srx would be more sense</p>
<p>federal govrnt &#8211; then ssg series</p>
<p>managed services &#8211; srx</p>
<p>3g connectivity &#8211; srx</p>
<p>poe &#8211; srx series</p>
<p>wlan today &#8211; ssg</p>
<p>ipv6 security &#8211; ssg</p>
<p>anything between srx240 &#8211; srx650 is j-series</p>
<p>ssg products provides deep inspection are replaced with ips on srx</p>
<p>express av &#8211; hardware specific required</p>
<p>srx dosent support wan accel</p>
<p>Regards</p>
<p>Rakesh</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=338" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=338</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Status update and other things to share</title>
		<link>http://www.cciematrix.com/?p=333</link>
		<comments>http://www.cciematrix.com/?p=333#comments</comments>
		<pubDate>Fri, 21 May 2010 11:27:30 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=333</guid>
		<description><![CDATA[Hello all  ! hope everyone is doing good ! there are somethings to share .. first of all iam with  various firms as a consultant and been doing some work in setting up their networks and the other way is iam working with a juniper systems elite partner ! .. juniper is not that hard [...]]]></description>
			<content:encoded><![CDATA[<div class='images'></div><p>Hello all  ! hope everyone is doing good ! there are somethings to share .. first of all iam with  various firms as a consultant and been doing some work in setting up their networks and the other way is iam working with a juniper systems elite partner ! .. juniper is not that hard or illogical per se and its good to have so many resources available in juniper site . iam a juniper certified sales associate for m/mx series router platforms now ! &#8230; does this mean iam off with ccie track ?</p>
<p>A big No .. i almost done with all sorts of my prep work and in final stages to launch the official labbing experience and scenarios .. i was not getting enough time to blog and keep you informed with my status updates !</p>
<p>ok &#8230; as iam done with most of my technologies .iam now going through INE extended blue print which is well written by Anthony Here is the link</p>
<p><a href="http://blog.ine.com/2009/05/12/ccie-rs-4x-expanded-study-blueprint/">http://blog.ine.com/2009/05/12/ccie-rs-4x-expanded-study-blueprint/</a></p>
<p>For next week i will be on Spanning tree from layer 2 and  GRE tunnel and keep alive mechanisms from Layer 3 . just was going through a cisco doc on gre tunnel keep alive mechanism and was surprised as how Ethernet keepalives work</p>
<p>i will try to do a packet capture and see if that is how it works out &#8230; but to make it a soft finish let me brief you about what i read.. A detailed keepalive notes would be posted , this is just a what i have read about ethernet keepalives</p>
<p>ETHERNET KEEPALIVES</p>
<p>Generally keepalives are designed if the path to any particular neighbor is reachable and valid .. but on Ethernets it works in a different and strange way as there are many neighbors in a ethernet segment &#8230; A keepalive in this case of ethernet is designed such that local system has a read and write access to the ethernet segment itself ..</p>
<p>The Process</p>
<p>The router which for that matter any router local to itself produces a ethernet packet with source and destination mac addresses as itself and special ethernet code of 0&#215;9000 .. as the packet reaches ethernet hardware , it immediately sends and receives the same packet which should confirm the whole purpose of keepailve mechanism ..</p>
<p>This is amazing for me as of now i dint knew this and as i have known if now i will try to lab it up and see if i can catch the same packet</p>
<div></div>
<p>Regards</p>
<p>Rakesh</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=333" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=333</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>IP SLA &#8230;. GOT IT FINALLY :)</title>
		<link>http://www.cciematrix.com/?p=328</link>
		<comments>http://www.cciematrix.com/?p=328#comments</comments>
		<pubDate>Tue, 16 Mar 2010 09:24:11 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=328</guid>
		<description><![CDATA[Been so many sleep less nights wondering what ip sla was until i configured it my self . Ip sla is basically as one of the methods for enhanced object trackings . Few names for IP sla Ip sla -&#62; service level agreeement or RTR -&#62; response time reporter or SAA -&#62; service assurance agent [...]]]></description>
			<content:encoded><![CDATA[<div class='images'></div><p>Been so many sleep less nights wondering what ip sla was until i configured it my self .</p>
<p>Ip sla is basically as one of the methods for enhanced object trackings .</p>
<p>Few names for IP sla</p>
<p>Ip sla -&gt; service level agreeement</p>
<p>or</p>
<p>RTR -&gt; response time reporter</p>
<p>or</p>
<p>SAA -&gt; service assurance agent</p>
<p>Ip sla is used to track many things including DELAY , apps response time such as HTTP , DHCP , DNS , TCP and also reachability using ICMP ECHO</p>
<p>We will basically use it for FHRP (first hop redundancy tracking)</p>
<p>Here is the scenario with HSRP Enabled routers. i would use ip sla to track the interfaces and their status and if active goes down then standby should take over with the help of Ip sla . unlike interface tracking this is fun and powerful as i have added something spicy into the topology</p>
<p>here is what i have done</p>
<p><a href="http://cciematrix.com/wp-content/uploads/2010/03/ipsla-topology-with-hsrp.png"><img class="alignnone size-large wp-image-329" title="ipsla topology with hsrp" src="http://cciematrix.com/wp-content/uploads/2010/03/ipsla-topology-with-hsrp-1024x640.png" alt="" width="600" height="375" /></a></p>
<p>Initial Congiruation</p>
<p>R1</p>
<p>router eigrp 1</p>
<p>net 10.0.0.0</p>
<p>net 13.0.0.0</p>
<p>pass fa0/0</p>
<p>no auto</p>
<p>same conf on R2</p>
<p>r3</p>
<p>int l1</p>
<p>ip addr 1.1.1.1 255.255.255.0</p>
<p>router eigrp 1</p>
<p>net 13.0.0.0</p>
<p>net 23.0.0.0</p>
<p>net 1.0.0.0</p>
<p>no auto</p>
<p>R4 has a special configuration and will act like a host . so lets turn off routing for it</p>
<p>r4(conf)#no ip routing</p>
<p>r4(conf)#ip default-gateway 10.0.0.10 -&gt; this would be hsrp Virtual Ip address .</p>
<p>int fa0/0</p>
<p>ip addr 10.0.0.4 255.255.255.0</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>before enabling HSRP we should not be able to ping the V.ip lets verify it on R4</p>
<div id="_mcePaste">r4#ping 10.0.0.10</div>
<div id="_mcePaste">Type escape sequence to abort.</div>
<div id="_mcePaste">Sending 5, 100-byte ICMP Echos to 10.0.0.10, timeout is 2 seconds:</div>
<div id="_mcePaste">&#8230;..</div>
<div id="_mcePaste">Success rate is 0 percent (0/5)</div>
<p>r4#ping 10.0.0.10<br />
Type escape sequence to abort.Sending 5, 100-byte ICMP Echos to 10.0.0.10, timeout is 2 seconds:&#8230;..Success rate is 0 percent (0/5)</p>
<p>let us enable HSRP now on R1 and R2</p>
<p>r1(config)#int fa0/0</p>
<p>r1(config-if)#standby 1 ip 10.0.0.10</p>
<p>r1(config-if)#standby 1 preempt</p>
<p>r1(config-if)#exit</p>
<p>r1(config)#</p>
<p>*Mar  1 00:14:58.659: %HSRP-5-STATECHANGE: FastEthernet0/0 Grp 1 state Standby -&gt; Active</p>
<p>r1(config)#</p>
<div>&#8212;&#8212;&#8212;&#8212;</div>
<div>
<div>r2(config)#int fa0/0</div>
<div>r2(config-if)#standby 1 preempt</div>
<div>r2(config-if)#standby 1 ip 10.0.0.10</div>
<div>r2(config-if)#end</div>
<div></div>
<div>r2#</div>
<div>*Mar  1 00:15:07.643: %SYS-5-CONFIG_I: Configured from console by console</div>
<div>r2#</div>
<div>*Mar  1 00:15:26.727: %HSRP-5-STATECHANGE: FastEthernet0/0 Grp 1 state Speak -&gt; Standby</div>
</div>
<div>
<div>r1#show standby brief</div>
<div>P indicates configured to preempt.</div>
<div>|</div>
<div>Interface   Grp  Pri P State   Active          Standby         Virtual IP</div>
<div>Fa0/0       1    100 P Active  local           10.0.0.2        10.0.0.10</div>
<div>r1#</div>
</div>
<div></div>
<div>Now lets try to ping 10.0.0.10 from R4 host</div>
<div>Bingo</div>
<div>
<div>r4#ping 10.0.0.10</div>
<div>Type escape sequence to abort.</div>
<div>Sending 5, 100-byte ICMP Echos to 10.0.0.10, timeout is 2 seconds:</div>
<div>!!!!!</div>
<div>Success rate is 100 percent (5/5), round-trip min/avg/max = 16/259/1072 ms</div>
<div></div>
<div>r4#</div>
</div>
<div>lets try and see pinging 1.1.1.1 from R4 host</div>
<div>
<div>r4#ping 1.1.1.1</div>
<div>Type escape sequence to abort.</div>
<div>Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:</div>
<div>.!!!!</div>
<div>Success rate is 80 percent (4/5), round-trip min/avg/max = 16/56/84 ms</div>
<div></div>
<div>r4#</div>
<div>r4#traceroute 1.1.1.1</div>
<div>Type escape sequence to abort.</div>
<div>Tracing the route to 1.1.1.1</div>
<div>1 10.0.0.1 84 msec 96 msec 24 msec</div>
<div>2 13.0.0.3 48 msec *  68 msec</div>
</div>
<div>as traceroute indicates it is indeed taking R1 .</div>
<div>without implementing any ip sla lets shutdown fa0/0 port of R1 and see our results . R4 should now take R2</div>
<div>
<div>r1(config)#int fa0/0</div>
<div></div>
<div>r1(config-if)#shut</div>
<div></div>
<div>r1(config-if)#</div>
<div>*Mar  1 00:19:01.699: %HSRP-5-STATECHANGE: FastEthernet0/0 Grp 1 state Active -&gt; Init</div>
</div>
<div>
<div></div>
<div>r2#show standby brief</div>
<div>P indicates configured to preempt.</div>
<div>|</div>
<div>Interface   Grp  Pri P State   Active          Standby         Virtual IP</div>
<div>Fa0/0       1    100 P Active  local           unknown         10.0.0.10</div>
<div></div>
<div>r2#</div>
<div>Now R4 is taking R2 as the gateway</div>
<div>
<div></div>
<div>r4#ping 10.0.0.10</div>
<div>Type escape sequence to abort.</div>
<div>Sending 5, 100-byte ICMP Echos to 10.0.0.10, timeout is 2 seconds:</div>
<div>!!!!!</div>
<div>Success rate is 100 percent (5/5), round-trip min/avg/max = 1/31/124 ms</div>
<div></div>
<div>r4#ping 1.1.1.1</div>
<div>Type escape sequence to abort.</div>
<div>Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:</div>
<div>!!!!!</div>
<div>Success rate is 100 percent (5/5), round-trip min/avg/max = 4/48/128 ms</div>
<div></div>
<div>r4#traceroute 1.1.1.1</div>
<div>Type escape sequence to abort.</div>
<div>Tracing the route to 1.1.1.1</div>
<div>1 10.0.0.2 112 msec 32 msec 12 msec</div>
<div>2 23.0.0.3 84 msec *  116 msec</div>
<div></div>
<div>r4#</div>
</div>
<div>&#8212;&#8211;</div>
<div>now standby router took over as interface local to us went down . But what happens if the interface on the other end goes down ? .. yes we still have options such as interface tracking to employ but we will go with Ip sla and implement Enhanced object tracking .</div>
<div>
<div>r1(config)#ip sla 1</div>
<div></div>
<div>r1(config-ip-sla)#?</div>
<div></div>
<div>IP SLAs entry configuration commands:</div>
<div>dhcp         DHCP Operation</div>
<div>dlsw         DLSW Operation</div>
<div>dns          DNS Query Operation</div>
<div>exit         Exit Operation Configuration</div>
<div>frame-relay  Frame-relay Operation</div>
<div>ftp          FTP Operation</div>
<div>http         HTTP Operation</div>
<div>icmp-echo    ICMP Echo Operation</div>
<div>icmp-jitter  ICMP Jitter Operation</div>
<div>mpls         MPLS Operation</div>
<div>path-echo    Path Discovered ICMP Echo Operation</div>
<div>path-jitter  Path Discovered ICMP Jitter Operation</div>
<div>slm          SLM Operation</div>
<div>tcp-connect  TCP Connect Operation</div>
<div>udp-echo     UDP Echo Operation</div>
<div>udp-jitter   UDP Jitter Operation</div>
<div>voip         Voice Over IP Operation</div>
<div></div>
<div>r1(config-ip-sla)#icmp-echo ?</div>
<div>Hostname or A.B.C.D  Destination IP address or hostname, broadcast disallowed</div>
<div></div>
<div>r1(config-ip-sla)#icmp-echo 1.1.1.1 ?</div>
<div>source-interface  Source Interface (ingress icmp packet interface)</div>
<div>source-ip         Source Address</div>
<div>&lt;cr&gt;</div>
<div>r1(config-ip-sla)#icmp-echo 1.1.1.1</div>
<div></div>
<div>r1(config-ip-sla-echo)#?</div>
<div></div>
<div>IP SLAs echo Configuration Commands:</div>
<div></div>
<div>default            Set a command to its defaults</div>
<div>exit               Exit operation configuration</div>
<div>frequency          Frequency of an operation</div>
<div>history            History and Distribution Data</div>
<div>no                 Negate a command or set its defaults</div>
<div>owner              Owner of Entry</div>
<div>request-data-size  Request data size</div>
<div>tag                User defined tag</div>
<div>threshold          Operation threshold in milliseconds</div>
<div>timeout            Timeout of an operation</div>
<div>tos                Type Of Service</div>
<div>verify-data        Verify data</div>
<div>vrf                Configure IP SLAs for a VPN Routing/Forwarding instance</div>
<div></div>
<div>r1(config-ip-sla-echo)#frequency 3</div>
<div>%Illegal Value:  Cannot set Frequency to be less than Timeout</div>
<div></div>
<div>r1(config-ip-sla-echo)#timeout 2000</div>
<div></div>
<div>r1(config-ip-sla-echo)#exit</div>
<div></div>
<div>r1(config)#</div>
<div></div>
<div>r1(config)#track 1 ?</div>
<div>application  Application</div>
<div></div>
<div>interface    Select an interface to track</div>
<div>ip           IP protocol</div>
<div>list         Group objects in a list</div>
<div>rtr          Response Time Reporter (RTR) entry</div>
<div>stub-object  Stub tracking object</div>
<div>r1(config)#track 1 rtr 1 ?</div>
<div>reachability  Reachability</div>
<div>state         Return code state</div>
<div>&lt;cr&gt;</div>
<div></div>
<div>r1(config)#track 1 rtr 1 state ?</div>
<div>&lt;cr&gt;</div>
<div></div>
<div>r1(config)#track 1 rtr 1 state</div>
<div></div>
<div>r1(config-track)#?</div>
<div></div>
<div>Tracking instance configuration commands:</div>
<div></div>
<div>default  Set a command to its defaults</div>
<div>delay    Tracking delay</div>
<div>exit     Exit from tracking configuration mode</div>
<div>no       Negate a command or set its defaults</div>
<div></div>
<div>r1(config-track)#exit</div>
<div></div>
<div>r1(config)#</div>
<div></div>
<div>r1(config)#int fa0/0</div>
<div></div>
<div>r1(config-if)#standby 1 track 1 decrement 255</div>
<div></div>
<div>r1(config-if)#exit</div>
<div></div>
<div>r1(config)#</div>
</div>
</div>
<div>similarly on R2</div>
<div>now what i will shut down fa0/1 of R3 which is connecting to R2 active router of hsrp this should trigger Ip sla and R1 should take over .</div>
<div>we have forgot one of the most important commands</div>
<div>
<div></div>
<div>r1(config)#ip sla schedule 1  start-time now life forever</div>
</div>
<div>
<div></div>
<div>r2(config)#ip sla schedule 1 start-time now life forever</div>
<div>
<div></div>
<div>r2#show ip sla stat</div>
<div></div>
<div>Round Trip Time (RTT) for       Index 1</div>
<div>Latest RTT: 107 milliseconds</div>
<div>Latest operation start time: *00:32:34.023 UTC Fri Mar 1 2002</div>
<div>Latest operation return code: OK</div>
<div>Number of successes: 4</div>
<div>Number of failures: 0</div>
<div>Operation time to live: Forever</div>
<div>
<div></div>
<div>r3(config)#int fa0/1</div>
<div></div>
<div>r3(config-if)#</div>
<div></div>
<div>r3(config-if)#</div>
<div></div>
<div>r3(config-if)#shut</div>
<div></div>
<div>r3(config-if)#</div>
<div>*Mar  1 00:33:32.727: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor 23.0.0.2 (FastEthernet0/1) is down: interface down</div>
<div></div>
<div>r3(config-if)#</div>
<div>*Mar  1 00:33:34.483: %LINK-5-CHANGED: Interface FastEthernet0/1, changed state to administratively down</div>
<div>*Mar  1 00:33:35.483: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down</div>
<div></div>
<div>r3(config-if)#</div>
</div>
</div>
<div>
<div></div>
<div>r2#debug ip sla error</div>
<div>IP SLAs ERROR debugging for all operations is on</div>
<div></div>
<div>r2#</div>
<div>*Mar  1 00:33:38.007: %TRACKING-5-STATE: 1 rtr 1 state Up-&gt;Down</div>
<div></div>
<div>r2#</div>
<div>*Mar  1 00:33:40.527: %HSRP-5-STATECHANGE: FastEthernet0/0 Grp 1 state Active -&gt; Speak</div>
<div></div>
<div>r2#</div>
<div>*Mar  1 00:33:46.283: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor 23.0.0.3 (FastEthernet0/1) is down: holding time expired</div>
<div></div>
<div>r2#</div>
<div>*Mar  1 00:33:50.527: %HSRP-5-STATECHANGE: FastEthernet0/0 Grp 1 state Speak -&gt; Standby</div>
<div></div>
<div>r2#</div>
</div>
<div>look at sla debug message</div>
<div>Mar  1 00:33:38.007: %TRACKING-5-STATE: 1 rtr 1 state Up-&gt;Down</div>
<div>
<div></div>
<div>r4#ping 1.1.1.1</div>
<div>Type escape sequence to abort.</div>
<div>Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:</div>
<div>.!!!!</div>
<div>Success rate is 80 percent (4/5), round-trip min/avg/max = 32/73/120 ms</div>
<div></div>
<div>r4#traceroute 1.1.1.1</div>
<div>Type escape sequence to abort.</div>
<div>Tracing the route to 1.1.1.1</div>
<div>1 10.0.0.1 164 msec 68 msec 16 msec -&gt; its going through r1 now</div>
<div>2 13.0.0.3 28 msec</div>
</div>
<div>lets us look at sla output message</div>
<div>
<div></div>
<div>r2#show ip sla stat</div>
<div>Round Trip Time (RTT) for       Index 1</div>
<div>Latest RTT: NoConnection/Busy/Timeout</div>
<div>Latest operation start time: *00:35:34.023 UTC Fri Mar 1 2002</div>
<div>Latest operation return code: Timeout &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&gt; SEE ITS TIMEOUT HERE</div>
<div>Number of successes: 4</div>
<div>Number of failures: 3</div>
<div>Operation time to live: Forever</div>
<div></div>
<div>Now i would make some changes .. first i would increase the priority of R2 to 110 from defaul HSRP priority of 100 and then i will no shut or bring up the interface on R3 . lets see how sla tracks that .</div>
<div></div>
<div>r2</div>
<div></div>
<div>int fa0/0</div>
<div>standby 1 priority 110</div>
<div></div>
<div>R3</div>
<div></div>
<div>int fa0/0</div>
<div>no shut</div>
<div>
<div></div>
<div>r2#</div>
<div>*Mar  1 00:40:54.455: %DUAL-5-NBRCHANGE: IP-EIGRP(0) 1: Neighbor 23.0.0.3 (FastEthernet0/1) is up: new adjacency</div>
<div></div>
<div>r2#</div>
<div></div>
<div>*Mar  1 00:41:34.543: %TRACKING-5-STATE: 1 rtr 1 state Down-&gt;Up</div>
<div>*Mar  1 00:41:34.731: %HSRP-5-STATECHANGE: FastEthernet0/0 Grp 1 state Standby -&gt; Active</div>
<div></div>
<div>r2#</div>
</div>
<div>&#8212;&#8212;&#8212;&#8211;</div>
<div></div>
<div>This can be extended to track any protocol and can be used in any FHRP process as an effective tool .</div>
</div>
</div>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=328" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=328</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gateway Redundancy protocols ! First hop Redundancy</title>
		<link>http://www.cciematrix.com/?p=323</link>
		<comments>http://www.cciematrix.com/?p=323#comments</comments>
		<pubDate>Mon, 15 Mar 2010 16:40:04 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=323</guid>
		<description><![CDATA[Brief topology and configuration of protocol HSRP Configuration int fa0/0 standby 1 ip 10.0.0.10 standby 1 preempt r1(config-if)#standby 1 ip 10.0.0.10 r1(config-if)# *Mar  1 00:07:18.415: HSRP: Fa0/0 Starting minimum interface delay (1 secs) *Mar  1 00:07:18.415: HSRP: Fa0/0 Grp 1 Set group MAC 0000.0000.0000 -&#62; 0000.0c0                   [...]]]></description>
			<content:encoded><![CDATA[<div class='images'></div><p><strong>Brief topology and configuration of protocol </strong></p>
<p><strong><a href="http://cciematrix.com/wp-content/uploads/2010/03/topology.png"><img class="alignnone size-large wp-image-326" title="topology" src="http://cciematrix.com/wp-content/uploads/2010/03/topology-1024x640.png" alt="" width="600" height="375" /></a></strong></p>
<p><strong>HSRP Configuration </strong></p>
<p><strong>int fa0/0</strong></p>
<p><strong> standby 1 ip 10.0.0.10</strong></p>
<p><strong>standby 1 preempt </strong></p>
<p><strong> </strong></p>
<p><strong></p>
<div id="_mcePaste">r1(config-if)#standby 1 ip 10.0.0.10</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:07:18.415: HSRP: Fa0/0 Starting minimum interface delay (1 secs)</div>
<div id="_mcePaste">*Mar  1 00:07:18.415: HSRP: Fa0/0 Grp 1 Set group MAC 0000.0000.0000 -&gt; 0000.0c0                                                                             7.ac01</div>
<div id="_mcePaste">*Mar  1 00:07:18.419: HSRP: Fa0/0 MAC entry 0000.0c07.ac01 created</div>
<div id="_mcePaste">*Mar  1 00:07:18.419: HSRP: Fa0/0 MAC entry 0000.0c07.ac01, Added Fa0/0 Grp 1 to                                                                              list</div>
<div id="_mcePaste">*Mar  1 00:07:18.435: HSRP: Fa0/0 Grp 1 Disabled -&gt; Init</div>
<div id="_mcePaste">*Mar  1 00:07:18.435: HSRP: Fa0/0 Grp 1 Redundancy &#8220;hsrp-Fa0/0-1&#8243; state Disabled                                                                              -&gt; Init</div>
<div id="_mcePaste">*Mar  1 00:07:18.439: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; added</div>
<div id="_mcePaste">*Mar  1 00:07:18.439: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; update, Disabled                                                                              -&gt; Init</div>
<div id="_mcePaste">*Mar  1 00:07:19.415: HSRP: Fa0/0 Interface min delay expired</div>
<div id="_mcePaste">*Mar  1 00:07:19.415: HSRP: Fa0/0 Grp 1 Init: a/HSRP enabled</div>
<div id="_mcePaste">*Mar  1 00:07:19.415: HSRP: Fa0/0 Grp 1 Init -&gt; Listen</div>
<div id="_mcePaste">*Mar  1 00:07:19.419: HSRP: Fa0/0 Grp 1 Redundancy &#8220;hsrp-Fa0/0-1&#8243; state Init -&gt;                                                                              Backup</div>
<div id="_mcePaste">*Mar  1 00:07:19.419: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; update, Init -&gt; B                                                                             ackup</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:07:29.415: HSRP: Fa0/0 Grp 1 Listen: c/Active timer expired (unknown)</div>
<div id="_mcePaste">*Mar  1 00:07:29.415: HSRP: Fa0/0 Grp 1 Listen -&gt; Speak</div>
<div id="_mcePaste">*Mar  1 00:07:29.415: HSRP: Fa0/0 Grp 1 Redundancy &#8220;hsrp-Fa0/0-1&#8243; state Backup &#8211;                                                                             &gt; Speak</div>
<div id="_mcePaste">*Mar  1 00:07:29.419: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; update, Backup -&gt;                                                                              Speak</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:07:39.415: HSRP: Fa0/0 Grp 1 Speak: d/Standby timer expired (unknown)</div>
<div id="_mcePaste">*Mar  1 00:07:39.415: HSRP: Fa0/0 Grp 1 Standby router is local</div>
<div id="_mcePaste">*Mar  1 00:07:39.415: HSRP: Fa0/0 Grp 1 Speak -&gt; Standby</div>
<div id="_mcePaste">*Mar  1 00:07:39.415: HSRP: Fa0/0 Grp 1 Redundancy &#8220;hsrp-Fa0/0-1&#8243; state Speak -&gt;                                                                              Standby</div>
<div id="_mcePaste">*Mar  1 00:07:39.419: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; standby, unknown                                                                              -&gt; local</div>
<div id="_mcePaste">*Mar  1 00:07:39.419: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; update, Speak -&gt;                                                                              Standby</div>
<div id="_mcePaste">*Mar  1 00:07:39.915: HSRP: Fa0/0 Grp 1 Standby: c/Active timer expired (unknown                                                                             )</div>
<div id="_mcePaste">*Mar  1 00:07:39.915: HSRP: Fa0/0 Grp 1 Active router is local</div>
<div id="_mcePaste">*Mar  1 00:07:39.915: HSRP: Fa0/0 Grp 1 Standby router is unknown, was local</div>
<div id="_mcePaste">*Mar  1 00:07:39.915: HSRP: Fa0/0 Grp 1 Standby -&gt; Active</div>
<div id="_mcePaste">*Mar  1 00:07:39.915: %HSRP-5-STATECHANGE: FastEthernet0/0 Grp 1 state Standby &#8211;                                                                             &gt; Active</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:07:39.915: HSRP: Fa0/0 Grp 1 Redundancy &#8220;hsrp-Fa0/0-1&#8243; state Standby                                                                              -&gt; Active</div>
<div id="_mcePaste">*Mar  1 00:07:39.919: HSRP: Fa0/0 Grp 1 Activating MAC 0000.0c07.ac01</div>
<div id="_mcePaste">*Mar  1 00:07:39.923: HSRP: Fa0/0 Grp 1 Adding 0000.0c07.ac01 to MAC address fil                                                                             ter</div>
<div id="_mcePaste">*Mar  1 00:07:39.923: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; standby, local -&gt;                                                                              unknown</div>
<div id="_mcePaste">*Mar  1 00:07:39.923: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; update, Standby &#8211;                                                                             &gt; Active</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:07:42.919: HSRP: Fa0/0 IP Redundancy &#8220;hsrp-Fa0/0-1&#8243; update, Active -&gt;                                                                              Active</div>
<div id="_mcePaste">r1(config-if)#standby 1 preempt</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:08:14.383: HSRP: Fa0/0 Nbr 10.0.0.3 Adv in, active 0 passive 1</div>
<div id="_mcePaste">*Mar  1 00:08:14.387: HSRP: Fa0/0 Nbr 10.0.0.3 created</div>
<div id="_mcePaste">*Mar  1 00:08:14.387: HSRP: Fa0/0 Nbr 10.0.0.3 is passive</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:08:34.383: HSRP: Fa0/0 Grp 1 Standby router is 10.0.0.3</div>
<div id="_mcePaste">*Mar  1 00:08:34.383: HSRP: Fa0/0 Nbr 10.0.0.3 is no longer passive</div>
<div id="_mcePaste">*Mar  1 00:08:34.387: HSRP: Fa0/0 Nbr 10.0.0.3 standby for group 1</div>
<div id="_mcePaste">r1(config-if)#</div>
<div id="_mcePaste">*Mar  1 00:08:57.179: HSRP: Fa0/0 Nbr 10.0.0.2 Adv in, active 0 passive 1</div>
<div id="_mcePaste">*Mar  1 00:08:57.183: HSRP: Fa0/0 Nbr 10.0.0.2 created</div>
<div id="_mcePaste">*Mar  1 00:08:57.183: HSRP: Fa0/0 Nbr 10.0.0.2 is passive</div>
<div id="_mcePaste">r1(config-if)#end</div>
<div id="_mcePaste">r1#show</div>
<div id="_mcePaste">*Mar  1 00:09:23.027: %SYS-5-CONFIG_I: Configured from console by console</div>
<div id="_mcePaste">r1#show standby ?</div>
<div id="_mcePaste">FastEthernet  FastEthernet IEEE 802.3</div>
<div id="_mcePaste">Port-channel  Ethernet Channel of interfaces</div>
<div id="_mcePaste">all           Include groups in disabled state</div>
<div id="_mcePaste">brief         Brief output</div>
<div id="_mcePaste">capability    HSRP capability</div>
<div id="_mcePaste">delay         Group initialisation delay</div>
<div id="_mcePaste">internal      Internal HSRP information</div>
<div id="_mcePaste">neighbors     HSRP neighbors</div>
<div id="_mcePaste">redirect      HSRP ICMP redirect information</div>
<div id="_mcePaste">|             Output modifiers</div>
<div id="_mcePaste">&lt;cr&gt;</div>
<div id="_mcePaste">r1#show standby nei</div>
<div id="_mcePaste">HSRP neighbors on FastEthernet0/0</div>
<div id="_mcePaste">10.0.0.2</div>
<div id="_mcePaste">No active groups</div>
<div id="_mcePaste">No standby groups</div>
<div id="_mcePaste">Passive timer expires in 172.148</div>
<div id="_mcePaste">10.0.0.3</div>
<div id="_mcePaste">No active groups</div>
<div id="_mcePaste">Standby groups: 1</div>
<div id="_mcePaste">r1#show standby ?</div>
<div id="_mcePaste">FastEthernet  FastEthernet IEEE 802.3</div>
<div id="_mcePaste">Port-channel  Ethernet Channel of interfaces</div>
<div id="_mcePaste">all           Include groups in disabled state</div>
<div id="_mcePaste">brief         Brief output</div>
<div id="_mcePaste">capability    HSRP capability</div>
<div id="_mcePaste">delay         Group initialisation delay</div>
<div id="_mcePaste">internal      Internal HSRP information</div>
<div id="_mcePaste">neighbors     HSRP neighbors</div>
<div id="_mcePaste">redirect      HSRP ICMP redirect information</div>
<div id="_mcePaste">|             Output modifiers</div>
<div id="_mcePaste">&lt;cr&gt;</div>
<div id="_mcePaste">r1#show standby internal</div>
<div id="_mcePaste">Global           Confg: 0000</div>
<div id="_mcePaste">Fa0/0 If hw      Gt96k FE (18), State 0&#215;210040</div>
<div id="_mcePaste">Fa0/0 If hw      Confg: 0000</div>
<div id="_mcePaste">Fa0/0 If hw      Flags: 0000</div>
<div id="_mcePaste">Fa0/0 If sw      Confg: 0000</div>
<div id="_mcePaste">Fa0/0 If sw      Flags: 0000</div>
<div id="_mcePaste">Fa0/0 Grp 1      Confg: 0012, IP_PRI, PREEMPT</div>
<div id="_mcePaste">Fa0/0 Grp 1      Flags: 0000</div>
<div id="_mcePaste">HSRP MAC Address Table</div>
<div id="_mcePaste">173 Fa0/0 0000.0c07.ac01</div>
<div id="_mcePaste">Fa0/0 Grp 1</div>
<div id="_mcePaste">r1#show standby ?</div>
<div id="_mcePaste">FastEthernet  FastEthernet IEEE 802.3</div>
<div id="_mcePaste">Port-channel  Ethernet Channel of interfaces</div>
<div id="_mcePaste">all           Include groups in disabled state</div>
<div id="_mcePaste">brief         Brief output</div>
<div id="_mcePaste">capability    HSRP capability</div>
<div id="_mcePaste">delay         Group initialisation delay</div>
<div id="_mcePaste">internal      Internal HSRP information</div>
<div id="_mcePaste">neighbors     HSRP neighbors</div>
<div id="_mcePaste">redirect      HSRP ICMP redirect information</div>
<div id="_mcePaste">|             Output modifiers</div>
<div id="_mcePaste">&lt;cr&gt;</div>
<div id="_mcePaste">r1#show standby redirect</div>
<div id="_mcePaste">Interface          Redirects Unknown   Adv      Holddown</div>
<div id="_mcePaste">FastEthernet0/0    enabled   enabled   30       180</div>
<div id="_mcePaste">Active                Hits  Interface Group Virtual IP            Virtual MAC</div>
<div id="_mcePaste">local                 0     Fa0/0     1     10.0.0.10             0000.0c07.ac01</div>
<div id="_mcePaste">Passive               Hits  Interface Expires in</div>
<div id="_mcePaste">10.0.0.2              0     Fa0/0     166.720</div>
<div id="_mcePaste">r1#show standby summary</div>
<div id="_mcePaste">^</div>
<div id="_mcePaste">% Invalid input detected at &#8216;^&#8217; marker.</div>
<div id="_mcePaste">r1#show stan ?</div>
<div id="_mcePaste">FastEthernet  FastEthernet IEEE 802.3</div>
<div id="_mcePaste">Port-channel  Ethernet Channel of interfaces</div>
<div id="_mcePaste">all           Include groups in disabled state</div>
<div id="_mcePaste">brief         Brief output</div>
<div id="_mcePaste">capability    HSRP capability</div>
<div id="_mcePaste">delay         Group initialisation delay</div>
<div id="_mcePaste">internal      Internal HSRP information</div>
<div id="_mcePaste">neighbors     HSRP neighbors</div>
<div id="_mcePaste">redirect      HSRP ICMP redirect information</div>
<div id="_mcePaste">|             Output modifiers</div>
<div id="_mcePaste">&lt;cr&gt;</div>
<div id="_mcePaste">r1#show stan brief</div>
<div id="_mcePaste">P indicates configured to preempt.</div>
<div id="_mcePaste">|</div>
<div id="_mcePaste">Interface   Grp  Pri P State   Active          Standby         Virtual IP</div>
<div id="_mcePaste">Fa0/0       1    100 P Active  local           10.0.0.3        10.0.0.10</div>
<div id="_mcePaste">r1#</div>
<div id="_mcePaste">r1#</div>
<div id="_mcePaste">r1#show standby</div>
<div id="_mcePaste">FastEthernet0/0 &#8211; Group 1</div>
<div id="_mcePaste">State is Active</div>
<div id="_mcePaste">2 state changes, last state change 00:03:44</div>
<div id="_mcePaste">Virtual IP address is 10.0.0.10</div>
<div id="_mcePaste">Active virtual MAC address is 0000.0c07.ac01</div>
<div id="_mcePaste">Local virtual MAC address is 0000.0c07.ac01 (v1 default)</div>
<div id="_mcePaste">Hello time 3 sec, hold time 10 sec</div>
<div id="_mcePaste">Next hello sent in 0.272 secs</div>
<div id="_mcePaste">Preemption enabled</div>
<div id="_mcePaste">Active router is local</div>
<div id="_mcePaste">Standby router is 10.0.0.3, priority 100 (expires in 7.752 sec)</div>
<div id="_mcePaste">Priority 100 (default 100)</div>
<div id="_mcePaste">Group name is &#8220;hsrp-Fa0/0-1&#8243; (default)</div>
<div id="_mcePaste">r1#</div>
<p></strong></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=323" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=323</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Few Services and protocols which optimize the network :)</title>
		<link>http://www.cciematrix.com/?p=320</link>
		<comments>http://www.cciematrix.com/?p=320#comments</comments>
		<pubDate>Mon, 15 Mar 2010 09:31:47 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=320</guid>
		<description><![CDATA[Implement network services - implement HSRP - implement GLBP - implement VRRP -Implement syslog and local logging -implement ip sla -implement netflow -implement span , rspan , router ip traffice route . rite Share on Facebook]]></description>
			<content:encoded><![CDATA[<div class='images'></div><div id="_mcePaste">Implement network services</div>
<div id="_mcePaste"></div>
<div>- implement HSRP</div>
<div id="_mcePaste">- implement GLBP</div>
<div id="_mcePaste">- implement VRRP</div>
<div id="_mcePaste"></div>
<div>-Implement syslog and local logging</div>
<div id="_mcePaste">-implement ip sla</div>
<div id="_mcePaste">-implement netflow</div>
<div id="_mcePaste">-implement span , rspan , router ip traffice route . rite</div>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=320" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=320</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-BGP Multihop and TTL-Security</title>
		<link>http://www.cciematrix.com/?p=314</link>
		<comments>http://www.cciematrix.com/?p=314#comments</comments>
		<pubDate>Mon, 08 Feb 2010 20:02:19 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=314</guid>
		<description><![CDATA[The previous topology was concerned with establishing a E-BGP neighborings with two directly connected networks . Now lets turn our focus to the ones which are not directly connected but yet needs to be E-BGP peers The following topology will be used by me R2 -&#62;R1 &#8212; 172.16.1.0/24 R1-&#62;R4 &#8212; 172.16.2.0/24 R4 : router bgp [...]]]></description>
			<content:encoded><![CDATA[<div class='images'><a href='http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif'><img src="http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?fltr=usm&src=//wp-includes/images/smilies/icon_smile.gif&w=400" /></a><a href='http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif'><img src="http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?fltr=usm&src=//wp-includes/images/smilies/icon_smile.gif&w=400" /></a><a href='http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif'><img src="http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?fltr=usm&src=//wp-includes/images/smilies/icon_smile.gif&w=400" /></a></div><p>The previous topology was concerned with establishing a E-BGP neighborings with two directly connected networks . Now lets turn our focus to the ones which are not directly connected but yet needs to be E-BGP peers</p>
<p>The following topology will be used by me</p>
<p>R2 -&gt;R1 &#8212; 172.16.1.0/24</p>
<p>R1-&gt;R4 &#8212; 172.16.2.0/24</p>
<p><a href="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-1.png"><img class="alignnone size-large wp-image-315" title="ebgp2-1" src="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-1-1024x640.png" alt="" width="600" height="375" /></a></p>
<p>R4 :</p>
<p>router bgp 1</p>
<p>nei 172.16.1.2 remote-as 2</p>
<p>R4</p>
<p>router bgp 2</p>
<p>nei 172.16.2.2 remote-as 1</p>
<p>when we turn on debugging and wait for something to happen. Actually first we need see if we have network layer reachability to routers then we can worry about EBGP peerings . Hence i set up a static route and enable</p>
<p>DEBUG IP BGP IPV4 UNICAST</p>
<p>For EBgp relationships</p>
<p><a href="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-2.png"><img class="alignnone size-large wp-image-316" title="ebgp2-2" src="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-2-1024x640.png" alt="" width="600" height="375" /></a></p>
<p>Now if we are left with other configuration option such as Ttl-security lets see how things get worse from one end <!-- IMAGE REMOVED BY wp-image-resizer HERE --> </p>
<p><a href="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-3.png"><img class="alignnone size-large wp-image-317" title="ebgp2-3" src="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-3-1024x640.png" alt="" width="600" height="375" /></a></p>
<p>even though the state changes from IDLE / ACTIVE -&gt; OPEN SENT it never comes to established</p>
<p>The other router will always be in open confirm mode</p>
<p>Lets verify that</p>
<div id="_mcePaste">R2(config-router)#do sh bgp nei | in state</div>
<div id="_mcePaste">BGP state = OpenConfirm</div>
<div id="_mcePaste">Connection state is ESTAB, I/O status: 1, unread input bytes: 0</div>
<div id="_mcePaste">R2(config-router)#</div>
<div id="_mcePaste">R2(config-router)#do sh bgp nei | in TTL</div>
<div id="_mcePaste">Connection is ECN Disabled, Mininum incoming TTL 0, Outgoing TTL 2 &#8212;&gt; TTL WOULD BE &#8217;0&#8242; (ZERO) WHEN IT REACHES THE ROUTER R4</div>
<div></div>
<div id="_mcePaste">R2(config-router)#</div>
<div id="_mcePaste">R2(config-router)#do sh run | sec bgp</div>
<div id="_mcePaste">router bgp 2</div>
<div id="_mcePaste">no synchronization</div>
<div id="_mcePaste">bgp log-neighbor-changes</div>
<div id="_mcePaste">neighbor 172.16.2.2 remote-as 1</div>
<div id="_mcePaste">neighbor 172.16.2.2 ebgp-multihop 2</div>
<div id="_mcePaste">no auto-summary</div>
<div id="_mcePaste">R2(config-router)#</div>
<p>Because the other router is expecting a incoming ip packet value TTL should be atleast 253  or higher . so the solution is to configure R2 such that it sends TTL OF 255 so that by the time packet travels 2 hops its TTL would be 253 .</p>
<p>or the other option is to set ttl-security option to Router 2 also . But we would rather miss the fun Right <!-- IMAGE REMOVED BY wp-image-resizer HERE --> </p>
<p>Ok lets do it on R2</p>
<p><a href="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-4.png"><img class="alignnone size-large wp-image-318" title="ebgp2-4" src="http://cciematrix.com/wp-content/uploads/2010/02/ebgp2-4-1024x640.png" alt="" width="600" height="375" /></a></p>
<p>Yaa can you see the multihop working now in accordance with TTL-SECURITY <!-- IMAGE REMOVED BY wp-image-resizer HERE -->  . Its bed Time . Meet you Tomorrow with some other fun stuff</p>
<p>Regards</p>
<p>Rakesh</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=314" target="_blank" title="Share on Facebook">Share on Facebook</a></p><div class='presskit'><h3>High Resolution Press Images:</h3>[+] <a href='http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?src=http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif&down=true'>icon_smile.gif</a><br />[+] <a href='http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?src=http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif&down=true'>icon_smile.gif</a><br />[+] <a href='http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?src=http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif&down=true'>icon_smile.gif</a><br /></div>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=314</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>E-BGP Neighbors</title>
		<link>http://www.cciematrix.com/?p=309</link>
		<comments>http://www.cciematrix.com/?p=309#comments</comments>
		<pubDate>Sun, 07 Feb 2010 19:42:08 +0000</pubDate>
		<dc:creator>Rakesh</dc:creator>
				<category><![CDATA[CCIE Routing and Switching]]></category>

		<guid isPermaLink="false">http://cciematrix.com/?p=309</guid>
		<description><![CDATA[This is a simple lab which demonstrates the requirements of bgp external peerings we have got two routers on 172.16.1.0/24 subnet R1-&#62;172.16.1.1 ,r2-&#62;172.16.1.2 R1 Router bgp 1 neighbor 172.16.1.2 remote-as 2 R2 Router bgp 2 neighbor 172.16.1.1 remote-as 1 lets see the routers BGP process and some debug messages &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211; when we configure peer with [...]]]></description>
			<content:encoded><![CDATA[<div class='images'><a href='http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif'><img src="http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?fltr=usm&src=//wp-includes/images/smilies/icon_smile.gif&w=400" /></a></div><p>This is a simple lab which demonstrates the requirements of bgp external peerings</p>
<p>we have got two routers on 172.16.1.0/24 subnet</p>
<p>R1-&gt;172.16.1.1 ,r2-&gt;172.16.1.2</p>
<p><a href="http://cciematrix.com/wp-content/uploads/2010/02/1.png"><img class="alignnone size-medium wp-image-310" title="1" src="http://cciematrix.com/wp-content/uploads/2010/02/1-300x187.png" alt="" width="300" height="187" /></a></p>
<p>R1</p>
<p>Router bgp 1</p>
<p>neighbor 172.16.1.2 remote-as 2</p>
<p>R2</p>
<p>Router bgp 2</p>
<p>neighbor 172.16.1.1 remote-as 1</p>
<p>lets see the routers BGP process and some debug messages</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<div id="_mcePaste"><a href="http://cciematrix.com/wp-content/uploads/2010/02/2.png"><img class="alignnone size-medium wp-image-311" title="2" src="http://cciematrix.com/wp-content/uploads/2010/02/2-300x187.png" alt="" width="300" height="187" /></a></div>
<div></div>
<div>when we configure peer with wrong AS-number you can see the below output happen</div>
<div></div>
<div>R1</div>
<div></div>
<div>router bgp 1</div>
<div>neighbor 172.16.1.2 remote-as 2</div>
<div></div>
<div>R2</div>
<div></div>
<div>router bgp 2</div>
<div>neighbor 172.16.1.1 remote-as 11-&gt; this should be 1</div>
<div></div>
<div><a href="http://cciematrix.com/wp-content/uploads/2010/02/3.png"><img class="alignnone size-medium wp-image-312" title="3" src="http://cciematrix.com/wp-content/uploads/2010/02/3-300x187.png" alt="" width="300" height="187" /></a></div>
<div></div>
<div>More to come with E-bgp peering with EBGP-MULTIHOP And other ways of doing things <!-- IMAGE REMOVED BY wp-image-resizer HERE --> </div>
<div></div>
<div>Regards</div>
<div>Rakesh</div>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://www.cciematrix.com/?p=309" target="_blank" title="Share on Facebook">Share on Facebook</a></p><div class='presskit'><h3>High Resolution Press Images:</h3>[+] <a href='http://www.cciematrix.com/wp-content/plugins/wp-image-resizer/thumb/phpThumb.php?src=http://www.cciematrix.com/wp-includes/images/smilies/icon_smile.gif&down=true'>icon_smile.gif</a><br /></div>]]></content:encoded>
			<wfw:commentRss>http://www.cciematrix.com/?feed=rss2&amp;p=309</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
