This is a rather simple topology focused on different IPv6 addressing methods. There's a surprising amount of them:
EUI-64 Addressing: An addressing method for IPv6 where an engineer configures the subnet, and then tells the router to figure out its own host ID based on the local MAC address. Because of the large subnets supported by IPv6, this method of addressing is both possible, simple, and scaleable.
IPv6 Stateless AutoConfig/SLAAC: Hosts (or other router devices, if required) listen for RAs from an available router and copy the network/subnet address and add their own client address to the end (which they base on their MAC address if they can).
IPv6 Global Prefix: A shortcut on Cisco routers which allows a 'global' or 'organization' subnet to be set, which allows all local interfaces on that same router to be addresses with short-hand, instead of typing the entire address.
IPv6 Multicast Routing: Along with a new subnet range, PIM has been optimized for IPv6. It's also assumed to be on, and runs by default in sparse mode. There's very little config to set it up. Unfortunately there's no support yet for auto-rp, so route-points need to be set up manually, and each network device will need to be touched if there's ever a change. There is redundancy, though, by configuring multiple on each device - a manual but effective process.
Manual Addressing: That's not to say you can't just manually specify each octet (?) of your devices. A related thread: The groups are no longer 8 (oct-et) bit groups. Since IPv6 is based on hex, each grouping is worth 16 bits. So I guess they're.. hexakaidec-tet. But that's a really long name, so I'll continue calling it an 'octet,' unspecific as that is.
You can download the configuration here, with tasks labeled: http://1drv.ms/1rHb1SJ
Good luck!
kyler
Saturday, August 16, 2014
Monday, August 4, 2014
CCIE Route/Switch v5 GNS3 Lab: Multiple Default Routes
I recently discovered a secondary internet connection at our DR site. We have a private line between our sites, as well as another MPLS connection at our DR site.
I decided to built an automatic failover in case our internet or even the an entire site goes down, which is a wickedly complex problem. There is two-way redistribution between MPLS (which connects both sites) and our private link which runs EIGRP (obviously connecting both sites).
My solutions involves:
* Each gateway router running EIGRP has a default route based on a tracker. The trackers on each are a ping-check every 3 seconds to a public IP, which is forced (with a /32 static route) down a specific interface.
* Each gateway injects their default route when available into EIGRP with a route-map to set the default-route to a different value. The DR site's default-route adds 1,000,000 to the metric so no routers will use it. That number will vary based on the complexity of your company's topologies.
* Each BGP gateway router injects EIGRP routes into BGP with a route-map. That default route at our main site is set at metric 50 (remember, BGP's metric winner is lowest). The DR site prepends the local AS-number a few times to make sure it is a less desirable option than the primary MPLS site, and will only be used if the primary is down.
An internet connection failure can be simulated by shutting the loopback that's IP'd 8.8.4.4 on either ISP router.
The topology requires many of the elements in our production network, so it's more complex than usual - 19 routers.
Download the files and GNS3 topology here: http://1drv.ms/1kuDUmU
I decided to built an automatic failover in case our internet or even the an entire site goes down, which is a wickedly complex problem. There is two-way redistribution between MPLS (which connects both sites) and our private link which runs EIGRP (obviously connecting both sites).
My solutions involves:
* Each gateway router running EIGRP has a default route based on a tracker. The trackers on each are a ping-check every 3 seconds to a public IP, which is forced (with a /32 static route) down a specific interface.
* Each gateway injects their default route when available into EIGRP with a route-map to set the default-route to a different value. The DR site's default-route adds 1,000,000 to the metric so no routers will use it. That number will vary based on the complexity of your company's topologies.
* Each BGP gateway router injects EIGRP routes into BGP with a route-map. That default route at our main site is set at metric 50 (remember, BGP's metric winner is lowest). The DR site prepends the local AS-number a few times to make sure it is a less desirable option than the primary MPLS site, and will only be used if the primary is down.
An internet connection failure can be simulated by shutting the loopback that's IP'd 8.8.4.4 on either ISP router.
The topology requires many of the elements in our production network, so it's more complex than usual - 19 routers.
Download the files and GNS3 topology here: http://1drv.ms/1kuDUmU
Thursday, July 24, 2014
CCIE Route/Switch v5 GNS3 Lab: Infrastructure Security
Hey all,
This lab contains a whole lot of layer2 and layer3 infrastructure security features likes ACLs, RPF (reverse path forwarding checks), snmp controls, etc. GNS3 doesn't simulate switching features as well as routing, so some of what I wanted to do I wasn't able to. Some of that is documented in text on the right side of the lab where it can be read and still learned.
These labs are all based around subject matter defined in the CCIEv5 lab blueprint. The full workup is here: http://www.cisco.com/web/learning/exams/docs/ccieRS_Lab5.pdf (Cisco login required to view).
In any case, this lab contains an OSPFv3 IPv6 network bridged to an IPv4 EIGRP network, with these security features intertwined. I recommend looking at the requirements page and then deleting/renaming the local configs that I've uploaded. Then see if you can meet the requirements on the GNS3 file. Once done, compare your results to mine and see if we solved it a different way. Remember, there are always multiple ways to solve each problem, in real life and in the lab.
You can download the lab files and configs here: http://1drv.ms/1pfKL2g
Good luck!
kyler
This lab contains a whole lot of layer2 and layer3 infrastructure security features likes ACLs, RPF (reverse path forwarding checks), snmp controls, etc. GNS3 doesn't simulate switching features as well as routing, so some of what I wanted to do I wasn't able to. Some of that is documented in text on the right side of the lab where it can be read and still learned.
These labs are all based around subject matter defined in the CCIEv5 lab blueprint. The full workup is here: http://www.cisco.com/web/learning/exams/docs/ccieRS_Lab5.pdf (Cisco login required to view).
In any case, this lab contains an OSPFv3 IPv6 network bridged to an IPv4 EIGRP network, with these security features intertwined. I recommend looking at the requirements page and then deleting/renaming the local configs that I've uploaded. Then see if you can meet the requirements on the GNS3 file. Once done, compare your results to mine and see if we solved it a different way. Remember, there are always multiple ways to solve each problem, in real life and in the lab.
You can download the lab files and configs here: http://1drv.ms/1pfKL2g
Good luck!
kyler
Sunday, July 20, 2014
CCIE Route/Switch v5 GNS3 Lab: IGMP/PIM/AutoRP
Hey all,
This lab covers IGMP and PIM sparse-dense mode. I didn't delve much into sparse-mode and dense-mode PIM because they're all so similar -- a simple designation of mode, and they're configured. The main difference is whether the system assumes all nodes want the traffic (dense mode) or whether they assume everyone doesn't want the traffic (sparse-mode). Sparse-dense is an extension of PIM that allows a node to adapt to the group which it joins -- it defaults to dense mode but if a RP is known or configured for a group, it switches to sparse mode.
I also configured auto-rp, so all nodes will automatically learn the address of a route-point, and redundancy can easily be built into the system. This required one node to be configured to enter its candidacy for RP (or as many nodes as you want), and at least one rp-mapping agent. This agent doesn't have to be a RP candidate, and there can again be multiple configured. It'll listen for candidate RPs and advertise those to the regular members of PIM who are listening for information from them. You can learn more about Cisco sparse/dense/sparse-dense mode here: http://goo.gl/ZBZyoY
Download the GNS3 Lab toplogy with configurations here: http://1drv.ms/1qlAuFj
This lab covers IGMP and PIM sparse-dense mode. I didn't delve much into sparse-mode and dense-mode PIM because they're all so similar -- a simple designation of mode, and they're configured. The main difference is whether the system assumes all nodes want the traffic (dense mode) or whether they assume everyone doesn't want the traffic (sparse-mode). Sparse-dense is an extension of PIM that allows a node to adapt to the group which it joins -- it defaults to dense mode but if a RP is known or configured for a group, it switches to sparse mode.
I also configured auto-rp, so all nodes will automatically learn the address of a route-point, and redundancy can easily be built into the system. This required one node to be configured to enter its candidacy for RP (or as many nodes as you want), and at least one rp-mapping agent. This agent doesn't have to be a RP candidate, and there can again be multiple configured. It'll listen for candidate RPs and advertise those to the regular members of PIM who are listening for information from them. You can learn more about Cisco sparse/dense/sparse-dense mode here: http://goo.gl/ZBZyoY
Download the GNS3 Lab toplogy with configurations here: http://1drv.ms/1qlAuFj
Friday, July 18, 2014
CCIE Route/Switch v5 GNS3 Lab: CBT Nuggets Practice Lab
Hey all,
This lab is a lot of fun. I've been using CBTNuggets to study for the CCIE, and Jeremy Cioara (who, by the way, is a GENIUS) teaches a great course that's just a practice CCIE lab that he walks you through.
He recommended doing it yourself first to see if you could and I got all the way through it -- with a few exceptions. I posted it here for others to check out, and maybe learn from -- I didn't check most of my work against Jeremy's, so I imagine I solved some of the problems in different ways.
It's pretty ridiculous what you're asked to do -- very complex, overlapping technologies. Click on the picture below to see the entire topology that I used. Jeremy didn't provide one, so I built one myself.
You can download the unsolved as well as my version of the solved GNS3 lab below!
The GNS3 video series is here: https://www.cbtnuggets.com/it-training-videos/course/cisco-ccie-routing-switching-practice-lab <-- This requires a subscription, but you can check out the first minute or two of each video for free as a sample. You'll need to subscribe to get access to CBTNugget's great full lab topology and instruction requirements, but consider the solved as a taster for what you'll be asked to do.
Download both the solved and unsolved versions of the GNS3 lab here: http://1drv.ms/1jGAtsE.
Good luck!
kyler
This lab is a lot of fun. I've been using CBTNuggets to study for the CCIE, and Jeremy Cioara (who, by the way, is a GENIUS) teaches a great course that's just a practice CCIE lab that he walks you through.
He recommended doing it yourself first to see if you could and I got all the way through it -- with a few exceptions. I posted it here for others to check out, and maybe learn from -- I didn't check most of my work against Jeremy's, so I imagine I solved some of the problems in different ways.
It's pretty ridiculous what you're asked to do -- very complex, overlapping technologies. Click on the picture below to see the entire topology that I used. Jeremy didn't provide one, so I built one myself.
You can download the unsolved as well as my version of the solved GNS3 lab below!
The GNS3 video series is here: https://www.cbtnuggets.com/it-training-videos/course/cisco-ccie-routing-switching-practice-lab <-- This requires a subscription, but you can check out the first minute or two of each video for free as a sample. You'll need to subscribe to get access to CBTNugget's great full lab topology and instruction requirements, but consider the solved as a taster for what you'll be asked to do.
Download both the solved and unsolved versions of the GNS3 lab here: http://1drv.ms/1jGAtsE.
Good luck!
kyler
Thursday, July 17, 2014
CCIE Route/Switch v5 GNS3 Lab: Layer2 WAN Technologies
A lab which covers HDLC and PPP encapsulation, CHAP and PAP authentication, MLPPP to multiplex serial connections like T1 lines, and PPPoE, the common authentication and negotiation protocol used for at-home DSL connections.
You can find the lab here: http://1drv.ms/1yz4tKt
Good luck!
kyler
You can find the lab here: http://1drv.ms/1yz4tKt
Good luck!
kyler
Monday, July 14, 2014
CCIE Route/Switch v5 GNS3 Lab: MPLS VPN
Hey all,
As I lab practice for the CCIE, I think I'll upload my configuration samples and labs so you all are able to see them.
This lab covers a complete MPLS setup including private VPNs spanned across an MPLS cloud. It also includes the configuration many companies deploy at remote sites to redistribute their local site configurations into the MPLS VRF in order to use IGPs (this lab uses OSPF and EIGRP).
Lab is here: http://1drv.ms/1OFvMhw
Enjoy!
kyler
As I lab practice for the CCIE, I think I'll upload my configuration samples and labs so you all are able to see them.
This lab covers a complete MPLS setup including private VPNs spanned across an MPLS cloud. It also includes the configuration many companies deploy at remote sites to redistribute their local site configurations into the MPLS VRF in order to use IGPs (this lab uses OSPF and EIGRP).
Lab is here: http://1drv.ms/1OFvMhw
Enjoy!
kyler
Subscribe to:
Posts (Atom)






