<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>CCIE, CCIP, CCNP, CCSP, CCNA et all ....</title>
	<atom:link href="http://angolanetwork.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://angolanetwork.wordpress.com</link>
	<description>Jeriel Atienza, CCIE# 24263</description>
	<lastBuildDate>Thu, 17 Mar 2011 14:18:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='angolanetwork.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>CCIE, CCIP, CCNP, CCSP, CCNA et all ....</title>
		<link>http://angolanetwork.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://angolanetwork.wordpress.com/osd.xml" title="CCIE, CCIP, CCNP, CCSP, CCNA et all ...." />
	<atom:link rel='hub' href='http://angolanetwork.wordpress.com/?pushpress=hub'/>
		<item>
		<title>MPLS Tunnel LSP</title>
		<link>http://angolanetwork.wordpress.com/2010/09/20/mpls-tunnel-lsp/</link>
		<comments>http://angolanetwork.wordpress.com/2010/09/20/mpls-tunnel-lsp/#comments</comments>
		<pubDate>Mon, 20 Sep 2010 12:04:54 +0000</pubDate>
		<dc:creator>angolanetwork</dc:creator>
				<category><![CDATA[Traffic Engineering]]></category>

		<guid isPermaLink="false">http://angolanetwork.wordpress.com/?p=25</guid>
		<description><![CDATA[Hi All I am landing now come from Benguela (Fanta Dj tour), i want to make sure i will write a post per week because of time consumed on designing/writing/testing. Let focus on how MPLS Tunnel LSP works, this is our diagram. These are the initial setup for the MPLS Cloud, the config is pretty [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=25&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="color:#339966;">Hi All</span></p>
<p><span style="color:#339966;">I am landing now come from Benguela (Fanta Dj tour), i want to make sure i will write a post per week because of time consumed on designing/writing/testing. Let focus on how MPLS Tunnel LSP works, this is our diagram.</span></p>
<p><a href="http://angolanetwork.files.wordpress.com/2010/09/mpls-tunel.png"><img class="aligncenter size-full wp-image-26" title="MPLS Tunel" src="http://angolanetwork.files.wordpress.com/2010/09/mpls-tunel.png?w=614" alt=""   /></a></p>
<div id="_mcePaste"><span style="color:#339966;">These are the initial setup for the MPLS Cloud, the config is pretty simple, no big deal here.</span></div>
<div>PE1 Config:</div>
<div id="_mcePaste">PE1#sh run</div>
<div id="_mcePaste">Building configuration&#8230;</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">hostname PE1</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">ip vrf IWS</div>
<div id="_mcePaste">rd 1:1</div>
<div id="_mcePaste">route-target export 1:1</div>
<div id="_mcePaste">route-target import 1:1</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">mpls ldp router-id Loopback0</div>
<div id="_mcePaste">mpls label protocol ldp</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Loopback0</div>
<div id="_mcePaste">ip address 55.5.5.1 255.255.255.255</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Loopback1</div>
<div id="_mcePaste">ip vrf forwarding IWS</div>
<div id="_mcePaste">ip address 1.1.1.1 255.255.255.0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Serial1/0</div>
<div id="_mcePaste">ip address 55.5.1.1 255.255.255.252</div>
<div id="_mcePaste">mpls ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">router ospf 1</div>
<div id="_mcePaste">log-adjacency-changes</div>
<div id="_mcePaste">network 0.0.0.0 255.255.255.255 area 0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">router bgp 1</div>
<div id="_mcePaste">no bgp default ipv4-unicast</div>
<div id="_mcePaste">bgp log-neighbor-changes</div>
<div id="_mcePaste">neighbor 55.5.5.2 remote-as 1</div>
<div id="_mcePaste">neighbor 55.5.5.2 update-source Loopback0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">address-family vpnv4</div>
<div id="_mcePaste">neighbor 55.5.5.2 activate</div>
<div id="_mcePaste">neighbor 55.5.5.2 send-community extended</div>
<div id="_mcePaste">exit-address-family</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">address-family ipv4 vrf IWS</div>
<div id="_mcePaste">redistribute connected</div>
<div id="_mcePaste">no auto-summary</div>
<div id="_mcePaste">no synchronization</div>
<div id="_mcePaste">exit-address-family</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">end</div>
<div id="_mcePaste">PE2 Config:</div>
<div id="_mcePaste">PE2#sh run</div>
<div id="_mcePaste">Building configuration&#8230;</div>
<div id="_mcePaste">Current configuration : 1849 bytes</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">hostname PE2</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">ip vrf IWS</div>
<div id="_mcePaste">rd 1:1</div>
<div id="_mcePaste">route-target export 1:1</div>
<div id="_mcePaste">route-target import 1:1</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">mpls ldp router-id Loopback0</div>
<div id="_mcePaste">mpls label protocol ldp</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Loopback0</div>
<div id="_mcePaste">ip address 55.5.5.2 255.255.255.255</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Loopback1</div>
<div id="_mcePaste">ip vrf forwarding IWS</div>
<div id="_mcePaste">ip address 2.2.2.2 255.255.255.0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Serial1/0</div>
<div id="_mcePaste">ip address 55.5.1.10 255.255.255.252</div>
<div id="_mcePaste">mpls ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Serial1/1</div>
<div id="_mcePaste">ip address 55.5.1.14 255.255.255.252</div>
<div id="_mcePaste">mpls ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">router ospf 1</div>
<div id="_mcePaste">log-adjacency-changes</div>
<div id="_mcePaste">network 0.0.0.0 255.255.255.255 area 0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">router bgp 1</div>
<div id="_mcePaste">no bgp default ipv4-unicast</div>
<div id="_mcePaste">bgp log-neighbor-changes</div>
<div id="_mcePaste">neighbor 55.5.5.1 remote-as 1</div>
<div id="_mcePaste">neighbor 55.5.5.1 update-source Loopback0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">address-family vpnv4</div>
<div id="_mcePaste">neighbor 55.5.5.1 activate</div>
<div id="_mcePaste">neighbor 55.5.5.1 send-community extended</div>
<div id="_mcePaste">exit-address-family</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">address-family ipv4 vrf IWS</div>
<div id="_mcePaste">redistribute connected</div>
<div id="_mcePaste">no auto-summary</div>
<div id="_mcePaste">no synchronization</div>
<div id="_mcePaste">exit-address-family</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">end</div>
<div id="_mcePaste">P1 Config:</div>
<div id="_mcePaste">P1#sh run</div>
<div id="_mcePaste">Building configuration&#8230;</div>
<div id="_mcePaste">Current configuration : 1575 bytes</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">hostname P1</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">mpls label protocol ldp</div>
<div id="_mcePaste">tag-switching tdp router-id Loopback0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Loopback0</div>
<div id="_mcePaste">ip address 55.5.5.3 255.255.255.255</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Ethernet0/0</div>
<div id="_mcePaste">ip address 55.5.1.5 255.255.255.252</div>
<div id="_mcePaste">ip ospf network point-to-point</div>
<div id="_mcePaste">tag-switching ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Serial1/0</div>
<div id="_mcePaste">ip address 55.5.1.9 255.255.255.252</div>
<div id="_mcePaste">tag-switching ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Serial1/1</div>
<div id="_mcePaste">ip address 55.5.1.2 255.255.255.252</div>
<div id="_mcePaste">tag-switching ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">router ospf 1</div>
<div id="_mcePaste">log-adjacency-changes</div>
<div id="_mcePaste">network 0.0.0.0 255.255.255.255 area 0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">end</div>
<div id="_mcePaste">P2 Config:</div>
<div id="_mcePaste">P2#sh run</div>
<div id="_mcePaste">Building configuration&#8230;</div>
<div id="_mcePaste">Current configuration : 1546 bytes</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">hostname P2</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">mpls label protocol ldp</div>
<div id="_mcePaste">tag-switching tdp router-id Loopback0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Loopback0</div>
<div id="_mcePaste">ip address 55.5.5.4 255.255.255.255</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Ethernet0/0</div>
<div id="_mcePaste">ip address 55.5.1.6 255.255.255.252</div>
<div id="_mcePaste">ip ospf network point-to-point</div>
<div id="_mcePaste">tag-switching ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">interface Serial1/0</div>
<div id="_mcePaste">ip address 55.5.1.13 255.255.255.252</div>
<div id="_mcePaste">tag-switching ip</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">router ospf 1</div>
<div id="_mcePaste">log-adjacency-changes</div>
<div id="_mcePaste">network 0.0.0.0 255.255.255.255 area 0</div>
<div id="_mcePaste">!</div>
<div id="_mcePaste">end</div>
<p><span style="color:#339966;">The goal is to have end to end connectivity between IWS remote Sites, we need only to check the LSP between PE1 and PE2.</span></p>
<p>PE1:</p>
<p>PE1#show mpls forwarding-table 55.5.5.2</p>
<p>Local  Outgoing      Prefix            Bytes Label   Outgoing   Next Hop<br />
Label  Label or VC   or Tunnel Id      Switched      interface<br />
19     17            55.5.5.2/32       0             Se1/0      point2point<br />
PE1#</p>
<p><span style="color:#339966;">We see that to going to loopback of PE2 its gonna use Label 19.<br />
At this point the both P&#8217;s perform PHP operations</span></p>
<p>P1:</p>
<p>P1#show mpls forwarding-table 55.5.5.2<br />
Local  Outgoing    Prefix            Bytes tag  Outgoing   Next Hop<br />
tag    tag or VC   or Tunnel Id      switched   interface<br />
17     Pop tag     55.5.5.2/32       4873       Se1/0      point2point</p>
<p><span style="color:#339966;">Doesn&#8217;t need to check on PE2 because its direct connected.</span></p>
<p>P2</p>
<p>P2#show mpls forwarding-table 55.5.5.2<br />
Local  Outgoing    Prefix            Bytes tag  Outgoing   Next Hop<br />
tag    tag or VC   or Tunnel Id      switched   interface<br />
18     Pop tag     55.5.5.2/32       0          Se1/0      point2point</p>
<p><span style="color:#339966;">Ping to IWS remote site with success,</span></p>
<p>PE1#ping vrf IWS 2.2.2.2<br />
Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:<br />
!!!!!<br />
Success rate is 100 percent (5/5), round-trip min/avg/max = 8/16/28 ms<br />
PE1#</p>
<p><span style="color:#339966;">The MPLS is working properly, let says that we want to prefer link for PE1-&gt;P2-&gt;P1-&gt;PE2 for the customer IWS which is simulate on loopback on both PE1 and PE2. So our tunnel will end at the P1, due to prevent misrouting if P1 become PE.<br />
</span><span style="color:#339966;">First we gonna trace from PE1 to PE2 to check which path the traffic takes.</span></p>
<p>PE1#traceroute 55.5.5.2</p>
<p>Type escape sequence to abort.<br />
Tracing the route to 55.5.5.2</p>
<p>1 55.5.1.2 [MPLS: Label 17 Exp 0] 68 msec 12 msec 12 msec<br />
2 55.5.1.10 12 msec *  16 msec<br />
PE1#</p>
<p><span style="color:#339966;">Traffic is going from PE1 -&gt; P1 -&gt; PE2. At now all the thing is good and properly work!<br />
Let setup unidirectional Tunnel LSP between P1 and PE2, check the config:</span></p>
<p><span style="color:#339966;">P1 and P2 Configs:</span></p>
<p>mpls traffic-eng tunnels<br />
!<br />
router ospf 1<br />
mpls traffic-eng router-id Loopback0<br />
mpls traffic-eng area 0<br />
!<br />
interface Ethernet0/0<br />
mpls traffic-eng tunnels<br />
ip rsvp bandwidth<br />
!<br />
interface Serial1/0<br />
mpls traffic-eng tunnels<br />
ip rsvp bandwidth<br />
end</p>
<p>PE2:</p>
<p>mpls traffic-eng tunnels<br />
!<br />
router ospf 1<br />
mpls traffic-eng router-id Loopback0<br />
mpls traffic-eng area 0<br />
!<br />
interface Serial1/0<br />
mpls traffic-eng tunnels<br />
ip rsvp bandwidth<br />
!<br />
interface Serial1/1<br />
mpls traffic-eng tunnels<br />
ip rsvp bandwidth<br />
!<br />
interface Tunnel0<br />
ip unnumbered Loopback0<br />
tunnel destination 55.5.5.3<br />
tunnel mode mpls traffic-eng<br />
tunnel mpls traffic-eng autoroute announce<br />
tunnel mpls traffic-eng path-option 1 explicit name P2-&gt;P1<br />
tunnel mpls traffic-eng path-option 2 dynamic<br />
!<br />
ip explicit-path name P2-&gt;P1 enable<br />
next-address 55.5.1.13<br />
next-address 55.5.1.5<br />
next-address 55.5.5.3<br />
!<br />
end</p>
<p><span style="color:#339966;">At this point the Tunnel is up and working as u see on the outputs</span></p>
<p>PE2#show mpls traffic-eng tunnels brief | in PE2_t0<br />
PE2_t0                           55.5.5.3         &#8211;         Se1/1     up/up</p>
<p>PE2#show mpls forwarding-table 55.5.5.1 | in Tu0<br />
18     No Label  [T] 55.5.5.1/32       0             Tu0        point2point</p>
<p><span style="color:#339966;">At this time the Label Switched Path was broken, as u can see on the ping  output. There is No Label for the specific FEC …</span></p>
<p>PE2#ping vrf IWS 1.1.1.1 source lo1</p>
<p>Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 1.1.1.1, timeout is 2 seconds:<br />
Packet sent with a source address of 2.2.2.2<br />
&#8230;..<br />
Success rate is 0 percent (0/5)</p>
<p><span style="color:#339966;">Unidirectional TE will not work, we must setup another TE Tunnel from P1 to PE2 and enable MPLS on the tunnels link to form a LSP Tunnel. </span></p>
<p>P1:<br />
P1#sh run int tun0</p>
<p>interface Tunnel0<br />
ip unnumbered Loopback0<br />
<span style="color:#ff0000;"> mpls ip<br />
</span> tunnel destination 55.5.5.2<br />
tunnel mode mpls traffic-eng<br />
tunnel mpls traffic-eng autoroute announce<br />
tunnel mpls traffic-eng path-option 1 explicit name P2-PE2<br />
tunnel mpls traffic-eng path-option 2 dynamic<br />
no routing dynamic<br />
end</p>
<p>P1#sh run | se ip expli<br />
ip explicit-path name P2-&gt;PE2 enable<br />
next-address 55.5.1.6<br />
next-address 55.5.1.14<br />
next-address 55.5.5.2</p>
<p><span style="color:#339966;">PE2: just enable the mpls</span></p>
<p>interface Tunnel0<br />
<span style="color:#ff0000;">mpls ip</span></p>
<p><span style="color:#339966;">Now packet is Label Switched out Tunnel</span></p>
<p>PE2#show mpls forwarding-table 55.5.5.1 | in Tu0<br />
18     18        [T] 55.5.5.1/32       0             Tu0        point2point</p>
<p><span style="color:#339966;">Trying ping now …</span></p>
<p>PE2#ping vrf IWS 1.1.1.1 source lo1</p>
<p>Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to  1.1.1.1, timeout is 2 seconds:<br />
Packet sent with a source address of 2.2.2.2<br />
!!!!!<br />
Success rate is 100 percent (5/5), round-trip min/avg/max = 12/36/56 ms<br />
PE2#</p>
<p><span style="color:#339966;">So we conclude with this post, this post achieve an in-depth knowledge how MPLS LSP work and advanced concept about MPLS TE on the Field. Keep u understand the concepts and post a comment.</span></p>
<p><span style="color:#339966;">//Jeriel Atienza</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/angolanetwork.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/angolanetwork.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/angolanetwork.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/angolanetwork.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/angolanetwork.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/angolanetwork.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/angolanetwork.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/angolanetwork.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/angolanetwork.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/angolanetwork.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/angolanetwork.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/angolanetwork.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/angolanetwork.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/angolanetwork.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=25&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://angolanetwork.wordpress.com/2010/09/20/mpls-tunnel-lsp/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3f6359d94ab5d1e37fdbbf8d58a27d61?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">angolanetwork</media:title>
		</media:content>

		<media:content url="http://angolanetwork.files.wordpress.com/2010/09/mpls-tunel.png" medium="image">
			<media:title type="html">MPLS Tunel</media:title>
		</media:content>
	</item>
		<item>
		<title>Telnet to the star wars</title>
		<link>http://angolanetwork.wordpress.com/2010/09/14/telnet-to-the-star-wars/</link>
		<comments>http://angolanetwork.wordpress.com/2010/09/14/telnet-to-the-star-wars/#comments</comments>
		<pubDate>Tue, 14 Sep 2010 08:55:24 +0000</pubDate>
		<dc:creator>angolanetwork</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://angolanetwork.wordpress.com/?p=21</guid>
		<description><![CDATA[Hi All Just copy and past &#8230; telnet towel.blinkenlights.nl Enjoyyy<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=21&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hi All</p>
<p>Just copy and past &#8230;</p>
<p>telnet towel.blinkenlights.nl</p>
<p>Enjoyyy</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/angolanetwork.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/angolanetwork.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/angolanetwork.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/angolanetwork.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/angolanetwork.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/angolanetwork.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/angolanetwork.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/angolanetwork.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/angolanetwork.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/angolanetwork.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/angolanetwork.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/angolanetwork.wordpress.com/21/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/angolanetwork.wordpress.com/21/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/angolanetwork.wordpress.com/21/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=21&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://angolanetwork.wordpress.com/2010/09/14/telnet-to-the-star-wars/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3f6359d94ab5d1e37fdbbf8d58a27d61?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">angolanetwork</media:title>
		</media:content>
	</item>
		<item>
		<title>DNS Reply Modification usando OUTSIDE NAT e ICMP Reply no FWSM</title>
		<link>http://angolanetwork.wordpress.com/2010/09/13/dns-reply-modification-usando-outside-nat-e-icmp-reply-no-fwsm/</link>
		<comments>http://angolanetwork.wordpress.com/2010/09/13/dns-reply-modification-usando-outside-nat-e-icmp-reply-no-fwsm/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 16:55:53 +0000</pubDate>
		<dc:creator>angolanetwork</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://angolanetwork.wordpress.com/?p=7</guid>
		<description><![CDATA[FWSM (FireWall Switch Module) &#8216;e um firewall de alta performance comparado com o ASA e o PIX, &#8216;e um stateful firewall instalado no Catalyst 6500 Switch e no Cisco 7600 Router. Firewalls protegem redes internas de acessos nao autorizados vindo de fora, também de outras redes internas tais como separar a network Finance da Rede [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=7&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;">FWSM (FireWall Switch Module) &#8216;e um firewall de alta performance comparado com o ASA e o PIX, &#8216;e um stateful firewall instalado no Catalyst 6500 Switch e no Cisco 7600 Router. Firewalls protegem redes internas de acessos nao autorizados vindo de fora, também de outras redes internas tais como separar a network Finance da Rede Admin, conforme o diagrama.</p>
<p style="text-align:left;"><a href="http://angolanetwork.files.wordpress.com/2010/09/2.png"><img class="aligncenter size-full wp-image-8" title="2" src="http://angolanetwork.files.wordpress.com/2010/09/2.png?w=614&#038;h=269" alt="" width="614" height="269" /></a></p>
<p style="text-align:left;">
<p>Abaixo esta a configuração básica do FWSM no contexto Routed com o hostname IWS e o Router, as redes internas estão a ser simuladas pelas loopbacks com as referidas descrições.</p>
<p>FWSM:</p>
<p>C6500-MFW-01# changeto context IWS</p>
<p>C6500-MFW-01/IWS# sh run<br />
: Saved<br />
:<br />
FWSM Version 4.0(4) &lt;context&gt;<br />
!<br />
hostname IWS<br />
!<br />
names<br />
<strong>name 10.254.1.8 Finance<br />
name 10.254.1.16 Admin</strong><br />
dns-guard<br />
interface Vlan100<br />
description IWS OUTSIDE L3 INTERACE<br />
nameif outside<br />
<strong>security-level 0</strong><br />
ip address 61.1.1.1 255.255.255.0<br />
!<br />
interface Vlan110<br />
description IWS INSIDE L3 INTERFACE<br />
nameif inside<br />
<strong>security-level 100</strong><br />
ip address 10.254.1.1 255.255.255.248<br />
!<br />
<strong>route outside 0.0.0.0 0.0.0.0 61.1.1.2 1<br />
route inside Admin 255.255.255.248 10.254.1.2<br />
route inside Finance 255.255.255.248 10.254.1.2</strong><br />
!<br />
ssh 10.254.1.16 255.255.255.248 admin<br />
ssh timeout 5<br />
ssh version 2<br />
!<br />
policy-map global_policy<br />
class inspection_default<br />
inspect dns maximum-length 512<br />
inspect ftp<br />
inspect h323 h225<br />
inspect h323 ras<br />
inspect netbios<br />
inspect rsh<br />
inspect skinny<br />
inspect smtp<br />
inspect sqlnet<br />
inspect sunrpc<br />
inspect tftp<br />
inspect sip<br />
inspect xdmcp<br />
inspect snmp<br />
<strong> inspect icmp</strong> // by default, esta desactivado,<br />
!<br />
service-policy global_policy global<br />
Cryptochecksum:ac5d67f215d748f06748d6e469e7066b<br />
: end<br />
C6500-MFW-01/IWS#</p>
<p>!<br />
! Repare nos comandos &#8220;route inside&#8221;  que as redes foram substituídas pelos seus nomes,<br />
! route inside Admin 255.255.255.248 10.254.1.2 equivale a:<br />
! route inside 10.254.1.16 255.255.255.248 10.254.1.2.<br />
!<br />
O &#8220;security-level command&#8221; serve para controlar a direcção do trafego, sendo interfaces com security-level altas podem alcancar interfaces com security-level baixa. Faz sentido que a inside interface seja permitida para acessar a outside interface, mas nao o inverso ao menos que seja explicitamente configurado, por ACL/outros. Por padrão se for configurada o nome da interface como sendo inside automaticamente o FWSM assume level 100, e se for outside como level 0, fazendo com que o trafego flui de inside para outside.</p>
<p>Router:</p>
<p>CE#sh run<br />
Building configuration&#8230;<br />
Current configuration : 1035 bytes<br />
!<br />
version 12.4<br />
service timestamps debug datetime msec<br />
service timestamps log datetime msec<br />
service password-encryption<br />
!<br />
hostname CE<br />
!<br />
boot-start-marker<br />
boot-end-marker<br />
!<br />
!<br />
no aaa new-model<br />
ip subnet-zero<br />
!<br />
!<br />
no ip domain lookup<br />
interface Loopback0<br />
description Admin Network<br />
ip address 10.2541.17 255.255.255.248<br />
!<br />
interface Loopback1<br />
description Finance Network<br />
ip address 10.254.1.9 255.255.255.248<br />
!<br />
interfaceGigabitEthernet0/0<br />
description CONNECTION TO FWSM [CONTEXT IWS]<br />
ip address 10.254.1.2 255.255.255.248<br />
full-duplex<br />
!<br />
!<br />
ip classless<br />
!<br />
<strong>ip route 0.0.0.0 0.0.0.0 10.254.1.1 name MY_EXIT<br />
</strong>!<br />
line con 0<br />
!<br />
line aux 0<br />
!<br />
line vty 0 4<br />
login local<br />
!<br />
!<br />
end<br />
CE#</p>
<p>Vamos agora testar conectividade,</p>
<p>CE#ping 10.254.1.1</p>
<p>Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 10.254.1.1, timeout is 2 seconds:<br />
&#8230;..<br />
Success rate is 0 percent (0/5)<br />
CE#</p>
<p>Oh, bad news …</p>
<p>Vamos tentar com uma das redes internas &#8230;</p>
<p>CE#ping 10.254.1.1 source lo0<br />
Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 10.254.1.1, timeout is 2 seconds<br />
Packet sent with a source address of 10.2541.17<br />
&#8230;..<br />
Success rate is 0 percent (0/5)<br />
CE#</p>
<p>CE#ping 10.254.1.1 source lo1</p>
<p>Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 10.254.1.1, timeout is 2 seconds:<br />
Packet sent with a source address of 10.2541.9<br />
&#8230;..<br />
Success rate is 0 percent (0/5)<br />
CE#</p>
<p>As falhas de tentativas de pings deve-se ao facto de como o FWSM foi desenhado/programado, por padrão o FWSM nao responde pings, deve ser habilitado.</p>
<p>Vamos configurar o FWSM para responder as requisições dos pings, como best practice apenas para a rede Admin.</p>
<p>FWSM Config:</p>
<p>C6500-MFW-01/IWS# sh run icmp<br />
!<br />
<strong>icmp permit 10.254.1.16 255.255.255.248 inside</strong><br />
!<br />
C6500-MFW-01/IWS#</p>
<p>CE#ping 10.254.1.1</p>
<p>Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 10.254.1.1, timeout is 2 seconds:<br />
&#8230;..<br />
Success rate is 0 percent (0/5)<br />
CE#</p>
<p>Life is not easy , Againnn!!!!</p>
<p>Vamos tentar com uma das redes internas &#8230;</p>
<p>CE#ping 10.254.1.1 source lo0</p>
<p>Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 10.254.1.1, timeout is 2 seconds:<br />
Packet sent with a source address of 10.2541.17<br />
.!!!<br />
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/4 ms<br />
CE#</p>
<p>Life is pretty good, &#8230;</p>
<p>CE#ping 10.254.1.1 source lo1</p>
<p>Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 10.254.1.1, timeout is 2 seconds:<br />
Packet sent with a source address of 10.2541.9<br />
&#8230;..<br />
Success rate is 0 percent (0/5)<br />
CE#</p>
<p>E&#8217; normal que o primeiro e o ultimo ping nao sejam respondidos sendo um saindo pela interface directamente conectado ao FWSM, nao foram permitidas!</p>
<p>Ja temos a nossa rede a funcionar, agora vamos fazer o NAT para acessar o servidor www.iws.co.ao e outros servicos externos. Um dos desafios, e&#8217; o facto de que o dns nao faz parte da nossa rede, vamos usa-lo como sendo nosso dns server interno. Como a  rede outside nao tem rotas para a rede interna, e&#8217; necessário NAT para traduzir a rede interna para um dos enderecos da rede outside..</p>
<p>DNS Server IP 10.254.1.3.<br />
NAT Outside IP 61.1.10</p>
<p>C6500-MFW-01/IWS# sh run static</p>
<p>!<br />
<strong>static (outside,inside) 10.254.1.3 61.1.1.53 netmask 255.255.255.255 dns<br />
nat (inside) 1 10.254.1.16 255.255.255.248<br />
nat (inside) 1 10.254.1.8 255.255.255.248<br />
nat (global) 1 61.1.1.10</strong><br />
!<br />
C6500-MFW-01/IWS#</p>
<p>Primeiro cria-se as pools de endereços e associa-se ao NAT-ID, no nosso caso e&#8217; &#8220;1&#8243;, e depois o mapeamento da pool(INSIDE) com o endereço publico (Global). A chave no nat do dns e&#8217; a feature &#8220;dns&#8221; a.k.a DNS REPLY Modification.</p>
<p>Configuracao do DNS no router CE:</p>
<p>CE#sh run | in ip name-se<br />
!<br />
<strong>ip name-server 10.254.1.3</strong><br />
!<br />
CE#</p>
<p>Vamos agora testar a conectividade com o webserver da Internetworking Solutions (www.iws.co.ao).</p>
<p>CE#ping  www.iws.co.ao source lo0</p>
<p>Translating &#8220;www.iws.co.ao&#8221;…domain server (10.254.1.3) [OK]<br />
Type escape sequence to abort.<br />
Sending 5, 100-byte ICMP Echos to 61.1.1.80, timeout is 2 seconds:<br />
Packet sent with a source address of 10.2541.17<br />
!!!!!<br />
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms<br />
CE#</p>
<p>Realçar que o mesmo funciona no ASA/PIX, mas com pequenas diferenças.</p>
<p>HTH</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/angolanetwork.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/angolanetwork.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/angolanetwork.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/angolanetwork.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/angolanetwork.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/angolanetwork.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/angolanetwork.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/angolanetwork.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/angolanetwork.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/angolanetwork.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/angolanetwork.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/angolanetwork.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/angolanetwork.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/angolanetwork.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=7&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://angolanetwork.wordpress.com/2010/09/13/dns-reply-modification-usando-outside-nat-e-icmp-reply-no-fwsm/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3f6359d94ab5d1e37fdbbf8d58a27d61?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">angolanetwork</media:title>
		</media:content>

		<media:content url="http://angolanetwork.files.wordpress.com/2010/09/2.png" medium="image">
			<media:title type="html">2</media:title>
		</media:content>
	</item>
		<item>
		<title>Hi All</title>
		<link>http://angolanetwork.wordpress.com/2010/09/13/hello-world/</link>
		<comments>http://angolanetwork.wordpress.com/2010/09/13/hello-world/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 10:02:13 +0000</pubDate>
		<dc:creator>angolanetwork</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://angolanetwork.wordpress.com/?p=1</guid>
		<description><![CDATA[Sejam bem-vindos ao meu blog, Este blog tem por finalidade compartilhar recursos e melhores practicas no que diz respeito as Tecnologias de Redes e Telecomunicacoes, como guia practico para os Engenheiro de Redes que estejam envolvidos nas tecnologias e para auxilio dos candidatos para as Certificacoes Cisco. O blog vai abordar topicos deste o mais [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=1&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sejam bem-vindos ao meu blog,</p>
<p>Este blog tem por finalidade compartilhar recursos e melhores practicas no que diz respeito as Tecnologias de Redes e Telecomunicacoes, como guia practico para os Engenheiro de Redes que estejam envolvidos nas tecnologias e para auxilio dos candidatos para as Certificacoes Cisco. O blog vai abordar topicos deste o mais basico ate tecnicas avancadas.</p>
<p>Once again, welcome.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/angolanetwork.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/angolanetwork.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/angolanetwork.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/angolanetwork.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/angolanetwork.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/angolanetwork.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/angolanetwork.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/angolanetwork.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/angolanetwork.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/angolanetwork.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/angolanetwork.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/angolanetwork.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/angolanetwork.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/angolanetwork.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=angolanetwork.wordpress.com&amp;blog=15838981&amp;post=1&amp;subd=angolanetwork&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://angolanetwork.wordpress.com/2010/09/13/hello-world/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3f6359d94ab5d1e37fdbbf8d58a27d61?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">angolanetwork</media:title>
		</media:content>
	</item>
	</channel>
</rss>
