- maximum-paths: only allow equal-cost path load-sharing
- maximum-paths ibgp: enable both equal-cost and unequal-cost path load-sharing for internal BGP
- maximum-paths eibgp: enable both equal-cost and unequal-cost path load-sharing for both internal and external BGP
I have a wide scope of interests in IT, which includes hyper-v private cloud, remote desktop services, server clustering, PKI, network security, routing & switching, enterprise network management, MPLS VPN on enterprise network etc. Started this blog for my quick reference and to share technical knowledge with our team members.
Tuesday, August 23, 2011
Use BGP maximum-paths eibgp with Caution
Tuesday, April 26, 2011
Part 3: Configuring RIP routing on Windows Server 2008
Furthermore, you probably won’t want your servers to become routers and carry network traffics unknowingly. You can further secure it by limiting it to advertise its own addresses only. For each interface added to RIP routing, choose “Properties”. Permit only the NIC address and the loopback address for outgoing routes.
Sunday, April 17, 2011
Part 2: Network Redundancy for Windows Server: Dynamic IP Routing
Friday, April 8, 2011
Faster OSPF Convergence using iSPF
In many cases, the entire SPT need not be recomputed because most of the tree remains unchanged. Incremental SPF (iSPF) allows the system to recompute only the affected part of the tree. Recomputing only a portion of the tree rather than the entire tree results in faster OSPF convergence and saves CPU resources. Note that if the change to a Type-1 or Type-2 LSA occurs in the calculating router itself, then the full SPT is performed. Incremental SPF is scheduled in the same way as the full SPF. Routers enabled with incremental SPF and routers not enabled with incremental SPF can function in the same internetwork.
Given only pros and not cons, we should enable iSPF by default. iSPF can be easily enabled using ispf command under each router ospf process.
- router ospf 1
- ispf
- !
- show ip ospf 1 | inc SPF
- ........
- Incremental-SPF enabled
- .......
Friday, April 1, 2011
Cisco Performance Routing (PfR)
Saturday, March 26, 2011
Route filtering using route tags
To implement such routing policy using route-tag: - Router A
- access-list 1 permit 1.1.1.0 255.255.255.0
- access-list 1 permit 2.2.2.0 255.255.255.0
- access-list 2 permit 3.3.3.0 255.255.255.0
- !
- route-map route-tag permit 10
- match ip address 1
- set tag 111 --tag the 1st two remote sites with 111
- !
- route-map route-tag permit 20
- match ip address 2
- set tag 222 -- tag the 3rd remote site with 222
- !
- route-map route-tag permit 30 -- without this, all other routes will be dropped
- !
- router ospf 1
- redistribute bgp 65001 subnets route-map route-tag -- redistribute ISP routes into IGP
- ...
- ...
- Router B
- route-map tag-filter deny 10
- match tag 111 -- filter off sites with tag 111
- !
- route-map tag-filter permit 20
- match tag 222 --permit only sites with tag 222
- !
- router ospf 2
- distribute-list route-map tag-filter in
To verify, perform the necessary "show ip route" commands on both router A and B to ensure the route entries are in order. Do note that tagging does not work with BGP. The alternative in BGP is to use community string in AA:NN format (e.g. 100:300). For the adverting routers (typically on customer edge), use "set community" in place of "set tag" in the route-map statement. For the recieving routers (typically on provider edge), use "ip community-list" to describe the community string and "match community". For further example on using BGP community, see this Cisco example.









