http://www.inetzero.com - Copyright 2018 iNET ZERO. All rights reserved for personal non commercial use only – do not distribute iNET ZERO JNCIE-SP lab workbook with detailed solutions version 2.0 1 JNCIE-SP (Service Provider) Lab preparation workbook v2.0 For Juniper Networks, inc - JNCIE-SP Lab Exam
34
Embed
JNCIE-SP (Service Provider) - iNETZERO · the JNCIS-SP and JNCIP-SP written exams before you start using this workbook. iNET ZERO’s JNCIE-SP
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Belowtwoconfigurationlinesarerequiredtosuccessfullycompletethefirsttask. [edit] lab@R1# set system services ssh connection-limit 2 [edit] lab@R1# set system services ssh rate-limit 2
NETCONFprovidesmechanismstoinstall,manipulate,anddeletetheconfigurationofnetworkdevices.AfterenablingSSHonJUNOSdevices,NETCONFisenabledautomaticallyacceptingconnectionsonthedefaultSSHport22.ThetaskasksforenablingNETCONFoverthestandardport830definedbyRFC4742.InJUNOS,thisisdonewhenyouaddsshoptionunderthenetconfservice. [edit] lab@R1# set system services netconf ssh
BelowisexcerptfromthesystemconnectiontableonrouterR1aftercommittingthechange.[edit] lab@R1# run show system connections
[edit] lab@R1# set snmp interface fxp0.0 [edit] lab@R1# set snmp community superlab clients 10.10.10.1/32 [edit] lab@R1# set routing-options static route 10.10.10.1/32 next-hop 10.10.1.200 [edit] lab@R1# set system backup-router 10.10.1.200 [edit] lab@R1# set system backup-router destination 10.10.10.1/32
> to 10.50.0.46 via ge-0/0/4.56, label-switched-path r5-to-r1 192.168.22.0/24 *[BGP/170] 00:02:51, MED 1, localpref 100, from 10.50.250.10 AS path: 5673.873 I, validation-state: unverified > to 10.50.0.46 via ge-0/0/4.56, label-switched-path r5-to-r2 to 10.50.0.33 via ge-0/0/4.45, label-switched-path r5-to-r2 192.168.23.0/24 *[BGP/170] 00:02:51, MED 1, localpref 100, from 10.50.250.10 AS path: 5673.873 I, validation-state: unverified > to 10.50.0.46 via ge-0/0/4.56, label-switched-path r5-to-r2 to 10.50.0.33 via ge-0/0/4.45, label-switched-path r5-to-r2
RouterR5isadvertisingtheroutesfromtheotherthreesitestotheVPNA-CE1.TwoprefixesadvertisedbyCE2receivedfromtheMPLScore,areadvertisedasinternalbecauseoftheindependent-domainconfiguration. [edit] lab@R5# run show route advertising-protocol bgp 192.168.15.5 VPNA.inet.0: 13 destinations, 13 routes (13 active, 0 holddown, 0 hidden) Prefix Nexthop MED Lclpref AS path * 192.168.15.8/30 Self 100 I * 192.168.15.12/30 Self 100 5673.873 I * 192.168.15.16/30 Self 100 5673.873 I * 192.168.18.0/24 Self 100 I * 192.168.19.0/24 Self 100 I * 192.168.20.0/24 Self 1 100 5673.873 I * 192.168.21.0/24 Self 1 100 5673.873 I * 192.168.22.0/24 Self 1 100 5673.873 I * 192.168.23.0/24 Self 1 100 5673.873 I
Similarly,routerR8receivestworoutesfromVPNA-CE2andadvertisestheroutesfortheotherVPNAsites. [edit] lab@R8# run show bgp summary Groups: 3 Peers: 3 Down peers: 0 Table Tot Paths Act Paths Suppressed History Damp State Pending inet.0 511 511 0 0 0 0 inet6.0 16 0 0 0 0 0 bgp.l3vpn.0 30 30 0 0 0 0 bgp.l2vpn.0 2 2 0 0 0 0 Peer AS InPkt OutPkt OutQ Flaps Last Up/Dwn State|#Active/Received/Accepted/Damped... 192.168.15.9 64999 24 35 0 0 9:40 Establ VPNA.inet.0: 2/2/2/0 [edit] lab@R8# run show route table VPNA.inet.0 VPNA.inet.0: 13 destinations, 13 routes (13 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 192.168.15.4/30 *[BGP/170] 00:01:54, localpref 100, from 10.50.250.10 AS path: I, validation-state: unverified > to 10.50.0.49 via ge-0/0/4.58, Push 18 192.168.15.8/30 *[Direct/0] 07:47:26 > via ge-0/0/5.102 192.168.15.10/32 *[Local/0] 07:47:26 Local via ge-0/0/5.102 192.168.15.12/30 *[BGP/170] 00:09:50, localpref 100, from 10.50.250.10 AS path: 5673.873 I, validation-state: unverified > to 10.50.0.53 via ge-0/0/4.68, Push 16, Push 299795(top)
[edit] lab@R5# set policy-options policy-statement VPNB-export.target term filter.AS87.109 from protocol bgp [edit] lab@R5# set policy-options policy-statement VPNB-export.target term filter.AS87.109 from as-path 87.109.origin [edit] lab@R5# set policy-options policy-statement VPNB-export.target term filter.AS87.109 then reject
TheconfigurationlinesbelowareexplicitlyadvertisingtheroutesreceivedfromAS87.109toCE1. [edit] lab@R5# set policy-options policy-statement to.VPNB-CE1 term accept.AS87.109 from protocol bgp [edit] lab@R5# set policy-options policy-statement to.VPNB-CE1 term accept.AS87.109 from as-path 87.109.origin
[edit] lab@R5# set routing-options interface-routes rib-group inet local-interfaces
Therib-group bgp.to.VPNBisassociatedtotheinternalBGPgroup.Youmightmakethemistakehereandapplytherib-grouptotheexternalBGPgrouptopeerU2.Althoughthatwillaccomplishwhatisasked,youhavetotakeintoaccountthattheconnectiontoU2couldfail. [edit] lab@R5# set protocols bgp group internal family inet unicast rib-group bgp.to.VPNB [edit] lab@R5# set routing-instances VPNB routing-options interface-routes rib-group inet local-interfaces [edit] lab@R5# set routing-instances VPNB protocols bgp group VPNB-CE1 family inet unicast rib-group VPNB.to.bgp
b. Verifytheconfiguration
Afterthecommit,alltheroutesreceivedbyAS87.109arecopiedtotheVPNBtable.[edit] lab@R5# run show route table VPNB.inet.0 VPNB.inet.0: 492 destinations, 745 routes (491 active, 0 holddown, 1 hidden) + = Active Route, - = Last Active, * = Both 1.64.0.0/10 *[BGP/170] 02:27:24, MED 50, localpref 100, from 10.50.250.10 AS path: 87.109 1620 61671 I, validation-state: unverified > to 10.50.0.85 via ge-0/0/4.35 [BGP/170] 03:44:01, MED 150, localpref 100 AS path: 87.109 1620 61671 I, validation-state: unverified > to 15.16.18.85 via ge-0/0/5.2003 1.84.160.0/20 *[BGP/170] 03:44:01, MED 60, localpref 100 AS path: 87.109 1620 33112 I, validation-state: unverified > to 15.16.18.85 via ge-0/0/5.2003 1.96.0.0/11 *[BGP/170] 02:27:24, MED 50, localpref 100, from 10.50.250.10 AS path: 87.109 1620 33112 63164 40776 51777 I, validation-state: unverified > to 10.50.0.85 via ge-0/0/4.35 [BGP/170] 03:44:01, MED 150, localpref 100 AS path: 87.109 1620 33112 63164 40776 51777 I, validation-state: unverified > to 15.16.18.85 via ge-0/0/5.2003 1.161.192.0/21 *[BGP/170] 03:44:01, MED 60, localpref 100 AS path: 87.109 1620 33112 30404 32138 45045 I, validation-state: unverified > to 15.16.18.85 via ge-0/0/5.2003 1.176.0.0/12 *[BGP/170] 02:27:24, MED 50, localpref 100, from 10.50.250.10 AS path: 87.109 1620 33112 49129 16320 52954 I, validation-state: unverified > to 10.50.0.85 via ge-0/0/4.35 [BGP/170] 03:44:01, MED 150, localpref 100 AS path: 87.109 1620 33112 49129 16320 52954 I, validation-state: unverified > to 15.16.18.85 via ge-0/0/5.2003
Conversely,theroutesreceivedfromVPNB-CE1arecopiedtomasterroutingtable. [edit] lab@R5# run show route receive-protocol bgp 172.17.0.2
inet.0: 563 destinations, 907 routes (559 active, 0 holddown, 4 hidden) Prefix Nexthop MED Lclpref AS path * 172.17.1.0/24 172.17.0.2 65100 I * 172.17.2.0/24 172.17.0.2 65100 I * 172.17.3.0/24 172.17.0.2 65100 I * 172.17.4.0/24 172.17.0.2 65100 I * 172.17.5.0/24 172.17.0.2 65100 I * 172.17.6.0/24 172.17.0.2 65100 I inet.1: 4 destinations, 4 routes (4 active, 0 holddown, 0 hidden) inet.3: 5 destinations, 9 routes (3 active, 0 holddown, 4 hidden) VPNA.inet.0: 13 destinations, 13 routes (13 active, 0 holddown, 0 hidden) VPNB.inet.0: 491 destinations, 744 routes (491 active, 0 holddown, 0 hidden) Prefix Nexthop MED Lclpref AS path * 172.17.1.0/24 172.17.0.2 65100 I * 172.17.2.0/24 172.17.0.2 65100 I * 172.17.3.0/24 172.17.0.2 65100 I * 172.17.4.0/24 172.17.0.2 65100 I * 172.17.5.0/24 172.17.0.2 65100 I * 172.17.6.0/24 172.17.0.2 65100 I
TheAS87.109routesarenotsenttorouterR8,hencetheyarenotadvertisedtoVPNB-CE2. [edit] lab@R8# run show route advertising-protocol bgp 172.17.0.6 VPNB.inet.0: 28 destinations, 28 routes (28 active, 0 holddown, 0 hidden) Prefix Nexthop MED Lclpref AS path * 10.50.0.32/30 Self I * 10.50.0.44/30 Self I * 10.50.0.48/30 Self I * 10.50.0.84/30 Self I * 10.50.0.100/30 Self I * 10.50.250.5/32 Self I * 15.16.18.84/30 Self I * 172.16.5.4/30 Self 4356 I * 172.17.0.0/30 Self I * 172.17.1.0/24 Self 5673.873 I * 172.17.2.0/24 Self 5673.873 I * 172.17.3.0/24 Self 5673.873 I * 172.17.4.0/24 Self 5673.873 I * 172.17.5.0/24 Self 5673.873 I * 172.17.6.0/24 Self 5673.873 I
First,theinterfacebetweenthetwonetworksmustbeconfigured.Inter-ASoptionBexchangeslabeledroutesbetweentheASBRs,thismeanstheinterconnectinterfacesmustbealsoconfiguredwithfamily mpls.[edit] lab@R1# set interfaces ge-0/0/5 unit 112 description "=== connection to ISP1 ===" [edit] lab@R1# set interfaces ge-0/0/5 unit 112 vlan-id 112 [edit] lab@R1# set interfaces ge-0/0/5 unit 112 family inet address 172.17.0.9/30 [edit] lab@R1# set interfaces ge-0/0/5 unit 112 family mpls
NexttheexternalMP-BGPsessionisconfiguredbetweenrouterR1andtheISP1peer. [edit] lab@R1# set protocols bgp group ISP1 log-updown [edit] lab@R1# set protocols bgp group ISP1 family inet-vpn unicast [edit] lab@R1# set protocols bgp group ISP1 peer-as 4356 [edit] lab@R1# set protocols bgp group ISP1 neighbor 172.17.0.10
b. R5
BecauseusingaroutingpolicyonrouterR1tomanipulatetheroutesexchangedbetweentheASBRsisnotallowed,youcanaccepttheremoteroute-targetcommunityonrouterR5andR8.ThiswillprovidesuccessfulcommunicationbetweenthelocalandremotesitesofVPNB. [edit] lab@R5# set policy-options policy-statement VPNB-export.target term accept.rest then community add VPNB-CE3 [edit] lab@R5# set policy-options policy-statement VPNB-import.target term 1 from community VPNB-CE3
[edit] lab@R5# set policy-options community VPNB-CE3 members target:4356:500
c. R8
[edit] lab@R8# set policy-options policy-statement VPNB-export.target term accept.rest then community add VPNB-CE3 [edit] lab@R8# set policy-options policy-statement VPNB-import.target term 1 from community VPNB-CE3 [edit] lab@R8# set policy-options community VPNB-CE3 members target:4356:500
d. Verifytheconfiguration
RouterR1receivesvpnv4routesfromtheISP1peer. [edit] lab@R1# run show route table bgp.l3vpn.0 bgp.l3vpn.0: 39 destinations, 39 routes (39 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 4356:500:172.16.5.4/30 *[BGP/170] 04:41:35, localpref 100 AS path: 4356 I, validation-state: unverified > to 172.17.0.10 via ge-0/0/5.112, Push 299786 4356:500:172.17.31.0/24 *[BGP/170] 04:41:35, localpref 100 AS path: 4356 65100 I, validation-state: unverified > to 172.17.0.10 via ge-0/0/5.112, Push 299786 4356:500:172.17.32.0/24 *[BGP/170] 04:41:35, localpref 100 AS path: 4356 65100 I, validation-state: unverified > to 172.17.0.10 via ge-0/0/5.112, Push 299786 4356:500:172.17.33.0/24 *[BGP/170] 04:41:35, localpref 100 AS path: 4356 65100 I, validation-state: unverified > to 172.17.0.10 via ge-0/0/5.112, Push 299786 4356:500:172.17.34.0/24 *[BGP/170] 04:41:35, localpref 100 AS path: 4356 65100 I, validation-state: unverified > to 172.17.0.10 via ge-0/0/5.112, Push 299786 4356:500:172.17.35.0/24 *[BGP/170] 04:41:35, localpref 100 AS path: 4356 65100 I, validation-state: unverified > to 172.17.0.10 via ge-0/0/5.112, Push 299786
Usingtheremoteroute-targetcommunityintheimportvrfpolicy,routerR5importstheremoteroutesintothevrfroutingtable. [edit] lab@R5# run show route 172.17.31.0/24 VPNB.inet.0: 492 destinations, 745 routes (492 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 172.17.31.0/24 *[BGP/170] 02:48:55, localpref 100, from 10.50.250.10 AS path: 4356 65100 I, validation-state: unverified > to 10.50.0.46 via ge-0/0/4.56, label-switched-path r5-to-r1 bgp.l3vpn.0: 21 destinations, 21 routes (21 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both 4356:500:172.17.31.0/24 *[BGP/170] 02:48:55, localpref 100, from 10.50.250.10 AS path: 4356 65100 I, validation-state: unverified > to 10.50.0.46 via ge-0/0/4.56, label-switched-path r5-to-r1
Similarly,routerR8successfullyimportstheroutesintotheVPNBroutingtable. [edit] lab@R8# run show route advertising-protocol bgp 172.17.0.6 VPNB.inet.0: 28 destinations, 28 routes (28 active, 0 holddown, 0 hidden) Prefix Nexthop MED Lclpref AS path * 172.17.31.0/24 Self 4356 5673.873 I * 172.17.32.0/24 Self 4356 5673.873 I * 172.17.33.0/24 Self 4356 5673.873 I * 172.17.34.0/24 Self 4356 5673.873 I * 172.17.35.0/24 Self 4356 5673.873 I
[edit] lab@R1# set class-of-service schedulers af transmit-rate percent 20 [edit] lab@R1# set class-of-service schedulers af priority high [edit] lab@R1# set class-of-service schedulers nc transmit-rate percent 5 [edit] lab@R1# set class-of-service schedulers nc priority low [edit] lab@R1# set class-of-service schedulers be transmit-rate remainder [edit] lab@R1# set class-of-service schedulers be priority low
b. R5
Bydefault,associatingscheduler-mapcanbedoneunderthephysicalinterfacesundertheclass-of-servicestanza.However,sinceyouarenotallowedtoapplycustomCoSpoliciestotrafficotherthenVPNB,youhavetoenableper-unit-schedulerfortheinterfacetotheCEsites.Thisallowsyoutoapplythecustomscheduleronlyforaspecificunit.[edit] lab@R5# set interfaces ge-0/0/5 per-unit-scheduler [edit] lab@R5# set class-of-service interfaces ge-0/0/5 unit 110 scheduler-map custom-map [edit] lab@R5# set class-of-service interfaces ge-0/0/5 unit 110 classifiers inet-precedence VPNB-precedence
Whenvrf-table-labelisusedfortheroutinginstances,adefaultclassifierisappliedtotherouting-instancelogicalinterface.YouhavetoreplacethedefaultEXPclassifierwiththecustomone,tomapthetrafficcomingfromtheMPLScore.Thepurposeofthisclassifieristomatchonthevpnlabelafterthetransportlabelisstrippedoff. [edit] lab@R5# set class-of-service routing-instances VPNB classifiers exp custom-exp
c. R8
ThesameconfigurationisappliedtorouterR8aswell. [edit] lab@R8# set interfaces ge-0/0/5 per-unit-scheduler [edit] lab@R8# set class-of-service interfaces ge-0/0/5 unit 111 scheduler-map custom-map [edit] lab@R8# set class-of-service interfaces ge-0/0/5 unit 111 classifiers inet-precedence VPNB-precedence [edit] lab@R8# set class-of-service routing-instances VPNB classifiers exp custom-exp
[edit] lab@R1# set interfaces ge-0/0/3 unit 3001 description "=== connection to VPLS-1 ===" [edit] lab@R1# set interfaces ge-0/0/3 unit 3001 encapsulation vlan-vpls [edit] lab@R1# set interfaces ge-0/0/3 unit 3001 vlan-id 3001 [edit] lab@R1# set interfaces ge-0/0/3 unit 3001 family vpls
Makesuretheroutinginstancetypeissettovpls.BecauseBGPisusedforauto-discovery,youhavetoassignroute-distinguisherandroute-targettotheroutinginstanceconfiguration. [edit] lab@R1# set routing-instances VPLS instance-type vpls [edit] lab@R1# set routing-instances VPLS interface ge-0/0/3.3001 [edit] lab@R1# set routing-instances VPLS route-distinguisher 10.50.250.1:300
Theauto-discoveryprocessrequireauniqueextendedL2VPNcommunityidentifyingtheparticularinstance. [edit] lab@R1# set routing-instances VPLS l2vpn-id l2vpn-id:300:300 [edit] lab@R1# set routing-instances VPLS vrf-target target:371786601L:300
Theno-tunnel-serviceeliminatestheneedofhardwaretunnelinterface. [edit] lab@R1# set routing-instances VPLS protocols vpls interface ge-0/0/3.3001 [edit] lab@R1# set routing-instances VPLS protocols vpls no-tunnel-services
c. R8
ConfiguringanewphysicalinterfacetoconnectsiteVPLS-2.Youhavetoexcludetheapply-groupagain. [edit] lab@R8# set interfaces ge-0/0/3 apply-groups-except enable_mpls [edit] lab@R8# set interfaces ge-0/0/3 description "=== connection to VPLS-2 ===" [edit] lab@R8# set interfaces ge-0/0/3 vlan-tagging [edit] lab@R8# set interfaces ge-0/0/3 encapsulation vlan-vpls [edit] lab@R8# set interfaces ge-0/0/3 unit 3002 encapsulation vlan-vpls [edit]
[edit] lab@R6# set interfaces ge-0/0/3 description "=== connection to VPLS-2 ===" [edit] lab@R6# set interfaces ge-0/0/3 vlan-tagging [edit] lab@R6# set interfaces ge-0/0/3 encapsulation vlan-vpls [edit] lab@R6# set interfaces ge-0/0/3 unit 3002 encapsulation vlan-vpls [edit] lab@R6# set interfaces ge-0/0/3 unit 3002 vlan-id 3002 [edit] lab@R6# set interfaces ge-0/0/3 unit 3002 family vpls [edit] lab@R6# set routing-instances VPLS instance-type vpls [edit] lab@R6# set routing-instances VPLS interface ge-0/0/3.3002 [edit] lab@R6# set routing-instances VPLS route-distinguisher 10.50.250.6:300 [edit] lab@R6# set routing-instances VPLS l2vpn-id l2vpn-id:300:300 [edit] lab@R6# set routing-instances VPLS vrf-target target:371786601L:300 [edit] lab@R6# set routing-instances VPLS protocols vpls no-tunnel-services [edit] lab@R6# set routing-instances VPLS protocols vpls multi-homing site VPLS-2 identifier 2
RouterR6isconfiguredwithpreferencebackup,whichmeansthatitislesslikelytobecomeaDF. [edit] lab@R6# set routing-instances VPLS protocols vpls multi-homing site VPLS-2 preference backup [edit] lab@R6# set routing-instances VPLS protocols vpls multi-homing site VPLS-2 interface ge-0/0/3.3002
e. Verifytheconfiguration
TheVPLSisestablished. [edit] lab@R1# run show vpls connections Layer-2 VPN connections: Legend for connection status (St) EI -- encapsulation invalid NC -- interface encapsulation not CCC/TCC/VPLS EM -- encapsulation mismatch WE -- interface and instance encaps not same VC-Dn -- Virtual circuit down NP -- interface hardware not present CM -- control-word mismatch -> -- only outbound connection is up CN -- circuit not provisioned <- -- only inbound connection is up OR -- out of range Up -- operational OL -- no outgoing label Dn -- down
LD -- local site signaled down CF -- call admission control failure RD -- remote site signaled down SC -- local and remote site ID collision LN -- local site not designated LM -- local site ID not minimum designated RN -- remote site not designated RM -- remote site ID not minimum designated XX -- unknown connection status IL -- no incoming label MM -- MTU mismatch MI -- Mesh-Group ID not available BK -- Backup connection ST -- Standby connection PF -- Profile parse failure PB -- Profile busy RS -- remote site standby SN -- Static Neighbor LB -- Local site not best-site RB -- Remote site not best-site VM -- VLAN ID mismatch Legend for interface status Up -- operational Dn -- down Instance: VPLS L2vpn-id: 300:300 Local-id: 10.50.250.1 Remote-id Type St Time last up # Up trans 10.50.250.6 rmt Up Dec 3 17:16:19 2016 1 Remote PE: 10.50.250.6, Negotiated control-word: No Incoming label: 262156, Outgoing label: 262154 Negotiated PW status TLV: No Local interface: lsi.1048587, Status: Up, Encapsulation: ETHERNET Description: Intf - vpls VPLS local-id 10.50.250.1 remote-id 10.50.250.6 neighbor 10.50.250.6 Flow Label Transmit: No, Flow Label Receive: No 10.50.250.8 rmt Up Dec 3 17:16:44 2016 1 Remote PE: 10.50.250.8, Negotiated control-word: No Incoming label: 262157, Outgoing label: 262154 Negotiated PW status TLV: No Local interface: lsi.1048588, Status: Up, Encapsulation: ETHERNET Description: Intf - vpls VPLS local-id 10.50.250.1 remote-id 10.50.250.8 neighbor 10.50.250.8 Flow Label Transmit: No, Flow Label Receive: No
RouterR8isdesignatedasDFrouterfortheVPLS-2site. [edit] lab@R8# run show vpls connections Layer-2 VPN connections: Legend for connection status (St) EI -- encapsulation invalid NC -- interface encapsulation not CCC/TCC/VPLS EM -- encapsulation mismatch WE -- interface and instance encaps not same VC-Dn -- Virtual circuit down NP -- interface hardware not present CM -- control-word mismatch -> -- only outbound connection is up CN -- circuit not provisioned <- -- only inbound connection is up OR -- out of range Up -- operational OL -- no outgoing label Dn -- down LD -- local site signaled down CF -- call admission control failure RD -- remote site signaled down SC -- local and remote site ID collision LN -- local site not designated LM -- local site ID not minimum designated RN -- remote site not designated RM -- remote site ID not minimum designated XX -- unknown connection status IL -- no incoming label MM -- MTU mismatch MI -- Mesh-Group ID not available BK -- Backup connection ST -- Standby connection PF -- Profile parse failure PB -- Profile busy RS -- remote site standby SN -- Static Neighbor LB -- Local site not best-site RB -- Remote site not best-site VM -- VLAN ID mismatch Legend for interface status Up -- operational Dn -- down Instance: VPLS
L2vpn-id: 300:300 Local-id: 10.50.250.8 Remote-id Type St Time last up # Up trans 10.50.250.1 rmt Up Dec 5 12:23:28 2016 1 Remote PE: 10.50.250.1, Negotiated control-word: No Incoming label: 262402, Outgoing label: 262146 Negotiated PW status TLV: No Local interface: lsi.1048579, Status: Up, Encapsulation: ETHERNET Description: Intf - vpls VPLS local-id 10.50.250.8 remote-id 10.50.250.1 neighbor 10.50.250.1 Flow Label Transmit: No, Flow Label Receive: No 10.50.250.6 rmt Up Dec 5 12:25:17 2016 1 Remote PE: 10.50.250.6, Negotiated control-word: No Incoming label: 262401, Outgoing label: 262145 Negotiated PW status TLV: No Local interface: lsi.1048580, Status: Up, Encapsulation: ETHERNET Description: Intf - vpls VPLS local-id 10.50.250.8 remote-id 10.50.250.6 neighbor 10.50.250.6 Flow Label Transmit: No, Flow Label Receive: No Multi-home: Local-site Id Pref State VPLS-2 2 200 Up [edit] lab@R6# run show vpls connections Layer-2 VPN connections: Legend for connection status (St) EI -- encapsulation invalid NC -- interface encapsulation not CCC/TCC/VPLS EM -- encapsulation mismatch WE -- interface and instance encaps not same VC-Dn -- Virtual circuit down NP -- interface hardware not present CM -- control-word mismatch -> -- only outbound connection is up CN -- circuit not provisioned <- -- only inbound connection is up OR -- out of range Up -- operational OL -- no outgoing label Dn -- down LD -- local site signaled down CF -- call admission control failure RD -- remote site signaled down SC -- local and remote site ID collision LN -- local site not designated LM -- local site ID not minimum designated RN -- remote site not designated RM -- remote site ID not minimum designated XX -- unknown connection status IL -- no incoming label MM -- MTU mismatch MI -- Mesh-Group ID not available BK -- Backup connection ST -- Standby connection PF -- Profile parse failure PB -- Profile busy RS -- remote site standby SN -- Static Neighbor LB -- Local site not best-site RB -- Remote site not best-site VM -- VLAN ID mismatch Legend for interface status Up -- operational Dn -- down Instance: VPLS L2vpn-id: 300:300 Local-id: 10.50.250.6 Remote-id Type St Time last up # Up trans 10.50.250.1 rmt Up Dec 3 14:58:50 2016 1 Remote PE: 10.50.250.1, Negotiated control-word: No Incoming label: 262154, Outgoing label: 262156 Negotiated PW status TLV: No Local interface: lsi.1048586, Status: Up, Encapsulation: ETHERNET Description: Intf - vpls VPLS local-id 10.50.250.6 remote-id 10.50.250.1 neighbor 10.50.250.1 Flow Label Transmit: No, Flow Label Receive: No 10.50.250.8 rmt Up Dec 3 14:59:09 2016 1 Remote PE: 10.50.250.8, Negotiated control-word: No Incoming label: 262155, Outgoing label: 262155 Negotiated PW status TLV: No Local interface: lsi.1048587, Status: Up, Encapsulation: ETHERNET
Description: Intf - vpls VPLS local-id 10.50.250.6 remote-id 10.50.250.8 neighbor 10.50.250.8 Flow Label Transmit: No, Flow Label Receive: No Multi-home: Local-site Id Pref State VPLS-2 2 1 Up
Theroute-reflectorreceivesBGPauto-discoveryroutes. [edit] lab@route-reflector# run show route table bgp.l2vpn.0 bgp.l2vpn.0: 3 destinations, 3 routes (3 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 10.50.250.1:300:10.50.250.1/96 AD *[BGP/170] 02:45:57, localpref 100, from 10.50.250.1 AS path: I, validation-state: unverified > to 10.50.0.97 via ge-0/0/1.49 10.50.250.6:300:10.50.250.6/96 AD *[BGP/170] 02:45:59, localpref 100, from 10.50.250.6 AS path: I, validation-state: unverified > to 10.50.0.97 via ge-0/0/1.49 to 10.50.0.101 via ge-0/0/1.59 10.50.250.8:300:10.50.250.8/96 AD *[BGP/170] 02:45:43, localpref 100, from 10.50.250.8 AS path: I, validation-state: unverified > to 10.50.0.101 via ge-0/0/1.59
ConfiguretheinterfacetoconnectsiteL2VPN-3tothenetwork.Again,theapplygroupmustbeexcluded. [edit] lab@R2# set interfaces apply-groups enable_mpls [edit] lab@R2# set interfaces ge-0/0/3 apply-groups-except enable_mpls [edit] lab@R2# set interfaces ge-0/0/3 description "=== connection to L2VPN-3 ==="
Theencapsulationusedontheinterfacemustbeccc,aswellasthefamilyonlogicalinterface. [edit] lab@R2# set interfaces ge-0/0/3 encapsulation ethernet-ccc [edit] lab@R2# set interfaces ge-0/0/3 unit 0 family ccc