MPLS IP VPNs: Design & Best Practices
MPLS IP VPNs: Design & Best Practices
Designing IP VPNs
MPLS with/out Segment Routing
Rajiv Asati
CTO, VP/Cisco Fellow
BRKMPL-2102
#CiscoLive
Slido Poll
Abstract
• This session describes IP Virtual Private Networks (IP VPNs) overlays using MPLS data
plane. It is the most common Layer 3 VPN technology, as standardized by IETF
RFC2547/4364, enabling IPv6 (and/or IPv4) WAN connectivity among 2 or more sites,
endpoints, functions etc. over IP/MPLS network(s).
• SPs have been using IP VPN to provide scalable site-to-site/WAN connectivity to
Enterprises/Public Sector/SMBs for 2+ decades (and recently to create 5G slices), whereas
Enterprises/Public Sectors have been using it to address network segmentation
(virtualization and traffic separation) inside their sites e.g. Campus, Branch, Data Center,
Cloud. The session will cover:
• Technology & Config Overview
• Deployment Scenarios
• Use-Cases Summary
• Best Practices
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Prerequisites Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Terminology Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
• IP/VPN Overview
• Deployment Scenarios
• Use-Cases Summary
• Best Practices
Agenda • Conclusion
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
• IP/VPN Overview
• Technology Overview
• Configuration Overview
(reference only)
• Deployment Scenarios
• Use-Cases
Agenda • Best Practices
• Conclusion
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
IP/VPN Technology Overview
• More than one routing and forwarding tables
• Control plane—VPN route propagation
• Data plane—VPN packet forwarding
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
IP/VPN Technology Overview
Network Topology / Connection Model
IP/MPLS Network
CE P P
CE
PE PE
P P
CE
CE
MP-iBGP Session
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
IP/VPN Technology Overview
Virtual Routing and Forwarding (VRF) Instance
CE2
VPN 2 VRF Green
PE
CE1 MPLS Network IGP (OSPF, ISIS)
VPN 1 GE0/0
VRF Blue
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
IP/VPN Technology Overview
Virtual Routing and Forwarding Instance
EIGRP, eBGP, OSPF, RIPv2, Static Routing Advertisements
CE2
VPN 2 VRF Green
PE
CE1 MPLS Network IGP (OSPF, ISIS)
VPN 1
VRF Blue
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
IP/VPN Technology Overview
VPN Control Plane
MP-iBGP Session
PE
PE
MPLS Network
PE
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
IP/VPN Technology Overview
VPN Control Plane = Multi-Protocol BGP (MP-BGP)
8 Bytes 4 Bytes 8 Bytes 3 Bytes
(16 Bytes) MP-BGP UPDATE Message
1:1
Showing VPN route, RT,
RD IPv4 (or IPv6) Route-Target Label
VPN Label only
MP-BGP on PE Customizes the VPN Customer Routing Information as per the Locally
Configured VRF Information using:
• Route Distinguisher (RD)
• Route Target (RT)
• Label (not configured)
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
IP/VPN Technology Overview: Control Plane Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
IP/VPN Technology Overview: Control Plane
Route-Distinguisher (rd): 8-byte field
8 Bytes 4 Bytes 8 Bytes 3 Bytes 8 Bytes 16 Bytes 8 Bytes 3 Bytes
• VPN customer IP prefix is converted into a VPN prefix by appending the RD (3:1, say)
to make the customer’s IP prefixes unique inside the shared IP/MPLS network
• [Link] => 1:1:[Link] ; 2001:DB8:: => 1:1:2001:DB8::
• Route Distinguisher (rd) is mapped to a VRF at PE IOS_PE#
!
ip vrf green
• RD is not a BGP attribute, just a field in another attribute (MP_REACH_NLRI) rd 1:1
!
• RD format is X:Y
* Since 12.4(3)T, 12.4(3) 12.2(32)S, 12.0(32)S etc., RD Configuration
within VRF Has Become Optional. Prior to That, It Was Mandatory.
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
IP/VPN Technology Overview: Control Plane
Route-Target (rt): 8-byte extended community attribute
8 Bytes 4 Bytes 8 Bytes 3 Bytes 8 Bytes 16 Bytes 8 Bytes 3 Bytes
address-family ipv6
• IPv4 and IPv6 address-family RT values are allowed to be different (as shown) route-target import 1:1
route-target export 1:5
!
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
IP/VPN Technology Overview: Control Plane
Label : 20-bit value
8 Bytes 4 Bytes 8 Bytes 3 Bytes 8 Bytes 16 Bytes 8 Bytes 3 Bytes
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
IP/VPN Technology Overview: Control Plane
Putting it all together
MP-iBGP Update:
1:1:2001:DB8::
Site 1 3 Next-Hop=PE-1 Site 2
RT=1:5, Label=115
2001:DB8:: CE1
2 P P
CE2
2001:DB8::
Next-Hop=CE-1
P P
1 PE1 PE2
MPLS Backbone
2.2 PE1 translates it into VPNv6(v4) address & sends MP-iBGP UPDATE message
• Associates the RT values (export RT =1:5, say) per VRF green configuration
• Rewrites next-hop attribute to its IP address (usually loopback0 int)
• Assigns a label (115, say); Installs it in the MPLS forwarding table.
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
IP/VPN Technology Overview: Control Plane
Putting it all together
MP-iBGP Update:
1:1:2001:DB8:: 2001:DB8::
MPLS Backbone
4 PE2 receives and checks whether the RT=1:5 is locally configured as ‘import RT’
4.
within any VRF, if yes, then
• PE2 translates VPN prefix back to IP prefix
• PE2 updates its VRF CEF Table (green) with IP prefix - 2001:DB8:: along with label=115
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
IP/VPN Technology Overview
Forwarding Plane
VPN Site 2
VPN Site 1
CE1
MPLS Forwarding Table
[Link]/24 MPLS Backbone
P P
• StoresCE2
labels for PE/P routes i.e. next-hops
• Label learned SR/IGP or LDP, RSVP or BGP
P P
PE1 PE2
IOS:show mpls forwarding
NX-OS: show mpls forwarding
IOS-XR: show mpls forwarding
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
IP/VPN Technology Overview: Forwarding Plane
Packet Forwarding
Site 1 Site 2
CE1
[Link]/24 CE2
P3 P4
PE1 PE2
[Link] [Link] IP Packet
23 [Link] P1 P2
IP Packet
• PE2 imposes two labels (in 2 MPLS headers) for each IP packet going towards remote site
• Outer label 100 for PE1 address (learned via SR/IGP or LDP or RSVP or static..)
• Inner label 23 for VPN address (learned via BGP)
• P2 swaps the outer label (100 with 50) per its MPLS forwarding table
• P1 does the Penultimate Hop Popping (PHP) i.e. removes the outer label 50
• PE1 removes label 23, retrieves IP packet and forwards it to CE1.
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
IP/VPN Technology Overview: Forwarding Plane
Reference
Ethernet Header
Outer MPLS header
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
• IP/VPN Overview
• Technology Overview
• Configuration Overview
(reference only)
• Deployment Scenarios
• Best Practices
Agenda • Use-Cases
• Conclusion
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
MPLS based IP/VPN Sample Configuration (IOS)
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
MPLS based IP/VPN Sample Configuration (IOS)
Reference
router bgp 1
PE: MP-IBGP Config neighbor [Link] remote-as 1
neighbor [Link] update-source loopback0
!
R address-family vpnv4
R neighbor [Link] activate
PE1 PE2 PE neighbor [Link] send-community both
1 !
address-family vpnv6
neighbor [Link] activate
!
neighbor [Link] send-community both Config Shows
Both IPv6 VPN
And IPv4 VPN
RR: MP-IBGP Config router bgp 1
no bgp default route-target filter
neighbor [Link] remote-as 1
R neighbor [Link] update-source loopback0
R RR !
PE1 PE2 address-family vpnv4 | vpnv6
neighbor [Link] route-reflector- client
neighbor [Link] activate
!
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
MPLS based IP/VPN Sample Configuration (IOS)
Reference
PE-CE Routing: OSPF router ospf 2 unicast vrf VPN-A router ospfv3
network [Link] [Link] area 0 !
redistribute bgp 1 subnets address-family unicast vrf VPN-A
Site 1
CE1 ! router-id 2001:DB8::2
redistribute bgp 1 subnets
[Link]/24 PE1
!
interface Serial0
[Link] PE1 ospfv3 2 ipv6 area 0
2001:DB8::2
redistribute bgp 1 subnets
[Link] !
2001:DB8::1
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
MPLS based IP/VPN Sample Configuration (IOS)
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
MPLS based IP/VPN Sample Configuration (IOS)
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
MPLS based IP/VPN Sample Configuration (IOS)
Reference
PE-P Configuration
mpls ip
int GE1
P !
PE1 GE1 PE
GE
1 router ospf 1
0
area 0
interface GE1
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
MPLS based IP/VPN Sample Config (IOS-XR)
Reference
router bgp 1
RR: MP-IBGP Config router-id [Link]
address-family vpnv4 unicast
!
R neighbor [Link]
R remote-as 1
RR update-source loopback0
PE1 PE2
address-family vpnv4 unicast
send-community extended
route-reflector-client
!
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
MPLS based IP/VPN Sample Config (IOS-XR)
Reference
router bgp 1
PE-CE Routing: BGP !
vrf VPN-A
Site 1 neighbor [Link]
CE1 remote-as 2
[Link]/24 PE1 address-family ipv4 unicast
route-policy pass-all in|out
[Link] GE0 PE1 !
!
[Link] !
!
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
MPLS based IP/VPN Sample Config (IOS-XR)
Reference
[Link]
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
MPLS based IP/VPN Sample Config (IOS-XR)
Reference
[Link]
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
MPLS based IP/VPN Sample Config (IOS-XR)
Reference
If PE-CE Protocol Is Non-BGP, then Redistribution of Local VPN Routes into MP-IBGP Is
Required (Shown Below)
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
MPLS based IP/VPN Sample Config (NX-OS)
Reference
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
MPLS based IP/VPN Sample Config (NX-OS)
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
MPLS based IP/VPN Sample Config (NX-OS)
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
MPLS based IP/VPN Sample Config (NX-OS)
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
MPLS based IP/VPN Sample Config (NX-OS)
Reference
[Link]
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
MPLS based IP/VPN Sample Config (NX-OS)
Reference
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub and Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
IP/VPN Deployment Scenarios:
1. Multi-homing & Loadsharing of VPN Traffic
RR
PE11
CE1 PE2 CE2
[Link]/24
PE12
Site A Site B
MPLS Backbone
Route Advertisement
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
IP/VPN Deployment Scenarios:
1. Multi-homing & Loadsharing of VPN Traffic
Vrf <name> 2 <BGP>
1 RR
rd 300:11 address-family ipv4 vrf green
route-target both 1:1 PE11 maximum-paths eibgp 2
CE1 PE2 CE2
[Link]/24
PE12
Site A Site B
1 MPLS Backbone
Vrf <name>
Vrf <name>
rd 300:12
rd 300:13
route-target both 1:1
route-target both 1:1
• Enable eiBGP multipath within the relevant BGP VRF address-family at remote PE
routers such as PE2 (why PE2?).
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Supported in IOS,
and IOS-XR
Traffic Is RR
Dropped VPN Traffic
by PE11 PE11 Redirected VPN Traffic
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
IP/VPN Deployment Scenarios:
Supported in IOS,
and IOS-XR 3.4
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
IP/VPN Deployment Scenarios:
2. Hub and Spoke Service
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
IP/VPN Deployment Scenarios:
2. Hub and Spoke Service
PE-Hub
Eth0/0
Spoke B PE-SB
CE-SB CE-Hub
MPLS VPN Backbone
[Link]/24
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Supported in IOS,
NXOS and IOS-XR
Eth0/0.1
PE-Hub Eth0/0.2
Spoke B PE-SB
CE-SB CE-Hub
MPLS VPN Backbone
[Link]/24
<VRF IN for Hub>
rd 300:12
<VRF GREEN for Spoke B> route-target export 2:2
rd 300:112
route-target export 1:1
route-target import 2:2
• If BGP is used between every PE and CE, then allowas-in and as-override*
knobs must be used at the PE_Hub**
• Otherwise AS_PATH looping will occur
* Only If Hub and Spoke Sites Use the Same BGP ASN
** Configuration for This Is Shown on the Next Slide
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Supported in IOS,
NXOS and IOS-XR
Spoke A
CE-SA PE-SA
[Link]/24
Eth0/0.1
Spoke B PE-Hub Eth0/0.2
PE-SB
CE-SB CE-Hub
MPLS VPN Backbone
[Link]/24
<BGP>
address-family ipv4 vrf HUB-OUT
neighbor <CE> allowas-in 2
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Supported in IOS,
NXOS and IOS-XR
MP-iBGP Update
VRF FIB and LFIB
1:1:[Link]/16
VRF HUB-IN
[Link]/16 PE-Hub 35
Label 35
[Link]/24 CE-SB PE-Hub VRF HUB-OUT
PE-SB Route-Target 2:2
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Supported in IOS,
NXOS and IOS-XR
VRF HUB-IN
CE-Hub
Spoke B PE-Hub
VRF HUB-OUT
CE-SB PE-SB L1 35 [Link]
[Link]
[Link]/24
[Link]
• If more than one spoke router (CE) connects to the same PE router (within
the same VRF), then such spokes can reach other without needing the hub.
• Defeats the purpose of hub and spoke CE-SA1 PE-Hub
CE-SA2 PE-SA
Note: 12.2(33) SRE. XE 3.0S Support Any Interface Type (Eth, Ser, POS, Virtual-Access, etc.)
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Supported in IOS
PE-Hub
Spoke B CE-Hub
Interface GigEthernet 0/0 - 1 ip vrf HUB-OUT
[Link]/24 ip address 172.18.13.x [Link] description VRF for traffic to HUB
ip vrf forward green-up downstream green-down rd 300:12
CE-SB .. route-target export 2:2
1. PE-SA installs the Spoke routes only in downstream VRF i.e. green-down
2. PE-SA installs the Hub routes only in upstream VRF i.e. green-up
3. PE-SA forwards the incoming IP traffic (from Spokes) using upstream VRF i.e. green-up routing table.
4. PE-SA forwards the incoming MPLS traffic (from Hub) using downstream VRF i.e. green-down routing table
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
IP/VPN Deployment Scenarios
3. Extranet VPN
• MPLS based IP/VPN, by default, isolates one VPN customer from another
• Separate virtual routing table for each VPN customer
• Communication between VPNs may be required i.e. extranet
• External intercompany communication (dealers with manufacturer, retailer with
wholesale provider, etc.)
• Management VPN, shared-service VPN, etc.
• Implemented by sharing import and export route-target (RT) values within
the VRFs of extranets.
• Export-map or import-map may be used for advanced extranet.
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
IP/VPN Deployment Scenarios Supported in IOS,
NXOS and IOS-XR
3. Extranet VPN – Simple Extranet (IOS Config sample)
[Link]/16
MPLS Backbone
VPN_A Site#2
VPN_A Site#1
[Link]/16 PE1 PE2
P [Link]/16
VPN_B Site#1
[Link]/16
MPLS Backbone
VPN_A Site#2
VPN_A Site#1
[Link]/16 PE1 PE2
P
[Link]/16
VPN_B Site#1
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Use-Cases
1. SP – Business VPN Service, Mobile Backhaul
2. SP – Internal Usage (e.g. IT), Mobile Backhaul
3. Enterprise – Campus Virtualization/Segmentation
4. Data Center – Multi-Tenancy
5. Data Center – Cloud/Virtualization/Hypervisor
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Use-Case #1
SP – Business VPN Services, Mobile Backhaul
• SPs can use IP/VPN to offer L3 site-to-site connectivity to
Enterprises/SMB customers’
• SPs can even offer Remote Access integrated with L3VPN
Enterprise Green
Site 1 Enterprise Green
CE1 Site 2
P P
CE2
Enterprise Green Enterprise Green
Site 3 P P Site 4
PE1 PE2
CE4
SP Network
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Use-Case #2
SP – Internal Usage (e.g. IT, Mobile Backhaul)
• SP/ISPs can overlay its Enterprise and/or IT WAN connectivity over
its MPLS network (that is used to offer L3VPN services to its
customers) SP IT
SP IT
Site 1
Site 2
SP Network
SP IT
Site 3
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Use-Case#3
Enterprise – Campus Segmentation/Virtualization
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Eliminates the need for VXLAN
Use-Case#4
Data Center – Multi-Tenancy Campus/ Global
• IP/VPN can be used by “ Cloud or Internet WAN Edge Interconn
ect
MPLS
• Data Center services to B2B customers
• MPLS upto TOR/Leaf;
• Segment Routing could be used
PE
Layer-2
• MPLS PE function on TOR / Leaf
Device CE
• CE function on VMs or Bare Metal POD POD POD
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Eliminates the need for VXLAN
Use-Case#5
Data Center – Cloud / Virtualization Campus/ Global
• MPLS in Data Center (Underlay) Internet WAN Edge Interconn
ect
MPLS
•
• Segment Routing could be used
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Best Practices (1)
1. Use RR to scale BGP; deploy RRs in pair for the redundancy
Keep RRs out of the forwarding paths and disable CEF (saves memory)
2. Choose AS format for RT and RD i.e., ASN: X
Reserve first few 100s of X for the internal purposes such as filtering
3. Consider unique RD per VRF per PE,
Helpful for many scenarios such as multi-homing, hub&spoke etc.
Helpful to avoid add-path, shadow RR etc.
4. Don’t use customer names (V458:GodFatherNYC32ndSt) as the VRF names; nightmare
for the NOC.
Consider v101, v102, v201, v202, etc. and Use VRF description for naming
5. Utilize SP’s public address space for PE-CE IP addressing
Helps to avoid overlapping; Use /31 subnetting on PE-CE interfaces
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Best Practices (2)
6. Limit number of prefixes per-VRF and/or per-neighbor on PE
Max-prefix within VRF configuration; Suppress the inactive routes
Max-prefix per neighbor (PE-CE) within OSPF/RIP/BGP VRF af
7. Leverage BGP Prefix Independent Convergence (PIC) for fast convergence <100ms (IPv6
and IPv4):
• PIC Core, PIC Edge
• Best-external advertisement
• Next-hop tracking (ON by default)
8. Consider RT-constraint for PE & RR scalability (millions of routes)
9. Consider ‘BGP slow peer’ for PE or RR – faster BGP convergence
10. Use a dedicated VPN for CE Management
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
• IP/VPN Overview
• Deployment Scenarios
• Use-Cases Summary
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Conclusion
• IP/VPN is the most optimal L3VPN technology
• Any-to-any, Partial-mesh, Hub-and-Spoke topologies
• IPv6 or IPv4 or both
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Fill out your session surveys!
These points help you get on the leaderboard and increase your chances of winning daily and grand prizes
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
• Visit the Cisco Showcase
for related demos
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Thank you
#CiscoLive
Gamify your Cisco Live experience!
Get points for attending this session!
How:
1 Open the Cisco Events App.
4 Click the + at the bottom of the screen and scan the QR code:
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
#CiscoLive
Supplemental Material
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary
4. Internet Access
Agenda • Best Practices
• Conclusion
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
IP/VPN Deployment Scenarios
4. Internet Access Service to VPN Customers
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
IP/VPN Deployment Scenarios
4. Internet Access: Design Options
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
IP/VPN Deployment Scenarios
4. Internet Access: Design Options
• VRF specific default route • Separate PE-CE Interface • Extranet with Internet-VRF
• Static default route to move • Besides VRF interface, a • Internet routes inside a
traffic from VRF to Internet global interface also connect dedicated VRF (e.g.
(global routing table) to each VPN site Internet-VRF)
• Static routes for VPN • May use eBGP on the global • Extranet between Internet-
customers to move traffic interface, if dynamic routing VRF and Customer VRFs
from Internet (global routing pr internet routes are that need internet access
table) to VRF needed
•
• Works well, but doesn’t • Works well and scales well,
scale well (limited to default despite the operational
routing) overhead
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
IP/VPN Deployment Scenarios: Internet Access Supported in IOS
P
PE1 [Link]
PE1#
ip vrf VPN-A Internet GW
rd 100:1
route-target both 100:1
Interface Serial0
ip address [Link] [Link] ▪ A default route, pointing to the
ip vrf forwarding VPN-A
ASBR, is installed into the site VRF
Router bgp 100 at each PE
no bgp default ipv4-unicast
redistribute static
neighbor [Link] remote 100 ▪ The static route, pointing to the
neighbor [Link] activate VRF interface, is installed in the
neighbor [Link] next-hop-self
neighbor [Link] update-source loopback0
global routing table and
redistributed into BGP
ip route vrf VPN-A [Link] [Link] [Link] global
ip route [Link] [Link] Serial0
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
IP/VPN Deployment Scenarios: Internet Access Supported in IOS,
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
IP/VPN Deployment Scenarios: Internet Access Supported in IOS,
NXOS and IOS-XR
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Supported in IOS,
NXOS and IOS-XR
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
IOS-XR 4.3.1
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary
4. Internet Access
Agenda 5. IP/VPN o IP • Best Practices
transport • Conclusion
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Supported in IOS,
NXOS and IOS-XR
[Link]
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Supported in IOS,
NXOS and IOS-XR
VRF
IP VRF
IP Header
GRE Header
VPN Label
Agenda
2. Hub and Spoke
3. Extranet
4. Internet Access
5. IP/VPN over IP Transport
6. Multi-VRF CE
BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Supported in IOS,
NXOS and IOS-XR
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
IP/VPN Deployment Scenarios:
Supported in IOS,
NXOS and IOS-XR
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 106