0% found this document useful (0 votes)
37 views101 pages

MPLS IP VPNs: Design & Best Practices

Uploaded by

anmq1991
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
37 views101 pages

MPLS IP VPNs: Design & Best Practices

Uploaded by

anmq1991
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

#CiscoLive

Designing IP VPNs
MPLS with/out Segment Routing

Rajiv Asati
CTO, VP/Cisco Fellow
BRKMPL-2102

#CiscoLive
Slido Poll
Abstract
• This session describes IP Virtual Private Networks (IP VPNs) overlays using MPLS data
plane. It is the most common Layer 3 VPN technology, as standardized by IETF
RFC2547/4364, enabling IPv6 (and/or IPv4) WAN connectivity among 2 or more sites,
endpoints, functions etc. over IP/MPLS network(s).
• SPs have been using IP VPN to provide scalable site-to-site/WAN connectivity to
Enterprises/Public Sector/SMBs for 2+ decades (and recently to create 5G slices), whereas
Enterprises/Public Sectors have been using it to address network segmentation
(virtualization and traffic separation) inside their sites e.g. Campus, Branch, Data Center,
Cloud. The session will cover:
• Technology & Config Overview
• Deployment Scenarios
• Use-Cases Summary
• Best Practices

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Prerequisites Reference

• Must understand basic IP routing, especially BGP

• Must understand MPLS basics (push, pop, swap,


label stacking)
• Should understand MPLS IP/VPN basics

• Must keep the speaker engaged…


• …by asking bad questions ☺

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Terminology Reference

• LSR: label switch router


• LSP: label switched path (The chain of labels that are swapped at each hop to get from one LSR to another)
• VRF: VPN routing and forwarding (Mechanism in Cisco IOS® used to build per-customer RIB and FIB)
• MP-BGP: multiprotocol BGP
• PE: provider edge router interfaces with CE routers
• P: provider (core) router, without knowledge of VPN
• VPNv4: address family used in BGP to carry IPv4 routes
• VPNv6: address family used in BGP to carry IPv6 routes
• RD: route distinguisher (Distinguish same network/mask prefix in different VRFs)
• RT: route target (Extended community attribute used to control import and export policies of VPN routes)
• FIB: forwarding information base (same as CEF - Cisco Express Forwarding)
• LFIB: label forwarding information base
• 6VPE: IPv6 VPN

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Cisco Webex App

Questions?
Use Cisco Webex App to chat
with the speaker after the session

How
1 Find this session in the Cisco Live Mobile App

2 Click “Join the Discussion”

3 Install the Webex App or go directly to the Webex space Enter your personal notes here

4 Enter messages/questions in the Webex space

Webex spaces will be moderated


by the speaker until June 9, 2023. [Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
• IP/VPN Overview
• Deployment Scenarios
• Use-Cases Summary
• Best Practices
Agenda • Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
• IP/VPN Overview
• Technology Overview
• Configuration Overview
(reference only)
• Deployment Scenarios
• Use-Cases
Agenda • Best Practices
• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
IP/VPN Technology Overview
• More than one routing and forwarding tables
• Control plane—VPN route propagation
• Data plane—VPN packet forwarding

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
IP/VPN Technology Overview
Network Topology / Connection Model

IP/MPLS Network

CE P P
CE
PE PE

P P
CE
CE

MP-iBGP Session

CE Routers PE Routers P Routers


▪ Sit at the Customer Edge ▪ Sit at the Provider Edge of IP/MPLS Network ▪ Sit inside the network
▪ Exchange IP traffic with PE ▪ Exchange IP traffic with CE routers* ▪ Exchange MPLS traffic - Forward
routers (and C routers)* ▪ Exchange MPLS traffic with P routers packets by looking
▪ Exchange IP routes with PE ▪ Distributes VPN routes using MP-BGP sessions at MPLS labels
routers using IP routing to other PE routers ▪ Share a common IGP with PE
protocol
* IP/MPLS traffic in case of Carrier Supporting Carrier (CsC), which is an advanced use-case, not covered here
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
IP/VPN Technology Overview
Separate Routing & Forwarding Tables at PE
CE2
VPN 2
PE
CE1 IP/MPLS Network IGP (OSPF, ISIS)
VPN 1

Customer Specific IP Routing Table Global MPLS Label Database


Global IP Routing Table
• Routing table (RIB) and forwarding table • Created by IP routing bestpaths
(FIB/CEF) dedicated to VPN customer • Created by IP routing bestpaths.
• Populated by either LDP or RSVP or
• VPN1 routing table • Populated by OSPF, ISIS, etc. running
• Routing Protocol (SR/IGP) inside the
VPN2 routing table inside the MPLS network
• Referred to as VRF table for <named VPN> MPLS network
IOS: “show ip route”
IOS: “show ip route vrf <name>” IOS-XR:“sh route ipv6 uni” IOS: “show mpls ldp”
IOS-XR:“sh route vrf <name> ipv6 NX-OS: “sh ip route” IOS-XR:“sh mpls ldp ”
NX-OS: “sh ip route vrf <name>” NX-OS: “sh mpls ldp”

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
IP/VPN Technology Overview
Virtual Routing and Forwarding (VRF) Instance
CE2
VPN 2 VRF Green
PE
CE1 MPLS Network IGP (OSPF, ISIS)
VPN 1 GE0/0
VRF Blue

• VRF = Representation of VPN customer inside the MPLS network


• Each customer VPN is associated with at least one VRF
• VRF configured on each PE and associated with PE-CE interface(s)
• Privatize an interface, i.e., coloring of the interface
• No changes needed at CE IOS_PE(conf)#ip vrf blue
IOS_PE(conf)#interface GE0/0
IOS_PE(conf)#ip vrf forwarding blue

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
IP/VPN Technology Overview
Virtual Routing and Forwarding Instance
EIGRP, eBGP, OSPF, RIPv2, Static Routing Advertisements
CE2
VPN 2 VRF Green
PE
CE1 MPLS Network IGP (OSPF, ISIS)
VPN 1
VRF Blue

• PE installs the VPN customer’ IP routes in VRF routing table(s)


• VPN routes are learned from CE routers or remote PE routers
• VRF-aware routing protocol (static, RIP, BGP, EIGRP, OSPF) on each PE
• PE installs the internal routes (IGP) in global routing table

• VPN customers can use overlapping IP addresses


• BGP plays a key role. Let’s understand few BGP specific details..…

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
IP/VPN Technology Overview
VPN Control Plane
MP-iBGP Session
PE

PE
MPLS Network
PE

• PE routers exchange VPN routes with other PE routers using BGP


• Multi-Protocol BGP aka MP-BGP
• PE routers advertise the IP routes to their CE routers

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
IP/VPN Technology Overview
VPN Control Plane = Multi-Protocol BGP (MP-BGP)
8 Bytes 4 Bytes 8 Bytes 3 Bytes
(16 Bytes) MP-BGP UPDATE Message
1:1
Showing VPN route, RT,
RD IPv4 (or IPv6) Route-Target Label
VPN Label only

MP-BGP on PE Customizes the VPN Customer Routing Information as per the Locally
Configured VRF Information using:
• Route Distinguisher (RD)
• Route Target (RT)
• Label (not configured)

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
IP/VPN Technology Overview: Control Plane Reference

MP-BGP UPDATE Message Capture Reference

• Visualize how the BGP UPDATE


message carrying VPNv4 routes
looks like.
• Notice the Path Attributes.

Route Target = 3:3

VPNv4 Prefix 1:1:[Link]/30


; Label = 23

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
IP/VPN Technology Overview: Control Plane
Route-Distinguisher (rd): 8-byte field
8 Bytes 4 Bytes 8 Bytes 3 Bytes 8 Bytes 16 Bytes 8 Bytes 3 Bytes

1:1 [Link] 1:1 2001:DB8::


RD IPv4 Route-Target Label RD IPv6 Route-Target Label
VPNv4 VPNv6
MP_REACH_NLRI (VPNv4) MP_REACH_NLRI (VPNv6)

• VPN customer IP prefix is converted into a VPN prefix by appending the RD (3:1, say)
to make the customer’s IP prefixes unique inside the shared IP/MPLS network
• [Link] => 1:1:[Link] ; 2001:DB8:: => 1:1:2001:DB8::
• Route Distinguisher (rd) is mapped to a VRF at PE IOS_PE#
!
ip vrf green
• RD is not a BGP attribute, just a field in another attribute (MP_REACH_NLRI) rd 1:1
!

• RD format is X:Y
* Since 12.4(3)T, 12.4(3) 12.2(32)S, 12.0(32)S etc., RD Configuration
within VRF Has Become Optional. Prior to That, It Was Mandatory.
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
IP/VPN Technology Overview: Control Plane
Route-Target (rt): 8-byte extended community attribute
8 Bytes 4 Bytes 8 Bytes 3 Bytes 8 Bytes 16 Bytes 8 Bytes 3 Bytes

1:1 [Link] 3:3 1:1 2001:DB8:: 1:5


RD IPv4 Route-Target Label RD IPv6 Route-Target Label

• Route-target (rt) helps PEs color the VPN prefixes


• Export rt values : attached to VPN routes by PEs in MP-iBGP advertisements
• Import rt values : used by PEs to identify which VRF(s) keep the received VPN prefixes
IOS_PE#
• Each VRF should be configured with 1 or more route-targets at PE !
ip vrf green
• Export & Import rt must be the same for Any-to-Any topology address-family ipv4
route-target import 3:3
• Export & Import rt must be different for Hub & Spoke topology !
route-target export 3:3

address-family ipv6
• IPv4 and IPv6 address-family RT values are allowed to be different (as shown) route-target import 1:1
route-target export 1:5
!

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
IP/VPN Technology Overview: Control Plane
Label : 20-bit value
8 Bytes 4 Bytes 8 Bytes 3 Bytes 8 Bytes 16 Bytes 8 Bytes 3 Bytes

1:1 [Link] 3:3 23 1:1 2001:DB8:: 1:5 115


RD IPv4 Route-Target Label RD IPv6 Route-Target Label

• PE auto-generates & assigns a label for each VPN prefix(es);


• Next-hop-self towards MP-iBGP neighbors by default i.e. PE sets the NEXT-HOP attribute to
its own address (as configured)
• Label is not an attribute.
• PE addresses used as the BGP next-hops must be uniquely known in IGP
• CAUTION - Do not summarize the PE loopback addresses in the core

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
IP/VPN Technology Overview: Control Plane
Putting it all together
MP-iBGP Update:
1:1:2001:DB8::
Site 1 3 Next-Hop=PE-1 Site 2
RT=1:5, Label=115
2001:DB8:: CE1
2 P P
CE2
2001:DB8::
Next-Hop=CE-1
P P
1 PE1 PE2

MPLS Backbone

1.1 PE1 receives an IPv6 (or IPv4) update (eBGP/OSPF/ISIS/RIP/EIGRP)

2.2 PE1 translates it into VPNv6(v4) address & sends MP-iBGP UPDATE message
• Associates the RT values (export RT =1:5, say) per VRF green configuration
• Rewrites next-hop attribute to its IP address (usually loopback0 int)
• Assigns a label (115, say); Installs it in the MPLS forwarding table.

3.3 PE1 sends MP-iBGP update to other PE routers

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
IP/VPN Technology Overview: Control Plane
Putting it all together
MP-iBGP Update:
1:1:2001:DB8:: 2001:DB8::

Site 1 3 Next-Hop=PE-1 Next-Hop=PE-2 Site 2


RT=1:5, Label=100
2001:DB8:: CE1 5
2 P P 4
CE2
2001:DB8::
Next-Hop=CE-1
P P
1 PE1 PE2

MPLS Backbone

4 PE2 receives and checks whether the RT=1:5 is locally configured as ‘import RT’
4.
within any VRF, if yes, then
• PE2 translates VPN prefix back to IP prefix
• PE2 updates its VRF CEF Table (green) with IP prefix - 2001:DB8:: along with label=115

5 PE2 advertises this IP prefix to CE2 (using whatever routing protocol)


5.

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
IP/VPN Technology Overview
Forwarding Plane
VPN Site 2
VPN Site 1
CE1
MPLS Forwarding Table
[Link]/24 MPLS Backbone
P P
• StoresCE2
labels for PE/P routes i.e. next-hops
• Label learned SR/IGP or LDP, RSVP or BGP
P P
PE1 PE2
IOS:show mpls forwarding
NX-OS: show mpls forwarding
IOS-XR: show mpls forwarding

Customer/VPN Forwarding Table Global CEF Forwarding Table


• Stores VPN routes with associated labels • Stores PE routes i.e. next-hops with labels
• VPN routes learned via BGP • Next-hop i.e. PE routes learned via IGP
• Labels learned via BGP • Label learned SR/IGP or LDP, RSVP or BGP

IOS:show ip cef vrf <name> IOS:show ip cef


NX-OS: show forwarding vrf <name> NX-OS: show forwarding ipv6|ipv4
IOS-XR: show cef vrf <name> ipv6|ipv4 IOS-XR: show cef ipv6|ip4

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
IP/VPN Technology Overview: Forwarding Plane
Packet Forwarding
Site 1 Site 2
CE1
[Link]/24 CE2
P3 P4
PE1 PE2
[Link] [Link] IP Packet
23 [Link] P1 P2
IP Packet

50 23 [Link] 100 23 [Link] MPLS Packet

• PE2 imposes two labels (in 2 MPLS headers) for each IP packet going towards remote site
• Outer label 100 for PE1 address (learned via SR/IGP or LDP or RSVP or static..)
• Inner label 23 for VPN address (learned via BGP)
• P2 swaps the outer label (100 with 50) per its MPLS forwarding table
• P1 does the Penultimate Hop Popping (PHP) i.e. removes the outer label 50
• PE1 removes label 23, retrieves IP packet and forwards it to CE1.
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
IP/VPN Technology Overview: Forwarding Plane
Reference

MPLS IP/VPN Packet Capture


Reference

• Visualize an MPLS VPN Packet


on the wire (PE-P or P-P)
• 2 MPLS headers

Ethernet Header
Outer MPLS header

Inner MPLS Header


Note: The MPLS values & IP
addresses to not refer to the
IP Header
previous examples, sorry. 

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
• IP/VPN Overview
• Technology Overview
• Configuration Overview
(reference only)
• Deployment Scenarios
• Best Practices
Agenda • Use-Cases
• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
MPLS based IP/VPN Sample Configuration (IOS)
Reference

VRF Definition vrf definition VPN-A


!
ip vrf VPN-A
rd 1:1 rd 1:1
Site 1
address-family ipv4 route-target export 100:1
CE1 route-target export 100:1
[Link]/24 route-target import 100:1
PE1 route-target import 100:1 !
address-family ipv6
PE1 route-target export 100:1
Se0 route-target import 100:1
IPv4 VPN only config

Both IPv6 VPN


VRF to Interface Association And IPv4 VPN

Site 1 interface Serial0


CE1 ip address [Link]/24
[Link]/24
PE1 ipv6 address 2001:DB8::1/124
ip vrf forwarding VPN-A
PE1
Se0
[Link]
2001:DB8::1

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
MPLS based IP/VPN Sample Configuration (IOS)
Reference

router bgp 1
PE: MP-IBGP Config neighbor [Link] remote-as 1
neighbor [Link] update-source loopback0
!
R address-family vpnv4
R neighbor [Link] activate
PE1 PE2 PE neighbor [Link] send-community both
1 !
address-family vpnv6
neighbor [Link] activate

!
neighbor [Link] send-community both Config Shows
Both IPv6 VPN
And IPv4 VPN
RR: MP-IBGP Config router bgp 1
no bgp default route-target filter
neighbor [Link] remote-as 1
R neighbor [Link] update-source loopback0
R RR !
PE1 PE2 address-family vpnv4 | vpnv6
neighbor [Link] route-reflector- client
neighbor [Link] activate
!

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
MPLS based IP/VPN Sample Configuration (IOS)
Reference

PE-CE Routing: BGP


Site 1 router bgp 1 router bgp 1
CE1 ! !
[Link]/24 address-family ipv4 vrf VPN-A address-family ipv6 vrf VPN-A
PE1 neighbor [Link] remote-as 2 neighbor [Link] remote-as 2
[Link] PE1 neighbor [Link] activate neighbor [Link] activate
2001:DB8::2 ! !
[Link]
2001:DB8::1

PE-CE Routing: OSPF router ospf 2 unicast vrf VPN-A router ospfv3
network [Link] [Link] area 0 !
redistribute bgp 1 subnets address-family unicast vrf VPN-A
Site 1
CE1 ! router-id 2001:DB8::2
redistribute bgp 1 subnets
[Link]/24 PE1
!
interface Serial0
[Link] PE1 ospfv3 2 ipv6 area 0
2001:DB8::2
redistribute bgp 1 subnets
[Link] !
2001:DB8::1

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
MPLS based IP/VPN Sample Configuration (IOS)
Reference

PE-CE Routing: RIP router rip ipv6 rip vrf-mode enable


! !
Site 1 address-family ipv4 vrf VPN-A ipv6 router rip XYZ
CE1
version 2 redistribute bgp 1
[Link]/24 PE1 no auto-summary !
network [Link] interface Serial0/0
[Link] PE1 redistribute bgp 1 metric transparent ipv6 vrf VPN-A XYZ enable
! !
[Link]

PE-CE Routing: EIGRP router eigrp 1


!
address-family ipv4 vrf VPN-A router eigrp XYZ
Site 1 address-family ipv6 vrf VPN-A
CE1 no auto-summary
PE1 network [Link] [Link] autonomous-system 1
[Link]/24
autonomous-system 10 af-interface Serial0/0
redistribute bgp 1 metric 100000 100 !
[Link] PE1 255 1 1500
[Link] !
2001:DB8::1

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
MPLS based IP/VPN Sample Configuration (IOS)
Reference

PE-CE Routing: Static


Site 1
CE1 ip route vrf VPN-A [Link] [Link] [Link]
[Link]/24
PE1
2001:DB8:100:: ipv6 route vrf VPN-A 2001:DB8:100::/48 2001:DB8::2
[Link] PE1
2001:DB8::2
[Link]
2001:DB8::1

If PE-CE Protocol Is Non-BGP (Such as RIP), then Redistribution of


VPN Routes from MP-IBGP Is Required (Shown Below for RIP) -

PE-CE: MB-iBGP Routes to VPN


router rip
Site 1 address-family ipv4 vrf VPN-A
R version 2
R redistribute bgp 1 metric transparent
PE1 PE1 no auto-summary
network [Link]
CE1
exit-address-family

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
MPLS based IP/VPN Sample Configuration (IOS)
Reference

If PE-CE Protocol Is Non-BGP, then Redistribution of Local


VPN Routes into MP-IBGP Is Required (Shown Below)

PE-CE (Route Distribution)


Site 1 router bgp 1
RR neighbor [Link] remote-as 1
neighbor [Link] update-source loopback 0
PE1
PE1 address-family ipv4|ipv6 vrf VPN-A
CE1 redistribute {rip|connected|static|eigrp|ospf}

• For hands-on learning, please attend the lab sessions:


• LTRMPL-2104 Implementing MPLS in SP Networks (Intro Level)
• LTRMPL-2105 Implementing MPLS in SP Networks (Advanced Level)
• Having familiarized with IOS based config, let’s peek through IOS-XR and NX-OS
config for VPNs
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
MPLS based IP/VPN Sample Config (IOS-XR)
Reference

vrf VPN-A vrf VPN-A


VRF Definition address-family ipv4 unicast address-family ipv6 unicast
import route-target 100:1 import route-target 100:1
Site 1 export route-target 100:1 export route-target 100:1
CE1 ! !
[Link]/24 router bgp 1 router bgp 1
PE vrf VPN-A vrf VPN-A
GE0 PE1 1 rd 1:1 rd 1:1
Interface GE0
[Link] ipv4 address [Link] [Link]
vrf VPN-A

PE-P Configuration
mpls ip
int GE1
P !
PE1 GE1 PE
GE
1 router ospf 1
0
area 0
interface GE1

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
MPLS based IP/VPN Sample Config (IOS-XR)
Reference

PE: MP-IBGP Config router bgp 1


router-id [Link]
address-family vpnv4 unicast
R !
R neighbor [Link]
PE1 PE2 PE remote-as 1
1 update-source loopback0
address-family vpnv4 unicast
send-community extended
!

router bgp 1
RR: MP-IBGP Config router-id [Link]
address-family vpnv4 unicast
!
R neighbor [Link]
R remote-as 1
RR update-source loopback0
PE1 PE2
address-family vpnv4 unicast
send-community extended
route-reflector-client
!

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
MPLS based IP/VPN Sample Config (IOS-XR)
Reference

router bgp 1
PE-CE Routing: BGP !
vrf VPN-A
Site 1 neighbor [Link]
CE1 remote-as 2
[Link]/24 PE1 address-family ipv4 unicast
route-policy pass-all in|out
[Link] GE0 PE1 !
!
[Link] !
!

PE-CE Routing: OSPF


router ospf 2
vrf VPN-A
Site 1 address-family ipv4 unicast
CE1
redistribute bgp 1
[Link]/24 PE1 !
GE0 PE1 area 0
[Link] interface GE0
!
[Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
MPLS based IP/VPN Sample Config (IOS-XR)
Reference

PE-CE Routing: RIP


router rip
Site 1
CE1 vrf VPN-A
interface GE0
[Link]/24 PE1 redistribute bgp 1
GE0 PE1 !
[Link]

[Link]

PE-CE Routing: EIGRP


router eigrp 1
vrf VPN-A
Site 1 address-family ipv4
CE1
PE1 as 10
[Link]/24 default-metric 100000 100 255 1 1500
GE0 PE1 interface GE0
[Link] redistribute bgp 1
[Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
MPLS based IP/VPN Sample Config (IOS-XR)
Reference

PE-CE Routing: Static


Site 1 router static
CE1 vrf VPN-A
[Link]/24 PE1 address-family ipv4 unicast
ip route [Link]/8 [Link]
[Link] GE0 PE1

[Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
MPLS based IP/VPN Sample Config (IOS-XR)
Reference

If PE-CE Protocol Is Non-BGP, then Redistribution of Local VPN Routes into MP-IBGP Is
Required (Shown Below)

PE-PE (Route Distribution)


Site 1
R router bgp 1
R vrf VPN-A
PE1 address-family ipv4 unicast
PE1 redistribute {rip|connected|static|eigrp|ospf}
CE1

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
MPLS based IP/VPN Sample Config (NX-OS)
Reference

Reference

VRF Definition vrf context VPN-A vrf context VPN-A


rd 1:1 rd 1:1
Site 1 address-family ipv4 unicast address-family ipv6 unicast
CE1 route-target import 1:1 route-target import 1:1
[Link]/24 route-target export 1:1 route-target export 1:1
PE
GE 1
PE1 Interface GE0
0 ip address [Link] [Link]
[Link] vrf member VPN-A

PE-P Configuration Interface GE1


ip address [Link] [Link]
mpls ip
P ip ospf 1 area 0
PE1 GE1 PE
GE
1
0 router ospf 1

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
MPLS based IP/VPN Sample Config (NX-OS)
Reference

PE: MP-IBGP Config


router bgp 1
R router-id [Link]
neighbor [Link] remote-as 1
R update-source loopback0
PE1 PE2 PE address-family vpnv4 unicast
1 send-community extended
!

RR: MP-IBGP Config router bgp 1


router-id [Link]
R neighbor [Link] remote-as 1
R update-source loopback0
RR address-family vpnv4 unicast
PE1 PE2 send-community extended
route-reflector-client
!

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
MPLS based IP/VPN Sample Config (NX-OS)
Reference

PE-CE Routing: BGP


Site 1 router bgp 1
CE1 !
[Link]/24 vrf VPN-A
PE1 neighbor [Link] remote-as 2
GE0 PE1 address-family ipv4 unicast
[Link]
!
[Link]

PE-CE Routing: OSPF router ospf 2


vrf VPN-A
Site 1 address-family ipv4 unicast
CE1 redistribute bgp 1 route-map name
[Link]/24 PE1 !
interface GE1
GE0 PE1 ip address [Link]/24
[Link]
ip router ospf 2 area 0
[Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
MPLS based IP/VPN Sample Config (NX-OS)
Reference

PE-CE Routing: RIP router rip ripxyz1


vrf VPN-A
Site 1 address-family ipv4 unicast
CE1 redistribute bgp 1 route-map name
[Link]/24 PE1 !
interface GE0
[Link] GE0 PE1 vrf member vpn1
ip router rip ripxyz1
[Link]

PE-CE Routing: EIGRP router eigrp 100


vrf VPN-A
address-family ipv4
Site 1 redistribute bgp 1 route-map name
CE1
PE1 !
[Link]/24 interface GE0
GE0 PE1 vrf member vpn1
[Link] ip router eigrp 100
site-of-origin 1:11
[Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
MPLS based IP/VPN Sample Config (NX-OS)
Reference

PE-CE Routing: Static


Site 1
CE1 vrf context VPN-A
[Link]/24 PE1 ip route [Link]/8 [Link]

[Link] GE0 PE1

[Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
MPLS based IP/VPN Sample Config (NX-OS)
Reference

If PE-CE Protocol Is Non-BGP, then Redistribution of Local


VPN Routes into MP-IBGP Is Required (Shown Below)

PE-RR (VPN Routes to VPNv4)


Site 1
R router bgp 1
R vrf VPN-A
PE1 address-family ipv4 unicast
PE1 redistribute {rip|direct|static|eigrp|ospf} route-map name
CE1

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub and Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary

Agenda • Best Practices


• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
IP/VPN Deployment Scenarios:
1. Multi-homing & Loadsharing of VPN Traffic
RR
PE11
CE1 PE2 CE2
[Link]/24

PE12
Site A Site B
MPLS Backbone

Route Advertisement

• VPN sites (such as Site A) could be multihomed

• VPN sites need the traffic to (the site A) be loadshared

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
IP/VPN Deployment Scenarios:
1. Multi-homing & Loadsharing of VPN Traffic
Vrf <name> 2 <BGP>
1 RR
rd 300:11 address-family ipv4 vrf green
route-target both 1:1 PE11 maximum-paths eibgp 2
CE1 PE2 CE2
[Link]/24

PE12
Site A Site B
1 MPLS Backbone
Vrf <name>
Vrf <name>
rd 300:12
rd 300:13
route-target both 1:1
route-target both 1:1

• Configure unique RD per VRF per PE for multi-homed site/interfaces

• Enable eiBGP multipath within the relevant BGP VRF address-family at remote PE
routers such as PE2 (why PE2?).

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Supported in IOS,
and IOS-XR

IP/VPN Deployment Scenarios:


1. VPN Fast Convergence—PE-CE Link Failure

Traffic Is RR
Dropped VPN Traffic
by PE11 PE11 Redirected VPN Traffic

CE1 PE2 CE2


[Link]/24
PE12
Site A MPLS Backbone Site B

• What if PE11-CE link fails?


• Need to wait for BGP convergence (~seconds)

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
IP/VPN Deployment Scenarios:
Supported in IOS,
and IOS-XR 3.4

1. VPN Fast Convergence—PE-CE Link Failure – PIC Edge Feature

Traffic Is RR VPN Traffic


Redirected Redirected VPN Traffic
by PE11 PE11

CE1 PE2 CE2


[Link]/24

Site A MPLS Backbone Site B


PE12

• BGP PIC Edge feature provides fast convergence (~msec) .


• PE11 temporarily redirects the CE1 bound traffic to PE12 until BGP has converged

• BGP PIC Edge is independent of whether multipath is enabled on PE2 or not

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary

Agenda • Best Practices


• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
IP/VPN Deployment Scenarios:
2. Hub and Spoke Service

• Many VPN deployments require hub and spoke topology


• Spoke to spoke communication via Hub site only
• Example: ATM Machines to HQ, Router Management traffic to NMS/DC
• Despite MPLS based IP/VPN’s implicit any-to-any, i.e. full-mesh
connectivity, hub and spoke service can easily be offered
• Uses different import and export of route-target (RT) values
• Requires unique RD per VRF per PE
• Independent of PE-CE routing protocol per site

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
IP/VPN Deployment Scenarios:
2. Hub and Spoke Service

• Two configuration Options :


1. 1 PE-CE interface to Hub & 1 VRF;
2. 2 PE-CE interfaces to Hub & 2 VRFs;

• Use option#1 if VPN Hub site advertises default or summary routes


towards the Spoke sites, otherwise use Option#2

* HDVRF Feature Is Discussed Later


#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


Import and Export RT
2. Hub and Spoke Service: IOS Configuration – Option#1 Values Must Be Different
<VRF GREEN for Spoke A>
rd 300:111
<VRF GREEN for HUB>
route-target export 1:1
rd 300:11
route-target import 2:2
route-target export 2:2
Spoke A route-target import 1:1
CE-SA PE-SA
[Link]/24

PE-Hub
Eth0/0

Spoke B PE-SB
CE-SB CE-Hub
MPLS VPN Backbone
[Link]/24

<VRF GREEN for SPOKE B>


rd 300:112
route-target export 1:1
route-target import 2:2

Note: Only RD and RT Configuration Shown Here

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


Import and Export RT
2. Hub and Spoke Service: IOS Configuration – Option#2 Values Must Be Different
<VRF GREEN for Spoke A>
rd 300:111
route-target export 1:1
route-target import 2:2 <VRF IN for Hub>
rd 300:11
Spoke A CE-SA PE-SA route-target import 1:1
[Link]/24

Eth0/0.1
PE-Hub Eth0/0.2
Spoke B PE-SB
CE-SB CE-Hub
MPLS VPN Backbone
[Link]/24
<VRF IN for Hub>
rd 300:12
<VRF GREEN for Spoke B> route-target export 2:2
rd 300:112
route-target export 1:1
route-target import 2:2

Note: Only RD and RT Configuration Shown Here


#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


2. Hub and Spoke Service: Configuration – Option#2

• If BGP is used between every PE and CE, then allowas-in and as-override*
knobs must be used at the PE_Hub**
• Otherwise AS_PATH looping will occur

* Only If Hub and Spoke Sites Use the Same BGP ASN
** Configuration for This Is Shown on the Next Slide
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


2. Hub and Spoke Service: Configuration – Option#2
<BGP>
address-family ipv4 vrf HUB-IN
neighbor <CE> as-override

Spoke A

CE-SA PE-SA
[Link]/24

Eth0/0.1
Spoke B PE-Hub Eth0/0.2
PE-SB
CE-SB CE-Hub
MPLS VPN Backbone
[Link]/24

<BGP>
address-family ipv4 vrf HUB-OUT
neighbor <CE> allowas-in 2

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


2. Hub and Spoke Service: Control Plane (Option#2)
VRF FIB and LFIB
Destination NextHop Label MPLS Backbone
[Link]/16 PE-Hub 35 FIB—IP Forwarding Table
[Link]/24 CE-SA LFIB—MPLS Forwarding Table

Spoke A MP-iBGP Update


1:2:[Link]/24 VRF HUB-IN FIB and LFIB
[Link]/24 CE-SA PE-SA Label 40 Destination NextHop Label
Route-Target 1:1 [Link]/24 PE-SA 40
[Link]/24 PE-SB 50

MP-iBGP Update
VRF FIB and LFIB
1:1:[Link]/16
VRF HUB-IN
[Link]/16 PE-Hub 35
Label 35
[Link]/24 CE-SB PE-Hub VRF HUB-OUT
PE-SB Route-Target 2:2

Spoke B VRF HUB-OUT FIB


Destination NextHop
CE-Hub
MP-iBGP Update
[Link]/24 1:3:[Link]/24 [Link]/16 CE-H1
CE-SB Label 50
Route-Target 1:1

• Two VRFs at the PE-Hub:


• VRF HUB-IN to learn every spoke routes from remote PEs
• VRF HUB-OUT to advertise spoke routes or summary [Link]/16 routes to remote PEs

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


2. Hub and Spoke Service: Forwarding Plane (Option#2)

[Link] MPLS Backbone


Spoke A
PE-SA
CE-SA L2 40 [Link]
[Link]/24 [Link]

VRF HUB-IN
CE-Hub
Spoke B PE-Hub
VRF HUB-OUT
CE-SB PE-SB L1 35 [Link]
[Link]
[Link]/24

[Link]

L1 Is the Label to Get to PE-Hub


L2 Is the Label to Get to PE-SA
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Supported in IOS
and IOS-XR 3.6
IP/VPN Deployment Scenarios:
2. What If Many Spoke Sites Connect to the Same PE Router?

• If more than one spoke router (CE) connects to the same PE router (within
the same VRF), then such spokes can reach other without needing the hub.
• Defeats the purpose of hub and spoke  CE-SA1 PE-Hub

CE-SA2 PE-SA

• Half-duplex VRF is the answer CE-SA3


• Uses two VRFs on the PE (spoke) router :
• A VRF for spoke->hub communication (e.g. upstream)
• A VRF for spoke<-hub communication (e.g. downstream)

Note: 12.2(33) SRE. XE 3.0S Support Any Interface Type (Eth, Ser, POS, Virtual-Access, etc.)

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Supported in IOS

IP/VPN Deployment Scenarios:


2. Hub and Spoke Service: Half-Duplex VRF
ip vrf green-up ip vrf green-down
description – For upstream traffic (to Hub) description - For downstream traffic (from Hub)
rd 300:111 rd 300:112
route-target import 2:2 route-target export 1:1 ip vrf HUB-IN
description VRF for traffic from HUB
Spoke A rd 300:11
route-target import 1:1
CE-SAGE0/0
[Link]/24 Hub Site
GE0/1 MPLS Backbone
PE-SA

PE-Hub
Spoke B CE-Hub
Interface GigEthernet 0/0 - 1 ip vrf HUB-OUT
[Link]/24 ip address 172.18.13.x [Link] description VRF for traffic to HUB
ip vrf forward green-up downstream green-down rd 300:12
CE-SB .. route-target export 2:2

Upstream VRF Downstream VRF

1. PE-SA installs the Spoke routes only in downstream VRF i.e. green-down
2. PE-SA installs the Hub routes only in upstream VRF i.e. green-up
3. PE-SA forwards the incoming IP traffic (from Spokes) using upstream VRF i.e. green-up routing table.
4. PE-SA forwards the incoming MPLS traffic (from Hub) using downstream VRF i.e. green-down routing table
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary

Agenda • Best Practices


• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
IP/VPN Deployment Scenarios
3. Extranet VPN

• MPLS based IP/VPN, by default, isolates one VPN customer from another
• Separate virtual routing table for each VPN customer
• Communication between VPNs may be required i.e. extranet
• External intercompany communication (dealers with manufacturer, retailer with
wholesale provider, etc.)
• Management VPN, shared-service VPN, etc.
• Implemented by sharing import and export route-target (RT) values within
the VRFs of extranets.
• Export-map or import-map may be used for advanced extranet.

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
IP/VPN Deployment Scenarios Supported in IOS,
NXOS and IOS-XR
3. Extranet VPN – Simple Extranet (IOS Config sample)

[Link]/16
MPLS Backbone
VPN_A Site#2
VPN_A Site#1
[Link]/16 PE1 PE2
P [Link]/16
VPN_B Site#1

<VRF for VPN_A> <VRF for VPN_B>


route-target import 3000:111 route-target import 3000:222
route-target export 3000:111 route-target export 3000:222
route-target import 3000:222 route-target import 3000:111

All Sites of Both VPN_A and VPN_B Can Communicate


with Each Other
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
IP/VPN Deployment Scenarios Supported in IOS,
NXOS and IOS-XR
3. Extranet VPN – Advanced Extranet (IOS Config sample)

[Link]/16
MPLS Backbone
VPN_A Site#2
VPN_A Site#1
[Link]/16 PE1 PE2
P
[Link]/16
VPN_B Site#1

<VRF for VPN_A> <VRF for VPN_B>


route-target import 3000:111 route-target import 3000:222
route-target export 3000:111 route-target export 3000:222
route-target import 3000:1 route-target import 3000:2
import map VPN_A_Import import map VPN_B_Import
export map VPN_A_Export export map VPN_B_Export
! !
route-map VPN_A_Export permit 10 route-map VPN_B_Export permit 10
match ip address 1 match ip address 2
set extcommunity rt 3000:2 additive set extcommunity rt 3000:1 additive Lack of ‘Additive’
! ! Would Result in
route-map VPN_A_Import permit 10 route-map VPN_B_Import permit 10 3000:222 Being
match ip address 2 match ip address 1 Replaced with 3000:1.
! ! We Don’t Want That.
access-list 1 permit [Link] [Link] access-list 1 permit [Link] [Link]
access-list 2 permit [Link] [Link] access-list 2 permit [Link] [Link]

Only Site #1 of Both VPN_A and VPN_B Would Communicate


with Each Other
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
• IP/VPN Overview
• Deployment Scenarios
• Use-Cases Summary

Agenda • Best Practices


• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Use-Cases
1. SP – Business VPN Service, Mobile Backhaul
2. SP – Internal Usage (e.g. IT), Mobile Backhaul
3. Enterprise – Campus Virtualization/Segmentation
4. Data Center – Multi-Tenancy
5. Data Center – Cloud/Virtualization/Hypervisor

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Use-Case #1
SP – Business VPN Services, Mobile Backhaul
• SPs can use IP/VPN to offer L3 site-to-site connectivity to
Enterprises/SMB customers’
• SPs can even offer Remote Access integrated with L3VPN

Enterprise Green
Site 1 Enterprise Green
CE1 Site 2
P P
CE2
Enterprise Green Enterprise Green
Site 3 P P Site 4
PE1 PE2
CE4

SP Network

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Use-Case #2
SP – Internal Usage (e.g. IT, Mobile Backhaul)
• SP/ISPs can overlay its Enterprise and/or IT WAN connectivity over
its MPLS network (that is used to offer L3VPN services to its
customers) SP IT
SP IT
Site 1
Site 2

Enterprise Green PE4 PE5


Site 1 Enterprise Green
CE1 Site 2
P P
CE2
Enterprise Green Enterprise Green
Site 3 P P Site 4
PE1 PE2
CE4

SP Network
SP IT
Site 3

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Use-Case#3
Enterprise – Campus Segmentation/Virtualization

• IP/VPN can be used to create multiple logical topologies in the Campus


• Allows the use of unique security policies per logical domain
• Provides traffic isolation per application, group, service etc. per logical domain
• IP/VPN segmentation in the Campus can also be extended over the WAN

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Eliminates the need for VXLAN
Use-Case#4
Data Center – Multi-Tenancy Campus/ Global
• IP/VPN can be used by “ Cloud or Internet WAN Edge Interconn
ect

Hosted DC” providers for multi-


tenancy

MPLS
• Data Center services to B2B customers
• MPLS upto TOR/Leaf;
• Segment Routing could be used
PE

Layer-2
• MPLS PE function on TOR / Leaf
Device CE
• CE function on VMs or Bare Metal POD POD POD

• Layer2 between PE and CE

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Eliminates the need for VXLAN
Use-Case#5
Data Center – Cloud / Virtualization Campus/ Global
• MPLS in Data Center (Underlay) Internet WAN Edge Interconn
ect

• MPLS based IP/VPN as Overlay


MPLS upto x86 Host;

MPLS

• Segment Routing could be used

• MPLS PE function on virtual Router (VM) or


Virtual Forwarder (VM or Container)
• SDN Control Plane and Data Plane Separation
in case of latter PE
• CE function on VMs or Bare Metal
CE
POD POD POD
• Layer2 between PE and CE

Please see BRKMPL-2115 for MPLS in DC/Cloud Details


#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
• IP/VPN Overview
• Deployment Scenarios
• Use-Cases

Agenda • Best Practices


• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Best Practices (1)
1. Use RR to scale BGP; deploy RRs in pair for the redundancy
Keep RRs out of the forwarding paths and disable CEF (saves memory)
2. Choose AS format for RT and RD i.e., ASN: X
Reserve first few 100s of X for the internal purposes such as filtering
3. Consider unique RD per VRF per PE,
Helpful for many scenarios such as multi-homing, hub&spoke etc.
Helpful to avoid add-path, shadow RR etc.
4. Don’t use customer names (V458:GodFatherNYC32ndSt) as the VRF names; nightmare
for the NOC.
Consider v101, v102, v201, v202, etc. and Use VRF description for naming
5. Utilize SP’s public address space for PE-CE IP addressing
Helps to avoid overlapping; Use /31 subnetting on PE-CE interfaces

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Best Practices (2)
6. Limit number of prefixes per-VRF and/or per-neighbor on PE
Max-prefix within VRF configuration; Suppress the inactive routes
Max-prefix per neighbor (PE-CE) within OSPF/RIP/BGP VRF af
7. Leverage BGP Prefix Independent Convergence (PIC) for fast convergence <100ms (IPv6
and IPv4):
• PIC Core, PIC Edge
• Best-external advertisement
• Next-hop tracking (ON by default)
8. Consider RT-constraint for PE & RR scalability (millions of routes)
9. Consider ‘BGP slow peer’ for PE or RR – faster BGP convergence
10. Use a dedicated VPN for CE Management

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
• IP/VPN Overview
• Deployment Scenarios
• Use-Cases Summary

Agenda • Best Practices


• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Conclusion
• IP/VPN is the most optimal L3VPN technology
• Any-to-any, Partial-mesh, Hub-and-Spoke topologies
• IPv6 or IPv4 or both

• Various IP/VPN deployment scenarios for additional value/revenue

• IP/VPN paves the way for virtualization & Cloud Services


• Benefits SPs, Enterprises, Data Centers

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Fill out your session surveys!

Attendees who fill out a minimum of four session


surveys and the overall event survey will get
Cisco Live-branded socks (while supplies last)!

Attendees will also earn 100 points in the


Cisco Live Challenge for every survey completed.

These points help you get on the leaderboard and increase your chances of winning daily and grand prizes

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
• Visit the Cisco Showcase
for related demos

• Book your one-on-one


Meet the Engineer meeting

• Attend the interactive education


with DevNet, Capture the Flag,
Continue and Walk-in Labs

your education • Visit the On-Demand Library


for more sessions at
[Link]/on-demand

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Thank you

#CiscoLive
Gamify your Cisco Live experience!
Get points for attending this session!

How:
1 Open the Cisco Events App.

2 Click on 'Cisco Live Challenge’ in the side menu.

3 Click on View Your Badges at the top.

4 Click the + at the bottom of the screen and scan the QR code:

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
#CiscoLive
Supplemental Material

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary
4. Internet Access
Agenda • Best Practices
• Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
IP/VPN Deployment Scenarios
4. Internet Access Service to VPN Customers

• Internet access service could be provided as another value-added


service to VPN customers
• Security mechanism must be in place at both provider network and
customer network
• To protect from the Internet vulnerabilities
• VPN customers benefit from the single point of contact for both
Intranet and Internet connectivity

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
IP/VPN Deployment Scenarios
4. Internet Access: Design Options

Three Options to Provide the Internet Service -

1. VRF specific default route with “global” keyword


2. Separate PE-CE sub-interface (non-VRF)
3. Extranet with Internet-VRF

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
IP/VPN Deployment Scenarios
4. Internet Access: Design Options
• VRF specific default route • Separate PE-CE Interface • Extranet with Internet-VRF
• Static default route to move • Besides VRF interface, a • Internet routes inside a
traffic from VRF to Internet global interface also connect dedicated VRF (e.g.
(global routing table) to each VPN site Internet-VRF)
• Static routes for VPN • May use eBGP on the global • Extranet between Internet-
customers to move traffic interface, if dynamic routing VRF and Customer VRFs
from Internet (global routing pr internet routes are that need internet access
table) to VRF needed

• Works well, but doesn’t • Works well and scales well,
scale well (limited to default despite the operational
routing) overhead

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
IP/VPN Deployment Scenarios: Internet Access Supported in IOS

4.1 Option#1: VRF Specific Default Route


Site1 MPLS Backbone
CE1
[Link]/16 Internet
SO [Link] ASBR

P
PE1 [Link]
PE1#
ip vrf VPN-A Internet GW
rd 100:1
route-target both 100:1
Interface Serial0
ip address [Link] [Link] ▪ A default route, pointing to the
ip vrf forwarding VPN-A
ASBR, is installed into the site VRF
Router bgp 100 at each PE
no bgp default ipv4-unicast
redistribute static
neighbor [Link] remote 100 ▪ The static route, pointing to the
neighbor [Link] activate VRF interface, is installed in the
neighbor [Link] next-hop-self
neighbor [Link] update-source loopback0
global routing table and
redistributed into BGP
ip route vrf VPN-A [Link] [Link] [Link] global
ip route [Link] [Link] Serial0
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
IP/VPN Deployment Scenarios: Internet Access Supported in IOS,

4.1 Option#1: VRF Specific Default Route (Forwarding)

Site1 MPLS Backbone


IP Packet
IP Packet Internet
[Link]/16 [Link] MPLS Packet
30 [Link] [Link] ([Link]/16)
E0 PE1 PE2
[Link] P IP Packet
[Link]
[Link]
E0 [Link]
PE1: Global Routing/FIB Table
[Link] 35 [Link] PE2: Global Table and LFIB
Destination Label/Interface IP Packet Destination Label/Interface
[Link]/32 Label=30 MPLS Packet
[Link]/32 Label=35
[Link]/16 Ethernet 0
[Link]/16 [Link]
[Link]/16 Ethernet 0

PE1: VRF Routing/FIB Table Pros Cons


Destination Label/Interface ▪ Using default route
[Link]/0 [Link] (Global) for Internet
Site-1 Ethernet 0 ▪ Different Internet gateways
▪ Routing does not allow any other
▪ Can be used for default route for intra-VPN routing
different VRFs Increasing size
▪ PE routers need not to of global routing table by leaking
hold the Internet table VPN routes
▪ Simple configuration ▪ Static configuration (possibility of
traffic blackholing)

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
IP/VPN Deployment Scenarios: Internet Access Supported in IOS,
NXOS and IOS-XR

4.2 Option#2: Separate PE-CE Subinterfaces


Site1
[Link]/16 MPLS Backbone
iBGP Internet
Internet
CE1
Eth0.2
PE1 PE2
Eth0.1 [Link] P [Link]
ip vrf VPN-A
rd 100:1 Internet GW
route-target both 100:1

Interface Ethernet0.1 ▪ PE1-CE1 has one sub-interface


ip vrf forwarding VPN-A associated to a VRF for VPN routing
ip address [Link] [Link]
frame-relay interface-dlci 100 ▪ PE1-CE has another subinterface
! (global) for Internet routing
Interface Ethernet0.2
ip address [Link] [Link] ▪ PE1 may have eBGP peering with CE1
frame-relay interface-dlci 200 over the global interface and advertise
!
full Internet routes or a default route to
CE1
Router bgp 100
no bgp default ipv4-unicast ▪ PE2 must advertise VPN/site1 routes
neighbor [Link] remote-as 502 to the Internet.
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
IP/VPN Deployment Scenarios: Internet Access Supported in IOS,
NXOS and IOS-XR

4.2 Option#2: Separate PE-CE Subinterfaces (Forwarding)


Site1
[Link]/16 IP Packet
[Link] MPLS Backbone
IP Packet Internet
Internet
CE1 MPLS Packet [Link]
E0.2 30 [Link]
PE1
PE2
E0.1 [Link] P [Link]

CE Routing Table PE-Internet GW


VPN Routes Eth 0.1
Internet Routes Eth 0.2

PE1 Global Table and FIB Pros Cons


Internet Routes
[Link] 1. CE is dual-homed and can 1. PE to Hold Full Internet Routes
perform Optimal Routing or default route via the Internet
[Link] Label=30 GW
2. Traffic Separation Done
by CE . BGP Complexities Introduced at
CE; CE1 May Need to Aggregate
to Avoid AS_PATH Looping

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios: Internet Access


4.3 Option#3: Extranet with Internet
• The Internet routes could be placed within the VRF at the Internet-
GW i.e., ASBR
• VRFs for customers could ‘extranet’ with the Internet VRF and
receive either default, partial or full Internet routes
• Default route is recommended
• Be careful if multiple customer VRFs, at the same PE, are importing
full Internet routes
• Works well only if the VPN customers don’t have overlapping
addresses

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
IOS-XR 4.3.1

IP/VPN Deployment Scenarios: Internet Access


IOS-XE 3.7

4.3 Option#3: VPN Extranet with Global (Internet) Table


• Export an IPv6/v4 prefix from VRF to Global routing table
• Import a VPNv6/v4 prefix from Global routing table into VRF
• Advertise imported prefixes to the CE router
VRF red
import ipv4 unicast map foo (10.5/16) # from global
export ipv4 unicast map bar (192.34/16) # to global [Link]/16
2001:FD8::/32
10.5
[Link]
/16
CE 192.3 PE MPLS-VPN

VRF <-> Global Route Leaking


#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
VRF <-> Global Route Leaking IOS-XR 4.3.1

eBGP (CE) and iBGP (PE) Advertisement


IOS-XE 3.10

• Export an IPv6/v4 prefix from VRF to Global routing table


• Import a VPNv6/v4 prefix from Global routing table into VRF
• Advertise imported prefixes to the CE router and optionally PE
router
VRF red
import ipv4 unicast map foo (10.5/16) export # from global
export ipv4 unicast map bar (192.34/16) # to global [Link]/16
2001:FD8::/32
10.5
[Link]
/16
CE 192.34 PE MPLS-VPN

VRF <-> Global Route Leaking


#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Supported in IOS,

IP/VPN Deployment Scenarios: Internet Access


4.4 Option#4: Using VRF-Aware NAT

• If the VPN customers need Internet access without Internet routes,


then VRF-aware NAT can be used at the Internet-GW i.e., ASBR
• The Internet GW doesn’t need to have Internet
routes either
• Overlapping VPN addresses is no longer a problem
• Check out “VRF-aware NAT” … reference

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
1. Multihoming / • IP/VPN Overview
Load-sharing
2. Hub & Spoke • Deployment Scenarios
3. Extranet • Use-Cases Summary
4. Internet Access
Agenda 5. IP/VPN o IP • Best Practices
transport • Conclusion

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


5. Providing MPLS/VPN over IP Transport

• MPLS/VPN (rfc2547) can also be deployed using IP transport


• No MPLS needed in the core
• PE-to-PE IP tunnel is used, instead of MPLS tunnel, for sending MPLS/VPN
packets
• MPLS labels are still allocated for VPN prefixes by PE routers and used only by the
PE routers
• MPLS/VPN packet is encapsulated inside an IP header
• IP tunnel could be point-to-point or Multipoint GRE encapsulation based.

[Link]

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


5. Providing MPLS/VPN over IP Transport

CE1 PE1 PE2 CE2


GRE/IP Tunnel

VRF
IP VRF

IP Header
GRE Header
VPN Label

Src Add Src Add Src Add


IP Packet Dst Add Dst Add Dst Add

Data Data Data

▪ GRE/IP header and VPN label imposed on VPN traffic by PE1


▪ VPN traffic is forwarded towards egress PE using IP forwarding
▪ Egress PE2 decapsulates, and uses VPN label to forward packet to CE2
Source -- [Link]
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
• IP/VPN Deployment
Scenarios
1. Multihoming & Load-sharing

Agenda
2. Hub and Spoke
3. Extranet
4. Internet Access
5. IP/VPN over IP Transport
6. Multi-VRF CE

BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
Supported in IOS,
NXOS and IOS-XR

IP/VPN Deployment Scenarios:


7. Providing Multiple VPNs inside VPN Site
• Is it possible for a CE router to keep multiple customer connections
separated ?
• Yes, “multi-VRF CE” a.k.a. vrf-lite can be used
• “Multi-VRF CE” provides multiple virtual routing tables (and forwarding
tables) per customer at the CE router
• Not a feature but an application based on VRF implementation
• Any routing protocol that is supported by normal VRF can be used in
a multi-VRF CE implementation
• No MPLS functionality needed on CE, no label exchange between CE and
any router (including PE) ☺

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
IP/VPN Deployment Scenarios:
Supported in IOS,
NXOS and IOS-XR

7. Multi-VRF CE aka VRF-Lite

<VRF for Green>


rd 3000:111
route-target both 3000:1
<VRF for Blue>
Building rd 3000:222
route-target both 3000:2
<VRF for Red> One of Deployment
Models for VRF-Lite
rd 3000:333
route-target both 3000:3
Vrf
Green
Campus
is Campus
SubInterfaces* MPLS Virtualization:=
Network Vrf Green
Vrf Extending IP/VPN to
CE
Red Vrf Red PE
Multi-VRF PE Router
CE Router
Vrf Red

<VRF for Green>


<VRF for Blue>
<VRF for Red>

*SubInterfaces —Any Interface Type that Supports Sub Interfaces =


Ethernet Vlan, Frame Relay, ATM VCs
#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
• After ensuring CiscoSans TT font is installed on your

CiscoSans TT Font Test computer quit and restart PowerPoint.


• Delete this slide after the font is installed.

This presentation template uses the


CiscoSans TT Light font. If the text
in these two columns does not
match, please take a moment to
install the font. Otherwise, your
presentation will not display
correctly.
Please download the fonts from
Brand Exchange here. The font can
also be found in the zipped folder.
Double-click the font file and click
“Install” in the window that appears.

#CiscoLive BRKMPL-2102 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 106

You might also like