LTRMPL 3102
LTRMPL 3102
LTRMPL 3102
Introduction
Session prerequisites and goals
Lab Overview
Technology
Design Logic
Access Instructions
Execute Lab
The Prerequisites
Know how to navigate and configure Cisco IOS
Familiarity with MPLS (what it is, what it does, and how it does it)
Understanding of IP routing fundamentals
This is an advanced lab
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Session Goal
Provide every attendee with hands-on experience in the configuration of multiple
network virtualization technologies.
Demonstrate the interoperability of various network virtualization protocols and
the integration of services within a functioning end-to-end topology.
This lab should not be considered a design guide.
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Lab Overview
MPLS Concepts and Capabilities
Reference points and their roles within an MPLS domain (P, PE, CE)
Virtual Routing and Forwarding (VRFs)
Inter-AS options (Options A, B, and C)
MPLS over GRE
Use cases
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Services Edge
Definition
The Services Edge functional area is where a great deal of policy enforcement
and traffic manipulation is done.
Three main functionalities:
Control inter-VPN traffic/access
Control access to VPN-dedicated resources
Control access to shared resources
Two types of access to shared services
Uncontrolled access
Controlled access
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Uncontrolled Access
Sharing Between VPNs with Route-target
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Refer to BRKMPL-2108 for more details
R9 R10
R2 R5
AS65000
WAN Core
R3
DC1 R1 SP
AS65001
FW1 R22
R6 R25 R12 Host5
R4
R14 R7
AS100
R11 R23
R8 R21
Host6
R13
R15
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Complete Your Online Session Evaluation
Please complete your Online
Session Evaluations after each
session
Complete 4 Session Evaluations &
the Overall Conference Evaluation
(available from Thursday) to receive
your Cisco Live T-shirt
All surveys can be completed via
the Cisco Live Mobile App or the
Dont forget: Cisco Live sessions will be available
Communication Stations for viewing on-demand after the event at
CiscoLive.com/Online
Presentation ID 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Continue Your Education
Demos in the Cisco Campus
Walk-in Self-Paced Labs
Table Topics
Meet the Engineer 1:1 meetings
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Q&A
Reference
Network Virtualization
Giving one physical network the ability to support multiple virtual networks
Separation between:
Line of business
Customers
App layers Alpha Network Cust2 Cust2
MPLS/Tunnel Labels
and Route Targets
IP link
802.1q
VRF
VRF
VRF
Logical or Physical
PE Router Int
(Layer 3)
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Background
Info
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
MPLS Inter-AS Use Cases
Cust1 Cust1
AS1 AS3
DC1 WAN
Core (AS2) DC2
Cust2 Cust2
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Extending MPLS with Inter-AS
Back-to-Back VRFs
ASBR1 (Option A)
ASBR2
CE1 CE2
VPN-R1 VPN-R2
IP Network
MPLS MPLS
DC1 MPLSoGRE
DC2
PE1 P1 P2 PE2
IGP Label GRE Header IGP Label
VPN Label IGP Label VPN Label
IP Payload VPN Label IP Payload
IP Payload
IP WAN Transport
IPSEC Option for security
P to P Tunnel
Looks like an MPLS Link
Drawbacks:
Cumbersome with multiple sites (MPLSoMGRE is an alternate solution)
MTU
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Refer to BRKMPL-2108 for more details
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Refer to BRKMPL-2108 for more details
Big Picture
Design: Firewall Placement w/Virtualization
Option1 CORE Option2
MPLS
LB
LB
Default Gateway
Spine Layer (N7k)
Default Gateway
Spine Layer (N7k)
F2e
FabricPath
FabricPath
LTRMPL-3102 2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Recommended Reading
Coming
Soon
2017 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Thank You