<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title><![CDATA[CCIE's way]]></title>
<link>http://www.gotoccie.cn/</link>
<description><![CDATA[| CCIE is that go forward every day | Decisive battle in 2010|Less talk and more work|]]></description>
<language>zh-cn</language>
<copyright><![CDATA[Copyright 2005 PBlog3 v2.8]]></copyright>
<webMaster><![CDATA[showbay@vip.qq.com(Bay Wei)]]></webMaster>
<generator>PBlog2 v2.4</generator> 
<image>
	<title>CCIE&#39;s way</title>
	<url>http://www.gotoccie.cn/images/logos.gif</url>
	<link>http://www.gotoccie.cn/</link>
	<description>CCIE&#39;s way</description>
</image>

			<item>
			<link>http://www.gotoccie.cn/article.asp?id=128</link>
			<title><![CDATA[Inter-AS MPLS VPN 2]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[VPN]]></category>
			<pubDate>Wed,24 Feb 2010 10:15:11 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=128</guid>
		<description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp;在《10210030002 Inter-AS MPLS VPN》中我已经写过了关于Inter-AS MPLS VPN的知识，但是发现，其实这个知识点是很不容易理解的。我又翻阅了相关的文档，现在用更加通俗的语言写写此点的关键。<br/>在RFC中定义了三种方案，我们称作Optin A/B/C，如下所示：<br/>Option A：VRF-to-VRF<br/>Option B：MP-EBGP ASBR-to-ASBR<br/>Option C：Multi-hop MP-EBGP<br/>我们在学习的时候，主要应该从这几个方面学习它：<br/>IGP label，VPN label，Next-hop<br/>我们主要明白这三个点就熟知了Inter-AS MPLS VPN的操作流程。接下来我们就按照以上三个方面讨论Option A/B/C.......<br/><br/>更多参阅PDF文档：<img src="http://www.gotoccie.cn/images/download.gif" alt="下载文件" style="margin:0px 2px -4px 0px"/> <a href="http://www.gotoccie.cn/attachments/month_1002/n201022410122.pdf" target="_blank">点击下载此文件</a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=127</link>
			<title><![CDATA[Cisco Announces Service Provider Operations Track]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[Others]]></category>
			<pubDate>Tue,26 Jan 2010 08:00:28 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=127</guid>
		<description><![CDATA[Cisco Announces New Service Provider Operations Track<br/> <br/>Built on the growing demand for dedicated professionals who can manage, maintain and troubleshoot complex service provider IP NGN core network infrastructures, Cisco is introducing a new Service Provider (SP) Operations track. This new track is focused on developing associate, professional and expert-level capabilities to operate large, complex SP networks. These new, first of their kind certifications are designed specifically for Cisco Service Provider Customers, Partners and Cisco Networking Engineers.<br/><br/> <br/>Over the coming months Cisco will release new CCIE, CCNP, and CCNA SP Operations courses and exams. In addition, the written exam topics for the CCIE SP Operations certification are now available on the Cisco Learning Network. The CCIE SP Operations written exam is scheduled for release in the second quarter of 2010.<br/><br/>CCIE SP Operations Certification<br/>The Cisco CCIE SP Operations certification assesses and validates core IP NGN service provider operations expertise.&nbsp;&nbsp;Candidates who pass the CCIE SP Operations certification exams demonstrate skills required of a expert-level (Tier III o&#114; Tier IV support) operations engineer to troubleshoot and maintain complex service provider IP NGN core (PE-PE and PE-CE) network infrastructures in both IOS and IOS XR operating environments, plus validate broad theoretical knowledge of operations management processes, frameworks, and network management systems.<br/><br/> <br/>CCIE SP Operations Certification benefits:<br/><br/>•Certification helps qualify personnel for customer’s Operations (NOC) Centers<br/>•Provides a credential (certification) that a person holds significant knowledge in SP Operations<br/>•Provides expert level certification to network operations (i.e. NOC) personnel to validate they are qualified to support various Build-Operate Transfer operation models<br/> <br/>The CCIE SP Operations written exam is scheduled for release in the second quarter of 2010. The practical exam is scheduled for release in the third quarter of 2010.<br/><br/>CCNP SP Operations Certification<br/>The Cisco Certified Network Professional&nbsp;&nbsp;in Service Provider Operations (CCNP SP Operations) validates knowledge and skills required (of a Tier II o&#114; Tier III support engineer) to troubleshoot and maintain service provider IP NGN core (PE-PE and PE-CE) network infrastructures.&nbsp;&nbsp;With a CCNP SP Operations certification, a network professional demonstrates the knowledge and skills required to isolate network performance problems, implement proactive fault measures using operations management processes, frameworks, and network management systems. The CCNP SP Operations curriculum includes maintaining carrier class routing protocol environments, MPLS VPN and TE deployments, and QoS mechanisms using Cisco IOS and IOS XR.<br/><br/> <br/>CCNP SP Operations Certification benefits: <br/><br/>•Certification helps qualify personnel for customers Operations Centers<br/>•Certification classes provide a developmental path for personnel in Operations<br/>•Provides advanced level training and certification to network operations (i.e. NOC) personnel<br/> <br/>The Cisco CCNP SP Operations certification will be made available in the third quarter of 2010.<br/><br/>CCNA SP Operations Certification<br/>Cisco Certified Network Associate in Service Provider Operations (CCNA SP Operations) validates basic knowledge and skills (of a Tier I support engineer) in a prescriptive troubleshooting environment within carrier class IP NGN core network infrastructure.&nbsp;&nbsp;CCNA SP Operations curriculum includes incident (event), fault, configuration, change, and performance management procedures, along with NMS tools and protocols.<br/><br/> <br/>CCNA SP Operations Certification benefits:<br/><br/>•Provides students with a foundation of network operations skills for SP NGN environments<br/>•Provides training and certifications around Network Operations job role<br/>•Provides entry level training and certification to entry level network operations (i.e. NOC) personnel<br/> <br/>The CCNA SP Operations certification is scheduled to be released in the second quarter of 2010.<br/><br/><br/>开设新的SP Rack也是由市场机制决定的。现在RS增加了MPLS VPN部分。如今的350-029都是SP的基础。看来Cisco想用SPO来取代350-029 lab。这也是一大调整。不过我觉得调整后的SPO更加贴近SP的要求。]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=125</link>
			<title><![CDATA[Online Help]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[Others]]></category>
			<pubDate>Thu,31 Dec 2009 08:17:11 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=125</guid>
		<description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;如果你有关于网络方面的难题？请提交问题给我，我会尽力为你解答。<br/>&nbsp;&nbsp;&nbsp;&nbsp;感谢您提交的问题，如果您有任何问题，请提交您的问题。 （最好包括以前的问题）<br/>&nbsp;&nbsp;&nbsp;&nbsp;让我们共同进步！<br/>&nbsp;&nbsp;&nbsp;&nbsp;If you have problems on the network? Please submit questions to me, I will try to answer for you。<br/>&nbsp;&nbsp;&nbsp;&nbsp;Thank you for your submission problem, if you have any questions, please resubmit your question. (Preferably including the previous issues).<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Let us make progress together!<br/><img src="http://www.gotoccie.cn/attachments/month_0912/d200912318164.png" border="0" alt=""/><br/><br/>E-mail: <span style="color:Red"><span style="font-size:14pt">help@gotoccie.cn</span></span>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=124</link>
			<title><![CDATA[Site of o&#114;igin(SOO)]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[VPN]]></category>
			<pubDate>Wed,23 Dec 2009 17:44:42 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=124</guid>
		<description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Site-of-Origin(SOO)是PE路由器分发VPNv4路由时分配给路由的一种属性。他主要的作用是防止路由环路的产生。当然你也可以使用其它的策略。<br/>&nbsp;&nbsp;&nbsp;&nbsp;有时两端的Site使用相同的AS号码，这就在路由的分发时会发生问题。我们要使用as-overwide来解决这个问题。但同时可能会引起相同的路由再转发回来。这时候我们使用SOO就可以很好的解决这个问题。如果PE看到和某个接口使用相同的SOO，那么PE就不会将此路由加入到VRF路由表中，反之亦然。这点和距离矢量路由协议的水平分割有些类似。当然SOO还可以使用在其他的用途，你可以使用route-map来匹配相应的SOO值，然后分给相应的策略。<br/>&nbsp;&nbsp;&nbsp;&nbsp;.......<br/> <br/><br/>更多参阅PDF文档：<img src="http://www.gotoccie.cn/images/download.gif" alt="下载文件" style="margin:0px 2px -4px 0px"/> <a href="http://www.gotoccie.cn/attachments/month_0912/320091223174425.pdf" target="_blank">点击下载此文件</a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=123</link>
			<title><![CDATA[Project Study of MPLS Rack]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[Others]]></category>
			<pubDate>Wed,23 Dec 2009 12:33:26 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=123</guid>
		<description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp;本Rack由8台7206vxr组成。可以在其上做与MPLS相关的实验。基本的MPLS,BGP,IGP,MPLS VPN都已经配置完成。下载文件后自己运行即可。<br/><br/>拓扑图如下(在下载包中有):<br/><img src="http://www.gotoccie.cn/attachments/month_0912/820091223122823.gif" border="0" alt=""/><br/>以下是net文件(在下载包中有):<br/>##################################################<br/>#<br/>#&nbsp;&nbsp;&nbsp;&nbsp;Welcome to Rack of CCIE Service Provider<br/>#<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Project Study<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; WWW.GOTOCCIE.CN<br/>#<br/>##################################################<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;CCIE is that go forward ever day<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Edit:bay Wei<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;QQ：3087274&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Email:showbay@vip.qq.com<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;MSN:jncies@gmail.com<br/>##################################################<br/># |Define v60&nbsp;&nbsp;Router as follows:<br/># |Cisco 7206VXR---&gt; <br/>#&nbsp;&nbsp; IOS:&nbsp;&nbsp; c7200-k91p-mz.122-25.S15.bin<br/>#&nbsp;&nbsp; Ram:&nbsp;&nbsp; 128M<br/>#&nbsp;&nbsp; NPE:&nbsp;&nbsp; NPE-400<br/>#&nbsp;&nbsp; disk0: 128<br/>#&nbsp;&nbsp; disk1: 0<br/>#&nbsp;&nbsp; Slot0: PA-C7200-IO-2FE<br/>#&nbsp;&nbsp; Slot1: PA-2FE-TX<br/>#----------------------------------------------<br/><br/> autostart = False<br/> ghostios = True<br/> sparsemem = True<br/> mmap = true<br/><br/>################################################## |<br/># |<br/># |The 1st instance for AS123&#39;s Backbone(R1,R2,R3) and R8<br/># |Backbone use Cisco 7206VXR router<br/># |Dynamips use prot 9100 and UDP port is 11000<br/># |Console port is 8000 serial(8001 - 8012)<br/># |All FastEthernet interface connected to Switch<br/># |<br/>#################################################<br/><br/>&nbsp;&nbsp;[127.0.0.1:9100]<br/>&nbsp;&nbsp;&nbsp;&nbsp;port = 9100<br/>&nbsp;&nbsp;&nbsp;&nbsp;udp = 11000<br/>&nbsp;&nbsp;&nbsp;&nbsp;workingdir = ..\tmp\<br/>&nbsp;&nbsp;&nbsp;&nbsp;<br/>&nbsp;&nbsp;&nbsp;&nbsp;[[7200]]<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;image = ..\ios\IMAGES\c7200-k91p-mz.122-25.S15.image<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;npe = npe-400<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ram = 128<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;disk0 = 128<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;disk1 = 0<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;confreg = 0x2102<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;exec_area = 64<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;idlepc = 0x6084ab10<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;slot0 = PA-C7200-IO-2FE<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;slot1 = PA-2FE-TX<br/><br/>&nbsp;&nbsp; [[ROUTER R1]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8001<br/>&nbsp;&nbsp;&nbsp;&nbsp; f0/0 = R3 f0/0<br/>&nbsp;&nbsp;&nbsp;&nbsp; f0/1 = R2 f0/1<br/>&nbsp;&nbsp;&nbsp;&nbsp; f1/1 = R8 f1/1<br/><br/>&nbsp;&nbsp; [[ROUTER R2]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8002<br/>&nbsp;&nbsp;&nbsp;&nbsp; f1/0 = R3 f1/0<br/>&nbsp;&nbsp;&nbsp;&nbsp; f1/1 = R4 f1/1<br/><br/>&nbsp;&nbsp; [[ROUTER R3]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8003<br/>&nbsp;&nbsp;&nbsp;&nbsp; f0/1 = HUB 1<br/><br/>&nbsp;&nbsp; [[ROUTER R8]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8008<br/><br/><br/>#################################################<br/># |<br/># |The 2st instance for AS456&#39;s Backbone(R4,R5,R6) R7 and EthernetSwitch<br/># |Backbone use Cisco 7206VXR router<br/># |Dynamips use prot 9200 and UDP port is 12000<br/># |Console port is 8000 serial(8001 - 8012)<br/># |All FastEthernet interface connected to Switch<br/># |<br/>#################################################<br/><br/>&nbsp;&nbsp;[127.0.0.1:9200]<br/>&nbsp;&nbsp;&nbsp;&nbsp;port = 9200<br/>&nbsp;&nbsp;&nbsp;&nbsp;udp = 12000<br/>&nbsp;&nbsp;&nbsp;&nbsp;workingdir = ..\tmp\<br/>&nbsp;&nbsp;&nbsp;&nbsp;<br/>&nbsp;&nbsp;&nbsp;&nbsp;[[7200]]<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;image = ..\ios\IMAGES\c7200-k91p-mz.122-25.S15.image<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;npe = npe-400<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;ram = 128<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;disk0 = 128<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;disk1 = 0<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;confreg = 0x2102<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;exec_area = 64<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;idlepc = 0x6084ab10<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;slot0 = PA-C7200-IO-2FE<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;slot1 = PA-2FE-TX<br/><br/>&nbsp;&nbsp; [[ROUTER R4]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8004<br/>&nbsp;&nbsp;&nbsp;&nbsp; f0/0 = R5 f0/0<br/>&nbsp;&nbsp;&nbsp;&nbsp; f0/1 = R6 f0/1<br/><br/><br/>&nbsp;&nbsp; [[ROUTER R5]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8005<br/>&nbsp;&nbsp;&nbsp;&nbsp; f1/0 = R6 f1/0<br/>&nbsp;&nbsp;&nbsp;&nbsp; f0/1 = HUB 1<br/><br/><br/>&nbsp;&nbsp; [[ROUTER R6]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8006<br/>&nbsp;&nbsp;&nbsp;&nbsp; f0/0 = R7 f0/0<br/><br/><br/>&nbsp;&nbsp; [[ROUTER R7]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; model = 7200<br/>&nbsp;&nbsp;&nbsp;&nbsp; console = 8007<br/><br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;[[ethsw HUB]]<br/>&nbsp;&nbsp;&nbsp;&nbsp; 1 = dot1q 1<br/>&nbsp;&nbsp;&nbsp;&nbsp; 2 = dot1q 1<br/>&nbsp;&nbsp;&nbsp;&nbsp; 3 = access 1 NIO_gen_eth:\Device\NPF_{C7A34BF2-7E96-4B2B-97A1-B9CD5D67E0F5}<br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br/>&nbsp;&nbsp; <br/><br/>##################################################<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Bay Wei<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; CCIE&#39;s way<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; WWW.GOTOCCIE.CN<br/>#&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 2009-12-23<br/>##################################################<br/>我在R3--R5之间桥接了一个本地接口，主要用来抓包，学习包的格式，你下载后需要修改&lt;NIO_gen_eth:\Device\NPF_{C7A34BF2-7E96-4B2B-97A1-B9CD5D67E0F5}&gt;。至于抓包工具你可以自己选择。我使用的是OmniEngines with OmniPeek 。<br/><br/>-----------------------------------<br/>OmniEngines with OmniPeek Download：<a href="http://www.wildpackets.com/support/downloads" target="_blank" rel="external">http://www.wildpackets.com/support/downloads</a><br/>配置文件包下载：<a href="http://www.namipan.com/d/Project%20Study.rar/8a33019368797b8581a0affdb63f6e7ac0c105062402e301" target="_blank" rel="external">http://www.namipan.com/d/Project%20Study.rar/8a33019368797b8581a0affdb63f6e7ac0c105062402e301</a><br/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=122</link>
			<title><![CDATA[MPLS  Knowledge Architectures Clouds]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[MPLS]]></category>
			<pubDate>Tue,22 Dec 2009 12:51:57 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=122</guid>
		<description><![CDATA[&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;我把和MPLS相关的知识点画到一个云图上了,希望能对大家建立一个MPLS架构图，对于学习MPLS也知道如何下手。如果你懂得了云图的知识点，可以将相关的知识点组合来学习更深入的学习。后面我的学习也是根据这个云图来学习的。以后的文档也基本上都是根据这个图来写。<br/><span style="color:Red">Note：原图右键保存图片即可</span><br/><img src="http://www.gotoccie.cn/attachments/month_0912/320091222125127.gif" border="0" alt=""/><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=121</link>
			<title><![CDATA[Inter-AS MPLS VPN]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[VPN]]></category>
			<pubDate>Mon,14 Dec 2009 15:58:27 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=121</guid>
		<description><![CDATA[对于Inter-AS MPLS VPN 这里有两种标签：<br/>1.&nbsp;&nbsp;VPN标签（由MP-BGP分发而来）。<br/>2.&nbsp;&nbsp;IGP标签（由LDP/TDP根据IGP分发而来）。<br/>在同一个AS中，MPLS VPN可以很好的工作，因为所有的数据包都是使用两个标签，而同一AS中，所有的PE的Loopback地址都是相互保持的。而在Inter-AS 中，由于是两个不同的AS管理着，那么他们之间的策略可能不一致。那么如何保持他们之间能够正常的通讯。这个就对标签的分发，LSP的建立是很重要的。在Inter-AS MPLS VPN中，有两个点是很重要的。<br/>1. 标签的分发<br/>2. 下一跳<br/>只要这两个能够正常的工作，Inter-AS MPLS VPN就可以工作了。<br/>MPLS VPN Inter-AS RFC定义了三种方法：<br/>Option A：Back-to-Back VRF<br/>Option B：ASBR-to-ASBR<br/>Option C：Multi-Hop MP-eBGP Between RR and eBGP Between ASBRs<br/>在CCIE ISP LAB中，Inter-AS VPN也是相当重要的，它会影响到其他的需求，因此对于Inter-AS的学习也是很重要的。<br/><br/><span style="color:Red">Note：看不清图片请右键另存为即可</span><img src="http://www.gotoccie.cn/attachments/month_0912/c20091214155649.jpg" border="0" alt=""/><br/><br/>更多内容请参与PDF文档：<img src="http://www.gotoccie.cn/images/download.gif" alt="下载文件" style="margin:0px 2px -4px 0px"/> <a href="http://www.gotoccie.cn/attachments/month_0912/d20091214155745.pdf" target="_blank">点击下载此文件</a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=120</link>
			<title><![CDATA[Core Knowledge Questions Now on All CCIE Labs]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[Others]]></category>
			<pubDate>Wed,09 Dec 2009 20:02:54 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=120</guid>
		<description><![CDATA[Effective January 4, 2010, the CCIE® Service Provider, Storage, and Wireless Lab Exams will add a new type of question format in a section called Core Knowledge. In this new section, candidates will be asked a series of four open-ended questions which require a short written response be entered into the computer–typically several words. The questions will be randomly drawn from a pool of questions on topics eligible for testing. Candidates can review the topics by visiting the CCIE track information on Cisco.com o&#114; Cisco Learning Network. No new topics are being added as a result of this change. Candidates will have up to 30 minutes to complete the Core Knowledge section and may not return to it once they have moved on. A passing score on the Core Knowledge section is required to achieve certification. Core Knowledge questions were implemented on Routing and Switching labs in February 2009, Security labs in June 2009, and Voice labs in July 2009, and allow Cisco to maintain strong exam security and ensure only qualified candidates are awarded CCIE certification. Candidates with exam dates January 4, 2010 o&#114; later should expect to see the new question format on their lab exam. To find out more information regarding up&#100;ates to the CCIE Lab and scoring format, please click here to go to the CCIE Q&amp;A section.<br/><br/>Come on!2010!<br/>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=119</link>
			<title><![CDATA[CCIE SP Lab Checklist v3 Edition]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[Others]]></category>
			<pubDate>Sun,06 Dec 2009 08:11:10 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=119</guid>
		<description><![CDATA[I have re-compiled my v2 CCIE SP Checklist which I published here before my last attempt back in February. I have added in nuances, new tips and additional information I have come across in other forums which I hope can help not only you but also me!!<br/><br/>Here is the copy in blog format and I have also added a rapidshare link at the bottom of this blog entry for the PDF Version – let me know what you think.<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br/><br/>Title:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; CCIE SP Lab Checklist<br/><br/>Author:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Stephen Bowes<br/><br/>Version:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 3.0<br/><br/>Date:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;November 2009<br/><br/>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br/><br/>Abstract: <br/><br/>This is a compilation of notes, gotcha’s, pointers, etc from my research in preparation for my upcoming CCIE SP Lab exam which I have acquired over many years. Please feel free to notify me of more improved ways to those listed below and o&#114; errata through my CCIE blog at cciesplab.wordpress.com o&#114; by email at cciesp@rocketmail.com.<br/><br/>Points Scoring and Timings:<br/><br/>I am conscious of the number of candidates who have failed due to running out of time. There are a number of reasons for this, here they are and proposed solutions. <br/><br/>Reasons for Failure: Solutions: <br/>Misinterpreting the questions Read the question more slowly, read it again, do not over-engineer the solution, answer what is asked, confirm any doubts with proctor, if proctor answer unacceptable, ask the same question a different way again. <br/>Typing in the right configuration on the wrong interface o&#114; router Tread carefully, cross-check and reference, validate before moving on. <br/>Tasks taking too long to configure in the time window available Practise speed drills, type faster, use aliases, notepad for verbose configurations, and use the Doc CD less if possible. Configure technologies router by router rather than interface by interface [explained later] <br/>Lack of Task Verification Failing to fully verify – ensure you use the three way approach [1] Ping, [2] Trace Route &amp; [3] Routing Table <br/><br/> To this end my timing plan is as follows -&gt; Total Time = 8 hours = 480 Minutes. Lab Points Total = 100 Points, allowing 30 minutes for opening moves [see below] and 45 minutes for checking, validation and verification at the end, gives me 400 minutes for configuration<br/><br/>=&gt; 4 Minutes/Point.<br/><br/>Pre-Lab Actions:<br/><br/>1 Month:<br/><br/>Adjust your body to performing 8 hour labs – Stamina will be key – you will be no use to anyone if you get tired after 5 hours of labbing. With 1 month to go ensure you are not doing 4 hour mini-labs rather the longer ones.<br/><br/>1 Week:<br/><br/>Adjust your body clock to the lab time. In my case I work 11am-7pm GMT wh&#101;reas the Lab Exam in Brussels starts at 0745. This is 0645 GMT so with a week to go I will be up, showered, and had breakfast and sitting at my desk at 0730 to start an 8 hour lab with lunch at 12 for 30 minutes. I need to be fully alert at 0745 on Lab Day.<br/><br/>Lab Exam Day:<br/><br/>Get as much sleep as is feasible the night before, up, showered, breakfast complete and be at Cisco by 0730. I booked into the nearest hotel I could find 250m away so no reliance on transport, etc. <br/>Bring a number of layers of clothes in case the room is cool, bring ear plugs so that the 11 guys/girls typing next to you and also so that the CCIE Voice candidates testing faxes will not interfere with your concentration levels. <br/>Documentation Location is <a href="http://www.cisco.com/web/psa/products/index.html" target="_blank" rel="external">http://www.cisco.com/web/psa/products/index.html</a> <br/>15 Minute Immediate Action: Anyone who has served in the military knows what an Immediate Action is – when something goes wrong a backup plan – in this case I’m going to move on if I cannot get any 3 pointer completed within 15 minutes ensuring I finish the lab!<br/><br/>Lab Action Plan: [Note: All times below are estimates and dependent on points values as per timing plan noted above]<br/><br/>Opening Moves: [30 Minutes: 0800-&gt;0830]<br/><br/>After the proctor instructions, take a minute, calm yourself, open the booklet, read the exam end to end, visualise the Bridging/Switching, IGP, EGP, MPLS, etc. <br/>Draw a personalised diagram of the topology – Note: This is a talking point, some do, some don’t, and I think it’s advantageous especially from an IP/Interface perspective. <br/>Ignore the rush of the other candidates typing o&#114; the urge to get started. <br/>Cr&#101;ate a point checklist on the rough paper provided. Here is my example. <br/>Example Point Checklist:<br/><br/>Task: Section: Points: Time: [Mins] Completed: Total Points: Comments: <br/>Switching 1.1 3 15 Yes 3 Watch security requirement section 7.2 <br/>Switching 1.2 2 10 Yes 5 All ok <br/>Switching 1.3 2 10 No, moved on 5 Look up DocCD to confirm solution. <br/><br/>Troubleshooting: [15 Minutes: 0830-&gt;0845]<br/><br/>A number of faults may have been entered into the pre-configured devices. Check your SecureCRT software – can you see each of the devices? Reload each device, look for any hardware errors on boot-up, now is the time to spot this, not 11am.<br/><br/>As any issues could have been introduced check everything, IP Addresses matching Interfaces, subnet masks, FR DLCI’s, FR Inverse-Arp, pre-defined VLAN’s, VTP Modes on 3550’s, watch any pre-defined configurations configured on correct interfaces, ATM configurations, NSAP, IP, IP CEF, etc. <br/><br/>I am not an Alias guy but now would be the time to do this, type these into notepad and cut &amp; paste onto the routers ‘show run | b Se’ – Remember for large o&#114; repetitive configurations such as BGP, use notepad and then copy and paste but be aware of changing values such as IP’s, subnets, etc as you copy and paste.<br/><br/> Bridging &amp; Switching:<br/><br/>Frame-Relay: [15 Minutes: 0845-&gt;0900]<br/><br/>Use your diagram to draw out the FR Topology <br/>A lot of this may be pre-configured so verification doubly important <br/>Use [1] shut [2] enc frame-relay [3] no frame inverse-arp [4] no shut. <br/>Decide to use either frame-relay map o&#114; use sub-interfaces <br/>Ping from spoke to spoke if possible to validate. <br/>Extra mapping required if required to ping your own interface <br/>If PPP over FR, then always cr&#101;ate VT first, user/password <br/>Save, reload, and then verify all working. <br/>FRTS – Know your CIR=Bc x 1000\Tc; Be=(AR-CIR) x Tc/1000. <br/>DocCD Location =&gt; Main URL = <a href="http://www.cisco.com/web/psa/products/index.html" target="_blank" rel="external">http://www.cisco.com/web/psa/products/index.html</a> <br/>– Cisco IOS SW Release 12.4 Family – 12.4 Mainline – Configuration Guides – Cisco IOS Wide-Area Networking Configuration Guide, Release 12.4.<br/><br/>Verification Tools – ping, show frame-relay map, show int virtual-template, show int virtual-access, show traffic-shape, show interfaces serial, show frame-relay lmi, show frame-relay pvc, clear frame-relay inarp, clear interface, debug serial interface, debug frame-relay lmi, debug frame-delay events, debug frame-relay packets <br/>=&gt; Golden Moment: Frame-Relay is the spinal cord of the inter-network, it must be 100% &lt;=<br/><br/>Switching: [15 minutes: 0900-&gt;0915]<br/><br/>Check VLAN’s as per instruction <br/>Check VTP Modes <br/>Check Trunking &amp; Access Ports <br/>A lot of pre-configuration completed so use the verification commands below. <br/>Ping vlan by vlan. Sel&#101;ct only one device and ping all other on a specific vlan. <br/>If naming something, type it exactly as specified – Ref: Narbik <br/>Specify both Duplex and Speed as Auto-Sense can be troublesome – Ref: IEMentor &amp; Gorito <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS LAN Switching Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show interfaces, show interfaces trunk, show vlan brief, show vtp status, clear interface <br/> Cell-Mode MPLS: [15 Minutes: 0915-&gt;0930]<br/><br/>Configure any ATM interfaces required – PVC/SVC, NSAP Addressing, <br/>Watch for tag-switching o&#114; label-switching. <br/>Security authentication may be required <br/>Use ping to verify <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS Asynchronous Transfer Mode Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show interfaces, show atm pvc, show atm svc, show atm map, show atm traffic, <br/> PPP/Ethernet: [15 Minutes: 0930-&gt;0945]<br/><br/>Configure PPP/PPPoE as required, PPPoE enable, pppoe-client, interface dialer, etc. <br/>Know security configurations, ping and validate. <br/>Be aware of IOS nuances with these types of features. <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS VPDN Configuration Guide, Release 12.4 &amp; Cisco IOS Broadband Access Aggregation and DSL Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show pppoe session <br/> =&gt; Golden Moment – Bridging &amp; Switching Complete – Total Time 1 Hour 45Mins &lt;=<br/><br/>IGP: [Note that probably only one of these will be the core IGP] <br/><br/>OSPF: [30 Minutes: 0945-&gt;1015]<br/><br/>While reading the task, use your master diagram to configure OSPF router by router not area by area. Look for the following OSPF characteristics. <br/>Authentication, stub o&#114; nssa, virtual link <br/>Refer again to your master diagram, colour in the OSPF areas. <br/>Make a note on redistribution, summary, area-range, DR/BDR, OPSF network type. <br/>Get Area 0 working 100% first. <br/>Ensure Area 0 Contiguous, test, cr&#101;ate GRE/Virtual-links, and test again. <br/>Configure other areas. <br/>Leave OSPF Security until last. <br/>From a time perspective, router by router saves you revisiting router and typing in additional commands after the fact. <br/>First Interface and then router ospf <br/>Preferred sequence for configuring interface<br/><br/>1) OPSF network type based,<br/><br/>2) priority,<br/><br/>3) Authentication,<br/><br/>Preferred sequence for configuring OSPF process<br/><br/>1) router-id<br/><br/>2) area authentication,<br/><br/>3) neighbor,<br/><br/>4) Network (copy paste from interface address)<br/><br/>Validate everything is working (show ip os ne, show ip os vir, show ip os interface, show ip route) <br/>Do redistribute summary, area range, filtering [Be Careful!] <br/>Validate and verify prior to moving on. <br/>Save Configurations, <br/>Reload routers and final verification.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br/>Note: Some candidates do not reload, some do – I will.<br/><br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS IP Routing Protocols Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show ip ospf, show ip ospf interfaces, show ip ospf neighbor, show ip ospf database, show ip ospf virtual-links, debug ip ospf events, debug ip ospf hello, debug ip ospf packet <br/>IS-IS: [30 Minutes: 1015-&gt;1030] – Same as OSPF – Allowing additional 15 minutes in case both are present.<br/><br/>This has been noted by previous candidates and having quite a bit to do on the SP Exam! Refer again to your master diagram, colour in the ISIS areas. <br/>Configure ISIS on relevant routers <br/>Note what ISIS Levels are required – 1 o&#114; 2, <br/>Assign appropriate NET addresses <br/>Remember unlike other IGP’s, ISIS configured at Interface level and is essentially a L2 protocol. <br/>Verify adjacencies <br/>Due to ISIS only knowing two forms of media – LAN o&#114; point-to-point -&gt; use the frame-relay map clns command to cr&#101;ate maps for protocol to run. <br/>Configure any ISIS filtering/redistribution <br/>Configure Authentication if required. <br/>Configure any additional ISIS nuances/parameters such as metrics/timers, etc we encounter. <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS IP Routing Protocols Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show isis database, show isis topology, show clns protocol, show clns interface, show clns neighbors. <br/>=&gt; Golden Moment – IGP Complete – IGP Time 1 hour – Total Time 3 Hours &lt;=<br/><br/>BGP: [60 Minutes: 1030-1130 – dependent on points] <br/><br/>While reading task, draw BGP topology on master diagram, this is important. <br/>Determine Route Reflector o&#114; confederation o&#114; both to do full-mesh iBGP. <br/>See if neighbor peer-group is required, <br/>Configure router by router not BGP session-by-session <br/>Configure one AS then another – be AS focussed. <br/>Ascertain required address families &amp; configure – ipv4, vpnv4, ipv4 vrf, etc <br/>Ensure reachability, one AS at a time. <br/>Spend enough time to be absolutely correct on route-filtering (ACL, prefix-list, as-path filer), route-aggregate(w/ as-set, summary-only, supress-map, attribute-map, advertise-map), route-manipulation( w/as-prepending, med, local-pref, weight, next-hop, advertise-map/non/existing-map, o&#114;igin, community, etc ) route-dampening, etc. <br/>Resolve any next-hop-self issues which are easier to troubleshoot working one AS at a time. <br/>Validate config. Use “clear ip bgp * soft “not”, clear ip bgp *. <br/>Leave BGP Authentication until last. <br/>Save, reload and test. <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS IP Routing Protocols Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show ip bgp, show ip bgp summary, show ip route bgp, show ip bgp neighbors, show ip bgp neighbors neighbor-ip-address, debug ip bgp <br/>=&gt; Golden Moment – EGP Complete – Ensure full Reachability Maintained, Save Configs &lt;=<br/><br/>Reachability Test: [Before lunch if possible followed by reloading routers]<br/><br/>Test full reachability with TCL Script. Check you get an ICMP response from every router to every router. If ping has no response, write down IP address and troubleshoot.<br/><br/>The master diagram will help here. Method involves – show ip alias, Copy to Notepad, Search and Replace to “Massage the Data and toss in the PING Command), Wrap what’s left in a TCL o&#114; Macro, Copy and Paste into a Router.<br/><br/>&nbsp;&nbsp;Run tclsh script<br/><br/>&nbsp;&nbsp;“foreach addr {<br/><br/>&nbsp;&nbsp;1.1.1.1 &lt;<a href="http://1.1.1.1" target="_blank" rel="external">http://1.1.1.1</a><br/><br/>&nbsp;&nbsp;…<br/><br/>&nbsp;&nbsp;} { ping $ addr}” Just copy past after tclsh – To quit, just type ” tclq”. Also to quote Scott Morris -&gt; I’d leave “debug ip routing” turned on through the rest of the day. It can be a quick indicator to things getting messed up (like when you add ACL’s o&#114; play with NAT!)<br/><br/>MPLS: [30 Minutes: 1130-&gt;1200] <br/><br/>Tag Switching v Label Switching, when to use which ones – Watch for IOS Bugs here! <br/>Watch any integration with EGP <br/>MPLS might be the final piece of the jigsaw for full lab reachability. <br/>Cell Mode v Frame Mode <br/>MPLS Traffic Engineering – Levels, metric-style wide, ip explicit config, RSVP? etc. <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS Multiprotocol Label Switching Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show mpls forwarding-table, show mpls interfaces, show mpls ldp neighbor, show mpls ldp parameters, show mpls traffic-eng autoroute <br/>Golden Moment – Lunch – Reachability, Save Configurations &amp; Reload.<br/><br/>Afternoon Session:<br/><br/>SP Management: [15 Minutes: 1230-&gt;1245] <br/><br/>Know SNMP, setting up community strings, traps, RMON, pointing at various devices, etc <br/>Netflow, destination address, port no, version, etc <br/>NTP, master, server, source, etc. <br/>Know about various IP Services available in the IOS <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS NetFlow Configuration Guide, Release 12.4 &amp; Cisco IOS Network Management Configuration Guide, Release 12.4 &amp; Cisco IOS Configuration Fundamentals Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; Multiple Commands. <br/>SP Security: [30 Minutes: 1245-&gt;1315]<br/><br/>Be careful not to block o&#114; dro&#112; any IGP up&#100;ates; Draw a flow on paper if required<br/><br/>Consider all options for classification – std/ext/reflexive/dynamic ACL, IP Prefix List, IP inspect, tcp intercept, Unicast RFP, ip accounting output packet /access-violation/precedence. <br/>Be aware of various ways to configure MD5 for IGP, some of this may be completed via the IGP\EGP sections, ensure you have read ahead at the start of the lab. <br/>When configuring Switchport port-security mac-address, be careful to include virtual and physical mac if HSRP is running <br/>Know response planning to common security attacks such as DOS, Smurf, etc. <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS Security Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; Multiple Commands. <br/>MPLS VPN: [75 Minutes: 1315-&gt;1445]<br/><br/>So much here: VRF, VRF-Lite, MP-iBGP, MP-eBGP, Important to map out on your master diagram, the flow/direction of the VPN Traffic so that the correct configuration can be applied to the correct interface on the correct router in the correct direction!<br/><br/>MP-BGP filtering, specifying route-targets, etc <br/>PE-CE Routing, RIP – Watch Split-Horizon is off on physical FR and ATM, authentication, version, auto-summary, etc; Other IGP/EGP considerations configure router-by-router, Advanced Options-CSC, Internet Access, Central Services, etc. <br/>Be aware of various backup routes for the VPN traffic in the event of line/router failure, redistribution of PE-CE to Core and vice versa. <br/>Be aware of VPN and Frame Relay specific limitations <br/>GRE/mGRE tunnels, when to use, how to configure. <br/>Be able to provide Internet Access from one portion of the inter-network to another. <br/>Be able to exchange EGP traffic across AS’s, watch next-hop, watch multi-hop, etc <br/>QinQ/PPoE – benefits = reduce no of VLANs, scalability, encap dot1q, pppoe enabled, etc. <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS Multiprotocol Label Switching Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show ip vrf, show ip route, show ip route vrf vrf-name [prefix], show ip cef vrf vrf-name [ip-prefix], ping vrf, show ip bgp vpn all summary, show ip vrf detail, ping vrf &lt;vrf&gt; &lt;ip address&gt; source &lt;source ip&gt;, sh ip bgp vpn all summary, sh ip bgp vpn all, sh ip bgp vpn vrf &lt;vrf&gt; summary, sh ip bgp vpn vrf &lt;vrf&gt;, sh ip bgp vpn vrf &lt;vrf&gt; labels, sh mpls forwarding, sh mpls forwarding | inc &lt;prefix&gt;, sh mpls forwarding vrf &lt;vrf&gt; &lt;prefix&gt;, sh mpls forwarding label &lt;label&gt;.<br/><br/>SP Multicast: [30 Minutes: 1445-&gt;1515]<br/><br/>Setup PIM Mode as required – Sparse/Sparse-Dense – Use address-family ipv4 multicast were required <br/>Identify PIM RP o&#114; Bootstrap requirements <br/>Don’t forget ip multicast-routing and/or ip multicast-routing vrf &lt;VRF&gt; <br/>Be aware of route filtering <br/>Join any IGMP Groups if required, check with pings, <br/>Check Unicast and multicast traffic work across different AS. <br/>Multicast VPN, default MDT, data MDT, MDT Group Addresses, MSDP, etc <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS IP Multicast Configuration Guide, Release 12.4 <br/>Verification Tools =&gt;&nbsp;&nbsp; show ip igmp groups, show ip pim rp mapping, show ip mroute, show ip interfaces. <br/>SP QoS: [30 Minutes: 1515-&gt;1545] <br/><br/>Be careful not to block o&#114; dro&#112; any IGP up&#100;ates <br/>Draw a flow on paper <br/>Interpretation of what is required &amp; which QoS Method to use is Key!! <br/>Determine classification method (ACL, NBAR) and direction. <br/>Determine Shaping v Policing <br/>Consider all options for queuing (legacy custom/priority, bandwidth/priority, shape average/peak, FRTS/GTS) – Always Outbound. <br/>Consider all options for policing ( police, rate-limit, ip multicast rate-limit, aggregate police( 3550)) <br/>If frame-relay, don’t forget adaptive-shaping.( becn, fecn, foresight) <br/>Consider all dro&#112;ping mode (random detect, ecn, tail dro&#112;, marking, etc) <br/>DocCD Location =&gt; Main URL, Cisco IOS SW Release 12.4 Family, 12.4 Mainline, Configuration Guides, Cisco IOS Quality of Service Solutions Configuration Guide, Release 12.4 <br/>Verification Tools =&gt; show ip rsvp, show class-map, show ip rsvp reservation, show mls qos, show policy-map, show queueing, show traffic-shape, etc. <br/>Timings &amp; Tips:<br/><br/>According to this schedule this allows me 45 minutes for checking, saving, reloading, troubleshooting, going back to skipped sections, etc. <br/>Remember the pass mark is 80% not 100% – we can allow for 6 sections worth 3 points each not to work out and still pass!!!! <br/>Route Filtering – Know this cold, affects several areas, pass o&#114; fail the lab on this alone IMO! <br/>Skipping Difficult Sections – This is a dangerous but potentially rewarding path up the mountain but slippery and easy to fall down on – Risky Approach. <br/>Redistribution – Say no more, need to pass routes, this is it – potential failure point. <br/>Strategy has to be flexible depending on the progress through the day. <br/>Ensure the “gimme” questions are answered 100% – These are key to success. <br/>Ongoing Validation, via show commands and TCL Script, saving and reloading at least twice I believe is essential. <br/>Speed accessing resources on the DOCCD is essential – should be less than 90 seconds lookup per topic. <br/>Authors Note: Please feel free to contact me if you can add value to this 3rd Edition as I would like to think this can help other SP candidates with a lab structure going forward.<br/><br/>PDF Upload Location =&gt; <a href="http://rapidshare.com/files/304716095/CCIE_SP_Lab_Checklist_v3.pdf" target="_blank" rel="external">http://rapidshare.com/files/304716095/CCIE_SP_Lab_Checklist_v3.pdf</a><br/>]]></description>
		</item>
		
			<item>
			<link>http://www.gotoccie.cn/article.asp?id=118</link>
			<title><![CDATA[OSPF in MPLS VPN PE-CE capability vrf-lite]]></title>
			<author>showbay@vip.qq.com(admin)</author>
			<category><![CDATA[VPN]]></category>
			<pubDate>Sat,21 Nov 2009 08:13:42 +0800</pubDate>
			<guid>http://www.gotoccie.cn/default.asp?id=118</guid>
		<description><![CDATA[We have two features doing the same thing - Down BIT and Route Tag. They both are used to prevent routing loops to occur in case that carrier is cross connected to customer&#39;s network (check my ASCI &#34;art&#34; below).<br/><br/> <br/>(CE-A) ------- (PE-1)<br/>&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br/>&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;{AS127 MPLS}<br/>&nbsp;&nbsp; |&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; |<br/>(CE-B) ------- (PE-2)<br/><br/> <br/><br/>Okay, but why do we need two options for that you may ask - well it&#39;s because of LSA type design. When OSPF advertise link state messages, it encloses them into different types of LSA messages. When we have PE-CE routing, PE1 receives the announces from the CE-A , sets them appropriate extended communities and pass them through the next PE. When the PE-2 receives the mBGP up&#100;ate, it checks the provided information in BGP messages regarding this prefix. There is information such Area, DomainID, RouterID and etc. When the PE-2 ins&#101;rts those prefixes/routes into the appropriate VRF, it sets the &#34;OSPF Down BIT&#34; in o&#114;der to prevent routing loops. When the other router (PE-1) receives the LSA with the down bit set, it does not redistribute the route back into MP-BGP. So far so good, but why do we have two different options (Down bit and Router tag) when they both are using for the same thing? It&#39;s because of OSPF messages. The LSA type 5 (external routes) doesn&#39;t have an option field. Since we don&#39;t have it, we can&#39;t set it Therefore we need another technique to inform the PE that this LSA has already been redistributed and it doesn&#39;t need to turns back again and forming a routing loops. Here it comes the &#34;Router tag&#34;. It uses the ospf External Route Tag field which is part of LSA type 5 message. This is a 32 bit value which has four highest bits set to 1101 (according to RFC 1745) and the lowest 16 bits are used to identify (actually to MAP) the BGP AS of the PE router. It looks something like this: External Route Tag: 3489661055 (if you check your OSPF external database). If you turn this into binary, you&#39;ll get 11010000000000000000000001111111. Here we have highest bits set to 1101000000000000 and lower bits set to 0000000001111111. Now let turn this back to a decimal value 0000000001111111 = 127. Now we know the AS which has imported this route into the OSPF database. So next-time when the PE router receives an ospf LSA5 up&#100;ate which contains this tag - the message well be ignored and wouldn&#39;t be redistributed back to the BGP. There is one more thing. When you&#39;re using BGP to carry customer&#39;s OSPF traffic, the customer both ends received up&#100;ates as LSA type3 (Inter-area Summary). There is something else - called the DomainID. It&#39;s not used for any preventions, it&#39;s used to handle OSPF behavior. When PE routers establish OSPF connectivity between each other (on both sites) the &#34;ospf proccess id&#34; which is used in the provider&#39;s network is important to bo equal on both sites. If it differs, the route will be exported into the customer&#39;s OSPF as E2 (ospf external) not as Inter area (IA) type. So, to your first question - vrf-lite capability. What this command do, is to tell the router NOT to concern about any of theese techniques, but to proceed redistribution proccess as usual routing-to-routing protocol redistribution.<br/><br/><br/>Here you are an URL address when you can check what you&#39;re looking for:<br/><a href="http://www.cisco.com/en/US/docs/ios/iproute/command/reference/irp_osp1.html" target="_blank" rel="external">http://www.cisco.com/en/US/docs/ios/iproute/command/reference/irp_osp1.html</a>#wp1012376 <br/><br/>The commands which are helpfull for troubleshooting are:<br/><br/> <br/>show ip ospf summary - check for the DownBit set in Options field as Downward<br/>show ip ospf database external - check the external route tag if available<br/>show ip bgp vpnv4 all &lt;prefix&gt; - check the DomainID which is set to the prefix as extended community<br/><br/>Danail Petrov<br/><a href="https://learningnetwork.cisco.com/thread/6097?tstart=0" target="_blank" rel="external">https://learningnetwork.cisco.com/thread/6097?tstart=0</a>]]></description>
		</item>
		
</channel>
</rss>
