ãã¹ãŠã®åé¡
8.æå°ã®ãããã¯ãŒã¯ã ããŒããšã€ãã BGPããã³IP SLA
7.æå°ã®ãããã¯ãŒã¯ã ããŒã7ã VPN
6.æå°ã®ãããã¯ãŒã¯ã ããŒã6 åçã«ãŒãã£ã³ã°
5.æå°ã®ãããã¯ãŒã¯ïŒããŒã5ã NATããã³ACL
4.æå°ã®ãããã¯ãŒã¯ïŒããŒã4ã STP
3.æå°ã®ãããã¯ãŒã¯ïŒããŒã3ã éçã«ãŒãã£ã³ã°
2.æå°ã®ãããã¯ãŒã¯ã ããŒã2 æŽæµ
1.æå°ã®ãããã¯ãŒã¯ã ããŒã1 Ciscoæ©åšã«æ¥ç¶ãã
0.æå°ã®ãããã¯ãŒã¯ã ããŒããŒãã èšç»äž
7.æå°ã®ãããã¯ãŒã¯ã ããŒã7ã VPN
6.æå°ã®ãããã¯ãŒã¯ã ããŒã6 åçã«ãŒãã£ã³ã°
5.æå°ã®ãããã¯ãŒã¯ïŒããŒã5ã NATããã³ACL
4.æå°ã®ãããã¯ãŒã¯ïŒããŒã4ã STP
3.æå°ã®ãããã¯ãŒã¯ïŒããŒã3ã éçã«ãŒãã£ã³ã°
2.æå°ã®ãããã¯ãŒã¯ã ããŒã2 æŽæµ
1.æå°ã®ãããã¯ãŒã¯ã ããŒã1 Ciscoæ©åšã«æ¥ç¶ãã
0.æå°ã®ãããã¯ãŒã¯ã ããŒããŒãã èšç»äž
ãããŸã§ã®ãšãããVLANãéçã«ãŒããOSPFãªã©ãç¬èªã®æ¹æ³ã§èª¿çããŸããã ç°å¢ã«ããããåŠçãã匷åãªãšã³ãžãã¢ãŸã§ãèªãã®äžã«ã¹ã ãŒãºã«æé·ããŠããŸãã
ããŠããããã®ããã¡ããèã«çœ®ããŠãBGPã®æéã§ãã
ä»æ¥ã¯
- BGPãããã³ã«ãç解ããŠããŸãïŒã¿ã€ããå±æ§ãåäœåçãæ§æ
- BGPãä»ããŠãããã€ããŒã«æ¥ç¶ããŸã
- è€æ°ã®ãªã³ã¯éã®äºçŽãšè² è·åæ£ãæŽçããŸã
- BGPã䜿çšããã«ããã¯ã¢ãããªãã·ã§ã³ãæ€èšãã-IP SLA
ãŸããåçã«ãŒãã£ã³ã°ãããã³ã«ã®åºæ¬ãæŽæ°ããŸãããã
ãããã³ã«ã«ã¯ãIGPïŒèªåŸã·ã¹ãã ã®å éšïŒãšEGPïŒå€éšïŒã®2çš®é¡ããããŸãã
ã©ã¡ãããDVïŒDistance VectorïŒãšLSïŒLink StateïŒã®2ã€ã®ã¢ã«ãŽãªãºã ã®ããããã«äŸåããŠããŸãã
ãã§ã«å éšã®ãã®ãæ€èšããŠããŸãã ãããã«ã¯ãISIS / OSPF / RIP / EIGRPãå«ãŸããŸãã ãããã¯ããããã¯ãŒã¯å ã§ã«ãŒãã£ã³ã°æ å ±ã確å®ã«é ä¿¡ããããã«å¿ èŠã§ãã
EGPã¯ãBGP-Border Gateway Protocolã®1ã€ã®ãããã³ã«ã®ã¿ãè¡šããŸãã ç°ãªããããã¯ãŒã¯ïŒèªåŸã·ã¹ãã ïŒéã§ã«ãŒãã確å®ã«è»¢éããããã«èšèšãããŠããŸãã
倧ãŸãã«èšãã°ãBalagan Telecomãšãã®ã¢ãããªã³ã¯ãããã€ããŒéã®æ¥ç¶ã¯ãBGPãä»ããŠæ£ç¢ºã«ç·šæãããŸãã
ã€ãŸããã¢ããªã±ãŒã·ã§ã³ã¹ããŒã ã¯ããã次ã®ãšããã§ãã
èªåŸã·ã¹ãã -AS
BGPã¯ãèªåŸã·ã¹ãã ïŒAS-èªåŸã·ã¹ãã ïŒã®æŠå¿µãšå¯æ¥ã«ãªã³ã¯ããŠããŸããèªåŸã·ã¹ãã ã¯ããã§ã«ãµã€ã¯ã«ã§è€æ°åèŠãããŠããŸãã
Wikiã®å®çŸ©ã«ããã°ãASã¯ãã€ã³ã¿ãŒããããšå ±éã®ã«ãŒãã£ã³ã°ããªã·ãŒãæã€1ã€ä»¥äžã®ãªãã¬ãŒã¿ãŒã«ãã£ãŠç®¡çãããIPãããã¯ãŒã¯ãšã«ãŒã¿ãŒã®ã·ã¹ãã ã§ãã
å°ãããããããããããã«ãããšãã°ãéœåžãèªåŸã·ã¹ãã ã§ãããšæ³åã§ããŸãã 2ã€ã®éœåžãé«ééè·¯ã§çžäºæ¥ç¶ãããŠããããã«ã2ã€ã®ã¹ããŒã«ãŒãBGPã§çžäºæ¥ç¶ãããŠããŸãã åæã«ãåéœåžã«ã¯ç¬èªã®éè·¯ã·ã¹ãã -IGPããããŸãã
è¿è·é¢ããèŠããšæ¬¡ã®ããã«ãªããŸãã
BGPã§ã¯ãASã¯äŸ¿å®äžã®åãªãæœè±¡çãªãã®ã§ã¯ãããŸããã ãã®ããšã¯éåžžã«åœ¢åŒåãããŠããã瀟äŒä¿ééšéã«ã¯ç¹å¥ãªãŠã£ã³ããŠããããå¹³æ¥9ãã6ã«èªåŸã·ã¹ãã ã®çªå·ãååŸã§ããŸãã ãããã®çªå·ã¯ãRIRïŒRegional Internet RegistryïŒãŸãã¯LIRïŒLocal Internet RegistryïŒã«ãã£ãŠçºè¡ãããŸãã
äžè¬ã«ã IANAã¯ãããã°ããŒãã«ã«è¡ããŸãã ãããã圌女ãåŒãè£ãããªãããã«ã圌女ã¯ä»äºãå§ä»»ããŸãRIRã¯å°åçµç¹ã§ããããããããå°çã®ç¹å®ã®éšåãæ åœããŠããŸãïŒãšãŒããããšãã·ã¢ã®å Žåã¯RIPE NCCïŒ
å¿ èŠãªææžãæã€ã»ãšãã©ãã¹ãŠã®çµç¹ãLIRã«ãªãããšãã§ããŸãã RIRãLinkMiApã®ãããªå°èŠæš¡ãªãã£ã¹ããã®èŠæ±ã«è² æ ããããå¿ èŠããªãããã«ããããã«å¿ èŠã§ãã
ããšãã°ãBalagan-Telecomã¯LIRã«ãªãå¯èœæ§ããããŸãã ãããŠã圌ããASNïŒACçªå·ïŒ-64500ãªã©ãåããŸããã ãããŠã圌èªèº«ãAS 64501ãæã£ãŠããŸãã
2007幎ãŸã§ã¯ã16ãããã®ASçªå·ãã䜿çšã§ããŸããã§ãããã€ãŸããåèš65,536åã®çªå·ã䜿çšå¯èœã§ããã 0ããã³65535ã¯äºçŽãããŠããŸãã
64512ãã65534ãŸã§ã®çªå·ã¯ãã°ããŒãã«ã«ã«ãŒãã£ã³ã°ãããªããã©ã€ããŒãASïŒãã©ã€ããŒãIPã¢ãã¬ã¹ãªã©ïŒçšã§ãã
çªå·64496-64511-䜿çšããäŸãšããã¥ã¡ã³ãã§äœ¿çšããŸãã
32ãããASçªå·ã䜿çšã§ããããã«ãªããŸããã ãã®ç§»è¡ã¯ãIPv4-> IPv6ãããã¯ããã«ç°¡åã§ãã
ç¹°ãè¿ããŸãããIPã¢ãã¬ã¹ã®ãããã¯ã«çžãããã«èªåŸã·ã¹ãã ã«ã€ããŠè©±ãããšã¯ã§ããŸããã å®éã«ã¯ãã¢ãã¬ã¹ã®ãããã¯ãåASã«é¢é£ä»ããå¿ èŠããããŸãã
PIããã³PAã¢ãã¬ã¹
ç§ã®ããã®è¥ãã®ãšããç§ãã¡ã®LIRãšã®å¥çŽãèªãã§ããéãç§ã¯IPã¢ãã¬ã¹ãæ£ããæžãããšãã§ããªãã£ããããŒãžã£ãŒãç¬ããŸããããPIã¢ãã¬ã¹ããšããèšèãããã¹ãã«çŸããŸããã
ç¥ã«æè¬ããç§ã¯ãã®è³ªåãã°ãŒã°ã«ããå¿ãæã£ãŠãã
å®éãPIã¯ãããã€ããŒéäŸåã§ãã
éåžžã®ç¶æ³ã§ã¯ããããã€ããŒã«æ¥ç¶ãããšããããªãã¯ã¢ãã¬ã¹ã®ç¯å²ãããããPAã¢ãã¬ã¹ïŒãããã€ããŒéçŽå¯èœïŒãæäŸãããŸãã
ããããåãåãããšã¯åãªãã€ã°ã§ãããLIRã§ãªãå Žåã¯ããããã€ããŒãå€æŽãããšãã«PAã¢ãã¬ã¹ãè¿ãå¿ èŠããããŸãã ããã«ãå®éã«ã¯1ã€ã®ãããã€ããŒã®ã¿ã«æ¥ç¶ã§ããŸãã
ãããŠããããã€ããŒãå€æŽããããšã«ããå Žåãå€ãã¢ãã¬ã¹ã¯åœŒã«æ®ãããæ°ãããããã€ããŒã¯æ°ããã¢ãã¬ã¹ãçºè¡ããŸãã ããŠãæè»æ§ã¯ã©ãã«ãããŸããïŒ
LIRããã¯ãPover-Independent Address BlockïŒPIïŒãè³Œå ¥ã§ãã å¿ ç¶çã« ASNãè³Œå ¥ã§ããŸãã ãã®å Žåããããã¯100.0.0.0/23ãšããBGPã§ãã€ããŒã«éç¥ããŸãã ãããŠããããã®ã¢ãã¬ã¹ã¯ãã§ã«çŽç²ã«ç§ãã¡ã®ãã®ã§ããããããã€ããŒã¯ç§ãã¡ãæãã£ãŠããŸãããç§ãã¡ã¯äžæ¹ã奜ãã§ã¯ãããŸããã§ããã
PIã¢ãã¬ã¹ã®ååŸã¯ãã€ãŠãªãã»ã©å®¹æã«ãªããŸããã å€ãã®ããã¥ã¡ã³ããæºåãããã®ãããªãããã¯ã®å¿ èŠæ§ãæ£åœåããå¿ èŠããããŸãã
çŸåšãIPv4ã®æ¯æžã«ããã倧ããªãããã¯ãååŸããããšã¯é£ãããªã£ãŠããŸãã RIRã¯ããããçºè¡ããªããªããLIRã¯åŸè ãé åžããŸãã
ãããã£ãŠãåããªãã£ã¹ã§ASçªå·ãšPIã¢ãã¬ã¹ã®äž¡æ¹ãååŸã§ããŸãã
ãã®ãã¡ãŒã ããã¹ãŠåãåã£ãããRIPEããŒã¿ããŒã¹ã«å€æŽãå ããå¿ èŠããããŸãã ãã®ããžãã¹ã¯é¢åã§å°é£ã§ãããç解ããã®ã«é·ãæéãããããŸãã
RIPEããŒã¿ããŒã¹ã®ãªããžã§ã¯ãã«é¢ããç°¡åãªèª¬æã次ã«ç€ºããŸãã
ãã®å ŽåãLinkMiApãã¢ãã¬ã¹ãããã¯100.0.0.0/23ããã³AS 64500ãåä¿¡ãããšä»®å®ããŸããé¡æšã«æ»ã£ãŠãéœåžã«ååãä»ããããŸããŸãªã€ã³ããã¯ã¹ãæäŸããŸããã
ãã®ãããã¯ã«é¢ããå¥ã®èšäº ã
ç°¡åãªFAQ
BGP
ãã®ããããããã®ãããªãã¯ã¢ãã¬ã¹ã«é¢ããæ å ±ãASããå¥ã®ASïŒã€ã³ã¿ãŒãããã§èªã¿åãããïŒã«è»¢éããããã«ãBGPã䜿çšãããŸãã ãããŠãYandexãŸãã¯Microsoftãäœããã®å€©äœãã¯ãããžãŒã䜿çšããŠããŒã¿ã»ã³ã¿ãŒãã€ã³ã¿ãŒãããã«æ¥ç¶ããŠãããšæãå Žåãããªãã¯ééã£ãŠããŸã-ãã¹ãŠåãBGPã
ããŠãåå¿è ã«ãšã£ãŠåžžã«èå³æ·±ãäž»ãªè³ªåïŒãªãBGPãªã®ããæªåé«ãOSPFãéçãªãã®ãããšããªãã®ãïŒ
ãããã倧åç¶ã¯ãããéåžžã«è©³çŽ°ãã€åŸ¹åºçã«èª¬æã§ãããããããŸããããè¡šé¢çãªç解ãäžããããšããŸãã
-OSPF / IS-ISãšããã°ããããã¯ïŒæ³šæïŒïŒåã«ãŒã¿ãŒããããã¯ãŒã¯å šäœã®ããããžãç¥ã£ãŠããããšãæå³ãããªã³ã¯ç¶æ ã¢ã«ãŽãªãºã ã§ãã ã€ã³ã¿ãŒãããäžã®äœçŸäžãã®ã«ãŒã¿ãŒãæ³åããŠããããã®ç®çã®ããã«ãªã³ã¯ç¶æ ãäžè¬çã«äœ¿çšãããšããèããæšãŠãŠãã ããã
äžè¬ã«ããšãªã¢éã®ã«ãŒãã£ã³ã°æã®OSPFã¯ãå®éã«ã¯è·é¢ãã¯ãã«ãããã³ã«ã§ãã ä»®ã«ãã°ããŒãã«ã«ãŒãã£ã³ã°ã®èŠ³ç¹ãããASããããšãªã¢ãã«çœ®ãæããããšãã§ããŸãããOSPFã¯ãã®ãããªå€§éã®ã«ãŒãã£ã³ã°æ å ±ãæ¶åããããã«èšèšãããŠããããã€ã³ã¿ãŒãããäžã®ãšãªã¢0ãéé¢ããããšã¯äžå¯èœã§ãã
RIPãEIGRP ... Khe-kheã ããŠãããã§ã¯ãã¹ãŠãæ確ã§ãã
-IGPã¯èŠªå¯ãªãã®ã§ãããåºäŒããã¹ãŠã®ISPã«èŠããããšã¯äŸ¡å€ããããŸããã ASããªããŠããã¯ã©ã€ã¢ã³ãããããã€ããŒã§IGPãäžããç¶æ³ã¯éåžžã«ãŸãã§ãïŒL3VPNãé€ãïŒã å®éãIGPã«ã¯ååãªæè»æ§ã®ããã«ãŒã管çã·ã¹ãã ããããŸãã-LSãããã³ã«ã®å Žåãäžè¬çã«ãã¹ãŠãŸãã¯äœãç¥ããªãããšã§ãïŒããã§ãããŸãŒã³ã®å¢çã§ãã£ã«ã¿ãªã³ã°ã§ããŸãããæè»æ§ã¯ãããŸããïŒã
ãã®çµæããã©ã€ããŒããããã¯ãŒã¯ã®é ãããéšåãä»ã®äººã«å ¬éããããç°ãªãIGPããã»ã¹éã§ããªãããŒãªã€ã³ããŒãããªã·ãŒãèšå®ããå¿ èŠãããããšãããããŸããã
-çŸåšãã€ã³ã¿ãŒãããã«ã¯450,000以äžã®ã«ãŒãããããŸãã OSPF / ISISã§ãããã€ã³ã¿ãŒãããããããžå šäœãä¿åã§ããå ŽåãSPFã¢ã«ãŽãªãºã ã«ãããæéãæ³åããŠãã ããã
以äžã¯ãã°ããŒãã«ãªãã®ãèŠæ±ãããå Žæã§IGPã䜿çšããããšãå±éºãªå Žåã®è¯ãäŸã§ã ã
ãããã£ãŠãASéã®çžäºäœçšã«ã¯ç¬èªã®ç¹å¥ãªãããã³ã«ãå¿ èŠã§ãã
ãŸãã è·é¢ãã¯ãã«ã§ãªããã°ãªããŸãã-ããã¯äžæã§ãã ã«ãŒã¿ãŒã¯ãã€ã³ã¿ãŒãããäžã®åãããã¯ãŒã¯ãžã®ã«ãŒããèšç®ããå¿ èŠã¯ãããŸãããããã€ãã®æšå¥šããããã®ã®1ã€ãéžæããã ãã§ãã
次ã«ãéåžžã«æè»ãªã«ãŒããã£ã«ã¿ãªã³ã°ã·ã¹ãã ãå¿ èŠã§ãã è¿æã®äººãã¡ãäœãç §ãããäœãå°å±ããæã¡åºããŠã¯ãªããªãããç°¡åã«å€æããå¿ èŠããããŸãã
第äžã«ãããã¯å®¹æã«ã¹ã±ãŒã©ãã«ã§ãªããã°ãªããã ã«ãŒãã«å¯Ÿããä¿è·ãš ã«ãŒãã®åªå é äœã管çããã·ã¹ãã ãæããªããã°ãªããŸããã
第åã«ã é«ãå®å®æ§ãå¿ èŠã§ãã çµè·¯ããŒã¿ã¯åžžã«å質ãä¿èšŒãããŠãããšã¯éããªãç°å¢ïŒå°ãªããšã2ã€ã®çµç¹ããžã£ã³ã¯ã·ã§ã³ãæ åœããŠããïŒãä»ããŠéä¿¡ããããããçµè·¯æ å ±ã®æ倱ã®å¯èœæ§ãæé€ããå¿ èŠããããŸãã
第5ã«ãASãä»äººãšåºå¥ããããã«ãASãç解ããå¿ èŠããããŸãã
äŒãïŒ BGP
äžè¬ã«ããã®çã«å£®å€§ãªãããã³ã«ã®äœæ¥ã®èª¬æã2ã€ã®éšåã«åå²ããŸãã ãããŠä»æ¥ã¯åºæ¬çãªãã€ã³ããæ€èšããŸãã
BGPã¯IBGPãšEBGPã«åãããŠããŸãã
IBGP㯠ãåäžã®èªåŸã·ã¹ãã å ã§BGPã«ãŒãã転éããããã«å¿ èŠã§ãã ã¯ããBGPã¯å€ãã®å ŽåAS å ã§èµ·åãããŸãã ãããã«ã€ããŠã¯åŸã§å°ã説æããŸãã
EBGPã¯ãèªåŸã·ã¹ãã éã®éåžžã®BGPã§ãã ãã®äžã§åæ¢ããŸãã
BGPã»ãã·ã§ã³ã®ç¢ºç«ãšã«ãŒã亀ææé
ãããã€ããŒã²ãŒããŠã§ã€ã«çŽæ¥æ¥ç¶ããŠããå žåçãªç¶æ³ãèããŠã¿ãŸãããã
BGPã»ãã·ã§ã³ã確ç«ãããããã€ã¹ã¯ãBGPãã¢ãŸãã¯BGPãã€ããŒãšåŒã°ããŸãã
BGPã¯ãã€ããŒãèªåçã«æ€åºããŸããâåãã€ããŒã¯æåã§æ§æãããŸãã
è¿é£é¢ä¿ã確ç«ããããã»ã¹ã¯æ¬¡ã®ãšããã§ãã
IïŒ BGPè¿é£ã®åæç¶æ ã¯IDLEã§ãã äœãèµ·ããŠããŸããã
BGPãã€ããŒãžã®ã«ãŒãããªãå ŽåãBGPã¯IDLEç¶æ ã«ãªããŸãã
IIïŒ BGPã¯TCPã䜿çšããŠä¿¡é Œæ§ã確ä¿ããŸãã
ããã¯ãçè«çã«ã¯BGPãã¢ãçŽæ¥æ¥ç¶ããã®ã§ã¯ãªããããšãã°æ¬¡ã®ããã«æ¥ç¶ã§ããããšãæå³ããŸãã
ãã ãããããã€ããŒã«æ¥ç¶ããå ŽåãååãšããŠãçŽæ¥æ¥ç¶ãåŒãç¶ã䜿çšããããããçŽæ¥æ¥ç¶ãããŠãããããè¿é£ãžã®ã«ãŒãã¯åžžã«ããã«ãããŸãã
BGPã«ãŒã¿ãŒïŒBGPã¹ããŒã«ãŒ/ã¹ããŒã«ãŒãŸãã¯BGPã¹ããŒã«ãŒãšãåŒã°ããïŒã¯ã179çªç®ã®TCPããŒãããªãã¹ã³ããŠéä¿¡ããŸãã
ãªãã¹ã³ããŠãããšããããã¯CONNECTç¶æ ã§ãã BGPã¯ããçæéãã®ç¶æ ã«ãããŸãã
éä¿¡ããããã€ããŒããã®å¿çãåŸ æ©ããŠããå Žåãããã¯ACTIVEç¶æ ã§ãã
R1ã¯TCP SYNããã€ããŒã®ããŒã179ã«éä¿¡ããTCPã»ãã·ã§ã³ãéå§ããŸãã
R2ã¯TCP ACKãè¿ããŸãã圌ãã¯èšããç§ã¯ãã¹ãŠãåŸããç§ã¯TCP SYNã«åæããŸãã
R1ã¯ãR2ããSYNãåä¿¡ããããšãå ±åããŸãã
ãã®åŸãTCPã»ãã·ã§ã³ã確ç«ãããŸãã
ACTIVEç¶æ ã§ã¯ãBGPãããªãŒãºããå ŽåããããŸã
- R2ãšã®IPæ¥ç¶ãªã
- BGPã¯R2ã§å®è¡ãããŠããŸãã
- ããŒã179ã¯ACLã«ãã£ãŠéããããŸã
倱æããTCPã»ãã·ã§ã³ã®äŸã次ã«ç€ºããŸãã BGPã¯ACTIVEç¶æ ã«ãªããæã IDLEã«åãæ¿ãããåã³å ã«æ»ããŸãã
R1ããR2ã«éä¿¡ãããTCP SYNã
BGPã¯R2ã§å®è¡ãããŠããããR2ã¯SYNãR1ããã³RSTããåä¿¡ãããããšã瀺ãACKãè¿ããŸããã€ãŸããæ¥ç¶ããªã»ããããå¿ èŠããããŸãã
å®æçã«ãR1ã¯TCPã»ãã·ã§ã³ã®ç¢ºç«ãåè©Šè¡ããŸãã
ç§ãç°å¢ã«ããããé ãç§ããããã€ããŒãšæåã«BGPãã¢ãªã³ã°ãèšå®ãããšããç§ã¯åæ¥ãããŠåé¡ãæ¢ããŸããã BGPãã©ã®ããã«èšå®ãããŠããã®ãæ¬åœã«ç¥ããŸããã§ããããèšå®ã®ãšã©ãŒãæ¢ããŸãããèªåã®ç¶æ³ã«åŸ®åŠãªç¹ããããšæã£ãã®ã§ããã§ã«ã³ãã¥ããã£ã«ã€ããŠèªã¿å§ããŸããã ãããæåŸã«ããããã¯ãŒã¯ã®å ¥ãå£ã§ACLã確èªãããšããæããèããæµ®ãã³ãŸããã ã¯ãããããã€ããŒã®TCPãªã¯ãšã¹ãã¯æåŠãããã»ãã·ã§ã³ã¯ç¢ºç«ãããŸããã§ããã
泚æããŠãã ããã ãããã€ããŒã¯ãACLã®ãäžçãã«åºå·ãããã¹ãŠã®å€éšã€ã³ã¿ãŒãã§ã€ã¹ã«åºå·ããããšãäžè¬çã§ãã
IIIïŒ TCPã»ãã·ã§ã³ã確ç«ãããåŸãBGPã¹ããŒã«ãŒã¯OPENã¡ãã»ãŒãžã³ã°ãéå§ããŸãã
OPENã¯ãBGPã¡ãã»ãŒãžã®æåã®ã¿ã€ãã§ãã ãã©ã¡ãŒã¿ããŽã·ãšãŒã·ã§ã³ã®ããã«ãBGPã»ãã·ã§ã³ã®æåã«ã®ã¿éä¿¡ãããŸãã
ãããã³ã«ããŒãžã§ã³ãASçªå·ãããŒã«ãã¿ã€ããŒãã«ãŒã¿ãŒIDãéä¿¡ããŸãã BGPã»ãã·ã§ã³ãç«ã¡äžããã«ã¯ã次ã®æ¡ä»¶ãæºããããŠããå¿ èŠããããŸãã
- ãããã³ã«ããŒãžã§ã³ã¯åãã§ããå¿ èŠããããŸãã ç°ãªãå¯èœæ§ã¯äœã
- OPENã¡ãã»ãŒãžã®ASçªå·ã¯ããªã¢ãŒãåŽã®èšå®ãšäžèŽããå¿ èŠããããŸã
- ã«ãŒã¿ãŒIDã¯ç°ãªãå¿ èŠããããŸã
ãŸããäžéšã§ã¯ãã«ãŒã¿ãŒãè¿œå ã®ãããã³ã«æ©èœããµããŒãããŠãããã©ããã確èªã§ããŸãã
R1ããOPENãåä¿¡ãããšãR2ã¯OPENãšKEEPALIVEãéä¿¡ããR1ããOPENãåä¿¡ããããšã瀺ããŸããããã¯ãR1ã次ã®ç¶æ ã«ç§»è¡ããããã®ä¿¡å·ã§ã-確ç«æžã¿ã
ãã©ã¡ãŒã¿ãŒã®äžäžèŽã®äŸã次ã«ç€ºããŸãã
aïŒäžæ£ãªAS ïŒAS 300ã¯R2ã§èšå®ãããŸãããR1ã§ã¯ããã®ãã€ããŒã¯AS 200ã«ãããšèŠãªãããŸãïŒïŒ
R2ã¯éåžžã®OPENãéä¿¡ããŸã
R1ã¯ãã¡ãã»ãŒãžå ã®ASãæ§ææžã¿ã®ASãšäžèŽããªãããšã«æ°ä»ãã NOTIFICATIONã¡ãã»ãŒãžãéä¿¡ããŠã»ãã·ã§ã³ããªã»ããããŸã ã ã»ãã·ã§ã³ãäžæããããã«åé¡ãçºçããå Žåã«éä¿¡ãããŸãã
ãã®å ŽåãR1ã³ã³ãœãŒã«ã«æ¬¡ã®ã¡ãã»ãŒãžã衚瀺ãããŸãã
bïŒåãã«ãŒã¿ãŒID
R2ã¯OPENã«ãŒã¿ãŒIDãéä¿¡ããŸããããã¯R1 IDãšåãã§ãã
R1ã¯NOTIFICATIONãè¿ããŸãã
åæã«ã次ã®ã¡ãã»ãŒãžãã©ã³ãã³ã³ãœãŒã«ã«è¡šç€ºãããŸãã
ãããã®ãšã©ãŒã®åŸãBGPã¯æåã«ã¢ã€ãã«ç¶æ ã«ãªãã次ã«ã¢ã¯ãã£ãç¶æ ã«ãªããTCPã»ãã·ã§ã³ãå確ç«ããŠããOPENã¡ãã»ãŒãžãå床亀æããããšããŸãããçªç¶ãäœããå€æŽãããŸãããïŒ
Openã¡ãã»ãŒãžãéä¿¡ããããšãããã¯OPEN SENTç¶æ ã«ãªããŸãã
åä¿¡ãããšãããã¯OPEN CONFIRMã®ç¶æ ã§ãã
ããŒã«ãã¿ã€ããŒãç°ãªãå Žåãæå°ã®ãã®ãéžæãããŸãã ããŒãã¢ã©ã€ãã¿ã€ããŒã¯OPENã¡ãã»ãŒãžã§éä¿¡ãããªããããèªåçã«èšç®ãããŸãïŒHold Timer / 3ïŒã ã€ãŸããããŒãã¢ã©ã€ãã¯ãã€ããŒã«ãã£ãŠç°ãªãå ŽåããããŸã
次ã«äŸã瀺ããŸããR2ã§ã¯ãã¿ã€ããŒã¯æ¬¡ã®ããã«æ§æãããŸããããŒãã¢ã©ã€ã30ãããŒã«ã170ã
R2ã¯ãããã®ãã©ã¡ãŒã¿ãŒãOPENã¡ãã»ãŒãžã§éä¿¡ããŸãã R1ã¯ãããååŸããŠæ¯èŒããŸããåä¿¡ããå€ã¯170ãç¬èªã®180ã§ããå°ããæ¹ã®å€-170ãéžæããããŒãã¢ã©ã€ãã¿ã€ããŒãèšç®ããŸãã
ããã¯ãR2ãããŒãã¢ã©ã€ãã30ç§ããšã«éä¿¡ããR1-56ãéä¿¡ããããšãæå³ããŸããããããæãéèŠãªããšã¯ããããã¯åãããŒã«ãã¿ã€ããŒãæã¡ãäºåã«ã»ãã·ã§ã³ãäžæããªãããšã§ãã
OPENSENTãŸãã¯OPENCONFIRMã®ç¶æ ã確èªããããšã¯ã»ãšãã©äžå¯èœã§ããBGPã¯ããããä¿æããŸããã
IVïŒããããã¹ãŠã®ã¹ãããã®åŸããããã¯ESTABLISHEDã®å®å®ç¶æ ã«ç§»è¡ããŸãã
ããã¯ãBGPã®æ£ããããŒãžã§ã³ãå®è¡ãããŠããããã¹ãŠã®èšå®ã«äžè²«æ§ãããããšãæå³ããŸãã
åãã€ããŒã«ã€ããŠã皌åæé-ESTABLISHEDç¶æ ã«ãªã£ãŠããæéã確èªã§ããŸãã
VïŒ BGPããŒãã«ã«BGPã»ãã·ã§ã³ãã€ã³ã¹ããŒã«ããåŸã®æåã®ç¬éã«ã¯ãããŒã«ã«ã«ãŒãã«é¢ããæ å ±ã®ã¿ã
ã«ãŒãã£ã³ã°æ å ±ã®äº€æã«é²ãããšãã§ããŸãã
ãã®ããã«ã UPDATEã¡ãã»ãŒãžã䜿çšãããŸãã
åUPDATEã¡ãã»ãŒãžã«ã¯ã 1ã€ã®æ°ããã«ãŒãã«é¢ããæ å ±ããŸãã¯å€ãã«ãŒãã®ã°ã«ãŒãã®åé€ã«é¢ããæ å ±ãå«ããããšãã§ããŸãã ãããŠåæã«ã
ãããããã詳现ã«åæããŸãã
R1ã¯R2ã«ã«ãŒãã£ã³ã°æ å ±ãéä¿¡ããŸãã
UPDATEã¡ãã»ãŒãžã®æåã®ãã©ã¹èšå·ã¯ããã¹å±æ§ã§ãã ãããã«ã€ããŠã¯åŸã§è©³ããæ€èšããŸããããã§ã«2ã€ãç解ããŠããå¿ èŠããããŸãã AS_PATHã¯ãã«ãŒãã100ã®ASããæ¥ãããšãæå³ããŸãã
NEXT_HOP-ããã¯ãR2ã®è«ççãªæ å ±ã§ããããã®ã«ãŒãã®ã²ãŒããŠã§ã€ãšããŠæå®ãããã®ã§ãã çè«çã«ã¯ãå¿ ãããã¢ãã¬ã¹R1ããããšã¯éããŸããã
ORIGINå±æ§ã¯ãã«ãŒãã®èµ·ç¹ãå ±åããŸãã
- IGP -networkã³ãã³ãã§æåã§èšå®ããããBGPçµç±ã§åä¿¡ããŸãã!!!!!!!!!!!!!!!!!
- EGP-ãã®ã³ãŒãã¯è¡šç€ºãããŸãããããã¯ãã«ãŒãããEGPããšåŒã°ããå€ããããã³ã«ããååŸããããã¹ãŠã®å Žæã§BGPã«å®å šã«çœ®ãæããããããšãæå³ããŸã
- äžå®å š -ã»ãšãã©ã®å Žåãã«ãŒãã¯åé åžãéããŠåä¿¡ãããããšãæå³ããŸã
2çªç®ã®ãã©ã¹ã¯ãå®éã®ã«ãŒãæ å ±-NLRI-ãããã¯ãŒã¯å±€å°éå¯èœæ§æ å ±ã§ãã å®éã«ã¯ããããã¯ãŒã¯100.0.0.0/23ãããã«ç€ºãããŠããŸãã
ããŠãR2ããR1ã«æŽæ°ããŸãã
次ã®KEEPALIVIEã¯ãæ å ±ãåä¿¡ãããããšã®äžçš®ã®ç¢ºèªã§ãã
ãããã¯ãŒã¯æ å ±ãBGPããŒãã«ã«è¡šç€ºãããŸãã
ãããŠãã«ãŒãã£ã³ã°ããŒãã«ã§ïŒ
BGPã»ãã·ã§ã³ãç¶ç¶ããéãããããã¯ãŒã¯å ã®ãã¹ãŠã®å€æŽã§æŽæ°ãéä¿¡ãããŸãã OSPFãšã¯ç°ãªããã«ãŒãã£ã³ã°ããŒãã«ã®åæã¯è¡ãããªãããšã«æ³šæããŠãã ããã ããã¯æè¡çã«ã¯æããªããšã§ããå®å šãªBGPã«ãŒãããŒãã«ã¯ãåãã€ããŒã§æ°åã¡ã¬ãã€ãã®éãããããŸãã
VIïŒãã¹ãŠãé 調ã«ãªã£ããããåBGPã«ãŒã¿ãŒã¯å®æçã«KEEPALIVEã¡ãã»ãŒãžãéä¿¡ããŸã ã ä»ã®ãããã³ã«ãšåæ§ãããã¯ãç§ã¯ãŸã çããŠããããšããæå³ã§ãã ããã¯ãããŒãã¢ã©ã€ãã¿ã€ããŒã®æéãåãããšãã«çºçããŸã-ããã©ã«ãã¯60ç§ã§ãã
BGPã»ãã·ã§ã³ãæ£åžžã«ç¢ºç«ãããŠãããããã®åŸäžæããäžå®ã®é »åºŠã§ç¹°ãè¿ãããå Žå-ããŒãã¢ã©ã€ãããã¹ããªãããšã確èªããŠãã ããã ã»ãšãã©ã®å Žåããµã€ã¯ã«æéã¯3åã§ãïŒããã©ã«ãã§ã¯ããŒã«ãã¿ã€ããŒïŒã L2ã§åé¡ãæ¢ãå¿ èŠããããŸãã ããšãã°ãéä¿¡å質ã®äœäžãã€ã³ã¿ãŒãã§ã€ã¹ã®èŒ»èŒ³ãCRCãšã©ãŒãªã©ãèããããŸãã
å¥ã®ã¿ã€ãã®BGPã¡ãã»ãŒãž-ã«ãŒãæŽæ° -ã䜿çšãããšãBGPããã»ã¹ãåèµ·åããã«ããã¹ãŠã®ã«ãŒããå床è¿é£ããèŠæ±ã§ããŸãã
ãã¹ãŠã®ã¿ã€ãã®BGPã¡ãã»ãŒãžã®è©³çŽ°ãã芧ãã ãã ã
BGPã®å®å šãªFSM ïŒ ç¶æ ãã·ã³ ïŒã¯æ¬¡ã®ããã«ãªããŸãã
ãããã¯ãŒã¯ã§åã¹ãããã®è©³çŽ°ãªèª¬æãèŠã€ãããŸããã
ããã¯ãã£ã«ã®è³ªåïŒã¢ããã¿ã€ã BGPã»ãã·ã§ã³ã24æéã§ãããšããŸãã éå»12æéã«ã©ã®ã¡ãã»ãŒãžããã€ããŒéã§éä¿¡ãããããšãä¿èšŒãããŠããŸããã§ãããïŒ
次ã«ããã®ãããªãããã¯ãŒã¯ã«èŠéãåºããŸãã
ãµããããã®ãªãåç
ãããŠãã«ãŒã¿R1ã«ããBGPã«ãŒãããŒãã«ãèŠãŠã¿ãŸãããã
ã芧ã®ãšãããã«ãŒãã¯NextHopã ãã§ãªããç®çã®ãµãããããžã®ããã€ã¹ã®ãªã¹ãã ãã§ã¯ãããŸããã ããã¯ASã®ãªã¹ãã§ãã ãã以å€ã®å ŽåãAS-PathãšåŒã°ããŸãã
ã€ãŸãã123.0.0.0 / 24ãããã¯ãŒã¯ã«å ¥ãããã«ã¯ããã±ãããéä¿¡ããAS 200ããã³AS 300ãå æããå¿ èŠããããŸãã
ASãã¹ã¯æ¬¡ã®ããã«åœ¢æãããŸãã
aïŒã«ãŒããASå ãæ©ããŠããéããªã¹ãã¯ç©ºã§ãã ãã¹ãŠã®ã«ãŒã¿ãŒã¯ãåãASããåä¿¡ããã«ãŒããç解ããŸã
bïŒã«ãŒã¿ã¯ãå€éšãã€ããŒãžã®ã«ãŒããã¢ããŠã³ã¹ãããšããã«ãASãã¹çªå·ã«ASçªå·ãè¿œå ããŸãã
cïŒé£æ¥ASå ã§ã¯ããªã¹ãã¯å€æŽããããå ã®ASã®çªå·ã®ã¿ãå«ãŸããŸã
dïŒã«ãŒããé£æ¥ASãããªã¹ãã®å é ã«ããã«è»¢éããããšãçŸåšã®ASçªå·ãè¿œå ãããŸãã
ãªã©ãªã©ã ã«ãŒããå€éšãã€ããŒã«æž¡ããããšãASçªå·ã¯åžžã«ASãã¹ãªã¹ãã®å é ã«è¿œå ãããŸãã ã€ãŸããå®éã«ã¯ãããã¯ã¹ã¿ãã¯ã§ãã
ASãã¹ã¯ãR1ãå®å ãããã¯ãŒã¯ãžã®ãã¹ãç¥ãã ãã§ãªããå®éã«ã¯ãã¯ã¹ããããã§ååã§ããåã«ãŒã¿ãŒã¯ãã«ãŒãã£ã³ã°ããŒãã«ã«åºã¥ããŠæ±ºå®ãè¡ããŸãã å®éãããã§ã¯ããã«2ã€ã®éèŠãªç®æšãè¿œæ±ããŠããŸãã
1ïŒã«ãŒãã£ã³ã°ã«ãŒãã®é²æ¢ã AS-Pathã«ã¯éè€ããçªå·ã䜿çšããªãã§ãã ãã
å®éãAS-Pathã§2ã€ã®å Žåã«ASNãç¹°ãè¿ãããšãã§ããŸã
aïŒä»¥äžã§èª¬æããAS-Path Prependã䜿çšããå Žåã
bïŒäºãã«çŽæ¥æ¥ç¶ãããŠããªããåãASã®2ã€ã®éšåãæ¥ç¶ããå Žåã
2ïŒæé©ãªã«ãŒãã®éžæã ASãã¹ãçãã»ã©ãã«ãŒãã®åªå 床ã¯é«ããªããŸãããããã«ã€ããŠã¯åŸã§è©³ãã説æããŸã
BGPã®ã»ããã¢ãããšå®è·µ
ãã®åé¡ã§ã¯ãçè«ãæãç解ãããããããçè«ãšå®è·µãçµã¿åãããŠããŸãã å®éãLinkMiApãããã¯ãŒã¯ã«ç®ãåããŸãã
ãã€ãã®ããã«ãäžèŠãªãã®ã¯ãã¹ãŠåãåããå¿ èŠãªãã®ãè¿œå ããŸãã
以äžã¯ãã¡ã€ã³ã«ãŒã¿ãŒmsk-arbat-gw1ã§ãã æ§æãšç解ãç°¡çŽ åããããã«ããã¹ãŠã®å€ãèšå®ãšç¡æã®ã€ã³ã¿ãŒãã§ãŒã¹ãæŸæ£ããŸãã
äžèšã®2ã€ã®å€ããããã€ããŒ-Balagan TelecomãšFilkin Certificateã§ãã
ãã¡ãããåãããã€ããŒã«ã¯ç¬èªã®ASããããŸãã ãã1ã€ã®ããããšã³ãASãè¿œå ããŸããããã®åã«ãããšãã°ã€ã³ã¿ãŒãããäžã®ããŒã¿ã»ã³ã¿ãŒã§ãã£ãŠããã§ãã¯ããŸãã
ç°¡åã«ããããã«ãåASã¯1ã€ã®ã«ãŒã¿ãŒã®ã¿ã§è¡šãããACLã¯ãªããäžéããã€ã¹ã¯ãªãããšãåæãšããŠããŸãã
äž¡æ¹ã®ãããã€ããŒãšã®BGPã»ãã·ã§ã³ãçºçãããŠããŸãã
次ã®æ å ±ã¯éèŠã§ãã
1ïŒASçªå·ãšIPã¢ãã¬ã¹ã®ãããã¯ã AS64500ãšãããã¯ïŒ100.0.0.0/23ãæ¢ã«åãåã£ãŠããŸãã
2ïŒAS AS Balagan Telecomçªå·ããã³ãããšã®ãªã³ã¯ãµããããã AS64501ããã³ãªã³ã¯ãããã¯ãŒã¯ïŒ101.0.0.0/30ã
3ïŒASããã£ã«ãã³èšŒææžããšããã«ãªã³ã¯ãããµããããã®çªå·ã AS64502ããã³ãªã³ã¯ãããã¯ãŒã¯ïŒ102.0.0.0/30ã
BGPãä»ããŠæ¥ç¶ããå Žåã/ 30ãµãããããã¹ã¯ã®ãããªãã¯ã¢ãã¬ã¹ã¯éåžžãªã³ã¯ã¢ãã¬ã¹ãšããŠäœ¿çšãããäžäœãããã€ããŒããæäŸãããŸãã
ããã¯ãã©ãã§ããã©ãã£ãã¯ããããªãã¯ã¢ãã¬ã¹ããã©ãããã¬ãŒã¹ã®éäžã§10.X.X.Xã衚瀺ãããªããšããåçŽãªçç±ã§è¡ãããŸãã çŠæ¢ãããŠããããã§ã¯ãããŸããããéåžžã¯ãã®ã«ãŒã«ãé å®ããŠããŸãã
ãããããããå§ããŸãããã
ã€ã³ã¿ãŒãã§ã€ã¹èšå®ïŒ
msk-arbat-gw1 R1(config)#int fa0/0 R1(config-if)#ip address 101.0.0.2 255.255.255.252 R1(config-if)#no shutdown R1(config)#int fa0/1 R1(config-if)#ip address 102.0.0.2 255.255.255.252 R1(config-if)#no shutdown
次ã«ãã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ãã¬ã¹ãå²ãåœãŠãŠãããæ¥ç¶ã確èªããŸãã
R1(config)#int loopback 0 R1(config-if)#ip address 100.0.0.1 255.255.255.255
BGPã®çªã ããã§ã¯ãåè¡ã«çŠç¹ãåœãŠãŸãã
R1(config)#router bgp 64500
æåã«ãBGPããã»ã¹ãéå§ããASçªå·ãæå®ããŸãã ããã¯ãLIRãçºè¡ããçªå·ã§ãã ããã¯OSPFã§ã¯ãããŸãã-èªç±ã¯èš±å¯ãããŠããŸããã
次ã«ããã¢ãªã³ã°ãäžããŸãã
R1(config-router)#neighbor 101.0.0.1 remote-as 64501
neighborã³ãã³ãã䜿çšããŠã誰ãšã»ãã·ã§ã³ã確ç«ããããæå®ããŸãã ã«ãŒã¿ãŒãæåã«TCP-SYNãéä¿¡ãã次ã«OPENããã®ã¯ã¢ãã¬ã¹101.0.0.1ã§ãã ãŸãããªã¢ãŒãèªåŸã·ã¹ãã ã®çªå·-64501ã瀺ãå¿ èŠããããŸãã
èé¢ã®æ§æã¯å¯Ÿç§°çã§ãïŒ
R2(config)#router bgp 64501 R2(config-router)#neighbor 101.0.0.2 remote-as 64500
ãã§ã«1ã€ã®ã¡ãã»ãŒãž
*Mar 1 00:11:12.203: %BGP-5-ADJCHANGE: neighbor 101.0.0.2 Up
BGPãäžæãããšå€æã§ããŸããããã®ã¹ããŒã¿ã¹ã確èªããŸãããã
ããã§ã圌ãã¯ãã¹ãŠã®å·ãé§ãå·¡ããçŸåšã圌ãã®ã¹ããŒã¿ã¹ã¯ç¢ºç«ãããŠããŸãã
ã«ãŒã¿ãŒã¯1ã€ã®OPENãéåä¿¡ãããã®éã«ãã§ã«2ã€ã®ããŒãã¢ã©ã€ããéåä¿¡ã§ããŸããã
sh ip bgpã³ãã³ãã䜿çšãããšã BGPãèªèããŠãããããã¯ãŒã¯ã確èªã§ããŸãã
空ã§ãã ãã®ã°ãªãã100.0.0.0/23ãããããšã瀺ããŠããããã€ããŒã«æž¡ãå¿ èŠããããŸããïŒ
ããã«ã¯3ã€ã®ãªãã·ã§ã³ããããŸãã
-networkã³ãã³ãã§ãããã¯ãŒã¯ãå®çŸ©ãã
-å¥ã®ãœãŒã¹ããã®ã€ã³ããŒãïŒçŽæ¥ãéçãIGPïŒ
-aggregate-addressã³ãã³ãã䜿çšããŠéçŽã«ãŒããäœæããŸã
ä»åŸã®å±æãšããŠããããã¯ãŒã¯ã®åªå 床ãé«ãããšã«æ³šæããŠãã ãããã€ã³ããŒãã§ã¯ãéå°ãéããªãããã«æ³šæããå¿ èŠããããŸãã
R1(config)#router bgp 64500 R1(config-router)#network 100.0.0.0 mask 255.255.254.0
ãããã¯ãŒã¯ãè¡šã«è¡šç€ºãããŠãããã©ããã確èªããŸãã
å¥åŠã ãããããäœãçŸããªãã£ãã R2ã§ãã
ãããŠãåé¡ã¯ã networkã³ãã³ãã§ç»é²ãããããã¯ãŒã¯ãžã®æ£ç¢ºãªã«ãŒãããªããã°ãªããªããšããããšã§ããããã§ãªããã°ãBGPããŒãã«ã«è¿œå ãããŸãã-ããã¯åææ¡ä»¶ã§ãã ãã¡ããããã®ãããªã«ãŒãã¯ãããŸããã 圌ã¯ã©ãããæ¥ãã®ã§ããïŒ
å®éã«ã¯ããã®ãããªã«ãŒããç»é²ããå Žæã¯ãªãã®ã§ã1ã€ã®ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ãé€ãããã®ãããªãããã¯ãŒã¯ã¯ã©ãã«ãååšããªãããã次ã®ããšãã§ããŸãã
R1(config)#ip route 100.0.0.0 255.255.254.0 Null 0
ãã®ã«ãŒãã¯ããã®ãµããããäžã®ãã¹ãŠã®ãã±ãããç Žæ£ãããããšã瀺ããŠããŸãã ããããå¿é ããªãã§ãã ãããéåžžã®æäœã¯éªéãããŸããã ããæ£ç¢ºãªã«ãŒãïŒ/ 23ãããšãã°ã/ 24ã/ 30ã/ 32ããã倧ãããã¹ã¯ïŒãããå Žåãæé·ãã¬ãã£ãã¯ã¹äžèŽã«ãŒã«ã«åŸã£ãŠæšå¥šãããŸãã
ãããŠä»ãBGPããŒãã«ã«ããŒã«ã«ã«ãŒãããããŸãã
ã¹ããŒã ã®ãã¹ãŠã®ããã€ã¹ã§BGPãšå¿ èŠãªã«ãŒããèšå®ãããšãå¢çïŒå¢ç-ãããã¯ãŒã¯å¢çäžã®ã«ãŒã¿ãŒïŒã®BGPãšã«ãŒãã£ã³ã°ããŒãã«ã¯æ¬¡ã®ããã«ãªããŸãã
BGPããŒãã«ã«ã¯ããã€ãã®ãããã¯ãŒã¯ãžã®2ã€ã®ã«ãŒãããããã«ãŒãã£ã³ã°ããŒãã«ã«ã¯1ã€ãããªãããšã«æ³šæããŠãã ããã ã«ãŒã¿ãŒã¯æé©ãªãã®ãéžæããã«ãŒãã£ã³ã°ããŒãã«ã«è»¢éããã ãã§ãã ããã«ã€ããŠã¯åŸã§èª¬æããŸãã
ããã¯å¿ èŠæå°éã§ããããã®åŸã¯ããå°ã幞ãã«ãªããŸãã
=======================
ã¿ã¹ã¯çªå·1
ã¹ããŒã ïŒ
æ¡ä»¶ïŒ
ã«ãŒã¿ãŒã®èšå®ã¯éèŠã§ã¯ãããŸããã ã«ãŒããã£ã«ã¿ã¯èšå®ãããŠããŸããã AS400çµç±ã®ãããã¯ãŒã¯195.12.0.0/16ãžã®ä»£æ¿ã«ãŒããæ¬ èœããŠããã®ã¯ãªãã§ããïŒ
ãµã€ãã§ã®ã¿ã¹ã¯ã®è©³çŽ°
=======================
å®å šãªãã¥ãŒãšããã©ã«ãã«ãŒã
BGPã«ã€ããŠè©±ãããããã€ããŒã«æ¥ç¶ããå Žåããã®ãããã¯ã«è§Šããããšã¯ã§ããŸããã ASãšPIã¢ãã¬ã¹ããã§ã«æã£ãŠããLinkMiApãBalagan-Telecomãšæ¥ç¶ããå Žåããããããã®æåã®è³ªåã®1ã€ã¯ããã«ãã¥ãŒãŸãã¯ããã©ã«ãïŒãã§ãã ããã§ã®äž»ãªããšã¯ãæ··ä¹±ããªãããšããã³ã»ã³ã¹ãåçµããªãããšã§ãã
ãããŸã§ã«èŠãŠããããšããããããã«ãã¥ãŒ-ã«ãŒã¿ãŒã¯ããã®å Žå5åãŸãã¯6åã§ãã£ãŠãã ãã¹ãŠã®ã€ã³ã¿ãŒãããã«ãŒãã絶察ã«åŠç¿ããŸãã å®éã«ã¯ãçŸåš40äžãè¶ ããŠããŸãããããã£ãŠã1ã€ã®ãããã€ããŒãã40äžã®ã«ãŒããåãåãã2çªç®ã®ãããã€ããŒããã¯40äžã®ã«ãŒããåãåããŸãã 3çªç®ã®ããã¯ã¢ããã«å ããŠãããã«400kãããå ŽåããããŸãã åèšã§çŸäžäººä»¥äžã
ããŠããã®ããã ãã«å°ãã¢ã³ããŒãšã³ã¿ãŒãã©ã€ãºtsiskaã·ãã¢ã·ãªãŒãºãè³Œå ¥ããªãã§ãã ããïŒ
*ãããªãã¯ãµãŒããŒã®1ã€ããã®ã«ãŒãã£ã³ã°ããŒãã«ã®åºåïŒtelnet route-server.ip.att.netã§å©çšå¯èœïŒ
å®éãASãæã£ãŠãããã¹ãŠã®äººãå®å šãªãã¥ãŒãå¿ èŠãšããããã§ã¯ãããŸããã éåžžãåœç€Ÿã®ãããªäŒæ¥ã®å Žåãããã©ã«ãã«ãŒãã§ååã§ããååãããããããã«ãéãã¯æããã§ãã åŸè ã®å Žåãæ°åäžã®ç¹å®ã®ã«ãŒãã§ã¯ãªããåãããã€ããŒããããã©ã«ãã«ãŒãã1ã€ã ãéä¿¡ãããŸãïŒäžè¬çã«eãå«ãããšãã§ããŸãïŒã
äž¡æ¹ãæ¯æããå°ããªè°è«ãããŸãããã
- å®å
šãªãã¥ãŒ ã ã€ã³ã¿ãŒãããã®æ§é ã«é¢ããå®å
šã§çŽç²ãªç¥èããããŸãã ã€ã³ã¿ãŒãããäžã®ä»»æã®ã¢ãã¬ã¹ã«ãèªåãããã¹ã衚瀺ã§ããŸãã
ã©ã®ASãããã«ã€ãªããããç¥ã£ãŠããŸãã RIPE Webãµã€ããéããŠãã©ã®ãããã€ããŒããã©ã³ãžãããæäŸããŠãããã確èªã§ããŸãã ãã¹ãŠã®å€æŽã«åŸããŸãã 誰ããæåã®ãªã³ã¯ïŒçªç¶ãããªãããããã€ããŒã§ã¯ãªããããã«å¥ã®å ŽæïŒã«çªç¶èœã¡ãå ŽåãBGPã¯ã«ãŒãã£ã³ã°ããŒãã«ã远跡ããŠåæ§ç¯ãã2çªç®ã®ãããã€ããŒãä»ããŠããŒã¿ã転éããŸãã
åæã«ãã«ãŒããéåžžã«æè»ã«ç®¡çã§ãããããæé©ãªãã¹ãéžæããããã®æšæºçãªæé ã«å¹²æžããŸãã
ããšãã°ãBalagan Telecomãä»ããŠYandexãžã®ãã¹ãŠã®ãã©ãã£ãã¯ãèš±å¯ããFilkin蚌ææžãä»ããŠgoogleãèš±å¯ããŸãã ããã¯ã è² è·åæ£ãšåŒã°ããŸã ã
ããã¯ãããšãã°ãç¹å®ã®ãã¬ãã£ãã¯ã¹ã®ã«ãŒãåªå 床ãèšå®ããããšã«ããå®çŸãããŸãã
ã¹ããŒã«ãŒã移åäžã®å Žåãã€ãŸããBGPãä»ããŠããå€ãã®ã¯ã©ã€ã¢ã³ããæ¥ç¶ããå Žåã¯ããã«ãã¥ãŒãå¿ èŠã§ãã
ãããã®ãã¹ãŠã®å©ç¹ãããã©ãŒãã³ã¹ã§æ¯æãå¿ èŠããããŸããã€ãŸããã¡ã¢ãªäœ¿çšçãé«ããBGPã»ãã·ã§ã³ã確ç«ããåŸã®ã«ãŒãã£ã³ã°æ å ±ã®éåžžã«é·ã調æ»ã§ãã ããšãã°ãäžäœãããã€ããŒãšã®ãªã³ã¯ãããããããåŸãå®å šãªåŸ©æ§ã«ã¯æ°åãããå ŽåããããŸãã
- ããã©ã«ãã«ãŒã
ãŸãããã¡ãããããã«ãããæ©åšã®ãªãœãŒã¹ãå€§å¹ ã«ç¯çŽãããŸãã
第äºã«ãä¿å®ãç°¡åã ãšãã人ããããããããŸããã ASå šäœã§äœåäžãã®ã«ãŒããé転ããå¿ èŠã¯ãããŸããã
第äžã«ãã€ã³ã¿ãŒãããã®ç¶æ ãšåä¿¡è ã®å®éã®å¯çšæ§ã«ã€ããŠã®èãããããŸãããäžæµããåä¿¡ããããã©ã«ããç²ç®çã«åçŽã«ä¿¡é ŒããŸãã ã€ãŸããäžèšã®åé¡ã®å Žåãããªãã¯ããã«ã€ããŠç¥ãããããã€ãã®ãµãŒãã¹ãèœã¡ããããããŸããã ããããããã§ã¯ãããé«ããããã€ããŒã§ã¯ããããã¯ãŒã¯ã®ä¿¡é Œæ§ãæ¡éãã«é«ããå¿é ããå¿ èŠããªãããšãé¡ã£ãŠããŸãã
ããã©ã«ãã§ã«ãŒããåä¿¡ãããšãã®çä¿¡ãã©ãã£ãã¯ã®ãã©ã³ã¹ãšåæ£ã¯ããŸã£ãã圱é¿ãåããŸãã-åé¡ã¯åãã§ãã ãããããã¡ããããã¹ãŠãçºä¿¡ããããšã§ãå°ãç°ãªããŸããã以åã®æè»æ§ã¯ãããããŸããã
äžè¬çã«ãéåžžã«ç¡ç€Œãªã¢ããã€ã¹ã¯æ¬¡ã®ããã«èãããŸãã
èªåã§ãã©ã³ãžãããæŽçããäºå®ããªãïŒã¯ã©ã€ã¢ã³ããã¹ããŒã«ãŒã«æ¥ç¶ããïŒãçºä¿¡ãã©ãã£ãã¯ã现ããåé ããå¿ èŠããªãå Žåã¯ãããã©ã«ãã«ãŒãã§ååã§ãã
ãã ãããããããã€ããŒãããã«ãã¥ãŒãåãå ¥ããå¥ã®ãããã€ããŒããããã©ã«ããåãå ¥ããããšã¯ç¢ºãã«æå³ããããŸããããã®å Žåãã«ãŒã¿ãŒã¯ããå ·äœçãªãã¹ãéžæãããããçºä¿¡ãã©ãã£ãã¯ã§åžžã«1ã€ã®ãªã³ã¯ãã¢ã€ãã«ç¶æ ã«ãªããŸãã
ããã«ããã¹ãŠã®ãããã€ããŒãããDefaultãšç¹å®ã®ãã¬ãã£ãã¯ã¹ïŒãã®ç¹å®ã®ãããã€ããŒãªã©ïŒãååŸã§ããŸãã ãããã£ãŠãå¿ èŠãªãªãœãŒã¹ãžã®ãã«ãã¥ãŒã®ãªãç¹å®ã®ã«ãŒãããããŸãã
ããŠã³ã¹ããªãŒã ã«ãŒã¿ãŒãžã®ããã©ã«ãã«ãŒã転éãæ§æããæ¹æ³ã®äŸã次ã«ç€ºããŸãã
balagan-router(config-router)#neighbor 101.0.0.2 default-originate
ãããŠããã®åŸã®ããŒããŒã®ã«ãŒãããŒãã«ã¯æ¬¡ã®ããã«ãªããŸãã
ã€ãŸããéåžžã®ã«ãŒãïŒãã«ãã¥ãŒïŒã«å ããŠãããã©ã«ãã«ãŒããéä¿¡ãããŸãã
ããã§ãããã©ã«ãã«ãŒãã¯ãã«ãã¥ãŒãšã¯å¯Ÿç §çã§ã¯ãªããšæšæž¬ãå§ããå¿ èŠããããŸãã å¿ ããããã©ã¡ããäžæ¹ãïŒè±èªã®XORã®ããã«healyãŸãã¯xylã®æŠå¿µãå°å ¥ããå¿ èŠããããŸãïŒãååšããããã§ã¯ãããŸãããããã«ãã¥ãŒãŸãã¯ããã©ã«ãã«ãŒããšä»ã®ããã€ãã®ã«ãŒãã«å ããŠããã©ã«ãã«ãŒãã䜿çšã§ããŸãã
=======================
ã¿ã¹ã¯çªå·2
ã¹ããŒã ïŒäžè¬çãªãããã¯ãŒã¯å³
å²ãåœãŠïŒ
ãããã€ããŒã«ãããã£ã«ã¿ãªã³ã°ãèšå®ããŠãããã©ã«ãã«ãŒãã®ã¿ãæäŸãããã以å€ã¯æäŸããªãããã«ããŸãã
ã€ãŸããBGPããŒãã«ã¯æ¬¡ã®ããã«ãªããŸãã
ãµã€ãã§ã®ã¿ã¹ã¯ã®è©³çŽ°
=======================
å®å šãªBGPããŒãã«ã®å©ç¹ãšå®³ã«ã€ããŠ
Looking Glassããã³ãã®ä»ã®ããŒã«
BGPãæäœããããã®éåžžã«åŒ·åãªããŒã«ã®1ã€ã¯ãLooking Glassã§ãã ãããã¯ã€ã³ã¿ãŒãããäžã«ãããµãŒããŒã§ãå€éšãããããã¯ãŒã¯ãèŠãããšãã§ããŸããå¯çšæ§ã確èªããèªåŸã·ã¹ãã ãžã®ãã¹ãã©ã®ASãä»ããŠãããã確èªããå éšã¢ãã¬ã¹ãžã®ãã¬ãŒã¹ãéå§ããŸãã
ãèããŠãã§ãããã«ç§ã®çºè¡šãã©ã®ããã«èŠãããèŠãŠã¿ãŠãã ããããšèª°ãã«å°ãããã®ããã§ãããããã誰ãã«å°ããå¿ èŠã¯ãããŸããã
å€éšããŒã«ã®åãéå°è©äŸ¡ããªãã§ãã ããã ãã€ãŠç§ã¯ãå€éšãžã®è¿åçãéåžžã«äœããšããåé¡ãæ±ããŠããŸããã 圌女ã¯ãããããŠæ°ã¡ã¬ããããè¶ ããŸããã ããªãé·ãéãã©ãã«ã·ã¥ãŒãã£ã³ã°ãè¡ã£ãåŸãLooking GlassãèŠãããšã«ããŸããã VPNãã£ãã«ãä»ããŠãIBGPãã€ã³ã¹ããŒã«ãããŠããå¥ã®éœåžã®æ¯ç€Ÿãžã®ãã©ãã£ãã¯ãå°çããŠããããšãçºèŠãããšããç§ã¯é©ããŸããã åœç¶ããã£ãã«å¹ ã¯å°ãããã»ãŒå®å šã«å©çšãããŠããŸããã
ã€ã³ã¿ãŒãããäžã®BGPã¢ããŠã³ã¹ã远跡ããäºæããªãäœããçºçããå Žåããããã¯ãŒã¯ææè ïŒ BGPMon ã Renesys ã RouterViewsïŒã«éç¥ã§ããç¹å¥ãªçµç¹ããããŸãã
圌ãã®ãããã§ãããã€ãã®äžççãªäºæ ãé²æ¢ãããŸããã
BGPlayãµãŒãã¹ã䜿çšãããšãã«ãŒãé åžæ å ±ãèŠèŠåã§ããŸãã
nag.ruã§ã¯ããAS 7007ã€ã³ã·ãã³ããããGoogleã®2005幎5æã®åæ¢ããªã©ã誀ã£ãBGPã¢ããŠã³ã¹ã¡ã³ããã€ã³ã¿ãŒãããäžã§ã°ããŒãã«ãªåé¡ãåŒãèµ·ãããæãé¡èãªã±ãŒã¹ã«ã€ããŠèªãããšãã§ããŸãã
BGPãæäœããããã®ããŸããŸãªåªããããŒã«ã«é¢ããéåžžã«åªããèšäº ã
Looking GlassãµãŒããŒã®ãªã¹ã ã
ã³ã³ãããŒã«ãã¬ãŒã³ãšããŒã¿ãã¬ãŒã³
ã«ãŒã管çã®æ·±ã枊ã«çªå ¥ããåã«ãæåŸã®åæ çãªäœè«ãããŸãã ç« ã®ã¿ã€ãã«ã®æŠå¿µã«å¯ŸåŠããå¿ èŠããããŸãã
ãããŠã MPLS Enabled Applicationãèªãã§ãè³ãå£ããŸããã èè ãäœã«ã€ããŠè©±ããŠããã®ãç解ã§ããŸããã§ããã
æ¥ãããããªãããã«ã
ãããã¯ã¢ãã«ã®ã¬ãã«ã§ã¯ãªããç°å¢ã®ã¬ãã«ã§ãããŒã¿è»¢éã®ç¬éã§ããããŸãã-ããã¯éåžžã«æœè±¡çãªåºåã§ãã
å¶åŸ¡ã¬ãã«ïŒ Control Plane ïŒ-ããŒã¿è»¢éã®æ¡ä»¶ãæäŸãããµãŒãã¹ãããã³ã«ã®äœæ¥ã
ããšãã°ãBGPãèµ·åãããšããã¹ãŠã®ç¶æ ãå®è¡ããã«ãŒãã£ã³ã°æ å ±ã亀æããŸãã
ãŸãã¯ãMPLSãããã¯ãŒã¯ã§ã¯ãLDPã¯ã©ãã«ããã¬ãã£ãã¯ã¹ã«é åžããŸãã
ãŸãã¯ãBPDUã亀æããSTPãL2ããããžãæ§ç¯ããŸãã
ãããã¯ãã¹ãŠãã³ã³ãããŒã«ãã¬ãŒã³ããã»ã¹ã®äŸã§ãã ã€ãŸããéä¿¡ã®ããã®ãããã¯ãŒã¯ã®æºåãã€ãŸããã«ãŒãã£ã³ã°ããŒãã«ãåããã¹ã€ããã³ã°ã®ç·šæã§ãã
éä¿¡ã¬ã€ã€ãŒïŒ ããŒã¿ãã¬ãŒã³ ïŒ-æçšãªé¡§å®¢ããŒã¿ãå®éã«éä¿¡ããŸãã
2ã€ã®ã¬ãã«ã®ããŒã¿ããäºãã«åãã£ãŠãç°ãªãæ¹åã«é²ãããšããããããŸãã ãããã£ãŠãBGPã§ã¯ãAS200ãAS100ã«ããŒã¿ã転éã§ããããã«ãAS100ããAS200ã«ã«ãŒãã転éãããŸãã
ããã«ãããŸããŸãªã¬ãã«ã§ãããŸããŸãªäœæ¥ãã©ãã€ã ãååšããå ŽåããããŸãã ããšãã°ãMPLS Data Planeã§ã¯ãæ¥ç¶ã®äœæã«éç¹ã眮ãããŠããŸããã€ãŸããããŒã¿ã¯äºåââå®çŸ©ããããã¹ïŒLSPïŒã«æ²¿ã£ãŠããã«éä¿¡ãããŸãã
ãããããã®ãã¹èªäœã¯ããã¹ããããã¹ããžã®æšæºçãªIPæ³ã«åŸã£ãŠæºåãããŸãã
ã¬ãã«ã®ç®çãšéãã¯äœããç解ããããšãéèŠã§ãã
BGPã®å Žåãããã¯ååã®åé¡ã§ãã ã«ãŒããã¢ããŠã³ã¹ãããšãå®éã«ã¯çä¿¡ãã©ãã£ãã¯ã®ãã¹ãäœæãããŸãã ã€ãŸããã«ãŒãã¯ããªãããæ¥ãŠããã©ãã£ãã¯ã¯ããªãã«æ¥ãŸãã
ã«ãŒãéžæ
ãã®ãããªç¶æ³ã¯ã«ãŒãã«ãããŸãã
è¿é£ããåä¿¡ãã絶察çã«ãã¹ãŠã®ã«ãŒããä¿åãããBGPããŒãã«ããããŸãã
ã€ãŸãããããã¯ãŒã¯100.0.0.0/23ãžã®è€æ°ã®ã«ãŒããããå Žåããããã®ãäžè¯ãã«é¢ä¿ãªãããããã¯ãã¹ãŠBGPããŒãã«ã«å«ãŸããŸãã
ãããŠãæé«ã®æé«ã®ãã®ã ããä¿åããã«ãŒãã£ã³ã°ããŒãã«ããããŸãã åæ§ã«ãBGPã¯ãã¹ãŠã®çä¿¡ã«ãŒããã¢ããŠã³ã¹ããã®ã§ã¯ãªããæè¯ã®ãã®ã®ã¿ãã¢ããŠã³ã¹ããŸãã ã€ãŸãã1ã€ã®è¿é£ããåããããã¯ãŒã¯ãžã®2ã€ã®ã«ãŒããååŸããããšã¯ãããŸããã
ãããã£ãŠãæè¯ã®éžæåºæºïŒ
- æ倧ééïŒã«ãŒã¿ãŒã®ããŒã«ã«ãCiscoã®ã¿ïŒ
- æ倧ããŒã«ã«ããªãã¡ã¬ã³ã¹ïŒASå šäœïŒ
- ã«ãŒã¿ãŒã®ããŒã«ã«ã«ãŒããåªå ããïŒãã¯ã¹ãããã= 0.0.0.0ïŒ
- èªåŸã·ã¹ãã ãéãæççµè·¯ã ïŒæçAS_PATHïŒ
- æå°ãªãªãžã³ã³ãŒãïŒIGP
- æå°MEDå€ïŒã¹ã¿ã³ãã¢ãã³ã·ã¹ãã éã§åæ£ïŒ
- eBGPãã¹ã¯iBGPãã¹ãããåªããŠããŸã
- æãè¿ãIGPãã€ããŒãéããã¹ãéžæããŸã
ãã®æ¡ä»¶ãæºãããããšãè€æ°ã®åçã®ãªã³ã¯éã§è² è·åæ£ãè¡ãããŸã
次ã®æ¡ä»¶ã¯ãã³ããŒã«ãã£ãŠç°ãªãå ŽåããããŸãã
- eBGPãã¹ã®æãå€ãã«ãŒããéžæãã
- æå°ã®BGPã«ãŒã¿ãŒIDãæã€ãã€ããŒãéããã¹ãéžæããŸã
- æå°ã®IPã¢ãã¬ã¹ãæã€ãã€ããŒãéããã¹ãéžæããŸã
ã芧ã®ãšãããå€ãã®éžæåºæºããããŸãã ããã«ããããã¯éåžžã«è€éã§ããããããããã¹ãŠç解ããããšã¯ç°¡åã§ã¯ãããŸããã ãã£ããåå ããŠãã ããã
以äžã§èª¬æããå±æ§ã®ããã€ãã«ã€ããŠèª¬æããŸããå ·äœçã«ã¯ãå¥ã®èšäºã§ã«ãŒããéžæããŸãã
=======================
ã¿ã¹ã¯çªå·3
ã¹ããŒã ïŒäžè¬çãªãããã¯ãŒã¯å³
æ¡ä»¶ïŒãã¹ãŠã®ã«ãŒã¿ãŒã®å šæ¯
ããã§Balagan Telecomãããã€ããŒã®ã«ãŒã¿ãŒã®BGPããŒãã«ãèŠããšããããã¯ãŒã¯102.0.0.0/21-Filkin蚌ææžãããã¯ãŒã¯ãžã®3ã€ã®ã«ãŒãã衚瀺ãããŸãã ãããŠãã«ãŒãã®1ã€ãLinkMiApãããã¯ãŒã¯ãçµç±ããŠããŸãã
ããã¯ãããŒããŒãä»ã®äººã®ã«ãŒããããã«çºè¡šããŠããããšãã€ãŸãASãééããŠããããšã瀺ããŠããŸãã
å²ãåœãŠïŒ
AS64500ãéä¿¡äžã«ãªããªãããã«ãã£ã«ã¿ãªã³ã°ãèšå®ããŸãã
ãµã€ãã§ã®ã¿ã¹ã¯ã®è©³çŽ°
=======================
ã«ãŒã管ç
BGPã䜿çšããè² è·åæ£ã®å€§ããªãããã¯ã«ç§»ãåã«ããã®ãããã³ã«ã§ã«ãŒããäžè¬çã«ç®¡çããæ¹æ³ãç解ããå¿ èŠããããŸãã
ã«ãŒãã£ã³ã°æ å ±ã®äº€æããã®ããã«å¶åŸ¡ã§ããå¯èœæ§ããããããIGPãšã¯ç°ãªããBGPãããã€ãã®ç°ãªããããã€ããŒã®çžäºäœçšã«æè»ã§é©åãªãã®ã«ãªããŸãã
ãããŠããã®ããã®ããŒã«ããããããããŸãã
- AS-Path ACL
- ãã¬ãã£ãã¯ã¹ãªã¹ã
- éã
- ããŒã«ã«èšå®
- MED
ãã ããã¢ããã¿ã€ãºãŸãã¯åä¿¡ãããã«ãŒãããã£ã«ã¿ãªã³ã°ã§ããã®ã¯æåã®2ã€ã®ã¿ã§ãæ®ãã¯åªå é äœã®ã¿ãèšå®ããŸãã
AS-Path ACL
éåžžã«åŒ·åã§ãããæãäžè¬çãªã¡ã«ããºã ã§ã¯ãããŸããã
AS-Path ACLã䜿çšãããšãããšãã°ãAS 200ã«å±ããã«ãŒãã®ã¢ããŠã³ã¹ã®åãå ¥ããçŠæ¢ããããšãã§ããŸããããããããšã¯ããããããŸããã
ãã®ã¢ãããŒãã®æãé£ããéšåã¯ããã¹ãŠã®æ£èŠè¡šçŸãèŠããŠããããã®äœ¿çšæ¹æ³ãåŠã¶ããšã§ãã æåã«ã圌ãããã®é ïŒ
ãµã€ã³ | äŸ¡å€ |
---|---|
ã | ã¹ããŒã¹ãå«ãä»»æã®æå |
* | expressionãšäžèŽãã0å以äžã®äžèŽ |
+ | åŒãšã®1ã€ä»¥äžã®äžèŽ |
ïŒ | åŒãšäžèŽãã0ãŸãã¯1ã€ã®äžèŽ |
^ | è¡é |
$ | è¡æ« |
_ | ä»»æã®ã»ãã¬ãŒã¿ãŒïŒéå§ãçµäºãã¹ããŒã¹ãå«ãïŒ |
\ | 次ã®æåãç¹å¥ãªãã®ãšããŠåãåããªãã§ãã ãã |
[] | ç¯å²å ã®æåã®ããããã«äžèŽ |
| | è«ççãŸã㯠|
ããå°ãæ確ã«ããããã«ãããã€ãäŸã瀺ããŸãã
1
_200_ | AS 200ãééããã«ãŒã |
ASçªå·ã®ååŸã«èšå·ã_ãããããŸããããã¯ãASãã¹çªå·200ã®å é ãäžéããŸãã¯æ«å°Ÿã«ããããšãã§ããããšãæå³ããŸãã
2
^ 200 $ | é£æ¥AS 200ããã®ã«ãŒã |
ã^ãã¯ãªã¹ãã®å é ãæå³ããã$ãã¯æ«å°Ÿãæå³ããŸãã ã€ãŸããASãã¹ã«ã¯ASçªå·ã1ã€ãããããŸãããããã¯ãã«ãŒããAS 200ã§çºä¿¡ãããããããããã«è»¢éãããããšãæå³ããŸãã
3
_200 $ | AS 200ããéä¿¡ãããã«ãŒã |
ã$ãã¯ãªã¹ãã®æåŸãæå³ããŸããã€ãŸãããããæåã®ASã§ããããã®ã«ãŒãããå§ãŸããŸããã_ãèšå·ã¯ã次ã«äœãé¢ä¿ãªããå°ãªããšã7ã€ã®ä»ã®ASã§ããããšã瀺ããŸãã
4
^ 200_ | AS 200ã®èåŸã«ãããããã¯ãŒã¯ |
ã^ãèšå·ã¯ãASN 200ãæåŸã«è¿œå ãããããšãã€ãŸãAS 200ããã«ãŒããæ¥ãããšãæå³ããŸãããããã¯åœŒãçãŸãããšããæå³ã§ã¯ãããŸãã-ã_ãèšå·ã¯ãããããªã¹ãã®æåŸã§ããããšã瀺ãããŸãã¯ã次ã®ASã®åã®ã¹ããŒã¹ãããããŸããã
5
^ $ | ããŒã«ã«ASã«ãŒã |
ASãã¹ãªã¹ãã¯ç©ºã§ããã€ãŸããã«ãŒãã¯ããŒã«ã«ã§ãããASå ã§çæãããŸãã
äŸ
ããã§ã¯ããããã¯ãŒã¯ã§ãAS 64501ããçºä¿¡ãããã«ãŒãããã£ã«ã¿ãªã³ã°ããŸããã€ãŸãã101.0.0.1è¿é£ãããã¹ãŠã®ã€ã³ã¿ãŒãããã«ãŒããåä¿¡ããŸãããããŒã«ã«ã«ãŒãã¯åä¿¡ããŸããã
ããã€ã¹æ§æip as-path access-list 100 deny ^64501$ ip as-path access-list 100 permit .* router bgp 64500 neighbor 101.0.0.1 filter-list 100 in
æ£èŠè¡šçŸã®æ瀺
ãã¬ãã£ãã¯ã¹ãªã¹ã
ããã§ã¯ãã¹ãŠãã·ã³ãã«ã§è«ççã§ãã ãŸããã»ãšãã©ã
ãã¬ãã£ãã¯ã¹ãªã¹ãã¯ãéåžžã®ãããã¯ãŒã¯/ãã¹ã¯ã§ããããã®ãããªã«ãŒããèš±å¯ãããŠãããã©ããã瀺ããŠããŸãã
ã³ãã³ãæ§æïŒ
list-name-ãªã¹ãã®åå ã ããªãã®KOã éåžžã name_inãŸãã¯name_outãšããŠæå®ãããŸãã ããã«ãããçä¿¡ã«ãŒããšçºä¿¡ã«ãŒãã®ã©ã¡ããåäœããããããããŸã ïŒãã¡ããããã®æ®µéã§ã¯æ±ºå®ãããŸããïŒãip prefix-list {list-name} [seq {value}] {deny|permit} {network/length} [ge {value}] [le {value}]
seq-ã«ãŒã«ã®åºæ°ïŒACLã®å Žåãšåæ§ïŒããããã£ãŠããããã䜿çšããŠæäœãããããªããŸãã
æåŠ/èš±å¯ -ãã®ãããªã«ãŒããèš±å¯ãããã©ããã決å®ããŸã
ãããã¯ãŒã¯/é·ã -192.168.14.0/24ãªã©ã®éåžžã®ã¬ã³ãŒãã
ããããããã«æ³šæãå¿ èŠã§ãããã£ãšè€éã§ããããã«2ã€ã®ãã©ã¡ãŒã¿ãŒã geãšleãå¯èœã§ãã NATïŒãŸãã¯FortranïŒã®æ§æãšåæ§ã«ãããã¯ã g reater or e qualãããã³ãlessãŸãã¯e qualããæå³ããŸãã
ã€ãŸããç¹å®ã®ãã¬ãã£ãã¯ã¹ã1ã€ã ãã§ãªãããã®ç¯å²ãæå®ã§ããŸãã
ããšãã°ããã®ãããªèšé²
ip prefix-list NetDay permit 10.0.0.0/8 ge 10 le 16
次ã®ã«ãŒããéžæãããããšãæå³ããŸãã
10.0.0.0/10ã10.0.0.0/11ã10.0.0.0/12ã10.0.0.0/13ã10.0.0.0/14ã10.0.0.0/15ã10.0.0.0/16
äŸ
ããã§ããããã€ããŒFilkin蚌ææžãä»ãããããã¯ãŒã¯120.0.0.0/24ã®ã¢ããŠã³ã¹ã®åãå ¥ããçŠæ¢ãããã®ä»ãã¹ãŠãèš±å¯ããŸãã ãšã³ããª0.0.0.0/0 le 32ã¯ããã¹ã¯é·ïŒ32ïŒ0-32ïŒä»¥äžïŒã®ãµãããããæå³ããŸãã
ip prefix-list TEST_PL_IN seq 5 deny 120.0.0.0/24 ip prefix-list TEST_PL_IN seq 10 permit 0.0.0.0/0 le 32 router bgp 64500 neighbor 102.0.0.1 prefix-list TEST_PL_IN in
念ã®ãããäºçŽããŸããæåŸã®äŸã¯ã次ã®ãããã€ããŒãããªãã«éä¿¡ããªãããšãæå³ããŸãã-ãã¡ãããããã¯ããªãã®ããªã·ãŒã«ã€ããŠäœãç¥ããªãããã§ã-ãããããã®ãããªã¢ããŠã³ã¹ãåãåã£ãã«ãŒã¿ãŒã¯ãã®ã«ãŒããBGPã«è¿œå ããŸãã-ããŒãã«ã
ããã€ã¹æ§æ
ã«ãŒãããã
ãããŸã§ããã¹ãŠã®ã«ãŒã«ã¯ç¡æ¡ä»¶ã§é©çšãããŠããŸãã-ãã¡ãããŸãã¯ãã¡ããããã®ãã¹ãŠã®çºè¡šã«å¯ŸããŠã
ã«ãŒããããïŒä»ã®ãã³ããŒã®å Žåã¯ã«ãŒãã£ã³ã°ããªã·ãŒãšåŒã¶ããšãã§ããŸãïŒã䜿çšããŠãã¢ããŠã³ã¹ãå·®å¥åããããšã§éåžžã«æè»ã«ã«ãŒã«ãé©çšã§ããŸãã
ã³ãã³ãã®æ§æã¯æ¬¡ã®ãšããã§ãã
map_name-ãããåroute-map {map_name} {permit|deny} {seq} [match {expression}] [set {expression}]
èš±å¯/æåŠ -ã«ãŒããããã®æ¡ä»¶ã«è©²åœããããŒã¿ã®ééãèš±å¯ãããã©ãã
seq-ã«ãŒããããã®ã«ãŒã«çªå·
match-ãã©ãã£ãã¯ããã®ã«ãŒã«ã«è©²åœããæ¡ä»¶ã
åŒ ïŒ
åºæº | èšå®ã³ãã³ã |
---|---|
ãããã¯ãŒã¯/ãã¹ã¯ | äžèŽããIPã¢ãã¬ã¹ã®ãã¬ãã£ãã¯ã¹ãªã¹ã |
ASãã¹ | ãã¹ãšããŠäžèŽ |
BGPã³ãã¥ãã㣠| ãããã³ãã¥ãã㣠|
ã«ãŒãçºä¿¡è | match ip route-source |
BGPãã¯ã¹ããããã¢ãã¬ã¹ | ãããIPãã¯ã¹ãããã |
èšå® -ãã£ã«ã¿åŠçã«ãŒããã©ãããã
ã®åŒïŒ
ãã©ã¡ãŒã¿ | èšå®ã³ãã³ã |
---|---|
ASãã¹ã®å é ã«è¿œå | ãã¹ãšããŠè¿œå ãã |
éã | èšå®éé |
ããŒã«ã«èšå® | ããŒã«ã«èšå®ãèšå®ããŸã |
BGPã³ãã¥ãã㣠| ã³ãã¥ããã£ãèšå®ãã |
MED | ã¡ããªãã¯ãèšå® |
èµ·æº | åç¹ãèšå® |
BGPãã¯ã¹ãããã | ãã¯ã¹ãããããèšå®ãã |
å¿çšäŸ
Filkin蚌ææžãä»ããŠ120.0.0.0/24ãµããããã«è¡ããBalagan Telecomãä»ããŠ103.0.0.0/22ã«è¡ãããšãæãŸããããšãææããŸãããããè¡ãã«ã¯ãLocal Preferenceå±æ§ã䜿çšããŸãããã®ãã©ã¡ãŒã¿ãŒã®å€ãé«ãã»ã©ãã«ãŒãã®åªå 床ãé«ããªããŸãã
ip prefix-list TEST1_IN seq 5 permit 120.0.0.0/24 ip prefix-list TEST2_IN seq 5 permit 103.0.0.0/22 route-map BGP1_IN permit 10 match ip address prefix-list TEST1_IN set local-preference 50 route-map BGP1_IN permit 20 set local-preference 100 route-map BGP2_IN permit 10 match ip address prefix-list TEST2_IN set local-preference 50 route-map BGP2_IN permit 20 set local-preference 100 router bgp 64500 neighbor 101.0.0.1 route-map BGP2_IN in neighbor 102.0.0.1 route-map BGP1_IN in
æåã«ãéåžžã®æ¹æ³ã§prefix-listãäœæãã120.0.0.0 / 24ãµãããããå²ãåœãŠãŸãããèš±å¯ã¯ãã«ãŒããããã«ãŒã«ãå°æ¥ãã®ãã¬ãã£ãã¯ã¹ã«äœçšããããšãæå³ããŸããéåžžã®ACLãšåæ§ã«ãä»ã®ãã¹ãŠã«å¯Ÿããæé»ã®æåŠã«ãŒã«ãç¶ããŸãããã®å Žåãã«ãŒããããã«è©²åœããã®ã¯120.0.0.0/24ã®ã¿ã§ããããã以å€ã¯äœãå«ãŸããªãããšãæå³ããŸãã
äœæãããã«ãŒããããBGP1_INã§ã¯ãäœæãããprefix-listã«è©²åœããã«ãŒãã£ã³ã°æ å ±ïŒpermitïŒã®ééãèš±å¯ããŸããïŒmatch ip address prefix-list TEST1_INïŒã
ãããã®ã¢ããŠã³ã¹ã¡ã³ãã§ã¯ãããŒã«ã«ããªãã¡ã¬ã³ã¹ã50ã«èšå®ããŸã-æšæºã®100ãããäœãèšå®ããŸãïŒlocal-preference 50ãèšå®ããŸãïŒãã€ãŸãã圌ãã¯ãé¢çœããªããã§ãããã
æåŸã«ãããããç¹å®ã®BGPãã€ããŒïŒãã€ããŒ102.0.0.1 route-map BGP1_IN inïŒã«ãã€ã³ãããŸãã
çµæã¯äœã§ããïŒ
ããã€ã¹æ§æ
ä»ã®äŸã«ã€ããŠã¯ã次ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãã
=====================
ã¿ã¹ã¯ïŒ4
ã¹ããŒã ïŒäžè¬çãªãããã¯ãŒã¯å³
æ¡ä»¶ïŒLinkMiApã¯äž¡æ¹ã®ãããã€ããŒãããã«ãã¥ãŒãåãåããŸãã
件åïŒãã©ãã«ã·ã¥ãŒãã£ã³ã°ã
ãããã€ããŒããïŒå®å šãªBGPã«ãŒãããŒãã«
msk-arbat-gw1ã«ãŒã¿ãŒã§ããããã€ããŒBalagan TelecomãšFilkin Certificateéã®çºä¿¡ãã©ãã£ãã¯ã®é ä¿¡ãèšå®ãããŸãããããã€ããŒãããã¯ãŒã¯Filkin蚌ææžãžã®ãã©ãã£ãã¯ã¯ãå©çšå¯èœãªå Žåããããééããå¿ èŠããããŸããæ®ãã®çºä¿¡ãã©ãã£ãã¯ã¯ãå©çšå¯èœãªå Žåã¯ãããã€ããŒBalagan Telecomãä»ããŠéä¿¡ããå¿ èŠããããŸãã
çºä¿¡ãã©ãã£ãã¯ããã§ãã¯ãããšããBalagan TelecomãåæãããšãããŒã¿ã»ã³ã¿ãŒïŒ103.0.0.1ïŒãžã®çºä¿¡ãã©ãã£ãã¯ã¯Filkin蚌ææžãééããªãããšãå€æããŸããã
æ§æïŒ
neighbor 102.0.0.1 route-map OUTBOUND in no auto-summary ! route-map OUTBOUND permit 10 match as-path 10 set weight 1000 ! ip prefix-list LAN permit 100.0.0.0/23 ! ip as-path access-list 10 permit ^64502$ ! ip route 100.0.0.0 255.255.254.0 Null0
æ®ãã®æ§æã¯æšæºã§ãã
ã¿ã¹ã¯ïŒ
èšå®ãä¿®æ£ããŠãISP2ãããã€ããŒã®ãããã¯ãŒã¯ããã¯ã©ã€ã¢ã³ãããã³äŒç€Ÿã®ãªã¢ãŒããªãã£ã¹ã®ãããã¯ãŒã¯ãžã®çºä¿¡ãã©ãã£ãã¯ãISP2ãããã€ããŒãééããããã«ããŸãããµã€ã
ã§ã®ã¿ã¹ã¯ã®è©³çŽ°======================
è² è·åæ£ãšåæ£
ããããŠãBGPã§ãã©ãã£ãã¯ã®ãã©ã³ã¹ãåãæ¹æ³ãç¥ã£ãŠããŸããïŒã
ããã¯ãã€ã³ã¿ãã¥ãŒäžã«äººã ãå°ããã質åã§ãã
ãã®èšäºã®æºåãå§ããŠãç§ã¯ãã¿ãŒã·ã£ãšäŒè©±ããŸããããããããBGPã®ãã©ã³ã¹ãšåæ£ã¯2ã€ã®å€§ããªéãã§ããããšãæããã«ãªããŸããã
ããã«èããããåå²ã¯æ¡ä»¶ä»ãã§ããã代æ¿ã®èŠè§£ãååšããŸãã
è² è·åæ£
ãã©ã³ã·ã³ã°ã¯éåžžãåããããã¯ãŒã¯ã«åãããããã©ãã£ãã¯ã®è€æ°ã®ãªã³ã¯éã®åæ£ãšããŠç解ãããŸãã
ãã ãªã³ã«ãªããŸã
router bgp 100 maximum-paths 2
次ã®æ¡ä»¶ãæºãããŠããå¿ èŠããããŸãã
- ãã®ãããã¯ãŒã¯ã®BGPããŒãã«ã«å°ãªããšã2ã€ã®ã«ãŒãã
- äž¡æ¹ã®ã«ãŒãã¯1ã€ã®ãããã€ããŒãééããŸãã
- Weight, Local Preference, AS-Path, Origin, MED, IGP .
- Next Hop .
router bgp 64500 bgp bestpath as-path multipath-relax
AS-path, - .
ãããã¯ãŒã¯ã§ãããã©ã®ããã«ãã¹ãã§ããŸããïŒãã©ã³ã¹ãæ©èœããããšã確èªããå¿ èŠããããŸãã
éåžžããã©ã³ã·ã³ã°ã¯ã¹ããªãŒã ïŒéä¿¡è ã®IPã¢ãã¬ã¹/ããŒããšåä¿¡è ã®IPã¢ãã¬ã¹/ããŒãïŒã«åºã¥ããŠããããããã±ããã¯æ£ããé åºã§å°çããŸãããããã£ãŠã2ã€ã®ã¹ã¬ãããäœæããå¿ èŠããããŸãã
äœãç°¡åã§ããããšãã§ããªãã£ãïŒ
1ïŒçŽæ¥103.0.0.1ã§ping MSK-ã¢ã«ããŒã-GW1ãã
2ïŒãœãŒã¹ïŒã¹ã¬ããäœããæã€ä»ã®ã«ãŒã¿ããã®MSK-ã¢ã«ããŒã-GW1ïŒèšå®ãæ§æããããšãå¿ããªãã§ãã ããïŒãããã³å®è¡ã®pingã«Telnetãä»ããŠæ¥ç¶ãããŠããŸããäºãã«ç°ãªãïŒã¯
ãã®åŸãpingãäžæ¹ã®ãªã³ã¯åã³ä»ä»ããŠç¬¬2ééããŸããæ€èšŒæžã¿
ããã©ã«ãã§ã¯ãå€éšãã£ãã«ã®åž¯åå¹ ã¯èæ ®ãããŸããããã ãããã®ãããªæ©äŒã¯ããŒã ã«ãã£ãŠå®è£ ããã³éå§ãããŸãã
ããã€ã¹æ§ærouter bgp 64500 bgp dmzlink-bw neighbor 101.0.0.1 dmzlink-bw neighbor 102.0.0.1 dmzlink-bw
=====================
ã¿ã¹ã¯No. 5
ã¹ããŒã ïŒäžè¬çãªãããã¯ãŒã¯ã¹ããŒã
æ¡ä»¶ïŒLinkMiApã¯äž¡æ¹ã®ãããã€ããŒããããã©ã«ãã«ãŒããåä¿¡ããŸãã
ã¿ã¹ã¯ïŒ
ãããã€ããŒBalagan TelecomãšFilkin蚌ææžããã®ããã©ã«ãã«ãŒãéã®çºä¿¡ãã©ãã£ãã¯ã®ãã©ã³ã¹ã3察1ã®æ¯çã§èšå®ããŸãããµã€ã
ã§ã®ã¿ã¹ã¯ã®è©³çŽ°====================
è² è·åæ£
é ä¿¡ã®ãããŸã£ããç°ãªãæ²ã¯ãçºä¿¡ãã©ãã£ãã¯ãšçä¿¡ãã©ãã£ãã¯ã®ãã¹ããã现ãã調æŽããããšã§ãã
çºä¿¡
çºä¿¡ãã©ãã£ãã¯ã¯ãäžããåä¿¡ããã«ãŒãã«åŸã£ãŠã«ãŒãã£ã³ã°ãããŸãã
ãããã£ãŠããããã管çããå¿ èŠããããŸãã
ãããã¯ãŒã¯ã®ã¹ããŒã ãæãåºããŠãã ããã
ãããã£ãŠã以äžã®æ¹æ³ããããŸãïŒ
1ïŒéã¿ãèšå®ãããããã¯tsiskovskyã®å éšãã©ã¡ãŒã¿ãŒã§ãããã©ãã«ãéä¿¡ããããã«ãŒã¿ãŒå ã§æ©èœããŸããå€ãã®å Žåãä»ã®ãã³ããŒã«ãé¡äŒŒè£œåããããŸãïŒããšãã°ãHuaweiã®PreValïŒãå ·äœçãªããšã¯äœããããŸãã-ç§ãã¡ãæ¢ãŸããªãã§ããããïŒããã©ã«ãã¯0ïŒ
è¿é£ããåä¿¡ãããã¹ãŠã®ã«ãŒãã«é©çšããŸãã
neighbor 192.168.1.1 weight 500
ã«ãŒããããçµç±ã®ã¢ããªã±ãŒã·ã§ã³ïŒ
route-map SET_WEIGHT permit 10 set weight 500 ! router bgp 64500 neighbor 102.0.0.1 route-map SET_WEIGHT in
2ïŒããŒã«ã«èšå®ããã®ãã©ã¡ãŒã¿ãŒã¯æšæºã§ããããã©ã«ãã¯ããã¹ãŠã®ã«ãŒãã§100ã§ããç¹å®ã®ãµãããããžã®ãã©ãã£ãã¯ãç¹å®ã®ãªã³ã¯ã«è»¢éããå Žåã¯ãããŒã«ã«ããªãã¡ã¬ã³ã¹ãäžå¯æ¬ ã§ãããã®ãã©ã¡ãŒã¿ãŒã®äœ¿çšäŸã«ã€ããŠ
ã¯æ¢ã«æ€èšããŸããã
3ïŒmaximum-paths ã³ãã³ãã
䜿çšããäžèšã®ãã©ã³ã·ã³ã°=====================
ã¿ã¹ã¯çªå·6
ã¹ããŒã ïŒäžè¬çãªãããã¯ãŒã¯ã¹ããŒã
æ¡ä»¶ïŒLinkMiApã¯äž¡æ¹ã®ãããã€ããŒãããã«ãã¥ãŒãåä¿¡ããŸãã
ã¿ã¹ã¯ïŒ
éã¿ãããŒã«ã«ããªãã¡ã¬ã³ã¹ããŸãã¯ãã£ã«ã¿ãªã³ã°å±æ§ã䜿çšããã«ãmsk-arbat-gw1ã«ãŒã¿ãŒãæ§æããŠãBalagan Telecomãçºä¿¡ãã©ãã£ãã¯ã®ã¡ã€ã³ã«ãŒã¿ãŒã«ãªããFilkin蚌ææžãããã¯ã¢ãããããããã«ããŸãããµã€ã
ã§ã®ã¿ã¹ã¯ã®è©³çŽ°
=======================
çä¿¡
ããã§ã¯ãã¹ãŠãè€éã§ãã
äºå®ã倧èŠæš¡ãªãããã€ããŒã§ãã£ãŠããçºä¿¡ãã©ãã£ãã¯ã¯çä¿¡ãšæ¯èŒããŠç¡èŠã§ããã»ã©ã§ãããããŠãäžåäžãªååžãéåžžã«ã¯ã£ãããšèŠãããŸãã
ããããããŒã¿åŠçã»ã³ã¿ãŒãŸãã¯ãã¹ãã£ã³ã°ãããã€ããŒã«ã€ããŠè©±ããŠããå Žåãç¶æ³ã¯éã§ããããã©ã³ã¹ã®åé¡ã¯éåžžã«æ·±å»ã§ãã
ããã§ã¯ãæ段ãéåžžã«å¶éãããŠããŸãã
1ïŒAS-Path Prepend
æãããããããªãã¯ã®1ã€ã¯ããã¹ããæªåããããããšã§ãã 1ã€ã®ãããã€ããŒãä»ããŠãå¥ã®ãããã€ããŒãããé·ãASãã¹é·ã§ã«ãŒããéä¿¡ãããããšããããããŸãããã¡ãããBGPã¯æåã«ã«ããŽãªãéžæãããããä»ããŠã®ã¿ãã©ãã£ãã¯ãéä¿¡ãããŸããã«ãŒããçºè¡šãããšãã®ç¶æ³ãåçã«ããããã«ãAS-Pathã«è¿œå ã®ããããããè¿œå ã§ããŸãã
ãããŠããããããã€ããŒãå°ãã®ãéã§ããåºããã£ãã«ãæäŸããããšããããŸããããããéãçµè·¯ã¯ããé·ãããã¹ãŠã®ãã©ãã£ãã¯ã¯å¥ã®ãã®ã«è¡ããŸã-é«äŸ¡ã§çãããã®ç¶æ³ã¯ç§ãã¡ã«ãšã£ãŠäžæ¡ç®ã§ãããçããã£ãã«ãããã¯ã¢ããã«ããããšèããŠããŸãã
ããã§åæããŸããããããããªãã¯å®å šã«éåããç¶æ³ãåãå¿ èŠããããŸããããšãã°ãBalagan TelecomããLikMiApãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ã
ããã¯ãéåžžã®ç¶æ³ã§Balagan Telecomãããã€ããŒäžã§BGPãšã«ãŒãã£ã³ã°ããŒãã«ãã©ã®ããã«èŠããã
ã§ããã¡ã€ã³ãã¹ïŒãããã®éã®çŽæ¥ãªã³ã¯ïŒãäœäžãããå ŽåãAS-ASãªã¹ãã«ASãè¿œå ããå¿ èŠããããŸãã
router bgp 64500 neighbor 101.0.0.1 route-map AS_PATH_PREP out route-map AS_PATH_PREP permit 10 set as-path prepend 64500 64500
ãããŠãçµµã¯æ¬¡ã®ããã«ãªããŸãã
Fil'kin蚌ææžïŒAS6502ïŒãä»ããŠãããããšãASãã¹çãé·ãã§ãã¹ãéžæããåœç¶ã®ããšãªããã
ãã®ã«ãŒãããã³ã«ãŒãã£ã³ã°ããŒãã«ã«è¿œå ãããŸãã
éåžžãAS-Pathã§ã¯ç¬èªã®ASçªå·ãè¿œå ããããšã«æ³šæããŠãã ããããã¡ãããä»ã®äººã®ããšãã§ããŸããããŸãšããªç€ŸäŒã§ã¯ç解ãããŸããã
ãããã£ãŠããã©ãã£ãã¯ãèšç»ãããã¹ã«æ²¿ã£ãŠããããšã確èªããŸããã
åœç¶ããã£ãã«ã®1ã€ãã¯ã©ãã·ã¥ãããšãèšå®ãããAS-Path Prependsã«é¢ä¿ãªãããã©ãã£ãã¯ã¯2çªç®ã«åãæ¿ãããŸãã
ããã€ã¹æ§æã
2ïŒMED
å€éåºå£åŒå¥åšãã·ã¹ã³ã§ã¯ãã¡ããªãã¯ïŒASéã¡ããªãã¯ïŒãšåŒã°ããŸããMEDã¯åŒ±ãå±æ§ã§ãã匱ããã«ãŒããéžæããéã«6çªç®ã®ã¹ãããã§ã®ã¿ãã§ãã¯ãããæ¬è³ªçã«åŒ±ãå¹æãããããã
ããŒã«ã«ããªãã¡ã¬ã³ã¹ãèªåŸã·ã¹ãã ããã®ãã©ãã£ãã¯åºå£ã®ãã¹ã®éžæã«åœ±é¿ãäžããå ŽåãMEDã¯é£æ¥ASã«è»¢éãããããããã©ãã£ãã¯å ¥åãã¹ã«åœ±é¿ããŸãã
äžè¬ã«ãMEDãšããŒã«ã«ããªãã¡ã¬ã³ã¹ã¯åå¿è ã«ãã£ãŠæ··åãããããšãå€ãããããã¬ãŒãã®éãã«ã€ããŠèª¬æããŸãã
ããŒã«ã«èšå® | MED |
---|---|
ãã©ãã£ãã¯ãçµäºããããã®ãã¹ã®åªå 床ã決å®ããŸãã | ãã©ãã£ãã¯ãšã³ããªã®ãã¹ã®åªå 床ã決å®ããŸã |
ASå ã§ã®ã¿æå¹ã§ããä»ã®ASã«è»¢éãããŸãã | ä»ã®ASã«éä¿¡ããããã©ãã£ãã¯ã転éããããšãæãŸããæ¹æ³ãä»ããŠãã³ã |
å¥ã®ASã«æ¥ç¶ãããšæ©èœããŸã | 1ã€ã®ASãžã®è€æ°ã®æ¥ç¶ã§ã®ã¿æ©èœããŸã |
å€ã倧ããã»ã©ãåªå 床ãé«ããªããŸãã | å€ãé«ãã»ã©ãåªå é äœã¯äœããªããŸãã |
䜿çšããããšã¯ãã£ãã«ãªãã®ã§ãããã§ã¯èª¬æããŸããããããã¯ãŒã¯ã¯ããã«é©ããŠããªãããã2ã€ã®ASéã«è€æ°ã®æ¥ç¶ãããããããã1ã€ãããããŸããã
3ïŒç°ãªãISPãä»ããç°ãªããã¬ãã£ãã¯ã¹ã®ã¢ããŠã³ã¹
è² è·ãåæ£ããå¥ã®æ¹æ³ã¯ãç°ãªããããã¯ãŒã¯ãç°ãªããããã€ããŒã«åæ£ããããšã§ãã
ããŒã¿ã»ã³ã¿ãŒãããã¯ãŒã¯ã§ã¯ãã¢ããŠã³ã¹ã¯æ¬¡ã®ããã«ãªããŸãã
ã€ãŸãããããã¯ãŒã¯100.0.0.0/23ã¯2ã€ã®æ¹æ³ã§ç¥ãããŠããŸãããã«ãŒãã£ã³ã°ããŒãã«ã«è¿œå ãããã®ã¯1ã€ã ãã§ãããããã£ãŠããã¹ãŠã®ãã©ãã£ãã¯ã¯1ã€ã«æ»ããŸã-æè¯ã®æ¹æ³ã§ãã
ãããïŒ
ããã2ã€ã®ãµãããã/ 24ã«åå²ãã1ã€ãBalagan Telecomã«ããã1ã€ãFilkin Certificateã«æž¡ãããšãã§ããŸãã
ãããã£ãŠãããŒã¿ã»ã³ã¿ãŒã¯ç°ãªããã¹ãä»ããŠãããã®ãµãããããèªèã
ãŸãããã®ããã«æ§æãããŸãã
æåã«ããã¹ãŠã®ãµãããããèŠå®ããŸãã3ã€ãã¹ãŠïŒ1ã€ã®å€§/ 23ãš2ã€ã®å°/ 24ïŒ
router bgp 64500 network 100.0.0.0 mask 255.255.254.0 network 100.0.0.0 mask 255.255.255.0 network 100.0.1.0 mask 255.255.255.0
ããããã¢ããŠã³ã¹ããã«ã¯ããããã®ãµãããããžã®ã«ãŒããäœæããå¿ èŠããããŸãã
ip route 100.0.0.0 255.255.254.0 Null0 ip route 100.0.0.0 255.255.255.0 Null0 ip route 100.0.1.0 255.255.255.0 Null0
ãããŠä»ãç§ãã¡ã¯ãããã1ã€ã®ãµãããã/ 24ãšäžè¬çãª/ 23ãµãããããèš±å¯ãããã¬ãã£ãã¯ã¹ãªã¹ããäœæããŸãã
ip prefix-list LIST_OUT1 seq 5 permit 100.0.0.0/24 ip prefix-list LIST_OUT1 seq 10 permit 100.0.0.0/23 ! ip prefix-list LIST_OUT2 seq 5 permit 100.0.1.0/24 ip prefix-list LIST_OUT2 seq 10 permit 100.0.0.0/23
ãã¬ãã£ãã¯ã¹ãªã¹ãããã€ããŒã«ãã€ã³ãããŸãã
router bgp 64500 neighbor 101.0.0.1 remote-as 64501 neighbor 101.0.0.1 prefix-list LIST_OUT1 out neighbor 102.0.0.1 remote-as 64502 neighbor 102.0.0.1 prefix-list LIST_OUT2 out
å€éšã«éä¿¡ããã«ãŒãã«ã€ããŠè©±ããŠãããããããããOUT-çºä¿¡ã«çµã³ä»ããŸãã
ãã®ããããããã¯ãŒã¯100.0.0.0/24ããã³100.0.0.0/23ããã€ããŒ101.0.0.1ïŒBalagan TelecomïŒã«çºè¡šããŸãã
ãããŠããã€ããŒ102.0.0.1ïŒãã£ã«ãã³èšŒææžïŒ-ãããã¯ãŒã¯100.0.1.0/24ããã³100.0.0.0/23ã
çµæã¯æ¬¡ã®ããã«ãªããŸãã
ãã©ã¬ã³ãã¬ã³ã ãšFilkin蚌ææžãä»ããŠãåãããã¯ãŒã¯/ 24ã«2ã€ã®ã«ãŒãããããããééã£ãŠããããã§ãã
ããããããèŠããšãAS-Pathã«ãã
ãšããã®ãããªã«ãŒããããããšãããããŸããã€ãŸããå®éã«ã¯ãã¹ãŠãæ£ãããšããããšã§ããã¯ãããã¹ãŠãã«ãŒãã£ã³ã°ããŒãã«ã«æ£ããåãŸããŸãã
ä»ã倧ããªãµãããã/ 23ãèªåã®ããã«ãã©ãã°ããã®ã¯ã©ã®ãããªæªéãªã®ããšãã質åã«çããå¿ èŠããããŸããïŒå®éãæé·ãã¬ãã£ãã¯ã¹äžèŽã«ãŒã«ã«ããã°ã/ 24ãããå Žåã¯äžèŠã§ãããã®ããã«ãããæ£ç¢ºãªã«ãŒããã€ãŸã/ 23ãæãŸããã§ãã
ããããBalagan Telecomã®ãããã¯ãŒã¯ã厩å£ããç¶æ³ãæ³åããŠãã ãããã©ããªãã®ïŒ 100.0.0.0/24ãµããããã¯ã€ã³ã¿ãŒãããäžã§èªèãããªããªããŸã-æ§æã®ãããã§Balagan Telecomã ããäœãã«ã€ããŠç¥ã£ãŠããããã§ãããããã£ãŠããããã¯ãŒã¯ã®äžéšãèœã¡ãŸãããããïŒããäžè¬çãªã«ãŒã100.0.0.0/23ã§ç¯çŽã§ããŸããFilkin蚌ææžã¯ããã«ã€ããŠç¥ã£ãŠãããã€ã³ã¿ãŒãããã§ãããçºè¡šããŸãããããã£ãŠãããŒã¿ã»ã³ã¿ãŒã¯ãããã¯ãŒã¯100.0.0.0/24ãèªèããŸãããã100.0.0.0 / 23ãèªèããFilkin蚌ææžã®æ¹åã«ãã©ãã£ãã¯ãéããŸãã
ã€ãŸããã©ã€ããããã®æ å ãç§ãã¡ã¯ãã®ãããªç¶æ³ã«ä¿éºããããããŠããŸãã
ã«ãŒã¿ãŒã®æ§æã«å ããŠãRIPEããŒã¿ããŒã¹ã«3ã€ãã¹ãŠã®ãããã¯ãŒã¯ãäœæããå¿ èŠãããããšã«æ³šæããŠãã ããããããã¯ãŒã¯/ 24ãšãããã¯ãŒã¯/ 23ã®äž¡æ¹ãããã¯ãã§ãã
ããã€ã¹æ§æ
4ïŒBGPã³ãã¥ããã£
BGPã³ãã¥ããã£ã®å©ããåããŠããããã€ããŒã«ãã¬ãã£ãã¯ã¹ã®åŠçæ¹æ³ã転éå ã転éå ãèšå®ããããŒã«ã«èšå®ãªã©ãæ瀺ã§ããŸããã³ãã¥ããã£ã®ãããã¯ã次ã®å·ã«ç§»ãã®ã§ããã®ãªãã·ã§ã³ã¯ä»ã¯èæ ®ããŸããã
=====================
ã¿ã¹ã¯ïŒ7
ã¹ããŒã ïŒäžè¬çãªãããã¯ãŒã¯å³
æ¡ä»¶ïŒmsk-arbat-gw1ã«ãŒã¿ãŒã§ãçä¿¡ããã³çºä¿¡ãã©ãã£ãã¯å¶åŸ¡ãèšå®ãããŠããŸããã¡ã€ã³ãããã€ããŒã¯Balagan Telecomãããã¯ã¢ããã¯Filkin Certificateã§ããèšå®ã確èªãããšãçºä¿¡ãã©ãã£ãã¯ãæ£ããéä¿¡ãããŠããããšãããããŸãããçä¿¡ãã©ãã£ãã¯ã確èªãããšãçä¿¡ãã©ãã£ãã¯ã¯Balagan Telecomãããã€ããŒãééããŸãããBalagan Telecomãåæããããšãçä¿¡ãã©ãã£ãã¯ã¯Filkin蚌ææžãééããŸããã§ããã
ã¿ã¹ã¯ïŒèšå®ãä¿®æ£ããŸãã
æ§æïŒ
hostname msk-arbat-gw1 ! interface Loopback0 ip address 100.0.0.1 255.255.255.255 ! interface FastEthernet0/0 description Balagan_Telecom_Internet ip address 101.0.0.2 255.255.255.252 duplex auto speed auto ! interface FastEthernet0/1 description Philkin_Certificate_Internet ip address 102.0.0.2 255.255.255.252 speed 100 full-duplex ! router bgp 64500 no synchronization bgp log-neighbor-changes network 100.0.0.0 mask 255.255.254.0 neighbor 101.0.0.1 remote-as 64501 neighbor 101.0.0.1 prefix-list LAN out neighbor 101.0.0.1 weight 500 neighbor 102.0.0.1 remote-as 64502 neighbor 102.0.0.1 prefix-list LAN out neighbor 102.0.0.1 route-map INBOUND out no auto-summary ! route-map INBOUND permit 10 set as-path prepend 64502 64502 64502 ! ip prefix-list LAN permit 100.0.0.0/23 ! ip route 100.0.0.0 255.255.254.0 Null0
äžã®åé¡ã®è©³çŽ°ã«ã€ããŠãµã€ã
=====================
åè¡¡ãšè² è·åæ£åœä»€ã®çš®é¡ã«ãã£ãŠã
ãã¿ãŒã·ã£Samoylenko -èè xgu.ruã¯ãç§ãã¡ã®ããã«ãã¬ãŒã³ããŒã·ã§ã³ãæºåããŸããã
http://www.slideshare.net/NatashaSamoylenko/linkmeup-bgpipsla åž°å±è¡šç€ºã䜿çšããŠãå¿ èŠã«å¿ããŠããŠã³ããŒãããŠäœ¿çšã§ããŸãã
PBR
éçã«ãŒãã£ã³ã°ãåçã«ãŒãã£ã³ã°ïŒIGPãŸãã¯EGPïŒã®ãããã§ãã£ãŠããèšäºã§ãããŸã§äœ¿çšããŠãããã¹ãŠã®ã«ãŒãã£ã³ã°ãã¯ãããžãŒã¯ããã±ããã®1ã€ã®å åã®ã¿ãèæ ®ããŸããïŒå®å ã¢ãã¬ã¹ãåçŽã«ã圌ãã¯ãã¹ãŠåãååã«åºã¥ããŠè¡åããŸããã圌ãã¯ãã±ãããã©ãã«åãã£ãŠããã®ããèŠãŠãã«ãŒãã£ã³ã°ããŒãã«ã§å®å ãžã®æãå ·äœçãªã«ãŒãïŒæé·äžèŽïŒãèŠã€ãããã®ã«ãŒãã®å察åŽã®ããŒãã«ã«æžã蟌ãŸããã€ã³ã¿ãŒãã§ã€ã¹ã«ãã±ããã転éããŸãããããã¯äžè¬ã«ãã«ãŒãã£ã³ã°ã®æ¬è³ªã§ãããããããã®é åºãç§ãã¡ã«åããªãå Žåã¯ã©ãã§ããããïŒéä¿¡å ã¢ãã¬ã¹ã«åºã¥ããŠãã±ãããã«ãŒãã£ã³ã°ããå Žåã¯ã©ããªããŸããïŒãŸãã¯
ãã®ç¶æ³ã§ã¯ãPBRïŒããªã·ãŒããŒã¹ã«ãŒãã£ã³ã°ïŒãšããããªã·ãŒã«åºã¥ãã«ãŒãã£ã³ã°ã圹ç«ã¡ãŸãããã®ãã¯ãããžãŒã«ãããããã±ãŒãžã®æ¬¡ã®æ©èœã«åºã¥ããŠãã©ãã£ãã¯ã管çã§ããŸãã
- éä¿¡å ã¢ãã¬ã¹ïŒãŸãã¯éä¿¡å ã¢ãã¬ã¹ãšåä¿¡è ã¢ãã¬ã¹ã®çµã¿åããïŒ
- OSIã¬ãã«7ïŒã¢ããªã±ãŒã·ã§ã³ïŒæ å ±
- ãã±ãããæ¥ãã€ã³ã¿ãŒãã§ãŒã¹
- QoSã¿ã°
- äžè¬çã«ãæ¡åŒµACLã§äœ¿çšãããæ å ±ïŒéä¿¡å \å®å ããŒãããããã³ã«ãªã©ãä»»æã®çµã¿åããïŒã ã€ãŸã æ¡åŒµACLã䜿çšããŠé¢å¿ã®ãããã©ãã£ãã¯ãåé¢ã§ããå Žåã¯ãå¿ èŠã«å¿ããŠã«ãŒãã£ã³ã°ã§ããŸãã
PBRã䜿çšããå©ç¹ã¯æããã§ããã«ãŒãã£ã³ã°ã®ä¿¡ããããªãã»ã©ã®æè»æ§ã§ããããããçæããããŸãïŒ
- ãã¹ãŠãæã§æžãå¿ èŠããããããå€ãã®äœæ¥ãšãšã©ãŒã®ãªã¹ã¯
- ããã©ãŒãã³ã¹ã ã»ãšãã©ã®è ºã§ã¯ãPBRã¯éåžžã®ã«ãŒãã£ã³ã°ãããäœéã§ãïŒäŸå€ã¯Catalys 6500ã§ããéPBRããµããŒãããã¹ãŒããŒãã€ã¶ãŒãããŸãïŒ
PBRã®å®è£ ã«åºã¥ãããªã·ãŒã¯ãã«ãŒããããPOLICY_NAMEã³ãã³ãã«ãã£ãŠäœæããã2ã€ã®ã»ã¯ã·ã§ã³ãå«ãŸããŸãã
- å¿ èŠãªãã©ãã£ãã¯ã®å²ãåœãŠãACLã䜿çšãããããã©ãã£ãã¯ãå°çããã€ã³ã¿ãŒãã§ã€ã¹ã«å¿ããŠå®è¡ãããŸããmatchã³ãã³ãã¯ãã«ãŒããããã³ã³ãã£ã®ã¥ã¬ãŒã·ã§ã³ã¢ãŒãã§ãããæ åœããŸãã
- ãã®ãã©ãã£ãã¯ã«ã¢ã¯ã·ã§ã³ãé©çšããŸããããã¯setã³ãã³ããæ
åœããŸãã
ä¿®æ£ã®ããã®å°ãã®ç·Žç¿
ïŒãã®ããããžãŒããããŸãïŒ
çŸæç¹ã§ã¯ããã©ãã£ãã¯R1-R5ããã³ããã¯ã¯ã«ãŒãR1-R2-R4-R5ã«æ²¿ã£ãŠé²ã¿ã䟿å®äžãã¢ãã¬ã¹ã®æåŸã®æ¡ãã«ãŒã¿ãŒçªå·ã«ãªãããã«ã¢ãã¬ã¹ãå²ãåœãŠãããŸãã
R1ïŒtraceroute 192.168.100.5
1 192.168.0.2 20ããªç§36ããªç§20ããªç§
2 192.168.2.4 40ããªç§44ããªç§16ããªç§
3 192.168.100.5 56ããªç§* 84ããªç§
R5ïŒtraceroute 192.168.0.1
1 192.168.100.4 56ããªç§40ããªç§8ããªç§
2 192.168.2.2 20ããªç§24ããªç§16ããªç§
3 192.168.0.1 64ããªç§* 84ããªç§
ããšãã°ãã«ãŒãR5-R4- R3 -R1ã«æ²¿ã£ãŠç§»åããããã«ãR5ããã®ãã©ãã£ãã¯ïŒéä¿¡å ã¢ãã¬ã¹ãå«ãïŒãå¿ èŠã§ãããšããŸããã¹ããŒã ã«ããã°ãR4ãããã決å®ããå¿ èŠãããããšã¯æããã§ãããã®äžã§ããŸãå¿ èŠãªããã±ãŒãžãéžæããACLãäœæããŸãã
R4(config)#access-list 100 permit ip host 192.168.100.5 any
次ã«ããBACKããšããååã®ã«ãŒãã£ã³ã°ããªã·ãŒãäœæããŸãã
R4(config)#route-map BACK
ãã®äžã«ãç§ãã¡ãèå³ãæã£ãŠãããã©ãã£ãã¯ã瀺ããŸã
R4(config-route-map)#match ip address 100
ãããŠãããã©ããããïŒ
R4(config-route-map)#set ip next-hop 192.168.3.3
次ã«ãR5ã®æ¹ãåãã€ã³ã¿ãŒãã§ã€ã¹ã«ç§»åããŸãïŒPBRã¯çä¿¡ãã©ãã£ãã¯ã§æ©èœããŸãïŒïŒãããŠåä¿¡ããããªã·ãŒãé©çšããŸãïŒ
R4(config)#int fa1/0 R4(config-if)#ip policy route-map BACK
ç§ãã¡ã¯ãã§ãã¯ããŸãïŒ
R5ïŒtraceroute 192.168.0.1
1 192.168.100.4 40ããªç§40ããªç§16ããªç§
2 192.168.3.3 52ããªç§52ããªç§44ããªç§
3 192.168.1.1 56ããªç§* 68ããªç§
ããŸãããïŒããŠããã€ã¢ã°ã©ã ã泚ææ·±ãèŠãŠãèããŠã¿ãŸãããïŒãã¹ãŠã¯å€§äžå€«ã§ããïŒ
ãããŠããïŒ
ãã®ACLã«åŸã£ãŠãR5ãœãŒã¹ãæã€ãã¹ãŠã®ãã©ãã£ãã¯ã¯R3ã§ã©ãããããŸããããã¯ãããšãã°ãR5ãçãæçœãªã«ãŒãR5-R4-R2ã§ã¯ãªãR2ã«ä¹ãããå Žåãã«ãŒãR5-R4-R3-R1-R2ã«æ²¿ã£ãŠéä¿¡ãããããšãæå³ããŸãããããã£ãŠãPBRã®ACLãéåžžã«æ éãã€ææ ®æ·±ãã³ã³ãã€ã«ããã§ããã ãå ·äœçã«ããå¿ èŠããããŸãã
ãã®äŸã§ã¯ããã©ãã£ãã¯ã«é©çšãããã¢ã¯ã·ã§ã³ãšããŠãnextopïŒãã¹ãããã±ãããããã«é²ãå ŽæïŒãåå®çŸ©ããããšãéžæããŸãããPBRã§ä»ã«äœãã§ããŸããïŒæ¬¡ã®ã³ãã³ãã䜿çšã§ããŸãã
- ip next-hopãèšå®ããŸã
- ã€ã³ã¿ãŒãã§ã€ã¹ãèšå®ãã
- ip default next-hopãèšå®ããŸã
- ããã©ã«ãã®ã€ã³ã¿ãŒãã§ãŒã¹ãèšå®ãã
æåã®2ã€ã§ã¯ããã¹ãŠãæ¯èŒçæ確ã§ã-ãããã¯ãããã¯ã¹ããããšãã±ãããåºãã€ã³ã¿ãŒãã§ã€ã¹ãåå®çŸ©ããŸãïŒã»ãšãã©ã®å Žåãèšå®ãããã€ã³ã¿ãŒãã§ã€ã¹ã¯ãã€ã³ãããŒãã€ã³ããªã³ã¯ã«äœ¿çšãããŸãïŒããŸããset ip default next-hopãŸãã¯set default interface ã³ãã³ãã䜿çšããå Žåãã«ãŒã¿ãŒã¯æåã«ã«ãŒãã£ã³ã°ããŒãã«ã調ã¹ããã§ãã¯å¯Ÿè±¡ã®ãã±ããã®ã«ãŒããããå Žåãããã«å¿ããŠããŒãã«ã«éä¿¡ããŸããã«ãŒãããªãå Žåãããªã·ãŒã«èšèŒãããŠããããã«ããã±ãããéä¿¡ãããŸããããšãã°ãããããžã§set ip next-hop 192.168.3.3ã®ä»£ããã«set ip default next-hop 192.168.3.3ã泚æããå ŽåãR4ã«ã¯R1ãžã®ã«ãŒããããããïŒR2çµç±ïŒãäœãå€æŽãããŸãããããããååšããªãå Žåããã©ãã£ãã¯ã¯R3ã«éãããŸãã
, set : QoS MPLS BGP
======================
ã¿ã¹ã¯çªå·8
æ¡ä»¶ïŒLinkMiApã¯ããããã€ããŒïŒBGPã§ã¯ãªãïŒãžã®éçã«ãŒãã䜿çšããŸãã
ã¹ããŒã ãšæ§æããããã€ããŒã«ãŒã¿ãŒãBGPã䜿çšããŸããã
ã¿ã¹ã¯ïŒãããã€ããŒéã®åãæ¿ããæ§æããŸãã
google pingïŒ103.0.0.10ïŒãŸãã¯yandexïŒ103.0.0.20ïŒãžã®icmpå¿çãå°çããéããBalagan Telecomãžã®ããã©ã«ãã«ãŒãã䜿çšããå¿ èŠããããŸãããªã¯ãšã¹ãã¯ãBalagan Telecomçµç±ã§éä¿¡ããå¿ èŠããããŸããæå®ããããªãœãŒã¹ã®ããããå¿çããªãå Žåãããã©ã«ãã«ãŒãã¯Filkin蚌ææžãããã€ããŒã«åãæ¿ããå¿ èŠããããŸããåã ã®icmpå¿çã®äžæçãªæ倱ã«ããåãæ¿ããé²ãããã«ãåãæ¿ãé 延ãå°ãªããšã5ç§ã«èšå®ããå¿ èŠããããŸãã
ã¿ã¹ã¯ã®è©³çŽ°ãã
======================
IP SLA
ãããŠä»ãæãããããïŒç§ãã¡ã®ã¹ããŒã ã§ã¯ãã¡ã€ã³ãã¹R4-R2-R1ã1ã€ã®ãããã€ããŒã«ãã£ãŠæäŸãããã¹ãã¢ã®R4-R3-R1ãå¥ã®ãããã€ããŒã«ãã£ãŠæäŸãããããšãæ³åããŠã¿ãŸããããå Žåã«ãã£ãŠã¯ãæåã®ãããã€ããŒã®è² è·ã®åé¡ã«ãããé³å£°ãã©ãã£ãã¯ãäœäžãå§ããããšããããŸããåæã«ãå¥ã®ã«ãŒããã¢ã³ããŒãããããã®æç¹ã§é³å£°ã転éããã®ãè¯ãã§ããããããŠãäžèšã§è¡ã£ãããã«ãã«ãŒãããããäœæããŸããããã¯ãé³å£°ãã©ãã£ãã¯ãå²ãåœãŠãéåžžåäœãããããã€ããŒãä»ããŠéä¿¡ããŸãããããŠãããã§-opãç¶æ³ã¯é転ããŸãã-åã³ããã¹ãŠãå ã«æ»ãå¿ èŠããããŸããå¹³æ¥ã®ãã¯ãã«ã«ãµããŒãïŒããããŠãäžæ¥äžãã®ãããªãŽãïŒã¢ã¶ã©ã·ãåŒã³åºãã次ã«é¹¿ãåŒã³åºããŸããããã ããå¿ èŠãªã¡ã€ã³ãã£ãã«ã®ç¹æ§ïŒããšãã°ãé 延ããžãã¿ãŒïŒã远跡ã§ããã°ãããã¯ã¯ãŒã«ã§ããããã®å€ã«å¿ããŠããã©ã€ããªãŸãã¯ããã¯ã¢ãããã£ãã«ã«é³å£°ãŸãã¯ãããªãèªåçã«éä¿¡ããŸããïŒããã§ãå¥è·¡ãèµ·ãããŸãããã®å Žåãå¥è·¡ã¯IP SLAãšåŒã°ããŸãã
ãã®æè¡ã¯ãå®éã«ã¯ãã¢ã¯ãã£ããªãããã¯ãŒã¯ç£èŠã§ããç¹å®ã®ãããã¯ãŒã¯ç¹æ§ãè©äŸ¡ããããã®ãã©ãã£ãã¯ã®çæãããããç£èŠã¯ããã§çµããã§ã¯ãããŸãããã«ãŒã¿ãŒã¯ãåä¿¡ããããŒã¿ã䜿çšããŠãã«ãŒãã£ã³ã°ã«é¢ããææ決å®ã«åœ±é¿ãäžããåé¡ã«åå¿ããŠè§£æ±ºããããšãã§ããŸããããšãã°ãããžãŒãªãã£ãã«ãã¢ã³ããŒãããè² è·ãä»ã®ãŠãŒã¶ãŒã«åæ£ããŸãã
ããã«èŠåŽããã«ãããã«èšå®ã«ããŸããç£èŠãããããšãèšãå¿ èŠããããŸããç£èŠãªããžã§ã¯ããäœæããããã«çªå·ãå²ãåœãŠãŸãã
R4(config)#ip sla 1
ããã§ã¯ãããã§äœãç£èŠã§ããŸããïŒ
R4(config-ip-sla)#?
IP SLAs entry configuration commands:
dhcp DHCP Operation
dns DNS Query Operation
exit Exit Operation Configuration
frame-relay Frame-relay Operation
ftp FTP Operation
http HTTP Operation
icmp-echo ICMP Echo Operation
icmp-jitter ICMP Jitter Operation
mpls MPLS Operation
path-echo Path Discovered ICMP Echo Operation
path-jitter Path Discovered ICMP Jitter Operation
slm SLM Operation
tcp-connect TCP Connect Operation
udp-echo UDP Echo Operation
udp-jitter UDP Jitter Operation
voip Voice Over IP Operation
, , IP SLA, : IOS 12.4(4)T , , . , ip sla 1 rtr 1 ip sla responder â rtr responder
ã芧ã®ãšããããã®ãªã¹ãã¯å°è±¡çã§ããèå³ããã人ã¯tsisko.comã«è©³çŽ°ãªèšäºããããŸãã
======================
ã¿ã¹ã¯No. 9
æ¡ä»¶ïŒLinkMiApã¯ãããã€ããŒïŒBGPã§ã¯ãªãïŒãžã®éçã«ãŒãã䜿çšããŸãã
ã¹ããŒã ãšæ§æããããã€ããŒã«ãŒã¿ãŒãBGPã䜿çšããŸããã
ã¿ã¹ã¯ïŒ
ããŒã«ã«ãããã¯ãŒã¯10.0.1.0ããã®HTTPãã©ãã£ãã¯ãBalagan Telecomãééãããããã¯ãŒã¯10.0.2.0ããã®ãã¹ãŠã®ãã©ãã£ãã¯ãFilkin蚌ææžãééããããã«ã«ãŒãã£ã³ã°ãæ§æããŸããéä¿¡è ã®ã¢ãã¬ã¹ã«ä»ã®ã¢ãã¬ã¹ãå«ãŸããŠããå Žåããã©ãã£ãã¯ã¯ç Žæ£ãããæšæºã®ã«ãŒãã£ã³ã°ããŒãã«ã«åŸã£ãŠã«ãŒãã£ã³ã°ãããŸããïŒã€ã³ã¿ãŒãã§ãŒã¹ã«é©çšãããACLã䜿çšããŠãã£ã«ã¿ãªã³ã°ãªãã§ã¿ã¹ã¯ãå®äºããå¿ èŠããããŸãïŒã
è¿œå æ¡ä»¶ïŒPBRã«ãŒã«ã¯ãé©åãªãããã€ããŒã䜿çšå¯èœãªå Žåã«ã®ã¿æ©èœããå¿ èŠããããŸãïŒãã®ã¿ã¹ã¯ã§ã¯ãæãè¿ããããã€ããŒããã€ã¹ã®å¯çšæ§ã確èªããã ãã§ååã§ãïŒããã以å€ã®å Žåã¯ãæšæºã®ã«ãŒãã£ã³ã°ããŒãã«ã䜿çšããå¿ èŠããããŸãã
ã¿ã¹ã¯ã®è©³çŽ°ã¯ãã¡ã
======================
éåžžãIP SLAã®åäœã¯ãæãåçŽãªicmp-echoã®äŸã䜿çšããŠèæ ®ãããŸããã€ãŸããè¡ã®çµããã«pingã§ããå Žåããã©ãã£ãã¯ã¯ãããééããŸãããã§ããªããã°-ããäžæ¹ã«æ²¿ã£ãŠééããŸããããããããå°ãè€éãªæ¹æ³ã§é²ããŸãããããã£ãŠããžãã¿ãªã©ãé³å£°ãã©ãã£ãã¯ã«ãšã£ãŠéèŠãªãã£ãã«ç¹æ§ã«é¢å¿ããããŸããããå ·äœçã«ã¯ãudp-jitterããããã£ãŠã
R4(config-ip-sla)#udp-jitter 192.168.200.1 55555
ãã®ã³ãã³ãã§ã¯ãæ€èšŒã®ã¿ã€ãïŒudp-jitterïŒãæå®ããåŸããµã³ãã«ã®éä¿¡å IPã¢ãã¬ã¹ãéä¿¡ãããŸãïŒã€ãŸããç§ãã¡ãã192.168.200.1ãŸã§ã枬å®ããŸã-ããã¯R1ãžã®ã«ãŒãããã¯ã§ãïŒããã³ããŒãïŒç®æ¡æžã55555ããïŒã§ãã次ã«ããã§ãã¯ã®é »åºŠãèšå®ã§ããŸãïŒããã©ã«ãã¯60ç§ã§ãïŒã
R4(config-ip-sla-jitter)#frequency 10
å¶éå€ãè¶ ãããšãip sla 1ãªããžã§ã¯ãã¯äœ¿çšäžå¯ã«ã€ããŠå ±åããŸãã
R4(config-ip-sla-jitter)#threshold 10
IP SLAã®äžéšã®ã¿ã€ãã®æž¬å®ã§ã¯ãå察åŽã«ãããããã¬ã¹ãã³ããŒãã®ååšãå¿ èŠã§ãããäžéšã®ã¿ã€ãïŒFTPãHTTPãDHCPãDNSãªã©ïŒã¯å¿ èŠãããŸãããç§ãã¡ã®UDPãžãã¿ã¯ãããªãã枬å®ãéå§ããåã«ãããªãã¯R1ãæºåããå¿ èŠããããå¿ èŠããããŸãã
R1(config)#ip sla responder
次ã«ãçµ±èšã®åéãéå§ããå¿ èŠããããŸããåœãã
R4(config)#ip sla schedule 1 start-time now life forever
ã€ãŸã ããã«ãªããžã§ã¯ã1ã®ç£èŠãéå§ããæ°æ¥ãçµãããŸã§ç£èŠããŸãã
çµ±èšåéãéå§ãããŠããå Žåããªããžã§ã¯ããã©ã¡ãŒã¿ãå€æŽããããšã¯ã§ããŸããã ã€ãŸãããšãã°ããµã³ãã«ã®é »åºŠãå€æŽããã«ã¯ããŸãæ å ±ã®åéããªãã«ããå¿ èŠããããŸãïŒno ip sla schedule 1
ããã§äœãèµ·ãã£ãŠããã®ããããããŸãã
R4#sh ip sla statistics 1
Round Trip Time (RTT) for Index 1
Latest RTT: 36 milliseconds
Latest operation start time: *00:39:01.531 UTC Fri Mar 1 2002
Latest operation return code: OK
RTT Values:
Number Of RTT: 10 RTT Min/Avg/Max: 19/36/52 milliseconds
Latency one-way time:
Number of Latency one-way Samples: 0
Source to Destination Latency one way Min/Avg/Max: 0/0/0 milliseconds
Destination to Source Latency one way Min/Avg/Max: 0/0/0 milliseconds
Jitter Time:
Number of SD Jitter Samples: 9
Number of DS Jitter Samples: 9
Source to Destination Jitter Min/Avg/Max: 0/5/20 milliseconds
å®å ãããœãŒã¹ãžã®ãžãã¿ãŒæå°/å¹³å/æ倧ïŒ0/16/28ããªç§
ãã±ããæ倱å€ïŒ
æ倱ãœãŒã¹ããå®å ïŒ0æ倱å®å ãããœãŒã¹ïŒ0
ã·ãŒã±ã³ã¹å€ïŒ0ããŒã«ããããïŒ0
ãã±ããé 延å°çïŒ0ãã±ããã¹ãããïŒ0
é³å£°ã¹ã³ã¢å€ïŒ
èšç®ãããèšç»é害ä¿æ°ïŒICPIFïŒïŒ0
å¹³åãªãããªã³ã¹ã³ã¢ïŒMOSïŒïŒ0
æå
æ°ïŒ12 倱ææ°ïŒ0
皌åæéïŒæ°žé
ããã«èšå®ãããã®ãšåæ§ã«
R4#sh ip sla conf
IP SLAs Infrastructure Engine-II
Entry number: 1
Owner:
Tag:
Type of operation to perform: udp-jitter
Target address/Source address: 192.168.200.1/0.0.0.0
Target port/Source port: 55555/0
Request size (ARR data portion): 32
Operation timeout (milliseconds): 5000
Packet Interval (milliseconds)/Number of packets: 20/10
Type Of Service parameters: 0x0
Verify data: No
Vrf Name:
Control Packets: enabled
Schedule:
Operation frequency (seconds): 10 (not considered if randomly scheduled)
Next Scheduled Start Time: Pending trigger
Group Scheduled: FALSE
Randomly Scheduled: FALSE
Life (seconds): 3600
Entry Ageout (seconds): never
Recurring (Starting Everyday): FALSE
Status of entry (SNMP RowStatus): Active
Threshold (milliseconds): 10
Distribution Statistics:
Number of statistic hours kept: 2
Number of statistic distribution buckets kept: 1
Statistic distribution interval (milliseconds): 4294967295
Enhanced History:
次ã«ããããããã©ãã¯ãèšå®ããŸãïŒæ£ãããªãããç解ã§ãã翻蚳ããã©ãã«ãŒãïŒããã®åŸãã«ãŒããããã®ã¢ã¯ã·ã§ã³ãæ·»ä»ãããŸãããã©ãã¯ã§ã¯ãç¶æ ã®åãæ¿ãã®é 延ãèšå®ã§ããŸããããã«ããã1ã€ã®å€±æãããµã³ãã«ã®ã«ãŒãã£ã³ã°ãå€æŽãã次ã®æ¢ã«æåãããµã³ãã«ã®ã«ãŒãã£ã³ã°ãå€æŽãããšãã®åé¡ã解決ã§ããŸãããã©ãã¯çªå·ãšãæ¥ç¶ããip slaãªããžã§ã¯ãã®çªå·ïŒrtr 1ïŒã瀺ããŸãã
R4(config)#track 1 rtr 1
é 延ã調æŽããŸãã
R4(config-track)#delay up 10 down 15
ã€ãŸããç£èŠãªããžã§ã¯ããèœäžããŠ15ç§ä»¥å ã«äžæããªãã£ãå Žåããã©ãã¯ãdownã«èšå®ããŸãããªããžã§ã¯ããããŠã³ç¶æ ã§ãã£ãããäžæããå°ãªããšã10ç§éäžæç¶æ ã§ãã£ãå Žåããã©ãã¯ãã¢ããç¶æ ã«ããŸãã
次ã®ã¹ãããã¯ããã©ãã¯ãã«ãŒããããã«ãã€ã³ãããããšã§ããç§ã¯R1ã«R5ããæšæºçãªæ¹æ³ã¯ãR2ãééãããªããæãåºãããããŸããããããããæã ã¯ãã¹-MAPAãæã£BACKãããã©ã«ãã®ç¶æ³ãåå²ãåœãŠãR5ã®ãœãŒã¹ã®å ŽåïŒ
R4ïŒsh run | sec route-map
ip policy route-map BACK
route-map BACK permit 10
match ip address 100
set ip next-hop 192.168.3.3
ç£èŠããã®ãããã«é¢é£ä»ããset ip next-hop 192.168.3.3ã³ãã³ããset ip next-hop verify-availability 192.168.3.3 10 track 1ã«çœ®ãæãããšãéã®å¹æãåŸãããŸãïŒãã©ãã¯ããããã®å ŽåïŒã€ã³ãžã±ãŒã¿ãŒãè¶ ããããïŒ sla 1ã®ãžãã¿ãŒïŒããããã¯åäœããŸããïŒãã¹ãŠãã«ãŒãã£ã³ã°ããŒãã«ã«åŸã£ãŠç§»åããŸãïŒãããã³ãã®éãéåžžã®å€ã®å Žåããã©ãã¯ã¯ã¢ãããããã©ãã£ãã¯ã¯R3ãééããŸãã
ä»çµã¿ïŒã«ãŒã¿ãŒã¯ããã±ãããäžèŽæ¡ä»¶ãæºãããŠããããšã確èªããŸãããPBRã®åã®äŸã®ããã«ããã«èšå®ããããäžéã¢ã¯ã·ã§ã³ã§æåã«ãã©ãã¯1ã®ç¶æ ããã§ãã¯ãããã®åŸãèšå®ãããŠããå Žåã¯èšå®æžã¿ã§ãããã§ãªãå Žåã¯ãã«ãŒããããã®æ¬¡ã®è¡ã«ç§»åããŸãã
ããããæ£åžžã«æ©èœããããã«ã¯ãäœããã®æ¹æ³ã§ãã©ãã¯ã®å€ãå転ãããå¿ èŠããããŸãããžãã¿ã倧ããå Žåããã©ãã¯ã¯UPã§ããå¿ èŠããããŸããããã¯ããã©ãã¯ãªã¹ããªã©ã®åŠçã«åœ¹ç«ã¡ãŸããIP SLAã§ã¯ããã©ãã¯å ã®ä»ã®ãã©ãã¯ã®ãªã¹ãïŒæ¬è³ªçã«1ãŸãã¯0ãåºåïŒãçµã¿åãããŠããããã«å¯ŸããŠè«çæŒç®ORãŸãã¯ANDãå®è¡ã§ããŸãããããã®æŒç®ã®çµæã¯ããã®ãã©ãã¯ã®ç¶æ ã«ãªããŸããããã«ããã©ãã¯ã®ç¶æ ã«è«çåŠå®ãé©çšã§ããŸãããã©ãã¯ãªã¹ããäœæããŸãã
R4(config)#track 2 list boolean or
ãã®ããªã¹ããã®å¯äžã®ãã®ã¯ããã©ãã¯1ã®å€ã®è«çåŠå®ã§ãã
R4(config-track)#object 1 not
ã«ãŒããããããã®ãã©ãã¯ã«ãã€ã³ãããŸã
R4(config)#route-map BACK R4(config-route-map)#no set ip next-hop 192.168.3.3 R4(config-route-map)#set ip next-hop verify-availability 192.168.3.3 10 tr 2
neksthopã¢ãã¬ã¹ã®åŸã®10ã¯ããã®ã·ãŒã±ã³ã¹çªå·ã§ããããšãã°ã次ã®ããã«äœ¿çšã§ããŸãã
route-map BACK permit 10 match ip address 100 set ip next-hop verify-availability 192.168.3.3 <b>10</b> track 1 set ip next-hop verify-availability 192.168.2.2 <b>20</b> track 2
ããžãã¯ã¯æ¬¡ã®ãšããã§ããACL100ã«è©²åœãããã©ãã£ãã¯ãéžæãããã©ãã¯1ã®äžéãã§ãã¯ããããã¢ããããŠããå Žåã¯ãã±ããã192.168.3.3 neksthopã«èšå®ããããŠã³ããŠããå Žåã¯æ¬¡ã®ã·ãªã¢ã«çªå·ïŒãã®å Žåã¯20ïŒã«è¡ããåã³äžéã®ã¹ããŒã¿ã¹ããã§ãã¯ããŸããã©ãã¯ïŒãã§ã«ç°ãªããŸãã2ïŒãçµæã«å¿ããŠãnextop 192.168.2.2ãèšå®ããããå¹³åçã«éä¿¡ããŸãïŒäžè¬çãªã«ãŒãã£ã³ã°ïŒã
ããã§ãééã£ãŠããããšãèšèã§å°ã説æããŸãããããã®ãããR2ãéãã«ãŒãã«æ²¿ã£ãŠããœãŒã¹R4ããã¬ã¹ãã³ããŒR1ãŸã§ã®ãžãã¿ãŒã枬å®ããŸãããã®ã«ãŒãã®æ倧蚱容ãžãã¿ãŒå€ã¯10ã§ãããžãã¿ãŒããã®å€ãè¶ ãã15ç§éãã®ã¬ãã«ã®ãŸãŸã§ããå ŽåãR5ã«ãã£ãŠçæããããã©ãã£ãã¯ãR3ãä»ããŠã«ãŒãã«åãæ¿ããŸãããžãã¿ã10ãäžåããå°ãªããšã10ç§éããã«çãŸãå ŽåãR5ããæšæºã«ãŒãã«æ²¿ã£ãŠãã©ãã£ãã¯ãéå§ããŸãããããªã¢ã«ãçµ±åããã«ã¯ããããã®ãã¹ãŠã®å€ãèšå®ãããŠããã³ãã³ããèŠã€ããŠãã ããã
ãã®ãããç®æšãéæããŸãããã¡ã€ã³ãã£ãã«ã®å質ãäœäžããå ŽåïŒå°ãªããšããudp-jitterã®å€ïŒãããã¯ã¢ãããã£ãã«ã«åãæ¿ããŸããããããããŸããªãå Žåã¯ã©ãã§ããïŒãã®åé¡ã解決ããããã«IP SLAã䜿çšããŠã¿ãŠãã ããã
ããããããšã®ããžãã¯ãæ§ç¯ããŠã¿ãŸããããããã¯ã¢ãããã£ãã«ã«åãæ¿ããåã«ããžãã¿ãã©ã®ããã«åŠçããŠãããã確èªããŸãããããè¡ãã«ã¯ãè¿œå ã®ç£èŠãªããžã§ã¯ããååŸããå¿ èŠããããŸããããã¯ããã¹R4-R3-R1ã®ãžãã¿ãŒãèæ ®ãã2ãšããŸããåãå€ã䜿çšããŠãæåã®ãªããžã§ã¯ããšåæ§ã«ããŸããããã¯ã¢ãããã£ãã«ã«æ¡ä»¶ãåãæ¿ãããšããã®åŸã次ã®ããã«ãªããŸãããªããžã§ã¯ãããŠã³1 ãšãªããžã§ã¯ã2ã¢ãããã¡ã€ã³ãã£ãã«ã®å€åŽã®ãžãã¿ã枬å®ããã«ã¯ãR1ããã³R4ã§ã«ãŒãããã¯ã€ã³ã¿ãŒãã§ã€ã¹ãäœæããR3ã©ãŠã³ãããªãããä»ããŠéçã«ãŒããç»é²ããSLA 2ãªããžã§ã¯ãã«ãããã®ã¢ãã¬ã¹ã䜿çšãããšããããªãã¯ãè¡ãå¿ èŠããããŸãã
R1(config)#int lo1 R1(config-if)#ip add 192.168.30.1 255.255.255.0 R1(config-if)#exit R1(config)#ip route 192.168.31.0 255.255.255.0 192.168.1.3 R3(config)#ip route 192.168.30.0 255.255.255.0 192.168.1.1 R3(config)#ip route 192.168.31.0 255.255.255.0 192.168.3.4 R4(config)#int lo0 R4(config-if)#ip add 192.168.31.4 255.255.255.0 R4(config-ip-sla-jitter)#exit R4(config)#ip sla 2 R4(config-ip-sla)#udp-jitter 192.168.30.1 55555 source-ip 192.168.31.4 R4(config-ip-sla-jitter)#threshold 10 R4(config-ip-sla-jitter)#frequency 10 R4(config-ip-sla-jitter)#exit R4(config)#ip route 192.168.30.0 255.255.255.0 192.168.3.3 R4(config)#ip sla schedule 2 start-time now life forever R4(config)#track 3 rtr 2
次ã«ãã«ãŒãããããã¢ã¿ããããããã©ãã¯2ã®æ¡ä»¶ãå€æŽããŸãã
R4(config)#track 2 list boolean and R4(config-track)#object 1 not R4(config-track)#object 3
ããã§ããã©ãã£ãã¯R5-> R1ã¯ãã¡ã€ã³ãã£ãã«ã®ãžãã¿ã10ãè¶ ããåæã«ããã¯ã¢ãããã£ãã«ã®ãžãã¿ã10æªæºã®å Žåã«ã®ã¿ãã©ãŒã«ããã¯ã«ãŒãã«åãæ¿ãããŸããäž¡æ¹ã®ãã£ãã«ã§é«ããžãã¿ã芳å¯ãããå Žåããã©ãã£ãã¯ã¯ã¡ã€ã³ã«æ²¿ã£ãŠé²ã¿ãŸããããŠéãã«èŠããã
ãã©ãã¯ã¹ããŒã¿ã¹ã¯éçã«ãŒãã«ãªã³ã¯ããããšãã§ããŸããããšãã°ãip route 0.0.0.0 0.0.0.0 192.168.1.1 track 1ã³ãã³ãã䜿çšããŠãããã©ã«ãã²ãŒããŠã§ã€192.168.1.1ãäœæããããããã©ãã¯1ã«æ¥ç¶ããŸãïŒããã«ããã確èªã§ããŸãïŒããããã¯ãŒã¯äžã«ãããšåã192.168.1.1ãååšãããããããšã®éä¿¡å質ã®éèŠãªç¹æ§ã枬å®ããŸãïŒããªã³ã¯ããããã©ãã¯ãèœã¡ãå Žåãã«ãŒãã¯ã«ãŒãã£ã³ã°ããŒãã«ããåé€ãããŸãã
ãŸããIP SLAãä»ããŠåä¿¡ããæ å ±ãSNMPãä»ããŠåŒãåºããŠãç£èŠã·ã¹ãã ã®ã©ããã«ä¿åããã³åæã§ããããã«ããããšãéèŠã§ããSNMPãã©ããã æ§æããããšãã§ããŸãã
======================
ã¿ã¹ã¯çªå·10
ã¹ããŒã ïŒä»ã®PBRã¿ã¹ã¯ãšåæ§ã以äžã®èšå®ã
æ¡ä»¶ïŒLinkMiApã¯ããããã€ããŒïŒBGPã§ã¯ãªãïŒãžã®éçã«ãŒãã䜿çšããŸããPBRã¯msk-arbat-gw1ã«ãŒã¿ãŒã§æ§æã
ããŸããHTTPãã©ãã£ãã¯ã¯Filkin蚌ææžãããã€ããŒãééããå¿ èŠãããã10.0.2.0ãããã¯ãŒã¯ããã®ãã©ãã£ãã¯ã¯Balagan Telecomãééããå¿ èŠããããŸãã
æå®ããããã©ãã£ãã¯ã¯æ£ããéä¿¡ãããŸãããBalagan Telecomãããã€ããŒãä»ããŠéä¿¡ããå¿ èŠãããããŒã«ã«ãããã¯ãŒã¯ããã®æ®ãã®ãã©ãã£ãã¯ã¯ã«ãŒãã£ã³ã°ãããŸããã
ã¿ã¹ã¯ïŒ
æ¡ä»¶ãæºããããã«èšå®ãä¿®æ£ããŸãã
æ§æïŒ
ãã ã§ã®ã¿ã¹ã¯ã®è©³çŽ°
======================
eucariot thegluck
ã
hostname msk-arbat-gw1 interface Loopback1 ip address 10.0.1.1 255.255.255.0 ip nat inside ! interface Loopback2 ip address 10.0.2.1 255.255.255.0 ip nat inside ! interface FastEthernet0/0 description Balagan_Telecom_Internet ip address 101.0.0.2 255.255.255.252 ip nat outside duplex auto speed auto ! interface FastEthernet0/1 description Philkin_Certificate_Internet ip address 102.0.0.2 255.255.255.252 ip nat outside speed 100 full-duplex ! ! ip access-list extended LAN permit ip 10.0.1.0 0.0.0.255 any permit ip 10.0.2.0 0.0.0.255 any ! route-map BALAGAN permit 10 match ip address LAN match interface FastEthernet0/0 route-map PH_CERT permit 10 match ip address LAN match interface FastEthernet0/1 ! ip nat inside source route-map BALAGAN interface Fa0/0 overload ip nat inside source route-map PH_CERT interface Fa0/1 overload ! ip access-list extended HTTP permit tcp any any eq 80 ! ip access-list extended LAN2 permit ip 10.0.2.0 0.0.0.255 any ! route-map PBR permit 10 match ip address HTTP set ip next-hop 102.0.0.1 route-map PBR permit 20 match ip address LAN2 set ip next-hop 101.0.0.1 ! ip local policy route-map PBR
ãã ã§ã®ã¿ã¹ã¯ã®è©³çŽ°
======================
䟿å©ãªãªã³ã¯
BGP
- æŠèŠ
- BGPã§ã®æ£èŠè¡šçŸã®äœ¿çš
- ,
- BGP
- LIR, RIR
- FAQ
- BGP
- AS-PATH ACL , AS-PATH Prepend , Load Balancing , Load Sharing Prefix List , Prefix List , Route Map
IP SLA
eucariot thegluck
å©ããŠãããŠããããšããJDimaã
ã¿ã¹ã¯ã¯ãæ¯é¡ã®ãªããã¿ãŒã·ã£ã»ãµã¢ã€ã¬ã³ã³ã«ãã£ãŠç§ãã¡ã«æžãããŸããã
ãæå°ã®ãããã¯ãŒã¯ããšãããµã€ã¯ã«ã«ã¯ãç¬èªã®Webãµã€ãlinkmeup.ruãããããã¹ãŠã®åé¡ããã¡ããšæããããã§ææ ®æ·±ãèªæžã®æºåãã§ããŠããŸãã