cancelar
Mostrando los resultados de 
Buscar en lugar de 
Quiere decir: 
cancel
1339
Visitas
10
ÚTIL
2
Respuestas

MP-BGP With VRF - troubleshooting

inteldarvid
Level 1
Level 1

hello team


Good day

Could you help me with the following query, I am configuring a topology, core, h10, B4 and R1. The H10 and B4 Device have a VRF called VRF-MONTAJE and the core is a reflector route of the topology, between the CORE and H10 and B4 there is an MPLS. I configured the ipv4 and vpnv4 families and I can advertise and receive the prefixes of the networks, and I can even receive the R1 with ospf pefixes that are injected into the VRF-MONTAJE. I have the routes in the routing table, but I can't ping the routes, I have no prefix list, no route-map, no ACL, nothing. My question is the following, is something missing at the routing level to reach the networks?

 

Notes I have networks configured with loopbacks


Thank you

I attach the topology and configurations

 

inteldarvid_1-1674945335840.png

 

 

B-4#sh bgp vrf
B-4#sh ip bgp al su
B-4#sh ip bgp al summary
For address family: IPv4 Unicast
BGP router identifier 3.3.3.3, local AS number 22927
BGP table version is 1, main routing table version 1

Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd
1.1.1.1 4 22927 10 6 1 0 0 00:03:39 0

For address family: VPNv4 Unicast
BGP router identifier 3.3.3.3, local AS number 22927
BGP table version is 13, main routing table version 13
6 network entries using 822 bytes of memory
6 path entries using 408 bytes of memory
4/3 BGP path/bestpath attribute entries using 496 bytes of memory
1 BGP rrinfo entries using 24 bytes of memory
2 BGP extended community entries using 64 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
BGP using 1814 total bytes of memory
BGP activity 6/0 prefixes, 6/0 paths, scan interval 15 secs

Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd
1.1.1.1 4 22927 10 6 13 0 0 00:03:39 6
B-4#sh ip bgp al nei
B-4#sh ip bgp al neighbors 1.1.11.1
For address family: IPv4 Unicast

For address family: IPv6 Unicast

For address family: VPNv4 Unicast

For address family: IPv4 Multicast

For address family: IPv6 Multicast

For address family: NSAP Unicast
B-4#sh ip bgp al neighbors 1.1.1.1 ro
B-4#sh ip bgp al neighbors 1.1.1.1 routes
For address family: IPv4 Unicast

Total number of prefixes 0

For address family: VPNv4 Unicast
BGP table version is 13, local router ID is 3.3.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete

Network Next Hop Metric LocPrf Weight Path
Route Distinguisher: 22927:20 (default for vrf VRF-MONTAJE)
*>i5.5.5.5/32 2.2.2.2 2 100 0 ?
*>i172.16.31.0/28 1.1.1.1 0 100 0 ?
*>i172.16.36.0/28 2.2.2.2 0 100 0 ?
*>i172.16.36.17/32 2.2.2.2 2 100 0 ?
*>i172.16.36.33/32 2.2.2.2 2 100 0 ?
*>i172.16.37.0/28 2.2.2.2 0 100 0 ?

Total number of prefixes 6

B-4#sh ip ro
B-4#sh ip route vrf
B-4#sh ip route vrf VRF-MONTAJE PRO
B-4#sh ip route vrf VRF-MONTAJE BGP
B-4#sh ip route vrf VRF-MONTAJE BGP
5.0.0.0/32 is subnetted, 1 subnets
B 5.5.5.5 [200/2] via 2.2.2.2, 00:03:07
172.16.0.0/16 is variably subnetted, 5 subnets, 2 masks
B 172.16.36.17/32 [200/2] via 2.2.2.2, 00:03:07
B 172.16.36.0/28 [200/0] via 2.2.2.2, 00:03:07
B 172.16.37.0/28 [200/0] via 2.2.2.2, 00:03:07
B 172.16.31.0/28 [200/0] via 1.1.1.1, 00:03:07
B 172.16.36.33/32 [200/2] via 2.2.2.2, 00:03:07
B-4#PC
Translating "PC"

Translating "PC"
% Unknown command or computer name, or unable to find computer address
B-4#PC
% Unknown command or computer name, or unable to find computer address
B-4#ping vrf
B-4#ping vrf VRF VRF-MONTAJE 5.5.5.5

Translating "VRF-MONTAJE"

Translating "vrf"
^
% Invalid input detected at '^' marker.

B-4#ping vrf VRF-MONTAJE 5.5.5.5

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 5.5.5.5, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
B-4#ping vrf VRF-MONTAJE 172.16.31.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.31.1, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
B-4#ping vrf VRF-MONTAJE 172.16.36.33

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.36.33, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)
B-4#

######################################################################

 

CORE#sh run
CORE#sh running-config
Building configuration...

Current configuration : 3272 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname CORE
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$Wxip$JUrUe5kg82DBSy9olvlaT1
!
no aaa new-model
!
resource policy
!
ip subnet-zero
no ip icmp rate-limit unreachable
ip cef
ip tcp synwait-time 5
!
!
!
!
ip vrf VRF-BODY
rd 22927:30
route-target export 22927:3020
route-target import 22927:3010
!
ip vrf VRF-MGMT
rd 22927:10
route-target export 22927:1010
route-target import 22927:1010
!
ip vrf VRF-MONTAJE
rd 22927:20
route-target export 22927:2010
route-target import 22927:2020
route-target import 22927:2010
!
no ip domain lookup
ip domain name lab.com
ip ssh version 2
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
username cisco privilege 15 password 0 cisco
!
!
!
!
!
!
!
interface Loopback0
ip address 1.1.1.1 255.255.255.255
ip ospf 1 area 0
!
interface Loopback31
description TEST-VRF-MONTAJE
ip vrf forwarding VRF-MONTAJE
ip address 172.16.31.1 255.255.255.240
!
interface FastEthernet0/0
description Dtribuccion Montaje
ip address 172.16.24.109 255.255.255.252
ip ospf network point-to-point
ip ospf 1 area 0
duplex half
mpls label protocol ldp
mpls ip
!
interface FastEthernet1/0
description BODY Distribuccion
ip address 172.16.24.113 255.255.255.252
ip ospf network point-to-point
ip ospf 1 area 0
duplex half
mpls label protocol ldp
mpls ip
!
router ospf 1
router-id 1.1.1.1
log-adjacency-changes
passive-interface default
no passive-interface FastEthernet0/0
no passive-interface FastEthernet1/0
no passive-interface Loopback0
!
router bgp 22927
bgp router-id 1.1.1.1
bgp log-neighbor-changes
neighbor 2.2.2.2 remote-as 22927
neighbor 2.2.2.2 description MONTAJE
neighbor 2.2.2.2 update-source Loopback0
neighbor 3.3.3.3 remote-as 22927
neighbor 3.3.3.3 description MONTAJE
neighbor 3.3.3.3 update-source Loopback0
!
address-family ipv4
neighbor 2.2.2.2 activate
neighbor 2.2.2.2 soft-reconfiguration inbound
neighbor 3.3.3.3 activate
neighbor 3.3.3.3 soft-reconfiguration inbound
no auto-summary
no synchronization
exit-address-family
!
address-family vpnv4
neighbor 2.2.2.2 activate
neighbor 2.2.2.2 send-community both
neighbor 2.2.2.2 route-reflector-client
neighbor 2.2.2.2 next-hop-self
neighbor 2.2.2.2 maximum-prefix 100
neighbor 3.3.3.3 activate
neighbor 3.3.3.3 send-community both
neighbor 3.3.3.3 route-reflector-client
neighbor 3.3.3.3 next-hop-self
exit-address-family
!
address-family ipv4 vrf VRF-MONTAJE
redistribute connected
redistribute static
no auto-summary
no synchronization
exit-address-family
!
address-family ipv4 vrf VRF-MGMT
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
address-family ipv4 vrf VRF-BODY
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
ip classless
no ip http server
no ip http secure-server
!
!
!
logging alarm informational
no cdp log mismatch duplex
!
!
!
!
control-plane
!
!
!
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line aux 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line vty 0 4
login local
transport input ssh
!
!
end

CORE#
CORE#

 

######################################################################

 

H10#SH RUNning-config
Building configuration...

Current configuration : 3551 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname H10
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$J/LH$OTW2MUPG7HGXB.O4Pwzo1.
!
no aaa new-model
!
resource policy
!
ip subnet-zero
no ip icmp rate-limit unreachable
ip cef
ip tcp synwait-time 5
!
!
!
!
ip vrf VRF-BODY
rd 22927:30
route-target export 22927:3020
route-target import 22927:3010
!
ip vrf VRF-MGMT
rd 22927:10
route-target export 22927:1010
route-target import 22927:1010
!
ip vrf VRF-MONTAJE
rd 22927:20
route-target export 22927:2010
route-target import 22927:2020
route-target import 22927:2010
route-target import 22927:2030
!
no ip domain lookup
ip domain name lab.com
ip ssh version 2
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
username cisco privilege 15 password 0 cisco
!
!
!
!
!
!
!
interface Loopback0
ip address 2.2.2.2 255.255.255.255
ip ospf 1 area 0
!
interface Loopback1
description PLANO CONTROL VRF OSPF 36
ip address 12.12.12.12 255.255.255.255
!
interface Loopback2
description RED1
no ip address
!
interface Loopback3
description RED2
no ip address
!
interface Loopback37
description PREFIJO_TEST_VRF_CONNECT_BGP
ip vrf forwarding VRF-MONTAJE
ip address 172.16.37.1 255.255.255.240
!
interface FastEthernet0/0
description CORE
ip address 172.16.24.110 255.255.255.252
ip ospf network point-to-point
ip ospf 1 area 0
duplex half
mpls label protocol ldp
mpls ip
!
interface FastEthernet1/0
description A1
ip vrf forwarding VRF-MONTAJE
ip address 172.16.36.1 255.255.255.240
ip ospf network point-to-point
duplex full
!
router ospf 36 vrf VRF-MONTAJE
router-id 12.12.12.12
log-adjacency-changes
capability vrf-lite
passive-interface default
no passive-interface FastEthernet1/0
network 12.12.12.12 0.0.0.0 area 0
network 172.16.36.0 0.0.0.15 area 0
default-information originate
!
router ospf 1
router-id 2.2.2.2
log-adjacency-changes
passive-interface default
no passive-interface FastEthernet0/0
no passive-interface Loopback0
!
router ospf 22927
log-adjacency-changes
!
router bgp 22927
bgp router-id 2.2.2.2
bgp log-neighbor-changes
neighbor 1.1.1.1 remote-as 22927
neighbor 1.1.1.1 description MONTAJE
neighbor 1.1.1.1 update-source Loopback0
!
address-family ipv4
neighbor 1.1.1.1 activate
neighbor 1.1.1.1 soft-reconfiguration inbound
no auto-summary
no synchronization
exit-address-family
!
address-family vpnv4
neighbor 1.1.1.1 activate
neighbor 1.1.1.1 send-community both
neighbor 1.1.1.1 next-hop-self
exit-address-family
!
address-family ipv4 vrf VRF-MONTAJE
redistribute connected
redistribute static
redistribute ospf 36 vrf VRF-MONTAJE match internal external 1 external 2
no auto-summary
no synchronization
exit-address-family
!
address-family ipv4 vrf VRF-MGMT
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
address-family ipv4 vrf VRF-BODY
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
ip classless
no ip http server
no ip http secure-server
!
!
!
ip access-list standard permitetodo
!
!
ip prefix-list 10 seq 5 permit 0.0.0.0/0
!
ip prefix-list permitetodo seq 10 permit 0.0.0.0/0
logging alarm informational
no cdp log mismatch duplex
!
!
!
!
control-plane
!
!
!
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line aux 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line vty 0 4
login local
transport input ssh
!
!
end

H10#

 

######################################################################

 

B-4#SH RUN
B-4#SH RUNning-config
Building configuration...

Current configuration : 2464 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname B-4
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$GLlu$1Ok1RIUOpKCvvjVJ2Rtdw/
!
no aaa new-model
!
resource policy
!
ip subnet-zero
no ip icmp rate-limit unreachable
ip cef
ip tcp synwait-time 5
!
!
!
!
ip vrf VRF-BODY
rd 22927:30
route-target export 22927:3020
route-target import 22927:3010
!
ip vrf VRF-MGMT
rd 22927:10
route-target export 22927:1010
route-target import 22927:1010
!
ip vrf VRF-MONTAJE
rd 22927:20
route-target export 22927:2030
route-target import 22927:2020
route-target import 22927:2010
!
no ip domain lookup
ip domain name lab.com
ip ssh version 2
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
username cisco privilege 15 password 0 cisco
!
!
!
!
!
!
!
interface Loopback0
ip address 3.3.3.3 255.255.255.255
ip ospf 1 area 0
!
interface FastEthernet0/0
no ip address
shutdown
duplex half
!
interface FastEthernet1/0
description CORE
ip address 172.16.24.114 255.255.255.252
ip ospf network point-to-point
ip ospf 1 area 0
duplex half
mpls label protocol ldp
mpls ip
!
router ospf 1
router-id 3.3.3.3
log-adjacency-changes
passive-interface default
no passive-interface FastEthernet1/0
no passive-interface Loopback0
!
router bgp 22927
no synchronization
bgp router-id 3.3.3.3
bgp log-neighbor-changes
neighbor 1.1.1.1 remote-as 22927
neighbor 1.1.1.1 description MONTAJE
neighbor 1.1.1.1 update-source Loopback0
neighbor 1.1.1.1 soft-reconfiguration inbound
no auto-summary
!
address-family vpnv4
neighbor 1.1.1.1 activate
neighbor 1.1.1.1 send-community both
neighbor 1.1.1.1 next-hop-self
exit-address-family
!
address-family ipv4 vrf VRF-MONTAJE
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
address-family ipv4 vrf VRF-MGMT
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
address-family ipv4 vrf VRF-BODY
redistribute connected
no auto-summary
no synchronization
exit-address-family
!
ip classless
no ip http server
no ip http secure-server
!
!
!
logging alarm informational
no cdp log mismatch duplex
!
!
!
!
control-plane
!
!
!
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line aux 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line vty 0 4
login local
transport input ssh
!
!
end

B-4#

 

######################################################################

 

R1#SH RUN
R1#SH RUNning-config
Building configuration...

Current configuration : 2906 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
resource policy
!
ip subnet-zero
no ip icmp rate-limit unreachable
ip cef
ip tcp synwait-time 5
!
!
!
!
ip vrf ospf_montaje
rd 36:1
!
no ip domain lookup
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface Loopback0
ip vrf forwarding ospf_montaje
ip address 5.5.5.5 255.255.255.255
!
interface Loopback2
description RED1
ip vrf forwarding ospf_montaje
ip address 172.16.36.17 255.255.255.248
!
interface Loopback3
description RED2
ip vrf forwarding ospf_montaje
ip address 172.16.36.33 255.255.255.248
!
interface Loopback31
no ip address
!
interface FastEthernet0/0
description H10
ip vrf forwarding ospf_montaje
ip address 172.16.36.2 255.255.255.240
ip ospf network point-to-point
duplex full
!
interface GigabitEthernet1/0
no ip address
shutdown
negotiation auto
!
!
router ospf 36 vrf ospf_montaje
router-id 5.5.5.5
log-adjacency-changes
capability vrf-lite
network 5.5.5.5 0.0.0.0 area 0
network 172.16.36.0 0.0.0.15 area 0
network 172.16.36.16 0.0.0.7 area 0
network 172.16.36.32 0.0.0.7 area 0
!
ip classless
no ip http server
no ip http secure-server
!
!
!
logging alarm informational
no cdp log mismatch duplex
!
!
!
!
control-plane
!
!
!
!
!
!
gatekeeper
shutdown
!
!
line con 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line aux 0
exec-timeout 0 0
privilege level 15
logging synchronous
stopbits 1
line vty 0 4
login
!
!
end

R1#

1 SOLUCIÓN ACEPTADA

Soluciones aceptadas
2 RESPUESTAS 2

Jose Suarez
Level 1
Level 1

Hi,

I copy a link that you can use as a reference:


https://www.cisco.com/c/en/us/support/docs/multiprotocol-label-switching-mpls/mpls/13733-mpls-vpn-basic.html

Regards

Jose Suarez
CCIE No. 66421

.

Thank  you so much José. 

Have Nice day

Vamos a comenzar

¡Conecte con otros expertos de Cisco y del mundo! Encuentre soluciones a sus problemas técnicos o comerciales, y aprenda compartiendo experiencias.

Queremos que su experiencia sea grata, le compartimos algunos links que le ayudarán a familiarizarse con la Comunidad de Cisco: