05-15-2020 07:11 PM
Hi, Experts,
i've encountered a issue of routing when we separate a router ASR 1001-X to multiple VRF and OSPF processes.
VRF 1: Blue, router ospf 1 vrf blue
VRF 2: red, router ospf 2 vrf red
a routes was redistributed from BGP to OSPF 2 under vrf red.
vrf red and vrf blue are both connecting to an external firewall in a same OSPF Area 0.
the issue we found, we redistributed static routes into OSPF 1 under VRF blue. though firewall, and then VRF Red can learn this route. but we redistributed BGP routes into OSPF 1 at the same way, either VRF red or VRF blue can not learn it.
but the firewall in between can learn all routes properly. it seems the router itself can't install the routes into routing table.
Would you please help on this case.
THanks and regards
Solved! Go to Solution.
05-16-2020 12:00 AM
Hello rock.zhang@fil.com ,
what you see is an expected behaviour as the router acting as a PE node checks the DN bit in the LSAs.
The DN down bit says that the LSA is originated from redistribution from MP BGP and it is a simple but effiicient routing loop avoidance tool.
To disable this checking you need a command in each router ospf process:
router ospf 10
capability vrf-lite
This command should make the router to skip the check of the DN bit.
In the past I had a customer where we used heavily the DN bit concept to avoid mixing routes of different VRFs via the CE nodes.
Hope to help
Giuseppe
05-15-2020 07:18 PM - edited 05-15-2020 07:19 PM
Hi
I'm not sure I got you because you said it works from blue to red but it doesn't work at the same time.
The one working is ospf for GTR (Global Routing Table)?
Do you see the prefix in ospf database or nowhere at all? What the next hop of the route you're looking at? Do your VRFs knows the next hop?
You said firewall knows about these routes but the VRF attached aren't seeing them in their routing table. That's why I'm asking these questions.
05-16-2020 12:00 AM
Hello rock.zhang@fil.com ,
what you see is an expected behaviour as the router acting as a PE node checks the DN bit in the LSAs.
The DN down bit says that the LSA is originated from redistribution from MP BGP and it is a simple but effiicient routing loop avoidance tool.
To disable this checking you need a command in each router ospf process:
router ospf 10
capability vrf-lite
This command should make the router to skip the check of the DN bit.
In the past I had a customer where we used heavily the DN bit concept to avoid mixing routes of different VRFs via the CE nodes.
Hope to help
Giuseppe
05-16-2020 06:22 AM
Many thanks.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide