SOLID WASTE MANAGEMENT SYSTEM OF FENI PAURASHAVA, BANGLADESH.pdf
PLNOG 6: Marcin Kuczera - Obsługa abonentów poprzez sieć L2 i L3, czyli ciąg dalszy centralnego BRASa w sieci?
1. PLNOG 6, Warszawa, 17 Marca 2010
● coś o mnie
● dlaczego kontynuacja tematu ?
Obsługa abonentów poprzez sieć
L2 i L3, czyli ciąg dalszy
centralnego BRASa w sieci
2. PLNOG 6, Warszawa, 17 Marca 2010
SE100 #1
BGP peer 1 BGP peer 2 BGP peer 3
Obecna struktura sieci
SE100 #2
3. PLNOG 6, Warszawa, 17 Marca 2010
O&M
Radius
PPPoE - implementacja
context wifi1
vlan 521
vlan 522
vlan 523
vlan 524
Vlan 525
port ethernet 2/3
dot1q pvc 521 encapsulation multi
mac-address 00:00:01:ac:01:00
circuit protocol pppoe
bind authentication chap maximum 2000
dot1q pvc 522 encapsulation multi
mac-address 00:00:01:ac:01:00
circuit protocol pppoe
bind authentication chap maximum 2000
802.1Q or QinQ
4. PLNOG 6, Warszawa, 17 Marca 2010
[local]RedBack_SE100#context wifi1
[wifi1]RedBack_SE100#show config
Building configuration...
Current configuration:
!
context wifi1
domain wifi advertise
!
…
[wifi1]RedBack_SE100#context voip1
[voip1]RedBack_SE100#show config
Building configuration...
Current configuration:
!
context voip1
domain voip advertise
!
…
[voip1]RedBack_SE100#context sgt-tv
[sgt-tv]RedBack_SE100#show config
Building configuration...
Current configuration:
!
context sgt-tv
!
...
[voip1]RedBack_SE100#context local
[local]RedBack_SE100#show config
!
…
!
pppoe services marked-domains
pppoe tag ac-name leon-ac01
pppoe always-send-padt
!
...
PPPoE implmentacja - cont.
5. PLNOG 6, Warszawa, 17 Marca 2010
O&M
Radius
CLIPS implementatacja
context clips
vlan 3301
vlan 3302
vlan 3303port ethernet 2/3
dot1q pvc 3301 encapsulation multi
mac-address 00:00:01:ac:01:00
service clips dhcp context clips
dot1q pvc 3302 encapsulation multi
mac-address 00:00:01:ac:01:00
service clips dhcp context clips
802.1Q or QinQ
87.101.75.212/20
87.101.64.89/20
87.101.66.120/20
87.101.70.227/20
87.101.71.56/20
interface clips multibind
description GW interface
ip address 87.101.64.1/20
dhcp server interface
ip arp proxy-arp
ClientLess IP Service
6. PLNOG 6, Warszawa, 17 Marca 2010
BGP
management
clips
wifi
voip
bgp peer 1
bgp peer 2
bgp peer 3
RedBack SE100
lan-1
wifi vlan-1
wifi vlan-n
lan-n
O&M
Radius
voip
IP PBX
CLIPS & PPPoE
7. PLNOG 6, Warszawa, 17 Marca 2010
CLIPS & PPPoE
# regular DHCP + PPPoE
!
port ethernet 2/3
encapsulation dot1q
dot1q pvc 5 encapsulation multi
bind interface vlan5 bgp1
circuit protocol pppoe
bind authentication chap maximum 100
!
# CLIPS (DHCP) + PPPoE
!
port ethernet 2/3
encapsulation dot1q
dot1q pvc 10 encapsulation multi
service clips dhcp context clips
circuit protocol pppoe
bind authentication chap maximum 100
!
8. PLNOG 6, Warszawa, 17 Marca 2010
Wprowadzamy GEPON
10.0.0.10/24
10.0.0.227/24
10.0.0.99/24
OLT
ONUAle w czym problem ???
PON
10.0.0.13/24
10.0.0.108/24
10.0.0.1/24
9. PLNOG 6, Warszawa, 17 Marca 2010
Wprowadzamy GEPON
10.0.0.10/24
10.0.0.227/24
10.0.0.99/24
OLT
ONUAle w czym problem ???
PON
10.0.0.13/24
10.0.0.108/24
10.0.0.1/24
10. PLNOG 6, Warszawa, 17 Marca 2010
Jak to podobno zrobił Dialog ?
10.0.0.10/32
10.0.0.227/32
10.0.0.99/32
OLT
ONU
PON
10.0.0.13/32
10.0.0.108/32
10.0.0.1/24
BRAS
Sesje PPPoE
11. PLNOG 6, Warszawa, 17 Marca 2010
O&M
Radius
A jak my to zrobiliśmy ??
context clips
port ethernet 2/4
dot1q pvc 3301 encapsulation multi
service clips dhcp context clips
188.137.48.10/23
188.137.48.17/23
188.137.48.99/23
188.137.49.10/23
188.137.49.89/23
interface GEPON multibind
description Adresacja dla GEPONa
ip address 188.137.48.1/23
dhcp server interface
ip arp proxy-arp always
GEPON + CLIPS
OLT
ONU
vlan3036
12. PLNOG 6, Warszawa, 17 Marca 2010
OLT
ONUI po problemie ;)
PON
188.137.48.1/23
GEPON + CLIPS cont.
188.137.48.10/23
188.137.48.17/23
188.137.48.99/23
188.137.49.10/23
188.137.49.89/23
ip arp proxy-arp always
13. PLNOG 6, Warszawa, 17 Marca 2010
CLIPS po L3 ???
O&M
Radius
context clips
LAN 1
LAN 2
LAN 3
802.1Q vlan
MAC LIMIT
Np. usługa Netii lub 3s
14. PLNOG 6, Warszawa, 17 Marca 2010
O&M
Radius
BRAS
context bgp2
95.131.35.64/26
vlan 806
95.131.35.249/30
Świat
Switch L3
95.131.35.250/30
95.131.35.65
95.131.35.90
95.131.35.70
95.131.35.77
CLIPS po L3
16. PLNOG 6, Warszawa, 17 Marca 2010
CLIPS po L3 – BRAS
# BRAS
# Ericsson/Redback SE100
!
context bgp2
!
no ip domain-lookup
!
interface to-l3-router
ip address 95.131.35.249/30
ip access-group acl-for-l3-relays-only in
!
interface vlan300
description ATMAN - transit.global
ip address 212.91.8.246/30
!
interface vlan796
description crowley-decix AS49001
ip address 93.159.57.138/30
!
interface vlan806 multibind
description clipsL3
ip address 95.131.35.126/26
dhcp server interface
no logging console
!
!
ip access-list acl-for-l3-relays-only
seq 10 permit ip host 95.131.35.250
seq 11 permit ip host 95.131.35.65
!
aaa authentication subscriber none
!
subscriber default
dhcp max-addrs 1
dns primary 195.66.73.2
dns secondary 195.66.73.11
!
ip route 95.131.35.64/26 95.131.35.250 connected tag 777
!
dhcp server policy
option domain-name-server 195.66.73.2 195.66.73.11
subnet 95.131.35.64/26 name clipsL3
range 95.131.35.70 95.131.35.100
option router 95.131.35.65
!
!
port ethernet 2/16
auto-negotiate flc tx&rx force enable
no shutdown
encapsulation dot1q
dot1q pvc 806
bind interface to-l3-router bgp2
service clips dhcp context bgp2
!
17. PLNOG 6, Warszawa, 17 Marca 2010
CLIPS po L3 – BRAS
[bgp2]R1_SE100#show subscribers active
00:00:24:c5:03:e0
Session state Up
Circuit 2/16 vlan-id 806 clips 212855
Internal Circuit 2/16:1023:63/7/2/46895
Interface bound vlan806
Current port-limit unlimited
dns primary 195.66.73.2 (applied from sub_default)
dns secondary 195.66.73.11 (applied from sub_default)
dhcp max-addrs 1 (applied)
IP host entries installed by DHCP: (max_addr 1 cur_entries 1)
95.131.35.70 00:00:24:c5:03:e0
[bgp2]R1_SE100#show circuit
Circuit Internal Id Encap State Bound to
2/16 vlan-id 806 1/2/636 dot1q Up to-l3-router@bgp2
2/16 vlan-id 806 clips 212855 7/2/46895 dot1q clips Up vlan806@bgp2
[bgp2]R1_SE100#show bindings
Circuit State Encaps Bind Type Bind Name
2/16 vlan-id 806 Up dot1q interface to-l3-router@bgp2
2/16 vlan-id 806 clips 212855 Up dot1q clips authen 00:00:24:c5:03:e0
18. PLNOG 6, Warszawa, 17 Marca 2010
CLIPS po L3 – Zapętlić ruch przez BRAS
Ale po co ???
O&M
Radius
BRAS
context bgp2
95.131.35.64/26
vlan 806
Świat
Switch L3
Cisco – private vlan z forwardowaniem ruchu na wybrany port
19. PLNOG 6, Warszawa, 17 Marca 2010
Co z obsługą RouteSerwerów ??
Wprowadzone od SEOS 6.4.1.1.. ale....
20. PLNOG 6, Warszawa, 17 Marca 2010
Co z Ipv6 dla abonentów (BRAS) ??
Wprowadzone w SEOS 6.3.1.2
Oraz w SEOS 6.4.1.1.. ale....
21. PLNOG 6, Warszawa, 17 Marca 2010
W przypadku pytań:
Marcin Kuczera
E-mail: marcin.kuczera@leon.pl
Tel. +48 605 592 617