ãã®èšäºã§ã¯ãCisco Embedded Event ManagerïŒEEMïŒã䜿çšããŠè€æ°ã®ã¢ããã¹ããªãŒã ãããã€ããŒããã®ã€ã³ããŠã³ããã©ãã£ãã¯ãšã¢ãããªã³ã¯åé·æ§ã®ãã©ã³ã¹ããšããIOS XEãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšããCiscoã«ãŒã¿ãŒã§ã®BPGã¢ããŠã³ã¹ã¡ã³ãã®ç®¡çæ¹æ³ã«ã€ããŠèª¬æããŸãã
ã¯ããã«
å€ãã®å Žåãå°èŠæš¡ãããã€ããŒã®ãããã¯ãŒã¯ã§ã¯ãã¢ãããªã³ã¯ã2ã€ä»¥äžã®ãªãã¬ãŒã¿ãŒãžã®BGPæ¥ç¶ã§ãããšããç¶æ³ã«ééããå¯èœæ§ããããŸãã ããã«ã2çªç®ã®ãããã€ããŒã¯ãªã¶ãŒããšããŠã¯äœ¿çšãããŸããããæåã®ãããã€ããŒãšåæã«ãåæã«äœ¿çšãããŸãã ããã«ããããã®ãã£ãã«ã¯é床ã察称ã§ã¯ãªãå¯èœæ§ããããããç¶æ³ã¯è€éã§ãã ããšãã°ãåèš2 Gbpsã®ã¢ãããªã³ã¯ãå¿
èŠãªå Žåã2ã€ã®ç°ãªããããã€ããŒïŒ1500 Mbpsãš500 MbpsïŒãã2ã€ã®ãã£ãã«ã賌å
¥ãããŸãã ãã®å ŽåãBGPã¯åé·æ§ã®åé¡ãå®å
šã«è§£æ±ºããŸãã ãã¡ãããããã«ã¯å®å
šãªæºåéã¯ãããŸããã æããã«ãå å
¥è
ã®ãµãŒãã¹ãäœäžãããã«500ã¡ã¬ãããã§2ã®ã¬ããããäºçŽããããšã¯äžå¯èœã§ããããµãŒãã¹ã®å®å
šãªé害ã¯çºçããŸããã ãŸããPRNã§æåŠãçºçããªãå ŽåïŒæå€§è² è·ã®æéïŒããµãŒãã¹ã¯ãŸã£ãã圱é¿ãåããªãå¯èœæ§ããããŸãã
ãã®ç¶æ³ã§ã¯ãåé·æ§ã§ã¯ãªããã©ã³ã¹ã®åé¡ã倧å¹
ã«çºçããŸãã ç¹ã«é床ã®ãã£ã³ãã«ã®é察称æ§ã®ããã ããã«ãçºä¿¡ãã©ãã£ãã¯ã®ãã©ã³ã¹èª¿æŽïŒå€ããå°ãªããå¶åŸ¡ã§ããŸãïŒã¯ããã»ã©éèŠã§ã¯ãããŸããã ãã ããçä¿¡ãã©ãã£ãã¯ãå¶åŸ¡ããããšã¯ã¯ããã«å°é£ã§ãã
äŸãšããŠã次ã®ã¹ããŒã ãèããŸãã
AS65000ã¯ãISPïŒ1ïŒAS65001ïŒãšISPïŒ2ïŒAS65002ïŒã®2ã€ã®ãããã€ããŒã«ãããã1.5 Gbpsãš500 Mbpsã®ãã£ãã«ã§æ¥ç¶ãããŠããŸãã ãããã¯ãŒã¯å
ã®ãµãã¹ã¯ã©ã€ããŒã¯ã3ã€ã®ããŒã«ã«ã«ãŒã¿ãŒR7ãR8ãããã³R9ã®èåŸã«ããããããã3ã€ã®ãµããããã䜿çšããŠããŸãã
- 172.16.7.0/24
- 172.16.8.0/24
- 172.16.9.0/24
3ã€ã®ã«ãŒã¿ãŒããã°ããŒãã«ã€ã³ã¿ãŒããããªãœãŒã¹ããšããŠæ©èœããŸãã
- R5ïŒAS65050ã10.0.5.0 / 24ïŒ-äž¡æ¹ã®ãããã€ããŒã«å å
¥ããŠããŸãã
- R10ïŒAS65100ã10.0.10.0 / 24ïŒ-ISPïŒ1ã®ã¿ã«æ¥ç¶;
- R11ïŒAS65110ã10.0.11.0 / 24ïŒ-ISPïŒ2ã«ã®ã¿æ¥ç¶ãããŠããŸãã
ãããã€ããŒã«ã¯ãã¢ããŒãã¢ãžã§ã€ã³ãããããŸãïŒR12ãšR13ã®éïŒã
ããŠã³ããŒãããããã€ããŒã®åçã«çŽæ¥é¢é£ããã¯ã©ã€ã¢ã³ãæ¥ç¶ãšã¯ç°ãªãããã¢ããŒãã¢æ¥ç¶ã¯ãããã€ããŒã«çŽæ¥åå
¥ããããããªãããæ¶è²»ããããšããã§ããŸããã ãããã£ãŠãã¯ã©ã€ã¢ã³ãæ¥ç¶ã®BPG Local Preferenceãå¢ããããã¢ã®BPG Local Preferenceãæžããã®ãéåžžã§ãã ãã®ã¹ããŒã ã§ã¯ãããŒã«ã«ããªãã¡ã¬ã³ã¹å€ã¯èµ€ãããŒã«ãŒã§ç€ºãããŸãïŒäž¡æ¹ã®ãããã€ããŒã®ãã¢ãªã³ã°ã®å€ã¯100ïŒããã©ã«ãïŒã§ãããã¯ã©ã€ã¢ã³ããšã®æ¥ç¶ã§ã¯120ã«å¢å ããŸãããã®ãªãã·ã§ã³ã«ããããããã€ããŒã¯ã¯ã©ã€ã¢ã³ãããåãBPGã«ãŒããåä¿¡ã§ããŸãå¥ã®ãããã€ããŒãæ瀺çã«ã¯ã©ã€ã¢ã³ãæ¥ç¶ã奜ãã åæã«ãããã¯æšæºã®BGPããŒã«ã䜿çšããã¢ãããªã³ã¯ãã©ã³ã·ã³ã°ã®åé¡ã®åå ã®1ã€ã§ãã
ãã©ã³ã¹èª¿æŽ
ãã§ã«æžããããã«ãçºä¿¡ãã©ãã£ãã¯ã®ãã©ã³ã¹èª¿æŽã¯ã»ãšãã©ã®ãããã€ããŒã«ãšã£ãŠããã»ã©éèŠã§ã¯ãªãããããã®èšäºã®ãããã¯ã¯çä¿¡ãã©ãã£ãã¯ã®ç®¡çã§ãã ãã©ãã£ãã¯ã2ã€ã®é察称ãã£ãã«ã«å解ããå¿
èŠããããŸãã
- ISPïŒ1ãä»ãã1500 Mbps;
- ISPïŒ2ãä»ãã500 Mbps
çµéšçã«ãå¿
èŠãªå²åã§ãã©ãã£ãã¯ããæ¶è²»ããã2ã€ã®ç¯å²ã®IPã¢ãã¬ã¹ã確ç«ããŸãã ç¶æ³ãç°¡åã«ããããã«ïŒæ¹æ³ã®ååã¯ããããå€æŽãããŸããïŒãR7ããã³R8ã«ãŒã¿ãŒã®èåŸã«ãããµãã¹ã¯ã©ã€ããŒãåèšçä¿¡ãã©ãã£ãã¯ã®çŽ4åã®3ãæ¶è²»ããæ®ãã®4åã®1ãR9ã«ãŒã¿ãŒã®ãµãã¹ã¯ã©ã€ããŒã«è©²åœãããšä»®å®ããŸãã ãã®å ŽåãBGPã¢ããŠã³ã¹ã¡ã³ãã䜿çšããŠããããã¯ãŒã¯172.16.7.0/24ããã³172.16.8.0/24ã®ãã©ãã£ãã¯ãISPïŒ1ãééãããããã¯ãŒã¯172.16.9.0/24ã®ãã©ãã£ãã¯ãISPïŒ2ãééããããšã確èªããå¿
èŠããããŸãã
2ã€ã®ãã¬ãã£ãã¯ã¹ãªã¹ããäœæãããã£ãã«ããšã«ãããã®ãã©ãã£ãã¯ãåé¢ããæ¹æ³ãæ€èšããŸãã
ip prefix-list isp-1-out seq 5 permit 172.16.7.0/24 ip prefix-list isp-1-out seq 10 permit 172.16.8.0/24 ip prefix-list isp-2-out seq 5 permit 172.16.9.0/24
AS-PATH Prepend
ãã®åé¡ã®æšæºçãªè§£æ±ºçãšããŠãBGPã¯AS-PATH Prependã¡ã«ããºã ãæäŸããŸãã ãã®æ¬è³ªã¯ãããã€ãã®å¯èœãªãã®ããæé©ãªã«ãŒããéžæãããšãã«ãBGPãããã³ã«ãAS-PATHå±æ§ã®å€ã䜿çšããBGPã¢ããŠã³ã¹ã¡ã³ããééãããã¹ãŠã®èªåŸã·ã¹ãã ã®çªå·ãé çªã«ãªã¹ãããããšã§ãã æçã®AS-PATHã«ãŒããåªå
ãããŸãã AS-PATH prependã¡ãœããã䜿çšãããšãäžéšã®ã«ãŒãã®å±æ§å€ã人çºçã«æ¡åŒµã§ããŸãã
ãã®ã¡ãœããããããã¯ãŒã¯ã«é©çšããŠã¿ãŸãããã ãããè¡ãã«ã¯ãCSRã«2ã€ã®ã«ãŒãããããäœæããŠäœ¿çšããŸãã
route-map isp-1-out permit 10 match ip address prefix-list isp-1-out route-map isp-1-out permit 20 match ip address prefix-list isp-2-out set as-path prepend 65000 65000 65000 route-map isp-2-out permit 10 match ip address prefix-list isp-1-out set as-path prepend 65000 65000 65000 route-map isp-2-out permit 20 match ip address prefix-list isp-2-out router bgp 65000 address-family ipv4 neighbor 192.168.101.1 route-map isp-1-out out neighbor 192.168.103.3 route-map isp-2-out out
ããã§ãISPïŒ1ã«åããŠããã¬ãã£ãã¯ã¹172.16.9.0/24ã3ã€ã®AS65000çªå·ã«ãã£ãŠæ¡åŒµãããAS-PATHã§ã¢ããŠã³ã¹ãããISPïŒ2ã«åããŠããã¬ãã£ãã¯ã¹172.16.7.0/24ããã³172.16.8.0/24ã«å¯ŸããŠåãããšãè¡ãããŸãã
ããã§ãçæ³çã«ã¯ããã¬ãã£ãã¯ã¹ã®åã°ã«ãŒãã®ãã©ãã£ãã¯ã¯ãã®ãããã€ããŒãçµç±ããã¢ãããªã³ã¯ã®1ã€ãèœã¡ãå Žåãprependã䜿çšããã¢ããŠã³ã¹ã¡ã³ããæ©èœãå§ããŸãã ããšãã°ãISPïŒ2ãã¯ã©ãã·ã¥ããå Žåã172.16.9.0 / 24ã®ãã©ãã£ãã¯ã¯äžæãããŸãããããã¯ãAS-PATHãæ¡åŒµãããŠããŠããå
šäžçã§ISPïŒ1ãéããŠãã®ãã¬ãã£ãã¯ã¹ã衚瀺ãããããã§ãã
ãã®æ¹æ³ã¯æ©èœããŸãããããã§ã¯ãããã€ããŒãã¯ã©ã€ã¢ã³ããšãã¢ãªã³ã°ã«äœ¿çšããããŸããŸãªããŒã«ã«èšå®ãã²ãŒã ã«å¹²æžããŸãã ã«ãŒããéžæãããšããLOCAL PREFERENCEå±æ§ãAS-PATHãããåªå
ããããããããªãã³ãã¯åãããã€ããŒå
ã§åœ¹å²ãæãããããã©ãã£ãã¯ã¯åžžã«ã¯ã©ã€ã¢ã³ããã£ãã«ãä»ããŠã«ãŒãã£ã³ã°ãããŸãã ãããã¯ãŒã¯ã§ã¯ããã®æ¹æ³ã¯äž¡æ¹ã®ãããã€ããŒã«æ¥ç¶ãããŠãããããAS65050ã§ã®ã¿æ©èœããŸãã
ãã£ãšè©³ããèŠãŠã¿ãŸãããã
å®éãR5ã§ã¯ãã¹ãŠåé¡ãããŸããã
R5#sh ip bgp ... * 172.16.7.0/24 192.168.45.4 0 65002 65000 65000 65000 65000 ? *> 192.168.25.2 0 65001 65000 ? * 172.16.8.0/24 192.168.45.4 0 65002 65000 65000 65000 65000 ? *> 192.168.25.2 0 65001 65000 ? *> 172.16.9.0/24 192.168.45.4 0 65002 65000 ? * 192.168.25.2 0 65001 65000 65000 65000 65000 ? R5#sh ip route ... 172.16.0.0/24 is subnetted, 3 subnets B 172.16.7.0 [20/0] via 192.168.25.2, 1d00h B 172.16.8.0 [20/0] via 192.168.25.2, 1d00h B 172.16.9.0 [20/0] via 192.168.45.4, 1d00h R5#traceroute 172.16.7.1 source 10.0.5.1 ... 1 192.168.25.2 0 msec 0 msec 1 msec 2 192.168.12.1 0 msec 1 msec 0 msec 3 192.168.101.100 3 msec 3 msec 3 msec 4 192.168.107.7 2 msec * 2 msec R5#traceroute 172.16.9.1 source 10.0.5.1 ... 1 192.168.45.4 1 msec 0 msec 1 msec 2 192.168.34.3 0 msec 1 msec 0 msec 3 192.168.103.100 3 msec 3 msec 3 msec 4 192.168.109.9 2 msec * 3 msec
AS-PATHå±æ§ã«åºã¥ããŠããã¬ãã£ãã¯ã¹ã®åã°ã«ãŒãã«å¯ŸããŠããããã€ããŒãä»ããŠæé©ãªã«ãŒããéžæããããã¬ãŒã¹ã確èªãããŸãã
ããããR11ïŒAS65110ïŒã§ã¯ããã¹ãŠããã©è²ã§ã¯ãããŸããã
R11#traceroute 172.16.7.1 source 10.0.11.1 ... 1 192.168.114.4 0 msec 1 msec 4 msec 2 192.168.34.3 1 msec 0 msec 0 msec 3 192.168.103.100 3 msec 3 msec 3 msec 4 192.168.107.7 2 msec * 2 msec R11#traceroute 172.16.9.1 source 10.0.11.1 ... 1 192.168.114.4 0 msec 1 msec 0 msec 2 192.168.34.3 0 msec 0 msec 0 msec 3 192.168.103.100 3 msec 2 msec 3 msec 4 192.168.109.9 2 msec * 2 msec
äž¡æ¹ã®ãã¹ããžã®ãã©ãã£ãã¯ã¯ãåã5ã¡ã¬ãã€ãã®ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠéä¿¡ãããŸãã
ãã®çç±ã¯ãåã«å°å
ã®å¥œã¿ã§ãã ISPïŒ2ãããã€ããŒR13ã確èªããŸãã
R13>sh ip bgp ... * 172.16.7.0/24 192.168.200.12 0 65001 65000 ? *>i 192.168.103.100 0 120 0 65000 65000 65000 65000 ? * 172.16.8.0/24 192.168.200.12 0 65001 65000 ? *>i 192.168.103.100 0 120 0 65000 65000 65000 65000 ? * 172.16.9.0/24 192.168.200.12 0 65001 65000 65000 65000 65000 ? *>i 192.168.103.100 0 120 0 65000 ? R13#sh ip route ... 172.16.0.0/24 is subnetted, 3 subnets B 172.16.7.0 [200/0] via 192.168.103.100, 1d00h B 172.16.8.0 [200/0] via 192.168.103.100, 1d00h B 172.16.9.0 [200/0] via 192.168.103.100, 1d00h
ã«ãŒã¿ãŒã§ã¯ã2ã€ã®ã³ããŒã®ãããã¯ãŒã¯ã®ãã¹ãŠã®BGPã¢ããŠã³ã¹ã¡ã³ãïŒ
- ã¯ã©ã€ã¢ã³ãæ¥ç¶ïŒnext-hop 192.168.103.100ïŒãä»ããŠåä¿¡ã
- ãã¢ãªã³ã°ãä»ããŠåä¿¡ïŒnext-hop 192.168.200.12ïŒã
ãã ããAS-PATHãé·ãã«ããããããã172.16.7.0 / 24ããã³172.16.8.0/24ã®ãã¬ãã£ãã¯ã¹ã®å Žåãæé©ãªã«ãŒãã¯ã¯ã©ã€ã¢ã³ããä»ããããŒã«ã«ããªãã¡ã¬ã³ã¹120ã®ã«ãŒãã§ãã ãã¢ãªã³ã°ã§ã¯ãªããç§ãã¡ãéããŠã ISPïŒ2ã¯ãå å
¥è
ã®ãã¹ãŠã®ãã©ãã£ãã¯ã500Mbpsãã£ãã«ãä»ããŠéä¿¡ããããšãããããŸããã ãããŠããã®ãããã€ããŒãäž»èŠãªã³ã³ãã³ããããã€ããŒïŒVK.comãªã©ïŒã®ããŒã¿ã»ã³ã¿ãŒã§ããããšãå€æããå Žåãããã¯ãã£ãã«ã®éè² è·ãšãµãŒãã¹ã®åé¡ã«ã€ãªãããŸãã
æšæºã®AS-PATHããªãã³ãã¯åœ¹ã«ç«ããªãããšãããããŸãã
ãç¥ããã®é€å€
ãã©ãã£ãã¯ãåé¢ããå¥ã®æ¹æ³ã¯ããã®ãããã€ããŒãä»ããŠãã©ãã£ãã¯ãåä¿¡ããããªããã¬ãã£ãã¯ã¹ããªãã¬ãŒã¿ãŒãžã®BGPã¢ããŠã³ã¹ããåã«é€å€ããããšã§ãã
ãã£ãŠã¿ãŸãããã
ã«ãŒããããã®ä»£ããã«ãåãã€ããŒã«ãã£ã«ã¿ãªã³ã°ãã¬ãã£ãã¯ã¹ãªã¹ããèšå®ããŸãã
router bgp 65000 address-family ipv4 neighbor 192.168.101.1 prefix-list isp-1-out out neighbor 192.168.103.3 prefix-list isp-2-out out
çŸåšããã®ãžã£ã³ã¯ã·ã§ã³ãä»ããŠãã©ãã£ãã¯ãåä¿¡ããå¿
èŠãããã«ãŒãã®ã¿ãåãããã€ããŒã«ã¢ããŠã³ã¹ãããŸãã
CSR#sh ip bgp neighbors 192.168.101.1 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.7.0/24 192.168.107.7 0 32768 ? *> 172.16.8.0/24 192.168.108.8 0 32768 ? Total number of prefixes 2 CSR#sh ip bgp neighbors 192.168.103.3 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.9.0/24 192.168.109.9 0 32768 ? Total number of prefixes 1
ãã®ã¢ãããŒãã§ã¯ããªãã¬ãŒã¿ãŒã¯å¿
èŠã«å¿ããŠã«ãŒãã£ã³ã°ããŒãã«ãäœæããŸãã
R13>sh ip route ... 172.16.0.0/24 is subnetted, 3 subnets B 172.16.7.0 [20/0] via 192.168.200.12, 00:04:53 B 172.16.8.0 [20/0] via 192.168.200.12, 00:04:53 B 172.16.9.0 [200/0] via 192.168.103.100, 00:05:13
R11ã§ã®ãã¬ãŒã¹ã¯ãããŸããŸãªãããã€ããŒãééããŸãã
R11#traceroute 172.16.7.1 source 10.0.11.1 ... 1 192.168.114.4 4 msec 4 msec 4 msec 2 192.168.134.13 1 msec 0 msec 1 msec 3 192.168.200.12 0 msec 1 msec 0 msec 4 192.168.121.1 0 msec 1 msec 1 msec 5 192.168.101.100 2 msec 4 msec 3 msec 6 192.168.107.7 2 msec * 2 msec R11#traceroute 172.16.9.1 source 10.0.11.1 ... 1 192.168.114.4 0 msec 4 msec 0 msec 2 192.168.34.3 0 msec 1 msec 0 msec 3 192.168.103.100 3 msec 3 msec 3 msec 4 192.168.109.9 2 msec * 2 msec
ãã ããåé·æ§ã«åé¡ããããŸãã å®éãISPïŒ2ã厩å£ãããšã172.16.9.0 / 24ãããã¯ãŒã¯ããã®å å
¥è
ã¯ãå
šäžçããã¯ã圌ããžã®ã«ãŒãããèŠãªããããããµãŒãã¹ã倱ããŸãã éåžžãããã¯äºçŽã®ãã¬ãã£ãã¯ã¹ã®éçŽãçºè¡šããããšã§è§£æ±ºã§ããŸãã ããšãã°ã172.16.6.0ãã172.16.9.255ã®ç¯å²ã®ã¢ãã¬ã¹ãããå Žåããã¬ãã£ãã¯ã¹ãå«ãæ¡å€§ããããµãããã172.16.6.0/23ããã³172.16.8.0/23ãäž¡æ¹ã®ãããã€ããŒã«ããã«ã¢ããŠã³ã¹ã§ããŸãã ãã®åŸããããã€ããŒã®1ã€ãã¯ã©ãã·ã¥ãã/ 24ã«ãŒãã®ãç¹ç°æ§ããã€ã³ã¿ãŒãããäžã§æ¶å€±ããå Žåã/ 23ã¯äŸç¶ãšããŠæ®ãããµãŒãã¹ã¯1ã€ã®ã¢ãããªã³ã¯ã§ããã¹ãŠã®ãµãã¹ã¯ã©ã€ããŒã«å¯ŸããŠæ©èœããŸãã ãããããã®äŸã§ã¯ãããã¯äžå¯èœã§ãã ã¯ã©ã€ã¢ã³ããããã¯ãŒã¯ã1ã€ãŸãã¯2ã€ã®ãã¬ãã£ãã¯ã¹ã«éçŽããããšã¯ã§ããŸããã ãã¡ããããã®äŸã®ãããã¯ãŒã¯ã¯ç¹å¥ã«éžæãããŸããããæ£ç¢ºã«ã¯ãå®éã«ã¯ãã®ãããªç¶æ³ãšã®è¡çªã«ãããã¡ã¢ãæžãããã«ä¿ãããŸããã
ãäºçŽ
çä¿¡ãã©ãã£ãã¯ã®ãã©ã³ã¹ããšãåé¡ã解決ããŸããã åé·æ§ãéæããããã«æ®ã£ãŠããŸãã äžè¬çãªè§£æ±ºçã¯æ確ã§ãããã¢ã®1ã€ãèœã¡ãå Žåãçºä¿¡ã¢ããŠã³ã¹ã¡ã³ãã®ãã£ã«ã¿ãŒãããŸã çããŠãããã¢ã«å€æŽããŸãã ããã¯ãSSHãŸãã¯SNMPãä»ããã¹ã¯ãªããã䜿çšããŠå¢çã«ãŒã¿ãŒã®èšå®ãå€æŽããããšã«ããããå€éšãã§å®è£
ã§ããŸãã ãã ãããã®ããŒãã®ç®çã¯ãã·ã¹ã³ã®ãã¹ãŠã®çµã¿èŸŒã¿ããŒã«ãäœæããããšã§ãã
BGPæ¡ä»¶ä»ãã¢ããã¿ã€ãºã¡ã³ã
BGPãã€ããŒãããã®ç¶æ
ã«å¿ããŠBGPã¢ããŠã³ã¹ã¡ã³ãã管çãããªãã·ã§ã³ã®1ã€ã¯Conditional Advertisementã§ã ãããã«ãããBGPããŒãã«å
ã®ãå¶åŸ¡ããã¬ãã£ãã¯ã¹ã®æç¡ã«å¿ããŠãç¹å®ã®ãã¬ãã£ãã¯ã¹ããã€ããŒã«ã¢ããŠã³ã¹ã§ããŸãã
ã¢ããŠã³ã¹ãããå¿
èŠãããããŸãã¯éã«ã¢ããŠã³ã¹ããåé€ãããå¿
èŠããããã¬ãã£ãã¯ã¹ã¯ãç¹å¥ãªã«ãŒããããadvertise-mapã«ãã£ãŠæ±ºå®ãããŸãã ãå¶åŸ¡ããã¬ãã£ãã¯ã¹ã¯ãå¥ã®condition-mapã«ãã£ãŠå®çŸ©ãããŸã ãããã¯ã exist-mapãŸãã¯non-exist-mapãšããŠå®£èšã§ããŸãã æåã®å Žåãadvertise-mapããã®ãã¬ãã£ãã¯ã¹ã¯ãBGPããŒãã«ã«exist-mapã«å¯Ÿå¿ãããã¬ãã£ãã¯ã¹ãããå Žåã«ã®ã¿ã¢ããŠã³ã¹ãããŸãã non-exist-mapã®å Žåãéã®ããšãåœãŠã¯ãŸããŸããnon-exist-mapããã¬ãã£ãã¯ã¹ã®ç©ºã®ãªã¹ããè¿ãå Žåãadvertise-mapãã¬ãã£ãã¯ã¹ãã¢ããŠã³ã¹ãããããã§ãªãå Žåãã¢ããŠã³ã¹ããé€å€ãããŸãã
ãã®å Žåãnon-exist-mapãªãã·ã§ã³ãé©åã§ãã ããã§ã®ã«ãŒããããèšå®ã«ã¯ãããã€ãã®æ©èœããããŸãã
- ã«ãŒããããã«ã¯èš±å¯ã»ã¯ã·ã§ã³ã®ã¿ãå«ããå¿
èŠããããŸãã
- äžèŽæ¡ä»¶ã®åã»ã¯ã·ã§ã³ã«ã¯ããã¬ãã£ãã¯ã¹ãªã¹ããå«ããå¿
èŠããããŸãïŒas-pathãŸãã¯ã³ãã¥ããã£ã§ã®ã¿ãã£ã«ã¿ãŒã§ããŸããïŒã
- prefix-listã¯ãå®å
šäžèŽããã€ãŸã leãŸãã¯geãã©ã¡ãŒã¿ãŒãªãã
- ãã¯ã¹ãããããŸãã¯ã€ã³ã¿ãŒãã§ãŒã¹ã®ãã£ã«ã¿ãªã³ã°ã¯ãµããŒããããŠããŸããã
ãããã£ãŠãå¶åŸ¡ãã¬ãã£ãã¯ã¹ãå¿
èŠã§ãã ãããã€ããŒãç§ãã¡ã«çºè¡šãããã®ããäœããéžæããããšãã§ããŸãïŒãŸãã¯æ¡ä»¶ä»ãåºåã䜿çšããŠããããšãäŒããçŠç¹ãåœãŠãããšãã§ãããç¥ããã«ãã¬ãã£ãã¯ã¹ãè¿œå ããããã«äŸé Œããããšãã§ããŸãïŒã ãã ããã»ãšãã©ã®å ŽåïŒã¯ã©ã€ã¢ã³ãã«ä»ã®ãããã€ããŒããªãå ŽåïŒããã«ãã¥ãŒã§ã¯ãªãã芪ãããã€ããŒããããã©ã«ãã®ãã¬ãã£ãã¯ã¹0.0.0.0/0ãååŸããŸãã ã³ã³ãããŒã«ãšããŠäœ¿çšããŸãã ãŸãããããããã€ããŒã®ããã©ã«ããå¥ã®ãããã€ããŒãšåºå¥ããããã«ãAS-PATHãã£ã«ã¿ãŒãnon-exist-mapã«è¿œå ããŸãã
ãã¬ãã£ãã¯ã¹ãªã¹ããš2ã€ã®as-path ACLãäœæããŸãã
ip prefix-list default seq 5 permit 0.0.0.0/0 ip as-path access-list 1 permit ^65001.* ip as-path access-list 2 permit ^65002.*
2ã€ã®æ¡ä»¶ããããè¿œå ããŸããããããã®æ¡ä»¶ãããã¯ã察å¿ããISPãžã®æ¥ç¶ã確ç«ãããå Žåã«ã®ã¿ç©ºã§ãªããªã¹ããè¿ããŸãã
route-map isp-1-is-alive permit 10 match ip address prefix-list default match as-path 1 route-map isp-2-is-alive permit 10 match ip address prefix-list default match as-path 2
2ã€ã®ã«ãŒãããããäœæããŸããããã¯ã察å¿ãããã¢ã®ã¢ããã¿ã€ãºãããã«ãªããŸãã
route-map isp-1-adv permit 10 match ip address prefix-list isp-2-out route-map isp-2-adv permit 10 match ip address prefix-list isp-1-out
å¥ã®ã«ãŒããããã䜿çšããŠããã¹ãŠã®çºä¿¡ã¢ããŠã³ã¹ããã£ã«ã¿ãªã³ã°ããŸãã
route-map full-out permit 10 match ip address prefix-list isp-1-out isp-2-out
次ã«ãBGPãã€ããŒã®æ§æã«ããããé©çšããŸãã
router bgp 65000 address-family ipv4 neighbor 192.168.101.1 advertise-map isp-1-adv non-exist-map isp-2-is-alive neighbor 192.168.101.1 route-map full-out out neighbor 192.168.103.3 advertise-map isp-2-adv non-exist-map isp-1-is-alive neighbor 192.168.103.3 route-map full-out out
ãã€ããŒ192.168.103.3ã®æ§æãããã«è©³ããæ€èšããŸãã
- ã¢ããŠã³ã¹ã®ãã¬ãã£ãã¯ã¹ã¯route-map full-outã«ãã£ãŠéžæãããŸãã
- non-exist-map isp-1-is-aliveãããã«ãã§ãã¯ãããŸãïŒ
- isp-1-is-aliveã空ã§ãªããªã¹ããè¿ããå Žåãã¹ããŒã¿ã¹withdrawã advertise-map isp-1-advã«å²ãåœãŠããããã®ãã¬ãã£ãã¯ã¹ãã¢ããŠã³ã¹ããé€å€ãããŸãã
- isp-1-is-aliveã空ã®ãªã¹ããè¿ããå Žåãadvertise-map isp-1-advã«advertiseãå²ãåœãŠããããã®ãã¬ãã£ãã¯ã¹ãã¢ããŠã³ã¹ãããŸãã
äœãèµ·ãã£ãã®ãèŠãŠã¿ãŸãããã æåã¯ãäž¡æ¹ã®éååšãããã®ãå¶åŸ¡ããã¬ãã£ãã¯ã¹ã¯BGPããŒãã«ã«ããã察å¿ããã¢ããã¿ã€ãºãããã¯æ€åã¹ããŒã¿ã¹ã«ãããŸãã
CSR#sh ip bgp neighbors 192.168.101.1 | i Condition Condition-map isp-2-is-alive, Advertise-map isp-1-adv, status: Withdraw CSR#sh ip bgp neighbors 192.168.103.3 | i Condition Condition-map isp-1-is-alive, Advertise-map isp-2-adv, status: Withdraw
äž¡æ¹ã®ãããã€ããŒã¯ãçããŠãããã®ã§ããã¬ãã£ãã¯ã¹ã®äžéšã®ã¿ãããããã®æ¹åã«ã¢ããŠã³ã¹ãããŸãïŒ
CSR#sh ip bgp neighbors 192.168.101.1 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.7.0/24 192.168.107.7 0 32768 i *> 172.16.8.0/24 192.168.108.8 0 32768 i Total number of prefixes 2 CSR#sh ip bgp neighbors 192.168.103.3 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.9.0/24 192.168.109.9 0 32768 i Total number of prefixes 1
ISPïŒ1ã§BGPãã€ããŒããããç¡å¹ã«ããå Žåãã«ãŒããããisp-1-is-aliveã®ãã¬ãã£ãã¯ã¹ã¯BGPããŒãã«ããæ¶ããISPïŒ2ã®advertise-map isp-2-advã¯ã¹ããŒã¿ã¹ãã¢ããã¿ã€ãºããŸãã
CSR#sh ip bgp neighbors 192.168.103.3 | i Condition Condition-map isp-1-is-alive, Advertise-map isp-2-adv, status: Advertise
ããã§ãã«ãŒããããisp-2-advãã¬ãã£ãã¯ã¹ã¯ã¢ããŠã³ã¹ããé€å€ãããªããªããISPïŒ2ã«åããŠããã¬ãã£ãã¯ã¹ã®å®å
šãªã»ãããã¢ããŠã³ã¹ãããŸãã
CSR#sh ip bgp neighbors 192.168.103.3 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.7.0/24 192.168.107.7 0 32768 i *> 172.16.8.0/24 192.168.108.8 0 32768 i *> 172.16.9.0/24 192.168.109.9 0 32768 i Total number of prefixes 3
BGPãã€ããŒãããã埩å
ãããšãadvertise-mapã®ã¹ããŒã¿ã¹ã¯withdrawã«æ»ãããã¬ãã£ãã¯ã¹ã¯ãã©ã³ã·ã³ã°ã®ããã«ãããã€ããŒéã§åã³é
åžãããŸãã
æ¡ä»¶ä»ãã¢ããã¿ã€ãºã¡ã³ãã䜿çšããå¥ã®ãªãã·ã§ã³ã¯ãåé¡ããããã€ããŒã®åŽã«ããŸãã¯ãã®è²¬ä»»ç¯å²ãè¶
ããŠç¹å®ããããšã§ãã ãã¹ãåè·¯ã®å ŽåãAS65110ã«ã¯å€§èŠæš¡ãªã³ã³ãã³ããããã€ããŒã®äžå¿ããããå å
¥è
ã«ãšã£ãŠã¢ã¯ã»ã¹ãéèŠã§ããããšãæ³åã§ããŸãã 2ã€ã®ãããã€ããŒéã®ãã¢ãªã³ã°æ¥ç¶ãäœäžããå Žåããã¬ãã£ãã¯ã¹ãISPïŒ1ã«ã®ã¿ã¢ããŠã³ã¹ããããµãã¹ã¯ã©ã€ããŒã®äžéšã¯ãAS65110ãžã®ã¢ã¯ã»ã¹ã倱ããŸãã åæã«ããããã€ããŒãšã®æ¥ç¶ãããããããããã¬ãã£ãã¯ã¹ãšããã©ã«ãããããŸããããµãã¹ã¯ã©ã€ããŒãµãŒãã¹ãäœäžããŸãã ãã®å ŽåãAS65110ã§éèŠãªãªãœãŒã¹ã®ã¢ãã¬ã¹ã䜿çšããããã®ãå¶åŸ¡ããã¬ãã£ãã¯ã¹ãšããŠã®ã¿ãäžèšãšåæ§ã®æ§æã䜿çšã§ããŸãã
Cisco Embedded Event Manager
以äžã«èª¬æããæ¹æ³ã¯ãBGPæ¡ä»¶ä»ãã¢ããã¿ã€ãºã¡ã³ãã®æ©èœãèãããšããã®ãããªåçŽãªã¿ã¹ã¯ã解決ããããã«å°ã人工çã«èŠããŸãã ãã®çç±ã¯ãCisco EEMã«ã€ããŠã®è©±ãã¡ã¢ãæžãç®çã§ãã£ããããèšäºã®å
ã®ããŒãžã§ã³ã§ã¯å¯äžã®èšäºã§ãã£ãããã§ãã ããã«ããã©ã³ã¹ã®åé¡ã¯ãå³ã®æãåçŽã§ç解å¯èœãªããŒãžã§ã³ãšããŠéžæãããŸããã ããããåŸã§ã³ã¡ã³ãã®äžã§ã圌ãã¯ç§ã«ãBGPã¢ããŠã³ã¹ã¡ã³ãã®ç®¡çã®åé¡ã«ã€ããŠããã®ç®çã®ããã«èšèšãããŠããªãããŒã«ã«èšåããã«èª¬æããŠããããšãæ£ããææããŸããã ãã®ãããBGPæ¡ä»¶ä»ãã¢ããã¿ã€ãºã¡ã³ãã«é¢ããèšäºãç»å ŽããŸããããCisco EEMã®äœ¿çšã¯é¢åã§åé·ãªããã§ãã ãã ããããã¯éåžžã«åŒ·åãªããŒã«ã§ãããèšå€§ãªåéã®ã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠããã®ã§ãç¥ã䟡å€ã¯ãããŸãã
çä¿¡ãã©ãã£ãã¯ã®ãã©ã³ã¹ããšãåé¡ã解決ããŸããã åé·æ§ãéæããããã«æ®ã£ãŠããŸãã äžè¬çãªè§£æ±ºçã¯ç解ã§ããŸãããã¢ã®1ã€ãèœã¡ãå Žåãçºä¿¡ã¢ããŠã³ã¹ã¡ã³ãã®ãã£ã«ã¿ãŒãããŸã çããŠãããã¢ã«å€æŽããŸãã ããã¯ãSSHãŸãã¯SNMPãä»ããã¹ã¯ãªããã䜿çšããŠå¢çã«ãŒã¿ãŒã®èšå®ãå€æŽããããšã«ããããå€éšãã§å®è£
ã§ããŸãã ãã ãããã®ããŒãã®ç®çã¯ãã·ã¹ã³ã®ãã¹ãŠã®çµã¿èŸŒã¿ããŒã«ãäœæããããšã§ãã
ããã¯ã Cisco Embedded Event ManagerïŒEEMïŒãšã³ãžã³ã圹ç«ã€å Žæã§ãã ããã¯ãã«ãŒã¿ãŒã管çãããããã¯ãŒã¯äžã®åé¡ããã©ãã«ã·ã¥ãŒãã£ã³ã°ããããã®éåžžã«æè»ãªã¡ã«ããºã ã§ãããã®æ©èœã¯ã説æããã¿ã¹ã¯ã®ç¯å²ãã¯ããã«è¶
ããŠããŸãã ç¹å®ã®ã€ãã³ãïŒBGPè¿é£ã®ãã©ãŒã«ãŸãã¯åŸ©å
ïŒã®çºçããã£ããããç¹å®ã®ã³ãã³ãã»ãããå®è¡ãã圌ã®èœåãå¿
èŠã§ãã
æåã«ããã¹ãŠã®ãã¬ãã£ãã¯ã¹ãå«ããã¬ãã£ãã¯ã¹ãªã¹ããäœæããŸãã
ip prefix-list full-out seq 5 permit 172.16.7.0/24 ip prefix-list full-out seq 10 permit 172.16.8.0/24 ip prefix-list full-out seq 15 permit 172.16.9.0/24
次ã«ãEEMã¢ãã¬ãããèšå®ããŸããããã¯ãBGPãã€ããŒãããã®ã¹ããŒã¿ã¹ã®å€åã«é¢ããã¬ã³ãŒãããã°ã«è¡šç€ºããããšãã«èµ·åãããŸãïŒæ£èŠè¡šçŸã«ãã£ãŠå®çŸ©ãããŸãïŒã ã¢ãã¬ããïŒ
- ãã°å
ã®ã¡ãã»ãŒãžã解æãã以äžã決å®ããŸãã
- ã¡ãã»ãŒãžãããªã¬ãŒããBGPãã€ããŒã®ã«ãŒã¿ãŒIDã
- 圌ã®ã¹ããŒã¿ã¹ã
- IPã¢ãã¬ã¹ãšã¹ããŒã¿ã¹ã«å¿ããŠã1ã€ãŸãã¯å¥ã®ãã¬ãã£ãã¯ã¹ãªã¹ããå¥ã®BGPãã€ããŒã«é©çšããŸãã
- ã«ãŒãã£ã³ã°æ
å ±ã®é
åžãšå ããããå€æŽã®é©çšãå éããããã«ãããœããã«ã2çªç®ã®ãã€ããŒãžã®ã¢ããŠã³ã¹ããªã»ããããŸãã
ã¢ãã¬ããæ§æïŒ
event manager applet isp event syslog pattern "neighbor 192.168.10[13].[13] (Up|Down|reset)" action 01.0 regexp "(192.168.10[13].[13])" "$_syslog_msg" _match _ip action 02.0 if $_ip eq "192.168.101.1" action 03.0 set _name "ISP #1" action 04.0 set _target_ip "192.168.103.3" action 05.0 set _list "isp-2-out" action 06.0 elseif $_ip eq "192.168.103.3" action 07.0 set _name "ISP #2" action 08.0 set _target_ip "192.168.101.1" action 09.0 set _list "isp-1-out" action 10.0 else action 11.0 exit action 12.0 end action 13.0 regexp "(Up|Down|reset)" "$_syslog_msg" _match _state action 14.0 if $_state eq "Up" action 15.0 set _status "UP" action 16.0 else action 17.0 set _status "DOWN" action 18.0 set _list "full-list" action 19.0 end action 20.0 syslog priority warnings msg "$_name now is $_status !" action 21.0 syslog priority warnings msg "Applying prefix list '$_list' to the neighbor $_target_ip" action 22.0 cli command "enable" action 23.0 cli command "configure terminal" action 24.0 cli command "router bgp 65000" action 25.0 cli command "address-family ipv4" action 26.0 cli command "neighbor $_target_ip prefix-list $_list out" action 27.0 cli command "end" action 28.0 syslog priority warnings msg "Soft clear BGP session $_target_ip" action 29.0 cli command "clear ip bgp $_target_ip soft out"
æåã¯ãäž¡æ¹ã®BGPã»ãã·ã§ã³ãã¢ã¯ãã£ãã§ãã¢ããŠã³ã¹ã¯æ¬¡ã®ããã«ãªããŸãã
CSR#show ip bgp summary ... Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.101.1 4 65001 8 5 7 0 0 00:00:19 3 192.168.103.3 4 65002 8 5 7 0 0 00:00:24 3 CSR#show ip bgp neighbors 192.168.101.1 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.7.0/24 192.168.107.7 0 32768 ? *> 172.16.8.0/24 192.168.108.8 0 32768 ? Total number of prefixes 2 CSR#show ip bgp neighbors 192.168.103.3 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.9.0/24 192.168.109.9 0 32768 ? Total number of prefixes 1
ISPïŒ2ãããã¯ãŒã¯ã§ã®çºè¡šã¯æ¬¡ã®ãšããã§ãã
R13>show ip bgp ... Network Next Hop Metric LocPrf Weight Path *> 172.16.7.0/24 192.168.200.12 0 65001 65000 ? *> 172.16.8.0/24 192.168.200.12 0 65001 65000 ? *>i 172.16.9.0/24 192.168.103.100 0 120 0 65000 ?
R11ã䜿çšãããã¬ãŒã¹ã¯ãå¿
èŠã«å¿ããŠãããã¯ãŒã¯ã«éãããŸãã
R11#traceroute 172.16.7.1 source 10.0.11.1 Type escape sequence to abort. Tracing the route to 172.16.7.1 VRF info: (vrf in name/id, vrf out name/id) 1 192.168.114.4 0 msec 1 msec 0 msec 2 192.168.134.13 0 msec 0 msec 1 msec 3 192.168.200.12 0 msec 0 msec 1 msec 4 192.168.121.1 1 msec 1 msec 1 msec 5 192.168.101.100 3 msec 3 msec 3 msec 6 192.168.107.7 2 msec * 3 msec R11#traceroute 172.16.9.1 source 10.0.11.1 Type escape sequence to abort. Tracing the route to 172.16.9.1 VRF info: (vrf in name/id, vrf out name/id) 1 192.168.114.4 1 msec 0 msec 1 msec 2 192.168.34.3 0 msec 1 msec 0 msec 3 192.168.103.100 3 msec 3 msec 3 msec 4 192.168.109.9 2 msec * 2 msec
次ã«ããããã€ããŒããISPïŒ1ãã¢ãç¡å¹ã«ããŸãããã ãã®çµæãå¢çäžã®BGPã»ãã·ã§ã³ã®1ã€ãIDLEã«ç§»åããŸãã
CSR#show ip bgp summary ... Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.101.1 4 65001 0 0 1 0 0 00:00:10 Idle 192.168.103.3 4 65002 26 26 9 0 0 00:16:31 3
åæã«ãã€ãã³ãïŒ
BGP-5-NBR_RESETïŒNeighbor 192.168.101.1 resetïŒPeer closed the sessionïŒãçºçãããšããã«ãã¢ãã¬ãããæ©èœãããã¬ãã£ãã¯ã¹ãªã¹ããå€æŽããããšããã°ã«è¡šç€ºãããŸãã
*Jul 20 09:00:58.208: %BGP-5-NBR_RESET: Neighbor 192.168.101.1 reset (Peer closed the session) *Jul 20 09:00:58.208: %BGP-5-ADJCHANGE: neighbor 192.168.101.1 Down Peer closed the session *Jul 20 09:00:58.214: %HA_EM-4-LOG: isp: ISP #1 now is DOWN ! *Jul 20 09:00:58.214: %HA_EM-4-LOG: isp: Applying prefix list 'full-list' to the neighbor 192.168.103.3 *Jul 20 09:00:58.778: %SYS-5-CONFIG_I: Configured from console by on vty0 (EEM:isp) *Jul 20 09:00:58.879: %HA_EM-4-LOG: isp: Soft clear BGP session 192.168.103.3
ISPïŒ2ã«åããŠçŸåšçºè¡šããŠãããã®ãèŠãŠã¿ãŸãããã
CSR#show ip bgp neighbors 192.168.103.3 advertised-routes ... Network Next Hop Metric LocPrf Weight Path *> 172.16.7.0/24 192.168.107.7 0 32768 ? *> 172.16.8.0/24 192.168.108.8 0 32768 ? *> 172.16.9.0/24 192.168.109.9 0 32768 ? Total number of prefixes 3
ã€ãŸã çŸåšãISPïŒ2ãéããŠãã¹ãŠã®ãã¬ãã£ãã¯ã¹ãçºè¡šããŠããŸãã R13ã§ã®è¡šç€ºã¯æ¬¡ã®ãšããã§ãã
R13>show ip bgp ... Network Next Hop Metric LocPrf Weight Path *>i 172.16.7.0/24 192.168.103.100 0 120 0 65000 ? *>i 172.16.8.0/24 192.168.103.100 0 120 0 65000 ? *>i 172.16.9.0/24 192.168.103.100 0 120 0 65000 ?
ãããŠããããã¯ãŒã¯å
ã®ãã¹ãŠã®ãã¬ãŒã¹ã¯1ã€ã®ãããã€ããŒãééããŸãã
IPSïŒ1ã§BGPã»ãã·ã§ã³ã埩å
ãããšãã¢ãã¬ããã¯åã³ISPïŒ2ã®ãã¬ãã£ãã¯ã¹ãªã¹ããå
ã®äœçœ®ã«æ»ããŸãã
ãããã«
ãã®èšäºã®ç®çã¯ãããã€ãã®ã¢ãããªã³ã¯ã®ãã©ã³ã¹ãåããªããçä¿¡ãã©ãã£ãã¯ã管çããããã®Cisco EEMã®äœ¿çšãç°¡åã«æ€èšããããšã§ããã ãã¡ããããã®æ¹æ³ã¯æé©ãšã¯èšããŸããã ããããããã¯ãé¡ãã®ãœãªã¥ãŒã·ã§ã³ã§ãã ãã ããããã¯æ©èœããããçšåºŠã®ãã©ãŒã«ããã¬ã©ã³ã¹ãæäŸããŸãã ã¡ã¢ãæžãããã«ãåè·¯å
šäœãCisco IOLããã³Cisco CSRv1000ã€ã¡ãŒãžäžã®UNELABã§çµã¿ç«ãŠãããŸããã ãã®äŸã®ãã¹ãŠã®ããã€ã¹ã®æ§æã¯ã ããããããŠã³ããŒãã§ããŸã ã