Tuesday, March 24, 2015

IPv6 notes. Addressing.

 Addressing 


First every network engineer should know about IPv6 is the  IPv6 addressing.
Here some of them:
     IPv6 addresses can be Unicast, Anycasy and Multicast.

     Unicast 

Unicast address is the identifier of a single interface. Each packet sent to unicast address will be delivered to only one interface.

     Anycast 

Anycast address is the identifier for a set of interfaces(different nodes). Each packet sent to anycast address will be delivered to the "nearest" based on the routing protocol metric. Anycast addresses are taken from unicast addresses spaces.

      Multicast

Multicast address is the identifier of a set of interfaces(different nodes). Each packet sent to multicast address will be delivered to multiple interfaces which "listen" to this multicast address.

     There are no broadcast addresses in IPv6 protocol. 

     Every IPv6 interface can have multiple IPv6 addresses of any type or scope(unicast, anycast, multicast). All interfaces are required to have at least one link-local address.

     IPv6 address has a form x:x:x:x : x:x:x:x where "x"s are 1-4 hex digits (128 bits or 16 bytes at all)
     Examples:
 2001:1234:5678:9101:1121:3141:5161:7181
 2001:1234:5678:9101:0:0:5161:7181
 2001:0:0:1:0:0:0:7181
 2001:0:0:1::7181
     Here are some rules that help you make IPv6 address shorter:
      "Leading zeros" rule that says, that it is not necessary to write leading zeros in an individual field (see Example), to indicate one or more groups of 16 zero bits you can use "::" (see Example). You should remember that you can set "::" symbol only one time to show all zeros 16 bit field. You can not write IPv6 address mentioned above as 2001::1::7181 because it will be impossible to recognize the address and you can's say how match zeros you replaced by "::" symbol.
     Also you there are some form of IPv6 addresses ( within a mixed IPv4 and  IPv6 environment) x:x:x:x:x:x:d.d.d.d where "d" is a decimal ipv4 address field and "x" is a hexadecimal values.
     Examples:
 0:0:0:0:0:0:192.168.1.2             --> ::192.168.1.2
 0:0:0:0:0:FFFF:192.168.1.2        --> ::FFFF:192.168.1.2 

     IPv6 prefix can be written as IPv4 prefix <ipv6-address>/<prefix-length>
     Examples:
 FE80::1/64
 2001:1:2::1/48

    It is possible to identify address type by the high-order bits of the address:




IPv6 address can be represented as follows:






Here is IPv6 address represented as subnet prefix and host portion (as ipv4 CIDR): 







Interface Identifier (Interface ID)

 - identifies each router interface on a link. It is required for node to have unique 64-bit interface ID on a different links. For example: if  nodes within the site will be given the same global unique prefix ( global unicast address )  it required to have unique interface ID's in case getting global unicast address by stateless dhcp ("ipv6 address autoconfiguration" command). You can assign interface ID manually to interface or using EUI-64.

EUI-64

EIU-64 global identifier format of ipv6 address is ieee standard  which describe how to get interface identifier using link-layer address (http://standards.ieee.org/develop/regauth/tut/eui64.pdf) 




Unicast addresses:

unspecified 

0:0:0:0:0:0:0:0 - indicates the absence of an address. This address can not be the source address, can not be manually assigned to interface.

loopback

0:0:0:0:0:0:0:1 - loopback address may be used by a node to send ipv6 packets to itself. This address must never be forwarded by an ipv6 router. A packet received on interface with a destination address of loopback must be dropped

global unicast

Global uncast address have the next forms:
- the general format of Global IPv6 unicast address 


-  rfc 4291 (ipv6 address architecture) required address format:
RFC 4291 requires that all addresses, except those that start with binary value "000" (ipv6 addresses with embedded ipv4 addresses) have Interface ID that are 64-bit long  and to be constructed in Modified EUI-64 format.  







- 2000::/3 (prefix begins with "001" 2000::/3- 3FFF::/3)  is example of Global unicast prefix delegated by IANA (https://www.iana.org/about).







link-local

Link-local addresses are designed to address single local link of a node for interaction between nodes within a link scope such a autoconfiguration or neighbor discovery. Link-local addresses are not routed and router must not forward such a packets that have source or destination link-local addresses 
Link-local address format:
          
          FE80::/64


site local

Prefix FEC0::/10. Site local addresses are now deprecated and must no longer be supported. 

unique-local (ULA)

Prefix FC00::/7 (now used the upper half FD00/8) - comparable the ipv4 private addressing. ULA's are routable only within the routing domain, but not in the global Internet.


where prefix is FC00::/7, L - set to 1 means that prefix is locally assigned, Global ID is the globally unique prefix, Subnet ID identifies a subnet within the site. 


IPv6 addresses with embedded ipv4 addresses

- ipv4 to ipv6 compatible (deprecated)
     ::/96 addresses ::x.x.x.x where x - are ipv4 octets.     
- ipv4 to ipv6 mapping
     ::FFFF:0:0
 ::FFFF:x:x:x:x/96 where x - are ipv4 octets







Anycast addresses:

Anycast address is assigned to more than one interface (different nodes). A packet sent to the anycast address will be delivered to the "nearest" interface having that address. There is no special address space for IPv6 anycast address, anycast addresses are allocated from unicast address space.Anycast address must not be used as source address for sending IPv6 packets. Anycast address can be configured with "anycast" cisco ios command.
Another words:  any unicast address assigned to different nodes makes this address anycast with exception that when you configure anycast address on cisco router, Duplicated Address Detection (DAD) becomes automatically disabled.
(config-if)#ipv6 address x::y/z anycast


Multicast addresses:

IPv6 multicast address have the next format:
All multicast addresses begin with 1111 1111 in binary,  as FF in hex or as a prefix FF00::/8







Where : flgs - is a flag field (ff)      

- The higher order flag is reserved and must be initialized to 0 ( zero )
- T = 0 means that address is well known and permanently assigned by IANA, T=1 means that address is "dynamically" assigned (for example generated from IPv4 multicast address). 
- P flag is used for indicating, that multicast address was assigned based on a network prefix (ipv4 based, Source Specific Multicast SSM). P=1 means that T must be set to 1. 
SSM range of IPv6 addresses is FF3x::/32
- R flag  shows us that Rendezvous Point (RP) Address is embedded in IPv6 address, of course P must be set to 1 ant T must be set to 1. 
IPv6 with RP embedded address space is FF70::/32. (RFC 3956)

scop  - is a 64-bit multicast scope value. It shows us the scope of the multicast group (internal-local, link-local,site-local, organization-local e.t.c RFC4291)

Common IPv6 multicast addresses

(XX01::1 - interface local , XX02::1 all nodes in link-local scope): 
FF0x::1 - all nodes 
FF0x::2 - all routers
FF02::5 - all OSPFIGP
FF02::6 - all OSPFIGP DR
FF02::9 - all RIP 
FF02::a - all EIGRP


Solicited-node multicast address

Solicited-node multicast address is formed by taking a 24 low-order bits of node's unicast or anycast address and appending those bits to the special multicast prefix FF02::1:FFxx:xxxx/104 where xx:xxxx - those 24 low-order bits.
When you assign the unicast or anycast address to router's interface, this interface automatically "subscribes" to solicited-node multicast address corresponding to unicast address you assigned.
Cisco IOS command "show ipv6 interface <ifname>" will show you all ipv6 solicited-node multicast addresses.
Example:
IPv6 unicast address: FD00::1234:5678
IPv6 solicited-node mcast address: FF02::1:FF34:5678

Mapping multicast IPv6 address to multicast MAC-address


In IPv6 as in IPv4 you still need to have destination multicast MAC-address to send multicast IPv6 packets. To map IPv6 multicast address to MAC-address you should  append low-order 32 bits of ipv6 address to multicast mac-address whos first two octets are "3333" in hex:




Tuesday, February 3, 2015

GLBP protocol part two





GLBP Protocol  part two.


I decided to break GLBP notes on two parts. The first part of GLBP notes was about protocol functioning with some packet captures and debugging. This part will cover testing of GLBP in production.



Pic.1 Topology.






GLBP in production

As mentioned on the topology above, we have multilayer switch and default gateway configured to virtual IP of GLBP group 1 10.12.10.100. 
We will ping Loopback interface of router R2 with IP address 2.2.2.2 as a connectivity test with source IP address 10.12.10.12.

SWITCH_2#sh ip route
C       10.12.10.0 is directly connected, Vlan12
S*   0.0.0.0/0 [1/0] via 10.12.10.100

First look at GLBP configuration on GLBP routers:


R1
R1#sh run int fa 0/1

interface FastEthernet0/1
mac-address 0011.1111.1111
ip address 10.12.10.1 255.255.255.0
duplex full
speed 100
glbp 1 ip 10.12.10.100
end

R4
R4#sh run int fa 0/1

interface FastEthernet0/1
mac-address 0044.4444.4444
ip address 10.12.10.4 255.255.255.0
duplex full
speed 100
glbp 1 ip 10.12.10.100
end
R3
R4#sh run int fa 0/1

interface FastEthernet0/1
mac-address 0044.4444.4444
ip address 10.12.10.4 255.255.255.0
duplex full
speed 100
glbp 1 ip 10.12.10.100
end

R2#sh run int lo2
interface Loopback2
 ip address 2.2.2.2 255.255.255.255
end


Verify GLBP with "show" command:
R1#sh glbp
FastEthernet0/0 - Group 1
  State is Listen  <---- Local router is in the "Listen" GLBP state       
    11 state changes, last state change 11:47:14
  Virtual IP address is 10.12.10.100 
 <----- IP address protected by this router
  Hello time 3 sec, hold time 10 sec    <--- Configured  AVG timers (inherited from the AVG)
    Next hello sent in 1.532 secs
  Redirect time 10 sec, forwarder timeout 610 sec    <----- configured AVF timers ( inherited from the AVG) 
  Preemption disabled                                                                          
  Active is 10.12.10.4, priority 100 (expires in 9.552 sec)           <--- IP address of AVG
  Standby is 10.12.10.3, priority 100 (expires in 5.188 sec)             <--- IP address of ASG
  Priority 100 (default)                                                                        <--- local AVG priority
  Weighting 30, low (configured 100), thresholds: lower 40, upper 100     <---- 30 is a weight of  the local forwarder
    Track object 1 state Down decrement 70    <----here you can see tracking information related to local GLBP group
  Load balancing: round-robin
  Group members:
    0011.1111.1111 (10.12.10.1) local
    0033.3333.3333 (10.12.10.3)
    0044.4444.4444 (10.12.10.4)
  There are 3 forwarders (1 active)    <---- "1 active" means that our router is responsible for one mac address
  Forwarder 1
    State is Active                    
      21 state changes, last state change 00:49:22
    MAC address is 0007.b400.0101 (default)
    Owner ID is 0011.1111.1111
    Preemption enabled, min delay 30 sec
    Active is local, weighting 30
  Forwarder 2                      
    State is Listen               <--means that our router is watching to this address and can pick it up in case this forwarder will go down
    MAC address is 0007.b400.0102 (learnt)
    Owner ID is 0033.3333.3333
    Time to live: 604.356 sec (maximum 610 sec)
    Preemption enabled, min delay 30 sec
    Active is 10.12.10.3 (primary), weighting 200 (expires in 4.352 sec)  
  Forwarder 3
    State is Listen
    MAC address is 0007.b400.0103 (learnt)
    Owner ID is 0044.4444.4444
    Time to live: 608.712 sec (maximum 610 sec)
    Preemption enabled, min delay 30 sec   <---After 30 seconds. Forwarder 3 will pick up our virtual mac-address in case our router will go down
    Active is 10.12.10.4 (primary), weighting 100 (expires in 8.708 sec)



ARP table on multilayer switch:
SWITCH_2#sh arp | i 10.12.10.1|Add
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.12.10.12             -   0012.d994.fdc4  ARPA   Vlan12

Let's ping IP address of R2:
SWITCH_2#ping 2.2.2.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 25/46/93 ms

We can see arp entry in arp table:
SWITCH_2#sh arp | i 10.12.10.1|Add
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.12.10.12             -   0012.d994.fdc4  ARPA   Vlan12
Internet  10.12.10.100            0   0007.b400.0103  ARPA   Vlan12
SWITCH_2#


Now we will manually "shut" and "no shut"  interface Vlan 12 (which IP is the source IP address for ICMP request) and look at ARP table:

SWITCH_2#sh arp | i Add|10.12.10.1
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.12.10.12             -   0012.d994.fdc4  ARPA   Vlan12
Internet  10.12.10.100           73   0007.b400.0103  ARPA   Vlan12
SWITCH_2(config)#int vl 12
SWITCH_2(config-if)#shut
SWITCH_2(config-if)#no shut

*Apr 19 01:31:09.367: %LINK-5-CHANGED: Interface Vlan12, changed state to administratively down
*Apr 19 01:31:09.376: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan12, changed state to down
*Apr 19 01:31:11.439: %LINK-3-UPDOWN: Interface Vlan12, changed state to up
*Apr 19 01:31:11.448: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan12, changed state to up

SWITCH_2(config-if)#do sh arp | i Add|10.12.10.1
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.12.10.12             -   0012.d994.fdc4  ARPA   Vlan12
Internet  10.12.10.100            0   0007.b400.0102  ARPA   Vlan12
SWITCH_2(config-if)#shut
SWITCH_2(config-if)#no shut
SWITCH_2(config-if)#do sh arp | i Add|10.12.10.1
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.12.10.12             -   0012.d994.fdc4  ARPA   Vlan12
Internet  10.12.10.100            0   0007.b400.0101  ARPA   Vlan12     
<---- Mac address changes every time
SWITCH_2(config-if)#shut
SWITCH_2(config-if)#no shut
SWITCH_2(config-if)#do sh arp | i Add|10.12.10.1
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.12.10.12             -   0012.d994.fdc4  ARPA   Vlan12
Internet  10.12.10.100            0   0007.b400.0102  ARPA   Vlan12
We have different IP  virtual mac address every time when SVI_12 Up/Down. Round robin scheme in work.


GLBP forwarding preemption

Now we will manually shut interface to current forwarder  :
First look at current ARP entry for IP address 10.12.10.100

SWITCH_2#sh arp | i Addr|10.12.10.10
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.12.10.100            0   0007.b400.0101  ARPA   Vlan12
SWITCH_2#

0007.b400.0101 is the mac address of R4:
R4(config-if)#do sh glbp bri
Interface   Grp  Fwd Pri State    Address         Active router   Standby router
Fa0/1       1    -   100 Standby  10.12.10.100    10.12.10.3      local
Fa0/1       1    1   -   Active   0007.b400.0101  local           -
Fa0/1       1    2   -   Listen   0007.b400.0102  10.12.10.3      -
Fa0/1       1    3   -   Listen   0007.b400.0103  10.12.10.1      -

 
Now let's shut R4's GLBP interface configured and look who will preempt is's virtual mac address:
Turn on GLBP debugging
R4(config-if)#do deb glbp terse
GLBP:
  GLBP Errors debugging is on
  GLBP Events debugging is on
    (protocol, redundancy, track)
  GLBP Packets debugging is on
    (Request, Reply)





Do the ping test :
Type escape sequence to abort.
Sending 100, 100-byte ICMP Echos to 2.2.2.2, timeout is 2 seconds:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!....!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Success rate is 96 percent (96/100), round-trip min/avg/max = 16/30/75 ms
SWITCH_2#


R4's interface "shutdown":
R4(config)#int fa 0/1
R4(config-if)#
R4(config-if)#
R4(config-if)#shut
R4(config-if)#

*Jan 23 11:15:27.459: GLBP: Fa0/1 Interface down
*Jan 23 11:15:27.463: GLBP: Fa0/1 1.1 Active: e/Forwarder disabled
*Jan 23 11:15:27.463: GLBP: Fa0/1 1.1 Active -> Init           <--GLBP stops      
*Jan 23 11:15:27.463: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 1 state Active -> Init
*Jan 23 11:15:27.475: GLBP: Fa0/1 1.2 Listen: e/Forwarder disabled
*Jan 23 11:15:27.475: GLBP: Fa0/1 1.2 Listen -> Init
*Jan 23 11:15:27.475: GLBP: Fa0/1 1.3 Listen: e/Forwarder disabled
*Jan 23 11:15:27.475: GLBP: Fa0/1 1.3 Listen -> Init
*Jan 23 11:15:27.479: GLBP: Fa0/1 1 Standby: e/GLBP disabled
*Jan 23 11:15:27.479: GLBP: Fa0/1 1 Active router IP is unknown, was 10.12.10.3  
<--R4 lost GLBP active router
*Jan 23 11:15:27.479: GLBP: Fa0/1 1 Standby router is unknown, was local   <-- R4 was standby router
*Jan 23 11:15:27.479: GLBP: Fa0/1 1 Standby -> Init
*Jan 23 11:15:29.459: %LINK-5-CHANGED: Interface FastEthernet0/1, changed state to administratively down
*Jan 23 11:15:30.459: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down




Look at debugging on other routers in this GLBP group R1 and R3:

R1#
*Jan 23 11:25:39.711: GLBP: Fa0/1 1 Listen: f/Standby timer expired (10.12.10.4)
*Jan 23 11:25:39.711: GLBP: Fa0/1 1 Standby router is unknown, was 10.12.10.4
 <--we lost R4 as a GLBP neighbor
*Jan 23 11:25:39.711: GLBP: Fa0/1 1 Listen -> Speak
*Jan 23 11:25:40.099: GLBP: Fa0/1 1.1 Ignoring Hello (135/10.12.10.3 < 167/10.12.10.4)
*Jan 23 11:25:40.891: GLBP: Fa0/1 1.1 Ignoring Hello (135/10.12.10.3 < 167/10.12.10.4) 
<---Ignore this GLBP hellos because R4 is no longer a GLBP neighbor
*Jan 23 11:25:41.439: GLBP: Fa0/1 1.1 Listen: g/Active timer expired
*Jan 23 11:25:41.439: GLBP: Fa0/1 1.1 Listen -> Active
*Jan 23 11:25:41.439: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 1 state Listen -> Active 
<--Became an active forwarder for R4 
*Jan 23 11:25:43.907: GLBP: Fa0/1 1.1 Active: i/Hello rcvd from higher pri Active router (135/10.12.10.3)  <--R3 is more prefered as backup forwarder for R4's virtual mac address
*Jan 23 11:25:43.911: GLBP: Fa0/1 1.1 Active -> Listen 
*Jan 23 11:25:43.911: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 1 state Active -> Listen
*Jan 23 11:25:49.727: GLBP: Fa0/1 1 Speak: f/Standby timer expired (unknown)
*Jan 23 11:25:49.727: GLBP: Fa0/1 1 Standby router is local
*Jan 23 11:25:49.727: GLBP: Fa0/1 1 Speak -> Standby  <-- became the GLBP standby router


R3#
*Jan 23 11:23:39.283: GLBP: Fa0/1 1 Standby router is unknown, was 10.12.10.4
*Jan 23 11:23:39.635: GLBP: Fa0/1 1.1 Listen: g/Active timer expired
*Jan 23 11:23:39.635: GLBP: Fa0/1 1.1 Listen -> Active
*Jan 23 11:23:39.635: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 1 state Listen -> Active
*Jan 23 11:23:41.031: GLBP: Fa0/1 1.1 Active: j/Hello rcvd from lower pri Active router (135/10.12.10.1)
*Jan 23 11:23:42.139: GLBP: Fa0/1 1.1 Active: j/Hello rcvd from lower pri Active router (135/10.12.10.1)
*Jan 23 11:23:49.327: GLBP: Fa0/1 1 Standby router is 10.12.10.1
R3#sh glbp brief
Interface   Grp  Fwd Pri State    Address         Active router   Standby router
Fa0/1       1    -   100 Active   10.12.10.100    local           10.12.10.1
Fa0/1       1    1   -   Active   0007.b400.0101  local           -  
<- two active virtual mac addresses
Fa0/1       1    2   -   Active   0007.b400.0102  local           -
Fa0/1       1    3   -   Listen   0007.b400.0103  10.12.10.1      -  <- it is R1 


Now we will shut R3's interface and remain only one GLBP gateway (simulate R3 crash):


R3(config)#int fa 0/1
R3(config-if)#shut

*Jan 23 11:54:03.623: %GLBP-6-STATECHANGE: FastEthernet0/1 Grp 1 state Active -> Init
*Jan 23 11:54:05.599: %LINK-5-CHANGED: Interface FastEthernet0/1, changed state to administratively down
*Jan 23 11:54:06.599: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to down

We can see above, that R1  became active GLBP forwarder or all 3 routers:
R1#
*Jan 23 11:56:12.823: GLBP: Fa0/1 1.1 Listen: g/Active timer expired
*Jan 23 11:56:12.823: GLBP: Fa0/1 1.1 Listen -> Active
*Jan 23 11:56:12.823: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 1 state Listen -> Active
*Jan 23 11:56:13.015: GLBP: Fa0/1 1.2 Listen: g/Active timer expired
*Jan 23 11:56:13.015: GLBP: Fa0/1 1.2 Listen -> Active
*Jan 23 11:56:13.015: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 2 state Listen -> Active
*Jan 23 11:56:13.535: GLBP: Fa0/1 1 Standby: g/Active timer expired (10.12.10.3)
*Jan 23 11:56:13.535: GLBP: Fa0/1 1 Active router IP is local, was 10.12.10.3
*Jan 23 11:56:13.535: GLBP: Fa0/1 1 Standby router is unknown, was local
*Jan 23 11:56:13.535: GLBP: Fa0/1 1 Standby -> Active  
<---R1 is the AVG now
*Jan 23 11:56:13.539: %GLBP-6-STATECHANGE: FastEthernet0/1 Grp 1 state Standby -> Active


Verify GLBP:
R1#sh glbp brief
Interface   Grp  Fwd Pri State    Address         Active router   Standby router
Fa0/1       1    -   100 Active   10.12.10.100    local           unknown
Fa0/1       1    1   -   Active   0007.b400.0101  local           -
Fa0/1       1    2   -   Active   0007.b400.0102  local           -
Fa0/1       1    3   -   Active   0007.b400.0103  local           -

R1#sh glbp
FastEthernet0/1 - Group 1
  State is Active
    10 state changes, last state change 00:04:10
  Virtual IP address is 10.12.10.100
  Hello time 3 sec, hold time 10 sec
    Next hello sent in 2.656 secs
  Redirect time 600 sec, forwarder timeout 14400 sec
  Preemption disabled
  Active is local
  Standby is unknown
  Priority 100 (default)
  Weighting 100 (default 100), thresholds: lower 1, upper 100
  Load balancing: round-robin
  Group members:
    0011.1111.1111 (10.12.10.1) local
  There are 3 forwarders (3 active)
  Forwarder 1
    State is Active
      9 state changes, last state change 00:04:11
    MAC address is 0007.b400.0101 (learnt)
    Owner ID is 0044.4444.4444
    Redirection disabled
    Time to live: 12305.408 sec (maximum 12567 sec)
    Preemption enabled, min delay 30 sec
    Active is local, weighting 100
  Forwarder 2
    State is Active
      1 state change, last state change 00:04:11
    MAC address is 0007.b400.0102 (learnt)
    Owner ID is 0033.3333.3333
    Redirection enabled, 337.824 sec remaining (maximum 600 sec)
    Time to live: 14137.824 sec (maximum 14400 sec)
    Preemption enabled, min delay 30 sec
    Active is local, weighting 100
  Forwarder 3
    State is Active
      7 state changes, last state change 00:58:27
    MAC address is 0007.b400.0103 (default)
    Owner ID is 0011.1111.1111
    Redirection enabled
    Preemption enabled, min delay 30 sec
    Active is local, weighting 100



We can see above after forwarder timeout expired GLBP Active gateway stops protection:

R3(config-if)#
*Jan 22 05:16:27.011: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 3 state Active -> Disabled
R3(config-if)#
*Jan 22 05:17:06.031: %GLBP-6-FWDSTATECHANGE: FastEthernet0/1 Grp 1 Fwd 1 state Active -> Disabled
R3(config-if)#




Monday, January 19, 2015

GLBP protocol



GLBP protocol

GLBP (Gateway Load Balancing Protocol ) as other fhrp  VRRP and HSRP provides gateway redundancy for hosts. This protocol gives more load sharing then other fhrp with condition that clients will have just one default gateway configured. It is more flexible.
GLBP routers exchange messages which contain the information providing Active Virtual Gateway election, determines GLBP router roles and tracking their states. GLBP provides up to four gateways in the group. One router in the group is elected as AVG (Active Virtual Gateway) and one router is elected as standby virtual gateway, other routers within the group are placed in "Listening" state. 
Active Virtual Gateway is responsible to reply for the ARP requests to virtual IP. AVG sends one of the forwarder's virtual MAC address inside the ARP reply. AVG maintaining virtual mac to IP mapping in the client cache. 

All routers of the group are forwarders and each router is the owner of the virtual mac-address assigned by the AVG and responsible for sending packets to its virtual address. 
Protocol does load sharing by responding to ARP request sent to virtual IP  with different virtual mac-addresses assigned to all GLBP routers. There are three different load sharing schemes: round-robin (default), weighted and host dependent.

GLBP:

-hello timer - 3 sec by default
-hold timer 10 sec by default
-GLBP group number available: 1-1023
-redirect timer -  AVG will reply to arp with failed forwarder's mac address due redirect time
-time to live - time while failed forwarder's virtual mac address is staying alive
-Virtual mac address has the following form: 0004.b4xx.xxyy where xx.xx - 16 bits where 6 bits are empty and next 10 bits are reserved for GLBP group number. yy - are the forwarder number.
-GLBP packets are sent to destination UDP port 3222 multicast address 224.0.0.102 to destination multicast MAC address 0105.5e00.0006 from source primary IP address and source virtual MAC address.
-Router with the priority equal to AVG and higher IP address didn't preempt the active GLBP router.
-GLBP is not IPv6 compatible
-GLBP doesn't support stacking feature

AVG election

AVG election is provided by priority (default value is 100). Router with the higher priority becomes AVG.

AVG fails

When AVG fails, the standby router becomes AVG after hold down timeout and new standby router would be elected.

AVF fails

After AVF fails it stops  to send it's GLBP messages, One of the GLBP forwarders pick up this failed  AVF's virtual mac address and this mac address become "Active" for it ----> now this backup forwarder has primary virtual address and secondary. this secondary virtual address is staying alive within minimum 600 seconds (default ARP timeout) and then flushes from arp table of clients. Due time to live backup forwarder sends additional TLV where specifyed onemore secondary virtual mac address.  

GLBP scenario or what are we going to do:

Our GLBP mini-lab include the next two parts related to Active Virtual Gateway (AVG) and Active Virtual Forwarding (AVF).

AVG discovering:

- Enable GLBP on one router, looking for information related to AVG
- explore TCP dump with GLBP packets
- explore debugging
- Enable GLBP on the neighboring router
- Tuning AVG timers
- enable AVG preemption
- exploring AVG election procedure

AVF discovering:

- configure 3 GLBP routers
- configure simple topology for sample traffic forwarding and testing
- testing failover with default timers
- tuning timers
- configure weighting
- explore tracking and weights thresholds




As known GLBP datagrams are sent over UDP port 3222.  GLBP information is transmitted inside the specified TLVs:
We enabled GLBP only on one router that is why the same router is will be the AVG and AVF.

R1(config-if)#glbp 1 ip 10.12.10.100

*Mar  1 01:56:31.767: %GLBP-6-STATECHANGE: FastEthernet0/0 Grp 1 state Standby -> Active
*Mar  1 01:56:41.767: %GLBP-6-FWDSTATECHANGE: FastEthernet0/0 Grp 1 Fwd 1 state Listen -> Active

All GLBP parameters are default.

R1(config-if)#do sh glbp
FastEthernet0/0 - Group 1
  State is Active
    2 state changes, last state change 00:00:05
  Virtual IP address is 10.12.10.100
  Hello time 3 sec, hold time 10 sec  
<--------- default AVG timer values
    Next hello sent in 0.488 secs
  Redirect time 600 sec, forwarder timeout 14400 sec  
  Preemption disabled
  Active is local
  Standby is unknown
  Priority 100 (default)
  Weighting 100 (default 100), thresholds: lower 1, upper 100
  Load balancing: round-robin
  Group members:
    0011.1111.1111 (10.12.10.1) local
  There is 1 forwarder (0 active)
  Forwarder 1
    State is Listen
    MAC address is 0007.b400.0101 (default)
    Owner ID is 0011.1111.1111
    Redirection enabled
    Preemption enabled, min delay 30 sec
    Active is unknown

HELLO TLV:

Router sends GLBP packet with only HELLO TLV while being starting GLBP process and while transition Init--->Listen and Listen---> Speak occurs.
Source MAC address is a primary mac of the router
Destination MAC address is a multicast MAC  0100.5e00.0066
Source IP address is a primary address of the router and destination IP is multicast IP address 224.0.0.102

PIC.1 Hello GLBP message:



Request/response

The next step after router advertised itself as a AVG, it is time to advertise itself as a AVF and it sends GLBP message with request/response TLV:

GLBP router sends Requet/response message with the virtual assigned source mac address to multicast mac address
Source IP address is a primary IP of the GLBP interface of the router.
GLBP router advertise assigned virtual mac-address.
Virtual mac address has the following form:
0004.b4xx.xxyy where xx.xx - 16 bits where 6 bits are empty and next 10 bits are reserved for GLBP group number. yy - are the forwarder number.

PIC.2 GLBP  Request/response TLV



After advertising itself as a GLBP, router send GLBP messages with both TLVs  with source virtual mac address: 

PIC.3 GLBP message with both TLVs.





GLBP AVG preemption is disabled on the port by default, that is why after enabling GLBP on the neighboring router with higher priority or with the same priority, but higher IP address, new router GLBP state will be "Standby"
AVF preemption is enabled by default.

R3(config-if)#glbp 1 ip 10.12.10.100
R3(config-if)#

*Mar  1 03:15:44.911: %GLBP-6-FWDSTATECHANGE: FastEthernet0/0 Grp 1 Fwd 2 state Listen -> Active
R3(config-if)#do sh glbp
FastEthernet0/0 - Group 1
  State is Standby
    1 state change, last state change 00:51:53
  Virtual IP address is 10.12.10.100
  Hello time 3 sec, hold time 10 sec
    Next hello sent in 0.380 secs
  Redirect time 600 sec, forwarder timeout 14400 sec
  Preemption disabled
  Active is 10.12.10.1, priority 100 (expires in 8.656 sec)
  Standby is local
  Priority 100 (default)
  Weighting 100 (default 100), thresholds: lower 1, upper 100
  Load balancing: round-robin
  Group members:
    0011.1111.1111 (10.12.10.1)
    0033.3333.3333 (10.12.10.3) local
  There are 2 forwarders (1 active)
  Forwarder 1
    State is Listen
    MAC address is 0007.b400.0101 (learnt)
    Owner ID is 0011.1111.1111
    Time to live: 14398.644 sec (maximum 14400 sec)
    Preemption enabled, min delay 30 sec
           <--------------------- AVF preemption


As you can see from debugging there are two active forwarders, one active and one standby gateways:
*Mar  1 12:19:32.964: GLBP: Fa0/0 Grp 1 Hello  out VG Active  pri 100 vIP 10.12.10.100 hello 20000, hold 100000 VF 1 Active  pri 167 vMAC 0007.b400.0101
*Mar  1 12:19:33.544: GLBP: Fa0/0 Grp 1 Hello  in  VG Standby pri 100 vIP 10.12.10.100 hello 20000, hold 100000 VF 2 Active  pri 167 vMAC 0007.b400.0102

Let's tune timers on the AVG and look at the timers on standby gateway GLBP router:
R1(config-if)# glbp 1 timers ?
  <1-60>    Hello interval in seconds
  msec      Specify hello interval in milliseconds
  redirect  Specify timeout values for failed forwarders
R1(config-if)# glbp 1 timers 20 ?
  <21-180>  Hold time in seconds
  msec      Specify hold time in milliseconds

R1(config-if)# glbp 1 timers 20 100


Next look at the standby GLBP router's timers:

R3(config-if)#do sh glbp
FastEthernet0/0 - Group 1
  State is Standby
    1 state change, last state change 09:01:27
  Virtual IP address is 10.12.10.100
 Hello time 20 sec, hold time 100 sec   <----------------Changing timers on the AVG 
  automatically changes timers for all GLBP standby gateways in the group
    Next hello sent in 1.888 secs
  Redirect time 600 sec, forwarder timeout 14400 sec
  Preemption enabled, min delay 0 sec
  Active is 10.12.10.1, priority 100 (expires in 81.380 sec)
  Standby is local
  Priority 100 (default)
  Weighting 100 (default 100), thresholds: lower 1, upper 100
  Load balancing: round-robin
  Group members:
    0011.1111.1111 (10.12.10.1)
    0033.3333.3333 (10.12.10.3) local
  There are 2 forwarders (1 active)
  Forwarder 1
    State is Listen
    MAC address is 0007.b400.0101 (learnt)
    Owner ID is 0011.1111.1111
    Time to live: 14381.368 sec (maximum 14400 sec)
    Preemption enabled, min delay 30 sec
    Active is 10.12.10.1 (primary), weighting 100 (expires in 89.940 sec)
  Forwarder 2
    State is Active
      1 state change, last state change 09:02:26
    MAC address is 0007.b400.0102 (default)
    Owner ID is 0033.3333.3333
    Preemption enabled, min delay 30 sec
    Active is local, weighting 100


Let's enable AVG preemption:
R3(config-if)# glbp 1 preempt
R3(config-if)# do sh run int fa 0/0
Building configuration...

Current configuration : 162 bytes
!
interface FastEthernet0/0
mac-address 0033.3333.3333
ip address 10.12.10.3 255.255.255.0
speed 100
full-duplex
glbp 1 ip 10.12.10.100
glbp 1 preempt
end


Router with the priority equal to AVG and higher IP address didn't preempt the active GLBP router.

Now we change priority on the standby gateway:
R3(config-if)#glbp 1 priority ?
  <1-255>  Priority value
 R3(config-if)#glbp 1 priority 105
R3(config-if)#

*Mar  1 12:29:21.072: GLBP: Fa0/0 1 Standby: l/Hello rcvd from lower pri Active router (100/10.12.10.1)
*Mar  1 12:29:21.076: GLBP: Fa0/0 1 Active router IP is local, was 10.12.10.1
*Mar  1 12:29:21.076: GLBP: Fa0/0 1 Standby router is unknown, was local
*Mar  1 12:29:21.076: GLBP: Fa0/0 1 Standby -> Active
*Mar  1 12:29:21.076: %GLBP-6-STATECHANGE: FastEthernet0/0 Grp 1 state Standby -> Active

Look at the Active router debugging:
R1(config-if)#
*Mar  1 12:29:13.084: GLBP: Fa0/0 Grp 1 Hello  out VG Active  pri 100 vIP 10.12.10.100 hello 20000, hold 100000 VF 1 Active  pri 167 vMAC 0007.b400.0101
*Mar  1 12:29:13.248: GLBP: Fa0/0 Grp 1 Hello  in  VG Active  pri 105 vIP 10.12.10.100 hello 20000, hold 100000 VF 2 Active  pri 167 vMAC 0007.b400.0102
*Mar  1 12:29:13.248: GLBP: Fa0/0 1 Active router IP is 10.12.10.3, was local
*Mar  1 12:29:13.252: GLBP: Fa0/0 1 Standby router is unknown, was 10.12.10.3
*Mar  1 12:29:13.252: GLBP: Fa0/0 1 Active: k/Hello rcvd from higher pri Active router (105/10.12.10.3)
*Mar  1 12:29:13.252: GLBP: Fa0/0 1 Active -> Speak
*Mar  1 12:29:13.252: %GLBP-6-STATECHANGE: FastEthernet0/0 Grp 1 state Active -> Speak
R1(config-if)#
*Mar  1 12:29:13.256: GLBP: Fa0/0 Grp 1 Hello  out VG Speak   pri 100 vIP 10.12.10.100 hello 20000, hold 100000 VF 1 Active  pri 167 vMAC 0007.b400.0101
After some hello messages exchanging we have new active and standby GLBP routers:
R1(config-if)#
*Mar  1 12:30:53.160: GLBP: Fa0/0 Grp 1 Hello  in  VG Active  pri 105 vIP 10.12.10.100 hello 20000, hold 100000 VF 2 Active  pri 167 vMAC 0007.b400.0102
*Mar  1 12:30:53.252: GLBP: Fa0/0 1 Speak: f/Standby timer expired (unknown)
*Mar  1 12:30:53.252: GLBP: Fa0/0 1 Standby router is local
*Mar  1 12:30:53.252: GLBP: Fa0/0 1 Speak -> Standby
*Mar  1 12:30:53.252: GLBP: Fa0/0 Grp 1 Hello  out VG Standby pri 100 vIP 10.12.10.100 hello 20000, hold 100000 VF 1 Active  pri 167 vMAC 0007.b400.0101

 Verify GLBP router's states:

R1(config-if)#do sh glbp bri
Interface   Grp  Fwd Pri State    Address         Active router   Standby router
Fa0/0       1    -   100 Standby  10.12.10.100    10.12.10.3      local
Fa0/0       1    1   -   Active   0007.b400.0101  local           -
Fa0/0       1    2   -   Listen   0007.b400.0102  10.12.10.3      -


Let's configure third router to be in this GLBP group:

R4(config-if)#do sh run int fa 0/0
interface FastEthernet0/0
mac-address 0044.4444.4444
ip address 10.12.10.4 255.255.255.0
speed 100
full-duplex
glbp 1 ip 10.12.10.100
glbp 1 preempt
end
This config caused the router R1 with the lowest IP address to be in the "Listen" state and R3 and R4 in the Active and Standby states.
As conclusion we can say, that Standby GLBP router will preempt only when it's priority becomes higher then priority of the Active router. Routers with lower IP addresses automatically becomes "Listen" GLBP routers. There are only one Active and Only one standby router.

Weighting and tracking
In GLBP can be used three different schemes of load sharing.
Weighting can be assign manually and every GLBP router will advertise it to each other. ARP replies with virtual mac addresses will be sent proportionally weights of GLBP router s in the group.
You can set lower and upper threshold to track the state of GLBP router. You also can configure tracking the way you need to automatically tune GLBP weight depending of operation of your network. It is a very flexible tool to solve specific tasks related with load sharing.


Configuration example:
We need the weight of R1 to be decreased lower the threshold after line protocol of one of specified interfaces goes down.


R1(config-if)#do sh ip inter bri
Interface                  IP-Address      OK? Method Status                Protocol
FastEthernet0/0            10.12.10.1      YES manual up                    up
FastEthernet1/0            172.20.123.1    YES manual up                    up
R1(config-if)#int fa 0/0
R1(config-if)#glbp 1 weightin ?
  <1-254>  Weighting maximum value
  track    Interface tracking

R1(config-if)#glbp 1 weightin 100 ?
  lower  Weighting lower threshold
  upper  Weighting upper threshold
  <cr>

 R1(config-if)#glbp 1 weightin 100 lower ?
  <1-99>  Weighting lower threshold value  
        <----------- Possible threshold values lower

R1(config-if)#glbp 1 weightin 100 lower 40 ?
  upper  Weighting upper threshold                   
 <------------ Possible threshold values upper
  <cr>

R1(config-if)#glbp 1 weightin 100 lower 40 upper 100
R1(config-if)#do sh run int fa 0/0
Building configuration...

Current configuration : 208 bytes
!
interface FastEthernet0/0
mac-address 0011.1111.1111
ip address 10.12.10.1 255.255.255.0
speed 100
full-duplex
glbp 1 ip 10.12.10.100
glbp 1 weighting 100 lower 40
end

Configure tracking

R1(config-if)#glbp 1 weighting track 1 decrement ?
  <1-255>  Decrement value
R1(config-if)#glbp 1 weighting track 1 decrement 70
R1(config-if)#exit
R1(config)#track 1 interface fa 1/0 line-protocol


Now we manually shut tracked interface and look at the debufg output:

R1(config-if)#do deb glbp terse <----- turn on brief debugging of GLBP 
GLBP:
  GLBP Errors debugging is on
  GLBP Events debugging is on
    (protocol, redundancy, track)
  GLBP Packets debugging is on
    (Request, Reply)
R1(config-if)#
R1(config-if)#int fa 1/0
R1(config-if)#shut              <----Manually shutting interface
*Mar  2 13:06:34.674: %TRACKING-5-STATE: 1 interface Fa1/0 line-protocol Up->Down
*Mar  2 13:06:34.678: GLBP: Fa0/0 1 Track 1 object changed, state Up -> Down
*Mar  2 13:06:34.678: GLBP: Fa0/0 1 Weighting 100 -> 30
*Mar  2 13:06:36.674: %LINK-5-CHANGED: Interface FastEthernet1/0, changed state to administratively down
*Mar  2 13:06:37.674: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet1/0, changed state to down
*Mar  2 13:07:06.118: GLBP: Fa0/0 1.1 Active: i/Hello rcvd from higher pri Active router (135/10.12.10.3)
*Mar  2 13:07:06.118: GLBP: Fa0/0 1.1 Active -> Listen

R1(config-if)#
*Mar  2 13:07:06.118: %GLBP-6-FWDSTATECHANGE: FastEthernet0/0 Grp 1 Fwd 1 state Active -> Listen   <---Forwarder becomes "Listen"
R1(config-if)#



Let's look at debugging on ohter GLBP routers :
Here is debugging from the router that became backup forwarder after R1 failed:

R4(config-if)#
*Mar  2 13:06:43.794: GLBP: Fa0/0 1.1 Preemption delayed, 30 secs remaining <----default preemption delay
 *Mar  2 13:07:13.806: GLBP: Fa0/0 1.1 Listen: k/Hello rcvd from lower pri Active router (39/10.12.10.1) <---- R1 became a lower priority GLBP forwarder
*Mar  2 13:07:13.810: GLBP: Fa0/0 1.1 Listen -> Active
*Mar  2 13:07:13.810: %GLBP-6-FWDSTATECHANGE: FastEthernet0/0 Grp 1 Fwd 1 state Listen -> Active

PIC.4 R4 becomes a backup forwarder fot R1 and carry two TLVs:



If you disable forwarding preemprtion on all GLBP routers then after time to live timer expire --> virtual mac address will become disable:

R4(config-if)#do sh run int fa 0/0 | i glbp
glbp 1 ip 10.12.10.100
glbp 1 timers redirect 10 610

glbp 1 preempt                        <-------------AVG preemption is enabled
glbp 1 load-balancing weighted
no glbp 1 forwarder preempt  
   <------------ AVF preemption is disabled


R4(config-if)#do sh glbp | i live
    Time to live: 0.568 sec (maximum 609 sec) 
 <--------time to live timer expires
    Time to live: 607.848 sec (maximum 610 sec)
R4(config-if)#
*Mar  1 18:36:48.839: GLBP: Fa0/0 1.1 Active: c/Secondary timer expired
*Mar  1 18:36:48.839: GLBP: Fa0/0 1.1 Active -> Disabled

*Mar  1 18:36:48.839: %GLBP-6-FWDSTATECHANGE: FastEthernet0/0 Grp 1 Fwd 1 state Active -> Disabled
R4(config-if)#
%GLBP-6-FWDSTATECHANGE: FastEthernet0/0 Grp 1 Fwd 1 state Active -> Disabled   <----AVF's virtual mac is disabled

I the next part of GLBP protocol notes I will test GLBP in action.