Professional Documents
Culture Documents
RE CB
PIC 4/1
FPC #4
FEB #4
(10.2.2.2, 10.2.2.1)
SIBs
so-1/0/0
10.2.2/30 10.3.3/30
so-4/1/0 .2 so-5/1/0
www.juniper.net
M320
.1 so-1/1/0
M120
RE CB
PIC 4/1
FPC #4
FEB #4
SIBs
so-1/0/0
10.2.2/30 10.3.3/30
so-4/1/0 .2 so-5/1/0
www.juniper.net
M320
.1 so-1/1/0
M120
The interface option only alters the source IP address by default Similar to source option (monitor traffic interface displays packets)
RE CB
FPC #1 user@m320> ping 10.2.2.2 interface so-1/1/0 FEB #4
RE CB
FEB #5 FPC #5 PIC 5/1
PIC 1/1
PIC 1/0
so-1/0/0
10.2.2/30 10.3.3/30
so-4/1/0 .2 so-5/1/0
www.juniper.net
M320
.1 so-1/1/0
M120
bypass-routing allows to force the packet to go out a given interface Only works properly at SONET/SDH interfaces
RE CB FPC #1
user@m320> ping 10.2.2.2 interface so-1/1/0 bypass-routing PIC 1/1
(SA, DA) = (10.3.3.1, 10.2.2.2)
RE CB
FPC #5
PIC 5/1
FEB #5
(10.2.2.2, 10.3.3.1)
SIBs
so-1/0/0
10.2.2/30 10.3.3/30
so-4/1/0 .2 so-5/1/0
www.juniper.net
M320
.1 so-1/1/0
M120
RE CB
(10.2.2.1, 10.2.2.1)
RE CB
FPC #1
PIC 1/0
PIC 4/1
FPC #4
FEB #4
M320
so-1/0/0 .1
10.2.2/30
so-4/1/0 .2
M120
www.juniper.net
RE CB
(10.2.2.1, 10.2.2.1)
RE CB
FPC #1
PIC 1/0
PIC 4/1
FPC #4
FEB #4
M320
so-1/0/0 .1
10.2.2/30
so-4/1/0 .2
M120
www.juniper.net
bypass-routing allows to force the packet to go out a given interface Only works properly at SONET/SDH interfaces
(10.2.2.1, 10.2.2.1)
RE CB FPC #1
RE CB
FPC #4
PIC 4/1
FEB #4
M320
so-1/0/0 .1
10.2.2/30
so-4/1/0 .2
M120
www.juniper.net
RE CB FPC #1
RE CB
PIC 1/0
(10.2.2.1, 10.2.2.2)
PIC 4/1
FPC #4
FEB #4
M320
user@m320> ping 10.2.2.2 PING 10.2.2.2 (10.2.2.2): 56 data bytes 36 bytes from 10.2.2.1: Time to live exceeded Vr HL TOS Len ID Flg off TTL Pro cks Src 4 5 00 0054 8212 0 0000 01 01 1f91 10.2.2.1
11
Copyright 2009 Juniper Networks, Inc. www.juniper.net
M120
Dst 10.2.2.2
RE CB FPC #1
(10.2.2.1, 10.2.2.2) (10.2.2.2, 10.2.2.1)
RE CB FEB #4
PIC 1/0
PIC 4/1
FPC #4
M320
M120
user@M320# edit interfaces so-1/0/0 [ no-keepalives ; sonet-options loopback local; ] user@M120# edit interfaces so-4/1/0 [ no-keepalives ; sonet-options loopback local; ]
(*) May be necessary to remove family iso and family mpls for the test
12
Copyright 2009 Juniper Networks, Inc. www.juniper.net
RE CB FPC #1
(10.2.2.1, 10.2.2.2) (10.2.2.2, 10.2.2.1)
RE CB FEB #4
PIC 1/0
PIC 4/1
FPC #4
SIBs
[edit firewall family inet filter prueba-loopback] term unico then { count paquetes; accept; } [edit interfaces so-1/0/0 unit 0 family inet] filter output prueba-loopback;
13
Copyright 2009 Juniper Networks, Inc. www.juniper.net
RE CB FPC #1
RE CB
FPC #4
PIC 4/1
FEB #4
M320
M120
user@M320# set interfaces so-1/0/0 no-keepalives user@M120# set interfaces so-4/1/0 no-keepalives user@M120# set interfaces so-4/1/0 sonet-options loopback remote
14
Copyright 2009 Juniper Networks, Inc. www.juniper.net
bypass-routing allows to force the packet to go out a given interface Only works properly at SONET/SDH interfaces
user@m320> ping 10.2.2.1 interface so-1/0/0 bypass-routing user@m120> ping 10.2.2.2 interface so-4/1/0 bypass-routing
RE CB FPC #1
(10.2.2.1, 10.2.2.2) (10.2.2.2, 10.2.2.1)
RE CB FEB #4
PIC 1/0
PIC 4/1
FPC #4
M320
M120
user@M320# edit interfaces so-1/0/0 [ no-keepalives ; sonet-options loopback local; ] user@M120# edit interfaces so-4/1/0 [ no-keepalives ; sonet-options loopback local; ]
15
Copyright 2009 Juniper Networks, Inc. www.juniper.net
IMPLEMENTATION DETAILS
16
Copyright 2009 Juniper Networks, Inc. www.juniper.net
RE CB FPC #1
PIC 1/0
(10.2.2.1, 10.2.2.1)
RE CB
PIC 4/1
FPC #4
FEB #4
M320
17
SONET FRAMERS
Copyright 2009 Juniper Networks, Inc. www.juniper.net
M120
RE CB FPC #1
PIC 1/0
RE CB FEB #4
PIC 4/1
(10.2.2.1, 10.2.2.2)
FPC #4
M320
18
SONET FRAMERS
Copyright 2009 Juniper Networks, Inc. www.juniper.net
M120
RE CB (control) FEB #5
PIC 4/0
FPC #4 FPC #5
5/1 PIC
CB (fabric)
transit ping with record-route option transit ping with no special option
19
Copyright 2009 Juniper Networks, Inc. www.juniper.net
FEB #4
remote Yes No No No
TOS OPTION
21
Copyright 2009 Juniper Networks, Inc. www.juniper.net
IP Precedence 3 bit bin 000 001 010 011 100 101 110 111
22
DSCP 6 bit 8 bit dec 0 8 16 24 32 40 48 56 bin 00000000 00100000 01000000 01100000 10000000 10100000 11000000 11100000
www.juniper.net
dec 0 1 2 3 4 5 6 7
The ping tos option can change the DSCP/IP Precedence but not the queue the packet goes to The ICMP echo reply mirrors the DSCP/IP Precedence from the original ICMP echo request In Junos OS 10.4 output lo0 firewall filters support actions to rewrite FC,PLP (queue number) and DSCP/IP Precedence independently before sending packet to PFE Egress control packets are never processed by rewrite rules
23
Copyright 2009 Juniper Networks, Inc. www.juniper.net
LAB DIAGRAMS
24
Copyright 2009 Juniper Networks, Inc. www.juniper.net
NETWORK DIAGRAM
lo0.0 10.100.3.3
M7i
lo0.0 10.100.2.2
M320
.1 so-1/1/0
M120
25
www.juniper.net
RE CB FPC #1
PIC 1/0
RE CB
PIC 4/1
FPC #4
FEB #4
M320
M120
26
www.juniper.net
M120
RE CB
PIC 5/1
FPC #5
FEB #4
FEB #5 FPC #4
PIC 1/1 PIC 4/1
PIC 4/0
27
www.juniper.net
M120
RE CB
PIC 1/1
FPC #1
PIC 5/1
FEB #4
FEB #5 FPC #4
PIC 4/1
PIC 4/0
PIC 1/0
M7i
28
www.juniper.net
amonge@juniper.net v1.0 Presented to customer amonge@juniper.net v1.1 Added lab slides, sending to customer