Networking-Blog

My WordPress Blog

BGP – Route-map filtering configuration

Using route-map, you can control in/outbound BGP announcement and apply various attributes :

router bgp 65535
network z.z.z.z
neighbor y.y.y.y remote-as 65500
neighbor y.y.y.y route-map ISP-out out
!
route-map ISP-out permit 10
match ip address 100
!
access-list 100 permit z.z.z.0 0.0.0.255

Recommended to use ip prefix-list since it is lower on cpu/memory resources :

ip prefix-list IPV4-OUT seq 5 permit z.z.z.0/21
ip prefix-list IPV4-OUT seq 10 deny 0.0.0.0/0 le 32
!
route-map ISP-out permit 10
match ip address IPV4-OUT
!
neighbor y.y.y.y route-map ISP-out out

How to configure secure BGP?

How to configure secure BGP?

There are few ways to make robust BGP session. Keep it in your mind, ISP doesn’t provide all
below commands (Don’t wasting time). They would configure MD5 hash for your link. 

1. Using MD5 password

MD5 setting is common and easy to implement.

router bgp 300
neighbor x.x.x.x password cisco

How to hide private BGP ASN from ISP

We know how to change peer ASN without changing BGP processor ID which might be private ASN.
That is local-as commands is the one to replace ASN for outside of world. However, your BGP peer
keep on sending private ASN or current BGP processor ID. Here is the magic command to fix it. 

“neighbor x.x.x.x local-as yyy no-prepend replace-as“

CISCO – LAB CHALLENGE – BASIC BGP

Complete the following tasks:

– Configure R1 for basic BGP with ISP1 and ISP2. 
– Use the existing WAN IP addressing and provided ASNs 
– Advertise 10.1.3.0/24 to both providers equally
– Advertise 10.1.4.0/24 to both providers equally

 

R1 :

interface Loopback0
ip address 10.1.3.1 255.255.255.0
!
interface Loopback4
ip address 10.1.4.1 255.255.255.0
!
interface FastEthernet0/0
ip address 10.1.1.2 255.255.255.252
duplex auto
speed auto
!
interface FastEthernet1/0
ip address 10.1.2.2 255.255.255.252
duplex auto
speed auto
!
router bgp 300
no synchronization
bgp log-neighbor-changes
network 10.1.3.0 mask 255.255.255.0
network 10.1.4.0 mask 255.255.255.0
neighbor 10.1.1.1 remote-as 100
neighbor 10.1.2.1 remote-as 200
no auto-summary
!
ip route 10.1.3.0 255.255.255.0 Null0
ip route 10.1.4.0 255.255.255.0 Null0

 

ISP1 :

interface FastEthernet0/0
ip address 10.1.1.1 255.255.255.252
!
router bgp 100
no synchronization
bgp log-neighbor-changes
neighbor 10.1.1.2 remote-as 300
no auto-summary

 

ISP2 :

interface FastEthernet0/0
ip address 10.1.2.1 255.255.255.252
!
router bgp 200
no synchronization
bgp log-neighbor-changes
neighbor 10.1.2.2 remote-as 300
no auto-summary

 

CISCO – BGP ROUTING

CISCO BGP SUMMARY

I have seen static route pointing towards a null0 interface in BGP. Can I know why it is used for?

The static route to null 0 is needed to advertise networks into BGP,

BGP would advertise Networks using any of the bellow methods:

1– with the Network command set.
2– Redistribution into BGP.
3– Aggregate address command.

All of these methods needs an exact match in the routing table , except for the aggregation which
needs at least one route part of the aggregate address exist.

However, doesn’t need the (network command under bgp) as long as the aggregate address along with
one part of the aggregate address exist in the IP routing table.

EG :

ip route 196.196.1.0 255.255.255.0 Null0

router bgp myASN
network 196.196.1.0 mask 255.255.255.0

…

(((
modern way

router bgp myASN
aggregate-address 196.196.0.0 255.255.252.0 summary-only

))))

it is a way to create an aggregate = a summary route

 

Route Reflectors

Another solution for the explosion of iBGP peering within an AS is Route Reflectors (RRs).
As the iBGP section demonstrates, a BGP speaker does not advertise a route that the BGP speaker
learned via another iBGP speaker to a third iBGP speaker.
You can relax this restriction a bit and provide additional control, which allows a router to
advertise, or reflect, iBGP learned routes to other iBGP speakers. This route reflection reduces the
number of iBGP peers within an AS.

neighbor route-reflector-client

The router with this command is the RR, and the neighbors at which the command points are
the clients of that RR.

 

Tuning BGP Transport

Tuning BGP transport mechanism is a very important factor for improving BGP performance in
the cases where purely BGP-based re-convergence process is in use. TCP is the underlying transport
used for propagating BGP UPDATE messages,and optimizing TCP performance directly benefits BGP.

If you take the full Internet routing table, which is above 300k prefixes (Y2010), then simply transporting
the prefixes alone will consume over 10 Megabytes, not to count the path attributes and other
information. Tuning TCP transport performance includes the following:

Enabling TCP Path MTU discovery for every neighbor, to allow the TCP selecting optimum MSS size.
Notice that this requires that no firewall blocks the ICMP unreachable messages used during the
discovery process Tuning the router’s ingress queue size to allow for successful absorption of large
amount of TCP ACK messages. When a router starts replicating BGP UPDATES to its peers, every peer
responds with TCP ACK message to normally every second segment sent (TCP Delayed ACK).
The more peers router has, the higher will be the pressure on the ingress queue.

ASA – Group Object

Create a Object-Group icmp-type ICMP traffic :

object-group icmp-type INBOUND
description Permit necessary inbound ICMP traffic
icmp-object echo
icmp-object echo-reply
icmp-object unreachable
icmp-object time-exceeded

Create a Object-Group service for TCP traffic :

object-group service INBOUND tcp
description Inbound Access
port-object eq 3389
port-object range 9998 9999

ADSL2 v ADSL2+

There’s a common misconception that ADSL2+ is faster than ADSL2 on any line.
That’s not really the case. In simple terms,

ADSL2+ utilises twice the frequency range available on your phone line that ADSL2 does.
This again, in simple terms means twice as fast BUT that is only seen on short low attenuation lines.

If your line is only capable of supporting 7meg on ADSL2 then it’s only capable of supporting 7meg on ADSL2+
as it can only usually allow the use of the same frequencies for both (see below).

However, if you’re lucky enough to have a line that can support higher frequencies then you get up to :
 
12meg
on ADSL2 (the maximum possible)
but up to
24meg on ADSL2+.

The cross over between ADSL2 and ADSL2+ is therefore in the 10-12 meg range (typically 35-40db if the line is relatively noise free).

It can give faster speeds but usually only on short lines as explained above.
The only time that wouldn’t be true is for a moderately short line
(that offered some higher frequencies above those usable by ADSL2)
that had induced noise at the lower frequencies and was clean at higher frequencies,
in which case ADSL2+ would possibly be better as it could use those higher frequencies.

There is also the possibility that a network uses equipment whose firmware works better in
certain conditions with specific ADSL modes hence why it is mentioned G.DMT sometimes being
better for problem lines.

Cisco: 1841 – 3G Configuration

This configuration example is for use with a 3G WIC card within a Cisco based
Router.

This was configured with a Vodafone Network.

Initialization

Place the SIM card into it, then insert the card in the router and power it on.

Create a Profile specific to your mobile ISP

  • Insert the APN told by your ISP (Vodafone UK: ‘Internet’ username: ‘web’ password: ‘web’)
  • Insert the authentication method (chap or pap) and the credentials, also supplied from your ISP

Below is an example of a Vodafone UK Cellar Profilule.
Router# cellular 0/0/0 gsm profile create 1 Internet chap web web

From the profile you’ve just created, you can review it using command

router# sh cellular 0 profile

Profile Information
====================
Profile 1 = ACTIVE
--------
PDP Type = IPv4
PDP address = 192.168.1.1
Access Point Name (APN) = Internet
Authentication = PAP
Username: web, Password: web 

* - Default profile

Configuration

You need to define a chat script first, which is used for modem setup and call
initialization. If you are familiar with IOS dial configurations, you feel at home.
Please note that the last number in the dial string (1 in the example below) refers
to the modem profile number you hopefully have defined earlier.

! your chat script
chat-script vodafone “” “ATDT*98*1#” TIMEOUT 60 CONNECT

! the bare interface config
! subcommands at the Cellular interface

interface Cellular0/0/0
ip address negotiated
ip virtual-reassembly
encapsulation ppp
dialer in-band
dialer idle-timeout 0
dialer string vodafone
dialer-group 1
async mode interactive
ppp chap hostname web
ppp chap password 0 web
ppp ipcp dns request

!

ip route 0.0.0.0 0.0.0.0 Cellular0
dialer-list 1 protocol ip permit

! this is the async line assigned to the 3G modem
you need to specify your chat script here

line 0/0/0
script dialer vodaphone
no exec
rxspeed 3600000
txspeed 384000

If cellular int does not get an ip address, might need to go into
config t and add this line
even thou we see it above :

line 0/0/0
script dialer vodaphone

!
!

show command:

Just in case you need it for troubleshooting, here are the show commands to use.

  • show cellular 0 network
  • show cellular 0 hardware
  • show cellular 0 connection
  • show cellular 0 radio
  • show cellular 0 profile
  • show cellular 0 security
  • show cellular 0 all Debug commands :
  • debug chat Rather than reloading the router to restart the module, you can
    actually using CLI to reset or reboot the module
    :

    debug chat

    router(config)# service internal
    router(config)# exit
    router# test cellular 0 modem-power-cycle ! for rebooting
    router# test cellular 0 modem-reset ! for resetting

    debug commands :

    debug chat
    debug modem
    debug dialer events
    debug ppp authentication

  • Remember to create the Cellular Profile, after tftp config to router :
    cellular 0/0/0 gsm profile create 1 Internet chap web web
  • This is the bare configuration, you will need to add NAT, firewalls etc etc.

Linux Video Driver Version Command

Video Driver Version Command

dmesg | grep NVIDIA
sudo lspci -vvnn | grep 10de

 

What I did from the command line is to find the packages for nvidia

(dpkg -l | grep nvidia)
and then
apt-get remove nvidia-173 

(or whatever package you get from the previous command).

The problem is that you will still have the nvidia modues listed in xorg.conf.
So, I also  mv /etc/X11/xorg.conf /etc/X11/xorg.conf_backup
and rebooted.

I landed in a graphical mode as usual, without the nvidia GL stuff,
but then there are graphical tools to set it up.

At this state, it’s safe to delete the xorg.conf backup you just created.

####################
Whenever I try to start my computer from kernel version 3 (it boots fine with 2.6) Kubuntu stops booting

altogether.

11.10 stops booting at “Checking battery state … [OK]”

I had to reinstall my graphics drivers.

sudo apt-get install --reinstall nvidia-173

Home Linux Ubuntu Iptables Firewall Rule

# Generated by iptables-save v1.4.4 on Wed Dec 29 15:11:27 2010
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -d 127.0.0.0/8 ! -i lo -j REJECT –reject-with icmp-port-unreachable
-A INPUT -m state –state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 222 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 222 -m state –state NEW -m recent –update –seconds 60 –hitcount 8 –rttl –name SSH –rsource -j DROP
-A INPUT -d 172.16.254.3/32 -i eth0 -p tcp -m tcp –dport 8080 -j ACCEPT
-A INPUT -d 10.20.254.254/32 -i eth0 -p tcp -m tcp –dport 1723 -j ACCEPT
-A INPUT -d 172.16.254.3/32 -i eth0 -p udp -m udp –dport 7777 -j ACCEPT
-A INPUT -d 172.16.254.3/32 -i eth0 -p udp -m udp –dport 7778 -j ACCEPT
-A INPUT -d 172.16.254.3/32 -i eth0 -p udp -m udp –dport 7787 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 5800 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 5900 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 5901 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 5902 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 5938 -j ACCEPT
-A INPUT -s 10.20.254.249/32 -d 192.168.2.4/32 -i ppp0 -p tcp -m tcp –dport 139 -j ACCEPT
-A INPUT -s 192.168.6.0/29 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 139 -j ACCEPT
-A INPUT -s 172.16.254.3/32 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 139 -j ACCEPT
-A INPUT -s 172.16.254.3/32 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -s 10.0.0.0/24 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -s 10.0.1.0/24 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -s 192.168.6.0/29 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -s 10.20.254.249/32 -d 192.168.2.4/32 -i ppp0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -s 192.168.3.0/29 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -s 192.168.4.0/28 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -s 172.16.0.2/32 -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 445 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 21 -j ACCEPT
-A INPUT -s 192.168.2.1/32 -d 192.168.2.4/32 -i eth0 -p udp -m udp –dport 514 -j ACCEPT
-A INPUT -s 192.168.2.1/32 -d 192.168.2.4/32 -i eth0 -p udp -m udp –dport 9996 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p udp -m udp –dport 50518 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p tcp -m tcp –dport 50518 -j ACCEPT
-A INPUT -d 192.168.2.4/32 -i eth0 -p udp -m udp –dport 6881 -j ACCEPT
-A INPUT -s 192.168.2.1/32 -d 10.20.254.248/29 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 192.168.2.1/32 -d 172.16.254.2/32 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 192.168.2.1/32 -d 172.16.254.3/32 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 192.168.2.1/32 -d 172.16.254.3/32 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 192.168.4.0/28 -d 192.168.2.4/32 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 192.168.4.0/28 -d 172.16.254.3/32 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 192.168.6.0/29 -d 192.168.2.4/32 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 172.16.0.2/32 -d 192.168.2.4/32 -i eth0 -p icmp -j ACCEPT
-A INPUT -s 10.20.254.248/29 -d 10.20.254.248/29 -i ppp0 -p icmp -j ACCEPT
-A INPUT -s 10.20.254.249/32 -d 192.168.2.4/32 -i ppp0 -p icmp -j ACCEPT
-A INPUT -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7
-A INPUT -j DROP
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 80 -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -p tcp -m tcp –sport 8080 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 443 -j ACCEPT
-A OUTPUT -s 10.20.254.254/32 -p tcp -m tcp –sport 1723 -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -p udp -m udp –sport 7777 -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -p udp -m udp –sport 7778 -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -p udp -m udp –sport 7787 -j ACCEPT
-A OUTPUT -s 10.20.254.254/32 -p gre -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 5938 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 5900 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 21 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.2.1/32 -p tcp -m tcp –dport 2222 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.3.2/32 -p tcp -m tcp –dport 2223 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.4.2/32 -p tcp -m tcp –dport 2223 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.2.1/32 -p udp -m udp –dport 53 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 30000 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p icmp -j ACCEPT
-A OUTPUT -s 172.16.254.2/32 -d 192.168.2.1/32 -p icmp -j ACCEPT
-A OUTPUT -s 172.16.254.2/32 -d 172.16.254.1/32 -p icmp -j ACCEPT
-A OUTPUT -s 172.16.254.2/32 -d 172.16.254.3/32 -p icmp -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -d 172.16.254.1/32 -p icmp -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -d 172.16.254.2/32 -p icmp -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -d 192.168.2.4/32 -p icmp -j ACCEPT
-A OUTPUT -s 172.16.254.3/32 -d 192.168.4.0/28 -p icmp -j ACCEPT
-A OUTPUT -s 10.20.254.254/32 -d 192.168.2.1/32 -p icmp -j ACCEPT
-A OUTPUT -s 10.20.254.254/32 -d 192.168.2.4/32 -p icmp -j ACCEPT
-A OUTPUT -s 10.20.254.249/32 -d 192.168.2.4/32 -p icmp -j ACCEPT
-A OUTPUT -s 10.20.254.254/32 -d 10.20.254.249/32 -p icmp -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p udp -m udp –dport 69 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 23 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p udp -m udp –dport 123 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 81.103.221.11/32 -p tcp -m tcp –dport 25 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.2.1/32 -p udp -m udp –dport 514 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.2.1/32 -p udp -m udp –dport 161 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.2.1/32 -p udp -m udp –dport 162 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 4070 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 192.168.5.2/32 -p tcp -m tcp –dport 9100 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -d 94.136.40.61/32 -p tcp -m tcp –dport 110 -j ACCEPT
-A OUTPUT -s 192.168.2.4/32 -p tcp -m tcp –dport 1024:65535 -j ACCEPT
-A OUTPUT -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7
-A OUTPUT -j DROP
COMMIT
# Completed on Wed Dec 29 15:11:27 2010
# Generated by iptables-save v1.4.4 on Wed Dec 29 15:11:27 2010
*nat
:PREROUTING ACCEPT [430:32842]
:POSTROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [2773:170524]
COMMIT
# Completed on Wed Dec 29 15:11:27 2010
# Generated by iptables-save v1.4.4 on Wed Dec 29 15:11:27 2010
*mangle
:PREROUTING ACCEPT [1735576:104189954]
:INPUT ACCEPT [1735512:104181797]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [2877496:3782379744]
:POSTROUTING ACCEPT [2874912:3782220690]
COMMIT
# Completed on Wed Dec 29 15:11:27 2010