After configuring IPv6 under an interface, see the ipv6 neighbor or host resolution doesn't work.
Router1.10:36:22(config-if-Po5)#sh ipv6 interface po5
Port-Channel5 is up, line protocol is up (connected)
IPv6 is stalled, link-local is unassigned
Global unicast address(es):
2000:170:1:170::1, subnet is 2000:170:1:170::/64 [INACTIVE]
No joined group addresses
ND DAD status is unavailable
ND Reachable time is 30000 milliseconds
ND retransmit interval is 1000 milliseconds
The reason is that, I have a line of a left-over configuration of smaller-than-normal mtu size - 1200. The lowest MTU size of IPv6 is 1280.
interface Port-Channel5
description Cdn_Test_upLink
mtu 1200
no switchport
vrf IxCdn
ip address 170.1.170.1/24
ipv6 nd cache expire 60
ipv6 enable
ipv6 address 2000:170:1:170::1/64
ipv6 nd ra disabled all
no mpls ip
no qos trust
spanning-tree bpdufilter enable
After removing this line, everything is fine.
Port-Channel5 is up, line protocol is up (connected)
IPv6 is enabled, link-local is fe80::464c:a8ff:fea5:1140/64
Global unicast address(es):
2000:170:1:170::1, subnet is 2000:170:1:170::/64
Joined group address(es):
ff02::1
ff02::1:ff00:1
ff02::1:ffa5:1140
Disclaimer: The information contained in this blog is for informational purposes only and should not be considered as official documentation on any subject matter. The postings on this blog are my own and do not necessarily represent the opinions of my current and previous employers.
11/21/2019
11/05/2019
Arista EOS Segment Routing (3) - SR Routing #1, Static Route + NHG
The Arista MPLS Segment Routing White Paper(Page 8) lists 4 SR routing solutions:
1) Static label push via NHG
2) Controller via EOS SDK
3) BGP LU with SR
4) SR-TE
This blog gives an example of solution #1.

The configuration is straightforward:
1) Static label push via NHG
2) Controller via EOS SDK
3) BGP LU with SR
4) SR-TE
This blog gives an example of solution #1.

The configuration is straightforward:
- Instead of running a routing protocol between PE1 and PE2, a static route of remote destination (100.255.4.1/32 on PE1) is configured and pointing to NHG.
- The NHG defines:
- MPLS encapsulation
- Push a label of 900004
- The NH is 10.1.2.2 for out-interface and destination MAC.
- Obviously, 2 NHGs are needed to 2 way traffic.
- Not like the regular NHG setup, decap group is NOT needed.
- P1 and P2 have no idea of destination ip - 100.255.4.1, but use label to forward traffic
PE1#sh ip route 100.255.4.1
VRF: default
Codes: C - connected, S - static, K - kernel,
O - OSPF, IA - OSPF inter area, E1 - OSPF external type 1,
E2 - OSPF external type 2, N1 - OSPF NSSA external type 1,
N2 - OSPF NSSA external type2, B - BGP, B I - iBGP, B E - eBGP,
R - RIP, I L1 - IS-IS level 1, I L2 - IS-IS level 2,
O3 - OSPFv3, A B - BGP Aggregate, A O - OSPF Summary,
NG - Nexthop Group Static Route, V - VXLAN Control Service,
DH - DHCP client installed default route, M - Martian,
DP - Dynamic Policy Route, L - VRF Leaked
NG 100.255.4.1/32 [1/0] via sr-1-push-label-900004, Nexthop Group ID 1
The output of tcpdump on P2's et42/4 (the interface facing to P1) shows MPLS with the correct label in both directions.
23:10:17.713412 44:4c:a8:97:84:5f > 44:4c:a8:97:8c:51, ethertype MPLS unicast (0x8847), length 118: MPLS (label 900001, exp 0, [S], ttl 63)
(tos 0x0, ttl 64, id 6381, offset 0, flags [none], proto ICMP (1), length 100)
100.255.4.1 > 100.255.1.1: ICMP echo request, id 9258, seq 5, length 80
23:10:17.713473 44:4c:a8:97:8c:51 > 44:4c:a8:97:84:5f, ethertype MPLS unicast (0x8847), length 118: MPLS (label 900004, exp 0, [S], ttl 63)
(tos 0x0, ttl 64, id 2480, offset 0, flags [none], proto ICMP (1), length 100)
100.255.1.1 > 100.255.4.1: ICMP echo reply, id 9258, seq 5, length 80
Now you have the simplest, but completed ISIS segment-routing solution, control plane + data plane :-) In the real network, you can complete the puzzle by adding,
- Have a controller participate in the ISIS domain via the ISIS over GRE tunnel.
- As an ISIS neighbor, it can fetch the full ISIS LSDB to have a global view of the network including the segment.
- Then it can program the edge router vi CLI/capi to steer the traffic. Or use the EOS SDK for faster program speed (this is the solution #2)
Arista EOS Segment Routing (2) - MPLS Ping to verify SR data plane

With the same topology, to verify the SR data plane, we can use the command - "ping mpls" to have PE1 send a UDP packet with the correct label.
PE1#ping mpls segment-routing ip 4.4.4.4/32 repeat 1
LSP ping to Segment-Routing route 4.4.4.4/32
timeout is 5000ms, interval is 1000ms
Via 10.1.2.2, Ethernet2/4, label stack (top label first): [900004]
Reply from 10.3.4.4: seq=1, time=0.53ms, success: egress ok
--- Segment-Routing target fec 4.4.4.4/32 : lspping statistics ---
Via 10.1.2.2, Ethernet2/4, label stack (top label first): [900004]
1 packets transmitted, 1 received, 0% packet loss, time 150ms
1 received from 10.3.4.4, rtt min/max/avg 0.530/0.530/0.530 ms
Turning on tcpdump on P1, it shows the following packets:
P1#sh run | grep moni
monitor session sr source Ethernet54/4
monitor session sr destination Cpu
P1#bash tcpdump -nvvvi mirror1 udp or mpls
tcpdump: listening on mirror1, link-type EN10MB (Ethernet), capture size 262144 bytes
13:48:15.934459 44:4c:a8:97:77:21 > 44:4c:a8:97:8c:51, ethertype MPLS unicast (0x8847), length 98: MPLS (label 900004, exp 0, [S], ttl 255)
(tos 0x0, ttl 1, id 0, offset 0, flags [DF], proto UDP (17), length 80, options (RA))
10.1.2.1.36260 > 127.0.0.1.lsp-ping:
LSP-PINGv1, msg-type: MPLS Echo Request (1), length: 48
reply-mode: Reply via an IPv4/IPv6 UDP packet (2)
Return Code: No return code or return code contained in the Error Code TLV (0)
Return Subcode: (0)
Sender Handle: 0x00000000, Sequence: 1
Sender Timestamp: -16:-39:-45.54962696 Receiver Timestamp: no timestamp
Target FEC Stack TLV (1), length: 12
Unknown subTLV (31744), length: 6
0x0000: 0404 0404 2002
0x0000: 7c00 0006 0404 0404 2002 0000
13:48:15.934737 44:4c:a8:97:8c:51 > 44:4c:a8:97:77:21, ethertype IPv4 (0x0800), length 74: (tos 0x0, ttl 62, id 36448, offset 0, flags [DF], proto UDP (17), length 60)
10.3.4.4.lsp-ping > 10.1.2.1.36260:
LSP-PINGv1, msg-type: MPLS Echo Reply (2), length: 32
reply-mode: Reply via an IPv4/IPv6 UDP packet (2)
Return Code: Replying router is an egress for the FEC at stack depth 1 (3)
Return Subcode: (1)
Sender Handle: 0x00000000, Sequence: 1
Sender Timestamp: -16:-39:-45.54962696 Receiver Timestamp: -16:-40:-1.401478080
From the above packet capture,
- The icmp echo request is encap'ed in MPLS packet with label 90004 as expected.
- The dest address of inner ip is 127.0.0.1. With destination address on network 127, the packet can't be routed if LSP is broken before the final destination and the packet is decap'ed prematurely.
- The icmp echo reply is just a native ipv4 packet.
Arista EOS Segment Routing (1) - Simplest Setup/Configuration
Here is the simplest SR setup,
1) Only IPv4, only ipv4 node-segment;
2) No IPv6, no ISIS multi-topology

From the above configuration, we can observe:
To verify the SR setup, you can use the following CLI commands:
1) Only IPv4, only ipv4 node-segment;
2) No IPv6, no ISIS multi-topology

From the above configuration, we can observe:
- The basic ISIS-SR configuration is quite simple:
- enable "segment-routing mpls" under router isis to attach SR info to ISIS LSA;
- Specify the loopback0 interface with a globally unique node-segment index.
- ISIS-SR calculates the node-segment label = mpls label range base + index, so the routers in whole domain use the same label. This is an important characteristic of SR, for anycast.
To verify the SR setup, you can use the following CLI commands:
- show mpls label ranges
- show isis segment-routing
- show isis database PE2.00-00 detail !PE2.00-00 is id
- show mpls lfib route
- show mpls segment-routing bindings
- show platform jericho mpls route
Detailed output of PE1:
PE1#show mpls label ranges
Start End Size Usage
------------------------------------------------
0 15 16 reserved
16 99999 99984 static mpls
100000 116383 16384 ldp (dynamic)
116384 132767 16384 pseudowire (dynamic)
132768 149151 16384 bgp (dynamic)
149152 165535 16384 isis (dynamic)
165536 362143 196608 free (dynamic)
362144 899999 537856 unassigned
900000 965535 65536 isis-sr <<< default ISIS-SR range
900000 965535 65536 bgp-sr
965536 1031071 65536 srlb
1031072 1036287 5216 unassigned
1036288 1048575 12288 l2evpn
PE1#show isis segment-routing
System ID: PE1 Instance: sr
SR supported Data-plane: MPLS SR Router ID: 1.1.1.1
SR Global Block( SRGB ): Base: 900000 Size: 65536
Adj-SID allocation mode: SR-adjacencies
Adj-SID allocation pool: Base: 149152 Size: 16384
All Prefix Segments have : P:0 E:0 V:0 L:0
IS-IS Reachability Algorithm : SPF (0)
Number of IS-IS segment routing capable peers: 3
Self-Originated Segment Statistics:
Node-Segments : 1
Prefix-Segments : 0
Proxy-Node-Segments : 0
Adjacency Segments : 1
PE1#show isis database PE2.00-00 detail
IS-IS Instance: sr VRF: default
IS-IS Level 2 Link State Database
LSPID Seq Num Cksum Life IS Flags
PE2.00-00 12 57553 1049 L2 <>
NLPID: 0xCC(IPv4)
Hostname: PE2
Area address: 49.0001
Interface address: 4.4.4.4
Interface address: 10.3.4.4
IS Neighbor : P2.11 Metric: 10
LAN-Adj-sid: 100000 flags: [ L V ] weight: 0 system ID: 0000.0000.3333
Reachability : 4.4.4.4/32 Metric: 10 Type: 1 Up
SR Prefix-SID: 4 Flags: [ N ] Algorithm: 0
Reachability : 10.3.4.0/24 Metric: 10 Type: 1 Up
Router Capabilities: Router Id: 4.4.4.4 Flags: [ ]
SR Local Block:
SRLB Base: 965536 Range: 65536
Area leader priority: 250 algorithm: 0
SR Capability: Flags: [ I ]
SRGB Base: 900000 Range: 65536
PE1#show mpls lfib route
MPLS forwarding table (Label [metric] Vias) - 4 routes
MPLS next-hop resolution allow default route: False
Via Type Codes:
M - MPLS via, P - Pseudowire via,
I - IP lookup via, V - VLAN via,
VA - EVPN VLAN aware via, ES - EVPN ethernet segment via,
VF - EVPN VLAN flood via, AF - EVPN VLAN aware flood via,
NG - Nexthop group via
Source Codes:
G - gRIBI, S - Static MPLS route,
B2 - BGP L2 EVPN, B3 - BGP L3 VPN,
R - RSVP, LP - LDP pseudowire,
L - LDP, M - MLDP,
IP - IS-IS SR prefix segment, IA - IS-IS SR adjacency segment,
IL - IS-IS SR segment to LDP, LI - LDP to IS-IS SR segment,
BL - BGP LU, ST - SR TE policy,
DE - Debug LFIB
IA 149152 [1]
via M, 10.1.2.2, pop
payload autoDecide, ttlMode uniform, apply egress-acl
interface Ethernet2/4
IP 900002 [1], 2.2.2.2/32
via M, 10.1.2.2, pop
payload autoDecide, ttlMode uniform, apply egress-acl
interface Ethernet2/4
IP 900003 [1], 3.3.3.3/32
via M, 10.1.2.2, forward
payload autoDecide, ttlMode uniform, apply egress-acl
interface Ethernet2/4
IP 900004 [1], 4.4.4.4/32
via M, 10.1.2.2, forward
payload autoDecide, ttlMode uniform, apply egress-acl
interface Ethernet2/4
PE1#show mpls segment-routing bindings
1.1.1.1/32
Local binding: Label: imp-null
Remote binding: Peer ID: 0000.0000.2222, Label: 900001
2.2.2.2/32
Local binding: Label: 900002
Remote binding: Peer ID: 0000.0000.2222, Label: imp-null
3.3.3.3/32
Local binding: Label: 900003
Remote binding: Peer ID: 0000.0000.2222, Label: 900003
4.4.4.4/32
Local binding: Label: 900004
Remote binding: Peer ID: 0000.0000.2222, Label: 900004
PE1#show platform jericho mpls route
D - ECMP is divergent across switching chips
---------------------------------------------------------------------------------------------
| Mpls Table |
|---------------------------------------------------------------------------------------------|
| label | Destination | VID | MAC Code | egress action | FEC |olif | arp | remark |
|---------------------------------------------------------------------------------------------|
|149152 |Et2/4 |1027 | 44:4c:a8:97:8c:51 | PopE pipe auto|32773 |8200 |8 | 0 |
Egress Action Codes:
M - Mpls Tunnel, G - GRE Tunnel, MoG - Mpls-over-GRE Tunnel
ECMP Codes:
D - ECMP is divergent across switching chips
-----------------------------------------------------------------------------------------------
| Mpls Table
|-----------------------------------------------------------------------------------------------
| | Label | | | | | ECMP| FEC | Egress
| Label | Action | Destination | VID |Outlif | MAC / CPU Code |Index| Index| Action
|-----------------------------------------------------------------------------------------------
|900002 |Pop | Et2/4 |1027 |8188 | 44:4c:a8:97:8c:51 | - |32771 | -
|900003 |Forward | Et2/4 |1027 |8188 | 44:4c:a8:97:8c:51 | - |32771 | -
|900004 |Forward | Et2/4 |1027 |8188 | 44:4c:a8:97:8c:51 | - |32771 | -
Subscribe to:
Posts (Atom)