• MTU and PMTUD on L2VPNs

    I recently ran into an interesting issue at work today. One of our customers were having issues with a site in Gothenburg. They were using L2VPNs as circuits between their central site and the remote sites. Across this L2VPN they are running MPLS MP-eBGP peering using inter AS option 2b to allow multiplexing of different…

  • MPLS basics – tips & trix

    This will be a living document, for troubleshooting and tracing MPLS traffic. The idea is for me and others to be able to reference this post for basic MPLS troubleshooting. < MPLS purpose and MPLS packet headers The original purpose of MPLS was to allow for faster packet routing through a provider network. This is…

  • DC@Home 3 – Configuring the MPLS WAN

    DC@Home 3 – Configuring the MPLS WAN

    The past two weeks I have been working hard at getting the new MPLS WAN up and running. The idea is to build a scaleable solution, even though my MPLS cloud never will grow large enough to require the scalability. The plan is also to allow my colleagues to join the MPLS WAN, which means…

  • Route-maps for VPNv4 filtering

    In my series DC@Home I recently ran into the issue of how to filter which VRF:s should be allowed to propagate from the provider core, out to the customer sites. It turns our it is quite simple and can be done in a manner similar to prefix-lists for regular BGP peering. For VPNv4 multiplexing the…

  • DC@Home 2 – Setting up the core and underlay

    This weekend I started setting up the core of the provider network. This mainly consisted of configuring MPLS and MP-BGP to run L3VPNs between provider nodes. I also setup a secondary internet connection, which will primarily be used to run active-active tunnels from sites into the MPLS core. One big goal of this new setup…

  • Filtering redistribution through route-maps

    I recently ran into a case where a customer wanted to be able to monitor their primary and secondary WAN-links in order to determine if they are up. We owned the primary WAN-link, which served the primary router at the site. The secondary link was a DIA running DMVPN across the interwebz. In order for…