Index

Numbers

802.1w. See Rapid STP (Spanning Tree Protocol)

A

AAA servers, 176

ABR (Area Border Router), 467

access control lists

MAC address access lists, 904906

verifying, 9

access lists, filtering with, 704714

access list configuration, 712713

BGP peering, 704708

outbound prefixes, filtering, 713714

prefix-list and distribute-list configuration, 709710

R2 configuration, 708709

R3 configuration, 711712

ACFC (Address and Control Field Compression), 179

ACLs. See access control lists

acquiring IPv6 addresses

DHCP client/server configuration, 746751

DHCP prefix delegation, 755763

modified EUI-64 addressing, 737739

neighbor discovery, 739743

overview of, 737

R2 configuration, 751754

R5 configuration, 754755

SLAAC (stateless address auto-configuration), 743746

Address and Control Field Compression (ACFC), 179

Address field (PPP), 170171

addresses (IP), 36

acquiring

DHCP client/server configuration, 746751

DHCP prefix delegation, 755763

modified EUI-64 addressing, 737739

neighbor discovery, 739743

overview of, 737

R2 configuration, 751754

R5 configuration, 754755

SLAAC (stateless address auto-configuration), 743746

assigning, 187190

configuration, 387388

addresses (MAC), 36, 904906

MAC address access lists, 904906

match destination and source address MAC

overview of, 885

R2 configuration to classify and mark IP routed traffic, 882885

RIPv2 configuration, 881

address-family command, 312

adjacency

neighbor adjacencies, 635641

OSPF (Open Shortest Path First), 391397

advertising

conditional label advertising, 10581064

loopback interfaces, 501502

networks, 381

DMVPN configuration, 389391

IP addressing, 387388

OSPF adjacency, 391397

OSPF summarization and, 468469, 472475

R1 and R4 connections and loopback interfaces, 385387

R4, R5, and R6 connections, 381385

static default routes, 388389

of prefixes originating in own AS, preventing, 721723

af-interface default command, 324

always keyword, 824

announcements (RP), filtering, 10041005

application-specific integrated circuits (ASICs), 839

area 2 nssa command, 534

Area Border Router (ABR), 467

area range command, 473, 783

ARP table, showing, 9

AS-path attribute (BGP), 679686

ASBR (Autonomous System Boundary Router), 467

ASICs (application-specific integrated circuits), 839

attributes

Cluster-ID, 642

community, 667679

BGP peering, 668671

R1 configuration, 672673

R2 configuration, 677679

R3 configuration, 675677

R5 configuration, 674675

multi-exit discriminator, 695703

Originator-ID, 642

AS-path, 679686

weight, 686695

AUTH-ACK message, 190, 194

Authenticate-Request message, 177

authentication

CHAP (Challenge-Handshake Authentication Protocol)

messages, 198200

one-way authentication, 198201

overview of, 175179

R4, configuring to authenticate R3, 202207

two-way authentication, 201202

EAP (Extensible Authentication Protocol), 175176, 216218

EIGRP (Enhanced Interior Gateway Routing Protocol)

EIGRP AS 100 configuration, 360361

HMAC-SHA-256, 362363, 833834

MD5, 361, 831833

router configuration, 359360

topology, 359

MS-CHAP (Microsoft CHAP), 175176, 215218

OSPF (Open Shortest Path First), 431

demand circuits, 456457

MD5 authentication, 440462

plaintext authentication, 433439

router interfaces in Area 0, 431433

PAP (Password Authentication Protocol)

one-way authentication, 190192

overview of, 175179

two-way authentication, 192194

PPP (Point-to-Point Protocol), 175177

Authentication Phase (PPP), 175177

AUTH-REQ message, 190, 194

autoconfiguration (LDP), enabling, 10681071

Autonomous System Boundary Router (ASBR), 467

autonomous-system command, 1108

Auto-RP, 993

Lo0 interface of R1, 10061010

OSPF Area 0 configuration, 994

PIM sparse-dense-mode configuration, 994997

primary and backup RP configuration, 9971003

R3 configuration, 10051006

RP announcements, filtering on R6, 10041005

B

backdoor (BGP), 650667

configuration, 654658

IP address, removing from F0/0 interfaces, 658

loopback1 interfaces, advertising, 653

peer session configuration, 650651

policies for R1 configuration, 659667

R1, R2, and R3 configuration, 651

RIPv2 and EIGRP 100 configuration, 651652

backdoor links and OSPF, 1123

CE (customer edge) router configuration, 11361141

F0/1 interface of R1 and the G0/1 interface of R7, 11411147

LDP configuration between core routers, 11281132

MP-BGP AS 100 configuration between R2 and R6, 11321133

OSPF configuration on core MPLS routers, 11231128

RDs (route distinguishers), 11341136

RTs (route targets), 11341136

topology, 11231125

VRF (Virtual Routing and Forwarding), 11341136

backup RP (rendezvous point) configuration, 9971003, 10171022

bandwidth usage, configuring (EIGRP), 324325, 830

bandwidth-percent command, 324

bba-group, 207

BGP (Border Gateway Protocol), 635

community attribute, 667679

BGP peering, 668671

R1 configuration, 672673

R2 configuration, 677679

R3 configuration, 675677

R5 configuration, 674675

conditional advertisement and BGP backdoor, 650667

backdoor configuration, 654658

IP address, removing from F0/0 interfaces, 658

loopback1 interfaces, advertising, 653

peer session configuration, 650651

policies for R1 configuration, 659667

R1, R2, and R3 configuration, 651

RIPv2 and EIGRP 100 configuration, 651652

confederation, 731736

filtering with access lists and prefix lists, 704714

access list configuration, 712713

BGP peering, 704708

outbound prefixes, filtering, 713714

prefix-list and distribute-list configuration, 709710

R2 configuration, 708709

R3 configuration, 711712

multi-exit discriminator attribute, 695703

neighbor adjacencies, establishing, 635641

AS-path attribute, 679686

regular expressions, 714731

advertising of prefixes originating in own AS, preventing, 721723

BGP peering, 715717

prefixes from directly connected neighbors, blocking, 725726

prefixes originating in AS 200, blocking, 723725

prefixes originating in AS 300, blocking, 727728

prefixes originating in AS 300, filtering, 717719

prefixes with AS 300 in path list, filtering, 719721

prefixes with prepended AS numbers, blocking, 728731

router reflectors, 642649

in VPN, 11481154

weight attribute, 686695

binary conversion, 279

Bootstrap Router. See BSR (Bootstrap Router)

boundary ports (MST), 94

BPDU (bridge protocol data unit)

BPDU Guard, 128134

filtering

F0/21 interface configuration, 139142

forwarding loops, 142146

overview of, 135136

policies, 146148

router and switch configuration, 136139

bridge-group 1 command, 132

Broad Band Aggregation, 207

broadcast keyword, 225

broadcast networks (OSPF), 397410

BSR (Bootstrap Router), 1013

Lo0 interface of R1, 10221023

OSPF Area 0 configuration, 10131014

PIM sparse mode configuration, 10141017

ping command, 10221023

primary and backup RP configuration, 10171022

C

candidate RPs (rendezvous points), 997998

Candidate-BSRs, 1019

CCP (Compression Control Protocol), 180

CDP (Cisco Discovery Protocol), 11

CE (customer edge) routers

BGP routing in VPN, 11481154

OSPF (Open Shortest Path First), 11361141

CEF (Cisco Express Forwarding), 899

Challenge packet (CHAP), 199

Challenge-Handshake Authentication Protocol. See CHAP (Challenge-Handshake Authentication Protocol)

CHAP (Challenge-Handshake Authentication Protocol), 198200

one-way authentication, 198201

overview of, 175179

R4, configuring to authenticate R3, 202207

two-way authentication, 201202

Cisco Discovery Protocol. See CDP (Cisco Discovery Protocol)

Cisco Lab Builder, 5

Class A networks

filtering through IP prefix lists, 269272

identifying, 271

Class B networks

filtering through IP prefix lists, 272275

identifying, 274

Class C networks

filtering through IP prefix lists, 275278

identifying, 276

class of service. See COS (class of service)

class-based policing, 898

F0/0 interface on R2, configuring, 903904

HTTP, FTP, and ICMP traffic, 906907

MAC address access lists, 904906

S1/2 interface on R1, configuring, 899902

class-based shaping, 907910

classic mode (EIGRP), 337338

clear ip route command, 608, 616

clients, DHCP, 746751

Cluster-ID attribute, 642

Code-Reject message, 175

commands

address-family, 312

af-interface default, 324

area 2 nssa, 534

area range, 473, 783

autonomous-system, 1108

bandwidth-percent, 324

bridge-group 1, 132

clear ip route, 608, 616

crypto ipsec transform-set, 921

debug ip igmp, 968, 973974

debug ip ospf lsa-generation, 631

debug ip pim auto-rp, 999

debug ip rip, 631

debug ip route, 574575

debug ip routing, 578, 631

debug ipv6 dhcp, 748, 754

debug nhrp cache, 248

debug nhrp packet, 248

debug ppp authentication, 190, 194, 200, 202

debug ppp negotiation, 183

default-metric, 604, 626

discard-route external 255, 585

distance, 581

distribute-list OUT, 494

distribute-list prefix-list, 836

eigrp stub, 378379

eigrp stub connected, 373374

eigrp stub receive-only, 377378

eigrp stub redistributed, 376377

eigrp stub static, 375376

eigrp stub summary, 375

frame-relay map, 225

igmp immediate-leave group-list 1, 969

igmp join-group, 969

import, 1092

interface-configuration, 568

ip address negotiated, 187

ip helper-address, 212, 752

ip igmp join-group, 963, 968

ip igmp limit, 973

ip igmp querier-timeout, 962

ip igmp query-interval, 962, 974

ip igmp query-max-response-time, 962, 976

ip igmp static-group, 963

ip local pool, 212

ip multicast boundary, 1004

ip nhrp map, 248

ip nhrp network-id, 265

ip nhrp nhs, 248, 249

ip nhrp redirect, 255, 266

ip nhrp shortcut, 255, 266, 310

ip ospf demand-circuit, 816

ip ospf network point-to-point, 770

ip pim send-rp-announce, 999

ip routing, 221, 230, 238, 245, 253

ip summary-address, 257, 262

ip summary-address eigrp 100 0.0.0.0 0.0.0.0, 304

IP vrf, 1091

ipv6 address, 759

ipv6 address autoconfig default, 748, 750

ipv6 address dhcp, 750

ipv6 bandwidth-percent eigrp, 830

ipv6 dhcp client pd, 758

ipv6 enable, 748

ipv6 nd managed-config-flag, 747

ipv6 nd other-config-flag, 747

ipv6 nd prefix default no-advertise, 751

ipv6 router ospf, 765

leak-map, 355

match ip route-source, 598

match source-address mac, 904

metric rib-scale, 340

mls qos, 853

mls qos cos 2, 846, 849

mls qos cos override, 846, 847

mls qos trust cos, 846, 849

mls qos trust dscp, 854

mpls ip, 1033

mpls label protocol, 1033

mpls label protocol ldp, 1033

mpls label range 16 1048575, 1048

mpls ldp advertise-labels, 1058

mpls ldp router-id, 1033

no auto-summary, 312

no discard-route internal, 585

no mpls ip propagate-ttl local, 1066

no peer neighbor-route, 185

peer default ip address 23.1.1.3 interface, 187

peer default ip address pool, 212

ping, 10221023

ppp authentication chap, 198, 203

ppp authentication pap, 190

ppp chap hostname, 199, 203

ppp chap password, 177

ppp pap sent-username, 191

redistribute, 572573

redistribute connected, 570, 579

route-map tst permit 90, 570

router ospf, 765

router ospfv3, 765

Rx(config)#ip multicast-routing, 959

sh interface, 41, 48

sh mac address-table dynamic vlan 21, 48

sh mac-address-table, 41

sh spanning-tree, 37

sh spanning-tree vlan 12 interface f0/19 detail, 44

sh version | inc Base, 37

show cdp neighbors, 20

show ip bgp peer-group TST, 641

show ip eigrp topology 8.8.8.0/24, 341

show ip route | include 3.3.3.0, 629

show ipv6 ospf database, 795

show ipv6 route, 750

show ppp all, 193

show ppp interface, 195

spanning-tree portfast, 75

summary-address, 783

summary-prefix, 783

traceroute, 613614

traceroute 3.3.3.3, 263

username R4 password Cisco, 203

VRF definition, 1091

community attribute (BGP), 667679

BGP peering, 668671

R1 configuration, 672673

R2 configuration, 677679

R3 configuration, 675677

R5 configuration, 674675

composite metrics, filtering, 602604

compression (PPP), 179180

Compression Control Protocol (CCP), 180

conditional advertisement, 650667

backdoor configuration, 654658

IP address, removing from F0/0 interfaces, 658

loopback1 interfaces, advertising, 653

peer session configuration, 650651

policies for R1 configuration, 659667

R1, R2, and R3 configuration, 651

RIPv2 and EIGRP 100 configuration, 651652

conditional label advertising, 10581064

CONFACK (Configure-Ack) message, 172175

confederation (BGP), 731736

configuration

advertising networks, 381

DMVPN, 389391

IP addressing, 387388

OSPF adjacency, 391397

R1 and R4 connections and loopback interfaces, 385387

R4, R5, and R6 connections, 381385

static default routes, 388389

authentication

EIGRP AS 100, 360361

HMAC-SHA-256, 362363

MD5, 361

router configuration, 359360

topology, 359

backdoor links and OSPF, 1123

CE (customer edge) router, 11361141

F0/1 interface of R1 and the G0/1 interface of R7, 11411147

LDP configuration between core routers, 11281132

MP-BGP AS 100 configuration between R2 and R6, 11321133

OSPF configuration on core MPLS routers, 11231128

RDs (route distinguishers), 11341136

RTs (route targets), 11341136

topology, 11231125

VRF (Virtual Routing and Forwarding), 11341136

BGP

BGP routing in VPN, 11481154

community attribute, 667679

conditional advertisement and BGP backdoor, 650667

confederation, 731736

filtering with access lists and prefix lists, 704714

multi-exit discriminator attribute, 695703

neighbor adjacencies, 635641

AS-path attribute, 679686

regular expressions, 714731

router reflectors, 642649

weight attribute, 686695

BPDU filtering

F0/21 interface, 139142

forwarding loops, 142146

overview of, 135136

policies, 146148

router and switch configuration, 136139

BPDU Guard, 128134

BSR, 1013

Lo0 interface of R1, 10221023

OSPF Area 0, 10131014

PIM sparse mode, 10141017

ping command, 10221023

primary and backup RPs, 10171022

class-based policing

F0/0 interface on R2, 903904

HTTP, FTP, and ICMP traffic, 906907

MAC address access lists, 904906

overview of, 898

S1/2 interface on R1, 899902

class-based shaping, 907910

COS-DSCP mapping

F0/1 interface on R2, 866

F0/1 interface on SW1, 866

F0/19 interface SW2, 866869

default route injection, 363368

DMVPN Phase 1

dynamic mapping, 229236

static mapping, 219229

DMVPN Phase 2

dynamic mapping, 244251

static mapping, 236244

DMVPN Phase 3

hub and spoke configuration, 255266

interface and router configuration, 253255

overview of, 251252

DMVPN tunnel protection, 946

F0/0 and loopback0 interfaces of R1, R2, and R3, 947948

hub and spoke configuration, 948952

IP routing, enabling, 946947

traffic protection, 952958

DSCP-COS mapping

overview of, 860

R1 configuration, 862

R2 configuration, 861

SW2 configuration, 862865

DSCP-Mutation

DSCP rewrites, enabling, 857860

DSCP-mutation map, 855857

mls qos, enabling on SW2, 853854

mls qos trust dscp, 854855

MQC on R1, configuring to mark egress traffic with DSCP value of 1, 851852

overview of, 851

dynamic RP learning and Auto-RP, 993

Lo0 interface of R1, 10061010

OSPF Area 0, 994

PIM sparse-dense-mode, 994997

primary and backup RPs, 9971003

R3 configuration, 10051006

RP announcements, filtering on R6, 10041005

EIGRP basic configuration

configuring for future DMVPN spokes, 304311

DMVPN Phase 1, 289292

DMVPN Phase 2, 298301

EIGRP AS 100, 293297

loopback interfaces, 301304

static default routes, 287289

EIGRP metrics

classic mode, 337338

EIGRP AS 100, 334335

FD set to Infinity, resolving, 343348

mutual redistribution between RIPv2 and EIGRP, 335337

named mode, 338341

topology, 333

Wide Metric support, 341342

EIGRP named mode, 311

bandwidth usage, configuring, 324325

EIGRP 200, 318319

EIGRP AS 100, 316317

fixed metric for the EIGRP summary route, 327328

hello intervals, 323324

number of received prefixes, limiting, 329333

OSPF, 319323

policy for configuring, 311315

summarization, 325327

unicast, 317318

EIGRP routing in VPN, 11071113

EIGRP stub

EIGRP AS 100, 368370

eigrp stub connected option, 373374

eigrp stub option, 378379

eigrp stub receive-only option, 377378

eigrp stub redistributed option, 376377

eigrp stub static option, 375376

eigrp stub summary option, 375

redistribution, 372373

static routes, 370372

summarization, 370

topology, 368

EIGRP summarization

loopback interfaces for R1, 349350

loopback interfaces for R2, 350

loopback interfaces for R3, 351

loopback interfaces for R4, 351353

R1 configuration, 358359

R2 configuration, 353356

R3 configuration, 357358

R4 configuration, 356357

topology, 349

EIGRPv6

bandwidth usage, 830

EIGRPv6 AS 100, 819820

external routes, filtering, 834837

Hello interval and Hold timer, 825826

HMAC-SHA-256 authentication, 833834

loopback1 interface on R1, 830831

loopback1 interface on R2, 826829

MD5 authentication, 831833

OSPFv3 Area 0, 818819

overview of, 817818

on R1, R2, R3, and R4, 821824

redistributing OSPFv3 into, 824825

hostnames, 20

IGMP, 959

F0/0 and F0/1 interface configuration on R1 and R2, 959962

F0/0 interface configuration on R3 and R4, 963

F0/1 interface configuration on R5 and R6, 964

G0/1 interface on R7, 965

hosts connected to F0/1 on R1, restricting, 965967

hosts connected to F0/1 on R2, stopping multicast traffic with, 967969

mroute states, limiting, 971974

query max response time, 976977

query messages, sending, 969971

querying router and the query interval, 974976

input-interface and match NOT

f0/0 interface on R4, configuring, 873876

overview of, 873

s1/1 interface on R2, configuring, 877881

interfaces, verifying, 910

IP prefix lists, 267

allowing only unsubnetted Class B networks, 272275

allowing only unsubnetted Class C networks, 275278

allowing unsubnetted Class A networks, plus Class B and C networks, 269272

basic configuration, 267269

configuring loopback interfaces, 277278, 285

denying certain prefixes, 278281

filtering existing and future host routes, 286

filtering networks with certain prefix lengths, 283285

injecting default route in EIGRP routing domain, 281283

IP-precedence-DSCP mapping, 870873

IPv6 addresses

DHCP server configuration, 746751

SLAAC (stateless address auto-configuration), 743746

LDP, 1026

conditional label advertising, 10581064

control plane for the 7.7.7.0/24 prefix, 10511057

hello intervals, 10421044

hold timer, 10421044

labels, 10481051

LDP autoconfiguration, enabling, 10681071

LDP router ID (RID), 1033

Loopback1 interface of R1, 10441048

LSRs (label switch routers), 10331037

MLPS structure, hiding, 10651067

MPLS forwarding, 1034

neighbor discovery, 10371042

OSPF Area 0, 10291032

serial connection between R3 and R5, 10721073

session keepalives, 1044

session protection, 10731077

topology, 10261029

TTL propagation, testing, 10641065

LSA Type 4 and FA suppression, 539548

LSAs in OSPFv3, 790

Intra-Area Prefix LSAs, 799800

Link LSAs, 795799

Network LSAs, 795

OSPF Area 0 on DMVPN network, 813816

OSPF Area 0 on F0/1 and loopback0 interfaces of R1, R2, and R4, 790793

OSPF Area 13 on S1/3 and loopback13 interfaces of R3, 800809

OSPF Area 37 on F0/0, 809813

Router LSAs, 793795

match destination and source address MAC

overview of, 881

R2 configuration to classify and mark IP routed traffic, 882885

RIPv2 configuration, 881

match IP DSCP/Precedence vs. match DSCP, 885893

match protocol HTTP URL, MIME, and Host, 893898

MLS QoS

f0/1 interface on SW1, configuring to mark ingress traffic with COS marking of 2, 844850

mls qos, enabling on SW1, 842844

overview of, 840

R1, configuring to send all traffic with COS marking of 1, 840842

MST, 9394

boundary ports, 94

configuring with policies, 99106

edge ports, 94

IST (Internal Spanning Tree), 95

MSTP (Multiple Instance Spanning Tree Protocol), 96

port configuration, 96

regions, 94

switch hostname configuration, 96

trunking mode, 97

VLAN configuration, 9799

OSPF authentication, 431

demand circuits, 456457

MD5 authentication, 440462

plaintext authentication, 433439

router interfaces in Area 0, 431433

OSPF broadcast networks, 397410

OSPF filtering, 476

loopback interface advertisement, 501502

loopback interface redistribution, 493

loopback interfaces of R1 and R2, 481482

LSA flooding, preventing, 502504

network filtering in Area 0, 486488

network filtering in Area 0 and Area 2, 488490

network filtering in Area 2, 484486

network filtering on all routers except R1, 490493

network filtering on all routers except R5, 494495

network filtering on R1’s routing table, 496

network filtering on R2, 482483

R1 and R2’s directly connected interfaces, 476478

removing, 497501

serial connection between R3 and R4, 478479

serial connection between R4 and R5, 480481

OSPF non-broadcast networks, 411421

OSPF point-to-multipoint networks, 425430

OSPF point-to-point networks, 421424

OSPF routing in VPN, 11131122

OSPF stub, totally stubby, and NSSA areas, 517

default route injection, 533536

loopback interfaces on R5, 532533

loopback30 interface on R3, 522523

NSSA configuration, 528532

R1’s directly connected interfaces, 518

R2’s directly connected interfaces, 518519

R3’s directly connected interfaces, 519520

R4’s directly connected interfaces, 521523

stub area configuration, 523526

totally stubby area configuration, 526528

OSPF suboptimal paths, 549555

OSPF summarization

advertising networks, 468469, 472475

discard routes, 471472

external route summarization, 467468

network summarization, 470

R1 configuration, 465466

R2 configuration, 464465

R3 configuration, 463464

R4 configuration, 463

OSPFv3, 763771

physical-to-logical topology

desired topology, 1819

hostname configuration, 20

port shutdown, 20

VLAN 12, 2324

VLAN 13, 2022

VLAN 28, 2425

VLAN 34, 2729

VLAN 45, 2930

VLAN 56, 3033

VLAN 789, 2627

PPP

DHCP server, 212215

EAP authentication, 216218

interfaces, 182186

IP address assignment, 187190

loopback0 interface, pinging, 186187

MLPPP (Multilink PPP), 216218

MPPE protocol and MS-CHAP authentication, 215218

one-way CHAP authentication, 198201

one-way PAP authentication, 190192

PPPoE (PPP over Ethernet), 207212

R1 and R2 serial interfaces, 215218

R4, configuring to authenticate R3, 202207

two-way CHAP authentication, 201202

two-way PAP authentication, 192194

Rapid STP

lab setup, 7577

link type, 8385

operational enhancements of, 74

overview of, 73

port roles, 74

port states, 74

rapid convergence mechanisms, 75, 7880

rapid convergence process, demonstrating, 8083

SW2, enabling for RSTP mode, 8992

switch operation, 8589

redistribution (basic)

composite metrics, filtering, 602604

eigrp 100 redistribution into ospf 1, 592593

EIGRP AS 100, 578580, 589590

link between R1 and R3, 567569

loopback interfaces on R2, 583

loopback interfaces on R2/R3, 575578

loopback interfaces on R3, 569

network 4.4.4.0 /24, filtering on R2, 596597

ospf 1 and eigrp 100 redistribution into ospf 36, 599602

ospf 1 redistribution into eigrp 100, 595596

OSPF area 0, 587589, 591

overview of, 567

R1/R2, 571575

RIP redistribution into EIGRP, 580583

RIPv2 redistribution into OSPF, 584586

route maps, 570571

routes originated by R4, filtering with R5, 597599

routes tag of 111, configuring R4 to filter, 593594, 595

RFC 3101 and RFC 1587, 556566

RIPv2 and EIGRP redistribution

allowing only required routes to be redistributed, 617619

control plane mechanism, 614615

EIGRP AS 100 configuration, 607608

filtering RIP routes from being advertised out of F0/1 interface, 615617

filtering tagged routes, 619622

loopback0 interface, 607

mutual redistribution between RIPv2 and EIGRP, 608614

overview of, 604605

RIPv2 configuration on R2, R3, and R4, 605606

summarization, 622625

RIPv2 and OSPF redistribution

mutual redistribution on R1, 629634

OSPF area 0 configuration on f0/0 interface, 626

overview of, 625626

RIPv2 configuration on R1, R2, and R3, 626627

update, invalidation, and flush timer values, 628629

RIPv2 routing in VPN, 1078

configuration between R1 and PE-2, 10961107

configuration between R7 and PE-6, 10961107

LDP configuration on core MPLS routers, 10841088

MP-BGP AS 100 configuration on R2 to R6, 10881090

OSPF configuration on core MPLS routers, 10811083

RDs (route distinguishers), 10911095

RTs (route targets), 10911095

topology, 10791081

VRF (Virtual Routing and Forwarding), 10911095

site-to-site IPSec VPN, 911

GRE/IP with Transport mode, 940942

GRE/IPSec with Tunnel mode, 937940

IKE configuration, 913917

IKE Phase 1 message 1, 917

IKE Phase 1 message 2, 918919

IKE Phase 1 message 3, 919

IKE Phase 1 message 4, 919920

IKE Phase 1 message 5, 920

IKE Phase 1 message 6, 920921

IKE Phase 2 message 1, 921925

ISAKMP, 912

and NAT, 925930

non-scalable configuration, 930937

OAKLEY, 912913

policy guidelines, 912

S-VTI, 942946

Spanning Tree Backbone Fast, 148154

Spanning Tree Loop Guard, 162167

Spanning Tree Portfast, 106115

Spanning Tree Root Guard, 154162

static RP, 977

PIM sparse mode, 983985

R2 and R3 configuration, 986991

S1/4 interface on R5, 991993

topology, 981983

STP

designated ports, moving, 4345

initial configuration, 3641

overview of, 50

policy, 5964

root bridge, 5659, 6567

root primary macro, 4648

spanning-tree cost on port in VLAN 12, raising, 4142

spanning-tree port ID, raising, 4849

switch hostnames, 5152

switches, 5455

trunk port, 5254

VLAN 100, 200, 300, and 400 creation, 5556

VLAN 500 creation, 6770

VLAN 600 creation, 7073

summarization of internal/external networks

discard routes, 786789

external route summarization, 782786

loopback interface summarization, 778782

OSPFv3 configuration, 771778

overview of, 771

UplinkFast, 115128

virtual links and GRE tunnels

GRE tunnel configuration, 513516

OSPF configuration, 506509

overview of, 504506

virtual link configuration, 509513

VLANs, 12

Configure-Ack (CONFACK) message, 172175

Configure-Nak (CONFNAK) message, 173175

Configure-Reject (CONFREJ) message, 174175

Configure-Request (CONFREQ) message, 172175

CONFNAK (Configure-Nak) message, 173175

CONFREJ (Configure-Reject) message, 174175

CONFREQ (Configure-Request) message, 172175

contiguous identical bits, 279280

Control field (PPP), 170171

control plane, 171

authentication, 175177

examining, 10511057

LCP (Link Control Protocol), 171175

NCPs (Network Control Protocols), 177179

COS (class of service)

COS-DSCP mapping

R2 F0/1 interface, configuring, 866

SW1 F0/1 interface, configuring, 866

SW2 F0/19 interface, configuring, 866869

DSCP-COS mapping

overview of, 860

R1 configuration, 862

R2 configuration, 861

SW2 configuration, 862865

CRC (cyclic redundancy check), 171

crypto ipsec transform-set command, 921

customer edge (CE) routers

BGP routing in VPN, 11481154

OSPF (Open Shortest Path First), 11361141

cyclic redundancy check (CRC), 171

D

DAD (Duplicate Address Protection), 748

databases

filtering. See filtering

verifying, 1112

debug ip igmp command, 968, 973974

debug ip ospf lsa-generation command, 631

debug ip pim auto-rp command, 999

debug ip rip command, 631

debug ip route command, 574575

debug ip routing command, 578, 631

debug ipv6 dhcp command, 748, 754

debug nhrp cache command, 248

debug nhrp packet command, 248

debug output (RSTP)

link type, 8385

rapid convergence mechanisms, 7880

rapid convergence process, demonstrating, 8083

switch operation, 8589

debug ppp authentication command, 190, 194, 200, 202

debug ppp negotiation command, 183

DEFAULT distribute list, 284285

default route injection

configuration, 364368

DMVPN Phase 1 using static mapping, 220239

EIGRP AS 100, 363364

EIGRP routing domain, 281283

OSPF (Open Shortest Path First), 533536

overview of, 363

default-metric command, 604, 626

delay (DLY), 338

demand circuits, 456457

dense mode (PIM), 959962, 994997

denying. See filtering

designated ports, moving, 4345

destination keyword, 752

DH (Diffie-Hellman) groups, 912

DHCP (Dynamic Host Configuration Protocol)

client configuration, 746751

prefix delegation, 755763

server configuration, 212215, 746751

Dialer interface, 208209

Differential Service Code Point. See DSCP (Differential Service Code Point)

Diffie-Hellman (DH) groups, 912

disabling

debug command, 575

Spanning Tree Portfast, 114115

discard routes, 471472, 786789

discard-route external 255 command, 585

discovery, neighbor, 739743, 10371042

Discovery stage (PPPoE), 181182

distance command, 581

distribute-list OUT command, 494

distribute-list prefix-list command, 836

DLY (delay), 338

DMVPNs (dynamic multipoint virtual private networks)

configuration, 389391

configuring for EIGRP

DMVPN Phase 1, 289292

DMVPN Phase 2, 298301

DMVPN Phase 1 using dynamic mapping

hub and spoke configuration, 232236

interface and router configuration, 229232

overview of, 229

DMVPN Phase 1 using static mapping

hub and spoke configuration, 223229

interface and router configuration, 220239

NHRP (Next-Hop Resolution Protocol), 223

overview of, 219

DMVPN Phase 2 using dynamic mapping

hub and spoke configuration, 247251

interface and router configuration, 245247

overview of, 244

DMVPN Phase 2 using static mapping

hub and spoke configuration, 240244

interface and router configuration, 237240

overview of, 236237

DMVPN Phase 3

hub and spoke configuration, 255266

interface and router configuration, 253255

overview of, 251252

overview of, 219

tunnels, protecting, 946

F0/0 and loopback0 interfaces of R1, R2, and R3, 947948

hub and spoke configuration, 948952

IP routing, enabling, 946947

traffic protection, 952958

DSCP (Differential Service Code Point)

class-based policing

F0/0 interface on R2, configuring, 903904

HTTP, FTP, and ICMP traffic, 906907

MAC address access lists, 904906

overview of, 898

S1/2 interface on R1, configuring, 899902

class-based shaping, 907910

COS-DSCP mapping

F0/1 interface on R2, configuring, 866

F0/1 interface on SW1, configuring, 866

F0/19 interface SW2, configuring, 866869

DSCP-COS mapping

overview of, 860

R1 configuration, 862

R2 configuration, 861

SW2 configuration, 862865

DSCP-Mutation

DSCP rewrites, enabling, 857860

DSCP-mutation map configuration, 855857

mls qos, enabling on SW2, 853854

mls qos trust dscp configuration, 854855

MQC on R1, configuring to mark egress traffic with DSCP value of 1, 851852

overview of, 851

IP-precedence-DSCP mapping, 870873

match IP DSCP/Precedence vs. match DSCP, 885893

rewrites, enabling, 857860

duplicate address protection, 740741, 744

Duplicate Address Protection (DAD), 748

Dynamic Host Configuration Protocol. See DHCP (Dynamic Host Configuration Protocol)

dynamic mapping, DMVPN Phase 1 using

hub and spoke configuration, 232236

interface and router configuration, 229232

overview of, 229

dynamic multipoint virtual private networks. See DMVPNs (dynamic multipoint virtual private networks)

dynamic RP learning and Auto-RP, 993

Lo0 interface of R1, 10061010

OSPF Area 0 configuration, 994

PIM sparse-dense-mode configuration, 994997

primary and backup RP configuration, 9971003

R3 configuration, 10051006

RP announcements, filtering on R6, 10041005

E

EAP (Extensible Authentication Protocol)

configuration, 216218

overview of, 175176

Echo-Reply message, 175

Echo-Request message, 175

edge ports, 75, 94

EIGRP (Enhanced Interior Gateway Routing Protocol)

authentication

EIGRP AS 100 configuration, 360361

HMAC-SHA-256, 362363

MD5, 361

router configuration, 359360

topology, 359

basic configuration

configuring for future DMVPN spokes, 304311

DMVPN Phase 1, 289292

DMVPN Phase 2, 298301

EIGRP AS 100, 293297

loopback interfaces, 301304

static default routes, 287289

default route injection

configuration, 364368

EIGRP AS 100, 363364

overview of, 363

EIGRP AS 100 configuration, 578580, 589590

EIGRPv6

bandwidth usage, configuring, 830

configuration on R1, R2, R3, and R4, 821824

EIGRPv6 AS 100 configuration, 819820

external routes, filtering, 834837

Hello interval and Hold timer, 825826

HMAC-SHA-256 authentication, 833834

loopback1 interface on R1, 830831

loopback1 interface on R2, 826829

MD5 authentication, 831833

OSPFv3 Area 0, 818819

overview of, 817818

redistributing OSPFv3 into, 824825

metrics, 604

classic mode configuration, 337338

EIGRP AS 100 configuration, 334335

FD set to Infinity, resolving, 343348

mutual redistribution between RIPv2 and EIGRP, 335337

named mode configuration, 338341

topology, 333

Wide Metric support, 341342

named mode

bandwidth usage, configuring, 324325

EIGRP 200 configuration, 318319

EIGRP AS 100 configuration, 316317

fixed metric for the EIGRP summary route, 327328

hello intervals, 323324

number of received prefixes, limiting, 329333

OSPF configuration, 319323

overview of, 311

policy for configuring, 311315

summarization, 325327

unicast configuration, 317318

redistribution

eigrp 100 redistribution into ospf 1, 592593

network 4.4.4.0 /24, filtering on R2, 596597

ospf 1 and eigrp 100 redistribution into ospf 36, 599602

ospf 1 redistribution into eigrp 100, 595596

overview of, 604605

RIP redistribution into EIGRP, 580583

routes originated by R4, filtering with R5, 597599

RIPv2 and EIGRP redistribution

allowing only required routes to be redistributed, 617619

control plane mechanism, 614615

EIGRP AS 100 configuration, 607608

filtering RIP routes from being advertised out of F0/1 interface, 615617

filtering tagged routes, 619622

loopback0 interface, 607

mutual redistribution between RIPv2 and EIGRP, 608614

summarization, 622625

routing domain, injecting default route into, 281283

stub

EIGRP AS 100 configuration, 368370

eigrp stub connected option, 373374

eigrp stub option, 378379

eigrp stub receive-only option, 377378

eigrp stub redistributed option, 376377

eigrp stub static option, 375376

eigrp stub summary option, 375

redistribution, 372373

static routes, 370372

summarization, 370

topology, 368

summarization

loopback interfaces for R1, 349350

loopback interfaces for R2, 350

loopback interfaces for R3, 351

loopback interfaces for R4, 351353

R1 configuration, 358359

R2 configuration, 353356

R3 configuration, 357358

R4 configuration, 356357

topology, 349

in VPN, 11071113

eigrp stub command, 378379

eigrp stub connected command, 373374

eigrp stub receive-only command, 377378

eigrp stub redistributed command, 376377

eigrp stub static command, 375376

eigrp stub summary command, 375

enabling. See configuration

encryption, MPPE (Microsoft Point-to-Point Encryption), 215218

Enhanced Interior Gateway Routing Protocol. See EIGRP (Enhanced Interior Gateway Routing Protocol)

establishing PPP (Point-to-Point Protocol) sessions

Authentication Phase, 175177

Link Establishment Phase, 171175

Network Layer Protocol Phase, 177179

Ethernet, PPP over. See PPPoE (PPP over Ethernet)

EUI-64 addressing, 737739

expressions, regular. See regular expressions

Extensible Authentication Protocol. See EAP (Extensible Authentication Protocol)

external network summarization

discard routes, 786789

external route summarization, 782786

loopback interface summarization, 778782

OSPFv3 configuration, 771778

overview of, 771

external routes

filtering, 834837

summarization, 467468, 782786

F

FA (forward address), suppressing, 539548

FD set to Infinity, resolving, 343348

FEC (forwarding equivalence class), 1025

filtering

with access lists and prefix lists, 704714

BPDU filtering

F0/21 interface configuration, 139142

forwarding loops, 142146

overview of, 135136

policies, 146148

router and switch configuration, 136139

composite metrics, 602604

with IP prefix lists, 267

allowing only unsubnetted Class B networks, 272275

allowing only unsubnetted Class C networks, 275278

allowing unsubnetted Class A networks, plus Class B and C networks, 269272

basic configuration, 267269

denying certain prefixes, 278281

filtering existing and future host routes, 286

filtering networks with certain prefix lengths, 283285

injecting default route in EIGRP routing domain, 281283

loopback interfaces, 277278, 285

network 4.4.4.0 /24 on R2, 596597

OSPF (Open Shortest Path First), 476

loopback interface advertisement, 501502

loopback interface redistribution, 493

loopback interfaces of R1 and R2, 481482

LSA flooding, preventing, 502504

network filtering in Area 0, 486488

network filtering in Area 0 and Area 2, 488490

network filtering in Area 2, 484486

network filtering on all routers except R1, 490493

network filtering on all routers except R5, 494495

network filtering on R1’s routing table, 496

network filtering on R2, 482483

R1 and R2’s directly connected interfaces, 476478

removing, 497501

serial connection between R3 and R4, 478479

serial connection between R4 and R5, 480481

prefixes

advertising of prefixes originating in own AS, 721723

prefixes from directly connected neighbors, 725726

prefixes originating in AS 200, 723725

prefixes originating in AS 300, 717719, 727728

prefixes with AS 300 in path list, 719721

prefixes with prepended AS numbers, 728731

routes, 593595, 597599

RP announcements, 10041005

tagged routes, 619622

Flag field (PPP), 170171

flooding (LSA), 502504

flush timer, 628629

forward address (FA), suppressing, 539548

forwarding equivalence class (FEC), 1025

Forwarding Information Base, 306

forwarding loops (BPDU), 142146

frame format (PPP), 170171

frame-relay map command, 225

FSC field (PPP), 171

future host routes, denying, 286

G

GDOI (group domain of interpretation), 914

Generic Routing Encapsulation (GRE), 223

Global IGMP State Limiter, 971

GRE (Generic Routing Encapsulation)

GRE/IPSec

Transport mode, 940942

Tunnel mode, 937940

overview of, 223

tunnels

configuration, 513516

overview of, 504506

group domain of interpretation (GDOI), 914

H

Hashed Message Authentication Code-Secure Hash Algorithm-256, 362363

hashing, 176

HDLC (High-Level Data Link Control), 169170

header compression, 179180

Hello interval

EIGRP (Enhanced Interior Gateway Routing Protocol), 323324, 825826

LDP (Label Distribution Protocol) configuration, 10421044

hiding MLPS structure, 10651067

High-Level Data Link Control (HDLC), 169170

HMAC-SHA-256 authentication, 362363, 833834

Hold timer, 825826, 10421044

hop count (SIT), 95

host routes, denying, 286

hostnames

configuration, 20

switch hostnames, 5152, 96

hosts

auto-configuration, 740

match protocol HTTP URL, MIME, and Host, 893898

HTTP URL, 893898

hubs (DMVPN)

DMVPN Phase 1

dynamic mapping, 232236

static mapping, 223229

DMVPN Phase 2

dynamic mapping, 247251

static mapping, 240244

DMVPN Phase 3, 255266

I

icmp rate-limit parameter, 616

IGMP (Internet Group Management Protocol), 959

F0/0 and F0/1 interface configuration on R1 and R2, 959962

F0/0 interface configuration on R3 and R4, 963

F0/1 interface configuration on R5 and R6, 964

G0/1 interface on R7, 965

hosts connected to F0/1 on R1, restricting, 965967

hosts connected to F0/1 on R2, stopping multicast traffic with, 967969

mroute states, limiting, 971974

query max response time, 976977

query messages, sending, 969971

querying router and the query interval, 974976

igmp immediate-leave group-list 1 command, 969

igmp join-group command, 969

IKE (Internet Key Exchange), 911

Phase 1

configuration, 913917

message 1, 917, 921925

message 2, 918919

message 3, 919

message 4, 919920

message 5, 920

message 6, 920921

Phase 2, 914917

import command, 1092

include-connected keyword, 825

Infinity, FD set to, 343348

Information field (PPP), 171

interface configuration, verifying, 910

interface-configuration command, 568

interfaces. See also loopback interfaces

Dialer, 208209

DMVPNs (dynamic multipoint virtual private networks)

DMVPN Phase 1 using dynamic mapping, 229232

DMVPN Phase 1 using static mapping, 220239

DMVPN Phase 2 using dynamic mapping, 245247

DMVPN Phase 2 using static mapping, 237240

DMVPN Phase 3, 253255

PPP (Point-to-Point Protocol)

configuration, 182186

DHCP server configuration, 212215

EAP authentication, 216218

IP address assignment, 187190

MLPPP (Multilink PPP), 216218

MPPE protocol and MS-CHAP authentication, 215218

one-way CHAP authentication, 198201

one-way PAP authentication, 190192

PPPoE (PPP over Ethernet), 207212

R1 and R2 serial interface configuration, 215218

R4, configuring to authenticate R3, 202207

two-way CHAP authentication, 201202

two-way PAP authentication, 192194

trunk interfaces, verifying, 1213

Virtual-Template, 207

internal network summarization

discard routes, 786789

external route summarization, 782786

loopback interface summarization, 778782

OSPFv3 configuration, 771778

overview of, 771

Internal Spanning Tree (IST), 95

Internet Group Management. See IGMP (Internet Group Management Protocol)

Internet Key Exchange. See IKE (Internet Key Exchange)

Internet Security Association and Key Management Protocol (ISAKMP), 911, 912

intervals

Hello interval

EIGRP (Enhanced Interior Gateway Routing Protocol), 323324, 825826

LDP (Label Distribution Protocol) configuration, 10421044

query interval (IGMP), 974976

Intra-Area Prefix LSAs, 799800

ip address negotiated command, 187

IP CEF, 899

IP DSCP/Precedence, 881

ip helper-address command, 212, 752

ip igmp join-group command, 963, 968

ip igmp limit command, 973

ip igmp querier-timeout command, 962

ip igmp query-interval command, 962, 974

ip igmp query-max-response-time command, 962, 976

ip igmp static-group command, 963

ip local pool command, 212

ip multicast boundary command, 1004

ip nhrp map command, 248

ip nhrp network-id command, 265

ip nhrp nhs command, 248, 249

ip nhrp redirect command, 255, 266

ip nhrp shortcut command, 255, 266, 310

ip ospf demand-circuit command, 816

ip ospf network point-to-point command, 770

ip pim send-rp-announce command, 999

IP prefix list configuration, 267

allowing only unsubnetted Class B networks, 272275

allowing only unsubnetted Class C networks, 275278

allowing unsubnetted Class A networks, plus Class B and C networks, 269272

basic configuration, 267269

configuring loopback interfaces, 277278, 285

denying certain prefixes, 278281

filtering existing and future host routes, 286

filtering networks with certain prefix lengths, 283285

injecting default route in EIGRP routing domain, 281283

ip routing command, 221, 230, 238, 245, 253

ip summary-address command, 257, 262

ip summary-address eigrp 100 0.0.0.0 0.0.0.0 command, 304

IP vrf command, 1091

IP-precedence-DSCP mapping, 870873

IPSec VPN

basic site-to-site IPSec VPN, 911

GRE/IP with Transport mode, 940942

GRE/IPSec with Tunnel mode, 937940

IKE configuration, 913917

IKE Phase 1 message 1, 917

IKE Phase 1 message 2, 918919

IKE Phase 1 message 3, 919

IKE Phase 1 message 4, 919920

IKE Phase 1 message 5, 920

IKE Phase 1 message 6, 920921

IKE Phase 2 message 1, 921925

ISAKMP, 912

and NAT, 925930

non-scalable configuration, 930937

OAKLEY, 912913

policy guidelines, 912

S-VTI, 942946

DMVPN tunnels, protecting, 946

F0/0 and loopback0 interfaces of R1, R2, and R3, 947948

hub and spoke configuration, 948952

IP routing, enabling, 946947

traffic protection, 952958

overview of, 911

IPv4 addresses, 36

assigning, 187190

configuration, 387388

IPv6

addresses, acquiring

DHCP client/server configuration, 746751

DHCP prefix delegation, 755763

modified EUI-64 addressing, 737739

neighbor discovery, 739743

overview of, 737

R2 configuration, 751754

R5 configuration, 754755

SLAAC (stateless address auto-configuration), 743746

EIGRPv6

bandwidth usage, configuring, 830

configuration on R1, R2, R3, and R4, 821824

EIGRPv6 AS 100 configuration, 819820

external routes, filtering, 834837

Hello interval and Hold timer, 825826

HMAC-SHA-256 authentication, 833834

loopback1 interface on R1, 830831

loopback1 interface on R2, 826829

MD5 authentication, 831833

OSPFv3 Area 0 configuration, 818819

overview of, 817818

redistributing OSPFv3 into, 824825

LSAs in OSPFv3, 790

Intra-Area Prefix LSAs, 799800

Link LSAs, 795799

Network LSAs, 795

OSPF Area 0 on DMVPN network, 813816

OSPF Area 0 on F0/1 and loopback0 interfaces of R1, R2, and R4, 790793

OSPF Area 13 on S1/3 and loopback13 interfaces of R3, 800809

OSPF Area 37 on F0/0, 809813

Router LSAs, 793795

OSPFv3 configuration, 763771

summarization of internal/external networks

discard routes, 786789

external route summarization, 782786

loopback interface summarization, 778782

OSPFv3 configuration, 771778

overview of, 771

ipv6 address autoconfig default command, 748, 750

ipv6 address command, 759

ipv6 address dhcp command, 750

ipv6 bandwidth-percent eigrp command, 830

ipv6 dhcp client pd command, 758

ipv6 enable command, 748

ipv6 nd managed-config-flag command, 747

ipv6 nd other-config-flag command, 747

ipv6 nd prefix default no-advertise command, 751

ipv6 router ospf command, 765

ISAKMP (Internet Security Association and Key Management Protocol), 911, 912

IST (Internal Spanning Tree), 95

J-K-L

Lab Builder, 5

Label Forwarding Information Base (LFIB), 1073

Label Information Base (LIB), 1073

label switch routers. See LSRs (label switch routers)

labels

advertising, 1105

assignment, 1105

conditional label advertising, 10581064

configuration, 10481051

labs

advanced STP

overview of, 50

policy configuration, 5964

root bridge configuration, 5659, 6567

switch configuration, 5455

switch hostname configuration, 5152

trunk port configuration, 5254

VLAN 100, 200, 300, and 400 creation, 5556

VLAN 500 creation, 6770

VLAN 600 creation, 7073

advertising networks, 381

DMVPN configuration, 389391

IP addressing, 387388

OSPF adjacency, 391397

R1 and R4 connections and loopback interfaces, 385387

R4, R5, and R6 connections, 381385

static default routes, 388389

authentication

EIGRP AS 100 configuration, 360361

HMAC-SHA-256, 362363

MD5, 361

router configuration, 359360

topology, 359

backdoor links and OSPF, 1123

CE (customer edge) router configuration, 11361141

F0/1 interface of R1 and the G0/1 interface of R7, 11411147

LDP configuration between core routers, 11281132

MP-BGP AS 100 configuration between R2 and R6, 11321133

OSPF configuration on core MPLS routers, 11231128

RDs (route distinguishers), 11341136

RTs (route targets), 11341136

topology, 11231125

VRF (Virtual Routing and Forwarding), 11341136

basic redistribution 1

EIGRP AS 100, 578580

link between R1 and R3, 567569

loopback interfaces on R2, 583

loopback interfaces on R2/R3, 575578

loopback interfaces on R3, 569

overview of, 567

R1/R2, 571575

RIP redistribution into EIGRP, 580583

RIPv2 redistribution into OSPF, 584586

route maps, 570571

basic redistribution 2

composite metrics, filtering, 602604

eigrp 100 redistribution into ospf 1, 592593

EIGRP AS 100, 589590

network 4.4.4.0 /24, filtering on R2, 596597

ospf 1 and eigrp 100 redistribution into ospf 36, 599602

ospf 1 redistribution into eigrp 100, 595596

OSPF area 0, 587589, 591

overview of, 586

routes originated by R4, filtering with R5, 597599

routes tag of 111, configuring R4 to filter, 593594, 595

basic site-to-site IPSec VPN, 911

IKE configuration, 913917

IKE Phase 1 message 1, 917

IKE Phase 1 message 2, 918919

IKE Phase 1 message 3, 919

IKE Phase 1 message 4, 919920

IKE Phase 1 message 5, 920

IKE Phase 1 message 6, 920921

IKE Phase 2 message 1, 921925

ISAKMP, 912

OAKLEY, 912913

policy guidelines, 912

basic site-to-site IPSec VPN and NAT, 925930

basic STP

designated ports, moving, 4345

initial configuration, 3641

root primary macro configuration, 4648

spanning-tree cost on port in VLAN 12, raising, 4142

spanning-tree port ID, raising, 4849

BGP (Border Gateway Protocol)

BGP confederation, 731736

community attribute, 667679

conditional advertisement and BGP backdoor, 650667

filtering with access lists and prefix lists, 704714

multi-exit discriminator attribute, 695703

neighbor adjacencies, establishing, 635641

AS-path attribute, 679686

regular expressions, 714731

router reflectors, 642649

weight attribute, 686695

BGP routing in VPN, 11481154

BPDU filtering

F0/21 interface configuration, 139142

forwarding loops, 142146

overview of, 135136

policies, 146148

router and switch configuration, 136139

BPDU Guard, 128134

BSR (Bootstrap Router), 1013

Lo0 interface of R1, 10221023

OSPF Area 0 configuration, 10131014

PIM sparse mode configuration, 10141017

ping command, 10221023

primary and backup RP configuration, 10171022

class-based policing

F0/0 interface on R2, configuring, 903904

HTTP, FTP, and ICMP traffic, 906907

MAC address access lists, 904906

overview of, 898

S1/2 interface on R1, configuring, 899902

class-based shaping, 907910

COS-DSCP mapping

F0/1 interface on R2, configuring, 866

F0/1 interface on SW1, configuring, 866

F0/19 interface SW2, configuring, 866869

default route injection

configuration, 364368

EIGRP AS 100, 363364

overview of, 363

DMVPN Phase 1 using dynamic mapping

hub and spoke configuration, 232236

interface and router configuration, 229232

overview of, 229

DMVPN Phase 1 using static mapping

hub and spoke configuration, 223229

interface and router configuration, 220239

NHRP (Next-Hop Resolution Protocol), 223225

overview of, 219

DMVPN Phase 2 using dynamic mapping

hub and spoke configuration, 247251

interface and router configuration, 245247

overview of, 244

DMVPN Phase 2 using static mapping

hub and spoke configuration, 240244

interface and router configuration, 237240

overview of, 236237

DMVPN Phase 3

hub and spoke configuration, 255266

interface and router configuration, 253255

overview of, 251252

DMVPN tunnels, protecting, 946

F0/0 and loopback0 interfaces of R1, R2, and R3, 947948

hub and spoke configuration, 948952

IP routing, enabling, 946947

traffic protection, 952958

DSCP-COS mapping

overview of, 860

R1 configuration, 862

R2 configuration, 861

SW2 configuration, 862865

DSCP-Mutation

DSCP rewrites, enabling, 857860

DSCP-mutation map configuration, 855857

mls qos, enabling on SW2, 853854

mls qos trust dscp configuration, 854855

MQC on R1, configuring to mark egress traffic with DSCP value of 1, 851852

overview of, 851

dynamic RP learning and Auto-RP, 993

Lo0 interface of R1, 10061010

OSPF Area 0 configuration, 994

PIM sparse-dense-mode configuration, 994997

primary and backup RP configuration, 9971003

R3 configuration, 10051006

RP announcements, filtering on R6, 10041005

EIGRP basic configuration

configuring for future DMVPN spokes, 304311

DMVPN Phase 1, 289292

DMVPN Phase 2, 298301

EIGRP AS 100, 293297

loopback interfaces, 301304

static default routes, 287289

EIGRP metrics

classic mode configuration, 337338

EIGRP AS 100 configuration, 334335

FD set to Infinity, resolving, 343348

mutual redistribution between RIPv2 and EIGRP, 335337

named mode configuration, 338341

topology, 333

Wide Metric support, 341342

EIGRP named mode, 311

bandwidth usage, configuring, 324325

EIGRP 200 configuration, 318319

EIGRP AS 100 configuration, 316317

fixed metric for the EIGRP summary route, 327328

hello intervals, 323324

number of received prefixes, limiting, 329333

OSPF configuration, 319323

policy for configuring, 311315

summarization, 325327

unicast configuration, 317318

EIGRP routing in VPN, 11071113

EIGRP stub

EIGRP AS 100 configuration, 368370

eigrp stub connected option, 373374

eigrp stub option, 378379

eigrp stub receive-only option, 377378

eigrp stub redistributed option, 376377

eigrp stub static option, 375376

eigrp stub summary option, 375

redistribution, 372373

static routes, 370372

summarization, 370

topology, 368

EIGRP summarization

loopback interfaces for R1, 349350

loopback interfaces for R2, 350

loopback interfaces for R3, 351

loopback interfaces for R4, 351353

R1 configuration, 358359

R2 configuration, 353356

R3 configuration, 357358

R4 configuration, 356357

topology, 349

EIGRPv6

bandwidth usage, configuring, 830

configuration on R1, R2, R3, and R4, 821824

EIGRPv6 AS 100 configuration, 819820

external routes, filtering, 834837

Hello interval and Hold timer, 825826

HMAC-SHA-256 authentication, 833834

loopback1 interface on R1, 830831

loopback1 interface on R2, 826829

MD5 authentication, 831833

OSPFv3 Area 0 configuration, 818819

overview of, 817818

redistributing OSPFv3 into, 824825

GRE/IPSec Tunnel mode, Transport mode, and S-VTI

GRE/IP with Transport mode, 940942

GRE/IPSec with Tunnel mode configuration, 937940

non-scalable configuration, 930937

S-VTI, 942946

How Is This Possible?536–538

IGMP (Internet Group Management Protocol), 959

F0/0 and F0/1 interface configuration on R1 and R2, 959962

F0/0 interface configuration on R3 and R4, 963

F0/1 interface configuration on R5 and R6, 964

G0/1 interface on R7, 965

hosts connected to F0/1 on R1, restricting, 965967

hosts connected to F0/1 on R2, stopping multicast traffic with, 967969

mroute states, limiting, 971974

query max response time, 976977

query messages, sending, 969971

querying router and the query interval, 974976

input-interface and match NOT

f0/0 interface on R4, configuring, 873876

overview of, 873

s1/1 interface on R2, configuring, 877881

introductory lab, 817

IP-precedence-DSCP mapping, 870873

IPv6 addresses, acquiring

DHCP client/server configuration, 746751

DHCP prefix delegation, 755763

modified EUI-64 addressing, 737739

neighbor discovery, 739743

overview of, 737

R2 configuration, 751754

R5 configuration, 754755

SLAAC (stateless address auto-configuration), 743746

LDP (Label Distribution Protocol)

conditional label advertising, 10581064

control plane for the 7.7.7.0/24 prefix, 10511057

hello intervals, 10421044

hold timer, 10421044

labels, 10481051

LDP autoconfiguration, enabling, 10681071

LDP router ID (RID), 1033

loopback1 interface of R1, 10441048

LSRs (label switch routers), 10331037

MLPS structure, hiding, 10651067

MPLS forwarding, 1034

neighbor discovery, 10371042

OSPF Area 0, 10291032

serial connection between R3 and R5, 10721073

session keepalives, 1044

session protection, 10731077

topology, 10261029

TTL propagation, testing, 10641065

LDP (Label Distribution Protocol) configuration, 1026

LSA Type 4 and Suppress FA, 539548

LSAs in OSPFv3, 790

Intra-Area Prefix LSAs, 799800

Link LSAs, 795799

Network LSAs, 795

OSPF Area 0 on DMVPN network, 813816

OSPF Area 0 on F0/1 and loopback0 interfaces of R1, R2, and R4, 790793

OSPF Area 13 on S1/3 and loopback13 interfaces of R3, 800809

OSPF Area 37 on F0/0, 809813

Router LSAs, 793795

match destination and source address MAC

overview of, 881

R2 configuration to classify and mark IP routed traffic, 882885

RIPv2 configuration, 881

match IP DSCP/Precedence vs. match DSCP, 885893

match protocol HTTP URL, MIME, and Host, 893898

MLS QoS

f0/1 interface on SW1, configuring to mark ingress traffic with COS marking of 2, 844850

mls qos, enabling on SW1, 842844

overview of, 840

R1, configuring to send all traffic with COS marking of 1, 840842

MST (Multiple Spanning Tree), 9394

boundary ports, 94

configuring with policies, 99106

edge ports, 94

IST (Internal Spanning Tree), 95

MSTP (Multiple Instance Spanning Tree Protocol), 96

port configuration, 96

regions, 94

switch hostname configuration, 96

trunking mode, 97

VLAN configuration, 9799

OSPF authentication, 431

demand circuits, 456457

MD5 authentication, 440462

plaintext authentication, 433439

router interfaces in Area 0, 431433

OSPF broadcast networks, 397410

OSPF filtering, 476

loopback interface advertisement, 501502

loopback interface redistribution, 493

loopback interfaces of R1 and R2, 481482

LSA flooding, preventing, 502504

network filtering in Area 0, 486488

network filtering in Area 0 and Area 2, 488490

network filtering in Area 2, 484486

network filtering on all routers except R1, 490493

network filtering on all routers except R5, 494495

network filtering on R1’s routing table, 496

network filtering on R2, 482483

R1 and R2’s directly connected interfaces, 476478

removing, 497501

serial connection between R3 and R4, 478479

serial connection between R4 and R5, 480481

OSPF non-broadcast networks, 411421

OSPF point-to-multipoint networks, 425430

OSPF point-to-point networks, 421424

OSPF routing in VPN, 11131122

OSPF stub, totally stubby, and NSSA areas, 517

default route injection, 533536

loopback interfaces on R5, 532533

loopback30 interface on R3, 522523

NSSA configuration, 528532

R1’s directly connected interfaces, 518

R2’s directly connected interfaces, 518519

R3’s directly connected interfaces, 519520

R4’s directly connected interfaces, 521523

stub area configuration, 523526

totally stubby area configuration, 526528

OSPF suboptimal paths, 549555

OSPF summarization

advertising networks, 468469, 472475

discard routes, 471472

external route summarization, 467468

network summarization, 470

R1 configuration, 465466

R2 configuration, 464465

R3 configuration, 463464

R4 configuration, 463

OSPFv3 configuration, 763771

physical-to-logical topology

desired topology, 1819

hostname configuration, 20

port shutdown, 20

VLAN 12, 2324

VLAN 13, 2022

VLAN 28, 2425

VLAN 34, 2729

VLAN 45, 2930

VLAN 56, 3033

VLAN 789, 2627

PPP (Point-to-Point Protocol)

DHCP server configuration, 212215

EAP authentication, 216218

interface configuration, 182186

IP address assignment, 187190

loopback0 interface, pinging, 186187

MLPPP (Multilink PPP), 216218

MPPE protocol and MS-CHAP authentication, 215218

one-way CHAP authentication, 198201

one-way PAP authentication, 190192

PPPoE (PPP over Ethernet), 207212

R1 and R2 serial interface configuration, 215218

R4, configuring to authenticate R3, 202207

two-way CHAP authentication, 201202

two-way PAP authentication, 192194

prefix list configuration, 267

allowing only unsubnetted Class B networks, 272275

allowing only unsubnetted Class C networks, 275278

allowing unsubnetted Class A networks, plus Class B and C networks, 269272

basic configuration, 267269

configuring loopback interfaces, 277278, 285

denying certain prefixes, 278281

filtering existing and future host routes, 286

filtering networks with certain prefix lengths, 283285

injecting default route in EIGRP routing domain, 281283

Rapid STP

lab setup, 7577

link type, 8385

operational enhancements of, 74

overview of, 73

port roles, 74

port states, 74

rapid convergence mechanisms, 75, 7880

rapid convergence process, demonstrating, 8083

SW2, enabling for RSTP mode, 8992

switch operation, 8589

RFC 3101 and RFC 1587, 556566

RIPv2 and EIGRP redistribution

allowing only required routes to be redistributed, 617619

control plane mechanism, 614615

EIGRP AS 100 configuration, 607608

filtering RIP routes from being advertised out of F0/1 interface, 615617

filtering tagged routes, 619622

loopback0 interface, 607

mutual redistribution between RIPv2 and EIGRP, 608614

overview of, 604605

RIPv2 configuration on R2, R3, and R4, 605606

summarization, 622625

RIPv2 and OSPF redistribution

mutual redistribution on R1, 629634

OSPF area 0 configuration on f0/0 interface, 626

overview of, 625626

RIPv2 configuration on R1, R2, and R3, 626627

update, invalidation, and flush timer values, 628629

RIPv2 routing in VPN, 1078

configuration between R1 and PE-2, 10961107

configuration between R7 and PE-6, 10961107

LDP configuration on core MPLS routers, 10841088

MP-BGP AS 100 configuration on R2 to R6, 10881090

OSPF configuration on core MPLS routers, 10811083

RDs (route distinguishers), 10911095

RTs (route targets), 10911095

topology, 10791081

VRF (Virtual Routing and Forwarding), 10911095

Spanning Tree Backbone Fast, 148154

Spanning Tree Loop Guard, 162167

Spanning Tree Portfast, 106115

Spanning Tree Root Guard, 154162

static RP (rendezvous point), 977

PIM sparse mode, 983985

R2 and R3 configuration, 986991

S1/4 interface on R5, 991993

topology, 981983

summarization of internal/external networks

discard routes, 786789

external route summarization, 782786

loopback interface summarization, 778782

OSPFv3 configuration, 771778

overview of, 771

UplinkFast, 115128

virtual links and GRE tunnels

GRE tunnel configuration, 513516

OSPF configuration, 506509

overview of, 504506

virtual link configuration, 509513

LCP (Link Control Protocol), 171175

LDP (Label Distribution Protocol) configuration, 1026

backdoor links

CE (customer edge) router configuration, 11361141

F0/1 interface of R1 and the G0/1 interface of R7, 11411147

LDP configuration between core routers, 11281132

MP-BGP AS 100 configuration between R2 and R6, 11321133

RDs (route distinguishers), 11341136

RTs (route targets), 11341136

VRF (Virtual Routing and Forwarding), 11341136

conditional label advertising, 10581064

control plane for the 7.7.7.0/24 prefix, 10511057

hello intervals, 10421044

hold timer, 10421044

labels, 10481051

LDP autoconfiguration, enabling, 10681071

LDP router ID (RID), 1033

loopback1 interface of R1, 10441048

LSRs (label switch routers), 10331037

MLPS structure, hiding, 10651067

MPLS forwarding, 1034

neighbor discovery, 10371042

OSPF Area 0, 10291032

RIPv2 routing in VPN

LDP configuration on core MPLS routers, 10841088

MP-BGP AS 100 configuration on R2 to R6, 10881090

serial connection between R3 and R5, 10721073

session keepalives, 1044

session protection, 10731077

topology, 10261029

TTL propagation, testing, 10641065

leak-map command, 355

LFI (Link Fragmentation and Interleaving), 180

LFIB (Label Forwarding Information Base), 1073

LIB (Label Information Base), 1073

Link Control Protocol (LCP), 171175

Link Establishment Phase (PPP), 171175

Link Fragmentation and Interleaving (LFI), 180

Link Layer, 78

Link LSAs, 795799

links

backdoor links and OSPF, 1123

CE (customer edge) router configuration, 11361141

F0/1 interface of R1 and the G0/1 interface of R7, 11411147

LDP configuration between core routers, 11281132

MP-BGP AS 100 configuration between R2 and R6, 11321133

OSPF configuration on core MPLS routers, 11231128

RDs (route distinguishers), 11341136

RTs (route targets), 11341136

topology, 11231125

VRF (Virtual Routing and Forwarding), 11341136

RSTP link types, 8385

sham links, 11411147

link-state advertisements. See LSAs (link-state advertisements)

link-state databases, filtering items in. See filtering

lists, prefix. See prefix lists

logical topology

definition of, 8

transitioning physical topology to, 1833

desired topology, 1819

hostname configuration, 20

port shutdown, 20

VLAN 12 configuration, 2324

VLAN 13 configuration, 2022

VLAN 28 configuration, 2425

VLAN 34 configuration, 2729

VLAN 45 configuration, 2930

VLAN 56 configuration, 3033

VLAN 789 configuration, 2627

transitioning to physical topology, 817

loopback interfaces

advertising networks

R1 and R4 loopback interfaces, 385387

R4, R5, and R6 loopback interfaces, 381385

BGP (Border Gateway Protocol), 653

configuration, 575578, 583

DMVPNs (dynamic multipoint virtual private networks), 947948

EIGRP redistribution, 607

EIGRP summarization

loopback interfaces for R1, 349350

loopback interfaces for R2, 350

loopback interfaces for R3, 351

loopback interfaces for R4, 351353

EIGRPv6, 826829

LDP (Label Distribution Protocol), 10441048

OSPF (Open Shortest Path First), 501502

OSPF filtering, 481482

OSPF stub, totally stubby, and NSSA areas, 522523, 532533

pinging, 186187

redistribution, 493, 569

summarization, 325327, 778782

LSAs (link-state advertisements)

flooding, 502504

in OSPFv3, 790

Intra-Area Prefix LSAs, 799800

Link LSAs, 795799

Network LSAs, 795

OSPF Area 0 on DMVPN network, 813816

OSPF Area 0 on F0/1 and loopback0 interfaces of R1, R2, and R4, 790793

OSPF Area 13 on S1/3 and loopback13 interfaces of R3, 800809

OSPF Area 37 on F0/0, 809813

Router LSAs, 793795

Type-4 LSAs, 539548

LSRs (label switch routers)

configuration, 10331037

hello intervals, 10421044

M

MAC (media access control) addresses, 36

MAC address access lists, 904906

match destination and source address MAC

overview of, 885

R2 configuration to classify and mark IP routed traffic, 882885

RIPv2 configuration, 881

mapping

COS-DSCP mapping

F0/1 interface on R2, configuring, 866

F0/1 interface on SW1, configuring, 866

F0/19 interface SW2, configuring, 866869

DSCP-COS mapping

overview of, 860

R1 configuration, 862

R2 configuration, 861

SW2 configuration, 862865

DSCP-mutation maps, 855857

dynamic mapping, DMVPN Phase 1 using

hub and spoke configuration, 232236

interface and router configuration, 229232

overview of, 229

IP-precedence-DSCP mapping, 870873

mapping agents, 998

route map configuration, 570571

static mapping

DMVPN Phase 1, 219229

DMVPN Phase 2, 236244

match interface option, 569

match ip route-source command, 598

match source-address mac command, 904

matches, configuring

class-based policing

F0/0 interface on R2, configuring, 903904

HTTP, FTP, and ICMP traffic, 906907

MAC address access lists, 904906

overview of, 898

S1/2 interface on R1, configuring, 899902

class-based shaping, 907910

input-interface and match NOT

f0/0 interface on R4, configuring, 873876

overview of, 873

s1/1 interface on R2, configuring, 877881

match destination and source address MAC

overview of, 881

R2 configuration to classify and mark IP routed traffic, 882885

RIPv2 configuration, 881

match IP DSCP/Precedence vs. match DSCP, 885893

match protocol HTTP URL, MIME, and Host, 893898

MD5 authentication, 176

configuration, 361

authentication password, 448451

EIGRPv6, 831833

between R1 and R2, 444447, 455462

on serial links, 440443

removing, 443444, 451455

media access control addresses. See MAC (media access control) addresses

messages

CHAP (Challenge-Handshake Authentication Protocol), 198200

IGMP (Internet Group Management Protocol), 969971

IPv6, 739742

LCP (Link Control Protocol), 172175

NHRP (Next-Hop Resolution Protocol), 251252

PAP (Password Authentication Protocol), 190

PPPoE (PPP over Ethernet), 181

metric rib-scale command, 340

metrics

composite metrics, filtering, 602604

EIGRP (Enhanced Interior Gateway Routing Protocol), 604

classic mode configuration, 337338

EIGRP AS 100 configuration, 334335

FD set to Infinity, resolving, 343348

mutual redistribution between RIPv2 and EIGRP, 335337

named mode configuration, 338341

topology, 333

Wide Metric support, 341342

mGRE (Multipoint Generic Routing Encapsulation), 219, 223

Microsoft CHAP. See MS-CHAP (Microsoft CHAP)

Microsoft Point-to-Point Encryption. See MPPE (Microsoft Point-to-Point Encryption)

MIME (Multipurpose Internet Mail Extensions), 893898

MLPPP (Multilink PPP), 180, 216218

MLS QoS

f0/1 interface, configuring to mark ingress traffic with COS marking of 2, 844850

mls qos, enabling on SW1, 842844

overview of, 840

R1, configuring to send all traffic with COS marking of 1, 840842

mls qos command, 853

mls qos cos 2 command, 846, 849

mls qos cos override command, 846, 847

mls qos trust cos command, 846, 849

mls qos trust dscp command, 854

modified EUI-64 addressing, 737739

Modular Quality of Service Command Line Interface (MQC), 844

moving designated ports, 4345

MPLS (Multiprotocol Label Switching)

backdoor links and OSPF, 1123

CE (customer edge) router configuration, 11361141

F0/1 interface of R1 and the G0/1 interface of R7, 11411147

LDP configuration between core routers, 11281132

MP-BGP AS 100 configuration between R2 and R6, 11321133

OSPF configuration on core MPLS routers, 11231128

RDs (route distinguishers), 11341136

RTs (route targets), 11341136

topology, 11231125

VRF (Virtual Routing and Forwarding), 11341136

BGP routing in VPN, 11481154

EIGRP routing in VPN, 11071113

LDP (Label Distribution Protocol), 1026

conditional label advertising, 10581064

control plane for the 7.7.7.0/24 prefix, 10511057

hello intervals, 10421044

hold timer, 10421044

labels, 10481051

LDP autoconfiguration, 10681071

LDP router ID (RID), 1033

loopback1 interface of R1, 10441048

LSRs (label switch routers), 10331037

MLPS structure, hiding, 10651067

MPLS forwarding, 1034

neighbor discovery, 10371042

OSPF Area 0, 10291032

serial connection between R3 and R5, 10721073

session keepalives, 1044

session protection, 10731077

topology, 10261029

TTL propagation, testing, 10641065

OSPF routing in VPN, 11131122

overview of, 1025

RIPv2 routing in VPN, 1078

configuration between R1 and PE-2, 10961107

configuration between R7 and PE-6, 10961107

LDP configuration on core MPLS routers, 10841088

MP-BGP AS 100 configuration on R2 to R6, 10881090

OSPF configuration on core MPLS routers, 10811083

RDs (route distinguishers), 10911095

RTs (route targets), 10911095

topology, 10791081

VRF (Virtual Routing and Forwarding), 10911095

mpls ip command, 1033

mpls label protocol command, 1033

mpls label protocol ldp command, 1033

MPLS label range 16 1048575 command, 1048

mpls ldp advertise-labels command, 1058

mpls ldp router-id command, 1033

MPPE (Microsoft Point-to-Point Encryption), 215218

MQC (Modular Quality of Service Command Line Interface), 844

mroute states (IGMP), 971974

MS-CHAP (Microsoft CHAP), 175176, 215218

MST (Multiple Spanning Tree), 9394

boundary ports, 94

configuring with policies, 99106

edge ports, 94

IST (Internal Spanning Tree), 95

MSTP (Multiple Instance Spanning Tree Protocol), 96

port configuration, 96

regions, 94

switch hostname configuration, 96

trunking mode, 97

VLAN configuration, 9799

MSTP (Multiple Instance Spanning Tree Protocol), 96

multicast

BSR (Bootstrap Router), 1013

Lo0 interface of R1, 10221023

OSPF Area 0 configuration, 10131014

PIM sparse mode configuration, 10141017

ping command, 10221023

primary and backup RP configuration, 10171022

dynamic RP learning and Auto-RP, 993

Lo0 interface of R1, 10061010

OSPF Area 0 configuration, 994

PIM sparse-dense-mode configuration, 994997

primary and backup RP configuration, 9971003

R3 configuration, 10051006

RP announcements, filtering on R6, 10041005

IGMP (Internet Group Management Protocol), 959

F0/0 and F0/1 interface configuration on R1 and R2, 959962

F0/0 interface configuration on R3 and R4, 963

F0/1 interface configuration on R5 and R6, 964

G0/1 interface on R7, 965

hosts connected to F0/1 on R1, restricting, 965967

hosts connected to F0/1 on R2, stopping multicast traffic with, 967969

mroute states, limiting, 971974

query max response time, 976977

query messages, sending, 969971

querying router and the query interval, 974976

static RP (rendezvous point), 977

PIM sparse mode, 983985

R2 and R3 configuration, 986991

S1/4 interface on R5, 991993

topology, 981983

multi-exit discriminator attribute (BGP), 695703

Multilink PPP (MLPPP), 180

Multiple Instance Spanning Tree (MSTP), 96

Multiple Spanning Tree. See MST (Multiple Spanning Tree)

Multipoint Generic Routing Encapsulation (mGRE), 219, 223

Multiprotocol Label Switching. See MPLS (Multiprotocol Label Switching)

Multipurpose Internet Mail Extensions (MIME), 893898

mutation map (DSCP), 855857

mutual redistribution between RIPv2 and EIGRP, 335337, 608614

allowing only required routes to be redistributed, 617619

control plane mechanism, 614615

filtering RIP routes from being advertised out of F0/1 interface, 615617

filtering tagged routes, 619622

summarization, 622625

N

Name field (CHAP), 199

named mode (EIGRP), 311

bandwidth usage, configuring, 324325

EIGRP 200 configuration, 318319

EIGRP AS 100 configuration, 316317

fixed metric for the EIGRP summary route, 327328

hello intervals, 323324

metrics and, 338341

number of received prefixes, limiting, 329333

OSPF configuration, 319323

policy for configuring, 311315

summarization, 325327

unicast configuration, 317318

NAT (network address translation), 224, 925930

NBAR (Network Based Application Recognition), 899

NBMA (Non-Broadcast Multi-Access), 219, 294

NCPs (Network Control Protocols), 177179

neighbor adjacencies, establishing, 635641

neighbor advertisements, 740

neighbor discovery, 739743, 10371042

neighbor routes, 182

NET prefix list, 268269

network address translation (NAT), 224

Network Based Application Recognition (NBAR), 899

Network Control Protocols (NCPs), 177179

Network Layer Protocol Phase (PPP), 177179

network layer reachability information (NLRI), 509

Network LSAs, 795

Next Hop Server (NHS), 219

NHRP (Next-Hop Resolution Protocol)

DMVPNs (dynamic multipoint virtual private networks)

DMVPN Phase 1 using dynamic mapping, 232

DMVPN Phase 1 using static mapping, 223225

DMVPN Phase 2 using dynamic mapping, 248249

DMVPN Phase 3, 255259

NHRP Redirect, 251252

NHRP Response, 252

NHRP Shortcut, 252

Resolution requests, 251, 301

Traffic Indication message, 265

NHS (Next Hop Server), 219

NLRI (network layer reachability information), 509

no auto-summary command, 312

no discard-route internal command, 585

no mpls ip propagate-ttl local command, 1066

no peer neighbor-route command, 185

Non-Broadcast Multi-Access (NBMA), 294

Non-Broadcast Multi-Access (NBMA) address, 219

non-broadcast networks (OSPF)

configuration, 411421

point-to-multipoint networks, 425430

nonces, 913

NSSA (not-so-stubby area), 517

configuration, 528532

default route injection, 533536

loopback interfaces on R5, 532533

loopback30 interface on R3, 522523

R1’s directly connected interfaces, 518

R2’s directly connected interfaces, 518519

R3’s directly connected interfaces, 519520

R4’s directly connected interfaces, 521523

number of received prefixes, limiting, 329333

O

OAKLEY, 912913

one-way PAP authentication, 190192

Open Shortest Path First. See OSPF (Open Shortest Path First)

Originator-ID attribute, 642

OSPF (Open Shortest Path First), 536538. See also EIGRP (Enhanced Interior Gateway Routing Protocol)

advertising networks, 381

DMVPN configuration, 389391

IP addressing, 387388

OSPF adjacency, 391397

R1 and R4 connections and loopback interfaces, 385387

R4, R5, and R6 connections, 381385

static default routes, 388389

authentication, 431

demand circuits, 456457

MD5 authentication, 440462

plaintext authentication, 433439

router interfaces in Area 0, 431433

backdoor links, 1123

OSPF configuration on core MPLS routers, 11231128

topology, 11231125

basic redistribution

eigrp 100 redistribution into ospf 1, 592593

network 4.4.4.0 /24, filtering on R2, 596597

ospf 1 and eigrp 100 redistribution into ospf 36, 599602

ospf 1 redistribution into eigrp 100, 595596

OSPF area 0 configuration, 587589, 591

RIPv2 redistribution into OSPF, 584586

routes originated by R4, filtering with R5, 597599

broadcast networks, 397410

EIGRP (Enhanced Interior Gateway Routing Protocol) configuration, 319323

filtering, 476

loopback interface advertisement, 501502

loopback interface redistribution, 493

loopback interfaces of R1 and R2, 481482

LSA flooding, preventing, 502504

network filtering in Area 0, 486488

network filtering in Area 0 and Area 2, 488490

network filtering in Area 2, 484486

network filtering on all routers except R1, 490493

network filtering on all routers except R5, 494495

network filtering on R1’s routing table, 496

network filtering on R2, 482483

R1 and R2’s directly connected interfaces, 476478

removing, 497501

serial connection between R3 and R4, 478479

serial connection between R4 and R5, 480481

LSA Type 4 and FA suppression, 539548

LSAs in OSPFv3, 790

Intra-Area Prefix LSAs, 799800

Link LSAs, 795799

Network LSAs, 795

OSPF Area 0 on DMVPN network, 813816

OSPF Area 0 on F0/1 and loopback0 interfaces of R1, R2, and R4, 790793

OSPF Area 13 on S1/3 and loopback13 interfaces of R3, 800809

OSPF Area 37 on F0/0, 809813

Router LSAs, 793795

non-broadcast networks, 411421

OSPFv3, 763771

bandwidth usage, configuring, 830

Hello interval and Hold timer, 825826

loopback1 interface on R2, 826829

redistributing into EIGRPv6, 824825

point-to-multipoint networks, 425430

point-to-point networks, 421424

RFC 3101 and RFC 1587, 556566

RIPv2 and OSPF redistribution

mutual redistribution on R1, 629634

OSPF area 0 configuration on f0/0 interface, 626

overview of, 625626

RIPv2 configuration on R1, R2, and R3, 626627

update, invalidation, and flush timer values, 628629

RIPv2 routing in VPN, 10811083

stub, totally stubby, and NSSA areas, 517

default route injection, 533536

loopback interfaces on R5, 532533

loopback30 interface on R3, 522523

NSSA configuration, 528532

R1’s directly connected interfaces, 518

R2’s directly connected interfaces, 518519

R3’s directly connected interfaces, 519520

R4’s directly connected interfaces, 521523

stub area configuration, 523526

totally stubby area configuration, 526528

suboptimal paths, 549555

summarization

advertising networks, 468469, 472475

discard routes, 471472, 786789

external route summarization, 467468, 782786

loopback interface summarization, 778782

network summarization, 470

OSPFv3 configuration, 771778

overview of, 771

R1 configuration, 465466

R2 configuration, 464465

R3 configuration, 463464

R4 configuration, 463

virtual links and GRE tunnels

GRE tunnel configuration, 513516

OSPF configuration, 506509

overview of, 504506

virtual link configuration, 509513

in VPN, 11131122

P

Packet Description Language Modules (PDLM), 899

packet label assignment, 1106

Padding field (PPP), 171

PADI (PPPoE Active Discovery Initiation) frame, 181

PADO (PPPoE Active Discovery Offer) frame, 181

PADR (PPPoE Active Discovery Request) frame, 181

PADS (PPPoE Active Discovery Session) frame, 181

PADT (PPPoE Active Discovery Termination) message, 181

PAP (Password Authentication Protocol)

AUTH-ACK message, 190, 194

AUTH-REQ message, 190, 194

one-way CHAP authentication, 198201

one-way PAP authentication, 190192

overview of, 175179

R4, configuring to authenticate R3, 202207

two-way CHAP authentication, 201202

two-way PAP authentication, 192194

passwords, authentication passwords, 448451

payload compression, 179180

PDLM (Packet Description Language Modules), 899

peer default ip address 23.1.1.3 interface command, 187

peer default ip address pool command, 212

peer session configuration, 650651

peering (BGP), 704708, 715717

Perfect Forward Secrecy (PFS), 913

PFC (Protocol Field Compression), 179

PFS (Perfect Forward Secrecy), 913

Phase 1 DMVPN (dynamic multipoint virtual private network)

configuring for EIGRP, 289292

NHRP (Next-Hop Resolution Protocol), 223

using dynamic mapping

hub and spoke configuration, 232236

interface and router configuration, 229232

overview of, 229

using static mapping

hub and spoke configuration, 223229

interface and router configuration, 220239

overview of, 219

Phase 2 DMVPN (dynamic multipoint virtual private network)

configuring for EIGRP, 298301

using dynamic mapping

hub and spoke configuration, 247251

interface and router configuration, 245247

overview of, 244

using static mapping

hub and spoke configuration, 240244

interface and router configuration, 237240

overview of, 236237

Phase 3 DMVPN (dynamic multipoint virtual private network)

hub and spoke configuration, 255266

interface and router configuration, 253255

overview of, 251252

physical topology

definition of, 78

serial connections between routers, 35

switching devices, 13

transitioning logical topology to, 817

transitioning to logical topology, 1833

desired topology, 1819

hostname configuration, 20

port shutdown, 20

VLAN 12 configuration, 2324

VLAN 13 configuration, 2022

VLAN 28 configuration, 2425

VLAN 34 configuration, 2729

VLAN 45 configuration, 2930

VLAN 56 configuration, 3033

VLAN 789 configuration, 2627

PIM (Protocol-Independent Multicast)

dense mode, 959962

sparse mode, 983985, 994997, 10141017

ping command, 10221023

plaintext authentication

configuration, 433438

removing, 438439

point-to-multipoint networks (OSPF), 425430

point-to-point networks (OSPF), 421424

Point-to-Point Protocol. See PPP (Point-to-Point Protocol)

policing, class-based. See class-based policing

Portfast, 106115

ports

edge ports, 75

shutting down, 20

STP (Spanning Tree Protocol)

boundary ports, 94

designated ports, moving, 4345

edge ports, 94

MSTP (Multiple Instance Spanning Tree Protocol), 96

port roles, 74

port states, 74

spanning-tree port ID, raising, 4849

trunk port configuration, 5254

trunking mode, 97

PPP (Point-to-Point Protocol)

control plane, 171

authentication, 175177

LCP (Link Control Protocol), 171175

NCPs (Network Control Protocols), 177179

frame format, 170171

header compression, 179180

lab, 180182

DHCP server configuration, 212215

EAP authentication, 216218

interface configuration, 182186

IP address assignment, 187190

loopback0 interface, pinging, 186187

MLPPP (Multilink PPP), 216218

MPPE protocol and MS-CHAP authentication, 215218

one-way CHAP authentication, 198201

one-way PAP authentication, 190192

PPPoE (PPP over Ethernet), 207212

R1 and R2 serial interface configuration, 215218

R4, configuring to authenticate R3, 202207

two-way CHAP authentication, 201202

two-way PAP authentication, 192194

MLPPP (Multilink PPP), 180

overview of, 169170

payload compression, 179180

PPPoE (PPP over Ethernet), 180182

session establishment

Authentication Phase, 175177

Link Establishment Phase, 171175

Network Layer Protocol Phase, 177179

ppp authentication chap command, 198, 203

ppp authentication pap command, 190

ppp chap hostname command, 199, 203

ppp chap password command, 177

PPP over Ethernet. See PPPoE (PPP over Ethernet)

ppp pap sent-username command, 191

PPPoE (PPP over Ethernet), 180182, 207212

PPPoE Active Discovery Initiation (PADI) frame, 181

PPPoE Active Discovery Offer (PADO) frame, 181

PPPoE Active Discovery Request (PADR) frame, 181

PPPoE Active Discovery Session (PADS) frame, 181

PPPoE Active Discovery Termination (PADT) message, 181

precedence, IP-precedence-DSCP mapping, 870873

prefix delegation (DHCP), 755763

prefix lists

configuration, 267

allowing only unsubnetted Class B networks, 272275

allowing only unsubnetted Class C networks, 275278

allowing unsubnetted Class A networks, plus Class B and C networks, 269272

basic configuration, 267269

configuring loopback interfaces, 277278, 285

denying certain prefixes, 278281

filtering existing and future host routes, 286

filtering networks with certain prefix lengths, 283285

injecting default route in EIGRP routing domain, 281283

filtering with, 704714

access list configuration, 712713

BGP peering, 704708

outbound prefixes, filtering, 713714

prefix-list and distribute-list configuration, 709710

R2 configuration, 708709

R3 configuration, 711712

prefixes, filtering

advertising of prefixes originating in own AS, 721723

prefixes from directly connected neighbors, 725726

prefixes originating in AS 200, 723725

prefixes originating in AS 300, 717719, 727728

prefixes with AS 300 in path list, 719721

prefixes with prepended AS numbers, 728731

preshared keys (PSK), 913

primary RP (rendezvous point) configuration, 9971003, 10171022

propagation (TTL), testing, 10641065

Protocol field (CHAP), 198

Protocol Field Compression (PFC), 179

Protocol field (PPP), 171

Protocol-Independent Multicast. See PIM (Protocol-Independent Multicast)

Protocol-Reject (PROTREJ) message, 178179

Protocol-Reject message, 175

PROTREJ (Protocol-Reject) message, 178179

PSK (preshared keys), 913

Q

QoS (quality of service)

class-based policing

F0/0 interface on R2, configuring, 903904

HTTP, FTP, and ICMP traffic, 906907

MAC address access lists, 904906

overview of, 898

S1/2 interface on R1, configuring, 899902

class-based shaping, 907910

COS-DSCP mapping

F0/1 interface on R2, configuring, 866

F0/1 interface on SW1, configuring, 866

F0/19 interface SW2, configuring, 866869

DSCP-COS mapping

overview of, 860

R1 configuration, 862

R2 configuration, 861

SW2 configuration, 862865

DSCP-Mutation

DSCP rewrites, enabling, 857860

DSCP-mutation map configuration, 855857

mls qos, enabling on SW2, 853854

mls qos trust dscp configuration, 854855

MQC on R1, configuring to mark egress traffic with DSCP value of 1, 851852

overview of, 851

input-interface and match NOT

f0/0 interface on R4, configuring, 873876

overview of, 873

s1/1 interface on R2, configuring, 877881

IP-precedence-DSCP mapping, 870873

LFI (Link Fragmentation and Interleaving), 180

match destination and source address MAC

overview of, 881

R2 configuration to classify and mark IP routed traffic, 882885

RIPv2 configuration, 881

match IP DSCP/Precedence vs. match DSCP, 885893

match protocol HTTP URL, MIME, and Host, 893898

MLS QoS

f0/1 interface on SW1, configuring to mark ingress traffic with COS marking of 2, 844850

mls qos, enabling on SW1, 842844

overview of, 840

R1, configuring to send all traffic with COS marking of 1, 840842

overview of, 839840

quality of service. See QoS (quality of service)

queries (IGMP)

query interval, 974976

query max response time, 976977

query messages, 969971

querying router, 974976

querying router and the query interval, 974976

R

RA (router advertisement) messages, 739740, 744

raising spanning-tree cost on port in VLAN 12, 4142

rapid convergence (RSTP), 75

link type, 8385

rapid convergence mechanisms, 7880

rapid convergence process, demonstrating, 8083

Rapid STP (Spanning Tree Protocol)

lab setup, 7577

link type, 8385

operational enhancements of, 74

overview of, 73

port roles, 74

port states, 74

rapid convergence mechanisms, 75, 7880

rapid convergence process, demonstrating, 8083

SW2, enabling for RSTP mode, 8992

switch operation, 8589

rapid-commit option, 755

RDs (route distinguishers), 10911095, 11341136

Redirect message, 251252, 740

redistribute command, 572573

redistribute connected command, 570, 579

redistribution

basic configuration

composite metrics, filtering, 602604

eigrp 100 redistribution into ospf 1, 592593

EIGRP AS 100, 578580, 589590

link between R1 and R3, 567569

loopback interfaces on R2, 583

loopback interfaces on R2/R3, 575578

loopback interfaces on R3, 569

network 4.4.4.0 /24, filtering on R2, 596597

ospf 1 and eigrp 100 redistribution into ospf 36, 599602

ospf 1 redistribution into eigrp 100, 595596

OSPF area 0, 587589, 591

overview of, 567

R1/R2, 571575

RIP redistribution into EIGRP, 580583

RIPv2 redistribution into OSPF, 584586

route maps, 569

routes originated by R4, filtering with R5, 597599

routes tag of 111, configuring R4 to filter, 593594

routes tag of 222, configuring R4 to filter, 595

RIPv2 and EIGRP redistribution

allowing only required routes to be redistributed, 617619

control plane mechanism, 614615

EIGRP AS 100 configuration, 607608

filtering RIP routes from being advertised out of F0/1 interface, 615617

filtering tagged routes, 619622

loopback0 interface, 607

mutual redistribution between RIPv2 and EIGRP, 608614

overview of, 604605

RIPv2 configuration on R2, R3, and R4, 605606

summarization, 622625

RIPv2 and OSPF redistribution

mutual redistribution on R1, 629634

OSPF area 0 configuration on f0/0 interface, 626

overview of, 625626

RIPv2 configuration on R1, R2, and R3, 626627

update, invalidation, and flush timer values, 628629

reflectors, router, 642649

regions (MST), 94

regular expressions, 714731

advertising of prefixes originating in own AS, preventing, 721723

BGP peering, 715717

prefixes from directly connected neighbors, blocking, 725726

prefixes originating in AS 200, blocking, 723725

prefixes originating in AS 300, blocking, 727728

prefixes originating in AS 300, filtering, 717719

prefixes with AS 300 in path list, filtering, 719721

prefixes with prepended AS numbers, blocking, 728731

Rendezvous Point Set (RP-SET), 1019

rendezvous points. See RPs (rendezvous points)

Resolution requests (NHRP), 251, 301

Response message

CHAP (Challenge-Handshake Authentication Protocol), 199

NHRP (Next-Hop Resolution Protocol), 252

rewrites (DSCP), enabling, 857860

RFC 1587, 556566

RFC 3101, 556566

RIB (Routing Information-Base), 306

RID (router ID), 1033

RIPv2 (Routing Information Protocol version 2), 295

basic redistribution

overview of, 604605

redistribution into OSPF, 584586

RIPv2 configuration on R2, R3, and R4, 605606

EIGRP redistribution

allowing only required routes to be redistributed, 617619

control plane mechanism, 614615

EIGRP AS 100 configuration, 607608

filtering RIP routes from being advertised out of F0/1 interface, 615617

filtering tagged routes, 619622

loopback0 interface, 607

mutual redistribution, 335337

mutual redistribution between RIPv2 and EIGRP, 608614

summarization, 622625

match destination and source address MAC, 881

OSPF redistribution

mutual redistribution on R1, 629634

OSPF area 0 configuration on f0/0 interface, 626

overview of, 625626

RIPv2 configuration on R1, R2, and R3, 626627

update, invalidation, and flush timer values, 628629

redistribution into EIGRP, 580583

in VPN, 1078

configuration between R1 and PE-2, 10961107

configuration between R7 and PE-6, 10961107

LDP configuration on core MPLS routers, 10841088

MP-BGP AS 100 configuration on R2 to R6, 10881090

OSPF configuration on core MPLS routers, 10811083

RDs (route distinguishers), 10911095

RTs (route targets), 10911095

topology, 10791081

VRF (Virtual Routing and Forwarding), 10911095

roles, port, 74

root bridge configuration, 5659, 6567

root primary macro configuration, 4648

route distinguishers (RDs), 10911095, 11341136

route map configuration, 570571

route maps, 598604

route redistribution. See redistribution

route targets (RTs), 10911095, 11341136

route-map tst permit 90 command, 570

router advertisement (RA) messages, 739740, 744

router configuration. See configuration

router discovery, 741

router ID (RID), 1033

Router LSAs, 793795

router ospf command, 765

router ospfv3 command, 765

router reflectors, 642649

router solicitation, 740

Routing Information Protocol. See RIPv2 (Routing Information Protocol version 2)

Routing Information-Base (RIB), 306

routing tables, filtering items in. See filtering

RPs (rendezvous points)

candidate RPs, 997998

dynamic RP learning and Auto-RP, 993

Lo0 interface of R1, 10061010

OSPF Area 0 configuration, 994

PIM sparse-dense-mode configuration, 994997

primary and backup RP configuration, 9971003

R3 configuration, 10051006

RP announcements, filtering on R6, 10041005

static RP (rendezvous point), 977

PIM sparse mode, 983985

R2 and R3 configuration, 986991

S1/4 interface on R5, 991993

topology, 981983

RP-SET (Rendezvous Point Set), 1019

RSA encrypted pseudorandom numbers, 913

RSA signatures, 913

RTs (route targets), 10911095, 11341136

Rx(config)#ip multicast-routing command, 959

S

sending messages. See messages

serial connections between routers, 35

servers

AAA servers, 176

DHCP server configuration, 746751

DHCP servers, 212215

session keepalives, 1044

session protection (LDP), 10731077

Session stage (PPPoE), 181182

sessions (PPP), establishing

Authentication Phase, 175177

Link Establishment Phase, 171175

Network Layer Protocol Phase, 177179

sh interface command, 41, 48

sh mac address-table dynamic vlan 21 command, 48

sh mac-address-table command, 41

sh spanning-tree command, 37

sh spanning-tree vlan 12 interface f0/19 detail command, 44

sh version | inc Base command, 37

sham links, 11411147

shaping, class-based, 907910

Shortcut message (NHRP), 252

show cdp neighbors command, 20

show ip bgp peer-group TST command, 641

show ip eigrp topology 8.8.8.0/24 command, 341

show ip route | include 3.3.3.0 command, 629

show ipv6 ospf database command, 795

show ipv6 route command, 750

show ppp all command, 193

show ppp interface command, 195

shutting down ports, 20

site-to-site IPSec VPN

basic site-to-site IPSec VPN, 911

IKE configuration, 913917

IKE Phase 1 message 1, 917

IKE Phase 1 message 2, 918919

IKE Phase 1 message 3, 919

IKE Phase 1 message 4, 919920

IKE Phase 1 message 5, 920

IKE Phase 1 message 6, 920921

IKE Phase 2 message 1, 921925

ISAKMP, 912

OAKLEY, 912913

policy guidelines, 912

basic site-to-site IPSec VPN and NAT, 925930

DMVPN tunnels, protecting, 946

F0/0 and loopback0 interfaces of R1, R2, and R3, 947948

hub and spoke configuration, 948952

IP routing, enabling, 946947

traffic protection, 952958

GRE/IP with Transport mode, 940942

GRE/IPSec with Tunnel mode, 937940

non-scalable configuration, 930937

S-VTI, 942946

SLAAC (stateless address auto-configuration), 743746

source-protocol option, 600

Spanning Tree Backbone Fast, 148154

Spanning Tree Loop Guard, 162167

Spanning Tree Portfast, 106115

Spanning Tree Root Guard, 154162

spanning-tree portfast command, 75

sparse mode (PIM), 983985, 994997

spokes (DMVPN)

configuring for future DMVPN spokes, 304311

Phase 1

dynamic mapping, 232236

static mapping, 223229

Phase 2

dynamic mapping, 247251

static mapping, 240244

Phase 3, 255266

stateless address auto-configuration (SLAAC), 743746

states

mroute states (IGMP), 971974

port states, 74

static default routes

EIGRP (Enhanced Interior Gateway Routing Protocol), 287289

OSPF (Open Shortest Path First), 388389

static mapping

DMVPN Phase 1

hub and spoke configuration, 223229

NHRP (Next-Hop Resolution Protocol), 223225

overview of, 219, 220239

DMVPN Phase 2

hub and spoke configuration, 240244

interface and router configuration, 237240

overview of, 236237

static RP (rendezvous point), 977

PIM sparse mode, 983985

R2 and R3 configuration, 986991

S1/4 interface on R5, 991993

topology, 981983

static virtual tunnel interfaces (S-VTI), 942946

STP (Spanning Tree Protocol)

advanced STP (Spanning Tree Protocol)

overview of, 50

policy configuration, 5964

root bridge configuration, 5659, 6567

switch configuration, 5455

switch hostname configuration, 5152

trunk port configuration, 5254

VLAN 100, 200, 300, and 400 creation, 5556

VLAN 500 creation, 6770

VLAN 600 creation, 7073

basic STP (Spanning Tree Protocol)

designated ports, moving, 4345

initial configuration, 3641

IP and MAC addressing, 36

root primary macro configuration, 4648

spanning-tree cost on port in VLAN 12, raising, 4142

spanning-tree port ID, raising, 4849

BPDU filtering

F0/21 interface configuration, 139142

forwarding loops, 142146

overview of, 135136

policies, 146148

router and switch configuration, 136139

BPDU Guard, 128134

MST (Multiple Spanning Tree), 9394

boundary ports, 94

configuring with policies, 99106

edge ports, 94

IST (Internal Spanning Tree), 95

MSTP (Multiple Instance Spanning Tree Protocol), 96

port configuration, 96

regions, 94

switch hostname configuration, 96

trunking mode, 97

VLAN configuration, 9799

Rapid STP

initial configuration, 7677

lab setup, 7576

link type, 8385

operational enhancements of, 74

overview of, 73

port roles, 74

port states, 74

rapid convergence mechanisms, 75, 7880

rapid convergence process, demonstrating, 8083

SW2, enabling for RSTP mode, 8992

switch operation, 8589

Spanning Tree Backbone Fast, 148154

Spanning Tree Loop Guard, 162167

Spanning Tree Portfast, 106115

Spanning Tree Root Guard, 154162

UplinkFast, 115128

stubs

EIGRP (Enhanced Interior Gateway Routing Protocol)

EIGRP AS 100 configuration, 368370

eigrp stub connected option, 373374

eigrp stub option, 378379

eigrp stub receive-only option, 377378

eigrp stub redistributed option, 376377

eigrp stub static option, 375376

eigrp stub summary option, 375

redistribution, 372373

static routes, 370372

summarization, 370

topology, 368

OSPF (Open Shortest Path First), 517

configuration, 523526

default route injection, 533536

loopback interfaces on R5, 532533

loopback30 interface on R3, 522523

R1’s directly connected interfaces, 518

R2’s directly connected interfaces, 518519

R3’s directly connected interfaces, 519520

R4’s directly connected interfaces, 521523

subnets keyword, 570, 626

suboptimal paths (OSPF), 549555

Success message (CHAP), 199

summarization

EIGRP (Enhanced Interior Gateway Routing Protocol)

configuration, 325327

fixed metric for the EIGRP summary route, 327328

loopback interfaces for R1, 349350

loopback interfaces for R2, 350

loopback interfaces for R3, 351

loopback interfaces for R4, 351353

R1 configuration, 358359

R2 configuration, 353356

R3 configuration, 357358

R4 configuration, 356357

topology, 349

of internal/external networks

discard routes, 786789

external route summarization, 782786

loopback interface summarization, 778782

OSPFv3 configuration, 771778

overview of, 771

OSPF (Open Shortest Path First)

advertising networks, 468469, 472475

discard routes, 471472

external route summarization, 467468

network summarization, 470

R1 configuration, 465466

R2 configuration, 464465

R3 configuration, 463464

R4 configuration, 463

summary-address command, 783

summary-prefix command, 783

suppressing FA (forward address), 539548

SVCs (switched virtual circuits), 456457

S-VTI (static virtual tunnel interfaces), 942946

switch hostnames, 5152, 96

switch topology, 13

switched virtual circuits (SVCs), 456457

T

tables (ARP), 9. See also filtering

tagged routes, filtering, 619622

TCP/IP architecture, 78

Terminate-Ack message, 175

Terminate-Request message, 175

testing TTL propagation, 10641065

timers. See Hold timer

topologies. See logical topology; physical topology

TOS Byte field, 839

totally stubby areas (OSPF), 517

configuration, 526528

default route injection, 533536

loopback interfaces on R5, 532533

loopback30 interface on R3, 522523

R1’s directly connected interfaces, 518

R2’s directly connected interfaces, 518519

R3’s directly connected interfaces, 519520

R4’s directly connected interfaces, 521523

traceroute 3.3.3.3 command, 263

traceroute command, 613614

Traffic Indication message (NHRP), 265

Transport mode (GRE/IPSec), 940942

trunk interfaces, verifying, 1213

trunk port configuration, 5254

trunking mode, 97

tst-pool, 207

TTL propagation, testing, 10641065

tunnels

DMVPNs (dynamic multipoint virtual private networks)

DMVPN Phase 1 using dynamic mapping, 232

DMVPN Phase 1 using static mapping, 225226

DMVPN Phase 2 using dynamic mapping, 248249

DMVPN Phase 3, 259

protecting, 946952

GRE (Generic Routing Encapsulation), 504506, 513516

GRE/IPSec Tunnel mode, 937940

S-VTI (static virtual tunnel interfaces), 942946

two-way PAP authentication, 192194

Type of Services (TOS Byte) field, 839

Type-1 LSAs, 793795

Type-2 LSAs, 795

Type-4 LSAs, 539548

Type-8 LSAs, 795799

Type-9 LSAs, 799800

U

U/L (universal/local) bit, 738

unicast configuration, 317318

universal/local (U/L) bit, 738

UP phase (PPP), 177179

UplinkFast, 115128

username R4 password Cisco command, 203

V

Value field (CHAP), 199

VIRL (Virtual Internet Routing Lab), 5

virtual links

configuration, 509513

overview of, 504506

virtual local area networks. See VLANs (virtual LANs)

virtual private networks. See VPNs (virtual private networks)

Virtual Routing and Forwarding (VRF), 10911095, 11341136

Virtual-Template interface, 207

VLANs (virtual LANs)

databases, verifying, 1112

global configuration mode, 12

physical-to-logical topology lab

VLAN 12, 2324

VLAN 13, 2022

VLAN 28, 2425

VLAN 34, 2729

VLAN 45, 2930

VLAN 56, 3033

VLAN 789, 2627

STP (Spanning Tree Protocol)

MST (Multiple Spanning Tree), 9799

policies, 5964

root bridge configuration, 5659, 6567

VLAN 100, 200, 300, and 400, 5556

VLAN 500 creation, 6770

VLAN 600 creation, 7073

VPNID, 1094

VPNs (virtual private networks). See also DMVPNs (dynamic multipoint virtual private networks); IPSec VPN

BGP routing in, 11481154

EIGRP routing in, 11071113

OSPF routing in, 11131122

RIPv2 routing in, 1078

configuration between R1 and PE-2, 10961107

configuration between R7 and PE-6, 10961107

LDP configuration on core MPLS routers, 10841088

MP-BGP AS 100 configuration on R2 to R6, 10881090

OSPF configuration on core MPLS routers, 10811083

RDs (route distinguishers), 10911095

RTs (route targets), 10911095

topology, 10791081

VRF (Virtual Routing and Forwarding), 10911095

VRF (Virtual Routing and Forwarding), 10911095, 11341136

vrf definition command, 1091

W-X-Y-Z

weight attribute (BGP), 686695

Wide Metric support (EIGRP), 341342

Wireshark, 190

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.143.25.144