10.advanced OSPF Topics Part I

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 9

Cisco CCNP ROUTE Training

Instructor: Joe Rinehart, CCIE #14256


Advanced OSPF
Topics Part I
Cisco CCNP ROUTE Training
Advanced OSPF Topics
In This Lesson:
OSPF Authentication
OSPF Network Types
OSPF Area Types
Default Routes
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Authentication
1. Understanding OSPF Authentication
2. Configuring OSPF Authentication
3. Verifying OSPF Authentication
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Authentication
Understanding OSPF Authentication
What OSPF Neighbor Authentication
Provides
Restricting what devices may form
neighbor relationships
Authentication of all messages sent
between configured peers
Prevents denial of service type attacks
What OSPF Neighbor Authentication Does
Not Provide
Encryption of traffic between
neighbors
Any type of data privacy
Frame Relay
WAN
607
706
R6
R7 R8
608
806
708
807
OSPF
Area 0
Key
Myospfkey
(MD5 or Text)
MATCH
Key
Myospfkey
(MD5 or Text)
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Authentication
Understanding OSPF Authentication
How OSPF Neighbor Authentication
Operates
Three modes supported:
Type 0 (no authentication)
Type 1 (clear text authentication)
Type 2 (MD5 authentication)
Preshared key configured on
neighbors
Authentication completed on a per-
interface basis
Parameters can be set per area also
Frame Relay
WAN
607
706
R6
R7 R8
608
806
708
807
OSPF
Area 0
Key
Myospfkey
(MD5 or Text)
MATCH
Key
Myospfkey
(MD5 or Text)
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Authentication
Configuring OSPF Authentication
Defining OSPF Preshared Keys
For plain text, Keys are defined using
the ip ospf authentication-key
<string> interface subcommand
For MD5, Keys are defined using the
ip ospf message-digest-key <key
#> md5 <string> interface
subcommand
Activating OSPF Authentication
For plain text, use the ip ospf
authentication interface
subcommand
Frame Relay
WAN
607
706
R6
R7 R8
608
806
708
807
OSPF
Area 0
Key
Myospfkey
(MD5 or Text)
MATCH
Key
Myospfkey
(MD5 or Text)
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Authentication
Configuring OSPF Authentication
Activating OSPF Authentication
For MD5, use the ip ospf
authentication message-digest
interface subcommand
Configuring settings per area are
accomplished as follows:
For plain text, use the area
<area#> authentication command
in ospf router configuration mode
For plain text, use the area
<area#> authentication
message-digest command in ospf
router configuration mode
Frame Relay
WAN
607
706
R6
R7 R8
608
806
708
807
OSPF
Area 0
Key
Myospfkey
(MD5 or Text)
MATCH
Key
Myospfkey
(MD5 or Text)
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Authentication
Verifying OSPF Authentication
Verify Neighbor Relationships are Up and
Functioning
show ip ospf interfaces should list
active peers (non-zero)
show ip ospf neighbors should
show all the expected neighbors
debug ip ospf adj can display
neighbor exchange messages for
troubleshooting purposes
Setting NTP can assist in clock
synchronization
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Network Types
1. Understanding OSPF Network Types
2. Configuring OSPF Network Types
3. Verifying OSPF Network Types
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Network Types
Understanding OSPF Network Types
OSPF Defines Differing Network Types
that Specify Neighbor Behaviors:
Discovery of neighbors by multicast
hello or manual configuration
Whether or not a DR/BDR will be
elected on the segment
If one or more neighbor is involved
Configuration is on a Per-Interface Basis
ip ospf network <type> command
Each network type creates different
impacts on configuration
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Network Types
Understanding OSPF Network Types
Broadcast Network Type:
Discovers neighbors by multicast hello
Elects a DR/BDR on the segment
Sends hello packets every 10 seconds
Multiple neighbors permitted
Point-to-Point Network Type:
Discovers neighbors by multicast hello
Does not elect a DR/BDR
Sends hello packets every 10 seconds
Only one other neighbor permitted
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Network Types
Understanding OSPF Network Types
Broadcast Network Type:
Discovers neighbors by multicast hello
Elects a DR/BDR on the segment
Sends hello packets every 10 seconds
Multiple neighbors permitted
Nonbroadcast Network Type:
Requires manual neighbor
configuration
Elects a DR/BDR on the segment
Sends hello packets every 30 seconds
Multiple neighbors permitted
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Network Types
Understanding OSPF Network Types
Point-to-Multipoint Network Type:
Discovers neighbors by multicast hello
Elects a DR/BDR on the segment
Sends hello packets every 30 seconds
Multiple neighbors permitted
Point-to-Multipoint Nonbroadcast
Network Type:
Requires manual neighbor
configuration
Elects a DR/BDR on the segment
Sends hello packets every 30 seconds
Multiple neighbors permitted
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Network Types
Configuring OSPF Network Types
Configured Per-Interface using the ip
ospf network <type> command
Verifying OSPF Network Types
Verify Neighbor Relationships are Up and
Functioning
show ip ospf should list configured
areas including SPF and LSA data
show ip ospf interfaces should
show the expected network types
Show ip ospf border-routers can
display information on area ABRs
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Area Types
1. Understanding OSPF Area Types
2. Configuring OSPF Area Types
3. Verifying OSPF Area Types
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Area Types
Understanding OSPF Area Types
OSPF Has Several Unique Area Types
Backbone Area (Area 0)
In single area OSPF networks the
area number can be any integer
Serves as the transit area for all areas
Accepts LSA types 1-5
Normal/Standard Area (default)
Default area type
Serves as the transit area for all areas
Accepts accept intra-area, inter-area
and external routes
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Area Types
Understanding OSPF Area Types
OSPF Has Several Unique Area Types
Stub Area
Configured using the area <area#>
stub command
Accepts LSA types 1-4
Does not accept LSA type 5 (external
routes)
Default route generated for external
destinations
Stub area cannot be a backbone area,
use virtual-links or have an ASBR
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Area Types
Understanding OSPF Area Types
OSPF Has Several Unique Area Types
Totally Stubby Area
Configured using the area <area#>
stub no-summary command
Accepts LSA types 1-2
Does not accept LSA type 3,4 and 5
(inter-area and external routes)
Default route generated for all
destinations outside the area
Also usable for branch offices not
needing awareness of every prefix in
the network
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Area Types
Understanding OSPF Area Types
OSPF Has Several Unique Area Types
No So Stubby Area (NSSA)
Configured using the area <area#>
nssa [no-summary] command
Accepts LSA types 1-2
Allows one or more routers in the
area to act in the role of ASBR
Allows for external routes using LSA
type 7 that must be converted to LSA
type 5 at the NSSA ABR
Totally stubby option also available
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Area Types
Configuring OSPF Area Types
Stub: Configured Per-Area using the
area <type> stub command on each
router in the stub area
Totally Stubby: Configured Per-Area
using the area <type> stub no-
summary command on each router in
the stub area
NSSA/Totally NSSA: Configured Per-
Area using the area <type> nssa [no-
summary] command on each router in
the nssa area
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
OSPF Area Types
Verifying OSPF Area Types
Verify Neighbor Relationships are Up and
Functioning
show ip ospf should list configured
area types
show ip protocols should also list
the various area types in the output
show ip route ospf should list active
OSPF routes including N1, N2,
stub/totally stubby area default routes
show ip ospf nssa-external should
display NSSA data
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
Default Routes
1. Understanding Default Routing
2. Configuring Default Routing
3. Verification of Default Routing
Cisco CCNP ROUTE Training
Advanced OSPF Topics
Default Routes
Understanding Default Routing
General Purposes for a Default Route
Communicates path to other networks
in host routing (discussed earlier)
Designates the path within an
enterprise to one or more routers
connected to the Internet
Creates very simple routing
configuration for stub networks
Mathematical Significance of the Default
Route
The opposite of 255.255.255.255
Designates the most general prefix
possible (any)
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
Default Routes
Configuring Default Routing
Static Route Configuration
Configure one or more default routes
using the command ip route 0.0.0.0
0.0.0.0 <next-hop> <metric>
Floating static routes can be created
to build backup default routes
ip route 0.0.0.0 0.0.0.0 <next-
hop> 2 (primary route)
ip route 0.0.0.0 0.0.0.0 <next-
hop> 250 (secondary route)
Importing the Route Into OSPF
Using redistribute static/default-
information originate commands
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
Default Routes
Verification of Default Routing
Verify Existence of OSPF Default Route
show ip route ospf should list route
0.0.0.0/0
show ip route 0.0.0.0 should list
route details (E1/E2 route)
show ip ospf database will list
entire topology table, look for
network 0.0.0.0/0
show ip ospf border-routers will
list ABR and ASBR information
Use ping and trace to a public IP
address to verify routing to/from the
device
Frame Relay
WAN
607
706
VLAN 79
VLAN 910
R6
R7 R8
R10 R9
608
806
708
807
OSPF
Area 0
OSPF
Area 79
OSPF
Area 8
(Stub)
OSPF
Area 910
Backbone
Cisco CCNP ROUTE Training
Advanced OSPF Topics
Key Terms You Should Know
Message-digest Also referred to as OSPF authentication type
2, which requires use of an MD5 hash of a preshared key to
authenticate packets sent between neighbor routers
Broadcast OSPF network type in which neighbors are
discovered through hello messages and a DR/BDR is elected
Point-to-Point OSPF network type which neighbors are
discovered through hello messages and only two are permitted
Stub Area Special OSPF area type in which all external routes
are not permitted (LSA Type 5)
Totally Stubby Area Special OSPF area type in which only
area routes are permitted and a default route represents others
NSSA Not-So-Stubby-Area, a special OSPF area type that
permits redistribution of external routes using LSA Type 7 which
are translated to LSA Type 5 by the ABR
Cisco CCNP ROUTE Training
Advanced OSPF Topics
What We Covered
OSPF Authentication
OSPF Network Types
OSPF Area Types
Default Routes

You might also like