Professional Documents
Culture Documents
S105684GC11 Ag Lab05
S105684GC11 Ag Lab05
Overview
In this lab, you will interconnect two VCNs in the same region that have overlapping IPv4 CIDR
blocks. The Dynamic Routing Gateway (DRG) will be used because the Local Peering Gateway
does not allow peering two VCNs that have overlapping CIDRs. The DRG does allow the
attachment of two VCNs with overlapping CIDRs.
The objective is to bypass the IPv4 CIDR block overlap limitation and be able to communicate
two compute instances, one in each VCN, with each other without changing the VMs IPv4
private addresses. These two VMs should be able to communicate privately via the DRG with
IPv6. Ping6 will be used for testing the success of the lab.
For this, the VCNs, subnets, and compute instances’ vNICs need to be enabled for IPv6
addressing.
In addition, the compute instances’ internal OS firewall needs to be configured for IPv6. After
enabling IPv6 on all OCI components that require it, you will SSH to both VMs and run the
following commands:
60 Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment
Set up environment: Create VCNs and instances
As a prerequisite for this lab, you’ll first build two VCNs in the same region and in the same
compartment. They must have an overlapping IPv4 CIDRs (10.0.0.0/16) with a public subnet
in each VCN, with access to the internet. It also requires two compute instances, one in each
subnet.
Two VCNs:
Names: IAD–AP–LAB05-1–VCN–01, IAD–AP–LAB05-1–VCN–02
CIDR Block: 10.0.0.0/16
Public Subnet
CIDR Block: 10.0.0.0/24
3. Make sure that under the Compartments field you select the correct compartment.
a. Name: IAD–AP–LAB05-1–VCN–01
5. Click Create VCN. The VCN will open. Click Create Subnet and fill in the fields:
a. Name: IAD-AP-LAB05-1-VCN-01-SNT-01
Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment 61
c. IPv4 CIDR block: 10.0.0.0/24
7. Under Resources in the left navigation pane, click Internet Gateways. Click Create
Internet Gateway, and fill in the fields:
a. Name: IAD-AP-LAB05-1-VCN-01-IG-01
b. Make sure that the compartment is the same one as the VCN compartment.
9. Under Resources in the left navigation pane, click Route Tables. Click Default Route
Table for IAD–AP–LAB05-1–VCN–01.
The Route Table screen will remain open after the rule is configured. This completes this VCN.
Now you’ll create the second VCN. In the breadcrumbs link at the top left, click Virtual Cloud
Networks.
1. Make sure that under the Compartments field you select the correct compartment.
a. Name: IAD–AP–LAB05-1–VCN–02
62 Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment
c. Leave all other fields as they are
3. Click Create VCN. The VCN will open. Click Create Subnet and fill in the fields:
a. Name: IAD-AP-LAB05-1-VCN-02-SNT-01
5. Under Resources in the left navigation pane, click Internet Gateways. Click Create
Internet Gateway, and fill in the fields:
a. Name: IAD-AP-LAB05-1-VCN-02-IG-01
b. Make sure that the compartment is the same one as the VCN compartment.
7. Under Resources in the left navigation pane, click Route Tables. Click Default Route
Table for IAD–AP–LAB05-1–VCN–02.
2. Make sure that under the Compartments field you select the correct compartment.
Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment 63
3. Click Create Instance, and fill in the fields:
a. Name: IAD–AP–LAB05-1–VM–01
b. In the Create in compartment picklist make sure that you select the correct
compartment.
c. Placement: AD1
e. For Shape, click Change Shape. Click Ampere, and select VM.Standard.A1.Flex with
1 OCPU and 6 GB .
4. Under Networking, click Select existing virtual cloud network and choose IAD–AP–
LAB05-1–VCN–01.
7. Under Add SSH keys, proceed with the best option for you.
9. Click Create.
This completes the first instance. Now, you’ll create the second one. In the breadcrumbs link to
the top left click Instances.
2. Make sure that under the Compartments field you select the correct compartment.
a. Name: IAD–AP–LAB05-1–VM–02
64 Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment
b. In the Create in compartment picklist make sure that you select the correct
compartment
c. Placement: AD2
e. For Shape, click Change Shape. Click Ampere, and select VM.Standard.A1.Flex with
1 OCPU and 6 GB .
4. Under Networking, click Select existing virtual cloud network and choose IAD–AP–
LAB05-1–VCN–02.
7. Under Add SSH keys, proceed with the best option for you.
9. Click Create.
Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment 65
Enable IPv6 on virtual cloud networks and subnets
Tasks
5. Under IPv6 Prefixes, check the Assign an Oracle allocated IPv6 /56 prefix checkbox
11. Check the Assign an Oracle allocated IPv6 /64 prefix checkbox.
12. Complete the IPv6 CIDR prefix by entering two hexadecimal digits between 00 and FF –
for example, 7E.
14. Repeat steps 2-13 for IAD-AP-LAB05-1-VCN-02 and add the subnet IAD-AP-LAB05-1-
VCN-02-SNT-01.
66 Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment
Enable IPv6 on compute instances
Tasks
4. Click IAD-AP-LAB05-VM-01.
8. Click Assign.
9. SSH to IAD-AP-LAB05-VM-01 (use the provided private SSH Key) using the public IP
address.
Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment 67
Create a dynamic routing gateway and attach the VCNs
Tasks
1. In the main menu, in Networking and Customer Connectivity, click Dynamic Routing
Gateway.
3. Name it IAD-AP-LAB05-1-DRG-01.
6. Name it IAD-AP-LAB05-1-VCN-01-ATCH.
9. Name it IAD-AP-LAB05-1-VCN-02-ATCH.
10. From the Select a Virtual Cloud Network list, select IAD-AP-LAB05-1-VCN-02.
14. Notice how there is an IPv4 conflict, and how IPv6 is fine.
15. Under Destination CIDR, copy into memory or notepad the IPv6 CIDR prefixes, making
sure you keep track to which VCN each one corresponds.
68 Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment
Add route rules to both VCNs’ route tables
Tasks
8. In the Destination CIDR Block field, enter the VCN-2 IPv6 CIDR prefix you copied in step
15 of the previous task (Create a dynamic routing gateway and attach the VCNs).
10. Repeat steps 2-9 for VCN-02 with the appropriate route table and IPv6 CIDR prefixes.
Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment 69
Add route rules to both VCNs’ security lists
11. In the Source CIDR field, enter the VCN-02 IPv6 CIDR prefix you copied in step 15 of the
previous task, Create a dynamic routing gateway, and attach the VCNs.
70 Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment
Test your configuration
3. Repeat steps 1 and 2 for your IAD–AP–LAB05-1–VM–02 compute instance and ping6 IAD–
AP–LAB05-1–VM–02.
Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment 71
Copyright © 2023, Oracle and/or its affiliates.
72 Virtual Cloud Network (VCN): Use IPv6 as a tool to overcome VCN IPv4 CIDR overlaps in a private environment