<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Interface on Aaron&#39;s Worthless Words</title>
    <link>https://a996c8ee.aww-3cz.pages.dev/tags/interface/</link>
    <description>Recent content in Interface on Aaron&#39;s Worthless Words</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Sat, 02 Mar 2013 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://a996c8ee.aww-3cz.pages.dev/tags/interface/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Junos - Logical Tunnel Interfaces with Virtual Routers</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2013/03/junos-logical-tunnel-interfaces-with-virtual-routers/</link>
      <pubDate>Sat, 02 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2013/03/junos-logical-tunnel-interfaces-with-virtual-routers/</guid>
      <description>&lt;p&gt;There are a few ways to leak routes in and out of virtual routers in Junos. On the list is a cool feature called the logical tunnel interface.&lt;/p&gt;&#xA;&lt;p&gt;So, what am I talking about?  One way to separate traffic on a router is to use virtual routers (VRs) so that you wind up with multiple routing tables on the same router.  This separate traffic, but you will usually (read: always) have a demand to get traffic from one VR to another.  There are a few different way to do that (see rib-group, instance-import, next-table, et al.), but one really cool way to do it is through logical tunnel interfaces.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Exercises with IPv6 ACLs</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2011/04/some-exercises-with-ipv6-acls/</link>
      <pubDate>Fri, 15 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2011/04/some-exercises-with-ipv6-acls/</guid>
      <description>&lt;p&gt;ACLs in IPv6 aren&amp;rsquo;t that different from what you&amp;rsquo;re used to dealing with in the IPv4 world.  You create a list of denies and permits for use with some other structure like filtering, PBR, and all sorts of other stuff.  Let&amp;rsquo;s take a look at building an ACL and filtering traffic with it.&lt;/p&gt;&#xA;&lt;p&gt;For those playing at home, here&amp;rsquo;s the setup I used to generate the configs and get the output.  Execute some click action for the whole thing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Stubby Post - What&#39;s an IDB?</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2010/09/stubby-post-whats-an-idb/</link>
      <pubDate>Fri, 03 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2010/09/stubby-post-whats-an-idb/</guid>
      <description>&lt;p&gt;I &lt;a href=&#34;http://twitter.com/aconaway/status/22554005934&#34;&gt;posed the philosophical question&lt;/a&gt; on Twitter the other day asking if single trunk links should be in an EtherChannel bundle just in case you need to expand later.  I didn&amp;rsquo;t really expect an answer, but the ever-verbose &lt;a href=&#34;http://twitter.com/WannabeCCIE&#34;&gt;@WannabeCCIE&lt;/a&gt; pointed out (in not so many words) that you should watch your IDBs.  What is that?&lt;/p&gt;&#xA;&lt;p&gt;That&amp;rsquo;s an &lt;a href=&#34;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_tech_note09186a0080094322.shtml&#34;&gt;interface descriptor block&lt;/a&gt;.  I admit that I&amp;rsquo;m not intimately familiar with them, bu they&amp;rsquo;re data structs in IOS used to keep track of the interfaces on that device.  They come in two flavors - hardware and software.  HWIDBs usually represent a physical interface but they also represent tunnels, SVIs, PortChannels, subinterfaces, and any other virtual interface that you can configure.  The SWIDBs represent the layer-2 encapsulation of each HWIDB, so you&amp;rsquo;ll see entries talking about Ethernet, HDLC, PPP, etc.  That means that every interface you have on a router consumes two IDBs (there are always exceptions).  That&amp;rsquo;s important because each platform and IOS version combination has a limit to the number IDBs that device supports.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ONT Notes - AutoQoS</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2010/02/ont-notes-autoqos/</link>
      <pubDate>Wed, 10 Feb 2010 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2010/02/ont-notes-autoqos/</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;AutoQoS benefits&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Automates QoS for most deployments&lt;/li&gt;&#xA;&lt;li&gt;Protects business-critical apps to maximize availability&lt;/li&gt;&#xA;&lt;li&gt;Simplifies QoS deployments&lt;/li&gt;&#xA;&lt;li&gt;Reduces configuration errors&lt;/li&gt;&#xA;&lt;li&gt;Cheaper, faster, and simpler deployments&lt;/li&gt;&#xA;&lt;li&gt;Follows DiffServ&lt;/li&gt;&#xA;&lt;li&gt;Allows complete control over QoS configs&lt;/li&gt;&#xA;&lt;li&gt;Allows modification of auto-generated configs&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;AutoQoS phases of evolution&#xA;&lt;ul&gt;&#xA;&lt;li&gt;AutoQoS VOIP - Early version that configures the basics without discovery&lt;/li&gt;&#xA;&lt;li&gt;AutoQoS for Enterprise - Second version that only runs on routers and uses two-step process&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Autodiscovery using NBAR&lt;/li&gt;&#xA;&lt;li&gt;Generation of class maps&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;AutoQoS key elements&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Application classification&lt;/li&gt;&#xA;&lt;li&gt;Policy generation&lt;/li&gt;&#xA;&lt;li&gt;Configuration&lt;/li&gt;&#xA;&lt;li&gt;Monitoring and reporting&lt;/li&gt;&#xA;&lt;li&gt;Consistency&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Interfaces that you can configure AutoQoS on&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Serial ifs with PPP and HDLC&lt;/li&gt;&#xA;&lt;li&gt;FR point-to-point subifs (NOT multipoint)&lt;/li&gt;&#xA;&lt;li&gt;ATM point-to-point subifs&lt;/li&gt;&#xA;&lt;li&gt;FR-to-ATM links&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Prerequsites&#xA;&lt;ul&gt;&#xA;&lt;li&gt;No Qos policy already configured on if&lt;/li&gt;&#xA;&lt;li&gt;CEF enabled on if&lt;/li&gt;&#xA;&lt;li&gt;Correct bandwidth configured on if&lt;/li&gt;&#xA;&lt;li&gt;IP address on low-speed if&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Configuring AutoQoS Enterprise on a router (NOT a switch)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;auto qos discovery&lt;/strong&gt; - begins discovery process&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;auto qos&lt;/strong&gt; - generates and applies MQC-based policies&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Configuring AutoQoS VOIP&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;auto qos voip [ trust | cisco-phone ]&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Verifying AutoQoS on router&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;show auto discovery qos&lt;/strong&gt; - get autodiscovery results&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;show auto qos&lt;/strong&gt; - examine configuration generated&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Number of classes&lt;/li&gt;&#xA;&lt;li&gt;Classification options&lt;/li&gt;&#xA;&lt;li&gt;Marking options&lt;/li&gt;&#xA;&lt;li&gt;Queuing mechanisms&lt;/li&gt;&#xA;&lt;li&gt;Other QoS mechanisms&lt;/li&gt;&#xA;&lt;li&gt;If, subif, PVC where policy is applied&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;show policy-map interface&lt;/strong&gt; - look at if stats&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Verify AutoQoS VOIP&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;show auto qos&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;show policy-map interface&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;show mls qos maps&lt;/strong&gt; - shows CoS to DSCP mappings&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Possible issues with AutoQoS&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Too many traffic classes - manually consolidate some&lt;/li&gt;&#xA;&lt;li&gt;Configuration doesn&amp;rsquo;t change - rerun AutoQoS&lt;/li&gt;&#xA;&lt;li&gt;Configuration may not fit your situation - fine-tune it by hand&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Fine-tuning AutoQoS&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Use QPM&lt;/li&gt;&#xA;&lt;li&gt;CLI&lt;/li&gt;&#xA;&lt;li&gt;copy policy into editor, change, reapply&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;AutoQoS can match on characteristics besides ACLs and NBAR&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;match input interface&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;match cos&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;match ip precedence&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;match ip dscp&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;match ip rtp&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
    <item>
      <title>ONT Notes - Pre-classify and End-to-end QoS</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2010/02/ont-notes-pre-classify-and-end-to-end-qos/</link>
      <pubDate>Thu, 04 Feb 2010 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2010/02/ont-notes-pre-classify-and-end-to-end-qos/</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;VPNs (Didn&amp;rsquo;t ISCW cover this?)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Provide&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Confidentiality&lt;/li&gt;&#xA;&lt;li&gt;Integrity&lt;/li&gt;&#xA;&lt;li&gt;Authentication&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Types&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Remote-access&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Client-initiated&lt;/li&gt;&#xA;&lt;li&gt;NAS-initiated&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Site-to-site&#xA;&lt;ul&gt;&#xA;&lt;li&gt;LAN-to-LAN&lt;/li&gt;&#xA;&lt;li&gt;Extranet&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;L3 Tunneling protocols&#xA;&lt;ul&gt;&#xA;&lt;li&gt;GRE&lt;/li&gt;&#xA;&lt;li&gt;IPSec&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Pre-classify allows traffic to be classified before being sent across a tunnel or crypto-ed.&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;em&gt;qos pre-classify&lt;/em&gt;&lt;/li&gt;&#xA;&lt;li&gt;Provides a view into the original IP headers&lt;/li&gt;&#xA;&lt;li&gt;To classify on pre-tunnel header, apply the policy to the tunnel interface WITHOUT pre-classify.&lt;/li&gt;&#xA;&lt;li&gt;To classify on post-tunnel header, apply the policy to the physical interface WITHOUT pre-classify.&lt;/li&gt;&#xA;&lt;li&gt;To classify on pre-tunnel header, apply the policy to the physical interface WITH pre-classify.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;SLA - agreement with provider to guarantee QoS mechanisms across their network based on your markings.&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Assures availability, loss, throughput, delay, and jitter.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;End-to-end QoS&#xA;&lt;ul&gt;&#xA;&lt;li&gt;To be effective, each hop in the path must have QoS configured similarly.&lt;/li&gt;&#xA;&lt;li&gt;Necessary in three locations&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Campus - within the customer network&lt;/li&gt;&#xA;&lt;li&gt;The edges - customer facing the provider, provider facing customer&lt;/li&gt;&#xA;&lt;li&gt;On the provider network&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;QoS tasks&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Campus access switches&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Speed/duplex settings&lt;/li&gt;&#xA;&lt;li&gt;Classification&lt;/li&gt;&#xA;&lt;li&gt;Trust&lt;/li&gt;&#xA;&lt;li&gt;Phone/access switch configs&lt;/li&gt;&#xA;&lt;li&gt;Multiple queues on switch ports, including priority for VOIP&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Campus distribution&#xA;&lt;ul&gt;&#xA;&lt;li&gt;L3 policing and marking&lt;/li&gt;&#xA;&lt;li&gt;Multiple queues on switch ports, including priority for VOIP&lt;/li&gt;&#xA;&lt;li&gt;WRED&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;WAN edge&#xA;&lt;ul&gt;&#xA;&lt;li&gt;SLA definitions&lt;/li&gt;&#xA;&lt;li&gt;LLQ&lt;/li&gt;&#xA;&lt;li&gt;LFI&lt;/li&gt;&#xA;&lt;li&gt;WRED&lt;/li&gt;&#xA;&lt;li&gt;Shaping&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Provider cloud&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Capacity planning&lt;/li&gt;&#xA;&lt;li&gt;PHB&lt;/li&gt;&#xA;&lt;li&gt;LLQ&lt;/li&gt;&#xA;&lt;li&gt;WRED&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Enterprise campus QoS implementation&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Implement multiple queues to avoid congestion&lt;/li&gt;&#xA;&lt;li&gt;Assign VOIP and video to highest priority queue&lt;/li&gt;&#xA;&lt;li&gt;Esablish trust boundaries&lt;/li&gt;&#xA;&lt;li&gt;Use policing to rate-limit excess traffic&lt;/li&gt;&#xA;&lt;li&gt;Use hardware QoS when possible&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Control Plane Policing (CoPP)&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Applies QoS policy to traffic destined for the router&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Routing protocols&lt;/li&gt;&#xA;&lt;li&gt;Management protocols&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Can be used to avoid DOS attacks&lt;/li&gt;&#xA;&lt;li&gt;Applied to &lt;em&gt;control-plane&lt;/em&gt; in global config&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;</description>
    </item>
  </channel>
</rss>
