Wednesday, February 26, 2020

Redistributing Routing Protocols

 

Prerequisites:

  • GNS3 (in my case, the last release GNS3 1.1)
  • Cisco c3725-adventerprisek9-mz124-25.image
    See if your version support IPSEC -
    Cisco Feature Navigator : http://tools.cisco.com/ITDIT/CFN/

  • VPC : for PC1 (30000 / 127.0.0.1 / 20000) & PC2 (30001 / 127.0.0.1 / 20001)
1
Architecture

 IPsec ESP Architecture

2
Explication

 

Objectif : To send L2 traffic over Internet, to have VLAN-to-VLAN connection between multi-sites with:

  • Encapsulation
  • Authentication
  • Encryption

ISP Network components :

  • BackBone Network (Two routers - Casa & Rabat - with Frame-Relay & OSPF area0 Technologies).
  • Inter-City Network (One router by city - Tanger & Marrakech in our case, with Frame-Relay & OSPF area2224 & area3739 technologies).
  • Intar-City Network (One router by zone - TangerMed & CenterMrk in our case, with Ethernet & EIGRP technologies).

Customer Network :

3
Configuration de l'adressage

 

3.1. Configuration du Frame-Relay :

We will configure the Frame-Relay in point-to-point mode:

3.1.1. Configuration of the FR Switch:

Right Clic, and 

DLCI Configuration: (Marrakech ==> Casa ==> Rabat ==> Tanger)

Port 1 Marrakech Marrakech ==> Casa 1:102
Port 2 Casa

Casa ==> Marrakech
Casa ==> Rabat 

2:201
2:203 
Port 3 Rabat Rabat ==> Casa
Rabat ==> Tanger
3:302
3:304 
Port 4 Tanger Tanger ==> Rabat 4:403

 

FR Cfg

3.1.2. Routers Configuration:

Marrakech Router connected to Switch FR Port 1

Marrakech(Config)#interface Serial0/0
Marrakech(Config-if)#no ip address 
Marrakech(Config-if)#encapsulation frame-relay
Marrakech(Config-if)#serial restart-delay 0
Marrakech(Config-if)#no shutdown 
Marrakech(Config-if)#exit 
Marrakech(Config)#interface Serial0/0.12 point-to-point
Marrakech(Config-if)#ip address 10.1.1.1 255.255.255.252
Marrakech(Config-if)#frame-relay interface-dlci 102
Marrakech(Config-if)#exit

Casa Router connected to Switch FR Port 2

Casa(Config)#interface Serial0/0
Casa(Config-if)#no ip address 
Casa(Config-if)#encapsulation frame-relay
Casa(Config-if)#serial restart-delay 0
Casa(Config-if)#no shutdown 
Casa(Config-if)#exit 
Casa(Config)#interface Serial0/0.21 point-to-point
Casa(Config-if)#ip address 10.1.1.2 255.255.255.252
Casa(Config-if)#frame-relay interface-dlci 201
Casa(Config-if)#exit
Casa(Config-if)#interface Serial0/0.23 point-to-point
Casa(Config-if)#ip address 10.1.1.5 255.255.255.252
Casa(Config-if)#frame-relay interface-dlci 203

Rabat Router connected to Switch FR Port 3

Rabat(Config)#interface Serial0/0
Rabat(Config-if)#no ip address 
Rabat(Config-if)#encapsulation frame-relay
Rabat(Config-if)#serial restart-delay 0
Rabat(Config-if)#no shutdown 
Rabat(Config-if)#exit 
Rabat(Config)#interface Serial0/0.32 point-to-point
Rabat(Config-if)#ip address 10.1.1.6 255.255.255.252
Rabat(Config-if)#frame-relay interface-dlci 302
Rabat(Config-if)#exit
Rabat(Config-if)#interface Serial0/0.34 point-to-point
Rabat(Config-if)#ip address 10.1.1.9 255.255.255.252
Rabat(Config-if)#frame-relay interface-dlci 304

Tanger Router connected to Switch FR Port 4

Tanger(Config)#interface Serial0/0
Tanger(Config-if)#no ip address 
Tanger(Config-if)#encapsulation frame-relay
Tanger(Config-if)#serial restart-delay 0
Tanger(Config-if)#no shutdown 
Tanger(Config-if)#exit 
Tanger(Config)#interface Serial0/0.43 point-to-point
Tanger(Config-if)#ip address 10.1.1.10 255.255.255.252
Tanger(Config-if)#frame-relay interface-dlci 403
Tanger(Config-if)#exit
3.2. Configuration IP au niveau du Routeur Tanger :
Tanger(Config)#interface Fastethernet0/0
Tanger(Config-if)#ip address 10.1.39.1 255.255.255.252
Tanger(Config-if)#no shutdown 
Tanger(Config-if)#exit 
3.3. Configuration IP au niveau du Routeur Marrakech :
Marrakech(Config)#interface Fastethernet0/0
Marrakech(Config-if)#ip address 10.1.24.1 255.255.255.252
Marrakech(Config-if)#no shutdown 
Marrakech(Config-if)#exit 
3.4. Configuration IP au niveau du Routeur TangerMed :
TangerMed(Config)#interface Fastethernet0/0
TangerMed(Config-if)#ip address 10.1.39.2 255.255.255.252
TangerMed(Config-if)#no shutdown 
TangerMed(Config-if)#exit 
TangerMed(Config)#interface Serial0/0
TangerMed(Config-if)#ip address 209.65.39.1 255.255.255.252
TangerMed(Config-if)#no shutdown 
TangerMed(Config-if)#exit 
3.5. Configuration IP au niveau du Routeur CentreMrk :
CentreMrk(Config)#interface Fastethernet0/0
CentreMrk(Config-if)#ip address 10.1.24.2 255.255.255.252
CentreMrk(Config-if)#no shutdown 
CentreMrk(Config-if)#exit 
CentreMrk(Config)#interface Serial0/0
CentreMrk(Config-if)#ip address 209.65.24.1 255.255.255.252
CentreMrk(Config-if)#no shutdown 
CentreMrk(Config-if)#exit 
3.6. Configuration IP au niveau du Routeur AgenceVoyage :
AgenceVoyage(Config)#interface Fastethernet0/0
AgenceVoyage(Config-if)#ip address 192.168.24.1 255.255.255.0
AgenceVoyage(Config-if)#no shutdown 
AgenceVoyage(Config-if)#exit 
AgenceVoyage(Config)#interface Serial0/0
AgenceVoyage(Config-if)#ip address 209.65.24.2 255.255.255.252
AgenceVoyage(Config-if)#no shutdown 
AgenceVoyage(Config-if)#exit 
3.7. Configuration IP au niveau du Routeur AgencePort :
AgencePort(Config)#interface Fastethernet0/0
AgencePort(Config-if)#ip address 192.168.39.2 255.255.255.0
AgencePort(Config-if)#no shutdown 
AgencePort(Config-if)#exit 
AgencePort(Config)#interface Serial0/0
AgencePort(Config-if)#ip address 209.65.39.2 255.255.255.252
AgencePort(Config-if)#no shutdown 
AgencePort(Config-if)#exit 
3.8. Configuration IP au niveau du Switch SWMrkt :
SWMrkt(Config)#interface Vlan 1
SWMrkt(Config-if)#ip address 192.168.24.200 255.255.255.0
SWMrkt(Config-if)#no shutdown 
SWMrkt(Config-if)#exit 
3.9. Configuration IP au niveau du Switch SWPort :
SWPort(Config)#interface Vlan 1
SWPort(Config-if)#ip address 192.168.39.200 255.255.255.0
SWPort(Config-if)#no shutdown 
SWPort(Config-if)#exit 
3.10. Configuration IP au niveau du PC1 :
PC1[C:\>]ip 192.168.24.20/24 192.168.24.1
3.11. Configuration IP au niveau du PC2 :
PC2[C:\>]ip 192.168.39.20/24 192.168.39.1
4
Routing Configuration

 

4.1. OSPF
4.1.1. Casa Router
Casa(Config)#interface Loopback2
Casa(Config-if)#ip address 2.2.2.2 255.255.255.255
Casa(Config-if)#exit 
Casa(Config)#router ospf 10
Casa(Config-router)#router-id 2.2.2.2
Casa(Config-router)#log-adjacency-changes 
Casa(Config-router)#area 2224 nssa no-summary 
Casa(Config-router)#network 2.2.2.2 0.0.0.0 area 0
Casa(Config-router)#network 10.1.1.4 0.0.0.3 area 0
Casa(Config-router)#network 10.1.1.0 0.0.0.3 area 2224
Casa(Config-router)#exit 
4.1.2. Rabat Router
Rabat(Config)#interface Loopback3
Rabat(Config-if)#ip address 3.3.3.3 255.255.255.255
Rabat(Config-if)#exit 
Rabat(Config)#router ospf 10
Rabat(Config-router)#router-id 3.3.3.3
Rabat(Config-router)#log-adjacency-changes 
Rabat(Config-router)#area 3739 nssa no-summary 
Rabat(Config-router)#network 3.3.3.3 0.0.0.0 area 0
Rabat(Config-router)#network 10.1.1.4 0.0.0.3 area 0
Rabat(Config-router)#network 10.1.1.8 0.0.0.3 area 3739
Rabat(Config-router)#exit 
4.1.3. Marrakech Router
Marrakech(Config)#interface Loopback1
Marrakech(Config-if)#ip address 1.1.1.1 255.255.255.255
Marrakech(Config-if)#exit 
Marrakech(Config)#router ospf 10
Marrakech(Config-router)#router-id 1.1.1.1
Marrakech(Config-router)#log-adjacency-changes 
Marrakech(Config-router)#area 2224 nssa
Marrakech(Config-router)#network 1.1.1.1 0.0.0.0 area 2224
Marrakech(Config-router)#network 10.1.1.0 0.0.0.3 area 2224
Marrakech(Config-router)#exit 
4.1.4. Tanger Router
Tanger(Config)#interface Loopback4
Tanger(Config-if)#ip address 4.4.4.4 255.255.255.255
Tanger(Config-if)#exit 
Tanger(Config)#router ospf 10
Tanger(Config-router)#router-id 4.4.4.4
Tanger(Config-router)#log-adjacency-changes 
Tanger(Config-router)#area 3739 nssa
Tanger(Config-router)#network 4.4.4.4 0.0.0.0 area 3739
Tanger(Config-router)#network 10.1.1.8 0.0.0.3 area 3739
Tanger(Config-router)#exit 
4.2. EIGRP
4.2.1. Marrakech Router
Marrakech(Config)#router eigrp 24
Marrakech(Config-router)#network 10.1.24.0 0.0.0.3
Marrakech(Config-router)#no auto-summary 
Marrakech(Config-router)#exit 
4.2.2. Tanger Router
Tanger(Config)#router eigrp 39
Tanger(Config-router)#network 10.1.39.0 0.0.0.3
Tanger(Config-router)#no auto-summary 
Tanger(Config-router)#exit 
4.2.3. CentreMrk Router
CentreMrk(Config)#router eigrp 24
CentreMrk(Config-router)#network 10.1.24.0 0.0.0.3
CentreMrk(Config-router)#no auto-summary 
CentreMrk(Config-router)#exit 
4.2.4. TangerMed Router
TangerMed(Config)#router eigrp 39
TangerMed(Config-router)#network 10.1.39.0 0.0.0.3
TangerMed(Config-router)#no auto-summary 
TangerMed(Config-router)#exit 
4.3. Static routing
4.3.1. CentreMrk Router
CentreMrk(Config)#ip route 209.65.24.0 255.255.255.252 serial0/0
4.3.2. TangerMed Router
TangerMed(Config)#ip route 209.65.39.0 255.255.255.252 serial0/0
4.3.3. AgenceVoyage
AgenceVoyage(Config)#ip route 0.0.0.0 0.0.0.0 serial0/0
4.3.4. AgencePort
AgencePort(Config)#ip route 0.0.0.0 0.0.0.0 serial0/0
4.3.5. CentreMrk
CentreMrk(Config)#ip route 0.0.0.0 0.0.0.0 10.1.24.1
4.3.6. TangerMed
TangerMed(Config)#ip route 0.0.0.0 0.0.0.0 10.1.39.1
4.4. Redistribution
4.3.1. Marrakech Router
Marrakech(Config)#ip access-list standard 10
Marrakech(Config-std-nacl)#10 permit 10.1.24.0 0.0.0.3
Marrakech(Config-std-nacl)#exit 
Marrakech(Config)#route-map EIGRP_OSPF permit 10
Marrakech(Config-route-map)#set metric 102400 1000 128 1 1500
Marrakech(Config-route-map)#match ip address 10
Marrakech(Config-route-map)#exit 
Marrakech(Config)#router eigrp 24
Marrakech(Config-router)#redistribute ospf 10 route-map EIGRP_OSPF
Marrakech(Config-router)#exit 
Marrakech(Config)#router ospf 10
Marrakech(Config-router)#redistribute eigrp 24 subnets
Marrakech(Config-router)#exit 
4.3.2. Tanger Router
Tanger(Config)#ip access-list standard 10
Tanger(Config-std-nacl)#10 permit 10.1.39.0 0.0.0.3
Tanger(Config-std-nacl)#exit 
Tanger(Config)#route-map EIGRP_OSPF permit 10
Tanger(Config-route-map)#set metric 102400 1000 128 1 1500
Tanger(Config-route-map)#match ip address 10
Tanger(Config-route-map)#exit 
Tanger(Config)#router eigrp 39
Tanger(Config-router)#redistribute ospf 10 route-map EIGRP_OSPF
Tanger(Config-router)#exit 
Tanger(Config)#router ospf 10
Tanger(Config-router)#redistribute eigrp 39 subnets
Tanger(Config-router)#exit 

NB : set metric 102400 1000 128 1 1500
Bandwidth – 102400 Kb/s;
Delay – 1000 (In ten of microseconds);
Reliability – 128;
Loading – 1;
MTU – 1500.

4.3.3. CentreMrk Router
CentreMrk(Config)#route-map STATIC_EIGRP permit 10
CentreMrk(Config-route-map)#match interface Serial0/0
CentreMrk(Config-route-map)#exit 
CentreMrk(Config)#router eigrp 24
CentreMrk(Config-router)#redistribute connected route-map STATIC_EIGRP
CentreMrk(Config-router)#exit 
4.3.3. TangerMed Router
TangerMed(Config)#route-map STATIC_EIGRP permit 10
TangerMed(Config-route-map)#match interface Serial0/0
TangerMed(Config-route-map)#exit 
TangerMed(Config)#router eigrp 39
TangerMed(Config-router)#redistribute connected route-map STATIC_EIGRP
TangerMed(Config-router)#exit 
5
Verification

Multiroute

L2TPv3PingOK

NB: We can't ping from PC1 to Public Address in Tanger ==> Configuration of NAT

L2TPv3pingNATKO

6
NAT Configuration



6.1. AgenceVoyage Router
AgenceVoyage(Config)#interface fastethernet0/0
AgenceVoyage(Config-if)#ip nat inside
AgenceVoyage(Config-if)#exit 
AgenceVoyage(Config)#interface Serial0/0
AgenceVoyage(Config-if)#ip nat outside
AgenceVoyage(Config-if)#exit 
AgenceVoyage(Config)#access-list 101 remark [Control NAT Translation]
AgenceVoyage(Config)#access-list 101 permit ip 192.168.24.0 0.0.0.255 any
AgenceVoyage(Config)#ip nat inside source list 101 interface serial 0/0 overload
6.2. AgenceMed Router
AgenceMed(Config)#interface fastethernet0/0
AgenceMed(Config-if)#ip nat inside
AgenceMed(Config-if)#exit 
AgenceMed(Config)#interface Serial0/0
AgenceMed(Config-if)#ip nat outside
AgenceMed(Config-if)#exit 
AgenceMed(Config)#access-list 101 remark [Control NAT Translation]
AgenceMed(Config)#access-list 101 permit ip 192.168.39.0 0.0.0.255 any
AgenceMed(Config)#ip nat inside source list 101 interface serial 0/0 overload

GET IN TOUCH

ESSALIFI MOHAMED FAICAL
Rabat - Maroc/Morocco
+212 6 61 233 909

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.
Skype: mf.essalifi

Scroll to top