Thursday, March 19, 2009

CCNA Certification: Three Occasions To Reload Or Reopen A Cisco Router Interface

Passing the CCNA certification exam means that you know how to configure and troubleshoot a Cisco router instead of using what I call the "hope method" - you know, "Let's reload the router and hope that takes care of it." The majority of Cisco router configurations take effect without the need for a reload, but every once in a while you just have to reload a router or shut and reopen an interface. Let's take a look at three such scenarios.

The first is when you change an OSPF Router ID from its default. For the new RID to take effect, you must either reload the router or clear the OSPF process, which means that all existing adjacencies will come down. Cisco routers are kind enough to tell you this with the following message after you configure a new RID: "Reload or use "clear ip ospf process" command, for this to take effect".

In a previous tutorial, I showed you how to configure an Etherchannel. You have to place each port into the Etherchannel with the channel-group command, and if you do so individually, some of the ports may go into error-disabled state, or "err-disable". This can also happen as a result of port security enforcement. You can see this with the show interface command:

sw1#show int fast 0/1

FastEthernet0/1 is down, line protocol is down (err-disabled)

A syslog message putting that port into err-disabled state will look like this:

04:10:23: %PM-4-ERR_DISABLE: channel-misconfig error detected on Po1, putting Fa0/1 in err-disable state

If this happens during an Etherchannel configuration, just finish the config and then shut and reopen the ports in err-disabled state. They'll come back up and be placed into the Etherchannel.

Finally, our old friend the SPID often makes us shut and reopen the BRI interface. If the BRI interface is open and you configure SPIDs on it, the SPID can be absolutely correct and you'll still see this in the output of show isdn status:

spid1 configured, spid1 NOT sent, spid1 NOT valid

At least the Cisco router puts "NOT" in caps, right? It's easier to see that way! With SPIDs, before you call the service provider or check the SPID you entered about 40 times, just shut and reopen the interface. That usually does the trick.

When you earn your CCNA certification, that means that you know what you're doing instead of hoping that you do - and part of that knowing is knowing when a simple reload or open/shut will take care of the issue.

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 200 free certification exam tutorials, including CCNA certification training articles. His exclusive CCNA study guide is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online Cisco CCNA training boot camp with The Bryant Advantage!

 

Labels: , , , ,

Thursday, February 12, 2009

California Dreaming on Highway One from San Francisco to Lose Angeles

As a teenager in the mid-sixties I was greatly inspired by the music of the Beach Boys. One balmy evening during the summer of 1964 I was stirred by the driving tempo of I Get Around by a group I'd never heard of blasting from the huge old bakelite valve-driven radio that dominated my bedroom. It was during those times when, against the British government?s wishes, every teenager was tuned to Radio Caroline, broadcasting illegally from an old coaster moored somewhere out on the North Sea. I?d heard nothing like this before. It was certainly beyond the play lists of Auntie BBC and her tedious Home Service! I was hooked, not only to the vibrant, close harmonies and falsettos of the vocals but by the very images the lyrics portrayed of sun, sand, striped-shirt freedom and long=legged bikini clad girls. Flower power, love-ins, peace movements and the whole Haight-Asbury thing followed. Then, in 1969, Pirelli published their highly collectible California calendar, containing evocative close-up images by photographer Harry Peccinotti of beautiful sun tanned Californian maidens. By modern standards the photographs were very tame, more like snapshots. Nevertheless that calendar re-enforced a yearning to visit California because it seemed the best place on earth. My vision was of stunning blond California girls, a youth culture driving Chevrolet Corvette Stingrays and a wild freedom that seemed unknown to teenaged Britain.

For various reasons, ok I?ll be honest ? a lack of funds, forced me to wait a decade before I managed to realize my dream and by this time LA, Carmel, Santa Monica, Santa Cruz and San Francisco had become household names through the lyrics of a continuous stream of hit songs by The Beach Boys, Eagles, Jan and Dean and The Mamas and Papas, California Dreaming really had become something of a reality. By the time I arrived in the City of Angels aboard a TWA westbound seven-forty-seven and things were every bit as I imagined. Once bitten, I was smitten and vowed to return as soon as I could. But it took more than twenty years, but with the love affair still intact, I was going back. Maybe I?d become an ageing hippie still listening to those melodic surfin? sounds that had continued to drive my mind through all of these years. Previously I?d flown from San Francisco to LA this time I was going to do things for real by driving the Pacific route between the two largest cities along California State Highway One.

Despite claims that the USA lacks culture, nobody can deny that what it does have is scenery ? huge, mind blowing scenery such as Yosemite, the Grand Canyon and Zabriski Point. California?s Pacific coast similarly does not go begging. It is where nature competes with itself for superiority along rugged cliff tops that rise and fall against the might of the great ocean; mist encrusted mountains against mighty sequoia forests. The Pacific is everything the Atlantic lacks. It can be wilder, more belligerent; the breakers tend to roll higher making it, sometimes a surfer?s paradise, at others a seafarer?s grave. California, despite an element of confident brashness, has always appealed more for its natural untamed beauty than say the tourism evoked retirement condominiums of Florida on America's opposite coast.

Many claim that Highway One is best tackled north to south. Route One really beings at Legett where the road clings tightly to the ocean for nearly 150 salt splashed miles as it passes close to the giant redwoods at Muir Woods before becoming US 101, the Golden Gate freeway, and crossing the magnificent, often fog enshrined, bridge of the same name. Most don?t bother with the first part, choosing to join the route at San Francisco and continuing at a gentile pace with a stop or two before reaching the congestion rush of greater Los Angeles. If you?re in a hurry, then the 400 mile drive can comfortably be made in a day although there?s little point in missing the enormous potential it offers. It?s best to stop and linger a while if you can. The West Coast can be chilly, often hemmed in by coastal fogs held in by the mountains, despite this you?ll still feel at one with the elements and it's best driven in an open-top sports car. I didn?t but, but should have and I regret that I didn?t!

San Francisco is a beautiful city of over six million and a delicate charm of its own, especially where the palatial Victorian homes have survived a series of earthquakes. There?s Lombard Street, short but steep, rising 27 degrees through a series of eight hairpins that twist and turn forcing a cars to proceed at a snail?s pace. Some of the main streets reach 300 feet at Pacific Heights before dropping through amazing gradients to the Marina District below. As you top each crest you?ll be transformed and in your minds-eye you are Steve McQueen playing Bullitt flooring the accelerator of that throaty Shelby-Mustang and bouncing over those bumps at breathtaking speed as you fight to tame this out-of-control beast. In reality you?ll take it slow, real slow, fearing the consequences should your brakes fail! A more sober way is to take the cable car from Nob Hill to the Bay and watch the floor show performed by the driver and his agile grip man as they work together to traverse the undulating tarmac. These days the cable cars are usually packed with tourists and it can be hard to get a ride.

Once more in the real world I start my journey at Fisherman?s Wharf, the trendy waterside area of good fish restaurants, a waxworks and tourist shops that compete with a fine view of the Bay. Alcatraz Island, the former penal establishment that is now a crumbling State Museum, stands formidably in turbulent waters three miles east of the Golden Gate. This, for seventeen years, was the home of Robert Stroud the infamous Bird Man but he was never the gentile ornithologist Bert Lancaster portrayed. It was also where Al Capone was finally caged up for, of all things, tax evasion.

Leaving behind the squawking sea lions feeding off restaurant scraps at one of the piers, I head south leaving the city behind, past San Francisco International Airport and some of the wealthy outlying suburbs. The car radio informs me that ?It?s going to be a fine day right across the whole of the Bay Area and there are no reported traffic snarl ups?. That?s good to hear because only weeks before floods had caused landslides that were still keeping the coast road closed until twenty miles south at Half Moon Bay. Between here and Ano Nuevo lie a number of State beaches renowned for their outstanding natural beauty. This is where the northern elephant seals and sea lions come to breed or just to wallow lazily in the sun. This was March however and the beaches were deserted.

For much of the way the route is a two-lane blacktop ? no dual carriageway, just a well maintained twin-lane tarmac highway that clings heroically around the cliff tops that tower and fall above the Ocean. I am surprised at so little traffic, most of the locals preferring to take highway 101, a faster route that meanders on an almost parallel inland course for most of the way. Better still I haven?t seen a single cop. But beware, I am told they patrol from low flying helicopters (bears in the air) so I watch my speed and although I try to keep to a steady 55mph my instincts push me to go ever faster.

The highway runs via Pescadero where there is a lighthouse built in 1872, then onward to the seaside resort of Santa Cruz on the northern point of Monterey Bay. A further 28 miles south around the coast and I reach the old Spanish town and former Californian capital. Monterey, a town made famous by John Steinbeck in his novels Cannery Row and Tortilla Flat. The old sardine canneries are now long closed but the buildings have been transformed into trendy shops and restaurants. There is also an excellent aquarium. Beyond the beach, in waters stretching 110 miles out to sea is the Monterey National Marine Sanctuary, containing the largest underwater cavern anywhere in offshore US.

I didn?t have sufficient time to take the 17 mile drive but if you do it starts just south at Pacific Grove, ends at Carmel and passes the world class golf courses at Pebble Beach and Spyglass Hill. Although you pay for the privilege, those that have taken the detour say that the beauty of the drive, much of it man-made, is exceptional. Instead, I remain on Highway One and head for Carmel, home of Clint Eastwood, aka Dirty Harry and the former mayor. He wasn?t about. At least he wasn?t driving the West Coast. The city dates back to 1770 when a Franciscan monk, Father Juniperro Serra built a mission and church. Although it fell into disrepair after being abandoned in 1834, the Mission, one of several along the coast, has been carefully restored.

South of Carmel is a truly wonderful stretch of coastline that runs almost a 100 miles below the Ventana Wilderness, part of the Los Padres National Forest. This is Big Sur, a mood-inspiring rocky, wild area of State Parks and exceptional natural beauty. I Linger for a while just listening to the breakers crashing against the rocks before continuing, crossing the Bixby Creek Bridge, once the world?s longest single-arch span at 550 feet. This was built in 1932 two years after the Highway was opened at Big Sur. In 1983 storms here swept much of the highway away forcing it to close for over a year.

At San Simeon there is a wooden pier on a rugged shale beach. I decide to stay the night at a reasonably priced motel. In the hills above the highway is Hearst Castle, a stately palace folly created from treasures imported from all over the world by newspaper magnate, William Randolph Hearst and bequeathed to the state of California in 1958. Visitors must park at the tourist center and be transported by buses up a long, winding hilltop drive to reach the surrealistic Castle. The creation reputedly cost $10 million to build but it is very much a statement of bad taste, nevertheless it?s sure to impress.

Just south of San Simeon is the artist?s colony of Cambria. It is also a weekend retreat for those wishing to escape the heavy yellow smogs of LA. Next, Morro Bay where the chimneys of the PG & E power station are the singular blot on the landscape of the entire route The road turns inland here around a sand spit and causeway that leads to a huge extinct Volcano known as Morro Rock. Soon I reach the halfway point between San Francisco and LA at San Luis Obispo where there is another mission. Now highway one unites with 101 for a brief stretch until Pismo, a 20 mile stretch of wide, sandy beaches.

The beautifully kept Spanish colonial style terracotta roofed houses and picturesque clean streets of Santa Barbara make it, for me, one of the loveliest small cities anywhere. Following the earthquake in 1925, the city was rebuilt in the adobe fashion and the buildings are now preserved by law but this didn?t stop nature from coming perilously close to covering some of the dwellings in mud washed down from by the floods from the surrounding hills. The high street is full of interesting shops, excellent, but expensive, restaurants and a wonderful book shop where I enjoyed a coffee and a muffin while browsing the shelves. There is a prosperous, relaxed air to Santa Barbara and I can see why the city has attracted so many Hollywood stars who have come to build their homes in the exclusive hills above the city.

The last leg of my journey takes me through Ventura and on to Santa Monica Bay. At the northern end is Malibu, where a long, wide stretch of state beach is exclusive to surfers (no swimming allowed). At Malibu Colony, another place favoured by the famous names of Hollywood, the lavish mansions line the shoreline but there is no public access to beach. In the hills above, the J Paul Getty museum claims to house some of the finest art in the world.

Santa Monica, a lively resort on the fringes of Los Angeles is the setting for Bay Watch. The city sits atop a cliff overlooking the beach and separated by a palm lined strip known as Pallisades Park. From here there are fantastic views of the Bay especially at sunset. My time however does not allow me to linger. As highway one turns inland away from the Pacific Coast cities of Venice, Marina Del Ray (where Beach Boy drummer Dennis Wilson drowned in 1983) and Long Beach before rejoining the ocean at Seal Beach, I bid a fond farewell. A short distance away my journey takes me to LAX and my flight home. As my jet climbs above the twinkling lights of Beverley Hills I reflect on my memories of this trip and in those famous words of Arnold Schwarzeineger I swear ?I?ll be back?.

Robert Bluffield is a full time professional photographer and writer based in Milton Keynes. As a writer he specialises in features on travel, cars, food and wine, business, current affairs and photography. He is an author of 3 published books and he is currently working on a history of Imperial Airways and the Birth of British Airlines. Web site: http://robertbluffield.co.uk

Labels: , , ,

Thursday, January 29, 2009

Cisco CCNA Certification Exam Training: Telnet, Passwords, and Privilege

Your CCNA certification exam is likely going to contain questions about Telnet, an application-level protocol that allows remote communication between two networking devices. With Telnet use being as common as it is, you had better know the details of how to configure it in order to pass your CCNA exam and to work in real-world networks.

The basic concept is pretty simple - we want to configure R1, but we're at R2. If we telnet successfully to R1, we will be able to configure R1 if we've been given the proper permission levels. In this CCNA case study, R2 has an IP address of 172.12.123.2 and R1 an address of 172.12.123.1. Let's try to telnet from R2 to R1.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

Password required, but none set

[Connection to 172.12.123.1 closed by foreign host]

This seems like a problem, but it's a problem we're happy to have. A Cisco router will not let any user telnet to it by default. That's a good thing, because we don't want just anyone connecting to our router! The "password required" message means that no password has been set on the VTY lines on R1. Let's do so now.

R1(config)#line vty 0 4

R1(config-line)#password baseball

A password of "baseball" has been set on the VTY lines, so we shouldn't have any trouble using Telnet to get from R2 to R1. Let's try that now.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

User Access Verification

Password:

R1>

We're in, and placed into user exec mode. Let's say we want to configure a new IP address on the ethernet interface on R1. We'll now go into privileged exec mode....

R1>enable

% No password set

R1>

... or maybe we won't! The default behavior of Telnet on a Cisco router is to place the incoming user into user exec mode, and require an enable password to allow that user into privileged exec mode! Right now, we can't configure anything on this router and even the show commands we would use are limited at best.

If we wanted to allow all telnetting users to be put into privileged exec mode immediately without being prompted for an enable password, the command privilege level 15 placed on the VTY lines will accomplish this.

R1(config)#line vty 0 4

R1(config-line)#privilege level 15

From R2, we'll telnet into R1 again.

R2#telnet 172.12.123.1

Trying 172.12.123.1 ... Open

User Access Verification

Password:

R1#

We were able to telnet in from R2 with the original password of "baseball", and even better, we were placed into privileged exec mode immediately!

You may or may not want to do this in real-world networks, though. If you want to assign privilege levels on an individual user basis, configure usernames and passwords and use the privilege 15 command in the actual username/password command itself to give this privilege levels to some users but not all.

R1(config)#username heidi password klum

R1(config)#username tim privilege 15 password gunn

Both users can telnet into the router, but the first user will be placed into user exec and challenged for the enable password to enter privileged exec mode. If there is no enable password, the user literally cannot get into privileged exec. The second user will be placed into privileged exec immediately after successfully authenticating.

Passwords on a Cisco router or switch are vitally important, and you're not tied down to granting "all-or-nothing" access. Knowing the details like the ones shown here help you tie down network security while allowing people to do their jobs - and it doesn't hurt to know this stuff for the CCNA exam, either!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

Labels: , , , , ,

Friday, October 31, 2008

Cisco CCNP Certification Training : The New CCNP BCMSN 642-812 Exam

Cisco CCNP certification is about to become more valuable and more difficult! Cisco is making major changes to the CCNP certification program, retiring two exams (BCRAN and CIT) while updating two old friends, the BSCI and BCMSN exam. Today, we'll take a look at the changes in the Building Converged Cisco Multilayer Switched Networks (BCMSN) exam.

According to Cisco's exam blueprint, there are some major additions with the introduction of the 642-812 exam. Wireless access, security, and voice are all rapidly growing features and concerns in today's real-world networks, and Cisco is responding to that by adding all three of these topics to the CCNP BCMSN exam. Cisco CCNP candidates should expect to be questioned on WLANs as well as wireless clients.

There were some security topics on the 642-811 BCMSN exam, port security and 802.1x among them. The successful Cisco CCNP certification candidate will now be expected to know about the different network attacks that can take place at the data link layer of the OSI model, including DHCP Spoofing and VLAN Hopping.

There was also just a bit of voice material on the 642-811 BCMSN exam, but you'll have to know more voice to pass the 642-812 exam. Voice VLANs, voice QoS, and IP Phone configuration are just some of the topics being added to the new BCMSN exam.

Cisco is obviously raising the bar with the new CCNP exams, and this certification is going to be harder to get than ever before. That also makes it more valuable than ever before, and 2007 will be the best year yet in which to earn your CCNP certification. Make your plans to earn this valuable Cisco certification, and then put that plan into action!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

Labels: , , , ,

Thursday, October 16, 2008

Cisco CCNP Certification Training: What's New On The BSCI 642-901 Exam

CCNP certification is getting a new look at the end of 2006. The BSCI and BCMSN exams are being updated, and the CIT and BCRAN exams are being retired. Let's take a look at what to expect from the new BSCI exam.

According to Cisco's exam blueprint - admittedly a very broad blueprint at this time - the major new topics are IP version 6 (IPv6) and multicasting. The addition of these two topics will make an already demanding Cisco certification exam that much tougher, but this is a great change for the exam and for the candidate. IPv6 is just going to become more and more prevalent in today's networks, and multicasting is as well.

Multicasting for the Cisco CCNP BSCI exam is going to go far beyond what you learned about it in your CCNA studies. For the new BSCI exam, you'll need to know the different methods of creating multicast groups as well as assigning members to them. This material was previously limited to CCIE-level books, and while I don't look for the questions to be as hard as the CCIE written exam, multicasting is not an easy topic and should not be taken lightly by the CCNP candidate in 2007.

One major CCNP exam topic that isn't going anywhere is BGP. The Border Gateway Protocol has been a big part of previous BSCI exams, and that looks to continue.

If you're pursuing your CCNP certification in 2007, be sure to monitor Cisco's website for additions to the CCNP blueprint. It's obvious that Cisco has raised the bar for CCNP certification, and earning this important Cisco certification will in turn raise your market value and networking knowledge like never before. Watch for future tutorials examining the other three new CCNP exams!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!

Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, ?How To Pass The CCNA?, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!

Labels: , , , ,

Wednesday, February 6, 2008

Cisco CCNP / BCMSN Exam Tutorial: The Core Layer Of Cisco's Three-Layer Model

In this section, you're going to be reintroduced to a networking model you first saw in your CCNA studies. No, it's not the OSI model or the TCP/IP model - it's the Cisco Three-Layer Hierarchical Model. Let's face it, just about all you had to do for the CCNA was memorize the three layers and the order they were found in that model, but the stakes are raised here in your CCNP studies. You need to know what each layer does, and what each layer should not be doing. This is vital information for your real-world network career as well, so let's get started with a review of the Cisco three-layer model, and then we'll take a look at each layer's tasks. Most of the considerations at each layer are common sense, but we'll go over them anyway!

Today we'll take a look at the core layer of the Cisco model.

The term core switches refers to any switches found here. Switches at the core layer allow switches at the distribution layer to communicate, and this is more than a full-time job. It's vital to keep any extra workload off the core switches, and allow them to do what they need to do - switch! The core layer is the backbone of your entire network, so we're interested in high-speed data transfer and very low latency - that's it!

Core layer switches are usually the most powerful in your network, capable of higher throughput than any other switches in the network. Remember, everything we do on a Cisco router or switch has a cost in CPU or memory, so we're going to leave most frame manipulation and filtering to other layers. The exception is Cisco QoS, or Quality of Service. QoS is generally performed at the core layer. We'll go into much more detail regarding QoS in another tutorial, but for now, know that QoS is basically high-speed queuing where special consideration can be given to certain data in certain queues. (You'll soon find that this is a very basic definition!)

We always want redundancy, but you want a lot of redundancy in your core layer. This is the nerve center of your entire network, so fault tolerance needs to be as high as you can possibly get it. Root bridges should also be located in the core layer.

The importance of keeping unnecessary workload off your core switches cannot be overstated. In the next part of this BCMSN tutorial, we'll take a look at how the other layers of the Cisco three-part model do just that.

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage , home of free CCNA and CCNP tutorials! Pass the CCNA exam with Chris Bryant!

Labels: , , , ,

Monday, January 28, 2008

Cisco CCNP / BCMSN Exam Tutorial: BPDU Skew Detection

You may look at that feature's name and think, "What is a BPDU Skew, and why do I want to detect it?" What we're actually attempting to detect are BPDUs that aren't being relayed as quickly as they should be.

After the root bridge election, the root bridge transmits BPDUs, and the non-root switches relay that BPDU down the STP tree. This should happen quickly all around, since the root bridge will be sending a BPDU every two seconds by default ("hello time"), and the switches should relay the BDPUs fast enough so every switch is seeing a BPDU every two seconds.

That's in a perfect world, though, and there are plenty of imperfect networks out there! You may have a busy switch that can't spare the CPU to relay the BDPU quickly, or a BPDU may just simply be lost in transmission. That two-second hello time value doesn't give the switches much leeway, but we don't want the STP topology recalculated unnecessarily either.

BDPU Skew Detection is strictly a notification feature. Skew Detection will not take action to prevent STP recalculation when BDPUs are not being relayed quickly enough by the switches, but it will send a syslog message informing the network administrator of the problem. The amount of time between when the BDPU should have arrived and when it did arrive is referred to as "skew time" or "BPDU latency".

A busy CPU could quickly find itself overwhelmed if it had to send a syslog message for every BPDU delivery that's skewed. The syslog messages will be limited to one every 60 seconds, unless the "skew time" is at a critical level. In that case, the syslog message will be sent immediately with no one-per-minute limit.

And what is "critical", according to BDPU Skew Detection? Any value greater than 1/2 of the MaxAge value, making the critical skew time level 10 seconds or greater.

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage (http://www.thebryantadvantage.com), home of free CCNP and CCNA tutorials! For my FREE "How To Pass The CCNA" or "CCNP" ebook, visit the website and download your copies. Pass your CCNP exam with The Bryant Advantage

Labels: , , , , , , ,

Tuesday, January 22, 2008

Cisco CCNP / BSCI Exam Tutorial: Configuring And Troubleshooting OSPF Virtual Links

Knowing when and how to create an OSPF virtual link is an essential skill for BSCI and CCNP exam success, not to mention how important it can be on your job! As a CCNA and CCNP candidate, you know the theory of virtual links, so let's take a look at how to configure a virtual link, as well as some real-world tips that many CCNA and CCNP study guides leave out!

In this configuration, no router with an interface in Area 4 has a physical interface in Area 0. This means a logical connection to Area 0, a virtual link, must be built.

In the following example, R1 and R3 are adjacent and both have interfaces in Area 0. R4 has an adjacency with R3 via Area 34, but R4 has no physical interface in Area 0 and is advertising its loopback 4.4.4.4 into OSPF. R1 doesn't have the route to that loopback.

R1#show ip route ospf

6.0.0.0/32 is subnetted, 1 subnets

O 6.6.6.6 [110/11] via 10.1.1.5, 01:05:45, Ethernet0

172.23.0.0/27 is subnetted, 1 subnets

O IA 172.23.23.0 [110/74] via 172.12.123.3, 00:04:14, Serial0

7.0.0.0/32 is subnetted, 1 subnets

O 7.7.7.7 [110/11] via 10.1.1.5, 01:05:45, Ethernet0

To resolve this, a virtual link will be built between R3 and R4 through Area 34. The area through which the virtual link is built, the transit area, cannot be a stub area of any kind.

R4(config)#router ospf 1

R4(config-router)#area 34 virtual-link 3.3.3.3

R3(config)#router ospf 1

2d07h: %OSPF-4-ERRRCV: Received invalid packet: mismatch area ID, from backbone area must be virtual-link but not found from 172.23.23.4, Ethernet0

R3(config)#router ospf 1

R3(config-router)#area 34 virtual-link 4.4.4.4

R3(config-router)#^Z

2d07h: %OSPF-5-ADJCHG: Process 1, Nbr 4.4.4.4 on OSPF_VL0 from LOADING to FULL, Loading Done

A few details worth noting... the virtual link command uses the remote device's RID, not necessarily the IP address on the interface that's in the transit area. Also, don't worry about that error message you see in the output from R3 that is normal and you'll see it until you finish building the virtual link.

Always confirm the virtual link with show ip ospf virtual-link. If you've configured it correctly, the VL should come up in a matter of seconds.

R3#show ip ospf virtual-link

Virtual Link OSPF_VL0 to router 4.4.4.4 is up

Run as demand circuit

DoNotAge LSA allowed.

Transit area 34, via interface Ethernet0, Cost of using 10

Transmit Delay is 1 sec, State POINT_TO_POINT,

Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5

Hello due in 00:00:00

Adjacency State FULL (Hello suppressed)

Index 2/4, retransmission queue length 1, number of retransmission 1

First 0x2C8F8E(15)/0x0(0) Next 0x2C8F8E(15)/0x0(0)

Last retransmission scan length is 1, maximum is 1

Last retransmission scan time is 0 msec, maximum is 0 msec

Link State retransmission due in 3044 msec

Virtual links are actually simple to configure, but for some reason they seem to intimidate people. It's my experience that the error message highlighted in R3's output above causes a lot of panic, but the only thing that message means is that you're not finished configuring the virtual link yet.

There are three main misconfigurations that cause 99% of virtual link configuration issues:

Using the wrong OSPF RID value

Trying to use a stub area as the transit area

Failure to configure link authentication on the virtual link when Area 0 is running authentication

That last one is the one that gets forgotten! A virtual link is really an extension of Area 0, and if Area 0 is running link authentication, the virtual link must be configured for it as well. Pay attention to the details. don't panic when you see the error message on the second router you configure with the virtual link, and you'll be ready for any virtual link situation on the job or in the CCNA / CCNP exam room!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage (http://www.thebryantadvantage.com), home of free CCNP and CCNA tutorials! For my FREE "How To Pass The CCNA" or "CCNP" ebook, visit the website and download your copies. Pass your CCNP exam with The Bryant Advantage!

Labels: , , , , ,