Hi,

I have an MPLS network where some 7600 PEs (running 12.2(33)SRD) have the internet with full routing table in a VRF (I know many of you and the CPU don't like this), and I want to connect internet customers to small PEs that cannot take a full routing table.

My current "solution" is to put a default route in each of the internet gateway PEs (those peering with our transits) on Null0 in the internet VRF, make a new VRF and leak that default route into it, and leak back customer routes from the new VRF to the internet VRF. Small PEs see the default route in the new VRF coming from vpnv4 BGP with the aggregate label of the internet VRF of the closest gateway PE.

This almost works: routes are leaked OK, egress packets from the small PEs reach the gateway PE and, if BGP says that it should leave the MPLS cloud and take the transit link, it does and works. If BGP says to forward it to a different gateway PE (that has a different peering which is better for that route), the packet is lost. After careful perusal of this list's archive I understand the reason: an MPLS packet received with the aggregate label needs a L3 FIB lookup, and after this point it cannot be re-labeled and re-enter the MPLS (in a PFC based MPLS).

Now I need a workaround, i.e. a way to make the packet received form the PE with the aggregate label, be forwarded to a different gateway PE. I would really appreciate your suggestions.

What comes to my mind is:

1 - Loopback cable on the gateway PEs: extremely ugly (and highly visible). This is the minimal case of the more general "add some piece of hardware outside the MPLS cloud", which I'd prefer to avoid if possible.

2 - Ensure connectivity among gateway PEs in the internet VRF, out of the MPLS cloud (this is possible in this network), and make them peer with ipv4 unicast IBGP in the internet VRF, in order to receive routes with a nexthop in the VRF and without labels. I wonder if this (IBGP over ipv4 in VRF) routes will be preferred over the MPLS (IBGP over vpnv4 with labels, RD and RT) ones. I also wonder if the 7600 CPU will finally give up and leave me alone: there is plenty of RAM free, but I am afraid my BGP table will double, doubling the time to scan it as well.

I can also avoid the second VRF altogether, and the leaking between the two, with an import map on the internet VRF on the small PEs to limit the imported routes to the default (this is probably less ugly), but the situation would be exactly the same, since they will send packets to the "wrong" egress PE for some routes, using the aggregate label, and I still would need a workaround.

Do you see any more intelligent/elegant workaround? Do you think workaround #2 could work without melting my CPU and flapping my adjacencies?

Thanks in advance,
                                Bergonz



--
Ing. Michele Bergonzoni - Laboratori Guglielmo Marconi S.p.a.
Phone:+39-051-4392826 Fax:+39-051-6153683 e-mail: [email protected]
alt.advanced.networks.design.configure.operate
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to