Multiple MPLS VPN Transit Duplicate BGP AS problem

Unanswered Question
Dec 29th, 2007
User Badges:

A customer wishes to use multiple MPLS VPNs within it's network. But since each VPN has the same BGP AS number routing updates are dropped due because the service provider PEs will not allow routes to be leant that have their own AS in the as-path. I would be very grateful for feedback from anyone who might have a solution. Please see attachment for a detailed description of the problem. Thanks, Peter.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
olorunloba Sun, 12/30/2007 - 18:03
User Badges:
  • Silver, 250 points or more

I think a simple solution will be for the provider to use different ASes for the different vrfs.


You could also try to configure confederations on the bordering CEs. The idea is to replace the service provider AS (1234) with the local AS (65000) before advertisement to the neighboring AS. Without a full view of your topology though, I can not guarantee that this will work, but it is worth trying.

p-smallwood Mon, 12/31/2007 - 03:11
User Badges:

Thanks for the suggestions Olorunloba. However, I can't find any way to configure a different AS for each VRF. It would be a good solution if it were possible but as far as I can see there is no way to stop the service provider's confederated AS appearing in the path. I would welome any futher advice you have on that. Thanks. Peter.

swmorris Mon, 12/31/2007 - 10:05
User Badges:
  • Bronze, 100 points or more

What about as override? You'd lose some features of BGP for path choice (which you can look to other policy features if necessary) but you would avoid your routing loop phobia of allowas-in.


As a note, allowas-in is a per-neighbor implementation, not global to the process, so you can control the amount of looping you open yourself up to.


Scott


p-smallwood Tue, 01/01/2008 - 13:59
User Badges:

Hi Scott. Thanks for the AS-OVERRIDE suggestion. This looks to me to be a suitable solution. And I am glad that we would not have to use ALLOWAS-IN. I am going to ask my colleagues for their feedback. I'll get back to you. Regards, Peter.

bhartispbase Sun, 12/30/2007 - 23:33
User Badges:

you can use allowas-in , this command is use for readvertisement of all prefixes containing duplicate autonomous system numbers

swmorris Mon, 12/31/2007 - 09:58
User Badges:
  • Bronze, 100 points or more

Is it not the CE side we're talking about?


For the PE side of things, you can use the as-override as well.


I'm thinking that we'd have to take a more detailed look at the total flow there and see what AS is going and where it's being rejected at.


If you are looking to re-inject an SP's routes back into the SP that seems to be a really strange idea. Otherwise, there are solutions out there.


I guess I didn't pay attention to who was trying to do the filtering. Sorry about that!


Scott


p-smallwood Wed, 01/02/2008 - 03:50
User Badges:

Dear all: Again thanks for your advice.

I note that Cisco advise that AS-OVERRIDE usually needs to be accompanied by SSO for loop prevention.

http://www.cisco.com/en/US/products/sw/iosswrel/ps1830/products_feature_guide09186a0080087b1f.html#wp1045899

We don't have an SSO capability on the CE and so I think we would be reliant on "shortest as-path length" for our loop prevention.

The ALLOWAS-IN option also seems to need us to rely on as-path length for loop prevention.

Generally speaking, do you feel that as-path length can be relied on for loop prevention?

swmorris Wed, 01/02/2008 - 07:32
User Badges:
  • Bronze, 100 points or more

All of these things are workarounds to make sure you get what routes you want and where you want them. You need to pay attention to all of the routes and see what is or is not happening!


AS Path length MAY be adequate to handle loop prevention. But once you are doing allowas-in or as-override in order to "fix" the normal loop prevention concepts, then you MAY be going back and doing things like various AS-path prepending in order to tweak the as-path lengths that you end up with in the end.


Once you get the routes actually appearing (not killed prematurely) then you'll need to pay attention to what you have and verify the path direction is what you want and possibly to make other adjustments.


HTH,


Scott

[email protected]

p-smallwood Wed, 07/23/2008 - 22:44
User Badges:

I am sucessfully using AS-OVERRIDE on the CE to allow the same MPLS-VPN BGP AS to appear multiple times in a customer network. And, of course, the AS-OVERRIDE config needs VRF-Lite to be configured on the CE. I'd like to thank the NetPro community for their contribution.

Actions

This Discussion