Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All...

30
Cisco Expo 2012 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 1 © 2012 Cisco and/or its affiliates. All rights reserved. Ivica Stipović, ožujak 2012.

Transcript of Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All...

Page 1: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11© 2012 Cisco and/or its affiliates. All rights reserved.

Ivica Stipović, ožujak 2012.

Page 2: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• 20 godina iskustva u IT industriji

• Sistem integrator koji pruža inovativna i skalabilna IT rješenjaposlovnih, informacijskih i komunikacijskih sustava

• Partnerski statusi: Cisco Gold Certified Partner, Hewlett-

© 2012 Cisco and/or its affiliates. All rights reserved. 2

• Partnerski statusi: Cisco Gold Certified Partner, Hewlett-Packard Gold Specialist, Microsoft Gold Certified Partner,Oracle Gold Partner

• http://www.storm.hr

• Tvrtka je članica STORM Grupe d.o.o.

Page 3: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Zašto IPv6?

• Zahtjevi projekta

• Prepreke u fazi dizajna i implementacije

• Kako je sve zaključeno

© 2012 Cisco and/or its affiliates. All rights reserved. 3

• Kako je sve zaključeno

• Pitanja

Page 4: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• IPv4 adrese gotovo iscrpljene

• Ukupan broj IPv4 adresa: 4,294,967,296

• Nužna upotreba NAT mehanizma kako bi se riješio problem premalog broja IPv4 adresa

• Ukupan broj IPv6 adresa: 340,282,366,920,938,463,463,374,607,431,768,211,456

© 2012 Cisco and/or its affiliates. All rights reserved. 4

Page 5: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Vrlo ambiciozni rokovi

• Složeni zahtjevi (redundancija sa „no single point of failure”,filtriranje IPv4 i IPv6 prometa, QoS, propusnost mreže za NAT-PT, multicast i unicast promete, ograničeni utjecaj ispadapojedine komponente (linka ili uređaja)

© 2012 Cisco and/or its affiliates. All rights reserved. 5

pojedine komponente (linka ili uređaja)

• Preferirana oprema koja se želi koristiti

• Nepoznati tehnički detalji na implementacijskom nivou (vrstav4 multicasta- SSM ili ASM, kolika propusnost i sa kolikim CPUopterećenjem, tokovi prometa s NAT-PT mehanizmom,...)

Page 6: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Velika količina opreme da se simulira okruženje mreže (interni ieksterni serveri, generatori i primatelji prometa, WAN provideroblaci, LAN infrastruktura,...)

© 2012 Cisco and/or its affiliates. All rights reserved. 6

Page 7: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Rigorozno ispitivanje (acceptance testing – zadana vremenakonvergencije, propusnosti, jitter, delay, packet loss, Qos,filtriranje prometa, preko 80 točaka prekida, syslog porukeprilikom promjena na topologiji,...)

© 2012 Cisco and/or its affiliates. All rights reserved. 7

Page 8: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Općeniti prikaz mreže

© 2012 Cisco and/or its affiliates. All rights reserved. 8

Page 9: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Kombinacija sklopova i softvera

• Bugovi i neprecizna dokumentacija proizvođača

• Performanse u realnoj situaciji vs. Performanse navedene udokumentaciji uređaja

© 2012 Cisco and/or its affiliates. All rights reserved. 9

dokumentaciji uređaja

• Međuovisnost funkcionalnosti (NAT-PT zahtijeva isključivanjeCEF-a)

• Kako točno konfigurirati IPv6 funkcionalnost-dual stack,tuneliranje ili translacija (NAT-PT)?

Page 10: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• IPv6 u tuneliranju kroz IPv4 je odbačeno odmah obzirom da ovajnačin ne dozvoljava inspekciju IPv6 prometa (koji je enkapsuliran uIPv4 )

© 2012 Cisco and/or its affiliates. All rights reserved. 10

• Potpuna funkcionalnost IP dual stacka je odbačena jer nisu bilepodržane sve zahtijevane IPv6 funkcionalnosti ili su iste imalebugove koje korisnik nije mogao prihvatiti (IPv6 adrese na ASA SSM-4GE kartici, syslog IPv6 u VRF-ovima, QoS na IPv6,...)

Page 11: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

IPv6 enabled application

TCP UDP

IPv4 IPv6

© 2012 Cisco and/or its affiliates. All rights reserved. 11

• NAT-PT je mehanizam korišten u implementaciji ovog projektajer je zahtijevano od strane korisnika

IPv6 enabled application

Page 12: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• ASA (5520 serija, 8.3 operativni sustav) multicast IPv6funkcionalnost nije podržana

• http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/route_multicast.html#wp1104600

© 2012 Cisco and/or its affiliates. All rights reserved. 12

Page 13: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• HSRP v4 i v6 istovremeno na 3560 switchevima nije podržano,a također nije podržano na svim IOS-ima za Cisco 2800 seriju

© 2012 Cisco and/or its affiliates. All rights reserved. 13

Page 14: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Istraživanje sa Cisco podrškom:

The simultaneous configuration of IPv4 and IPv6

groups is supported on 3560 E series switches.

It is supported on 3560X/3750X and 3560E/3750E

© 2012 Cisco and/or its affiliates. All rights reserved. 14

It is supported on 3560X/3750X and 3560E/3750Eswitches

The limitation is on non-E series switches and switchstack containing non-E switches. As this is a limitation ofNon-E series 3560 switches, there is no workaround,hence all HSRP groups on the switch must be either v4or v6.

Page 15: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• QoS V6 na seriji switcheva 3560/3750 nije podržan(CSCtk94270 3560/3750 incorrectly documented for IPv6 QoSpolicy-map support)

• Istraživanje sa Cisco podrškom:

3560/3560G/3750/3750G platforms do not support IPv6

© 2012 Cisco and/or its affiliates. All rights reserved. 15

3560/3560G/3750/3750G platforms do not support IPv6policy-maps for QoS i.e. Policy-maps with Ipv6 trafficclassification cannot be applied to interface for QoS.They only support "IPv6 Trust" based QoS

However documentation for the images of theseplatforms show support for „IPv6 QoS(Quality ofService)„

This should be corrected as it is very misleading

Page 16: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Kartica za ASA-u (SSM-4GE) ako se na njoj konfigurira IPv6 (CSCtn48877)

• ASA crashes by Watchdog failure or Assert failure infover_FSM_thread

IPv6 failover enabled and IPv6 configurations applied on interfaces of

© 2012 Cisco and/or its affiliates. All rights reserved. 16

IPv6 failover enabled and IPv6 configurations applied on interfaces ofSSM-4GE-INC. The crash is observed when performing the followingoperations:

- adding/modifying "ipv6 address" configurations under the interface

• Workaround:

Move the IPv6 configurations to onboard interfaces, avoid using SSM-4GE-INC with IPv6 failover

Page 17: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• IOS 15.1.4M, (Advanced IP Services) korišten na Cisco 2800performansno inferiorniji o odnosu na 12.4.25d i 12.4.25f (AdvancedIP Services). Za isti promet CPU opterećenje značajno veće na 15verziji jer 12.4.25 IOSi koriste fast switching za IPv4 unicast promet.15 koristi process switching!

• 15 serija IOS-a zahtijeva i više memorije (RAM i Flash) na uređajunego 12.4.x serija

© 2012 Cisco and/or its affiliates. All rights reserved. 17

nego 12.4.x serija

• S druge strane 15 verzija nema bugove koji se manifestiraju u 12.4.xverziji (konvergencija NAT-PT prometa) – koji onda IOS koristiti?

Memory/IOS 12.4.(25d) 15.1.4(M1)

RAM 256 MB 512 MB

Flash 64 MB 128 MB

Page 18: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• NAT-PT vs NAT64

• Zahtjev na funkcionalnost mreže je podržati NAT-PT promete.Uključivanje NAT-PT-a uvjetuje isključivanje CEF-a što dovodido značajnog pada performansi rutera (propusnost), a iisključuje korištenje VRF Lite funkcionalnosti.

© 2012 Cisco and/or its affiliates. All rights reserved. 18

• NAT-PT je tehnologija koju Cisco više ne razvija i preporukavendora je bila migrirati NAT-PT na NAT64 koja je recentna i urazvoju.

• Problem je što Cisco 2800 ni sa jednim IOS-om ne podržavaNAT64 već su to platforme ASR1k. Dizajn je već bio riješen,oprema naručena, korisnik nema dodatni budžet na novuopremu – što sad?

Page 19: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

© 2012 Cisco and/or its affiliates. All rights reserved. 19

Page 20: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Cisco 2800 ruteri ne podržavaju syslog po IPv6 VRF-ovima

• Syslog po IPv6 preko VRF-ova nije podržan niti će biti razvijenu softverima koje 2811 ruteri vrte. Development je završenverzijom 15.1.(4)M. Što se tiče G2 serije rutera (29xx serija) nepostoji još datum kada se planira ovu featuru implementirati.

© 2012 Cisco and/or its affiliates. All rights reserved. 20

postoji još datum kada se planira ovu featuru implementirati.

Page 21: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• ASA (5520 serija, 8.3 operativni sustav) multicast IPv6funkcionalnost nije podržana

• Rješenje: IPv4 Multicast funkcionalnost je implementirana naCisco 2800 ruterima sa firewall feature setom. Žrtvaperformansi za kvalitativnu funkcionalnost u ovom slučaju jebila opravdana nakon diskusije sa korisnikom. IPv6 multicast

© 2012 Cisco and/or its affiliates. All rights reserved. 21

bila opravdana nakon diskusije sa korisnikom. IPv6 multicastnije konfiguriran u ovoj fazi.

Page 22: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Istovremeni HSRP v4 i v6 nije podržan na switchevima 3560 ina svim IOS-ima za Cisco 2800 seriju rutera

• Rješenje: konfigurirani su ruteri tako da HSRP (redundancijasustava) ostaje zadužen za redundanciju unicast v4 prometa(i sa NAT-PT-om), a EIGRP multicast v4 prometa.

© 2012 Cisco and/or its affiliates. All rights reserved. 22

WAN1 WAN2

LAN

EIGRP+HSRP

EIGRP

Page 23: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• QoS IPv6 na seriji switcheva 3560/3750 nije podržan

• Rješenje: QoS za IPv4 konfiguriran na ruterima (Cisco 2800) idana preporuka korisniku koju porodicu switcheva uzeti u obzirza nabavku za slučaj da se u budućnosti pojavi zahtjevkonfiguriranja IPv6 QoS-a na switchevima

© 2012 Cisco and/or its affiliates. All rights reserved. 23

konfiguriranja IPv6 QoS-a na switchevima

Page 24: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Kartica za ASA-u (SSM-4GE) ako se na njoj konfigurira IPv6

• Rješenje: IPv6 funkcionalnost prebačena na rutere (Cisco2800) koji rade NAT-PT, a na SSM-4GE karticama u ASA-makorištene IPv4 adrese

© 2012 Cisco and/or its affiliates. All rights reserved. 24

Page 25: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• IOS 15.1.4M, (Advanced IP Services) korišten na Cisco 2800performansno inferiorniji o odnosu na 12.4.25d i 12.4.25f(Advanced IP Services). Za isto prometno opterećenje CPUopterećenje značajno veće na 15 verziji.

• Rješenje: korišteni 12.4 IOS-i, a bug na njima je riješenkonfiguracijskim workaroundom.

© 2012 Cisco and/or its affiliates. All rights reserved. 25

konfiguracijskim workaroundom.

Page 26: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Konkretno, ruter koji radi NAT-PT ima rutu za NAT-iranu mrežupreko NVI interfacea koja nestaje prekidom linka između dvaredundantna rutera. Workaround je definiranje statičke rute zatu mrežu.

© 2012 Cisco and/or its affiliates. All rights reserved. 26

Page 27: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• NAT-PT vs NAT64

• Rješenje: U dogovoru s korisnikom zadržali smo NAT-PT, aperformansni problemi uslijed isključivanja CEF-a su naprostomorali biti redefinirani u skladu sa realnim hardverskimograničenjem platforme.

© 2012 Cisco and/or its affiliates. All rights reserved. 27

ograničenjem platforme.

• U tom smislu definirano je nekoliko performansnih testova kojidokazuju koliko maksimalno prometno opterećenje uređajimogu izdržati, a da CPU opterećenje ni jednog ne prelazi 75%.U prometna opterećenja ušli su unicast, multicast i NAT-PTprometi odnosno njihove simultane kombinacije.

Page 28: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Cisco 2800 ruteri ne podržavaju syslog po IPv6 preko VRF-ova

• Rješenje: U dogovoru s korisnikom konfigurirano je praćenje inadzor uređaja samo po IPv4 protokolu.

© 2012 Cisco and/or its affiliates. All rights reserved. 28

Page 29: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

• Tijekom cijelog projekta intenzivna suradnja s Cisco uredomHrvatska, Cisco TAC odjelom i puno, puno testiranja iisprobavanja kombinacija operativnih sustava u pogleduperformansi i funkcionalnosti

© 2012 Cisco and/or its affiliates. All rights reserved. 29

Page 30: Cisco Expo 2012 · Cisco Expo 2012 © 201© 2010 Cisco and/or itsaffiliates.All rightsreserved.2Cisco and/or its affiliates. All rightsreserved. Cisco Confidential 1 Ivica Stipović

Cisco Expo 2012

E-mail: [email protected]

© 2012 Cisco and/or its affiliates. All rights reserved. 30

Hvala na pažnji!