Understanding VLAN Translation/Rewrites using Switches and Routers



Similar documents
MikroTik Training Module Understanding VLAN Translation/Rewrites using Switches and Routers

Network Architecture Validated designs utilizing MikroTik in the Data Center

BGP as an IGP for Carrier/Enterprise Networks

1 Basic Configuration of Cisco 2600 Router. Basic Configuration Cisco 2600 Router

MIKROTIK NETWORK SIMULATOR

Quality of Service in wireless Point-to-Point Links

OVERLAYING VIRTUALIZED LAYER 2 NETWORKS OVER LAYER 3 NETWORKS

VLAN in MikroTik. By Mohammed Khomeini Bin ABU MUM Indonesia, 2013

TRILL for Data Center Networks

Lab Diagramming Intranet Traffic Flows

Chapter 1 Reading Organizer

Management Software. Web Browser User s Guide AT-S106. For the AT-GS950/48 Gigabit Ethernet Smart Switch. Version Rev.

Networking and High Availability

Application Note Gigabit Ethernet Port Modes

Any-to-any switching with aggregation and filtering reduces monitoring costs

Copyright 2008 Link Technologies,Inc. A Proud Vendor Member of the

IP Addressing and Subnetting. 2002, Cisco Systems, Inc. All rights reserved.

GregSowell.com. Mikrotik Basics

CLOUD NETWORKING FOR ENTERPRISE CAMPUS APPLICATION NOTE

High Availability on MikroTik RouterOS

Networking and High Availability

Layer 2 Network Encryption where safety is not an optical illusion Marko Bobinac SafeNet PreSales Engineer

NETE-4635 Computer Network Analysis and Design. Designing a Network Topology. NETE Computer Network Analysis and Design Slide 1

TRILL Large Layer 2 Network Solution

SSVP SIP School VoIP Professional Certification

LAN Switching and VLANs

OpenFlow and Software Defined Networking presented by Greg Ferro. OpenFlow Functions and Flow Tables

Network Virtualization and Data Center Networks Data Center Virtualization - Basics. Qin Yin Fall Semester 2013

Local Area Networking technologies Unit number: 26 Level: 5 Credit value: 15 Guided learning hours: 60 Unit reference number: L/601/1547

Implementation of Virtual Local Area Network using network simulator

Lab - Using IOS CLI with Switch MAC Address Tables

Top-Down Network Design

Layer 3 Network + Dedicated Internet Connectivity

Lab Developing ACLs to Implement Firewall Rule Sets

PROPRIETARY CISCO. Cisco Cloud Essentials for EngineersV1.0. LESSON 1 Cloud Architectures. TOPIC 1 Cisco Data Center Virtualization and Consolidation

Flow Monitor Configuration. Content CHAPTER 1 MIRROR CONFIGURATION CHAPTER 2 RSPAN CONFIGURATION CHAPTER 3 SFLOW CONFIGURATION...

Virtual Private LAN Service on Cisco Catalyst 6500/6800 Supervisor Engine 2T

Implementation IPV6 in Mikrotik RouterOS. by Teddy Yuliswar

Bandwidth Management and QOS

Implementing Cisco Service Provider Next-Generation Edge Network Services **Part of the CCNP Service Provider track**

VLANs. Application Note

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

How To Understand and Configure Your Network for IntraVUE

WHITE PAPER. Network Virtualization: A Data Plane Perspective

Cisco Integrators Cisco Partners installing and implementing the Cisco Catalyst 6500 Series Switches

Building Effective Firewalls with MikroTik P R E S E N T E D B Y: R I C K F R E Y, N E T W O R K E N G I N E E R I P A R C H I T E C H S O P E R AT I

Topic 7 DHCP and NAT. Networking BAsics.

Evaluation guide. Vyatta Quick Evaluation Guide

VMDC 3.0 Design Overview

CAPsMAN Case Study. Uldis Cernevskis MikroTik, Latvia. MUM Pittsburgh September 2014

Introduction. What is a Remote Console? What is the Server Service? A Remote Control Enabled (RCE) Console

Walmart s Data Center. Amadeus Data Center. Google s Data Center. Data Center Evolution 1.0. Data Center Evolution 2.0

VLAN Workshop. Presenter: Paul Eriksson. VLAN Workshop 2009 RoamingNet Sweden ( 1

A Simulation Study of Effect of MPLS on Latency over a Wide Area Network (WAN)

ADVANCED NETWORK CONFIGURATION GUIDE

Burning Bridges - Routing Your Bridged WISP Network With MikroTik

Flow Monitor Configuration. Content CHAPTER 1 MIRROR CONFIGURATION CHAPTER 2 SFLOW CONFIGURATION CHAPTER 3 RSPAN CONFIGURATION...

Common VoIP problems, How to detect, correct and avoid them. Penny Tone LLC 1

Improving Quality of Service

LANs and VLANs A Simplified Tutorial

WISP 101. The DO s and DON T s of becoming a Wireless ISP

FSM73xx GSM73xx GMS72xxR Shared access to the Internet across Multiple routing VLANs using a Prosafe Firewall

2. What is the maximum value of each octet in an IP address? A. 28 B. 255 C. 256 D. None of the above

IT 3202 Internet Working (New)

This chapter covers four comprehensive scenarios that draw on several design topics covered in this book:

Knowledgebase Solution

JOB READY ASSESSMENT BLUEPRINT COMPUTER NETWORKING FUNDAMENTALS - PILOT. Test Code: 4514 Version: 01

Network Configuration Example

CET442L Lab #2. IP Configuration and Network Traffic Analysis Lab

SummitStack in the Data Center

Remote PC Guide Series - Volume 1

Network Agent Quick Start

hp ProLiant network adapter teaming

Installation of the On Site Server (OSS)

NEN Community REANNZ. Design Statement: NEN Edge Device

What is VLAN Routing?

How To Load Balance On A Libl Card On A S7503E With A Network Switch On A Server On A Network With A Pnet 2.5V2.5 (Vlan) On A Pbnet 2 (Vnet

Create Virtual AP for Network Campus with Mikrotik

CCNA Discovery Networking for Homes and Small Businesses Student Packet Tracer Lab Manual

VLAN 802.1Q. 1. VLAN Overview. 1. VLAN Overview. 2. VLAN Trunk. 3. Why use VLANs? 4. LAN to LAN communication. 5. Management port

MPLS for ISPs PPPoE over VPLS. MPLS, VPLS, PPPoE

Performance Evaluation of Linux Bridge

A New Approach to Developing High-Availability Server

Extending Networking to Fit the Cloud

CHAPTER 10 LAN REDUNDANCY. Scaling Networks

IT-AD08: ADD ON DIPLOMA IN COMPUTER NETWORK DESIGN AND INSTALLATION

MikroTik Certified Network Associate (MTCNA) Training outline

How to monitor network traffic inside an ESXi host

How To Switch In Sonicos Enhanced (Sonicwall) On A 2400Mmi 2400Mm2 (Solarwall Nametra) (Soulwall 2400Mm1) (Network) (

Overview of Routing between Virtual LANs

Set Up a VM-Series Firewall on the Citrix SDX Server

Data Center Use Cases and Trends

Security Labs in OPNET IT Guru

SSVVP SIP School VVoIP Professional Certification

Bandwidth-based load-balancing with failover. The easy way. We need more bandwidth.

WHITEPAPER. VPLS for Any-to-Any Ethernet Connectivity: When Simplicity & Control Matter

VLAN and QinQ Technology White Paper

Transcription:

www.iparchitechs.com 1-855-MIKROTI(K) Understanding VLAN Translation/Rewrites using Switches and Routers KEVIN MYERS, NETWORK ARCHITECT / MANAGING PARTNER MTCINE #1409 MIKROTIK CERTIFIED TRAINER

Kevin Myers, Network Architect 17 + years in IT, Network Architecture and Engineering Areas of Design Focus: MikroTik integration with large multi-vendor networks Design of BGP/MPLS/OSPF Service Provider Triple-Play networks Design of large enterprise Data Center networks Certifications MTCINE #1409 Certified CCNP, CCNA, MCP, MTCRE, MTCTCE, MTCNA

Need MikroTik help? Introducing IP SafeNET Flat-rate, yearly comprehensive MikroTik support with hardware replacement. Three SLA Tiers MUM Only promotion Try it FREE for 30 days!

Objectives Learn what a VLAN Translation is and the different use cases Understand the different implementation types for VLAN rewrites in RouterOS Walk through implementation examples that uses VLAN translations in a Router and CRS switch.

What is VLAN Translation? VLAN Translation (or rewrite) involves replacing one ingress tag with another and vice-versa on egress.

What is VLAN Translation? VLAN Translation (or rewrite) involves replacing one ingress tag with another and vice-versa on egress.

Is this QinQ? No. VLAN Translation only involves one tag whereas QinQ adds an outer VLAN tag. In the frame below, the TAG field is rewritten from one VLAN to another while preserving all other information in the frame.

What problem are we trying to solve? Merging companies When large companies merge, there are often duplicate VLANS with different functions in campus and headquarters environments Data Center Interconnect (DCI) When connecting large data centers at Layer 2, VLAN overlap is a major issue. A VLAN in one data center may used for web servers, while the same VLAN number in another data center could be for database servers. Service Provider Large carrier networks often deal with overlapping VLANs from customers and other providers. VLAN translation can be used to join segments with different tags or prevent overlap. What are some other use cases for VLAN Translations?

Example: Data Center 1 (NYC, NY, USA) needs to extend Vlan 101 for web Servers on 10.1.1.0/24 to the Denver, CO DC Data Center 2 (Denver, CO, USA) uses Vlan 101 for storage replication on 192.168.222.0/24 VLAN 101-10.1.1.0/24 from NYC must be rewritten in Denver as VLAN 201 to avoid conflict with the Storage Replication. Routerboards can do this via bridging and CRS via switching.

Example: VLAN 101 in NYC becomes VLAN 201 once it reaches Denver, CO. The broadcast domain (light blue) is the same even though the VLAN tag changes

Example: VLAN 101 in NYC becomes VLAN 201 once it reaches Denver, CO. The broadcast domain (light blue) is the same even though the VLAN tag changes Q. What is a broadcast domain? Q. What Layer of the OSI Model does it exist at? Q. Why would this be important when rewriting VLANs?

VLAN Translation LAB Scenario

Configuration Objective - Translate VLAN from R1 to R2 and ping successfully between laptops Materials Needed 2 RouterBoards (each with at least 2 Ethernet ports) 2 Laptops with Ethernet port 4 Ethernet cables CRS 125-24G-1S Switch

Configuration Objective - Translate VLAN from R1 to R2 and ping successfully between laptops VLAN Assignment R1 VLAN 101 R2 VLAN 201 IP Address assignment for the Laptop Laptop connected to R1 10.1.1.200/24 Laptop connected to R2 10.1.1.201/24

Step 1 Reset system config with no default on both routerboards in the pod Step 2 Connect all devices according to the topology diagram.

Step 3 Assign the IPs for both laptops 10.1.1.200 and.201 Example (Windows) Using Laptop 1 (NOTE: No default gateway is needed for this lab)

Step 4 Configure each lab Routerboard for the following R1 - Interface Vlan 10x on eth1 (where x is your POD number) R2 - Interface Vlan 20x on eth1 (where x is your POD number)

Step 5 Configure each lab Routerboard for the following R1 VLAN10x-Bridge (where x is your POD number) and add ports eth2 and Vlan10x R2 VLAN20x-Bridge (where x is your POD number) and add ports eth2 and Vlan20x

Step 6 Configure Ingress VLAN translation on the CRS Ether1 VLAN 101 to VLAN 201 Ether2 VLAN 201 to VLAN 101

Step 8 Configure Egress VLAN translation (POD1 shown as an example) Ether1 VLAN 201 to VLAN 101 (Use the correct port and VLAN for your POD) Ether2 VLAN 101 to VLAN 201 (Use the correct port and VLAN for your POD)

Configuration Objective - Translate VLAN from R1 to R2 in your POD and ping successfully between laptops Step 9 Validation Ping from laptop to laptop (be sure to turn off software firewalls)

How do we know that config worked? Packet Sniffer using port mirroring on the CRS Switch ports on CRS do not show up in packet sniffer unless a mirror is set up and pointed to the CPU

Packet capture of ICMP between R1 and R2 in Wireshark

Packet capture of ICMP from 10.1.1.200/24 (VLAN 101) to 10.1.1.201/24 (VLAN 201) in Wireshark

Packet capture of ICMP from 10.1.1.201/24 (VLAN 201) to 10.1.1.200/24 (VLAN 101) in Wireshark

Configuration example - Bridging This configuration can be used in almost any RouterBoard to translate between VLANs using a bridge. Create VLAN 500 and 3100 interface VLANs Create Bridge and add VLAN interface ports

When to use switching vs. bridging what is the difference? Speed and packet latency is the answer switching is done in hardware and so the traffic going through the VLAN translation can happen at wire speed without CPU load or latency of processing. 1 Gigabit in the case of the CRS

When to use switching vs. bridging what is the difference? Use CRS switches for applications that require higher throughput and port density. Data Center Interconnect (DCI) Service Provider core or aggregation layers WISP Core layer to support acquisition and migration of a new WISP. Use routers for lower speed scenarios like at the edge.

MUM Giveaway #1 (4) Google Virtual Reality Headsets

MUM Giveaway #2 (4) R/C Quadcopters

Questions? The content of this presentation will be available at iparchitechs.com Please come see us at the IP ArchiTechs booth in the Exhibitor Hall Email: kevin.myers@iparchitechs.com Office: (303) 590-9943 Web: www.iparchitechs.com Thank you for your time and enjoy the MUM!!