Use of next-hop-self versus Advertising DMZ
The demilitarized zone (DMZ) defines a shared network between ASs. The IP subnet used forthe DMZ link might or might not be owned by any of the networked ASs. As you havealready seen, the next-hop address learned from the EBGP peer is preserved within IBGP. It isimportant for the IGP to be able to reach the IP address denoted via the NEXT_HOP attributein the UPDATE message. One way to do this is for the DMZ subnet to be part of the IGP andhave the subnet advertised in the AS...
Troubleshooting RIPv2 and RIPng
Two configuration problems common to RIPv2 are mismatched versions and misconfigured authentication. Both difficulties are easy to discover with debugging, as Example 6-29 shows. Example 6-29. Debugging reveals mismatched versions and misconfigured authentication. Jemez#debug ip rip events RIP event debugging is on Jemez# RIP: ignored v1 packet from 172.25.150.249 (illegal version) RIP: ignored v2 packet from 172.25.150.249 (invalid authentication) Jemez# A more likel..
Converging to a New STP Topology
STP logic monitors the normal ongoing Hello process when the network topology is stable; when the Hello process changes, STP then needs to react and converge to a new STP topology. When STP has a stable topology, the following occurs: 1. The root switch generates a Hello regularly based on the Hello timer. 2. Each non-root switch regularly (based on the Hello timer) receives a copy of the root’s Hello on its RP. 3. Each switch updates and forwards the Hello out its Desi..
If ever there were a technology to consider outsourcing, it is IPsec. After you read this chapter, you should strongly consider whether it would be better to just write a nice check to your ISP for an outsourced VPN solution. IPsec deployment is at least 50 percent networking, and good SPs do networking pretty darn well. There are two main outsourcing options: • Network-based managed IPsec IPsec starts and ends in your SP's cloud. • Cu..
Next, you need to choose the VTP mode for the new switch. The three VTP modes of operation and their guidelines for use are as follows: ■ Server mode—Server mode can be used on any switch in a management domain, even if other server and client switches are in use. This mode provides some redundancy in case of a server failure in the domain. Each VTP management domain should have at least one server. The first server defined in a network also defines the management domain..



