Summary of the content on the page No. 1
APPENDIX A
Sample Configlets
This appendix provides sample configlets for L2VPN and Metro Ethernet service provisioning in ISC.
It contains the following sections:
• Overview, page A-1
� ERS (Point-to-Point), page A-3
� ERS (Point-to-Point) with UNI Port Security, page A-4
� EWS (Point-to-Point), page A-6
� EWS (Point-to-Point) with UNI Port Security, BPDU Tunneling, page A-7
� EWS Hybrid, page A-9
� VPLS (Multipoint) ERS, page A-12
� VPLS (Multipoint) EWS with BPDU Tunneling, page A-13
� ERS
Summary of the content on the page No. 2
Appendix A Sample Configlets Overview Note The configlets generated by ISC are only the delta between what needs to be provisioned and what currently exists on the device. This means that if a relevant CLI is already on the device, it does not show up in the associated configlet. Note The CLIs shown in bold are the most relevant commands. Note All examples in this appendix assume an MPLS core. Cisco IP Solution Center Metro Ethernet and L2VPN User Guide, 4.2 A-2 OL-10729-01
Summary of the content on the page No. 3
Appendix A Sample Configlets ERS (Point-to-Point) ERS (Point-to-Point) Configuration � Service: L2VPN/Metro Ethernet � Feature: ERS (point-to-point) � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with 12.2(25)EY1, no port security – L2VPN point-to-point. – C3750ME (FA1/0/4 – FA1/0/23) <–> C7600 (FA8/17) Configlets UP-E N-PE vlan 772 vlan 772 exit exit ! ! interface FastEthernet1/0/23 interface FastEthernet8/17 switchport tr
Summary of the content on the page No. 4
Appendix A Sample Configlets ERS (Point-to-Point) with UNI Port Security ERS (Point-to-Point) with UNI Port Security Configuration � Service: L2VPN/Metro Ethernet � Feature: ERS (point-to-point) with UNI port security � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, OSM – The U-PE is a CISCO3550 with IOS 12.2(25)SEC2. Port security is enabled. – L2VPN point-to-point – C3550ME (FA3/31– FA3/23) <–> C7600 (FA2/18) Configlets UP-E N-PE vlan 788 vlan 788 exit exit ! ! in
Summary of the content on the page No. 5
Appendix A Sample Configlets ERS (Point-to-Point) with UNI Port Security � A user-defined PACL entry is added to the default PACL. Cisco IP Solution Center Metro Ethernet and L2VPN User Guide, 4.2 OL-10729-01 A-5
Summary of the content on the page No. 6
Appendix A Sample Configlets EWS (Point-to-Point) EWS (Point-to-Point) Configuration � Service: L2VPN/Metro Ethernet � Feature: EWS (point-to-point) � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with IOS 12.2(25)EY1. No port security, no tunneling. – L2VPN point-to-point – QinQ UNI – C3750ME (FA1/0/20 – FA1/0/23) <–> C7600 (FA8/17) Configlets UP-E N-PE system mtu 1522 vlan 774 ! exit vlan 774 ! exit interface FastEthernet8/
Summary of the content on the page No. 7
Appendix A Sample Configlets EWS (Point-to-Point) with UNI Port Security, BPDU Tunneling EWS (Point-to-Point) with UNI Port Security, BPDU Tunneling Configuration � Service: L2VPN/Metro Ethernet � Feature: EWS (point-to-point) with Port security, BPDU tunneling � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with IOS 12.2(25)EY1. No port security, with tunneling. – L2VPN point-to-point – QinQ UNI Cisco IP Solution Center Metr
Summary of the content on the page No. 8
Appendix A Sample Configlets EWS (Point-to-Point) with UNI Port Security, BPDU Tunneling Configlets UP-E N-PE system mtu 1522 vlan 775 ! exit vlan 775 ! exit interface FastEthernet8/17 ! switchport trunk allowed vlan system mtu 1522 1,451,653,659,766-768,772,773-775,878 ! ! vlan 775 interface Vlan775 exit no ip address ! description L2VPN EWS interface FastEthernet1/0/19 xconnect 99.99.8.99 89029 encapsulation no cdp enable mpls no keepalive no shutdown switchport switchport access vlan
Summary of the content on the page No. 9
Appendix A Sample Configlets EWS Hybrid EWS Hybrid Configuration � Service: L2VPN/Metro Ethernet � Feature: EWS hybrid. One side is EWS UNI; the other side is ERS NNI � Device configuration: – The N-PE is a CISCO7600 with 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with 12.2(25)EY1. No port security, with tunneling. – L2VPN point-to-point – QinQ UNI – C3750ME (FA1/0/20 – FA1/0/23) <–> C7600 (FA8/17) Note The first configlet example is the EWS side (UNI). The second configlet is t
Summary of the content on the page No. 10
Appendix A Sample Configlets EWS Hybrid Configlets (EWS) UP-E N-PE system mtu 1522 vlan 775 ! exit vlan 775 ! exit interface FastEthernet8/17 ! switchport trunk allowed vlan system mtu 1522 1,451,653,659,766-768,772,773-775,878 ! ! vlan 775 interface Vlan775 exit no ip address ! description L2VPN EWS interface FastEthernet1/0/19 xconnect 99.99.8.99 89029 encapsulation no cdp enable mpls no keepalive no shutdown switchport switchport access vlan 775 switchport mode dot1q-tunnel switchpor
Summary of the content on the page No. 11
Appendix A Sample Configlets EWS Hybrid Configlets (ERS) UP-E N-PE system mtu 1522 vlan 775 exit vlan 775 ! exit interface FastEthernet8/17 switchport trunk allowed vlan interface FastEthernet1/17 1,451,653,659,766-768,772,773-775,878 switchport trunk allowed vlan ! 1,451,653,659,766-768,772,773-775,878 interface Vlan775 no ip address interface FastEthernet1/10 description L2VPN EWS switchport trunk allowed vlan xconnect 99.99.8.99 89029 encapsulation 1,451,653,659,766-768,772,773-775,8
Summary of the content on the page No. 12
Appendix A Sample Configlets VPLS (Multipoint) ERS VPLS (Multipoint) ERS Configuration � Service: L2VPN/Metro Ethernet � Feature: VPLS (multipoint) ERS � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with IOS 12.2(25)EY1. No port security, no tunneling. – VPLS Multipoint VPN with VLAN 767 – C3750ME (FA1/0/21 – FA1/0/23) <–> C7600 (FA2/18) Configlets UP-E N-PE vlan 767 l2 vfi vpls_ers_1-0 manual exit vpn id 89017 ! neighbor 9
Summary of the content on the page No. 13
Appendix A Sample Configlets VPLS (Multipoint) EWS with BPDU Tunneling VPLS (Multipoint) EWS with BPDU Tunneling Configuration � Service: L2VPN/Metro Ethernet � Feature: VPLS (multipoint) EWS with BPDU tunneling � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with IOS 12.2(25)EY1. No port security, no tunneling. – VPLS Multipoint VPN, with VLAN 767 – QinQ UNI – C3750ME (FA1/0/12 – FA1/0/23) <–> C7600 (FA2/18) Configlets UP-E
Summary of the content on the page No. 14
Appendix A Sample Configlets ERS with 1:1 VLAN Translation ERS with 1:1 VLAN Translation Configuration � Service: L2VPN/Metro Ethernet � Feature: ERS with 1:1 VLAN translation � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with IOS 12.2(25)EY1. VLAN translation on the NNI port (uplink). – L2VPN point-to-point. – C3750ME (FA1/0/8 – GI1/1/1) <–> C7600 (FA8/34) Configlets UP-E N-PE ! vlan 778 vlan 123 exit exit ! ! interface
Summary of the content on the page No. 15
Appendix A Sample Configlets ERS with 2:1 VLAN Translation ERS with 2:1 VLAN Translation Configuration � Service: L2VPN/Metro Ethernet � Feature: ERS with VLAN 2:1 translation � Device configuration: – The N-PE is a CISCO7600 with IOS 12.2(18)SXF, Sup720-3BXL – The U-PE is a CISCO3750ME with IOS 12.2(25)EY1. VLAN translation on the NNI port (uplink). – L2VPN point-to-point. – C3750ME (FA1/0/5 – GI1/1/1) <–> C7600 (FA8/34) Configlets UP-E N-PE vlan 567 vlan 779 exit exit ! ! interface Fa
Summary of the content on the page No. 16
Appendix A Sample Configlets ATM over MPLS (VC Mode) ATM over MPLS (VC Mode) Configuration � Service: L2VPN � Feature: ATM over MPLS (ATMoMPLS, a type of AToM) in VC mode � Device configuration: – The N-PE is a CISCO7200 with IOS 12.0(28)S – No CE – No U-PE – L2VPN point-to-point (ATMoMPLS) – C7200 (ATM2/0) Configlets UP-E N-PE (None) interface ATM2/0.34234 point-to-point pvc 213/423 l2transport encapsulation aal5 xconnect 99.99.4.99 89025 encapsulation mpls Comments � The N-PE is any MP
Summary of the content on the page No. 17
Appendix A Sample Configlets ATM over MPLS (VP Mode) ATM over MPLS (VP Mode) Configuration � Service: L2VPN � Feature: ATM over MPLS (ATMoMPLS, a type of AToM) in VP mode � Device configuration: – The N-PE is a CISCO7200 with IOS 12.0(28)S – No CE – No U-PE – L2VPN point-to-point (ATMoMPLS) – C7200 (ATM2/0) Configlets UP-E N-PE (None) pseudowire-class ISC-pw-tunnel-123 encapsulation mpls preferred-path interface tunnel123 disable-fallback ! interface ATM2/0 atm pvp 131 l2transport xconne
Summary of the content on the page No. 18
Appendix A Sample Configlets Frame Relay over MPLS Frame Relay over MPLS Configuration � Service: L2VPN � Feature: Frame Relay over MPLS (FRoMPLS, a type of AToM) � Device configuration: – The N-PE is a CISCO7200 with IOS 12.0(28)S – No CE – No U-PE – L2VPN point-to-point (ATMoMPLS) – C7200 (ATM2/0) Configlets UP-E N-PE (None) interface Serial1/1 exit ! connect C1_89001 Serial1/1 135 l2transport xconnect 99.99.4.99 89001 encapsulation mpls Comments � The N-PE is any MPLS-enabled router.
Summary of the content on the page No. 19
Appendix A Sample Configlets Frame Relay (DLCI Mode) Frame Relay (DLCI Mode) Configuration � Service: L2VPN over a L2TPv3 core � Feature: FR in DLCI mode � Device configuration: – The N-PE is a CISCO7200 with IOS 12.0(28)S – No CE – No U-PE – L2VPN point-to-point (ATMoMPLS) – C7200 (ATM2/0) Configlets UP-E N-PE (None) pseudowire-class ISC-pw-dynamic-default encapsulation l2tpv3 ip local interface Loopback10 ip dfbit set ! interface Serial3/2 encapsulation frame-relay exit ! connect ISC_10
Summary of the content on the page No. 20
Appendix A Sample Configlets Frame Relay (DLCI Mode) Cisco IP Solution Center Metro Ethernet and L2VPN User Guide, 4.2 A-20 OL-10729-01