routers update
This commit is contained in:
parent
e60ab3ebfb
commit
f1e8faa797
11 changed files with 146 additions and 13 deletions
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:51 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.21.4
|
||||
# software id = K4QG-8NQV
|
||||
#
|
||||
# model = RB5009UG+S+
|
||||
|
|
@ -503,6 +503,8 @@ add disabled=no lsr-id=10.254.254.111 transport-addresses=10.254.254.111 vrf=\
|
|||
main
|
||||
/mpls ldp interface
|
||||
add interface=ether2-climax
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set interim-update=15m use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:51 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.21.4
|
||||
# software id = FUVS-HCM5
|
||||
#
|
||||
# model = CCR1009-7G-1C-1S+
|
||||
|
|
@ -445,6 +445,8 @@ add disabled=no lsr-id=10.254.254.110 transport-addresses=10.254.254.110 vrf=\
|
|||
main
|
||||
/mpls ldp interface
|
||||
add interface=ether7-380
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:51 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:43 by RouterOS 7.21.4
|
||||
# software id = UETF-WF31
|
||||
#
|
||||
# model = CCR2004-16G-2S+
|
||||
|
|
@ -473,6 +473,8 @@ add disabled=no lsr-id=10.254.254.102 transport-addresses=10.254.254.102 vrf=\
|
|||
add interface=ether6-verona-11ghz
|
||||
add interface=ether4-380-airfiber24
|
||||
add interface=ether5-494
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set interim-update=1h use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:52 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.21.4
|
||||
# software id = XS5B-41QR
|
||||
#
|
||||
# model = CCR1009-7G-1C-1S+
|
||||
|
|
@ -433,6 +433,16 @@ add action=accept chain=forward comment=\
|
|||
"bypass fasttrack for MPLS spine (out)" out-interface=ether5-climax
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (in)" in-interface=ether5-climax
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (in)" in-interface=ether3-edge-direct
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (out)" out-interface=ether3-edge-direct
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (in)" in-interface=\
|
||||
sfp-sfpplus1-edge-preseem
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (out)" out-interface=\
|
||||
sfp-sfpplus1-edge-preseem
|
||||
add action=fasttrack-connection chain=forward comment=\
|
||||
"fasttrack established/related" connection-state=established,related
|
||||
add action=drop chain=forward disabled=yes src-address-list=suspended
|
||||
|
|
@ -558,6 +568,8 @@ add interface=ether5-climax mpls-mtu=1508
|
|||
add interface=ether6-culleoka-11ghz mpls-mtu=1508
|
||||
add interface=ether4-newhope mpls-mtu=1508
|
||||
add interface=ether1-982-60ghz mpls-mtu=1508
|
||||
add interface=ether3-edge-direct mpls-mtu=1508
|
||||
add interface=sfp-sfpplus1-edge-preseem mpls-mtu=1508
|
||||
/mpls ldp
|
||||
add disabled=no lsr-id=10.254.254.253 transport-addresses=10.254.254.253 vrf=\
|
||||
main
|
||||
|
|
@ -566,6 +578,8 @@ add interface=ether5-climax
|
|||
add interface=ether6-culleoka-11ghz
|
||||
add interface=ether4-newhope
|
||||
add interface=ether1-982-60ghz
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:52 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.21.4
|
||||
# software id = HVP9-3G0K
|
||||
#
|
||||
# model = CCR1009-7G-1C-1S+
|
||||
|
|
@ -651,6 +651,8 @@ add disabled=no lsr-id=10.254.254.104 transport-addresses=10.254.254.104 vrf=\
|
|||
main
|
||||
/mpls ldp interface
|
||||
add interface=ether6-380-11ghz
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set interim-update=1h use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# may/09/2026 13:02:52 by RouterOS 6.49.18
|
||||
# may/09/2026 14:55:43 by RouterOS 6.49.18
|
||||
# software id = 8XZE-R7EJ
|
||||
#
|
||||
# model = CCR2004-1G-12S+2XS
|
||||
|
|
@ -283,6 +283,17 @@ add action=accept chain=forward comment="Established Forward" \
|
|||
connection-state=established,related
|
||||
add action=accept chain=input comment="Allow Remote Winbox" disabled=yes \
|
||||
in-interface=*18
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (in)" in-interface=\
|
||||
sfp-sfpplus7-core-direct
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (out)" out-interface=\
|
||||
sfp-sfpplus7-core-direct
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (in)" in-interface=sfp-sfpplus11-preseem
|
||||
add action=accept chain=forward comment=\
|
||||
"bypass fasttrack for MPLS spine (out)" out-interface=\
|
||||
sfp-sfpplus11-preseem
|
||||
add action=fasttrack-connection chain=forward comment=\
|
||||
"fasttrack established/related" connection-state=established,related
|
||||
add action=accept chain=forward comment="accept established/related" \
|
||||
|
|
@ -573,13 +584,16 @@ add comment="infra: via direct (backup)" distance=2 dst-address=\
|
|||
/mpls interface
|
||||
set [ find default=yes ] mpls-mtu=1530
|
||||
add interface=sfp-sfpplus8-server-switch mpls-mtu=1530
|
||||
add interface=sfp-sfpplus7-core-direct
|
||||
add interface=sfp-sfpplus11-preseem
|
||||
/mpls ldp
|
||||
set distribute-for-default-route=yes enabled=yes loop-detect=yes lsr-id=\
|
||||
10.254.254.254 transport-address=10.254.254.254
|
||||
set enabled=yes loop-detect=yes lsr-id=10.254.254.254 transport-address=\
|
||||
10.254.254.254
|
||||
/mpls ldp accept-filter
|
||||
add
|
||||
/mpls ldp advertise-filter
|
||||
add
|
||||
add prefix=10.254.254.254/32
|
||||
add advertise=no
|
||||
/mpls ldp interface
|
||||
add disabled=yes interface=ether1
|
||||
add disabled=yes interface=sfp-sfpplus11-preseem transport-address=\
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:51 by RouterOS 7.22.3
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.22.3
|
||||
# software id = ZGNY-ZJW7
|
||||
#
|
||||
# model = RB5009UG+S+
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:52 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.21.4
|
||||
# software id = 2I9X-PQZP
|
||||
#
|
||||
# model = CCR1009-7G-1C-1S+
|
||||
|
|
@ -1322,6 +1322,8 @@ add disabled=no lsr-id=10.254.254.109 transport-addresses=10.254.254.109 vrf=\
|
|||
main
|
||||
/mpls ldp interface
|
||||
add interface=ether1-newhope
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set interim-update=1h use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
|
|
@ -211,3 +211,94 @@ returns the box to plain IP forwarding. OSPF is untouched.
|
|||
its loopback as `lsr-id`/`transport-addresses`, then add `/mpls ldp
|
||||
interface` on the link to whichever existing MPLS router it peers with.
|
||||
No flag day.
|
||||
|
||||
---
|
||||
|
||||
# Deferred work (2026-05-09 session)
|
||||
|
||||
## Customer traceroute hop-collapse — partially done
|
||||
|
||||
**Goal**: customer traceroutes from any tower should look like
|
||||
`customer → tower → core → edge → TWC → ...` — collapsing the intermediate
|
||||
spine LSRs (climax, newhope) into invisible transit hops.
|
||||
|
||||
**What's done as of 2026-05-09**:
|
||||
|
||||
- `propagate-ttl=no` set on all 8 fleet routers (verona/climax/culleoka/
|
||||
newhope/lowry/982/494/core). This switches MPLS from the default uniform
|
||||
model to the pipe model: ingress LSR sets label-TTL=255 (independent of
|
||||
IP-TTL), transit LSRs decrement label-TTL only, egress preserves the
|
||||
IP-TTL across the LSP. Effect: any traffic that actually rides an LSP
|
||||
collapses the intermediate label-switching hops in traceroute.
|
||||
- This works **today** for traffic whose destination has an LDP label
|
||||
binding — i.e., loopback-to-loopback (`10.254.254.x/32` between any
|
||||
two fleet routers), tower-to-tower-customer-prefix (`100.64.x.x/32`,
|
||||
the tower /44s), and the connected /29 backbone links. Verified:
|
||||
`verona /tool/traceroute 10.254.254.109` returns a single hop (lowry),
|
||||
the climax↔core↔newhope spine is invisible.
|
||||
|
||||
**What's still missing (the actual goal — customer→internet collapse)**:
|
||||
|
||||
ROS picks an outgoing label based on the **destination prefix's FEC**, not
|
||||
on the recursive next-hop. Internet destinations like `1.1.1.1` have no
|
||||
LDP label in any tower's forwarding table, so the packet leaves plain-IP
|
||||
even when the tower's static default points at a labeled prefix
|
||||
(`10.254.254.253` or `10.254.254.254`). We tested both gateway changes on
|
||||
494 — neither caused label imposition. Reverted.
|
||||
|
||||
**To finish this** the fleet would need **BGP labeled unicast** (RFC 3107,
|
||||
ROS `address-families=ip-labeled-unicast` on iBGP):
|
||||
|
||||
1. Core (and/or edge once MPLS-to-edge is solved) advertises BGP routes
|
||||
to towers with labels attached. Simplest version: just the default
|
||||
route `0.0.0.0/0` with next-hop=core's loopback and a label.
|
||||
2. Towers receive labeled BGP routes. When forwarding to any destination
|
||||
matching such a route, the tower pushes the BGP-LU label, then the LDP
|
||||
transport label on top, and rides the LSP.
|
||||
3. With `propagate-ttl=no` already set, the LSP is invisible in
|
||||
traceroute. Customer sees `tower → core → edge → TWC → ...` (3 hops to
|
||||
TWC, regardless of which tower they're on).
|
||||
|
||||
**Why we didn't do it today**:
|
||||
- Three MPLS-related outages already (`asymmetric_ldp_parallel_paths`
|
||||
memory entry). Don't add a fourth without a maintenance window.
|
||||
- BGP-LU isn't tested in this fleet. Need to:
|
||||
- Confirm ROS7 syntax for `address-families=ip-labeled-unicast` on the
|
||||
existing iBGP-RR mesh.
|
||||
- Decide whether to advertise LU labels for just the default route or
|
||||
for the full reflected RIB.
|
||||
- Decide what core advertises — just `0.0.0.0/0`, or also tower /44s
|
||||
so return-path traffic from edge to tower customers can also ride
|
||||
a labeled path with hop hiding (currently the return path
|
||||
edge → core → tower is plain-IP edge→core then labeled core→tower).
|
||||
- A future attempt should also revisit whether MPLS-to-edge is desirable
|
||||
alongside this. With BGP-LU from core, edge doesn't need to be in LDP
|
||||
for towers to ride an LSP toward edge — the LSP terminates at core
|
||||
(where the BGP-LU label is popped), and edge sees plain IP exactly
|
||||
like today. So **BGP-LU may be a cleaner path than extending LDP to
|
||||
edge** for this specific goal.
|
||||
|
||||
## Extending LDP to edge — blocked, root cause unknown
|
||||
|
||||
See `~/.claude/projects/-Users-graham-dev-network-mikrotik-tool/memory/
|
||||
asymmetric_ldp_parallel_paths.md` for the full incident notes. Three live
|
||||
attempts on 2026-05-09 to bring up an LDP session between core and edge
|
||||
all dropped fleet internet traffic within seconds. Hypotheses tried and
|
||||
disproven: asymmetric LDP path redirect, BGP-table label flooding (we
|
||||
tightened edge's advertise-filter to just `10.254.254.254/32`), and the
|
||||
flood still happened. **Don't attempt again live without lab replication
|
||||
or a console on edge.**
|
||||
|
||||
State left in place that survives across attempts:
|
||||
- `mpls-mtu=1508` on edge `sfp-sfpplus7-core-direct` and
|
||||
`sfp-sfpplus11-preseem`.
|
||||
- `mpls-mtu=1508` on core `ether3-edge-direct` and
|
||||
`sfp-sfpplus1-edge-preseem`.
|
||||
- Fasttrack-bypass pairs (in/out) on chain=forward for those four
|
||||
interfaces on both routers.
|
||||
- Edge `/mpls ldp advertise-filter` restricted to advertise only
|
||||
`10.254.254.254/32`.
|
||||
- Edge `/mpls ldp set distribute-for-default-route=no`.
|
||||
|
||||
These are all harmless and would be required again on the next attempt;
|
||||
do not roll them back.
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:52 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.21.4
|
||||
# software id = 5HTF-YFWV
|
||||
#
|
||||
# model = CCR1009-7G-1C-1S+
|
||||
|
|
@ -582,6 +582,8 @@ add disabled=no lsr-id=10.254.254.108 transport-addresses=10.254.254.108 vrf=\
|
|||
/mpls ldp interface
|
||||
add interface=ether2-380
|
||||
add interface=ether6-lowrycrossing
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set interim-update=1h use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# 2026-05-09 13:02:51 by RouterOS 7.21.4
|
||||
# 2026-05-09 14:55:44 by RouterOS 7.21.4
|
||||
# software id = Y1CT-1WB1
|
||||
#
|
||||
# model = CCR2004-16G-2S+
|
||||
|
|
@ -968,6 +968,8 @@ add disabled=no lsr-id=10.254.254.101 transport-addresses=10.254.254.101 vrf=\
|
|||
main
|
||||
/mpls ldp interface
|
||||
add interface=ether3-climax-11ghz
|
||||
/mpls settings
|
||||
set propagate-ttl=no
|
||||
/ppp aaa
|
||||
set interim-update=15m use-radius=yes
|
||||
/radius
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue