routers update

This commit is contained in:
Graham McIntire 2026-05-09 14:56:17 -05:00
parent e60ab3ebfb
commit f1e8faa797
No known key found for this signature in database
GPG key ID: F4ABF488E6029E59
11 changed files with 146 additions and 13 deletions

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:51 by RouterOS 7.21.4
# 2026-05-09 14:55:44 by RouterOS 7.21.4
# software id = K4QG-8NQV
#
# model = RB5009UG+S+
@ -503,6 +503,8 @@ add disabled=no lsr-id=10.254.254.111 transport-addresses=10.254.254.111 vrf=\
main
/mpls ldp interface
add interface=ether2-climax
/mpls settings
set propagate-ttl=no
/ppp aaa
set interim-update=15m use-radius=yes
/radius

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:51 by RouterOS 7.21.4
# 2026-05-09 14:55:44 by RouterOS 7.21.4
# software id = FUVS-HCM5
#
# model = CCR1009-7G-1C-1S+
@ -445,6 +445,8 @@ add disabled=no lsr-id=10.254.254.110 transport-addresses=10.254.254.110 vrf=\
main
/mpls ldp interface
add interface=ether7-380
/mpls settings
set propagate-ttl=no
/ppp aaa
set use-radius=yes
/radius

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:51 by RouterOS 7.21.4
# 2026-05-09 14:55:43 by RouterOS 7.21.4
# software id = UETF-WF31
#
# model = CCR2004-16G-2S+
@ -473,6 +473,8 @@ add disabled=no lsr-id=10.254.254.102 transport-addresses=10.254.254.102 vrf=\
add interface=ether6-verona-11ghz
add interface=ether4-380-airfiber24
add interface=ether5-494
/mpls settings
set propagate-ttl=no
/ppp aaa
set interim-update=1h use-radius=yes
/radius

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:52 by RouterOS 7.21.4
# 2026-05-09 14:55:44 by RouterOS 7.21.4
# software id = XS5B-41QR
#
# model = CCR1009-7G-1C-1S+
@ -433,6 +433,16 @@ add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (out)" out-interface=ether5-climax
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (in)" in-interface=ether5-climax
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (in)" in-interface=ether3-edge-direct
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (out)" out-interface=ether3-edge-direct
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (in)" in-interface=\
sfp-sfpplus1-edge-preseem
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (out)" out-interface=\
sfp-sfpplus1-edge-preseem
add action=fasttrack-connection chain=forward comment=\
"fasttrack established/related" connection-state=established,related
add action=drop chain=forward disabled=yes src-address-list=suspended
@ -558,6 +568,8 @@ add interface=ether5-climax mpls-mtu=1508
add interface=ether6-culleoka-11ghz mpls-mtu=1508
add interface=ether4-newhope mpls-mtu=1508
add interface=ether1-982-60ghz mpls-mtu=1508
add interface=ether3-edge-direct mpls-mtu=1508
add interface=sfp-sfpplus1-edge-preseem mpls-mtu=1508
/mpls ldp
add disabled=no lsr-id=10.254.254.253 transport-addresses=10.254.254.253 vrf=\
main
@ -566,6 +578,8 @@ add interface=ether5-climax
add interface=ether6-culleoka-11ghz
add interface=ether4-newhope
add interface=ether1-982-60ghz
/mpls settings
set propagate-ttl=no
/ppp aaa
set use-radius=yes
/radius

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:52 by RouterOS 7.21.4
# 2026-05-09 14:55:44 by RouterOS 7.21.4
# software id = HVP9-3G0K
#
# model = CCR1009-7G-1C-1S+
@ -651,6 +651,8 @@ add disabled=no lsr-id=10.254.254.104 transport-addresses=10.254.254.104 vrf=\
main
/mpls ldp interface
add interface=ether6-380-11ghz
/mpls settings
set propagate-ttl=no
/ppp aaa
set interim-update=1h use-radius=yes
/radius

View file

@ -1,4 +1,4 @@
# may/09/2026 13:02:52 by RouterOS 6.49.18
# may/09/2026 14:55:43 by RouterOS 6.49.18
# software id = 8XZE-R7EJ
#
# model = CCR2004-1G-12S+2XS
@ -283,6 +283,17 @@ add action=accept chain=forward comment="Established Forward" \
connection-state=established,related
add action=accept chain=input comment="Allow Remote Winbox" disabled=yes \
in-interface=*18
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (in)" in-interface=\
sfp-sfpplus7-core-direct
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (out)" out-interface=\
sfp-sfpplus7-core-direct
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (in)" in-interface=sfp-sfpplus11-preseem
add action=accept chain=forward comment=\
"bypass fasttrack for MPLS spine (out)" out-interface=\
sfp-sfpplus11-preseem
add action=fasttrack-connection chain=forward comment=\
"fasttrack established/related" connection-state=established,related
add action=accept chain=forward comment="accept established/related" \
@ -573,13 +584,16 @@ add comment="infra: via direct (backup)" distance=2 dst-address=\
/mpls interface
set [ find default=yes ] mpls-mtu=1530
add interface=sfp-sfpplus8-server-switch mpls-mtu=1530
add interface=sfp-sfpplus7-core-direct
add interface=sfp-sfpplus11-preseem
/mpls ldp
set distribute-for-default-route=yes enabled=yes loop-detect=yes lsr-id=\
10.254.254.254 transport-address=10.254.254.254
set enabled=yes loop-detect=yes lsr-id=10.254.254.254 transport-address=\
10.254.254.254
/mpls ldp accept-filter
add
/mpls ldp advertise-filter
add
add prefix=10.254.254.254/32
add advertise=no
/mpls ldp interface
add disabled=yes interface=ether1
add disabled=yes interface=sfp-sfpplus11-preseem transport-address=\

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:51 by RouterOS 7.22.3
# 2026-05-09 14:55:44 by RouterOS 7.22.3
# software id = ZGNY-ZJW7
#
# model = RB5009UG+S+

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:52 by RouterOS 7.21.4
# 2026-05-09 14:55:44 by RouterOS 7.21.4
# software id = 2I9X-PQZP
#
# model = CCR1009-7G-1C-1S+
@ -1322,6 +1322,8 @@ add disabled=no lsr-id=10.254.254.109 transport-addresses=10.254.254.109 vrf=\
main
/mpls ldp interface
add interface=ether1-newhope
/mpls settings
set propagate-ttl=no
/ppp aaa
set interim-update=1h use-radius=yes
/radius

View file

@ -211,3 +211,94 @@ returns the box to plain IP forwarding. OSPF is untouched.
its loopback as `lsr-id`/`transport-addresses`, then add `/mpls ldp
interface` on the link to whichever existing MPLS router it peers with.
No flag day.
---
# Deferred work (2026-05-09 session)
## Customer traceroute hop-collapse — partially done
**Goal**: customer traceroutes from any tower should look like
`customer → tower → core → edge → TWC → ...` — collapsing the intermediate
spine LSRs (climax, newhope) into invisible transit hops.
**What's done as of 2026-05-09**:
- `propagate-ttl=no` set on all 8 fleet routers (verona/climax/culleoka/
newhope/lowry/982/494/core). This switches MPLS from the default uniform
model to the pipe model: ingress LSR sets label-TTL=255 (independent of
IP-TTL), transit LSRs decrement label-TTL only, egress preserves the
IP-TTL across the LSP. Effect: any traffic that actually rides an LSP
collapses the intermediate label-switching hops in traceroute.
- This works **today** for traffic whose destination has an LDP label
binding — i.e., loopback-to-loopback (`10.254.254.x/32` between any
two fleet routers), tower-to-tower-customer-prefix (`100.64.x.x/32`,
the tower /44s), and the connected /29 backbone links. Verified:
`verona /tool/traceroute 10.254.254.109` returns a single hop (lowry),
the climax↔core↔newhope spine is invisible.
**What's still missing (the actual goal — customer→internet collapse)**:
ROS picks an outgoing label based on the **destination prefix's FEC**, not
on the recursive next-hop. Internet destinations like `1.1.1.1` have no
LDP label in any tower's forwarding table, so the packet leaves plain-IP
even when the tower's static default points at a labeled prefix
(`10.254.254.253` or `10.254.254.254`). We tested both gateway changes on
494 — neither caused label imposition. Reverted.
**To finish this** the fleet would need **BGP labeled unicast** (RFC 3107,
ROS `address-families=ip-labeled-unicast` on iBGP):
1. Core (and/or edge once MPLS-to-edge is solved) advertises BGP routes
to towers with labels attached. Simplest version: just the default
route `0.0.0.0/0` with next-hop=core's loopback and a label.
2. Towers receive labeled BGP routes. When forwarding to any destination
matching such a route, the tower pushes the BGP-LU label, then the LDP
transport label on top, and rides the LSP.
3. With `propagate-ttl=no` already set, the LSP is invisible in
traceroute. Customer sees `tower → core → edge → TWC → ...` (3 hops to
TWC, regardless of which tower they're on).
**Why we didn't do it today**:
- Three MPLS-related outages already (`asymmetric_ldp_parallel_paths`
memory entry). Don't add a fourth without a maintenance window.
- BGP-LU isn't tested in this fleet. Need to:
- Confirm ROS7 syntax for `address-families=ip-labeled-unicast` on the
existing iBGP-RR mesh.
- Decide whether to advertise LU labels for just the default route or
for the full reflected RIB.
- Decide what core advertises — just `0.0.0.0/0`, or also tower /44s
so return-path traffic from edge to tower customers can also ride
a labeled path with hop hiding (currently the return path
edge → core → tower is plain-IP edge→core then labeled core→tower).
- A future attempt should also revisit whether MPLS-to-edge is desirable
alongside this. With BGP-LU from core, edge doesn't need to be in LDP
for towers to ride an LSP toward edge — the LSP terminates at core
(where the BGP-LU label is popped), and edge sees plain IP exactly
like today. So **BGP-LU may be a cleaner path than extending LDP to
edge** for this specific goal.
## Extending LDP to edge — blocked, root cause unknown
See `~/.claude/projects/-Users-graham-dev-network-mikrotik-tool/memory/
asymmetric_ldp_parallel_paths.md` for the full incident notes. Three live
attempts on 2026-05-09 to bring up an LDP session between core and edge
all dropped fleet internet traffic within seconds. Hypotheses tried and
disproven: asymmetric LDP path redirect, BGP-table label flooding (we
tightened edge's advertise-filter to just `10.254.254.254/32`), and the
flood still happened. **Don't attempt again live without lab replication
or a console on edge.**
State left in place that survives across attempts:
- `mpls-mtu=1508` on edge `sfp-sfpplus7-core-direct` and
`sfp-sfpplus11-preseem`.
- `mpls-mtu=1508` on core `ether3-edge-direct` and
`sfp-sfpplus1-edge-preseem`.
- Fasttrack-bypass pairs (in/out) on chain=forward for those four
interfaces on both routers.
- Edge `/mpls ldp advertise-filter` restricted to advertise only
`10.254.254.254/32`.
- Edge `/mpls ldp set distribute-for-default-route=no`.
These are all harmless and would be required again on the next attempt;
do not roll them back.

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:52 by RouterOS 7.21.4
# 2026-05-09 14:55:44 by RouterOS 7.21.4
# software id = 5HTF-YFWV
#
# model = CCR1009-7G-1C-1S+
@ -582,6 +582,8 @@ add disabled=no lsr-id=10.254.254.108 transport-addresses=10.254.254.108 vrf=\
/mpls ldp interface
add interface=ether2-380
add interface=ether6-lowrycrossing
/mpls settings
set propagate-ttl=no
/ppp aaa
set interim-update=1h use-radius=yes
/radius

View file

@ -1,4 +1,4 @@
# 2026-05-09 13:02:51 by RouterOS 7.21.4
# 2026-05-09 14:55:44 by RouterOS 7.21.4
# software id = Y1CT-1WB1
#
# model = CCR2004-16G-2S+
@ -968,6 +968,8 @@ add disabled=no lsr-id=10.254.254.101 transport-addresses=10.254.254.101 vrf=\
main
/mpls ldp interface
add interface=ether3-climax-11ghz
/mpls settings
set propagate-ttl=no
/ppp aaa
set interim-update=15m use-radius=yes
/radius