diff --git a/mikrotik-tool/494.rsc b/mikrotik-tool/494.rsc index ba0f3f2..2b8854e 100644 --- a/mikrotik-tool/494.rsc +++ b/mikrotik-tool/494.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:51 by RouterOS 7.21.4 +# 2026-05-09 14:55:44 by RouterOS 7.21.4 # software id = K4QG-8NQV # # model = RB5009UG+S+ @@ -503,6 +503,8 @@ add disabled=no lsr-id=10.254.254.111 transport-addresses=10.254.254.111 vrf=\ main /mpls ldp interface add interface=ether2-climax +/mpls settings +set propagate-ttl=no /ppp aaa set interim-update=15m use-radius=yes /radius diff --git a/mikrotik-tool/982.rsc b/mikrotik-tool/982.rsc index 297f1e0..033aabd 100644 --- a/mikrotik-tool/982.rsc +++ b/mikrotik-tool/982.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:51 by RouterOS 7.21.4 +# 2026-05-09 14:55:44 by RouterOS 7.21.4 # software id = FUVS-HCM5 # # model = CCR1009-7G-1C-1S+ @@ -445,6 +445,8 @@ add disabled=no lsr-id=10.254.254.110 transport-addresses=10.254.254.110 vrf=\ main /mpls ldp interface add interface=ether7-380 +/mpls settings +set propagate-ttl=no /ppp aaa set use-radius=yes /radius diff --git a/mikrotik-tool/climax.rsc b/mikrotik-tool/climax.rsc index 2faae67..4b31723 100644 --- a/mikrotik-tool/climax.rsc +++ b/mikrotik-tool/climax.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:51 by RouterOS 7.21.4 +# 2026-05-09 14:55:43 by RouterOS 7.21.4 # software id = UETF-WF31 # # model = CCR2004-16G-2S+ @@ -473,6 +473,8 @@ add disabled=no lsr-id=10.254.254.102 transport-addresses=10.254.254.102 vrf=\ add interface=ether6-verona-11ghz add interface=ether4-380-airfiber24 add interface=ether5-494 +/mpls settings +set propagate-ttl=no /ppp aaa set interim-update=1h use-radius=yes /radius diff --git a/mikrotik-tool/core.rsc b/mikrotik-tool/core.rsc index 8fb1253..af6323d 100644 --- a/mikrotik-tool/core.rsc +++ b/mikrotik-tool/core.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:52 by RouterOS 7.21.4 +# 2026-05-09 14:55:44 by RouterOS 7.21.4 # software id = XS5B-41QR # # model = CCR1009-7G-1C-1S+ @@ -433,6 +433,16 @@ add action=accept chain=forward comment=\ "bypass fasttrack for MPLS spine (out)" out-interface=ether5-climax add action=accept chain=forward comment=\ "bypass fasttrack for MPLS spine (in)" in-interface=ether5-climax +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (in)" in-interface=ether3-edge-direct +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (out)" out-interface=ether3-edge-direct +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (in)" in-interface=\ + sfp-sfpplus1-edge-preseem +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (out)" out-interface=\ + sfp-sfpplus1-edge-preseem add action=fasttrack-connection chain=forward comment=\ "fasttrack established/related" connection-state=established,related add action=drop chain=forward disabled=yes src-address-list=suspended @@ -558,6 +568,8 @@ add interface=ether5-climax mpls-mtu=1508 add interface=ether6-culleoka-11ghz mpls-mtu=1508 add interface=ether4-newhope mpls-mtu=1508 add interface=ether1-982-60ghz mpls-mtu=1508 +add interface=ether3-edge-direct mpls-mtu=1508 +add interface=sfp-sfpplus1-edge-preseem mpls-mtu=1508 /mpls ldp add disabled=no lsr-id=10.254.254.253 transport-addresses=10.254.254.253 vrf=\ main @@ -566,6 +578,8 @@ add interface=ether5-climax add interface=ether6-culleoka-11ghz add interface=ether4-newhope add interface=ether1-982-60ghz +/mpls settings +set propagate-ttl=no /ppp aaa set use-radius=yes /radius diff --git a/mikrotik-tool/culleoka.rsc b/mikrotik-tool/culleoka.rsc index e61b837..0852cfe 100644 --- a/mikrotik-tool/culleoka.rsc +++ b/mikrotik-tool/culleoka.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:52 by RouterOS 7.21.4 +# 2026-05-09 14:55:44 by RouterOS 7.21.4 # software id = HVP9-3G0K # # model = CCR1009-7G-1C-1S+ @@ -651,6 +651,8 @@ add disabled=no lsr-id=10.254.254.104 transport-addresses=10.254.254.104 vrf=\ main /mpls ldp interface add interface=ether6-380-11ghz +/mpls settings +set propagate-ttl=no /ppp aaa set interim-update=1h use-radius=yes /radius diff --git a/mikrotik-tool/edge.rsc b/mikrotik-tool/edge.rsc index d337992..18305a5 100644 --- a/mikrotik-tool/edge.rsc +++ b/mikrotik-tool/edge.rsc @@ -1,4 +1,4 @@ -# may/09/2026 13:02:52 by RouterOS 6.49.18 +# may/09/2026 14:55:43 by RouterOS 6.49.18 # software id = 8XZE-R7EJ # # model = CCR2004-1G-12S+2XS @@ -283,6 +283,17 @@ add action=accept chain=forward comment="Established Forward" \ connection-state=established,related add action=accept chain=input comment="Allow Remote Winbox" disabled=yes \ in-interface=*18 +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (in)" in-interface=\ + sfp-sfpplus7-core-direct +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (out)" out-interface=\ + sfp-sfpplus7-core-direct +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (in)" in-interface=sfp-sfpplus11-preseem +add action=accept chain=forward comment=\ + "bypass fasttrack for MPLS spine (out)" out-interface=\ + sfp-sfpplus11-preseem add action=fasttrack-connection chain=forward comment=\ "fasttrack established/related" connection-state=established,related add action=accept chain=forward comment="accept established/related" \ @@ -573,13 +584,16 @@ add comment="infra: via direct (backup)" distance=2 dst-address=\ /mpls interface set [ find default=yes ] mpls-mtu=1530 add interface=sfp-sfpplus8-server-switch mpls-mtu=1530 +add interface=sfp-sfpplus7-core-direct +add interface=sfp-sfpplus11-preseem /mpls ldp -set distribute-for-default-route=yes enabled=yes loop-detect=yes lsr-id=\ - 10.254.254.254 transport-address=10.254.254.254 +set enabled=yes loop-detect=yes lsr-id=10.254.254.254 transport-address=\ + 10.254.254.254 /mpls ldp accept-filter add /mpls ldp advertise-filter -add +add prefix=10.254.254.254/32 +add advertise=no /mpls ldp interface add disabled=yes interface=ether1 add disabled=yes interface=sfp-sfpplus11-preseem transport-address=\ diff --git a/mikrotik-tool/home.rsc b/mikrotik-tool/home.rsc index 33f521d..742d89e 100644 --- a/mikrotik-tool/home.rsc +++ b/mikrotik-tool/home.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:51 by RouterOS 7.22.3 +# 2026-05-09 14:55:44 by RouterOS 7.22.3 # software id = ZGNY-ZJW7 # # model = RB5009UG+S+ diff --git a/mikrotik-tool/lowry.rsc b/mikrotik-tool/lowry.rsc index 15430f1..142ed87 100644 --- a/mikrotik-tool/lowry.rsc +++ b/mikrotik-tool/lowry.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:52 by RouterOS 7.21.4 +# 2026-05-09 14:55:44 by RouterOS 7.21.4 # software id = 2I9X-PQZP # # model = CCR1009-7G-1C-1S+ @@ -1322,6 +1322,8 @@ add disabled=no lsr-id=10.254.254.109 transport-addresses=10.254.254.109 vrf=\ main /mpls ldp interface add interface=ether1-newhope +/mpls settings +set propagate-ttl=no /ppp aaa set interim-update=1h use-radius=yes /radius diff --git a/mikrotik-tool/mpls.md b/mikrotik-tool/mpls.md index 2354c98..ad9b57f 100644 --- a/mikrotik-tool/mpls.md +++ b/mikrotik-tool/mpls.md @@ -211,3 +211,94 @@ returns the box to plain IP forwarding. OSPF is untouched. its loopback as `lsr-id`/`transport-addresses`, then add `/mpls ldp interface` on the link to whichever existing MPLS router it peers with. No flag day. + +--- + +# Deferred work (2026-05-09 session) + +## Customer traceroute hop-collapse — partially done + +**Goal**: customer traceroutes from any tower should look like +`customer → tower → core → edge → TWC → ...` — collapsing the intermediate +spine LSRs (climax, newhope) into invisible transit hops. + +**What's done as of 2026-05-09**: + +- `propagate-ttl=no` set on all 8 fleet routers (verona/climax/culleoka/ + newhope/lowry/982/494/core). This switches MPLS from the default uniform + model to the pipe model: ingress LSR sets label-TTL=255 (independent of + IP-TTL), transit LSRs decrement label-TTL only, egress preserves the + IP-TTL across the LSP. Effect: any traffic that actually rides an LSP + collapses the intermediate label-switching hops in traceroute. +- This works **today** for traffic whose destination has an LDP label + binding — i.e., loopback-to-loopback (`10.254.254.x/32` between any + two fleet routers), tower-to-tower-customer-prefix (`100.64.x.x/32`, + the tower /44s), and the connected /29 backbone links. Verified: + `verona /tool/traceroute 10.254.254.109` returns a single hop (lowry), + the climax↔core↔newhope spine is invisible. + +**What's still missing (the actual goal — customer→internet collapse)**: + +ROS picks an outgoing label based on the **destination prefix's FEC**, not +on the recursive next-hop. Internet destinations like `1.1.1.1` have no +LDP label in any tower's forwarding table, so the packet leaves plain-IP +even when the tower's static default points at a labeled prefix +(`10.254.254.253` or `10.254.254.254`). We tested both gateway changes on +494 — neither caused label imposition. Reverted. + +**To finish this** the fleet would need **BGP labeled unicast** (RFC 3107, +ROS `address-families=ip-labeled-unicast` on iBGP): + +1. Core (and/or edge once MPLS-to-edge is solved) advertises BGP routes + to towers with labels attached. Simplest version: just the default + route `0.0.0.0/0` with next-hop=core's loopback and a label. +2. Towers receive labeled BGP routes. When forwarding to any destination + matching such a route, the tower pushes the BGP-LU label, then the LDP + transport label on top, and rides the LSP. +3. With `propagate-ttl=no` already set, the LSP is invisible in + traceroute. Customer sees `tower → core → edge → TWC → ...` (3 hops to + TWC, regardless of which tower they're on). + +**Why we didn't do it today**: +- Three MPLS-related outages already (`asymmetric_ldp_parallel_paths` + memory entry). Don't add a fourth without a maintenance window. +- BGP-LU isn't tested in this fleet. Need to: + - Confirm ROS7 syntax for `address-families=ip-labeled-unicast` on the + existing iBGP-RR mesh. + - Decide whether to advertise LU labels for just the default route or + for the full reflected RIB. + - Decide what core advertises — just `0.0.0.0/0`, or also tower /44s + so return-path traffic from edge to tower customers can also ride + a labeled path with hop hiding (currently the return path + edge → core → tower is plain-IP edge→core then labeled core→tower). +- A future attempt should also revisit whether MPLS-to-edge is desirable + alongside this. With BGP-LU from core, edge doesn't need to be in LDP + for towers to ride an LSP toward edge — the LSP terminates at core + (where the BGP-LU label is popped), and edge sees plain IP exactly + like today. So **BGP-LU may be a cleaner path than extending LDP to + edge** for this specific goal. + +## Extending LDP to edge — blocked, root cause unknown + +See `~/.claude/projects/-Users-graham-dev-network-mikrotik-tool/memory/ +asymmetric_ldp_parallel_paths.md` for the full incident notes. Three live +attempts on 2026-05-09 to bring up an LDP session between core and edge +all dropped fleet internet traffic within seconds. Hypotheses tried and +disproven: asymmetric LDP path redirect, BGP-table label flooding (we +tightened edge's advertise-filter to just `10.254.254.254/32`), and the +flood still happened. **Don't attempt again live without lab replication +or a console on edge.** + +State left in place that survives across attempts: +- `mpls-mtu=1508` on edge `sfp-sfpplus7-core-direct` and + `sfp-sfpplus11-preseem`. +- `mpls-mtu=1508` on core `ether3-edge-direct` and + `sfp-sfpplus1-edge-preseem`. +- Fasttrack-bypass pairs (in/out) on chain=forward for those four + interfaces on both routers. +- Edge `/mpls ldp advertise-filter` restricted to advertise only + `10.254.254.254/32`. +- Edge `/mpls ldp set distribute-for-default-route=no`. + +These are all harmless and would be required again on the next attempt; +do not roll them back. diff --git a/mikrotik-tool/newhope.rsc b/mikrotik-tool/newhope.rsc index 2bebc96..fff2a00 100644 --- a/mikrotik-tool/newhope.rsc +++ b/mikrotik-tool/newhope.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:52 by RouterOS 7.21.4 +# 2026-05-09 14:55:44 by RouterOS 7.21.4 # software id = 5HTF-YFWV # # model = CCR1009-7G-1C-1S+ @@ -582,6 +582,8 @@ add disabled=no lsr-id=10.254.254.108 transport-addresses=10.254.254.108 vrf=\ /mpls ldp interface add interface=ether2-380 add interface=ether6-lowrycrossing +/mpls settings +set propagate-ttl=no /ppp aaa set interim-update=1h use-radius=yes /radius diff --git a/mikrotik-tool/verona.rsc b/mikrotik-tool/verona.rsc index 863ee26..f19e414 100644 --- a/mikrotik-tool/verona.rsc +++ b/mikrotik-tool/verona.rsc @@ -1,4 +1,4 @@ -# 2026-05-09 13:02:51 by RouterOS 7.21.4 +# 2026-05-09 14:55:44 by RouterOS 7.21.4 # software id = Y1CT-1WB1 # # model = CCR2004-16G-2S+ @@ -968,6 +968,8 @@ add disabled=no lsr-id=10.254.254.101 transport-addresses=10.254.254.101 vrf=\ main /mpls ldp interface add interface=ether3-climax-11ghz +/mpls settings +set propagate-ttl=no /ppp aaa set interim-update=15m use-radius=yes /radius