This document contains proprietary information, w hi ch is
protected by copyright. No par t of th is document may be
photocopied, reproduced, or translated into another language
without the prior written consent of Hew lett-Packar d .
Microsoft, Windows, Windows NT, and Windows XP are U.S.
registered trademarks of Microsoft Corporation.
Disclaimer
The information contained in this document is subject to change
without notice.
HEWLETT -P ACKARD COMPANY MAKES NO WARRANTY
OF ANY KIND WITH REGARD TO THIS MATERIAL,
INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PAR TICULAR PURPOSE. Hewlett-Packard shall not be
liable for errors contained herein or for incidental or consequential
damages in connection with the furni s hi ng, performance, or use
of this material.
The only warranties for HP products and services are set forth in
the express warranty statements accompanying such products and
services. Nothing herein should be c onst rue d as constituting an
additional warranty. HP shall not be liable for technical or editorial
errors or omissions contained herein.
Hewlett-Packard assumes no responsibility for the use or
reliability of its software on eq ui pment that is not furnished by
Hewlett-Packard.
Warranty
See the Customer Support/Warranty booklet included with the
product.
A copy of the specific warranty terms applicable to your HewlettPackard products and replacement parts can be obtained from your
HP Sales and Service Office or authorized dealer.
Hewlett-Packard Company
8000 Foothills Boulevard
Roseville, California 95747
http://www.procurve.com/
The ProCurve Secure Router Advanced Management and Configuration Guide describes how to use the ProCurve Secure Router 7000 series in a
network environment. Specifically, it focuses on two models:
■ProCurve Secure Router 7102dl
■ProCurve Secure Router 7203dl
Both this guide and the Basic Management and Configuration Guide
describe how to use the command line interface (CLI) and the Web browser
interface to configure, manage, monitor, and troubleshoot router operation.
The Advanced Management and Configuration Guide describes how to:
■increase bandwidth for particular WAN connections
■configure a backup WAN connection
■secure your network
■implement quality of service (QoS)
■configure multicast protocols
■select and implement a dynamic routing protocol
Refer to the Basic Management and Configuration Guide if you need
information about configuring:
■Ethernet interfaces and VLAN support
■E1- or T1-carrier lines
■serial interfaces for E1- or T1-carrier lines
■Data Link Layer protocols
■ADSL connections
■ISDN connections
■E1 + G.703 or T1 + DSX-1 interfaces
■bridging
■basic routing
■DNS server and client functions
■DHCP server and client functions
1-3
Page 32
Overview
Using This Guide
Understanding Command Syntax Statements
This guide uses the following conventions for command syntax and
information.
■Carats ( < > ) enclose a description of a command element, a part of the
command in which you enter information specific to your particular
router or WAN. For example, in the first command shown above, you
replace <listname> with the name of a particular access control list
(ACL) configured on your router.
■Square brackets ( [ ] ) are used in two ways:
•They enclose a set of options. When entering the command, you select
one option from the set. For example, in the second command shown
above, you would enter any or host <A.B.C.D> or <A.B.C.D> <wildcard bits>.
•They indicate an optional element. You can include the optional
element in the command, but it is not required.
■Vertical bars ( | ) separate alternative, mutually exclusive elements.
■Carats within square brackets ( [ < > ] ) indicate that you may optionally
add the information specific to your router or WAN to the command. For
example, in the first command above, you can either replace <listname>
with the name of a specific ACL or not enter a name at all to view all ACLs.
■Braces ( { } ) indicate an embedded option.
■Bold typeface is used for simulations of actual keys. For example, the “Y”
key appears as
■Italics indicate an element that you must replace with information that is
specific to your router or WAN.
y.
1-4
When examples of commands are included in this guide, the guide notes the
context required for the command and displays the context as it appears in
the CLI.
CLI Prompt Convention
When you first boot up your ProCurve Secure Router, the CLI prompt indicates
the router model:
ProCurveSR7102dl>
ProCurveSR7203dl>
Page 33
Overview
Using This Guide
For simplicity, throughout this manual the CLI prompt will be shown as:
ProCurve>
You can change the name displayed at the prompt of your router by changing
the router’s hostname. For more instructions on changing the router’s hostname and other basic router functions, see the Basic Management and Configuration Guide, Chapter 1: Overview.
Observing the IP Address Convention
You must sometimes enter an IP address or addresses as part of a command.
For example, you might need to assign an IP address to a logical interface on
the ProCurve Secure Router, or you might need to enter an IP address to be
filtered by an ACL.
When you enter IP addresses, you must use one of the following formats:
■IP address with subnet mask:
Syntax: ip address 192.168.1.1 255.255.255.0
■IP with Classless Inter-Domain Routing (CIDR) notation (prefix length):
■Syntax: ip address 192.168.1.1 /24
Interface Numbering Convention
When configuring a WAN connection, you will need to specify the slot and
port of the interface that is providing the connection. The syntax for specifying
an interface is <interface> <slot>/<port>.
Replace <interface> with the name of the interface. For example, for E1
interfaces, you would use e1, and for ADSL interfaces you would use adsl. For
ISDN interfaces, use bri.
Replace <slot> with the slot number in which the module is inserted. The
slots on the router are numbered from left to right. The left narrow slot is slot
1, and the slot to the right is slot 2. If you have a ProCurve Secure Router
7203dl, the wide module is installed in slot 3, the right most slot on the front
of the router.
Finally, replace <port> with the number of the port on the module. Like the
slots, the ports are numbered from left to right. The port number is printed
below each port on the module.
1-5
Page 34
Overview
Using This Guide
For example, if you have a two-port T1 module in slot one, you would
configure the left T1 port by entering:
ProCurve(config)# interface t1 1/1
To configure the other T1 port, you would enter:
ProCurve(config)# interface t1 1/2
As mentioned earlier, the Ethernet interfaces are also labeled in <slot>/<port>
notation as eth 0/2 and eth 0/1.
Quick Start Sections
Each chapter includes a Quick Start section that provides the instructions you
need to quickly configure your ProCurve Secure Router. Designed for experienced network administrators, the Quick Start sections provide minimal
explanation.
The first time you perform a task, ProCurve Networking strongly recommends
that you read the entire chapter so you thoroughly understand how to manage
the ProCurve Secure Router. If you begin to use the Quick Start instructions
and find that you need additional information about a specific aspect of
managing the OS, check the “Contents” for that chapter to locate the section
that contains the explanation you need.
1-6
The Quick Start section is located at the end of each chapter. For the specific
page number, consult the “Contents” pages located at the beginning of each
chapter to find the relevant Quick Start.
Obtaining Additional Information
You will need the Adobe® Acrobat® Reader to view, print, or copy product
documentation.
1.Access the ProCurve Networking Web site at http://www.procurve.com.
2.Click Technical support in the bar on the left side of the screen, and then
click Product manuals. (See Figure 1-1.)
3.Click the name of the product for which you want documentation.
4.On the resulting Web page, double-click the document you want.
5.When the document file opens, click the disk icon in the Acrobat® toolbar
and save a copy of the file.
Page 35
Click Product
Manuals
Overview
Using This Guide
Figure 1-1. The ProCurve Technical Support Web Page
Downloading Software Updates
ProCurve Networking periodically updates the router software to include new
features. You can download software updates and the corresponding release
notes from ProCurve Networking’s Web site as described below.
To download software, complete the following steps:
1.Access the ProCurve Networking Web site at http://www.procurve.com.
2.Click Software updates (in the sidebar). (See Figure 1-2.)
Release notes are included with the software updates and provide information
about:
■new features and how to configure and use them
■software management, including downloading software to the router
■software fixes addressed in current and previous releases
For information on how to configure basic router functions, see the Basic
Management and Configuration Guide.
Page 37
Interface Management Options
Overview
Interface Management Options
The ProCurve Secure Router includes two management interfaces: the
command line interface (CLI) and the Web browser interface.
CLI
To initially access the CLI, connect the COM port on your workstation to the
console port on the front panel of the router. Use the serial cable (5184-1894)
that was shipped with the ProCurve Secure Router. Then run terminal session
software such as Tera Term or Hyper Terminal on your workstation, and set
up the terminal session with the following parameters:
■Baud Rate = 9600
■Parity = None
■Data Bits = 8
■Stop Bits = 1
■Flow Control = None
Using the CLI provides you an organized, linear path to help you configure
your router. This guide will focus primarily on configuring the router through
the CLI.
Web Browser Interface
You can also manage the ProCurve Secure Router through the Web browser
interface, which allows you to navigate the router’s (OS) in a GUI environment.
Even if you are a dedicated CLI user, you should try out this easy-to-use Web
browser interface. You will find it especially helpful for more complicated
tasks such as configuring access control policies (ACPs) and virtual private
networks (VPNs). (See Figure 1-3.) In fact, the Web browser interface provides
wizards to help you configure VPNs, the router’s built-in firewall, or QoS
for VoIP.
1-9
Page 38
Overview
Interface Management Options
1-10
Figure 1-3. Configuring ACPs Using the Web Browser Interface
Accessing the Web Browser Interface
To access the Web browser interface, you must first establish a CLI session
and configure at least one interface through which you can establish an HTTP
session with the router. You must also enable the HTTP server and configure
a password for HTTP access. For more information on how to configure the
router to access the Web browser interface, see “Configuring HTTP Access”
on page 1-30, or Chapter 14: Using the Web Browser Interface for Advanced Configuration Tasks.
Page 39
Interface Management Options
Overview
Using the ProCurve Web Browser Interface
The ProCurve Web browser interface is organized into the following sections:
■System
■Router/Bridge
■Firewall
■VPN
■Utilities
The System section of the interface contains general router functions. In this
section, you can:
■configure WAN and LAN connections
■configure IP services
■enable the Dynamic Host Configuration Protocol (DHCP) and Domain
Name System (DNS) servers
■set the router’s hostname and add entries to the DNS host table
■configure Link Layer Discovery Protocol (LLDP) settings
You can also click Getting Started to display a help menu, or select System
Summary to display information about the router. Click Physical Interfaces
for a list of interfaces (including status and type) on your router.
The Router/Bridge section allows you to configure the router’s bridging and
routing functions. You can set a default gateway, configure the IP interfaces,
set up quality of service (QoS) maps and routing protocols, and add entries to
the route table. You can also configure the router to act as a bridge and
participate in a spanning tree.
The firewall wizard can be found in the Firewall section. Click Firewall Wizard to open the wizard in a new window. The wizard guides you through
establishing policies for controlling access to your network. From the Fire-wall section, you can also enable specific application-level gateways (ALGs)
and set protocol timeouts.
The VPN section includes a wizard that simplifies the process of configuring
an IPSec-compliant VPN. The VPN section eliminates the difficulty of remembering the many commands necessary for configuring a VPN in the CLI. The
VPN section only appears in the Web browser interface if you have installed
an optional IPSec encryption module in the rear panel of your router.
You can perform most of your file maintenance in the Utilities section. Click
Configure to complete tasks such as saving, downloading, uploading, and
deleting files. You can also click Firmware to view information about your
1-11
Page 40
Overview
CLI Tools
router’s current OS and upload any necessary upgrades. You can click Reboot
and restart the router, and you can also set up a Telnet session by clicking
Telnet to Unit.
NoteIn the CLI, boot and configuration files are referred to as software. In the Web
browser interface, the boot and configuration files are called firmware.
For more information on how to configure basic router functioning on your
ProCurve Secure Router using the Web browser interface, see the Basic
Management and Configuration Guide, Chapter 14: Using the Web Browser
Interface for Basic Configuration Tasks.
CLI Tools
This section gives a brief description of the CLI tools and commands that will
help you to configure and troubleshoot your router. If you need more detailed
information on the commands available in the CLI, it is highly recommended
that you consult the Basic Management and Configuration Guide. The Basic Management and Configuration Guide lists and describes the router’s show
commands, file management commands, and interface configuration commands.
1-12
Help Tools
The Secure Router OS features help tools, editing functions, and global
commands to help you navigate through the Secure Router OS and configure
and maintain your WAN.
CLI Help Commands
You can enter the ? character to help you enter commands in any mode context
in the CLI. The
and options available to those commands in your current router context. You
will not need to press
triggers the display.
■?. Entering the ? character displays a list of all the available commands in
your current mode with a brief description of their functions.
? character displays information about the available commands
Enter to activate the ? help tool; the character immediately
Page 41
Overview
CLI Tools
■letter?. If you know the beginning of a command but need to be reminded
of the entire word or if you want a more limited list of commands, enter
a letter or set of letters followed immediately by the
put a space between the letters and the
?. The router will then display only
? command. Do not
the specific commands that begin with those letters. For example,
ProCurve> e?
enable exception exit
■command ?. If you know the command but need to be reminded of the
available options, type the command followed by a space and
?. This will
bring up a display of the available options for that command in the current
mode and a brief description of each. For example,
ProCurve(config t1 1/1)#clock source ?
internal-Use internal clock source
line-Recover clock from line
Editing Commands
The router’s CLI supports basic editing functions that can move the cursor
through the command line and allow you to cycle through previous commands. Table 1-1 describes the ProCurve editing commands.
Table 1-1.Keystrokes for Moving Around the CLI
Editing CommandAction
Ctrl+p or up arrowrecall the most recent command
Ctrl+amove to the beginning of the line
Ctrl+emove to the end of the line
Ctrl+f or right arrowmove forward one character
Ctrl+b or left arrowmove backward one character
Tabfinish partially typed command
Command Recall. Recall the most recent command by entering
pressing the
up arrow. Pressing the up arrow again will cycle through the previous
Ctrl+p or
commands.
Moving within the Command Line. When typing a lengthy command, you
may make an error and need to move the cursor within the command line. See
Table 1-1 for a list of keystrokes that move the cursor within the command line.
1-13
Page 42
Overview
CLI Tools
Tab . The Ta b key is a shortcut of sorts. Press Tab after typing the first few
characters of a command. If you have typed enough characters to distinguish
the command from all other available commands, the Secure Router OS will
finish the word for you.
Truncation. The ProCurve Secure Router OS also recognizes truncated
commands. You only need to enter enough characters in the CLI to distinguish
the command you wish to execute. A good way to tell if you have typed enough
characters is to press the
OS is able to finish the command without having to list possible options, you
have typed enough characters.
For example, when entering the enable mode context, it is not necessary to
type the whole word enable. At the basic mode context prompt there are three
commands that begin with the letter “e” and only one command that begins
with the letters “en.” To enter the enable mode context from basic mode you
only need to enter en and press
typing en at the basic mode context prompt. Because the Secure Router OS
is able to finish the word enable, it completes the truncated command.
Ta b key. If, when you press Ta b, the Secure Router
Enter. This can be checked by pressing Tab after
Basic Commands
This section gives some basic CLI commands that you will need to operate
your router. Only basic commands are described here. For a more comprehensive list and description of router commands, see the Basic Management
and Configuration Guide, Chapter 1: Overview; or the SROS Command Line
Interface Reference Guide.
no
In the enable security mode context, typing the word no before a command
turns off or resets a command option to its defaults. For example, if you want
to stop events notices from displaying to the CLI screen, enter no events.
do
When in the configuration mode context, if you need to execute an enable
mode command, type do before you enter the command. The do command
allows you to stay in your current mode context while executing a command
that is usually only available in the enable mode context. You will most often
use this command with show commands. For example, to display the status
of an interface while configuring a protocol interface, enter:
Syntax: do show interface <interface type> <slot>/<port>
ProCurve(config-ppp 1)# do show interface e1 1/1
1-14
Page 43
Overview
CLI Tools
exit
To leave a specific interface or configuration mode, type exit. The exit
command moves you back one mode level. For example, if you were configuring an ATM interface in the ATM interface configuration mode context and
entered exit when you were finished, you would return to the global configuration mode context.
When you enter the exit command in the global configuration mode context
and return to the enable mode context, the CLI displays this message:
Appropriate commands must be issued to preserve configuration.
This message is a reminder to save the configuration you have completed. All
configuration changes are initially saved only in the router’s running-configuration file, which is stored in flash memory. If the router were powered down,
the running config, and any changed that you have not saved, would be lost.
The next section describes the file management commands you need to save
your configuration.
File Management Commands
This section describes the basic file management commands that allow you
to save your configurations, copy files from the router to another medium, or
erase files from your router’s flash or compact flash memory.
The router has two configuration files that keep track of the router’s settings:
startup-config and running-config. The router uses the startup-config file as a
map to setup the router’s configuration during the boot process. This file
contains saved configuration settings and is used to configure the router when
it is powered on and boots.
As you make configuration changes, the router stores these configuration
changes in the running-config file, which is stored in the routers RAM memory.
Only the currently running and implemented configurations are stored in
running-config. This file is lost when the router powers down. If you want to
keep the configuration changes you have made to the router, you must save
this file, as described in the following sections.
This command is used to copy and save files in the router’s internal flash and
compact flash memories. Table 1-2 gives the available options for the copy
command.
You can also use this command to save the changes you make in the runningconfig to the startup-config. If you do not save these changes, the next time
the router reboots, any changes will be lost.
To save configuration changes while using the CLI, enter:
Replace <config-file> with either running-config or startup-config and
replace <filename> with a name that you choose.
Ver ify t hat t he Percent Complete 100% message is displayed, indicating that
the download is complete. The current configuration is now saved in compact
flash with the specified filename.
To save a configuration as a file on internal flash, enter the following command
from the enable mode context:
Replace <source file location> with the location of the configuration file
you are saving. Replace <source config-file> with startup-config or run-ning-config. You must enter a destination filename unless the filename will
be the same as that of the source. For example, if you need to save the startupconfig file from the compact flash card to internal flash, enter:
Saving the Current or Start-up Configuration to a TFTP Server. To
initiate an upload of a configuration file to an external TFTP server, enter one
of the following commands from the enable mode context:
For example, if you wanted to upload the startup-config on compact flash to
your TFTP server, you would enter:
ProCurve# copy cflash tftp
When prompted for the Address of remote host?, enter the IP address of
the TFTP server.
When prompted for the Source filename?, enter the name of the configuration file (startup-config or running-config) you would like to upload.
When you are prompted for the Destination filename?, enter the filename
you’d like the uploaded configuration file to be named.
1-17
Page 46
Overview
CLI Tools
The copy command can be used for other file TFTP management tasks
such as:
■loading a running-configuration file from the TFTP server—Enter copy
tftp running-config.
■loading a startup-configuration from the TFTP server—Enter copy tftp
startup-config.
erase
The erase command removes files from the specified file location.
Syntax: erase <file location> <filename>
For example, entering erase flash <filename> will delete the file you specify
from internal flash:
ProCurve# erase flash oldconfig
This command also allows you to erase files from compact flash:
ProCurve# erase cflash config1.cfg
write
This command is similar to the copy and erase commands.
Entering write memory will save the running-configuration to the startupconfiguration. In J03_01.biz and later, this file will automatically save to the
compact flash card, if present. Otherwise the startup-config file will be saved
on the router’s internal flash.
Entering write erase deletes the startup-config file. If you have a compact
flash card, the startup-config is erased from cflash. If you are running the
AutoSynch™ function, this command erases startup-config from both flash
and compact flash. If you do not have a compact flash card, the file is erased
from flash.
The write network command saves the running config to a TFTP server. You
can set the filename to something meaningful to you when you are prompted
with Destination filename?.
The write terminal command is similar to the show running-config
command; it displays the current running-configuration in the CLI.
1-18
Page 47
Overview
CLI Tools
autosynch
The autosynch command is used with a compact flash card. Enabling the
AutoSynch™ function allows the router to automatically keep the startupconfig and SROS files in internal flash synchronized with the startup-config
and SROS file on the compact flash card.
The autosynch command is disabled in its default setting. To enable the
AutoSynch™ technology, enter the global configuration mode and enter:
AutoSynch: SROS.BIZ not synched
AutoSynch: startup-config not synched
For more information on file management and router boot functioning, please
see the Basic Management and Configuration Guide, Chapter 1: Overview.
Troubleshooting Commands
The following commands are some basic commands to help with troubleshooting router operation.
reload in
When you are configuring the ProCurve Secure Router through a Telnet, SSH,
or Web session, you may want to enter a safeguard to ensure that you do not
inadvertently block your access to the router. You can configure the ProCurve
Secure Router to reload the startup-config at a specified future time, returning
the router to its previous configurations.
To schedule a system reboot, enter the following command from the enable
mode context:
ProCurve# reload in <mmm>
or
ProCurve# reload in <hhh:mm>
1-19
Page 48
Overview
CLI Tools
Replace <mmm> with the number of minutes. You can specify a three-digit
number. Replace <hhh:mm> with a time such as 1:15 (1 hour and 15 minutes).
The CLI will prompt you to save the system configuration. If you have already
made the configurations that you want to test, reply no. If you are getting ready
to make the configurations to be tested and want to save previous configurations, reply yes. The CLI then displays:
You are about to reboot the system. Continue? [y/n]
Enter
y. The system will not reboot immediately. It will wait the amount of time
you have specified. Remember that you must not save the running-config to
the startup-config (by entering either write mem or copy run start) while
you are configuring the router. Otherwise, the ProCurve Secure Router will
load these configurations when it reboots.
To cancel the reload, enter:
ProCurve# reload cancel
show
The show commands are only available in the enable mode context or by using
the do command. These commands allow you to check the router’s configured
settings by displaying router functionality information in the CLI. This allows
you to find miskeyed commands or problem configurations and repair them.
Individual show commands are described throughout this book and the Basic Management and Configuration Guide. For a more detailed list and explanation of the available show commands, see the Basic Management and Configuration Guide, Chapter 1: Overview.
1-20
show tech
Unlike the other show commands, the show tech command does not display
the information in the CLI. This command creates a file named showtech.txt
in flash that contains a summary of the router’s show command information.
To create this file enter show tech at the enable mode context prompt. This
will prepare a showtech.txt file and save it in the router’s internal flash.
After the showtech.txt file is created, you can save it to compact flash or
upload it to a TFTP server. You can also save the contents of the showtech.txt
file to your terminal’s text editor. See “Managing Configuration Files Using a
Text Editor” on page 1-24 for more information on how to manage files with
a text editor.
Page 49
Overview
CLI Tools
NoteThe showtech.txt file is saved to internal flash. If you intend to use a compact
flash card to transport the file, you must save the showtech.txt file to a
compact flash card.
The showtech.txt file contains a readout of many of the show commands. This
readout allows a network administrator to pinpoint a router configuration
problem without a connection to the router. To display the contents of the
showtech.txt file, enter show file flash showtech.txt from the enable mode
context.
To have the router display the show tech readout without creating or saving
a showtech.txt file, use the terminal option:
Syntax: show tech terminal
ProCurve# show tech terminal
safe-mode
SafeMode is a CLI feature that allows you to perform configuration changes
without the fear of being disconnected from a Telnet or SSH session. Some
configuration changes can interrupt network connectivity. If you are
managing a router remotely via SSH or Telnet, you can inadvertently lose your
connection to the router.
For example, you may need to apply an ACL, but this ACL doesn’t allow Telnet
or SSH traffic. Once you applied the ACL, you would be locked out of the
router. In order to fix the configuration that has locked you out, you would
need physical access to the router so that you could establish a console session
with it. SafeMode allows you to make configuration changes using Telnet or
SSH without worrying about losing your connection and being unable to
reestablish it.
SafeMode requires you to periodically reset a reload timer. If the reload timer
runs out before you reset it, the Secure Router OS will assume that the current
running configuration has disrupted your connection to the router. It will save
the running-config to internal flash as “problem-config” and reboot the router.
Once the router has reloaded, it will display a reboot cause message and load
the currently saved startup-configuration file. The startup-config should allow
you to regain access to the router. You will then be able to review the saved
problem-config file and correct the setting that caused the disruption.
After you enable SafeMode and set the time limit, a reload timer is activated
for the Telnet and SSH access lines and begins to count down. You also set a
threshold timer, which is shorter than the reload timer. When the threshold
1-21
Page 50
Overview
CLI Tools
timer expires, a warning message is displayed in the CLI that allows you to
reset the timer. Unless you enter the reset keystroke before the reload timer
finishes counting down, the router reboots. This prevents you from being
locked out of the router if you lose the connection and are unable to reset the
timer.
While SafeMode is enabled, it temporarily suspends the AutoSynch™
function. This prevents a disruptive configuration from being saved to both
flash and compact flash. After the SafeMode configuration is complete and
you have disabled the SafeMode counter, the autosynch command, if
previously enabled, will automatically reenable and begin synchronization.
Enabling SafeMode. To enable SafeMode, access the global configuration
mode context and enter:
Set the <reload time> to the number of seconds to countdown until the
router reboots. Set the <threshold time> to the number of seconds to
countdown until you receive a reminder to reset the timer. Both the reload
time and threshold time must be between 30 and 3600 seconds. The default
value for the reload time is 300 seconds, and the default value for the threshold
time is 60 seconds. To enable SafeMode with the default settings, enter safe-mode at the global configuration prompt.
1-22
The reload time should be greater than the threshold time. If you enter a
threshold value greater than the reload value, the CLI displays an error
message.
When you are configuring in SafeMode from a Telnet or SSH session, the
configuration mode context prompt is displayed as safe-config. For example:
All configurations that you make during SafeMode are saved in RAM as part
of the running-config.
After the countdown for the reload timer has begun, it continues until you
either reset it by pressing
Ctrl+R, you disable it by entering no safe-mode, or
you exit out of the global configuration mode context.
Page 51
Overview
CLI Tools
Use the no form of the command to disable SafeMode and the countdown
timer:
ProCurve(safe-config)# no safe-mode
ProCurve(config)#
SafeMode Functioning. SafeMode events are displayed in the CLI. When
the threshold timer reaches zero, a notice is displayed in the CLI reminding
you to reset the timer:
SAFEMODE: SafeMode will reboot in <threshold> seconds.
When you activate SafeMode, or when you leave and re-enter the configuration
mode context while SafeMode is enabled, the reload timer is activated and a
message is displayed in the CLI:
SAFEMODE: SafeMode enabled. Reboot in <n> seconds!
Once SafeMode is enabled, any CLI user can reset the timer by entering
Ctrl+R.
You can reset the timer at any time, as often as you need to complete the
configuration.
CautionIf you save your configuration to the startup-config while in SafeMode, you
may essentially negate SafeMode’s effect: the rou ter may reboot with the saved
disruptive configuration and you will still be locked out of the router. Be very
careful about saving your in-process configurations when in SafeMode.
The problem-config file that is generated when the router reboots can be
examined and edited in a text editor to repair the commands that caused the
problems.
NoteThe problem-config file is saved in the router’s internal flash memory. If you
want to transport the file or save a backup of the file using compact flash, you
need to copy the file to compact flash by entering copy flash problem-config cflash problem-config from the enable mode context.
1-23
Page 52
Overview
Managing Configuration Files Using a Text Editor
Managing Configuration Files Using a
Tex t Editor
Configuration files can be adjusted to each router’s needs using your computer’s text editor. This allows you to set up a configuration on one router,
save it to a file, and edit it for installation on another router.
Begin creating a configuration file by creating a base configuration on an
originating router. Save the base configuration and impo rt it—using a compact
flash card, the router’s console, or a TFTP server—to a terminal with a text
editor. The readout of the configuration file will resemble the readout of the
running-config for the router (displayed by entering show run at the enable
mode context prompt). Once you have pasted this text into the text editor,
you can adjust the IP address, hostname, ACLs and ACPs, and other configuration concerns to prepare the file for the target router. These adjustments are
made by simply typing in the desired command or value using the format
displayed in the file readout. Then move the file to the target router and save
it as the startup-config. Reboot the router using the reload command and the
router will boot with the new configuration.
1-24
Using Error Messages to Repair a Configuration
The ProCurve Secure router configuration files are robust. If you miskey a
command or make a mistake in the text editor, the router will simply ignore
the mistake and use the default settings. If any necessary command is missing,
the router will simply substitute the default. Problem commands will trigger
an error message during bootup.
If you do have a problem command that is running on its default setting, it is
not necessary to re-edit the configuration in a text editor. To repair the
problem, simply enter the pertinent command in the CLI. Use the error
messages displayed during bootup to determine which command is faulty.
Page 53
Managing Configuration Files Using a Text Editor
Overview
Figure 1-4. Boot Error Messages
The error messages in Figure 1-4 were displayed during bootup. In this
particular case, the startup-config file has several VPNs configured, and the
router that is booting does not have an IPSec VPN module to support it. The
commands for the configuration of the VPNs are reported as errors.
Use error messages like these to locate and troubleshoot the problem in the
router’s configuration.
1-25
Page 54
Overview
Managing Configuration Files Using a Text Editor
Figure 1-5. Using Boot Error Messages to Target a Configuration Problem
The line number given in the error message is the line number in the runningconfig. You can use this information to repair any configuration problems.
You will need to scroll up in your terminal session software window to read
the error message. Make a note of the reported line number, the command,
and the resulting error message, as shown in Figure 1-5. Then return to the
command line and enter the enable mode context.
Enter show running-config to display the current configuration. When the
running-config is displayed, begin with the first exclamation point and count
down, line by line, until you reach the line that generated the error message.
Check the resulting message from the error report. Repair the problem by reentering the command on that line using the error report as a guide.
Error location
Resulting
message
1-26
For example, in Figure 1-5, there is an error in line 58. The faulty command was
ProCurve(config-ike)# peer 10.2.2.1
The peer at 10.2.2.1 was already assigned to IKE policy 100 and cannot be
assigned to more than one policy. In this example, the IKE policy configurations may need to be adjusted.
Page 55
Overview
Quick Start
Quick Start
This section provides the instructions you need to quickly access the ProCurve
Secure Router CLI and configure an enable mode password to protect the
router from unauthorized access. This section also explains how to configure
the Ethernet interface and the HTTP server so that you can access the Web
browser interface. You will then be able to manage the ProCurve Secure
Router through an Internet browser.
Only minimal explanation is provided. It is strongly recommended that you
read the entire chapter so that you understand how the Secure Router operating system (OS) is organized and how to manage the OS. If you need
information about a specific aspect of managing the OS, see the Basic Man-agement and Configuration Guide to locate the section that contains the
explanation you need.
Accessing the Secure Router OS
1.Use the serial cable (5184-1894) that shipped with the ProCurve Secure
Router to connect the COM port on your laptop to the console port on the
front panel of the router.
2.Open a terminal session with the ProCurve Secure Router, using the
following settings:
•Baud Rate = 9600
•Parity = None
•Data Bits = 8
•Stop Bits = 1
•Flow Control = None
3.Press
4.Access the enable mode context:
5.Access the global configuration mode:
Enter to access the basic mode context.
ProCurve> enable
ProCurve# configure terminal
1-27
Page 56
Overview
Quick Start
Configuring the Enable Mode Password
6.Configure an enable mode password.
Syntax: enable password [md5] <password>
Enter the md5 option to encrypt the password. Replace <password>
with an alphanumeric string of up to 16 characters.
For example, you might enter:
ProCurve(config)# enable password md5 ProCurve
NoteThe word ProCurve is shown as the password only for simplicity. In a
production environment, you should follow the standard guidelines for creating a password that cannot be easily guessed by unauthorized users. In
addition, you should avoid writing the password down and posting it where
others can read it.
Configuring the Ethernet Interface
1.Use a 10Base-T or 100Base-T cable to connect the Ethernet port on the
ProCurve Secure Router to the appropriate device on your LAN. In most
cases, you will connect the router to a core switch.
1-28
2.Access the configuration mode context for the Ethernet interface.
Syntax: interface ethernet 0/<port>
For example, if you want to configure the bottom Ethernet port, enter:
ProCurve(config)# interface ethernet 0/1
3.Assign the Ethernet interface an IP address.
Syntax: ip address <A.B.C.D> <subnet mask | /prefix length>
For example, if you want to assign the Ethernet interface an IP address
of 192.168.115.1 /24, enter
ProCurve(config-eth 0/1)# ip address 192.168.115.1 /24
4.Activate the Ethernet interface.
ProCurve(config-eth 0/1)# no shutdown
A message should be displayed at the CLI, reporting that the interface is
“administratively up.” In a few moments, another message should be
displayed reporting that the interface is up. (If this message does not
appear, you can find troubleshooting information in the Basic
Management and Configuration Guide, Chapter 3: Configuring
Ethernet Interfaces.)
Page 57
Overview
Quick Start
Configuring Telnet Access
After you configure an Ethernet interface and establish a connection to the
ProCurve Secure Router, you can configure Telnet access to the router.
Complete the following steps:
1.Establish a console session to the ProCurve Secure Router and move to
the global configuration mode context.
ProCurve# configure terminal
2.Enter the following command to access the Telnet line configuration
mode context:
Syntax: line telnet [0-4]
The ProCurve Secure Router supports five lines. Enter the number of the
line you want to configure. If you want to enable all five lines, enter:
ProCurve(configure)# line telnet 0 4
3.Create the Telnet password
Syntax: password [md5] <password>
Enter the md5 option to encrypt the password. Replace <password>
with an alphanumeric string of up to 16 characters.
For example, you might enter:
ProCurve(config-telnet0)# password md5 en$ter^tel
4.Exit to the global configuration mode context.
ProCurve(config-telnet0)# exit
5.Configure an enable mode password, if you have not done so already. The
enable mode password is required for Telnet access.
Syntax: enable password [md5] <password>
Enter the md5 option to encrypt the password. Replace <password>
with an alphanumeric string of up to 30 characters.
Configuring SSH Access
After you configure an Ethernet interface and establish a connection to the
ProCurve Secure Router, you can establish SSH access to the router. By
default, SSH access to the ProCurve Secure Router is enabled. After you have
set an enable mode password, you simply need to configure a username and
password.
1-29
Page 58
Overview
Quick Start
Complete the following steps:
1.Establish a console session to the ProCurve Secure Router and move to
the global configuration mode context.
ProCurve> enable
ProCurve# configure terminal
2.If you have not already done so, configure an enable mode password.
Enter:
Syntax: enable password <password>
3.Configure a username and password for SSH access. The username and
password you enter can be used for FTP and HTTP access as well.
Syntax: username <username> password <password>
Replace <username> and <password> with an alphanumeric string of
up to 30 characters.
Configuring HTTP Access
1.Enter the global configuration mode context.
2.Enable the HTTP server on the router.
ProCurve(config)# ip http server
3.If you have not already done so, configure a username and password for
the HTTP server. The username and password also secure FTP and SSH
access to the router.
Syntax: username <username> password <password>
4.Return to the enable mode context and save your configuration.
Point-to-Point Protocol (PPP) and other Data Link Layer protocols establish
point-to-point connections over a single carrier line, which may not provide
sufficient bandwidth to meet a business’s requirements. In a Frame Relay
network, a single Frame Relay port might carry several permanent virtual
connections (PVCs), all of which must share the bandwidth provided by one
carrier line. If a WAN line has inadequate bandwidth, it can become congested
and packets can be dropped.
Purchasing a high-bandwidth E3- or T3-carrier line to sidestep these limitations is not always feasible because some environments do not support them.
In addition, E3- or T3-carrier lines can be quite expensive, and you may not
need the high-bandwidth they provide. Your organization may only need to
double or triple its bandwidth, rather than increase it 28 fold. You cannot
justify the high-cost of an E3- or T3-carrier line when much of the bandwidth
will go unused.
The ProCurve Secure Router supports link-aggregation protocols to address
these problems. Such protocols treat multiple carrier lines as a single bundle,
providing two advantages:
■Faster connections—Traffic can access the combined bandwidth of
the bundle.
■More stable connections—If one line goes down, the other can still
carry traffic.
2-2
Theoretically, link aggregation is a simple idea: effectively double your available bandwidth by using two physical cables to connect your endpoints
instead of only one, triple your bandwidth by using three cables, quadruple
your bandwidth by using four cables, and so on. For example, you could
aggregate two 1.544-Mbps T1-carrier lines into a virtual single network connection with an underlying bandwidth of 3.088 Mbps.
The ProCurve Secure Router supports these link-aggregation protocols:
■Multilink PPP (MLPPP)
■Multilink Frame Relay (MLFR)
Link-aggregation protocols such as MLPPP and MLFR take advantage of
multiple physical cables by fragmenting frames into smaller frames. These
fragments are passed simultaneously over separate cables and then reassembled by the receiving peer. (See Figure 2-1.)
Page 61
PPP
PPP
Frame
Increasing Bandwidth
Configuring MLPPP
PPP
Frame
Router
E1 Line
MLPPP
PPP
Frame
Frame
fragments
Router
ab
d
c
e
f
Frag a
Frag d
Frag c
E1 Lines
Figure 2-1. MLPPP, a Link Aggregation Protocol
Configuring MLPPP
Although using MLPPP to increase a connection’s bandwidth does not require
deep technical expertise, you should understand:
■how a PPP session is established
■how MLPPP regulates the fragmentation and reconstruction of normal
PPP frames
Such an understanding will help you troubleshoot MLPPP connections and
regulate data flow.
2-3
Page 62
Increasing Bandwidth
Configuring MLPPP
PPP
The two peers at either end of a point-to-point connection establish a PPP
session in four phases. (See Figure 2-2.)
1. Link establishment
LCP
2. Authentication (optional)
ProCurve
Secure Router
3. Negotiation of Network Layer protocols
Figure 2-2. PPP Phases
1.Link establishment—Peers exchange Link Control Protocol (LCP) frames
to establish a link and negotiate the options for this link. These options
include the maximum receive unit (MRU), which determines the size of
the informational field in PPP frames, and the authentication protocol, if
used.
PAP, CHAP, or EAP
NCP: IPCP, BCP, and so on
4. Session established
PPP
ProCurve
Secure Router
2-4
2.Authentication—Peers exchange frames for the authentication protocol
agreed upon during link establishment. (If they did not select authentication, they proceed to the next stage.) After both peers authenticate
themselves successfully, they proceed to the next stage.
3.Network Layer protocol—Peers exchange Network Control Protocol
(NCP) frames to negotiate which Network Layer (Layer 3) protocol the
PPP frames will encapsulate. NCP frames serve two functions: they
specify which Network Layer protocol will be used, and they negotiate
options for that protocol. For example, IP Control Protocol (IPCP) is the
NCP for IP. An IPCP frame can include IP addresses for DNS servers and
a request to compress the IP datagram (which will be the PPP information
field).
4.PPP—PPP frames carry the actual information being transferred over
the WAN link. In PPP terminology, this information is called a datagram.
After the two peers successfully exchange LCP frames, authenticate the
link (if authentication is configured), and negotiate the Network Layer
protocol, a PPP session is established. The peers can then exchange PPP
datagrams.
Page 63
Increasing Bandwidth
Configuring MLPPP
MLPPP
MLPPP establishes a session between two peers using the same protocols and
phases as typical PPP. However, MLPPP adds:
■three option fields to the LCP frames
■an MLPPP header to the information field of the PPP frame
LCP Options
The receiving peer must know that the sending peer will be fragmenting PPP
frames and transmitting them over multiple carrier lines. The receiving peer
must also be able to recognize that these fragmented frames originate from a
single peer. Three LCP options prepare peers to exchange PPP frames over
an MLPPP connection:
■Maximum Receive Reconstructed Unit (MRRU)—The MRRU option
serves two functions: it indicates that the sending peer wants to, and that
the receiving peer can, use MLPPP, and it specifies the size of the reconstructed frame (replacing the MRU).
■Short Sequence Number Header Format—A peer can request to use a 12-
bit rather than a 24-bit sequence number in the MLPPP header. A 12-bit
sequence number enables a frame to be split into a little less than 5,000
fragments, which is more than adequate for the typical bundle of lines.
■Endpoint Discriminator (ED) options—Peers negotiate how the receiving
peer will identify the sending peer. One of these methods is an ED, which
can be generated from an IP address, media access control (MAC)
address, or PPP magic number. Every carrier line in the MLPPP bundle
originates from the same endpoint and is given the same ED. The receiving
peer recognizes that frames received from different carrier lines, but with
the same ED, come from the same peer.
MLPPP Header
The MLPPP header helps the receiving peer reconstruct frame fragments in
the correct order. When a peer sends a PPP frame across a multilink point-topoint connection, it first fragments the PPP frame. It then encapsulates
fragments in new PPP frames and sends them simultaneously over each
aggregated line. The new PPP frame includes:
■a new PPP header
■a four-field MLPPP header
■a fragment of the original PPP frame
2-5
Page 64
Increasing Bandwidth
Configuring MLPPP
If peers agreed to use the short sequence number header format during the
link establishment, the MLPPP header includes only two fields.
The MLPPP header includes a flag and a sequence number. The sequence
number indicates the fragment’s place in the reconstructed PPP frame.
MLPPP Configuration Concerns
When you enable MLPPP for a connection, the LCP automatically negotiates
the necessary options, such as the MRRU and ED. You simply need to bind the
extra carrier lines to the PPP interface. MLPPP automatically adds the lines
to the bundle.
Carrier lines send keepalive signals. MLPPP automatically removes lines that
go down from the bundle and adds lines that come back up. The PPP connection stays open as long as at least one line is good.
Enabling MLPPP
Identify the PPP interface for the connection whose bandwidth you want to
increase. Move to the configuration mode context for this interface and enable
multilink:
On the ProCurve Secure Router, links are always defined by the Data Link
Layer (for example, a PPP interface), rather than by the Physical Layer. You
bind a physical interface to a logical interface to grant the Data Link Layer
protocol access to the physical media over which to transmit data. This way
of defining links makes configuring MLPPP easy: you simply bind more than
one carrier line to the same PPP interface.
You can bind as many carrier lines to the PPP interface as are installed on the
router. The ProCurve Secure Router 7102dl provides up to 4 E1- or T1-carrier
lines, and the ProCurve Secure Router 7203dl provides up to 12 E1- or T1carrier lines, depending on the modules that you purchase.
Page 65
Increasing Bandwidth
Configuring MLPPP
You should have already configured the physical interfaces. If you have not,
see the Basic Management and Configuration Guide, Chapter 4: Configur-ing E1 and T1 Interfaces for instructions. To bind these interfaces to the PPP
interface, you need the following information:
■type of carrier line (E1 or T1)
■dl module slot for the carrier line’s module
■port number for the interface to which the line connects
■time division multiplexing (TDM) group number
The TDM group number defines the range of channels used by an E1- or T1carrier line. The carrier lines that will be aggregated can use the same or a
different TDM group number, but these groups must use the same number of
channels.
You can enter the bind command either from the global or the PPP interface
configuration mode contexts:
Like MLPPP, MLFR aggregates several physical connections into a single
logical connection. MLFR helps provide greater access rates for PVCs, particularly in environments in which the greater bandwidth of an E3- or T3-carrier
line is not available. MLFR also creates more stable PVCs: if one physical
interface goes down, the other interfaces can continue to provide bandwidth
for a connection.
Routers that support MLFR FRF.15 bundle multiple carrier lines at the user’s
end. The service provider does not recognize the bundle. It assigns each line
one Data Link Connection Identifier (DLCI) and carries traffic over the PVC
for each line, just as it would for non-bundled lines. The remote router, which
also runs MLFR FRF.15, receives the traffic from multiple PVCs but treats it
as traffic from a single PVC.
FRF.15 does not require the Frame Relay service provider to support MLFR.
However, each bundle can support only one point-to-point connection to a
remote site. The remote site must use the same number of carrier lines as the
local site.
2-8
The ProCurve Secure Router supports MLFR FRF.16 rather than FRF.15,
which means that your service provider must support MLFR. FRF.16 provides
several advantages over FRF.15. It allows a bundle to carry multiple PVCs to
multiple remote sites, and these sites can use different amounts of bandwidth.
FRF.16 aggregates multiple carrier lines to produce a high-speed connection
to the Frame Relay service provider. The service provider supports MLFR, so
it recognizes that these lines should be treated as a single bundle. The service
provider assigns you a DLCI for the lines as a bundle instead of for each line
individually. Rather than associating DLCI 101 with E1-carrier line 1 and DLCI
102 with E1-carrier line 2, the Frame Relay service provider associates DLCI
101 and 102 with both E1-carrier lines. (See Figure 2-3.)
You can request DLCIs for PVCs to as many remote sites as your organization
needs. In addition, the remote sites do not have to aggregate the same number
of lines as the local site or even run MLFR at all. The multilink connection is
to the Frame Relay provider, not to the remote sites.
MLFR does not necessarily fragment frames. However, it can use FRF.12 to
fragment large frames and minimize delay. An MLFR header is added to the
original Frame Relay header to mark the fragments’ sequence numbers.
Page 67
Increasing Bandwidth
Configuring MLFR
In essence, FRF.16 simply increases the committed information rate (CIR) you
can negotiate for a Frame Relay port in a T1 or E1 environment.
MLFR
E1
Router A
E1
bundle
Router B
Frame Relay
network
Router C
DLCI 101
DLCI 102
Figure 2-3. MLFR FRF.16
Figure 2-3 shows a Frame Relay connection that aggregates two E1-carrier
lines to connect to the Frame Relay provider. Router A establishes two PVCs—
one to Router B and one to Router C—on this connection.
You can aggregate as many carrier lines as are connected on the ProCurve
Secure Router, as long as they are of equal bandwidth. The MLFR interface
can carry as many PVCs as you request from your provider. Each PVC draws
on the aggregated bandwidth as needed, as available, and in accordance with
the CIR negotiated with the service provider. The endpoints of the PVC do not
have to use the same number of carrier lines (although a great difference in
bandwidth can lead to dropped packets). For example, Router A at the
company headquarters can use four E1 lines, while Router C at a small remote
site can connect to the network with only one line.
Enabling MLFR
Identify the Frame Relay interface for the connection whose bandwidth you
want to increase. Then, move the configuration mode context for this interface
and enable multilink. For example, you might enter:
Binding Multiple Carrier Lines to a Frame Relay Interface
On the ProCurve Secure Router, links are always defined by the Data Link
Layer rather than the Physical Layer. You bind a physical interface to a logical
interface to grant the Data Link Layer protocol access to the physical media
over which to transmit data. This way of defining links makes configuring
MLFR easy: you simply bind more than one carrier line to the same Frame
Relay interface.
You can bind as many lines to the Frame Relay interface as are installed on
the router. The ProCurve Secure Router 7102dl provides up to 4 E1- or T1carrier lines. The ProCurve Secure Router 7203dl provides up to 12 E1- or T1carrier lines, depending on the modules that you purchase.
You should have already configured the physical interfaces. If you have not,
see the Basic Management and Configuration Guide, Chapter 4: Configur-ing E1 and T1 Interfaces for instructions. To bind the physical interfaces to
the Frame Relay interface, you need this information:
■type of carrier line (E1 or T1)
■dl module slot for the carrier line’s module
■port number for the interface to which the line connects
■TDM group number
2-10
The TDM group number defines the range of channels used by an E1- or T1carrier line. Lines that will be aggregated can use the same or a different TDM
group number, but these lines must use the same number of channels.
If you bind a physical interface to the Frame Relay interface and then enable
multilink, the non-multilink binding is removed from the interface. You will
have to rebind the original line as well as the new lines to the Frame Relay
interface.
You can enter the bind command either from the global or the Frame Relay
interface configuration mode context. Enter the command for each carrier
line that you want to bundle:
NoteYou bind the physical interfaces to the Frame Relay interface, not the Frame
Relay subinterface. This is because Frame Relay subinterfaces define PVCs,
which are virtual connections, while the Frame Relay interface defines the
physical connection available to all the virtual ones.
Configuring the Bundle ID
MLFR manages the connection by periodically sending out hellos across each
carrier line included in the multilink connection. The hello includes the link
ID of the line and the bundle ID of the connection as a whole. The link ID lets
the router know which lines are up; the bundle ID lets the router know which
lines are actually part of the same logical connection.
By default, the Secure Router OS assigns this bundle ID to a Frame Relay
multilink:
MFR<interface number>
For example, the router might assign the bundle ID:
MFR1
You can configure a bundle ID for the connection. Move to the Frame Relay
interface configuration mode context and enter:
Syntax: frame-relay multilink bid <string>
The bundle ID can be up to 48 characters. It is a good idea to configure the
bundle ID at the same time as you enable multilink support: an active connection will go down briefly and then go back up while the new bundle ID is
negotiated.
2-11
Page 70
Increasing Bandwidth
Troubleshooting Multilinks
Troubleshooting Multilinks
Troubleshooting multilinks is similar to troubleshooting a link carried on a
single carrier line. You can review this process in “Standard Procedure” on
page 2-12. (For more troubleshooting tips, see the Basic Management and
Configuration Guide, Chapter 6: Configuring the Data Link Layer Protocol
for E1, T1, and Serial Interfaces.)
“Troubleshooting MLPPP” on page 2-15 and “Troubleshooting MLFR” on page
2-16 deal with special considerations for troubleshooting multilinks.
NoteThe show and debug commands that you use to troubleshoot are enable mode
commands. You can also enter them from any context except basic by adding
do to the beginning of the command.
Standard Procedure
When troubleshooting a multilink, follow the standard procedure for troubleshooting any PPP, Frame Relay, or Asymmetric Digital S ubscriber Line (ADSL)
connection:
2-12
1.Check the Physical Layer.
2.Check the Data Link Layer.
Physical Layer
Check the Stat LED for the module slot in which the line is installed. If the
LED is green, the Physical Layer is up. If you cannot send data over the link,
you will need to troubleshoot the Data Link Layer.
If the LED is red, try changing the cable and checking the other hardware. (If
the line is in a dual-module slot, you will need to use the show interfaces
command to determine which is port down.)
Next, check the configurations for the physical interface and make sure that
they match those used by your public carrier.
Data Link Layer
Different problems arise depending on the protocol the connection uses.
Page 71
Increasing Bandwidth
Troubleshooting Multilinks
PPP. Common PPP problems include:
■mismatched DS0 or E0 channels
■incorrect authentication information
■incompatible network-level protocols
Use the debug commands shown in Table 2-1 to determine where the PPP
session establishment ends. A good strategy can be to first view only the errors
and then pinpoint the problem from there.
CautionMessages resulting from debug ppp commands consume processing power
and in a live network may compromise network functions.
Table 2-1.PPP Debug Commands
Command SyntaxView
debug ppp verboseall PPP debug messages
debug ppp negotiationPPP messages dealing with negotiation of the link
debug ppp authenticationPPP messages dealing with authentication
debug ppp errorserrors and mismatches in negotiation and authentication
You can also view the status of an interface by entering show interface ppp
<interface number>.
If the LCP state does not open, the E1-carrier or T1-carrier lines have probably
been assigned an incorrect channel range. (This is properly a Physical Layer
problem but often does not show itself until peers exchange LCP frames.)
If you receive an authentication error and repeated Challenge Handshake
Authenticate Protocol (CHAP) or Password Authentication Protocol (PAP)
messages, you should check the router’s authentication information.
If you see NCP negotiation errors or if the LCP opens, but the PPP session
does not, determine which network protocol the peer uses. You may be using
incompatible protocols.
For more information about troubleshooting PPP and PPP authentication, see
the Basic Management and Configuration Guide, Chapter 6: Configuring the Data Link Layer Protocol for E1, T1, and Serial Interfaces.
Frame Relay. Enter show frame-relay lmi to view the link management
interface (LMI) statistics.
2-13
Page 72
Increasing Bandwidth
Troubleshooting Multilinks
ProCurve# show frame-relay lmi
LMI statistics for interface FR 1 LMI TYPE = ANSI
Num Status Enq. Sent 24 Num Status Msgs Rcvd 7
Num Update Status Rcvd 1 Num Status Timeouts 3
Number of polls
sent
Number of polls
received
Figure 2-4. LMI Statistics for a Frame Relay Connection
On a functioning Frame Relay connection, the polls sent and received should
be approximately equal. The Frame Relay interface in Figure 2-4 has sent 17
polls without receiving a reply. Steadily increasing polls sent out without
replies probably indicate:
■incompatible signaling type
■incorrect signaling role
■incorrect DLCI (also indicated by a deleted PVC)
■mismatched DS0 or E0 channels
Table 2-2 gives the command syntax for displaying information about Frame
Relay connections.
Table 2-2.Frame Relay show Commands
Command SyntaxView
show interfaces frame-relay <interface number>Frame Relay port:
• signaling type
• interface type (UNI or NNI)
2-14
show interfaces frame-relay <subinterface number> Frame Relay subinterface:
• PVC status
•DLCI
• IP address
show frame-relay pvcPVC end-to-end:
• PVC status
•DLCI
• packets in and out
• DE packets
• FECN/BECN packets
show frame-relay lmiLMI statistics—polls sent and
received
Page 73
Increasing Bandwidth
Troubleshooting Multilinks
View the Frame Relay interface and verify that its signaling type matches that
of your service provider. You can enter show interface fr <subinterface number> to view a subinterface (the PVC endpoint) and check DLCIs and the
PVC state. If the Frame Relay interface is down, you probably have a problem
with the signaling type or role.
If the Frame Relay interface is up but a PVC is inactive or deleted, you probably
have a problem with the DLCI.
Also check the TDM channels configured for the physical interface. Even
though mismatched channels is a Physical Layer problem, it sometimes does
not manifest itself until peers attempt to establish a link.
For more information about troubleshooting Frame Relay, see the Basic
Management and Configuration Guide, Chapter 6: Configuring the Data
Link Layer Protocol for E1, T1, and Serial Interfaces.
Troubleshooting MLPPP
The most important consideration for troubleshooting MLPPP is determining
whether the peer supports it. To determine this, view PPP debug messages:
ProCurve# debug ppp negotiation
As you examine the output, look for the following two fields in the negotiation
events:
■MRRU
■ED
MRRU
An MRRU field automatically signals MLPPP support. In Figure 2-5, the router
receives a message with an MRRU option, which indicates that the peer
supports MLPPP.
If the peer at the other end of the link rejects this option, the ProCurve Secure
Router will terminate the link because it assumes its peer cannot support
MLPPP.
2004.07.26 02:21:16 INTERFACE_STATUS.ppp 1 changed state to up
Multilink
support
T1 1/1 and T1
2/1 are the
same link
Figure 2-5. MLPPP Debug Messages
ED
Next, look for messages dealing with the ED option. The ED option identifies
the device transmitting the packet and allows the receiving peer to recognize
that frame fragments received on different carrier lines belong together. The
ED should be the same for each line in the bundle. For example, in Figure 2-5
the ED for the T1 1/1 interface and the T1 2/1 interface are the same.
Troubleshooting MLFR
To view debug messages for MLFR, enter the following command from the
enable mode context:
ProCurve# debug frame-relay multilink
MLFR periodically sends hellos to the remote endpoint. The local interface
should receive a hello ACK in reply. The Frame Relay interface should send a
hello for each carrier line. (See Figure 2-6.) If the interface is not sending hellos
for one of the carrier lines, then that line is down.
If the interface is continually sending requests to add a link instead of hellos,
the endpoint probably does not support MLFR. It is also possible that carrier
lines on either end of the link are configured for a different set of channels.
(See Figure 2-7.)
This section provides the commands you must enter to quickly configure:
■Multilink PPP (MLPPP)
■Multilink Frame Relay (MLFR)
Only a minimal explanation is provided. If you need additional information
about any of these options, check “Contents” on page 2-1 to locate the section
that contains the explanation you need.
You may want to print out and complete Table 2-3 to use while you configure
your router.
Table 2-3.Quick Start Configuration Worksheet
LineParameterYour Setting
new physical line 1slot
port
new physical line 2slot
port
new physical line 3slot
port
existing lineTDM group number
channels
logical interface type
logical interface number
IP address (logical interface)
2-19
Page 78
Increasing Bandwidth
Quick Start
MLPPP Configuration
Before you begin completing these instruction, you should connect the physical interfaces to the appropriate public carrier equipment. You should also
have a non-multilink PPP connection up and running.
1.Move to the global configuration mode context and configure the physical
interface(s) for the new carrier line(s):
a.Move to the interface configuration mode context:
Syntax: interface
b. TDM group numbers are significant for the interface only, so you can
use the same TDM group number as the original line. You must use
the same number of channels:
You can also have the interface take its address from the far end of the
link (negotiated). A PPP interface can take a dynamic address from a
DHCP server only when it is acting as a bridge. The interface can also take
its address from another router interface, such as the Ethernet interface:
Syntax: ip unnumbered <interface ID>
6. Activate the PPP interface:
ProCurve(config-ppp 1)# no shutdown
Quick Start
MLFR Configuration
Before you begin completing these instruction, you should connect the physical interfaces to the appropriate public carrier equipment. You should also
have a non-multilink Frame Relay connection up and running.
1. Move to the global configuration mode context and configure the physical
interface(s) for the new carrier line(s):
a.Move to the interface configuration mode context:
Syntax: interface [e1 | t1] <slot>/<port>
b. Configure the TDM group. You can use the same TDM group as the
original line. You must use the same number of channels:
Syntax: tdm-group
c. Activate the interface:
Syntax: no shutdown
d. Repeat these steps for each new carrier line.
2. Move to the Frame Relay interface for the connection:
Syntax: interface frame-relay <interface number>
3.Enable multilink functions:
ProCurve(config-fr 1)# frame-relay multilink
<tdm group number> timeslots <channels>
2-21
Page 80
Increasing Bandwidth
Quick Start
4.Enabling multilink unbinds physical lines from the interface. As well as
binding each new physical interface to the Frame Relay interface, you
must rebind the original line:
ProCurve(config-fr 1.101)# ip address 10.2.2.1 /30
The Frame Relay subinterface can also act as a DHCP client and take a
dynamic address from a connecting server. Use the dhcp option. The
interface can also take an address from another router interface, such as
an Ethernet interface:
Syntax: ip unnumbered <interface ID>
You might also need to change the signaling type and role for the Frame Relay
interface. For more information about configuring Frame Relay, see the Basic
Management and Configuration Guide, Chapter 6: Configuring the Data
Link Layer Protocol for E1, T1, and Serial Interfaces.
To ensure that users can always exchange data between two offices, you may
want to lease a dial-up WAN connection—such as an Integrated Services
Digital Network (ISDN) or telephone line—which can be used as a redundant
line in case a primary WAN connection fails. Dial-up WAN connections work
well as backup connections because you pay only for the time when the
connection is in use.
Like other WAN connections, dial-up connections are provided through the
public carrier network. In North America, dial-up connections are provided
through the public switched telephone network (PSTN). Outside of North
America, each country’s public telephone and telegraph (PTT) authority
provides dial-up connections.
All WAN connections, including dial-up connections, consist of three basic
elements:
■the physical transmission media
■electrical signaling specifications for generating, transmitting, and receiv-
ing the signals that transmit data through the telephone cables
■Data Link Layer protocols, which provide logical flow control for moving
data between the router and the public carrier’s central office (CO)
Just as you configure both a Physical Layer and a Data Link Layer for primary
WAN connections, you must configure these layers for backup connections.
Configuring the Physical and Data Link Layers for backup connections is a
slightly different process, however, because you must specify when and how
the backup connection is initiated.
Analog Backup Connections
If you want to create a backup connection over the existing telephone cabling,
you can use an analog modem, which establishes a dial-up connection to its
peer—another analog modem at the remote office. To initiate a physical
connection, the analog modem places a telephone call to its peer and then
negotiates a logical link with the peer using a Data Link Layer protocol. After
the connection is established, the analog modem translates digital data into
analog signals. When the two peers are finished exchanging data, the analog
modem terminates the connection just as a person would hang up a call.
3-5
Page 86
Configuring Backup WAN Connections
Backing Up Primary WAN Connections
Analog modems provide comparatively little bandwidth. (The ProCurve
Secure Router analog module provides between 300 bps and 33.6 kbps.) When
analog modems are incorporated into WAN routers, they are designed only to
provide redundancy for other WAN lines, not to furnish a long-term WAN
connection.
ISDN-Backup Connections
ISDN is a dial-up WAN connection that supports voice, data, fax, and video
services over standard telephone lines. Unlike analog communications, ISDN
communications are digital.
Public carriers offer two types of ISDN services:
■Basic Rate Interface (BRI)
■Primary Rate Interface (PRI)
ISDN BRI provides two 64-Kbps bearer (B) channels and one 16 Kbps data (D)
channel. The B channels carry data, and the D channel handles the signaling
and call control for the ISDN line.
PRI ISDN, on the other hand, provides 23 B channels and 1 D channel in North
America and Japan. It provides 30 B channels and 1 D channel in Europe, Asia
(except Japan), Australia, and South America. (When PRI includes 30 B
channels, channel 0 is used to maintain synchronization and is not counted as
either a B or D channel.) The transmission rates for PRI ISDN match the
transmission rates for an E1- or T1-carrier line. In North America and Japan,
PRI ISDN provides 1.544 Mbps. In other areas, PRI ISDN provides 2.048 Mbps.
3-6
In an ISDN connection, the B channels are treated independently. They can
be used for simultaneous voice and data; in other words, you can talk on the
phone and surf the Web at the same time. For example, if you have an ISDN
BRI connection, you can use both channels for data transmissions to a remote
network, or you can use each channel to connect to a different remote office.
Because the ProCurve Secure Router supports BRI ISDN for backup connections, this chapter focuses on BRI ISDN. (The ProCurve Secure Router also
supports BRI ISDN for primary WAN connections. For more information, see
Chapter 8: Configuring Demand Routing for Primary ISDN Modules in the
Basic Management and Configuration Guide.)
Page 87
Configuring Backup WAN Connections
Backing Up Primary WAN Connections
BRI ISDN
BRI ISDN operates over the twisted-pair cabling that is used for ordinary
telephones. All of the telecommunications infrastructure that is used to
connect your LAN to the CO is collectively called the local loop.
The local loop is divided into two sections by a line of demarcation (demarc),
which separates your company’s wiring and equipment from the public carrier’s wiring and equipment. (See Figure 3-1.) As a general rule, your company
owns, operates, and maintains the wiring and equipment on its side of the
demarc, and the public carrier owns, operates, and maintains the wiring and
equipment on its side of the demarc. For ISDN connections, the position of
the demarc varies, depending on which ISDN equipment the public carrier
provides.
TE2
R
interface
TEI
(Router)
Terminal
adapter
Demarc (outside
North America)
NT2
S
interfaceT interfaceUinterface
NT1
Demarc
(North America)
Interface Unit
(Smart Jack)
Network
Wire span
Repeater
Public
Carrier’s CO
ISDN
Switch
ISDN Switch
Figure 3-1. ISDN Network
In addition to the demarc, the local loop includes:
■ISDN switch—At the public carrier’s CO, the ISDN switch multiplexes and
de-multiplexes channels on the twisted pair wiring of the local loop. It
provides the physical and electrical termination for the ISDN line and then
forwards the data onto the public carrier’s network.
■Repeater—A repeater receives, amplifies, and retransmits the digital
signal so that the signal is always strong enough to be read. Because ISDN
lines use 2B1Q coding, which operates at a lower frequency range than
T1 or E1 encoding, repeaters are required only every 5.49 km (18,000 feet).
In contrast, T1 encoding requires a repeater approximately every 1.6 km
(1 mile or 5,280 feet).
3-7
Page 88
Configuring Backup WAN Connections
Backing Up Primary WAN Connections
■
Wire span—Because public carrier networks were originally designed to
carry analog voice calls, copper wire is the most common physical transmission medium used on the local loop. Although copper wire has a limited
signal-carrying capacity, ISDN is designed to maximize its capability.
■Network Interface Unit (NIU)—The NIU automatically maintains the
WAN connection and enables public carrier employees to perform simple
management tasks from a remote location. The NIU is usually located
outside the subscriber’s premises so that public carrier employees can
always access it. (The NIU is commonly referred to as the “smart jack” in
North America.)
■Network Termination (NT) 1—The NT1 provides the physical and electri-
cal termination for the ISDN line. It monitors the line, maintains timing,
and provides power to the ISDN line. In Europe and Asia, public carriers
supply the NT1. In North America, however, the subscriber provides the
NT1. In fact, many ISDN vendors are now building the NT1 directly into
ISDN equipment such as routers.
■NT 2—PRI ISDN also requires an NT2, which provides switching functions
and data concentration for managing traffic across multiple B channels.
In many regions, the NT1 and NT2 are combined into a single device,
which is called an NT12 (NT-one-two) or just NT.
■Terminal equipment (TE) 1—TE1 devices are ISDN-ready devices and can
be connected directly to the NT1 or the NT2. TE1 devices include routers,
digital phones, and digital fax machines.
■TE2—TE2 devices do not support ISDN and cannot connect directly to
an ISDN network. TE2 devices require a terminal adapter (TA) to convert
the analog signals produced by the TE2 device into digital signals that can
be transmitted over an ISDN connection. TE2 devices include analog
telephones and analog fax machines.
■Terminal adapter (TA)—A TA allows you to connect a TE2 device to an
ISDN network.
3-8
You do not need to understand all of the equipment used to create the local
loop with great technical precision. However, if your ISDN line ever goes
down, a basic knowledge and working vocabulary can help you troubleshoot
problems with your public carrier.
You should also understand that the demarc defines which equipment your
organization is responsible for maintaining. In addition, the demarc determines the type of ISDN backup module you use, as explained in the next
section.
Page 89
Configuring Backup WAN Connections
Backing Up Primary WAN Connections
ISDN Interfaces. The ISDN standard defines four interfaces, or points, at
which equipment can be added to the ISDN network:
■U interface (between the NT1 and the NIU)
■T interface (between the NT2 and the NT1)
■S interface (between the TE1 and the NT2)
■R interface (between the TE2 and the TA)
In Europe, Asia, and all other locations outside of North America, PTTs supply
the NT devices. The demarc then falls between the TE (in your case, the
router) and the NT1 at the S/T interface. The ProCurve Secure Router provides
an ISDN BRI S/T module, which enables a backup interface to connect to
either the NT2 or the NT1 provided by your PTT.
In North America, the subscriber must provide the NT devices. The demarc
falls between the NT devices and the public carrier’s NIU (or smart jack) at
the U interface. The ProCurve Secure Router’s ISDN BRI U module contains
the NT1 and enables a backup interface to function as a U interface.
Electrical Specifications for BRI ISDN
ISDN lines use 2B1Q coding, which uses four signal levels rather than the two
of T1- or E1-carrier lines. Each of the four levels, represented by a quaternary,
corresponds to a combination of two bits. For example, the signal level for 1
followed by 1 is different for that of 1 followed by 0. This coding scheme allows
BRI ISDN lines to compress data. Also, 2B1Q operates at a lower frequency
range than T1/E1 encoding and sustains fewer losses with fewer repeaters.
Backup Modules for the ProCurve Secure Router
All narrow Data Link m odules on the ProCurve Secure Router provide an extra
port for a backup interface. To activate the backup interface, you must
purchase and install one of the following backup modules:
■analog
■ISDN BRI U
■ISDN BRI S/T
The ProCurve Secure Router supports BRI ISDN, which provides a transmission rate of 64 Kbps or 128 Kbps. The analog module on the ProCurve Secure
Router supports between 300 bps and 33.6 Kbps.
3-9
Page 90
Configuring Backup WAN Connections
Backing Up Primary WAN Connections
As Figure 3-2 shows, the backup module is installed over the data link module.
Figure 3-2. Installing a Backup Module
After the backup module is installed, it can back up any interface on the router,
not only those interfaces installed in the same slot. You can back up:
■Point-to-Point Protocol (PPP) connections
■High-level Data Link Control (HDLC) connections
■Frame Relay connections
■ISDN primary connections
■Asymmetric Digital Subscriber Line (ADSL) connections
■Internet connections (using any Data Link Layer protocol)
3-10
Standards
On the ProCurve Secure Router, both ISDN backup modules support the
following standards:
■National ISDN-1—Defined in the mid 1990s by the National Institute of
Standards and Technology (NIS) and Bellcore (now called Telcordia),
National ISDN-1 specifies a common set of options that ISDN manufacturers and public carriers must provide.
■Northern Telecom Digital Multiplex System (DMS)-100—DMS-100 is
another standard for transmitting voice and data over an ISDN line.
■AT&T 5ESS—AT&T switches use Lucent signaling.
Page 91
Configuring Backup WAN Connections
Determining a Backup Method
In addition to these three options, the ISDN BRI S/T backup supports:
■Euro-ISDN—Also called Normes Européennes de Télécommunication 3
(NET3), Euro-ISDN was defined in the late 1980s by the European Commission so that equipment manufactured in one country could be used
throughout Europe.
You must configure your router’s BRI interface for the type of signaling your
service provider implements. Because switches can implement various types
of signaling depending on their software, the signaling type will not always be
that of the CO switch’s manufacturer.
Data Link Layer Protocols
On the ProCurve Secure Router, backup ISDN connections always use PPP as
the Data Link Layer protocol, no matter what Data Link Layer protocol is used
for the primary connection. For example, if the ISDN line is used to back up
a Frame Relay connection between two offices, the ISDN uses PPP.
Determining a Backup Method
The ProCurve Secure Router initiates a backup connection in response to a
backup condition. Backup conditions include Layer 1, or Physical Layer,
failures such as:
■T1 and E1 alarms
■ADSL failure due to low signal-to noise ratio (SNR)
■other line failures and WAN alarms
Backup conditions also include Layer 2, or Data Link Layer, failures such as:
■signaling failure
■loss of permanent virtual circuit (PVC)
You have two choices for configuring how the ProCurve Secure Router
responds to a backup condition:
■You can configure demand routing, which is activated only if both of the
following conditions are met:
•A backup condition occurs, bringing the primary interface down.
•The router receives traffic that must be transmitted to the far-end
network.
3-11
Page 92
Configuring Backup WAN Connections
Determining a Backup Method
■You can configure a persistent backup connection, which is initiated
immediately if a backup condition occurs on the primary connection and
stays up until the primary connection is available again.
Before you configure a backup connection, you should evaluate your network
environment and then determine which option best meets your company’s
particular needs.
Using Demand Routing for Backup Connections
Demand routing allows you to capitalize on the main advantage of a dial-up
connection: it establishes the dial-up connection when it is needed and
terminates the connection when it is no longer necessary. For example, you
may lease an ISDN line to serve as the backup WAN connection between the
main office and a branch office. If the primary interface goes down and no one
is transmitting traffic, you may not want the backup WAN connection to
become active. This type of usage would substantially increase your company’s telephone costs. Instead, you may want to establish the ISDN connection only when two conditions are met:
■the primary interface goes down
■traffic must be transmitted between the two offices
Demand routing only establishes the backup connection when traffic is sent
from the main office to the branch office and the primary interface is unavailable. (See Figure 3-3.)
In addition to establishing the connection only when it is needed for data
transmission, demand routing ensures that when the dial-up connection is idle
for certain amount of time, the ProCurve Secure Router terminates the call.
You can configure the idle timer to match the rates you are charged for the
ISDN line. For example, if your service provider charges your company for
every two minutes that the ISDN line is established, you can set the idle timer
to 110 seconds. The ProCurve Secure Router will then disconnect the ISDN
line when it has been idle for 110 seconds, and your company will not be
charged for an additional two minutes.
With demand routing, you can also be very selective in the type of traffic that
causes the router to initiate the ISDN connection. For example, you can limit
this “interesting” traffic to packets sent from one subnet to another subnet.
You can also exclude routing updates (if you are using a routing protocol) and
other traffic that you do not think is essential. Carefully selecting the type of
traffic that triggers an ISDN connection limits the amount of time that your
company uses its ISDN connection, thereby decreasing costs.
3-12
Page 93
Configuring Backup WAN Connections
Determining a Backup Method
Branch Office B
Edge Switch
Edge Switch
Edge Switch
Edge Switch
Edge Switch
Core Switch
192.168.1.0
192.168.2.0
Core Switch
Main Router
Frame Relay
over E1
Backup ISDN
connections
Frame Relay
over E1
Switch
Branch Router
Switch
The backup ISDN connection to Branch Office B is
triggered only when the primary interface on the Main
Router goes down and traffic with destination address
192.168.3.0 /24 or 192.168.4.0 /24 is forwarded to demand
interface 1 on the Main Router.
Branch Office C
Switch
Branch Router
Switch
The backup ISDN connection to Branch Office C is
triggered only when the primary interface on the Main
Router goes down and traffic with destination address
192.168.5.0 /24 or 192.168.6.0 /24 is forwarded to dem and
interface 2 on the Main Router.
192.168.3.0
192.168.4.0
192.168.5.0
192.168.6.0
Figure 3-3. Using Demand Routing for Backup Connections
Demand routing has another advantage: it supports two-port ISDN modules.
If you are not using all of the narrow slots in your ProCurve Secure Router,
you can purchase a two-port ISDN module and use it as a primary WAN
connection or as a backup to other primary WAN connections. To use the twoport module for backup connections, you follow the instructions outlined in
Chapter 8: Configuring Demand Routing for Primary ISDN Modules in the
Basic Management and Configuration Guide, with one exception. Rather
than creating a static route to the far-end network, you create a floating static
route, ensuring that the administrative distance for this floating static route is
higher than the administrative distance for the route through the primary
interface. For more information about static routes, see “Configuring a Floating Static Route for a Persistent Backup Connection” on page 3-67.
If you purchase this two-port ISDN module, you can use Multilink PPP
(MLPPP) to aggregate channels across ISDN lines, increasing bandwidth for
the dial-up connection.
3-13
Page 94
Configuring Backup WAN Connections
Determining a Backup Method
If you use the backup ISDN modules, you cannot use MLPPP to aggregate
channels. The ISDN backup modules support bonding, rather than channel
aggregation. You can bond channels on an ISDN backup module only if:
■you configure a persistent backup connection
■the router connects to another ProCurve Secure Router
If both of these conditions are met, you can use bonding to increase bandwidth.
NoteIf you use demand routing with a backup ISDN module, you can neither bond
nor multilink channels.
Using Persistent Backup Connections
You can also configure the backup module so that it immediately establishes
a dial-up connection when the primary interface fails. This connection stays
up until the primary interface is available again. You may want to configure
this type of backup connection between offices that require a constant connection.
The ProCurve Secure Router provides some settings to control when a persistent backup connection is established. For example, you can prevent the
connection from becoming active on weekends or evenings.
3-14
As mentioned earlier, when you configure a persistent backup connection,
you can bond two B channels for a total of 128 Kbps. The only limitation is
that the router must connect to another ProCurve Secure Router. If you want
to use MLPPP to aggregate channels, you must purchase and use a two-port
ISDN module, as described in Chapter 8: Configuring Demand Routing for Primary ISDN Modules in the Basic Management and Configuration Guide.
Comparing Demand Routing and Persistent Backup
Connections
Table 3-1 lists the main differences between demand routing and persistent
backup connections.
Page 95
Configuring Backup WAN Connections
Determining a Backup Method
Table 3-1.Differences Between Demand Routing and Persistent Backup
Connections
OptionDemand RoutingPersistent Backup Connection
supported hardware• analog and BRI backup modules, which can
be installed on top of any narrow module
• two-port ISDN modules, which are installed
in a narrow slot on the ProCurve Secure
Router
applications• backup modules—backup WAN connection
for two offices that require high availability
but need to limit usage and costs
• two-port ISDN modules—WAN connection
between two offices that exchange data
periodically and need a low-cost WAN
solution
Data Link Layer
protocol
initiation of dial-up
connection
termination of dial-up
connection
PPP, which is configured through the demand
interface
• backup connection—e stablished when two
conditions are met:
– primary connection is unavailable
– “interesting” traffic needs to be
transmitted
• primary ISDN connection—established
when “interesting” traffic must be
transmitted
• backup connection—terminated when primary connection is re-established or when
no interesting traffic is received before the
idle timer expires
• primary connection—terminated when no
interesting traffic is received for the time
specified in the idle timer
analog and backup modules, which can be
installed on top of any narrow module
backup for two locations that must maintain
a constant WAN connection
PPP, which is configured through a PPP
interface
backup connection established immediately
when the primary connection fails and
maintained until the primary connection is reestablished
terminated when primary connection is reestablished
methods to limit usage
of dial-up connections
increasing bandwidth • no bonding or MLPPP support for ISDN
• configure the access control list (ACL) to
limit “interesting” traffic, which triggers the
ISDN connection
• adjust idle timers to match the time intervals
for which your company is charged for its
dial-up connection
backup modules
• MLPPP support for two-port ISDN modules
specify times, such as weekends and evenings, when the dial-up connection should
not be established (even if the primary
connection goes down)
channel bonding with another ProCurve
Secure Router
3-15
Page 96
Configuring Backup WAN Connections
Determining a Backup Method
Figure 3-4 shows how a backup connection is established if demand routing is
configured. Figure 3-5 shows how a persistent backup connection is established.
10.1.1.010.4.4.0
Main Router
Switch
10.2.2.0
Routing Table
C 10.1.1.0/30 is directly connected, fr 1.1
C 10.2.2.0/24 is directly connected, eth 0/1
C 10.10.10.0/30 is directly connected, demand 1
S 10.4.4.0/24 [1/0] via 0.0.0.0, fr 1.1
Frame Relay
over E1
Office Router
To: 10.4.4.23
From: 10.2.2.5
Primary connection is av ailable, so
traffic is routed over Frame Relay
connection
Figure 3-4. Demand Routing for a Backup Connection
Primary
connection
fails
Connection
10.1.1.010.4.4.0
Main RouterOffice Router
Switch
10.2.2.0
Routing Table
C 10.2.2.0/24 is directly connected, eth 0/1
C 10.10.10.0/30 is directly connected, demand 1
S 10.4.4.0/24 [2/0] via 0.0.0.0, demand 1
ip access-list extended RouterA
permit ip 10.2.2.0 0.0.0.255 10.4.4.0 0.0.0.255
triggered by
interesting traffic
To: 10.4.4.23
From: 10.2.2.5
Primary connection is u navailable, so
traffic is routed to demand interface.
ACL determines which traffi c triggers
dial-up connection.
3-16
Page 97
Configuring Demand Routing for Backup Connections
Configuring Backup WAN Connections
10.1.1.010.4.4.0
Main Router
Switch
10.2.2.0
Routing Table
C 10.1.1.0/30 is directly connected, fr 1.1
C 10.2.2.0/24 is directly connected, eth 0/1
C 10.10.10.0/30 is directly connected, ppp 1
S 10.4.4.0/24 [1/0] via 0.0.0.0, fr 1.1
Frame Relay
over E1
Office Router
To: 10.4.4.23
From: 10.2.2.5
Primary connection available, so
traffic is routed over Frame Relay
connection
Figure 3-5. Persistent Backup Connection
If you want to use demand routing for your backup connections, continue with
the next section. If you want a persistent backup connection, continue with
“Configuring a Persistent Backup Connection” on page 3-47.
Primary
connection
fails
10.1.1.010.4.4.0
Main RouterOffice Router
Connection
triggered
immediately
Switch
10.2.2.0
Routing Table
C 10.2.2.0/24 is directly connected, eth 0/1
C 10.10.10.0/30 is directly connected, ppp 1
S 10.4.4.0/24 [2/0] via 0.0.0.0, ppp 1
Primary connection unavailable,
so traffic is routed over dial-up
connection
Configuring Demand Routing for Backup
Connections
To configure demand routing for backup connections, you must complete the
following steps:
1. Create an extended access control list (ACL) to define the traffic that will
trigger the dial-up connection when the primary interface is unavailable.
2.Configure a demand interface.
3. Configure the BRI interface.
4.Create a floating static route to the far-end network.
3-17
Page 98
Configuring Backup WAN Connections
Configuring Demand Routing for Backup Connections
Define the Traffic That Triggers the Connection
You must first define the interesting traffic—the traffic that triggers, or activates, the WAN connection. For example, if you are configuring demand
routing for a backup connection between the main office and a branch office,
the interesting traffic would be the packets destined for the branch office. The
ProCurve Secure Router will route these packets to the demand interface only
if the primary interface is down and the floating static route that you configure
for the traffic is activated in the routing table. (Floating static routes are
explained in more depth later in this chapter.)
To define the interesting traffic, you create an extended ACL. The ProCurve
Secure Router will use this ACL to identify and select interesting traffic.
From the global configuration mode context, enter:
Syntax: ip access-list extended <listname>
Replace <listname> with an alphanumeric descriptor that is meaningful to
you. The listname is case sensitive.
After you enter this command, you are moved to the extended ACL configuration mode context and can enter permit and deny statements to define the
traffic that will trigger the dial-up connection. Use the following command
syntax:
When you create a permit or deny statement for an extended ACL, you must
always specify a protocol. Valid protocols include:
■AHP
■ESP
■GRE
■ICMP
■IP
■TCP
■UDP
You can also specify a number between 0 and 255 for the protocol.
Page 99
Configuring Demand Routing for Backup Connections
Configuring Backup WAN Connections
For demand routing, you may want to create an ACL that selects all the traffic
to a particular subnet. In this case, you should specify ip as the protocol.
Defining the Source and Destination Addresses
When you create an extended ACL, you must configure both a source and a
destination address for each entry. You specify first the source address and
then the destination address, using the following syntax for each address:
Table 3-2 lists the options you have for specifying a source or destination
address.
Table 3-2.Options for Specifying Source and Destination Addresses
Option Meaning
anymatch all hosts
host <A.B.C.D>specify a single IP address or a single host
hostname <hostname>specify a single host, using a hostname rather than an IP
address
<A.B.C.D> <wildcard bits>specify a range of IP addresses
Using Wildcard Bits. You use wildcard bits to permit or deny a range of IP
addresses. Wildcard bits define which address bits the Secure Router OS
should match and which address bits it should ignore.
When you enter wildcard bits, you use a zero to indicate that the Secure Router
OS should match the corresponding bit in the IP address. You use a one to
indicate that the Secure Router OS can ignore the corresponding bit in the IP
address. In other words, the Secure Router OS does not have to match that bit.
For example, you might enter:
ProCurve(config-ext-nacl)# deny ip any 192.115.1.0 0.0.0.255
If you enter 192.115.1.0 with the wildcard bits 0.0.0.255, the Secure Router
OS will not match any address bits in the fourth octet of the IP address. The
Secure Router OS will match incoming packets to the IP subnet with the
address 192.115.1.0 /24. (For more information about configuring ACLs, see
Chapter 5: Applying Access Control to Router Interfaces.)
3-19
Page 100
Configuring Backup WAN Connections
Configuring Demand Routing for Backup Connections
Examples. For example, if you want any traffic to the far-end network
192.168.115.0 /24 to trigger the dial-up connection, you would enter:
ProCurve(config-ext-nacl)# permit ip any 192.168.115.0 0.0.0.255
If you want any outbound traffic from a particular network segment to trigger
a dial-up connection, use wildcard bits to specify that network as the source.
For example, enter:
ProCurve(config-ext-nacl)# permit ip 192.168.1.0 0.0.0.255 any
Implicit “Deny Any” for ACL. Each ACL includes an implicit “deny any”
entry at the end of the list. If a packet does not match any entry in the ACL
you create, it matches the implicit “deny any” entry.
After you have finished creating the ACL, enter exit to return to the global
configuration mode context.
After you create the ACL, you must apply it to the demand interface. In fact,
the ACL will have no effect until you apply it to the demand interface.
Configuring the Demand Interface
You must create a demand interface for each router to which the ProCurve
Secure Router will connect through a dial-up connection. The demand interface provides the Data Link Layer for the physical dial-up interface.
Like other logical interfaces such as Frame Relay or PPP, the demand interface
controls the logical functions for the WAN connection. In many ways, you
configure the demand interface as you do any other logical interface. For
example, you assign the demand interface an IP address. From this interface,
you apply the ACL that defines the interesting traffic that triggers the dial-up
WAN connection.
The demand interface is different from other logical interfaces, however. For
one thing, the demand interface is not bound to a specific physical interface
or interfaces. Instead, the demand interface is associated with the pool of dialup interfaces used for backup.
The demand interface must also handle its status differently: it must always
be up, whether or not the physical dial-up interface associated with the
demand interface is up. Because the demand interface cannot actually be up
if the Physical Layer is down, it “spoofs” an up state. As a result, the demand
interface can be listed as a directly connected interface in the router’s routing
table, even when the dial-up interface is not in use.
3-20
Loading...
+ hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.