<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CkMCSHs8eCp7ImA9WhRUFks.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641</id><updated>2012-01-27T17:34:29.570+07:00</updated><category term="OSPF" /><category term="Red Hat" /><category term="bgp" /><category term="Broadcast" /><category term="AutoRP" /><category term="AutoRP Listener" /><category term="Monitor" /><category term="Point-to-point" /><category term="Cisco" /><category term="ORF" /><category term="zone" /><category term="Masquerading" /><category term="Dynamic NAT" /><category term="class-map" /><category term="VRF" /><category term="Redundancy" /><category term="Virtual Host" /><category term="zone-pair" /><category term="Zone-based firewall" /><category term="RedHat" /><category term="Indexes" /><category term="Dense Mode" /><category term="Link" /><category term="ZFW" /><category term="Apache" /><category term="linux" /><category term="HSRP" /><category term="Web Server" /><category term="Frame-Relay" /><category term="Shell Script" /><category term="Sparse Mode" /><category term="Redudancy" /><category term="FollowSymLinks" /><category term="as-set" /><category term="Filtering" /><category term="Lagu" /><category term="403" /><category term="OSPF Network Type" /><category term="SLA" /><category term="chord" /><category term="Directory Listing" /><category term="MSDP" /><category term="NAT" /><category term="Options" /><category term="Regex" /><category term="SymLink" /><category term="aggregate" /><category term="Forbidden" /><category term="Stateful NAT" /><category term="SNAT" /><category term="Shamlink" /><category term="Ebiet G Ade" /><category term="Authentication" /><category term="Forwarding" /><category term="Multipoint" /><category term="Bash" /><category term="policy-map" /><category term="DHCP" /><category term="Multicast" /><title>yang Penting Jalan !</title><subtitle type="html" /><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://ianwijaya.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>74</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/YangPentingJalan" /><feedburner:info uri="yangpentingjalan" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;CU8DR305cSp7ImA9WhRWEEQ.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-1577727639941828307</id><published>2011-12-28T10:53:00.001+07:00</published><updated>2011-12-29T00:37:56.329+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-29T00:37:56.329+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Red Hat" /><category scheme="http://www.blogger.com/atom/ns#" term="Options" /><category scheme="http://www.blogger.com/atom/ns#" term="FollowSymLinks" /><category scheme="http://www.blogger.com/atom/ns#" term="Forbidden" /><category scheme="http://www.blogger.com/atom/ns#" term="Directory Listing" /><category scheme="http://www.blogger.com/atom/ns#" term="linux" /><category scheme="http://www.blogger.com/atom/ns#" term="403" /><category scheme="http://www.blogger.com/atom/ns#" term="Web Server" /><category scheme="http://www.blogger.com/atom/ns#" term="SymLink" /><category scheme="http://www.blogger.com/atom/ns#" term="Apache" /><category scheme="http://www.blogger.com/atom/ns#" term="Indexes" /><title>Forbidden 403</title><content type="html">&lt;br /&gt;
There are many reasons that could lead us getting forbidden message. Check the file permission, selinux, authorization or facl first. After all of those common things and u still don't work it out, then u shall read this blog !&lt;br /&gt;
&lt;br /&gt;
It was hard for me to trace this error. I had to copy fresh httpd 
configuration and compared it with the bad one. After diff-ed those 
files.&lt;br /&gt;
I realized this line: &lt;br /&gt;
&lt;br /&gt;
@@ -328,7 +335,7 @@&lt;br /&gt;
&amp;nbsp;# http://httpd.apache.org/docs/2.2/mod/core.html#options&lt;br /&gt;
&amp;nbsp;# for more information.&lt;br /&gt;
&amp;nbsp;#&lt;br /&gt;
-&amp;nbsp;&amp;nbsp;&amp;nbsp; Options Indexes FollowSymLinks&lt;br /&gt;
+&amp;nbsp;&amp;nbsp;&amp;nbsp; Options &lt;b&gt;+&lt;/b&gt;Indexes FollowSymLinks&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
I removed the bold-ed&amp;nbsp; + and my symlink expectedly works, but why ? &lt;br /&gt;
Kindly, check this quote:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote class="tr_bq"&gt;
source : http://httpd.apache.org/docs/2.0/mod/core.html&lt;/blockquote&gt;
&lt;blockquote class="tr_bq"&gt;
Normally, if multiple &lt;code class="directive"&gt;Options&lt;/code&gt; could
    apply to a directory, then the most specific one is used and
    others are ignored; the options are not merged. (See &lt;a href="http://httpd.apache.org/docs/2.0/sections.html#mergin"&gt;how sections are merged&lt;/a&gt;.)&lt;span style="color: lime;"&gt;
&lt;span style="color: #6aa84f;"&gt;    However if &lt;/span&gt;&lt;/span&gt;&lt;i style="color: #6aa84f;"&gt;all&lt;/i&gt;&lt;span style="color: #6aa84f;"&gt; the options on the
    &lt;/span&gt;&lt;code class="directive" style="color: #6aa84f;"&gt;Options&lt;/code&gt;&lt;span style="color: #6aa84f;"&gt; directive are preceded by a
    &lt;/span&gt;&lt;code style="color: #6aa84f;"&gt;+&lt;/code&gt;&lt;span style="color: #6aa84f;"&gt; or &lt;/span&gt;&lt;code style="color: #6aa84f;"&gt;-&lt;/code&gt;&lt;span style="color: #6aa84f;"&gt; symbol, the options are
    merged. Any options preceded by a &lt;/span&gt;&lt;code style="color: #6aa84f;"&gt;+&lt;/code&gt;&lt;span style="color: #6aa84f;"&gt; are added to the
    options currently in force, and any options preceded by a
    &lt;/span&gt;&lt;code style="color: #6aa84f;"&gt;-&lt;/code&gt;&lt;span style="color: #6aa84f;"&gt; are removed from the options currently in
    force. &lt;/span&gt;&lt;/blockquote&gt;
&lt;div class="warning"&gt;
&lt;blockquote&gt;
&lt;h3&gt;








Warning&lt;/h3&gt;
&lt;div style="color: red;"&gt;
Mixing &lt;code class="directive"&gt;Options&lt;/code&gt; with a &lt;code&gt;+&lt;/code&gt; or
    &lt;code&gt;-&lt;/code&gt; with those without is not valid syntax, and is likely
    to cause unexpected results.&lt;/div&gt;
&lt;/blockquote&gt;
&lt;br /&gt;
The point is, FollowSymLinks directive didn't work due to invalid syntax. :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
======== FIN ============&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-1577727639941828307?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/jLy16qOEvcvnB6IzxuKIaKDfX-A/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jLy16qOEvcvnB6IzxuKIaKDfX-A/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/jLy16qOEvcvnB6IzxuKIaKDfX-A/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jLy16qOEvcvnB6IzxuKIaKDfX-A/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/pb8UexD8K7Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/1577727639941828307/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=1577727639941828307" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/1577727639941828307?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/1577727639941828307?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/pb8UexD8K7Q/directory-listing-index-forbidden-403.html" title="Forbidden 403" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/directory-listing-index-forbidden-403.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIFRnw_cSp7ImA9WhRXFUg.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-2794908470491083802</id><published>2011-12-20T01:28:00.000+07:00</published><updated>2011-12-22T17:41:57.249+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-22T17:41:57.249+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SLA" /><category scheme="http://www.blogger.com/atom/ns#" term="linux" /><category scheme="http://www.blogger.com/atom/ns#" term="Link" /><category scheme="http://www.blogger.com/atom/ns#" term="Shell Script" /><category scheme="http://www.blogger.com/atom/ns#" term="Monitor" /><category scheme="http://www.blogger.com/atom/ns#" term="Bash" /><title>IP SLA-like Script</title><content type="html">#!/bin/bash&lt;br /&gt;
#&lt;br /&gt;
#Author         : Ian Wijaya&lt;br /&gt;
#Description    : Monitor IP SLA using icmp echo message, it's been designed to run as background process, thus need to be killed manually when no longer needed&lt;br /&gt;
#kill -9&amp;nbsp;&lt;pid&gt;&lt;br /&gt;#Creation date  : 12-10-2011&amp;nbsp;&lt;/pid&gt;&lt;br /&gt;
#Dependency: sendEmail v 1.56 -&amp;gt; &lt;a href="http://caspian.dotconf.net/menu/Software/SendEmail/"&gt;http://caspian.dotconf.net/menu/Software/SendEmail/&lt;/a&gt;&lt;br /&gt;
#&lt;br /&gt;
#usage: link_monitor.sh &amp;amp;&lt;br /&gt;
#&lt;br /&gt;
IFS="\n"&lt;br /&gt;
#Define parameter&lt;br /&gt;
host="8.8.8.8"            #hostname or IP to monitor&lt;br /&gt;
ping_interval=1                 #in second&lt;br /&gt;
ping_count=4&lt;br /&gt;
ping_threshold=3               &lt;br /&gt;
period=3                        #the ping monitor will be executed every n second&lt;br /&gt;
#so there will be 1 ping every 1s (4x1s) and then sleep for 3 sec&lt;br /&gt;
&lt;br /&gt;
mail_destination="receiver@domain.com"&lt;br /&gt;
mail_server="smtp.domain.com"&lt;br /&gt;
mail_account="sender@domain.com"&lt;br /&gt;
mail_subject="This is subject"&lt;br /&gt;
mail_password="senderpassword"&lt;br /&gt;
mail_send_interval=10           &amp;nbsp;#in minutes&lt;br /&gt;
mail_threshold=3                #if 3 consecutive pings are fail,&amp;nbsp; send email !&lt;br /&gt;
&lt;br /&gt;
#Declare variable&lt;br /&gt;
received_reply=0&lt;br /&gt;
rtt_summary=""&lt;br /&gt;
ping_result=""&lt;br /&gt;
prev_send_time=0&lt;br /&gt;
fail_count=0&lt;br /&gt;
&lt;br /&gt;
#param guard&lt;br /&gt;
if test $ping_count -lt $ping_threshold&lt;br /&gt;
then&lt;br /&gt;
&amp;nbsp;       &amp;nbsp; &amp;nbsp; &amp;nbsp;echo "ping_threshold value is not valid, it must be more than or equal to ping_count value" 2&amp;gt;&amp;amp;1&lt;br /&gt;
&amp;nbsp;       &amp;nbsp; &amp;nbsp; &amp;nbsp;exit&lt;br /&gt;
fi&lt;br /&gt;
&lt;br /&gt;
while true&lt;br /&gt;
do&lt;br /&gt;
&amp;nbsp;       &amp;nbsp; &amp;nbsp;ping_result=`ping -c $ping_count -i $ping_interval $host`&lt;br /&gt;
&amp;nbsp;       &amp;nbsp; &amp;nbsp;received_reply=`echo $ping_result | grep -i "received" |cut -d"," -f2 | awk {'print $1'}`&lt;br /&gt;
&amp;nbsp;       &amp;nbsp; &amp;nbsp;rtt_summary=`echo $ping_result | grep -i "rtt" | awk -F"=" '{print $2}'`&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;if test $received_reply -lt $ping_threshold&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;then&lt;br /&gt;
&amp;nbsp;               &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; now=`date +%s`&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;               &amp;nbsp; &amp;nbsp; msg="`date +%d"-"%m"-"%Y" "%T` | $received_reply/$ping_count | $rtt_summary"&lt;br /&gt;
&amp;nbsp;               &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; fail_count=`expr $fail_count + 1`&lt;br /&gt;
&amp;nbsp;               &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if test `expr $now - $prev_send_time` -gt `expr $mail_send_interval \\* 60` -a $fail_count -ge $mail_threshold&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;               &amp;nbsp; &amp;nbsp; then&lt;br /&gt;
&amp;nbsp;                       &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;./sendEmail-v1-56/sendEmail -f "$mail_account" -t "$mail_destination" -u "$mail_subject" -m "$msg" -s "$mail_server" -xu "$mail_account" -xp "$mail_password" 1&amp;gt; /dev/null&lt;br /&gt;
&amp;nbsp;                       &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;prev_send_time=$now&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;                       &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fail_count=0&lt;br /&gt;
&amp;nbsp;               &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; fi&lt;br /&gt;
&amp;nbsp;           &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; echo $msg &amp;gt;&amp;gt; link-monitor.log&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; else&lt;br /&gt;
&amp;nbsp;               &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if test $fail_count -gt 0&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;               &amp;nbsp; &amp;nbsp; then&lt;br /&gt;
&amp;nbsp;                       &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fail_count=`expr $fail_count - 1`&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;               &amp;nbsp; &amp;nbsp; fi&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; fi&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;sleep $period&lt;br /&gt;
done&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
If success reply is lower than ping_threshold, the result will be considered as negative result (and will be logged).&lt;br /&gt;
Negative ping result will increment fail_count whereas positive result will decrement it. If the counter has reached the mail_threshold and the mail has not sent within last 10 minutes, an email will be sent and the counter will be reset to zero.&lt;br /&gt;
&lt;br /&gt;
you can replace the /sendEmail part with another action. u may want to change route, delete route, reduce metric or anything else, depends on your requirement.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-2794908470491083802?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/yZeFTtKqz-NpOJGDOfF4qVLpixg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yZeFTtKqz-NpOJGDOfF4qVLpixg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/yZeFTtKqz-NpOJGDOfF4qVLpixg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/yZeFTtKqz-NpOJGDOfF4qVLpixg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/D7ymI4dKP8Y" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/2794908470491083802/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=2794908470491083802" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2794908470491083802?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2794908470491083802?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/D7ymI4dKP8Y/ip-sla-like-script.html" title="IP SLA-like Script" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/ip-sla-like-script.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MBSXw5eCp7ImA9WhRXEkU.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-6083459573013984045</id><published>2011-12-18T00:22:00.001+07:00</published><updated>2011-12-19T14:57:38.220+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-19T14:57:38.220+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Multicast" /><category scheme="http://www.blogger.com/atom/ns#" term="MSDP" /><title>Multicast Source Discovery Protocol (MSDP)</title><content type="html">Apabila terdapat 2 multicast domain, katakanlah domain A dan domain B dan masing-masing memiliki RP router tersendiri (RP-A dan RP-B), sedangkan multicast source terdapat pada multicast domain A, maka multicast domain B tidak akan mendapatkan paket multicast dari source tersebut.&lt;br /&gt;
Untuk mengatasi masalah tersebut, kita dapat mengkonfigurasikan MSDP peering pada kedua RP router.&lt;br /&gt;
Dengan MSDP peer, RP-A akan mengirimkan Source Active(SA) messages setiap 60 second
kepada RP-B. SA message berisi list IP address semua source untuk setiap group multicast yang terdapat pada RP-A.&lt;br /&gt;
&lt;br /&gt;
Berikut contoh lab nya.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-KifQr0ZG6DA/Tu7t9g9nBeI/AAAAAAAAAN4/X_yfWPQiw0s/s1600/msdp-n.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="158" src="http://3.bp.blogspot.com/-KifQr0ZG6DA/Tu7t9g9nBeI/AAAAAAAAAN4/X_yfWPQiw0s/s320/msdp-n.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;R1#&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;ip multicast-routing&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.12.1 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;router ospf 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.12.1 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;R2#&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;ip multicast-routing&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface Loopback1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 2.2.2.2 255.255.255.255&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.12.2 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.23.2 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;router ospf 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 2.2.2.2 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.12.2 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.23.2 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: orange;"&gt;&lt;span style="font-size: x-small;"&gt;ip pim send-rp-announce Loopback1 scope 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;ip pim send-rp-discovery scope 1&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;R3#&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;ip multicast-routing&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.23.3 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.34.3 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;router ospf 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.23.3 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.34.3 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;R4#&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;ip multicast-routing&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface Loopback1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 4.4.4.4 255.255.255.255&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.34.4 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.45.4 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;router ospf 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 4.4.4.4 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.34.4 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.45.4 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: orange;"&gt;&lt;span style="font-size: x-small;"&gt;ip pim send-rp-announce Loopback1 scope 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;ip pim send-rp-discovery scope 1&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;R5#&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;interface FastEthernet0/0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip address 10.10.45.5 255.255.255.0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; ip pim sparse-dense-mode&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color: orange;"&gt;&lt;span style="font-size: x-small;"&gt;ip igmp join-group 225.0.0.1&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;!&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;router ospf 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size: x-small;"&gt; network 10.10.45.5 0.0.0.0 area 0&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Kita buat R1 sebagai source (melakukan ping ke 225.0.0.1)&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-IHOQQt0TChI/Tu7ruAfEyGI/AAAAAAAAANo/Yq_eTqTIuuM/s1600/msdp-before.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="358" src="http://2.bp.blogspot.com/-IHOQQt0TChI/Tu7ruAfEyGI/AAAAAAAAANo/Yq_eTqTIuuM/s640/msdp-before.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Ternyata tidak ada reply. Berarti R1 tidak menemukan member dari multicast group 225.0.0.1.&lt;br /&gt;
Lalu kita coba tambahkan konfigurasi berikut pada R2 dan R4:&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;R2(config)#ip msdp peer 4.4.4.4 connect-source loopback 1&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;R4(config)#ip msdp peer 2.2.2.2 connect-source loopback 1&lt;/span&gt;&lt;br /&gt;
&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;
Lakukan ping lagi dari R1 ke 225.0.0.1:&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-1nvbne1au50/Tu7r1RRSVjI/AAAAAAAAANw/42b-GrqFEBw/s1600/after.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="282" src="http://4.bp.blogspot.com/-1nvbne1au50/Tu7r1RRSVjI/AAAAAAAAANw/42b-GrqFEBw/s640/after.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=====FIN====&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-6083459573013984045?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/XlPLP-KtHS_jHPsRFrAi2m2GFkU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XlPLP-KtHS_jHPsRFrAi2m2GFkU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/XlPLP-KtHS_jHPsRFrAi2m2GFkU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/XlPLP-KtHS_jHPsRFrAi2m2GFkU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/hDLMm8mQbiE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/6083459573013984045/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=6083459573013984045" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6083459573013984045?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6083459573013984045?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/hDLMm8mQbiE/multicast-source-discovery-protocol.html" title="Multicast Source Discovery Protocol (MSDP)" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-KifQr0ZG6DA/Tu7t9g9nBeI/AAAAAAAAAN4/X_yfWPQiw0s/s72-c/msdp-n.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/multicast-source-discovery-protocol.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUHQX4yeyp7ImA9WhRXEEs.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-7838730242006435274</id><published>2011-12-17T01:15:00.001+07:00</published><updated>2011-12-17T01:30:30.093+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-17T01:30:30.093+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="zone-pair" /><category scheme="http://www.blogger.com/atom/ns#" term="policy-map" /><category scheme="http://www.blogger.com/atom/ns#" term="class-map" /><category scheme="http://www.blogger.com/atom/ns#" term="Zone-based firewall" /><category scheme="http://www.blogger.com/atom/ns#" term="ZFW" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><category scheme="http://www.blogger.com/atom/ns#" term="zone" /><title>Zone-Based Firewall</title><content type="html">Zone-based firewall merupakan fitur yang dapat ditemui pada IOS advsecurity. Zone bersifat user-defined dan dapat diassign pada setiap interface router. Intinya adalah, IOS akan mendrop traffic antara 2 zona yang berbeda. Meskipun demikian kita dapat mendefine beberapa policy untuk memperbolehkan case-case tertentu saja. 

Ada beberapa langkah untuk mengkonfigur ZFW:
&lt;br /&gt;
1.) Tentukan nama-nama zone
&lt;br /&gt;
2.) Buat Class-map 
&lt;br /&gt;
3.) Buat Policy-map dan tentukan action apa yang akan dilakukan untuk setiap class. &lt;br /&gt;
4.) Tentukan Zone Pair. Zone Pair merupakan kombinasi dari sebuah source dan destination sebuah traffic berdasarkan zone-nya. Kemudian Apply Policy-map kedalam zone pair
&lt;br /&gt;
5.) Daftarkan interface menjadi member sebuah zone. 

Berikut contoh aplikasinya : &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-BR1mMRwTEEM/TuuAyXTAWxI/AAAAAAAAANM/p8FLMWFk6Hs/s1600/topologi.png" imageanchor="1" style="clear: left; float: center; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="86" src="http://3.bp.blogspot.com/-BR1mMRwTEEM/TuuAyXTAWxI/AAAAAAAAANM/p8FLMWFk6Hs/s400/topologi.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
Konfigurasikan ip address dan ip route untuk setiap router sehingga menjadi seperti digambar. Untuk lab ini saya asumsikan R1 sudah dapat melakukan telnet, ssh, ping dan browse web(telnet port 80) ke R2 (10.10.2.2 dan 8.8.8.8) 

&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-iYEv2hep8wc/TuuF4PPIoSI/AAAAAAAAANY/n_eXjoRqqP8/s1600/kondisi%2Bawal.png" imageanchor="1" style="clear: left; float: center; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="327" src="http://2.bp.blogspot.com/-iYEv2hep8wc/TuuF4PPIoSI/AAAAAAAAANY/n_eXjoRqqP8/s400/kondisi%2Bawal.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Kita akan memperbolehkan telnet dan ssh traffic dan mengontrol (policing) traffic web dari local zone ke external zone. 
&lt;br /&gt;
Semua traffic lain ke 10.10.2.2 akan di-&lt;b&gt;pass&lt;/b&gt;.&lt;br /&gt;
Semua traffic lain akan di-&lt;b&gt;drop&lt;/b&gt;

&lt;br /&gt;
&lt;br /&gt;
note: 
&lt;br /&gt;
drop - semua paket tidak akan dilewatkan (silently drop) 
&lt;br /&gt;
pass - semua paket akan dilewatkan tapi hanya 1 arah saja. pass tidak akan menambahkan record pada tabel connection tracking, sehingga semua trafik ke arah sebaliknya harus di-allow secara manual. 
&lt;br /&gt;
inspect - semua paket akan dilewatkan, dan firewall akan menambahkan record pada tabel connection tracking, sehingga trafik ke arah sebaliknya akan otomatis di-allow selama record tersebut masih ada.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Berikut langkah-langkah konfigurasinya : 

&lt;br /&gt;
1.) Tentukan Zone
&lt;br /&gt;
#zone security local
&lt;br /&gt;
#zone security external

&lt;br /&gt;
2.) Class-map (buat class map dengan &lt;b&gt;type inspect&lt;/b&gt;)
&lt;br /&gt;
#class-map type inspect match-any remote-access
&lt;br /&gt;
&amp;nbsp;match protocol ssh
&amp;nbsp; &lt;br /&gt;
&amp;nbsp;match protocol telnet
&lt;br /&gt;
#class-map type inspect match-all web
&amp;nbsp; &lt;br /&gt;
&amp;nbsp; match protocol http
&lt;br /&gt;
#class-map type inspect match-all toR2&lt;br /&gt;
&amp;nbsp; match access-group name myACL
&lt;br /&gt;
!
&lt;br /&gt;
#ip access-list extended myACL&lt;br /&gt;
&amp;nbsp; &amp;nbsp;permit ip any host 10.10.2.2

&lt;br /&gt;
&lt;br /&gt;
3.) Policy-map (buat dengan &lt;b&gt;type inspect&lt;/b&gt;)
&lt;br /&gt;
#policy-map type inspect myPOLICY&lt;br /&gt;
&amp;nbsp; &amp;nbsp;class type inspect remote-access&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; inspect&lt;br /&gt;
&amp;nbsp; &amp;nbsp;class type inspect web&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; inspect&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; police rate 50000 burst 8000&lt;br /&gt;
&amp;nbsp; &amp;nbsp;class type inspect toR2&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; pass&lt;br /&gt;
&amp;nbsp; &amp;nbsp;class class-default&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; drop &amp;nbsp; &lt;br /&gt;
!

&lt;br /&gt;
&lt;br /&gt;
4.) Buat zone-pair dan apply policy-map&lt;br /&gt;
#zone-pair security outside source local destination external&lt;br /&gt;
&amp;nbsp; &amp;nbsp;service-policy type inspect myPOLICY

&lt;br /&gt;
&lt;br /&gt;
5.) Daftarkan interface ke dalam sebuah zone&lt;br /&gt;
#interface FastEthernet1/0&lt;br /&gt;
&amp;nbsp; &amp;nbsp;zone-member security local&lt;br /&gt;
!&lt;br /&gt;
#interface FastEthernet1/1&lt;br /&gt;
&amp;nbsp; &amp;nbsp;zone-member security external&lt;br /&gt;
!

&lt;br /&gt;
&lt;br /&gt;
verifikasi: 
sh policy-map type inspect zone-pair &amp;lt;zone-pair-name&amp;gt;

&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Coba lakukan ssh, telnet, dan ping lagi ke R2. Ping tidak akan mendapatkan reply, karena keduanya akan meng-hit policy drop ataupun pass, sedangkan ping sendiri membutuhkan policy untuk 2 arah. Kita dapat mengakalinya dengan menggantinya menjadi inspect ataupun menambahkan policy pada zone-pair arah sebaliknya.&lt;br /&gt;
&lt;br /&gt;
&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;FW#sh policy-map type inspect zone-pair outside&lt;br /&gt;&lt;br /&gt;policy exists on zp outside&lt;br /&gt; Zone-pair: outside&lt;br /&gt;&lt;br /&gt;  Service-policy inspect : myPOLICY&lt;br /&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;Class-map: remote-access (match-any)&lt;br /&gt;      Match: protocol ssh&lt;br /&gt;        0 packets,&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt; 0 bytes&lt;br /&gt;        30 second rate 0 bps&lt;br /&gt;      &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;Match: protocol telnet&lt;br /&gt;        1 packets&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;, 24 bytes&lt;br /&gt;        30 second rate 0 bps&lt;br /&gt;&lt;br /&gt;   Inspect&lt;br /&gt;        Packet inspection statistics [process switch:fast switch]&lt;br /&gt;        tcp packets: [0:38]&lt;br /&gt;&lt;br /&gt;        Session creations since subsystem startup or last reset 1&lt;br /&gt;        Current session counts (estab/half-open/terminating) [0:0:0]&lt;br /&gt;        Maxever session counts (estab/half-open/terminating) [1:1:1]&lt;br /&gt;        Last session created 01:05:47&lt;br /&gt;        Last statistic reset never&lt;br /&gt;        Last session creation rate 0&lt;br /&gt;        Maxever session creation rate 1&lt;br /&gt;        Last half-open session total 0&lt;br /&gt;        TCP reassembly statistics&lt;br /&gt;        received 0 packets out-of-order; dropped 0&lt;br /&gt;        peak memory usage 0 KB; current usage: 0 KB&lt;br /&gt;        peak queue length 0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;Class-map: web (match-all)&lt;br /&gt;      Match: protocol http&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;br /&gt;   &lt;b&gt;Inspect&lt;/b&gt;&lt;br /&gt;        Packet inspection statistics [process switch:fast switch]&lt;br /&gt;        tcp packets: [0:12]&lt;br /&gt;&lt;br /&gt;        Session creations since subsystem startup or last reset 1&lt;br /&gt;        Current session counts (estab/half-open/terminating) [0:0:0]&lt;br /&gt;        Maxever session counts (estab/half-open/terminating) [1:1:1]&lt;br /&gt;        Last session created 00:59:47&lt;br /&gt;        Last statistic reset never&lt;br /&gt;        Last session creation rate 0&lt;br /&gt;        Maxever session creation rate 1&lt;br /&gt;        Last half-open session total 0&lt;br /&gt;        TCP reassembly statistics&lt;br /&gt;        received 0 packets out-of-order; dropped 0&lt;br /&gt;        peak memory usage 0 KB; current usage: 0 KB&lt;br /&gt;        peak queue length 0&lt;br /&gt;&lt;br /&gt;       Police&lt;br /&gt;        rate 50000 bps,8000 limit&lt;br /&gt;        &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;conformed 12 packets, 836 bytes; actions: transmit&lt;br /&gt;        exceeded 0 packets, 0 bytes; actions: drop&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;        conformed 0 bps, exceed 0 bps&lt;br /&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;Class-map: toR2 (match-all)&lt;br /&gt;      Match: access-group name myACL&lt;br /&gt;Pass&lt;br /&gt;        5 packets, 400 bytes&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;br /&gt;&lt;br /&gt;    &lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;Class-map: class-default (match-any)&lt;br /&gt;      Match: any&lt;br /&gt;Drop&lt;br /&gt;        10 packets, 800 bytes&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;blockquote&gt;
&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-7838730242006435274?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0S4HYD27x5N0HDxQXaQWb2TI-Bw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0S4HYD27x5N0HDxQXaQWb2TI-Bw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0S4HYD27x5N0HDxQXaQWb2TI-Bw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0S4HYD27x5N0HDxQXaQWb2TI-Bw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/ZzW4WZBkr4I" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/7838730242006435274/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=7838730242006435274" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/7838730242006435274?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/7838730242006435274?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/ZzW4WZBkr4I/zone-based-firewall.html" title="Zone-Based Firewall" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-BR1mMRwTEEM/TuuAyXTAWxI/AAAAAAAAANM/p8FLMWFk6Hs/s72-c/topologi.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/zone-based-firewall.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8CRngzeip7ImA9WhRQGUs.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-8694034433888801611</id><published>2011-12-15T23:48:00.001+07:00</published><updated>2011-12-15T23:51:07.682+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T23:51:07.682+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Ebiet G Ade" /><category scheme="http://www.blogger.com/atom/ns#" term="Lagu" /><title>Nyanyian Rindu</title><content type="html">&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://2.gvt0.com/vi/mg10UTLoTlI/0.jpg" height="480" width="640"&gt;&lt;param name="movie" value="http://www.youtube.com/v/mg10UTLoTlI&amp;fs=1&amp;source=uds" /&gt;



&lt;param name="bgcolor" value="#FFFFFF" /&gt;



&lt;embed width="640" height="480"  src="http://www.youtube.com/v/mg10UTLoTlI&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-8694034433888801611?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/DozoLLsnfA2HxwJchZAo-qu0KH8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DozoLLsnfA2HxwJchZAo-qu0KH8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/DozoLLsnfA2HxwJchZAo-qu0KH8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/DozoLLsnfA2HxwJchZAo-qu0KH8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/-SyeREQSlZU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/8694034433888801611/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=8694034433888801611" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/8694034433888801611?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/8694034433888801611?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/-SyeREQSlZU/blog-post.html" title="Nyanyian Rindu" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/blog-post.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08NQnw6cCp7ImA9WhRQGUs.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-1458459930880828597</id><published>2011-12-15T17:47:00.001+07:00</published><updated>2011-12-15T23:18:13.218+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T23:18:13.218+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Regex" /><title>Regular Expression</title><content type="html">Regex is an expression that specifies a set of strings.&lt;br /&gt;
Regex banyak sekali digunakan, baik dilingkungan UNIX, scripting, maupun perangkat-perangkat jaringan seperti Cisco.&lt;br /&gt;
Berikut metacharacter yang umum digunakan pada regex.&lt;br /&gt;
&lt;br /&gt;
^ = Awal dari sebuah kata&lt;br /&gt;
$ = Akhir dari sebuah kata&lt;br /&gt;
| &amp;nbsp;= Logical operator (or/atau)&lt;br /&gt;
_ = Delimiter (pemisah: blank, spasi, comma)&lt;br /&gt;
. &amp;nbsp;= karakter apa saja. (any character)&lt;br /&gt;
+ = 1 atau lebih karakter yang ada didepannya&lt;br /&gt;
* = 0 atau lebih karakter yang ada di depannya&lt;br /&gt;
? = 0 atau 1 karakter yang ada didepannya .&lt;br /&gt;
&lt;br /&gt;
( ) = Menandakan sebuah kesatuan&lt;br /&gt;
[ ] = Pilihan karakter&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Misal&lt;br /&gt;
1.) aku suka mangga&lt;br /&gt;
2.) balonku ada 5&lt;br /&gt;
3.) 5 bulan lagi aku CCIE&lt;br /&gt;
4.) 55555&lt;br /&gt;
5.) dia menertawakan aku&lt;br /&gt;
6.) aku suka minggat&lt;br /&gt;
7.) aku suka manggis&lt;br /&gt;
&lt;br /&gt;
^aku &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;gt; 1 &lt;br /&gt;
aku &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;gt; 1 3 5&lt;br /&gt;
aku$ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;gt; 5 &lt;br /&gt;
&lt;br /&gt;
m[ai]ngga &amp;nbsp;-&amp;gt; 1 6&lt;br /&gt;
mangg.* &amp;nbsp; &amp;nbsp;-&amp;gt; 1 7&lt;br /&gt;
^5$ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt; --&lt;br /&gt;
5+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt; 2 3 4&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-1458459930880828597?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/9CbkMMj_wvRE1oLc7TAqhc8MtyQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9CbkMMj_wvRE1oLc7TAqhc8MtyQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/9CbkMMj_wvRE1oLc7TAqhc8MtyQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9CbkMMj_wvRE1oLc7TAqhc8MtyQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/kbfzElyCt60" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/1458459930880828597/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=1458459930880828597" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/1458459930880828597?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/1458459930880828597?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/kbfzElyCt60/regular-expression.html" title="Regular Expression" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/regular-expression.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQCSXs5eCp7ImA9WhRQGUk.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-5468388246549833409</id><published>2011-12-15T17:15:00.000+07:00</published><updated>2011-12-15T17:19:28.520+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T17:19:28.520+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Redundancy" /><category scheme="http://www.blogger.com/atom/ns#" term="Dynamic NAT" /><category scheme="http://www.blogger.com/atom/ns#" term="Stateful NAT" /><category scheme="http://www.blogger.com/atom/ns#" term="SNAT" /><category scheme="http://www.blogger.com/atom/ns#" term="HSRP" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><title>SNAT - HSRP (Redundancy)</title><content type="html">Menyambung postingan yang lalu &lt;a href="http://ianwijaya.blogspot.com/2011/12/nat-redudancy-hsrp.html"&gt;http://ianwijaya.blogspot.com/2011/12/nat-redudancy-hsrp.html&lt;/a&gt;, saya akan membahas mengenai dynamic NAT failover dengan HSRP.&lt;br /&gt;
Fitur yang akan digunakan disini adalah Stateful NAT (SNAT). Dengan menggunakan SNAT, translasi table pada active router akan disinkronkan dengan standby router pada HSRP, sehingga pada saat terjadi perpindahan active router, proses translasi address tidak terganggu (tersendat-sendat).&lt;br /&gt;
Dengan topologi yang masih sama dan konfigurasi HSRP yang masih sama:&amp;nbsp;
&lt;br /&gt;
Hapus konfigurasi static nat pada percobaan sebelumnya. Kemudian tambahkan dynamic nat tanpa menggunakan SNAT pada router R2 dan R3.&lt;br /&gt;
#ip nat pool myPOOL 10.10.10.100 10.10.10.110 prefix-length 24&lt;br /&gt;
#ip nat inside source list myACL pool myPOOL &lt;br /&gt;
#ip access-list standard myACL&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp;permit 172.16.1.0 0.0.0.255
&lt;br /&gt;
&lt;br /&gt;
Sembari melakukan telnet ke R4 dari R1, shutdown interface fa0/1 R2. Rasakan sendatannya !! =))&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-S2qpHUuFhl4/TunHbBG1YNI/AAAAAAAAAM4/9cJS07J04vI/s1600/before2-2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="356" src="http://3.bp.blogspot.com/-S2qpHUuFhl4/TunHbBG1YNI/AAAAAAAAAM4/9cJS07J04vI/s640/before2-2.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Kemudian kita tambahkan konfigurasi SNAT seperti contoh dibawah.:&lt;br /&gt;
&lt;br /&gt;
R2#&lt;br /&gt;
!&lt;br /&gt;
&lt;b&gt;ip nat Stateful id 1&lt;br /&gt;&amp;nbsp; &amp;nbsp; redundancy myHSRP&lt;br /&gt;&amp;nbsp;  &amp;nbsp; mapping-id 10&lt;/b&gt;&lt;br /&gt;
&amp;nbsp;  &amp;nbsp; protocol   udp&lt;br /&gt;
ip nat pool myPOOL 10.10.10.100 10.10.10.110 prefix-length 24&lt;br /&gt;
ip nat inside source list myACL pool myPOOL &lt;b&gt;mapping-id 10&lt;/b&gt;&lt;br /&gt;
ip access-list standard myACL&lt;br /&gt;
&amp;nbsp; &amp;nbsp; permit 172.16.1.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
&lt;br /&gt;
R3#&lt;br /&gt;
!&lt;br /&gt;
&lt;b&gt;ip nat Stateful id 2&lt;br /&gt;&amp;nbsp; &amp;nbsp; redundancy myHSRP&lt;br /&gt;&amp;nbsp;  &amp;nbsp; mapping-id 10&lt;/b&gt;&lt;br /&gt;
&amp;nbsp;  &amp;nbsp; protocol   udp&lt;br /&gt;
ip nat pool myPOOL 10.10.10.100 10.10.10.110 prefix-length 24&lt;br /&gt;
ip nat inside source list myACL pool myPOOL &lt;b&gt;mapping-id 10&lt;/b&gt;&lt;br /&gt;
ip access-list standard myACL&lt;br /&gt;
&amp;nbsp; &amp;nbsp; permit 172.16.1.0 0.0.0.255&lt;br /&gt;
!&lt;br /&gt;
&lt;br /&gt;
Stateful ID haruslah berbeda pada setiap router.&lt;br /&gt;
Setiap konfigurasi SNAT harus di-bind dengan sebuah mapping-id yang kemudian ditambahkan pada konfigurasi NAT.&lt;br /&gt;
verifikasi: &lt;br /&gt;
#sh ip snat distributed &lt;br /&gt;
#sh ip nat translasions&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-RzaSDM15OYo/TunHcxHohSI/AAAAAAAAANA/OgYZ1d5kU6Y/s1600/after2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="359" src="http://4.bp.blogspot.com/-RzaSDM15OYo/TunHcxHohSI/AAAAAAAAANA/OgYZ1d5kU6Y/s640/after2.png" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
====FIN ======&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-5468388246549833409?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/7x0OoEaCt7Zu2KMkqsUlylR3itQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7x0OoEaCt7Zu2KMkqsUlylR3itQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/7x0OoEaCt7Zu2KMkqsUlylR3itQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/7x0OoEaCt7Zu2KMkqsUlylR3itQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/6_BR2Hw-f9k" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/5468388246549833409/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=5468388246549833409" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/5468388246549833409?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/5468388246549833409?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/6_BR2Hw-f9k/snat-hsrp-redundancy.html" title="SNAT - HSRP (Redundancy)" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-S2qpHUuFhl4/TunHbBG1YNI/AAAAAAAAAM4/9cJS07J04vI/s72-c/before2-2.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/snat-hsrp-redundancy.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYAQX85eSp7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-8821069900544029087</id><published>2011-12-14T17:16:00.007+07:00</published><updated>2011-12-15T15:02:20.121+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:02:20.121+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Authentication" /><category scheme="http://www.blogger.com/atom/ns#" term="Directory Listing" /><category scheme="http://www.blogger.com/atom/ns#" term="Virtual Host" /><category scheme="http://www.blogger.com/atom/ns#" term="RedHat" /><category scheme="http://www.blogger.com/atom/ns#" term="Apache" /><title>Apache Virtual Host</title><content type="html">Bila kita hanya memiliki 1 server namun ingin meng-hosting 2 web server atau lebih, kita dapat memanfaatkan fitur virtual host. &lt;br /&gt;&lt;br /&gt;Edit file /etc/httpd/conf/httpd.conf&lt;br /&gt;#&lt;br /&gt;NameVirtualHost {ip}:{port}&lt;br /&gt;#ip bisa diganti dengan * untuk listen di semua ip&lt;br /&gt;#lalu tambahkan stanza virtualhost untuk setiap web server &lt;br /&gt;&amp;lt;VirtualHost {ip}:{port}&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ServerName www.webserver1.com &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ServerAlias webserver1.com &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;DocumentRoot /path/to/web/dir&lt;br /&gt;&amp;lt;/VirtualHost&amp;gt;&lt;br /&gt;&lt;br /&gt;untuk memperbolehkan directory listing, kita dapat menambahkan &lt;br /&gt;Options +indexes&lt;br /&gt;&lt;br /&gt;untuk authentikasi kita dapat menambahkan stanza Directory didalam VirtualHost&lt;br /&gt;&amp;lt;Directory /path/to/allowed-dir&amp;gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AuthName "Title" &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AuthType basic &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;AuthUserFile /path/to/passfile&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Require valid-user&lt;br /&gt;&amp;lt;/Directory&amp;gt;&lt;br /&gt;&lt;br /&gt;save, exit, restart httpd&lt;br /&gt;&lt;br /&gt;user dan password dapat dibuat dengan command htpasswd&lt;br /&gt;htpasswd -cm /path/to/passfile user1&lt;br /&gt;htpasswd -m /path/to/passfile user2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;====FIN====&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-8821069900544029087?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/zV6fdKI-vfthbhzo7pK0bCJ9638/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zV6fdKI-vfthbhzo7pK0bCJ9638/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/zV6fdKI-vfthbhzo7pK0bCJ9638/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/zV6fdKI-vfthbhzo7pK0bCJ9638/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/a6k6NqQZDWA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/8821069900544029087/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=8821069900544029087" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/8821069900544029087?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/8821069900544029087?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/a6k6NqQZDWA/apache-virtual-host.html" title="Apache Virtual Host" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/apache-virtual-host.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D08MQn49eip7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-2629938274637813037</id><published>2011-12-14T16:58:00.014+07:00</published><updated>2011-12-15T14:58:03.062+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T14:58:03.062+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="NAT" /><category scheme="http://www.blogger.com/atom/ns#" term="Redudancy" /><category scheme="http://www.blogger.com/atom/ns#" term="HSRP" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><title>NAT - Redudancy  (HSRP)</title><content type="html">&lt;a href="http://2.bp.blogspot.com/-zlgEXaIfm9A/Tuh0m2NcM1I/AAAAAAAAALw/1VCr7GdXvdk/s1600/lab-nat.png"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 389px; height: 400px;" src="http://2.bp.blogspot.com/-zlgEXaIfm9A/Tuh0m2NcM1I/AAAAAAAAALw/1VCr7GdXvdk/s400/lab-nat.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5685922740290990930" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Kita dapat menggunakan HSRP untuk mendapatkan fitur high availabilty pada router gateway. namun apabila router2 gateway tersebut merangkap sebagai translator router (me-nat address local) maka hal tersebut akan menjadi masalah. &lt;br /&gt;&lt;br /&gt;Berikut hasil screen shot dari percobaan yang saya lakukan &lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-UKWeyK-e2so/Tuh0Q_sy5mI/AAAAAAAAALk/VRTt81ikgCI/s1600/before.png"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 225px;" src="http://4.bp.blogspot.com/-UKWeyK-e2so/Tuh0Q_sy5mI/AAAAAAAAALk/VRTt81ikgCI/s400/before.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5685922364881299042" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ketika interface fa 0/1 R2 saya shutdown, translasi memang ikut berpindah ke router R3, namun muncul pesan "DUPLICATE ADDRESS BLA BLA BLA". Hal ini akan menganggu paket-paket tcp yang di lewatkan. Alhasil sesi telnet ke R4(8.8.8.8) menjadi tersendat-sendat. &lt;br /&gt;Duplicate address ini dikarenakan interface NVI menggunakan address yang sama, yaitu 10.10.10.1 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hal ini dapat di atasi dengan menggunakan fitur NAT-redudancy. berikut konfigurasi pada router R2 dan R3 &lt;br /&gt;&lt;br /&gt;R2(config-if)#do sh run | s nat|interface&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.10.10.2 255.255.255.0&lt;br /&gt; ip nat outside&lt;br /&gt; ip virtual-reassembly&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; ip address 172.16.1.2 255.255.255.0&lt;br /&gt; ip nat inside&lt;br /&gt; ip virtual-reassembly&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt; standby 1 ip 172.16.1.100&lt;br /&gt; standby 1 priority 200&lt;br /&gt; standby 1 preempt&lt;br /&gt; &lt;b&gt;standby 1 name myHSRP&lt;/b&gt;&lt;br /&gt;ip nat inside source static 172.16.1.1 10.10.10.1 &lt;b&gt;redundancy myHSRP&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R3(config-if)#do sh run | s nat|interface&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 10.10.10.3 255.255.255.0&lt;br /&gt; ip nat outside&lt;br /&gt; ip virtual-reassembly&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; ip address 172.16.1.3 255.255.255.0&lt;br /&gt; ip nat inside&lt;br /&gt; ip virtual-reassembly&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt; standby 1 ip 172.16.1.100&lt;br /&gt; &lt;b&gt;standby 1 name myHSRP&lt;/b&gt;&lt;br /&gt;ip nat inside source static 172.16.1.1 10.10.10.1 &lt;b&gt;redundancy myHSRP&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-MCtIB-9sqSQ/Tuh2s9YxIzI/AAAAAAAAAMI/eSZYQoC2h3s/s1600/after.png"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 225px;" src="http://3.bp.blogspot.com/-MCtIB-9sqSQ/Tuh2s9YxIzI/AAAAAAAAAMI/eSZYQoC2h3s/s400/after.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5685925044320019250" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Konfigurasi ini hanya dapat digunakan untuk static nat saja. Untuk dynamic nat kita dapat menggunakan fitur stateful nat yang akan saya bahas pada tulisan saya selanjutnya. :D&lt;br /&gt;&lt;br /&gt;===== FIN =====&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-2629938274637813037?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZrROLvuz8KQDztd3WA_reMcLJag/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZrROLvuz8KQDztd3WA_reMcLJag/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZrROLvuz8KQDztd3WA_reMcLJag/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZrROLvuz8KQDztd3WA_reMcLJag/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/Q6VCunl3Qw4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/2629938274637813037/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=2629938274637813037" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2629938274637813037?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2629938274637813037?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/Q6VCunl3Qw4/nat-redudancy-hsrp.html" title="NAT - Redudancy  (HSRP)" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-zlgEXaIfm9A/Tuh0m2NcM1I/AAAAAAAAALw/1VCr7GdXvdk/s72-c/lab-nat.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/nat-redudancy-hsrp.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcCSXsyfip7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-2382220080676888221</id><published>2011-12-12T22:28:00.005+07:00</published><updated>2011-12-15T15:01:08.596+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:01:08.596+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="NAT" /><category scheme="http://www.blogger.com/atom/ns#" term="Forwarding" /><category scheme="http://www.blogger.com/atom/ns#" term="linux" /><category scheme="http://www.blogger.com/atom/ns#" term="Masquerading" /><category scheme="http://www.blogger.com/atom/ns#" term="RedHat" /><title>NAT Linux</title><content type="html">Sebelum melakukan NAT kita harus merubah default behavior dari linux machine untuk dapat melewatkan traffic yang tujuannya bukan mesin itu sendiri (transit node). &lt;br /&gt;&lt;br /&gt;vi /etc/sysctl.conf &lt;br /&gt;net_ipv4_forwarding=1 &lt;br /&gt;save, lalu reload sysctl dengan commmand &lt;br /&gt;sysctl -p &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pada linux, khusus nya Red Hat, nat dapat dikonfigurasi dengan menambahkan rules pada table nat. &lt;br /&gt;Untuk memanipulasi table nat kita membutuhkan tambahan parameter "-t nat". &lt;br /&gt;&lt;br /&gt;Untuk source nat kita bisa menggunakan table POSTROUTING maupung PREROUTING, sedangkan untuk destination nat kita hanya bisa menggunakan PREROUTING saja. &lt;br /&gt;PREROUTING artinya translasi address akan dilakukan sebelum proses routing dilakukan, sedangkan POST brarti setelah. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Untuk source nat kita menggunakan "-j SNAT", sedangkan destination nat menggunakan "-j DNAT". &lt;br /&gt;SNAT sebenarnya serupa dengan "-j MASQUERADE", hanya saja dengan SNAT kita bisa mengganti source address nya, tidak harus sama dengan interface. &lt;br /&gt;&lt;br /&gt;Berikut contohnya: &lt;br /&gt;SNAT, aplikasi umumnya untuk sharing internet(share ip public) &lt;br /&gt;iptables -t nat -A POSTROUTING -o &amp;lt;out interface&amp;gt; -j SNAT --to &amp;lt;ip_public&amp;gt;&lt;br /&gt;&lt;br /&gt;DNAT, aplikasi umumnya untuk port forwarding(virtual IP) &lt;br /&gt;iptables -t nat -A PREROUTING -p tcp -d &amp;lt;ip_public&amp;gt; --dport &amp;lt;port_public&amp;gt; -j DNAT --to &amp;lt;ip_private:port_private&amp;gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-2382220080676888221?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/I3rm1SLpm51VGo_3UOBb4NB5Vg4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/I3rm1SLpm51VGo_3UOBb4NB5Vg4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/I3rm1SLpm51VGo_3UOBb4NB5Vg4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/I3rm1SLpm51VGo_3UOBb4NB5Vg4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/tVwrp1F-PK8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/2382220080676888221/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=2382220080676888221" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2382220080676888221?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2382220080676888221?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/tVwrp1F-PK8/nat-linux.html" title="NAT Linux" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/nat-linux.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEYMQX05eSp7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-5270600207661949521</id><published>2011-12-10T08:04:00.005+07:00</published><updated>2011-12-15T15:03:00.321+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:03:00.321+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DHCP" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><title>Static DHCP binding</title><content type="html">Jika kita ingin meng-assign IP yang selalu sama pada suatu node melalui DHCP, kita dapat membinding nya secara staticc dengan menggunakan perintah "host" berikut contoh nya &lt;br /&gt;&lt;br /&gt;#ip dhcp pool my-pool &lt;br /&gt;dhcp#network 192.168.1.0 255.255.255.0 &lt;br /&gt;dhcp#default-router 192.168.1.1 &lt;br /&gt;dhcp#dns-server 8.8.8.8 &lt;br /&gt;&lt;br /&gt;#ip dhcp pool static-pool &lt;br /&gt;dhcp#host 192.168.1.8 255.255.255.0&lt;br /&gt;dhcp#hardware address xxxx.yyyy.zzzz &lt;br /&gt;dhcp#default-router 192.168.1.1 &lt;br /&gt;&lt;br /&gt;verifikasi: &lt;br /&gt;#sh ip dhcp binding&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-5270600207661949521?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/VJEYsPa6CZSdHPwUlSNnS5Xe3W8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/VJEYsPa6CZSdHPwUlSNnS5Xe3W8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/VJEYsPa6CZSdHPwUlSNnS5Xe3W8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/VJEYsPa6CZSdHPwUlSNnS5Xe3W8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/ZTP04PTehtI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/5270600207661949521/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=5270600207661949521" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/5270600207661949521?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/5270600207661949521?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/ZTP04PTehtI/static-dhcp-binding.html" title="Static DHCP binding" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/static-dhcp-binding.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUHRnY5fSp7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-3325350402354079032</id><published>2011-12-09T12:28:00.005+07:00</published><updated>2011-12-15T15:03:57.825+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:03:57.825+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="AutoRP Listener" /><category scheme="http://www.blogger.com/atom/ns#" term="Multicast" /><category scheme="http://www.blogger.com/atom/ns#" term="Sparse Mode" /><category scheme="http://www.blogger.com/atom/ns#" term="AutoRP" /><category scheme="http://www.blogger.com/atom/ns#" term="Dense Mode" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><title>AutoRP Listener</title><content type="html">Ketika kita menggunakan auto rp untuk mendistribusikan rp address, kita harus menggunakan sparse-dense mode pada interface yang tergabung dengan multicast. &lt;br /&gt;Source multicast akan menggunakan dense mode sampai source tersebut mempelajari dimana letak root tree(rp-address). Ketika source telah mempelajari rp, source akan beralih menggunakan sparse mode. &lt;br /&gt;&lt;br /&gt;Waktu yang dibutuhkan untuk menjadi sparse mode relatif lama. Ketika suatu source menggunakan dense mode dalam waktu yang relatif lama maka hal ini akan menjadi tidak efisien. &lt;br /&gt;Untuk menghindari hal ini, kita dapat menggunakan autoRP listener. Dengan autorp listener kita diperbolehkan menggunakan autorp dalam mode sparse mode, dengan pengecualian traffic untuk group 224.0.0.39 (RP) dan 224.0.0.40 (Mapping agent) (yang akan di distribusikan menggunakan dense mode) &lt;br /&gt; &lt;br /&gt;konfigurasi auto-RP dengan sparse mode &lt;br /&gt;&lt;br /&gt;R1-------R2---------R3 &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;konfigurasikan semua interface sebagai sparse mode&lt;br /&gt;if#ip pim sparse-mode &lt;br /&gt;&lt;br /&gt;R2 sebagai RP &lt;br /&gt;R2#&lt;br /&gt;ip pim send-rp announce &amp;lt;src interface&amp;gt; scope &amp;lt;value&amp;gt;&lt;br /&gt;ip pim send-rp discovery scope &amp;lt;value&amp;gt;&lt;br /&gt;&lt;br /&gt;R1&amp;3#ip pim autorp listener&lt;br /&gt;&lt;br /&gt;verifikasi: &lt;br /&gt;sh ip pim rp mapping&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-3325350402354079032?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/uDCdBXiObxK1RKjH7H44Xi9U4i8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uDCdBXiObxK1RKjH7H44Xi9U4i8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/uDCdBXiObxK1RKjH7H44Xi9U4i8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uDCdBXiObxK1RKjH7H44Xi9U4i8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/735q_k3HADE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/3325350402354079032/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=3325350402354079032" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/3325350402354079032?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/3325350402354079032?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/735q_k3HADE/autorp-listener.html" title="AutoRP Listener" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/autorp-listener.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMDRX0zfCp7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-8733454069097577973</id><published>2011-12-08T07:37:00.014+07:00</published><updated>2011-12-15T15:07:54.384+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:07:54.384+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="OSPF" /><category scheme="http://www.blogger.com/atom/ns#" term="bgp" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><category scheme="http://www.blogger.com/atom/ns#" term="Shamlink" /><title>MPLS VPN OSPF-Shamlink</title><content type="html">Sebelum mengkonfigur shamlink, mungkin anda merasakan ada yang aneh dengan route OSPF, mengapa prefix ospf dari PE dianggap sebagai O IA, tidak sebagai O External, padahal route tersebut di-redistribute dari BGP. &lt;br /&gt;Hal ini memang special case untuk MPLS. Berikut saya kutip penjelasan nya dari sebuah web.&lt;br /&gt;http://sites.google.com/site/amitsciscozone/home/important-tips/mpls-wiki/ospf-as-pe-ce-routing-protocol-in-mpls-vpn (paragraph 1, 4, dan 5) &lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;OSPF Domain: Two sites are considered to be in the same OSPF Domain if the routes from one site to other are considered intra-network routes. Both sites will run OSPF as their intra-site routing protocol.This can be done by presenting such routes as inter-area routes in Type 3 LSAs.&lt;br /&gt;&lt;b&gt;If normal BGP/OSPF interaction procedures are implemented, the routes from one site to be delivered to another site as External routes in Type 5 LSAs. This makes them impossible to be distinguished from "real" external routes in the VPN. Hence, a modified version of BGP/OSPF interaction procedure needs to be implemented so that routes delivered from one site to another are atleast interarea routes.&lt;/b&gt;&lt;br /&gt;If a VRF contains both an OSPF-distributed route and a VPNv4 route for the same IP prefix, then the OSPF-distributed route is preferred because of its lower AD. Hence, forwarding is done according to OSPF route. The only exception is when the sham-link is present.&lt;br /&gt;&lt;/blockquote&gt; &lt;br /&gt;&lt;br /&gt;Ketika kita menggunakan ospf sebagai IGP anatara router PE dan CE untuk menghubungkan 2 network DAN kemudian kita menambahkan intraarea route baru untuk mencapai network yang sama, ospf akan lebih memilih jalur melewati intra area route. Hal ini dikarenakan OSPF akan mem-flag route yang melewati MPLS sebagai interarea route. &lt;br /&gt;Kendala ini dapat diatasi dengan menambahkan konfigurasi shamlink pada PE router. Dengan shamlink, CE akan menggunakan path melalui MPLS sebagai primary path.&lt;br /&gt;&lt;br /&gt;Ada 4 langkah yang harus dilakukan untuk membentuk shamlink&lt;br /&gt;misalkan customer ada pada vrfA  maka: &lt;br /&gt;1.) Buat loopback interface di masing2 PE router, kemudian assign interface tersebut ke dalam vrfA (ip vrf forwarding) &lt;br /&gt;2.) Advertise loopback interface tersebut ke dalam BGP vrfA, (network command)&lt;br /&gt;3.) Assign ip loopback point 1 menjadi RID untuk protocol OSPF vrfA, buat shamlink pada masing2 &lt;br /&gt;PE router dengan comand &lt;br /&gt;#area &amp;lt;id:&amp;gt; sham-link &amp;lt;source RID&amp;gt; &amp;lt;destinations RID&amp;gt; &lt;br /&gt;&lt;br /&gt;Pada tahap ini route ospf ke vrfA akan di anggap sebagai intraarea route meskipun route tersebut didapat dari redistribusi BGP &lt;br /&gt;&lt;br /&gt;4.) Manipulasi cost pada interface CE router. Buat agar CE lebih memilih untuk melewati jalur MPLS&lt;br /&gt;if#ip ospf cost &amp;lt;value&amp;gt;&lt;br /&gt;&lt;br /&gt;Berikut contohnya: &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-UGWr6eC9t68/TuAY4gs0X_I/AAAAAAAAALA/l-6nv9isBgA/s1600/mpls-blog.png"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 238px;" src="http://1.bp.blogspot.com/-UGWr6eC9t68/TuAY4gs0X_I/AAAAAAAAALA/l-6nv9isBgA/s400/mpls-blog.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683570088871223282" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pada R7 dan R5, customer B membuat backup path baru, tambahkan konfigurasi OSPF seperti biasa pada router-router CE tersebut. &lt;br /&gt;Konfigurasi terkait:&lt;br /&gt;Nama VRF Bkiri (R1) dan Bkanan (R3)&lt;br /&gt;&lt;br /&gt;Konfigurasi dasar:&lt;br /&gt;R1#&lt;br /&gt;!&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;ip vrf Bkiri&lt;br /&gt; rd 65000:2&lt;br /&gt; route-target export 65000:2&lt;br /&gt; route-target import 65000:2&lt;br /&gt;!&lt;br /&gt;interface Loopback0&lt;br /&gt; ip address 10.10.10.1 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface Serial0/0&lt;br /&gt; description # link to P #&lt;br /&gt; ip address 192.168.10.1 255.255.255.252&lt;br /&gt; mpls ip&lt;br /&gt; clock rate 2000000&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; ip vrf forwarding Bkiri&lt;br /&gt; ip address 192.168.0.1 255.255.255.252&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;!&lt;br /&gt;router ospf 100 vrf Bkiri&lt;br /&gt; log-adjacency-changes &lt;br /&gt; redistribute bgp 65000 subnets&lt;br /&gt; network 192.168.0.0 0.0.255.255 area 0&lt;br /&gt;!&lt;br /&gt;router bgp 65000&lt;br /&gt; no synchronization&lt;br /&gt; bgp log-neighbor-changes&lt;br /&gt; neighbor 10.10.10.2 remote-as 65000&lt;br /&gt; neighbor 10.10.10.2 update-source Loopback0&lt;br /&gt; no auto-summary&lt;br /&gt; !&lt;br /&gt; address-family vpnv4&lt;br /&gt;  neighbor 10.10.10.2 activate&lt;br /&gt;  neighbor 10.10.10.2 send-community extended&lt;br /&gt; exit-address-family&lt;br /&gt; !&lt;br /&gt; address-family ipv4 vrf Bkiri&lt;br /&gt;  redistribute ospf 100 vrf Bkiri match internal external 1 external 2&lt;br /&gt;  no synchronization&lt;br /&gt; exit-address-family&lt;br /&gt; !&lt;br /&gt;&lt;br /&gt;R3#&lt;br /&gt;!&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;ip vrf Bkanan&lt;br /&gt; rd 65000:2&lt;br /&gt; route-target export 65000:2&lt;br /&gt; route-target import 65000:2&lt;br /&gt;!&lt;br /&gt;interface Loopback0&lt;br /&gt; ip address 10.10.10.2 255.255.255.255&lt;br /&gt;!&lt;br /&gt;interface Serial0/0&lt;br /&gt; description #link to P#&lt;br /&gt; ip address 192.168.20.2 255.255.255.252&lt;br /&gt; mpls ip&lt;br /&gt; clock rate 2000000&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/1&lt;br /&gt; ip vrf forwarding Bkanan&lt;br /&gt; ip address 192.168.0.5 255.255.255.0&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;!&lt;br /&gt;router ospf 100 vrf Bkanan&lt;br /&gt; log-adjacency-changes&lt;br /&gt; redistribute bgp 65000 subnets&lt;br /&gt; network 192.168.0.0 0.0.255.255 area 0&lt;br /&gt;!&lt;br /&gt;router bgp 65000&lt;br /&gt; no synchronization&lt;br /&gt; bgp log-neighbor-changes&lt;br /&gt; neighbor 10.10.10.1 remote-as 65000&lt;br /&gt; neighbor 10.10.10.1 update-source Loopback0&lt;br /&gt; no auto-summary&lt;br /&gt; !&lt;br /&gt; address-family vpnv4&lt;br /&gt;  neighbor 10.10.10.1 activate&lt;br /&gt;  neighbor 10.10.10.1 send-community extended&lt;br /&gt; exit-address-family&lt;br /&gt; !&lt;br /&gt; address-family ipv4 vrf Bkanan&lt;br /&gt;  redistribute ospf 100 vrf Bkanan match internal external 1 external 2&lt;br /&gt;  no synchronization&lt;br /&gt; exit-address-family&lt;br /&gt;!&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-jH9nNCBImIw/TuAbJJM728I/AAAAAAAAALM/m7uBwfQameI/s1600/route-before.png"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 166px;" src="http://2.bp.blogspot.com/-jH9nNCBImIw/TuAbJJM728I/AAAAAAAAALM/m7uBwfQameI/s400/route-before.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683572573644512194" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Kemudian tambahkan konfigurasi shamlink sesuai dengan step yang telah dijabarkan di atas &lt;br /&gt;R1#&lt;br /&gt;interface Loopback100&lt;br /&gt; ip vrf forwarding Bkiri&lt;br /&gt; ip address 100.100.100.4 255.255.255.255&lt;br /&gt;!&lt;br /&gt;router ospf 100 vrf Bkiri&lt;br /&gt;router-id 100.100.100.4&lt;br /&gt; area 0 sham-link 100.100.100.4 100.100.100.5&lt;br /&gt;!&lt;br /&gt;router bgp 65000&lt;br /&gt;address-family ipv4 vrf Bkiri&lt;br /&gt;network 100.100.100.4 mask 255.255.255.255&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;R3#&lt;br /&gt;interface Loopback5&lt;br /&gt; ip vrf forwarding Bkanan&lt;br /&gt; ip address 100.100.100.5 255.255.255.255&lt;br /&gt;!&lt;br /&gt;router ospf 100 vrf Bkanan&lt;br /&gt; router-id 100.100.100.5&lt;br /&gt; area 0 sham-link 100.100.100.5 100.100.100.4&lt;br /&gt;!&lt;br /&gt;router bgp 65000&lt;br /&gt; address-family ipv4 vrf Bkanan&lt;br /&gt;  network 100.100.100.5 mask 255.255.255.255&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-p1FC_3Q8rVE/TuAbJgKELLI/AAAAAAAAALY/Xk9n33y5YHM/s1600/route-after.png"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 166px;" src="http://1.bp.blogspot.com/-p1FC_3Q8rVE/TuAbJgKELLI/AAAAAAAAALY/Xk9n33y5YHM/s400/route-after.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683572579806489778" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-8733454069097577973?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/U0THpjy4aiZ2kiI8MMwd9T-FDvY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/U0THpjy4aiZ2kiI8MMwd9T-FDvY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/U0THpjy4aiZ2kiI8MMwd9T-FDvY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/U0THpjy4aiZ2kiI8MMwd9T-FDvY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/z3xCmMfUAWs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/8733454069097577973/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=8733454069097577973" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/8733454069097577973?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/8733454069097577973?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/z3xCmMfUAWs/mpls-vpn-ospf-shamlink.html" title="MPLS VPN OSPF-Shamlink" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-UGWr6eC9t68/TuAY4gs0X_I/AAAAAAAAALA/l-6nv9isBgA/s72-c/mpls-blog.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/mpls-vpn-ospf-shamlink.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMDQ3Yzeyp7ImA9WhRQEk8.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-3995492570759130005</id><published>2011-12-07T07:31:00.007+07:00</published><updated>2011-12-07T08:47:52.883+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-07T08:47:52.883+07:00</app:edited><title>BGP bestpath as-path multipath-relax</title><content type="html">Normal nya BGP akan me-load share 2 link atau lebih apabila kedua kondisi dibawah terpenuhi: &lt;br /&gt;1.) maximum-path &amp;gt; 1&lt;br /&gt;2.) terdapat 2 atau lebih link yang memiliki BGP attribute yang sama paling tidak sampai kriteria ke 8 (NWLLA OMNI, Next hop reachable, weight, Local pref, Locally injected, AS-path, Origin, MED, Neighbor type, dan IGP metric to next hop)&lt;br /&gt;&lt;br /&gt;Hal ini tidak akan menjadi masalah pada kasus 1 ISP multihome, namun apabila kasus multihome adalah dari 2 ISP yang berbeda maka akan terjadi perbedaan AS-path dan hanya akan ada 1 route ISP yang dimasukan ke dalam routing table. (karena syarat ke 2 tidak terpenuhi) &lt;br /&gt;&lt;br /&gt;untuk mengatasi masalah ini, kita dapat menambahkan konfigurasi : &lt;br /&gt;#bgp bestpath as-path multipath-relax &lt;br /&gt;&lt;br /&gt;Dengan menambahkan konfigurasi tersebut BGP akan menghiraukan perbedaan as number pada masing2 path asalkan length AS nya masih tetap sama. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;berikut contoh nya (perhatikan route entry untuk prefix 4.4.4.4) : &lt;br /&gt;1 ISP, Multihome&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-qR2i4C4mW74/Tt63sNx20GI/AAAAAAAAAJs/7hnrCfTJxdE/s1600/blog%2B1%2Bbgp.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 266px;" src="http://3.bp.blogspot.com/-qR2i4C4mW74/Tt63sNx20GI/AAAAAAAAAJs/7hnrCfTJxdE/s400/blog%2B1%2Bbgp.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683181750029045858" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-ybZJNk2kKlk/Tt63sTc8wtI/AAAAAAAAAJ4/sQxGBVIEruc/s1600/multihome1-1.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 267px;" src="http://2.bp.blogspot.com/-ybZJNk2kKlk/Tt63sTc8wtI/AAAAAAAAAJ4/sQxGBVIEruc/s400/multihome1-1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683181751551967954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Lalu saya ganti konfigurasinya agar R2 dan R3 menjadi berbeda AS (dual ISP) &lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-a0T9SduDP2Q/Tt66XEQJ5UI/AAAAAAAAAKE/rWCVIKIrlRc/s1600/multihome2-1.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 269px;" src="http://2.bp.blogspot.com/-a0T9SduDP2Q/Tt66XEQJ5UI/AAAAAAAAAKE/rWCVIKIrlRc/s400/multihome2-1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683184685229401410" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-6ToxdFaZHiE/Tt66XXGJ8GI/AAAAAAAAAKQ/MdMmisOhK9s/s1600/multihome2-2.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 264px;" src="http://3.bp.blogspot.com/-6ToxdFaZHiE/Tt66XXGJ8GI/AAAAAAAAAKQ/MdMmisOhK9s/s400/multihome2-2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683184690287734882" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;saya tambahkan konfigurasi multipath-relax &lt;br /&gt;R1#router bgp 100 &lt;br /&gt;R1(router)#bgp bestpath as-path multipath-relax &lt;br /&gt;R1(router)#maximum-path 2 &lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-Ppbbm7qKQTM/Tt66XunJ4UI/AAAAAAAAAKc/pYOYyMgACRE/s1600/multihome2-3.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 273px;" src="http://4.bp.blogspot.com/-Ppbbm7qKQTM/Tt66XunJ4UI/AAAAAAAAAKc/pYOYyMgACRE/s400/multihome2-3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5683184696600158530" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;command ini tidak terdapat pada intellisense/auto complete&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;===fin===&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-3995492570759130005?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/J8G7TTmRlgS5R3KD18mleVYjk6k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/J8G7TTmRlgS5R3KD18mleVYjk6k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/J8G7TTmRlgS5R3KD18mleVYjk6k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/J8G7TTmRlgS5R3KD18mleVYjk6k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/WCLn-3L0Z74" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/3995492570759130005/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=3995492570759130005" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/3995492570759130005?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/3995492570759130005?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/WCLn-3L0Z74/bgp-bestpath-as-path-multipath-relax.html" title="BGP bestpath as-path multipath-relax" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-qR2i4C4mW74/Tt63sNx20GI/AAAAAAAAAJs/7hnrCfTJxdE/s72-c/blog%2B1%2Bbgp.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/bgp-bestpath-as-path-multipath-relax.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAMQ3Y9eSp7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-6332736477085229900</id><published>2011-12-06T08:10:00.003+07:00</published><updated>2011-12-15T15:13:02.861+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:13:02.861+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="OSPF" /><category scheme="http://www.blogger.com/atom/ns#" term="Frame-Relay" /><category scheme="http://www.blogger.com/atom/ns#" term="Point-to-point" /><category scheme="http://www.blogger.com/atom/ns#" term="Broadcast" /><category scheme="http://www.blogger.com/atom/ns#" term="Multipoint" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><category scheme="http://www.blogger.com/atom/ns#" term="OSPF Network Type" /><title>OSPF Network Type</title><content type="html">&lt;a href="http://4.bp.blogspot.com/-tW9LEXy2FEs/Tt1sBuYyBGI/AAAAAAAAAJg/HlXlnqFQWFk/s1600/blog%2Bospf%2Bnetwork%2Btype.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 178px;" src="http://4.bp.blogspot.com/-tW9LEXy2FEs/Tt1sBuYyBGI/AAAAAAAAAJg/HlXlnqFQWFk/s400/blog%2Bospf%2Bnetwork%2Btype.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5682817081699075170" /&gt;&lt;/a&gt;&lt;br /&gt;*Default pada interface LAN adalah broadcast&lt;br /&gt;&lt;br /&gt;Ada 6 tipe network pada interface ospf.  &lt;br /&gt;Pilihan yang harus kita gunakan sangat bergantung pada komponen-komponen penyusun table tersebut. &lt;br /&gt;&lt;br /&gt;pada topologi frame relay, ada beberapa hal yang perlu diperhatikan dalam pemilihan tipe network: &lt;br /&gt;1.) Pastikan hello/dead timers tidak berbeda.  &lt;br /&gt;&lt;br /&gt;2.) Semua routers dalam suatu NBMA subnet disarankan menggunakan tipe network yang sama, antara semua menggunakan DR atau tidak sama sekali. &lt;br /&gt;&lt;br /&gt;3.) Apabila dikehendaki menggunakan DR, maka router yang harus menjadi DR adalah router yang punya PVC ke semua router yang lain. (set router2 DROther dengan "ip ospf priority 0")&lt;br /&gt;&lt;br /&gt;4.) "neighbor command" cukup dikonfigurasikan pada 1 router saja. &lt;br /&gt;&lt;br /&gt;5.) Apabila kita menggunakan dynamic mapping (frame-relay interface dlci) dan kita menggunakan tipe network ospf broadcast maka neighbor akan otomatis terdiscover &lt;br /&gt; &lt;br /&gt;6.) Apabila kita menggunakan frame-relay map broadcast (dengan broadcast) dan kita menggunakan tipe network ospf broadcast maka neighbor akan otomatis terdiscover &lt;br /&gt;&lt;br /&gt;7.) Apabila kita menggunakan frame-relay map (tanpa broadcast) atau kita menggunakan tipe network ospf non broadcast maka kita harus menggunakan "neighbor" command. &lt;br /&gt;&lt;br /&gt;*Broadcast keyword pada frame relay map dibutuhkan apabila kita ingin mengirimkan packet broadcast dan multicast ke spesifik dlci&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-6332736477085229900?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/QpwV1ItSqLpcKuoiNAKUjPfDhPQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QpwV1ItSqLpcKuoiNAKUjPfDhPQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/QpwV1ItSqLpcKuoiNAKUjPfDhPQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/QpwV1ItSqLpcKuoiNAKUjPfDhPQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/ImNT1sAK78M" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/6332736477085229900/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=6332736477085229900" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6332736477085229900?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6332736477085229900?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/ImNT1sAK78M/ospf-network-type.html" title="OSPF Network Type" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-tW9LEXy2FEs/Tt1sBuYyBGI/AAAAAAAAAJg/HlXlnqFQWFk/s72-c/blog%2Bospf%2Bnetwork%2Btype.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/ospf-network-type.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkYHRXo4fyp7ImA9WhRQEEg.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-4082949825211706899</id><published>2011-12-05T07:37:00.008+07:00</published><updated>2011-12-05T08:55:34.437+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-05T08:55:34.437+07:00</app:edited><title>EIGRP Stub</title><content type="html">&lt;a href="http://2.bp.blogspot.com/-miPyFCI6WLY/TtwTHJV3uRI/AAAAAAAAAJI/ZK-Hs2xc3Z0/s1600/stub%2B-blog.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 86px;" src="http://2.bp.blogspot.com/-miPyFCI6WLY/TtwTHJV3uRI/AAAAAAAAAJI/ZK-Hs2xc3Z0/s400/stub%2B-blog.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5682437843322386706" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Konfigurasi stub dibutuhkan saat sebuah router tidak boleh menjadi transit router. salah satu kegunaan konfigurasi stub adalah untuk mencegah sebuah router menerima query dari upstream router. Hal ini dapat memperpendek masa active dari upstream router dan menghindari kondisi stuck in active (SIA). &lt;br /&gt;&lt;br /&gt;Konfigurasi stub memiliki beberapa option. Secara default, stub akan mendistribusikan connected dan summary route, namun kita dapat mengubah behavior ini dengan menyebutkan route apa saja yang akan kita advertise ke upstream router. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;contoh: &lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-l9w2FkRvFh8/TtwYY5NGFaI/AAAAAAAAAJU/p1ANxuVKDgA/s1600/stub.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 388px; height: 115px;" src="http://4.bp.blogspot.com/-l9w2FkRvFh8/TtwYY5NGFaI/AAAAAAAAAJU/p1ANxuVKDgA/s400/stub.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5682443645786396066" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;font size="-8"&gt;&lt;br /&gt;R1# &lt;br /&gt;!&lt;br /&gt;interface Loopback1&lt;br /&gt; ip address 192.168.22.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback2&lt;br /&gt; ip address 192.168.23.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback3&lt;br /&gt; ip address 192.168.24.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback4&lt;br /&gt; ip address 192.168.25.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback5&lt;br /&gt; ip address 192.168.26.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 192.168.10.1 255.255.255.0&lt;br /&gt; ip summary-address eigrp 10 192.168.22.0 255.255.254.0 5&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;!&lt;br /&gt;router eigrp 10&lt;br /&gt; network 192.168.10.1 0.0.0.0&lt;br /&gt; network 192.168.0.0 0.0.255.255&lt;br /&gt; no auto-summary&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;R2#&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 192.168.10.2 255.255.255.0&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;!&lt;br /&gt;router eigrp 10&lt;br /&gt; network 192.168.10.2 0.0.0.0&lt;br /&gt; auto-summary&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;R2#sh ip route &lt;br /&gt;D    192.168.25.0/24 [90/409600] via 192.168.10.1, 00:04:18, FastEthernet0/0&lt;br /&gt;D    192.168.24.0/24 [90/409600] via 192.168.10.1, 00:04:24, FastEthernet0/0&lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;D    192.168.26.0/24 [90/409600] via 192.168.10.1, 00:04:13, FastEthernet0/0&lt;br /&gt;D    192.168.22.0/23 [90/409600] via 192.168.10.1, 00:06:13, FastEthernet0/0&lt;br /&gt;&lt;br /&gt;============================================================================&lt;br /&gt;&lt;br /&gt;R1(router)#eigrp stub &lt;br /&gt;&lt;br /&gt;R2#sh ip routte&lt;br /&gt;D    192.168.25.0/24 [90/409600] via 192.168.10.1, 00:00:30, FastEthernet0/0&lt;br /&gt;D    192.168.24.0/24 [90/409600] via 192.168.10.1, 00:00:30, FastEthernet0/0&lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;D    192.168.26.0/24 [90/409600] via 192.168.10.1, 00:00:30, FastEthernet0/0&lt;br /&gt;D    192.168.22.0/23 [90/409600] via 192.168.10.1, 00:00:30, FastEthernet0/0&lt;br /&gt;&lt;br /&gt;============================================================================&lt;br /&gt;&lt;br /&gt;R1(router)#eigrp stub connected &lt;br /&gt;R2#sh ip route &lt;br /&gt;D    192.168.25.0/24 [90/409600] via 192.168.10.1, 00:00:04, FastEthernet0/0&lt;br /&gt;D    192.168.24.0/24 [90/409600] via 192.168.10.1, 00:00:04, FastEthernet0/0&lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;D    192.168.26.0/24 [90/409600] via 192.168.10.1, 00:00:04, FastEthernet0/0&lt;br /&gt;D    192.168.23.0/24 [90/409600] via 192.168.10.1, 00:00:04, FastEthernet0/0&lt;br /&gt;D    192.168.22.0/24 [90/409600] via 192.168.10.1, 00:00:04, FastEthernet0/0&lt;br /&gt;&lt;br /&gt;============================================================================&lt;br /&gt;&lt;br /&gt;R1(router)#eigrp stub summary &lt;br /&gt;R2#sh ip route &lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;D    192.168.22.0/23 [90/409600] via 192.168.10.1, 00:00:02, FastEthernet0/0&lt;br /&gt;&lt;br /&gt;============================================================================&lt;br /&gt;&lt;br /&gt;leak-map digunakan untuk menspesifikasikan prefix eigrp apa saja yang akan kita distribusikan melalui leak-map (route-map). &lt;br /&gt;&lt;br /&gt;saya tambahkan R3. R3 terhubung dengan interface fa 0/1 R1(172.16.1.2/24) dengan konfigurasi sebagai berikut : &lt;br /&gt;&lt;br /&gt;interface Loopback1&lt;br /&gt; ip address 172.16.10.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback2&lt;br /&gt; ip address 172.16.11.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback3&lt;br /&gt; ip address 172.16.12.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/0&lt;br /&gt; ip address 172.16.1.1 255.255.255.0&lt;br /&gt; duplex auto&lt;br /&gt; speed auto&lt;br /&gt;!&lt;br /&gt;router eigrp 10&lt;br /&gt; network 172.16.0.0 0.0.255.255&lt;br /&gt; no auto-summary&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;R1#sh ip route &lt;br /&gt;C    192.168.25.0/24 is directly connected, Loopback4&lt;br /&gt;C    192.168.24.0/24 is directly connected, Loopback3&lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;     172.16.0.0/24 is subnetted, 4 subnets&lt;br /&gt;D       172.16.12.0 [90/409600] via 172.16.1.1, 00:02:44, FastEthernet0/1&lt;br /&gt;D       172.16.10.0 [90/409600] via 172.16.1.1, 00:02:44, FastEthernet0/1&lt;br /&gt;D       172.16.11.0 [90/409600] via 172.16.1.1, 00:02:44, FastEthernet0/1&lt;br /&gt;C       172.16.1.0 is directly connected, FastEthernet0/1&lt;br /&gt;C    192.168.26.0/24 is directly connected, Loopback5&lt;br /&gt;C    192.168.23.0/24 is directly connected, Loopback2&lt;br /&gt;C    192.168.22.0/24 is directly connected, Loopback1&lt;br /&gt;D    192.168.22.0/23 is a summary, 00:10:02, Null0&lt;br /&gt;&lt;br /&gt;kemudian saya konfigurasikan leak-map bernama lm1 &lt;br /&gt;!&lt;br /&gt;access-list 1 permit 172.16.12.0 0.0.0.255&lt;br /&gt;!&lt;br /&gt;route-map lm1 permit 1&lt;br /&gt; match ip address 1&lt;br /&gt;!&lt;br /&gt;router eigrp 10&lt;br /&gt;eigrp stub leak-map lm1&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;R2#sh ip route &lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;     172.16.0.0/24 is subnetted, 1 subnets&lt;br /&gt;D       172.16.12.0 [90/435200] via 192.168.10.1, 00:00:09, FastEthernet0/0&lt;br /&gt;&lt;br /&gt;================================================================&lt;br /&gt;receive-only digunakan untuk membuat sebuah router hanya menerima prefix tanpa memberitahukan prefix yang dimilikinya. &lt;br /&gt;&lt;br /&gt;R1(router)#eigrp stub receive-only &lt;br /&gt;R1#sh ip route &lt;br /&gt;&lt;br /&gt;C    192.168.25.0/24 is directly connected, Loopback4&lt;br /&gt;C    192.168.24.0/24 is directly connected, Loopback3&lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;     172.16.0.0/24 is subnetted, 4 subnets&lt;br /&gt;D       172.16.12.0 [90/409600] via 172.16.1.1, 00:00:24, FastEthernet0/1&lt;br /&gt;D       172.16.10.0 [90/409600] via 172.16.1.1, 00:00:24, FastEthernet0/1&lt;br /&gt;D       172.16.11.0 [90/409600] via 172.16.1.1, 00:00:24, FastEthernet0/1&lt;br /&gt;C       172.16.1.0 is directly connected, FastEthernet0/1&lt;br /&gt;C    192.168.26.0/24 is directly connected, Loopback5&lt;br /&gt;C    192.168.23.0/24 is directly connected, Loopback2&lt;br /&gt;C    192.168.22.0/24 is directly connected, Loopback1&lt;br /&gt;D    192.168.22.0/23 is a summary, 00:15:00, Null0&lt;br /&gt;&lt;br /&gt;R2#sh ip route &lt;br /&gt;C    192.168.10.0/24 is directly connected, FastEthernet0/0&lt;br /&gt;&lt;br /&gt;R3#&lt;br /&gt;     172.16.0.0/24 is subnetted, 4 subnets&lt;br /&gt;C       172.16.12.0 is directly connected, Loopback3&lt;br /&gt;C       172.16.10.0 is directly connected, Loopback1&lt;br /&gt;C       172.16.11.0 is directly connected, Loopback2&lt;br /&gt;C       172.16.1.0 is directly connected, FastEthernet0/0&lt;br /&gt;&lt;/font&gt;&lt;br /&gt;==fin==&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-4082949825211706899?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ReinebloWjOmqT7kEGG_da09PMM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ReinebloWjOmqT7kEGG_da09PMM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ReinebloWjOmqT7kEGG_da09PMM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ReinebloWjOmqT7kEGG_da09PMM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/bR-aQ6I4V_g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/4082949825211706899/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=4082949825211706899" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/4082949825211706899?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/4082949825211706899?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/bR-aQ6I4V_g/eigrp-stub.html" title="EIGRP Stub" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-miPyFCI6WLY/TtwTHJV3uRI/AAAAAAAAAJI/ZK-Hs2xc3Z0/s72-c/stub%2B-blog.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/eigrp-stub.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MEQ3g7cSp7ImA9WhRQEEk.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-825778671937257477</id><published>2011-12-04T15:45:00.008+07:00</published><updated>2011-12-05T07:36:42.609+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-05T07:36:42.609+07:00</app:edited><title>Distribusi Default Route</title><content type="html">4 cara untuk mendistribusikan default route :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-5AsVLgczZO8/Tts0VdM3S6I/AAAAAAAAAI8/cb44tUMoFaE/s1600/blog%2Bdefault%2Broute.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 105px;" src="http://2.bp.blogspot.com/-5AsVLgczZO8/Tts0VdM3S6I/AAAAAAAAAI8/cb44tUMoFaE/s400/blog%2Bdefault%2Broute.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5682192898078493602" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt; &lt;br /&gt; &lt;br  /&gt;&lt;br /&gt;&lt;br /&gt;1.) redistribusi static route &lt;br /&gt;konfigur static route &lt;br /&gt;#ip route &amp;lt;dest-net&amp;gt; &amp;lt;dest-netmask&amp;gt; &amp;lt;exit interface|next-hop ip&amp;gt; &lt;br /&gt;#router &amp;lt;protocol&amp;gt;&lt;br /&gt;#redistribute static &lt;br /&gt;&lt;br /&gt;2.) default information originate &lt;br /&gt;#router &amp;lt;protocol&amp;gt; &lt;br /&gt;#default-information originate &lt;br /&gt;&lt;br /&gt;3.) ip default network &lt;br /&gt;ada beberapa syarat yang harus di perhatikan untuk konfigurasi ip default network :&lt;br /&gt;a.) local router harus di konfigur dengan "ip default-network &amp;lt;network number&amp;gt;", dengan network number sebagai classful network number.&lt;br /&gt;b.) classful network tersebut harus terdapat pada routing table di local router tersebut, dengan cara apapun. &lt;br /&gt;c.) khusus untuk eigrp, classful network tersebut harus di advertised oleh local router kedalam EIGRP, dengan cara apapun &lt;br /&gt;&lt;br /&gt;konfigurasi &lt;br /&gt;masukan ke classful network ke routing table baik dengan konfigurasi interface maupun static routing ataupun cara yang lain. &lt;br /&gt; &lt;br /&gt;#interface loopback &amp;lt;id&amp;gt;&lt;br /&gt;if# ip address &amp;lt;usable IP address of a classfull network&amp;gt; &amp;lt;classful netmask&amp;gt;&lt;br /&gt;#ip default-network &amp;lt;classfull network number&amp;gt;&lt;br /&gt;&lt;br /&gt;contoh:&lt;br /&gt;#interface loopback 1 &lt;br /&gt;if#ip address 8.8.8.9 255.0.0.0 &lt;br /&gt;#ip default-network 8.0.0.0&lt;br /&gt;&lt;br /&gt;khusus untuk EIGRP, kita harus menambahkan command untuk mengadvertise ip tersebut agar disebarkan oleh EIGRP sebagai candidate default route. &lt;br /&gt;eigrp#network &amp;lt;network number&amp;gt; &amp;lt;network mask&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4.) ip summary address &lt;br /&gt;konfigur per interface &lt;br /&gt;#ip summary address eigrp &amp;lt;ASN&amp;gt; 0.0.0.0 0.0.0.0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;sumber: Cisco Press&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-825778671937257477?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-j6M1Ca-fojwsj4uVW1h2hJ8qwA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-j6M1Ca-fojwsj4uVW1h2hJ8qwA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-j6M1Ca-fojwsj4uVW1h2hJ8qwA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-j6M1Ca-fojwsj4uVW1h2hJ8qwA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/QSMxMJ70w48" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/825778671937257477/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=825778671937257477" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/825778671937257477?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/825778671937257477?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/QSMxMJ70w48/distribusi-default-route.html" title="Distribusi Default Route" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-5AsVLgczZO8/Tts0VdM3S6I/AAAAAAAAAI8/cb44tUMoFaE/s72-c/blog%2Bdefault%2Broute.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/distribusi-default-route.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUAMQnw5eyp7ImA9WhRRGUs.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-3577157265200312568</id><published>2011-12-04T07:05:00.005+07:00</published><updated>2011-12-04T08:56:23.223+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-04T08:56:23.223+07:00</app:edited><title>Konfigurasi PPP Multilink diatas Frame Relay</title><content type="html">&lt;a href="http://1.bp.blogspot.com/-n7ojOCeHJvE/TtrROsXeTHI/AAAAAAAAAIk/v_qaWf2zr5g/s1600/multilink.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 161px;" src="http://1.bp.blogspot.com/-n7ojOCeHJvE/TtrROsXeTHI/AAAAAAAAAIk/v_qaWf2zr5g/s400/multilink.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5682083930239290482" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Frame Relay merupakan Protocol Layer 2 yang tidak mendukung fitur authentikasi maupun link balancing. untungnya, PPP dapat menambal kekurangan tersebut. Dengan menggunakan PPP kita dapat menambahkan fitur authentikasi, kompresi, link management maupun link balancing (melalui multi link PPP). Seperti hal nya etherchannel, multilink dapat menggabungkan 2 link PPP atau lebih dan menjadikannya seolah menjadi 1 (logical) link. &lt;br /&gt;&lt;br /&gt;pada frame relay, kita tidak dapat menambahkan konfigurasi multilink pada physical interface, melainkan harus dalam "interface Virtual-Template". berikut contoh konfigurasi nya&lt;br /&gt;(saya mengasumsikan frame relay telah berjalan dengan baik) &lt;br /&gt;&lt;br /&gt;!buat account untuk authentikasi chap &lt;br /&gt;R1#username &amp;lt;neighbor-hostname&amp;gt; password &amp;lt;pass&amp;gt; &lt;br /&gt;&lt;br /&gt;!buat interface virtual-template &lt;br /&gt;R1#interface Virtual-Template &amp;lt;id&amp;gt;&lt;br /&gt;R1-if#ip address &amp;lt;ip&amp;gt; &amp;lt;netmask&amp;gt;&lt;br /&gt;R1-if#ppp multilink &lt;br /&gt;R1-if#ppp authentication chap &lt;br /&gt;&lt;br /&gt;R1#interface serial &amp;lt;if-id&amp;gt; &lt;br /&gt;R1-if#encapsulation frame-relay &lt;br /&gt;RF-if#frame-relay interface-dlci &amp;lt;dlci&amp;gt; ppp virtual-template &amp;lt;id&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;buat konfigurasi ini di router lain dengan perubahan seperlunya. &lt;br /&gt;&lt;br /&gt;verifikasi : &lt;br /&gt;debug ppp auth &lt;br /&gt;debug frame-relay lmi &lt;br /&gt;sh ppp multilink &lt;br /&gt;sh ip int br &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;kita juga dapat melakukan konfigurasi "interface multilink" layaknya konfigurasi multilink tanpa frame relay. kemudian kita harus mem-bundle interface virtual-template dan multilink dengan menambahkan: &lt;br /&gt;R1-if(multilink &amp; virtual template)#ppp multilink group &amp;lt;id&amp;gt&lt;br /&gt;&lt;br /&gt;bila menggunakan konfigurasi ini, lakukan semua konfigurasi: authentikasi, ip, kompresi dsb pada interface multilink.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-3577157265200312568?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/F0f8xsxWIA1s3wlxKi6ZTYLPEjk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/F0f8xsxWIA1s3wlxKi6ZTYLPEjk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/F0f8xsxWIA1s3wlxKi6ZTYLPEjk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/F0f8xsxWIA1s3wlxKi6ZTYLPEjk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/OcTJwejZt5A" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/3577157265200312568/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=3577157265200312568" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/3577157265200312568?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/3577157265200312568?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/OcTJwejZt5A/konfigurasi-ppp-multilink-diatas-frame.html" title="Konfigurasi PPP Multilink diatas Frame Relay" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-n7ojOCeHJvE/TtrROsXeTHI/AAAAAAAAAIk/v_qaWf2zr5g/s72-c/multilink.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/konfigurasi-ppp-multilink-diatas-frame.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkQASX4_eCp7ImA9WhRRGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-6593824402314865272</id><published>2011-12-03T23:01:00.006+07:00</published><updated>2011-12-03T23:39:08.040+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-03T23:39:08.040+07:00</app:edited><title>Frame Relay Bridging</title><content type="html">&lt;a href="http://2.bp.blogspot.com/-4XsjYz2spls/TtpKr9kKyqI/AAAAAAAAAIM/OR79gGPixXw/s1600/blog%2Bfr%2Bbridge.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 177px;" src="http://2.bp.blogspot.com/-4XsjYz2spls/TtpKr9kKyqI/AAAAAAAAAIM/OR79gGPixXw/s400/blog%2Bfr%2Bbridge.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5681935999002397346" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;We can create 2 router interfaces as a bridge when using frame-relay to join 2 nodes/areas into the same network even though it is separated by many routers.&lt;br /&gt;&lt;br /&gt;we need to configure R1 and R2 to use bridge interface:&lt;br /&gt;&lt;br /&gt;3 first steps (i-p-r) &lt;br /&gt;&lt;br /&gt;R1#bridge Irb   &amp;nbsp;&amp;nbsp;&amp;nbsp; !enabling irb (integrated routing bridging) &lt;br /&gt;R1#bridge &amp;lt;group id&amp;gt; Protocol ieee   &lt;br /&gt;R1#bridge &amp;lt;group id&amp;gt; route ip      &amp;nbsp;&amp;nbsp;&amp;nbsp; !IP will be routed in this bridge group &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Interface serial 0/0 is connected to frame relay switch &lt;br /&gt;Interface Fa 0/0 R1 is connected to the local network which will be bridged to the network on fa 0/0 on R2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R1#interface fa0/0 &lt;br /&gt;R1#bridge-group &amp;lt;group-id&amp;gt; &lt;br /&gt;R1#no shut&lt;br /&gt;&lt;br /&gt;R1#interface ser0/0 &lt;br /&gt;R1#no shut&lt;br /&gt;R1#frame-relay map bridge &amp;lt;dlci-number&amp;gt; broadcast&lt;br /&gt;R1#bridge-group &amp;lt;group ID&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;next step... place the ip address that was previously assigned to serial interface to the newly created Bridge Virtual Interface (BVI) &lt;br /&gt;&lt;br /&gt;R1#interface BVI &amp;lt;interface-id&amp;gt;&lt;br /&gt;R1-if#ip address &amp;lt;ip&amp;gt; &amp;lt;netmask&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;mirror this configuration to R2, with necessary changes. &lt;br /&gt;&lt;br /&gt;verification: &lt;br /&gt;sh frame-relay map &lt;br /&gt;sh ip int brief &lt;br /&gt;&lt;br /&gt;Source: CCIE RS Bootcamp p.30 (by Dedy Gunawan)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-6593824402314865272?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/FojWJLWgL-WVCpC_vHH53zRsrIc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FojWJLWgL-WVCpC_vHH53zRsrIc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/FojWJLWgL-WVCpC_vHH53zRsrIc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/FojWJLWgL-WVCpC_vHH53zRsrIc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/FQL-O9qIxss" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/6593824402314865272/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=6593824402314865272" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6593824402314865272?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6593824402314865272?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/FQL-O9qIxss/frame-relay-bridging.html" title="Frame Relay Bridging" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-4XsjYz2spls/TtpKr9kKyqI/AAAAAAAAAIM/OR79gGPixXw/s72-c/blog%2Bfr%2Bbridge.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/12/frame-relay-bridging.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUcNSXg7cSp7ImA9WhRTEkk.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-4501863375875068098</id><published>2011-11-02T21:03:00.003+07:00</published><updated>2011-11-02T21:11:38.609+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-02T21:11:38.609+07:00</app:edited><title>Convert 14 bits format to 3-8-3 format Point Code</title><content type="html">there are 2 kinds of point code format given by ITU. &lt;br /&gt;1.) International Network [3 bits (Zone) -8 bits (Area/network) -3 bits (Point)]&lt;br /&gt;2.) National Network (14 bits Signaling point) &lt;br /&gt;&lt;br /&gt;sometimes we need to convert the Point code in National Network format (14 bits) to International Format to determine the zone or area for a given point code. &lt;br /&gt;&lt;br /&gt;To convert it, simply convert the decimal value into 14 bits decimal then separate it by 3-8-3 format, then convert it back to decimal value and concatenate it . &lt;br /&gt;&lt;br /&gt;e.g &lt;br /&gt;National Network PC: 2200 &lt;br /&gt;then it will be       : 00100010011000&lt;br /&gt;separate it           : 001 00010011 000 &lt;br /&gt;convert to dec        : 1 19 0&lt;br /&gt;concat                : 1190&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-4501863375875068098?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/B-x4YG_ntVsIZR9bC0TDUQ3vks8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B-x4YG_ntVsIZR9bC0TDUQ3vks8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/B-x4YG_ntVsIZR9bC0TDUQ3vks8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B-x4YG_ntVsIZR9bC0TDUQ3vks8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/H547a_7eNaQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/4501863375875068098/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=4501863375875068098" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/4501863375875068098?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/4501863375875068098?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/H547a_7eNaQ/convert-14-bits-format-to-3-8-3-format.html" title="Convert 14 bits format to 3-8-3 format Point Code" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/11/convert-14-bits-format-to-3-8-3-format.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEIHSXwzfSp7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-1636800998846758887</id><published>2011-10-31T17:09:00.012+07:00</published><updated>2011-12-15T15:08:58.285+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:08:58.285+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ORF" /><category scheme="http://www.blogger.com/atom/ns#" term="Filtering" /><category scheme="http://www.blogger.com/atom/ns#" term="bgp" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><title>BGP - Outbound Route Filtering</title><content type="html">Sometimes, customers want to filter several routes from their ISP. we can filter the incoming update from the customer standpoint, but it will not stop the SP's router to keep sending the update. It will be totally ineffecient.&lt;br /&gt;To rectify this problem, We can configure Outbound Route Filtering (ORF) to tell the neighboring router that we are filtering those routes so&lt;br /&gt;"please stop sending unnecessary updates to us"&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-MivEllxc9zw/Tq6E7O90ULI/AAAAAAAAAH0/6mbeWr_sTWQ/s1600/bgp-orf.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 400px; FLOAT: left; HEIGHT: 123px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5669615134070558898" border="0" alt="" src="http://1.bp.blogspot.com/-MivEllxc9zw/Tq6E7O90ULI/AAAAAAAAAH0/6mbeWr_sTWQ/s400/bgp-orf.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R3&lt;br /&gt;!&lt;br /&gt;router bgp 100&lt;br /&gt;router#no synchronization&lt;br /&gt;router#bgp log-neighbor-changes&lt;br /&gt;router#neighbor 192.168.1.2 remote-as 200&lt;br /&gt;router#neighbor 192.168.1.2 soft-reconfiguration inbound&lt;br /&gt;router#no auto-summary&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R4&lt;br /&gt;!&lt;br /&gt;router bgp 200&lt;br /&gt;router#no synchronization&lt;br /&gt;router#bgp log-neighbor-changes&lt;br /&gt;router#network 10.1.2.0 mask 255.255.255.0&lt;br /&gt;router#network 172.16.2.0 mask 255.255.255.0&lt;br /&gt;router#network 192.168.2.0&lt;br /&gt;router#neighbor 192.168.1.1 remote-as 100&lt;br /&gt;router#no auto-summary&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-keAvyhwZcbQ/Tq6E7SO7PtI/AAAAAAAAAIA/Up0D4H5cxp4/s1600/R4-adv-route-b4.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 400px; FLOAT: left; HEIGHT: 106px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5669615134947622610" border="0" alt="" src="http://1.bp.blogspot.com/-keAvyhwZcbQ/Tq6E7SO7PtI/AAAAAAAAAIA/Up0D4H5cxp4/s400/R4-adv-route-b4.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R3&lt;br /&gt;!&lt;br /&gt;ip prefix-list eliminate-route seq 10 permit 10.1.2.0/24&lt;br /&gt;router bgp 100&lt;br /&gt;router#neighbor 192.168.1.2 capability orf prefix-list send&lt;br /&gt;router#neighbor 192.168.1.2 prefix-list eliminate-route in&lt;br /&gt;!&lt;br /&gt;R4&lt;br /&gt;!&lt;br /&gt;router bgp 200&lt;br /&gt;router#neighbor 192.168.1.1 capability orf prefix-list receive&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-FsaCc3S4LOQ/Tq6E6uSmzFI/AAAAAAAAAHo/xAAzicOkvNc/s1600/advertised%2Broute%2B2.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 400px; FLOAT: left; HEIGHT: 103px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5669615125299383378" border="0" alt="" src="http://1.bp.blogspot.com/-FsaCc3S4LOQ/Tq6E6uSmzFI/AAAAAAAAAHo/xAAzicOkvNc/s400/advertised%2Broute%2B2.png" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-1636800998846758887?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/aQW1oipLfeAMwNLF08Jhg1mRtKk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aQW1oipLfeAMwNLF08Jhg1mRtKk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/aQW1oipLfeAMwNLF08Jhg1mRtKk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/aQW1oipLfeAMwNLF08Jhg1mRtKk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/JJbjX-AWMck" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/1636800998846758887/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=1636800998846758887" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/1636800998846758887?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/1636800998846758887?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/JJbjX-AWMck/outbound-route-filtering.html" title="BGP - Outbound Route Filtering" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-MivEllxc9zw/Tq6E7O90ULI/AAAAAAAAAH0/6mbeWr_sTWQ/s72-c/bgp-orf.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/10/outbound-route-filtering.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C08CQnc_fyp7ImA9WhRTEEk.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-7297224752404965309</id><published>2011-10-31T13:10:00.006+07:00</published><updated>2011-10-31T13:17:43.947+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-31T13:17:43.947+07:00</app:edited><title>eBGP disable-connected-check</title><content type="html">By default, eBGP will check if the neighbor IP address is directly connected (TTL=1). when the neighbor statement is using loopback interface, the eBGP peering will not form. to disable this check we need to add 1 of this 2 configurations: &lt;br /&gt;&lt;br /&gt;-neighbor &amp;lt;addr&amp;gt; disable-connected-check &lt;br /&gt;-neighbor &amp;lt;addr&amp;gt; ebgp-multihop &amp;lt;ttl&amp;gt;&lt;br /&gt;&lt;br /&gt;!with TTL &gt; 1 &lt;br /&gt;&lt;br /&gt;source: http://neatherweb.com/index.php?option=com_content&amp;view=article&amp;id=21:bgp-disable-connected-check&amp;catid=8:ccie&amp;Itemid=13&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-7297224752404965309?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/fM1mddFtv_-iaj7KWo_szvYanBk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fM1mddFtv_-iaj7KWo_szvYanBk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/fM1mddFtv_-iaj7KWo_szvYanBk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/fM1mddFtv_-iaj7KWo_szvYanBk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/FmlNAATCr4s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/7297224752404965309/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=7297224752404965309" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/7297224752404965309?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/7297224752404965309?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/FmlNAATCr4s/ebgp-disable-connected-check.html" title="eBGP disable-connected-check" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/10/ebgp-disable-connected-check.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C08MQXo9cCp7ImA9WhdaGEo.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-2677889166746313057</id><published>2011-10-29T13:59:00.004+07:00</published><updated>2011-10-29T14:04:40.468+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-29T14:04:40.468+07:00</app:edited><title>Q-in-Q</title><content type="html">source : http://www.cisco.com/en/US/docs/routers/7600/ios/12.2SR/configuration/guide/dot1qtnl.html&lt;br /&gt;&lt;br /&gt;802.1Q tunneling enables service providers to use a single VLAN to support customers who have multiple VLANs, while preserving customer VLAN IDs and keeping traffic in different customer VLANs segregated.&lt;br /&gt;&lt;br /&gt;The link between the 802.1Q trunk port on a customer device and the tunnel port is called an asymmetrical link because one end is configured as an 802.1Q trunk port and the other end is configured as a tunnel port. You assign the tunnel port to an access VLAN ID unique to each customer.&lt;br /&gt;&lt;br /&gt;another words:&lt;br /&gt;CE (Trunk) ----- (dot1q-tunnel-if (access vlan)PE)&lt;br /&gt;&lt;br /&gt;simply add:&lt;br /&gt;interface#switchport mode dot1q-tunnel&lt;br /&gt;&lt;br /&gt;verification:&lt;br /&gt;#sh dot1q-tunnel interface&lt;br /&gt;&lt;br /&gt;native vlan can't be tagged correctly through this tunnel interface. either use ISL (i.e doesn't support native vlan) or configure:&lt;br /&gt;&lt;br /&gt;global#vlan dot1q tag native&lt;br /&gt;to tag native VLAN egress traffic and drop untagged native VLAN ingress traffic.&lt;br /&gt;&lt;br /&gt;-Jumbo frames can be tunneled as long as the jumbo frame length combined with the 802.1Q tag does not exceed the maximum frame size.&lt;br /&gt;-L3 and higher protocol can't be identified&lt;br /&gt;-CDP "native vlan mismatch" can be ignored&lt;br /&gt;-can't be configured to support private vlan&lt;br /&gt;-PortFast BPDU filtering is enabled automatically on tunnel ports.&lt;br /&gt;-CDP is automatically disabled on tunnel ports. &lt;br /&gt;-VLAN Trunk Protocol (VTP) does not work between the following devices:&lt;br /&gt;   --Devices connected by an asymmetrical link &lt;br /&gt;   --Devices communicating through a tunnel&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-2677889166746313057?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/IJZBCFFqCVdbDTgZpBaj1blGcTs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IJZBCFFqCVdbDTgZpBaj1blGcTs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/IJZBCFFqCVdbDTgZpBaj1blGcTs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IJZBCFFqCVdbDTgZpBaj1blGcTs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/Wbc3jHBmxbQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/2677889166746313057/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=2677889166746313057" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2677889166746313057?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/2677889166746313057?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/Wbc3jHBmxbQ/q-in-q.html" title="Q-in-Q" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/10/q-in-q.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkEHSH86eSp7ImA9WhdbEk8.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-6440167773897227502</id><published>2011-10-10T11:51:00.009+07:00</published><updated>2011-10-10T12:30:39.111+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-10T12:30:39.111+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="VRF" /><title>VRF (lite)</title><content type="html">&lt;blockquote&gt;From a design perspective, Multi-VRF CE feature gives the provider better choices about platforms, and where to put the relatively large workload required by a PE. A multitenant unit (MTU) design is a classic example, where the SP puts a single Layer 3 device in a building with multiple customers. &lt;span style="font-weight:bold;"&gt;The SP engineers could just make the CPE device act as PE. However, by making the CPE router act as CE, but with using Multi-VRF CE, the SP can easily separate customers at Layer 3, while avoiding the investment in a more powerful Layer 3 CPE platform to support full PE functionality.&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-bscX4Qr1J5o/TpJ8JpijsSI/AAAAAAAAAFg/LvvDLTB73OY/s1600/vrf-lite.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 215px;" src="http://2.bp.blogspot.com/-bscX4Qr1J5o/TpJ8JpijsSI/AAAAAAAAAFg/LvvDLTB73OY/s400/vrf-lite.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5661724186769600802" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;R1#&lt;br /&gt;version 12.4&lt;br /&gt;!&lt;br /&gt;hostname R1&lt;br /&gt;!&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;ip vrf cusA&lt;br /&gt;rd 1:1&lt;br /&gt;route-target export 1:1&lt;br /&gt;route-target import 1:1&lt;br /&gt;!&lt;br /&gt;ip vrf cusB&lt;br /&gt;rd 2:2&lt;br /&gt;route-target export 2:2&lt;br /&gt;route-target import 2:2&lt;br /&gt;!&lt;br /&gt;interface Loopback1&lt;br /&gt;ip vrf forwarding cusA&lt;br /&gt;ip address 192.168.1.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback2&lt;br /&gt;ip vrf forwarding cusB&lt;br /&gt;ip address 192.168.1.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Serial1/0&lt;br /&gt;no ip address&lt;br /&gt;encapsulation frame-relay&lt;br /&gt;no keepalive&lt;br /&gt;serial restart-delay 0&lt;br /&gt;clock rate 128000&lt;br /&gt;no dce-terminal-timing-enable&lt;br /&gt;!&lt;br /&gt;interface Serial1/0.10 point-to-point&lt;br /&gt;ip vrf forwarding cusA&lt;br /&gt;ip address 202.1.1.5 255.255.255.252&lt;br /&gt;frame-relay interface-dlci 101&lt;br /&gt;!&lt;br /&gt;interface Serial1/0.20 point-to-point&lt;br /&gt;ip vrf forwarding cusB&lt;br /&gt;ip address 202.1.1.1 255.255.255.252&lt;br /&gt;frame-relay interface-dlci 202&lt;br /&gt;!&lt;br /&gt;router eigrp 5000&lt;br /&gt;auto-summary&lt;br /&gt;!&lt;br /&gt;address-family ipv4 vrf cusB&lt;br /&gt;network 192.168.1.0&lt;br /&gt;network 202.1.1.0 0.0.0.3&lt;br /&gt;no auto-summary&lt;br /&gt;autonomous-system 200&lt;br /&gt;exit-address-family&lt;br /&gt;!&lt;br /&gt;address-family ipv4 vrf cusA&lt;br /&gt;network 192.168.1.0&lt;br /&gt;network 202.1.1.4 0.0.0.3&lt;br /&gt;no auto-summary&lt;br /&gt;autonomous-system 100&lt;br /&gt;exit-address-family&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;R2#sh run&lt;br /&gt;!&lt;br /&gt;version 12.4&lt;br /&gt;!&lt;br /&gt;hostname R2&lt;br /&gt;!&lt;br /&gt;ip cef&lt;br /&gt;!&lt;br /&gt;ip vrf cusA&lt;br /&gt;rd 1:1&lt;br /&gt;route-target export 1:1&lt;br /&gt;route-target import 1:1&lt;br /&gt;!&lt;br /&gt;ip vrf cusB&lt;br /&gt;rd 2:2&lt;br /&gt;route-target export 2:2&lt;br /&gt;route-target import 2:2&lt;br /&gt;!&lt;br /&gt;interface Loopback1&lt;br /&gt;ip vrf forwarding cusA&lt;br /&gt;ip address 192.168.2.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Loopback2&lt;br /&gt;ip vrf forwarding cusB&lt;br /&gt;ip address 192.168.3.1 255.255.255.0&lt;br /&gt;!&lt;br /&gt;interface Serial1/0&lt;br /&gt;no ip address&lt;br /&gt;encapsulation frame-relay&lt;br /&gt;no keepalive&lt;br /&gt;serial restart-delay 0&lt;br /&gt;clock rate 128000&lt;br /&gt;no dce-terminal-timing-enable&lt;br /&gt;!&lt;br /&gt;interface Serial1/0.10 point-to-point&lt;br /&gt;ip vrf forwarding cusA&lt;br /&gt;ip address 202.1.1.6 255.255.255.252&lt;br /&gt;frame-relay interface-dlci 101&lt;br /&gt;!&lt;br /&gt;interface Serial1/0.20 point-to-point&lt;br /&gt;ip vrf forwarding cusB&lt;br /&gt;ip address 202.1.1.2 255.255.255.252&lt;br /&gt;frame-relay interface-dlci 202&lt;br /&gt;!&lt;br /&gt;router eigrp 4000&lt;br /&gt;auto-summary&lt;br /&gt;!&lt;br /&gt;address-family ipv4 vrf cusB&lt;br /&gt;network 192.168.3.0&lt;br /&gt;network 202.1.1.0 0.0.0.3&lt;br /&gt;no auto-summary&lt;br /&gt;autonomous-system 200&lt;br /&gt;exit-address-family&lt;br /&gt;!&lt;br /&gt;address-family ipv4 vrf cusA&lt;br /&gt;network 192.168.2.0&lt;br /&gt;network 202.1.1.4 0.0.0.3&lt;br /&gt;no auto-summary&lt;br /&gt;autonomous-system 100&lt;br /&gt;exit-address-family&lt;br /&gt;!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-hOHFQaEzgWA/TpJ_YQdGzqI/AAAAAAAAAFo/rvqGAh4eaE4/s1600/eigrp%2BcusA.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 135px;" src="http://4.bp.blogspot.com/-hOHFQaEzgWA/TpJ_YQdGzqI/AAAAAAAAAFo/rvqGAh4eaE4/s400/eigrp%2BcusA.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5661727736268770978" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-w2q9brUeEv8/TpKCW6w9wvI/AAAAAAAAAGI/8U1y5yXpj9o/s1600/vrf%2Bip%2Broute.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 337px;" src="http://1.bp.blogspot.com/-w2q9brUeEv8/TpKCW6w9wvI/AAAAAAAAAGI/8U1y5yXpj9o/s400/vrf%2Bip%2Broute.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5661731011801498354" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-dTgJ2nziZ9s/TpKCXCBUvMI/AAAAAAAAAGQ/WW7nOhhKIHc/s1600/ping%2Btest%2Bvrf.png" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 199px;" src="http://1.bp.blogspot.com/-dTgJ2nziZ9s/TpKCXCBUvMI/AAAAAAAAAGQ/WW7nOhhKIHc/s400/ping%2Btest%2Bvrf.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5661731013749161154" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-6440167773897227502?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/b9clqOb9BB5NmnGV3zcJYW5km9M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/b9clqOb9BB5NmnGV3zcJYW5km9M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/b9clqOb9BB5NmnGV3zcJYW5km9M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/b9clqOb9BB5NmnGV3zcJYW5km9M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/YtxijnFgBKI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/6440167773897227502/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=6440167773897227502" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6440167773897227502?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6440167773897227502?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/YtxijnFgBKI/vrf-lite.html" title="VRF (lite)" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-bscX4Qr1J5o/TpJ8JpijsSI/AAAAAAAAAFg/LvvDLTB73OY/s72-c/vrf-lite.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/10/vrf-lite.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEIMQn48fyp7ImA9WhRQGU4.&quot;"><id>tag:blogger.com,1999:blog-7758318932195827641.post-6629255023527522557</id><published>2011-09-22T14:47:00.007+07:00</published><updated>2011-12-15T15:09:43.077+07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-15T15:09:43.077+07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="bgp" /><category scheme="http://www.blogger.com/atom/ns#" term="aggregate" /><category scheme="http://www.blogger.com/atom/ns#" term="Cisco" /><category scheme="http://www.blogger.com/atom/ns#" term="as-set" /><title>AS-set Attribute</title><content type="html">&lt;blockquote&gt;when the as-set option has been configured, the router creates an AS_SET segment for the aggregate route, BUT ONLY IF THE SUMMARY ROUTE'S AS_SEQ IS NULL. AS_SEQ will be null if aggregator can't create an accurate representation of AS_SEQ, due to differing AS_SEQ values of it's component route.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;in fact, if there are 2 routes with different length of AS_SEQ, but they have same AS_SEQ until the short's last ASN, the router will use the longest AS_SEQ values.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-s8Mu6vNwidk/TnrtkdaEwdI/AAAAAAAAAFI/ogF_MfrZfFg/s1600/bgp-as-set.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 224px;" src="http://2.bp.blogspot.com/-s8Mu6vNwidk/TnrtkdaEwdI/AAAAAAAAAFI/ogF_MfrZfFg/s400/bgp-as-set.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5655093492742144466" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;R2#router bgp 500&lt;br /&gt;no synchronization&lt;br /&gt;bgp log-neighbor-changes&lt;br /&gt;aggregate-address 10.1.0.0 255.255.0.0 as-set&lt;br /&gt;redistribute connected&lt;br /&gt;neighbor 192.168.1.2 remote-as 242&lt;br /&gt;neighbor 192.168.1.5 remote-as 90&lt;br /&gt;neighbor 192.168.1.10 remote-as 258&lt;br /&gt;neighbor 192.168.1.10 shutdown&lt;br /&gt;no auto-summary&lt;br /&gt;!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-esgTVDGfeBM/TnrtkkXILZI/AAAAAAAAAFQ/j6sALcH32EQ/s1600/r1.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 235px;" src="http://3.bp.blogspot.com/-esgTVDGfeBM/TnrtkkXILZI/AAAAAAAAAFQ/j6sALcH32EQ/s400/r1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5655093494608833938" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;R2#no neighbor 192.168.1.10 shutdown&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-OREEnqusdyY/Tnrtk6Q3sDI/AAAAAAAAAFY/HMGAXAEIpr4/s1600/r1-2.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 235px;" src="http://3.bp.blogspot.com/-OREEnqusdyY/Tnrtk6Q3sDI/AAAAAAAAAFY/HMGAXAEIpr4/s400/r1-2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5655093500488167474" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7758318932195827641-6629255023527522557?l=ianwijaya.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/B4MltKHjWxL2-TL8K-2gjUKROBI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B4MltKHjWxL2-TL8K-2gjUKROBI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/B4MltKHjWxL2-TL8K-2gjUKROBI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/B4MltKHjWxL2-TL8K-2gjUKROBI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/YangPentingJalan/~4/dGUvrcG2B9g" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://ianwijaya.blogspot.com/feeds/6629255023527522557/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=7758318932195827641&amp;postID=6629255023527522557" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6629255023527522557?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7758318932195827641/posts/default/6629255023527522557?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/YangPentingJalan/~3/dGUvrcG2B9g/as-set-attribute.html" title="AS-set Attribute" /><author><name>Ian Wijaya</name><uri>http://www.blogger.com/profile/16822956116107389067</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="29" height="32" src="http://4.bp.blogspot.com/-RjlyW7L5Iag/TZ0uBkHKDpI/AAAAAAAAAEE/WSIQYqkhCug/s220/homer_simpson.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-s8Mu6vNwidk/TnrtkdaEwdI/AAAAAAAAAFI/ogF_MfrZfFg/s72-c/bgp-as-set.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://ianwijaya.blogspot.com/2011/09/as-set-attribute.html</feedburner:origLink></entry></feed>

