[j-nsp] ISIS between ERX 1440 and MX960
david.roy at orange-ftgroup.com
david.roy at orange-ftgroup.com
Thu May 19 14:43:18 EDT 2011
Hi
Thanks
1. yes
2. I tried but without success. I believe that the ISO MTU is less than the padded hello of the MX. I will try to set mtu of the gi 12/0 of the ERX to 1518 : I will update you if it works
Regards
David
David Roy
Orange - IP Domestic Backbone - TAC
Tel. +33(0)299876472
Mob. +33(0)685522213
Email. david.roy at orange-ftgroup.com
JNCIE-M/T #703 ; JNCIS-ENT
-----Message d'origine-----
De : Kaliraj [mailto:kalirajv at gmail.com]
Envoyé : jeudi 19 mai 2011 20:37
À : ROY David DTF/DERX
Cc : juniper-nsp at puck.nether.net
Objet : Re: [j-nsp] ISIS between ERX 1440 and MX960
hi david,
1. is the erx interface configured with an ip-address?
http://www.juniper.net/techpubs/software/erx/junose72/swconfig-ip-ipv6-igp/html/isis-config6.html#89040
says erx should have atleast one ip-addres/router-id configured.
2. if yes, then pls try if adjusting hello-padding attributes on both ends. it does look like mtu and padding issue. perhaps try adaptive/strict padding on junos side to see if there are mtu issues.
kaliraj
On Thu, May 19, 2011 at 10:24 AM, <david.roy at orange-ftgroup.com> wrote:
> Hi all,
>
> I'm trying to establish an ISIS L2 adjacency between an ERX (Junose is
> new for me) and 1 MX without success : I double checked the mtu,
> subnet, Area (not checked for L2), authentication key (I tried simple
> and MD5 types)
>
> The problem seems to be at the ERX side. Indeed, the MX receives well the IIH of the ERX and put its state to Init, then it sends an IIH to the ERX. At the ERX level, IIH is discarded (at the Interface level : Input Discard counter). I don't understand why. I guess there is a MTU issue with the hello padding process but I'm not sure.
>
> Config at the MX side
> ---------------------------
>
> ge-2/2/2.0
> {
> family iso;
> faimly inet address 10.1.1.1/30
> }
>
> lo0
> {
> family iso address 49.0001.xxx
> }
>
> protocol isis
> {
> level 2 {
> authentication-key sdjskdjskd;
> authentication-type md5;
> }
> interface ge-2/2/2.0 {
> level 1 disable;
> level 2 {
> hello-authetication-key FOO;
> hello-authetication-type md5;
> }
> }
>
>
> Config at the ERX side :
>
> router isis 1234
> is-type level-2-only
> net 49.0001.xxx
> domain-message-digest-key 1 hmac-md5 FOO passive-interface loopback50
>
>
> int gi 12/0
> ip router isis 1234
> isis circuit-type level-2-only
> isis message-digest-key 1 hmac-md5 FOO level-2
>
>
> I tried to monitor ISIS packet at the MX side. I noticed that the PDU length of the MX IIH is equal to 1492 and the ERX one is equal to 1497. Moreover, the protocol capabilities of the MX are IPv4 and IPv6 and for the ERX that are CLNP and IPv4.
>
> Any help would be most welcome.
>
> thanks
> Regards,
> David
>
>
>
> ********************************************************************************
> IMPORTANT.Les informations contenues dans ce message electronique y compris les fichiers attaches sont strictement confidentielles
> et peuvent etre protegees par la loi.
> Ce message electronique est destine exclusivement au(x) destinataire(s) mentionne(s) ci-dessus.
> Si vous avez recu ce message par erreur ou s il ne vous est pas destine, veuillez immediatement le signaler a l expediteur et effacer ce message
> et tous les fichiers eventuellement attaches.
> Toute lecture, exploitation ou transmission des informations contenues dans ce message est interdite.
> Tout message electronique est susceptible d alteration.
> A ce titre, le Groupe France Telecom decline toute responsabilite notamment s il a ete altere, deforme ou falsifie.
> De meme, il appartient au destinataire de s assurer de l absence de tout virus.
>
> IMPORTANT.This e-mail message and any attachments are strictly confidential and may be protected by law. This message is
> intended only for the named recipient(s) above.
> If you have received this message in error, or are not the named recipient(s), please immediately notify the sender and delete this e-mail message.
> Any unauthorized view, usage or disclosure ofthis message is prohibited.
> Since e-mail messages may not be reliable, France Telecom Group shall not be liable for any message if modified, changed or falsified.
> Additionally the recipient should ensure they are actually virus free.
> ********************************************************************************
>
>
> _______________________________________________
> juniper-nsp mailing list juniper-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/juniper-nsp
>
********************************************************************************
IMPORTANT.Les informations contenues dans ce message electronique y compris les fichiers attaches sont strictement confidentielles
et peuvent etre protegees par la loi.
Ce message electronique est destine exclusivement au(x) destinataire(s) mentionne(s) ci-dessus.
Si vous avez recu ce message par erreur ou s il ne vous est pas destine, veuillez immediatement le signaler a l expediteur et effacer ce message
et tous les fichiers eventuellement attaches.
Toute lecture, exploitation ou transmission des informations contenues dans ce message est interdite.
Tout message electronique est susceptible d alteration.
A ce titre, le Groupe France Telecom decline toute responsabilite notamment s il a ete altere, deforme ou falsifie.
De meme, il appartient au destinataire de s assurer de l absence de tout virus.
IMPORTANT.This e-mail message and any attachments are strictly confidential and may be protected by law. This message is
intended only for the named recipient(s) above.
If you have received this message in error, or are not the named recipient(s), please immediately notify the sender and delete this e-mail message.
Any unauthorized view, usage or disclosure ofthis message is prohibited.
Since e-mail messages may not be reliable, France Telecom Group shall not be liable for any message if modified, changed or falsified.
Additionally the recipient should ensure they are actually virus free.
********************************************************************************
More information about the juniper-nsp
mailing list