martes, 11 de agosto de 2009

Module 5: Implementing High Availability in a Campus Environment Parte3

5.3 Configuring Layer 3 Redundancy with VRRP and GLBP


5.3.1 Describing Virtual Router Redundancy

Like HSRP, Virtual Router Redundancy Protocol (VRRP) allows a group of routers to form a single virtual router. In an HSRP or VRRP group, one router is elected to handle all requests sent to the virtual IP address. With HSRP, this is the active router. An HSRP group has one active router, at least one standby router, and perhaps many listening routers. A VRRP group has one master router and one or more backup routers. The LAN workstations are then configured with the address of the virtual router as their default gateway.

VRRP differs from HSRP in the following ways:

  • VRRP is an IEEE standard (RFC 2338) for router redundancy; HSRP is a Cisco-proprietary protocol.

  • The virtual router represents a group of routers, known as a VRRP group or virtual router group.

  • The active router is referred to as the master virtual router.

  • The master virtual router may have the same IP address as the virtual router group.

  • Multiple routers can function as backup routers.

  • VRRP is supported on Ethernet, Fast Ethernet, and Gigabit Ethernet interfaces, and with Multiprotocol Label Switching (MPLS), virtual private networks (VPNs), and VLANs.

In Figure , routers A, B, and C are members of a VRRP group. The IP address of the virtual router is the same as that of the LAN interface of router A (10.0.0.1). Router A is responsible for forwarding packets sent to this IP address.

The clients have a gateway address of 10.0.0.1. Routers B and C are backup routers. If the master router fails, the backup router with the highest priority becomes the master router. When router A recovers, it resumes the role of master router.

VRRP provides redundancy for the real IP address of a router or for a virtual IP address shared among the VRRP group members. If a real IP address is used, the router with that address becomes the master. If a virtual IP address is used, the master is the router with the highest priority. The master router uses VRRP messages to inform group members that it is the master.



5.3.2 Identifying the VRRP Operations Process


Figure shows a LAN topology in which VRRP is configured so that routers A and B share the load of being the default gateway for clients 1 through 4. Routers A and B act as backup virtual routers to one another should either one fail.

In this example, two virtual router groups are configured. For virtual router 1, router A is the owner of IP address 10.0.0.1, and therefore the master virtual router for clients configured with that default gateway address. Router B is the backup virtual router to router A.

For virtual router 2, router B is the owner of IP address 10.0.0.2 and is the master virtual router for clients configured with the default gateway IP address of 10.0.0.2. Router A is the backup virtual router to router B.

Given that the IP address of the VRRP group is that of a physical interface on one of the group members, the router owning that address is the master in the group. Its priority is set to 255. Backup router priority values can range from 1 to 254; the default is 100. A priority value of 0 indicates that the current master has stopped participating in VRRP. This setting is used to trigger backup routers to transition quickly to the master without having to wait for the current master to time out.

With VRRP, only the master sends advertisements (the equivalent of HSRP hellos). Advertisements are sent on multicast 224.0.0.18 protocol number 112 at a default interval of 1 second.

When the master becomes unavailable, the dynamic failover uses three timers: the advertisement interval, the master down interval, and the skew time.

  • The advertisement interval is the time between advertisements in seconds. The default is 1 second.

  • The master down interval is the number of seconds for the backup to declare the master down. The default is 3 x advertisement interval + skew time.

  • The skew time, (256 - priority) / 256 ms, ensures that the backup router with the highest priority becomes the new master.

Figure lists the steps involved in the VRRP transition.

Note:
If the VRRP master has an orderly shutdown, it sends an advertisement with a priority of 0. This priority setting then triggers the backup router to take over quicker by waiting only the skew time instead of the master down interval.


5.3.3 Configuring VRRP

VRRP is supported on select Cisco Catalyst platforms and can be configured using the commands in Figure .

Figure describes the VRRP command parameters.

Figure describes how to configure VRRP.

Example: Implementing VRRP

SwitchA(config)#interface vlan10
SwitchA(config-if)#ip address 10.1.10.5 255.255.255.0
SwitchA(config-if)#vrrp 10 ip 10.1.10.1
SwitchA(config-if)#vrrp 10 priority 150
SwitchA(config-if)#vrrp 10 timer advertise 4
SwitchB(config)#interface vlan10
SwitchB(config-if)#ip address 10.1.10.6 255.255.255.0
SwitchB(config-if)#vrrp 10 ip 10.1.10.1
SwitchB(config-if)#vrrp 10 priority 100
SwitchB(config-if)#vrrp 10 timer advertise 4

5.3.4 Describing GLBP


While HSRP and VRRP provide gateway resiliency, the upstream bandwidth is not used for the standby members of the redundancy group while the device is in standby mode. Only the active router for HSRP and VRRP groups forwards traffic for the virtual MAC. Resources associated with the standby router are not fully utilized. Some load balancing can occur by creating multiple groups and assigning multiple default gateways, but this configuration creates an administrative burden.

Cisco designed the Gateway Load Balancing Protocol (GLBP) to allow automatic selection, simultaneous use of multiple gateways, and automatic failover between those gateways. Multiple routers share the load of frames that, from a client perspective, are sent to a single default gateway address.

With GLBP, resources can be fully utilized without the administrative burden of configuring multiple groups and managing multiple default gateway configurations as is required with HSRP and VRRP.

GLBP has the following functions:

  • Active virtual gateway (AVG): Members of a GLBP group elect one gateway to be the AVG for that group. Other group members provide backup for the AVG if the AVG becomes unavailable. The AVG assigns a virtual MAC address to each member of the group.

  • Active virtual forwarder (AVF): Each gateway assumes responsibility for forwarding packets sent to the virtual MAC address assigned to it by the AVG. These gateways are known as AVFs for their virtual MAC address.

  • Communication: GLBP members communicate with each other using hello messages sent every 3 seconds to the multicast address 224.0.0.102, User Datagram Protocol (UDP) port 3222.

GLBP has the following features:

  • Load sharing: Traffic from LAN clients can be shared by multiple routers.

  • Multiple virtual routers: Up to 1,024 virtual routers (GLBP groups) can be on each physical interface of a router, and there can be up to four virtual forwarders per group.

  • Preemption: You can preempt an AVG with a higher priority backup virtual gateway. Forwarder preemption works in a similar way, except that it uses weighting instead of priority and is enabled by default.

  • Efficient resource utilization: Any router in a group can serve as a backup, which eliminates the need for a dedicated backup router because all available routers can support network traffic.

GLBP provides upstream load sharing by utilizing the redundant uplinks simultaneously. It uses link capacity efficiently, thus providing peak-load traffic coverage. By making use of multiple available paths upstream from the routers or Layer 3 switches running GLBP, output queues may also be reduced.

HSRP and VRRP use only a single path; other paths are idle, unless multiple groups and gateways are configured. The single path may encounter higher output queue rates during peak times, which leads to lower performance from higher jitter rates. The impact of jitter is lessened and overall performance is improved with GLBP, because more upstream bandwidth is available and additional upstream paths are used.



5.3.5 Identifying the GLBP Operations Process


GLBP allows automatic selection and simultaneous use of all available gateways in the group. The members of a GLBP group elect one gateway to be the AVG for that group. Other members of the group provide backup for the AVG if it becomes unavailable. The AVG assigns a virtual MAC address to each member of the GLBP group. All routers become AVFs for frames addressed to that virtual MAC address. As clients send Address Resolution Protocol (ARP) requests for the address of the default gateway, the AVG sends these virtual MAC addresses in the ARP replies. A GLBP group can have up to four group members.

GLBP supports the following operational modes for load balancing traffic across multiple default routers servicing the same default gateway IP address:

  • Weighted load-balancing algorithm: The amount of load directed to a router is dependent upon the weighting value advertised by that router.

  • Host-dependent load-balancing algorithm: A host is guaranteed to use the same virtual MAC address as long as that virtual MAC address is participating in the GLBP group.

  • Round-robin load-balancing algorithm: As clients send ARP requests to resolve the MAC address of the default gateway, the reply to each client contains the MAC address of the next possible router in round-robin fashion. All routers’ MAC addresses take turns being included in address resolution replies for the default gateway IP address.

GLBP automatically manages the virtual MAC address assignment, determines who handles the forwarding, and ensures that each station has a forwarding path for failures to gateways or tracked interfaces. If failures occur, the load-balancing ratio is adjusted among the remaining AVFs so that resources are used in the most efficient way.

As shown in Figure , GLBP attempts to balance traffic on a per-host basis using the round-robin algorithm.

Figure describes how GLBP balances traffic using the round-robin algorithm.

In Figure , clients A and B have each resolved a different MAC address for the default gateway, so they send their routed traffic to separate routers, although they both have the same default gateway address configured. Each GLBP router is an AVF for the virtual MAC address to which it has been assigned.

Like HSRP, GLBP can be configured to track interfaces. In Figure , the WAN link from router R1 is lost, and GLBP detects the failure.

Because interface tracking was configured on R1, the job of forwarding packets for virtual MAC address 0000.0000.0001 is taken over by the secondary virtual forwarder for the MAC, which is router R2. Therefore, the client sees no disruption of service nor does it need to resolve a new MAC address for the default gateway.

GLBP is supported on select Cisco Catalyst platforms. Figure illustrates the GLBP interface commands. Figure describes the command parameters. Figure describes the steps needed to configure GLBP.

The following example configures GLBP on two multilayer switches:

SwitchA(config)#interface vlan7
SwitchA(config-if)#ip address 10.1.7.5 255.255.255.0
SwitchA(config-if)#glbp 7 ip 10.1.7.1
SwitchA(config-if)#glbp 7 priority 150
SwitchA(config-if)#glbp 7 timers msec 250 msec 750
SwitchB(config)#interface vlan7
SwitchB(config-if)#ip address 10.1.7.6 255.255.255.0
SwitchB(config-if)#glbp 7 ip 10.1.7.1
SwitchB(config-if)#glbp 7 priority 100
SwitchB(config-if)#glbp 7 timers msec 250 msec 750
SwitchA#show glbp 7
Vlan7 - Group 7
State is Active
2 state changes, last state change 23:50:33
Virtual IP address is 10.1.7.1
Hello time 250 msec, hold time 750 msec
Next hello sent in 40 msecs
Redirect time 600 sec, forwarder time-out 7200 sec
Authentication text "stringabc"
Preemption enabled, min delay 60 sec
Active is local
Standby is unknown
Priority 254 (configured)
Weighting 105 (configured 110), thresholds: lower 95, upper 105
Track object 2 state Down decrement 5
Load balancing: host-dependent
There is 1 forwarder (1 active)
Forwarder 1
State is Active
1 state change, last state change 23:50:15
MAC address is 0007.b400.0101 (default)
Owner ID is 0005.0050.6c08
Redirection enabled
Preemption enabled, min delay 60 sec

5.4 High Availability Lab Exercise

5.4.1 Lab 5-1 Hot Standby Router Protocol


Lab Activity

Lab Exercise: Lab 5-1 Hot Standby Router Protocol

Configure inter-VLAN routing with HSRP to provide redundant, fault tolerant routing to the internal network.

Summary


Device, link, or hardware component redundancy at strategic points in the network leads to high availability. Hot Standby Router Protocol (HSRP) provides router redundancy to network hosts and can be optimized in several ways. Virtual Router Redundancy Protocol (VRRP) and Gateway Load Balancing Protocol (GLBP) were derived from HSRP and provide additional redundancy features.

Module 5: Implementing High Availability in a Camp...Parte2

5.2 Optimizing HSRP


5.2.1 Describing HSRP Optimization Options

The options illustrated in Figures and make it possible to optimize HSRP operation in the campus network.


Each standby group has its own active and standby routers. The network administrator can assign a priority value to each router in a standby group, allowing the administrator to influence the active and standby router selection.

To set the priority value of a router (default is 100), enter this command in interface configuration mode:

Switch(config-if)#standby group-number priority priority-value

Figure describes the variables for the standby command.

During the election process, the router with the highest priority in an HSRP group becomes the active router. In the case of a tie, the router with the highest configured IP address is chosen.

To reinstate the default standby priority value, use the no standby priority command.

The following example states that interface VLAN10 has a priority value of 150 in HSRP group 1. If this priority value is the highest number in that HSRP group, the routing device on which this interface resides is the active router for that group.

Switch#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.32 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 ip 172.16.10.110

The standby router automatically assumes the active router role when the active router fails or is removed from service. This new active router remains the forwarding router, even if a former active router with a higher priority regains service in the network.

A former active router can be configured to resume the forwarding router role from a router with a lower priority by using the following command in interface configuration mode:

Switch(config-if)#standby [group-number] preempt [{delay} [minimum delay] [sync delay]]

When the standby preempt command is issued, the interface changes to the appropriate state.

Note:
If the routers do not have preempt configured, a router that boots up significantly faster than the others in the standby group becomes the active router, regardless of the configured priority.

To remove the interface from preemptive status, use the no standby group preempt command.

The following example states that interface VLAN10 is configured to resume its role as the active router in HSRP group 1, assuming that interface VLAN10 on this router has the highest priority in that standby group.

Switch#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.82 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 preempt
standby 1 ip 172.16.10.110

HSRP hello messages are transmitted constantly by the active and standby HSRP routers and during elections by all HSRP-enabled routers. The hello message contains the priority of the router, along with the hello time and hold time values. The hello time is the interval between the hello messages that the router sends. The hold time is the amount of time that the current hello message is considered valid. The default hello and hold times are 3 and 10 seconds, respectively, which means failover time could be as much as 10 seconds for clients to start communicating with the new default gateway. In some cases, this interval may be excessive for application support.

You can change the default values of the timers to milliseconds to accommodate subsecond failovers. Lowering the hello timer results in increased traffic for hello messages and should be used cautiously. The hold time should be at least three times the value of the hello time.

To change the timers, enter this command in interface configuration mode:

Switch(config-if)#standby group-number timers [msec] hellotime holdtime
Note:
Hello and dead timers intervals must be identical for all devices within an HSRP group.

Figure describes the command options.

To reinstate the default values, use the no standby group timers command.

In some situations, the status of an interface directly affects which router needs to become the active router. This is particularly true when each of the routers in an HSRP group has a different path to resources within the campus network.

In Figure , routers A and B reside in one building, and they each support a Gigabit Ethernet link to the other building. Router A has the higher priority and is the active forwarding router for standby group 1. Router B is the standby router for that group. Routers A and B are exchanging hello messages through their E0 interfaces.


The Gigabit Ethernet link between the active forwarding router for the standby group and the other building experiences a failure.
If HSRP is not enabled, router A would detect the failed link and send an ICMP redirect to router B. However, when HSRP is enabled, ICMP redirects are disabled. Therefore, neither router A nor the virtual router sends an ICMP redirect. In addition, although the G1 interface on router A is no longer functional, router A still communicates hello messages out interface E0, indicating that router A is still the active router. Packets sent to the virtual router for forwarding to headquarters may not be routed.

It is possible that a dynamic routing protocol (if in use) would detect the link failure and then update the routing tables of the routers. However, traffic would then be sent by hosts to the active HSRP router and forwarded back across the Ethernet segment to the standby HSRP router where the functional Gigabit link would be used.


Interface tracking enables the priority of a standby group router to be automatically adjusted based on the availability of that router’s interfaces. When a tracked interface becomes unavailable, the HSRP priority of the router is decreased. When properly configured, the HSRP tracking feature ensures that a router with an unavailable key interface relinquishes the active router role.

In this example, the E0 interface on router A tracks the G1 interface. If the link between the G1 interface and the other building fails, the router automatically decrements the priority on the E0 interface and stops transmitting hello messages out that interface. Router B assumes the active router role when no hello messages are detected for the hold time period. The hello packet has a field that indicates the current priority of the HSRP-enabled interface. Router A changes this field to indicate its priority for subsequent hellos.

To configure HSRP tracking, enter the command in Figure in interface configuration mode.

To disable interface tracking, use the no standby group track command.

The command to configure HSRP tracking on a multilayer switch is the same as on the external router, except that the interface type can be identified as a switch virtual interface or as a physical interface.

Multiple tracking statements may be applied to an interface, which is useful if the intent is for the currently active HSRP interface to relinquish its status only when two (or more) tracked interfaces fail।


5.2.2 Tuning HSRP Operations

You can adjust HSRP timers to tune the performance of HSRP on distribution devices, thereby increasing their resilience and reliability in routing packets off the local VLAN.

You can set the HSRP hello and hold times to millisecond values so that HSRP failover occurs in less than 1 second. For example:

Switch(config-if)#standby 1 timers msec 200 msec 750

Remember that the lower the hello timer is, the greater the hello traffic.

Preemption is an important feature of HSRP, because it allows the primary router to resume the active role when the router comes back online after a failure or maintenance event. Preemption forces a predictable routing path for the VLAN during normal operations and ensures that the Layer 3 forwarding path for a VLAN parallels the Layer 2 Spanning Tree Protocol (STP) forwarding path whenever possible.

You should always use preemption when tracking interfaces. In the previous example, when the Gigabit link came back up, router A’s priority would increase, but without preemption, it would not become the HSRP active router until router B had a state change.

When a preempting distribution switch is rebooted, HSRP preempt communication should not begin until the distribution switch has established full connectivity to the rest of the network. This allows routing protocol convergence to occur more quickly once the preferred router is in an active state. To accomplish this, measure the system boot time and set the HSRP preempt delay to a value 50 percent greater than the boot time. This ensures that the primary distribution switch establishes full connectivity to the network before HSRP communication occurs.

For example, if the boot time for the distribution device is 120 seconds, the preempt configuration would be as follows:

standby 1 preempt
standby 1 preempt delay minimum 180


5.2.3 Describing Load Sharing

With a single HSRP group on a subnet, the active router is forwarding all the packets off that subnet while the standby router is not forwarding any packets. To facilitate load sharing, a single router may be a member of multiple HSRP groups on the same segment. Multiple standby groups further enable redundancy and load sharing. While a router is actively forwarding traffic for one HSRP group, the router can be in standby or listen state for another group. Each standby group emulates a single virtual router. There can be up to 255 standby groups on any LAN, but the maximum number of standby groups need be no more than the number of routers on a segment. In most cases, two standby groups are sufficient.

CAUTION:

Increasing the number of groups in which a router participates increases the load on the router, which can impact the router’s performance.

In Figure , both router A and B are members of groups 1 and 2. Router A is the active forwarding router for group 1 and the standby router for group 2. Router B is the active forwarding router for group 2 and the standby router for group 1.

The following example shows how multiple HSRP groups can be configured on the same segment to facilitate load sharing. To be useful, half the hosts on the segment need to use 172.16.10.110 as a default gateway, while the other half need to use 172.16.10.120.

RouterA#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.32 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 ip 172.16.10.110
standby 2 priority 50
standby 2 ip 172.16.10.120
RouterB#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.33 255.255.255.0
no ip redirects
standby 1 priority 50
standby 1 ip 172.16.10.110
standby 2 priority 150
standby 2 ip 172.16.10.120
RouterA#show standby brief
P indicates configured to preempt.
|
Interface Grp Prio P State Active Standby Virtual IP
Vl10 1 150 Active local 172.16.10.33 172.16.10.110
Vl10 2 50 Standby 172.16.10.33 local 172.16.10.120

Routers can simultaneously provide redundant backup and perform load sharing across different IP subnets.

In Figure , two HSRP-enabled routers participate in two separate VLANs, using ISL or 802.1Q. Running HSRP over trunks allows users to configure redundancy among multiple routers that are configured as front ends for VLAN IP subnets. By configuring HSRP over trunks, users can eliminate situations in which a single point of failure causes traffic interruptions. This feature provides some improvement in overall networking resilience by providing load balancing and redundancy capabilities between subnets and VLANs.

For a VLAN, configure the same device to be both the spanning tree root and the HSRP active router. This approach ensures that the Layer 2 forwarding path leads directly to the Layer 3 active router, thereby achieving maximum load balancing efficiency on the routers and trunks.

A standby group, an IP address, and a single well-known MAC address with a unique group identifier should be allocated to the group for each VLAN. Although up to 255 standby groups can be configured, the number of group identifiers used should be kept to a minimum. If you are configuring two distribution layer switches, you typically need only two standby group identifiers.

The following example shows how multiple HSRP groups can be configured on two HSRP-enabled routers participating in two separate VLANs

RouterB#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.32 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 ip 172.16.10.110
interface Vlan20
ip address 172.16.20.32 255.55.255.0
no ip redirects
standby 2 priority 50
standby 2 ip 172.16.20.120

RouterB#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.33 255.255.255.0
no ip redirects
standby 1 priority 50
standby 1 ip 172.16.10.110
interface Vlan20
ip address 172.16.20.33 255.255.255.0
no ip redirects
standby 2 priority 150
standby 2 ip 172.16.20.120


5.2.4 HSRP Debug Commands

The commands in Figure are used to debug HSRP operations.

Figure describes the debug commands.


5.2.5 Debugging HSRP Operations

The Cisco IOS implementation of HSRP supports the debug command, which displays HSRP state changes and information regarding the transmission and receipt of HSRP packets. To enable HSRP debugging, enter the following command in privileged EXEC mode:

Switch#debug standby

Figure provides a description of debug standby fields.

CAUTION:

Because debugging output is assigned high priority in the CPU process, this command can render the system unusable.

Example: Debugging with Two Active Routers

The example in Figure displays output on distribution router 1DSW1. Router 1DSW1 is also receiving an HSRP hello from 172.16.1.112 for the same VLAN and same virtual IP address but with a different standby group number. Hence, both routers are active for the same virtual IP address.

The debug standby command is being used to troubleshoot the problem. The standby group number is not consistent, so the two routers have not formed a standby group.

Example: Debugging Active Router Negotiation

This example displays the debug standby command output as the 1DSW1 router with IP address 172.16.1.111 initializes and negotiates for the role of active router.

*Mar 8 20:34:10.221: SB11: Vl11 Init: a/HSRP enabled
*Mar 8 20:34:10.221: SB11: Vl11 Init -> Listen
*Mar 8 20:34:20.221: SB11: Vl11 Listen: c/Active timer expired (unknown)
*Mar 8 20:34:20.221: SB11: Vl11 Listen -> Speak
*Mar 8 20:34:20.221: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:23.101: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:25.961: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:28.905: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Speak: d/Standby timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is local
*Mar 8 20:34:30.221: SB11: Vl11 Speak -> Standby
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Standby: c/Active timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Active router is local
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is unknown, was local
*Mar 8 20:34:30.221: SB11: Vl11 Standby -> Active
*Mar 8 20:34:30.221: %STANDBY-6-STATECHANGE: Vlan11 Group 11 state Standby -> Active
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115

To disable the debugging feature, use either the no debug standby or the no debug all command.

Example: Debugging First and Only Router on Subnet

Because 1DSW1 (172.16.11.111) is the only router on the subnet, and it is not configured for preempt, it goes through five HSRP states before becoming the active router. Notice that at Mar 8 20:34:10.221 the interface comes up, and 1DSW1 enters the listen state. The router stays in listen state for a hold time of 10 seconds. 1DSW1 then goes into speak state at Mar 8 20:34:20.221 for 10 seconds. When the router is speaking, it sends its state out every 3 seconds, according to its hello interval. After 10 seconds in speak state, the router has determined that there is no standby router and enters the standby state at Mar 8 20:34:30.221. The router has also determined that there is not an active router; therefore, it immediately enters active state at Mar 8 20:34:30.221. From that point on, the active router sends its active state hello message every 3 seconds. Because there are no other routers on this broadcast domain, no hellos are being received.

1DSW1(config)#interface vlan 11
1DSW1(config-if)#no shut

*Mar 8 20:34:08.925: %SYS-5-CONFIG_I: Configured from console by console
*Mar 8 20:34:10.213: %LINK-3-UPDOWN: Interface Vlan11, changed state to up
*Mar 8 20:34:10.221: SB: Vl11 Interface up
*Mar 8 20:34:10.221: SB11: Vl11 Init: a/HSRP enabled
*Mar 8 20:34:10.221: SB11: Vl11 Init -> Listen
*Mar 8 20:34:11.213: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan11, changed state to up
*Mar 8 20:34:20.221: SB11: Vl11 Listen: c/Active timer expired (unknown)
*Mar 8 20:34:20.221: SB11: Vl11 Listen -> Speak
*Mar 8 20:34:20.221: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:23.101: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:25.961: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:28.905: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Speak: d/Standby timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is local
*Mar 8 20:34:30.221: SB11: Vl11 Speak -> Standby
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Standby: c/Active timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Active router is local
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is unknown, was local
*Mar 8 20:34:30.221: SB11: Vl11 Standby -> Active
*Mar 8 20:34:30.221: %STANDBY-6-STATECHANGE: Vlan11 Group 11 state Standby -> Active
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 8 20:34:33.085: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 8 20:34:36.025: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 8 20:34:38.925: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115

Example: Router Without Preempt Coming Up

Router 1DSW1 (172.16.11.111) is configured with a priority of 100, which is higher than the priority of 50 of the current active router, 1DSW2 (172.16.11.112). Router 1DSW1 is not configured with preempt, so even though it has a higher priority, it does not immediately become the active router. After router 1DSW1 goes through the HSRP initialization states, it will come up as the standby router.

1DSW1(config)#interface vlan 11
1DSW1(config-if)#no shut

*Mar 1 00:12:16.871: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:16.871: SB11: Vl11 Active router is 172.16.11.112
*Mar 1 00:12:16.891: %SYS-5-CONFIG_I: Configured from console by console
*Mar 1 00:12:18.619: %LINK-3-UPDOWN: Interface Vlan11, changed state to up
*Mar 1 00:12:18.623: SB: Vl11 Interface up
*Mar 1 00:12:18.623: SB11: Vl11 Init: a/HSRP enabled
*Mar 1 00:12:18.623: SB11: Vl11 Init -> Listen
*Mar 1 00:12:19.619: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan11, changed state to up
*Mar 1 00:12:19.819: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:19.819: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:22.815: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:22.815: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:25.683: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:25.683: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:28.623: SB11: Vl11 Listen: d/Standby timer expired (unknown)
*Mar 1 00:12:28.623: SB11: Vl11 Listen -> Speak
*Mar 1 00:12:28.623: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:28.659: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:28.659: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:31.539: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:31.539: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:31.575: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:34.491: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:34.491: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:34.547: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:37.363: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:37.363: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:37.495: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:38.623: SB11: Vl11 Speak: d/Standby timer expired (unknown)
*Mar 1 00:12:38.623: SB11: Vl11 Standby router is local
*Mar 1 00:12:38.623: SB11: Vl11 Speak -> Standby
*Mar 1 00:12:38.623: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:40.279: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:40.279: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:41.551: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:43.191: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:43.191: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:44.539: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:46.167: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:46.167: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:47.415: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:49.119: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:49.119: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:50.267: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115

Example: Router with Preempt Coming Up

Router 1DSW1 (172.16.11.11) is configured with a priority of 100, which is higher than the priority of the active router, 1DSW2 (172.16.11.112). 1DSW1 is also configured with preempt. At Mar 1 00:16:43.099, VLAN11 on 1DSW1 comes up and transitions into the listen state. At Mar 1 00:16:43.295, 1DSW1 receives a hello message from the active router (1DSW2). 1DSW1 determines that the active router has a lower priority. At Mar 1 00:16:43.295, 1DSW1 immediately sends out a coup message indicating that 1DSW1 is transitioning to the active router. 1DSW2 enters the speak state and eventually becomes the standby router.

1DSW1(config)#interface vlan 11
1DSW1(config-if)#no shut

*Mar 1 00:16:41.295: %SYS-5-CONFIG_I: Configured from console by console
*Mar 1 00:16:43.095: %LINK-3-UPDOWN: Interface Vlan11, changed state to up
*Mar 1 00:16:43.099: SB: Vl11 Interface up
*Mar 1 00:16:43.099: SB11: Vl11 Init: a/HSRP enabled
*Mar 1 00:16:43.099: SB11: Vl11 Init -> Listen
*Mar 1 00:16:43.295: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:16:43.295: SB11: Vl11 Active router is 172.16.11.112
*Mar 1 00:16:43.295: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:16:43.295: SB11: Vl11 Active router is local, was 172.16.11.112
*Mar 1 00:16:43.295: SB11: Vl11 Coup out 172.16.11.111 Listen pri 100 ip 172.16.11.115
Mar 1 00:16:43.295
*Mar 1 00:16:43.299: %STANDBY-6-STATECHANGE: Vlan11 Group 11 state Listen -> Active
*Mar 1 00:16:43.299: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:43.303: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:44.095: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan11, changed state to up
*Mar 1 00:16:46.187: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:46.207: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:49.095: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:49.195: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:52.079: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:52.147: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:53.303: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:16:53.303: SB11: Vl11 Standby router is 172.16.11.112
*Mar 1 00:16:55.083: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:56.231: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:16:58.023: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:59.223: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:17:00.983: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:17:02.211: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:17:03.847: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115


lunes, 10 de agosto de 2009

Module 5: Implementing High Availability in a Campus Environment

Module 5: Implementing High Availability in a Campus Environment

Module Overview

A network with high availability provides alternative means by which all infrastructure paths and key servers can be accessed at all times. The Hot Standby Routing Protocol (HSRP) is one of those software features that can be configured to provide Layer 3 redundancy to network hosts. HSRP optimization provides immediate or link-specific failover and a recovery mechanism. Virtual Router Redundancy Protocol (VRRP) and Gateway Load Balancing Protocol (GLBP) evolved from HSRP, providing additional Layer 3 redundancy options. VRRP is a vendor-neutral Layer 3 redundancy protocol and GLBP is a Cisco-proprietary improvement to HSRP that provides intrinsic load balancing.


5.1 Configuring Layer 3 Redundancy with HSRP

5.1.1 Describing Routing Issues

When a default gateway is configured on a device, there is usually no means by which to configure a secondary gateway, even if a second route exists to carry packets off the local segment.

For example, primary and secondary paths between the Building Access and Building Distribution submodules provide continuous access if of a link fails at the Building Access layer. Primary and secondary paths between the Building Distribution and Building Core layers provide continuous operations if a link fails at the Building Distribution layer.

In Figure , router A is responsible for routing packets for subnet A, and router B is responsible for handling packets for subnet B. If router A becomes unavailable, routing protocols can quickly and dynamically converge and determine that router B will now transfer packets that would otherwise have gone through router A. However, most workstations, servers, and printers do not receive this dynamic routing information.

End devices are typically configured with a single default gateway IP address that does not change when network topology changes occur. If the router whose IP address is configured as the default gateway fails, the local device is unable to send packets off the local network segment, effectively disconnecting it from the rest of the network. Even if a redundant router that could serve as a default gateway for that segment exists, there is no dynamic method by which these devices can determine the address of a new gateway.

Cisco IOS software runs proxy Address Resolution Protocol (ARP) to enable hosts that have no knowledge of routing options to obtain the MAC address of a gateway that is able to forward packets off the local subnet. For example, if the proxy ARP router receives an ARP request for an IP address that it knows is not on the same interface as the request sender, it generates an ARP reply packet with its local MAC address as the destination MAC address of the IP address being resolved. The host that sent the ARP request sends all packets destined for the resolved IP address to the MAC address of the router. The router then forwards the packets toward the intended host, perhaps repeating this process along the way. Proxy ARP is enabled by default.

With proxy ARP, the end-user station behaves as if the destination device were connected to its own network segment. If the responsible router fails, the source end station continues to send packets for that IP destination to the MAC address of the failed router, and the packets are therefore discarded.

Eventually, the proxy ARP MAC address ages out of the workstation’s ARP cache. The workstation may eventually acquire the address of another proxy ARP failover router, but it cannot send packets off the local segment during this failover time.

For further information on proxy ARP, refer to RFC 1027.


5.1.2 Identifying the Router Redundancy Process

With this type of router redundancy and , a set of routers works in concert to present the illusion of a single virtual router to the hosts on the LAN. By sharing an IP address and a MAC (Layer 2) address, two or more routers can act as a single “virtual” router. The virtual router’s IP address is configured as the default gateway for the workstations on a specific IP segment. When frames are to be sent from the workstation to the default gateway, the workstation uses ARP to resolve the MAC address associated with the IP address of the default gateway. ARP returns the MAC address of the virtual router. Frames sent to the virtual router’s MAC address can then be physically processed by any active or standby router that is part of that virtual router group.

Two or more routers use a protocol to determine which physical router is responsible for processing frames sent to the MAC or IP address of a single virtual router. Host devices send traffic to the address of the virtual router. The physical router that forwards this traffic is transparent to the end stations. This redundancy protocol provides the mechanism for determining which router should take the active role in forwarding traffic and determining when that role must be assumed by a standby router. The transition from one forwarding router to another is transparent to the end devices.

Figure describes the steps that take place when the forwarding router fails.


5.1.3 Describing HSRP

Hot Standby Router Protocol (HSRP) defines a standby group, with each router assigned to a specific role within the group. HSRP provides gateway redundancy by sharing IP and MAC addresses between redundant gateways. The protocol transmits virtual MAC and IP address information between two routers belonging to the same HSRP group.

Figure describes some of the terms used with HSRP.

An HSRP group consists of the following:

  • Active router

  • Standby router

  • Virtual router

  • Other routers

HSRP active and standby routers send hello messages to the multicast address 224.0.0.2 using UDP port 1985.


5.1.4 Identifying HSRP Operations

All the routers in an HSRP group have specific roles and interact in prescribed ways.

The virtual router is simply an IP and MAC address pair that end devices have configured as their default gateway. The active router processes all packets and frames sent to the virtual router address. The virtual router does not process physical frames and exists in software only.

Within an HSRP group, one router is elected to be the active router. The active router physically forwards packets sent to the MAC address of the virtual router.

The active router responds to traffic for the virtual router. If an end station sends a packet to the virtual router MAC address, the active router receives and processes that packet. If an end station sends an ARP request with the virtual router IP address, the active router replies with the virtual router MAC address.

In this example, router A assumes the active role and forwards all frames addressed to the well-known MAC address of 0000.0c07.acxx, where xx is the HSRP group identifier.

The IP address and corresponding MAC address of the virtual router are maintained in the ARP table of each router in the HSRP group. As shown in the Figure , the show ip arp command displays the ARP cache on a multilayer switch.

Figure describes the output for the show ip arp command.

In the example illustrated in Figure , the output displays an ARP entry for a router that is a member of HSRP group 1 in VLAN10. The virtual router for VLAN10 is identified as 172.16.10.110. The well-known MAC address that corresponds to this IP address is 0000.0c07.ac01, where 01 is the HSRP group identifier for group 1. The HSRP group number is the standby group number (1) converted to hexadecimal (01).

The HSRP standby router monitors the operational status of the HSRP group and quickly assumes packet-forwarding responsibility if the active router becomes inoperable. Both the active and standby routers transmit hello messages to inform all other routers in the group of their role and status. The routers use destination multicast address 224.0.0.2 with UDP port 1985 for these messages. The source address is the interface IP address of the sending router.

An HSRP group may contain other routers that are group members but are not in an active or standby state. These routers monitor the hello messages sent by the active and standby routers to ensure that active and standby routers exist for the HSRP group of which they are a member. These routers do forward packets addressed to their own specific IP addresses, but they do not forward packets addressed to the virtual router. These routers issue speak messages at every hello interval time.

Figure describes some of the terms used with HSRP.

When the active router fails, the other HSRP routers stop seeing hello messages from the active router. The standby router then assumes the role of the active router. If other routers are participating in the group, they contend to be the new standby router.

If both the active and standby routers fail, all routers in the group contend for the active and standby router roles.

Because the new active router assumes both the IP and MAC addresses of the virtual router, the end stations see no disruption in service. The end-user stations continue to send packets to the virtual router MAC address, and the new active router delivers the packets to the destination.


5.1.5 Describing HSRP States

A router in an HSRP group can be in one of the following states: initial, learn, listen, speak, standby, or active.

Figure describes the different HSRP states.

When a router exists in one of these states, it performs the actions required for that state. Not all HSRP routers in the group transition through all states. For example, if there are three routers in the group, the router that is not the standby or active router remains in the listen state.

All routers begin in the initial state, indicating that HSRP is not running. This state is entered via a configuration change, such as when HSRP is disabled on an interface, or when an HSRP-enabled interface is first brought up, such as when the no shutdown command is issued.

After the initial state, the interface moves to the learn state. The interface is expecting to see HSRP packets and from these packets determine the virtual IP and active HSRP router for the group.

Once the interface has seen HSRP packets and determined the virtual IP, it moves to the listen state. The purpose of the listen state is to determine if there are already active or standby routers for the group. If the active and standby routers are functional, the interface remains in this state. However, if hellos are not seen from either router, the interface moves to the speak state.

In the speak state, the routers are actively participating in the election of the active router, standby router, or both. The routers look at each other’s hello packets to determine which router should assume which role.

Three timers are used in HSRP: active, standby, and hello. If a hello is not received from an active HSRP router within the active timer, the router transitions to a new HSRP state.

Figure describes the HSRP timers.

In the standby state , because the router is a candidate to become the next active router, it sends periodic hello messages. It also listens for hello messages from the active router. There can only be one standby router in the HSRP group.

In the active state , the router is currently forwarding packets that are sent to the virtual MAC address of the group. It also replies to ARP requests directed to the virtual router’s IP address. The active router sends periodic hello messages. There must be one active router in each HSRP group.


5.1.6 Describing HSRP Configuration Commands

Figure illustrates common HSRP configuration commands.

Figure describes the essential commands used to configure and verify HSRP.


5.1.7 Enabling HSRP


The following command enables HSRP on an interface:
Switch(config-if)#standby group-number ip ip-address

Figure describes the command parameters for configuring an HSRP group on an interface.

When HSRP is running, the end-user stations must not discover the actual MAC addresses of the routers in the standby group. Any protocol that informs a host of a router’s actual address must be disabled. Enabling HSRP on a Cisco router interface automatically disables Internet Control Message Protocol (ICMP) redirects on that interface, which ensures that the addresses of the participating HSRP routers are not discovered.

After the standby ip command is issued, the interface changes to the appropriate state, and the router issues an HSRP message.

To remove an interface from an HSRP group, enter the no standby group ip command.

The following example states that interface VLAN11 is a member of HSRP group 11, the virtual router IP address for the group is 172.16.11.115, and ICMP redirects are disabled. To verify the HSRP configuration, use the show running-config command:

Switch#show running-config
Building configuration...
Current configuration:!

interface Vlan11
ip address 172.16.11.113 255.255.255.0
no ip redirects
standby 11 ip 172.16.11.115
!

Another way to verify the HSRP configuration is with the show standby brief command, which displays abbreviated information about the current state of all HSRP operations on the device.

To display the status of the HSRP router, use one of these commands:

Switch#show standby [interface [group]] [active | init | listen | standby] [brief]

Switch#show standby delay [type-number]

If the optional interface parameters are not included, the show standby command displays HSRP information for all interfaces.

The following example shows the output of the show standby command:

Switch#show standby Vlan11 11
Vlan11 - Group 11
Local state is Active, priority 110
Hellotime 3 holdtime 10
Next hello sent in 00:00:02.944
Hot standby IP address is 172.16.11.115 configured
Active router is local
Standby router is 172.16.11.114 expires in 00:00:08
Standby virtual mac address is 0000.0c07.ac01

This is the output when you use the brief parameter:

Switch#show standby brief
Interface Grp Prio P State Active addr Standby addr Group addr
Vl11 11 110 Active local 172.16.11.114 172.16.11.115

Notice that the group address 172.16.11.115 is on the same subnet as the standby and active router IP addresses.