Import/Exporting iVRF routes in IPsec iVRF/FVRF environment

Hi,
I am currently terminating a number of IPsec VPNs into customers' 'inside' VRFs (iVRFs) with the 'classic' crypto-map applied in a separate Front-Door VRF (FVRF) on an ASR1k. I now want to export a VPN route from one iVRF into another VRF using MP-BGP. This works as expected in as far as the VPN prefix makes it into the BGP table, but not into the RIB - it would appear that this may be by design and a route with a next-hop in the FVRF (i.e. the VPN RRI route) cannot be exported from the VRF and imported into another VRF. Is there any workaround for this; the only one solution which looks like it might work is to import/export these routes using another VRF and back-to-back VASI interfaces, using ordinary BGP to leak routes. Another possible solution is also to use sVTIs instead of classic crypto (thus avoiding the RRI route), but this doesn't address the need to support classic crypto.
Cheers,
Matt

Hi,
I am currently terminating a number of IPsec VPNs into customers' 'inside' VRFs (iVRFs) with the 'classic' crypto-map applied in a separate Front-Door VRF (FVRF) on an ASR1k. I now want to export a VPN route from one iVRF into another VRF using MP-BGP. This works as expected in as far as the VPN prefix makes it into the BGP table, but not into the RIB - it would appear that this may be by design and a route with a next-hop in the FVRF (i.e. the VPN RRI route) cannot be exported from the VRF and imported into another VRF. Is there any workaround for this; the only one solution which looks like it might work is to import/export these routes using another VRF and back-to-back VASI interfaces, using ordinary BGP to leak routes. Another possible solution is also to use sVTIs instead of classic crypto (thus avoiding the RRI route), but this doesn't address the need to support classic crypto.
Cheers,
Matt

Similar Messages

  • Import/export route targets from E-BGP ?

    hi all,
    a newbie question again,
    can i import/export rte target in a vrf from/to ebgp session,
    in all my readings i only see samples from import/export with iBGP peering
    thanks for answer

    Yes you can do it this way as well, without the MP-EBGP peering between the both AS's RR's. (You have missed the multi-hop neighbor statement)
    This will achieve the RT exchange between the PE's, so next you will have to import that RT on the other side.
    Once you have the RT with the routes exchanged you will have VPN labels as well populated for the routes on the remote side.
    Now you will have to implement a method to assign an IGP label on top of the VPN label (this label should be for the PE's loopback of AS 100 who advertised this route to AS 200)
    In your case, you can use the send-label command at the ASBR's for the IGP route of the PE;s in their AS' with a label. For this you can redistribute IGP into BGP and again BGP into IGP (with a route-map matching only PE's loopback in their AS and the remote AS).
    So you will effectively have 2 labels to switch traffic between the AS's (IGP and the VPN label).
    HTH-Cheers,
    Swaroop

  • VRF Import/Export - how to filter routes

    Hi,
    Is there another way of filtering the routes you want to import into a vrf because the 'route-target export' and 'route-target import' imports ALL the routes tagged with the given 'asn:xx'. I wanted to have only selected routes imported from one vrf to another. Vrf 'import map' command does not work for me?
    Does filtering makes sense or practical at vrf-vrf level? Where do you use 'import map' command?
    thanks
    resti

    Hi Harold,
    Actually my needs are a little different. Instead of leaking between 2 VRFs, I need to leak to global. Have a default in my VRF that gets imported to global table.
    Goals:
    1. At hub and spoke both sites, let ISP connection run in a separate VRF. Gets a little extra security from internet.
    2. When ISP connection is active, let each site route its traffic out to internet directly. However when the local ISP connection fails, remove the default route that points to ISP so that OSPF learned default from the hub site routes all traffic to hub and puts on internet.
    What's working:
    DMVPN tunnels work fine across INET VRF.
    What's not working:
    1. The IP SLA tracked route leak to global VRF is not working. Traffic doesn't go out to internet directly using local connection.
    I followed following example for this configuration.
    http://www.cisco.com/c/en/us/support/docs/multiprotocol-label-switching-mpls/multiprotocol-label-switching-vpns-mpls-vpns/47807-routeleaking.html
    Any suggestions? Is it possible or supported configuration?
    Below is a diagram of my setup.
    Below is my relevant config snapshot. 2.2.2.1 is actually my another FW in front in the lab that does all NAT and provides internet connection to this lab.
    ip sla auto discovery
    ip sla 1
     icmp-echo 8.8.8.8 source-ip 2.2.2.2
     vrf INET
    ip sla schedule 1 life forever start-time now
    ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/1 2.2.2.1 track 1
    ip route vrf INET 0.0.0.0 0.0.0.0 2.2.2.1
    Lab-RTR#sh ip sla sumary
    IPSLAs Latest Operation Summary
    Codes: * active, ^ inactive, ~ pending
    ID           Type        Destination       Stats       Return      Last
                                               (ms)        Code        Run
    *1           icmp-echo   8.8.8.8           RTT=32      OK          4 seconds ago
    Lab-RTR#sh ip route | in 0.0.0.0
    Gateway of last resort is 10.254.2.99 to network 0.0.0.0
    O*E1  0.0.0.0/0 [110/221] via 10.254.2.99, 00:00:59, Tunnel2
    As you can see, its learning default from Tunnel instead of taking the static default.

  • Import/Export from Betacam SP to FCP

    I have been contacted to make minor edits to a program for broadcast. The program is on Betacam and I plan to import the footage using a Sony Betacam SP UVW-1600 plugged into an ADS Pyro AV Link Bidirectional DV Media Converter connected via firewire to a Mac Pro with FCP, make the edits and then export back to Betacam via the same route. Can this be done the way I have planned? If so are there any changes I need to make to the video before it is exported (timecode, etc.) for broadcast?
    This is not something we normally do and the import/export makes sense the way I have planned it out. But I have learned with video and all the various formats that it is usually never as easy as it seems.
    Any help or advice is appreciated.
    Thanks,
    Leon

    This isn't the best way...it really isn't. You are converting the beta footage to DV when you go through the Pyro...then editing it in a 720x480 space instead of 720x486...then you will be sending that back out to Beta...and now will have vertical blanking where you are missing 6 pixels...and your quality will really suffer...and might no longer pass QC.
    Then you have to figure out how you will do deck control...you will need a USB>RS-422 adapter.
    You really need to get a capture card. The Decklink Extreme can be had for $995 and does SD and now prepares you for HD work...as it does HD too. Decklink does have cheaper SD only cards, as does AJA...but since the world is moving HD, it is time to get prepared for that.
    Shane

  • Import - Export feature

    Is there a way to import - export routes or locations from HERE from-to other devices?
    I have a lot of routes created with different softwares and would like to import them on my Nokia phone.
    Igor
    http://jenga.wordpress.com

    I do this often and it is the only way to bulk add translation patterns. It will not remove any translation patterns it will only add/change the translation pattern. If all new patterns it will simply add your new entries.

  • Using "route-target import" only connected routes?

    When using the route-target import, the only routes imported are ones directly connected on one of the other PE routers. How does one get the advertised routes and the connected routes imported?
    PE1 -- PE2
    |
    |
    PE3
    Customer's remote site attaches to PE1 which peers to PE2. PE2 connects to Customer HQ.
    Another VRF (100:110) provides a centralized service that will be used by several different customers. Some of the subnets for this shared service are directly connected to PE2 while other subnets are directly connected to PE3.
    Since PE1 and PE2 were already peered, I thought all that was needed was an import statement to get the routes from the shared service vrf into the customer's vrf.
    PE1:
    ip vrf customer1
    rd 100:105
    route-target export 100:105
    route-target import 100:105
    route-target import 100:110
    When I do a 'show ip route vrf Customer1' the only routes that appear are the ones directly connected to PE2. I then peered PE1 to PE3, creating a full mesh but no other routes appeared in the routing table.
    PE1 -- PE2
    \ |
    \ |
    \ PE3
    I plan to use an export map and import map to filter the networks to the desired ones, but in this example, should not all routes be seen from the shared services VRF (100:110)?
    Thanks!

    Frank,
    Performing the import on one PE doesn't cause that one PE to start advertising the imported prefixes to other member of the same VRF on other PEs.
    If you want the prefixes from the shared services VRF to show up in the customer VRF on all PEs, you need to import RT 100:10 in VRF Customer1 on all PEs.
    Hope this helps,

  • Export CTI Route Point Dependencies

    Hello,
    CUCM version 8.6.2
    Is it possible to export CTI Route Point’s Dependency Records to a bat file or is there a tool available to download this information like the ones used in CUC?  We’ve associated employees to over 230+ route points.  I’m looking for the capability to export the employee’s associated to each CTI Route Point to a file rather than having to search each route point individually.
    So far, I’ve attempt to use Bulk Administration > Import/Export > Export > Selected CTI Route Point but the file generated didn’t display the user’s associated to the CTI Route Points. 
    At the least, I’d like to be able to export the dependencies.  If possible, I like the capability to update the file and re-import it.
    Thank you for your help in advance,
    Juffure

    Hi there,
    That CTIERR_REDIRECT_CALL_UNKNOWN_DESTINATION message indicates that
    CallManager believes that either
    1) the number you're redirecting to is not in the dial plan or
    2) the CTI Port the call is on does not have a proper Calling Search Space to allow it to "see" that number.
    I highly suspect the latter. Ensure that all of your CTI Ports have the proper CSS.
    If you still have issues after checking that, please open a TAC case for
    further analysis.
    Regards,
    Riccardo

  • Questions on Subviews and Import/Export in Data Modeler v3 EA1.

    I have a few questions about the capabilities of Data Modeler v3 EA1:
    1) Is it possible to rename subviews? Would like more meaningful names then Relational_x - Subview_x.
    2) Is it possible to save documents at subview level?
    3) Is it possible to import/export subsets of data?
    4) Having problems importing Erwin 7 .xml file, is there known problems with this import?
    Judy

    Hi Judy,
    1) To rename a subview just right click on it in the browser tree and select "Properties". In the properties dialog change the name and click OK button.
    2) You can save a subview as new Data Modeler design - from the File menu select Export -> To Data Modeling Design. In the newly opened dialog select the subview you want to export and click OK button.
    3) After saving a subview as new design (see answer #2) it can be imported in some other design (File -> Import -> Data Modeler Design).
    4) What kind of problems do you have with import of Erwin 7.* xml file?
    Regards,
    Ivan

  • How to import/export data in pl/sql developer

    how to import/export data,table script in pl/sql developer.
    By using the export functionality i am getting the dump file.I want a sql file.How do i do it?
    And i want the data in csv file and table script in a sep sql file.How do i do it?

    <li>run your query in "Query Builder"
    <li>Right-Click on the Query-Results
    <li>Click "Export"
    <li>Click on the "Drop-Down" in front of "Format" and choose "insert"
    <li>Provide the location and name of ther "sql" file.
    If you want output in CSV format, choose "csv" from the "format" drop-down.
    HTH

  • Getting an error while importing/exporting the universe from my BO Designer

    Hi,
       I am facing a issue while importing/exporting the universe from my BO Designer to the Server.The error is mentioned below.
       'File Repository Server Input is down'
       Once I click the OK button on this error message, it displays  the message
       'Could not import the Universe'.
      I tried the check the status of the File Repository Server (Ouput and Input) and also the of the Root Directory on the  Physical Server and also my machine.They all have read-write access.
    Installed Version of the Universe Designer Client: Business Object XI Release 2 SP3
    Installed Version of the BO Enterprise Server: Business Object XI Release 2 SP2
      Can you please help me to resolve the issue

    Hi,
       The step you have mentioned may not be applicable to my issue as one of my colleagues can import/export the universe from the same server
    The second thing is that a DB2 Client v9 is installed on both mine and my colleagues system.The Designer software can recognise the DB2 drivers on his system but it cannot recognise the same drivers on my system.I even checked the versions of the BO software installed on his and my system and they are same.
    The only difference is that his machine is a Windows XP Machine and mine is a Network Desktop.
    Will any of the above two things will affect the operation of the BO Designer.
    Thanks
    Prabhakar Korada

  • Attunity connectors for Oracle in Import Export Wizard in SQL Server 2008 R2

    Is there a way we can see the Attunity connectors drivers in the Import/Export Wizard (64 bit) for SQL Server 2008 R2?
    Although I made it work for SSIS, I would need these drivers in the Import/Export wizard so as to automate it for numerous number of tables which I want to migrate.
    Can the Attunity connectors for Oracle be used in the Import/Export wizard? If so please let me know.
    Regards,
    Ashutosh.
    Ashutosh.

    I have 100 tables to migrate. Creating a data flow for each table is tedious and that's why I was looking out for a way to do it through import export wizard so that I don't have to create a separate data source and destination for each table in the Data
    flow Task.
    Is there a way to loop through all tables and transfer data in SSIS without having multiple sources and destinations created for each table? This also involves a bit of transformation as well.
    Regards,
    Ashutosh.

  • IMPORT/EXPORT statement in Background Mode

    Hey dudes,
    I am facing a problem in my coding. I am dealing with coding in several events in IS-U, transaction FPY1.
    However, it's not so important ya. Now I am written some code on IMPORT and EXPORT some parameters between 2 program code. It's work very fine only in 'DEBUG MODE', but when it's running not debug mode (Is BACKGROUND MODE), coz it's massive run program.
    I suspect it's because of the background job. Does background job using ABAP Memory? IMPORT/EXPORT is only for dialog work process, not background work process?? I have a lot of question mark on my head now..
    Hope anyone facing dis issue before can help.
    Cheers,
    Isaac.

    Are you trying to pass data via EXPORT/IMPORT between two programs that are both running in background, or from an online session to a background process?... i.e. what are the two lots of program code that you are wanting to pass parameters between? 
    It would be fine for a background program to "export" data to a memory ID, then for the same batch program to submit another program that does the "import" from the same memory ID... but this method won't work for an online user doing an "export" and a batch job doing an "import" -> for this to work, you would need to persist the parameters so that the batch job can retrieve them.
    If you can explain the scenario a bit more, will try to offer more help...
    Jonathan

  • Import & Export of Internal table

    Hello All,
    In my requirement I need to call the MB5B program RM07MLBD. I used the code like this.
    SUBMIT rm07mlbd AND RETURN
                WITH matnr   IN  so_matnr
                WITH werks   IN  so_werks
                WITH datum   IN  so_budat.
    Now from the RM07MLBD program I need the get the values of the table * g_t_totals_flat * to my zprogram.
    Is it possible to import & export the Internal table from one program to other.
    Regards,
    Anil.

    Hi,
    You can export the internal table ot memory id and can access the (Import) in the called program.
    Consider this small code from ABAPDOCU.
    DATA text1(10) TYPE c VALUE 'Exporting'.
    DATA: itab TYPE TABLE OF sbook,
          wa_itab LIKE LINE OF itab.
    DO 5 TIMES.
      wa_itab-bookid = 100 + sy-index.
      APPEND wa_itab TO itab.
    ENDDO.
    EXPORT text1
           text2 = 'Literal'
      TO MEMORY ID 'text'.
    EXPORT itab
      TO MEMORY ID 'table'.
    Regards
    Bikas

  • ABAP command IMPORT/EXPORT

    Hi!
    I would like to know whats the replacement for the IMPORT and export commands used in 4.7c  in ECC6. Can anyone tell me whats the replacement commands for import and export command that is used in abap/4 4.7c for ECC6.
    Thanks

    Hi Aarav,
    there is nothing like replacement for import/export.there is another statements to transferdata which are Set/Get.
    when you are working with sap you have sessions.so in between session if you want to transfer data then you will use set/get parameters.import/export are used within the session.means you opened se38 and written a program and then go back to se38 initial screen and entered another program name and in that program you want the data which is in the previous program you have written in the se38 in same session.
    reward points if helpful.

  • How i can write a plug in for ai cs6 in c# for import/export of web type document

    can i write a plug in c#(or any other language) for import/export  a screen of the adobe illustrator cs6 in html (or any other format) if document of web type.

    If I understand you correctly, yes, you could write a plugin that imported an HTML file into Illustrator. You could also write one that exported to HTML. I'm not sure how easy it would be, and you won't find any HTML parsing help in the Illustrator SDK, but it's quite easy to create artwork with the SDK.

Maybe you are looking for

  • "Company code not assigned to country or country to calculation procedure"

    Hi , I'm practicing SAP on IDES at home. I have not created any 'Calculation procedure' (TAXINN or TAXINJ)  neither assigned any procedure to country 'IN'. I have maintained tax category 'MWST' for 'IN' in OVK1 and also assigned my delivering plant f

  • Can't find iPhoto in Finder

    While cleaning out my HD something vital to running iPhoto must have been accidently deleted...and I cleand out my Trash. Any recovery options? Thanks. iBookG4   Mac OS X (10.3.9)  

  • How do you change the opacity of a button when it is rolled over?

    I have the button created i am not trying to change the background or anything. I wanted to know how do you change the opacity for the over state of a button? by the default i have it set to 70% opacity i want to change the over state to 100%

  • Embeding video in web page

    Hi all, I'm a bit confused with video on iphone. iphone does not want to play a video (m4v created with qt pro) when it's embed in web page (html tag "embed" with attribute type "video/x-m4v"). But the SAME video send to iphone with itunes plays!! Wh

  • Create Symbol=Lose Events

    IE-Grouping elements into a symbol causes loss of events. Not sure if this is a bug but has anyone else noticed this? The workaround I've found is to to group the elements into a div, but then obviously... You can try yourself with the lynda tut / ch