Layer 3 to the Access Layer and MPLS Design Considerations

Hi,
We are about to install a new network consisting of Cat 4500s with Sup7E at the Access Layer, with Nexus 7000 at the Distribution and Core layers.
We have 14 floors with at least three 4500s on each floor. Within the office block where the Access Layer and Distribution Layer reside we need to support secure borderless networking using 802.1x to place users from different parts of the business into segregated networks at layer 3.
All switches will have the feature sets to support MPLS/ VRF / OSPF / EIGRP / BGP etc.
We quickly dismissed the idea of using VRF-Lite due to the sheer number of Vlans we would need to managage and maintain,  the point to point links alone just to get one additional VRF on each floor required far too many Vlans.
As a result we are now considering deploying MPLS. The obvious benefits include scalability and manageability, the fact that all switch to switch links can now be routed, instead of having to using SVIs.
My query is one of design surrounding MPLS and how this maps to an enterprise network with a routed access layer. Do Cat 4500s become the CEs and take part in MPLS / BGP and Label Distribution, or does the BGP peering and Label Distribution only occur between the Distrubtion - Core - Distrubtion layers, mapping to the PE - P - PE topology in an ISP environment, the access layer simply uses the IGP (OSPF in this case) to learn routes ?
Any help would be greatly appreciated.
Chris.

Hi Andy,
Thanks for your response.
I have been doing a little bit more research it seems the Cat 4500s do not support MPLS!! Nor do Cisco have any plans to support it on this platform. I find this a little rediculous considering the level that Cisco are pitching this platform. With the Sup 7E only VRF Lite is supported, with plans to support EVN (which still uses trunk links for logical separation).
So it looks like we are going to have to go back to the drawing board.
(perhaps we should have gone HP or Juniper!)
Chris.

Similar Messages

  • 6500 or 4500 for the access layer

    I would like to get some input as to the best switch to use at the access layer. I am considering both the 6500 with a Supervisor 32 and the 4500 with a Supervisor 5. I am using the Sup 720 in the data center so staying with a single platform is appealing although the 4500 clearly appears to out perform the Sup 32.
    Does anyone have experience with the Supervisor 32? Any feedback would be much appreciated.

    Go with the 6500 with the Sup32. Cisco has a bundle with a chassis, Sup32, and a Fan for the reduced price.
    Few reasons the Sup32 is a better choice.. (engage your Local Cisco account team for a overview to compare architectures)
    Same Layer2 engine as the Sup720. This means you will receive the same Layer2 performance as the Sup720 would using classic line cards
    Modular IOS and the Same IOS as your core. This allows you to only have to test and maintain one code for the network
    Can upgrade to a Sup720 later if your needs change. (or the next version line cards as well without replacing chassis)
    higher density POE support in the 6500 chassis.
    Many more features are supported in Hardware on the Sup32 due to the PFC3B.
    Control Plane Policing. Hardware policiers
    Service module support
    Dont let PPS fool you on the spec sheets. Look at the architecture as a whole. The Sup V on the 4500 is a shared memory architecture and has a limited "punt path". The Sup32 has a 1Gbs punt path and the SupV is under 250k pps. The Sup V also does not have a dedicated L2 engine like the Sup32 does (PFC3B vs asic)
    Your profile also lists you as with a financial firm. With multicast in the equation, the 6500 is always the best bet. The Multicast features/policers support in hardware to insure reliability and low latency switching is a perfect fit for the Sup32/Sup720.
    With the Sup32 you can have the same reliability you have in the core. Also, the 6500 bundle cost comes to roughly the same cost as the 4500.

  • Opening a new file in photoshopcc and the file name is displayed but no white working canvas. you can see it as a layer in the layers panel and if i draw on the grey area i can see int on the layer but not on the main screen.

    opening a new file in photoshop cc and the file name is displayed but no white working canvas. you can see it as a layer in the layers panel and if i draw on the grey area i can see int on the layer but not on the main screen.

    Graphics card is the problem.
    Trying to update drivers now.
    Thanks for your help
    john

  • Selecting (and resizing, for example) a layer under the top layer via the Program Monitor

    Hello all.
    Using CS5
    I am in the timeline and have selected layer 1 which is a video layer
    Layer 2 is a title layer.
    I want to manually resize layer 1, via the Program Monitor.
    But when I go to the Program Monitor and select it Layer 2 (the title layer) becomes selected, preventing me from selecting and manually resizing/repositioning Layer 1.
    The above example is a simplified version of what I usually find myself doing.  Usually I have many layers above a layer that I want to resize or reposition (or do something else) but when I try to resize or repositon via the program monitor I am only able to manipulate the top layer.
    Any suggestions, other than locking every layer other than what I want to resize etc .?
    Thanks
    Rowby

    Hi Bill,
    No they are separate orginal tracks. 
    Is there a way to "select" a layer below the top layer via the Progam Monitor -- and perform modifications on that lower level -- such a manually resizing on the Program Monitor.  I find if I want to do it via the Program  Monitor I have to temporarily lock the top layer.
    And if I have lots of layers above the layer I want to manually resize, I have to lock all of the layers above that layer so I don't start moving around (for example a title layer which might be the top layer of the sequence) in order to manually resize via the Program Monitor.
    I know (for example) in the case of scaling or repositioning a layer I could do it via the effects control panel, but I often want to do it via the Program Monitor.
    Rowby

  • I created a new layer and copied the contents of another layer into the new layer. Now whenever I ed

    I have a template that I am editing. I have created new layers by duplicating an existing layer. The problem I am having is that anytime I make a change to a duplicated layer it changes the original as well. ie if I attempt to edit the action script on the new layer it changes the action script on the original? It seems as though they are linked and I can not find a way to unlink them??

    You should be able to edit the immediately present contents of different layers without affecting other layers, but if you are editing anything at a level below the layer, such as doubleclicking to edit an object in that timeline, you are changing it anywhere it is used.

  • Exclude an layer from the adjustment layer

    Hi ,
    i don't know why adobe still didn't add this option to after effects !!!!!!!!
    we have alot of problems with this
    i can't just keep pre-comping stuff !!!!!
    adding a simple column between the 'track mat' and the 'parent' to exclude the selected layer from an adjustment layer in top of it will simple thing's Up .
    please consider this option
    My bests

    Hey guys.
    I was stuck with the same problem, so I found a way to solve it with minimal changes.
    I have a silly 2d animation representing days and nights passing by. To improve the sensation, I put an adjustment layer to tint all layers below every time the moon rises. But the adjustment layers also tints the sun and moon and with my current structure, full of overlaps, it will be a pain to reorder and mask all layers. So I simply duplicate the layer that I was working on and rename it to "MEGA LUMA MASK" and put them just above the adjustment layer. Inside this new duplicated layer, I tint all layers to total black, except for the moons and suns, which I tint to total white. What I got was a perfect luma mask that respects all overlaps without needing to touch the structure. Finally I just set the track matte of the adjustment layers to Luma Inverted!
    No pre composes (kinda), no crazy masks. Of course an adjustment layer exception system would be better, but it's a clean, fast and versatile solution.

  • Which layer is the target layer?

    How can I determine which layer among those in the ->layersDescriptor structures corresponds to the target layer?
    In photoshop cc x64 pc
    -- all the read channel numbers seem to be unique
    -- all channels have ->target=1
    (edit after more work with layersDescriptor)
    the information presented has a lot of errors and omissions, such that it's impossible
    in principal to display layers the same way as photoshop does.  Invisible "pass through"
    layers are listed as visible.  Layers with "stroke" special effects are indistinguishable
    from normal layers.

    Layers with "stroke" special effects are indistinguishable
    from normal layers.
    Here is how to find stroke (keyFrameFX, descLayer is starting layer descriptor, in this case code also look if effects are visible)
    hasKey=0;
        error = sPSActionDescriptor->HasKey(descLayer, keyLayerEffects, &hasKey);
        if (error) goto returnError;
        error = sPSActionDescriptor->GetBoolean(descLayer, keyLayerFXVisible, &effVisible);
        if (error) goto returnError;
        if (hasKey && effVisible){
                error = sPSActionControl->StringIDToTypeID("classLayerFXVisible", &runtimeClassID);
                if (error) goto returnError;
                error = sPSActionDescriptor->GetObject(descLayer, keyLayerEffects, &runtimeClassID, &descEFFECTS);
                if (error) goto returnError;
                // FRAME
                error = sPSActionDescriptor->HasKey(descEFFECTS, keyFrameFX, &hasKey);
                if (error) goto returnError;
                if (hasKey)
                    error = GetFrameAttributes(index, info);
                //etc.
    Regards,
    Momir Zecevic

  • Subtitles wont work on the secon layer of the dual layer disc

    even with scripts the subtitles goes automatic to stream 1 on the data (videos) in the second layer.
    the gprm info some how gets lost in the break point.
    please help
    Dub division

    How is the project set up?
    Is it one long track that crosses the layer break?
    Are the scripts attached properly?
    What are the scripts?
    Take a look here for some info to force subtitles
    http://discussions.apple.com/message.jspa?messageID=2069686#2069686
    and an example project
    http://www.geocities.com/mypix013/Subtitles.zip
    Some general info also of forcing streams
    http://discussions.apple.com/thread.jspa?messageID=2243316&#2243316

  • Populating users and groups - design considerations/best practice

    We are currently running a 4.5 Portal in production. We are doing requirements/design for the 5.0 upgrade.
    We currently have a stored procedure that assigns users to the appropriate groups based on the domain info and role info from an ERP database after they are imported and synched up by the authentication source.
    We need to migrate this functionality to the 5.0 portal. We are debating whether to provide this functionality by doing this process via a custom Profile Web service. It was recommended during ADC and other presentation that we should stay away from using the database security/membership tables in the database directy and use the EDK/PRC instead.
    Please advise on the best way to approach(With details) this issue. We need to finalize the best approach to take asap.
    Thanks.
    Vanita

    So the best way to do this is to write a custom Authentication Web Service.  Database customizations can do much more damage and the EDK/PRC/API are designed to prevent inconsistencies and problems.
    Along those lines they also make it really easy to rationalize data from multiple backend systems into an orgainzation you'd like for your portal.  For example you could write a Custom Authentication Source that would connect to your NT Domain and get all the users and groups, then connect to your ERP system and do the same work your stored procedure would do.  It can then present this information to the portal in the way that the portal expects and let the portal maintain its own database and information store.
    Another solution is to write an External Operation that encapsulates the logic in your stored procedure but uses the PRC/Server API to manipulate users and group memberships.  I suggest you use the PRC interface since the Server API may change in subtle ways from release to release and is not as well documented.
    Either of these solutions would be easier in the long term to maintain than a database stored procedure.
    Hope this helps,
    -Akash

  • Is NAT allowed between the Access Point and WLAN Controller?

    Suppose that the AP and Controller communicate over a L3 network.
    Can NAT be performed in between?
    For example, suppose that the AP is connected to an ADSL router that performs NAT.

    Just to expand on what George had said, when the controller sends the discovery response to an AP the controller's ap-manager interface IP address is embedded in the response.  So if this packet gets NATed the embedded address won't.  So just make sure they AP can route packets to whatever address is configured on the controller.  The controller doesn't need to see the AP's configured address, this one could be NATed.

  • Switches for Access, Distribution, and Core Layer

    I have this case study in school and we are tasked to build a network in a school. So we've decided to use the three layer hierarchical model. I'm not sure about what switch is best for these layers but I've decided that I'll use 3750 for the Access layer, 4500E for the Distribution layer, 6500 for the Core layer. Are these the ideal switches for each layer? If not, could you suggest any switch that is better than the current? Need your suggestions or thoughts about this. Thanks in advance!

    Hi Seb, thanks for replying. My groupmates and I have already decided that we're going to have a distribution layer. So basically, is 3750 enough to be the backbone/core of the network? We're configuring the to have a Layer 3 design so that makes me choose on 3750 on distrib and core rathen than 2960 switches cause I think that's better than Layer 2 though I don't know specifically what makes it better. Do you know? So I could have a thorough explanation when I present it to my professor. As for the budget, the case study didn't give us any limit so I think layer 3 would be a better choice than layer 3. Thanks Sib, appreciate it.

  • I have several layers for this image: Background, Moon, Tree, Grass and Clouds.  When I try to use the Move tool to move the Moon, the tool jumps to the Tree layer.  The same thing happens with the other layers as well (except the background layer).  How

    I have several layers for my image: Background, Moon, Tree, Grass and Clouds.  When I try to use the Move tool to move the Moon, the tool jumps to the Tree layer.  The same thing happens with the other layers as well (except the background layer).  How can I keep the move tool from jumpimg to the Tree layer?

    1. Pre-select (highlight) the layer to move in the Layers panel.  or-
    2. [ALT+Right mouse click]  to select the wanted layer in the image window.
    and maybe
    3. Set the PS option to "Auto-select" a layer with cursor hover.  (can be very confusing!)

  • I've got the move tool and the layer selected...

    but for some reason I can't get the text to align anywhere. The align buttons are acting as if they are greyed out. Is there something I'm missing?

    You need at least two layers selected (the text layer and the background layer) or the text layer and a selection (i.e. Select All...) for the alignment commands and buttons to enable and to alight the text to the document.

  • Bandwidth from Access Layer to Distribution Layer

    Folks:
    I am currently on Chapter 12 of “CCNP Switching 642-813, Official Certification Guide” ISBN: 978-1-58720-243-8. I am currently not grasping the three layers entirely, and I was hoping someone could offer insight in a different way.
    I believe I understand, that switches in the Access-Layer can be layer2 devices (2950, etc), and devices in the Distribution Layer should be Multilayer devices such as Layer-3 switches (3750) and inter-vlan routing takes place at the Distribution layer. But what I do not understand – how does one account for bandwidth and traffic from the Access Layer switches to the Distribution Switches?
    Let use a 24 port 2950 switch located at the Access-Layer. If everyone was online and communicating, the total traffic for the switch would be 4.8 Gbps. The latter is due to each port providing 100 Mbps but in Full-Duplex, so (100*2)*24. So, how does an engineer spec out the required uplink ports from the Access Layer to the Distribution?
    I am sure this is easy; however, I am not getting the concepts. Any insight is great.

    Disclaimer
    The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
    Liability Disclaimer
    In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
    Posting
    As noted by Peter, edge hosts don't generally all concurrently push/pull their full port bandwidth for substained periods.  However, host bandwidth usage often varies much by "kind" of host.  For example, many server hosts are "busier" than most user hosts, so when designing networks you normally design for lower oversubscription ratios for server hosts than for user hosts.  Old rule-of-thumbs ratios suggest oversubscription ratios of about 8:1 to 4:1 for servers, and about 48:1 to 24:1 for users.
    Keep in mind that oversubscription ratios can be "skewed" by what the host is doing, i.e. not all server or user hosts have similar bandwidth demands.  For example, your primary mail server or primary file server might be much "busier" than other server hosts.  Likewise, some user hosts might be much "busier", for example, years ago I supported a LAN segment of CADD (20) workstations which had more traffic on their local LAN than the (2,000 user) corporate backbone.

  • 6500 access layer QoS

    I have 6506E Sup32 PFC3B 12.2(18)SXE device at the access layer of the network and would like to implement QoS (for access ports) for Voice, Video.
    I suppose that untrusted microflow policing is best for me. But documents say that such kind functionality works for L3 MSFC routed traffic. For PFC3b I can use "mls qos bridged" for bridged traffic on specified vlans. Does it really work for input service policy on access ports for traffic from user ports (if I use this command on user's int VLAN)?
    Distribution and core layers of my networks are MPLS based.
    Config:
    interface FastEthernet2/1
    switchport
    switchport access vlan 10
    switchport mode access
    switchport voice vlan 30
    no ip address
    spanning-tree portfast
    service-policy input IPPHONE+VIDEO
    interface Vlan30 ! also for Vlan 30
    ip vrf forwarding VOICE
    ip address 10.168.8.254 255.255.255.0
    ip helper-address 10.168.2.33
    ip helper-address 10.168.2.34
    ip pim sparse-dense-mode
    mls qos bridged
    policy-map IPPHONE+VIDEO
    class VOICE
    police flow mask src-only 320000 8000 conform-action set-dscp-transmit ef exceed-action drop
    class VIDEO-INTERACTIVE
    police flow mask src-only 2400000 8000 conform-action set-dscp-transmit af41 exceed-action drop
    class CALL-SIGNALING
    police flow mask src-only 32000 8000 conform-action set-dscp-transmit cs3 exceed-action policed-dscp-transmit
    class class-default
    police flow mask src-only 5000000 8000 conform-action transmit exceed-action policed-dscp-transmit

    This URL should help you:
    http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00801c8c4b.shtml

Maybe you are looking for

  • Can't download itunes 10.7 without updating to Mac OS X 10.6.8

    I downloaded itunes 10.7 but cant install it unless i update my software to Mac OS X 10.6.8. I just got the iphone 5 and need to activate but am not able to due to that error message. When i check software updates thats not available to not sure what

  • HT201363 l have forgotten the answers to the securit questione

    Hi my name is pouria my apple id ******* l have forgotten the answers to the securit questione and there is no rescue email  security questions Please connect me to the security department Security is a security section to connect me please help me r

  • Nokia update help, v13.0.003 rm-159 nokia (68.03)

    my fone says update version v13.0.003, i think this is not the latest version after reading some threads on here, the software updater says its the latest version, why is my n95 being so gay?..... i have updated on an xp machine, and a vista machine,

  • Sign in problem for iCloud on W7

    I have not previous used the iCloud service, but have downloaded the "Control panel" for it. I am unable to sign-in using my iTunes login.  I can find no way to create and iCloud login, or change my iTunes login in order to have access to iCloud.  An

  • SQL for join table  problem?

    hi morning, my problem also haven find out the solution,can help me solve. I got one part of register student to exam,during that part is like that. Student Code:________(table3) Exam Code:_________(table 3) Student Name:________(table 1) Exam Name:_