Presentation is loading. Please wait.

Presentation is loading. Please wait.

Out-of-Band & NAT on NLR Grover Browning - Indiana University

Similar presentations


Presentation on theme: "Out-of-Band & NAT on NLR Grover Browning - Indiana University"— Presentation transcript:

1 Out-of-Band & NAT on NLR Grover Browning - Indiana University gcbrowni@grnoc.iu.edu

2 NLR Monitoring & Management Many L2 & L3 devices are managed by command line and thus can be reached on a hop-by-hop basis. Backbone Router Local Router Rack Router ISDN Router X 1. SSH to ISDN Router. 2. SSH/Dial to Rack-Lan Router. 3. SSH to unreachable router.

3 NLR Monitoring & Management Most optical devices, including the NLR 15808 platforms, are managed by GUI applications. These management stations require a route to the devices at all times, and generally don’t work well over dial-up lines. Denver 15808 Chicago 15808 Heartwell 15808

4 NLR Monitoring & Management Additionally, the 15808s are numbered out of RFC1918/10’s address space, which conflicts with local private addressing at both IU & CENIC. Denver 15808 Chicago 15808 Heartwell 15808 10.0.10.1/2410.0.10.2/24 10.0.10.3/24 IU Router IU 10.0.10.0/24 Subnet.

5 NLR Monitoring & Management Requirements Management speed > 128k. Automatic Routing during failures. Private address conflict resolution. Simple. Pick 3.

6  NAT to the Rescue!  Denver 15808 Chicago 15808 Heartwell 15808 10.0.10.1/2410.0.10.2/24 10.0.10.3/24 Rack Router Rack Router IU Router Level3 2 mb/s IU Commodity Peering 152.49.22.1 152.49.22.2 152.49.22.3 NAT 152.49.22.0/27 to 10.0.10.0/24 152.49.22.0/23 152.49.4.0/23

7 Inside NAT Denver 15808 Chicago 15808 Heartwell 15808 10.0.10.1/24 D: 10.0.10.254 10.0.10.2/24 D: 10.0.10.254 10.0.10.3/24 D: 10.0.10.254 Rack Router Rack Router 152.49.22.0/23 152.49.4.0/23 Inside NAT turns our 152.49.22.1 destination address in to a 10.0.10.1 address. The 15808s use the entry point Rack Router as their default route. This is enough for normal management, but will not work in an outage situation. Level3 10.0.10.254

8 Outside NAT Denver 15808 Chicago 15808 Heartwell 15808 10.0.10.1/24 D: 10.0.10.254 10.0.10.2/24 D: 10.0.10.254 10.0.10.3/24 D: 10.0.10.254 Rack Router Rack Router 152.49.22.0/23 152.49.4.0/23 Level3 10.0.10.254 X 10.0.10.253 Outside NAT turns our SOURCE address in to a 10.0.10.x address. Inside NAT then turn our 152.49.4.2 destination address in to a 10.0.10.2 address. The 15808 may then reply to 10.0.10.253 since that is a directly connected device. The entry point to 15808 segment is determined by the IP address managed, 152.49.22.1 or 152.49.4.1. The management station knows that each 15808 has two address, if the primary does not work then it tries the secondary.


Download ppt "Out-of-Band & NAT on NLR Grover Browning - Indiana University"

Similar presentations


Ads by Google