Cisco Systems OL-12518-01 Switch User Manual


 
4-23
Data Center High Availability Clusters Design Guide
OL-12518-01
Chapter 4 FCIP over IP/MPLS Core
Testing Scenarios and Results
VRF Configuration—PE2
The following are the VRF definitions on the PE2(7500-106) router:
ip vrf storage
rd 105:106
route-target export 105:106
route-target import 105:106
This test assumes the Cisco MDS 9216/9216i as the CPE. MPLS VPN VRFs allow the SPs to leverage
a common backbone to offer shared transport services. To facilitate these services, the provider gets the
added security mechanisms of VRFs. The VPN VRFs provide an address space separation; therefore, the
use of VRFs on the PE devices and MP-BGP between them achieves address separation not only among
the different VPNs but also with the SP core network. Thus Customer 1 cannot see any boxes or
interfaces of Customer 2, even though they are on the same transport network and may also share the
same PE device.
There is no visibility of the core network to the end storage customer, which means that the core network
infrastructure including addressing and topology is not visible to the VPN customers. Customer VPN
routes that originate from other PE routers across the core network are associated with the BGP next-hop
address of the originating PE router. The BGP next-hop address of the PE router is not visible or
reachable in the customer address space.
The use of the traceroute command can potentially reveal the addresses in the core topology. The core
network address can be hidden from view in a VPN by configuring the no mpls ip propagate-ttl
forwarded command. Therefore, the storage customer can be stopped from seeing the routers in the core
network that are carrying the storage traffic.
Scenario 1—MDS 9216i Connection to GSR MPLS Core
In this scenario, GSR is assumed to be the provider (P) and PE device (see Figure 4-11). FCIP traffic is
passed across the MPLS network. Tests were performed with different packet sizes. The MPLS networks
with proper configurations of MTU size and the TCP parameters on the CPE were able to carry line rate
traffic.