EIGRP · IPv6 · Routing

EIGRP IPv6 map-leak

! hostname R1 ! ipv6 unicast-routing ! interface Loopback1 ipv6 address 2001:A:B:1000::1/64 ipv6 enable ! interface FastEthernet0/0 ipv6 address 2001:A:B::2/127 ipv6 enable ! interface FastEthernet1/0 ipv6 address 2001:A:A:1000::2/127 ipv6 enable ! router eigrp CONFIG-IF ! address-family ipv6 unicast autonomous-system 65000 ! af-interface default passive-interface exit-af-interface ! af-interface FastEthernet0/0 no passive-interface exit-af-interface ! af-interface FastEthernet1/0 summary-address… Continue reading EIGRP IPv6 map-leak

IPv6 · munin

IPv6 conntrack and munin

Argh, my beloved linux IPv6 firewall was suffering, too many connections, munin graphs not updating; this needed looking at… Firstly I noticed multiple entries of the following in kern.log: nf_conntrack: table full, dropping packet After checking the existing table size: # /sbin/sysctl net.netfilter.nf_conntrack_count net.netfilter.nf_conntrack_count = 76768 …it seemed sensible to double it: # cat /proc/sys/net/nf_conntrack_max… Continue reading IPv6 conntrack and munin

IPv6 · VPN

Cisco ASA IPv6 Site-to-Site IPSec IKEv2 VPN

pre { font-family:arial; font-size:12px; border:1px dashed #CCCCCC; width:99%; height:auto; overflow:auto; background:#f0f0f0; padding:0px;color:#000000; text-align:left; line-height:20px; } code { color:#000000; word-wrap:normal; } Cisco ASA IPv6 Site-to-Site IPSec IKEv2 VPN I took delivery of a 5545-X from Bedfont Lakes to evaluate in my IPv6 lab; this post covers the steps to connect two ASA’s via IPv6 IPSec VPN.… Continue reading Cisco ASA IPv6 Site-to-Site IPSec IKEv2 VPN

IPv6 · Monitoring · munin

Munin IPv6 neighbor state graphs

A recent issue with a Linux IPv6 firewall which saw on-link hosts appear to be flapping according to monitoring tools, highlighting a IPv6 ND table overflow problem. The short version of the solution required: net.ipv6.neigh.default.gc_thresh1 = 256 net.ipv6.neigh.default.gc_thresh2 = 1024 net.ipv6.neigh.default.gc_thresh3 = 2048 To keep an eye on the neighbor table I created a series… Continue reading Munin IPv6 neighbor state graphs

7200VXR · IPv6

Cisco 7206VXR FA-GE= port adapter performance

Cisco 7206VXR FA-GE= port adapter performance High CPU utilization is not uncommon, especially when a router is struggling to process a packet and punts it between switching processes. The graphs below show the output from a production Cisco 7206VXR (NPE-G1, PA-GE=, PA-2FE-TX) router which is the primary for an IPv6 HSRP pair. Whenever the primary… Continue reading Cisco 7206VXR FA-GE= port adapter performance