Showing posts with label juniper. Show all posts
Showing posts with label juniper. Show all posts

Tuesday, June 9, 2026

Deploying SRv6 in Juniper: From Setup to Verification

I'm exploring the SRV6, and it's obvious that I am exploring now with Juniper after I tested SRV6 configurations and features in Nokia SROS.

In this blog post I will be covering the SRV6 enabling in Junos, and in upcoming blogs I will enable different services through the SRV6 tunnel and hurdles during the testing in detail.

I am using the below topology to enable SRv6 in Junos. IPv4 is not enabled; only IPv6 is configured and enabled ISIS over IPv6.











Loopback/locator IPv6 addresses







Let's configure the IPv6 address on respective interface as below

set interfaces ge-0/0/1 unit 0 family inet6 address 2001:db8:12::1/64

set interfaces ge-0/0/2 unit 0 family inet6 address 2001:db8:14::1/64

set interfaces lo0 unit 0 family inet6 address 2001:db8:0::1/128


Locator configuration on each router as per table

set routing-options source-packet-routing srv6 locator loc1 2001:db8:a1:1::/64 

Configure the flavour. How the IPV6 transit and endpoint and adjacency SID

Penultimate Segment Pop 

set protocols isis source-packet-routing srv6 locator loc1 end-sid 2001:db8:a1:1::0 flavor psp

Ultimate Segment Decapsulation

When a packet reaches its final SRv6 segment destination, if there are no more segments in the SRH, the USD instruction tells the router to pop the outer IPv6 header along with any remaining extension headers.

set protocols isis source-packet-routing srv6 locator loc1 end-sid 2001:db8:a1:1::0 flavor usd


Enable the Enhanced IP under the chassis

set chassis network-services enhanced-ip

Enable SRV6 in ISIS

set interfaces lo0 unit 0 family iso address 49.0001.0000.0000.0001.00

set interfaces ge-0/0/1 unit 0 family iso

set interfaces ge-0/0/2 unit 0 family iso

set protocols isis level 1 disable

set protocols isis interface ge-0/0/1.0

set protocols isis interface ge-0/0/2.0

set protocols isis interface lo0.0 passive

set protocols isis level 2 wide-metrics-only


Advertising SRV6 Locator in ISIS

set protocols isis source-packet-routing srv6


Verification:

IPv6 Locators are programmed in the inet6.0 table like other ipv6 loopback address and next hops that forward the traffic with next hop interface and Locator programmed in inet6.3 table and tunnel next hop tunnel SRV6. SRV6 traffic encoded with SRH header towards the destination.

show route table inet6.0 protocol isis   


2001:db8:a1:1::/64 *[IS-IS/18] 00:06:39, metric 0

                       Reject

2001:db8:a1:1::/128*[IS-IS/18] 00:06:39, metric 0

                       Receive

2001:db8:a1:2::/64 *[IS-IS/18] 00:01:57, metric 10

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0

2001:db8:a1:3::/64 *[IS-IS/18] 00:01:54, metric 20

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0

                       to fe80::5254:ff:feae:6d02 via ge-0/0/1.0

2001:db8:a2:5::/64 *[IS-IS/18] 00:01:50, metric 20

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0

2001:db8:a2:6::/64 *[IS-IS/18] 00:00:49, metric 30

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0

2001:db8:a3:7::/64 *[IS-IS/18] 00:01:44, metric 20

                    >  to fe80::5254:ff:feae:6d02 via ge-0/0/1.0

2001:db8:a3:8::/64 *[IS-IS/18] 00:02:03, metric 30

                    >  to fe80::5254:ff:feae:6d02 via ge-0/0/1.0


admin@R1# run show route table inet6.3 

inet6.3: 12 destinations, 12 routes (12 active, 0 holddown, 0 hidden)

+ = Active Route, - = Last Active, * = Both

2001:db8:a1:2::/64 *[SRV6-ISIS/14] 00:07:56, metric 10

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a1:2::

2001:db8:a1:2::/128*[SRV6-ISIS/14] 00:07:56, metric 10

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a1:2::

2001:db8:a1:3::/64 *[SRV6-ISIS/14] 00:07:53, metric 20

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a1:3::

                       to fe80::5254:ff:feae:6d02 via ge-0/0/1.0, SRV6-Tunnel, Dest: 2001:db8:a1:3::

2001:db8:a1:3::/128*[SRV6-ISIS/14] 00:07:53, metric 20

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a1:3::

                       to fe80::5254:ff:feae:6d02 via ge-0/0/1.0, SRV6-Tunnel, Dest: 2001:db8:a1:3::

2001:db8:a2:5::/64 *[SRV6-ISIS/14] 00:07:49, metric 20

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a2:5::

2001:db8:a2:5::/128*[SRV6-ISIS/14] 00:07:49, metric 20

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a2:5::

2001:db8:a2:6::/64 *[SRV6-ISIS/14] 00:06:48, metric 30

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a2:6::

2001:db8:a2:6::/128*[SRV6-ISIS/14] 00:06:48, metric 30

                    >  to fe80::5254:ff:fee8:e501 via ge-0/0/0.0, SRV6-Tunnel, Dest: 2001:db8:a2:6::

2001:db8:a3:7::/64 *[SRV6-ISIS/14] 00:07:43, metric 20

                    >  to fe80::5254:ff:feae:6d02 via ge-0/0/1.0, SRV6-Tunnel, Dest: 2001:db8:a3:7::

2001:db8:a3:7::/128*[SRV6-ISIS/14] 00:07:43, metric 20

                    >  to fe80::5254:ff:feae:6d02 via ge-0/0/1.0, SRV6-Tunnel, Dest: 2001:db8:a3:7::

2001:db8:a3:8::/64 *[SRV6-ISIS/14] 00:08:02, metric 30

                    >  to fe80::5254:ff:feae:6d02 via ge-0/0/1.0, SRV6-Tunnel, Dest: 2001:db8:a3:8::

2001:db8:a3:8::/128*[SRV6-ISIS/14] 00:08:02, metric 30

                    >  to fe80::5254:ff:feae:6d02 via ge-0/0/1.0, SRV6-Tunnel, Dest: 2001:db8:a3:8::


[edit]

admin@R1# run ping 2001:db8:a1:3:: 

PING6(56=40+8+8 bytes) 2001:db8:12::1 --> 2001:db8:a1:3::

16 bytes from 2001:db8:23::3, icmp_seq=0 hlim=63 time=796.705 ms

16 bytes from 2001:db8:23::3, icmp_seq=1 hlim=63 time=5.956 ms

16 bytes from 2001:db8:23::3, icmp_seq=2 hlim=63 time=205.600 ms

^C

--- 2001:db8:a1:3:: ping6 statistics ---

3 packets transmitted, 3 packets received, 0% packet loss

round-trip min/avg/max/std-dev = 5.956/336.087/796.705/335.749 ms


admin@R1> ping srv6 isis 2001:db8:a3:7:: detail   

Request for icmp_seq=1, via interface 429, packet size 64 

Reply for icmp_seq=1 from 2001:db8:47::7 via interface 429 hops-limit: 63, trip-time: 9.497 ms

        Local transmit time: 2026-06-09 07:20:17 UTC 844.327 ms

        Remote receive time: 2026-06-09 07:20:17 UTC 974.926 ms

Request for icmp_seq=2, via interface 429, packet size 64 

Reply for icmp_seq=2 from 2001:db8:47::7 via interface 429 hops-limit: 63, trip-time: 67.630 ms

        Local transmit time: 2026-06-09 07:20:18 UTC 840.312 ms

        Remote receive time: 2026-06-09 07:20:19 UTC 6.273 ms

Request for icmp_seq=3, via interface 429, packet size 64 

Reply for icmp_seq=3 from 2001:db8:47::7 via interface 429 hops-limit: 63, trip-time: 38.220 ms

        Local transmit time: 2026-06-09 07:20:19 UTC 843.228 ms

        Remote receive time: 2026-06-09 07:20:19 UTC 983.084 ms

Request for icmp_seq=4, via interface 429, packet size 64 

Reply for icmp_seq=4 from 2001:db8:47::7 via interface 429 hops-limit: 63, trip-time: 10.654 ms

        Local transmit time: 2026-06-09 07:20:20 UTC 840.931 ms

        Remote receive time: 2026-06-09 07:20:20 UTC 971.686 ms

Request for icmp_seq=5, via interface 429, packet size 64 

Reply for icmp_seq=5 from 2001:db8:47::7 via interface 429 hops-limit: 63, trip-time: 5.468 ms

        Local transmit time: 2026-06-09 07:20:21 UTC 846.190 ms

        Remote receive time: 2026-06-09 07:20:21 UTC 976.553 ms


--- lsping statistics ---

5 packets transmitted, 5 packets received, 0% packet loss

round-trip min/avg/max/stddev = 5.468/26.294/67.630/23.712 ms


Monday, April 3, 2023

BGP Prefix Limit Configuration in Cisco, Juniper and Nokia - Interop

BGP Prefix Limit

Maximum Prefix-limit is used to control the BGP peer not to overload your BGP routing table and it helps to avoid the situation. let's explore how to configure in Cisco, Juniper, and Nokia router


Cisco Configuration

 !
router bgp 300
 neighbor 192.168.1.1
  address-family ipv4 unicast
   maximum-prefix <max-limit> <percentage> <Actions>
  !
 !

Juniper  Configuration

edit protocol
bgp {
        group nokia {
            neighbor 192.168.0.1 {
                family inet {
                    unicast {
                        prefix-limit {
                            maximum 1000;
                            teardown;
                        }
                    }


Nokia Configuration

/configure router bgp
            group "juniper"
                type external
                local-as 100
                neighbor 192.168.0.2
                    prefix-limit <family> <prefix-limit>
                    peer-as 200
                exit

   


TCP AO configuration on Cisco, Juniper and Nokia SR - Interop Configuration

TCP-AO is a new authentication method proposed through RFC5925, The TCP Authentication Option to enhance the security and authenticity of TCP segments exchanged during BGP.

 It supports both IPv4 and IPv6 traffic


Benefits of TCP-AO




Support multiple stronger algorithms, such as HMAC-SHA1 and AES-128 to create an internal traffic key and message digest.

Add a new user-configured key to re-generate internal traffic keys for an established connection and a mechanism to synchronize key change between BGP peers

Nokia Configuration

/configure system security 

keychain "aes-128-cmac-96-keychain"

                tcp-option-number

                    send tcp-ao

                    receive tcp-ao

                exit

                direction

                    uni

                        send

                            entry 20 key “key”algorithm aes-128-cmac-96

                                begin-time 2023/04/03 08:22:32 UTC

                            exit

                        exit

                        receive       

                            entry 10 key “key” algorithm aes-128-cmac-96

                                begin-time 2023/04/03 08:23:24 UTC

                            exit

                        exit

                    exit

                exit

                no shutdown

            exit

Apply the TCP AO authentication under BGP neighbor or Group

/configure router bgp group "juniper"

                type external

                local-as 100

                neighbor 192.168.0.2

                 auth-keychain "aes-128-cmac-96-keychain"

                exit

            exit


Juniper Configuration#

security {                              

    authentication-key-chains {

        key-chain nokia {

            tolerance 30;

            key 10 {

                secret "$9$vxA87Vg4ZiqfDi/t0OSy7-Vb2aZGiq.5"; ## SECRET-DATA

                start-time "2023-2-1.00:00:00 +0000";

                algorithm ao;

                ao-attribute {

                    send-id 10;

                    recv-id 20;

                    tcp-ao-option enabled;

                    cryptographic-algorithm aes-128-cmac-96;

                }

            }

Apply the TCP AO authentication under BGP neighbor or Group

set protocols bgp group nokia authentication-algorithm ao


Cisco XR Configuration#

key chain AS300

 key 0

  accept-lifetime 00:00:00 april 01 2023 infinite

  key-string password 0701245859060B0E1B1309

  send-lifetime 00:00:00 april 01 2023 infinite

  cryptographic-algorithm MD5

 !

!

key chain AS300

 key 1

  accept-lifetime 00:00:00 april 01 2023 infinite

  key-string password 0701245859060B0E1B1309

  send-lifetime 00:00:00 april 01 2023 infinite

  cryptographic-algorithm MD5

 !

!

router bgp 300

 neighbor 192.168.1.1

  keychain AS300

 !



BGP MD5 Configuration on Cisco - Juniper - Nokia Interop

 In this blog, I will explain the benefits of the MD5 concept and how to configure it on Cisco, Juniper, and Nokia Router

TCP-MD5

MD5 is used to protect the BGP session between the peers to form the secured session over the public Network. 

TCP MD5 option supports only one key for a connection. Further, it only supports the MD5 algorithm. The MD5 algorithm takes the “secret” from the key and the TCP segment for encryption and generates a message digest. This message digest is then copied to the MD5 digest field in the TCP segment and is sent to the receiving device.





Cisco XR

router bgp 300
 neighbor 192.168.1.1
  password encrypted 011D03104C0414042D4D4C


Juniper

edit protocols {                             
    bgp {
        group nokia {
            neighbor 192.168.0.1 {
                authentication-key "key"; ## SECRET-DATA
                }
      
Nokia

/configure router 
protocols {                             
    bgp {
     group "juniper"
                type external
                local-as 100
                neighbor 192.168.0.2
                    authentication-key "D8XsPtn4bCNLm" hash2
                    peer-as 200
                exit


BGP Protection - TTL Security Configuratoion Cisco, Juniper and Nokia

Hi Everyone,

In the blog, I am going to explain how TTL security is useful in BGP Session protection. Time to Live will be added to every packet and it will be reduced at each hop it transfers.

Consider someone who wants to hack your BGP session and will send the spoofed  BGP packets and try to negotiate with your BGP session. to avoid this kind of spoofing we use TTL Security


TTL security is a mechanism that evaluates the TTL value of incoming IP packets to ensure

that they have not been faked. The IP TTL value will be set to 255 by directly connected BGP

peers, making it impossible to relay spoof Internet protocol with TTL=255 through non

directly connected interfaces.



Cisco XR

router bgp 100
 neighbor-group ebgp
  ttl-security
 !
neighbor 192.168.1.1
  remote-as 100
  use neighbor-group ebgp
  address-family ipv4 unicast
  !
 !


Juniper 


protocols {                             
    bgp {
        group nokia {
            type external;
            neighbor 192.168.0.1 {
                ttl <1-255>;
                peer-as 100;
                local-as 200;
            }


Nokia vSR


router bgp 
 group "juniper"
                type external
                local-as 100
                ttl-security <1-255>
                neighbor 192.168.0.2
                    peer-as 200
                exit
            exit