SP-A VPWS: an E-Line Between Two CustB Sites over the RSVP-TE Tunnel

E-Line is a point-to-point Ethernet service between two customer sites. On an MPLS network the same service is called VPWS: each PE connects the customer-facing port to a pseudowire. The two PEs exchange the pseudowire labels over a targeted LDP session. The pseudowire rides whatever LSP the PE has to the other PE: LDP, RSVP-TE or BGP labeled unicast.

This stage builds one E-Line between CustB-Hub on A-PE1 and CustB-Spk1 on A-PE2, with VC ID 2011. This is the pseudowire on A-PE1 after the stage was configured:

A-PE1#show mpls l2transport vc 2011 detail
Local interface: Gi5 up, line protocol up, Eth VLAN 11 up
  Interworking type is Ethernet
  Destination address: 10.1.0.6, VC ID: 2011, VC status: up
    Output interface: Tu10, imposed label stack {1112 1614}
    Preferred path: not configured
    Default path: active
    Next hop: point2point
  Create time: 00:14:39, last status change time: 00:13:21
    Last label FSM state change time: 00:13:21
  Signaling protocol: LDP, peer 10.1.0.6:0 up
    Targeted Hello: 10.1.0.5(LDP Id) -> 10.1.0.6, LDP is UP
    Graceful restart: not configured and not enabled
    Non stop routing: not configured and not enabled
    Status TLV support (local/remote)   : enabled/supported
      LDP route watch                   : enabled
      Label/status state machine        : established, LruRru
      Last local dataplane   status rcvd: No fault
      Last BFD dataplane     status rcvd: Not sent
      Last BFD peer monitor  status rcvd: No fault
      Last local AC  circuit status rcvd: No fault
      Last local AC  circuit status sent: No fault
      Last local PW i/f circ status rcvd: No fault
      Last local LDP TLV     status sent: No fault
      Last remote LDP TLV    status rcvd: No fault
      Last remote LDP ADJ    status rcvd: No fault
    MPLS VC labels: local 1517, remote 1614
    Group ID: local 10, remote 10
    MTU: local 1500, remote 1500
    Remote interface description: VPWS E-Line VC 2011 -> CustB-Spk1<->Hub
  Sequencing: receive disabled, send disabled
  Control Word: On
  SSO Descriptor: 10.1.0.6/2011, local label: 1517
  Dataplane:
    SSM segment/switch IDs: 4108/4105 (used), PWID: 1
  VC statistics:
    transit packet totals: receive 24, send 22
    transit byte totals:   receive 3234, send 2746
    transit packet drops:  receive 0, seq error 0, send 0

A-PE1 sends the pseudowire into Tunnel10 with two labels: 1112 is A-P1’s label for Tunnel10, and 1614 is the VC label A-PE2 advertised. No preferred path is configured, so the pseudowire follows the route to A-PE2’s loopback 10.1.0.6.

In the TE stage, autoroute destination on Tunnel10 installed a static route to 10.1.0.6/32 through the tunnel.

Topology file: topology.clab.yml · Addressing: ipam.md · Stage configs, 4 nodes (the two PEs and the two CustB CEs): stage_configs/lab02-s3a-spa-vpws/

Gi5 as an EVC Trunk

Each CustB CE has a single link to its PE, and the lab runs two L2 services for CustB on these two PEs. Gi5 on both PEs is an 802.1Q trunk with no IP address and one service instance per service: VLAN 11 for this E-Line, VLAN 12 left for an EVPN-ELAN (will be described later in the other lab).

interface GigabitEthernet5
 description CustB multi-service UNI -- VLAN11 VPWS VC2011 | VLAN12 EVPN(S3B,reserved)
 no ip address
 no ipv6 address 2001:DB8:1:22::1/64
 no keepalive
 service instance 11 ethernet
  description VPWS E-Line VC 2011 -> CustB-Hub<->Spk1
  encapsulation dot1q 11
  rewrite ingress tag pop 1 symmetric
  xconnect 10.1.0.6 2011 encapsulation mpls pw-class VPWS_CB_CW

Service instance 11 takes frames tagged 11, and its xconnect points to A-PE2’s loopback 10.1.0.6. rewrite ingress tag pop 1 symmetric removes tag 11 from frames coming from the CE and pushes it back on frames going to the CE. A-PE2 has the same service instance toward 10.1.0.5.

CustB-Hub sends VLAN 11 from a dot1Q subinterface:

interface Ethernet0/1.11
 description VPWS E-Line (VLAN 11) -> CustB-Spk1
 encapsulation dot1Q 11
 ip address 10.20.11.1 255.255.255.248
 ipv6 address 2001:DB8:20:11::1/64

The block above is trimmed to the subinterface, the full file is CustB-Hub.ios.

CustB has a third site, Spk2, attached to B-PE2 in SP-B. The subnet is a /29 so that Spk2 can use 10.20.11.3.

The Pseudowire

A pseudowire class is a set of pseudowire settings that the xconnect line points to with pw-class. Both PEs use the same one. It sets MPLS encapsulation and turns on the control word:

pseudowire-class VPWS_CB_CW
 encapsulation mpls
 control-word

The control word is an optional 4-byte field between the MPLS labels and the customer’s Ethernet frame. Core routers that load-balance MPLS traffic look at the first 4 bits after the labels: 4 means IPv4, 6 means IPv6. Without a control word, those bits are the start of the destination MAC address, so a MAC that starts with 4 or 6 looks like an IP packet. The control word starts with 0, so the routers don’t mistake the Ethernet frame for IP:

The pseudowire packet from A-PE1 to A-PE2, with and without the control word

The control word has other uses as well. It can carry a sequence number, and the far PE then drops frames that arrive out of order. A length field marks short frames that were padded, so the far PE can remove the padding. It also carries control bits for ATM and Frame Relay, and fragmentation bits for frames larger than the pseudowire MTU. Sequencing stays disabled on this pseudowire.

Each PE signals the control word with the C-bit in its LDP label advertisement for the pseudowire. If the two ends disagree, the pseudowire comes up without the control word. Without the control-word line, IOS-XE offers it and drops it when the other PE doesn’t use it. With the line on both PEs, both advertise Cbit: 1:

A-PE1#show mpls l2transport binding 2011
  Destination Address: 10.1.0.6,VC ID: 2011
    Local Label:  1517
        Cbit: 1,    VC Type: Ethernet,    GroupID: 10
        MTU: 1500,   Interface Desc: VPWS E-Line VC 2011 -> CustB-Hub<->Spk1
        VCCV: CC Type: CW [1], RA [2], TTL [3]
              CV Type: LSPV [2]
    Remote Label: 1614
        Cbit: 1,    VC Type: Ethernet,    GroupID: 10
        MTU: 1500,   Interface Desc: VPWS E-Line VC 2011 -> CustB-Spk1<->Hub
        VCCV: CC Type: CW [1], RA [2], TTL [3]
              CV Type: LSPV [2]

A pseudowire comes up only when both ends advertise the same MTU, 1500 here.

A-PE1 and A-PE2 are not directly connected, so the VC labels go over a targeted LDP session between their loopbacks:

A-PE1#show mpls ldp neigh 10.1.0.6
    Peer LDP Ident: 10.1.0.6:0; Local LDP Ident 10.1.0.5:0
        TCP connection: 10.1.0.6.40784 - 10.1.0.5.646
        State: Oper; Msgs sent/rcvd: 29/28; Downstream
        Up time: 00:13:54
        LDP discovery sources:
          Targeted Hello 10.1.0.5 -> 10.1.0.6, active, passive
        Addresses bound to peer LDP Ident:
          10.1.1.30       10.1.1.34       10.1.0.6        10.1.0.106

CustB-Hub to CustB-Spk1

A ping from CustB-Hub to CustB-Spk1 enters the pseudowire at A-PE1 and rides Tunnel10 to A-PE2:

A ping from CustB-Hub to CustB-Spk1 across the pseudowire and Tunnel10

The two CEs are on one subnet across the pseudowire, so each CE has the other CE’s MAC address in its ARP table. From CustB-Hub:

CustB-Hub#show ip int br | i Ethernet0/1
Ethernet0/1            unassigned      YES TFTP   up                    up
Ethernet0/1.11         10.20.11.1      YES manual up                    up
CustB-Hub#ping 10.20.11.2 source Eth0/1.11
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.11.2, timeout is 2 seconds:
Packet sent with a source address of 10.20.11.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/3 ms
CustB-Hub#ping 2001:db8:20:11::2 source eth0/1.11
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:20:11::2, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:20:11::1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/6 ms
CustB-Hub#show arp | i 10.20.11.2
Internet  10.20.11.2             17   aabb.cc00.1510  ARPA   Ethernet0/1.11
CustB-Hub#show ipv6 neigh Eth0/1
CustB-Hub#show ipv6 neigh Eth0/1.11
 ND cache expire time is 14400 seconds
IPv6 Address                              Age Link-layer Addr State Interface
2001:DB8:20:11::2                           0 aabb.cc00.1510  REACH Et0/1.11
FE80::A8BB:CCFF:FE00:1510                   0 aabb.cc00.1510  REACH Et0/1.11

From CustB-Spk1:

CustB-Spk1#ping 10.20.11.1 source Ethernet0/1.11
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.11.1, timeout is 2 seconds:
Packet sent with a source address of 10.20.11.2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/3 ms
CustB-Spk1#ping 2001:db8:20:11::1 source Ethernet0/1.11
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:20:11::1, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:20:11::2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/3 ms
CustB-Spk1#show arp | i 10.20.11.1
Internet  10.20.11.1             18   aabb.cc00.1410  ARPA   Ethernet0/1.11

What’s Next

The CustA L3VPN between HQ and Br1 still works over IPv4 and IPv6:

CustA-HQ#ping 10.10.0.2 source lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.0.2, timeout is 2 seconds:
Packet sent with a source address of 10.10.0.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/3 ms
CustA-HQ#ping 2001:db8:10::2 source lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:10::2, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:10::1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/4/13 ms

The next stage adds the EVPN-ELAN on VLAN 12 of the same Gi5 ports.

Leave a comment