Showing posts with label routing. Show all posts
Showing posts with label routing. Show all posts

Wednesday, August 17, 2011

good routing website

http://packetlife.net/
http://www.net-gyver.com/?p=1105
http://showipbgp.com/
http://routemyworld.com/

Sharing Koneksi Internet dengan Routing Static dengan Speedy menggunakan Windows 2003

Kondisi:
  • Tersedia 1 Modem ADSL (di lab ini menggunakan Aztech 605)
  • Tersedia 1 Switch untuk LAN
  • Pada Server windows 2003 tersedia 2 NIC, di Lab ini namanya NIC Atas (tersambung ke modem ADSL) dan NIC Tengah (tersambung ke Switch)
IP dari NIC Atas adalah :192.168.1.5
Subnet Mask :255.255.255.0
Gateway :192.168.1.1
IP dari NIC Tengah adalah :192.168.0.1
Subnet Mask :255.255.255.0

Friday, July 22, 2011

Static Route | indonesia


Pada suatu jaringan bisnis berskala besar atau enterprise yang terdiri dari banyak lokasi yang tersebar secara remote, maka komunikasi antar site dengan management routing protocol yang bagus adalah suatu keharusan. Baik static route ataupun dynamic routing haruslah di design sedemikian rupa agar sangat efficient.
Suatu static route adalah suatu mekanisme routing yang tergantung dengan routing table dengan konfigurasi manual. Disisi lain dynamic routing adalah suatu mekanisme routing dimana pertukaran routing table antar router yang ada pada jaringan dilakukan secara dynamic. Lihat juga artikel memahami IP routing protocols.
Dalam skala jaringan yang kecil yang mungkin terdiri dari dua atau tiga router saja, pemakaian static route lebih umum dipakai. Static router (yang menggunakan solusi static route) haruslah di configure secara manual dan dimaintain secara terpisah karena tidak melakukan pertukaran informasi routing table secara dinamis dengan router-router lainnya. Lihat juga artikel tentang memahami hardware router.
Suatu static route akan berfungsi sempurna jika routing table berisi suatu route untuk setiap jaringan didalam internetwork yang mana dikonfigure secara manual oleh administrator jaringan. Setiap host pada jaringan harus dikonfigure untuk mengarah kepada default route atau default gateway agar cocok dengan IP address dari interface local router, dimana router memeriksa routing table dan menentukan route yang mana digunakan untuk meneruskan paket. Lihat juga DNS forwarding untuk memahami default gateway.
Konsep dasar dari routing adalah bahwa router meneruskan IP paket berdasarkan pada IP address tujuan yang ada dalam header IP paket. Dia mencocokkan IP address tujuan dengan routing table dengan harapan menemukan kecocokan entry – suatu entry yang menyatakan kepada router kemana paket selanjutnya harus diteruskan. Jika tidak ada kecocokan entry yang ada dalam routing table, dan tidak ada default route, maka router tersebut akan membuang paket tersebut. Untuk itu adalah sangat penting untuk mempunyai isian routing table yang tepat dan benar.
Static route terdiri dari command-command konfigurasi sendiri-sendiri untuk setiap route kepada router. sebuah router hanya akan meneruskan paket hanya kepada subnet-subnet yang ada pada routing table. Sebuah router selalu mengetahui route yang bersentuhan langsung kepada nya – keluar interface dari router yang mempunyai status “up and up” pada line interface dan protocolnya. Dengan menambahkan static route, sebuah router dapat diberitahukan kemana harus meneruskan paket-paket kepada subnet-subnet yang tidak bersentuhan langsung kepadanya.
Gambar berikut adalah contoh diagram agar memudahkan kita memahami bagaimana kita harus memberikan konfigurasi static route kepada router. Pada contoh berikut ini dua buah ping dilakukan untuk melakukan test connectivity IP dari Sydney router kepada router Perth.
Digram router static route
Router Sydney melakukan beberapa EXEC command dengan hanya kepada router-router yang terhubung langsung kepadanya.
Sydney#show ip route
Codes: C – connected, S – static, I – IGRP, R – RIP, M – mobile, B – BGP
D – EIGRP, EX – EIGRP external, O – OSPF, IA – OSPF inter area
N1 – OSPF NSSA external type 1, N2 – OSPF NSSA external type 2
E1 – OSPF external type 1, E2 – OSPF external type 2, E – EGP
i – IS-IS, L1 – IS-IS level-1, L2 – IS-IS level-2, ia – IS-IS inter area
* – candidate default, U – per-user static route, o – ODR
P – periodic downloaded static route
Gateway of last resort is not set
10.0.0.0/24 is subnetted, 3 subnets
C 10.20.1.0 is directly connected, Ethernet0
C 10.20.130.0 is directly connected, Serial1
C 10.20.128.0 is directly connected, Serial0
Sydney#ping 10.20.128.252
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.128.252, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/8 ms
Sydney#ping 10.20.2.252
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.2.252, timeout is 2 seconds:
…..
Success rate is 0 percent (0/5)
Command ping mengirim paket pertama dan menunggu response. Jika diterima adanya respon, maka command menampilkan suatu karakter “!”. Jika tidak ada response diterima selama default time-out 2 seconds, maka command ping menampilkan response suatu karakter “.”. secara default router Cisco dengan command ping menampilkan 5 paket.
Pada contoh diagram diatas, command ping 10.20.128.252 adalah jalan bagus, akan tetapi untuk command ping 10.20.2.252 justru tidak jalan. Command ping pertama berjalan OK karena router Sydney mempunyai suatu route kepada subnet dimana 10.20.128.252 berada (pada subnet 10.20.128.0). akan tetapi, command ping 10.20.2.252 tidak jalan karena subnet dimana 10.20.2.252 berada (subnet 10.20.2.0) tidak terhubung langsung kepada router Sydney, jadi router Sydney tidak mempunyai suatu route pada subnet tersebut.
Untuk mengatasi masalah ini, maka perlu di-enabled pada ketiga router dengan routing protocols. Untuk konfigurasi sederhana seperti contoh diagram diatas, penggunaan route static adalah suatu solusi yang memadai.
Maka untuk router Sydney harus diberikan konfigurasi static route seperti berikut ini:
Ip route 10.20.2.0 255.255.255.9 10.20.128.252
Ip route 10.20.3.0 255.255.255.0 10.20.130.253
Pada command ip route haruslah diberikan nomor subnet dan juga IP address hop (router) berikutnya. Satu command ip route mendefinisikan suatu route kepada subnet 10.20.2.0 (mask 255.255.255.0), dimana berlokasi jauh di router Perth, sehingga IP address pada hop berikutnya pada router Sydney adalah 10.20.128.252, yang merupakan IP address serial0 dari router Perth. Serupa dengannya, suatu route kepada 10.20.3.0 yang merupakan subnet pada router Darwin, mengarah pada serial0 pada router Darwin yaitu 10.20.130.253. Ingat bahwa IP address pada hop berikutnya adalah IP address pada subnet yang terhubung langsung – dimana tujuannya adalah mengirim paket pada router berikutnya. Sekarang router Sydney sudah bisa meneruskan paket kepada kedua subnet di luar router tersebut (yang tidak bersentuhan pada router Sydney).
Anda bisa melakukan konfigurasi static route dengan dua cara yang berbeda. Dengan serial link point-to-point, anda juga bisa melakukan konfigurasi kepada interface outgoing ketimbang pada IP address router pada hop berikutnya. Misalkan anda bisa mengganti ip route diatas dengan command yang sama yaitu ip route 10.20.2.0 255.255.255.0 serial0 pada router pertama pada contoh diatas.
Kita sudah memberikan konfigurasi pada router Sydney dengan menambahkan static route, sayangnya hal ini juga belum menyelesaikan masalah. Konfigurasi static route pada router Sydney hanya membantu router tersebut agar bisa meneruskan paket pada subnet berikutnya, akan tetapi kedua router lainnya tidak mempunyai informasi routing untuk mengirim paket balik kepada router Sydney.
Misalkan saja, sebuah PC Jhonny tidak dapat melakukan ping ke PC Robert pada jaringan ini. Masalahnya adalah walaupun router Sydney mempunyai route ke subnet 10.20.2.0 dimana Robert berada, akan tetapi router Perth tidak mempunyai route kepada 10.20.1.0 dimana Jhonny berada. Permintaan ping berjalan dari PC Jhonny kepada Robert dengan baik, akan tetapi PC Robert tidak bisa merespon balik oleh router Perth kepada router Sydney ke Jhonny, sehingga dikatakan respon ping gagal.
Keuntungan static route:
  • Static route lebih aman disbanding dynamic route
  • Static route kebal dari segala usaha hacker untuk men-spoof paket dynamic routing protocols dengan maksud melakukan configure router untuk tujuan membajak traffic.
Kerugian:
  • Administrasinya adalah cukup rumit disbanding dynamic routing khususnya jika terdiri dari banyak router yang perlu dikonfigure secara manual.
  • Rentan terhadap kesalahan saat entry data static route dengan cara manual.

Static Route


In large scale enterprise computer network which span in multiple remote places, communication between sites with a well routing design is very essential. Both static route and dynamic route must be designed as efficient as possible. See types of WAN technologies.
A static route is a routing mechanism that depends on manually configured routing tables. Dynamic route is a routing mechanism for dynamically exchanging routing information among routers on an internetwork.
In smaller networks that contain only a couple of routers, the design of the static route is generally used. Static routers (routers that use static route) must be configured and maintained separately because static routers do not exchange routing information with each other. See also basic hardware of the router.
A static route will function properly when the routing table contains a route for every network in the internetwork which is configured manually by the administrator. Each host on the network must be configured to point their default gateway to match the Internet Protocol (IP) address of the local router interface. When a host needs to send a packet to another network, it forwards the packet to the local router, which checks its routing table and determines which route to use to forward the packet.
The basic concept of the routing (both static route and dynamic route) is that routers forward IP packets based on the destination IP address in the IP packet header. They compare the destination address to the routing table with the hope of finding a matching entry – an entry that tells the router where to forward the packet next. If the router does not match an entry in the routing table, and no default route exists, the router discards the packet. Therefore, having a full and accurate routing table is important.
Static routing consists of individual configuration commands that define a route to a router. A router can forward packets only to subnets in its routing table. The router always knows about directly connected routes—routes to subnets off interfaces that have an “up and up” status. By adding static routes, a router can be told how to forward packets to subnets that are not attached to it.
The following figure can be used to describe how to configure the static route. Two ping commands test the IP connectivity from Sydney router to Perth router.
An example of static route - implementation diagram
Sydney router EXEC Commands with only connected routers
Sydney#show ip route
Codes: C – connected, S – static, I – IGRP, R – RIP, M – mobile, B – BGP
D – EIGRP, EX – EIGRP external, O – OSPF, IA – OSPF inter area
N1 – OSPF NSSA external type 1, N2 – OSPF NSSA external type 2
E1 – OSPF external type 1, E2 – OSPF external type 2, E – EGP
i – IS-IS, L1 – IS-IS level-1, L2 – IS-IS level-2, ia – IS-IS inter area
* – candidate default, U – per-user static route, o – ODR
P – periodic downloaded static route
Gateway of last resort is not set
10.0.0.0/24 is subnetted, 3 subnets
C 10.20.1.0 is directly connected, Ethernet0
C 10.20.130.0 is directly connected, Serial1
C 10.20.128.0 is directly connected, Serial0
Sydney#ping 10.20.128.252
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.128.252, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/8 ms
Sydney#ping 10.20.2.252
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.2.252, timeout is 2 seconds:
…..
Success rate is 0 percent (0/5)
The ping command sends the first packet and waits on the response. If a response is received, the command displays a “!”. If no response is received within the default timeout of 2 seconds, the ping command displays a “.”. The IOS ping command sends 5 of these packets by default.
In the above figure example, the ping 10.20.128.252 command works, but the ping 10.20.2.252 command does not. The first ping command works because Sydney has a route to the subnet in which 10.20.128.252 resides (subnet 10.20.128.0). However, the ping to 10.20.2.252 does not work, because the subnet in which 10.20.2.252 resides, subnet 10.20.2.0, is not connected to Sydney, so Sydney does not have a route to that subnet.
To resolve this problem, routing protocols on all three routers should be enabled. For a simple network with 3 routers like in the above figure, a static route configuration would be a reasonable solution.
Static route in Sydney must be added as follows:
Ip route 10.20.2.0 255.255.255.9 10.20.128.252
Ip route 10.20.3.0 255.255.255.0 10.20.130.253
The ip route commands supply the subnet number and the next-hop IP address. One ip route command defines a route to 10.20.2.0 (mask 255.255.255.0), which is located off Perth, so the next-hop IP address as configured on Sydney is 10.20.128.252, which is Perth’s Serial0 IP address. Similarly, a route to 10.20.3.0, the subnet off Darwin, points to Darwin’s Serial0 IP address, 10.20.130.253. Note that the next-hop IP address is an IP address in a directly connected subnet—the goal is to define the next router to send the packet to. Now Sydney can forward packets to these two subnets.
You can configure static routes in a couple different ways. With point-to-point serial links, you can also configure the outgoing interface instead of the next-hop IP address. For instance, you could have configured ip route 10.20.2.0 255.255.255.0 serial0 for the first route in the above example.
Unfortunately, adding these two static routes to Sydney does not solve all the network’s routing problems. The static routes help Sydney deliver packets to these two subnets, but the other two routers don’t have enough routing information to forward packets back toward Sydney.
For instance, PC Jhonny cannot ping PC Robert in this network. The problem is that although Sydney has a route to subnet 10.20.2.0, where Robert resides, Perth does not have a route to 10.20.1.0, where Jhonny resides. The ping request packet goes from Jhonny to Robert correctly, but Robert’s ping response packet cannot be routed by the Perth router back through Sydney to Jhonny, so the ping fails.
Pros:
  • Static route is more secure than dynamic route
  • Static route is immune from attempts by hackers to spoof dynamic routing protocol packets in order to reconfigure the router and try to hijack network traffic.
Cons:
  • Administration is more difficult than dynamic routing particularly when there are many routers need to be configured manually.
  • Prone to the mistyping during manual configuration

Understanding Link State Routing Protocol


In the previous articles, the basic concept about the IP routing protocol and guideline has been discussed. And a comprehensive knowledge about the basic concept of the distance vector routing has been discussed too. Distance vector routing is fine for small to medium sized networks. But for enterprise class sized networks, a more robust method is required. The link state method offers several advantages over the distance vector method.
Link-state and distance vectors share a common goal—filling the routing tables with the currently-best routes. They differ significantly in how they accomplish this task. The largest difference between the two is that distance vector protocols advertise sparse information. In fact, distance vector protocols know that other routers exist only if the other router broadcasts a routing update to them.
When a distance vector protocol in a router receives a routing update, the update says nothing about the routers beyond the neighboring router that sent the update. Conversely, link-state protocols advertise a large amount of topological information about the network, and the routers perform some CPU-intensive computation on the topological data. They even discover their neighbors before exchanging routing information.
The figure illustrates a graphical representation how the router advertises with a link-state protocol. Router B tells Router A the metric associated with every link in the network, rather than Router B’s telling Router A what the metric (or cost) for the route should be. Besides, router B also tells router A about all the routers in the network, including which subnets they are attached to and their status. It’s like a map of a mathematical model of the network based on the topology information.
The link-state protocol on Router A calculates the lowest-cost route to all subnets based on the topology information, including the route to subnet 10.1.1.0, mask 255.255.255.0. When more than one route to a subnet exists, the link-state routing protocol chooses the lowest metric. Packets traveling to 10.1.1.0 from Router A go through Router C because this route has the lower cost.
Unlike distance vector protocols, link-state protocols must calculate the metric instead of simply being told the metric in the received routing update. For instance, with distance vector protocols, Router B tells Router A something like “subnet 10.1.1.0, metric 3.” With link state protocols, the topology information learned by a router includes a cost associated with each link in the network. A router totals the cost associated with each link in each route to find the metric associated with the route.
For instance, Router A discovers two routes to subnet 10.1.1.10, with a metric of 220 for the route to 10.1.1.0 through Router C and a metric of 310 for the route to 10.1.1.0 through Router D. In both cases, Router A uses Router B as the next hop. Therefore, Router A puts a route to 10.1.1.0 in its routing table, using Router B’s interface IP address as the next hop. Similarly, Router B calculates routes to 10.1.1.0 through Router C and Router D and places the better route (through Router C) in Router B’s routing table.
LinkState Routing protocols conceptual diagram
The algorithm used to calculate routes with link-state protocols is called the Shortest Path First (SPF) algorithm or Dijkstra SPF algorithm.
Link-state protocols do not just start broadcasting topology information out every interface when the router first boots. Instead, link-state protocols first use a process by which they discover neighbors. (Neighbors can also be statically defined instead of being discovered.)
Neighbors are other routers, also running the same link-state protocol, that share a common subnet. As soon as routers know that they are neighbors, they can exchange their respective copies of the topology information—called the topology database—and then run SPF to calculate new routes.
After a router identifies a neighbor, they exchange the information in their topology databases. The routing updates sent by an OSPF router are called link-state updates (LSUs), and the items sent in an LSU include individual link-state advertisements (LSAs). For instance, a link LSA describes a subnet number and mask, the cost (metric), and other information about the subnet. Also, OSPF uses a reliable protocol to exchange routing information, ensuring that lost LSU packets are retransmitted.
Keep in mind the following information about the links state method:
  • Routers broadcast LSPs to all routers (this process is known as flooding)
  • Routers send information about only their own links
  • LSPs are sent at regular intervals and when any of the following conditions occur:
    • There is a new neighbor
    • A neighbor has gone down
    • The cost to a neighbor has changed
    • Routers use LSPs to build their tables and calculate the best route
    • Routers select routes based on the shortest route using an algorithm known as shortest path first (SPF)
    • Network administrators have greatest flexibility in setting the metrics used to calculate routes
The link state method is less susceptible to routing loops, but requires more complicated routines to discover the network and calculate the best paths.
Links state problems and solutions
Although more stable than the distance vector method, the link state method has the following problems:
  • It requires more router resources (processor power and memory)
  • It generates high amount of traffic when LSPs are initially flooded through the network. however, after the initial configuration occurs, the traffic from the l inks state method is smaller than that from the distance vector method
  • It is possible for LSPs to get delayed or lost, resulting in an inconsistent view of the network. This is particularly a problem for larger networks, if parts of the network come on line at different times, of if the bandwidth between links vary (i.e. LSPs travel faster through parts of the network than through others.
In particularly, the last problem is of the greatest concern. The following solutions are often implemented to overcome some of the effects of inconsistent LSP information.
  • Slowing the LSP update rate keeps information more consistent
  • Routers can be grouped into areas. Routers share information within the area, and routers on area borders share information between areas.
  • LSPs can be identified with a time stamp, sequence or ID number, or aging timer to ensure proper synchronization.
  • One router in each area is designated as the authoritative source of routing information (called a designated router). Each area router receives updates from the designated router.
Link State advantages and disadvantages
The link state method has the following advantages over the distance vector method
  • Less convergence time (because updates are forwarded immediately)
  • Not susceptible to routing loops
  • Less susceptible to erroneous information (because only firsthand information is broadcast)
  • Bandwidth requirements negligible for a typical LAN environment
Link state has the following disadvantages:
  • The link state algorithm requires greater CPU and memory capability to calculate the network topology and select the route
  • Increased network traffic when the topology changes
Link state routing protocols are typically used by enterprise networks which consist of many offices around the world, or used by ISPs.

Routing Guide - Concept and Guidelines


In large-sized business networks with many remote branch offices, connecting each business units / branch offices typically implemented using any types of available WAN technology services. A router connects two networks or branch offices. A network is s segment with a unique network address. With regards to IP, the term network can be used to define two different things. Firstly, a segment with a unique IP address – typically refers to a subnet. Secondly, an IP address assigned to an organization. Speaking about connecting two different networks (typically via WAN cloud) you should understand about IP routing. The following section will discuss IP routing guide. See also basic knowledge about static route and alsoconcept of link state routing protocols
A subnet in IP routing guide is a summary address representing a group of adjacent hosts. In a very large network, such as the public Internet or a large corporate network, it is impractical to keep track of every individual device. Instead, the IP protocol groups devices together into subnets. And, similarly, you can summarize adjacent groups of subnet addresses. The result is an extremely efficient hierarchical addressing system. See also calculating the subnet networks.
In IP routing guide you should also be familiar with two different sets of rules for how groups of subnets can be summarized together. The older method uses a concept called class, while the newer method is classless and is often referred to by the acronym CIDR, for Classless Inter-Domain Routing which is extensively used in internet. To enable the CIDR, you can use the ip classless command in global configuration mode, and to disable it you can use no ip classless.
The biggest difference between classful and classless addressing is that classful addressing assumes that the first few bits of the address can tell you how big the network is. The previous article we have discussed about the IP address design and we know that there are 3 main IP address classes as in the following table.
Class TypeStart AddressEnd Address
Class A10.0.0.010.255.255.254
Class B172.16.0.0172.31.255.254
Class C192.168.0.0192.168.255.254
Several subnets within a Class A, B, or C network can be created. But for larger network structure, you can use CIDR that groups the networks into a single entire network which is called supernet. For example with the networks 192.168.100.0/24; 192.168.101.0/24; 192.168.102.0/24; and 192.168.103.0/24 can be summarized into 192.168.100.0/22 or in general writing as 192.168.100.0 255.255.252.0 in netmask notation.
Classless routing can use a mask of any length when looking for the best route to a destination, but classful routing cannot. For example on the above supernet 192.168.100.0/22, a router using classful routing would not consider the destination address 192.168.105.15 to be a part of 192.168.104.0/22 because it knows that anything beginning with 192 must be a Class C network. Instead, if there was no specific route for 192.168.105.0/24 or a subnet containing this destination, the router would skip straight to the default route. If you mix classless and classful routing, this could be the wrong path, and in the worst case, it could even cause a routing loop.
This is why it is so important to make sure that you are consistent about which type of routing and addressing you want to use. In general, it is better to use CIDR because of the improved flexibility it offers. Also, since CIDR allows more levels of route summarization, you can often simplify your routing tables so that they take up less memory in the routers. This, in turn, can improve network performance.
Before we need to discuss deeper about IP routing guide, we should understanding the concept about IP routing protocols. IP routing protocols fill the IP routing table with valid routes and (hopefully) loop-free routes. Each route includes a subnet number, the interface out which to forward packets so that they are delivered to that subnet, and the IP address of the next router that should receive packets destined for that subnet (if needed).
Before examining the underlying logic in this IP routing guide, considering the goals of a routing protocol is needed. The goals described in the following list are common for any IP routing protocol, regardless of its underlying logic type:
  • To dynamically learn and fill the routing table with a route to all subnets in the network.
  • If more than one route to a subnet is available, to place the best route in the routing table.
  • To notice when routes in the table are no longer valid, and to remove those routes from the routing table.
  • If a route is removed from the routing table and another route through another neighboring router is available, to add the route to the routing table. (Many people view this goal and the preceding one as a single goal.)
  • To add new routes, or to replace lost routes with the best currently available route as quickly as possible. The time between losing the route and finding a working replacement route is called convergence time.
  • To prevent routing loops.
Routing protocols in this routing guide basically is simple logic but can become rather complicated. Routing protocols take the routes in a routing table and send a message to their neighbors telling them about the routes. After a while, everyone has heard about all the routes.
Figure below shows a sample network for IP routing guide explanation, with routing updates shown. Table A lists Router B’s routing table before receiving the routing updates; and table B lists Router B’s routing table after receiving the routing updates.
IP Routing guide
Table A – Router B Routing table before receiving the update shown in the above networking diagram.
GroupOutgoing InterfaceNext-hop routerMetricDescription
162.11.7.0E0-0This is a directly connected route
162.11.8.0S0-0This is a directly connected route
Table B – Router B Routing Table After Receiving the Update Shown in the above networking diagram.
GroupOutgoing InterfaceNext-hop routerMetricDescription
162.11.5.0S0162.11.8.11Learned from Router A, so next-hop
is Router A.
162.11.7.0E0-0This is a directly connected route
162.11.8.0S0-0This is a directly connected route
162.11.9.0S0162.11.8.11Learned from Router A, so next-hop is Router A.
162.11.10.0S0162.11.8.12This one was learned from Router A,
which learned it from Router C.
Router B adds routes for directly connected subnets when the interfaces first initialize. In fact, no routing protocols are needed for a router to learn routes to the directly connected subnets. So, before Router B receives any routing updates, it knows about only two routes—the two connected routes—as listed in Table A. After receiving the update from Router A, Router B has learned three more routes. Because Router B learned those routes from Router A, all three of B’s routes point back to Router A as the next hop router. That makes sense because it is obvious from the figure that B’s only path to the other subnets lies through Router A.
Router A learned about subnets 162.11.5.0 and 162.11.9.0 because A is connected directly to those subnets. Router A, in turn, learned about subnet 162.11.10.0, the subnet off Router C’s Ethernet, from routing updates sent by Router C.

Inter VLAN Routing


Modern Switches allow you create Virtual LANs to divide the network into segments to limit the size of broadcast domain, to enforce better security, and separate specialized traffic from mainstream traffic. But Switches do not forward frames between different VLANs. Inter VLAN routing mechanism is needed to allow communication between VLANs.
Since the Switch is layer 2 device, it cannot forward frames between VLAN, to allow communication between VLANs you need a Layer 3 device as described on the following diagram. So to allow Inter VLAN routing, a router is used to forward frames between VLANs.
Inter VLAN Routing
Inter VLAN Routing
You can see in this example that there are three VLAN each corresponds to different subnet. The router needs an interface in each subnet to forward traffic between the subnets to allow Inter VLAN routing communication. Each router interface connects to each of the Switch interfaces that correspond to each VLAN1, VLAN2, and VLAN3. Each of hosts in each VLAN if they need to communicate to other VLANs, they have to send their packets to the router, which then forward them to another interface into the other VLAN.
Inter VLAN routing communication using the above method where each subnet / VLAN needs an interface connected to each router interface is wasteful. Therefore you need a router with Fast Ethernet port that supports trunking and use a single physical connection from the router to the switch.
Inter VLAN Routing Using Layer 3 Switch
Layer 3 Switches have the capability of routing features. So you don’t need a router for Inter VLAN routing to allow communication between VLANs. The only difference between routing using a router and a Layer 3 switch lies in the internal processing. L3 switches used specialized hardware to make the forwarding process run very fast. The actual receipt, changing of headers, and forwarding of the packets uses the same high-speed internal processing of the L2 switch. The L3 switch also includes the software used to run other processes, such as Inter VLAN routing protocols.
Inter VLAN Routing Using Layer 4 Switching
Layer 4 Switching considers the information in the Layer 4 headers when forwarding the packet. The forwarding decisions in some cases are based upon information inside the Layer 4 headers, and the other cases based on layer 3 headers, but the switch does accounting based on the Layer 4 headers. Inter VLAN Routing decision in Layer 4 Switching include the function of TCP and UDP port numbers.
The application process of the sender and the receiver of a packet are identified by the port numbers. Decision to where to forward the packet based on the information in the TCP or UDP header, typically the port numbers. Alternately, L4 Switch can also simply keep track of the numbers of packets and bytes sent per TCP port number, while still performing Layer 3 forwarding.
Inter VLAN routing using Layer 4 Switching can be described as in the following example diagram below where L4 switch making its forwarding decisions based on the TCP port number.
L4 Switching
L4 Switching
The figure shows a server farm, with two servers that have replicated web content, meaning that either server can be used to serve any user. The third server processes all FTP traffic—so when a user of the web server clicks something to start an FTP download, the download comes from SVR-3.
Suggested readings:
Source: Cisco.Com

Thursday, July 21, 2011

Routing


Mengingat Kembali Router

Router dibutuhkan untuk alasan-alasan berikut:
  • Router menyediakan mekanisme pengiriman yang diperlukan untuk IP addressing (lihat Internet Layer dan Subnetting). Kerapian dan efisiensi dari network yang hirarkis dan juga konsep subnet membutuhkan perangkat network yang dapat mengarahkan datagram berdasarkan IP address.
  • Router mem-filter traffik sehingga setiap komputer tidak perlu menerima pesan yang datang dari setiap komputer lainnya. Seperti yang sudah dibahas pada Network Hardware, switch juga mem-filter traffik, tetapi umumnya switch mem-filter berdasarkan physical address bukan IP address sehingga switch tidak begitu effektif pada network berskala besar.
  • Router menutupi detail dari physical network. Karena IP forwarding terjadi diatas network access layer, router dapat menghubungkan tipe-tipe network yang berbeda-beda. Sebuah komputer pada LAN ethernet di Bandung dapat berkomunikasi dengan komputer lain pada LAN token ring di Surabaya.

IP Forwarding

Deskripsi singkat mengenai proses IP Forwarding seperti berikut:
  1. Sebuah mesin ingin mengirimkan IP datagram. Mesin tersebut mengecek “tabel routing“nya.
  2. Jika datagram tidak bisa dikirimkan dalam network lokal, maka mesin akan mencari IP address dari router yang bisa menyampaikan datagram pada network tujuan. (biasanya IP address router dalam satu segment merupakan default gateway bagi mesin-mesin pada segment network tersebut). IP address router ini kemudian dipetakan ke physical address menggunakan ARP.
  3. Datagram tadi kemudian diserahkan kepada Network Access Layer dengan physical address tujuan adalah router. (tapi tetap IP address tujuannya adalah tetap IP address mesin tujuan yang ada di network lain).
  4. Network adapter (kartu jaringan) router menerima frame tersebut karena physical address tujuan dari frame tersebut cocok dengan physical address milik router.
  5. Router kemudian membongkar frame tersebut dan menyerahkan datagram ke layer atas kepada Internet Layer.
  6. Router mengecek IP address datagram. Jika IP address destination (tujuan) dari datagram tersebut sesuai dengan IP address router, berarti datagram memang ditujukan buat router itu sendiri. Jika IP address tujuan dari datagram tersebut tidak sesuai dengan IP address router, maka router akan berusaha mem-forward datagram dengan mengecek tabel routing untuk mencari jalur yang sesuai untuk mencapai network tujuan datagram tersebut.
  7. Jika datagram tidak bisa dikirimkan pada network yang terhubung langsung (directly connected) dengan router, maka router akan menyerahkan datagram tersebut kepada router lain, dan proses berulang dari langkah 1 sampai router terakhir dapat menyerahkan datagram langsung kepada mesin tujuan.
ip-forwarding
Perlu diingat bahwa sebuah perangkat tidak akan berperan sebagai router hanya karena memiliki 2 network adapter. Kecuali jika perangkat tersebut sudah mempunyai software yang dibutuhkan untuk bisa melakukan IP Forwarding, maka data tidak akan diserahkan dari satu interface ke interface lain. Ketika komputer yang tidak dikonfigurasi sebagai router menerima datagram yang tidak ditujukan untuk dirinya, maka datagram tersebut akan diabaikan.

Direct Vs Indirect Routing

Jika sebuah router hanya terhubung pada dua segment/subnet, maka tabel routingnya bisa jadi sangat sederhana. Router pada gambar dibawah ini tidak akan melihat IP address yang tidak berhubungan dengan ip address dari salah satu port/interface nya. Dengan kata lain, pada gambar dibawah, router bisa mengirimkan semua datagram dengan direct routing (routing ke network yang terhubung langsung/directly connected).
2-direct-routing
Sedangkan pada gambar dibawah ini, bagaimana caranya Router A bisa menemukan segment 3? Bagaimana Router A bisa tahu bahwa datagram yang ditujukan untuk segment 3 harus dikirim ke router B bukan C?
indirect-routing
Ada 2 cara agar router dapat mengetahui jalur ke network yang tidak terhubung langsung (indirect routes)
  • Dari sistem administrator (static routing, lihat Network Hardware)
  • Atau, dari router lainnya.
Static routing kadang-kadang lebih effektif untuk network yang kecil, sederhana dan permanent (topologi tidak berubah). Tapi jika jumlah segment-segment network semakin banyak dan kemungkinan jalur/route meningkat, maka statik routing jadi tidak effektif untuk network seperti ini.
Untuk itulah, umumnya router-router saat ini menerapkan dynamic routing. Router-router saling berkomunikasi satu sama lain untuk berbagi informasi segment dan jalur network, kemudia setiap router membangung tabel routingnya sendiri-sendiri berdasarkan informasi yang didapat dari proses tadi.

Algoritma Dynamic Routing

Ada beberapa protokol routing yang saat ini masih digunakan, umumnya di desain dengan salah satu dari 2 metode berikut:
  • Distance vector routing
  • Link state routing
Distance Vector Routing
Distance vector routing di desain untuk meminimalisir komunikasi yang dibutuhkan antar-router dan juga untuk meminimalisir jumlah data yang ada pada tabel routing. Filosofi utamanya adalahrouter tidak harus mengetahui semua jalur ke semua network secara lengkap. Router hanya harus tahu kemana datagram harus diarahkan (karenanya disebut vector). Router yang menggunakan algoritma distance vector berusaha mengoptimumkan jalur dengan meminimalisir jumlah router yang harus disinggahi oleh datagram. Parameter ini disebut hop count.
Distance vector routing bekerja seperti berikut:
  1. Ketika router A mulai aktif, ia akan tahu segment-segment mana yang terhubung langsung (directly connected) dan menempatkan segment-segment tersebut pada tabel routingnya. Hop countke setiap segment/network yang terhubung langsung (directly connected) adalah 0, karena datagram tidak perlu singgah ke router lain untuk mencapainya.
  2. Saat router A menerima pesan routing dari router tetangga (router B), ia akan mengintegrasikan informasi routing tersebut sebagai berikut :
    • Jika router B mengetahui informasi tentang segment network yang router A tidak punya didalam tabel routingnya, maka rouer A akan menambahkan segment tersebut kedalam tabel routingnya. Next hop dari segment baru tersebut adalah router B, yang berarti jika router A menerima datagram yang ditujukan untuk segment baru tersebut, maka router A akan menyerahkannya pada router B. hop count dari segment tersebut adalah hop count dari router B ditambah 1.
    • Jika router B mengirimkan informasi segment dimana router A sudah punya dalam tabel routingnya, maka router A akan menambahkan 1 angka pada hop count yang diterima dari router B dan membandingkannya dengan hop count pada informasi segment yang sudah diketahui pada tabel routingnya sendiri. Jika jalur yang melalui router B lebih effisien (hop count nya lebih kecil) maka router A akan memperbarui tabel routingnya dan menjadikan router B sebagai next hop yang baru untuk segment tersebut.
    • Jika  hop count router A yang lebih kecil maka tabel routing router A tidak berubah.
Contoh update distance vector routing dapat dilihat pada gambar berikut.
dvp
Link State Routing
Filosofi link state routing adalah setiap router berusaha membangun peta internal dari topologi network. Setiap router secara periodik mengirimkan pesan status kedalam network. Pesan status ini berisi list informasi network pada router lain yang terhubung langsung dan juga status dari link tersebut. Router menggunakan pesan status tersebut untuk membuat sebuah peta dari topologi network. Saat router harus mem-forward sebuah datagram, maka ia akan memilih jalur terbaik mencapai tujuan berdasar pada peta tersebut.
Link state protocols membutuhkan waktu pemrosesan yang lebih lama, tapi konsumsi bandwidth berkurang karena setiap router tidak perlu menyebarkan tabel routingnya secara lengkap. Juga, lebih mudah untuk melacak problem dalam network karena pesan status yang diberikan.

Routing pada Network Complex

Dalam Internet terdapat ribuan router, jadi tidak mungkin untuk semua router saling berbagi informasi untuk proses routing. Juga jika setiap router harus memproses setiap router lain di Internet maka traffik protokol routing dan isi tabel routing jadi terlalu padat.
Dalam Internet, group kecil dari router-router inti bertindak sebagai backbone pusat bagi internetwork, menghubungkan network-network individu yang yang di konfigurasi dan di manage secara autonomous. Router-router inti ini mengetahui informasi setiap network, walaupun tidak harus mengetahui informasi setiap subnetnya. Selama datagram dapat menemukan jalur menuju router inti, ia dapat mencapai tempat mana saja dalam sistem. Router-router dibawah router inti tidak harus tahu semua network di dunia, hanya harus tahu bagaimana mencapai router inti.
Perhatikan gambar dibawah. Router-router inti dalam backbone network mengantarkan pesan antar network. Network-network mandiri yang disebut autonomous system terhubung pada router inti. Pemilik autonomous system me-manage detail konfigurasi setiap router-nya. Router-router dalam satu autonomous system berbagi saling informasi network untuk membangun tabel routing masing-masing.
backbone
  • Core routers: router inti mempunyai informasi lengkap tentang router inti yang lain. Tabel routingnya berupa peta dimana network-network autonomous system terhubung pada router inti. Router inti tidak memiliki informasi detail mengenai routing internal didalam autonomous system. Beberapa contoh protocol routing router inti adalah Gateway-to-Gateway Protocol (GGP) dan SPREAD.
  • Exterior routers: Exterior routers adalah router-router non-inti yang mengkomunikasikan informasi-informasi router antar network autonomous. Protokol yang sekarang dipakai adalah Border Gateway Protocol (BGP).
  • Interior routers: router-router didalam sebuah autonomous sistem yang saling berbagi informasi network disebut interior gateways. Router-router ini menggunakan protokol routing yang disebut Interior Gateway Protocols (IGP). Contoh protokol interior routing adalah Routing Information Protocol (RIP) dan Open Shortest Path First (OSPF).

Lebih Dekat dengan Interior Router

Beberapa interior protokol routing yang terkenal antara lain :
  • Routing Information Protocol (RIP)
  • Open Shortest Path First (OSPF)

Routing Information Protocol (RIP)

RIP termasuk protokol distance vector, yang berarti ia menentukan jalur terbaik berdasarkan hop count. Mesin-mesin yang ikut berpartisipasi dalam RIP bisa termasuk aktif atau pasif RIP. Active RIP berupa router-router yang berpartisipasi dalam proses pertukaran data distance vector. Mesin-mesin Active RIP mengirimkan tabel routingnya kepada router lain dan memantau update dari router lain. Mesin passive RIP hanya memantau update tapi tidak ikut menyebarkan tabel routingnya. Mesin ini biasanya berupa komputer klien.
Jika ada dua jalur dengan network tujuan yang sama dan hop count yang sama maka router akan memilih jalur yang terlebih dahulu ada didalam tabel routing.
Router RIP membroadcast pesan update setiap 30 detik. Jika jumlah router-router terlalu banyak akan timbul masalah karena akan memperlambat waktu convergence. Untuk itu, RIP membatasi angka maximum hop count sebesar 15.

Open Shortest Path First (OSPF)

OSPF adalah protokol interior routing yang berangsur-angsur menggantikan posisi RIP dalam banyak network. OSPF termasuk protokol routing link state.
Setiap router dalam OSPF diberikan router ID. Router ID ini biasanya berupa IP address terbesar yang dimiliki router. Jika router memiliki interface loopback, maka router ID nya adalah IP address dari interface loopback yang terbesar.
Router Link State membangun peta internal dari topologi networknya. Router-router lain menggunakan router ID untuk mengidentifikasi router dalam topology. Setiap router menggambarkan network sebagai sebuah pohon dengan dirinya sendiri sebagai akarnya. Ongkos metric yang dipakai bisa berupa hop count, speed atau keandalan suatu link.