RE: Security portion in CCIE R & S

From: Salau,Olayemi (Olayemi.Salau@southampton.gov.uk)
Date: Thu Jan 04 2007 - 15:04:13 ART


Hello John, you're not alone

Could you be referring to the not-so-totally-stubby areas?

Well, I can share few things ...

NSSA Areas allow redistribution right? Which makes them different from
their Stub-Area Brothers. But they allow this redistribution only using
Type 7 LSA into the NSSA Area. Remember Stub area don't even allow Type
5 LSA in the first place, so NSSA being their brothers also don't allow
type 5 into the area BUT they are more intelligent in that they allow
redistributed routes through type 7 LSAs.

But if this Type 7 LSAs are to carry information/traffic about the
redistributed routes into another Separate Area(mostly Area 0); then the
Type 7 will translate to normal Type 5s into the third party Areas. So
the Routers in the 3rdParty Area will normally see these routes as
external type routes (E1/E2).

Now Take a Deep Breathe
------------------------------------------------------------------------
-------------

Not-So-Totally-Stubby Areas behave exactly like their brothers
Totally-Stub-Areas(Don't Allow Type 5/3/4), but they're more intelligent
in that they allow redistribution. Also NSTSA don't allow 3&4 Type LSAs,
literally they don't allow inter-Area routes. So if you're looking for
an area that Don't Allow Inter-Area Routes and Allows Redistribution
then NSTSA is what you should configure.

Take Another Deep Breathe
------------------------------------------------------------------------
-------------

The area X nssa no-redistribute command literally make sure that the
Router need not inject Type-7 LSAs into the NSSA (in this cases where an
NSSA ABR happen to double-up as an ASBR). Ask yourself, why will router
inject Type-7 LSAs into NSSA, answer is that: since NSSA don't allow
Type-5, those AS routes can come in as Type-7 and then when they are
about to go out, they translate into Type-5 for other areas which are
not NSSA areas.

Consider the scenario below:

          OSPF NSSA

          0 20 EIGRP

   R1-----------R2----------R3--------R4

                |

                | RIP

                |

                R5

R2 don't need to inject RIP's Routes using Type-7 into NSSA Area20 since
it will not be translated into Type-5 to a 3rdParty Area. But it needs
to inject Type-5 LSAs into Area0 since Area0 is like any other normal
OSPF Area which accepts all types of LSAs.

So in this case, R3 will inject Type-7 LSAs into Area20 which later
translates into Type-5 for Area0

But we will disallow Type-7 injection on R2 (into Area20) by using the
no-redistribute option of the area X nssa command

The no-summary option literally refuses the transmission of summary LSAs
(Type-3&4), so in this scenario, using no-summary option will make our
sweet loving Area20 a not-so-totally-stubby area(remember I said NSTSA
don't allow inter-area routes ... Type 3 & 4; but gives room for
redistribution of routes)

Many Thanks



This archive was generated by hypermail 2.1.4 : Thu Feb 08 2007 - 23:46:55 ART