Showing posts with label IPv6. Show all posts
Showing posts with label IPv6. Show all posts

Thursday, 14 May 2026

IPv6 eBGP and iBGP

IPv6 iBGP: The Internal Fabric

In an iBGP setup, the goal is to ensure all routers within your organization know how to reach external destinations.

  • The Full Mesh Requirement: Since iBGP routers do not re-advertise prefixes learned from one iBGP peer to another (to pr+event loops), you typically need a "Full Mesh" or Route Reflectors.
  • Next-Hop-Self: Because iBGP doesn't change the next-hop attribute, internal routers often don't know how to reach the original eBGP exit point. Using the next-hop-self command is a standard practice to ensure internal reachability.





IPv6 eBGP: Crossing the Border

eBGP is the handshake between different entities (like your network and an ISP).

  • Prefix Filtering: Unlike iBGP, you never trust an eBGP peer blindly. Strict prefix-lists and route-maps are essential to ensure you aren't leaking private routes or accepting "bogon" space.
  • The Link-Local Trap: In IPv6, eBGP can technically peer using Link-Local addresses (fe80::/10), but for stability and clarity, most engineers stick to Global Unicast Addresses (GUA) for peering.


In this blog, we configure the basics of IPv6 eBGP and iBGP. 

Topology:


  • Configure the topology as per the diagram.
  • Configure the IPv6 addresses as per the topology.
  • Configure IBGP on router 1 and router 2.
  • Advertise directly connected.
  • Configure EBGP on router 3
  • Configure next-hop-self on router 2 for router 1
  • Verify the configuration with ping, traceroute and show commands.


R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 address 2001:12::1/64
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#interface loopback 1
R1(config-if)#ipv6 address fc00:11::1/64
R1(config-if)#no shutdown
R1(config-if)#exit

R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 address 2001:12::2/64
R2(config-if)#no shutdown
R2(config-if)#exit
R2(config)#interface loopback 1
R2(config-if)#ipv6 address fc00:22::1/64
R2(config-if)#no shutdown
R2(config-if)#exit
R2(config)#interface serial 2/0
R2(config-if)#ipv6 address 2001:23::1/64
R2(config-if)#no shutdown
R2(config-if)#exit

R3(config)#interface loopback 1
R3(config-if)#ipv6 address fc00:33::1/64
R3(config-if)#no shutdown
R3(config-if)#exit
R3(config)#interface serial 2/0
R3(config-if)#ipv6 address 2001:23::2/64
R3(config-if)#no shutdown
R3(config-if)#exit

R1(config)#ipv6 unicast-routing
R1(config)#router bgp 6500
R1(config-router)#bgp router-id 1.1.1.1
R1(config-router)#no bgp default ipv4-unicast
R1(config-router)#neighbor 2001:12::2 remote-as 6500
R1(config-router)#address-family ipv6 unicast
R1(config-router-af)#neighbor 2001:12::2 activate
R1(config-router-af)#network fc00:11::/64
R1(config-router-af)#network 2001:12::/64
R1(config-router-af)#exit


R2(config)#ipv6 unicast-routing
R2(config)#router bgp 6500
R2(config-router)#bgp router-id 2.2.2.2
R2(config-router)#no bgp default ipv4-unicast
R2(config-router)#neighbor 2001:12::1 remote-as 6500
R2(config-router)#neighbor 2001:23::2 remote-as 6700
R2(config-router)#address-family ipv6 unicast
R2(config-router-af)#neighbor 2001:12::1 activate
R2(config-router-af)#neighbor 2001:23::2 activate
R2(config-router-af)#network fc00:22::/64
R2(config-router-af)#network 2001:12::/64
R2(config-router-af)#network 2001:23::/64
R2(config-router-af)#exit

%BGP-5-ADJCHANGE: neighbor 2001:12::1 Up

R2(config)#router bgp 6500
R2(config-router)#address-family ipv6 unicast
R2(config-router-af)#neighbor 2001:12::1 next-hop-self
R2(config-router-af)#exit

R3(config)#ipv6 unicast-routing
R3(config)#router bgp 6700
R3(config-router)#bgp router-id 3.3.3.3
R3(config-router)#no bgp default ipv4-unicast
R3(config-router)#neighbor 2001:23::1 remote-as 6500
R3(config-router)#address-family ipv6 unicast
R3(config-router-af)#neighbor 2001:23::1 activate
R3(config-router-af)#network fc00:33::/64
R3(config-router-af)#network 2001:23::/64
R3(config-router-af)#exit

%BGP-5-ADJCHANGE: neighbor 2001:23::1 Up

R1#show ip bgp ipv6 unicast summary
BGP router identifier 1.1.1.1, local AS number 6500
BGP table version is 7, main routing table version 7
5 network entries using 860 bytes of memory
6 path entries using 528 bytes of memory
3/3 BGP path/bestpath attribute entries using 408 bytes of memory
1 BGP AS-PATH entries using 24 bytes of memory
0 BGP route-map cache entries using 0 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
BGP using 1820 total bytes of memory
BGP activity 7/2 prefixes, 8/2 paths, scan interval 60 secs

Neighbor        V           AS MsgRcvd MsgSent   TblVer  InQ OutQ Up/Down  State/PfxRcd
2001:12::2      4         6500      24      21        7    0    0 00:16:06        4


R1#show ipv6 route bgp
IPv6 Routing Table - default - 8 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
       B - BGP, HA - Home Agent, MR - Mobile Router, R - RIP
       H - NHRP, I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea
       IS - ISIS summary, D - EIGRP, EX - EIGRP external, NM - NEMO
       ND - ND Default, NDp - ND Prefix, DCE - Destination, NDr - Redirect
       O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2, l - LISP
B   2001:23::/64 [200/0]
     via 2001:12::2
B   FC00:22::/64 [200/0]
     via 2001:12::2
B   FC00:33::/64 [200/0]
     via 2001:12::2



R2#ping fc00:11::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to FC00:11::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 24/30/40 ms

R2#ping fc00:33::1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to FC00:33::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 20/28/36 ms

R1#traceroute fc00:33::1
Type escape sequence to abort.
Tracing the route to FC00:33::1

  1 2001:12::2 20 msec 28 msec 20 msec
  2 2001:23::2 44 msec 64 msec 40 msec

(If you like this blog, please visit our YouTube channel.https://www.youtube.com/@internetworkss



Thursday, 15 January 2026

IPv6 Redistribution between EIGRPv3, OSPFv3 and RIPng

 **IPv6 Route Redistribution** 

Route redistribution in IPv6 allows different routing protocols (e.g., OSPFv3, EIGRP for IPv6, BGP, RIPng, IS-IS) to exchange routing information within the same network. This is useful in multi-vendor or multiprotocol environments where migration or integration is required.

 


**Key Points:**

- Redistribution is typically configured on routers that run multiple routing protocols.

- Careful planning is needed to avoid routing loops, suboptimal paths, or convergence issues.

- Use route filtering, metrics, and administrative distance tuning to control redistribution.

- Default metrics often need manual assignment when redistributing between protocols (e.g., OSPF to EIGRP).

 

**Example Use Case:** 

Connecting an OSPFv3 domain with a BGP IPv6 network, allowing internal routes to be advertised externally and vice versa.

 

**Configuration Note:** 

Always verify routes after redistribution and ensure prefix lengths and next-hop addresses are correctly advertised.


Let's see the configuration:-


Task:

  • Configure the topology as per the diagram
  • Configure the IPv6 addresses as per the topology
  • Configure EIGRPv3 on router 1 and advertise directly 
  • Configure OSPFv3 on router 2 and advertise FastEthernet 2/0 - 3/0
  • Configure EIGRPv3 on router 2 and advertise FastEthernet 0/0
  • Configure OSPFv3 on router 3 and advertise FastEthernet 3/0
  • Configure RIPng on router 3 and advertise FastEthernet 2/0
  • Configure redistribution between EIGRPv3 and OSPFv3 and vice versa 
  • Configure redistribution between RIPng and OSPFv3 and vice versa
  • Make sure all the routes are exchanged 
  • ensure the connectivity and verify with show commands



R1(config)#ipv6 unicast-routing
R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 address 2001:1122:1122:1122::1/64
R1(config-if)#no shutdown
R1(config-if)#exit

R1(config)#interface fastethernet 2/0
R1(config-if)#ipv6 address fc00:1111:1111:1111::1/64
R1(config-if)#no shutdown
R1(config-if)#no keepalive
R1(config-if)#exit
R1(config)#

R2(config)#ipv6 unicast-routing
R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 address 2001:1122:1122:1122::2/64
R2(config-if)#no shutdown
R2(config-if)#exit
R2(config)#interface fastethernet 2/0
R2(config-if)#ipv6 address fc00:2222:2222:2222::1/64
R2(config-if)#no shutdown
R2(config-if)#no keepalive
R2(config-if)#exit
R2(config)#interface fastethernet 3/0
R2(config-if)#ipv6 address 2001:2233:2233:2233::1/64
R2(config-if)#no shutdown
R2(config-if)#exit



R3#show ipv6 interface brief
FastEthernet0/0            [administratively down/down]
    unassigned
ATM1/0                     [administratively down/down]
    unassigned
FastEthernet2/0            [up/up]
    FE80::C803:A5FF:FE68:38
    FC00:3333:3333:3333::1
FastEthernet3/0            [up/up]
    FE80::C803:A5FF:FE68:54
    2001:2233:2233:2233::2



R1(config)#ipv6 router eigrp 65100
R1(config-rtr)#no shutdown
R1(config-rtr)#router-id 11.11.11.11
R1(config-rtr)#exit

R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 eigrp 65100
R1(config-if)#exit

R1(config)#interface fastethernet 2/0
R1(config-if)#ipv6 eigrp 65100
R1(config-if)#exit

R2(config)#ipv6 router eigrp 65100
R2(config-rtr)#no shutdown
R2(config-rtr)#router-id 22.22.22.22
R2(config-rtr)#exit

R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 eigrp 65100
R2(config-if)#exit

R2(config)#IPv6 router ospf 100
R2(config-rtr)#router-id 22.22.22.22
R2(config-rtr)#exit

R2(config)#interface fastethernet 2/0
R2(config-if)#ipv6 ospf 100 area 0
R2(config-if)#exit

R2(config)#interface fastethernet 3/0
R2(config-if)#ipv6 ospf 100 area 0
R2(config-if)#exit


R3(config)#IPv6 router ospf 100
R3(config-rtr)#router-id 33.33.33.33
R3(config-rtr)#exit

R3(config)#interface fastethernet 3/0
R3(config-if)#ipv6 ospf 100 area 0
R3(config-if)#exit


R3(config)#ipv6 unicast-routing
R3(config)#interface fastEthernet 2/0
R3(config-if)#ipv6 rip internetworks enable
R3(config-if)#exit


R2(config)#ipv6 router ospf 100
R2(config-rtr)#redistribute eigrp 65100 metric 100 metric-type 1 include-connected
R2(config-rtr)#exit

R2(config)#ipv6 router eigrp 65100
R2(config-rtr)#redistribute ospf 100 include-connected metric 1000 2000 255 1 1500
 metric <bw> <delay> <reliability> <load> <mtu>
R2(config-rtr)#exit

R3(config)#ipv6 router ospf 100
R3(config-rtr)#redistribute rip internetworks include-connected metric 100 metric-type 1
R3(config-rtr)#exit


R1#show ipv6 route
IPv6 Routing Table - Default - 8 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
       B - BGP, M - MIPv6, R - RIP, I1 - ISIS L1
       I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary, D - EIGRP
       EX - EIGRP external
       O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
C   2001:1122:1122:1122::/64 [0/0]
     via FastEthernet0/0, directly connected
L   2001:1122:1122:1122::1/128 [0/0]
     via FastEthernet0/0, receive
EX  2001:2233:2233:2233::/64 [170/3074560]
     via FE80::C802:59FF:FE98:0, FastEthernet0/0
C   FC00:1111:1111:1111::/64 [0/0]
     via FastEthernet2/0, directly connected
L   FC00:1111:1111:1111::1/128 [0/0]
     via FastEthernet2/0, receive
EX  FC00:2222:2222:2222::/64 [170/3074560]
     via FE80::C802:59FF:FE98:0, FastEthernet0/0
EX  FC00:3333:3333:3333::/64 [170/3074560]
     via FE80::C802:59FF:FE98:0, FastEthernet0/0
L   FF00::/8 [0/0]
     via Null0, receive

R2#show ipv6 protocol
IPv6 Routing Protocol is "connected"
IPv6 Routing Protocol is "eigrp 65100"
  EIGRP metric weight K1=1, K2=0, K3=1, K4=0, K5=0
  EIGRP maximum hopcount 100
  EIGRP maximum metric variance 1
  Interfaces:
    FastEthernet0/0
  Redistribution:
    Redistributing protocol ospf 100 with metric 0 include-connected
  Maximum path: 16
  Distance: internal 90 external 170

IPv6 Routing Protocol is "ospf 100"
  Interfaces (Area 0):
    FastEthernet3/0
    FastEthernet2/0
  Redistribution:
    Redistributing protocol eigrp 65100 with metric 100 type 1 include-connected

If you like this blog, please visit our YOUTUBE channel https://www.youtube.com/@internetworkss


Monday, 12 January 2026

IPv6 EIGRP: The Next-Generation Routing Protocol

 IPv6 EIGRP: The Next-Generation Routing Protocol

As networks transition to IPv6, routing protocols must evolve too. Enter EIGRP for IPv6 – Cisco’s enhanced interior gateway protocol, now ready for the modern internet.

 

What is IPv6 EIGRP?

IPv6 EIGRP is the IPv6-enabled version of Cisco’s advanced distance-vector protocol. It retains EIGRP’s popular features – rapid convergence, low bandwidth usage, and support for VLSM – while fully embracing IPv6 addressing and communication.




 

Key Advantages

Dual-Stack Ready: Runs alongside IPv4 EIGRP, allowing gradual migration

Separate Process: IPv6 EIGRP operates as an independent protocol instance

Link-local addressing: uses IPv6 link-local addresses for neighbor discovery

Same Dual Algorithm: Maintains the reliable loop-free path selection

 

Configuration Highlights

 

R1(config)#ipv6 unicast-routing
R1(config)#ipv6 router eigrp 65100
R1(config-rtr)#no shutdown
R1(config-rtr)#router-id 11.11.11.11
R1(config-rtr)#exit
R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 eigrp 65100
R1(config-if)#exit  

Let's see the configuration :

Topology:










TASK
  • Configure the topology as per the diagram 
  • Configure IPv6 addresses as per the topology
  • Configure IPv6 EIGRP AS 65100
  • Make sure both routers communicate 
  • Verify with show commands 
R1(config)#ipv6 unicast-routing
R1(config)#
R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 address 2001:1122:1122:1122::1/64
R1(config-if)#no shutdown
R1(config-if)#exit
R1(config)#
R1(config)#
R1(config)#interface fastethernet 2/0
R1(config-if)#ipv6 address fc00:1111:1111:1111::1/64
R1(config-if)#no shutdown
R1(config-if)#no keepalive
R1(config-if)#exit


R2(config)#ipv6 unicast-routing
R2(config)#
R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 address 2001:1122:1122:1122::2/64
R2(config-if)#no shutdown
R2(config-if)#exit
R2(config)#
R2(config)#interface fastethernet 2/0
R2(config-if)#ipv6 address fc00:2222:2222:2222::1/64
R2(config-if)#no shutdown
R2(config-if)#no keepalive
R2(config-if)#exit


R1(config)#ipv6 router eigrp 65100
R1(config-rtr)#no shutdown
R1(config-rtr)#router-id 11.11.11.11
R1(config-rtr)#exit
R1(config)#
R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 eigrp 65100
R1(config-if)#exit
R1(config)#
R1(config)#interface fastethernet 2/0
R1(config-if)#ipv6 eigrp 65100
R1(config-if)#exit


R2(config)#ipv6 router eigrp 65100
R2(config-rtr)#no shutdown
R2(config-rtr)#router-id 22.22.22.22
R2(config-rtr)#exit
R2(config)#
R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 eigrp 65100
R2(config-if)#exit
R2(config)#
R2(config)#interface fastethernet 2/0
R2(config-if)#ipv6 eigrp 65100
R2(config-if)#exit


R1#show ipv6 route
IPv6 Routing Table - Default - 6 entries
Codes: C - Connected, L - Local, S - Static, U - Per-user Static route
       B - BGP, M - MIPv6, R - RIP, I1 - ISIS L1
       I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary, D - EIGRP
       EX - EIGRP external
       O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
C   2001:1122:1122:1122::/64 [0/0]
     via FastEthernet0/0, directly connected
L   2001:1122:1122:1122::1/128 [0/0]
     via FastEthernet0/0, receive
C   FC00:1111:1111:1111::/64 [0/0]
     via FastEthernet2/0, directly connected
L   FC00:1111:1111:1111::1/128 [0/0]
     via FastEthernet2/0, receive
D   FC00:2222:2222:2222::/64 [90/30720]
     via FE80::C802:59FF:FE98:0, FastEthernet0/0
L   FF00::/8 [0/0]
     via Null0, receive

R1#show ipv6 eigrp neighbor
IPv6-EIGRP neighbors for process 65100
H   Address                 Interface       Hold Uptime   SRTT   RTO  Q  Seq
                                            (sec)         (ms)       Cnt Num
0   Link-local address:     Fa0/0             12 00:01:21  906  5000  0  5
    FE80::C802:59FF:FE98:0

R1#show ipv6 interface brief
FastEthernet0/0            [up/up]
    FE80::C801:A5FF:FED4:0
    2001:1122:1122:1122::1
ATM1/0                     [administratively down/down]
    unassigned
FastEthernet2/0            [up/up]
    FE80::C801:A5FF:FED4:38
    FC00:1111:1111:1111::1

R1#ping fc00:2222:2222:2222::1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to FC00:2222:2222:2222::1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 12/29/56 ms



















Friday, 21 November 2025

What is OSPFv3 IPsec authentication? How to configure OSPFv3 authentication?

 If you're coming from an OSPFv2 world, you're used to typing in a simple {IP OSPF AUTHENTICATION-KEY} command. When you jump to IPv6 OSPFv3, you might look for the equivalent command and be surprised to find it's not there.





How does OSPFv3 secure its neighbour relationships and routing updates? The answer is a fundamental shift in design: OSPFv3 relies on IPsec authentication. OSPFv3 doesn't include any authentication capabilities of its own. The OSPFv3 authentication field has been removed from OSPFv3 packet headers. OSPFv3 requires the IPv6 authentication header (AH) or IPv6 ESP header to ensure the integrity, authentication, and confidentiality of routing exchanges.


What are the benefits?

This approach has several benefits:

  1. No more cleartext passwords
  2. Stronger crypto (SHA-256, AES)
  3. Leverages existing infrastructure 
  4. Standardization


How does it work?

OSPFv3 supports two methods to implement IPsec.

1. Manual- this is the most straightforward and commonly used method, you manually configure a security policy index (SPI) and a pre-shared key on both routers.


The building blocks:

  •  SPI- a number that uniquely identifies the security policy to both routers. It must match on both sides.
  • Authentication algorithm- the hashing algorithm to use ( SHA1, SHA256).
  • Encryption key- the actual pre-shared password. It must match on both sides.


2. IPsec profile ( the scalable method)

  • For larger networks, manually configuring keys on every interface becomes a management headache. This is where the IPsec profile comes in.

  • An IPsec profile defines the security policy (algorithms, keys, etc) and is then applied to an OSPFv3 process. This applies the policy to all OSPFv3 interfaces, making it much more scalable.
  • This method is complex to set up, but it is the recommended way for large-scale deployments.


Let's see the configuration- So, we are going to configure OSPv3 authentication interface, and the area authentication.

Topology:-




Goal: ensure the integrity, authentication, and confidentiality of routing exchanges.
  • Configure the topology as per the diagram 
  • Configure the IPv6 addresses as per the topology
  • Configure OSPFv3, and both routers are in area 0
  • Configure OSPFv3 authentication on the interfaces
  • erase the previous configuration 
  • Reconfigure OSPFv3 authentication for the entire OSPFv3 area 0
  • Verify with show commands and messages.

R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 address 2001:1212:12:12::1/64
R1(config-if)#no shutdown
R1(config-if)#exit

R1(config)#interface fastethernet 2/0
R1(config-if)#ipv6 address fc00:1111:1111:1111::1/64
R1(config-if)#no shutdown
R1(config-if)#exit

R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 address 2001:1212:12:12::2/64
R2(config-if)#no shutdown
R2(config-if)#exit

R2(config)#interface fastethernet 2/0
R2(config-if)#ipv6 address fc00:2222:2222:2222::1/64
R2(config-if)#no shutdown
R2(config-if)#exit

R1(config)#ipv6 unicast-routing

R1(config)#ipv6 router ospf 100
R1(config-rtr)#router-id 10.10.10.10
R1(config-rtr)#exit

R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 ospf 100 area 0
R1(config-if)#exit
R1(config)#interface fastethernet 2/0
R1(config-if)#ipv6 ospf 100 area 0
R1(config-if)#exit

R2(config)#ipv6 unicast-routing

R2(config)#ipv6 router ospf 100
R2(config-rtr)#router-id 20.20.20.20
R2(config-rtr)#exit

R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 ospf 100 area 0
R2(config-if)#exit
R2(config)#interface fastethernet 2/0
R2(config-if)#ipv6 ospf 100 area 0
R2(config-if)#exit

 %OSPFv3-5-ADJCHG: Process 100, Nbr 20.20.20.20 on FastEthernet0/0 from LOADING to FULL, Loading Done
%OSPFv3-5-ADJCHG: Process 100, Nbr 10.10.10.10 on FastEthe rnet0/0 from LOADING to FULL, Loading Done 

R1(config)#interface fastethernet 0/0
R1(config-if)#IPv6 ospf authenticationb ipsec spi 499 md5 abcdef1234567890abcded1234567890
R1(config-if)#end

%IPSECV6-4-RECVD_PKT_NOT_IPSECV6: Rec'd packet not an IPSEC packet. (ip) dest_addr= FF02::5, src_addr= FE80::C802:63FF:FE30:0, prot= 89

 %OSPFv3-5-ADJCHG: Process 100, Nbr 20.20.20.20 on FastEthernet0/0 from FULL to DOWN, Neighbor Down: Dead timer expired

%IPSECV6-4-RECVD_PKT_NOT_IPSECV6: Rec'd packet not an IPSECv6 packet.
        (ip) dest_addr= FF02::5, src_addr= FE80::C802:63FF:FE30:0, prot= 89

R2(config)#interface fastethernet 0/0
R2(config-if)#IPv6 ospf authenticationb ipsec spi 499 md5 abcdef1234567890abcded1234567890
R2(config-if)#end

%OSPFv3-5-ADJCHG: Process 100, Nbr 10.10.10.10 on FastEthernet0/0 from LOADING to FULL, Loading Done
%OSPFv3-5-ADJCHG: Process 100, Nbr 20.20.20.20 on FastEthernet0/0 from LOADING to FULL, Loading Done

R1#show ipv6 ospf neighbor

Neighbor ID     Pri   State           Dead Time   Interface ID    Interface
20.20.20.20       1   FULL/DR         00:00:33    4               FastEthernet0/                                                                                                                                   0
R1#show ipv6 route ospf
IPv6 Routing Table - 7 entries
Codes: C - Connected, L - Local, S - Static, R - RIP, B - BGP
       U - Per-user Static route
       I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary
       O - OSPF intra, OI - OSPF inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
O   FC00:2222:2222:2222::/64 [110/2]
     via FE80::C802:63FF:FE30:0, FastEthernet0/0

R2#show ipv6 ospf neighbor

Neighbor ID     Pri   State           Dead Time   Interface ID    Interface
10.10.10.10       1   FULL/BDR        00:00:34    4               FastEthernet0/                                                                                                                                   0
R2#show ipv6 route ospf
IPv6 Routing Table - 7 entries
Codes: C - Connected, L - Local, S - Static, R - RIP, B - BGP
       U - Per-user Static route
       I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary
       O - OSPF intra, OI - OSPF inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
O   FC00:1111:1111:1111::/64 [110/2]
     via FE80::C801:3AFF:FE14:0, FastEthernet0/0

Saturday, 15 November 2025

IPv6 Static, Default, and Dynamic routing lab

 In this lab, we see the configuration of  IPv6 static, default, and dynamic routing protocols. This lab is divided into three labs:

  • IPv6 Static routing
  • IPv6 Default routing
  • IPv6 Dynamic routing


- starting with IPv6 Static routing

Topology:-



  • Configure the topology as per the picture.
  • Configure the IPv6 address as per the topology
  • Configure IPv6 Static routing 
  • Verify the configuration with ping and show commands



R1(config)#ipv6 unicast-routing
R1(config)#interface fastethernet 0/0
R1(config-if)#ipv6 address 2001:1234:1234:1234::1/64
R1(config-if)#no shutdown
R1(config-if)#exit

R1(config)#interface fastethernet 2/0
R1(config-if)#ipv6 address fc00:1111:1111:1111::1/64
R1(config-if)#no shutdown
R1(config-if)#exit

R2(config)#ipv6 unicast-routing
R2(config)#interface fastethernet 0/0
R2(config-if)#ipv6 address 2001:1234:1234:1234::2/64
R2(config-if)#no shutdown
R2(config-if)#exit

R2(config)#interface fastethernet 2/0
R2(config-if)#ipv6 address fc00:1111:1111:2222::2/64
R2(config-if)#no shutdown
R2(config-if)#exit

R1#show ipv6 interface brief
FastEthernet0/0            [up/up]
    FE80::C801:3FFF:FE40:0
    2001:1234:1234:1234::1

ATM1/0                     [administratively down/down]
FastEthernet2/0            [up/up]
    FE80::C801:3FFF:FE40:38
    FC00:1111:1111:1111::1

GigabitEthernet3/0         [administratively down/down]
FastEthernet4/0            [administratively down/down]
FastEthernet4/1            [administratively down/down]

R2#show ipv6 interface brief
FastEthernet0/0            [up/up]
    FE80::C802:6CFF:FE10:0
    2001:1234:1234:1234::2

ATM1/0                     [administratively down/down]
FastEthernet2/0            [up/up]
    FE80::C802:6CFF:FE10:38
    FC00:1111:1111:2222::2

GigabitEthernet3/0         [administratively down/down]
FastEthernet4/0            [administratively down/down]
FastEthernet4/1            [administratively down/down]

PC2> ip auto
GLOBAL SCOPE      : fc00:1111:1111:1111:2050:79ff:fe66:6801/64
ROUTER LINK-LAYER : ca:01:3f:40:00:38

PC7> ip auto
GLOBAL SCOPE      : fc00:1111:1111:2222:2050:79ff:fe66:6805/64
ROUTER LINK-LAYER : cc:04:3e:ac:00:00

R1(config)#ipv6 route fc00:1111:1111:2222::/64 2001:1234:1234:1234::2
R1(config)#end

R2(config)#ipv6 route fc00:1111:1111:1111::/64 2001:1234:1234:1234::1
R2(config)#end

R1#show ipv6 route static
IPv6 Routing Table - 7 entries
Codes: C - Connected, L - Local, S - Static, R - RIP, B - BGP
       U - Per-user Static route
       I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary
       O - OSPF intra, OI - OSPF inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
S   FC00:1111:1111:2222::/64 [1/0]
     via 2001:1234:1234:1234::2


R2#show ipv6 route static
IPv6 Routing Table - 7 entries
Codes: C - Connected, L - Local, S - Static, R - RIP, B - BGP
       U - Per-user Static route
       I1 - ISIS L1, I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary
       O - OSPF intra, OI - OSPF inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2
       ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2
S   FC00:1111:1111:1111::/64 [1/0]
     via 2001:1234:1234:1234::1


R1#ping fc00:1111:1111:2222::2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to FC00:1111:1111:2222::2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 32/48/64 ms


R1#traceroute fc00:1111:1111:2222::2
Type escape sequence to abort.
Tracing the route to FC00:1111:1111:2222::2
  1 FC00:1111:1111:2222::2 36 msec 32 msec 56 msec
PC2> ping 2001:1234:1234:1234::1/64
2001:1234:1234:1234::1 icmp6_seq=1 ttl=64 time=32.271 ms
2001:1234:1234:1234::1 icmp6_seq=2 ttl=64 time=32.632 ms
2001:1234:1234:1234::1 icmp6_seq=3 ttl=64 time=32.318 ms
2001:1234:1234:1234::1 icmp6_seq=4 ttl=64 time=32.362 ms
2001:1234:1234:1234::1 icmp6_seq=5 ttl=64 time=32.418 ms
PC2> ping 2001:1234:1234:1234::2/64
2001:1234:1234:1234::2 icmp6_seq=1 ttl=63 time=128.036 ms
2001:1234:1234:1234::2 icmp6_seq=2 ttl=63 time=79.702 ms
2001:1234:1234:1234::2 icmp6_seq=3 ttl=63 time=95.755 ms
2001:1234:1234:1234::2 icmp6_seq=4 ttl=63 time=80.116 ms
2001:1234:1234:1234::2 icmp6_seq=5 ttl=63 time=80.655 ms
PC2> ping fc00:1111:1111:2222::2/64
fc00:1111:1111:2222::2 icmp6_seq=1 ttl=63 time=80.813 ms
fc00:1111:1111:2222::2 icmp6_seq=2 ttl=63 time=63.469 ms
fc00:1111:1111:2222::2 icmp6_seq=3 ttl=63 time=80.616 ms
fc00:1111:1111:2222::2 icmp6_seq=4 ttl=63 time=64.005 ms
fc00:1111:1111:2222::2 icmp6_seq=5 ttl=63 time=79.650 ms



How to configure ASA Dynamic routing?

  Configuring EIGRP on Cisco ASA: A Quick Lab Guide Setting up EIGRP on a Cisco Adaptive Security Appliance (ASA) is a bit different from do...