[{"content":"In this guide, we establish a 6-node Nokia SR OS baseline in Containerlab and configure the physical interfaces, /30 point-to-point subnets, and system loopbacks required prior to enabling OSPF.\nSR OS Version: 25.7.R1 CLI Mode: MD-CLI (Model-Driven CLI) Containerlab Topology File (topology.clab.yml) name: OSPF-Lab topology: defaults: kind: nokia_srsim image: localhost/nokia/srsim:25.7.R1 type: sr-1 license: license/license.txt nodes: r1: mgmt-ipv4: 172.20.20.9 r2: mgmt-ipv4: 172.20.20.2 r3: mgmt-ipv4: 172.20.20.3 r4: mgmt-ipv4: 172.20.20.4 r5: mgmt-ipv4: 172.20.20.5 r6: mgmt-ipv4: 172.20.20.6 links: # --- CE to PE Links --- - endpoints: [\u0026#34;r1:1/1/c1/1\u0026#34;, \u0026#34;r2:1/1/c1/1\u0026#34;] - endpoints: [\u0026#34;r5:1/1/c1/1\u0026#34;, \u0026#34;r6:1/1/c1/1\u0026#34;] # --- Core Links --- - endpoints: [\u0026#34;r2:1/1/c2/1\u0026#34;, \u0026#34;r3:1/1/c1/1\u0026#34;] - endpoints: [\u0026#34;r2:1/1/c3/1\u0026#34;, \u0026#34;r4:1/1/c1/1\u0026#34;] - endpoints: [\u0026#34;r3:1/1/c2/1\u0026#34;, \u0026#34;r5:1/1/c2/1\u0026#34;] - endpoints: [\u0026#34;r4:1/1/c3/1\u0026#34;, \u0026#34;r5:1/1/c3/1\u0026#34;] Addressing Plan System (Loopback) Interfaces Node System IP Address Prefix Length R1 10.100.1.1 /32 R2 10.100.1.2 /32 R3 10.100.1.3 /32 R4 10.100.1.4 /32 R5 10.100.1.5 /32 R6 10.100.1.6 /32 Physical Interfaces Router R1 Interface Name Port ID IPv4 Address Prefix Length Subnet Neighbor toR2 1/1/c1/1 192.168.12.1 30 192.168.12.0/30 R2 (PE1) Router R2 Interface Name Port ID IPv4 Address Prefix Length Subnet Neighbor toR1 1/1/c1/1 192.168.12.2 30 192.168.12.0/30 R1 (CE1) toR3 1/1/c2/1 192.168.23.1 30 192.168.23.0/30 R3 (P1) toR4 1/1/c3/1 192.168.24.1 30 192.168.24.0/30 R4 (P2) Router R3 Interface Name Port ID IPv4 Address Prefix Length Subnet Neighbor toR2 1/1/c1/1 192.168.23.2 30 192.168.23.0/30 R2 (PE1) toR5 1/1/c2/1 192.168.35.1 30 192.168.35.0/30 R5 (PE2) Router R4 Interface Name Port ID IPv4 Address Prefix Length Subnet Neighbor toR2 1/1/c1/1 192.168.24.2 30 192.168.24.0/30 R2 (PE1) toR5 1/1/c3/1 192.168.45.1 30 192.168.45.0/30 R5 (PE2) Router R5 Interface Name Port ID IPv4 Address Prefix Length Subnet Neighbor toR3 1/1/c2/1 192.168.35.2 30 192.168.35.0/30 R3 (P1) toR4 1/1/c3/1 192.168.45.2 30 192.168.45.0/30 R4 (P2) toR6 1/1/c1/1 192.168.56.1 30 192.168.56.0/30 R6 (CE2) Router R6 Interface Name Port ID IPv4 Address Prefix Length Subnet Neighbor toR5 1/1/c1/1 192.168.56.2 30 192.168.56.0/30 R5 (PE2) Configuration Router R1 (CE1) edit-config global /configure system name \u0026#34;R1 (CE1)\u0026#34; /configure card 1 card-type iom-1 /configure card 1 mda 1 mda-type me6-100gb-qsfp28 /configure port 1/1/c1 connector breakout c1-100g /configure port 1/1/c1 admin-state enable /configure port 1/1/c1/1 admin-state enable /configure port 1/1/c1/1 ethernet mode hybrid /configure router interface \u0026#34;system\u0026#34; admin-state enable /configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.1 /configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32 /configure router interface \u0026#34;toR2\u0026#34; admin-state enable /configure router interface \u0026#34;toR2\u0026#34; ipv4 primary address 192.168.12.1 /configure router interface \u0026#34;toR2\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR2\u0026#34; port 1/1/c1/1:0 commit Router R2 (PE1) edit-config global /configure system name \u0026#34;R2 (PE1)\u0026#34; /configure card 1 card-type iom-1 /configure card 1 mda 1 mda-type me6-100gb-qsfp28 /configure port 1/1/c1 connector breakout c1-100g /configure port 1/1/c2 connector breakout c1-100g /configure port 1/1/c3 connector breakout c1-100g /configure port 1/1/c1 admin-state enable /configure port 1/1/c2 admin-state enable /configure port 1/1/c3 admin-state enable /configure port 1/1/c1/1 admin-state enable /configure port 1/1/c1/1 ethernet mode hybrid /configure port 1/1/c2/1 admin-state enable /configure port 1/1/c2/1 ethernet mode hybrid /configure port 1/1/c3/1 admin-state enable /configure port 1/1/c3/1 ethernet mode hybrid /configure router interface \u0026#34;system\u0026#34; admin-state enable /configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.2 /configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32 /configure router interface \u0026#34;toR1\u0026#34; admin-state enable /configure router interface \u0026#34;toR1\u0026#34; ipv4 primary address 192.168.12.2 /configure router interface \u0026#34;toR1\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR1\u0026#34; port 1/1/c1/1:0 /configure router interface \u0026#34;toR3\u0026#34; admin-state enable /configure router interface \u0026#34;toR3\u0026#34; ipv4 primary address 192.168.23.1 /configure router interface \u0026#34;toR3\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR3\u0026#34; port 1/1/c2/1:0 /configure router interface \u0026#34;toR4\u0026#34; admin-state enable /configure router interface \u0026#34;toR4\u0026#34; ipv4 primary address 192.168.24.1 /configure router interface \u0026#34;toR4\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR4\u0026#34; port 1/1/c3/1:0 commit Router R3 (P1) edit-config global /configure system name \u0026#34;R3 (P1)\u0026#34; /configure card 1 card-type iom-1 /configure card 1 mda 1 mda-type me6-100gb-qsfp28 /configure port 1/1/c1 connector breakout c1-100g /configure port 1/1/c2 connector breakout c1-100g /configure port 1/1/c1 admin-state enable /configure port 1/1/c2 admin-state enable /configure port 1/1/c1/1 admin-state enable /configure port 1/1/c1/1 ethernet mode hybrid /configure port 1/1/c2/1 admin-state enable /configure port 1/1/c2/1 ethernet mode hybrid /configure router interface \u0026#34;system\u0026#34; admin-state enable /configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.3 /configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32 /configure router interface \u0026#34;toR2\u0026#34; admin-state enable /configure router interface \u0026#34;toR2\u0026#34; ipv4 primary address 192.168.23.2 /configure router interface \u0026#34;toR2\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR2\u0026#34; port 1/1/c1/1:0 /configure router interface \u0026#34;toR5\u0026#34; admin-state enable /configure router interface \u0026#34;toR5\u0026#34; ipv4 primary address 192.168.35.1 /configure router interface \u0026#34;toR5\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR5\u0026#34; port 1/1/c2/1:0 commit Router R4 (P2) edit-config global /configure system name \u0026#34;R4 (P2)\u0026#34; /configure card 1 card-type iom-1 /configure card 1 mda 1 mda-type me6-100gb-qsfp28 /configure port 1/1/c1 connector breakout c1-100g /configure port 1/1/c3 connector breakout c1-100g /configure port 1/1/c1 admin-state enable /configure port 1/1/c3 admin-state enable /configure port 1/1/c1/1 admin-state enable /configure port 1/1/c1/1 ethernet mode hybrid /configure port 1/1/c3/1 admin-state enable /configure port 1/1/c3/1 ethernet mode hybrid /configure router interface \u0026#34;system\u0026#34; admin-state enable /configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.4 /configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32 /configure router interface \u0026#34;toR2\u0026#34; admin-state enable /configure router interface \u0026#34;toR2\u0026#34; ipv4 primary address 192.168.24.2 /configure router interface \u0026#34;toR2\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR2\u0026#34; port 1/1/c1/1:0 /configure router interface \u0026#34;toR5\u0026#34; admin-state enable /configure router interface \u0026#34;toR5\u0026#34; ipv4 primary address 192.168.45.1 /configure router interface \u0026#34;toR5\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR5\u0026#34; port 1/1/c3/1:0 commit Router R5 (PE2) edit-config global /configure system name \u0026#34;R5 (PE2)\u0026#34; /configure card 1 card-type iom-1 /configure card 1 mda 1 mda-type me6-100gb-qsfp28 /configure port 1/1/c1 connector breakout c1-100g /configure port 1/1/c2 connector breakout c1-100g /configure port 1/1/c3 connector breakout c1-100g /configure port 1/1/c1 admin-state enable /configure port 1/1/c2 admin-state enable /configure port 1/1/c3 admin-state enable /configure port 1/1/c1/1 admin-state enable /configure port 1/1/c1/1 ethernet mode hybrid /configure port 1/1/c2/1 admin-state enable /configure port 1/1/c2/1 ethernet mode hybrid /configure port 1/1/c3/1 admin-state enable /configure port 1/1/c3/1 ethernet mode hybrid /configure router interface \u0026#34;system\u0026#34; admin-state enable /configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.5 /configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32 /configure router interface \u0026#34;toR3\u0026#34; admin-state enable /configure router interface \u0026#34;toR3\u0026#34; ipv4 primary address 192.168.35.2 /configure router interface \u0026#34;toR3\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR3\u0026#34; port 1/1/c2/1:0 /configure router interface \u0026#34;toR4\u0026#34; admin-state enable /configure router interface \u0026#34;toR4\u0026#34; ipv4 primary address 192.168.45.2 /configure router interface \u0026#34;toR4\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR4\u0026#34; port 1/1/c3/1:0 /configure router interface \u0026#34;toR6\u0026#34; admin-state enable /configure router interface \u0026#34;toR6\u0026#34; ipv4 primary address 192.168.56.1 /configure router interface \u0026#34;toR6\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR6\u0026#34; port 1/1/c1/1:0 commit Router R6 (CE2) edit-config global /configure system name \u0026#34;R6 (CE2)\u0026#34; /configure card 1 card-type iom-1 /configure card 1 mda 1 mda-type me6-100gb-qsfp28 /configure port 1/1/c1 connector breakout c1-100g /configure port 1/1/c1 admin-state enable /configure port 1/1/c1/1 admin-state enable /configure port 1/1/c1/1 ethernet mode hybrid /configure router interface \u0026#34;system\u0026#34; admin-state enable /configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.6 /configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32 /configure router interface \u0026#34;toR5\u0026#34; admin-state enable /configure router interface \u0026#34;toR5\u0026#34; ipv4 primary address 192.168.56.2 /configure router interface \u0026#34;toR5\u0026#34; ipv4 primary prefix-length 30 /configure router interface \u0026#34;toR5\u0026#34; port 1/1/c1/1:0 commit Verification Step 1: Verify Port Operational Status Verify physical ports are administratively and operationally Up/Up across all routers:\nStep 2: Verify Router Interfaces Confirm system loopbacks and physical interfaces are assigned correct IPs and show operational status Up:\nStep 3: Test Direct Physical Link Reachability (Ping) Verify point-to-point reachability across directly connected links (e.g., pinging R1\u0026rsquo;s interface 192.168.12.1 from R2):\nStep 4: Test Remote Loopback Reachability (Expected Failure) Confirm that non-adjacent system loopbacks (e.g., R6 from R2) are unreachable prior to routing protocol activation:\n[!NOTE] Without a dynamic routing protocol or static routes, routers only maintain reachability to directly connected subnets. Part 2 covers single-area OSPF configuration to establish full topology reachability.\n","permalink":"https://dennismwangi.com/ospf/ospf-part-1-physical-foundation/","summary":"\u003cp\u003eIn this guide, we establish a 6-node Nokia SR OS baseline in Containerlab and configure the physical interfaces, \u003ccode\u003e/30\u003c/code\u003e point-to-point subnets, and system loopbacks required prior to enabling OSPF.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eSR OS Version:\u003c/strong\u003e 25.7.R1\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eCLI Mode:\u003c/strong\u003e \u003cstrong\u003eMD-CLI\u003c/strong\u003e (Model-Driven CLI)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"containerlab-topology-file-topologyclabyml\"\u003eContainerlab Topology File (\u003ccode\u003etopology.clab.yml\u003c/code\u003e)\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-yaml\" data-lang=\"yaml\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f92672\"\u003ename\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003eOSPF-Lab\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f92672\"\u003etopology\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#f92672\"\u003edefaults\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003ekind\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003enokia_srsim\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003eimage\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003elocalhost/nokia/srsim:25.7.R1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003etype\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003esr-1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003elicense\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003elicense/license.txt\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#f92672\"\u003enodes\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003er1\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \u003cspan style=\"color:#f92672\"\u003emgmt-ipv4\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e172.20.20.9\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003er2\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \u003cspan style=\"color:#f92672\"\u003emgmt-ipv4\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e172.20.20.2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003er3\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \u003cspan style=\"color:#f92672\"\u003emgmt-ipv4\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e172.20.20.3\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003er4\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \u003cspan style=\"color:#f92672\"\u003emgmt-ipv4\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e172.20.20.4\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003er5\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \u003cspan style=\"color:#f92672\"\u003emgmt-ipv4\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e172.20.20.5\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f92672\"\u003er6\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \u003cspan style=\"color:#f92672\"\u003emgmt-ipv4\u003c/span\u003e: \u003cspan style=\"color:#ae81ff\"\u003e172.20.20.6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  \u003cspan style=\"color:#f92672\"\u003elinks\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#75715e\"\u003e# --- CE to PE Links ---\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    - \u003cspan style=\"color:#f92672\"\u003eendpoints\u003c/span\u003e: [\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r1:1/1/c1/1\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r2:1/1/c1/1\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    - \u003cspan style=\"color:#f92672\"\u003eendpoints\u003c/span\u003e: [\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r5:1/1/c1/1\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r6:1/1/c1/1\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#75715e\"\u003e# --- Core Links ---\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    - \u003cspan style=\"color:#f92672\"\u003eendpoints\u003c/span\u003e: [\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r2:1/1/c2/1\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r3:1/1/c1/1\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    - \u003cspan style=\"color:#f92672\"\u003eendpoints\u003c/span\u003e: [\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r2:1/1/c3/1\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r4:1/1/c1/1\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    - \u003cspan style=\"color:#f92672\"\u003eendpoints\u003c/span\u003e: [\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r3:1/1/c2/1\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r5:1/1/c2/1\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    - \u003cspan style=\"color:#f92672\"\u003eendpoints\u003c/span\u003e: [\u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r4:1/1/c3/1\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#e6db74\"\u003e\u0026#34;r5:1/1/c3/1\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"addressing-plan\"\u003eAddressing Plan\u003c/h2\u003e\n\u003ch3 id=\"system-loopback-interfaces\"\u003eSystem (Loopback) Interfaces\u003c/h3\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eNode\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSystem IP Address\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePrefix Length\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e10.100.1.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e/32\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e10.100.1.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e/32\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR3\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e10.100.1.3\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e/32\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR4\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e10.100.1.4\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e/32\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR5\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e10.100.1.5\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e/32\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR6\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e10.100.1.6\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e/32\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch3 id=\"physical-interfaces\"\u003ePhysical Interfaces\u003c/h3\u003e\n\u003ch4 id=\"router-r1\"\u003eRouter R1\u003c/h4\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface Name\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePort ID\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eIPv4 Address\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePrefix Length\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSubnet\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eNeighbor\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c1/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.12.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.12.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR2 (PE1)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch4 id=\"router-r2\"\u003eRouter R2\u003c/h4\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface Name\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePort ID\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eIPv4 Address\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePrefix Length\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSubnet\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eNeighbor\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c1/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.12.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.12.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR1 (CE1)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR3\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c2/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.23.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.23.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR3 (P1)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR4\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c3/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.24.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.24.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR4 (P2)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch4 id=\"router-r3\"\u003eRouter R3\u003c/h4\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface Name\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePort ID\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eIPv4 Address\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePrefix Length\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSubnet\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eNeighbor\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c1/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.23.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.23.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR2 (PE1)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR5\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c2/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.35.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.35.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR5 (PE2)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch4 id=\"router-r4\"\u003eRouter R4\u003c/h4\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface Name\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePort ID\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eIPv4 Address\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePrefix Length\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSubnet\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eNeighbor\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c1/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.24.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.24.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR2 (PE1)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR5\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c3/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.45.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.45.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR5 (PE2)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch4 id=\"router-r5\"\u003eRouter R5\u003c/h4\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface Name\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePort ID\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eIPv4 Address\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePrefix Length\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSubnet\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eNeighbor\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR3\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c2/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.35.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.35.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR3 (P1)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR4\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c3/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.45.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.45.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR4 (P2)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR6\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c1/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.56.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.56.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR6 (CE2)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch4 id=\"router-r6\"\u003eRouter R6\u003c/h4\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface Name\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePort ID\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eIPv4 Address\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePrefix Length\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSubnet\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eNeighbor\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003etoR5\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e1/1/c1/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.56.2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e192.168.56.0/30\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eR5 (PE2)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"router-r1-ce1\"\u003eRouter R1 (CE1)\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-text\" data-lang=\"text\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eedit-config global\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure system name \u0026#34;R1 (CE1)\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 card-type iom-1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 mda 1 mda-type me6-100gb-qsfp28\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; ipv4 primary address 192.168.12.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; port 1/1/c1/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecommit\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"router-r2-pe1\"\u003eRouter R2 (PE1)\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-text\" data-lang=\"text\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eedit-config global\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure system name \u0026#34;R2 (PE1)\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 card-type iom-1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 mda 1 mda-type me6-100gb-qsfp28\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR1\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR1\u0026#34; ipv4 primary address 192.168.12.2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR1\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR1\u0026#34; port 1/1/c1/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; ipv4 primary address 192.168.23.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; port 1/1/c2/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; ipv4 primary address 192.168.24.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; port 1/1/c3/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecommit\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"router-r3-p1\"\u003eRouter R3 (P1)\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-text\" data-lang=\"text\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eedit-config global\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure system name \u0026#34;R3 (P1)\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 card-type iom-1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 mda 1 mda-type me6-100gb-qsfp28\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; ipv4 primary address 192.168.23.2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; port 1/1/c1/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; ipv4 primary address 192.168.35.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; port 1/1/c2/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecommit\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"router-r4-p2\"\u003eRouter R4 (P2)\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-text\" data-lang=\"text\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eedit-config global\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure system name \u0026#34;R4 (P2)\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 card-type iom-1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 mda 1 mda-type me6-100gb-qsfp28\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.4\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; ipv4 primary address 192.168.24.2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR2\u0026#34; port 1/1/c1/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; ipv4 primary address 192.168.45.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; port 1/1/c3/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecommit\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"router-r5-pe2\"\u003eRouter R5 (PE2)\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-text\" data-lang=\"text\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eedit-config global\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure system name \u0026#34;R5 (PE2)\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 card-type iom-1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 mda 1 mda-type me6-100gb-qsfp28\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c2/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c3/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.5\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; ipv4 primary address 192.168.35.2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR3\u0026#34; port 1/1/c2/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; ipv4 primary address 192.168.45.2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR4\u0026#34; port 1/1/c3/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR6\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR6\u0026#34; ipv4 primary address 192.168.56.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR6\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR6\u0026#34; port 1/1/c1/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecommit\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"router-r6-ce2\"\u003eRouter R6 (CE2)\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-text\" data-lang=\"text\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eedit-config global\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure system name \u0026#34;R6 (CE2)\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 card-type iom-1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure card 1 mda 1 mda-type me6-100gb-qsfp28\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 connector breakout c1-100g\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure port 1/1/c1/1 ethernet mode hybrid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary address 10.100.1.6\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;system\u0026#34; ipv4 primary prefix-length 32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; admin-state enable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; ipv4 primary address 192.168.56.2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; ipv4 primary prefix-length 30\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/configure router interface \u0026#34;toR5\u0026#34; port 1/1/c1/1:0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecommit\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"verification\"\u003eVerification\u003c/h2\u003e\n\u003ch3 id=\"step-1-verify-port-operational-status\"\u003eStep 1: Verify Port Operational Status\u003c/h3\u003e\n\u003cp\u003eVerify physical ports are administratively and operationally \u003ccode\u003eUp/Up\u003c/code\u003e across all routers:\u003c/p\u003e","title":"OSPF Part 1: Topology Setup and Interface Addressing"},{"content":"In enterprise campus networks, high availability requires redundant physical links between switches. However, redundant Layer 2 paths naturally introduce bridging loops and broadcast storms.\nTo resolve this, network engineers combine two essential Layer 2 technologies:\nSpanning Tree Protocol (STP): Blocks redundant paths logically to maintain a loop-free topology.\nEtherChannel (Link Aggregation): Bundles multiple physical interfaces into a single logical link, increasing bandwidth without triggering STP blocks on parallel links.\nLab Objective: Build a 3-switch topology where a single cable failure doesn\u0026rsquo;t disconnect users.\n📁 Lab File: Download the Layer 2 Redundancy Packet Tracer Lab (.pkt).\nCore Switch Configuration The Core switch acts as the Root Bridge for the network. We also apply Root Guard to the interfaces facing the distribution switches to maintain stability.\n! --- Basic Management --- enable configure terminal hostname Core spanning-tree mode rapid-pvst spanning-tree vlan 1 root primary ! --- EtherChannel to DS-A (f0/1, f0/3) --- interface range f0/1, f0/3 channel-group 1 mode active switchport mode trunk spanning-tree guard root exit ! --- EtherChannel to DS-B (f0/2, f0/4) --- interface range f0/2, f0/4 channel-group 2 mode active switchport mode trunk spanning-tree guard root exit DS-A Switch Configuration This switch connects to the Core and maintains a redundant inter-switch link to DS-B. Note that ports facing access devices use PortFast and BPDU Guard to prevent end-user loops.\n! --- Basic Management --- enable configure terminal hostname DS-A spanning-tree mode rapid-pvst ! --- EtherChannel to Core (f0/1, f0/3) --- interface range f0/1, f0/3 channel-group 1 mode active switchport mode trunk exit ! --- EtherChannel to DS-B (f0/2, f0/4) --- interface range f0/2, f0/4 channel-group 3 mode active switchport mode trunk exit ! --- PC Access Port --- interface f0/5 switchport mode access switchport access vlan 1 spanning-tree portfast spanning-tree bpduguard enable exit DS-B Switch Configuration DS-B mirrors the configuration of DS-A, ensuring it participates in all bundles.\n! --- Basic Management --- enable configure terminal hostname DS-B spanning-tree mode rapid-pvst ! --- EtherChannel to Core (f0/1, f0/3) --- interface range f0/1, f0/3 channel-group 2 mode active switchport mode trunk exit ! --- EtherChannel to DS-A (f0/2, f0/4) --- interface range f0/2, f0/4 channel-group 3 mode active switchport mode trunk exit ! --- PC Access Port --- interface f0/5 switchport mode access switchport access vlan 1 spanning-tree portfast spanning-tree bpduguard enable exit End-Device (PC) Configuration To test connectivity across the switching fabric, configure PCA and PCB with static IPv4 addresses within VLAN 1 (default subnet 192.168.1.0/24). Assign static IP parameters via the GUI (Desktop \u0026gt; IP Configuration):\nPCA Configuration (Interface f0) IP Address: 192.168.1.10 Subnet Mask: 255.255.255.0 Default Gateway: 192.168.1.1 PCB Configuration (Interface f0) IP Address: 192.168.1.20 Subnet Mask: 255.255.255.0 Default Gateway: 192.168.1.1 Verification Once you apply the configurations, validate link aggregation, STP topology roles, and real-time failover behavior.\nVerify EtherChannel Aggregation\nRun show etherchannel summary across your switches. Ensure member ports display the (P) flag (bundled in port-channel) rather than (D) (down) or (I) (stand-alone).\nValidate the STP Topology\nRun show spanning-tree vlan 1 to verify root bridge placement and loop prevention:\nCore: Should display This bridge is the root.\nDS-A or DS-B: One of the non-root Port-Channel interfaces must be in a BLK (Blocking/Alternate) state to break the Layer 2 loop across the triangle topology.\nTest Real-Time Convergence\nStart a continuous ping from PCA to PCB (ping -t 192.168.1.20). While ICMP traffic is flowing, manually delete one of the active physical links in the forwarding path. Rapid PVST+ and EtherChannel should retain connectivity with minimal to zero dropped packets.\n","permalink":"https://dennismwangi.com/ccna-labs/etherchannel-and-spanning-tree-protocol/","summary":"\u003cp\u003eIn enterprise campus networks, high availability requires redundant physical links between switches. However, redundant Layer 2 paths naturally introduce bridging loops and broadcast storms.\u003c/p\u003e\n\u003cp\u003eTo resolve this, network engineers combine two essential Layer 2 technologies:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eSpanning Tree Protocol (STP):\u003c/strong\u003e Blocks redundant paths logically to maintain a loop-free topology.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eEtherChannel (Link Aggregation):\u003c/strong\u003e Bundles multiple physical interfaces into a single logical link, increasing bandwidth without triggering STP blocks on parallel links.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eLab Objective:\u003c/strong\u003e Build a 3-switch topology where a single cable failure doesn\u0026rsquo;t disconnect users.\u003c/p\u003e","title":"CCNA Lab 1: Layer 2 Redundancy - EtherChannel and Spanning Tree Protocol"},{"content":"NetBox is an open-source Infrastructure Resource Management tool designed to act as that single source of truth. It decouples your network state variables from both your configuration playbooks and your physical hardware.\nIn this guide, we will deploy NetBox locally on Ubuntu and model a very simple set of infrastructural data.\ngraph LR subgraph Truth [Data Layer] NB[(NetBox)] -- \"Host Variables \u0026 State\" --\u003e API[REST API / GraphQL] end subgraph Logic [Execution Layer] API -- \"Dynamic Inventory\" --\u003e Ans{Ansible Engine} end subgraph Infrastructure [Network Layer] Ans -- \"SSH / Netconf\" --\u003e R1[Nokia 7750 SR-1] Ans -- \"SSH / Netconf\" --\u003e R2[Multi-Vendor Edge] end style NB fill:#2d3748,stroke:#4a5568,stroke-width:2px,color:#fff style Ans fill:#1a202c,stroke:#e2e8f0,stroke-width:2px,color:#fff style R1 fill:#2b6cb0,stroke:#4299e1,stroke-width:2px,color:#fff style R2 fill:#2b6cb0,stroke:#4299e1,stroke-width:2px,color:#fff1. System Architecture \u0026amp; Dependencies Before provisioning, we must understand NetBox\u0026rsquo;s application layers. It is not a single monolith; it is an ecosystem of decoupled components that work together over defined boundaries:\nThe Application Layer (Django/Python): Handles the core business logic and provides a rich REST and GraphQL API. The Storage Tier (PostgreSQL): A relational database that maintains strict data integrity for all physical and logical components. The Caching Layer (Redis): Handles session caching, background tasks, and queuing mechanisms. The Web Server (Nginx/Gunicorn): Manages inbound HTTP traffic and static asset delivery. 2. Low-Friction Provisioning via Docker Compose To avoid dependencies wrestling with individual system packages, the best approach for an engineering sandbox is to use Docker Compose. This packages the entire multi-tier architecture into isolated containers.\nStep 1: Clone the Official Docker Repository Open your terminal and pull down the optimized container configuration layout: NetBox Docker Repository:\ngit clone -b release https://github.com/netbox-community/netbox-docker.git Navigate into the project directory.\ncd netbox-docker Step 2: Enable Local Port Binding By default, the netbox-docker layout keeps the web application ports unexposed to external host machine networks. We must inject a standard Docker Compose override profile to bind port 8000:\ntee docker-compose.override.yml \u0026lt;\u0026lt;EOF services: netbox: ports: - 8000:8080 EOF Step 3: Fetch Images and Run Containers Download the underlying image abstractions (PostgreSQL, Redis, Core Nginx instances) and spin up the multi-tier runtime stack in background detached mode:\ndocker compose pull docker compose up -d Step 4: Create an Administrative Access Control Entry You cannot log into the web layer until you map a secure superuser account onto the database. Force an execution loop inside the active app container:\ndocker compose exec netbox /opt/netbox/netbox/manage.py createsuperuser Follow the interactive terminal prompts to map your administrative username and access password.\nStep 5: Access the Web Console Open a browser window on your workspace machine and navigate to: http://localhost:8000\n3. Explicit First-Time Configuration NetBox enforces strict, relational data integrity rules. For example, you cannot provision a router object until you define the physical site location it occupies. Log into the web UI at port 8000 and build out your infrastructure parameters from the top down using this exact order:\ngraph TD Org[1. Create Site: Lab-Home] --\u003e Mat[2. Create Manufacturer: Nokia] Mat --\u003e Template subgraph Template [Hardware Template] DT[3. Create Device Type: 7750 SR-1] DT -.-\u003e Int[Interfaces: 1/1/c1/1] DT -.-\u003e Bay[Module Bays: Slot 1] end Template --\u003e Dev[4. Instantiate Device: PE1] Dev --\u003e VRF[5. Provision VRF: VPRN-100] VRF --\u003e IP[6. Allocate IP Address] style Org fill:#2d3748,stroke:#4a5568,color:#fff style Mat fill:#2d3748,stroke:#4a5568,color:#fff style DT fill:#2b6cb0,stroke:#4299e1,color:#fff style Dev fill:#c53030,stroke:#f56565,color:#fff style VRF fill:#2d3748,stroke:#4a5568,color:#fff style IP fill:#2d3748,stroke:#4a5568,color:#fff1. Create a Site (Organization \u0026gt; Sites) Name: Lab-Home Status: Active Note: This models the physical or logical boundary where your network topologies sit.\n2. Create a Manufacturer (Devices \u0026gt; Device Types \u0026gt; Manufacturers) Name: Nokia Note: The hardware vendor identity wrapper.\n3. Create a Device Type (Devices \u0026gt; Device Types \u0026gt; Device Types) This functions as an object template defining hardware limits.\nManufacturer: Nokia Model: 7750 SR-1 Component Initialization: Click into your newly created 7750 SR-1 template page and click the Add Components dropdown to populate the component definitions: Interfaces: Add the Name (e.g 1/1/c1/1) and the correct interface type (e.g 10GBASE-SR (10GE)). Module Bays: Add Slot 1 (This models the input/output hardware slot). 4. Instantiate a Device (Devices \u0026gt; Devices) Now, deploy a node instance based on that underlying schema layout:\nName: PE1 Site: Lab-Home Device type: Nokia 7750 SR-1 Device role: Create a new operational role named Edge Router. Status: Active 5. Provision a Virtual Routing Instance (IPAM \u0026gt; VRFs): Name: VPRN-100 Route Distinguisher (RD): 65000:100 6. Allocate an IPv4 Entry (IPAM \u0026gt; IP Addresses): Address: 10.1.1.1/32 Status: Active VRF: VPRN-100 Interface Assignment: Map this IP explicit to target host PE1 on interface 1/1/c1/1. Conclusion \u0026amp; Next Steps We now have an oversimplified Source of Truth running locally on our machine. Our data model is clean, isolated, and strictly relational.\nIn Part 2 of the NetDevOps Pipeline series, we will step into the execution layer and explore Ansible Integration. We will throw away static inventory files and use the official NetBox plugin to dynamically turn these database fields into live, programmable execution targets.\n","permalink":"https://dennismwangi.com/netdevops/netbox/","summary":"\u003cp\u003e\u003cstrong\u003eNetBox\u003c/strong\u003e is an open-source Infrastructure Resource Management tool designed to act as that single source of truth. It decouples your network state variables from both your configuration playbooks and your physical hardware.\u003c/p\u003e\n\u003cp\u003eIn this guide, we will deploy NetBox locally on Ubuntu and model a very simple set of infrastructural data.\u003c/p\u003e\n\u003cdiv class=\"mermaid\"\u003egraph LR\n    subgraph Truth [Data Layer]\n        NB[(NetBox)] -- \"Host Variables \u0026 State\" --\u003e API[REST API / GraphQL]\n    end\n\n    subgraph Logic [Execution Layer]\n        API -- \"Dynamic Inventory\" --\u003e Ans{Ansible Engine}\n    end\n\n    subgraph Infrastructure [Network Layer]\n        Ans -- \"SSH / Netconf\" --\u003e R1[Nokia 7750 SR-1]\n        Ans -- \"SSH / Netconf\" --\u003e R2[Multi-Vendor Edge]\n    end\n\n    style NB fill:#2d3748,stroke:#4a5568,stroke-width:2px,color:#fff\n    style Ans fill:#1a202c,stroke:#e2e8f0,stroke-width:2px,color:#fff\n    style R1 fill:#2b6cb0,stroke:#4299e1,stroke-width:2px,color:#fff\n    style R2 fill:#2b6cb0,stroke:#4299e1,stroke-width:2px,color:#fff\u003c/div\u003e\u003ch2 id=\"1-system-architecture--dependencies\"\u003e1. System Architecture \u0026amp; Dependencies\u003c/h2\u003e\n\u003cp\u003eBefore provisioning, we must understand NetBox\u0026rsquo;s application layers. It is not a single monolith; it is an ecosystem of decoupled components that work together over defined boundaries:\u003c/p\u003e","title":"NetDevOps Pipeline Part 1: Initializing NetBox as your Network Source of Truth"},{"content":"This part covers Single-Area OSPFv2 (Area 0) configuration across the 6-node Nokia SR OS topology, verification of neighbor adjacencies, route table population, and LSDB behavior with point-to-point and broadcast network types.\nSR OS Version: 25.7.R1\nCLI Mode: MD-CLI (Model-Driven CLI)\nConfiguration Enable OSPF instance 0 in Area 0 across all nodes. Configure physical and system interfaces as point-to-point, set system interfaces as passive to advertise loopback reachability without sending unnecessary Hello packets, and secure adjacencies with MD5 authentication.\nRouter R1 (CE1) /configure router ospf 0 admin-state enable /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; passive true /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 commit Router R2 (PE1) /configure router ospf 0 admin-state enable /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; passive true /configure router ospf 0 area 0 interface \u0026#34;toR1\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR1\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR1\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 /configure router ospf 0 area 0 interface \u0026#34;toR3\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR3\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR3\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 /configure router ospf 0 area 0 interface \u0026#34;toR4\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR4\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR4\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 commit Router R3 (P1) /configure router ospf 0 admin-state enable /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; passive true /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 commit Router R4 (P2) /configure router ospf 0 admin-state enable /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; passive true /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 commit Router R5 (PE2) /configure router ospf 0 admin-state enable /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; passive true /configure router ospf 0 area 0 interface \u0026#34;toR3\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR3\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR3\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 /configure router ospf 0 area 0 interface \u0026#34;toR4\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR4\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR4\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 /configure router ospf 0 area 0 interface \u0026#34;toR6\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR6\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR6\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 commit Router R6 (CE2) /configure router ospf 0 admin-state enable /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;system\u0026#34; passive true /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; interface-type point-to-point /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; authentication-type message-digest /configure router ospf 0 area 0 interface \u0026#34;toR5\u0026#34; message-digest-key 1 md5 NokiaOSPF2026 commit Verification Verifying OSPF Interfaces Verify that all active physical links and system loopbacks show operational state PToP (show router ospf interface):\nRouter R2 (PE1): Router R3 (P1): Checking Adjacency States With point-to-point network types configured, OSPF bypasses DR/BDR election and transitions directly to Full adjacency:\nR1 (CE1): 1 full adjacency (toR2) R2 (PE1): 3 full adjacencies (toR1, toR3, toR4) R3 (P1) \u0026amp; R4 (P2): 2 full adjacencies each R5 (PE2): 3 full adjacencies (toR3, toR4, toR6) R6 (CE2): 1 full adjacency (toR5) Neighbor Verification Example: Router R2 (PE1) Validating End-to-End Reachability Verify OSPF and global routing tables on R1 (CE1). Remote loopbacks and transit subnets are learned dynamically via OSPF:\nOSPF Route Table Inspection (R1): Global Route Table Inspection (R1): Verify end-to-end data plane reachability across the core by pinging R6\u0026rsquo;s system loopback (10.100.1.6) from R1 (R1 → R2 → R3/R4 → R5 → R6):\nLSDB Analysis Inspect Link-State Database (LSDB) contents across the topology, then observe how changing the interface network type from point-to-point to broadcast alters LSA generation and triggers DR/BDR elections.\n1. Examining the OSPF Link-State Database Once OSPF converges, every router maintains an identical LSDB copy containing entries corresponding to each router\u0026rsquo;s system ID:\nDatabase Inspection on R1:\nDatabase Inspection on R5:\n2. Detailed LSA Inspection Inspecting a Router LSA (e.g., from R1 (CE1) via 10.100.1.1) details how physical topology (neighbors) and IP reachability (adjacent subnets) are advertised:\n3. Changing Interface Types: Point-to-Point to Broadcast Change the network type on the link between R1 (CE1) and R2 (PE1) from point-to-point to broadcast:\nOn R1: /configure router ospf 0 area 0 interface \u0026#34;toR2\u0026#34; interface-type broadcast commit On R2: /configure router ospf 0 area 0 interface \u0026#34;toR1\u0026#34; interface-type broadcast commit 4. Broadcast Verification Once committed on both routers, OSPF initiates a DR/BDR election:\nRouter R1 (CE1) Interface State: Router R2 (PE1) Interface State: The operational interface state transitions from PToP to either DR or BDR.\nRouter R1 (CE1) Database State: A Network LSA (Type 2) is generated and injected into the LSDB by the elected Designated Router, representing the transit broadcast segment and listing all adjacent routers.\n","permalink":"https://dennismwangi.com/ospf/ospf-part-2-single-area-configuration/","summary":"\u003cp\u003eThis part covers Single-Area OSPFv2 (Area 0) configuration across the 6-node Nokia SR OS topology, verification of neighbor adjacencies, route table population, and LSDB behavior with point-to-point and broadcast network types.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eSR OS Version:\u003c/strong\u003e 25.7.R1\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eCLI Mode:\u003c/strong\u003e \u003cstrong\u003eMD-CLI\u003c/strong\u003e (Model-Driven CLI)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eEnable OSPF instance 0 in Area 0 across all nodes. Configure physical and system interfaces as point-to-point, set system interfaces as passive to advertise loopback reachability without sending unnecessary Hello packets, and secure adjacencies with MD5 authentication.\u003c/p\u003e","title":"OSPF Part 2: Single-Area OSPFv2 (Area 0) Configuration"},{"content":"Segmenting corporate networks into logical VLANs isolates broadcast domains, but without explicit access controls, inter-VLAN routing allows unrestricted traffic flow between subnets.\nTo enforce security parameters at the network perimeter, engineers use Access Control Lists (ACLs) to filter traffic between guest networks and critical internal assets.\nLab Objective: Build a Router-on-a-Stick (ROAS) architecture using 802.1Q trunks, configure router-based DHCP services, and apply an Extended ACL to block guest VLAN traffic from accessing the internal server.\n📁 Lab File: Download the Inter-VLAN Routing and Guest Isolation Packet Tracer Lab (.pkt).\nTopology In this lab, we use a Cisco 4331 ISR, a Catalyst 2960 switch, and three end devices.\nSource Device Interface Destination Device Interface Assigned VLAN Switch0 Gi0/1 Router0 Gi0/0/0 Trunk (802.1Q) Switch0 Fa0/1 PC0 (Employee) Fa0 VLAN 10 Switch0 Fa0/2 Server0 (Internal) Fa0 VLAN 10 Switch0 Fa0/6 PC1 (Guest) Fa0 VLAN 20 Switch Configuration (VLANs \u0026amp; Trunks) Provision VLAN 10 (Employee) and VLAN 20 (Guest), assign access interfaces, and configure the trunk uplink to the router.\n! --- Create VLANs --- enable configure terminal hostname Switch0 vlan 10 name Employee vlan 20 name Guest exit ! --- Assign Employee Access Ports --- interface range fa0/1 - 5 switchport mode access switchport access vlan 10 exit ! --- Assign Guest Access Ports --- interface range fa0/6 - 10 switchport mode access switchport access vlan 20 exit ! --- Configure 802.1Q Trunk to Router --- interface gig0/1 switchport mode trunk exit Router Configuration (ROAS \u0026amp; DHCP Pools) Enable the physical interface, define 802.1Q sub-interfaces for inter-VLAN routing, and configure pool exclusions and DHCP pools.\n! --- System \u0026amp; Physical Interface Setup --- enable configure terminal hostname Router0 interface gig0/0/0 no shutdown exit ! --- Sub-interface: VLAN 10 (Employee Gateway) --- interface gig0/0/0.10 encapsulation dot1Q 10 ip address 192.168.10.1 255.255.255.0 exit ! --- Sub-interface: VLAN 20 (Guest Gateway) --- interface gig0/0/0.20 encapsulation dot1Q 20 ip address 192.168.20.1 255.255.255.0 exit ! --- Exclude Static Infrastructure IPs --- ip dhcp excluded-address 192.168.10.1 ip dhcp excluded-address 192.168.10.50 ip dhcp excluded-address 192.168.20.1 ! --- DHCP Pool: Employee Network --- ip dhcp pool EMPLOYEE_POOL network 192.168.10.0 255.255.255.0 default-router 192.168.10.1 dns-server 8.8.8.8 exit ! --- DHCP Pool: Guest Network --- ip dhcp pool GUEST_POOL network 192.168.20.0 255.255.255.0 default-router 192.168.20.1 dns-server 8.8.8.8 exit Access Control List Configuration (Router) To prevent guests from traversing inter-VLAN routing into the 192.168.10.0/24 subnet, apply an Extended Named ACL inbound on the guest sub-interface (Gi0/0/0.20).\nExtended ACLs filter as close to the source as possible based on source and destination parameters.\n! --- Define Extended ACL --- ip access-list extended BLOCK_GUEST deny ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255 permit ip any any exit ! --- Apply ACL to Guest Gateway Sub-interface --- interface gig0/0/0.20 ip access-group BLOCK_GUEST in exit End-Device Addressing (Desktop \u0026gt; IP Configuration) Configure static parameters on Server0. PC0 and PC1 obtain their IP parameters dynamically via the router\u0026rsquo;s DHCP pools.\nDevice IP Address Assignment Subnet Mask Default Gateway PC0 (Employee) Dynamic (DHCP: 192.168.10.2) 255.255.255.0 192.168.10.1 Server0 (Internal) Static: 192.168.10.50 255.255.255.0 192.168.10.1 PC1 (Guest) Dynamic (DHCP: 192.168.20.2) 255.255.255.0 192.168.20.1 Verification Validate inter-VLAN routing and ACL enforcement from the end-device command prompts (Desktop \u0026gt; Command Prompt).\nVerify Internal VLAN Access (Employee to Server):\nFrom PC0, ping the internal server address:\nping 192.168.10.50 Result: Replies are received successfully across VLAN 10.\nVerify Guest Network Isolation (ACL Enforcement):\nFrom PC1, attempt to ping the internal server across the router:\nping 192.168.10.50 Result: Output displays Destination host unreachable. as the inbound ACL on Gi0/0/0.20 drops the traffic.\nVerify Local Gateway Reachability:\nFrom PC1, ping its default gateway:\nping 192.168.20.1 Result: Replies are received, confirming local connectivity and external internet reachability (via permit ip any any).\nInspect ACL Matches on Router:\nExecute show ip access-lists on Router0 to verify match counters for dropped packets:\nRouter0# show ip access-lists BLOCK_GUEST Extended IP access list BLOCK_GUEST deny ip 192.168.20.0 0.0.0.255 192.168.10.0 0.0.0.255 (4 match (es)) permit ip any any (6 match (es)) ","permalink":"https://dennismwangi.com/ccna-labs/inter-vlan-routing-guest-isolation-acls/","summary":"\u003cp\u003eSegmenting corporate networks into logical VLANs isolates broadcast domains, but without explicit access controls, inter-VLAN routing allows unrestricted traffic flow between subnets.\u003c/p\u003e\n\u003cp\u003eTo enforce security parameters at the network perimeter, engineers use Access Control Lists (ACLs) to filter traffic between guest networks and critical internal assets.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eLab Objective:\u003c/strong\u003e Build a Router-on-a-Stick (ROAS) architecture using 802.1Q trunks, configure router-based DHCP services, and apply an Extended ACL to block guest VLAN traffic from accessing the internal server.\u003c/p\u003e","title":"CCNA Lab 2: Inter-VLAN Routing and Guest Traffic Isolation with ACLs"},{"content":"By default, Ansible relies on static inventory files (hosts.ini or hosts.yaml). In a dynamic, modern network environment, managing these text files manually becomes an operational nightmare.\nTo bridge this gap, we can tie Ansible\u0026rsquo;s execution directly to NetBox, using it as our single source of truth. Before we configure the plugin, your local control machine needs the official NetBox collection along with its underlying Python API wrapper and timezone dependencies:\n# Install the official NetBox Ansible collection ansible-galaxy collection install netbox.netbox # Install pynetbox and pytz for timezone parsing pip install pynetbox pytz ⚠️ Note on Python Environments: If you are using a Python virtual environment (venv) for your automation labs, ensure you activate it before running the pip command so Ansible can resolve the dependency.\nThe Big Picture: How Dynamic Discovery Works Rather than reading a static list of IP addresses from your local hard drive, our updated pipeline shifts the data gathering process entirely to an on-demand API loop.\nHere is exactly how Ansible communicates with NetBox to find your target routers before executing a playbook:\ngraph LR subgraph Control [Control Machine] A[Ansible Engine] --\u003e|1. Triggers| B(netbox_inv.yml / auto plugin) end subgraph SOT [NetBox Environment] B --\u003e|2. HTTP API Handshake| C[NetBox API Engine] C --\u003e|3. Database Query| D[(PostgreSQL Database)] D --\u003e|4. Node Metadata JSON| C end subgraph Infra [Lab Infrastructure] E[PE1 Nokia SR OS Node] end %% Flowing back out of NetBox to Ansible, then to the Node C --\u003e|5. Dynamic Host Mapping| B A --\u003e|6. Configuration Deployment via network_cli / NETCONF | E %% Styling style A fill:#1A1A1A,stroke:#EE2C34,stroke-width:2px,color:#fff style B fill:#333,stroke:#fff,stroke-width:1px,color:#fff style C fill:#0f172a,stroke:#2563eb,stroke-width:2px,color:#fff style D fill:#1e293b,stroke:#38bdf8,stroke-width:1px,color:#fff style E fill:#022c22,stroke:#10b981,stroke-width:2px,color:#fffWith the conceptual framework clear, let’s build the configuration file that initiates this handshake.\n1. Defining the NetBox Dynamic Inventory Instead of managing a static hosts.ini or hosts.yaml file, we use the netbox.netbox.nb_inventory plugin and create a YAML file that defines the connection.\nCreate a file named netbox_inv.yml:\n--- plugin: netbox.netbox.nb_inventory # Point directly to your NetBox instance api_endpoint: http://127.0.0.1:8000 validate_certs: false # Your secure API token (Admin \u0026gt; Authentication \u0026gt; API Tokens) token: \u0026#34;your_generated_netbox_api_token_here\u0026#34; # Automatically group devices based on NetBox metadata group_by: - device_roles - sites - platforms # Map NetBox data models directly to native Ansible variables compose: ansible_host: primary_ip4.address.ip ansible_network_os: platform.slug | replace(\u0026#39;-\u0026#39;, \u0026#39;.\u0026#39;) ansible_connection: \u0026#34;\u0026#39;network_cli\u0026#39;\u0026#34; 💡 Pro-Tip: Copy your NetBox API token immediately upon creation in the GUI. For security, NetBox only displays the full plain-text string once!\n2. Verifying the Real-Time Link Before executing code against your inventory, you can use native Ansible CLI tools to verify that the dynamic plugin is successfully parsing your database.\nRun the following command to print a visual graph of your infrastructure:\nansible-inventory -i netbox_inv.yml --graph Expected Output: Ansible automatically queries the API and builds structured groups based on your layout:\n@all: |--@ungrouped: |--@sites_lab-home: | |--PE1 |--@device_roles_edge-router: | |--PE1 |--@platforms_nokia_sros: | |--PE1 To see the exact variables passed down from NetBox for a single device, inspect a specific host:\nansible-inventory -i netbox_inv.yml --host PE1 3. Running Your First Automated Task Because Ansible translates NetBox device roles into executable host groups (@device_roles_edge-router), you can now run ad-hoc commands against whole classes of devices without maintaining text files.\n# Get devices info ansible all -i netbox_inv.yml -m nokia.sros.device_info -e \u0026#34;ansible_connection=ansible.netcommon.network_cli\u0026#34; # Target only edge routers ansible device_roles_edge-router -i netbox_inv.yml -m nokia.sros.device_info -e \u0026#34;ansible_connection=ansible.netcommon.network_cli\u0026#34; 4. Executing a Nokia SR OS Fact-Gathering Playbook With the dynamic inventory feeding accurate connection parameters (ansible_host and ansible_network_os) straight to Ansible, you can run structured automation tasks.\nCreate a playbook named nokia_info.yml:\n--- - name: Get Facts from Nokia SR OS hosts: device_roles_edge-router connection: network_cli gather_facts: false tasks: - name: Show System Version ansible.netcommon.cli_command: command: show version register: version_output - name: Print Version Details debug: var: version_output.stdout_lines Execute it locally using standard execution commands:\nansible-playbook -i netbox_inv.yml nokia_info.yml Conclusion \u0026amp; Next Steps This architecture shifts your operational workflow completely:\nModel: You provision a new node inside your NetBox single source of truth dashboard. Execute: You run your playbooks seamlessly via the local standard CLI. Automate: Ansible fetches the real-time target data from the API, constructs the inventory graph on the fly, and applies code variations safely. Now that our data model speaks directly to our automation engine, we are ready to take this architecture to the next step. In Part 3, we are shifting to Infrastructure-as-Code (IaC).\nWe will introduce Containerlab — a lightweight, containerized orchestration engine that will allow us to define our entire multi-node router topology as a simple YAML file. Instead of spinning up resource-heavy VMs, you will learn how to launch, tear down, and version-control a lab environment in seconds. Stay tuned!\n","permalink":"https://dennismwangi.com/netdevops/ansible-netbox-integration/","summary":"\u003cp\u003eBy default, Ansible relies on static inventory files (\u003ccode\u003ehosts.ini\u003c/code\u003e or \u003ccode\u003ehosts.yaml\u003c/code\u003e). In a dynamic, modern network environment, managing these text files manually becomes an operational nightmare.\u003c/p\u003e\n\u003cp\u003eTo bridge this gap, we can tie Ansible\u0026rsquo;s execution directly to NetBox, using it as our single source of truth. Before we configure the plugin, your local control machine needs the official NetBox collection along with its underlying Python API wrapper and timezone dependencies:\u003c/p\u003e","title":"NetDevOps Pipeline Part 2: Building a Dynamic Inventory with Ansible and NetBox"},{"content":" Lab Objective: Prevent rogue endpoints from acting as DHCP servers or spoofing ARP responses, and enforce dynamic MAC address binding to automatically shut down ports when unauthorized cable moves occur.\n📁 Lab File: Download the Layer 2 Security Hardening Packet Tracer Lab (.pkt).\nTopology The topology uses a single Catalyst 2960 switch connecting legitimate endpoints, an authorized DHCP server, and a rogue device acting as a fake DHCP server.\nSource Device Interface Destination Device Interface Port Security Role PC0 (Legitimate Host) Fa0 Switch0 Fa0/1 Untrusted (Sticky MAC) Server1 (Rogue DHCP/Host) Fa0 Switch0 Fa0/2 Untrusted (Sticky MAC) PC1 (Legitimate Host) Fa0 Switch0 Fa0/3 Untrusted (Sticky MAC) Server0 (Legitimate DHCP) Fa0 Switch0 Fa0/24 Trusted (Infrastructure) Global Configuration (Switch) Enable DHCP Snooping and DAI globally, then mark the DHCP server port (Fa0/24) as trusted.\nenable configure terminal hostname Switch0 ! --- Enable DHCP Snooping Globally and per VLAN --- ip dhcp snooping ip dhcp snooping vlan 1 no ip dhcp snooping information option ! --- Enable Dynamic ARP Inspection (DAI) --- ip arp inspection vlan 1 ip arp inspection validate src-mac dst-mac ip ! --- Configure Trusted Port --- interface FastEthernet0/24 description Legitimate DHCP Server Uplink ip dhcp snooping trust ip arp inspection trust exit Access Port Configuration (Untrusted Ports) - (Switch) Access interfaces (Fa0/1 - 3) handle untrusted endpoint traffic. Port security binds each port to its first learned MAC address; any violation triggers a port shutdown.\n! --- Secure Access Interfaces --- interface range FastEthernet0/1 - 3 switchport mode access switchport access vlan 1 switchport port-security switchport port-security mac-address sticky switchport port-security violation shutdown exit Verification Validate the security using show commands on Switch0.\nVerify the DHCP Snooping Binding Table:\nConfirm the switch successfully logs IP-to-MAC bindings for legitimate dynamic leases:\nSwitch0# show ip dhcp snooping binding MacAddress IpAddress Lease(sec) Type VLAN Interface ------------------ ---------------- ----------- -------------- ----- -------------------- 00:01:C9:2C:43:C5 192.168.1.101 86400 dhcp-snooping 1 FastEthernet0/1 Total number of bindings: 1 Result: The binding table contains IP-to-MAC mappings that DAI uses to validate ARP traffic.\nVerify Dynamic ARP Inspection Status:\nCheck the validation and operational status for VLAN 1:\nSwitch0# show ip arp inspection vlan 1 Source Mac Validation : Enabled Destination Mac Validation : Enabled IP Address Validation : Enabled Vlan Configuration Operation ACL Match Static ACL ---- ------------- --------- --------- ---------- 1 Enabled Active Vlan ACL Logging DHCP Logging Probe Logging ---- ----------- ------------ ------------- 1 Deny Deny Off Result: ARP inspection is active on VLAN 1 with src-mac, dst-mac, and IP validation enabled.\nVerify Port Security Interface State:\nInspect the operational state and sticky MAC binding on access interface Fa0/1:\nSwitch0# show port-security interface fa0/1 Port Security : Enabled Port Status : Secure-up Violation Mode : Shutdown Aging Time : 0 mins Aging Type : Absolute SecureStatic Address Aging : Disabled Maximum MAC Addresses : 1 Total MAC Addresses : 1 Configured MAC Addresses : 0 Sticky MAC Addresses : 1 Last Source Address:Vlan : 0001.C92C.43C5:1 Security Violation Count : 0 Result: Interface Fa0/1 is Secure-up with 0001.C92C.43C5 learned dynamically as a sticky MAC address.\n","permalink":"https://dennismwangi.com/ccna-labs/layer-2-security-dhcp-snooping-dai-port-security/","summary":"\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eLab Objective:\u003c/strong\u003e Prevent rogue endpoints from acting as DHCP servers or spoofing ARP responses, and enforce dynamic MAC address binding to automatically shut down ports when unauthorized cable moves occur.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cblockquote\u003e\n\u003cp\u003e📁 \u003cstrong\u003eLab File:\u003c/strong\u003e Download the \u003ca href=\"/labs/layer-2-security-hardening.pkt\"\u003eLayer 2 Security Hardening Packet Tracer Lab (.pkt)\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"topology\"\u003eTopology\u003c/h2\u003e\n\u003cp\u003eThe topology uses a single Catalyst 2960 switch connecting legitimate endpoints, an authorized DHCP server, and a rogue device acting as a fake DHCP server.\u003c/p\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eSource Device\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eDestination Device\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003eInterface\u003c/th\u003e\n\t\t\t\t\t\u003cth style=\"text-align: left\"\u003ePort Security Role\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003ePC0 (Legitimate Host)\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eSwitch0\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0/1\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eUntrusted (Sticky MAC)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eServer1 (Rogue DHCP/Host)\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eSwitch0\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0/2\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eUntrusted (Sticky MAC)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003ePC1 (Legitimate Host)\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eSwitch0\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0/3\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eUntrusted (Sticky MAC)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eServer0 (Legitimate DHCP)\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eSwitch0\u003c/strong\u003e\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eFa0/24\u003c/td\u003e\n\t\t\t\t\t\u003ctd style=\"text-align: left\"\u003eTrusted (Infrastructure)\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2 id=\"global-configuration-switch\"\u003eGlobal Configuration (Switch)\u003c/h2\u003e\n\u003cp\u003eEnable DHCP Snooping and DAI globally, then mark the DHCP server port (\u003ccode\u003eFa0/24\u003c/code\u003e) as trusted.\u003c/p\u003e","title":"CCNA Lab 3: Layer 2 Security Hardening - DHCP Snooping, DAI, and Port Security"},{"content":"Up until now, our pipeline has focused on the management and mapping of data. We modeled our nodes inside our NetBox source of truth (Part 1), and then we built a dynamic handshake to pull that data straight into Ansible (Part 2).\nBut there’s a missing link: Where are the actual routers coming from?\nIf we have to manually spin up heavy virtual machines, map virtual interfaces, and configure bridge links every time we want to test our playbooks, we lose all the speed advantages of automation.\nIn Part 3, we treat our entire network topology exactly like software application code. We use Containerlab to orchestrate, spin up, and destroy our multi-vendor lab fabric in seconds using a single, version-controlled YAML configuration file.\nThe Big Picture: Expanding the Architecture Before writing the configuration files, let’s look at how our architecture shifts when we bring Containerlab into the mix. Containerlab runs directly on your Linux host or virtual machine, utilizing lightweight containerized routing images (like FRR, VyOS, SRSIM) instead of resource-heavy hypervisor VMs.\nHere is the updated execution roadmap we will build out across this guide:\ngraph TD subgraph Spec [1. Code \u0026 Definitions] A[vpls.clab.yml] --\u003e|YAML Config Input| C[Containerlab Engine] end subgraph Fabric [2. Virtual Lab Infrastructure] C --\u003e|Spins up / binds| P1[PE1: Nokia SR OS Container] C --\u003e|Spins up / binds| P2[PE2: Nokia SR OS Container] end subgraph SOT [3. Source of Truth Sync] P1 --\u003e|Management IP Registration| NB[NetBox] P2 --\u003e|Management IP Registration| NB end %% Formatting style A fill:#1a1a1a,stroke:#38bdf8,stroke-width:2px,color:#fff style C fill:#0f172a,stroke:#2563eb,stroke-width:2px,color:#fff style P1 fill:#022c22,stroke:#10b981,stroke-width:2px,color:#fff style P2 fill:#022c22,stroke:#10b981,stroke-width:2px,color:#fff style NB fill:#333,stroke:#fff,stroke-width:1px,color:#fff style Spec fill:#262626,stroke:none style Fabric fill:#262626,stroke:none style SOT fill:#262626,stroke:noneWhy Containerlab for Labbing? If you\u0026rsquo;ve used tools like GNS3, you know they are great graphical sandboxes, but they have distinct drawbacks for automation pipelines:\nResource Constraints: Heavy QEMU/KVM virtual machines consume significant amounts of RAM and CPU cycles, quickly overwhelming standard laptop setups.\nLack of Version Control: You cannot easily save your entire canvas topology, interface connections, and base configurations into a Git repository.\nNo Automation API Hook: Starting, stopping, or replicating an environment requires manual intervention in a GUI.\nContainerlab changes this by launching routers as container processes. They boot up almost instantly, consume a fraction of the memory, and use simple text files to map interfaces.\n1. Setting Up the Containerlab Topology File To define our network, we create a core topology spec file. This tells Containerlab which container images to use, how much resource overhead to allocate, and exactly how the interfaces bind to one another.\nCreate a file named vpls.clab.yml:\nname: netdevops-lab topology: kinds: nokia_srsim: # Point to your local container registry or image path image: localhost/nokia/srsim:25.7.R1 license: /license/license.txt nodes: PE1: kind: nokia_srsim type: sr-1 # Simulates a hardware type profile mgmt-ipv4: 172.20.20.11 PE2: kind: nokia_srsim type: sr-1 mgmt-ipv4: 172.20.20.12 links: - endpoints: [\u0026#34;PE1:1/1/c1/1\u0026#34;, \u0026#34;PE2:1/1/c1/1\u0026#34;] Note on Node Images: Nokia SRSim images and their corresponding license files are proprietary assets obtained directly via official channels. However, because Containerlab utilizes standard Infrastructure-as-Code definitions, you can easily substitute these kinds with alternative open or vendor-specific virtual images (like Cisco IOS-XRd or Arista cEOS) to match what you have available in your local environment.\nDeconstructing the Configuration: kinds: This defines global properties for specific operating systems. Instead of repeating license paths and image versions for every router, we define a template for all nokia_srsim nodes.\nnodes: This is where we declare our actual host targets. Notice we are assigning fixed, predictable management IP addresses (mgmt-ipv4) and modeling an sr-1 profile. This ensures that our NetBox inventory data models will match our live lab environment perfectly.\nlinks: Instead of dragging lines on a visual canvas, we define links as an array matching endpoints. Containerlab automatically maps these directly into the specialized Nokia port syntax (1/1/c1/1), spawning virtual ethernet pairs (veth) on the underlying Linux kernel to splice them into the container interfaces.\n2. Deploying the Fabric via CLI Once your topology file is defined, launching your entire network infrastructure requires a single command in your Linux terminal:\nsudo containerlab deploy -t vpls.clab.yml Expected Deployment Output: Containerlab will pull the images, construct the bridge links, start the container instances, and print a clean matrix showing your running nodes:\nName Kind/Image State IPv4/6 Address clab-netdevops-lab-PE1 nokia_srsim localhost/nokia/srsim:25.7.R1 running 172.20.20.11 3fff:172:20:20::2 clab-netdevops-lab-PE2 nokia_srsim localhost/nokia/srsim:25.7.R1 running 172.20.20.12 3fff:172:20:20::3 To tear down the entire infrastructure and free up system resources instantly when you\u0026rsquo;re done labbing:\nsudo containerlab destroy -t vpls.clab.yml 3. Connecting Containerlab to our NetBox Pipeline This is where our three-part pipeline ties together cleanly into a single workflow engine.\nAligning the Source of Truth: Preparing NetBox for PE2 Before running our playbooks, we need to ensure our single source of truth accurately reflects our expanded lab footprint. Since we only modeled our initial node (PE1) back in Part 1, we need to mirror those steps for our new peer node so that Ansible can discover it.\nLog into your NetBox GUI instance and quickly add the second node:\nAdd Device: Name: PE2 | Device Role: Edge Router | Site: Lab-Home | Device Type: Nokia 7750 SR-1 Add Interface: Create interface 1/1/c1/1 on PE2 to match our physical fabric layout. Assign Management IP: Allocate 172.20.20.12/24 and assign it explicitly as the primary management IPv4 address for PE2. Running the End-to-End Verification Because we configured fixed management IPs in our vpls.clab.yml matching our records inside NetBox, our dynamic Ansible inventory infrastructure from Part 2 will now scale automatically without modifying a single line of local host files.\nLet\u0026rsquo;s test the entire integrated pipeline path. With your Containerlab fabric deployed, run your dynamic inventory graph to verify connection states:\nansible-inventory -i netbox_inv.yml --graph Your terminal output will now dynamically discover both nodes directly from the API:\n@all: |--@ungrouped: |--@sites_lab-home: | |--PE1 | |--PE2 |--@device_roles_edge-router: | |--PE1 | |--PE2 |--@platforms_nokia_sros: | |--PE1 | |--PE2 Then, execute your Nokia fact playbook to poll the live containerized nodes simultaneously:\nansible-playbook -i netbox_inv.yml nokia_info.yml Ansible will query NetBox via API, discover that PE1 is located at 172.20.20.11 and PE2 is at 172.20.20.12, open up parallel execution pipelines straight into the containerized Nokia instances running on your laptop, and retrieve live operational states without a single static inventory file ever being created.\nConclusion \u0026amp; Next Steps We have successfully migrated out of the legacy network configuration and built a modular, automated DevOps workspace:\nNetBox holds our intended architectural state (Our Single Source of Truth).\nContainerlab handles our physical fabric orchestration on demand (Our Infrastructure-as-Code).\nAnsible glues them together, pulling configuration parameters from the source data and applying execution parameters to the target container instances.\nThis loop provides the foundation for advanced workflows like continuous configuration compliance, automated pre-change testing, and real-time validation.\nWhat\u0026rsquo;s Next: Decoupling Logic with Jinja2 and YANG Now that we have our core framework established, the next major hurdle is scalability. If you hardcode configuration blocks directly into your Ansible tasks, your playbooks quickly become unmanageable monolithic files.\nIn Part 4, we are going to dive into keeping our playbooks clean by completely separating our execution logic from our configuration data. We will cover:\nJinja2 Templating: How to build dynamic configuration templates for our Nokia routers that read variables dynamically on the fly. Abstracting with YANG Models: Understanding how structural data models (like OpenConfig or native Nokia YANG) allow us to cleanly map network states. Structuring Variable Scopes: Moving variables cleanly between host files, group vars, and our NetBox API returns so that the playbook\u0026rsquo;s only job is to point to a template and push the result. ","permalink":"https://dennismwangi.com/netdevops/iac-containerlab/","summary":"\u003cp\u003eUp until now, our pipeline has focused on the management and mapping of data. We modeled our nodes inside our NetBox source of truth (Part 1), and then we built a dynamic handshake to pull that data straight into Ansible (Part 2).\u003c/p\u003e\n\u003cp\u003eBut there’s a missing link: \u003cstrong\u003eWhere are the actual routers coming from?\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIf we have to manually spin up heavy virtual machines, map virtual interfaces, and configure bridge links every time we want to test our playbooks, we lose all the speed advantages of automation.\u003c/p\u003e","title":"NetDevOps Pipeline Part 3: Topology Orchestration with Containerlab"},{"content":"Dynamic routing protocols like OSPF dynamically calculate the shortest path through a network using link metrics. By default, OSPF calculates interface cost based on reference bandwidth (100 Mbps / bandwidth). However, in modern networks with disparate WAN links (such as high-speed fiber vs. low-bandwidth backup copper), default calculations may not accurately reflect desired traffic paths.\nTo enforce traffic engineering, network administrators manually tune OSPF interface costs to prefer primary fiber paths over backup links.\nLab Objective: Connect three office locations using Single-Area OSPFv2, manually adjust interface costs to prefer the high-speed fiber link over copper links, and verify dynamic route convergence during a simulated link failure.\n📁 Lab File: Download the Single-Area OSPFv2 Path Selection Packet Tracer Lab (.pkt).\nTopology The topology forms a triangular WAN network connecting an HQ hub and two branch offices. HQ connects to Branch 2 via a primary fiber link and to Branch 1 via a backup copper link.\nLocal Router Local Interface Remote Router Remote Interface Link Purpose / Cost Adjustment HQ Gi0/0/2 Branch 2 Gi0/0/2 Primary Fiber Link (Default Cost: 1) HQ Gi0/0/0 Branch 1 Gi0/0/0 Backup Copper Link (Manual Cost: 500) Branch 1 Gi0/0/1 Branch 2 Gi0/0/1 Inter-Branch Link (Default Cost: 1) Router Configuration Configure interfaces, assign IP addressing, adjust the OSPF cost on the HQ copper interface, and instantiate OSPFv2 across Area 0 with explicit router IDs.\nHQ Router (Primary Hub) enable configure terminal hostname HQ ! --- Configure Fiber Interface to Branch 2 --- interface GigabitEthernet0/0/2 description Fiber Link to Branch 2 ip address 10.1.1.1 255.255.255.252 no shutdown exit ! --- Configure Copper Interface to Branch 1 --- interface GigabitEthernet0/0/0 description Backup Copper Link to Branch 1 ip address 10.1.1.5 255.255.255.252 ip ospf cost 500 no shutdown exit ! --- Instantiate OSPFv2 --- router ospf 1 router-id 1.1.1.1 network 10.1.1.0 0.0.0.3 area 0 network 10.1.1.4 0.0.0.3 area 0 exit Branch 1 Router (Intermediate Node) enable configure terminal hostname Branch1 ! --- Configure Interface to HQ --- interface GigabitEthernet0/0/0 description Link to HQ ip address 10.1.1.6 255.255.255.252 no shutdown exit ! --- Configure Interface to Branch 2 --- interface GigabitEthernet0/0/1 description Link to Branch 2 ip address 10.1.1.9 255.255.255.252 no shutdown exit ! --- Instantiate OSPFv2 --- router ospf 1 router-id 2.2.2.2 network 10.1.1.4 0.0.0.3 area 0 network 10.1.1.8 0.0.0.3 area 0 exit Branch 2 Router (Destination Node) enable configure terminal hostname Branch2 ! --- Configure Interface to HQ --- interface GigabitEthernet0/0/2 description Fiber Link to HQ ip address 10.1.1.2 255.255.255.252 no shutdown exit ! --- Configure Interface to Branch 1 --- interface GigabitEthernet0/0/1 description Link to Branch 1 ip address 10.1.1.10 255.255.255.252 no shutdown exit ! --- Instantiate OSPFv2 --- router ospf 1 router-id 3.3.3.3 network 10.1.1.0 0.0.0.3 area 0 network 10.1.1.8 0.0.0.3 area 0 exit Verification Validate neighbor adjacencies, path cost calculations, actual packet paths, and failover behavior across the topology.\nVerify OSPF Neighbor Adjacencies:\nExecute show ip ospf neighbor on HQ to confirm neighborship:\nHQ# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 2.2.2.2 1 FULL/DR 00:00:36 10.1.1.6 GigabitEthernet0/0/0 3.3.3.3 1 FULL/DR 00:00:38 10.1.1.2 GigabitEthernet0/0/2 Result: Both neighbors show FULL state, confirming full Link State Database (LSDB) synchronization.\nInspect Routing Table for Path Preference:\nInspect HQ\u0026rsquo;s routing table to verify path cost calculation to Branch 2\u0026rsquo;s subnet (10.1.1.8/30):\nHQ# show ip route ospf 10.0.0.0/8 is variably subnetted, 5 subnets, 2 masks O 10.1.1.8 [110/2] via 10.1.1.2, 00:04:12, GigabitEthernet0/0/2 Result: OSPF prefers the direct fiber path (via 10.1.1.2) with a metric cost of 2, completely bypassing the direct copper link to Branch 1 which has a cost penalty of 500.\nVerify Data Plane Path via Traceroute:\nTrace the path from HQ to Branch 2\u0026rsquo;s interface (10.1.1.10):\nHQ# traceroute 10.1.1.10 Type escape sequence to abort. Tracing the route to 10.1.1.10 1 10.1.1.2 0 msec 0 msec 0 msec Result: Traffic reaches the destination in a single hop over the high-speed fiber link.\nVerify Convergence:\nSimulate a physical failure on the primary fiber link by shutting down Gi0/0/2 on HQ:\nHQ(config)# interface GigabitEthernet0/0/2 HQ(config-if)# shutdown After receiving the OSPF adjacency down log, re-examine the routing table:\nHQ# show ip route ospf 10.0.0.0/8 is variably subnetted, 3 subnets, 2 masks O 10.1.1.8 [110/501] via 10.1.1.6, 00:00:16, GigabitEthernet0/0/0 Result: OSPF immediately reconverges, routing traffic through the backup copper path (via 10.1.1.6) with a combined cost of 501. Issuing no shutdown on Gi0/0/2 automatically restores the primary fiber path.\n","permalink":"https://dennismwangi.com/ccna-labs/single-area-ospfv2-path-selection-cost-tuning/","summary":"\u003cp\u003eDynamic routing protocols like OSPF dynamically calculate the shortest path through a network using link metrics. By default, OSPF calculates interface cost based on reference bandwidth (100 Mbps / bandwidth). However, in modern networks with disparate WAN links (such as high-speed fiber vs. low-bandwidth backup copper), default calculations may not accurately reflect desired traffic paths.\u003c/p\u003e\n\u003cp\u003eTo enforce traffic engineering, network administrators manually tune OSPF interface costs to prefer primary fiber paths over backup links.\u003c/p\u003e","title":"CCNA Lab 4: Single-Area OSPFv2 - Path Selection and Interface Cost Tuning"},{"content":"In Part 3 of this series, we treated our physical network topology like software application code, using Containerlab to spin up our test sandbox in seconds.\nWith our nodes live, how do we actually generate and push configurations to them?\nIf you hardcode configuration blocks directly into your Ansible tasks, your playbooks quickly become unmanageable. The moment a VLAN ID changes, or you swap a router from a Nokia SR OS node to a Cisco instance, your entire automation framework collapses under its own weight.\nWe solve this by decoupling our data from our execution logic. We will break down how to map design variables into structured local files, build dynamic blueprints using Jinja2 templates, and format the final payload using model-driven YANG structures rather than screen-scraping text.\nSeparating Data from Execution Before diving into code, it helps to understand the architectural flow. Our pipeline separates responsibilities into three distinct layers:\nThe Intent (The Data): Structured variables defining what the network should look like (e.g., interface names, IP addresses, ASNs). This data can live locally in static host_vars files for quick prototyping, pull dynamically from NetBox via its API for a centralized source of truth, or exist as a hybrid where NetBox handles inventory data and local files manage specific service-level variables.\nThe Blueprint (The Logic): Modular templates (Jinja2) that handle loops, conditionals, and formatting syntax.\nThe Engine (The Transport): The automation framework (Ansible) whose only job is to pair the data with the blueprint and push the resulting payload to the node.\n1. Defining the Intent: Structuring host_vars Instead of writing vendor commands, we define our network state inside a structured YAML file. For our lab topology, we are configuring a VPLS service between PE1 and PE2.\nCreate a file named group_vars/all.yml:\nansible_user: admin ansible_password: NokiaSros1! ansible_connection: ansible.netcommon.netconf Create a file named host_vars/PE1.yml:\n--- # Service vpls_services: - id: 1 vc_id: 1 description: \u0026#34;VPLS_Instance_1_Mesh\u0026#34; sap: \u0026#34;1/1/c2/1:1\u0026#34; mesh_sdps: [12] Create a file named host_vars/PE2.yml:\n--- # Service vpls_services: - id: 1 vc_id: 1 description: \u0026#34;VPLS_Instance_1_Mesh\u0026#34; sap: \u0026#34;1/1/c2/1:1\u0026#34; mesh_sdps: [21] Notice that there is zero vendor syntax here. This file purely represents the metadata of the service we want to build.\n📌 A Quick Note on Service Provider Architecture: If you are new to Nokia service modeling, it helps to distinguish the two interface types we are using here:\nSAP (Service Access Point): This is the physical or logical port on the PE router that connects directly down to the Customer Edge (CE) device. It defines how the customer hands off traffic to our network.\nSDP (Service Distribution Point): This is the virtual transport tunnel running across the core network infrastructure that connects PE routers together, allowing the local service instances to communicate seamlessly over the provider backbone.\n2. Building the Blueprint: The Jinja2 Template Next, we build the template that will parse our variables. Because we want to move past CLI screen-scraping, we format our Jinja2 blueprint to output a structured XML data model compliant with the router\u0026rsquo;s native YANG schema.\nCreate a file named templates/vpls_deploy.j2:\n\u0026lt;config xmlns=\u0026#34;urn:ietf:params:xml:ns:netconf:base:1.0\u0026#34;\u0026gt; \u0026lt;configure xmlns=\u0026#34;urn:nokia.com:sros:ns:yang:sr:conf\u0026#34;\u0026gt; \u0026lt;service\u0026gt; {% for vpls in vpls_services %} \u0026lt;vpls\u0026gt; \u0026lt;service-id\u0026gt;{{ vpls.id }}\u0026lt;/service-id\u0026gt; \u0026lt;customer\u0026gt;1\u0026lt;/customer\u0026gt; \u0026lt;description\u0026gt;{{ vpls.description }}\u0026lt;/description\u0026gt; {% if vpls.sap is defined %} \u0026lt;sap\u0026gt; \u0026lt;sap-id\u0026gt;{{ vpls.sap }}\u0026lt;/sap-id\u0026gt; \u0026lt;admin-state\u0026gt;enable\u0026lt;/admin-state\u0026gt; \u0026lt;/sap\u0026gt; {% endif %} {% for sdp_id in vpls.mesh_sdps %} \u0026lt;!-- Core Transport Tunnel between PE Routers --\u0026gt; \u0026lt;mesh-sdp\u0026gt; \u0026lt;sdp-bind-id\u0026gt;{{ sdp_id }}:{{ vpls.vc_id }}\u0026lt;/sdp-bind-id\u0026gt; \u0026lt;admin-state\u0026gt;enable\u0026lt;/admin-state\u0026gt; \u0026lt;/mesh-sdp\u0026gt; {% endfor %} \u0026lt;admin-state\u0026gt;enable\u0026lt;/admin-state\u0026gt; \u0026lt;/vpls\u0026gt; {% endfor %} \u0026lt;/service\u0026gt; \u0026lt;/configure\u0026gt; \u0026lt;/config\u0026gt; Deconstructing the Template Logic: xmlns=\u0026quot;urn:nokia.com:sros:ns:yang:sr:conf\u0026quot;: This tag specifies the precise YANG model namespace we are targeting. Instead of raw text strings, the router processes this as a direct, structural database manipulation.\n{% for vpls in ... %}: A native Jinja2 loop. If you append five more services to your host_vars file later, this template dynamically loops over them and generates all five payloads without requiring you to touch the core blueprint again.\n3. Driving the Engine: The Ansible Playbook With our data isolated and our template ready, our Ansible playbook becomes beautifully lightweight. Its only responsibility is to read the template, inject the variables, and transmit the resulting XML payload via NETCONF.\nCreate a file named deploy_services.yml:\n--- - name: \u0026#34;Deploy Services\u0026#34; hosts: platforms_nokia_sros gather_facts: false tasks: - name: \u0026#34;Render and Pushing YANG/XML Configuration Template\u0026#34; ansible.netcommon.netconf_config: xml: \u0026#34;{{ lookup(\u0026#39;template\u0026#39;, \u0026#39;templates/vpls_deploy.j2\u0026#39;) }}\u0026#34; register: netconf_output - name: \u0026#34;Print Execution Output Confirmation\u0026#34; ansible.builtin.debug: var: netconf_output Why This Architecture Wins: Vendor-Agnostic Extensibility: If you add a Cisco IOS-XR node to this topology tomorrow, you do not modify deploy_services.yml. You simply write a Cisco-specific Jinja2 template and save it.\nImmutable Automation Logic: Your execution playbook stays locked down and version-controlled. Changes to production only happen inside data structures (host_vars) or templates.\nExecuting the Pipeline Ensure your Containerlab network from Part 3 is fully operational, then execute your deployment engine:\nansible-playbook -i netbox_inv.yml deploy_services.yml When Ansible executes, it securely establishes a NETCONF connection over SSH, bypasses the CLI parsing engines entirely, updates the configuration candidate database on the target nodes, and commits the execution transactional loop natively.\nConclusion \u0026amp; Next Steps By completely separating our data structures from our execution logic, we have transitioned our lab from a basic scripting workspace into an automation framework:\nVariables (host_vars) define the individual intent parameters.\nTemplates (Jinja2) map out the logic.\nNETCONF/YANG payloads process transactional configuration updates.\nWhat\u0026rsquo;s Next: Verification and State Validation Now that we can programmatically push model-driven configurations to our virtual network fabric on demand, we face our next challenge: How do we prove it actually works?\nIn Part 5, we will tackle the final deployment stage of our NetDevOps journey: validation. We will cover:\nUtilizing state verification outputs to validate end-to-end data plane connectivity.\nParsing operational states (show commands) directly into structured data for automated pipeline decision-making.\n","permalink":"https://dennismwangi.com/netdevops/jinja2-and-yang/","summary":"\u003cp\u003eIn Part 3 of this series, we treated our physical network topology like software application code, using Containerlab to spin up our test sandbox in seconds.\u003c/p\u003e\n\u003cp\u003eWith our nodes live, \u003cstrong\u003ehow do we actually generate and push configurations to them?\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIf you hardcode configuration blocks directly into your Ansible tasks, your playbooks quickly become unmanageable. The moment a VLAN ID changes, or you swap a router from a Nokia SR OS node to a Cisco instance, your entire automation framework collapses under its own weight.\u003c/p\u003e","title":"NetDevOps Pipeline Part 4: Decoupling Logic with Jinja2 and YANG"},{"content":"In Part 4 of this series, we decoupled our network intent from the execution logic, using Jinja2 templates and model-driven YANG schemas to push VPLS configurations to our Nokia SR OS nodes via NETCONF.\nBut seeing a yellow CHANGED status in your terminal is only half the battle. The ultimate question isn\u0026rsquo;t \u0026ldquo;Did the configuration push successfully?\u0026rdquo;, it is \u0026ldquo;Is the service actually operational in the data plane?\u0026rdquo;\nIn this fifth and final part of our series, we close the loop. We will look at how to treat network operational states as structured data, execute automated Pre-Checks vs. Post-Checks, and build an immutable validation gate using Ansible assertions to guarantee compliance across our Containerlab fabric.\nThe Philosophy of Automated Verification In this NetDevOps pipeline, we move from a model of reactive firefighting to proactive assertion.\nInstead of treating verification as a manual afterthought, we write explicit test assertions that treat our operational state like unit tests in software engineering.\nBy querying the operational state datastore (state branches in YANG models) instead of configuration datastore, the router returns data paths including packet counters, operational flags, physical link states, and so on.\n1. The Strategy: Pre-Checks vs. Post-Checks An automated validation playbook should run twice during an execution window:\nPre-Check: Executed immediately before the configuration change to ensure the node is healthy, the transport tunnels are up, and the service ID we want to allocate isn\u0026rsquo;t already taken by another customer. Post-Check: Executed immediately after the configuration change. It compares the live state against our engineering definitions to confirm that the service transitioned smoothly into an operational state. To fulfill both requirements elegantly without managing two completely separate scripts, we will build a single verification playbook that dynamically shifts its validation logic based on a runtime variable called validation_phase passed via CLI extra variables (--extra-vars).\n2. Parsing Live Operational State via NETCONF Because we are using model-driven architecture, we bypass human-readable CLI outputs entirely. We query the router using the ansible.netcommon.netconf_get module, pointing explicitly to the Nokia SR OS state datastore.\nCreate a file named verify_services.yml:\n--- - name: \u0026#34;VPLS Service State Validation\u0026#34; hosts: platforms_nokia_sros gather_facts: false tasks: - name: \u0026#34;Query Operational VPLS State Namespace via NETCONF\u0026#34; ansible.netcommon.netconf_get: display: xml filter: | \u0026lt;state xmlns=\u0026#34;urn:nokia.com:sros:ns:yang:sr:state\u0026#34;\u0026gt; \u0026lt;service\u0026gt; \u0026lt;vpls\u0026gt; \u0026lt;service-id\u0026gt;1\u0026lt;/service-id\u0026gt; \u0026lt;/vpls\u0026gt; \u0026lt;/service\u0026gt; \u0026lt;/state\u0026gt; register: vpls_live_state - name: \u0026#34;Debug Live State Return Structure\u0026#34; ansible.builtin.debug: var: vpls_live_state.output What happens here? When this task runs, the Nokia SR OS node doesn\u0026rsquo;t spit out unparsed text. It returns an exact XML structure detailing every component of VPLS Service 1, mapping directly into our register variable vpls_live_state.\n3. Building the Validation Gate: Ansible Assertions With our operational data captured, we pass it into the ansible.builtin.assert module. This module evaluates boolean expressions. By introducing our validation_phase variable alongside logical or statements, we can toggle our validation gates seamlessly based on whether the pipeline is in the pre-change or post-change phase.\nLet\u0026rsquo;s expand verify_services.yml to include a task for the conditional pass/fail thresholds:\n- name: \u0026#34;Assert Service Operational Compliance\u0026#34; ansible.builtin.assert: that: # POST-CHECK CONDITIONS: Evaluated only when validation_phase is \u0026#39;post\u0026#39; - \u0026#34;validation_phase == \u0026#39;pre\u0026#39; or vpls_live_state.output.state.service.vpls[\u0026#39;admin-state\u0026#39;] == \u0026#39;enable\u0026#39;\u0026#34; - \u0026#34;validation_phase == \u0026#39;pre\u0026#39; or vpls_live_state.output.state.service.vpls[\u0026#39;oper-state\u0026#39;] == \u0026#39;up\u0026#39;\u0026#34; # PRE-CHECK CONDITION: Evaluated only when validation_phase is \u0026#39;pre\u0026#39; - \u0026#34;validation_phase == \u0026#39;post\u0026#39; or vpls_live_state.output.state.service.vpls is not defined\u0026#34; fail_msg: \u0026#34;CRITICAL ALERT: Operational validation failed during {{ validation_phase }} check!\u0026#34; success_msg: \u0026#34;SUCCESS: Fabric passed {{ validation_phase }} check requirements.\u0026#34; Deconstructing the Assertions: The validation_phase == 'pre' or ... Logic: In boolean operations, an or statement stops evaluating as soon as it encounters a true value. During a Pre-Check, the first statement evaluates to True, meaning Ansible completely skips looking at the admin-state or oper-state (which wouldn\u0026rsquo;t exist yet, avoiding a playbook crash). During a Post-Check, the first block is False, forcing Ansible to verify the live states are enable and up.\nThe Intent Leak Check (is not defined): During our Pre-Check, we want to ensure we aren\u0026rsquo;t accidentally overwriting an active deployment. If VPLS 1 is completely unconfigured, vpls is not defined evaluates to True and the check passes. If the service already exists, it evaluates to False and safely halts the pipeline before a single line of configuration is changed.\nExecuting the Verification Engine By passing the validation_phase parameter explicitly via runtime extra variables (-e), we can drive our entire pipeline cycle cleanly.\nPhase 1: Running the Pre-Check Gate Run the verification test runner before executing your configuration playbook to establish your safe baseline:\nansible-playbook -i netbox_inv.yml verify_services.yml -e \u0026#34;validation_phase=pre\u0026#34; If VPLS Service 1 is completely clear, the assertions pass smoothly, indicating the fabric is completely ready for deployment.\nPhase 2: Running the Post-Check Gate After running your configuration deployment playbook from Part 4, execute the exact same validation playbook, updating the runtime flag to verify the data plane:\nansible-playbook -i netbox_inv.yml verify_services.yml -e \u0026#34;validation_phase=post\u0026#34; Expected Output Log: PLAY [VPLS Service State Validation] *************************************************************** TASK [Query Operational VPLS State Namespace via NETCONF] ****************************************** ok: [PE1] ok: [PE2] TASK [Assert Service Operational Compliance] ******************************************************* ok: [PE1] =\u0026gt; { \u0026#34;changed\u0026#34;: false, \u0026#34;msg\u0026#34;: \u0026#34;SUCCESS: Fabric passed post check requirements.\u0026#34; } ok: [PE2] =\u0026gt; { \u0026#34;changed\u0026#34;: false, \u0026#34;msg\u0026#34;: \u0026#34;SUCCESS: Fabric passed post check requirements.\u0026#34; } PLAY RECAP ***************************************************************************************** PE1 : ok=2 changed=0 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 PE2 : ok=2 changed=0 unreachable=0 failed=0 skipped=0 rescued=0 ignored=0 Because our post-conditions passed perfectly, the pipeline exits cleanly with zero failures. We have successfully verified our network state across both phases using structured telemetry loops.\nReflecting on the Complete NetDevOps Pipeline Over this 5-part journey, we have focused on building a solid foundation for network automation, mapping out a clean and functional pipeline using a local lab environment:\nPart 1 (NetBox Source of Truth): We moved out of static spreadsheets and defined our intended network state inside a structured data model.\nPart 2 (Dynamic Ansible Handshake): We transitioned away from static host inventories, leveraging API integration to discover our lab layout dynamically.\nPart 3 (Topology Orchestration with Containerlab): We treated our testing infrastructure like code, spinning up lightweight virtual networks instantly from declarative files.\nPart 4 (Decoupling Logic with Jinja2/YANG): We separated our actual service variables from the deployment logic, pushing model-driven XML payloads over NETCONF.\nPart 5 (State Validation): We established basic validation gates, showing how to check the actual state of the network before and after a change.\nThis cohesive loop represents a practical shift from manual, command-by-command administration toward systematic, repeatable automation patterns.\nAlternative/Next-Step Validation Tooling As your automation framework grows, you can extend this native Ansible/NETCONF model to incorporate deeper specialized systems:\npyATS / Genie Framework: A dedicated Python testing testbed ecosystem excellent for state profiling and generating strict network configuration \u0026ldquo;diffs\u0026rdquo; before and after changes.\ngNMI / Streaming Telemetry: Swapping query-based polling loops (netconf_get) for real-time, event-driven protobuf push notifications to monitor performance states dynamically.\nThank you for following along with this building journey! Keep automating!!\n","permalink":"https://dennismwangi.com/netdevops/state-validation/","summary":"\u003cp\u003eIn Part 4 of this series, we decoupled our network intent from the execution logic, using Jinja2 templates and model-driven YANG schemas to push  VPLS configurations to our Nokia SR OS nodes via NETCONF.\u003c/p\u003e\n\u003cp\u003eBut seeing a yellow \u003ccode\u003eCHANGED\u003c/code\u003e status in your terminal is only half the battle. The ultimate question isn\u0026rsquo;t \u003cem\u003e\u0026ldquo;Did the configuration push successfully?\u0026rdquo;\u003c/em\u003e, it is \u003cstrong\u003e\u0026ldquo;Is the service actually operational in the data plane?\u0026rdquo;\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIn this fifth and final part of our series, we close the loop. We will look at how to treat network operational states as structured data, execute automated \u003cstrong\u003ePre-Checks vs. Post-Checks\u003c/strong\u003e, and build an immutable validation gate using Ansible assertions to guarantee compliance across our Containerlab fabric.\u003c/p\u003e","title":"NetDevOps Pipeline Part 5: Automated Verification and State Validation"}]