<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>irwan piesessa</title>
	<atom:link href="http://irwanp.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://irwanp.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Sat, 21 Feb 2009 10:53:50 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='irwanp.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/32da120cda637a446bf9f2ddcee52948?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>irwan piesessa</title>
		<link>http://irwanp.wordpress.com</link>
	</image>
			<item>
		<title>Securing MP-EBGP VPNv4 for Inter-AS MPLS VPN</title>
		<link>http://irwanp.wordpress.com/2009/02/21/securing-mp-ebgp-vpnv4-for-inter-as-mpls-vpn/</link>
		<comments>http://irwanp.wordpress.com/2009/02/21/securing-mp-ebgp-vpnv4-for-inter-as-mpls-vpn/#comments</comments>
		<pubDate>Sat, 21 Feb 2009 10:46:49 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[aaa]]></category>
		<category><![CDATA[access-list]]></category>
		<category><![CDATA[acl]]></category>
		<category><![CDATA[address-family]]></category>
		<category><![CDATA[asbr]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[BGP]]></category>
		<category><![CDATA[copp]]></category>
		<category><![CDATA[extcommunity-list]]></category>
		<category><![CDATA[inter-as]]></category>
		<category><![CDATA[interas]]></category>
		<category><![CDATA[ip]]></category>
		<category><![CDATA[ipv4]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[log]]></category>
		<category><![CDATA[maximum-prefix]]></category>
		<category><![CDATA[md5]]></category>
		<category><![CDATA[mpls]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[ntp]]></category>
		<category><![CDATA[pe]]></category>
		<category><![CDATA[rd]]></category>
		<category><![CDATA[route-map]]></category>
		<category><![CDATA[route-target]]></category>
		<category><![CDATA[rt]]></category>
		<category><![CDATA[secure]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[snmp]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[tcp]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vpnv4]]></category>
		<category><![CDATA[vrf]]></category>
		<category><![CDATA[vty]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=87</guid>
		<description><![CDATA[1.  Securing Inter-AS interfaces

Permit only BGP traffic because the other traffic that traverse between ASBRs is IP Labelled traffic.
Apply inbound and outbound. Logging the denied traffic for further investigation

interface FastEthernet0/0
ip address 172.16.0.2 255.255.255.252
ip access-group ASBR-IN in
ip access-group ASBR-OUT out
!
ip access-list extended ASBR-IN
permit tcp any any eq bgp
permit tcp any eq bgp any
deny ip any [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=87&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2009/02/21/securing-mp-ebgp-vpnv4-for-inter-as-mpls-vpn/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2009/02/interas-mpls-ethereal.jpg" medium="image">
			<media:title type="html">interas-mpls-ethereal</media:title>
		</media:content>
	</item>
		<item>
		<title>Inter-AS MPLS VPN using MP-EBGP VPNv4</title>
		<link>http://irwanp.wordpress.com/2009/02/16/inter-as-mpls-vpn-using-mp-ebgp-vpnv4/</link>
		<comments>http://irwanp.wordpress.com/2009/02/16/inter-as-mpls-vpn-using-mp-ebgp-vpnv4/#comments</comments>
		<pubDate>Mon, 16 Feb 2009 04:33:43 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[BGP]]></category>
		<category><![CDATA[ebgp]]></category>
		<category><![CDATA[inter-as]]></category>
		<category><![CDATA[interas]]></category>
		<category><![CDATA[mp-ebgp]]></category>
		<category><![CDATA[mpls]]></category>
		<category><![CDATA[mpls vpn]]></category>
		<category><![CDATA[rd]]></category>
		<category><![CDATA[route-target]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vpnv4]]></category>
		<category><![CDATA[vrf]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=82</guid>
		<description><![CDATA[There are a requirement from one company, who want to connect their sites that connected to the different ISP MPLS VPN. To fulfill the requirement, the two ISPs need to interconnect their MPLS Autonomous Systems. For this purpose, we  can use a few method below:

Back to back VRF
VPNv4 MP-EBGP
VPNv4 MP-EBGP between RR

The easy method [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=82&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2009/02/16/inter-as-mpls-vpn-using-mp-ebgp-vpnv4/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2009/02/interas-mpls.jpg" medium="image">
			<media:title type="html">interas-mpls</media:title>
		</media:content>
	</item>
		<item>
		<title>Multiple VRF on One Customer Site</title>
		<link>http://irwanp.wordpress.com/2009/02/10/multiple-vrf-on-one-customer-site/</link>
		<comments>http://irwanp.wordpress.com/2009/02/10/multiple-vrf-on-one-customer-site/#comments</comments>
		<pubDate>Tue, 10 Feb 2009 07:46:57 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[mpls]]></category>
		<category><![CDATA[multiple-vrf]]></category>
		<category><![CDATA[tunnel]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vrf]]></category>
		<category><![CDATA[vrf-lite]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=78</guid>
		<description><![CDATA[In MPLS VPN implementation, every interface have just one VRF.  Maybe for some reason, our customer named XYZ, need to have more than one VPN for their networks. For example they want to separate the Accounting and Manufacture Department networks in the different VPN.
To accomplish this requirement, we can apply a few solutions below:

Using [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=78&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2009/02/10/multiple-vrf-on-one-customer-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2009/02/multiple-vrf.jpg" medium="image">
			<media:title type="html">multiple-vrf</media:title>
		</media:content>
	</item>
		<item>
		<title>Securing MPLS LDP</title>
		<link>http://irwanp.wordpress.com/2008/11/25/securing-mpls-ldp/</link>
		<comments>http://irwanp.wordpress.com/2008/11/25/securing-mpls-ldp/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 05:47:02 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[LDP]]></category>
		<category><![CDATA[mpls]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=70</guid>
		<description><![CDATA[To secure LDP communication between LSRs peer (PE to P), we can use MD5 authentication. Below is the simple configuration for MPLS LDP authentication:
Router(config)#mpls ldp neighbor direct_peer_ip password p@55w0rd
Verification:
 Router#sh mpls ldp nei peer_ip_address detail
 Peer LDP Ident: peer_ip_address:0; Local LDP Ident local_ip_address:0
 TCP connection: peer_ip_address.12780 - local_ip_address.646; MD5 on
 Password: not required, neighbor, in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=70&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2008/11/25/securing-mpls-ldp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2008/11/ldp-md51.jpg" medium="image">
			<media:title type="html">ldp-md51</media:title>
		</media:content>
	</item>
		<item>
		<title>AToM Tunnel Selection Using MPLS Traffic-Engineering</title>
		<link>http://irwanp.wordpress.com/2008/07/28/atom-tunnel-selection-using-mpls-traffic-engineering/</link>
		<comments>http://irwanp.wordpress.com/2008/07/28/atom-tunnel-selection-using-mpls-traffic-engineering/#comments</comments>
		<pubDate>Mon, 28 Jul 2008 02:05:37 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[atom]]></category>
		<category><![CDATA[eompls]]></category>
		<category><![CDATA[mpls]]></category>
		<category><![CDATA[TE]]></category>
		<category><![CDATA[Traffic-Engineering]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=61</guid>
		<description><![CDATA[By default, AToM will use IGP to select what path that will used to send the pseudowire packets. In this scenario we will use MPLS Traffic-Engineering to select the pseudowire path.
Below is the diagram for our scenario:

We will build an AToM VC (Virtual Circuit) for CE-1 and CE-2 Ethernet connection. The VC will use Pseudowire [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=61&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2008/07/28/atom-tunnel-selection-using-mpls-traffic-engineering/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2008/07/te11.jpg" medium="image" />
	</item>
		<item>
		<title>Revealing AToM (Any Transport over MPLS) Packets</title>
		<link>http://irwanp.wordpress.com/2008/07/19/revealing-atom-any-transport-over-mpls-packets/</link>
		<comments>http://irwanp.wordpress.com/2008/07/19/revealing-atom-any-transport-over-mpls-packets/#comments</comments>
		<pubDate>Sat, 19 Jul 2008 00:39:10 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[atom]]></category>
		<category><![CDATA[eompls]]></category>
		<category><![CDATA[mpls]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=50</guid>
		<description><![CDATA[AToM is used to transport any layer 2 packet via MPLS cloud. This MPLS application is used two MPLS Label, one for tunnel label (per hop LSR label) and one for VC (virtual circuit) label.
You can learn AToM more in the CiscoPress books from Wei Luo (CCIE #13291), Carlos Pignataro (CCIE #4619), Dmitry Bokotey (CCIE [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=50&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2008/07/19/revealing-atom-any-transport-over-mpls-packets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2008/07/atom11.jpg?w=300" medium="image" />

		<media:content url="http://irwanp.files.wordpress.com/2008/07/atom21.jpg" medium="image" />

		<media:content url="http://irwanp.files.wordpress.com/2008/07/atom3.jpg" medium="image" />
	</item>
		<item>
		<title>The Largest Star Known&#8230;</title>
		<link>http://irwanp.wordpress.com/2008/07/15/the-largest-star-known/</link>
		<comments>http://irwanp.wordpress.com/2008/07/15/the-largest-star-known/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 15:10:36 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Canis Majoris]]></category>
		<category><![CDATA[earth]]></category>
		<category><![CDATA[star]]></category>
		<category><![CDATA[sun]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=42</guid>
		<description><![CDATA[VY Canis Majoris is the largest star known by human. It is located approximately 5000 million light years in the constellation Canis Major. As we know, light can traverse distance 300.000 km in one second. So, 5000 light years is 5000 x 60 x 60 x 24 x 365 = 157.680.000.000 km from our earth.
According [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=42&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2008/07/15/the-largest-star-known/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2008/07/canis.jpg?w=300" medium="image" />
	</item>
		<item>
		<title>Connecting Customer Trunk with QinQ</title>
		<link>http://irwanp.wordpress.com/2008/07/14/connecting-trunk-with-qinq/</link>
		<comments>http://irwanp.wordpress.com/2008/07/14/connecting-trunk-with-qinq/#comments</comments>
		<pubDate>Mon, 14 Jul 2008 06:24:37 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[cdp]]></category>
		<category><![CDATA[QinQ]]></category>
		<category><![CDATA[Tunneling]]></category>
		<category><![CDATA[vtp]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=30</guid>
		<description><![CDATA[So, straight to the point, below is the diagram:

Sw-PE-1 and Sw-PE-2 is the Service Provider edge Switches. Sw-CE-1 and Sw-CE2 is the customer switches that have dot1q trunk connection . R1, R2, R5 and R6 is the customer routers.
R1 and R2 are in the VLAN 100 segment and have IP Network 100.100.1.0/24. R5 and R6 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=30&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2008/07/14/connecting-trunk-with-qinq/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2008/07/1qinq2.jpg?w=279" medium="image" />
	</item>
		<item>
		<title>QinQ: 802.1q Tunneling on Cisco Switches</title>
		<link>http://irwanp.wordpress.com/2008/06/23/qinq-8021q-tunneling-on-cisco-switches/</link>
		<comments>http://irwanp.wordpress.com/2008/06/23/qinq-8021q-tunneling-on-cisco-switches/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 08:06:44 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[802.1q]]></category>
		<category><![CDATA[QinQ]]></category>
		<category><![CDATA[Tunneling]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=25</guid>
		<description><![CDATA[One of Metro Ethernet solution to extend Layer 2 Ethernet Connection between two customer sites is use 802.1q Tunneling, also known as QinQ.
QinQ concept is explained based on the diagram below:


Customer Switch Site A and B connected to SP (Service Provider) Edge Switch, usually use trunk mode on the port that facing to SP. SP [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=25&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2008/06/23/qinq-8021q-tunneling-on-cisco-switches/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2008/06/qinq11.jpg" medium="image" />

		<media:content url="http://irwanp.files.wordpress.com/2008/06/qinq2.jpg" medium="image" />
	</item>
		<item>
		<title>BGP Confederation</title>
		<link>http://irwanp.wordpress.com/2008/06/14/bgp-confederation/</link>
		<comments>http://irwanp.wordpress.com/2008/06/14/bgp-confederation/#comments</comments>
		<pubDate>Sat, 14 Jun 2008 14:37:20 +0000</pubDate>
		<dc:creator>irwanp</dc:creator>
				<category><![CDATA[Service Provider]]></category>
		<category><![CDATA[BGP]]></category>
		<category><![CDATA[Confederation]]></category>

		<guid isPermaLink="false">http://irwanp.wordpress.com/?p=21</guid>
		<description><![CDATA[My friend who now work in Dar-es-Salaam, Tanzania, asked me about BGP Confederation. He asked me why we don&#8217;t use BGP Confederation on our IP Networks nationwide, so our country just use one AS Number, and every ISP use Private AS Number.
But the answer is, no we can&#8217;t. Because the purpose of using BGP as [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=irwanp.wordpress.com&blog=3910265&post=21&subd=irwanp&ref=&feed=1" />]]></description>
		<wfw:commentRss>http://irwanp.wordpress.com/2008/06/14/bgp-confederation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/62f88b8a3660b7ee07899307adbb4a9b?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">irwanp</media:title>
		</media:content>

		<media:content url="http://irwanp.files.wordpress.com/2008/06/confed1.jpg?w=288" medium="image" />
	</item>
	</channel>
</rss>