在家也要玩BGP(1.5):我的双线分流规则

本系列文章的第一篇只讲了配置的技术要点,没有讲规则具体怎么写。本文大概讲一下我现在所使用的规则。

规则:

  • 电信自己的ASN走电信
  • 移动自己的ASN走移动
  • 其它国内流量走电信
  • 出国(默认)流量走移动

目前这样的规则会带来一万五千条左右路由。IOS XE的资源占用情况:

Router#show ip route summary
Route Source    Networks    Subnets     Replicates  Overhead    Memory (bytes)
connected       0           14          0           1424        4256
static          1           4           0           480         1520
bgp 65534       5179        15044       0           1941408     6147792
  External: 0 Internal: 20223 Local: 0
Router#show ip bgp summ
BGP router identifier 192.168.1.1, local AS number 65001
BGP table version is 10538219, main routing table version 10538219
13183 network entries using 3269384 bytes of memory
18727 path entries using 2546872 bytes of memory
525/281 BGP path/bestpath attribute entries using 147000 bytes of memory
2 BGP rrinfo entries using 80 bytes of memory
375 BGP AS-PATH entries using 25840 bytes of memory
2 BGP community entries using 48 bytes of memory
1 BGP extended community entries using 24 bytes of memory
517 BGP route-map cache entries using 33088 bytes of memory
0 BGP filter-list cache entries using 0 bytes of memory
BGP using 6022336 total bytes of memory
BGP activity 804938/764611 prefixes, 13180009/13137706 paths, scan interval 60 secs

Router#show platform resources
**State Acronym: H - Healthy, W - Warning, C - Critical
Resource                 Usage                 Max             Warning         Critical        State
----------------------------------------------------------------------------------------------------
RP0 (ok, active)                                                                               H
 Control Processor       28.74%                100%            80%             90%             H
  DRAM                   2687MB(78%)           3421MB          88%             93%             H
ESP0(ok, active)                                                                               H
 QFP                                                                                           H
  DRAM                   101005KB(51%)         196608KB        80%             90%             H
  IRAM                   414KB(20%)            2048KB          80%             90%             H
  CPU Utilization        12.00%                100%            90%             95%             H


BGP Controller的资源占用情况:

[email protected]:~# free -wh
              total        used        free      shared     buffers       cache   available
Mem:          878Mi       682Mi        61Mi       1.0Mi        10Mi       123Mi        60Mi
Swap:         1.0Gi       3.0Mi       1.0Gi

继续阅读

在家也要玩BGP(1):简单的多运营商接入策略路由配置

拉了两条不同运营商的宽带,想要有效利用两条线路的带宽,但是这时候单纯的负载均衡体验并不好,因为随机分配的出口并不一定速度最快。BGP全球路由表里正好有我们需要的信息——每个IP到哪个运营商距离最近(某种意义来说,速度也应当最快)。那么怎么利用它来优化网络的体验呢?

继续阅读

Windows MDM未知错误0x80192efe的解决方案

症状:

设备无法自动enroll MDM,事件管理器里面(Applications and Services Logs -> Microsoft -> Windows -> DeviceManagement-Enterprise-Diagnostics-Provider -> Admin)有如下报错:

MDM Enroll: Failed (Unknown Win32 Error code: 0x80192efe)

解决方法:

首先去Azure AD和Intune删掉这台设备(能看到的都删掉)。

然后让Azure AD Sync重新同步一次:在安装有Azure AD Sync的服务器上执行

PS C:\Windows\system32> Import-Module ADSync
PS C:\Windows\system32> Start-ADSyncSyncCycle -PolicyType Initial

等这台机子被重新同步到Azure AD以后,强制重新enroll MDM:在目标设备上执行

gpupdate /force