SV-217064r639663_rule
V-217064
SRG-NET-000512-RTR-000003
JUNI-RT-000580
CAT III
10
Configure the MPLS router to synchronize IGP and LDP, minimizing packet loss when an IGP adjacency is established prior to LDP peers completing label exchange.
[edit protocols ospf area 0.0.0.0]
set interface ge-0/0/0.0 ldp-synchronization hold-time 10
[edit protocols isis]
set interface ge-0/0/0.0 ldp-synchronization hold-time 10
Note: The hold-time is the amount of time (in seconds) the routing device advertises the maximum cost metric for a link that is not fully operational. Default is infinity.
Review the router OSPF or IS-IS configuration and verify that LDP will synchronize with the link-state routing protocol as shown in the example below.
OSPF Example:
protocols {
mpls {
interface ge-0/0/0.0;
}
…
…
…
ospf {
export REDISTRIBUTE;
area 0.0.0.0 {
interface ge-0/0/0.0 {
ldp-synchronization {
hold-time 10;
}
…
…
…
}
}
ldp {
interface ge-0/0/0.0;
}
}
IS-IS Example:
protocols {
mpls {
interface ge-0/0/0.0;
}
…
…
…
isis {
level 1 authentication-key-chain ISIS_KEY;
level 2 authentication-key-chain ISIS_KEY;
interface ge-0/0/0.0 {
ldp-synchronization {
hold-time 10;
}
…
…
…
}
}
ldp {
interface ge-0/0/0.0;
}
}
If the router is not configured to synchronize IGP and LDP, this is a finding.
V-217064
False
JUNI-RT-000580
Review the router OSPF or IS-IS configuration and verify that LDP will synchronize with the link-state routing protocol as shown in the example below.
OSPF Example:
protocols {
mpls {
interface ge-0/0/0.0;
}
…
…
…
ospf {
export REDISTRIBUTE;
area 0.0.0.0 {
interface ge-0/0/0.0 {
ldp-synchronization {
hold-time 10;
}
…
…
…
}
}
ldp {
interface ge-0/0/0.0;
}
}
IS-IS Example:
protocols {
mpls {
interface ge-0/0/0.0;
}
…
…
…
isis {
level 1 authentication-key-chain ISIS_KEY;
level 2 authentication-key-chain ISIS_KEY;
interface ge-0/0/0.0 {
ldp-synchronization {
hold-time 10;
}
…
…
…
}
}
ldp {
interface ge-0/0/0.0;
}
}
If the router is not configured to synchronize IGP and LDP, this is a finding.
M
4032