Segment Routing v6 Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

Segment Routing v6 Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

Key concepts of SRv6 IS-IS TI-LFA

Want to summarize with AI?

Log in

Explains how SRv6 IS-IS TI-LFA provides rapid, topology-independent protection against link and node failures in an IS-IS segment routing network.


Topology-Independent Loop-Free Alternate (TI-LFA) provides link protection in topologies where other fast reroute techniques cannot provide protection. The goal of TI-LFA is to reduce the packet loss that results while routers converge after a topology change due to a link failure. TI-LFA leverages the post-convergence path which is planned to carry the traffic and ensures link and node protection with in 50 milliseconds. TI-LFA with IS-IS SR-MPLS is already supported.

TI-LFA provides link, node, and Shared Risk Link Groups (SRLG) protection in any topology. For more information, see Configure Topology-Independent Loop-Free Alternate (TI-LFA).


SRv6 IS-IS TI-LFA guidelines and limitations

The following usage guidelines and limitations apply:

  • TI-LFA provides link protection by default. Additional tiebreaker configuration is required to enable node or SRLG protection.

  • Usage guidelines for node and SRLG protection:

    • TI-LFA node protection functionality provides protection from node failures. The neighbor node is excluded during the post convergence backup path calculation.

    • Shared Risk Link Groups (SRLG) refer to situations in which links in a network share a common fiber (or a common physical attribute). These links have a shared risk: when one link fails, other links in the group might also fail. TI-LFA SRLG protection attempts to find the post-convergence backup path that excludes the SRLG of the protected link. All local links that share any SRLG with the protecting link are excluded.

    • When you enable link protection, you can also enable node protection, SRLG protection, or both, and specify a tiebreaker priority in case there are multiple LFAs.

    • Valid priority values are from 1 to 255. The lower the priority value, the higher the priority of the rule. Link protection always has a lower priority than node or SRLG protection.

    • Cisco 8000 Series Routers support the insertion of up to two SIDs. If the computed backup path requires more than two SIDs, the backup path will not be installed in the RIB and the path will not be protected.


Configure SRv6 IS-IS TI-LFA

Set up SRv6 IS-IS TI-LFA to provide fast network reroute protection for IPv6 traffic.

SRv6 IS-IS TI-LFA uses fast reroute mechanisms to provide immediate backup paths, minimizing service interruption during link or node failures.

Follow these steps to configure SRv6 IS-IS TI-LFA:

Procedure

  1. Configure SRv6 under IS-IS and enable TI-LFA on the protected interfaces.

    Example:

    Router(config)# router isis core
    Router(config-isis)# address-family ipv6 unicast
    Router(config-isis-af)# segment-routing srv6
    Router(config-isis-srv6)# locator locator1
    Router(config-isis-srv6-loc)# exit
    Router(config-isis)# interface loopback 0
    Router(config-isis-if)# passive
    Router(config-isis-if)# address-family ipv6 unicast
    Router(config-isis-if-af)# exit
    Router(config-isis)# interface bundle-ether 1201
    Router(config-isis-if)# address-family ipv6 unicast
    Router(config-isis-if-af)# fast-reroute per-prefix
    Router(config-isis-if-af)# fast-reroute per-prefix ti-lfa
    Router(config-isis-if-af)# exit
    Router(config-isis)# interface bundle-ether 1301
    Router(config-isis-if)# address-family ipv6 unicast
    Router(config-isis-if-af)# fast-reroute per-prefix
    Router(config-isis-if-af)# fast-reroute per-prefix ti-lfa
    Router(config-isis-if-af)# fast-reroute per-prefix tiebreaker node-protecting index 100
    Router(config-isis-if-af)# fast-reroute per-prefix tiebreaker srlg-disjoint index 200
    Router(config-isis-if-af)# exit
  2. Verify the SRv6 IS-IS TI-LFA configuration using the show isis ipv6 fast-reroute ipv6-prefix detail command.

    Router# show isis ipv6 fast-reroute cafe:0:0:66::/64 detail 
    Thu Nov 22 16:12:51.983 EST
    
    L1 cafe:0:0:66::/64 [11/115] low priority
         via fe80::2, TenGigE0/0/0/6, SRv6-HUB6, Weight: 0
           Backup path: TI-LFA (link), via fe80::1, Bundle-Ether1201 SRv6-LF1, Weight: 0, Metric: 51
             P node: SRv6-TP8.00 [8::8], SRv6 SID: cafe:0:0:88:1:: End (PSP)
             Backup-src: SRv6-HUB6.00
           P: No, TM: 51, LC: No, NP: No, D: No, SRLG: Yes
         src SRv6-HUB6.00-00, 6::6
  3. Verify the SRv6 IS-IS TI-LFA configuration using the show route ipv6 ipv6-prefix detail command.

    Router# show route ipv6 cafe:0:0:66::/64 detail  
    Thu Nov 22 16:14:07.385 EST
    
    Routing entry for cafe:0:0:66::/64
      Known via "isis srv6", distance 115, metric 11, type level-1
      Installed Nov 22 09:24:05.160 for 06:50:02
      Routing Descriptor Blocks
        fe80::2, from 6::6, via TenGigE0/0/0/6, Protected
          Route metric is 11
          Label: None
          Tunnel ID: None
          Binding Label: None
          Extended communities count: 0
          Path id:1       Path ref count:0
          NHID:0x2000a(Ref:11)
          NHID eid:0xffffffffffffffff
          Backup path id:65
        fe80::1, from 6::6, via Bundle-Ether1201, Backup (TI-LFA)
          Repair Node(s): 8::8
          Route metric is 51
          Label: None
          Tunnel ID: None
          Binding Label: None
          Extended communities count: 0
          Path id:65              Path ref count:1
          NHID:0x2000d(Ref:11)
          NHID eid:0xffffffffffffffff
          SRv6 Headend: H.Encaps.Red 
          SRv6 SID-list { cafe:0:0:88:1:: }
          MPLS eid:0x1380800000001
  4. Verify the SRv6 IS-IS TI-LFA configuration using the show cef ipv6 ipv6-prefix detail location location command.

    Router# show cef  ipv6 cafe:0:0:66::/64 detail location 0/0/cpu0 
    Thu Nov 22 17:01:58.536 EST
    cafe:0:0:66::/64, version 1356, SRv6 Transit, internal 0x1000001 0x2 (ptr 0x8a4a45cc) [1], 0x0 (0x8a46ae20), 0x0 (0x8c8f31b0)
     Updated Nov 22 09:24:05.166 
     local adjacency fe80::2
     Prefix Len 64, traffic index 0, precedence n/a, priority 2
      gateway array (0x8a2dfaf0) reference count 4, flags 0x500000, source rib (7), 0 backups
                    [5 type 3 flags 0x8401 (0x8a395d58) ext 0x0 (0x0)]
      LW-LDI[type=3, refc=1, ptr=0x8a46ae20, sh-ldi=0x8a395d58]
      gateway array update type-time 1 Nov 22 09:24:05.163
     LDI Update time Nov 22 09:24:05.163
     LW-LDI-TS Nov 22 09:24:05.166
       via fe80::2/128, TenGigE0/0/0/6, 8 dependencies, weight 0, class 0, protected [flags 0x400]
        path-idx 0 bkup-idx 1 NHID 0x2000a [0x8a2c2fd0 0x0]
        next hop fe80::2/128
       via fe80::1/128, Bundle-Ether1201, 8 dependencies, weight 0, class 0, backup (TI-LFA) [flags 0xb00]
        path-idx 1 NHID 0x2000d [0x8c2670b0 0x0]
        next hop fe80::1/128, Repair Node(s): 8::8
        local adjacency
         SRv6 H.Encaps.Red SID-list {cafe:0:0:88:1::}
    
    
        Load distribution: 0 (refcount 5)
    
        Hash  OK  Interface                 Address
        0     Y   TenGigE0/0/0/6            fe80::2 
  5. Verify the SRv6 IS-IS TI-LFA configuration using the show cef ipv6 fast-reroute-db command.

    Example:

    Router# show cef ipv6 fast-reroute-db 
    Sun Dec  9 20:23:08.111 EST
    
     PROTECT-FRR: per-prefix [1, 0x0, 0x0, 0x98c83270]
     protect-interface: Te0/0/0/6 (0x208) 
     protect-next-hop:  fe80::2/128
     ipv6 nhinfo [0x977397d0]
     Update Time Dec  9 17:29:42.427
    
         BACKUP-FRR: per-prefix [5, 0x0, 0x2, 0x98c83350]
         backup-interface: BE1201 (0x800002c) 
         backup-next-hop:  fe80::1/128
         ipv6 nhinfo [0x977396a0 protect-frr: 0x98c83270]
     Update Time Dec  9 17:29:42.428
    
     PROTECT-FRR: per-prefix [1, 0x0, 0x0, 0x98c830b0]
     protect-interface: BE1201 (0x800002c) 
     protect-next-hop:  fe80::1/128
     ipv6 nhinfo [0x977396a0]
     Update Time Dec  9 17:29:42.429
    
         BACKUP-FRR: per-prefix [5, 0x0, 0x1, 0x98c83190]
         backup-interface: Te0/0/0/6 (0x208) 
         backup-next-hop:  fe80::2/128
         ipv6 nhinfo [0x977397d0 protect-frr: 0x98c830b0]
     Update Time Dec  9 17:29:42.429

SRv6 IS-IS TI-LFA is configured and operational. The system now provides fast reroute protection for IPv6 prefixes, as confirmed by the verification commands.