ISP Backbone & Multi-Tenant Data Center Architecture
Simulasi Arsitektur ISP Backbone MPLS/BGP, Spine-Leaf VXLAN, VRF Multi-Tenant & IPsec Security.
Expert / Specialist
240 Menit
Total 32 Devices
Skor Rubrik Modul
0 / 100
Topologi Interaktif (Klik Perangkat untuk Konfigurasi Modul)
Jadwal 240 Menit
Reset Lab
ISP Core Backbone (MPLS + OSPF Area 0 + BGP)
Enterprise HQ
Data Center (Spine-Leaf & Tenants)
Cloud Provider & Web Farm
!
Router P1
Core ISP
!
Router P2
Core ISP
!
Router PE1
Edge (HQ)
!
Router PE2
Edge (DC Utama)
!
Router PE3
Edge (DC Backup/Cloud)
!
CE-HQ / ASA Firewall
10.1.0.1
Core SW HQ (L3)
VLAN 10/20
HQ Clients (8 PCs)
Workstations
!
Spine-1 Switch
L3 ECMP Fabric
!
Spine-2 Switch
L3 ECMP Fabric
!
Leaf-1 Switch
VXLAN VTEP 1
!
Leaf-2 Switch
VXLAN VTEP 2
Server Tenant A
VRF-Tenant-A
Server Tenant B
VRF-Tenant-B
Shared DNS & NTP
Management Subnet
!
CE-Cloud Router
BGP Path Selection
Web & App Farm
HTTP/HTTPS (80, 443)
Rubrik Penilaian Modul (Total 100 Point)
Modul 1: ISP Backbone (OSPF, MPLS & BGP)
25 Point
Konfigurasi OSPF Area 0 internal ISP, aktifkan MPLS LDP di P1/P2/PE, dan tetapkan iBGP/eBGP peering.
Modul 2: DC Spine-Leaf Architecture & VXLAN
25 Point
Terapkan ECMP di Spine Switch dan bangun Tunneling Overlay VXLAN antar-Leaf (L2 Extension).
Modul 3: Multi-Tenant Isolation (VRF Lite)
20 Point
Isolasi trafik VRF-Tenant-A dan B, serta konfigurasi Inter-VRF Leaking khusus akses Shared Services (DNS/NTP).
Modul 4: IPsec VPN & Firewall Hardening
15 Point
Bangun IPsec VPN (AES-256) HQ to DC, serta Stateful Firewall (Blok Mgmt, izinkan Port 80/443 & Anti-Spoofing).
Modul 5: Traffic Engineering, QoS & Disaster Failover
15 Point
Prioritas DSCP EF (VoIP/DB), BGP Local Pref PE2 (Utama) / PE3 (Backup), dan uji Live Failover saat P1-PE2 diputus.
Interactive Console & Audit Log
admin@backbone-core-console:~#
Check MPLS & BGP Status
Audit VRF & IPsec VPN
Verify QoS & BGP Path
Simulasikan Kabel Putus (Disaster)
Modul 1: ISP Core Backbone (MPLS & BGP)
×
Konfigurasi protokol IGP (OSPF Area 0), Multiprotocol Label Switching (MPLS LDP), dan iBGP/eBGP Peering.
OSPF Internal IGP
Disabled
OSPF Area 0 (P1, P2, PE1, PE2, PE3)
MPLS Label Distribution Protocol (LDP)
Disabled
MPLS LDP Active on All ISP Core Interfaces
BGP Peering Topology
Disabled
iBGP Mesh (PE-PE) + eBGP (PE-CE Active)
Modul 2: DC Spine-Leaf Architecture
×
Hubungkan Spine-1 & 2 ke Leaf-1 & 2 tanpa cross-link. Terapkan ECMP dan Overlay VXLAN.
Spine Switch Routing & Load Balancing
Single Path (No ECMP)
Equal-Cost Multi-Path (ECMP Active)
VXLAN Overlay Tunneling (Leaf-1 to Leaf-2)
Disabled (VLAN Traditional)
VXLAN Tunneling Configured (VNI 10001 - L2 Extension)
Modul 3: Multi-Tenant VRF Isolation
×
Isolasi trafik Tenant A dan Tenant B pada infrastruktur fisik yang sama menggunakan VRF-Lite.
VRF Status Isolation
Global Routing Table (No Isolation - Risky)
VRF-Tenant-A & VRF-Tenant-B Configured
Inter-VRF Route Leaking (Shared Services)
Disabled (No Access to Shared DNS/NTP)
Leaking Active for Shared DNS (10.50.0.53) Only
Modul 4: Enterprise Security & IPsec VPN
×
Enkripsi jalur site-to-site CE-HQ ke CE-DC dan amankan server dari ancaman luar.
Site-to-Site IPsec VPN Tunnel
Disabled (Plain Text Transit)
IPsec Active (AES-256, SHA-256, DH Group 14)
Stateful Firewall & ZBF Rules
Permit Any (No Firewall)
Block Mgmt, Allow HTTP/HTTPS (80/443), Anti-Spoofing ACL
Modul 5: Traffic Engineering & QoS
×
Atur prioritas data VoIP/Database serta jalur BGP utama via PE2 dan cadangan via PE3.
Quality of Service Tagging (DSCP)
Best Effort (No Policy)
DSCP EF for VoIP & Database Traffic
BGP Local Preference / Path Control
Default BGP Path Selection
PE2 Local-Pref 200 (Primary), PE3 AS-Path Prepend (Backup)
Rincian Alokasi Waktu Lab (240 Menit / 4 Jam)
×
Waktu
Durasi
Focus Area
Target Deliverables
00:00 – 00:35
35 Min
Topology & IP Planning
Menyusun 32 perangkat & skema IP / BGP AS.
00:35 – 01:20
45 Min
ISP Core Setup
Backbone OSPF, MPLS LDP, & iBGP/eBGP up.
01:20 – 02:05
45 Min
Spine-Leaf & VRF Isolation
ECMP DC, VXLAN Tunnel, VRF Tenant A/B.
02:05 – 02:50
45 Min
Site-to-Site VPN & Security
IPsec Tunnel AES-256 & Stateful Firewall.
02:50 – 03:25
35 Min
TE & QoS Tuning
DSCP Tagging & BGP Local Preference.
03:25 – 03:45
20 Min
Live Failover Test
Pemutusan link paksa; konvergensi < 15 detik.
03:45 – 04:00
15 Min
Final Verification
Audit show ip bgp, show mpls ldp & submit.