ืžืคืขืœ VxLAN. ื—ืœืง 1

ืฉืœื•ื, ื”ืื‘ืจ. ื›ื™ื•ื ืื ื™ ืžื ื—ื” ื”ืงื•ืจืก ืฉืœ ืงื•ืจืก ืžื”ื ื“ืก ืจืฉืช ื‘-OTUS.
ืœืงืจืืช ืชื—ื™ืœืช ื”ืจืฉืžื” ื—ื“ืฉื” ืœืงื•ืจืก "ืžื”ื ื“ืก ืจืฉืช", ื”ื›ื ืชื™ ืกื“ืจื” ืฉืœ ืžืืžืจื™ื ืขืœ ื˜ื›ื ื•ืœื•ื’ื™ื™ืช VxLAN EVPN.

ื™ืฉ ื›ืžื•ืช ืขืฆื•ืžื” ืฉืœ ื—ื•ืžืจ ืขืœ ืื™ืš VxLAN EVPN ืขื•ื‘ื“, ืื– ืื ื™ ืจื•ืฆื” ืœืืกื•ืฃ ืžืฉื™ืžื•ืช ื•ืคืจืงื˜ื™ืงื•ืช ืฉื•ื ื•ืช ืœืคืชืจื•ืŸ ื‘ืขื™ื•ืช ื‘ืžืจื›ื– ื ืชื•ื ื™ื ืžื•ื“ืจื ื™.

ืžืคืขืœ VxLAN. ื—ืœืง 1

ื‘ื—ืœืง ื”ืจืืฉื•ืŸ ืฉืœ ื”ืกื“ืจื” ืขืœ ื˜ื›ื ื•ืœื•ื’ื™ื™ืช VxLAN EVPN, ืื ื™ ืจื•ืฆื” ืœื‘ื—ื•ืŸ ื“ืจืš ืœืืจื’ืŸ ืงื™ืฉื•ืจื™ื•ืช L2 ื‘ื™ืŸ ืžืืจื—ื™ื ืขืœ ื’ื‘ื™ ืžืืจื’ ืจืฉืช.

ื›ืœ ื”ื“ื•ื’ืžืื•ืช ื™ื‘ื•ืฆืขื• ืขืœ Cisco Nexus 9000v, ื”ืžื•ืจื›ื‘ ื‘ื˜ื•ืคื•ืœื•ื’ื™ื” ืฉืœ Spine-Leaf. ืœื ื ืชืขื›ื‘ ืขืœ ื”ืงืžืช ืจืฉืช Underlay ื‘ืžืืžืจ ื–ื”.

  1. ืจืฉืช ืชืฉืชื™ืช
  2. BGP-ื”ืฆืฆื” ืขื‘ื•ืจ l2vpn evpn ืฉืœ ืžืฉืคื—ืช ื›ืชื•ื‘ืช
  3. ื”ื’ื“ืจืช NVE
  4. ื“ื™ื›ื•ื™-ืืจืค

ืจืฉืช ืชืฉืชื™ืช

ื”ื˜ื•ืคื•ืœื•ื’ื™ื” ืฉื‘ื” ื ืขืฉื” ืฉื™ืžื•ืฉ ื”ื™ื ื›ื“ืœืงืžืŸ:

ืžืคืขืœ VxLAN. ื—ืœืง 1

ื‘ื•ืื• ื ื’ื“ื™ืจ ื›ืชื•ื‘ืช ื‘ื›ืœ ื”ืžื›ืฉื™ืจื™ื:

Spine-1 - 10.255.1.101
Spine-2 - 10.255.1.102

Leaf-11 - 10.255.1.11
Leaf-12 - 10.255.1.12
Leaf-21 - 10.255.1.21

Host-1 - 192.168.10.10
Host-2 - 192.168.10.20

ื‘ื•ืื• ื ื‘ื“ื•ืง ืฉื™ืฉ ืงื™ืฉื•ืจื™ื•ืช IP ื‘ื™ืŸ ื›ืœ ื”ืžื›ืฉื™ืจื™ื:

Leaf21# sh ip route
<........>
10.255.1.11/32, ubest/mbest: 2/0                      ! Leaf-11 ะดะพัั‚ัƒะฟะตะฝ ั‡ะตะตั€ะท ะดะฒะฐ Spine
    *via 10.255.1.101, Eth1/4, [110/81], 00:00:03, ospf-UNDERLAY, intra
    *via 10.255.1.102, Eth1/3, [110/81], 00:00:03, ospf-UNDERLAY, intra
10.255.1.12/32, ubest/mbest: 2/0                      ! Leaf-12 ะดะพัั‚ัƒะฟะตะฝ ั‡ะตะตั€ะท ะดะฒะฐ Spine
    *via 10.255.1.101, Eth1/4, [110/81], 00:00:03, ospf-UNDERLAY, intra
    *via 10.255.1.102, Eth1/3, [110/81], 00:00:03, ospf-UNDERLAY, intra
10.255.1.21/32, ubest/mbest: 2/0, attached
    *via 10.255.1.22, Lo0, [0/0], 00:02:20, local
    *via 10.255.1.22, Lo0, [0/0], 00:02:20, direct
10.255.1.101/32, ubest/mbest: 1/0
    *via 10.255.1.101, Eth1/4, [110/41], 00:00:06, ospf-UNDERLAY, intra
10.255.1.102/32, ubest/mbest: 1/0
    *via 10.255.1.102, Eth1/3, [110/41], 00:00:03, ospf-UNDERLAY, intra

ื‘ื•ืื• ื ื‘ื“ื•ืง ืฉื“ื•ืžื™ื™ืŸ ื”-VPC ื ื•ืฆืจ ื•ืฉื ื™ ื”ืžืชื’ื™ื ืขื‘ืจื• ืืช ื‘ื“ื™ืงืช ื”ืขืงื‘ื™ื•ืช ื•ื”ื”ื’ื“ืจื•ืช ื‘ืฉื ื™ ื”ืฆืžืชื™ื ื–ื”ื•ืช:

Leaf11# show vpc 

vPC domain id                     : 1
Peer status                       : peer adjacency formed ok
vPC keep-alive status             : peer is alive
Configuration consistency status  : success
Per-vlan consistency status       : success
Type-2 consistency status         : success
vPC role                          : primary
Number of vPCs configured         : 0
Peer Gateway                      : Disabled
Dual-active excluded VLANs        : -
Graceful Consistency Check        : Enabled
Auto-recovery status              : Disabled
Delay-restore status              : Timer is off.(timeout = 30s)
Delay-restore SVI status          : Timer is off.(timeout = 10s)
Operational Layer3 Peer-router    : Disabled

vPC status
----------------------------------------------------------------------------
Id    Port          Status Consistency Reason                Active vlans
--    ------------  ------ ----------- ------                ---------------
5     Po5           up     success     success               1

BGP ื”ืฆืฆื”

ืœื‘ืกื•ืฃ, ืืชื” ื™ื›ื•ืœ ืœืขื‘ื•ืจ ืœื”ื’ื“ืจืช ืจืฉืช ื”-Overlay.

ื›ื—ืœืง ืžื”ืžืืžืจ, ื™ืฉ ืฆื•ืจืš ืœืืจื’ืŸ ืจืฉืช ื‘ื™ืŸ ืžืืจื—ื™ื, ื›ืคื™ ืฉืžื•ืฆื’ ื‘ืชืจืฉื™ื ืฉืœื”ืœืŸ:

ืžืคืขืœ VxLAN. ื—ืœืง 1

ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืจืฉืช ืฉื›ื‘ืช-ืขืœ, ืขืœื™ืš ืœื”ืคืขื™ืœ BGP ื‘ืžืชื’ื™ ื”ืฉื“ืจื” ื•ื”ืขืœื” ืขื ืชืžื™ื›ื” ื‘ืžืฉืคื—ืช l2vpn evpn:

feature bgp
nv overlay evpn

ืœืื—ืจ ืžื›ืŸ, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ื”ืฆืฆื” BGP ื‘ื™ืŸ Leaf ื•-Spine. ื›ื“ื™ ืœืคืฉื˜ ืืช ื”ื”ื’ื“ืจื” ื•ืœื™ื™ืขืœ ืืช ื”ืคืฆืช ืžื™ื“ืข ื”ื ื™ืชื•ื‘, ืื ื• ืžื’ื“ื™ืจื™ื ืืช Spine ื›ืฉืจืช Route-Reflector. ื ื›ืชื•ื‘ ืืช ื›ืœ Leaf ื‘ืชืฆื•ืจื” ื‘ืืžืฆืขื•ืช ืชื‘ื ื™ื•ืช ื›ื“ื™ ืœื™ื™ืขืœ ืืช ื”ื”ื’ื“ืจื”.

ืื– ื”ื”ื’ื“ืจื•ืช ื‘ืขืžื•ื“ ื”ืฉื“ืจื” ื ืจืื•ืช ื›ืš:

router bgp 65001
  template peer LEAF 
    remote-as 65001
    update-source loopback0
    address-family l2vpn evpn
      send-community
      send-community extended
      route-reflector-client
  neighbor 10.255.1.11
    inherit peer LEAF
  neighbor 10.255.1.12
    inherit peer LEAF
  neighbor 10.255.1.21
    inherit peer LEAF

ื”ื”ื’ื“ืจื” ื‘ืžืชื’ Leaf ื ืจืื™ืช ื“ื•ืžื”:

router bgp 65001
  template peer SPINE
    remote-as 65001
    update-source loopback0
    address-family l2vpn evpn
      send-community
      send-community extended
  neighbor 10.255.1.101
    inherit peer SPINE
  neighbor 10.255.1.102
    inherit peer SPINE

ื‘ืขืžื•ื“ ื”ืฉื“ืจื”, ื‘ื•ืื• ื ื‘ื“ื•ืง ืืช ื”ื”ืฆืฆื” ืขื ื›ืœ ืžืชื’ื™ ื”ืขืœื™ื:

Spine1# sh bgp l2vpn evpn summary
<.....>
Neighbor        V    AS MsgRcvd MsgSent   TblVer  InQ OutQ Up/Down  State/PfxRcd
10.255.1.11     4 65001       7       8        6    0    0 00:01:45 0
10.255.1.12     4 65001       7       7        6    0    0 00:01:16 0
10.255.1.21     4 65001       7       7        6    0    0 00:01:01 0

ื›ืคื™ ืฉืืชื” ื™ื›ื•ืœ ืœืจืื•ืช, ืœื ื”ื™ื• ื‘ืขื™ื•ืช ืขื BGP. ื‘ื•ืื• ื ืขื‘ื•ืจ ืœื”ื’ื“ืจืช VxLAN. ืชืฆื•ืจื” ื ื•ืกืคืช ืชืชื‘ืฆืข ืจืง ื‘ืฆื“ ื”ืขืœื” ืฉืœ ื”ืžืชื’ื™ื. ืขืžื•ื“ ื”ืฉื“ืจื” ืคื•ืขืœ ืจืง ื‘ืชื•ืจ ื”ืœื™ื‘ื” ืฉืœ ื”ืจืฉืช ื•ืžืขื•ืจื‘ ืจืง ื‘ื”ืขื‘ืจืช ืชืขื‘ื•ืจื”. ื›ืœ ืขื‘ื•ื“ืช ื”ืื ืงืคืกื•ืœืฆื™ื” ื•ืงื‘ื™ืขืช ื”ื ืชื™ื‘ ืžืชืจื—ืฉืช ืจืง ืขืœ ืžืชื’ื™ ืขืœื”.

ื”ื’ื“ืจืช NVE

NVE - ืžืžืฉืง ื•ื™ืจื˜ื•ืืœื™ ื‘ืจืฉืช

ืœืคื ื™ ืชื—ื™ืœืช ื”ื”ื’ื“ืจื”, ื‘ื•ืื• ื ืฆื™ื’ ื›ืžื” ืžื™ื ื•ื—ื™ื:

VTEP - Vitual Tunnel End Point, ื”ืžื›ืฉื™ืจ ื‘ื• ืžืชื—ื™ืœื” ืื• ืžืกืชื™ื™ืžืช ืžื ื”ืจืช VxLAN. VTEP ืื™ื ื• ื‘ื”ื›ืจื— ื›ืœ ื”ืชืงืŸ ืจืฉืช. ืฉืจืช ื”ืชื•ืžืš ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช VxLAN ื™ื›ื•ืœ ืœืฉืžืฉ ื’ื ื›ืฉืจืช. ื‘ื˜ื•ืคื•ืœื•ื’ื™ื” ืฉืœื ื•, ื›ืœ ืžืชื’ื™ ื”ืขืœื™ื ื”ื VTEP.

VNI - Virtual Network Index - ืžื–ื”ื” ืจืฉืช ื‘ืชื•ืš VxLAN. ื ื™ืชืŸ ืœืฆื™ื™ืจ ืื ืœื•ื’ื™ื” ืขื VLAN. ืขื ื–ืืช, ื™ืฉื ื ื›ืžื” ื”ื‘ื“ืœื™ื. ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืžืืจื’, ืจืฉืชื•ืช VLAN ื”ื•ืคื›ื•ืช ื™ื™ื—ื•ื“ื™ื•ืช ืจืง ื‘ืชื•ืš ืžืชื’ Leaf ืื—ื“ ื•ืื™ื ืŸ ืžื•ืขื‘ืจื•ืช ืขืœ ืคื ื™ ื”ืจืฉืช. ืื‘ืœ ืœื›ืœ VLAN ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžืฉื•ื™ืš ืืœื™ื• ืžืกืคืจ VNI, ืฉื›ื‘ืจ ืžื•ืขื‘ืจ ื“ืจืš ื”ืจืฉืช. ืื™ืš ื–ื” ื ืจืื” ื•ื›ื™ืฆื“ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื™ื™ื“ื•ื ื• ื‘ื”ืžืฉืš.

ื‘ื•ืื• ื ืคืขื™ืœ ืืช ื”ืชื›ื•ื ื” ืœื˜ื›ื ื•ืœื•ื’ื™ื™ืช VxLAN ืœืขื‘ื•ื“ ื•ืืช ื”ื™ื›ื•ืœืช ืœืฉื™ื™ืš ืžืกืคืจื™ VLAN ืœืžืกืคืจ VNI:

feature nv overlay
feature vn-segment-vlan-based

ื‘ื•ืื• ื ื’ื“ื™ืจ ืืช ืžืžืฉืง NVE, ืฉืื—ืจืื™ ืขืœ ืชืคืขื•ืœ VxLAN. ืžืžืฉืง ื–ื” ืื—ืจืื™ ืœืงืคืกื•ืœ ืžืกื’ืจื•ืช ื‘ื›ื•ืชืจื•ืช VxLAN. ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืจ ืื ืœื•ื’ื™ื” ืขื ืžืžืฉืง ื”ืžื ื”ืจื” ืขื‘ื•ืจ GRE:

interface nve1
  no shutdown
  host-reachability protocol bgp ! ะธัะฟะพะปัŒะทัƒะตะผ BGP ะดะปั ะฟะตั€ะตะดะฐั‡ะธ ะผะฐั€ัˆั€ัƒั‚ะฝะพะน ะธะฝั„ะพั€ะผะฐั†ะธะธ
  source-interface loopback0    ! ะธะฝั‚ะตั€ั„ะตะนั  ั ะบะพั‚ะพั€ะพะณะพ ะพั‚ะฟั€ะฐะฒะปัะตะผ ะฟะฐะบะตั‚ั‹ loopback0

ืขืœ ื”ืžืชื’ Leaf-21 ื”ื›ืœ ื ื•ืฆืจ ืœืœื ื‘ืขื™ื•ืช. ืขื ื–ืืช, ืื ื ื‘ื“ื•ืง ืืช ื”ืคืœื˜ ืฉืœ ื”ืคืงื•ื“ื” show nve peers, ืื– ื”ื•ื ื™ื”ื™ื” ืจื™ืง. ื›ืืŸ ืืชื” ืฆืจื™ืš ืœื—ื–ื•ืจ ืœืชืฆื•ืจืช VPC. ืื ื• ืจื•ืื™ื ืฉ-Leaf-11 ื•-Leaf-12 ืขื•ื‘ื“ื™ื ื‘ื–ื•ื’ื•ืช ื•ืžืื•ื—ื“ื™ื ืขืœ ื™ื“ื™ ืชื—ื•ื VPC. ื–ื” ื ื•ืชืŸ ืœื ื• ืืช ื”ืžืฆื‘ ื”ื‘ื:

Host-2 ืฉื•ืœื— ืคืจื™ื™ื ืื—ื“ ืœื›ื™ื•ื•ืŸ Leaf-21 ื›ืš ืฉื”ื•ื ืžืฉื“ืจ ืื•ืชื• ื“ืจืš ื”ืจืฉืช ืœื›ื™ื•ื•ืŸ Host-1. ืขื ื–ืืช, Leaf-21 ืจื•ืื” ืฉื›ืชื•ื‘ืช ื”-MAC ืฉืœ Host-1 ื ื’ื™ืฉื” ื“ืจืš ืฉื ื™ VTEP ื‘ื•-ื–ืžื ื™ืช. ืžื” ืขืœ Leaf-21 ืœืขืฉื•ืช ื‘ืžืงืจื” ื–ื”? ืื—ืจื™ ื”ื›ืœ, ื–ื” ืื•ืžืจ ืฉืขืœื•ืœื” ืœื”ื•ืคื™ืข ืœื•ืœืื” ื‘ืจืฉืช.

ื›ื“ื™ ืœืคืชื•ืจ ืืช ื”ืžืฆื‘ ื”ื–ื”, ืื ื—ื ื• ืฆืจื™ื›ื™ื ืืช Leaf-11 ื•-Leaf-12 ืฉื™ืคืขืœื• ื’ื ื›ืžื›ืฉื™ืจ ืื—ื“ ื‘ืชื•ืš ื”ืžืคืขืœ. ื”ืคืชืจื•ืŸ ื“ื™ ืคืฉื•ื˜. ื‘ืžืžืฉืง Loopback ืฉืžืžื ื• ืื ื• ื‘ื•ื ื™ื ืืช ื”ืžื ื”ืจื”, ื”ื•ืกืฃ ื›ืชื•ื‘ืช ืžืฉื ื™ืช. ื”ื›ืชื•ื‘ืช ื”ืžืฉื ื™ืช ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ื–ื”ื” ื‘ืฉื ื™ ื”-VTEPs.

interface loopback0
 ip add 10.255.1.10/32 secondary

ืœืคื™ื›ืš, ืžื ืงื•ื“ืช ื”ืžื‘ื˜ ืฉืœ VTEPs ืื—ืจื™ื, ืื ื• ืžืงื‘ืœื™ื ืืช ื”ื˜ื•ืคื•ืœื•ื’ื™ื” ื”ื‘ืื”:

ืžืคืขืœ VxLAN. ื—ืœืง 1

ื›ืœื•ืžืจ, ื›ืขืช ืชื™ื‘ื ื” ื”ืžื ื”ืจื” ื‘ื™ืŸ ื›ืชื•ื‘ืช ื”-IP ืฉืœ Leaf-21 ืœื‘ื™ืŸ ื”-IP ื”ื•ื•ื™ืจื˜ื•ืืœื™ ื‘ื™ืŸ ืฉื ื™ Leaf-11 ืœ-Leaf-12. ื›ืขืช ืœื ื™ื”ื™ื• ื‘ืขื™ื•ืช ืœืœืžื•ื“ ืืช ื›ืชื•ื‘ืช ื”-MAC ืžืฉื ื™ ืžื›ืฉื™ืจื™ื ื•ืชืขื‘ื•ืจื” ื™ื›ื•ืœื” ืœืขื‘ื•ืจ ืž-VTEP ืื—ื“ ืœืื—ืจ. ืžื™ ืžืฉื ื™ ื”-VTEPs ื™ืขื‘ื“ ืืช ื”ืชืขื‘ื•ืจื” ื ืงื‘ืข ื‘ืืžืฆืขื•ืช ื˜ื‘ืœืช ื”ื ื™ืชื•ื‘ ื‘ืขืžื•ื“ ื”ืฉื“ืจื”:

Spine1# sh ip route
<.....>
10.255.1.10/32, ubest/mbest: 2/0
    *via 10.255.1.11, Eth1/1, [110/41], 1d01h, ospf-UNDERLAY, intra
    *via 10.255.1.12, Eth1/2, [110/41], 1d01h, ospf-UNDERLAY, intra
10.255.1.11/32, ubest/mbest: 1/0
    *via 10.255.1.11, Eth1/1, [110/41], 1d22h, ospf-UNDERLAY, intra
10.255.1.12/32, ubest/mbest: 1/0
    *via 10.255.1.12, Eth1/2, [110/41], 1d01h, ospf-UNDERLAY, intra

ื›ืคื™ ืฉื ื™ืชืŸ ืœืจืื•ืช ืœืขื™ืœ, ื”ื›ืชื•ื‘ืช 10.255.1.10 ื–ืžื™ื ื” ื‘ืื•ืคืŸ ืžื™ื™ื“ื™ ื“ืจืš ืฉื ื™ Next-hops.

ื‘ืฉืœื‘ ื–ื” ืขืกืงื ื• ื‘ืงื™ืฉื•ืจื™ื•ืช ื”ื‘ืกื™ืกื™ืช. ื‘ื•ืื• ื ืขื‘ื•ืจ ืœื”ื’ื“ืจืช ืžืžืฉืง NVE:
ื‘ื•ืื• ื ืคืขื™ืœ ืžื™ื“ ืืช Vlan 10 ื•ื ืฉื™ื™ืš ืื•ืชื• ืœ-VNI 10000 ื‘ื›ืœ ืขืœื” ืขื‘ื•ืจ ื”ืžืืจื—ื™ื. ื‘ื•ืื• ื ื’ื“ื™ืจ ืžื ื”ืจื” L2 ื‘ื™ืŸ ื”ืžืืจื—ื™ื

vlan 10                 ! ะ’ะบะปัŽั‡ะฐะตะผ VLAN ะฝะฐ ะฒัะตั… VTEP ะฟะพะดะบะปัŽั‡ะตะฝะฝั‹ั… ะบ ะฝะตะพะฑั…ะพะดะธะผั‹ะผ ั…ะพัั‚ะฐะผ
  vn-segment 10000      ! ะััะพั†ะธะธั€ัƒะตะผ VLAN ั ะฝะพะผะตั€ VNI 

interface nve1
  member vni 10000      ! ะ”ะพะฑะฐะฒะปัะตะผ VNI 10000 ะดะปั ั€ะฐะฑะพั‚ั‹ ั‡ะตั€ะตะท ะธะฝั‚ะตั€ั„ะตะนั NVE. ะดะปั ะธะฝะบะฐะฟััƒะปัั†ะธะธ ะฒ VxLAN
    ingress-replication protocol bgp    ! ัƒะบะฐะทั‹ะฒะฐะตะผ, ั‡ั‚ะพ ะดะปั ั€ะฐัะฟั€ะพัั‚ั€ะฐะฝะตะฝะธั ะธะฝั„ะพั€ะผะฐั†ะธะธ ะพ ั…ะพัั‚ะต ะธัะฟะพะปัŒะทัƒะตะผ BGP

ืขื›ืฉื™ื• ื‘ื•ืื• ื ื‘ื“ื•ืง nve ืขืžื™ืชื™ื ื•ืืช ื”ื˜ื‘ืœื” ืขื‘ื•ืจ BGP EVPN:

Leaf21# sh nve peers
Interface Peer-IP          State LearnType Uptime   Router-Mac
--------- ---------------  ----- --------- -------- -----------------
nve1      10.255.1.10      Up    CP        00:00:41 n/a                 ! ะ’ะธะดะธะผ ั‡ั‚ะพ peer ะดะพัั‚ัƒะฟะตะฝ ั secondary ะฐะดั€ะตัะฐ

Leaf11# sh bgp l2vpn evpn

   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)        ! ะžั‚ ะบะพะณะพ ะธะผะตะฝะฝะพ ะฟั€ะธัˆะตะป ัั‚ะพั‚ l2VNI
*>l[3]:[0]:[32]:[10.255.1.10]/88                                   ! EVPN route-type 3 - ะฟะพะบะฐะทั‹ะฒะฐะตั‚ ะฝะฐัˆะตะณะพ ัะพัะตะดะฐ, ะบะพั‚ะพั€ั‹ะน ั‚ะฐะบ ะถะต ะทะฝะฐะตั‚ ะพะฑ l2VNI10000
                      10.255.1.10                       100      32768 i
*>i[3]:[0]:[32]:[10.255.1.20]/88
                      10.255.1.20                       100          0 i
* i                   10.255.1.20                       100          0 i

Route Distinguisher: 10.255.1.21:32777
* i[3]:[0]:[32]:[10.255.1.20]/88
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i

ืœืžืขืœื” ืื ื• ืจื•ืื™ื ืจืง ืžืกืœื•ืœื™ื ืžืกื•ื’ EVPN ืžืกืœื•ืœ 3. ืกื•ื’ ื–ื” ืฉืœ ืžืกืœื•ืœ ืžื“ื‘ืจ ืขืœ ืขืžื™ืช(Leaf), ืื‘ืœ ืื™ืคื” ื”ืžืืจื—ื™ื ืฉืœื ื•?
ื”ืขื ื™ื™ืŸ ื”ื•ื ืฉืžื™ื“ืข ืขืœ ืžืืจื—ื™ ื”-MAC ืžื•ืขื‘ืจ ื“ืจืš EVPN ืžืกืœื•ืœ ืžืกื•ื’ 2

ืขืœ ืžื ืช ืœืจืื•ืช ืืช ื”ืžืืจื—ื™ื ืฉืœื ื•, ืขืœื™ืš ืœื”ื’ื“ื™ืจ EVPN ืžืกืœื•ืœ ืžืกื•ื’ 2:

evpn
  vni 10000 l2
    route-target import auto   ! ะฒ ั€ะฐะผะบะฐั… ะดะฐะฝะฝะพะน ัั‚ะฐั‚ัŒะธ ะธัะฟะพะปัŒะทัƒะตะผ ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธะน ะฝะพะผะตั€ ะดะปั route-target
    route-target export auto

ื‘ื•ืื• ื ื‘ืฆืข ืคื™ื ื’ ืž-Host-2 ืœ-Host-1:

Firewall2# ping 192.168.10.1
PING 192.168.10.1 (192.168.10.1): 56 data bytes
36 bytes from 192.168.10.2: Destination Host Unreachable
Request 0 timed out
64 bytes from 192.168.10.1: icmp_seq=1 ttl=254 time=215.555 ms
64 bytes from 192.168.10.1: icmp_seq=2 ttl=254 time=38.756 ms
64 bytes from 192.168.10.1: icmp_seq=3 ttl=254 time=42.484 ms
64 bytes from 192.168.10.1: icmp_seq=4 ttl=254 time=40.983 ms

ื•ืœืžื˜ื” ืื ื• ื™ื›ื•ืœื™ื ืœืจืื•ืช ืฉืžืกืœื•ืœ ืžืกื•ื’ 2 ืขื ื›ืชื•ื‘ืช MAC ืžืืจื— ื”ื•ืคื™ืข ื‘ื˜ื‘ืœืช BGP - 5001.0007.0007 ื•-5001.0008.0007

Leaf11# sh bgp l2vpn evpn
<......>

   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216                      !  evpn route-type 2 ะธ mac ะฐะดั€ะตั ั…ะพัั‚ะฐ 1
                      10.255.1.10                       100      32768 i
*>i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216                      ! evpn route-type 2 ะธ mac ะฐะดั€ะตั ั…ะพัั‚ะฐ 2
* i                   10.255.1.20                       100          0 i
*>l[3]:[0]:[32]:[10.255.1.10]/88
                      10.255.1.10                       100      32768 i
Route Distinguisher: 10.255.1.21:32777
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i

ืœืื—ืจ ืžื›ืŸ, ืชื•ื›ืœ ืœืจืื•ืช ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ Update, ืฉื‘ื• ืงื™ื‘ืœืช ืžื™ื“ืข ืขืœ ื”-MAC Host. ืœื”ืœืŸ ืœื ื›ืœ ืคืœื˜ ื”ืคืงื•ื“ื”.

Leaf21# sh bgp l2vpn evpn 5001.0007.0007

BGP routing table information for VRF default, address family L2VPN EVPN
Route Distinguisher: 10.255.1.11:32777        !  ะพั‚ะฟั€ะฐะฒะธะป Update ั MAC Host. ะะต ะฒะธั€ั‚ัƒะฐะปัŒะฝั‹ะน ะฐะดั€ะตั VPC, ะฐ ะฐะดั€ะตั Leaf
BGP routing table entry for [2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216,
 version 1507
Paths: (2 available, best #2)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not i
n HW

  Path type: internal, path is valid, not best reason: Neighbor Address, no labe
led nexthop
  AS-Path: NONE, path sourced internal to AS
    10.255.1.10 (metric 81) from 10.255.1.102 (10.255.1.102)    ! ั ะบะตะผ ะธะผะตะฝะฝะพ ัั‚ั€ะพะธะผ VxLAN ั‚ะพะฝะฝะตะปัŒ
      Origin IGP, MED not set, localpref 100, weight 0
      Received label 10000         ! ะะพะผะตั€ VNI, ะบะพั‚ะพั€ั‹ะน ะฐััะพั†ะธะธั€ะพะฒะฐะฝ ั VLAN, ะฒ ะบะพั‚ะพั€ะพะผ ะฝะฐั…ะพะดะธั‚ัั Host
      Extcommunity: RT:65001:10000 SOO:10.255.1.10:0 ENCAP:8        ! ะขัƒั‚ ะฒะธะดะฝะพ, ั‡ั‚ะพ RT ัั„ะพั€ะผะธั€ะพะฒะฐะปัั ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธ ะฝะฐ ะพัะฝะพะฒะต ะฝะพะผะตั€ะพะฒ AS ะธ VNI
      Originator: 10.255.1.11 Cluster list: 10.255.1.102
<........>

ื‘ื•ืื• ื ืจืื” ืื™ืš ื ืจืื•ืช ืžืกื’ืจื•ืช ื›ืฉื”ืŸ ืขื•ื‘ืจื•ืช ื“ืจืš ื”ืžืคืขืœ:

ืžืคืขืœ VxLAN. ื—ืœืง 1

ื“ื™ื›ื•ื™-ARP

ื ื”ื“ืจ, ื™ืฉ ืœื ื• ืขื›ืฉื™ื• ืชืงืฉื•ืจืช L2 ื‘ื™ืŸ ื”ืžืืจื—ื™ื ื•ื™ื›ื•ืœื ื• ืœืกื™ื™ื ืฉื. ืขื ื–ืืช, ืœื ื”ื›ืœ ื›ืœ ื›ืš ืคืฉื•ื˜. ื›ืœ ืขื•ื“ ื™ืฉ ืœื ื• ืžืขื˜ ืžืืจื—ื™ื ืœื ื™ื”ื™ื• ื‘ืขื™ื•ืช. ืื‘ืœ ื‘ื•ืื• ื ื“ืžื™ื™ืŸ ืžืฆื‘ ืฉื‘ื• ื™ืฉ ืœื ื• ืžืื•ืช ื•ืืœืคื™ ืžืืจื—ื™ื. ื‘ืื™ื–ื• ื‘ืขื™ื” ืื ื• ืขืœื•ืœื™ื ืœื”ืชืžื•ื“ื“?

ื‘ืขื™ื” ื–ื• ื”ื™ื ืชืขื‘ื•ืจืช BUM(Broadcast, Unknown Unicast, Multicast). ื‘ืžืืžืจ ื–ื” ื ืฉืงื•ืœ ืืช ื”ืืคืฉืจื•ืช ืœื”ืชืžื•ื“ื“ ืขื ืชืขื‘ื•ืจืช ืฉื™ื“ื•ืจ.
ืžื—ื•ืœืœ ื”ืฉื™ื“ื•ืจ ื”ืขื™ืงืจื™ ื‘ืจืฉืชื•ืช Ethernet ื”ื•ื ื”ืžืืจื—ื™ื ืขืฆืžื ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ ARP.

Nexus ืžื™ื™ืฉืžืช ืืช ื”ืžื ื’ื ื•ืŸ ื”ื‘ื ื›ื“ื™ ืœื”ื™ืœื—ื ื‘ื‘ืงืฉื•ืช ARP - suppress-arp.
ืชื›ื•ื ื” ื–ื• ืคื•ืขืœืช ื‘ืื•ืคืŸ ื”ื‘ื:

  1. Host-1 ืฉื•ืœื— ื‘ืงืฉืช APR ืœื›ืชื•ื‘ืช ื”ืฉื™ื“ื•ืจ ืฉืœ ื”ืจืฉืช ืฉืœื•.
  2. ื”ื‘ืงืฉื” ืžื’ื™ืขื” ืœืžืชื’ Leaf ื•ื‘ืžืงื•ื ืœื”ืขื‘ื™ืจ ื‘ืงืฉื” ื–ื• ื”ืœืื” ืœืžืืจื’ ืœื›ื™ื•ื•ืŸ Host-2, Leaf ืžื’ื™ื‘ื” ื‘ืขืฆืžื” ื•ืžืฆื™ื™ื ืช ืืช ื”-IP ื•ื”-MAC ื”ื ื“ืจืฉื™ื.

ืœืคื™ื›ืš, ื‘ืงืฉืช ื”ืฉื™ื“ื•ืจ ืœื ื”ื’ื™ืขื” ืœืžืคืขืœ. ืื‘ืœ ืื™ืš ื–ื” ื™ื›ื•ืœ ืœืขื‘ื•ื“ ืื ืœื™ืฃ ื™ื•ื“ืข ืจืง ืืช ื›ืชื•ื‘ืช ื”-MAC?

ื”ื›ืœ ื“ื™ ืคืฉื•ื˜, EVPN ืžืกืœื•ืœ ืžืกื•ื’ 2, ื‘ื ื•ืกืฃ ืœื›ืชื•ื‘ืช MAC, ื™ื›ื•ืœ ืœืฉื“ืจ ืฉื™ืœื•ื‘ MAC/IP. ื›ื“ื™ ืœืขืฉื•ืช ื–ืืช, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ื›ืชื•ื‘ืช IP ื‘-VLAN on Leaf. ื ืฉืืœืช ื”ืฉืืœื” ืื™ื–ื” IP ืื ื™ ืฆืจื™ืš ืœื”ื’ื“ื™ืจ? ื‘-nexus ืืคืฉืจ ืœื™ืฆื•ืจ ื›ืชื•ื‘ืช ืžื‘ื•ื–ืจืช (ืื•ืชื”) ื‘ื›ืœ ื”ืžืชื’ื™ื:

feature interface-vlan

fabric forwarding anycast-gateway-mac 0001.0001.0001    ! ะทะฐะดะฐะตะผ virtual mac ะดะปั ัะพะทะดะฐะฝะธั ั€ะฐัะฟั€ะตะดะตะปะตะฝะฝะพะณะพ ัˆะปัŽะทะฐ ะผะตะถะดัƒ ะฒัะตะผะธ ะบะพะผะผัƒั‚ะฐั‚ะพั€ะฐะผะธ

interface Vlan10
  no shutdown
  ip address 192.168.10.254/24          ! ะฝะฐ ะฒัะตั… Leaf ะทะฐะดะฐะตะผ ะพะดะธะฝะฐะบะพะฒั‹ะน IP
  fabric forwarding mode anycast-gateway    ! ะณะพะฒะพั€ะธะผ ะธัะฟะพะปัŒะทะพะฒะฐั‚ัŒ Virtual mac

ืœืคื™ื›ืš, ืžื ืงื•ื“ืช ืžื‘ื˜ื ืฉืœ ื”ืžืืจื—ื™ื, ื”ืจืฉืช ืชื™ืจืื” ื›ืš:

ืžืคืขืœ VxLAN. ื—ืœืง 1

ื‘ื•ื ื ื‘ื“ื•ืง ืืช BGP l2route evpn

Leaf11# sh bgp l2vpn evpn
<......>

   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
                      10.255.1.21                       100      32768 i
*>i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216
                      10.255.1.10                       100          0 i
* i                   10.255.1.10                       100          0 i
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.10.20]/248
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i

<......>

Route Distinguisher: 10.255.1.21:32777
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.10.20]/248
*>i                   10.255.1.20                       100          0 i

<......>

ืžืคืœื˜ ื”ืคืงื•ื“ื” ื ื™ืชืŸ ืœืจืื•ืช ืฉื‘-EVPN route-type 2, ื‘ื ื•ืกืฃ ืœ-MAC, ืื ื• ืจื•ืื™ื ื›ืขืช ื’ื ืืช ื›ืชื•ื‘ืช ื”-IP ื”ืžืืจื—.

ื ื—ื–ื•ืจ ืœื”ื’ื“ื™ืจ suppress-arp. ื”ื’ื“ืจื” ื–ื• ืžื•ืคืขืœืช ืขื‘ื•ืจ ื›ืœ VNI ื‘ื ืคืจื“:

interface nve1
  member vni 10000   
    suppress-arp

ื•ืื– ืžืชืขื•ืจืจืช ืžื•ืจื›ื‘ื•ืช ืžืกื•ื™ืžืช:

  • ื›ื“ื™ ืฉืชื›ื•ื ื” ื–ื• ืชืคืขืœ, ื ื“ืจืฉ ืžืงื•ื ื‘ื–ื™ื›ืจื•ืŸ TCAM. ื”ื ื” ื“ื•ื’ืžื” ืœื”ื’ื“ืจื•ืช ืขื‘ื•ืจ suppress-arp:

hardware access-list tcam region arp-ether 256

ื”ื’ื“ืจื” ื–ื• ืชื“ืจื•ืฉ ืจื—ื‘ื” ื›ืคื•ืœื”. ื›ืœื•ืžืจ, ืื ืืชื” ืžื’ื“ื™ืจ 256, ืื– ืืชื” ืฆืจื™ืš ืœืฉื—ืจืจ ืืช 512 ื‘-TCAM. ื”ื’ื“ืจืช TCAM ื”ื™ื ืžืขื‘ืจ ืœืชื—ื•ื ืฉืœ ืžืืžืจ ื–ื”, ืฉื›ืŸ ื”ื’ื“ืจืช TCAM ืชืœื•ื™ื” ืจืง โ€‹โ€‹ื‘ืžืฉื™ืžื” ืฉื”ื•ืงืฆืชื” ืœืš ื•ืขืฉื•ื™ื” ืœื”ื™ื•ืช ืฉื•ื ื” ืžืจืฉืช ืื—ืช ืœืื—ืจืช.

  • ื™ื™ืฉื•ื suppress-arp ื—ื™ื™ื‘ ืœื”ื™ืขืฉื•ืช ื‘ื›ืœ ืžืชื’ื™ ื”ืขืœื™ื. ืขื ื–ืืช, ืžื•ืจื›ื‘ื•ืช ื™ื›ื•ืœื” ืœื”ืชืขื•ืจืจ ื‘ืขืช ืงื‘ื™ืขืช ืชืฆื•ืจื” ืขืœ ื–ื•ื’ื•ืช ืขืœื™ื ื”ืฉื•ื›ื ื™ื ื‘ืชื—ื•ื VPC. ืื TCAM ื™ืฉืชื ื”, ื”ืขืงื‘ื™ื•ืช ื‘ื™ืŸ ื–ื•ื’ื•ืช ืชื™ืฉื‘ืจ ื•ืฆื•ืžืช ืื—ื“ ืขืฉื•ื™ ืœืฆืืช ืžืคืขื™ืœื•ืช. ื‘ื ื•ืกืฃ, ื™ื™ืชื›ืŸ ืฉื™ื™ื“ืจืฉ ืืชื—ื•ืœ ื”ืžื›ืฉื™ืจ ื›ื“ื™ ืœื”ื—ื™ืœ ืืช ื”ื’ื“ืจืช ื”ืฉื™ื ื•ื™ ื‘-TCAM.

ื›ืชื•ืฆืื” ืžื›ืš, ืขืœื™ืš ืœืฉืงื•ืœ ื”ื™ื˜ื‘ ื”ืื, ื‘ืžืฆื‘ืš, ื›ื“ืื™ ืœื™ื™ืฉื ื”ื’ื“ืจื” ื–ื• ื‘ืžืคืขืœ ืคื•ืขืœ.

ื‘ื›ืš ืžืกืชื™ื™ื ื”ื—ืœืง ื”ืจืืฉื•ืŸ ืฉืœ ื”ืกื“ืจื”. ื‘ื—ืœืง ื”ื‘ื ื ืกืชื›ืœ ืขืœ ื ื™ืชื•ื‘ ื“ืจืš ืžืืจื’ VxLAN ืขื ื”ืคืจื“ื” ืฉืœ ืจืฉืชื•ืช ืœ-VRFs ืฉื•ื ื™ื.

ื•ืขื›ืฉื™ื• ืื ื™ ืžื–ืžื™ื ื” ืืช ื›ื•ืœื ืกืžื™ื ืจ ืžืงื•ื•ืŸ ื—ื™ื ื, ืฉื‘ืชื•ื›ื• ืืกืคืจ ืœื›ื ื‘ื”ืจื—ื‘ื” ืขืœ ื”ืงื•ืจืก. 20 ื”ืžืฉืชืชืคื™ื ื”ืจืืฉื•ื ื™ื ืฉื™ื™ืจืฉืžื• ืœืกืžื™ื ืจ ืžืงื•ื•ืŸ ื–ื” ื™ืงื‘ืœื• ืชืขื•ื“ืช ื”ื ื—ื” ื‘ื“ื•ื"ืœ ืชื•ืš 1-2 ื™ืžื™ื ืœืื—ืจ ื”ืฉื™ื“ื•ืจ.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”