α α α αΆαα αααα»ααααααααααΈααα’αααααα’αααΈαα
αα
αααα·ααααΆ VxLAN EVPN ααα ααααΌαααΆααααααααΆαα·ααααααααΆααααΆαα
αΆααααααΎααααααααα·ααααΆ
αα αααα»ααααααα α»αααααα ααΎααααααα ααΆααααααααΆααα½αααααααααΎαα‘αΎααα ααΎααααΌααααααααΆαααααααΆααα ααΎ Nexus 9000v α ααααααΆαααΆααααα ααααα·ααααααΆαα·α αα ααΆαααΆααααΌααααααααΌααααααααΆααααα»αααααααααααααααααΆαααααααααααα·αααααααααααα α αΎααααααααααΎαααΉααα·α αΆαααΆαα·α αα ααΆαααΆαααααα - αααααααααΌααααΆααααααΆαα¬αααΆα VNIs α
αααα»αααΌαααααΉαα’αααααΆ Spine-Leaf topology ααααΌαααΆαααααΎα
ααΎααααΈα αΆααααααΎα ααΎαααΉααα·ααΆαααΈαααααααααΆααααααΌαααΎαα‘αΎα αα·ααααααααα·αααα’αααΈαααααΆααΆαα
αααααΆααααΆααααααΉα ααΌαααααα½αααααΆααααΆααααααα·ααααΆ αα·ααααααα VNI 20000 αααααααααααααΆαα Host-2 α ααααααααΊα
αααα»αααααΈααα ααΎα’αααα’αΆα αααααα ααΆα αααΈ Host αα½ααα Host αα½ααααααααααααααααααΆ?
ααΆαααααΎαααΈαααΊα
- αααααΆααααααΆαα’αααΈ VNIs ααΆααα’αααα ααΎ Leaf switches ααΆααα’αα αααααΆααααααΆααααΆαααΆαααααΌαααΉαααΎαα‘αΎααα ααΎ Leaf ααααΌααα αααα»ααααααΆαα
- ααααΎα§αααα·α - L3 VNI
αα·ααΈααΈαα½αααΊααΆαααααα·αααΆααααα½αα αααααΆαααα’αααααααΆααααααααΌαα αΆααααααΎα VNI ααΆααα’αααα ααΎα§αααααααααΌα Leaf ααΆααα’ααα ααααααΆαααΆααααα ααΆαααααΎαααΆα VNI ααΈαααΈααα¬ααΆααααΆαααα ααΎααααΉαααΆααααΌαα αΆααααΌα ααΆααΆαααΆαααΆααααα½ααααα αΎαα ααΌα αααααα αααα»αααΆαααΆαααΆααααΌαααΆαααααααΎααααααΆααα
ααΎαααΉααα·ααΆααα·ααΈααΆαααααααΈ 2 ααΌα ααΆαα½αα±ααα αΆααα’αΆαααααα αα·ααααα»αααααΆαααΆαααααα·α ααα»αααααααααααΆαααααααααααααααααααα»αααΆααααα ααααα αααα
α αΌααααααα "PROD" αα αααα»α VRF topology α α αΌαααααααα ααα»α αααααΆαα vlan 10 αα ααΆαα ααΎααΌ Leaf-11/12 αα·αα ααα»α αααααΆαα VLAN 20 αα ααΎ Leaf-21 α VLAN 20 ααααΌαααΆαααααΆααααΆαα½α VNI 20000
vrf context PROD
rd auto ! Route Distinguisher Π½Π΅ ΠΏΡΠΈΠ½ΡΠΈΠΏΠΈΠ°Π»Π΅Π½ ΠΈ ΠΌΠΎΠΆΠ΅ΠΌ ΠΈΡΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΡ ΡΡΠΎΡΠΌΠΈΡΠΎΠ²Π°Π½Π½ΡΠΉ Π°Π²ΡΠΎΠΌΠ°ΡΠΈΡΠ΅ΡΠΊΠΈ
address-family ipv4 unicast
route-target both auto ! ΡΠΊΠ°Π·ΡΠ²Π°Π΅ΠΌ Route-target Ρ ΠΊΠΎΡΠΎΡΡΠΌ Π±ΡΠ΄ΡΡ ΠΈΠΌΠΏΠΎΡΡΠΈΡΠΎΠ²Π°ΡΡΡΡ ΠΈ ΡΠΊΡΠΏΠΎΡΡΠΈΡΠΎΠ²Π°ΡΡΡΡ ΠΏΡΠ΅ΡΠΈΠΊΡΡ Π²/ΠΈΠ· VRF
vlan 20
vn-segment 20000
interface nve 1
member vni 20000
ingress-replication protocol bgp
interface Vlan10
no shutdown
vrf member PROD
ip address 192.168.20.1/24
fabric forwarding mode anycast-gateway
ααΎααααΈααααΎ L3VNI α’αααααααΌααααααΎα VLAN ααααΈ ααααΆααααΆααΆαα½α VNI ααααΈα VNI ααααΈααααΌαααααΌα ααααΆαα ααΎααααΉαααΆααα’αααααα αΆααα’αΆααααααααΎααααααΆα VLAN 10 αα·α 20 α
vlan 99
vn-segment 99000
interface nve1
member vni 99000 associate-vrf ! Π‘ΠΎΠ·Π΄Π°Π΅ΠΌ L3 VNI
vrf context PROD
vni 99000 ! ΠΡΠΈΠ²ΡΠ·ΡΠ²Π°Π΅ΠΌ L3 VNI ΠΊ ΠΎΠΏΡΠ΅Π΄Π΅Π»Π΅Π½Π½ΠΎΠΌΡ VRF
ααΆααααααααααΆααααΆαααΉαααΎααα ααΌα αααα
ααΆαα αααααΎααααΈαααα ααααααα·α - ααααααα ααα»α αααααΆαααα½αααααααααα - α ααα»α αααααΆαα vlan 99 αα αααα»α VRF PROD
interface Vlan99
no shutdown
vrf member PROD
ip forward ! ΠΠ° ΠΈΠ½ΡΠ΅ΡΡΠ΅ΠΉΡΠ΅ Π½Π΅ Π΄ΠΎΠ»ΠΆΠ½ΠΎ Π±ΡΡΡ IP. ΠΡΠΏΠΎΠ»ΡΠ·ΡΠ΅ΡΡΡ ΡΠΎΠ»ΡΠΊΠΎ Π΄Π»Ρ ΠΏΠ΅ΡΠ΅ΡΡΠ»ΠΊΠΈ ΠΏΠ°ΠΊΠ΅ΡΠΎΠ² ΠΌΠ΅ΠΆΠ΄Ρ Leaf
ααΆαααααα αααααα·ααααΆααααΆαααααααΆααααα»αααΈ Host-1 αα Host-2 ααΆαααΌα ααΆααααααα
- ααα»ααααααΆαααααΎααα Host-1 ααααααα ααΎααααΉααα αααα»α VLAN 10 αααααααΌαααΆαααααΆααααΆαα½α VNI 10000;
- Leaf αα·αα·αααααΎααααααααααα’αΆααααααΆαααααα ααΊ αα·ααααααααααΆααΆαααα L3 VNI αα ααΎααΆαααααΆααααααΌα Leaf ααΈααΈαα
- αααΆαααΆααααΌααα ααΆααα’αΆααααααΆαααααα ααααΌαααΆαααααΎα Leaf ααα ααααα»αα αΌααα αααα»αααααααΆααΆαα½α L3VNI 99000 α αΆαααΆα α - α αΎαααααΎααΆαα Leaf ααΈααΈα;
- Leaf switch ααΈααΈαααα½αααΆααα·ααααααααΈ L3VNI 99000α ααα½αααΆαααα»αααΎα α αΎααααααααΆαα L2VNI 20000 αααααααΌαααΆα α αΎααααααΆαααααα VLAN 20α
ααΆααααααααααΆαααΆαααα L3VNI ααα ααααΌααααααΌαααΆαααΎααααΈαααααΆααααααΆαα’αααΈ VNI ααΆααα’αααααααΆααα ααΎαααααΆααα ααΎα§αααααααααΌα Leaf ααΆααα’ααα
ααΆαααααααα ααααααααΎαααααΎα ααΆα αααΈ Host-1 αα Host-2 αααα ααααααααΆαααααΌαααΆαααα αααα ααΆααααα»α VxLAN ααΆαα½αααΉα VNI ααααΈ - 99000α
ααΆαα ααααααΌαααΆαααααΎαααΎαααΈααααααα Leaf-1 αααα’αααΈα’αΆααααααΆα MAC ααΈ VNI ααααααααα ααΆααααΎαα‘αΎαααααααααααΆααααα½αααΈ EVPN route-type 2 (MAC / IP) α
ααΆααααααααααααα αΆαααΈααααΎαααΆαααααΆαααααααααααΆαααααΌαα’αααΈαα»ααααααααααΆαααΈααΆαααα VNI αα½αααααααααα
αααααΊα’αΆααααααΆααααααα½αααΆαααΈ VNI 20000 ααΆα RTs ααΈαα
αααα»αααΌαααααΉαα’αααααΆααααΌααααααΆαααα½αααΈααΆαα’αΆαααααααααΆααα
αΌααα
αααα»αααΆααΆα BGP ααΆαα½αααΉααα·ααα
ααααΌααααααΆααααααΆαααα
αααα»αααΆαααααα VRF (ααααΎαααΆαααΆαααΆααααα»αααααΆαααααα·α
ααα»ααααααΎαααΉααα·αα
αΌααα
αααα»αα’αααααααααα)α
RT αααα½αααΆααααΌαααΆααααααΎαα‘αΎααααααΌαααααα AS:VNI (ααααα·αααΎααααααααααααααααα·ααααΌαααΆαααααΎ) α
α§ααΆα αααααααΆααααααΎα RT αα αααα»αααααααααααααααααα· αα·ααααααα
vrf context PROD
address-family ipv4 unicast
route-target import auto - Π°Π²ΡΠΎΠΌΠ°ΡΠΈΡΠ΅ΡΠΊΠΈΠΉ ΡΠ΅ΠΆΠΈΠΌ ΡΠ°Π±ΠΎΡΡ
route-target export 65001:20000 - ΡΡΡΠ½ΠΎΠΉ ΡΠ΅ΠΆΠΈΠΌ ΡΠΎΡΠΌΠΈΡΠΎΠ²Π°Π½ΠΈΡ RT
ααΆαααααα α’αααα’αΆα
ααΎαααΎαααΆαααΎααΆαα»αααααααΈ VNI ααααααααααΆαααααα RT ααΈαα
αα½ααααα»αα
αααααα½ααα 65001: 99000 ααΊααΆ L3 VNI ααααααα αααααΆα VNI αααααΊααΌα
ααααΆαα
ααΎααααΉαααΆααα’αα α αΎααααα·ααα
αααααα
αααΆααααΆαα
αΌαααααααΎααα
αααα»αααΆαααααα VRF αα»αααααααΉαα
αΌααα
αααα»αααΆααΆα BGP αααα’αΆα
ααΎαααΎαααΈααααααα
sh bgp l2vpn evpn
<.....>
Network Next Hop Metric LocPrf Weight Path
Route Distinguisher: 10.255.1.11:32777 (L2VNI 10000)
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
10.255.1.10 100 32768 i
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[32]:[192.168.10.10]/272
10.255.1.10 100 32768 i
*>l[3]:[0]:[32]:[10.255.1.10]/88
10.255.1.10 100 32768 i
Route Distinguisher: 10.255.1.21:32787
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.20.20]/272 ! ΠΡΠ΅ΡΠΈΠΊΡ ΠΏΠΎΠ»ΡΡΠ΅Π½Π½ΡΠΉ ΠΈΠ· VNI 20000
10.255.1.20 100 0 i
*>i 10.255.1.20 100 0 i
ααααα·αααΎααΎααααα‘ααααΎαααΆαα’αΆααααααααααα½αααΆαααΆαααααα·αααα ααΎαα’αΆα ααΎαααΆαα»ααααααααααΆα RTs ααΈαα
Leaf11# sh bgp l2vpn evpn 5001.0008.0007
BGP routing table information for VRF default, address family L2VPN EVPN
Route Distinguisher: 10.255.1.21:32787
BGP routing table entry for [2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.20.2
0]/272, version 5164
Paths: (2 available, best #2)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not i
n HW
Path type: internal, path is valid, not best reason: Neighbor Address, no labeled nexthop
AS-Path: NONE, path sourced internal to AS
10.255.1.20 (metric 81) from 10.255.1.102 (10.255.1.102)
Origin IGP, MED not set, localpref 100, weight 0
Received label 20000 99000 ! ΠΠ²Π° label Π΄Π»Ρ ΡΠ°Π±ΠΎΡΡ VxLAN
Extcommunity: RT:65001:20000 RT:65001:99000 SOO:10.255.1.20:0 ENCAP:8 ! ΠΠ²Π° Π·Π½Π°ΡΠ΅Π½ΠΈΡ Route-target, Π½Π° ΠΎΡΠ½ΠΎΠ²Π΅, ΠΊΠΎΡΠΎΡΡΡ
Π΄ΠΎΠ±Π°Π²ΠΈΠ»ΠΈ Π΄Π°Π½Π½ΡΠΉ ΠΏΡΠ΅ΡΠΈΠΊΡ
Router MAC:5001.0005.0007
Originator: 10.255.1.21 Cluster list: 10.255.1.102
<......>
αα αααα»αααΆααΆαααΆαααααΌααα ααΎ Leaf-1 α’αααααα’αΆα ααΎααα»ααααα 192.168.20.20/32α
Leaf11# sh ip route vrf PROD
192.168.10.0/24, ubest/mbest: 1/0, attached
*via 192.168.10.1, Vlan10, [0/0], 01:29:28, direct
192.168.10.1/32, ubest/mbest: 1/0, attached
*via 192.168.10.1, Vlan10, [0/0], 01:29:28, local
192.168.10.10/32, ubest/mbest: 1/0, attached
*via 192.168.10.10, Vlan10, [190/0], 01:27:22, hmm
192.168.20.20/32, ubest/mbest: 1/0 ! ΠΠ΄ΡΠ΅Ρ Host-2
*via 10.255.1.20%default, [200/0], 01:20:20, bgp-65001, internal, tag 65001 ! ΠΠΎΡΡΡΠΏΠ½ΡΠΉ ΡΠ΅ΡΠ΅Π· Leaf-2
(evpn) segid: 99000 tunnelid: 0xaff0114 encap: VXLAN ! Π§Π΅ΡΠ΅Π· VNI 99000
ααααααααΆαααα»αααααα
αααααααααΆαα 192.168.20.0/24 αα
αααα»αααΆααΆαααΆαααααΌα?
ααααΌαα αΎα ααΆαααα·ααα
ααΈαααααα αααααΊ Leafs ααΈα
ααααΆαααα½αααΆαααααααΆαααα’αααΈαααΆαααΈααααααΆααα
ααΎαααααΆαααααα’αααα α αΎααααααΊααΆα’αΆαααααα·αα·ααΆααααΉαααααΌαα ααΆαααΎ αα
αααα»αααΆαα’αΆαααααααΆααα’αα α’αααα’αΆα
ααΎαααααααΆααααααααΆαα½αααααΉαααΆααα MAC/IP α αα·αααΆααα»ααααααααααααΌααα·ααΆαα’αααΈα
αααααΊααΆαα·ααΈααΆα Host Mobility Manager (HMM) ααααααααααΆααΆα ARP αααααΆααΆα BGP ααααΌαααΆαααααααααααα (ααΎαααΉααα»αα ααααααΎαααΆαααααααα»ααααααααααααα’αααααααα)α αααααα’ααααΎααααααΆααααααα½αααΆαααΈ HMM ααααΌααααααα 2 EVPNs ααααΌαααΆααααααΎαα‘αΎα (αααααΌαααα MAC/IP) α
ααααααΆαααΆαααααα α»ααααΆαααΆααΎα αΆαααΆα αααααΌααααααΌαααααααΆαα’αααΈαα»ααααα?
αααααΆααααααααΆααααααααααααΆα EVPN route-type 5 - ααΆα’αα»ααααΆαα±ααα’αααααααΎαα»αααααααΆαααα address-family l2vpn evpn (ααααααααααΌαααααα
αααααααααααααΊααΆααααα
αααα»αααααααααΆαααα»ααααα
ααΎααααΈααααααα»ααααα α αΆαααΆα αααααΌααααααααα»ααααααα αααα»αααααΎαααΆα BGP αααααΆαα VRF αααααΉαααααΌαααΆαααααααααααΆαα
router bgp 65001
vrf PROD
address-family ipv4 unicast
redistribute direct route-map VNI20000 ! Π Π΄Π°Π½Π½ΠΎΠΌ ΡΠ»ΡΡΠ°Π΅ Π°Π½ΠΎΠ½ΡΠΈΡΡΠ΅ΠΌ ΠΏΡΠ΅ΡΠΈΠΊΡΡ ΠΏΠΎΠ΄ΠΊΠ»ΡΡΠ΅Π½ΠΈΠ΅ Π½Π΅ΠΏΠΎΡΡΠ΅Π΄ΡΡΠ²Π΅Π½Π½ΠΎ ΠΊ Leaf Π² VNI 20000
route-map VNI20000 permit 10
match ip address prefix-list VNI20000_OUT ! Π£ΠΊΠ°Π·ΡΠ²Π°Π΅ΠΌ ΠΊΠ°ΠΊΠΎΠΉ ΠΈΡΠΏΠΎΠ»ΡΠ·ΠΎΠ²Π°ΡΡ prefix-list
ip prefix-list VNI20000_OUT seq 5 permit 192.168.20.0/24 ! Π£ΠΊΠ°Π·ΡΠ²Π°Π΅ΠΌ ΠΊΠ°ΠΊΠΈΠ΅ ΡΠ΅ΡΠΈ Π±ΡΠ΄ΡΡ ΠΏΠΎΠΏΠ°Π΄Π°ΡΡ Π² EVPN route-type 5
ααΆαααααα ααΆαα’αΆαααααααΉαααΆαα
ααΌααααα‘ααααΎαααΆααΆα BGP α ααααααααΈααΎααααααααααΌα EVPN 2,3 ααααΌααααααα 5 ααΆααααα αΆααααα½ααααααΆαααααααΆαα’αααΈααααααααΆαα
<......>
Network Next Hop Metric LocPrf Weight Path
Route Distinguisher: 10.255.1.11:3
* i[5]:[0]:[0]:[24]:[192.168.10.0]/224
10.255.1.10 0 100 0 ?
*>i 10.255.1.10 0 100 0 ?
Route Distinguisher: 10.255.1.11:32777
* i[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
10.255.1.10 100 0 i
*>i 10.255.1.10 100 0 i
* i[2]:[0]:[0]:[48]:[5001.0007.0007]:[32]:[192.168.10.10]/272
10.255.1.10 100 0 i
*>i 10.255.1.10 100 0 i
* i[3]:[0]:[32]:[10.255.1.10]/88
10.255.1.10 100 0 i
*>i 10.255.1.10 100 0 i
Route Distinguisher: 10.255.1.12:3
*>i[5]:[0]:[0]:[24]:[192.168.10.0]/224 ! EVPN route-type 5 Ρ Π½ΠΎΠΌΠ΅ΡΠΎΠΌ ΠΏΡΠ΅ΡΠΈΠΊΡΠ°
10.255.1.10 0 100 0 ?
* i
<.......>
αα»αααααααααΆαααα α αααα αααα»αααΆααΆαααΆαααααΌααααααα
Leaf21# sh ip ro vrf PROD
192.168.10.0/24, ubest/mbest: 1/0
*via 10.255.1.10%default, [200/0], 00:14:32, bgp-65001, internal, tag 65001 ! Π£Π΄Π°Π»Π΅Π½Π½ΡΠΉ ΠΏΡΠ΅ΡΠΈΠΊΡ, Π΄ΠΎΡΡΡΠΏΠ½ΡΠΉ ΡΠ΅ΡΠ΅Π· Leaf1/2(Π°Π΄ΡΠ΅Ρ Next-hop = virtual IP ΠΌΠ΅ΠΆΠ΄Ρ ΠΏΠ°ΡΠΎΠΉ VPC)
(evpn) segid: 99000 tunnelid: 0xaff010a encap: VXLAN ! ΠΡΠ΅ΡΠΈΠΊΡ Π΄ΠΎΡΡΡΠΏΠ΅Π½ ΡΠ΅ΡΠ΅Π· L3VNI 99000
192.168.10.10/32, ubest/mbest: 1/0
*via 10.255.1.10%default, [200/0], 02:33:40, bgp-65001, internal, tag 65001
(evpn) segid: 99000 tunnelid: 0xaff010a encap: VXLAN
192.168.20.0/24, ubest/mbest: 1/0, attached
*via 192.168.20.1, Vlan20, [0/0], 02:39:44, direct
192.168.20.1/32, ubest/mbest: 1/0, attached
*via 192.168.20.1, Vlan20, [0/0], 02:39:44, local
192.168.20.20/32, ubest/mbest: 1/0, attached
*via 192.168.20.20, Vlan20, [190/0], 02:35:46, hmm
ααααααα αααααααααΈααΈααααααααΈααα’ααααααα ααΎ VxLAN EVPN α αα ααααααααααΆαα ααΎαααΉααα·α αΆαααΆαααααΎααααααααααααΆααααΆααααααΌαααααΌααααΆα VRFs α
ααααα: www.habr.com