VxLAN ๊ณต์žฅ. 1 ๋ถ€

์•ˆ๋…•ํ•˜์„ธ์š”, ํ•˜๋ธŒ๋ฅด๋‹˜. ์ €๋Š” ํ˜„์žฌ OTUS ๋„คํŠธ์›Œํฌ ์—”์ง€๋‹ˆ์–ด ๊ณผ์ •์˜ ์ฝ”์Šค ๋ฆฌ๋”์ž…๋‹ˆ๋‹ค.
์ƒˆ๋กœ์šด ๊ณผ์ •์˜ ์‹œ์ž‘์„ ์˜ˆ์ƒํ•˜์—ฌ "๋„คํŠธ์›Œํฌ ์—”์ง€๋‹ˆ์–ด", VxLAN EVPN ๊ธฐ์ˆ ์— ๋Œ€ํ•œ ์ผ๋ จ์˜ ๊ธฐ์‚ฌ๋ฅผ ์ค€๋น„ํ–ˆ์Šต๋‹ˆ๋‹ค.

VxLAN EVPN์˜ ์ž‘๋™ ๋ฐฉ์‹์— ๋Œ€ํ•œ ์ž๋ฃŒ๊ฐ€ ๋ฐฉ๋Œ€ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ํ˜„๋Œ€ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ์—์„œ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•œ ๋‹ค์–‘ํ•œ ์ž‘์—…๊ณผ ์‚ฌ๋ก€๋ฅผ ์ˆ˜์ง‘ํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 1 ๋ถ€

VxLAN EVPN ๊ธฐ์ˆ ์— ๋Œ€ํ•œ ์‹œ๋ฆฌ์ฆˆ์˜ ์ฒซ ๋ฒˆ์งธ ๋ถ€๋ถ„์—์„œ๋Š” ๋„คํŠธ์›Œํฌ ํŒจ๋ธŒ๋ฆญ ์œ„์—์„œ ํ˜ธ์ŠคํŠธ ๊ฐ„์˜ L2 ์—ฐ๊ฒฐ์„ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์‚ดํŽด๋ณด๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  ์˜ˆ๋Š” Spine-Leaf ํ† ํด๋กœ์ง€๋กœ ์กฐ๋ฆฝ๋œ Cisco Nexus 9000v์—์„œ ์ˆ˜ํ–‰๋ฉ๋‹ˆ๋‹ค. ์ด ๊ธ€์—์„œ๋Š” Underlay ๋„คํŠธ์›Œํฌ ์„ค์ •์— ๋Œ€ํ•ด ์ž์„ธํžˆ ๋‹ค๋ฃจ์ง€ ์•Š๊ฒ ์Šต๋‹ˆ๋‹ค.

  1. ์–ธ๋”๋ ˆ์ด ๋„คํŠธ์›Œํฌ
  2. ์ฃผ์†Œ ๊ณ„์—ด l2vpn evpn์— ๋Œ€ํ•œ BGP ํ”ผ์–ด๋ง
  3. NVE ์„ค์ •
  4. ์–ต์ œ-arp

์–ธ๋”๋ ˆ์ด ๋„คํŠธ์›Œํฌ

์‚ฌ์šฉ๋œ ํ† ํด๋กœ์ง€๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 1 ๋ถ€

๋ชจ๋“  ์žฅ์น˜์— ์ฃผ์†Œ ์ง€์ •์„ ์„ค์ •ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

Spine-1 - 10.255.1.101
Spine-2 - 10.255.1.102

Leaf-11 - 10.255.1.11
Leaf-12 - 10.255.1.12
Leaf-21 - 10.255.1.21

Host-1 - 192.168.10.10
Host-2 - 192.168.10.20

๋ชจ๋“  ์žฅ์น˜ ๊ฐ„์— IP ์—ฐ๊ฒฐ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

Leaf21# sh ip route
<........>
10.255.1.11/32, ubest/mbest: 2/0                      ! Leaf-11 ะดะพัั‚ัƒะฟะตะฝ ั‡ะตะตั€ะท ะดะฒะฐ Spine
    *via 10.255.1.101, Eth1/4, [110/81], 00:00:03, ospf-UNDERLAY, intra
    *via 10.255.1.102, Eth1/3, [110/81], 00:00:03, ospf-UNDERLAY, intra
10.255.1.12/32, ubest/mbest: 2/0                      ! Leaf-12 ะดะพัั‚ัƒะฟะตะฝ ั‡ะตะตั€ะท ะดะฒะฐ Spine
    *via 10.255.1.101, Eth1/4, [110/81], 00:00:03, ospf-UNDERLAY, intra
    *via 10.255.1.102, Eth1/3, [110/81], 00:00:03, ospf-UNDERLAY, intra
10.255.1.21/32, ubest/mbest: 2/0, attached
    *via 10.255.1.22, Lo0, [0/0], 00:02:20, local
    *via 10.255.1.22, Lo0, [0/0], 00:02:20, direct
10.255.1.101/32, ubest/mbest: 1/0
    *via 10.255.1.101, Eth1/4, [110/41], 00:00:06, ospf-UNDERLAY, intra
10.255.1.102/32, ubest/mbest: 1/0
    *via 10.255.1.102, Eth1/3, [110/41], 00:00:03, ospf-UNDERLAY, intra

VPC ๋„๋ฉ”์ธ์ด ์ƒ์„ฑ๋˜์—ˆ๊ณ  ๋‘ ์Šค์œ„์น˜ ๋ชจ๋‘ ์ผ๊ด€์„ฑ ๊ฒ€์‚ฌ๋ฅผ ํ†ต๊ณผํ–ˆ์œผ๋ฉฐ ๋‘ ๋…ธ๋“œ์˜ ์„ค์ •์ด ๋™์ผํ•œ์ง€ ํ™•์ธํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

Leaf11# show vpc 

vPC domain id                     : 1
Peer status                       : peer adjacency formed ok
vPC keep-alive status             : peer is alive
Configuration consistency status  : success
Per-vlan consistency status       : success
Type-2 consistency status         : success
vPC role                          : primary
Number of vPCs configured         : 0
Peer Gateway                      : Disabled
Dual-active excluded VLANs        : -
Graceful Consistency Check        : Enabled
Auto-recovery status              : Disabled
Delay-restore status              : Timer is off.(timeout = 30s)
Delay-restore SVI status          : Timer is off.(timeout = 10s)
Operational Layer3 Peer-router    : Disabled

vPC status
----------------------------------------------------------------------------
Id    Port          Status Consistency Reason                Active vlans
--    ------------  ------ ----------- ------                ---------------
5     Po5           up     success     success               1

BGP ํ”ผ์–ด๋ง

๋งˆ์ง€๋ง‰์œผ๋กœ ์˜ค๋ฒ„๋ ˆ์ด ๋„คํŠธ์›Œํฌ ์„ค์ •์œผ๋กœ ๋„˜์–ด๊ฐˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ๊ธฐ์‚ฌ์˜ ์ผ๋ถ€๋กœ ์•„๋ž˜ ๋‹ค์ด์–ด๊ทธ๋žจ์— ํ‘œ์‹œ๋œ ๋Œ€๋กœ ํ˜ธ์ŠคํŠธ ๊ฐ„ ๋„คํŠธ์›Œํฌ๋ฅผ ๊ตฌ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 1 ๋ถ€

์˜ค๋ฒ„๋ ˆ์ด ๋„คํŠธ์›Œํฌ๋ฅผ ๊ตฌ์„ฑํ•˜๋ ค๋ฉด l2vpn evpn ์ œํ’ˆ๊ตฐ์„ ์ง€์›ํ•˜๋Š” Spine ๋ฐ Leaf ์Šค์œ„์น˜์—์„œ BGP๋ฅผ ํ™œ์„ฑํ™”ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

feature bgp
nv overlay evpn

๋‹ค์Œ์œผ๋กœ Leaf์™€ Spine ์‚ฌ์ด์— BGP ํ”ผ์–ด๋ง์„ ๊ตฌ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์„ค์ •์„ ๋‹จ์ˆœํ™”ํ•˜๊ณ  ๋ผ์šฐํŒ… ์ •๋ณด ๋ฐฐํฌ๋ฅผ ์ตœ์ ํ™”ํ•˜๊ธฐ ์œ„ํ•ด Spine์„ Route-Reflector ์„œ๋ฒ„๋กœ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. ์„ค์ •์„ ์ตœ์ ํ™”ํ•˜๊ธฐ ์œ„ํ•ด ํ…œํ”Œ๋ฆฟ์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ตฌ์„ฑ์— ๋ชจ๋“  Leaf๋ฅผ ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ Spine์˜ ์„ค์ •์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

router bgp 65001
  template peer LEAF 
    remote-as 65001
    update-source loopback0
    address-family l2vpn evpn
      send-community
      send-community extended
      route-reflector-client
  neighbor 10.255.1.11
    inherit peer LEAF
  neighbor 10.255.1.12
    inherit peer LEAF
  neighbor 10.255.1.21
    inherit peer LEAF

Leaf ์Šค์œ„์น˜์˜ ์„ค์ •์€ ๋น„์Šทํ•ฉ๋‹ˆ๋‹ค.

router bgp 65001
  template peer SPINE
    remote-as 65001
    update-source loopback0
    address-family l2vpn evpn
      send-community
      send-community extended
  neighbor 10.255.1.101
    inherit peer SPINE
  neighbor 10.255.1.102
    inherit peer SPINE

Spine์—์„œ ๋ชจ๋“  Leaf ์Šค์œ„์น˜์™€์˜ ํ”ผ์–ด๋ง์„ ํ™•์ธํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

Spine1# sh bgp l2vpn evpn summary
<.....>
Neighbor        V    AS MsgRcvd MsgSent   TblVer  InQ OutQ Up/Down  State/PfxRcd
10.255.1.11     4 65001       7       8        6    0    0 00:01:45 0
10.255.1.12     4 65001       7       7        6    0    0 00:01:16 0
10.255.1.21     4 65001       7       7        6    0    0 00:01:01 0

๋ณด์‹œ๋‹ค์‹œํ”ผ BGP์—๋Š” ๋ฌธ์ œ๊ฐ€ ์—†์—ˆ์Šต๋‹ˆ๋‹ค. VxLAN ์„ค์ •์œผ๋กœ ๋„˜์–ด ๊ฐ‘์‹œ๋‹ค. ์ถ”๊ฐ€ ๊ตฌ์„ฑ์€ ์Šค์œ„์น˜์˜ ๋ฆฌํ”„ ์ธก์—์„œ๋งŒ ์ˆ˜ํ–‰๋ฉ๋‹ˆ๋‹ค. Spine์€ ๋„คํŠธ์›Œํฌ์˜ ํ•ต์‹ฌ ์—ญํ• ๋งŒ ํ•˜๋ฉฐ ํŠธ๋ž˜ํ”ฝ ์ „์†ก์—๋งŒ ๊ด€์—ฌํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  ์บก์Šํ™” ๋ฐ ๊ฒฝ๋กœ ๊ฒฐ์ • ์ž‘์—…์€ ๋ฆฌํ”„ ์Šค์œ„์น˜์—์„œ๋งŒ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

NVE ์„ค์ •

NVE - ๋„คํŠธ์›Œํฌ ๊ฐ€์ƒ ์ธํ„ฐํŽ˜์ด์Šค

์„ค์ •์„ ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— ๋ช‡ ๊ฐ€์ง€ ์šฉ์–ด๋ฅผ ์†Œ๊ฐœํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

VTEP - VxLAN ํ„ฐ๋„์ด ์‹œ์ž‘๋˜๊ฑฐ๋‚˜ ๋๋‚˜๋Š” ์žฅ์น˜์ธ ๊ฐ€์ƒ ํ„ฐ๋„ ๋์ ์ž…๋‹ˆ๋‹ค. VTEP๊ฐ€ ๋ฐ˜๋“œ์‹œ ๋„คํŠธ์›Œํฌ ์žฅ์น˜์ผ ํ•„์š”๋Š” ์—†์Šต๋‹ˆ๋‹ค. VxLAN ๊ธฐ์ˆ ์„ ์ง€์›ํ•˜๋Š” ์„œ๋ฒ„๋Š” ์„œ๋ฒ„ ์—ญํ• ๋„ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์šฐ๋ฆฌ ํ† ํด๋กœ์ง€์—์„œ ๋ชจ๋“  ๋ฆฌํ”„ ์Šค์œ„์น˜๋Š” VTEP์ž…๋‹ˆ๋‹ค.

VNI - ๊ฐ€์ƒ ๋„คํŠธ์›Œํฌ ์ธ๋ฑ์Šค - VxLAN ๋‚ด์˜ ๋„คํŠธ์›Œํฌ ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค. VLAN์— ๋น„์œ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋ช‡ ๊ฐ€์ง€ ์ฐจ์ด์ ์ด ์žˆ์Šต๋‹ˆ๋‹ค. ํŒจ๋ธŒ๋ฆญ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ VLAN์€ ํ•˜๋‚˜์˜ ๋ฆฌํ”„ ์Šค์œ„์น˜ ๋‚ด์—์„œ๋งŒ ๊ณ ์œ ํ•ด์ง€๋ฉฐ ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ์ „์†ก๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๊ฐ VLAN์—๋Š” ์ด๋ฏธ ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ์ „์†ก๋œ VNI ๋ฒˆํ˜ธ๊ฐ€ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๊ฒƒ์ด ์–ด๋–ป๊ฒŒ ์ƒ๊ฒผ๋Š”์ง€, ์–ด๋–ป๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š”์ง€์— ๋Œ€ํ•ด์„œ๋Š” ๋” ์ž์„ธํžˆ ๋…ผ์˜ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

VxLAN ๊ธฐ์ˆ ์ด ์ž‘๋™ํ•˜๊ณ  VLAN ๋ฒˆํ˜ธ๋ฅผ VNI ๋ฒˆํ˜ธ์™€ ์—ฐ๊ฒฐํ•˜๋Š” ๊ธฐ๋Šฅ์„ ํ™œ์„ฑํ™”ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

feature nv overlay
feature vn-segment-vlan-based

VxLAN์˜ ๋™์ž‘์„ ๋‹ด๋‹นํ•˜๋Š” NVE ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ๊ตฌ์„ฑํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์ด ์ธํ„ฐํŽ˜์ด์Šค๋Š” VxLAN ํ—ค๋”์˜ ํ”„๋ ˆ์ž„ ์บก์Šํ™”๋ฅผ ๋‹ด๋‹นํ•ฉ๋‹ˆ๋‹ค. GRE์šฉ Tunnel ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋น„์œ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

interface nve1
  no shutdown
  host-reachability protocol bgp ! ะธัะฟะพะปัŒะทัƒะตะผ BGP ะดะปั ะฟะตั€ะตะดะฐั‡ะธ ะผะฐั€ัˆั€ัƒั‚ะฝะพะน ะธะฝั„ะพั€ะผะฐั†ะธะธ
  source-interface loopback0    ! ะธะฝั‚ะตั€ั„ะตะนั  ั ะบะพั‚ะพั€ะพะณะพ ะพั‚ะฟั€ะฐะฒะปัะตะผ ะฟะฐะบะตั‚ั‹ loopback0

Leaf-21 ์Šค์œ„์น˜์—์„œ๋Š” ๋ชจ๋“  ๊ฒƒ์ด ๋ฌธ์ œ ์—†์ด ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋ช…๋ น์˜ ์ถœ๋ ฅ์„ ํ™•์ธํ•˜๋ฉด show nve peers, ๊ทธ๋Ÿฌ๋ฉด ๋น„์–ด ์žˆ์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์„œ VPC ๊ตฌ์„ฑ์œผ๋กœ ๋Œ์•„๊ฐ€์•ผ ํ•ฉ๋‹ˆ๋‹ค. Leaf-11๊ณผ Leaf-12๋Š” ์Œ์œผ๋กœ ์ž‘๋™ํ•˜๊ณ  VPC ๋„๋ฉ”์ธ์œผ๋กœ ํ†ตํ•ฉ๋˜์–ด ์žˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ƒํ™ฉ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

Host-2๋Š” ํ•˜๋‚˜์˜ ํ”„๋ ˆ์ž„์„ Leaf-21๋กœ ์ „์†กํ•˜์—ฌ ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด Host-1๋กœ ์ „์†กํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ Leaf-21์€ ๋‘ ๊ฐœ์˜ VTEP๋ฅผ ํ†ตํ•ด ๋™์‹œ์— Host-1์˜ MAC ์ฃผ์†Œ์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Œ์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ Leaf-21์€ ์–ด๋–ป๊ฒŒ ํ•ด์•ผ ํ•ฉ๋‹ˆ๊นŒ? ๊ฒฐ๊ตญ ์ด๋Š” ๋„คํŠธ์›Œํฌ์— ๋ฃจํ”„๊ฐ€ ๋‚˜ํƒ€๋‚  ์ˆ˜ ์žˆ์Œ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ์ƒํ™ฉ์„ ํ•ด๊ฒฐํ•˜๋ ค๋ฉด Leaf-11๊ณผ Leaf-12๋„ ๊ณต์žฅ ๋‚ด์—์„œ ํ•˜๋‚˜์˜ ์žฅ์น˜๋กœ ์ž‘๋™ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ํ•ด๊ฒฐ์ฑ…์€ ๋งค์šฐ ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค. ํ„ฐ๋„์„ ๊ตฌ์ถ•ํ•˜๋Š” ๋ฃจํ”„๋ฐฑ ์ธํ„ฐํŽ˜์ด์Šค์— ๋ณด์กฐ ์ฃผ์†Œ๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. ๋ณด์กฐ ์ฃผ์†Œ๋Š” ๋‘ VTEP ๋ชจ๋‘์—์„œ ๋™์ผํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

interface loopback0
 ip add 10.255.1.10/32 secondary

๋”ฐ๋ผ์„œ ๋‹ค๋ฅธ VTEP์˜ ๊ด€์ ์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ† ํด๋กœ์ง€๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 1 ๋ถ€

์ฆ‰, ์ด์ œ Leaf-21์˜ IP ์ฃผ์†Œ์™€ ๋‘ Leaf-11๊ณผ Leaf-12 ์‚ฌ์ด์˜ ๊ฐ€์ƒ IP ์‚ฌ์ด์— ํ„ฐ๋„์ด ๊ตฌ์ถ•๋ฉ๋‹ˆ๋‹ค. ์ด์ œ ๋‘ ์žฅ์น˜์—์„œ MAC ์ฃผ์†Œ๋ฅผ ๋ฐฐ์šฐ๋Š” ๋ฐ ๋ฌธ์ œ๊ฐ€ ์—†์œผ๋ฉฐ ํŠธ๋ž˜ํ”ฝ์ด ํ•œ VTEP์—์„œ ๋‹ค๋ฅธ VTEP๋กœ ์ด๋™ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‘ VTEP ์ค‘ ์–ด๋Š ๊ฒƒ์ด ํŠธ๋ž˜ํ”ฝ์„ ์ฒ˜๋ฆฌํ• ์ง€๋Š” Spine์˜ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ฒฐ์ •๋ฉ๋‹ˆ๋‹ค.

Spine1# sh ip route
<.....>
10.255.1.10/32, ubest/mbest: 2/0
    *via 10.255.1.11, Eth1/1, [110/41], 1d01h, ospf-UNDERLAY, intra
    *via 10.255.1.12, Eth1/2, [110/41], 1d01h, ospf-UNDERLAY, intra
10.255.1.11/32, ubest/mbest: 1/0
    *via 10.255.1.11, Eth1/1, [110/41], 1d22h, ospf-UNDERLAY, intra
10.255.1.12/32, ubest/mbest: 1/0
    *via 10.255.1.12, Eth1/2, [110/41], 1d01h, ospf-UNDERLAY, intra

์œ„์—์„œ ๋ณผ ์ˆ˜ ์žˆ๋“ฏ์ด ์ฃผ์†Œ 10.255.1.10์€ ๋‘ ๊ฐœ์˜ Next-hop์„ ํ†ตํ•ด ์ฆ‰์‹œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

์ด ๋‹จ๊ณ„์—์„œ๋Š” ๊ธฐ๋ณธ์ ์ธ ์—ฐ๊ฒฐ์„ฑ์„ ๋‹ค๋ฃจ์—ˆ์Šต๋‹ˆ๋‹ค. NVE ์ธํ„ฐํŽ˜์ด์Šค ์„ค์ •์œผ๋กœ ๋„˜์–ด ๊ฐ‘์‹œ๋‹ค.
Vlan 10์„ ์ฆ‰์‹œ ํ™œ์„ฑํ™”ํ•˜๊ณ  ์ด๋ฅผ ํ˜ธ์ŠคํŠธ์˜ ๊ฐ ๋ฆฌํ”„์—์„œ VNI 10000๊ณผ ์—ฐ๊ฒฐํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ํ˜ธ์ŠคํŠธ ๊ฐ„ L2 ํ„ฐ๋„์„ ์„ค์ •ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

vlan 10                 ! ะ’ะบะปัŽั‡ะฐะตะผ VLAN ะฝะฐ ะฒัะตั… VTEP ะฟะพะดะบะปัŽั‡ะตะฝะฝั‹ั… ะบ ะฝะตะพะฑั…ะพะดะธะผั‹ะผ ั…ะพัั‚ะฐะผ
  vn-segment 10000      ! ะััะพั†ะธะธั€ัƒะตะผ VLAN ั ะฝะพะผะตั€ VNI 

interface nve1
  member vni 10000      ! ะ”ะพะฑะฐะฒะปัะตะผ VNI 10000 ะดะปั ั€ะฐะฑะพั‚ั‹ ั‡ะตั€ะตะท ะธะฝั‚ะตั€ั„ะตะนั NVE. ะดะปั ะธะฝะบะฐะฟััƒะปัั†ะธะธ ะฒ VxLAN
    ingress-replication protocol bgp    ! ัƒะบะฐะทั‹ะฒะฐะตะผ, ั‡ั‚ะพ ะดะปั ั€ะฐัะฟั€ะพัั‚ั€ะฐะฝะตะฝะธั ะธะฝั„ะพั€ะผะฐั†ะธะธ ะพ ั…ะพัั‚ะต ะธัะฟะพะปัŒะทัƒะตะผ BGP

์ด์ œ nve ํ”ผ์–ด์™€ BGP EVPN ํ…Œ์ด๋ธ”์„ ํ™•์ธํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

Leaf21# sh nve peers
Interface Peer-IP          State LearnType Uptime   Router-Mac
--------- ---------------  ----- --------- -------- -----------------
nve1      10.255.1.10      Up    CP        00:00:41 n/a                 ! ะ’ะธะดะธะผ ั‡ั‚ะพ peer ะดะพัั‚ัƒะฟะตะฝ ั secondary ะฐะดั€ะตัะฐ

Leaf11# sh bgp l2vpn evpn

   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)        ! ะžั‚ ะบะพะณะพ ะธะผะตะฝะฝะพ ะฟั€ะธัˆะตะป ัั‚ะพั‚ l2VNI
*>l[3]:[0]:[32]:[10.255.1.10]/88                                   ! EVPN route-type 3 - ะฟะพะบะฐะทั‹ะฒะฐะตั‚ ะฝะฐัˆะตะณะพ ัะพัะตะดะฐ, ะบะพั‚ะพั€ั‹ะน ั‚ะฐะบ ะถะต ะทะฝะฐะตั‚ ะพะฑ l2VNI10000
                      10.255.1.10                       100      32768 i
*>i[3]:[0]:[32]:[10.255.1.20]/88
                      10.255.1.20                       100          0 i
* i                   10.255.1.20                       100          0 i

Route Distinguisher: 10.255.1.21:32777
* i[3]:[0]:[32]:[10.255.1.20]/88
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i

์œ„์—๋Š” EVPN ๊ฒฝ๋กœ ์œ ํ˜• 3๊ฐœ ๊ฒฝ๋กœ๋งŒ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. ์ด ์œ ํ˜•์˜ ๊ฒฝ๋กœ๋Š” ํ”ผ์–ด(Leaf)์— ๋Œ€ํ•ด ์ด์•ผ๊ธฐํ•˜์ง€๋งŒ ํ˜ธ์ŠคํŠธ๋Š” ์–ด๋””์— ์žˆ์Šต๋‹ˆ๊นŒ?
๋ฌธ์ œ๋Š” MAC ํ˜ธ์ŠคํŠธ์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ EVPN ๊ฒฝ๋กœ ์œ ํ˜• 2๋ฅผ ํ†ตํ•ด ์ „์†ก๋œ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

ํ˜ธ์ŠคํŠธ๋ฅผ ๋ณด๋ ค๋ฉด EVPN ๊ฒฝ๋กœ ์œ ํ˜• 2๋ฅผ ๊ตฌ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

evpn
  vni 10000 l2
    route-target import auto   ! ะฒ ั€ะฐะผะบะฐั… ะดะฐะฝะฝะพะน ัั‚ะฐั‚ัŒะธ ะธัะฟะพะปัŒะทัƒะตะผ ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธะน ะฝะพะผะตั€ ะดะปั route-target
    route-target export auto

Host-2์—์„œ Host-1๋กœ ping์„ ๋ณด๋‚ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

Firewall2# ping 192.168.10.1
PING 192.168.10.1 (192.168.10.1): 56 data bytes
36 bytes from 192.168.10.2: Destination Host Unreachable
Request 0 timed out
64 bytes from 192.168.10.1: icmp_seq=1 ttl=254 time=215.555 ms
64 bytes from 192.168.10.1: icmp_seq=2 ttl=254 time=38.756 ms
64 bytes from 192.168.10.1: icmp_seq=3 ttl=254 time=42.484 ms
64 bytes from 192.168.10.1: icmp_seq=4 ttl=254 time=40.983 ms

์•„๋ž˜์—์„œ๋Š” ํ˜ธ์ŠคํŠธ MAC ์ฃผ์†Œ๊ฐ€ ์žˆ๋Š” ๊ฒฝ๋กœ ์œ ํ˜• 2๊ฐ€ BGP ํ…Œ์ด๋ธ”(5001.0007.0007 ๋ฐ 5001.0008.0007)์— ๋‚˜ํƒ€๋‚˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Leaf11# sh bgp l2vpn evpn
<......>

   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216                      !  evpn route-type 2 ะธ mac ะฐะดั€ะตั ั…ะพัั‚ะฐ 1
                      10.255.1.10                       100      32768 i
*>i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216                      ! evpn route-type 2 ะธ mac ะฐะดั€ะตั ั…ะพัั‚ะฐ 2
* i                   10.255.1.20                       100          0 i
*>l[3]:[0]:[32]:[10.255.1.10]/88
                      10.255.1.10                       100      32768 i
Route Distinguisher: 10.255.1.21:32777
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i

๋‹ค์Œ์œผ๋กœ MAC ํ˜ธ์ŠคํŠธ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๋ฐ›์€ ์—…๋ฐ์ดํŠธ์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์ •๋ณด๋ฅผ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜๋Š” ๋ช…๋ น ์ถœ๋ ฅ์˜ ์ „๋ถ€๋Š” ์•„๋‹™๋‹ˆ๋‹ค.

Leaf21# sh bgp l2vpn evpn 5001.0007.0007

BGP routing table information for VRF default, address family L2VPN EVPN
Route Distinguisher: 10.255.1.11:32777        !  ะพั‚ะฟั€ะฐะฒะธะป Update ั MAC Host. ะะต ะฒะธั€ั‚ัƒะฐะปัŒะฝั‹ะน ะฐะดั€ะตั VPC, ะฐ ะฐะดั€ะตั Leaf
BGP routing table entry for [2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216,
 version 1507
Paths: (2 available, best #2)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not i
n HW

  Path type: internal, path is valid, not best reason: Neighbor Address, no labe
led nexthop
  AS-Path: NONE, path sourced internal to AS
    10.255.1.10 (metric 81) from 10.255.1.102 (10.255.1.102)    ! ั ะบะตะผ ะธะผะตะฝะฝะพ ัั‚ั€ะพะธะผ VxLAN ั‚ะพะฝะฝะตะปัŒ
      Origin IGP, MED not set, localpref 100, weight 0
      Received label 10000         ! ะะพะผะตั€ VNI, ะบะพั‚ะพั€ั‹ะน ะฐััะพั†ะธะธั€ะพะฒะฐะฝ ั VLAN, ะฒ ะบะพั‚ะพั€ะพะผ ะฝะฐั…ะพะดะธั‚ัั Host
      Extcommunity: RT:65001:10000 SOO:10.255.1.10:0 ENCAP:8        ! ะขัƒั‚ ะฒะธะดะฝะพ, ั‡ั‚ะพ RT ัั„ะพั€ะผะธั€ะพะฒะฐะปัั ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธ ะฝะฐ ะพัะฝะพะฒะต ะฝะพะผะตั€ะพะฒ AS ะธ VNI
      Originator: 10.255.1.11 Cluster list: 10.255.1.102
<........>

ํ”„๋ ˆ์ž„์ด ๊ณต์žฅ์„ ํ†ต๊ณผํ•  ๋•Œ ์–ด๋–ค ๋ชจ์Šต์ธ์ง€ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 1 ๋ถ€

ARP ์–ต์ œ

์ข‹์Šต๋‹ˆ๋‹ค. ์ด์ œ ํ˜ธ์ŠคํŠธ ๊ฐ„ L2 ํ†ต์‹ ์ด ๊ฐ€๋Šฅํ•ด์กŒ์œผ๋ฉฐ ์—ฌ๊ธฐ์„œ ๋งˆ๋ฌด๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋ชจ๋“  ๊ฒƒ์ด ๊ทธ๋ ‡๊ฒŒ ๋‹จ์ˆœํ•˜์ง€๋Š” ์•Š์Šต๋‹ˆ๋‹ค. ํ˜ธ์ŠคํŠธ๊ฐ€ ์ ์œผ๋ฉด ๋ฌธ์ œ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์ˆ˜๋ฐฑ, ์ˆ˜์ฒœ ๊ฐœ์˜ ํ˜ธ์ŠคํŠธ๊ฐ€ ์žˆ๋Š” ์ƒํ™ฉ์„ ์ƒ์ƒํ•ด ๋ด…์‹œ๋‹ค. ์šฐ๋ฆฌ๋Š” ์–ด๋–ค ๋ฌธ์ œ์— ์ง๋ฉดํ•˜๊ฒŒ ๋ ๊นŒ์š”?

์ด ๋ฌธ์ œ๋Š” BUM(Broadcast, Unknown Unicast, Multicast) ํŠธ๋ž˜ํ”ฝ์ž…๋‹ˆ๋‹ค. ์ด ๊ธฐ์‚ฌ์—์„œ๋Š” ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ํŠธ๋ž˜ํ”ฝ์„ ์ฒ˜๋ฆฌํ•˜๋Š” ์˜ต์…˜์„ ๊ณ ๋ คํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.
์ด๋”๋„ท ๋„คํŠธ์›Œํฌ์˜ ์ฃผ์š” ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ์ƒ์„ฑ๊ธฐ๋Š” ARP ํ”„๋กœํ† ์ฝœ์„ ํ†ตํ•œ ํ˜ธ์ŠคํŠธ ์ž์ฒด์ž…๋‹ˆ๋‹ค.

Nexus๋Š” ARP ์š”์ฒญ์— ๋Œ€์ฒ˜ํ•˜๊ธฐ ์œ„ํ•ด Suppress-arp๋ผ๋Š” ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ๊ตฌํ˜„ํ•ฉ๋‹ˆ๋‹ค.
์ด ๊ธฐ๋Šฅ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

  1. ํ˜ธ์ŠคํŠธ-1์€ ๋„คํŠธ์›Œํฌ์˜ ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ์ฃผ์†Œ๋กœ APR ์š”์ฒญ์„ ๋ณด๋ƒ…๋‹ˆ๋‹ค.
  2. ์š”์ฒญ์€ ๋ฆฌํ”„ ์Šค์œ„์น˜์— ๋„๋‹ฌํ•˜๊ณ  ์ด ์š”์ฒญ์„ Host-2๋ฅผ ํ–ฅํ•œ ํŒจ๋ธŒ๋ฆญ์œผ๋กœ ์ „๋‹ฌํ•˜๋Š” ๋Œ€์‹  ๋ฆฌํ”„๋Š” ์Šค์Šค๋กœ ์‘๋‹ตํ•˜๊ณ  ํ•„์š”ํ•œ IP ๋ฐ MAC๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ์š”์ฒญ์ด ๊ณต์žฅ์œผ๋กœ ์ „๋‹ฌ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ Leaf๊ฐ€ MAC ์ฃผ์†Œ๋งŒ ์•Œ๊ณ  ์žˆ๋‹ค๋ฉด ์ด๊ฒƒ์ด ์–ด๋–ป๊ฒŒ ์ž‘๋™ํ•  ์ˆ˜ ์žˆ์„๊นŒ์š”?

๋ชจ๋“  ๊ฒƒ์ด ๋งค์šฐ ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค. EVPN ๊ฒฝ๋กœ ์œ ํ˜• 2๋Š” MAC ์ฃผ์†Œ ์™ธ์— MAC/IP ์กฐํ•ฉ์„ ์ „์†กํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ํ•˜๋ ค๋ฉด ๋ฆฌํ”„์˜ VLAN์—์„œ IP ์ฃผ์†Œ๋ฅผ ๊ตฌ์„ฑํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์งˆ๋ฌธ์ด ์ƒ๊น๋‹ˆ๋‹ค. ์–ด๋–ค IP๋ฅผ ์„ค์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๊นŒ? ๋„ฅ์„œ์Šค์—์„œ๋Š” ๋ชจ๋“  ์Šค์œ„์น˜์— ๋ถ„์‚ฐ(๋™์ผ) ์ฃผ์†Œ๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

feature interface-vlan

fabric forwarding anycast-gateway-mac 0001.0001.0001    ! ะทะฐะดะฐะตะผ virtual mac ะดะปั ัะพะทะดะฐะฝะธั ั€ะฐัะฟั€ะตะดะตะปะตะฝะฝะพะณะพ ัˆะปัŽะทะฐ ะผะตะถะดัƒ ะฒัะตะผะธ ะบะพะผะผัƒั‚ะฐั‚ะพั€ะฐะผะธ

interface Vlan10
  no shutdown
  ip address 192.168.10.254/24          ! ะฝะฐ ะฒัะตั… Leaf ะทะฐะดะฐะตะผ ะพะดะธะฝะฐะบะพะฒั‹ะน IP
  fabric forwarding mode anycast-gateway    ! ะณะพะฒะพั€ะธะผ ะธัะฟะพะปัŒะทะพะฒะฐั‚ัŒ Virtual mac

๋”ฐ๋ผ์„œ ํ˜ธ์ŠคํŠธ์˜ ๊ด€์ ์—์„œ ๋ณด๋ฉด ๋„คํŠธ์›Œํฌ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 1 ๋ถ€

BGP l2route evpn์„ ํ™•์ธํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

Leaf11# sh bgp l2vpn evpn
<......>

   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
                      10.255.1.21                       100      32768 i
*>i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216
                      10.255.1.10                       100          0 i
* i                   10.255.1.10                       100          0 i
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.10.20]/248
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i

<......>

Route Distinguisher: 10.255.1.21:32777
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[0]:[0.0.0.0]/216
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.10.20]/248
*>i                   10.255.1.20                       100          0 i

<......>

๋ช…๋ น ์ถœ๋ ฅ์—์„œ โ€‹โ€‹EVPN ๊ฒฝ๋กœ ์œ ํ˜• 2์—์„œ MAC ์™ธ์—๋„ ์ด์ œ ํ˜ธ์ŠคํŠธ IP ์ฃผ์†Œ๋„ ํ‘œ์‹œ๋˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Suppress-arp ์„ค์ •์œผ๋กœ ๋Œ์•„๊ฐ€ ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์ด ์„ค์ •์€ ๊ฐ VNI์— ๋Œ€ํ•ด ๊ฐœ๋ณ„์ ์œผ๋กœ ํ™œ์„ฑํ™”๋ฉ๋‹ˆ๋‹ค.

interface nve1
  member vni 10000   
    suppress-arp

๊ทธ๋Ÿฌ๋ฉด ์•ฝ๊ฐ„์˜ ๋ณต์žก์„ฑ์ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

  • ์ด ๊ธฐ๋Šฅ์ด ์ž‘๋™ํ•˜๋ ค๋ฉด TCAM ๋ฉ”๋ชจ๋ฆฌ ๊ณต๊ฐ„์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ์€ Suppress-arp ์„ค์ •์˜ ์˜ˆ์ž…๋‹ˆ๋‹ค.

hardware access-list tcam region arp-ether 256

์ด ์„ค์ •์—๋Š” ์ด์ค‘ ๋„ˆ๋น„๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์ฆ‰, 256์„ ์„ค์ •ํ•œ ๊ฒฝ์šฐ TCAM์—์„œ 512๋ฅผ ํ•ด์ œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. TCAM ์„ค์ •์€ ์‚ฌ์šฉ์ž์—๊ฒŒ ํ• ๋‹น๋œ ์ž‘์—…์—๋งŒ ์˜์กดํ•˜๊ณ  ๋„คํŠธ์›Œํฌ๋งˆ๋‹ค ๋‹ค๋ฅผ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ TCAM ์„ค์ •์€ ์ด ๊ธฐ์‚ฌ์˜ ๋ฒ”์œ„๋ฅผ ๋ฒ—์–ด๋‚ฉ๋‹ˆ๋‹ค.

  • Suppress-arp ๊ตฌํ˜„์€ ๋ชจ๋“  ๋ฆฌํ”„ ์Šค์œ„์น˜์—์„œ ์ˆ˜ํ–‰๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ VPC ๋„๋ฉ”์ธ์— ์žˆ๋Š” ๋ฆฌํ”„ ์Œ์— ๊ตฌ์„ฑํ•  ๋•Œ ๋ณต์žก์„ฑ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. TCAM์ด ๋ณ€๊ฒฝ๋˜๋ฉด ์Œ ๊ฐ„์˜ ์ผ๊ด€์„ฑ์ด ๊นจ์ง€๊ณ  ํ•œ ๋…ธ๋“œ๊ฐ€ ์ž‘๋™ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ TCAM ๋ณ€๊ฒฝ ์„ค์ •์„ ์ ์šฉํ•˜๋ ค๋ฉด ์žฅ์น˜๋ฅผ ์žฌ๋ถ€ํŒ…ํ•ด์•ผ ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

๋”ฐ๋ผ์„œ ํ˜„์žฌ ์ƒํ™ฉ์—์„œ ์ด ์„ค์ •์„ ์‹คํ–‰ ์ค‘์ธ ํŒฉํ† ๋ฆฌ์— ๊ตฌํ˜„ํ•˜๋Š” ๊ฒƒ์ด ๊ฐ€์น˜๊ฐ€ ์žˆ๋Š”์ง€ ์‹ ์ค‘ํ•˜๊ฒŒ ๊ณ ๋ คํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ด๊ฒƒ์œผ๋กœ ์‹œ๋ฆฌ์ฆˆ์˜ ์ฒซ ๋ฒˆ์งธ ๋ถ€๋ถ„์„ ๋งˆ์นฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ๋ถ€๋ถ„์—์„œ๋Š” ๋„คํŠธ์›Œํฌ๋ฅผ ์„œ๋กœ ๋‹ค๋ฅธ VRF๋กœ ๋ถ„๋ฆฌํ•˜์—ฌ VxLAN ํŒจ๋ธŒ๋ฆญ์„ ํ†ตํ•œ ๋ผ์šฐํŒ…์„ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

์ด์ œ ๋‚˜๋Š” ๋ชจ๋‘๋ฅผ ์ดˆ๋Œ€ํ•ฉ๋‹ˆ๋‹ค ๋ฌด๋ฃŒ ์›น ์„ธ๋ฏธ๋‚˜, ๊ทธ ์•ˆ์—์„œ ์ฝ”์Šค์— ๋Œ€ํ•ด ์ž์„ธํžˆ ์„ค๋ช…ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ๋ณธ ์›จ๋น„๋‚˜์— ๋“ฑ๋กํ•˜๋Š” ์„ ์ฐฉ์ˆœ 20๋ช…์˜ ์ฐธ๊ฐ€์ž๋Š” ๋ฐฉ์†ก ํ›„ 1~2์ผ ์ด๋‚ด์— ์ด๋ฉ”์ผ์„ ํ†ตํ•ด ํ• ์ธ ์ธ์ฆ์„œ๋ฅผ ๋ฐ›๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€