VxLAN ๊ณต์žฅ. 2 ๋ถ€

ํ—ค์ด ํ•˜๋ธŒ๋ฅด. ๋‚˜๋Š” VxLAN EVPN ๊ธฐ์ˆ ์— ๋Œ€ํ•œ ์ผ๋ จ์˜ ๊ธฐ์‚ฌ๋ฅผ ๊ณ„์†ํ•ฉ๋‹ˆ๋‹ค. ์ฝ”์Šค ์‹œ์ž‘์„ ์œ„ํ•ด ํŠน๋ณ„ํžˆ ์ž‘์„ฑ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. "๋„คํŠธ์›Œํฌ ์—”์ง€๋‹ˆ์–ด" ์˜คํˆฌ์Šค์— ์˜ํ•ด. ๊ทธ๋ฆฌ๊ณ  ์˜ค๋Š˜ ์šฐ๋ฆฌ๋Š” ๋ผ์šฐํŒ… ์ž‘์—…์˜ ํฅ๋ฏธ๋กœ์šด ๋ถ€๋ถ„์„ ๊ณ ๋ คํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์•„๋ฌด๋ฆฌ ์ง„๋ถ€ํ•˜๊ฒŒ ๋“ค๋ฆฌ๋”๋ผ๋„ ๋„คํŠธ์›Œํฌ ํŒฉํ† ๋ฆฌ ์ž‘์—…์˜ ์ผ๋ถ€๋กœ ๋ชจ๋“  ๊ฒƒ์ด ๊ทธ๋ ‡๊ฒŒ ๊ฐ„๋‹จํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 2 ๋ถ€

์ฃผ๊ธฐ์˜ ํ•œ ๋ถ€๋ถ„ - ์„œ๋ฒ„ ๊ฐ„ L1 ์—ฐ๊ฒฐ

๋งˆ์ง€๋ง‰ ๋ถ€๋ถ„์—์„œ๋Š” Nexus 9000v์˜ ๋„คํŠธ์›Œํฌ ํŒจ๋ธŒ๋ฆญ ์œ„์— ๊ตฌ์ถ•๋œ ํ•˜๋‚˜์˜ ๋ธŒ๋กœ๋“œ์บ์ŠคํŠธ ๋„๋ฉ”์ธ์„ ๋‹ฌ์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ด๊ฒƒ์€ ๋ฐ์ดํ„ฐ ์„ผํ„ฐ ๋„คํŠธ์›Œํฌ์˜ ํ”„๋ ˆ์ž„์›Œํฌ ๋‚ด์—์„œ ํ•ด๊ฒฐํ•ด์•ผ ํ•˜๋Š” ์ „์ฒด ์ž‘์—… ๋ฒ”์œ„๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ์˜ค๋Š˜ ์šฐ๋ฆฌ๋Š” ๋„คํŠธ์›Œํฌ ๊ฐ„ ๋˜๋Š” VNI ๊ฐ„ ๋ผ์šฐํŒ…๊ณผ ๊ฐ™์€ ์ž‘์—…์„ ๊ณ ๋ คํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

Spine-Leaf ํ† ํด๋กœ์ง€๊ฐ€ ์‚ฌ์šฉ๋จ์„ ์ƒ๊ธฐ์‹œ์ผœ ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 2 ๋ถ€

๋จผ์ € ๋ผ์šฐํŒ…์ด ์–ด๋–ป๊ฒŒ ๋ฐœ์ƒํ•˜๊ณ  ์–ด๋–ค ๊ธฐ๋Šฅ์ด ์žˆ๋Š”์ง€ ๋ถ„์„ํ•ฉ๋‹ˆ๋‹ค.

์ดํ•ด๋ฅผ ๋•๊ธฐ ์œ„ํ•ด ๋…ผ๋ฆฌ ๋‹ค์ด์–ด๊ทธ๋žจ์„ ๋‹จ์ˆœํ™”ํ•˜๊ณ  Host-20000์šฉ VNI 2์„ ์ถ”๊ฐ€ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ๊ฒฐ๊ณผ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 2 ๋ถ€

์ด ๊ฒฝ์šฐ ํ•œ ํ˜ธ์ŠคํŠธ์—์„œ ๋‹ค๋ฅธ ํ˜ธ์ŠคํŠธ๋กœ ์–ด๋–ป๊ฒŒ ํŠธ๋ž˜ํ”ฝ์„ ์ „์†กํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?

๋‘ ๊ฐ€์ง€ ์˜ต์…˜์ด ์žˆ์Šต๋‹ˆ๋‹ค :

  1. ๋ชจ๋“  ๋ฆฌํ”„ ์Šค์œ„์น˜์˜ ๋ชจ๋“  VNI์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์œ ์ง€ํ•˜๋ฉด ๋ชจ๋“  ๋ผ์šฐํŒ…์ด ๋„คํŠธ์›Œํฌ์˜ ์ฒซ ๋ฒˆ์งธ ๋ฆฌํ”„์—์„œ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.
  2. ์ „์šฉ ์‚ฌ์šฉ - L3 VNI

์ฒซ ๋ฒˆ์งธ ๋ฐฉ๋ฒ•์€ ๊ฐ„๋‹จํ•˜๊ณ  ํŽธ๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  ๋ฆฌํ”„ ์Šค์œ„์น˜์—์„œ ๋ชจ๋“  VNI๋งŒ ์‹œ์ž‘ํ•˜๋ฉด ๋˜๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ „์ฒด ๋ฆฌํ”„์—์„œ ์ˆ˜๋ฐฑ ๋˜๋Š” ์ˆ˜์ฒœ ๊ฐœ์˜ VNI๋ฅผ ์‹คํ–‰ํ•˜๋Š” ๊ฒƒ์€ ๋” ์ด์ƒ ์‰ฌ์šด ์ž‘์—…์ด ์•„๋‹Œ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ์ž‘์—…์—์„œ๋Š” ๊ฑฐ์˜ ์‚ฌ์šฉ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๋” ํฅ๋ฏธ๋กญ๊ณ  ์•ฝ๊ฐ„ ๋” ๋ณต์žกํ•˜์ง€๋งŒ ๊ณต์žฅ ์„ค์ •์— ๋” ๋งŽ์€ ์œ ์—ฐ์„ฑ์„ ์ œ๊ณตํ•˜๋Š” ๋ฐฉ๋ฒ• 2๋ฅผ ๋ถ„์„ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

VRF ํ† ํด๋กœ์ง€์— "PROD"๋ฅผ ์ถ”๊ฐ€ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. Leaf-10/11 ์Œ์— ์ธํ„ฐํŽ˜์ด์Šค vlan 12์„ ์ถ”๊ฐ€ํ•˜๊ณ  Leaf-20์— ์ธํ„ฐํŽ˜์ด์Šค VLAN 21์„ ์ถ”๊ฐ€ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. VLAN 20์€ VNI 20000๊ณผ ์—ฐ๊ฒฐ๋ฉ๋‹ˆ๋‹ค.

vrf context PROD
  rd auto       ! Route Distinguisher ะฝะต ะฟั€ะธะฝั†ะธะฟะธะฐะปะตะฝ ะธ ะผะพะถะตะผ ะธัะฟะพะปัŒะทะพะฒะฐั‚ัŒ ัั„ะพั€ะผะธั€ะพะฒะฐะฝะฝั‹ะน ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธ
  address-family ipv4 unicast
    route-target both auto      ! ัƒะบะฐะทั‹ะฒะฐะตะผ Route-target ั ะบะพั‚ะพั€ั‹ะผ ะฑัƒะดัƒั‚ ะธะผะฟะพั€ั‚ะธั€ะพะฒะฐั‚ัŒัั ะธ ัะบัะฟะพั€ั‚ะธั€ะพะฒะฐั‚ัŒัั ะฟั€ะตั„ะธะบัั‹ ะฒ/ะธะท VRF
vlan 20
  vn-segment 20000

interface nve 1
  member vni 20000
    ingress-replication protocol bgp

interface Vlan10
  no shutdown
  vrf member PROD
  ip address 192.168.20.1/24
  fabric forwarding mode anycast-gateway

L3VNI๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด ์ƒˆ VLAN์„ ์ƒ์„ฑํ•˜๊ณ  ์ƒˆ VNI์™€ ์—ฐ๊ฒฐํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ƒˆ VNI๋Š” VLAN 10 ๋ฐ 20 ์ •๋ณด์— ๊ด€์‹ฌ์ด ์žˆ๋Š” ๋ชจ๋“  ๋ฆฌํ”„์—์„œ ๋™์ผํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

vlan 99
  vn-segment 99000

interface nve1
  member vni 99000 associate-vrf        ! ะกะพะทะดะฐะตะผ L3 VNI

vrf context PROD
  vni 99000                             ! ะŸั€ะธะฒัะทั‹ะฒะฐะตะผ L3 VNI ะบ ะพะฟั€ะตะดะตะปะตะฝะฝะพะผัƒ VRF

๊ฒฐ๊ณผ์ ์œผ๋กœ ๋‹ค์ด์–ด๊ทธ๋žจ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 2 ๋ถ€

์กฐ๊ธˆ ๋” ๋งˆ๋ฌด๋ฆฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ•˜๋‚˜ ๋” ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค. VRF PROD์˜ ์ธํ„ฐํŽ˜์ด์Šค vlan 99

interface Vlan99
  no shutdown
  vrf member PROD
  ip forward  ! ะะฐ ะธะฝั‚ะตั€ั„ะตะนัะต ะฝะต ะดะพะปะถะฝะพ ะฑั‹ั‚ัŒ IP. ะ˜ัะฟะพะปัŒะทัƒะตั‚ัั ั‚ะพะปัŒะบะพ ะดะปั ะฟะตั€ะตัั‹ะปะบะธ ะฟะฐะบะตั‚ะพะฒ ะผะตะถะดัƒ Leaf

๊ฒฐ๊ณผ์ ์œผ๋กœ Host-1์—์„œ Host-2๋กœ ํ”„๋ ˆ์ž„์„ ์ „๋‹ฌํ•˜๋Š” ๋…ผ๋ฆฌ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  1. Host-1์—์„œ ๋ณด๋‚ธ ํ”„๋ ˆ์ž„์€ VNI 10๊ณผ ์—ฐ๊ฒฐ๋œ VLAN 10000์˜ ๋ฆฌํ”„์— ๋„์ฐฉํ•ฉ๋‹ˆ๋‹ค.
  2. Leaf๋Š” ๋Œ€์ƒ ์ฃผ์†Œ๊ฐ€ ์–ด๋””์— ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๊ณ  ๋‘ ๋ฒˆ์งธ Leaf ์Šค์œ„์น˜์˜ L3 VNI๋ฅผ ํ†ตํ•ด ์ฐพ์Šต๋‹ˆ๋‹ค.
  3. ๋ชฉ์ ์ง€ ์ฃผ์†Œ์— ๋Œ€ํ•œ ๊ฒฝ๋กœ๊ฐ€ ๋ฐœ๊ฒฌ๋˜๋Š” ์ฆ‰์‹œ Leaf๋Š” ํ•„์š”ํ•œ L3VNI 99000์„ ์‚ฌ์šฉํ•˜์—ฌ ํ”„๋ ˆ์ž„์„ ํ—ค๋”์— ์••์ถ•ํ•˜์—ฌ ๋‘ ๋ฒˆ์งธ Leaf๋กœ ๋ณด๋ƒ…๋‹ˆ๋‹ค.
  4. ๋‘ ๋ฒˆ์งธ ๋ฆฌํ”„ ์Šค์œ„์น˜๋Š” L3VNI 99000์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ˆ˜์‹ ํ•ฉ๋‹ˆ๋‹ค. ์›๋ณธ ํ”„๋ ˆ์ž„์„ ๊ฐ€์ ธ์™€ ํ•„์š”ํ•œ L2VNI 20000์œผ๋กœ ์ „์†กํ•œ ๋‹ค์Œ VLAN 20์œผ๋กœ ์ „์†กํ•ฉ๋‹ˆ๋‹ค.

์ด ์ž‘์—…์˜ ๊ฒฐ๊ณผ๋กœ L3VNI๋Š” ๋ชจ๋“  ๋ฆฌํ”„ ์Šค์œ„์น˜์˜ ๋„คํŠธ์›Œํฌ์— ์žˆ๋Š” ๋ชจ๋“  VNI์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์œ ์ง€ํ•  ํ•„์š”๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค.

๊ฒฐ๊ณผ์ ์œผ๋กœ Host-1์—์„œ Host-2๋กœ ํŠธ๋ž˜ํ”ฝ์„ ๋ณด๋‚ผ ๋•Œ ํŒจํ‚ท์€ ์ƒˆ๋กœ์šด VNI - 99000์„ ์‚ฌ์šฉํ•˜์—ฌ VxLAN ๋‚ด๋ถ€์— ํŒจํ‚น๋ฉ๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 2 ๋ถ€

Leaf-1์ด ๋‹ค๋ฅธ VNI์—์„œ MAC ์ฃผ์†Œ์— ๋Œ€ํ•ด ์ •ํ™•ํžˆ ์–ด๋–ป๊ฒŒ ํ•™์Šตํ•˜๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” EVPN ๊ฒฝ๋กœ ์œ ํ˜• 2(MAC/IP)์˜ ๋„์›€์œผ๋กœ๋„ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ์€ ๋‹ค๋ฅธ VNI์— ์žˆ๋Š” ์ ‘๋‘์‚ฌ์— ๋Œ€ํ•œ ๊ฒฝ๋กœ ์ „ํŒŒ ํ”„๋กœ์„ธ์Šค๋ฅผ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 2 ๋ถ€

์ฆ‰, VNI 20000์—์„œ ๋ฐ›์€ ์ฃผ์†Œ๋Š” XNUMX๊ฐœ์˜ RT๋ฅผ ๊ฐ€์ง‘๋‹ˆ๋‹ค.
Update์—์„œ ๋ฐ›์€ ๊ฒฝ๋กœ๋Š” VRF ์„ค์ •์— ์ง€์ •๋œ Route-target์ด ์žˆ๋Š” BGP ํ…Œ์ด๋ธ”์— ์†ํ•œ๋‹ค๋Š” ์ ์„ ์ƒ๊ธฐ์‹œ์ผœ ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค(ํ”„๋กœ์„ธ์Šค๊ฐ€ ๋‹ค์†Œ ๋ณต์žกํ•˜์ง€๋งŒ ์ด ๊ธฐ์‚ฌ์—์„œ๋Š” ๋‹ค๋ฃจ์ง€ ์•Š๊ฒ ์Šต๋‹ˆ๋‹ค).
RT ์ž์ฒด๋Š” AS:VNI ๊ณต์‹์œผ๋กœ ๊ตฌ์„ฑ๋ฉ๋‹ˆ๋‹ค(์ž๋™ ๋ชจ๋“œ๊ฐ€ ์‚ฌ์šฉ๋˜๋Š” ๊ฒฝ์šฐ).

์ž๋™ ๋ฐ ์ˆ˜๋™ ๋ชจ๋“œ์—์„œ RT ๊ตฌ์„ฑ์˜ ์˜ˆ:

vrf context PROD
  address-family ipv4 unicast
    route-target import auto - ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธะน ั€ะตะถะธะผ ั€ะฐะฑะพั‚ั‹
    route-target export 65001:20000 - ั€ัƒั‡ะฝะพะน ั€ะตะถะธะผ ั„ะพั€ะผะธั€ะพะฒะฐะฝะธั RT

๊ฒฐ๊ณผ์ ์œผ๋กœ ๋‹ค๋ฅธ VNI์˜ ์ ‘๋‘์‚ฌ์—๋Š” ๋‘ ๊ฐœ์˜ RT ๊ฐ’์ด ์žˆ์Œ์„ ์œ„์—์„œ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
65001:99000 ์ค‘ ํ•˜๋‚˜๋Š” ์ถ”๊ฐ€ L3 VNI์ž…๋‹ˆ๋‹ค. ์ด VNI๋Š” ๋ชจ๋“  Leafs์—์„œ ๋™์ผํ•˜๊ณ  VRF ์„ค์ •์˜ ๊ฐ€์ ธ์˜ค๊ธฐ ๊ทœ์น™์— ์†ํ•˜๋ฏ€๋กœ ์ถœ๋ ฅ์—์„œ โ€‹โ€‹๋ณผ ์ˆ˜ ์žˆ๋Š” ์ ‘๋‘์‚ฌ๊ฐ€ BGP ํ…Œ์ด๋ธ”์— ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.

sh bgp l2vpn evpn
<.....>
   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
                      10.255.1.10                       100      32768 i
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[32]:[192.168.10.10]/272
                      10.255.1.10                       100      32768 i
*>l[3]:[0]:[32]:[10.255.1.10]/88
                      10.255.1.10                       100      32768 i

Route Distinguisher: 10.255.1.21:32787
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.20.20]/272    ! ะŸั€ะตั„ะธะบั ะฟะพะปัƒั‡ะตะฝะฝั‹ะน ะธะท VNI 20000
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i

์ˆ˜์‹ ๋œ ์—…๋ฐ์ดํŠธ๋ฅผ ์ž์„ธํžˆ ์‚ดํŽด๋ณด๋ฉด ์ด ์ ‘๋‘์‚ฌ์— ๋‘ ๊ฐœ์˜ RT๊ฐ€ ์žˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Leaf11# sh bgp l2vpn evpn 5001.0008.0007
BGP routing table information for VRF default, address family L2VPN EVPN
Route Distinguisher: 10.255.1.21:32787
BGP routing table entry for [2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.20.2
0]/272, version 5164
Paths: (2 available, best #2)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not i
n HW

  Path type: internal, path is valid, not best reason: Neighbor Address, no labeled nexthop
  AS-Path: NONE, path sourced internal to AS
    10.255.1.20 (metric 81) from 10.255.1.102 (10.255.1.102)
      Origin IGP, MED not set, localpref 100, weight 0
      Received label 20000 99000                                 ! ะ”ะฒะฐ label ะดะปั ั€ะฐะฑะพั‚ั‹ VxLAN
      Extcommunity: RT:65001:20000 RT:65001:99000 SOO:10.255.1.20:0 ENCAP:8     ! ะ”ะฒะฐ ะทะฝะฐั‡ะตะฝะธั Route-target, ะฝะฐ ะพัะฝะพะฒะต, ะบะพั‚ะพั€ั‹ั… ะดะพะฑะฐะฒะธะปะธ ะดะฐะฝะฝั‹ะน ะฟั€ะตั„ะธะบั
          Router MAC:5001.0005.0007
      Originator: 10.255.1.21 Cluster list: 10.255.1.102
<......>

Leaf-1์˜ ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์—์„œ ์ ‘๋‘์‚ฌ 192.168.20.20/32๋„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Leaf11# sh ip route vrf PROD
192.168.10.0/24, ubest/mbest: 1/0, attached
    *via 192.168.10.1, Vlan10, [0/0], 01:29:28, direct
192.168.10.1/32, ubest/mbest: 1/0, attached
    *via 192.168.10.1, Vlan10, [0/0], 01:29:28, local
192.168.10.10/32, ubest/mbest: 1/0, attached
    *via 192.168.10.10, Vlan10, [190/0], 01:27:22, hmm
192.168.20.20/32, ubest/mbest: 1/0                                        ! ะะดั€ะตั Host-2
    *via 10.255.1.20%default, [200/0], 01:20:20, bgp-65001, internal, tag 65001     ! ะ”ะพัั‚ัƒะฟะฝั‹ะน ั‡ะตั€ะตะท Leaf-2
(evpn) segid: 99000 tunnelid: 0xaff0114 encap: VXLAN                                ! ะงะตั€ะตะท VNI 99000

๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์—์„œ ๊ธฐ๋ณธ ์ ‘๋‘์‚ฌ 192.168.20.0/24๊ฐ€ ๋ˆ„๋ฝ๋œ ๊ฒƒ์„ ํ™•์ธํ•˜์…จ์Šต๋‹ˆ๊นŒ?
๋งž์Šต๋‹ˆ๋‹ค. ๊ทธ๋Š” ๊ฑฐ๊ธฐ์— ์—†์Šต๋‹ˆ๋‹ค. ์ฆ‰, ์›๊ฒฉ ๋ฆฌํ”„๋Š” ๋„คํŠธ์›Œํฌ์— ์žˆ๋Š” ํ˜ธ์ŠคํŠธ์— ๋Œ€ํ•œ ์ •๋ณด๋งŒ ์ˆ˜์‹ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ์ด๊ฒƒ์€ ์˜ฌ๋ฐ”๋ฅธ ํ–‰๋™์ž…๋‹ˆ๋‹ค. ์œ„์˜ ๋ชจ๋“  ์—…๋ฐ์ดํŠธ์—์„œ ์ •๋ณด๊ฐ€ MAC / IP์˜ ๋‚ด์šฉ๊ณผ ํ•จ๊ป˜ ์ œ๊ณต๋˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋งํ•  ์ ‘๋‘์‚ฌ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค.

์ด๊ฒƒ์€ BGP ํ…Œ์ด๋ธ”์ด ์ถ”๊ฐ€๋กœ ์ฑ„์›Œ์ง€๋Š” ARP ํ…Œ์ด๋ธ”์„ ์ฑ„์šฐ๋Š” HMM(Host Mobility Manager) ํ”„๋กœํ† ์ฝœ์ž…๋‹ˆ๋‹ค(์ด ๋ฌธ์„œ์˜ ํ”„๋ ˆ์ž„์›Œํฌ ๋‚ด์—์„œ ์ด ํ”„๋กœ์„ธ์Šค๋Š” ์ƒ๋žตํ•จ). HMM์œผ๋กœ๋ถ€ํ„ฐ ๋ฐ›์€ ์ •๋ณด๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ route-type 2 EVPN์ด ํ˜•์„ฑ๋œ๋‹ค(MAC/IP๋กœ ์ „์†ก).

๊ทธ๋Ÿฌ๋‚˜ ์ ‘๋‘์‚ฌ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ „๋‹ฌํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” ์–ด๋–ป๊ฒŒ ํ•ด์•ผ ํ•ฉ๋‹ˆ๊นŒ?

์ด๋Ÿฌํ•œ ์œ ํ˜•์˜ ์ •๋ณด์—๋Š” EVPN ๊ฒฝ๋กœ ์œ ํ˜• 5๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด address-family l2vpn evpn์„ ํ†ตํ•ด ์ ‘๋‘์‚ฌ๋ฅผ ๋ณด๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(์ด ์ž‘์„ฑ ๋‹น์‹œ ์ด ์œ ํ˜•์˜ ๊ฒฝ๋กœ๋Š” ์ดˆ์•ˆ ๋ฒ„์ „์—๋งŒ ์žˆ์Œ). RFC, ์ด๋กœ ์ธํ•ด ๋‹ค๋ฅธ ์ œ์กฐ์—…์ฒด๋Š” ์ด๋Ÿฌํ•œ ์œ ํ˜•์˜ ๊ฒฝ๋กœ์— ๋Œ€ํ•ด ๋‹ค๋ฅธ ๋™์ž‘์„ ๊ฐ€์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.)

์ ‘๋‘์‚ฌ๋ฅผ ์ „์†กํ•˜๋ ค๋ฉด VRF์— ๋Œ€ํ•œ BGP ํ”„๋กœ์„ธ์Šค์—์„œ ์ ‘๋‘์‚ฌ๋ฅผ ์ถ”๊ฐ€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

router bgp 65001
  vrf PROD
    address-family ipv4 unicast
      redistribute direct route-map VNI20000        ! ะ’ ะดะฐะฝะฝะพะผ ัะปัƒั‡ะฐะต ะฐะฝะพะฝัะธั€ัƒะตะผ ะฟั€ะตั„ะธะบัั‹ ะฟะพะดะบะปัŽั‡ะตะฝะธะต ะฝะตะฟะพัั€ะตะดัั‚ะฒะตะฝะฝะพ ะบ Leaf ะฒ VNI 20000
route-map VNI20000 permit 10
  match ip address prefix-list VNI20000_OUT    ! ะฃะบะฐะทั‹ะฒะฐะตะผ ะบะฐะบะพะน ะธัะฟะพะปัŒะทะพะฒะฐั‚ัŒ prefix-list

ip prefix-list VNI20000_OUT seq 5 permit 192.168.20.0/24   ! ะฃะบะฐะทั‹ะฒะฐะตะผ ะบะฐะบะธะต ัะตั‚ะธ ะฑัƒะดัƒั‚ ะฟะพะฟะฐะดะฐั‚ัŒ ะฒ EVPN route-type 5

๊ฒฐ๊ณผ์ ์œผ๋กœ ์—…๋ฐ์ดํŠธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

VxLAN ๊ณต์žฅ. 2 ๋ถ€

BGP ํ…Œ์ด๋ธ”์„ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. EVPN ๊ฒฝ๋กœ ์œ ํ˜• 2,3 ์™ธ์—๋„ ๋„คํŠธ์›Œํฌ ๋ฒˆํ˜ธ์— ๋Œ€ํ•œ ์ •๋ณด๊ฐ€ ํฌํ•จ๋œ ์œ ํ˜• 5 ๊ฒฝ๋กœ๊ฐ€ ๋‚˜ํƒ€๋‚ฌ์Šต๋‹ˆ๋‹ค.

<......>
   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:3
* i[5]:[0]:[0]:[24]:[192.168.10.0]/224
                      10.255.1.10              0        100          0 ?
*>i                   10.255.1.10              0        100          0 ?

Route Distinguisher: 10.255.1.11:32777
* i[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i
* i[2]:[0]:[0]:[48]:[5001.0007.0007]:[32]:[192.168.10.10]/272
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i
* i[3]:[0]:[32]:[10.255.1.10]/88
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i

Route Distinguisher: 10.255.1.12:3
*>i[5]:[0]:[0]:[24]:[192.168.10.0]/224      ! EVPN route-type 5 ั ะฝะพะผะตั€ะพะผ ะฟั€ะตั„ะธะบัะฐ
                      10.255.1.10              0        100          0 ?
* i
<.......>                   

์ ‘๋‘์‚ฌ๋Š” ๋ผ์šฐํŒ… ํ…Œ์ด๋ธ”์—๋„ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค.

Leaf21# sh ip ro vrf PROD
192.168.10.0/24, ubest/mbest: 1/0
    *via 10.255.1.10%default, [200/0], 00:14:32, bgp-65001, internal, tag 65001  ! ะฃะดะฐะปะตะฝะฝั‹ะน ะฟั€ะตั„ะธะบั, ะดะพัั‚ัƒะฟะฝั‹ะน ั‡ะตั€ะตะท Leaf1/2(ะฐะดั€ะตั Next-hop = virtual IP ะผะตะถะดัƒ ะฟะฐั€ะพะน VPC)
(evpn) segid: 99000 tunnelid: 0xaff010a encap: VXLAN      ! ะŸั€ะตั„ะธะบั ะดะพัั‚ัƒะฟะตะฝ ั‡ะตั€ะตะท L3VNI 99000

192.168.10.10/32, ubest/mbest: 1/0
    *via 10.255.1.10%default, [200/0], 02:33:40, bgp-65001, internal, tag 65001
(evpn) segid: 99000 tunnelid: 0xaff010a encap: VXLAN

192.168.20.0/24, ubest/mbest: 1/0, attached
    *via 192.168.20.1, Vlan20, [0/0], 02:39:44, direct
192.168.20.1/32, ubest/mbest: 1/0, attached
    *via 192.168.20.1, Vlan20, [0/0], 02:39:44, local
192.168.20.20/32, ubest/mbest: 1/0, attached
    *via 192.168.20.20, Vlan20, [190/0], 02:35:46, hmm

์ด๊ฒƒ์œผ๋กœ VxLAN EVPN์— ๋Œ€ํ•œ ๊ธฐ์‚ฌ ์‹œ๋ฆฌ์ฆˆ์˜ ๋‘ ๋ฒˆ์งธ ๋ถ€๋ถ„์„ ๋งˆ์นฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ๋ถ€๋ถ„์—์„œ๋Š” VRF ๊ฐ„์˜ ๋ผ์šฐํŒ…์„ ์œ„ํ•œ ๋‹ค์–‘ํ•œ ์˜ต์…˜์„ ๊ณ ๋ คํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

IPv6์˜ ๊ธฐ๋ณธ ์‚ฌํ•ญ ๋ฐ IPv4์™€ ๋‹ค๋ฅธ ์ 

์ถœ์ฒ˜ : habr.com

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€