VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ื”ืขืœื, ื”ืื‘ืจ. ืื™ืš ืคืึธืจื–ืขืฆืŸ ื“ื™ ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹ืึทืจื˜ื™ืงืœืขืŸ ืื•ื™ืฃ VxLAN EVPN ื˜ืขื›ื ืึธืœืึธื’ื™ืข, ื•ื•ืึธืก ื–ืขื ืขืŸ ื’ืขืฉืจื™ื‘ืŸ ืกืคึผืขืฆื™ืขืœ ืคึฟืึทืจ ื“ื™ ืงืึทื˜ืขืจ ืคื•ืŸ ื“ืขื ืงื•ืจืก "ื ืขื˜ื•ื•ืึธืจืง ื™ื ื–ืฉืขื ื™ืจ" ืคึฟื•ืŸ OTUS. ืื•ืŸ ื”ื™ื™ึทื ื˜ ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ืึท ื˜ืฉื™ืงืึทื•ื•ืข ื˜ื™ื™ืœ ืคื•ืŸ ื“ืขืจ ืึทืจื‘ืขื˜ - ืจื•ื˜ื™ื ื’. ื ื™ื˜ ืงื™ื™ืŸ ืขื ื™ืŸ ื•ื•ื™ ื ื™ืฉื˜ื™ืง ืขืก ืงืขืŸ ื’ืขื–ื•ื ื˜, ืึธื‘ืขืจ, ืื™ืŸ ื“ื™ ืจืึทื ืคื•ืŸ ื“ื™ ืึทืจื‘ืขื˜ ืคื•ืŸ ืึท ื ืขืฅ ืคืึทื‘ืจื™ืง, ืึทืœืฅ ืงืขืŸ ื ื™ืฉื˜ ื–ื™ื™ืŸ ืึทื–ื•ื™ ืคึผืฉื•ื˜.

VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ื˜ื™ื™ืœ 1 ืคื•ืŸ ื“ื™ ืฆื™ืงืœ - ืœ 2 ืงืึทื ืขืงื˜ื™ื•ื•ื™ื˜ื™ ืฆื•ื•ื™ืฉืŸ ืกืขืจื•ื•ืขืจืก

ืื™ืŸ ื“ื™ ืœืขืฆื˜ืข ื˜ื™ื™ืœ, ืžื™ืจ ืึทื˜ืฉื™ื•ื•ื“ ืื™ื™ืŸ ื‘ืจืึธื“ืงืึทืกื˜ ืคืขืœื“ ื’ืขื‘ื•ื™ื˜ ืื•ื™ืฃ ืฉืคึผื™ืฅ ืคื•ืŸ ื“ื™ ื ืขืฅ ืฉื˜ืึธืฃ ืื•ื™ืฃ ื“ื™ Nexus 9000v. ืึธื‘ืขืจ, ื“ืึธืก ืื™ื– ื ื™ืฉื˜ ื“ื™ ื’ืื ืฆืข ืงื™ื™ื˜ ืคื•ืŸ ื˜ืึทืกืงืก ื•ื•ืึธืก ื“ืึทืจืคึฟืŸ ืฆื• ื–ื™ื™ืŸ ืกืึทืœื•ื•ื“ ืื™ืŸ ื“ื™ ื“ืึทื˜ืŸ ืฆืขื ื˜ืขืจ ื ืขืฅ. ืื•ืŸ ื”ื™ื™ึทื ื˜ ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืึทืจื‘ืขื˜ - ืจื•ื˜ื™ื ื’ ืฆื•ื•ื™ืฉืŸ ื ืขื˜ื•ื•ืึธืจืงืก ืึธื“ืขืจ ืฆื•ื•ื™ืฉืŸ VNIs.

ืœืึธื–ืŸ ืžื™ืจ ื“ืขืจืžืึธื ืขืŸ ืื™ืจ ืึทื– ื“ื™ ืกืคึผื™ื ืข-ื‘ืœืึทื˜ ื˜ืึธืคึผืึธืœืึธื’ื™ ืื™ื– ื’ืขื ื™ืฆื˜:

VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ืขืจืฉื˜ืขืจ, ืœืึธื–ืŸ ืก ืงื•ืง ืื™ืŸ ื•ื•ื™ ืจื•ื˜ื™ื ื’ ืึทืงืขืจื– ืื•ืŸ ื•ื•ืึธืก ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ืขืก ื”ืื˜.

ืคึฟืึทืจ ืคืืจืฉื˜ืื ื“, ืœืึธืžื™ืจ ืคืึทืจืคึผืึธืฉืขื˜ืขืจืŸ ื“ื™ ืœืึธื’ื™ืง ื“ื™ืึทื’ืจืึทืžืข ืื•ืŸ ืœื™ื™ื’ืŸ ืืŸ ืื ื“ืขืจ VNI 20000 ืคึฟืึทืจ ื”ืึธืกื˜-2. ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ื–:

VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ื•ื•ื™, ืื™ืŸ ื“ืขื ืคืึทืœ, ืงืขื ืขืŸ ืื™ืจ ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืคืึทืจืงืขืจ ืคื•ืŸ ืื™ื™ืŸ ื”ืึธืกื˜ ืฆื• ืื ื“ืขืจืŸ?

ืขืก ื–ืขื ืขืŸ ืฆื•ื•ื™ื™ ืึธืคึผืฆื™ืขืก:

  1. ื”ืึทืœื˜ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึทืœืข VNIs ืื•ื™ืฃ ืึทืœืข ื‘ืœืึทื˜ ืกื•ื•ื™ื˜ืฉื™ื–, ืื•ืŸ ืึทืœืข ืจื•ื˜ื™ื ื’ ื•ื•ืขื˜ ืคึผืึทืกื™ืจืŸ ืื•ื™ืฃ ื“ืขืจ ืขืจืฉื˜ืขืจ ื‘ืœืึทื˜ ืื™ืŸ ื“ืขืจ ื ืขืฅ;
  2. ื ื™ืฆืŸ ืึท ื“ืขื“ืึทืงื™ื™ื˜ืึทื“ L3 VNI

ื“ืขืจ ืขืจืฉื˜ืขืจ ืื•ืคึฟืŸ ืื™ื– ืคึผืฉื•ื˜ ืื•ืŸ ื‘ืึทืงื•ื•ืขื. ื–ื™ื ื˜ ืื™ืจ ื ืึธืจ ื“ืึทืจืคึฟืŸ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ืึทืœืข VNI ืื•ื™ืฃ ืึทืœืข ื‘ืœืึทื˜ ืกื•ื•ื™ื˜ืฉื™ื–. ืึธื‘ืขืจ, ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืขื˜ืœืขื›ืข ื”ื•ื ื“ืขืจื˜ ืึธื“ืขืจ ื˜ื•ื™ื–ื ื˜ VNIs ืคึฟืึทืจ ืึทืœืข ื‘ืœืขื˜ืขืจ ื ื™ื˜ ืžืขืจ ืกื™ืžื– ื•ื•ื™ ืึท ืคึผืฉื•ื˜ ืึทืจื‘ืขื˜. ื“ืขืจื™ื‘ืขืจ, ืขืก ืื™ื– ื’ืขื ื™ืฆื˜ ื’ืึทื ืฅ ืจืึทืจืขืœื™ ืื™ืŸ ืึทืจื‘ืขื˜.

ื–ืืœ ืก ืงื•ืง ืื™ืŸ ืื•ืคึฟืŸ 2, ื•ื•ืึธืก ืื™ื– ืžืขืจ ื˜ืฉื™ืงืึทื•ื•ืข ืื•ืŸ ืึท ื‘ื™ืกืœ ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜, ืึธื‘ืขืจ ื’ื™ื˜ ืžืขืจ ื‘ื™ื™ื’ื™ืงื™ื™ื˜ ืื™ืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ืคืึทื‘ืจื™ืง.

ืœืึธืžื™ืจ ืœื™ื™ื’ืŸ "PROD" ืฆื• ื“ื™ VRF ื˜ืึธืคึผืึธืœืึธื’ื™. ืฆื• ืขืก ืžื™ืจ ื•ื•ืขืœืŸ ืœื™ื™ื’ืŸ ืฆื•ื‘ื™ื ื“ ื•ื•ืœืึทืŸ 10 ืื•ื™ืฃ ื“ื™ Leaf-11/12 ืคึผืึธืจ ืื•ืŸ ืฆื•ื‘ื™ื ื“ ื•ื•ืœืึทืŸ 20 ืื•ื™ืฃ Leaf-21. VLAN 20 ืื™ื– ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ VNI 20000

vrf context PROD
  rd auto       ! Route Distinguisher ะฝะต ะฟั€ะธะฝั†ะธะฟะธะฐะปะตะฝ ะธ ะผะพะถะตะผ ะธัะฟะพะปัŒะทะพะฒะฐั‚ัŒ ัั„ะพั€ะผะธั€ะพะฒะฐะฝะฝั‹ะน ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธ
  address-family ipv4 unicast
    route-target both auto      ! ัƒะบะฐะทั‹ะฒะฐะตะผ Route-target ั ะบะพั‚ะพั€ั‹ะผ ะฑัƒะดัƒั‚ ะธะผะฟะพั€ั‚ะธั€ะพะฒะฐั‚ัŒัั ะธ ัะบัะฟะพั€ั‚ะธั€ะพะฒะฐั‚ัŒัั ะฟั€ะตั„ะธะบัั‹ ะฒ/ะธะท VRF
vlan 20
  vn-segment 20000

interface nve 1
  member vni 20000
    ingress-replication protocol bgp

interface Vlan10
  no shutdown
  vrf member PROD
  ip address 192.168.20.1/24
  fabric forwarding mode anycast-gateway

ืื™ืŸ ืกื“ืจ ืฆื• ื ื•ืฆืŸ L3VNI, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฉืึทืคึฟืŸ ืึท ื ื™ื™ึทืข VLAN ืื•ืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืขืก ืžื™ื˜ ื“ื™ ื ื™ื™ึทืข VNI. ื“ื™ ื ื™ื™ึทืข VNI ืžื•ื–ืŸ ื–ื™ื™ืŸ ื“ื™ ื–ืขืœื‘ืข ืื•ื™ืฃ ืึทืœืข ื‘ืœืขื˜ืขืจ ื•ื•ืึธืก ื–ืขื ืขืŸ ืื™ื ื˜ืขืจืขืกื™ืจื˜ ืื™ืŸ VLAN 10 ืื•ืŸ 20 ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข

vlan 99
  vn-segment 99000

interface nve1
  member vni 99000 associate-vrf        ! ะกะพะทะดะฐะตะผ L3 VNI

vrf context PROD
  vni 99000                             ! ะŸั€ะธะฒัะทั‹ะฒะฐะตะผ L3 VNI ะบ ะพะฟั€ะตะดะตะปะตะฝะฝะพะผัƒ VRF

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ื“ื™ ื“ื™ืึทื’ืจืึทืžืข ื•ื•ืขื˜ ืงื•ืงืŸ ื•ื•ื™ ื“ืึธืก:

VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ืขืก ื‘ืœื™ื™ื‘ื˜ ืฆื• ื˜ืึธืŸ ืึท ื‘ื™ืกืœ - ืœื™ื™ื’ืŸ ื ืึธืš ืึท ืฆื•ื‘ื™ื ื“ - ืฆื•ื‘ื™ื ื“ ื•ื•ืœืึทืŸ 99 ืื™ืŸ VRF PROD

interface Vlan99
  no shutdown
  vrf member PROD
  ip forward  ! ะะฐ ะธะฝั‚ะตั€ั„ะตะนัะต ะฝะต ะดะพะปะถะฝะพ ะฑั‹ั‚ัŒ IP. ะ˜ัะฟะพะปัŒะทัƒะตั‚ัั ั‚ะพะปัŒะบะพ ะดะปั ะฟะตั€ะตัั‹ะปะบะธ ะฟะฐะบะตั‚ะพะฒ ะผะตะถะดัƒ Leaf

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ื“ื™ ืœืึธื’ื™ืง ืคึฟืึทืจ ืคืึธืจืŸ ืึท ืจืึทื ืคื•ืŸ Host-1 ืฆื• Host-2 ืื™ื– ื•ื•ื™ ื’ื™ื™ื˜:

  1. ื“ืขืจ ืจืึทื ื’ืขืฉื™ืงื˜ ื“ื•ืจืš ื”ืึธืกื˜-1 ืขืจื™ื™ื•ื•ื– ืื™ืŸ ืœื™ืฃ ืื™ืŸ ื•ื•ืœืึทืŸ 10, ื•ื•ืึธืก ืื™ื– ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ VNI 10000;
  2. ื‘ืœืึทื˜ ื˜ืฉืขืงืก ื•ื•ื• ื“ื™ ื“ืขืกื˜ื™ื ื™ื™ืฉืึทืŸ ืึทื“ืจืขืก ืื™ื– ืื•ืŸ ื’ืขืคื™ื ื˜ ืขืก ื“ื•ืจืš L3 VNI ืื•ื™ืฃ ื“ื™ ืจื’ืข ื‘ืœืึทื˜ ื‘ืึทืฉื˜ื™ืžืขืŸ;
  3. ื•ื•ื™ ื‘ืึทืœื“ ื•ื•ื™ ืึท ืžืึทืจืฉืจื•ื˜ ืฆื• ื“ื™ ื“ืขืกื˜ื™ื ื™ื™ืฉืึทืŸ ืึทื“ืจืขืก ืื™ื– ื’ืขืคึฟื•ื ืขืŸ, Leaf ืคึผืึทืงื˜ ื“ื™ ืจืึทื ืื™ืŸ ืึท ื›ืขื“ืขืจ ืžื™ื˜ ื“ื™ ื ื™ื™ื˜ื™ืง L3VNI 99000 - ืื•ืŸ ืกืขื ื“ื– ืขืก ืฆื• ื“ื™ ืจื’ืข ื‘ืœืึทื˜;
  4. ื“ืขืจ ืฆื•ื•ื™ื™ื˜ืขืจ ื‘ืœืึทื˜ ื‘ืึทืฉื˜ื™ืžืขืŸ ื ืขืžื˜ ื“ืึทื˜ืŸ ืคื•ืŸ L3VNI 99000. ืขืก ื ืขืžื˜ ื“ื™ ืึธืจื™ื’ื™ื ืขืœ ืจืึทื ืื•ืŸ ื˜ืจืึทื ืกืคืขืจืก ืขืก ืฆื• ื“ื™ ืคืืจืœืื ื’ื˜ L2VNI 20000 ืื•ืŸ ื“ืขืจื ืึธืš ืฆื• VLAN 20.

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ืขื ืึทืจื‘ืขื˜, L3VNI ื™ืœื™ืžืึทื ื™ื™ืฅ ื“ื™ ื ื•ื™ื˜ ืฆื• ื”ืึทืœื˜ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึทืœืข VNIs ื•ื•ืึธืก ื–ืขื ืขืŸ ืื•ื™ืฃ ื“ื™ ื ืขืฅ ืื•ื™ืฃ ืึทืœืข ื‘ืœืึทื˜ ืกื•ื•ื™ื˜ืฉื™ื–.

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ื•ื•ืขืŸ ืžื™ืจ ืฉื™ืงืŸ ืคืึทืจืงืขืจ ืคื•ืŸ Host-1 ืฆื• Host-2, ื“ื™ ืคึผืึทืงืึทื˜ ืื™ื– ืคึผืึทืงื˜ ื™ืŸ VxLAN ืžื™ื˜ ืึท ื ื™ื™ึทืข VNI - 99000:

VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ืขืก ื‘ืœื™ื™ื‘ื˜ ืฆื• ื–ืขืŸ ื•ื•ื™ ืคึผื•ื ืงื˜ Leaf-1 ืœืขืจื ื˜ ื•ื•ืขื’ืŸ ื“ื™ MAC ืึทื“ืจืขืก ืคื•ืŸ ืืŸ ืื ื“ืขืจ VNI. ื“ืึธืก ืื•ื™ืš ื›ืึทืคึผืึทื ื– ืžื™ื˜ EVPN ืžืึทืจืฉืจื•ื˜-ื˜ื™ืคึผ 2 (MAC / IP).

ื“ื™ ืคืืœื’ืขื ื“ืข ื•ื•ื™ื™ื–ื˜ ื“ืขื ืคึผืจืึธืฆืขืก ืคื•ืŸ ืคึผืจืึทืคึผืึทื’ื™ื™ื˜ื™ื ื’ ืึท ืžืึทืจืฉืจื•ื˜ ื•ื•ืขื’ืŸ ืึท ืคึผืจืขืคื™ืงืก ืื™ืŸ ืืŸ ืื ื“ืขืจ VNI:

VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ื“ืึธืก ืื™ื–, ืึทื“ืจืขืกืขืก ื‘ืืงื•ืžืขืŸ ืคื•ืŸ VNI 20000 ื”ืึธื‘ืŸ ืฆื•ื•ื™ื™ ืจื˜ืก.
ืœืึธื–ืŸ ืžื™ืจ ื“ืขืจืžืึธื ืขืŸ ืื™ืจ ืึทื– ืจื•ืฅ ื‘ืืงื•ืžืขืŸ ืคึฟื•ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืขื ื“ื™ืงื˜ ื–ื™ืš ืื™ืŸ ื“ื™ BGP ื˜ื™ืฉ ืžื™ื˜ ื“ื™ ืจื•ื˜ ืฆื™ืœ ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ VRF ืกืขื˜ื˜ื™ื ื’ืก (ื“ืขืจ ืคึผืจืึธืฆืขืก ืื™ื– ืขืคึผืขืก ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜, ืึธื‘ืขืจ ืžื™ืจ ื•ื•ืขืœืŸ ื ื™ืฉื˜ ื“ืขืœื•ื• ืื™ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ).
ืจื˜ ื–ื™ืš ืื™ื– ื’ืขืฉืืคืŸ ืœื•ื™ื˜ ื“ื™ ืคืึธืจืžื•ืœืข: AS:VNI (ืื•ื™ื‘ ืึธื˜ืึทืžืึทื˜ื™ืง ืžืึธื“ืข ืื™ื– ื’ืขื ื™ืฆื˜).

ื‘ื™ื™ึทืฉืคึผื™ืœ ืคื•ืŸ RT ืคืึธืจืžื™ืจื•ื ื’ ืื™ืŸ ืึธื˜ืึทืžืึทื˜ื™ืง ืื•ืŸ ืžืึทื ื•ืึทืœ ืžืึธื“ืข:

vrf context PROD
  address-family ipv4 unicast
    route-target import auto - ะฐะฒั‚ะพะผะฐั‚ะธั‡ะตัะบะธะน ั€ะตะถะธะผ ั€ะฐะฑะพั‚ั‹
    route-target export 65001:20000 - ั€ัƒั‡ะฝะพะน ั€ะตะถะธะผ ั„ะพั€ะผะธั€ะพะฒะฐะฝะธั RT

ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืื•ื™ื‘ืŸ ื•ื•ื™ื™ื–ื˜ ืึทื– ืคึผืจืขืคื™ืงืก ืคื•ืŸ ืืŸ ืื ื“ืขืจ VNI ื”ืึธื‘ืŸ ืฆื•ื•ื™ื™ RT ื•ื•ืึทืœื•ืขืก.
ืื™ื™ื ืขืจ ืคื•ืŸ ื–ื™ื™ ืื™ื– 65001:99000 - ืึทืŸ ื ืึธืš L3 VNI. ื–ื™ื ื˜ ื“ืขื VNI ืื™ื– ื“ื™ ื–ืขืœื‘ืข ืื•ื™ืฃ ืึทืœืข ื‘ืœืขื˜ืขืจ ืื•ืŸ ืคืืœืŸ ืื•ื ื˜ืขืจ ืื•ื ื“ื–ืขืจ ืึทืจื™ื™ึทื ืคื™ืจ ื›ึผืœืœื™ื ืื™ืŸ ื“ื™ VRF ืกืขื˜ื˜ื™ื ื’ืก, ื“ื™ ืคึผืจืขืคื™ืงืก ืขื ื“ืก ืื™ืŸ ื“ื™ BGP ื˜ื™ืฉ, ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื–ืขืŸ ืคึฟื•ืŸ ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜:

sh bgp l2vpn evpn
<.....>
   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:32777    (L2VNI 10000)
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
                      10.255.1.10                       100      32768 i
*>l[2]:[0]:[0]:[48]:[5001.0007.0007]:[32]:[192.168.10.10]/272
                      10.255.1.10                       100      32768 i
*>l[3]:[0]:[32]:[10.255.1.10]/88
                      10.255.1.10                       100      32768 i

Route Distinguisher: 10.255.1.21:32787
* i[2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.20.20]/272    ! ะŸั€ะตั„ะธะบั ะฟะพะปัƒั‡ะตะฝะฝั‹ะน ะธะท VNI 20000
                      10.255.1.20                       100          0 i
*>i                   10.255.1.20                       100          0 i

ืื•ื™ื‘ ืžื™ืจ ืงื•ืงืŸ ืžืขืจ ืขื ื’ ืื™ืŸ ื“ื™ ื‘ืืงื•ืžืขืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ, ืžื™ืจ ืงืขื ืขืŸ ื–ืขืŸ ืึทื– ื“ื™ ืคึผืจืขืคื™ืงืก ื”ืื˜ ืฆื•ื•ื™ื™ RTs:

Leaf11# sh bgp l2vpn evpn 5001.0008.0007
BGP routing table information for VRF default, address family L2VPN EVPN
Route Distinguisher: 10.255.1.21:32787
BGP routing table entry for [2]:[0]:[0]:[48]:[5001.0008.0007]:[32]:[192.168.20.2
0]/272, version 5164
Paths: (2 available, best #2)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not i
n HW

  Path type: internal, path is valid, not best reason: Neighbor Address, no labeled nexthop
  AS-Path: NONE, path sourced internal to AS
    10.255.1.20 (metric 81) from 10.255.1.102 (10.255.1.102)
      Origin IGP, MED not set, localpref 100, weight 0
      Received label 20000 99000                                 ! ะ”ะฒะฐ label ะดะปั ั€ะฐะฑะพั‚ั‹ VxLAN
      Extcommunity: RT:65001:20000 RT:65001:99000 SOO:10.255.1.20:0 ENCAP:8     ! ะ”ะฒะฐ ะทะฝะฐั‡ะตะฝะธั Route-target, ะฝะฐ ะพัะฝะพะฒะต, ะบะพั‚ะพั€ั‹ั… ะดะพะฑะฐะฒะธะปะธ ะดะฐะฝะฝั‹ะน ะฟั€ะตั„ะธะบั
          Router MAC:5001.0005.0007
      Originator: 10.255.1.21 Cluster list: 10.255.1.102
<......>

ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ ืื•ื™ืฃ Leaf-1 ืื™ืจ ืงืขื ืขืŸ ืื•ื™ืš ื–ืขืŸ ื“ื™ ืคึผืจืขืคื™ืงืก 192.168.20.20/32:

Leaf11# sh ip route vrf PROD
192.168.10.0/24, ubest/mbest: 1/0, attached
    *via 192.168.10.1, Vlan10, [0/0], 01:29:28, direct
192.168.10.1/32, ubest/mbest: 1/0, attached
    *via 192.168.10.1, Vlan10, [0/0], 01:29:28, local
192.168.10.10/32, ubest/mbest: 1/0, attached
    *via 192.168.10.10, Vlan10, [190/0], 01:27:22, hmm
192.168.20.20/32, ubest/mbest: 1/0                                        ! ะะดั€ะตั Host-2
    *via 10.255.1.20%default, [200/0], 01:20:20, bgp-65001, internal, tag 65001     ! ะ”ะพัั‚ัƒะฟะฝั‹ะน ั‡ะตั€ะตะท Leaf-2
(evpn) segid: 99000 tunnelid: 0xaff0114 encap: VXLAN                                ! ะงะตั€ะตะท VNI 99000

ื‘ืืžืขืจืงื˜ ื“ื™ ืคืขืœืŸ ืคื•ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ืคึผืจืขืคื™ืงืก 192.168.20.0/24 ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ?
ืจืขื›ื˜, ืขืจ ืื™ื– ื ื™ืฉื˜ ื“ืึธืจื˜. ื“ืึธืก ืื™ื–, ื•ื•ื™ื™ึทื˜ ืœื™ืคืก ื‘ืึทืงื•ืžืขืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื‘ืœื•ื™ื– ื•ื•ืขื’ืŸ ื“ื™ ืžื—ื ื•ืช ื•ื•ืึธืก ื–ืขื ืขืŸ ืื•ื™ืฃ ื“ื™ื™ืŸ ื ืขืฅ. ืื•ืŸ ื“ืึธืก ืื™ื– ื“ื™ ืจื™ื›ื˜ื™ืง ื ืึทื˜ื•ืจ. ืื•ื™ื‘ืŸ ืื™ืŸ ืึทืœืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืื™ืจ ืงืขื ืขืŸ ื–ืขืŸ ืึทื– ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืงื•ืžื˜ ืžื™ื˜ MAC / IP ืื™ื ื”ืึทืœื˜. ื•ื•ืขื’ืŸ ืงื™ื™ืŸ ืคึผืจืขืคื™ืงืก ืื™ื– ื ื™ื˜ ื’ืขืจืขื“ื˜.

ื“ืึธืก ืื™ื– ื•ื•ื™ ื“ื™ ื”ืึธืกื˜ ืžืึธื‘ื™ืœื™ื˜ื™ ืžืึทื ืึทื’ืขืจ (HMM) ืคึผืจืึธื˜ืึธืงืึธืœ ืึทืจื‘ืขื˜, ื•ื•ืึธืก ืคื™ืœื– ื“ื™ ARP ื˜ื™ืฉ ืคึฟื•ืŸ ื•ื•ืึธืก ื“ื™ BGP ื˜ื™ืฉ ืื™ื– ืึธื ื’ืขืคื™ืœื˜ (ืžื™ืจ ื•ื•ืขืœืŸ ืคืึทืจืœืึธื–ืŸ ื“ืขื ืคึผืจืึธืฆืขืก ืคึฟืึทืจ ื“ื™ ืฆื•ื•ืขืงืŸ ืคื•ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ). ื‘ืึทื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื‘ืืงื•ืžืขืŸ ืคื•ืŸ ื“ื™ HMM, EVPN ืžืึทืจืฉืจื•ื˜ ื˜ื™ืคึผ 2 ืื™ื– ื’ืขืฉืืคืŸ (ื˜ืจืึทื ืกืžื™ื˜ื˜ืขื“ ื“ื•ืจืš MAC / IP).

ืึธื‘ืขืจ, ื•ื•ืึธืก ืื•ื™ื‘ ืขืก ืื™ื– ืึท ื ื•ื™ื˜ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืึท ืคึผืจืขืคื™ืงืก?

ืคึฟืึทืจ ื“ืขื ื˜ื™ืคึผ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข, ืขืก ืื™ื– EVPN ืžืึทืจืฉืจื•ื˜ ื˜ื™ืคึผ 5 - ืขืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืคึผืจืขืคื™ืงืกื™ื– ื“ื•ืจืš ืึทื“ืจืขืก-ืžืฉืคึผื—ื” l2vpn evpn (ื“ืขื ื˜ื™ืคึผ ืคื•ืŸ ืจื•ืฅ ืื™ืŸ ื“ืขืจ ืฆื™ื™ื˜ ืคื•ืŸ ืฉืจื™ื™ื‘ืŸ ืื™ื– ื‘ืœื•ื™ื– ืื™ืŸ ื“ื™ ืคึผืœืึทืŸ ื•ื•ืขืจืกื™ืข ืจืคืง, ื•ื•ื™ื™ึทืœ ืคื•ืŸ ื“ืขื, ื“ื™ ื ืึทื˜ื•ืจ ืคื•ืŸ ื“ืขื ื˜ื™ืคึผ ืคื•ืŸ ืžืึทืจืฉืจื•ื˜ ืงืขืŸ ื–ื™ื™ืŸ ืึทื ื“ืขืจืฉ ืฆื•ื•ื™ืฉืŸ ืคืึทืจืฉื™ื“ืขื ืข ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื–)

ืฆื• ื™ื‘ืขืจืฉื™ืงืŸ ืคึผืจืขืคื™ืงืก, ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืฆื• ืœื™ื™ื’ืŸ ืคึผืจืขืคื™ืงืก ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึทื“ื•ื•ืขืจื˜ื™ื™ื–ื“ ืื™ืŸ ื“ื™ BGP ืคึผืจืึธืฆืขืก ืคึฟืึทืจ VRF:

router bgp 65001
  vrf PROD
    address-family ipv4 unicast
      redistribute direct route-map VNI20000        ! ะ’ ะดะฐะฝะฝะพะผ ัะปัƒั‡ะฐะต ะฐะฝะพะฝัะธั€ัƒะตะผ ะฟั€ะตั„ะธะบัั‹ ะฟะพะดะบะปัŽั‡ะตะฝะธะต ะฝะตะฟะพัั€ะตะดัั‚ะฒะตะฝะฝะพ ะบ Leaf ะฒ VNI 20000
route-map VNI20000 permit 10
  match ip address prefix-list VNI20000_OUT    ! ะฃะบะฐะทั‹ะฒะฐะตะผ ะบะฐะบะพะน ะธัะฟะพะปัŒะทะพะฒะฐั‚ัŒ prefix-list

ip prefix-list VNI20000_OUT seq 5 permit 192.168.20.0/24   ! ะฃะบะฐะทั‹ะฒะฐะตะผ ะบะฐะบะธะต ัะตั‚ะธ ะฑัƒะดัƒั‚ ะฟะพะฟะฐะดะฐั‚ัŒ ะฒ EVPN route-type 5

ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ื“ืขืจ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื•ื•ืขื˜ ื”ืึธื‘ืŸ:

VxLAN ืคืึทื‘ืจื™ืง. ื˜ื™ื™ืœ 2

ื–ืืœ ืก ืงื•ืง ืื™ืŸ ื“ื™ BGP ื˜ื™ืฉ. ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• EVPN ืžืึทืจืฉืจื•ื˜ ื˜ื™ืคึผ 2,3, ื˜ื™ืคึผ 5 ืจื•ืฅ ื–ืขื ืขืŸ ืืจื•ื™ืก, ื•ื•ืึธืก ืึทื ื˜ื”ืึทืœื˜ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื ืขืฅ ื ื•ืžืขืจ:

<......>
   Network            Next Hop            Metric     LocPrf     Weight Path
Route Distinguisher: 10.255.1.11:3
* i[5]:[0]:[0]:[24]:[192.168.10.0]/224
                      10.255.1.10              0        100          0 ?
*>i                   10.255.1.10              0        100          0 ?

Route Distinguisher: 10.255.1.11:32777
* i[2]:[0]:[0]:[48]:[5001.0007.0007]:[0]:[0.0.0.0]/216
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i
* i[2]:[0]:[0]:[48]:[5001.0007.0007]:[32]:[192.168.10.10]/272
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i
* i[3]:[0]:[32]:[10.255.1.10]/88
                      10.255.1.10                       100          0 i
*>i                   10.255.1.10                       100          0 i

Route Distinguisher: 10.255.1.12:3
*>i[5]:[0]:[0]:[24]:[192.168.10.0]/224      ! EVPN route-type 5 ั ะฝะพะผะตั€ะพะผ ะฟั€ะตั„ะธะบัะฐ
                      10.255.1.10              0        100          0 ?
* i
<.......>                   

ื“ื™ ืคึผืจืขืคื™ืงืก ืื•ื™ืš ืืจื•ื™ืก ืื™ืŸ ื“ื™ ืจื•ื˜ื™ื ื’ ื˜ื™ืฉ:

Leaf21# sh ip ro vrf PROD
192.168.10.0/24, ubest/mbest: 1/0
    *via 10.255.1.10%default, [200/0], 00:14:32, bgp-65001, internal, tag 65001  ! ะฃะดะฐะปะตะฝะฝั‹ะน ะฟั€ะตั„ะธะบั, ะดะพัั‚ัƒะฟะฝั‹ะน ั‡ะตั€ะตะท Leaf1/2(ะฐะดั€ะตั Next-hop = virtual IP ะผะตะถะดัƒ ะฟะฐั€ะพะน VPC)
(evpn) segid: 99000 tunnelid: 0xaff010a encap: VXLAN      ! ะŸั€ะตั„ะธะบั ะดะพัั‚ัƒะฟะตะฝ ั‡ะตั€ะตะท L3VNI 99000

192.168.10.10/32, ubest/mbest: 1/0
    *via 10.255.1.10%default, [200/0], 02:33:40, bgp-65001, internal, tag 65001
(evpn) segid: 99000 tunnelid: 0xaff010a encap: VXLAN

192.168.20.0/24, ubest/mbest: 1/0, attached
    *via 192.168.20.1, Vlan20, [0/0], 02:39:44, direct
192.168.20.1/32, ubest/mbest: 1/0, attached
    *via 192.168.20.1, Vlan20, [0/0], 02:39:44, local
192.168.20.20/32, ubest/mbest: 1/0, attached
    *via 192.168.20.20, Vlan20, [190/0], 02:35:46, hmm

ื“ืึธืก ืขื ื“ื™ืงื˜ ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ื˜ื™ื™ืœ ืคื•ืŸ ื“ืขืจ ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืึทืจื˜ื™ืงืœืขืŸ ืื•ื™ืฃ VxLAN EVPN. ืื™ืŸ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ื˜ื™ื™ืœ ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ืคืึทืจืฉื™ื“ืŸ ืึธืคึผืฆื™ืขืก ืคึฟืึทืจ ืจื•ื˜ื™ื ื’ ืฆื•ื•ื™ืฉืŸ VRFs.

ื“ื™ ื‘ืึทืกื™ืงืก ืคื•ืŸ ื“ื™ IPv6 ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ืŸ ื“ื™ ื“ื™ืคืขืจืึทื ืกื™ื– ืฆื•ื•ื™ืฉืŸ ื“ื™ IPv4

ืžืงื•ืจ: www.habr.com

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster