VXLAN&EVPN 集中式网关实验

拓扑说明:Underlay层使用isis协议,宣告每个设备的loopback接口
Spine1作为集中式网关,Leaf_1作为租户1的Leaf,vlan=10 vxlan=10010,Leaf_2作为租户2的Leaf,vlan=20 vxlan=10020
需求:使用vxlan&evpn方式组网,使用集中式网关场景,最终PC1可以与PC2通讯,只展示Spine和Leaf的配置,Leaf2与Leaf1类似。

配置流程:

  1. 开启evpn-overlay enable使能evpn为vxlan的控制层面
  2. 创建相关BD,设置对应VXLAN,设置evpn的RD与RT
  3. 建立BGP EVPN邻居关系
  4. 配置NVE接口,指定源接口地址和头端复制,使用BGP协议
  5. 在spine上配置vbdif接口
  6. leaf上需要配置l2类型的子接口,关联相应的vlan和BD

Spine1:

#
sysname Spine-1
#
evpn-overlay enable
#
evpn
#
bridge-domain 10010
 vxlan vni 10010
 evpn
  route-distinguisher 10:10
  vpn-target 10:10 export-extcommunity
  vpn-target 10:10 import-extcommunity
#
bridge-domain 10020
 vxlan vni 10020
 evpn
  route-distinguisher 20:20
  vpn-target 20:20 export-extcommunity
  vpn-target 20:20 import-extcommunity
#
isis 1
 is-level level-2
 network-entity 86.0001.0010.0100.1001.00
#
interface Vbdif10010
 ip address 192.168.10.254 255.255.255.0
#
interface Vbdif10020
 ip address 192.168.20.254 255.255.255.0
#
interface GE1/0/0
 undo portswitch
 undo shutdown
 ip address 10.0.11.1 255.255.255.252
 isis enable 1
 isis circuit-type p2p
 isis circuit-level level-2
#
interface GE1/0/1
 undo portswitch
 undo shutdown
 ip address 10.0.12.1 255.255.255.252
 isis enable 1
 isis circuit-type p2p
 isis circuit-level level-2
#
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255
 isis enable 1
#
interface Nve1
 source 1.1.1.1
 vni 10010 head-end peer-list protocol bgp
 vni 10020 head-end peer-list protocol bgp
#
bgp 100
 peer 3.3.3.3 as-number 100
 peer 3.3.3.3 connect-interface LoopBack0
 peer 4.4.4.4 as-number 100
 peer 4.4.4.4 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo peer 3.3.3.3 enable
  undo peer 4.4.4.4 enable
 #
 l2vpn-family evpn
  policy vpn-target
  peer 3.3.3.3 enable
  peer 4.4.4.4 enable
#
return

Leaf_1:

#
sysname Leaf-1
#
evpn-overlay enable
#
bridge-domain 10010
 vxlan vni 10010
 evpn
  route-distinguisher 10:11
  vpn-target 10:10 export-extcommunity
  vpn-target 10:10 import-extcommunity
#
isis 1
 is-level level-2
 network-entity 86.0001.0030.0300.3003.00
#
interface GE1/0/0
 undo shutdown
#
interface GE1/0/0.10 mode l2
 encapsulation dot1q vid 10
 bridge-domain 10010
#
interface GE1/0/1
 undo portswitch
 undo shutdown
 ip address 10.0.11.2 255.255.255.252
 isis enable 1
 isis circuit-type p2p
 isis circuit-level level-2
#
interface GE1/0/2
 undo portswitch
 undo shutdown
 ip address 10.0.21.2 255.255.255.252
 isis enable 1
 isis circuit-type p2p
 isis circuit-level level-2
#
interface LoopBack0
 ip address 3.3.3.3 255.255.255.255
 isis enable 1
#
interface Nve1
 source 3.3.3.3
 vni 10010 head-end peer-list protocol bgp
#
interface NULL0
#
bgp 100
 peer 1.1.1.1 as-number 100
 peer 1.1.1.1 connect-interface LoopBack0
 peer 2.2.2.2 as-number 100
 peer 2.2.2.2 connect-interface LoopBack0
 #
 ipv4-family unicast
  undo peer 1.1.1.1 enable
  undo peer 2.2.2.2 enable
 #
 l2vpn-family evpn
  policy vpn-target
  peer 1.1.1.1 enable
  peer 2.2.2.2 enable
#
return

实验现象:

VXLAN&EVPN 集中式网关实验》有3个想法

      1. 你好,之前只下载了ce6800的设备包,用ensp一直用不起来,方便的话给否给个12800镜像,qq:45413389 email:m0ster@sina.com

发表评论

电子邮件地址不会被公开。 必填项已用*标注

此站点使用Akismet来减少垃圾评论。了解我们如何处理您的评论数据