VXLAN IBGP RR 实验
阅读原文时间:2023年07月10日阅读:1

网络拓扑图:

SPINE1配置

======================================================

hostname SPINE-1
nv overlay evpn
feature ospf
feature bgp
feature pim
feature nv overlay

ip pim rp-address 192.168.1.8 group-list 239.0.0.0/24
ip pim log-neighbor-changes
ip pim ssm range 232.0.0.0/8
ip pim anycast-rp 192.168.1.8 192.168.1.1
ip pim anycast-rp 192.168.1.8 192.168.1.2

vrf context management

interface Ethernet1/1
no switchport
ip address 10.10.1.1/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface Ethernet1/2
no switchport
ip address 10.10.3.1/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface loopback0
ip address 192.168.1.1/32
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode

interface loopback1
ip address 192.168.1.8/32
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
line console
line vty
boot nxos bootflash:/nxos.7.0.3.I5.2.bin
router ospf 100
router-id 192.168.1.1
log-adjacency-changes
router bgp 65001
router-id 192.168.1.1
log-neighbor-changes
address-family ipv4 unicast
address-family l2vpn evpn
retain route-target all
template peer VTEP
remote-as 65001
update-source loopback0
address-family ipv4 unicast
send-community
send-community extended
route-reflector-client
address-family l2vpn evpn
send-community
send-community extended
route-reflector-client
neighbor 192.168.1.3
inherit peer VTEP
remote-as 65001
neighbor 192.168.1.4
inherit peer VTEP
remote-as 65001

SPINE2配置

======================================================

hostname SPINE-2

nv overlay evpn
feature ospf
feature bgp
feature pim
feature nv overlay

ip pim rp-address 192.168.1.8 group-list 239.0.0.0/24
ip pim log-neighbor-changes
ip pim ssm range 232.0.0.0/8
ip pim anycast-rp 192.168.1.8 192.168.1.1
ip pim anycast-rp 192.168.1.8 192.168.1.2

vrf context management

interface Ethernet1/1
no switchport
ip address 10.10.4.1/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface Ethernet1/2
no switchport
ip address 10.10.2.1/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface loopback0
ip address 192.168.1.2/32
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode

interface loopback1
ip address 192.168.1.8/32
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
line console
line vty
boot nxos bootflash:/nxos.7.0.3.I5.2.bin
router ospf 100
router-id 192.168.1.2
log-adjacency-changes
router bgp 65001
router-id 192.168.1.2
log-neighbor-changes
address-family ipv4 unicast
address-family l2vpn evpn
retain route-target all
template peer VTEP
remote-as 65001
update-source loopback0
address-family ipv4 unicast
send-community
send-community extended
route-reflector-client
address-family l2vpn evpn
send-community
send-community extended
route-reflector-client
neighbor 192.168.1.3
inherit peer VTEP
remote-as 65001
neighbor 192.168.1.4
inherit peer VTEP
remote-as 65001

LEAF101配置

======================================================

hostname LEAF101

nv overlay evpn
feature ospf
feature bgp
feature pim
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay

vlan 1,11,21,31,41,901-904
fabric forwarding anycast-gateway-mac 0000.1111.2222
ip pim rp-address 192.168.1.8 group-list 239.0.0.0/24
ip pim log-neighbor-changes
ip pim ssm range 232.0.0.0/8
vlan 11
vn-segment 160011
vlan 21
vn-segment 160021
vlan 31
vn-segment 160031
vlan 41
vn-segment 160041
vlan 901
vn-segment 900901
vlan 902
vn-segment 900902
vlan 903
vn-segment 900903
vlan 904
vn-segment 900904

vrf context APP
vni 900901
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context CTRIX
vni 900903
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context DB
vni 900904
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context VM
vni 900902
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context management

interface Vlan1

interface Vlan11
no shutdown
mtu 9216
vrf member APP
ip address 10.133.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan21
no shutdown
mtu 9216
vrf member VM
ip address 10.63.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan31
no shutdown
mtu 9216
vrf member CTRIX
ip address 10.158.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan41
no shutdown
mtu 9216
vrf member DB
ip address 10.79.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan901
no shutdown
mtu 9216
vrf member APP
no ip redirects
ip forward

interface Vlan902
no shutdown
mtu 9216
vrf member VM
no ip redirects
ip forward

interface Vlan903
no shutdown
mtu 9216
vrf member CTRIX
no ip redirects
ip forward

interface Vlan904
no shutdown
mtu 9216
vrf member DB
no ip redirects
ip forward

interface nve1
no shutdown
source-interface loopback0
host-reachability protocol bgp
member vni 160011
mcast-group 239.0.0.1
member vni 160021
mcast-group 239.0.0.2
member vni 160031
mcast-group 239.0.0.3
member vni 160041
mcast-group 239.0.0.4
member vni 900901 associate-vrf
member vni 900902 associate-vrf
member vni 900903 associate-vrf
member vni 900904 associate-vrf

interface Ethernet1/1
no switchport
ip address 10.10.1.2/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface Ethernet1/2
no switchport
ip address 10.10.2.2/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface Ethernet1/3
switchport access vlan 11

interface loopback0
ip address 192.168.1.3/32
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
line console
line vty
boot nxos bootflash:/nxos.7.0.3.I5.2.bin
router ospf 100
router-id 192.168.1.3
log-adjacency-changes
router bgp 65001
router-id 192.168.1.3
log-neighbor-changes
address-family ipv4 unicast
address-family l2vpn evpn
neighbor 192.168.1.1
remote-as 65001
update-source loopback0
address-family ipv4 unicast
send-community
send-community extended
address-family l2vpn evpn
send-community
send-community extended
neighbor 192.168.1.2
remote-as 65001
update-source loopback0
address-family ipv4 unicast
send-community
send-community extended
address-family l2vpn evpn
send-community
send-community extended
vrf APP
address-family ipv4 unicast
advertise l2vpn evpn
maximum-paths 2
vrf CTRIX
address-family ipv4 unicast
advertise l2vpn evpn
maximum-paths ibgp 2
vrf DB
address-family ipv4 unicast
advertise l2vpn evpn
maximum-paths ibgp 2
vrf VM
address-family ipv4 unicast
advertise l2vpn evpn
maximum-paths ibgp 2
evpn
vni 160011 l2
rd auto
route-target import auto
route-target export auto
vni 160021 l2
rd auto
route-target import auto
route-target export auto
vni 160031 l2
rd auto
route-target import auto
route-target export auto
vni 160041 l2
rd auto
route-target import auto
route-target export auto
ip tcp path-mtu-discovery

BORDERLEAF配置

======================================================

hostname BORDERLEAF

nv overlay evpn
feature ospf
feature bgp
feature pim
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay

vlan 1,11,21,31,41,901-904
fabric forwarding anycast-gateway-mac 0000.1111.2222
ip pim rp-address 192.168.1.8 group-list 239.0.0.0/24
ip pim log-neighbor-changes
ip pim ssm range 232.0.0.0/8
vlan 11
vn-segment 160011
vlan 21
vn-segment 160021
vlan 31
vn-segment 160031
vlan 41
vn-segment 160041
vlan 901
vn-segment 900901
vlan 902
vn-segment 900902
vlan 903
vn-segment 900903
vlan 904
vn-segment 900904

ip prefix-list static2bgp seq 5 permit 0.0.0.0/0 le 32
route-map static2bgp permit 10
match ip address prefix-list static2bgp
vrf context APP
vni 900901
ip route 0.0.0.0/0 Ethernet1/3.110 10.20.1.2
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context CTRIX
vni 900903
ip route 0.0.0.0/0 Ethernet1/3.130 10.20.3.2
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context DB
vni 900904
ip route 0.0.0.0/0 Ethernet1/3.140 10.20.4.2
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context VM
vni 900902
ip route 0.0.0.0/0 Ethernet1/3.120 10.20.2.2
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
vrf context management

interface Vlan11
no shutdown
mtu 9216
vrf member APP
ip address 10.133.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan21
no shutdown
mtu 9216
vrf member VM
ip address 10.63.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan31
no shutdown
mtu 9216
vrf member CTRIX
ip address 10.158.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan41
no shutdown
mtu 9216
vrf member DB
ip address 10.79.1.254/24
fabric forwarding mode anycast-gateway

interface Vlan901
no shutdown
mtu 9216
vrf member APP
no ip redirects
ip forward

interface Vlan902
no shutdown
mtu 9216
vrf member VM
no ip redirects
ip forward

interface Vlan903
no shutdown
mtu 9216
vrf member CTRIX
no ip redirects
ip forward

interface Vlan904
no shutdown
mtu 9216
vrf member DB
no ip redirects
ip forward

interface nve1
no shutdown
source-interface loopback0
host-reachability protocol bgp
member vni 160011
mcast-group 239.0.0.1
member vni 160021
mcast-group 239.0.0.2
member vni 160031
mcast-group 239.0.0.3
member vni 160041
mcast-group 239.0.0.4
member vni 900901 associate-vrf
member vni 900902 associate-vrf
member vni 900903 associate-vrf
member vni 900904 associate-vrf

interface Ethernet1/1
no switchport
ip address 10.10.4.2/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface Ethernet1/2
no switchport
ip address 10.10.3.2/30
ip ospf network point-to-point
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
no shutdown

interface Ethernet1/3
no switchport
no shutdown

interface Ethernet1/3.110
encapsulation dot1q 110
vrf member APP
ip address 10.20.1.1/30
no shutdown

interface Ethernet1/3.120
encapsulation dot1q 120
vrf member VM
ip address 10.20.2.1/30
no shutdown

interface Ethernet1/3.130
encapsulation dot1q 130
vrf member CTRIX
ip address 10.20.3.1/30
no shutdown

interface Ethernet1/3.140
encapsulation dot1q 140
vrf member DB
ip address 10.20.4.1/30
no shutdown

interface loopback0
ip address 192.168.1.4/32
ip router ospf 100 area 0.0.0.0
ip pim sparse-mode
line console
line vty
boot nxos bootflash:/nxos.7.0.3.I5.2.bin
router ospf 100
router-id 192.168.1.4
log-adjacency-changes
router bgp 65001
router-id 192.168.1.4
log-neighbor-changes
address-family ipv4 unicast
address-family l2vpn evpn
neighbor 192.168.1.1
remote-as 65001
update-source loopback0
address-family ipv4 unicast
send-community
send-community extended
address-family l2vpn evpn
send-community
send-community extended
neighbor 192.168.1.2
remote-as 65001
update-source loopback0
address-family ipv4 unicast
send-community
send-community extended
address-family l2vpn evpn
send-community
send-community extended
vrf APP
address-family ipv4 unicast
advertise l2vpn evpn
redistribute static route-map static2bgp
maximum-paths 2
default-information originate
vrf CTRIX
address-family ipv4 unicast
advertise l2vpn evpn
redistribute static route-map static2bgp
maximum-paths ibgp 2
default-information originate
vrf DB
address-family ipv4 unicast
advertise l2vpn evpn
redistribute static route-map static2bgp
maximum-paths ibgp 2
default-information originate
vrf VM
address-family ipv4 unicast
advertise l2vpn evpn
redistribute static route-map static2bgp
maximum-paths ibgp 2
default-information originate
evpn
vni 16004 l2
rd auto
vni 160011 l2
rd auto
route-target import auto
route-target export auto
vni 160021 l2
rd auto
route-target import auto
route-target export auto
vni 160031 l2
rd auto
route-target import auto
route-target export auto
vni 160041 l2
rd auto
route-target import auto
route-target export auto
ip tcp path-mtu-discovery

ISP配置

======================================================

!
hostname ISP

!
interface Loopback0
ip address 123.103.15.129 255.255.255.255
!
interface GigabitEthernet1.110
encapsulation dot1Q 110
ip address 10.20.1.2 255.255.255.252
!
interface GigabitEthernet1.120
encapsulation dot1Q 120
ip address 10.20.2.2 255.255.255.252
!
interface GigabitEthernet1.130
encapsulation dot1Q 130
ip address 10.20.3.2 255.255.255.252
!
interface GigabitEthernet1.140
encapsulation dot1Q 140
ip address 10.20.4.2 255.255.255.252
!
interface GigabitEthernet2
no ip address
shutdown
negotiation auto
!
interface GigabitEthernet3
no ip address
shutdown
negotiation auto
!
interface GigabitEthernet4
no ip address
shutdown
negotiation auto
!
!
virtual-service csr_mgmt
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
ip route 10.63.0.0 255.255.0.0 GigabitEthernet1.120 10.20.2.1
ip route 10.79.0.0 255.255.0.0 GigabitEthernet1.140 10.20.4.1
ip route 10.133.0.0 255.255.0.0 GigabitEthernet1.110 10.20.1.1
ip route 10.158.0.0 255.255.0.0 GigabitEthernet1.130 10.20.3.1
!

在leaf上查看NVE peer

======================================================

在VPC上ping测试external的loopback地址123.103.15.129/32

======================================================