实验目的
通过evpn + vxlan 自动建立隧道,实现不同资源池的租户二层互通。
实验环境
华三HCL 模拟器,两台6850(sw1,sw2)当做RR(路由反射器),两台6850(sw3,sw4)当做VXLAN网关,两台5820(sw5,sw6)当做终端接入
拓扑如下
配置步骤
1、SW1,SW2,SW3,SW4 之间配置通过ospf 互联
2、SW3,SW4 分别与SW1,SW2 建立BGP EVPN 邻居
3、配置VSI,并关联VXLAN ID
4、配置SW3,SW4,SW5,SW6接入交换机端口
5、测试PC二层互通
步骤1 SW1,SW2,SW3,SW4 之间配置通过ospf 互联
sw1
sysname sw1
int lo 0
ip add 1.1.1.1 32
quit
int gi 1/0/47
port link-mode route
y
ip add 172.13.1.1 24
quit
int gi 1/0/48
port link-mode route
y
ip add 172.14.1.1 24
quit
ospf 1 route-id 1.1.1.1
area 0
network 172.13.1.1 0.0.0.0
network 172.14.1.1 0.0.0.0
network 1.1.1.1 0.0.0.0
quit
sw2
sysname sw2
int lo 0
ip add 2.2.2.2 32
quit
int gi 1/0/47
port link-mode route
y
ip add 172.24.1.1 24
quit
int gi 1/0/48
port link-mode route
y
ip add 172.23.1.1 24
quit
ospf 1 router-id 2.2.2.2
area 0
network 172.24.1.1 0.0.0.0
network 172.23.1.1 0.0.0.0
network 2.2.2.2 0.0.0.0
quit
sw3
sysname sw3
int lo 0
ip add 3.3.3.3 32
quit
int gi 1/0/47
port link-mode route
y
ip add 172.13.1.2 24
quit
int gi 1/0/48
port link-mode route
y
ip add 172.23.1.2 24
quit
ospf 1 router-id 3.3.3.3
area 0
network 172.13.1.2 0.0.0.0
network 172.23.1.2 0.0.0.0
network 3.3.3.3 0.0.0.0
quit
sw4
sysname sw4
int lo 0
ip add 4.4.4.4 32
quit
int gi 1/0/47
port link-mode route
y
ip add 172.24.1.2 24
quit
int gi 1/0/48
port link-mode route
y
ip add 172.14.1.2 24
quit
ospf 1 router-id 4.4.4.4
area 0
network 172.14.1.2 0.0.0.0
network 172.24.1.2 0.0.0.0
network 4.4.4.4 0.0.0.0
quit
ospf 状态
步骤2 SW3,SW4 分别与SW1,SW2 建立BGP EVPN 邻居
sw1/sw2
bgp 100
peer 3.3.3.3 as 100
peer 3.3.3.3 con lo 0
peer 4.4.4.4 as 100
peer 4.4.4.4 con lo 0
address-family l2vpn evpn
peer 3.3.3.3 enable
peer 3.3.3.3 reflect-client
peer 4.4.4.4 enable
peer 4.4.4.4 reflect-client
undo policy vpn-target
quit
sw3/sw4
bgp 100
peer 1.1.1.1 as 100
peer 1.1.1.1 con lo 0
peer 2.2.2.2 as 100
peer 2.2.2.2 con lo 0
address-family l2vpn evpn
peer 1.1.1.1 enable
peer 2.2.2.2 enable
quit
BGP EVPN 状态
步骤3 配置VSI,并关联VXLAN ID
sw3/sw4
l2vpn enable
vxlan tun mac-lea disable
vxlan tun arp-lear disable
vsi vpna
vxlan 10
quit
evpn enc vxlan
route-dis 10:10
vpn-target 10:10
quit
vxlan 隧道状态
步骤4 配置SW3,SW4,SW5,SW6接入交换机端口
sw3/sw4
int gi 1/0/1
port link-type trunk
port trunk permit vlan all
vtep access port
service-instance 10
encapsulation s-vid 10
xconnect vsi vpna
quit
sw5/sw6
sysname sw6
vlan 10
int gi 1/0/1
port link-type trunk
port trunk permit vlan all
quit
int gi 1/0/10
port link-type access
port access vlan 10
quit
步骤5 测试PC二层互通
以上 ,实现相同vlan 的租户二层互通