外部连通性和与对称IRB的IVRL的示例

在对称的IRB部署中,IVRL通常在边框VTEP上配置。

在Border VTEP上,安装了主机路由(由Route-2通过远程VTEP发布)。同样,由其他VTEP宣传的EVPN Type-5前缀也被安装为前缀路由(例如,IPv4覆盖网络的A /24前缀)。这些路由可以进一步汇总并泄漏到其他VRF(例如,一个名称的VRF外部的),然后通过诸如OSPF或EBGP等协议向外部网络做广告。

同样,在边境VTEP上,VRF的路线外部的可以泄漏到EVPN覆盖VRF,然后作为所有其他VTEP的5型前缀做广告。

例子

此示例显示了拓扑和样品配置,其中IVRL与对称IRB一起使用:

有2个VTEP,即VTEP1和VTEP2。VTEP2是边界VTEP。两个VTEP都有两个租户VRF,即VRF红色的和VRF蓝色的。在VTEP2上,还有一个额外的VRF外部的配置为具有EXT_RTR的外部连接。EXT_RTR是运行OSPF的路由器。在VTEP2上,OSPF路线从Ext_RTR接收到VRF外部的被泄漏到VRF红色的和VRF蓝色的(通过配置重新分配OSPF在里面路由器bgp上下文和配置路由泄漏所需的路由目标),然后将泄漏的路由宣传为EVPN类型5的前缀VTEP1。

同样在VTEP2上,EVPN覆盖路由在VRF中红色的和VRF蓝色的被泄漏到VRF外部的然后由OSPF宣传泄漏的路线(通过配置重新分配BGP在里面路由器OSPF上下文)到外部路由器。

脊柱:  -  - - !router ospf 1 router-id 2.2.2.2 area 0.0.0.0 interface 1/1/1 no shutdown routing ip address 10.10.10.2/24 ip ospf 1 area 0.0.0.0 interface 1/1/2 no shutdown routing ip address 20.20.20.2/24 IP OSPF 1区域0.0.0.0接口回路1 IP地址2.2.2.2.24 IP OSPF 1区域0.0.0.0 Router BGP 1邻居1.1.1.1远程AS 1邻居1邻居1.1.1.1 Update-ource-source loopback 1远程AS 1邻居3.3.3.3 Update-ource loopback 1地址 - 家庭L2VPN evpn evpn邻居1.1.1.1激活邻居1.1.1.1 route-reflecter-reflector-client-client邻居1.1.1.1 send-community扩展邻居3.3.3.3.3.3.3.3.3.3激活邻居3.3.3.3.33.3路线- 反射委员会 - 客户邻居3.3.3.3发送社区扩展出口地址 - 地址 - 家庭叶1:------ VRF蓝色RD 1:100 Route-Target-Target Target Export 1:100 EVPN Route-target-target-target-target toctim 1:100 EVPN VRF VRF RED RD RD 1:200路线目标导出1:200 EVPN路线目标进口1:200 EVPN!VLAN 1,20,40 Virtual-Mac 00:01:00:00:00:00!路由器OSPF 1 Router-ID 1.1.1.1区域0.0.0.0 EVPN VLAN 20 RD AUTO ROUTE-ROUSE-TARGET目标导出自动路线目标导入Aut Auto VLAN 40 RD AUTO ROUTO ROUTA-TARGET TARGET TARGET TARGET EXTOR-TARGET AUTO ROUSE TARGORT AUTO ROUSE-TARGORT AUTO ROUSA-TARGET AUTO ROUSA-TARGET AUTO-TARGET IMPART AUTO AUTO ITPOR AUTO AUTO界面1/1/1/1/1/1/1/1/1/1/1/1/1/1/1/1/1/1/路由IP地址10.10.10.1/24 IP OSPF 1区域0.0.0.0接口1/1/2否关闭无路由VLAN访问20接口20接口1/1/3 no shutdown no shutdown no theardown no routing vlan访问vlan访问40接口loopback 1 ip地址1.1.1.1.1/24 IP OSPF 1区域0.0.0.0接口VLAN20 VRF附件蓝色IP地址100.100.20.24 Active-Gateway IP Mac 00:01:00:00:00:00:00:01 Active-Gateway IP 100.100.20.20.2200.200.40.2/24 Active-Gateway IP Mac 00:01:00:00:00:00:01 Active-Gateway IP 200.200.200.40.1接口VXLAN 1源IP 1.1.1.1 no shutdown vni vni 20 vni 20 vlan 20!vni 40 vlan 40!vni 10000路由VRF蓝色VNI 20000路由VRF红色路由器BGP 1邻居2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2 update-oure-source loopback 1地址 - 户主l2vpn evpn evpn evpn evpn evpn ever 2.2.2.2激活邻居2.2.2.2.2.2.2.2.2.2.2.2.2.2.2.2地址家庭! vrf blue address-family ipv4 unicast redistribute connected exit-address-family ! vrf red address-family ipv4 unicast redistribute connected exit-address-family ! LEAF2: (Border leaf) ----- vrf blue rd 1:100 route-target export 1:100 evpn route-target import 1:100 evpn address-family ipv4 unicast route-target export 1:100 route-target import 1:300 exit-address-family vrf red rd 1:200 route-target export 1:200 evpn route-target import 1:200 evpn address-family ipv4 unicast route-target export 1:200 route-target import 1:300 exit-address-family vrf external rd 1:300 address-family ipv4 unicast route-target export 1:300 route-target import 1:100 route-target import 1:200 exit-address-family vlan 1,10,30 virtual-mac 00:02:00:00:00:00 ! router ospf 1 router-id 3.3.3.3 area 0.0.0.0 router ospf 1 vrf external router-id 30.1.1.1 redistribute bgp area 0.0.0.0 evpn vlan 10 rd auto route-target export auto route-target import auto vlan 30 rd auto route-target export auto route-target import auto interface 1/1/1 no shutdown routing ip address 20.20.20.1/24 ip ospf 1 area 0.0.0.0 interface 1/1/2 no shutdown no routing vlan access 10 interface 1/1/3 no shutdown no routing vlan access 30 interface 1/1/4 no shutdown routing vrf attach shared ip address 30.1.1.1/24 ip ospf 1 area 0.0.0.0 interface loopback 1 ip address 3.3.3.3/24 ip ospf 1 area 0.0.0.0 interface vlan10 vrf attach blue ip address 100.100.10.2/24 active-gateway ip mac 00:02:00:00:00:02 active-gateway ip 100.100.10.1 interface vlan30 vrf attach red ip address 200.200.30.2/24 active-gateway ip mac 00:02:00:00:00:02 active-gateway ip 200.200.30.1 interface vxlan 1 source ip 3.3.3.3 no shutdown vni 10 vlan 10 ! vni 30 vlan 30 ! vni 10000 routing vrf blue ! vni 20000 routing vrf red ! router bgp 1 neighbor 2.2.2.2 remote-as 1 neighbor 2.2.2.2 update-source loopback 1 address-family l2vpn evpn neighbor 2.2.2.2 activate neighbor 2.2.2.2 send-community extended exit-address-family ! vrf blue address-family ipv4 unicast redistribute connected exit-address-family ! vrf red address-family ipv4 unicast redistribute connected exit-address-family ! vrf external address-family ipv4 unicast redistribute connected redistribute ospf exit-address-family ! EXT_RTR(OSPF): Router connected to border leaf ------------- vrf external router ospf 1 vrf external router-id 30.1.1.2 area 0.0.0.0 interface 1/1/1 no shutdown routing vrf attach external ip address 30.1.1.2/24 ip ospf 1 area 0.0.0.0 interface 1/1/2 no shutdown routing vrf attach external ip address 40.1.1.1/24 ip ospf 1 area 0.0.0.0
笔记:

在VTEP上,本地学到的邻居条目(ARP/ND)可以通过客户/面向租户SVI的动态学习(通过数据平面)通过BGP-EVPN控制平面上的路由类型2作为主机路由发布。这些动态条目不能在非BGP-EVPN路由域中重新分配为主机路由。例如,在上图中,重新分配主机路由在EVPN-VLAN上下文下配置,以确保在VTEP2的本地学习的ARP条目在路由2 type-2 AS /32前缀vtep1中宣传。但是,这些ARP条目不能被广告为 /32通往ext_rtr的路由。