BGP EVPN实验 同子网互访
要求:PC1和PC3属于BD100,PC2和PC4属于BD200,vlan id从左到右依次为10,20,30,40,实现同BD下的网段二层互通。用户网段PC1和PC3为192.168.1.0/24,PC2和PC4为192.168.2.0/24,AR1和CE1-3的互联网段分别为10.0.11.0/30 10.0.12.0/30
过程:
1 配置OSPF路由协议实现CE1和CE3的loopback 0地址10.1.1.1和10.3.3.3的互通
2 配置基础二层接口类型和vlan放行
3 打开evpn对于虚拟网络的支持,建立BGP evpn的邻居关系
4 创建广播域bridge-domain 100和200,并且创建关联VXLAN网络标识VNI 100和200,配置evpn的RD与RT
5 创建NVE接口配置源ip和VNI指定远端VTPE的ip地址建立头端复制列表,协议为bgp
6 创建二层子接口业务接入方式,封装vlan tag,绑定BD
具体步骤:
1(OSPF)
#CE1 (AR1和CE3一样)
ospf 100
area 0.0.0.0
network 0.0.0.0 255.255.255.255
测试联通性:
2(Vlan)
#S1 (S2配置雷同)
VLAN 10
VLAN 20
interface GE1/0/1
port default vlan 10
interface GE1/0/2
port default vlan 20
interface GE1/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
#CE1 (CE3配置一样)
interface GE1/0/3
port link-type trunk
3 (Evpn)
evpn-overlay enable
#CE1
bgp 100
private-4-byte-as enable
peer 10.3.3.3 as-number 100
peer 10.3.3.3 connect-interface LoopBack0
#
ipv4-family unicast
peer 10.3.3.3 enable
#
l2vpn-family evpn
policy vpn-target
peer 10.3.3.3 enable
#CE3
bgp 100
private-4-byte-as enable
peer 10.1.1.1 as-number 100
peer 10.1.1.1 connect-interface LoopBack0
#
ipv4-family unicast
peer 10.1.1.1 enable
#
l2vpn-family evpn
policy vpn-target
peer 10.1.1.1 enable
4 (BD和VNI)
#CE1 (CE3一样)
bridge-domain 100
vxlan vni 100
#
evpn
route-distinguisher 100:1
vpn-target 100:1 export-extcommunity
vpn-target 100:1 import-extcommunity
#
bridge-domain 200
vxlan vni 200
#
evpn
route-distinguisher 200:1
vpn-target 200:1 export-extcommunity
vpn-target 200:1 import-extcommunity
5 (NVE接口)
#CE1
interface Nve1
source 10.1.1.1
vni 100 head-end peer-list protocol bgp
vni 200 head-end peer-list protocol bgp
#CE3
interface Nve1
source 10.3.3.3
vni 100 head-end peer-list protocol bgp
vni 200 head-end peer-list protocol bgp
6 (子接口)
#CE1
interface GE1/0/3.100 mode l2
encapsulation dot1q vid 10
bridge-domain 100
#
interface GE1/0/3.200 mode l2
encapsulation dot1q vid 20
bridge-domain 200
#CE3
interface GE1/0/3.100 mode l2
encapsulation dot1q vid 30
bridge-domain 100
#
interface GE1/0/3.200 mode l2
encapsulation dot1q vid 40
bridge-domain 200
查询与验证:
查看bgp evpn邻居状态
查看bgp evpn路由表
查看vxlan vni信息
查看vxlan隧道详细信息
测试pc连通性,并抓包观察
刷新BGP路由或者进程,抓取type 2和3类路由