一、实验需求:
利用Vxlan技术将不同设备下的服务器(PC)构建成一个虚拟网络。相同业务的服务器(PC1与PC2)之间需要实现二层互通。
二、实验拓扑:
三、配置思路:
1.分别在VTEP1(HF)、VTEP2(SH)、CE1上配置路由协议,保证网络三层互通。
2.分别在VTEP1(HF)、VTEP2(SH)上配置VXLAN接入业务部署方式,在LSW1、LSW2上配置VLAN。
3.分别在VTEP1(HF)、VTEP2(SH)上配置VXLAN隧道。
四、配置过程:
1.配置CE1、VTEP1(HF)、VTEP2(SH)的路由协议做三层互通:
sysname CE1
interface GE1/0/0
undo portswitch
undo shutdown
ip address 10.1.12.1 255.255.255.0
interface GE1/0/1
undo portswitch
undo shutdown
ip address 10.1.13.1 255.255.255.0
interface LoopBack0
ip address 1.1.1.1 255.255.255.255
ospf 1 router-id 1.1.1.1
area 0.0.0.0
network 1.1.1.1 0.0.0.0
network 10.1.12.0 0.0.0.255
network 10.1.13.0 0.0.0.255
---------------------------------------------------------------------
sysname HF
interface GE1/0/0
undo portswitch
undo shutdown
ip address 10.1.12.2 255.255.255.0
interface LoopBack0
ip address 2.2.2.2 255.255.255.255
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 2.2.2.2 0.0.0.0
network 10.1.12.0 0.0.0.255
---------------------------------------------------------------------
sysname SH
interface GE1/0/0
undo portswitch
undo shutdown
ip address 10.1.13.3 255.255.255.0
interface LoopBack0
ip address 3.3.3.3 255.255.255.255
ospf 1 router-id 3.3.3.3
area 0.0.0.0
network 3.3.3.3 0.0.0.0
2.分别在LSW1、LSW2上配置VLAN,在VTEP1(HF)、VTEP2(SH)上配置业务接入点(VAP)
sysname SW1
vlan batch 10
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10
interface GigabitEthernet0/0/2
port link-type access
port default vlan 10
-------------------------------------------------------------------
sysname SW2
vlan batch 10
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10
interface GigabitEthernet0/0/2
port link-type access
port default vlan 10
-------------------------------------------------------------------
HF:
bridge-domain 10
vxlan vni 10
interface GE1/0/1
undo portswitch
undo shutdown
interface GE1/0/1.10 mode l2
encapsulation dot1q vid 10
bridge-domain 10
-------------------------------------------------------------------
SH:
bridge-domain 10
vxlan vni 10
interface GE1/0/1
undo portswitch
undo shutdown
interface GE1/0/1.10 mode l2
encapsulation dot1q vid 10
bridge-domain 10
3.分别在VTEP1(HF)、VTEP2(SH)上配置VXLAN隧道
HF:
interface Nve1
source 2.2.2.2
vni 10 head-end peer-list 3.3.3.3
-----------------------------------------------------------------
SH:
interface Nve1
source 3.3.3.3
vni 10 head-end peer-list 2.2.2.2
五、结果验证:
1.尝试PC1ping通PC2:
2.抓包学习MAC in UDP封装模式:
1).外层以太网报文头部,源MAC为VTEP(HF)的NVE接口MAC,目的MAC为下一跳设备(CE1的GE1/0/0)的接口MAC;
2)外层IP报文头部,源IP为VTEP(HF)的NVE隧道地址,目的IP为VTEP(SH)的NVE隧道地址;
3)UDP报文,源端口号HASH算法计算得出,目的端口号固定4789;
4)真实互访的以太网头部和IP报文头部,以及真实需要传递的业务数据。