一、实验需求:
将散落在不同设备上的服务器(PC)构建成一个虚拟网络,实现资源整合和业务灵活部署。相同网段的服务器(PC)之间实现二层互通。
二、实验拓扑:
三、配置思路:
1.分别在CE1、VTEP1(HF)、VTEP2(SH)上配置路由协议,保证网络三层互通。
2.分别在VTEP1(HF)、VTEP2(SH)上配置VXLAN接入业务部署方式,在SW1、SW2上配置VLAN。
3.分别在VTEP1(HF)、VTEP2(SH)上BD域里配置EVPN实例。
4.分别在VTEP1(HF)、VTEP2(SH)上配置之间的BGP EVPN对等体关系。
5.分别在VTEP1(HF)、VTEP2(SH)上配置VXLAN隧道目的端地址。
四、配置过程:
1.CE1、VTEP1(HF)、VTEP2(SH)配置三层接口地址,跑OSPF:
sysname CE1
interface GE1/0/0
undo portswitch
undo shutdown
ip address 10.1.12.1 255.255.255.0
interface GE1/0/1
undo portswitch
undo shutdown
ip address 10.1.13.1 255.255.255.0
interface LoopBack0
ip address 1.1.1.1 255.255.255.255
ospf 1 router-id 1.1.1.1
area 0.0.0.0
network 1.1.1.1 0.0.0.0
network 10.1.12.0 0.0.0.255
network 10.1.13.0 0.0.0.255
--------------------------------------------------------------
sysname HF
evpn-overlay enable
interface GE1/0/0
undo portswitch
undo shutdown
ip address 10.1.12.2 255.255.255.0
interface LoopBack0
ip address 2.2.2.2 255.255.255.255
ospf 1 router-id 2.2.2.2
area 0.0.0.0
network 2.2.2.2 0.0.0.0
network 10.1.12.0 0.0.0.255
--------------------------------------------------------------
sysname SH
evpn-overlay enable
interface GE1/0/0
undo portswitch
undo shutdown
ip address 10.1.13.3 255.255.255.0
interface LoopBack0
ip address 3.3.3.3 255.255.255.255
ospf 1 router-id 3.3.3.3
area 0.0.0.0
network 3.3.3.3 0.0.0.0
network 10.1.13.0 0.0.0.255
2.VTEP1(HF)、VTEP2(SH)上以dot1q封装模式配置VAP,SW1、SW2上配置VLAN:
HF:
interface GE1/0/1
undo portswitch
undo shutdown
interface GE1/0/1.10 mode l2
encapsulation dot1q vid 10
bridge-domain 10
--------------------------------------------------
SH:
interface GE1/0/1
undo portswitch
undo shutdown
interface GE1/0/1.10 mode l2
encapsulation dot1q vid 10
bridge-domain 10
---------------------------------------------------
SW1:
sysname SW1
vlan batch 10
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10
interface GigabitEthernet0/0/2
port link-type access
port default vlan 10
----------------------------------------------------
SW2:
sysname SW2
vlan batch 10
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 10
interface GigabitEthernet0/0/2
port link-type access
port default vlan 10
3.VTEP1(HF)、VTEP2(SH)配置EVPN实例:
HF:
bridge-domain 10
vxlan vni 10
evpn
route-distinguisher 65000:2
vpn-target 1:1 export-extcommunity
vpn-target 2:2 import-extcommunity
-----------------------------------------------------------
SH:
bridge-domain 10
vxlan vni 10
evpn
route-distinguisher 65000:3
vpn-target 2:2 export-extcommunity
vpn-target 1:1 import-extcommunity
4.VTEP1(HF)、VTEP2(SH)配置BGP EVPN对等体关系:
HF:
bgp 65000
router-id 2.2.2.2
peer 3.3.3.3 as-number 65000
peer 3.3.3.3 connect-interface LoopBack0
l2vpn-family evpn
policy vpn-target
peer 3.3.3.3 enable
-----------------------------------------------------------
SH:
bgp 65000
router-id 3.3.3.3
peer 2.2.2.2 as-number 65000
peer 2.2.2.2 connect-interface LoopBack0
l2vpn-family evpn
policy vpn-target
peer 2.2.2.2 enable
5.VTEP1(HF)、VTEP2(SH)配置NVE:
HF:
interface Nve1
source 2.2.2.2
vni 10 head-end peer-list protocol bgp
------------------------------------------------------------
SH:
interface Nve1
source 3.3.3.3
vni 10 head-end peer-list protocol bgp
五、结果验证:
1.PC1ping通PC2:
2.HF与SH之间vxlan隧道正常,类型动态:
3.查看ARP信息,并查看HF--CE1侧抓包报文如下:
六、实验链接:
永久链接:https://pan.baidu.com/s/19FuMT6xOpX5Ro42iFXPBrg?pwd=7bil
提取码:7bil