Vxlan Evpn Notes
Vxlan Evpn Notes
com
Page | 1
bestpath-network.com
• DC.A-Spine-01
hostname DC.A-Spine-01
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
evpn multisite border-gateway 500
delay-restore time 300
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback102
multisite border-gateway interface loopback103
member vni 100000 associate-vrf
member vni 101001
multisite ingress-replication
ingress-replication protocol bgp
member vni 101002
multisite ingress-replication
ingress-replication protocol bgp
interface Ethernet1/1
Page | 2
bestpath-network.com
no switchport
mtu 9000
ip address 10.1.1.2/30
evpn multisite dci-tracking
no shutdown
interface Ethernet1/3
no switchport
mtu 9000
ip address 10.0.1.5/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface Ethernet1/5
no switchport
mtu 9000
ip address 10.0.1.1/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface loopback0
ip address 1.1.1.1/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback1
description Anycast-RP
ip address 1.1.1.10/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback101
ip address 1.1.1.101/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback102
ip address 1.1.1.102/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback103
description Anycast-VTEP-Multi_Site
ip address 1.1.1.103/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
Page | 3
bestpath-network.com
neighbor 3.3.3.3
remote-as 65001
update-source loopback0
address-family ipv4 unicast
address-family l2vpn evpn
send-community
send-community extended
route-reflector-client
neighbor 4.4.4.4
remote-as 65001
update-source loopback0
address-family ipv4 unicast
address-family l2vpn evpn
send-community
send-community extended
route-reflector-client
neighbor 5.5.5.101
remote-as 65002
update-source loopback101
ebgp-multihop 255
peer-type fabric-external
address-family l2vpn evpn
send-community
send-community extended
rewrite-evpn-rt-asn
neighbor 6.6.6.101
remote-as 65002
update-source loopback101
ebgp-multihop 255
peer-type fabric-external
address-family l2vpn evpn
send-community
send-community extended
rewrite-evpn-rt-asn
neighbor 10.1.1.1
remote-as 65000
update-source Ethernet1/1
address-family ipv4 unicast
next-hop-self
Page | 4
bestpath-network.com
• DC.A-Spine-02
hostname DC.A-Spine-02
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
evpn multisite border-gateway 500
delay-restore time 300
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback102
multisite border-gateway interface loopback103
member vni 100000 associate-vrf
member vni 101001
multisite ingress-replication
ingress-replication protocol bgp
member vni 101002
multisite ingress-replication
ingress-replication protocol bgp
interface Ethernet1/2
Page | 5
bestpath-network.com
no switchport
mtu 9000
ip address 10.1.1.6/30
evpn multisite dci-tracking
no shutdown
interface Ethernet1/4
no switchport
mtu 9000
ip address 10.0.1.9/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface Ethernet1/6
no switchport
mtu 9000
ip address 10.0.1.13/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface loopback0
ip address 2.2.2.2/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback1
description Anycast-RP
ip address 1.1.1.10/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback101
ip address 2.2.2.101/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback102
ip address 2.2.2.102/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback103
description Anycast-VTEP-Multi_Site
ip address 1.1.1.103/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
Page | 6
bestpath-network.com
neighbor 3.3.3.3
remote-as 65001
update-source loopback0
address-family ipv4 unicast
address-family l2vpn evpn
send-community
send-community extended
route-reflector-client
neighbor 4.4.4.4
remote-as 65001
update-source loopback0
address-family ipv4 unicast
address-family l2vpn evpn
send-community
send-community extended
route-reflector-client
neighbor 5.5.5.101
remote-as 65002
update-source loopback101
ebgp-multihop 255
peer-type fabric-external
address-family l2vpn evpn
send-community
send-community extended
rewrite-evpn-rt-asn
neighbor 6.6.6.101
remote-as 65002
update-source loopback101
ebgp-multihop 255
peer-type fabric-external
address-family l2vpn evpn
send-community
send-community extended
rewrite-evpn-rt-asn
neighbor 10.1.1.5
remote-as 65000
update-source Ethernet1/2
address-family ipv4 unicast
next-hop-self
Page | 7
bestpath-network.com
• DC.A-Leaf-01
hostname DC.A-Leaf-01
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface Vlan1001
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.101.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
interface Vlan1002
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.102.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
Page | 8
bestpath-network.com
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback0
member vni 100000 associate-vrf
member vni 101001
suppress-arp
mcast-group 239.0.0.1
member vni 101002
suppress-arp
mcast-group 239.0.0.1
interface Ethernet1/1
switchport access vlan 1001
spanning-tree port type edge
interface Ethernet1/4
no switchport
mtu 9000
ip address 10.0.1.10/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface Ethernet1/5
no switchport
mtu 9000
ip address 10.0.1.2/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface loopback0
ip address 3.3.3.3/32
ip router isis UNDERLAY
ip pim sparse-mode
Page | 9
bestpath-network.com
• DC.A-Leaf-02
hostname DC.A-Leaf-02
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface Vlan1001
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.101.1/24
Page | 10
bestpath-network.com
no ipv6 redirects
fabric forwarding mode anycast-gateway
interface Vlan1002
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.102.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback0
member vni 100000 associate-vrf
member vni 101001
suppress-arp
mcast-group 239.0.0.1
member vni 101002
suppress-arp
mcast-group 239.0.0.1
interface Ethernet1/1
switchport access vlan 1002
spanning-tree port type edge
interface Ethernet1/3
no switchport
mtu 9000
ip address 10.0.1.6/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface Ethernet1/6
no switchport
mtu 9000
ip address 10.0.1.14/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface loopback0
ip address 4.4.4.4/32
ip router isis UNDERLAY
ip pim sparse-mode
Page | 11
bestpath-network.com
• DC.B-Spine-01
hostname DC.B-Spine-01
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
evpn multisite border-gateway 600
delay-restore time 300
Page | 12
bestpath-network.com
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback102
multisite border-gateway interface loopback103
member vni 100000 associate-vrf
member vni 101001
multisite ingress-replication
ingress-replication protocol bgp
member vni 101002
multisite ingress-replication
ingress-replication protocol bgp
interface Ethernet1/1
no switchport
mtu 9000
ip address 10.1.2.2/30
evpn multisite dci-tracking
no shutdown
interface Ethernet1/3
no switchport
mtu 9000
ip address 10.0.2.5/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface Ethernet1/5
no switchport
mtu 9000
ip address 10.0.2.1/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface loopback0
ip address 5.5.5.5/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback1
description Anycast-RP
ip address 5.5.5.10/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback101
ip address 5.5.5.101/32 tag 8910
Page | 13
bestpath-network.com
interface loopback102
ip address 5.5.5.102/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback103
description Anycast-VTEP-Multi_Site
ip address 5.5.5.103/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
Page | 14
bestpath-network.com
• DC.B-Spine-02
hostname DC.B-Spine-02
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
evpn multisite border-gateway 600
delay-restore time 300
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback102
multisite border-gateway interface loopback103
member vni 100000 associate-vrf
member vni 101001
suppress-arp
multisite ingress-replication
ingress-replication protocol bgp
Page | 15
bestpath-network.com
interface Ethernet1/2
no switchport
mtu 9000
ip address 10.1.2.6/30
evpn multisite dci-tracking
no shutdown
interface Ethernet1/4
no switchport
mtu 9000
ip address 10.0.2.9/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface Ethernet1/6
no switchport
mtu 9000
ip address 10.0.2.13/30
ip router isis UNDERLAY
ip pim sparse-mode
evpn multisite fabric-tracking
no shutdown
interface loopback0
ip address 6.6.6.6/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback1
description Anycast-RP
ip address 5.5.5.10/32
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback101
ip address 6.6.6.101/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback102
ip address 6.6.6.102/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
interface loopback103
description Anycast-VTEP-Multi_Site
ip address 5.5.5.103/32 tag 8910
ip router isis UNDERLAY
ip pim sparse-mode
Page | 16
bestpath-network.com
• DC.B-Leaf-01
hostname DC.B-Leaf-01
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
Page | 17
bestpath-network.com
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface Vlan1001
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.101.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
interface Vlan1002
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.102.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback0
member vni 100000 associate-vrf
member vni 101001
suppress-arp
mcast-group 239.100.1.1
member vni 101002
suppress-arp
mcast-group 239.100.1.1
interface Ethernet1/1
switchport access vlan 1001
Page | 18
bestpath-network.com
interface Ethernet1/4
no switchport
mtu 9000
ip address 10.0.2.10/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface Ethernet1/5
no switchport
mtu 9000
ip address 10.0.2.2/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface loopback0
ip address 7.7.7.7/32
ip router isis UNDERLAY
ip pim sparse-mode
Page | 19
bestpath-network.com
• DC.B-Leaf-02
hostname DC.B-Leaf-02
feature telnet
nv overlay evpn
feature bgp
feature pim
feature isis
feature fabric forwarding
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
interface Vlan1000
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip forward
no ipv6 redirects
interface Vlan1001
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.101.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
interface Vlan1002
no shutdown
mtu 9216
vrf member EVPN_Multi-Site
no ip redirects
ip address 172.16.102.1/24
no ipv6 redirects
fabric forwarding mode anycast-gateway
Page | 20
bestpath-network.com
interface nve1
no shutdown
host-reachability protocol bgp
source-interface loopback0
member vni 100000 associate-vrf
member vni 101001
suppress-arp
mcast-group 239.100.1.1
member vni 101002
suppress-arp
mcast-group 239.100.1.1
interface Ethernet1/1
switchport access vlan 1002
spanning-tree port type edge
interface Ethernet1/3
no switchport
mtu 9000
ip address 10.0.2.6/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface Ethernet1/6
no switchport
mtu 9000
ip address 10.0.2.14/30
ip router isis UNDERLAY
ip pim sparse-mode
no shutdown
interface loopback0
ip address 8.8.8.8/32
ip router isis UNDERLAY
ip pim sparse-mode
Page | 21
bestpath-network.com
• DC.A-BGW-01
hostname DC.A-BGW-01
interface Loopback0
no shutdown
ip address 10.10.10.10 255.255.255.255
interface GigabitEthernet0/0
no shutdown
mtu 9000
ip address 30.0.1.1 255.255.255.252
duplex auto
speed auto
media-type rj45
interface GigabitEthernet0/1
no shutdown
mtu 9000
ip address 10.1.1.1 255.255.255.252
duplex auto
speed auto
media-type rj45
interface GigabitEthernet0/2
no shutdown
mtu 9000
ip address 10.1.1.5 255.255.255.252
duplex auto
speed auto
media-type rj45
Page | 22
bestpath-network.com
• DC.B-BGW-01
hostname DC.B-BGW-01
interface Loopback0
no shutdown
ip address 20.20.20.20 255.255.255.255
interface GigabitEthernet0/1
no shutdown
mtu 9000
ip address 10.1.2.1 255.255.255.252
duplex auto
speed auto
media-type rj45
interface GigabitEthernet0/2
no shutdown
mtu 9000
ip address 10.1.2.5 255.255.255.252
duplex auto
speed auto
media-type rj45
interface GigabitEthernet0/3
no shutdown
mtu 9000
ip address 30.0.1.2 255.255.255.252
duplex auto
speed auto
media-type rj45
Page | 23
bestpath-network.com
• WAN Private
hostname Switch
interface GigabitEthernet0/0
no shutdown
mtu 9000
media-type rj45
negotiation auto
interface GigabitEthernet0/3
no shutdown
mtu 9000
media-type rj45
negotiation auto
• Example Verification
a. Verification IS-IS routing protocol
For this verification, you can use command show isis adjacency and make
sure stete of ISIS neighbor is “UP”
b. Verification MP-BGP for L2VPN EVPN
On this lab, we have two BGP neighbor, neighbor IPv4 unicast & neighbor for
EVPN. So we for this verification we can use “show bgp ipv4 unicast
summary” to verify BGP IPv4 stete
Page | 24
bestpath-network.com
Make sure the admin & oper status is "UP" and multi-site
VTEP verification we can check on the spine device because this
spine will communicate directly between DC.A and DC.B
Page | 25
bestpath-network.com
if the oper status is “down”, make sure the BGP is used between DC.A
& DC.B is established, and make sure the spine DC.A & DC.B loopback
102 & 103 can communicate.
d. verification EVPN table
For this verification, you can use the command "show bgp l2vpn evpn"
And in this table, you can see prefixes from clients advertised by
leaf devices into EVPN.
e. verification L2ROUTE
On this l2route, you can see IP as well as client mac address
advertised by leaf device to EVPN, in this table all prefixes
advertised from local DC or remote DC will appear.
And it can be confirmed when the prefix client is from DC.A
(172.16.101.100 & 172.16.102.100) appears here, it means that our
multi-site configuration has been successful and the clients between
DC.A & DC.B can communicate with each other.
Page | 26
bestpath-network.com
You can see the IP configuration used by the client in the topology
Page | 27