VXLAN Journey - Part 06 - VXLAN and vPC Leaf Switches
This is the last part before we scale up our topology with dedicated Spine, Leaf, Border Gateway and Border Leaf switches which represent - how VXLAN network is built in modern data center networks. In this blog - we will explore how to configure a pair of vPC switches for VXLAN/MPBGP-EVPN. We need to do some extra configurations in the switches because in vPC enabled switches, they each member switch run their own control plane (no shared control plane when we connect switches using stacking).
Network Topology
Our topology looks like below -
01 - Network Topology
Other network settings are -
BGP ASN - 64512
loopback0 - 10.81.0.X/32
loopback1 - 10.81.1.X/32
loopback1 secondary (vPC switches only) - 10.81.1.23/32
Anycast GW MAC 2020.0000.00aa
Vlan 100 - L3VNI 100000 - Vrf-Blue
Vlan 101 - L2VNI 100101 - 10.85.101.0/24
Vlan 102 - L2VNI 100102 - 10.85.102.0/24
vPC keep-alive - over mgmt0 interface - 10.10.11.X/24
vPC peer-link - port-channel 500 (e1/3 & e1/4)
System NVE Infra-Vlans - vlan 3600
vPC peer-link SVI for VXLAN - interface vlan 3600 - 10.81.2.0/30
Now we will start configuring the switches. Only new settings will be explained, for other settings check-out other blogs in the series.
Leaf-Sw-01 Configuration
hostname Leaf-Sw-01
!
nv overlay evpn
feature ospf
feature bgp
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
!
fabric forwarding anycast-gateway-mac 2020.0000.00aa
!
vlan 100
name Vrf-Blue_L3-Vlan
vn-segment 100000
vlan 101
name Vrf-Blue_Vlan-101_10.85.101.0/24
vn-segment 100101
!
route-map Rmap_Tag-12345 permit 10
description Used-To-Redistribute-Connected-Routes-In-Vrf
match tag 12345
!
vrf context Vrf-Blue
description Vrf-Blue
vni 100000
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
!
interface Vlan100
description Vrf-Blue_L3-Interface
no shutdown
mtu 9216
vrf member Vrf-Blue
ip forward
!
interface Vlan101
description Vrf-Blue_Vlan-101_10.85.101.0/24_Anycast-Gw
no shutdown
mtu 9216
vrf member Vrf-Blue
ip address 10.85.101.1/24 tag 12345
fabric forwarding mode anycast-gateway
!
interface nve1
no shutdown
description Vtep-Vxlan
host-reachability protocol bgp
source-interface loopback1
member vni 100000 associate-vrf
member vni 100101
ingress-replication protocol bgp
!
interface Ethernet1/1
description To_Leaf-Sw-02_e1/1
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
interface Ethernet1/2
description To_Leaf-Sw-02_e1/2
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
interface Ethernet1/3
description To_Leaf-Sw-03_e1/1
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
interface Ethernet1/4
description To_Leaf-Sw-04_e1/2
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
interface Ethernet1/15
description To_Vlan-101-Pc-01_eth0
switchport access vlan 101
spanning-tree port type edge
mtu 9216
!
interface loopback0
description Underlay-Routing-Loopback
ip address 10.81.0.1/32
ip router ospf UNDERLAY area 0.0.0.0
!
interface loopback1
description Overlay-Vtep-Loopback
ip address 10.81.1.1/32
ip router ospf UNDERLAY area 0.0.0.0
!
router ospf UNDERLAY
router-id 10.81.0.1
log-adjacency-changes detail
!
router bgp 64512
router-id 10.81.0.1
log-neighbor-changes
!!! We do not have Spine or ibgp route-reflector switches.
!!! We need ibgp full mesh neighborship.
neighbor 10.81.0.2
remote-as 64512
description Leaf-Sw-02
update-source loopback0
address-family l2vpn evpn
send-community
send-community extended
neighbor 10.81.0.3
remote-as 64512
description Leaf-Sw-03
update-source loopback0
address-family l2vpn evpn
send-community
send-community extended
vrf Vrf-Blue
address-family ipv4 unicast
redistribute direct route-map Rmap_Tag-12345
maximum-paths ibgp 2
!
evpn
vni 100101 l2
rd auto
route-target import auto
route-target export auto
!
Leaf-Sw-02 Configuration
hostname Leaf-Sw-02
!
nv overlay evpn
feature ospf
feature bgp
feature interface-vlan
feature vn-segment-vlan-based
feature nv overlay
!
!!! Enable necessary features related to vpc.
feature lacp
feature vpc
!
vrf context management
!
!!! mgmt0 will be used for vPC keepalive.
interface mgmt0
vrf member management
ip address 10.10.11.2/24
!
!!! vpc domain configuration.
vpc domain 1
!!! Lower priority switch becomes vPC primary switch.
role priority 10
!!! vPC keepalive is sent using vrf management and mgmt0 interface.
peer-keepalive destination 10.10.11.3 source 10.10.11.2
!!! Enable peer-switch, peer-router and layer3 peer-router enhancements.
peer-switch
peer-gateway
layer3 peer-router
!!! vPC port-channel interface bring up will be delayed for 150 seconds.
!!! This is to allow layer 3 routing protocols to converge before allowing traffic on server facing vPC port-channel interfaces.
delay restore 150
!!! During vPC recovery if only secondary switch comes back online, all vPC port-channel interfaces will be permanently down, until primary switch comes back online.
!!! With auto-recovery; instead of permanently disabling all vPC port-channels and wait for primary switch to be online; secondary switch will enable it's vPC port-channels after waiting for specified time in seconds.
auto-recovery reload-delay 360
!!! Synchronize ARP information with vPC member switches.
ip arp synchronize
!
interface Ethernet1/3
description Po500_To_Leaf-Sw-03_e1/3
switchport mode trunk
channel-group 500 mode active
!
interface Ethernet1/4
description Po500_To_Leaf-Sw-03_e1/4
switchport mode trunk
channel-group 500 mode active
!
!!! vPC peer-link is a port-channel interface using e1/3 and e1/4 physical interfaces.
interface port-channel500
description Po500_Vpc_Peer-Link
!!! Mode must be trunk which allows all the vlans.
switchport mode trunk
!!! Spanning-tree port type must be network.
spanning-tree port type network
!!! Use this port-channel interface as peer-link.
vpc peer-link
!
!!! We need a SVI over peer-link to transport VXLAN encapsulated traffic for failover scenarios.
vlan 3600
name Vpc_Peer_Link_Svi_Vlan
!
!!! Vlan reserved as infra-vlan; otherwise Cisco NXOS does not allow VXLAN encapsulated traffic over vlan interface/SVI.
system nve infra-vlans 3600
!
!!! The actual SVI configuration.
interface Vlan3600
description Vpc_Peer_Link_Svi
no shutdown
mtu 9216
no ip redirects
ip address 10.81.2.1/30
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
!
fabric forwarding anycast-gateway-mac 2020.0000.00aa
!
vlan 100
name Vrf-Blue_L3-Vlan
vn-segment 100000
vlan 101
name Vrf-Blue_Vlan-101_10.85.101.0/24
vn-segment 100101
!!! Even though vlan 102 is only available on Leaf-Sw-03, it must be defined in both vPC member switch.
vlan 102
name Vrf-Blue_Vlan-102_10.85.102.0/24
vn-segment 100102
!
route-map Rmap_Tag-12345 permit 10
description Used-To-Redistribute-Connected-Routes-In-Vrf
match tag 12345
!
vrf context Vrf-Blue
description Vrf-Blue
vni 100000
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
!
interface Vlan100
description Vrf-Blue_L3-Interface
no shutdown
mtu 9216
vrf member Vrf-Blue
no ip redirects
ip forward
!
interface Vlan101
description Vrf-Blue_Vlan-101_10.85.101.0/24_Anycast-Gw
no shutdown
mtu 9216
vrf member Vrf-Blue
no ip redirects
ip address 10.85.101.1/24 tag 12345
fabric forwarding mode anycast-gateway
!
!!! Even though vlan 102 is only available on Leaf-Sw-03, it must be defined in both vPC member switch.
interface Vlan102
description Vrf-Blue_Vlan-102_10.85.102.0/24_Anycast-Gw
no shutdown
mtu 9216
vrf member Vrf-Blue
no ip redirects
ip address 10.85.102.1/24 tag 12345
fabric forwarding mode anycast-gateway
!
interface loopback0
description Underlay-Routing-Loopback
ip address 10.81.0.2/32
ip router ospf UNDERLAY area 0.0.0.0
interface loopback1
description Overlay-Vtep-Loopback
ip address 10.81.1.2/32
!!! loopback 1 will have a secondary IP address.
!!! Secondary IP address will be the same in both vPC switches.
ip address 10.81.1.23/32 secondary
ip router ospf UNDERLAY area 0.0.0.0
!
interface nve1
no shutdown
description Vtep-Vxlan
host-reachability protocol bgp
!!! Advertising virtual-rmac is a must for vPC switches.
!!! rt-2 routes (both mac and mac+ip) will be advertised loopback 1 secondary shared IP address as bgp-evpn next-hop.
!!! RMAC for those rt-2 routes will be virtual-rmac created from secondary IP address.
advertise virtual-rmac
source-interface loopback1
member vni 100000 associate-vrf
member vni 100101
ingress-replication protocol bgp
!!! Even though vlan 102/l2vni 100102 is only available on Leaf-Sw-03, it must be defined in both vPC member switch.
member vni 100102
ingress-replication protocol bgp
!
interface Ethernet1/1
description To_Leaf-Sw-01_e1/1
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
interface Ethernet1/2
description To_Leaf-Sw-01_e1/2
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
router ospf UNDERLAY
router-id 10.81.0.2
log-adjacency-changes detail
!
router bgp 64512
router-id 10.81.0.2
log-neighbor-changes
address-family l2vpn evpn
!!! advertise-pip is a must for vPC switches.
!!! rt-5 routes (subnet-prefix) will be announced using loopback1's primary IP address as bgp-evpn next-hop.
!!! The rmac for rt-5 routes will be vPC switches individual local router mac.
advertise-pip
!!! We do not have Spine or ibgp route-reflector switches.
!!! We need ibgp full mesh neighborship; even with vpc member switches.
neighbor 10.81.0.1
remote-as 64512
description Leaf-Sw-01
update-source loopback0
address-family l2vpn evpn
send-community
send-community extended
neighbor 10.81.0.3
remote-as 64512
description Leaf-Sw-03
update-source loopback0
address-family l2vpn evpn
send-community
send-community extended
vrf Vrf-Blue
address-family ipv4 unicast
redistribute direct route-map Rmap_Tag-12345
maximum-paths ibgp 2
evpn
vni 100101 l2
rd auto
route-target import auto
route-target export auto
!!! Even though vlan 102/l2vni 100102 is only available on Leaf-Sw-03, it must be defined in both vPC member switch.
vni 100102 l2
rd auto
route-target import auto
route-target export auto
!
!!! Vlan-101-Pc-02 is connected with both switches e1/15 interfaces.
interface Ethernet1/15
description Po15_Vpc15_To_Vlan-101-Pc-02_eth0
switchport access vlan 101
mtu 9216
channel-group 15 mode active
!
!!! Creating a vpc port-channel interface for Vlan-101-Pc-02.
interface port-channel15
description Po15_Vpc15_To_Vlan-101-Pc-02_bond0
switchport access vlan 101
spanning-tree port type edge
mtu 9216
vpc 15
!
Leaf-Sw-03 Configuration
hostname Leaf-Sw-03
!
nv overlay evpn
feature ospf
feature bgp
feature interface-vlan
feature vn-segment-vlan-based
feature lacp
feature vpc
feature nv overlay
!
fabric forwarding anycast-gateway-mac 2020.0000.00aa
!
vlan 100
name Vrf-Blue_L3-Vlan
vn-segment 100000
vlan 101
name Vrf-Blue_Vlan-101_10.85.101.0/24
vn-segment 100101
vlan 102
name Vrf-Blue_Vlan-102_10.85.102.0/24
vn-segment 100102
vlan 3600
name Vpc_Peer_Link_Svi_Vlan
!
route-map Rmap_Tag-12345 permit 10
description Used-To-Redistribute-Connected-Routes-In-Vrf
match tag 12345
!
vrf context Vrf-Blue
description Vrf-Blue
vni 100000
rd auto
address-family ipv4 unicast
route-target both auto
route-target both auto evpn
!
vrf context management
!
system nve infra-vlans 3600
!
vpc domain 1
peer-switch
role priority 20
peer-keepalive destination 10.10.11.2 source 10.10.11.3
delay restore 150
peer-gateway
layer3 peer-router
auto-recovery reload-delay 360
ip arp synchronize
!
interface Vlan100
description Vrf-Blue_L3-Interface
no shutdown
mtu 9216
vrf member Vrf-Blue
no ip redirects
ip forward
!
interface Vlan101
description Vrf-Blue_Vlan-101_10.85.101.0/24_Anycast-Gw
no shutdown
mtu 9216
vrf member Vrf-Blue
no ip redirects
ip address 10.85.101.1/24 tag 12345
fabric forwarding mode anycast-gateway
!
interface Vlan102
description Vrf-Blue_Vlan-102_10.85.102.0/24_Anycast-Gw
no shutdown
mtu 9216
vrf member Vrf-Blue
no ip redirects
ip address 10.85.102.1/24 tag 12345
fabric forwarding mode anycast-gateway
!
interface Vlan3600
description Vpc_Peer_Link_Svi
no shutdown
mtu 9216
no ip redirects
ip address 10.81.2.2/30
no ipv6 redirects
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
!
interface port-channel15
description Po15_Vpc15_To_Vlan-101-Pc-02_bond0
switchport access vlan 101
spanning-tree port type edge
mtu 9216
vpc 15
!
interface port-channel500
description Po500_Vpc_Peer-Link
switchport mode trunk
spanning-tree port type network
vpc peer-link
!
interface nve1
no shutdown
description Vtep-Vxlan
host-reachability protocol bgp
advertise virtual-rmac
source-interface loopback1
member vni 100000 associate-vrf
member vni 100101
ingress-replication protocol bgp
member vni 100102
ingress-replication protocol bgp
!
interface Ethernet1/1
description To_Leaf-Sw-01_e1/3
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
interface Ethernet1/2
description To_Leaf-Sw-01_e1/4
no switchport
mtu 9216
medium p2p
no ip redirects
ip unnumbered loopback0
ip ospf network point-to-point
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
!
interface Ethernet1/3
description Po500_To_Leaf-Sw-02_e1/3
switchport mode trunk
channel-group 500 mode active
!
interface Ethernet1/4
description Po500_To_Leaf-Sw-02_e1/4
switchport mode trunk
channel-group 500 mode active
!
!!! Vlan-102-Pc-01 is connected with Leaf-Sw-03 only using a single physical interface e1/14.
interface Ethernet1/14
description To_Vlan-102-Pc-01_eth0
switchport access vlan 102
spanning-tree port type edge
mtu 9216
!!! If the switch is vPC secondary switch, orphan ports will be suspended until peer-link between vPC members is restored.
!!! When a host is connected with only with one of the vPC switch (single-homed).
vpc orphan-port suspend
!
interface Ethernet1/15
description Po15_Vpc15_To_Vlan-101-Pc-02_eth1
switchport access vlan 101
mtu 9216
channel-group 15 mode active
!
interface mgmt0
vrf member management
ip address 10.10.11.3/24
!
interface loopback0
description Underlay-Routing-Loopback
ip address 10.81.0.3/32
ip router ospf UNDERLAY area 0.0.0.0
!
interface loopback1
description Overlay-Vtep-Loopback
ip address 10.81.1.3/32
ip address 10.81.1.23/32 secondary
ip router ospf UNDERLAY area 0.0.0.0
!
router ospf UNDERLAY
router-id 10.81.0.3
log-adjacency-changes detail
!
router bgp 64512
router-id 10.81.0.3
log-neighbor-changes
address-family l2vpn evpn
advertise-pip
neighbor 10.81.0.1
remote-as 64512
description Leaf-Sw-01
update-source loopback0
address-family l2vpn evpn
send-community
send-community extended
neighbor 10.81.0.2
remote-as 64512
description Leaf-Sw-02
update-source loopback0
address-family l2vpn evpn
send-community
send-community extended
vrf Vrf-Blue
address-family ipv4 unicast
redistribute direct route-map Rmap_Tag-12345
maximum-paths ibgp 2
evpn
vni 100101 l2
rd auto
route-target import auto
route-target export auto
vni 100102 l2
rd auto
route-target import auto
route-target export auto
!
Verification
Firstly we will verify our vPC configuration.
Leaf-Sw-03# show vpc
Legend:
(*) - local vPC is down, forwarding via vPC peer-link
vPC domain id : 1
Peer status : peer adjacency formed ok
vPC keep-alive status : peer is alive
Configuration consistency status : success
Per-vlan consistency status : success
Type-2 consistency status : success
vPC role : secondary
Number of vPCs configured : 1
Peer Gateway : Enabled
Dual-active excluded VLANs : -
Graceful Consistency Check : Enabled
!!! Auto-recovery and Delay-restore timers.
Auto-recovery status : Enabled, timer is off.(timeout = 360s)
Delay-restore status : Timer is off.(timeout = 150s)
Delay-restore SVI status : Timer is off.(timeout = 10s)
Delay-restore Orphan-port status : Timer is off.(timeout = 0s)
Operational Layer3 Peer-router : Enabled
Virtual-peerlink mode : Disabled
vPC Peer-link status
---------------------------------------------------------------------
id Port Status Active vlans
-- ---- ------ -------------------------------------------------
!!! vpc peer-link port-channel
1 Po500 up 1,100-102,3600
vPC status
----------------------------------------------------------------------------
Id Port Status Consistency Reason Active vlans
-- ------------ ------ ----------- ------ ---------------
!!! vpc port-channel for Vlan-101-Pc-02.
15 Po15 up success success 101
Please check "show vpc consistency-parameters vpc <vpc-num>" for the
consistency reason of down vpc and for type-2 consistency reasons for
any vpc.
Leaf-Sw-03# show vpc role
vPC Role status
----------------------------------------------------
vPC role : secondary
Dual Active Detection Status : 2
vPC system-mac : 00:23:04:ee:be:01
vPC system-priority : 32667
vPC local system-mac : 50:00:20:00:1b:08
!!! Local switch vPC priority.
vPC local role-priority : 20
vPC local config role-priority : 20
vPC local Sticky-Bit : FALSE
vPC peer system-mac : 50:00:1f:00:1b:08
!!! Remote switch (peer) vPC priority. This is primary switch.
vPC peer role-priority : 10
vPC peer config role-priority : 10
Leaf-Sw-03# show vpc peer-keepalive
vPC keep-alive status : peer is alive
--Peer is alive for : (1203) seconds, (938) msec
--Send status : Success
--Last send at : 2026.09.28 18:11:00 860 ms
!!! vPC keep alive is sent using mgmt0 interface.
--Sent on interface : mgmt0
--Receive status : Success
--Last receive at : 2026.09.28 18:11:00 861 ms
--Received on interface : mgmt0
--Last update from peer : (0) seconds, (995) msec
vPC Keep-alive parameters
--Destination : 10.10.11.2
--Keepalive interval : 1000 msec
--Keepalive timeout : 5 seconds
--Keepalive hold timeout : 3 seconds
!!! Vrf management used for vPC keep alive.
--Keepalive vrf : management
--Keepalive udp port : 3200
--Keepalive tos : 192
Now we will look at our infra-vlan which is required when VXLAN encapsulated traffic passes through vlan interface (SVI).
Leaf-Sw-03# show system nve infra-vlans
Currently active infra Vlans: 3600
Currently active infra Vlans: 3600
Both the vPC switches are using the same virtual rmac - it will be the same in both Leaf-Sw-02 and Leaf-Sw-03. The virtual rmac is derived from the shared secondary IP address - 10.81.1.23. The virtual rmac will be - 0200+10.81.1.23 (in hex) = 0200.0a51.0117.
Leaf-Sw-02# show nve interface nve 1 detail
Interface: nve1, State: Up, encapsulation: VXLAN
VPC Capability: VPC-VIP-Only [notified]
!!! Unique Local rmac.
Local Router MAC: 5000.1f00.1b08
Host Learning Mode: Control-Plane
Source-Interface: loopback1 (primary: 10.81.1.2, secondary: 10.81.1.23)
Source Interface State: Up
Virtual RMAC Advertisement: Yes
NVE Flags:
Interface Handle: 0x49000001
Source Interface hold-down-time: 180
Source Interface hold-up-time: 30
Remaining hold-down time: 0 seconds
!!! Shared virtual rmac derived from shared secondary ip address 10.81.1.23.
Virtual Router MAC: 0200.0a51.0117
Interface state: nve-intf-add-complete
Fabric convergence time: 135 seconds
Fabric convergence time left: 0 seconds
Leaf-Sw-03# show nve interface nve 1 detail
Interface: nve1, State: Up, encapsulation: VXLAN
VPC Capability: VPC-VIP-Only [notified]
!!! Unique Local rmac.
Local Router MAC: 5000.2000.1b08
Host Learning Mode: Control-Plane
Source-Interface: loopback1 (primary: 10.81.1.3, secondary: 10.81.1.23)
Source Interface State: Up
Virtual RMAC Advertisement: Yes
NVE Flags:
Interface Handle: 0x49000001
Source Interface hold-down-time: 180
Source Interface hold-up-time: 30
Remaining hold-down time: 0 seconds
!!! Shared virtual rmac derived from shared secondary ip address 10.81.1.23.
Virtual Router MAC: 0200.0a51.0117
Interface state: nve-intf-add-complete
Fabric convergence time: 135 seconds
Fabric convergence time left: 0 seconds
We are using advertise-pip and advertise virtual-rmac. The following will happen to rt-2 and rt-5 evpn routes -
- rt-2 (mac) - bgp evpn next-hop will be the shared secondary ip address (10.81.1.23) configured on loopback1 interface. rt-2 (mac) routes do not have rmac.
- rt-2 (mac+ip) - bgp evpn next-hop will be the shared secondary ip address (10.81.1.23) configured on loopback1 interface. And router-mac will be the virtual-rmac (0200.0a51.0117).
- rt-5 (prefix) - bgp evpn next-hop will be the primary ip address (10.81.1.2 and 10.81.1.3) configured on loopback1 interface. And router-mac will be the local-rmac (5000.1f00.1b08 and 5000.2000.1b08) of the switches.
Let's verify them one by one from Leaf-Sw-01.
Vlan-101-Pc-02 has ip/mac - 10.85.101.12/503e.8b00.2300.
Leaf-Sw-01# show bgp l2vpn evpn 503e.8b00.2300
BGP routing table information for VRF default, address family L2VPN EVPN
!!! EVPN rt-2 (mac) route received from Leaf-Sw-02.
Route Distinguisher: 10.81.0.2:32868
!!! 503e.8b00.2300 mac-address of Vlan-101-Pc-02.
BGP routing table entry for [2]:[0]:[0]:[48]:[503e.8b00.2300]:[0]:[0.0.0.0]/216, version 852
Paths: (1 available, best #1)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not in HW
Advertised path-id 1
Path type: internal, path is valid, is best path, no labeled nexthop
Imported to 1 destination(s)
Imported paths list: L2-100101
AS-Path: NONE, path sourced internal to AS
!!! bgp-evpn next-hop is 10.81.1.23 secondary ip address configured on loop1.
10.81.1.23 (metric 41) from 10.81.0.2 (10.81.0.2)
Origin IGP, MED not set, localpref 100, weight 0
Received label 100101
Extcommunity: RT:64512:100101 SOO:10.81.1.23:0 ENCAP:8
Path-id 1 not advertised to any peer
!!! EVPN rt-2 (mac) route received from Leaf-Sw-03.
Route Distinguisher: 10.81.0.3:32868
!!! 503e.8b00.2300 mac-address of Vlan-101-Pc-02.
BGP routing table entry for [2]:[0]:[0]:[48]:[503e.8b00.2300]:[0]:[0.0.0.0]/216, version 854
Paths: (1 available, best #1)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not in HW
Advertised path-id 1
Path type: internal, path is valid, is best path, no labeled nexthop
Imported to 1 destination(s)
Imported paths list: L2-100101
AS-Path: NONE, path sourced internal to AS
!!! bgp-evpn next-hop is 10.81.1.23 secondary ip address configured on loop1.
10.81.1.23 (metric 41) from 10.81.0.3 (10.81.0.3)
Origin IGP, MED not set, localpref 100, weight 0
Received label 100101
Extcommunity: RT:64512:100101 SOO:10.81.1.23:0 ENCAP:8
Path-id 1 not advertised to any peer
As this is a rt-2 (mac) route, it will be programmed into the switch's mac address-table.
Leaf-Sw-01# show mac address-table vlan 101
Legend:
* - primary entry, G - Gateway MAC, (R) - Routed MAC, O - Overlay MAC
age - seconds since last seen,+ - primary entry using vPC Peer-Link,
(T) - True, (F) - False, C - ControlPlane MAC, ~ - vsan,
(NA)- Not Applicable A - ESI Active Path, S - ESI Standby Path
TL - True Learned, PS - Peer Sync, RO - Re-originate
VLAN MAC Address Type age Secure NTFY Ports
---------+-----------------+--------+---------+------+----+------------------
!!! 503e.8b00.2300 is learnt from nve peer 10.81.1.23.
C 101 503e.8b00.2300 dynamic NA F F nve1(10.81.1.23)
* 101 509f.d200.2100 dynamic NA F F Eth1/15
G 101 5000.1e00.1b08 static - F F sup-eth1(R)
Leaf-Sw-01 will have 3-nve peers.
Leaf-Sw-01# show nve peers
Interface Peer-IP State LearnType Uptime Router-Mac
--------- -------------------------------------- ----- --------- -------- -----------------
!!! Leaf-Sw-02 is peer.
nve1 10.81.1.2 Up CP 01:36:34 5000.1f00.1b08
!!! Leaf-Sw-03 is peer.
nve1 10.81.1.3 Up CP 01:36:35 5000.2000.1b08
!!! 10.81.1.23 is a peer shared by both Leaf-Sw-02 and Leaf-Sw-03.
nve1 10.81.1.23 Up CP 01:36:35 0200.0a51.0117
The rt-2 (mac+ip) will behave exactly same. The only difference will be it will carry one extra bgp extended community that will be rmac. And the rmac will be 0200.0a51.0117 (derived from 0200+shared ip 10.81.1.23 in hex).
Leaf-Sw-01# show bgp l2vpn evpn 10.85.101.12
BGP routing table information for VRF default, address family L2VPN EVPN
!!! EVPN rt-2 (mac+ip) route received from Leaf-Sw-02.
Route Distinguisher: 10.81.0.2:32868
!!! Vlan-101-Pc-02 IP/mac - 10.85.101.12/503e.8b00.2300.
BGP routing table entry for [2]:[0]:[0]:[48]:[503e.8b00.2300]:[32]:[10.85.101.12]/272, version 860
Paths: (1 available, best #1)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not in HW
Advertised path-id 1
Path type: internal, path is valid, is best path, no labeled nexthop
Imported to 3 destination(s)
Imported paths list: Vrf-Blue L2-100101 L3-100000
AS-Path: NONE, path sourced internal to AS
10.81.1.23 (metric 41) from 10.81.0.2 (10.81.0.2)
Origin IGP, MED not set, localpref 100, weight 0
Received label 100101 100000
Extcommunity: RT:64512:100000 RT:64512:100101 SOO:10.81.1.23:0 ENCAP:8
!!! rmac is the virtual-rmac derived from shared secondary ip address on loop1.
Router MAC:0200.0a51.0117
Path-id 1 not advertised to any peer
!!! EVPN rt-2 (mac+ip) route received from Leaf-Sw-03.
Route Distinguisher: 10.81.0.3:32868
!!! Vlan-101-Pc-02 IP/mac - 10.85.101.12/503e.8b00.2300.
BGP routing table entry for [2]:[0]:[0]:[48]:[503e.8b00.2300]:[32]:[10.85.101.12]/272, version 863
Paths: (1 available, best #1)
Flags: (0x000202) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not in HW
Advertised path-id 1
Path type: internal, path is valid, is best path, no labeled nexthop
Imported to 3 destination(s)
Imported paths list: Vrf-Blue L2-100101 L3-100000
AS-Path: NONE, path sourced internal to AS
10.81.1.23 (metric 41) from 10.81.0.3 (10.81.0.3)
Origin IGP, MED not set, localpref 100, weight 0
Received label 100101 100000
Extcommunity: RT:64512:100000 RT:64512:100101 SOO:10.81.1.23:0 ENCAP:8
!!! rmac is the virtual-rmac derived from shared secondary ip address on loop1.
Router MAC:0200.0a51.0117
Path-id 1 not advertised to any peer
rt-2 (mac+ip) will enter in the vrf's routing table.
Leaf-Sw-01# show ip route 10.85.101.12 vrf Vrf-Blue
IP Route Table for VRF "Vrf-Blue"
'*' denotes best ucast next-hop
'**' denotes best mcast next-hop
'[x/y]' denotes [preference/metric]
'%<string>' in via output denotes VRF <string>
10.85.101.12/32, ubest/mbest: 1/0
*via 10.81.1.23%default, [200/0], 03:31:14, bgp-64512, internal, tag 64512, segid: 100000 tunnelid: 0xa510117 encap:
VXLAN
Now we can have a look on how next-hop 10.81.1.23 (shared secondary ip) is reachable in the underlay network - we have 4 way ICMP for that.
Leaf-Sw-01# show ip route 10.81.1.23
IP Route Table for VRF "default"
'*' denotes best ucast next-hop
'**' denotes best mcast next-hop
'[x/y]' denotes [preference/metric]
'%<string>' in via output denotes VRF <string>
10.81.1.23/32, ubest/mbest: 4/0
*via 10.81.0.2, Eth1/1, [110/41], 04:36:29, ospf-UNDERLAY, intra
*via 10.81.0.2, Eth1/2, [110/41], 04:36:29, ospf-UNDERLAY, intra
*via 10.81.0.3, Eth1/3, [110/41], 04:36:29, ospf-UNDERLAY, intra
*via 10.81.0.3, Eth1/4, [110/41], 04:36:29, ospf-UNDERLAY, intra
rt-5 (prefix) route will be announced by both vPC switches using their primary ip address used by the loopback1 interface and rmac will be the switches individual local rmac.
Leaf-Sw-01# show bgp l2vpn evpn 10.85.102.0
BGP routing table information for VRF default, address family L2VPN EVPN
!!! rt-5 for 10.85.102.0/24 received for Leaf-Sw-02.
Route Distinguisher: 10.81.0.2:4
BGP routing table entry for [5]:[0]:[0]:[24]:[10.85.102.0]/224, version 834
Paths: (1 available, best #1)
Flags: (0x000002) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not in HW
Advertised path-id 1
Path type: internal, path is valid, is best path, no labeled nexthop
Imported to 2 destination(s)
Imported paths list: Vrf-Blue L3-100000
Gateway IP: 0.0.0.0
AS-Path: NONE, path sourced internal to AS
!!! next-hop is loop1 primary ip address of Leaf-Sw-02.
10.81.1.2 (metric 41) from 10.81.0.2 (10.81.0.2)
Origin incomplete, MED 0, localpref 100, weight 0
Received label 100000
!!! rmac is local router mac of Leaf-Sw-02.
Extcommunity: RT:64512:100000 ENCAP:8 Router MAC:5000.1f00.1b08
Path-id 1 not advertised to any peer
!!! rt-5 for 10.85.102.0/24 received for Leaf-Sw-03.
Route Distinguisher: 10.81.0.3:4
BGP routing table entry for [5]:[0]:[0]:[24]:[10.85.102.0]/224, version 948
Paths: (1 available, best #1)
Flags: (0x000002) (high32 00000000) on xmit-list, is not in l2rib/evpn, is not in HW
Advertised path-id 1
Path type: internal, path is valid, is best path, no labeled nexthop
Imported to 2 destination(s)
Imported paths list: Vrf-Blue L3-100000
Gateway IP: 0.0.0.0
AS-Path: NONE, path sourced internal to AS
!!! next-hop is loop1 primary ip address of Leaf-Sw-03.
10.81.1.3 (metric 41) from 10.81.0.3 (10.81.0.3)
Origin incomplete, MED 0, localpref 100, weight 0
Received label 100000
!!! rmac is local router mac of Leaf-Sw-03.
Extcommunity: RT:64512:100000 ENCAP:8 Router MAC:5000.2000.1b08
Path-id 1 not advertised to any peer
rt-5 (prefix) will enter in the vrf's routing table.
Leaf-Sw-01# show ip route 10.85.102.0 vrf Vrf-Blue
IP Route Table for VRF "Vrf-Blue"
'*' denotes best ucast next-hop
'**' denotes best mcast next-hop
'[x/y]' denotes [preference/metric]
'%<string>' in via output denotes VRF <string>
10.85.102.0/24, ubest/mbest: 2/0
*via 10.81.1.2%default, [200/0], 07:35:45, bgp-64512, internal, tag 64512, segid: 100000 tunnelid: 0xa510102 encap:
VXLAN
*via 10.81.1.3%default, [200/0], 00:06:26, bgp-64512, internal, tag 64512, segid: 100000 tunnelid: 0xa510103 encap:
VXLAN
That's all about vPC and VXLAN.
From Part - 07 - we will work with actual Spine-Leaf topology as now we have covered most of the foundational basics for VXLAN-EVPN.

Comments
Post a Comment