Add Campus EVPN-VXLAN fabric configs and host interfaces
- campus-spine1/2 (AS 66000): eBGP underlay + EVPN RR toward leafs and border leafs, addressing plan 10.1.x.x. - campus-leaf1/2 (VTEP1, AS 66001, VTEP 10.1.255.11): VLAN 50 (stretched L2 VXLAN, VNI 110050) and VLAN 60 (VRF gold anycast 10.60.60.1, L3 VNI 100001). - campus-leaf3/4 (VTEP2, AS 66002, VTEP 10.1.255.12): VLAN 50 and VLAN 70 (VRF gold anycast 10.60.70.1). - border-leaf-campus1/2 (AS 66005, VTEP 10.1.255.21): MLAG pair, OSPF + eBGP to cores, VRF gold stitched via vxlan vrf gold vni 100001 with RT 1:100001. - campus-access1/2: L2-only uplinks to campus leaf MLAG pairs, trunks VLAN 50+60 / 50+70. - campus-host1/2 interface files: bond0 + VLAN sub-interfaces for the stretched L2 VLAN 50 and the VRF gold subnets.
This commit is contained in:
195
configs/campus-leaf1.cfg
Normal file
195
configs/campus-leaf1.cfg
Normal file
@@ -0,0 +1,195 @@
|
||||
! Campus-Leaf1 Configuration
|
||||
! Campus VTEP1 - AS 66001 (MLAG pair with campus-leaf2)
|
||||
!
|
||||
hostname campus-leaf1
|
||||
!
|
||||
! LLDP Management0
|
||||
lldp management-address Management0
|
||||
!
|
||||
! enable gNMI API
|
||||
management api gnmi
|
||||
transport grpc default
|
||||
provider eos-native
|
||||
!
|
||||
! admin/admin for ssh access
|
||||
username admin privilege 15 role network-admin secret sha512 $6$xQktFrbdeqEhVzLM$.1wOJB25nw2fqYaSXDu6y4mo6AP9hngMCFe2vGDl84hWoz00Q.4unoEBqspNI0HEoRz.OZhdBHqQv12KABf0B0
|
||||
!
|
||||
! Enable IP routing
|
||||
ip routing
|
||||
!
|
||||
! Enable routing protocols
|
||||
service routing protocols model multi-agent
|
||||
!
|
||||
! VRF Definition
|
||||
vrf instance gold
|
||||
!
|
||||
! VLANs
|
||||
vlan 50
|
||||
name test-l2-vxlan-campus
|
||||
!
|
||||
vlan 60
|
||||
name vrf-gold-campus-subnet1
|
||||
!
|
||||
vlan 4090
|
||||
name mlag-peer
|
||||
trunk group mlag-peer
|
||||
!
|
||||
vlan 4091
|
||||
name mlag-ibgp
|
||||
trunk group mlag-peer
|
||||
!
|
||||
! Management interface
|
||||
interface Management0
|
||||
ip address 172.16.0.51/24
|
||||
!
|
||||
! MLAG Peer-link SVI
|
||||
interface Vlan4090
|
||||
description MLAG Peer-Link
|
||||
ip address 10.1.199.252/31
|
||||
no autostate
|
||||
!
|
||||
! iBGP Peering SVI
|
||||
interface Vlan4091
|
||||
description MLAG iBGP Peering
|
||||
ip address 10.1.3.0/31
|
||||
mtu 9214
|
||||
!
|
||||
! VRF VLAN Interface
|
||||
interface Vlan60
|
||||
vrf gold
|
||||
ip address 10.60.60.2/24
|
||||
ip virtual-router address 10.60.60.1
|
||||
!
|
||||
! Loopbacks
|
||||
interface Loopback0
|
||||
description Router-ID
|
||||
ip address 10.1.250.11/32
|
||||
!
|
||||
interface Loopback1
|
||||
description VTEP
|
||||
ip address 10.1.255.11/32
|
||||
!
|
||||
! MLAG Peer-link
|
||||
interface Ethernet10
|
||||
description mlag peer link
|
||||
channel-group 999 mode active
|
||||
!
|
||||
interface Port-Channel999
|
||||
description MLAG Peer
|
||||
switchport mode trunk
|
||||
switchport trunk group mlag-peer
|
||||
spanning-tree link-type point-to-point
|
||||
!
|
||||
! Underlay P2P interfaces to Campus Spines
|
||||
interface Ethernet11
|
||||
description campus-spine1
|
||||
no switchport
|
||||
ip address 10.1.1.1/31
|
||||
mtu 9214
|
||||
!
|
||||
interface Ethernet12
|
||||
description campus-spine2
|
||||
no switchport
|
||||
ip address 10.1.2.1/31
|
||||
mtu 9214
|
||||
!
|
||||
! Access-facing interface (MLAG with LACP)
|
||||
interface Ethernet1
|
||||
description campus-access1
|
||||
channel-group 1 mode active
|
||||
!
|
||||
interface Port-Channel1
|
||||
description campus-access1
|
||||
switchport mode trunk
|
||||
switchport trunk allowed vlan 50,60
|
||||
mlag 1
|
||||
port-channel lacp fallback timeout 5
|
||||
port-channel lacp fallback individual
|
||||
no shutdown
|
||||
!
|
||||
! Spanning-tree
|
||||
no spanning-tree vlan 4090
|
||||
no spanning-tree vlan 4091
|
||||
!
|
||||
! Virtual MAC for Anycast Gateway
|
||||
ip virtual-router mac-address c001.cafe.babe
|
||||
!
|
||||
! MLAG Configuration
|
||||
mlag configuration
|
||||
domain-id campus-leafs
|
||||
local-interface Vlan4090
|
||||
peer-address 10.1.199.253
|
||||
peer-link Port-Channel999
|
||||
dual-primary detection delay 10 action errdisable all-interfaces
|
||||
peer-address heartbeat 172.16.0.52 vrf mgmt
|
||||
!
|
||||
! VXLAN Interface
|
||||
interface Vxlan1
|
||||
vxlan source-interface Loopback1
|
||||
vxlan udp-port 4789
|
||||
vxlan learn-restrict any
|
||||
vxlan vlan 50 vni 110050
|
||||
vxlan vrf gold vni 100001
|
||||
!
|
||||
! IP Routing
|
||||
ip routing
|
||||
ip routing vrf gold
|
||||
ip route 100.64.0.0/10 172.16.0.254
|
||||
!
|
||||
! BGP Configuration
|
||||
router bgp 66001
|
||||
router-id 10.1.250.11
|
||||
no bgp default ipv4-unicast
|
||||
bgp log-neighbor-changes
|
||||
distance bgp 20 200 200
|
||||
maximum-paths 4 ecmp 64
|
||||
!
|
||||
! Underlay peer-group
|
||||
neighbor underlay peer group
|
||||
neighbor underlay remote-as 66000
|
||||
neighbor underlay maximum-routes 12000 warning-only
|
||||
neighbor 10.1.1.0 peer group underlay
|
||||
neighbor 10.1.2.0 peer group underlay
|
||||
!
|
||||
! iBGP peer-group
|
||||
neighbor underlay_ibgp peer group
|
||||
neighbor underlay_ibgp remote-as 66001
|
||||
neighbor underlay_ibgp maximum-routes 12000 warning-only
|
||||
neighbor underlay_ibgp next-hop-self
|
||||
neighbor 10.1.3.1 peer group underlay_ibgp
|
||||
!
|
||||
! EVPN peer-group
|
||||
neighbor evpn peer group
|
||||
neighbor evpn remote-as 66000
|
||||
neighbor evpn update-source Loopback0
|
||||
neighbor evpn ebgp-multihop 3
|
||||
neighbor evpn send-community extended
|
||||
neighbor evpn maximum-routes 12000 warning-only
|
||||
neighbor 10.1.250.1 peer group evpn
|
||||
neighbor 10.1.250.2 peer group evpn
|
||||
!
|
||||
! VLAN 50 for L2 VXLAN (stretched across Campus VTEPs)
|
||||
vlan 50
|
||||
rd 66001:110050
|
||||
route-target both 50:110050
|
||||
redistribute learned
|
||||
!
|
||||
! IPv4 address family
|
||||
address-family ipv4
|
||||
neighbor underlay activate
|
||||
neighbor underlay_ibgp activate
|
||||
network 10.1.250.11/32
|
||||
network 10.1.255.11/32
|
||||
!
|
||||
! EVPN address family
|
||||
address-family evpn
|
||||
neighbor evpn activate
|
||||
!
|
||||
! VRF Gold configuration
|
||||
vrf gold
|
||||
rd 10.1.250.11:1
|
||||
route-target import evpn 1:100001
|
||||
route-target export evpn 1:100001
|
||||
redistribute connected
|
||||
!
|
||||
end
|
||||
Reference in New Issue
Block a user