! Campus-Leaf1 Configuration ! Campus VTEP1 - AS 66001 (MLAG pair with campus-leaf2) ! hostname campus-leaf1 ! ! LLDP Management0 lldp management-address Management0 ! ! enable gNMI API management api gnmi transport grpc default provider eos-native ! ! admin/admin for ssh access username admin privilege 15 role network-admin secret sha512 $6$xQktFrbdeqEhVzLM$.1wOJB25nw2fqYaSXDu6y4mo6AP9hngMCFe2vGDl84hWoz00Q.4unoEBqspNI0HEoRz.OZhdBHqQv12KABf0B0 ! ! Enable IP routing ip routing ! ! Enable routing protocols service routing protocols model multi-agent ! ! VRF Definition vrf instance gold ! ! VLANs vlan 50 name test-l2-vxlan-campus ! vlan 60 name vrf-gold-campus-subnet1 ! vlan 4090 name mlag-peer trunk group mlag-peer ! vlan 4091 name mlag-ibgp trunk group mlag-peer ! ! Management interface interface Management0 ip address 172.16.0.51/24 ! ! MLAG Peer-link SVI interface Vlan4090 description MLAG Peer-Link ip address 10.1.199.252/31 no autostate ! ! iBGP Peering SVI interface Vlan4091 description MLAG iBGP Peering ip address 10.1.3.0/31 mtu 9214 ! ! VRF VLAN Interface interface Vlan60 vrf gold ip address 10.60.60.2/24 ip virtual-router address 10.60.60.1 ! ! Loopbacks interface Loopback0 description Router-ID ip address 10.1.250.11/32 ! interface Loopback1 description VTEP ip address 10.1.255.11/32 ! ! MLAG Peer-link interface Ethernet10 description mlag peer link channel-group 999 mode active ! interface Port-Channel999 description MLAG Peer switchport mode trunk switchport trunk group mlag-peer spanning-tree link-type point-to-point ! ! Underlay P2P interfaces to Campus Spines interface Ethernet11 description campus-spine1 no switchport ip address 10.1.1.1/31 mtu 9214 ! interface Ethernet12 description campus-spine2 no switchport ip address 10.1.2.1/31 mtu 9214 ! ! Access-facing interface (MLAG with LACP) interface Ethernet1 description campus-access1 channel-group 1 mode active ! interface Port-Channel1 description campus-access1 switchport mode trunk switchport trunk allowed vlan 60 mlag 1 port-channel lacp fallback timeout 5 port-channel lacp fallback individual no shutdown ! ! Spanning-tree no spanning-tree vlan 4090 no spanning-tree vlan 4091 ! ! Virtual MAC for Anycast Gateway ip virtual-router mac-address c001.cafe.babe ! ! MLAG Configuration mlag configuration domain-id campus-leafs local-interface Vlan4090 peer-address 10.1.199.253 peer-link Port-Channel999 dual-primary detection delay 10 action errdisable all-interfaces peer-address heartbeat 172.16.0.52 vrf mgmt ! ! VXLAN Interface interface Vxlan1 vxlan source-interface Loopback1 vxlan udp-port 4789 vxlan learn-restrict any vxlan vlan 50 vni 110050 vxlan vrf gold vni 100001 ! ! IP Routing ip routing ip routing vrf gold ip route 100.64.0.0/10 172.16.0.254 ! ! BGP Configuration router bgp 66001 router-id 10.1.250.11 no bgp default ipv4-unicast bgp log-neighbor-changes distance bgp 20 200 200 maximum-paths 4 ecmp 64 ! ! Underlay peer-group neighbor underlay peer group neighbor underlay remote-as 66000 neighbor underlay maximum-routes 12000 warning-only neighbor 10.1.1.0 peer group underlay neighbor 10.1.2.0 peer group underlay ! ! iBGP peer-group neighbor underlay_ibgp peer group neighbor underlay_ibgp remote-as 66001 neighbor underlay_ibgp maximum-routes 12000 warning-only neighbor underlay_ibgp next-hop-self neighbor 10.1.3.1 peer group underlay_ibgp ! ! EVPN peer-group neighbor evpn peer group neighbor evpn remote-as 66000 neighbor evpn update-source Loopback0 neighbor evpn ebgp-multihop 3 neighbor evpn send-community extended neighbor evpn maximum-routes 12000 warning-only neighbor 10.1.250.1 peer group evpn neighbor 10.1.250.2 peer group evpn ! ! VLAN 50 for L2 VXLAN (stretched across Campus VTEPs) vlan 50 rd 66001:110050 route-target both 50:110050 redistribute learned ! ! IPv4 address family address-family ipv4 neighbor underlay activate neighbor underlay_ibgp activate network 10.1.250.11/32 network 10.1.255.11/32 ! ! EVPN address family address-family evpn neighbor evpn activate ! ! VRF Gold configuration vrf gold rd 10.1.250.11:1 route-target import evpn 1:100001 route-target export evpn 1:100001 redistribute connected ! end