附录:通过此交换矩阵配置 Junos OS
园区交换矩阵 EVPN 多宿主配置
本节显示使用 eBGP 在核心交换机和分布式交换机上为 IP 交换矩阵底层瞻博网络Mist云输出的配置。
瞻博网络 Mist 提供以下选项(括号内默认配置):
- BGP 本地 AS (65000)
- AS 基数 (65001)
- 环路池 (172.16.254.0/23)
- 子网 (10.255.240.0/20) - 相邻层之间的点对点接口
在核心层和分布层之间的整个园区交换矩阵中,瞻博网络 Mist 使用 ECMP 实现按数据包(Junos OS 将其定义为按流)负载平衡,并使用 BFD 在发生链路或节点故障时实现 BGP 的快速融合。
Core1 配置:
- 与 core2 互连:
set interfaces et-0/0/48 description evpn_downlink-to-b033a6114900 set interfaces et-0/0/48 unit 0 family inet address 10.255.240.4/31 set interfaces et-0/0/49 description evpn_uplink-to-b033a6114900 set interfaces et-0/0/49 unit 0 family inet address 10.255.240.3/31
- 环路接口和路由器 ID:
set groups top interfaces lo0 unit 0 family inet address 172.16.254.2/32 set groups top routing-options router-id 172.16.254.2
- 按数据包负载均衡:
set groups top policy-options policy-statement ecmp_policy then load-balance per-packet set groups top policy-options policy-statement ecmp_policy then accept set groups top routing-options forwarding-table export ecmp_policy
- 两个分布交换机之间的 BGP 底层网络:
set protocols bgp group evpn_underlay type external set protocols bgp group evpn_underlay log-updown set protocols bgp group evpn_underlay import evpn_underlay_import set protocols bgp group evpn_underlay family inet unicast set protocols bgp group evpn_underlay authentication-key "xyz" set protocols bgp group evpn_underlay export evpn_underlay_export set protocols bgp group evpn_underlay local-as 65002 set protocols bgp group evpn_underlay multipath multiple-as set protocols bgp group evpn_underlay bfd-liveness-detection minimum- interval 350 set protocols bgp group evpn_underlay bfd-liveness-detection multiplier 3 set protocols bgp group evpn_underlay neighbor 10.255.240.2 peer-as 65001 set protocols bgp group evpn_underlay neighbor 10.255.240.5 peer-as 65001
Core2 配置:
- 两个分布式交换机之间的互连:
set interfaces et-0/0/48 description evpn_uplink-to-c042d016afa0 set interfaces et-0/0/48 unit 0 family inet address 10.255.240.5/31 set interfaces et-0/0/49 description evpn_downlink-to-c042d016afa0 set interfaces et-0/0/49 unit 0 family inet address 10.255.240.2/31
- 环路接口和路由器 ID:
set groups top interfaces lo0 unit 0 family inet address 172.16.254.1/32 set groups top routing-options router-id 172.16.254.1
- 按数据包负载平衡:
set groups top policy-options policy-statement ecmp_policy then load-balance per-packet set groups top policy-options policy-statement ecmp_policy then accept set groups top routing-options forwarding-table export ecmp_policy
- 两个分布交换机之间的 BGP 底层网络:
set protocols bgp group evpn_underlay type external set protocols bgp group evpn_underlay type external set protocols bgp group evpn_underlay log-updown set protocols bgp group evpn_underlay import evpn_underlay_import set protocols bgp group evpn_underlay family inet unicast set protocols bgp group evpn_underlay authentication-key "xyz" set protocols bgp group evpn_underlay export evpn_underlay_export set protocols bgp group evpn_underlay local-as 65001 set protocols bgp group evpn_underlay multipath multiple-as set protocols bgp group evpn_underlay bfd-liveness-detection minimum- interval 350 set protocols bgp group evpn_underlay bfd-liveness-detection multiplier 3 set protocols bgp group evpn_underlay neighbor 10.255.240.4 peer-as 65002 set protocols bgp group evpn_underlay neighbor 10.255.240.3 peer-as 65002
EVPN-VXLAN 叠加和虚拟网络的配置
本节显示使用 eBGP 在核心交换机和分布式交换机上进行 EVPN-VXLAN 叠加的瞻博网络 Mist 云配置输出。
瞻博网络 Mist 利用核心层和分布层之间的 BFD,实现跨叠加网络的负载平衡,并在链路或节点发生故障时实现 BGP 的快速融合。
瞻博网络 Mist 在分布层上配置第 3 层 IRB 接口。
瞻博网络 Mist 支持 VXLAN 隧道、VLAN 到 VXLAN 映射以及 MP-BGP 配置片段,如分布式和核心交换机上的 VRF 目标。
用于流量隔离的 VRF 配置在分布交换机上。
Core1 配置:
- 两个分布式交换机之间的 BGP 叠加对等:
set protocols bgp group evpn_overlay type internal set protocols bgp group evpn_overlay local-address 172.16.254.2 set protocols bgp group evpn_overlay log-updown set protocols bgp group evpn_overlay family evpn signaling set protocols bgp group evpn_overlay authentication-key "xyz" set protocols bgp group evpn_overlay cluster 1.0.0.1 set protocols bgp group evpn_overlay local-as 65000 set protocols bgp group evpn_overlay multipath set protocols bgp group evpn_overlay bfd-liveness-detection minimum- interval 1000 set protocols bgp group evpn_overlay bfd-liveness-detection multiplier 3 set protocols bgp group evpn_overlay bfd-liveness-detection session-mode automatic set protocols bgp group evpn_overlay neighbor 172.16.254.1
- 用于定义 VRF 目标和用于 VXLAN 的源环路接口的交换机选项:
set groups top switch-options vtep-source-interface lo0.0 set groups top switch-options route-distinguisher 172.16.254.2:1 set groups top switch-options vrf-target target:65000:1 set groups top switch-options vrf-target auto
- VXLAN 封装:
set groups top protocols evpn no-core-isolation set groups top protocols evpn encapsulation vxlan set groups top protocols evpn default-gateway no-gateway-community set groups top protocols evpn extended-vni-list all
- 用于流量隔离的 VRF:
set groups top routing-instances guest-wifi instance-type vrf set groups top routing-instances guest-wifi routing-options static route 0.0.0.0/0 next-hop 10.33.33.254 set groups top routing-instances guest-wifi routing-options auto-export set groups top routing-instances guest-wifi interface irb.1033 set groups top routing-instances guest-wifi route-distinguisher 172.16.254.2:103 set groups top routing-instances guest-wifi vrf-target target:65000:103 set groups top routing-instances guest-wifi vrf-table-label set groups top routing-instances developers instance-type vrf set groups top routing-instances developers routing-options static route 0.0.0.0/0 next-hop 10.88.88.254 set groups top routing-instances developers routing-options auto-export set groups top routing-instances developers interface irb.1088 set groups top routing-instances developers route-distinguisher 172.16.254.2:102 set groups top routing-instances developers vrf-target target:65000:102 set groups top routing-instances developers vrf-table-label set groups top routing-instances corp-it instance-type vrf set groups top routing-instances corp-it routing-options static route 0.0.0.0/0 next-hop 10.99.99.254 set groups top routing-instances corp-it routing-options auto-export set groups top routing-instances corp-it interface irb.1099 set groups top routing-instances corp-it route-distinguisher 172.16.254.2:101 set groups top routing-instances corp-it vrf-target target:65000:101 set groups top routing-instances corp-it vrf-table-label
- VLAN 到 VXLAN 映射:
set vlans vlan1033 vlan-id 1033 set vlans vlan1033 l3-interface irb.1033 set vlans vlan1033 vxlan vni 11033 set vlans vlan1088 vlan-id 1088 set vlans vlan1088 l3-interface irb.1088 set vlans vlan1088 vxlan vni 11088 set vlans vlan1099 vlan-id 1099 set vlans vlan1099 l3-interface irb.1099 set vlans vlan1099 vxlan vni 11099
- 使用虚拟网关寻址实现第 3 层 IRB 接口支持:
set interfaces irb unit 1033 virtual-gateway-accept-data set interfaces irb unit 1033 description vlan1033 set interfaces irb unit 1033 family inet address 10.33.33.2/24 virtual-gateway-address 10.33.33.1 set interfaces irb unit 1088 virtual-gateway-accept-data set interfaces irb unit 1088 description vlan1088 set interfaces irb unit 1088 family inet address 10.88.88.2/24 virtual-gateway-address 10.88.88.1 set interfaces irb unit 1099 virtual-gateway-accept-data set interfaces irb unit 1099 description vlan1099 set interfaces irb unit 1099 family inet address 10.99.99.2/24 virtual-gateway-address 10.99.99.1
Core2 配置:
- 两个分布式交换机之间的 BGP 叠加对等:
set protocols bgp group evpn_overlay type internal set protocols bgp group evpn_overlay local-address 172.16.254.1 set protocols bgp group evpn_overlay log-updown set protocols bgp group evpn_overlay family evpn signaling set protocols bgp group evpn_overlay authentication-key "xyz" set protocols bgp group evpn_overlay cluster 1.0.0.1 set protocols bgp group evpn_overlay local-as 65000 set protocols bgp group evpn_overlay multipath set protocols bgp group evpn_overlay bfd-liveness-detection minimum- interval 1000 set protocols bgp group evpn_overlay bfd-liveness-detection multiplier 3 set protocols bgp group evpn_overlay bfd-liveness-detection session-mode automatic set protocols bgp group evpn_overlay neighbor 172.16.254.2
- 用于定义 VRF 目标和用于 VXLAN 的源环路接口的交换机选项:
set groups top switch-options vtep-source-interface lo0.0 set groups top switch-options route-distinguisher 172.16.254.1:1 set groups top switch-options vrf-target target:65000:1 set groups top switch-options vrf-target auto
- VXLAN 封装:
set groups top protocols evpn no-core-isolation set groups top protocols evpn encapsulation vxlan set groups top protocols evpn default-gateway no-gateway-community set groups top protocols evpn extended-vni-list all
- 用于流量隔离的 VRF:
set groups top routing-instances guest-wifi instance-type vrf set groups top routing-instances guest-wifi routing-options static route 0.0.0.0/0 next-hop 10.33.33.254 set groups top routing-instances guest-wifi routing-options auto-export set groups top routing-instances guest-wifi interface irb.1033 set groups top routing-instances guest-wifi route-distinguisher 172.16.254.1:103 set groups top routing-instances guest-wifi vrf-target target:65000:103 set groups top routing-instances guest-wifi vrf-table-label set groups top routing-instances developers instance-type vrf set groups top routing-instances developers routing-options static route 0.0.0.0/0 next-hop 10.88.88.254 set groups top routing-instances developers routing-options auto-export set groups top routing-instances developers interface irb.1088 set groups top routing-instances developers route-distinguisher 172.16.254.1:102 set groups top routing-instances developers vrf-target target:65000:102 set groups top routing-instances developers vrf-table-label set groups top routing-instances corp-it instance-type vrf set groups top routing-instances corp-it routing-options static route 0.0.0.0/0 next-hop 10.99.99.254 set groups top routing-instances corp-it routing-options auto-export set groups top routing-instances corp-it interface irb.1099 set groups top routing-instances corp-it route-distinguisher 172.16.254.1:101 set groups top routing-instances corp-it vrf-target target:65000:101 set groups top routing-instances corp-it vrf-table-label
- VLAN 到 VXLAN 映射:
set vlans vlan1033 vlan-id 1033 set vlans vlan1033 l3-interface irb.1033 set vlans vlan1033 vxlan vni 11033 set vlans vlan1088 vlan-id 1088 set vlans vlan1088 l3-interface irb.1088 set vlans vlan1088 vxlan vni 11088 set vlans vlan1099 vlan-id 1099 set vlans vlan1099 l3-interface irb.1099 set vlans vlan1099 vxlan vni 11099
- 通过虚拟网关寻址实现第 3 层 IRB 接口启用。
set interfaces irb unit 1033 virtual-gateway-accept-data set interfaces irb unit 1033 description vlan1033 set interfaces irb unit 1033 family inet address 10.33.33.3/24 virtual-gateway-address 10.33.33.1 set interfaces irb unit 1088 virtual-gateway-accept-data set interfaces irb unit 1088 description vlan1088 set interfaces irb unit 1088 family inet address 10.88.88.3/24 virtual-gateway-address 10.88.88.1 set interfaces irb unit 1099 virtual-gateway-accept-data set interfaces irb unit 1099 description vlan1099 set interfaces irb unit 1099 family inet address 10.99.99.3/24 virtual-gateway-address 10.99.99.1
分布交换机与接入交换机之间的第 2 层 ESI-LAG 配置
本部分显示瞻博网络 Mist 云输出的配置,用于在分布交换机和接入交换机之间启用第 2 层 ESI-LAG。此瞻博网络 Mist 配置文件支持以太网捆绑包上的所有 VLAN,并具有必要的 ESI 和 LACP 配置选项。从接入交换机的角度来看,在接入层上配置的以太网捆绑包将 ESI-LAG 视为具有相同 LACP 系统 ID 的单个 MAC 地址。这样就能在分布层和接入层之间实现负载散列,而无需 RSTP 等第 2 层无环路检测协议。
Core1 配置:
- 与新创建的以太网捆绑包(包括 ESI 和 LACP 配置)的接口关联:
set interfaces ae0 apply-groups esi-lag set interfaces ae0 esi 00:11:00:00:00:01:00:01:02:00 set interfaces ae0 esi all-active set interfaces ae0 aggregated-ether-options lacp active set interfaces ae0 aggregated-ether-options lacp periodic fast set interfaces ae0 aggregated-ether-options lacp system-id 00:00:00:31:57:00 set interfaces ae0 aggregated-ether-options lacp admin-key 0 set interfaces ae1 apply-groups esi-lag set interfaces ae1 esi 00:11:00:00:00:01:00:01:02:01 set interfaces ae1 esi all-active set interfaces ae1 aggregated-ether-options lacp active set interfaces ae1 aggregated-ether-options lacp periodic fast set interfaces ae1 aggregated-ether-options lacp system-id 00:00:00:31:57:01 set interfaces ae1 aggregated-ether-options lacp admin-key 1 set groups esi-lag interfaces <*> unit 0 family ethernet-switching interface-mode trunk set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1033 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1088 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1099 set interfaces xe-0/0/1 description esilag-to-4c734f095900 set interfaces xe-0/0/1 hold-time up 120000 set interfaces xe-0/0/1 hold-time down 1 set interfaces xe-0/0/1 ether-options 802.3ad ae1 set interfaces xe-0/0/1 unit 0 family ethernet-switching storm-control default deactivate interfaces xe-0/0/1 unit 0 set interfaces xe-0/0/2 description esilag-to-4c734f095900 set interfaces xe-0/0/2 hold-time up 120000 set interfaces xe-0/0/2 hold-time down 1 set interfaces xe-0/0/2 ether-options 802.3ad ae0
Core2 配置:
- 与新创建的以太网捆绑包(包括 ESI 和 LACP 配置)的接口关联:
set interfaces ae0 apply-groups esi-lag set interfaces ae0 esi 00:11:00:00:00:01:00:01:02:00 set interfaces ae0 esi all-active set interfaces ae0 aggregated-ether-options lacp active set interfaces ae0 aggregated-ether-options lacp periodic fast set interfaces ae0 aggregated-ether-options lacp system-id 00:00:00:31:57:00 set interfaces ae0 aggregated-ether-options lacp admin-key 0 set interfaces ae1 apply-groups esi-lag set interfaces ae1 esi 00:11:00:00:00:01:00:01:02:01 set interfaces ae1 esi all-active set interfaces ae1 aggregated-ether-options lacp active set interfaces ae1 aggregated-ether-options lacp periodic fast set interfaces ae1 aggregated-ether-options lacp system-id 00:00:00:31:57:01 set interfaces ae1 aggregated-ether-options lacp admin-key 1 set groups esi-lag interfaces <*> unit 0 family ethernet-switching interface-mode trunk set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1033 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1088 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1099 set interfaces xe-0/0/1 description esilag-to-4c734f095900 set interfaces xe-0/0/1 hold-time up 120000 set interfaces xe-0/0/1 hold-time down 1 set interfaces xe-0/0/1 ether-options 802.3ad ae1 set interfaces xe-0/0/1 unit 0 family ethernet-switching storm-control default deactivate interfaces xe-0/0/1 unit 0 set interfaces xe-0/0/2 description esilag-to-4c734f095900 set interfaces xe-0/0/2 hold-time up 120000 set interfaces xe-0/0/2 hold-time down 1 set interfaces xe-0/0/2 ether-options 802.3ad ae0 set interfaces xe-0/0/2 unit 0 family ethernet-switching storm-control default deactivate interfaces xe-0/0/2 unit 0
Access1 配置:
- 与新的 LACP 以太网捆绑包关联的 VLAN:
set groups esi-lag interfaces <*> mtu 9200 set groups esi-lag interfaces <*> unit 0 family ethernet-switching interface-mode trunk set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1033 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1088 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1099 set interfaces ae1 apply-groups esi-lag set interfaces ae1 aggregated-ether-options lacp active set interfaces xe-0/2/0 ether-options 802.3ad ae1 set interfaces xe-0/2/0 unit 0 family ethernet-switching storm-control default deactivate interfaces xe-0/2/0 unit 0 set interfaces xe-0/2/3 ether-options 802.3ad ae1 set interfaces xe-0/2/3 unit 0 family ethernet-switching storm-control default deactivate interfaces xe-0/2/3 unit 0
Access2 配置:
- 与新的 LACP 以太网捆绑包关联的 VLAN:
set groups esi-lag interfaces <*> mtu 9200 set groups esi-lag interfaces <*> unit 0 family ethernet-switching interface-mode trunk set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1033 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1088 set groups esi-lag interfaces <*> unit 0 family ethernet-switching vlan members vlan1099 set interfaces ae0 apply-groups esi-lag set interfaces ae0 aggregated-ether-options lacp active set interfaces xe-0/2/0 ether-options 802.3ad ae0 set interfaces xe-0/2/0 unit 0 family ethernet-switching storm-control default deactivate interfaces xe-0/2/0 unit 0 set interfaces xe-0/2/3 ether-options 802.3ad ae0 set interfaces xe-0/2/3 unit 0 family ethernet-switching storm-control default deactivate interfaces xe-0/2/3 unit 0
核心交换机与 MX 路由器之间的第 2 层 ESI-LAG 配置
本部分显示瞻博网络 Mist 云输出的配置,用于在核心交换机和 SRX 系列防火墙之间启用第 2 层 ESI LAG。此 Mist 配置文件可通过必要的 ESI 和 LACP 配置选项启用以太网捆绑包上的所有 VLAN。从 SRX 系列防火墙的角度来看,在 SRX 系列防火墙上配置的以太网捆绑包会将 ESI-LAG 视为具有相同 LACP 系统 ID 的单个 MAC 地址。这样可以在核心和 SRX 系列防火墙之间实现负载散列,而无需 RSTP 等第 2 层无环路检测协议。
的第 2 层 ESI-LAG
核心 1 配置:
- 与新创建的以太网捆绑包(包括 ESI 和 LACP 配置)的接口关联:
set interfaces ge-0/0/10 description esilag-to-4c734f095900 set interfaces ge-0/0/10 hold-time up 120000 set interfaces ge-0/0/10 hold-time down 1 set interfaces ge-0/0/10 ether-options 802.3ad ae2 set interfaces ge-0/0/10 unit 0 family ethernet-switching storm-control default deactivate interfaces ge-0/0/10 unit 0 set interfaces ae2 apply-groups esi-lag set interfaces ae2 esi 00:11:00:00:00:01:00:01:02:02 set interfaces ae2 esi all-active set interfaces ae2 aggregated-ether-options lacp active set interfaces ae2 aggregated-ether-options lacp periodic fast set interfaces ae2 aggregated-ether-options lacp system-id 00:00:00:31:57:02 set interfaces ae2 aggregated-ether-options lacp admin-key 2
核心 2 配置:
- 与新创建的以太网捆绑包(包括 ESI 和 LACP 配置)的接口关联:
set interfaces ge-0/0/10 description esilag-to-4c734f095900 set interfaces ge-0/0/10 hold-time up 120000 set interfaces ge-0/0/10 hold-time down 1 set interfaces ge-0/0/10 ether-options 802.3ad ae2 set interfaces ge-0/0/10 unit 0 family ethernet-switching storm-control default deactivate interfaces ge-0/0/10 unit 0 set interfaces ae2 apply-groups esi-lag set interfaces ae2 esi 00:11:00:00:00:01:00:01:02:02 set interfaces ae2 esi all-active set interfaces ae2 aggregated-ether-options lacp active set interfaces ae2 aggregated-ether-options lacp periodic fast set interfaces ae2 aggregated-ether-options lacp system-id 00:00:00:31:57:02 set interfaces ae2 aggregated-ether-options lacp admin-key 2
SRX 系列防火墙配置:
- 与新创建的以太网捆绑包和 LACP 配置的接口关联:
set interfaces ae0 flexible-vlan-tagging set interfaces ae0 aggregated-ether-options lacp active set interfaces ae0 unit 1033 vlan-id 1033 set interfaces ae0 unit 1033 family inet address 10.33.33.254/24 set interfaces ae0 unit 1088 vlan-id 1088 set interfaces ae0 unit 1088 family inet address 10.88.88.254/24 set interfaces ae0 unit 1099 vlan-id 1099 set interfaces ae0 unit 1099 family inet address 10.99.99.254/24