Duplicate IP Address Detection for IP Mobility

Configure duplicate IP address detection settings to detect duplicate IP addresses, generate syslog messages, and specify how the device will respond when a duplicate IP address is detected.

IP mobility refers to endpoints, such as virtual machines, containers, and physical hosts, retaining their IP addresses while being moved within an EVPN-VXLAN data center. PE devices advertise their locally learned MAC-IP bindings using EVPN Type 2 MAC/IP advertisement route messages. When an endpoint moves from one PE device to another, the new PE device advertises a MAC-IP route for the same IP address with a higher sequence number. This allows remote PE devices to identify the most current location of the endpoint. As endpoints move within the EVPN-VXLAN network, multiple MAC/IP advertisement routes for the same IP address can exist in the control plane. EVPN IP mobility uses sequence numbers and route precedence rules to identify the active advertisement and ensure that traffic is forwarded to the endpoint's current location.

PE devices in the network use the following precedence order in selecting which IP address source to advertise:

  1. IP address of the local IRB (most preferred).

  2. Locally pinned IP address.

  3. Remotely pinned IP address.

  4. Learned local IP address with a static MAC address.

  5. Learned remote IP address with a static MAC address.

  6. IP address with the highest sequence number.

  7. IP address with the latest timestamp.

Network misconfigurations can lead to unstable endpoint movements, which cause route instability and excessive MAC/IP advertisement route messages. In some scenarios, you may also wish to exclude specific IP addresses from duplicate IP address detection.

Duplicate IP address detection supports valid IP moves by providing you with the mechanism to manage the following:

  • Detect duplicate IP addresses and generate syslog messages.
  • Use EVPN Type 2 route sequence numbers to determine the preferred MAC-IP route to use when multiple MAC/IP advertisement routes exist for the same IP address.
  • Either suppress or continue to forward traffic associated with a duplicate IP address.

  • Exclude selected IP addresses from duplicate IP address detection.

This feature is supported for both IPv4 and IPv6 underlay networks.

Limitations

  • In CRB deployments where proxy-macip-advertisement is enabled, Junos does not apply duplicate IP address detection to IP addresses that are not locally learned on the spine device. Because the MAC/IP advertisement route messages generated on behalf of leaf devices for the endpoints do not have sequence numbers, when proxy-macip-advertisement is enabled. So, duplicate IP address detection cannot be applied to those IP addresses.

  • When no-sequence-numbers is enabled for mac-mobility, MAC/IP advertisement route messages are sent without sequence numbers. Duplicate IP Address Detection will then default to using timestamps.

Benefits of Using Duplicate IP Address Detection for IP Mobility

  • Detects unstable endpoint movement.

  • Prevents excessive MAC/IP advertisement route messages that can be caused by continuous IP movement.

  • Protects against forwarding instability caused by duplicate IP usage.

  • Supports configurable operational responses (block or no-ip-suppression) based on your deployment policy.

  • Provides improved operational visibility through mobility tracking and duplicate IP syslogs.

  • Supports automatic or manual recovery mechanisms when duplicate conditions are resolved.

Configure Duplicate IP Address Detection for IP Mobility

Duplicate IP address detection helps you to manage the IP mobility in an EVPN-VXLAN network. Duplicate IP address detection uses the same detection window and detection threshold configuration settings that are used for duplicate MAC address detection. An IP address is identified as a duplicate IP address when the number of IP mobility events associated with that IP address exceeds the configured detection threshold within the detection window. The duplicate status of the IP address is stored in the EVPN control plane. When the IP address is identified as a duplicate IP in the control plane, the device generates a syslog message and carries out the configured duplicate-ip-detection action.

Configure Duplicate IP Address Detection

To configure duplicate IP address detection, include the following duplicate-ip-detection options at the global [edit protocols evpn] hierarchy level.

  • action—Specify one of the following actions:

    • block—The device generates a syslog message for the duplicate IP address. It stops responding to ARP/ND requests for that IP address and will drop traffic bound for that IP address.

    • no-ip-suppression— The device generates a syslog message for the duplicate IP address. It continues to advertise the MAC-IP routes, responds to ARP/ND requests and will forward traffic destined for the IP address.

  • use-timestamp—The device does not use sequence numbers in the MAC/IP advertisement route messages. Instead, it uses the most recent timestamp to determine the best source selection when a duplicate IP address is detected.

  • exclude-policy—The device uses the policy to exclude IP addresses from duplicate IP address detection.

Exclude IP Addresses from Duplicate IP Address Detection

In some cases, you might want to exclude specific IP addresses from duplicate IP address detection. Examples of IP addresses that might be commonly excluded are anycast IP addresses, shared service IP addresses, static infrastructure IP addresses, or other IP addresses that are expected to move frequently.

Excluded IP addresses are not evaluated for duplicate IP address detection and the device does not take any action or generate syslog messages for those addresses.

The following is a sample policy and configuration for excluding IP addresses 10.10.10.5/32 and 192.168.100.0/24.

For more information about configuring prefix lists in policies, see Understanding Prefix Lists for Use in Routing Policy Match Conditions.

Clear Duplicate IP Addresses

Junos OS does not automatically clear identified duplicate IP addresses. The duplicate IP addresses remain in the suppressed state when the automatic recovery timer is not configured or when you do not manually clear the duplicate IP addresses. Clearing the duplicate IP addresses allows the device to resume normal MAC/IP advertisement route messages.

To set an autorecovery timer for clearing EVPN duplicate IP addresses, configure auto-recovery-time in the [edit routing-instances routing-instance-name protocols duplicate-mac-detection] hierarchy level. The automatic recovery timer defines how long an IP address remains in a duplicate IP state. At the end of this timer, the PE device starts advertising the IP address when there are no conflicting MAC-IP address bindings detected.

Note: Duplicate IP address detection uses the same time interval and detection threshold settings that are used in duplicate MAC address detection. The detection-window and detection-threshold settings are configured as part of the duplicate-mac-detection. Both settings apply to both duplicate MAC address and duplicate IP address detections.

For more information duplicate MAC address detection settings, see Changing Duplicate MAC Address Detection Settings.

To manually clear the suppression of duplicate IP addresses, use the clear evpn duplicate-ip-suppression command. The PE device starts advertising the IP address if no conflicting MAC-IP address bindings were detected.

Viewing Duplicate IP Address Information

Use the following commands to check the status of duplicate IP addresses:

  • show evpn globals
  • show evpn database extensive
  • show evpn instance <instance> mac-ipv4-tracking
  • show evpn instance <instance> mac-ipv6-tracking

The following sample output from the show evpn globals command displays the status of duplicate IP address detection.

The following sample output displays the status of MAC-IP bindings.