E-LAN is a multipoint Ethernet service: every customer site can reach every other site, as if all of them were on one LAN. With EVPN, each PE learns the MAC addresses of its own sites from their frames and advertises them to the other PEs in BGP. Frames between the PEs cross the MPLS core with a label that the receiving PE advertised for the service.
This stage builds a single-homed EVPN-ELAN, EVI 12, between CustB-Hub on A-PE1 and CustB-Spk1 on A-PE2. It runs on VLAN 12 of the same Gi5 ports that carry the VPWS on VLAN 11. This is bridge domain 12 on A-PE1 after the stage was configured:
A-PE1#show bridge-domain 12
Bridge-domain 12 (2 ports in all)
State: UP Mac learning: Enabled
Aging-Timer: 300 second(s)
GigabitEthernet5 service instance 12
EVPN Instance 12
AED MAC address Policy Tag Age Pseudoport
- AABB.CC00.1510 forward static_r 0 OCE_PTR:0xe927fc60
- AABB.CC00.1410 forward dynamic_c 144 GigabitEthernet5.EFP12
AABB.CC00.1410 is CustB-Hub’s MAC, learned from frames arriving on service instance 12. AABB.CC00.1510 is CustB-Spk1’s MAC: A-PE1 installed it as a static entry from the BGP route A-PE2 advertised for it.
Topology file: topology.clab.yml · Addressing: ipam.md · Stage configs, 5 nodes (the two PEs, the route reflector and the two CustB CEs): stage_configs/lab02-s3b-spa-evpn/
Gi5 and the EVPN Instance
The whole configuration of A-PE1 for this stage:
l2vpn evpn
replication-type ingress
router-id Loopback0
!
l2vpn evpn instance 12 vlan-based
!
bridge-domain 12
member GigabitEthernet5 service-instance 12
member evpn-instance 12
!
interface GigabitEthernet5
service instance 12 ethernet
description EVPN-ELAN EVI 12 -> CustB ELAN (VLAN 12)
encapsulation dot1q 12
rewrite ingress tag pop 1 symmetric
!
router bgp 64501
address-family l2vpn evpn
neighbor 10.1.0.7 activate
neighbor 10.1.0.7 send-community both
Service instance 12 uses the same rewrite as service instance 11 of the VPWS: it removes tag 12 from frames coming from CustB-Hub and pushes it back on frames going to it.
A bridge domain is a Layer 2 broadcast domain made of ports. Bridge domain 12 has two: service instance 12 toward CustB-Hub and EVPN instance 12 toward the other PEs.
replication-type ingress makes A-PE1 copy each broadcast, unknown-unicast and multicast frame to every PE that advertised a Type-3 route for EVI 12.
In BGP, the l2vpn evpn address family goes on the existing iBGP session to A-RR, 10.1.0.7. send-community both is there because route targets are extended communities. A-PE2 has the same configuration.
CustB-Hub sends VLAN 12 from a dot1Q subinterface, and CustB-Spk1 uses 10.20.12.2 on the same subnet:
interface Ethernet0/1.12
description EVPN-ELAN (VLAN 12) -> CustB-Spk1
encapsulation dot1Q 12
ip address 10.20.12.1 255.255.255.248
ipv6 address 2001:DB8:20:12::1/64
As on VLAN 11, the subnet is a /29 so that Spk2 can use 10.20.12.3.
Gi5 on A-PE1 now has one service instance in a bridge domain and one on an xconnect, both up:
A-PE1#show ethernet service instance interface gi5 sum
Associated interface: GigabitEthernet5
Total Up AdminDo Down ErrorDi Unknown Deleted BdAdmDo
bdomain 1 1 0 0 0 0 0 0
xconnect 1 1 0 0 0 0 0 0
local sw 0 0 0 0 0 0 0 0
other 0 0 0 0 0 0 0 0
all 2 2 0 0 0 0 0 0
EVI 12
On A-PE1, we have the following output for the EVI section:
A-PE1#show l2vpn evpn evi 12 det
EVPN instance: 12 (VLAN Based)
RD: 10.1.0.5:12 (auto)
Import-RTs: 64501:12
Export-RTs: 64501:12
Per-EVI Label: none
State: Established
Encapsulation: mpls
Bridge Domain: 12
Ethernet-Tag: 0
BUM Label: 1518
Per-BD Label: 1519
State: Established
Pseudoports:
GigabitEthernet5 service instance 12
A-PE1 builds the route distinguisher 10.1.0.5:12 from its Loopback0 and the EVI number. It builds the route target 64501:12 from the AS number and the EVI number and uses it for both import and export. A-PE2 builds 10.1.0.6:12 and the same route target, so each PE imports the routes of the other.
A-PE1 expects label 1518 on broadcast, unknown-unicast and multicast frames from other PEs, and label 1519 on unicast frames for a MAC in bridge domain 12.
Type-2 and Type-3 Routes
A-PE1’s BGP table for the l2vpn evpn address family:
A-PE1#show bgp l2vpn evpn
BGP table version is 7, local router ID is 10.1.0.5
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter,
x best-external, a additional-path, c RIB-compressed,
t secondary path, L long-lived-stale,
Origin codes: i - IGP, e - EGP, ? - incomplete
RPKI validation codes: V valid, I invalid, N Not found
Network Next Hop Metric LocPrf Weight Path
Route Distinguisher: 10.1.0.5:12
*> [2][10.1.0.5:12][0][48][AABBCC001410][0][*]/20
:: 32768 ?
*>i [2][10.1.0.5:12][0][48][AABBCC001510][0][*]/20
10.1.0.6 0 100 0 ?
Route Distinguisher: 10.1.0.6:12
*>i [2][10.1.0.6:12][0][48][AABBCC001510][0][*]/20
10.1.0.6 0 100 0 ?
Route Distinguisher: 10.1.0.5:12
*> [3][10.1.0.5:12][0][32][10.1.0.5]/17
:: 32768 ?
*>i [3][10.1.0.5:12][0][32][10.1.0.6]/17
10.1.0.6 0 100 0 ?
Route Distinguisher: 10.1.0.6:12
*>i [3][10.1.0.6:12][0][32][10.1.0.6]/17
10.1.0.6 0 100 0 ?
The [2] routes are MAC/IP Advertisement routes. The fields after the route type are the RD, the Ethernet Tag (0), the MAC length (48), the MAC and the IP length (0), so these routes carry MAC addresses only.
CustB-Hub’s MAC has next hop :: because A-PE1 originated the route. A-PE2’s routes appear twice: under A-PE2’s RD 10.1.0.6:12 as received from A-RR, and under A-PE1’s RD 10.1.0.5:12 after the import into EVI 12.
The [3] routes are Inclusive Multicast Ethernet Tag routes, one from each PE. Each one tells the other PEs that its originator is in EVI 12, gives the address to send copies of flooded frames to, and carries the originator’s BUM label.
Only Type-2 and Type-3 routes are in the table. Type-1 and Type-4 routes come with multi-homing, but in my current lab I have only single-homed CEs.
A-PE2 installed CustB-Hub’s MAC from A-PE1’s Type-2 route the same way:
A-PE2#show bridge-domain 12
Bridge-domain 12 (2 ports in all)
State: UP Mac learning: Enabled
Aging-Timer: 300 second(s)
GigabitEthernet5 service instance 12
EVPN Instance 12
AED MAC address Policy Tag Age Pseudoport
- AABB.CC00.1510 forward dynamic_c 275 GigabitEthernet5.EFP12
- AABB.CC00.1410 forward static_r 0 OCE_PTR:0xe92de460
The Route Reflector
A-RR is an XRd control-plane node, with l2vpn evpn enabled globally and under each PE neighbor with route-reflector-client. The last lines of A-RR’s show bgp l2vpn evpn neighbors 10.1.0.5:
Connections established 3; dropped 2
Local host: 10.1.0.7, Local port: 179, IF Handle: 0x00000000
Foreign host: 10.1.0.5, Foreign port: 43071
Last reset 00:17:32, due to Address family activated
Activating l2vpn evpn reset the session to A-PE1, which will also affect the VPNv4 and VPNv6 address families of the L3VPNs.
CustB-Hub to CustB-Spk1
The EVPN routes from A-PE2 have next hop 10.1.0.6, and A-PE1 reaches 10.1.0.6 through Tunnel10:
A-PE1#show ip cef 10.1.0.6 detail
10.1.0.6/32, epoch 2, flags [attached]
dflt local label info: global/1504 [0x3]
3 RR sources [no flags]
attached to Tunnel10
Tunnel10’s autoroute destination installed that route in the TE stage, so frames for CustB-Spk1 ride Tunnel10, as the VPWS does.

From CustB-Hub:
CustB-Hub#ping 10.20.12.2 source Eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.12.2, timeout is 2 seconds:
Packet sent with a source address of 10.20.12.1
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
CustB-Hub#ping 2001:db8:20:12::2 source Eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:20:12::2, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:20:12::1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms
CustB-Hub#show arp | i 10.20.12.2
Internet 10.20.12.2 0 aabb.cc00.1510 ARPA Ethernet0/1.12
CustB-Hub#
IOS drops the packet that triggers an ARP request, so the first IPv4 echo was lost while CustB-Hub resolved 10.20.12.2. The ARP entry points to aabb.cc00.1510, the MAC in both bridge-domain tables.
From CustB-Spk1:
CustB-Spk1#ping 10.20.12.1 sou Eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.12.1, timeout is 2 seconds:
Packet sent with a source address of 10.20.12.2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/3 ms
CustB-Spk1#ping 2001:db8:20:12::1 source eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:20:12::1, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:20:12::2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
CustB-Spk1#show arp | i 10.20.12.1
Internet 10.20.12.1 1 aabb.cc00.1410 ARPA Ethernet0/1.12
CustB-Spk1#
What’s Next
The CustA L3VPN between HQ and Br1 works over IPv4 and IPv6 after the reset:
CustA-HQ#ping 10.10.0.2 sour lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.0.2, timeout is 2 seconds:
Packet sent with a source address of 10.10.0.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/3 ms
CustA-HQ#ping 2001:db8:10::2 sou lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:10::2, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:10::1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
CustA-HQ#
The next stage builds an IP multicast core in SP-A.
Leave a Reply