SP-A EVPN-ELAN: an E-LAN Between Two CustB Sites over the RSVP-TE Tunnel

E-LAN is a multipoint Ethernet service: every customer site can reach every other site, as if all of them were on one LAN. With EVPN, each PE learns the MAC addresses of its own sites from their frames and advertises them to the other PEs in BGP. Frames between the PEs cross the MPLS core with a label that the receiving PE advertised for the service.

This stage builds a single-homed EVPN-ELAN, EVI 12, between CustB-Hub on A-PE1 and CustB-Spk1 on A-PE2. It runs on VLAN 12 of the same Gi5 ports that carry the VPWS on VLAN 11. This is bridge domain 12 on A-PE1 after the stage was configured:

A-PE1#show bridge-domain 12
Bridge-domain 12 (2 ports in all)
State: UP                    Mac learning: Enabled
Aging-Timer: 300 second(s)
    GigabitEthernet5 service instance 12
    EVPN Instance 12
   AED MAC address    Policy  Tag       Age  Pseudoport
   -   AABB.CC00.1510 forward static_r  0    OCE_PTR:0xe927fc60
   -   AABB.CC00.1410 forward dynamic_c 144  GigabitEthernet5.EFP12

AABB.CC00.1410 is CustB-Hub’s MAC, learned from frames arriving on service instance 12. AABB.CC00.1510 is CustB-Spk1’s MAC: A-PE1 installed it as a static entry from the BGP route A-PE2 advertised for it.

Topology file: topology.clab.yml · Addressing: ipam.md · Stage configs, 5 nodes (the two PEs, the route reflector and the two CustB CEs): stage_configs/lab02-s3b-spa-evpn/

Gi5 and the EVPN Instance

The whole configuration of A-PE1 for this stage:

l2vpn evpn
 replication-type ingress
 router-id Loopback0
!
l2vpn evpn instance 12 vlan-based
!
bridge-domain 12
 member GigabitEthernet5 service-instance 12
 member evpn-instance 12
!
interface GigabitEthernet5
 service instance 12 ethernet
  description EVPN-ELAN EVI 12 -> CustB ELAN (VLAN 12)
  encapsulation dot1q 12
  rewrite ingress tag pop 1 symmetric
!
router bgp 64501
 address-family l2vpn evpn
  neighbor 10.1.0.7 activate
  neighbor 10.1.0.7 send-community both

Service instance 12 uses the same rewrite as service instance 11 of the VPWS: it removes tag 12 from frames coming from CustB-Hub and pushes it back on frames going to it.

A bridge domain is a Layer 2 broadcast domain made of ports. Bridge domain 12 has two: service instance 12 toward CustB-Hub and EVPN instance 12 toward the other PEs.

replication-type ingress makes A-PE1 copy each broadcast, unknown-unicast and multicast frame to every PE that advertised a Type-3 route for EVI 12.

In BGP, the l2vpn evpn address family goes on the existing iBGP session to A-RR, 10.1.0.7. send-community both is there because route targets are extended communities. A-PE2 has the same configuration.

CustB-Hub sends VLAN 12 from a dot1Q subinterface, and CustB-Spk1 uses 10.20.12.2 on the same subnet:

interface Ethernet0/1.12
 description EVPN-ELAN (VLAN 12) -> CustB-Spk1
 encapsulation dot1Q 12
 ip address 10.20.12.1 255.255.255.248
 ipv6 address 2001:DB8:20:12::1/64

As on VLAN 11, the subnet is a /29 so that Spk2 can use 10.20.12.3.

Gi5 on A-PE1 now has one service instance in a bridge domain and one on an xconnect, both up:

A-PE1#show ethernet service instance interface gi5 sum
Associated interface: GigabitEthernet5
            Total       Up  AdminDo     Down  ErrorDi  Unknown  Deleted  BdAdmDo
bdomain         1        1        0        0        0        0        0        0
xconnect        1        1        0        0        0        0        0        0
local sw        0        0        0        0        0        0        0        0
other           0        0        0        0        0        0        0        0
all             2        2        0        0        0        0        0        0

EVI 12

On A-PE1, we have the following output for the EVI section:

A-PE1#show l2vpn evpn evi 12 det
EVPN instance:    12 (VLAN Based)
  RD:             10.1.0.5:12 (auto)
  Import-RTs:     64501:12
  Export-RTs:     64501:12
  Per-EVI Label:  none
  State:          Established
  Encapsulation:  mpls
  Bridge Domain:  12
    Ethernet-Tag: 0
    BUM Label:    1518
    Per-BD Label: 1519
    State:        Established
    Pseudoports:
      GigabitEthernet5 service instance 12

A-PE1 builds the route distinguisher 10.1.0.5:12 from its Loopback0 and the EVI number. It builds the route target 64501:12 from the AS number and the EVI number and uses it for both import and export. A-PE2 builds 10.1.0.6:12 and the same route target, so each PE imports the routes of the other.

A-PE1 expects label 1518 on broadcast, unknown-unicast and multicast frames from other PEs, and label 1519 on unicast frames for a MAC in bridge domain 12.

Type-2 and Type-3 Routes

A-PE1’s BGP table for the l2vpn evpn address family:

A-PE1#show bgp l2vpn evpn
BGP table version is 7, local router ID is 10.1.0.5
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
              r RIB-failure, S Stale, m multipath, b backup-path, f RT-Filter,
              x best-external, a additional-path, c RIB-compressed,
              t secondary path, L long-lived-stale,
Origin codes: i - IGP, e - EGP, ? - incomplete
RPKI validation codes: V valid, I invalid, N Not found

     Network          Next Hop            Metric LocPrf Weight Path
Route Distinguisher: 10.1.0.5:12
 *>   [2][10.1.0.5:12][0][48][AABBCC001410][0][*]/20
                      ::                                 32768 ?
 *>i  [2][10.1.0.5:12][0][48][AABBCC001510][0][*]/20
                      10.1.0.6                 0    100      0 ?
Route Distinguisher: 10.1.0.6:12
 *>i  [2][10.1.0.6:12][0][48][AABBCC001510][0][*]/20
                      10.1.0.6                 0    100      0 ?
Route Distinguisher: 10.1.0.5:12
 *>   [3][10.1.0.5:12][0][32][10.1.0.5]/17
                      ::                                 32768 ?
 *>i  [3][10.1.0.5:12][0][32][10.1.0.6]/17
                      10.1.0.6                 0    100      0 ?
Route Distinguisher: 10.1.0.6:12
 *>i  [3][10.1.0.6:12][0][32][10.1.0.6]/17
                      10.1.0.6                 0    100      0 ?

The [2] routes are MAC/IP Advertisement routes. The fields after the route type are the RD, the Ethernet Tag (0), the MAC length (48), the MAC and the IP length (0), so these routes carry MAC addresses only.

CustB-Hub’s MAC has next hop :: because A-PE1 originated the route. A-PE2’s routes appear twice: under A-PE2’s RD 10.1.0.6:12 as received from A-RR, and under A-PE1’s RD 10.1.0.5:12 after the import into EVI 12.

The [3] routes are Inclusive Multicast Ethernet Tag routes, one from each PE. Each one tells the other PEs that its originator is in EVI 12, gives the address to send copies of flooded frames to, and carries the originator’s BUM label.

Only Type-2 and Type-3 routes are in the table. Type-1 and Type-4 routes come with multi-homing, but in my current lab I have only single-homed CEs.

A-PE2 installed CustB-Hub’s MAC from A-PE1’s Type-2 route the same way:

A-PE2#show bridge-domain 12
Bridge-domain 12 (2 ports in all)
State: UP                    Mac learning: Enabled
Aging-Timer: 300 second(s)
    GigabitEthernet5 service instance 12
    EVPN Instance 12
   AED MAC address    Policy  Tag       Age  Pseudoport
   -   AABB.CC00.1510 forward dynamic_c 275  GigabitEthernet5.EFP12
   -   AABB.CC00.1410 forward static_r  0    OCE_PTR:0xe92de460

The Route Reflector

A-RR is an XRd control-plane node, with l2vpn evpn enabled globally and under each PE neighbor with route-reflector-client. The last lines of A-RR’s show bgp l2vpn evpn neighbors 10.1.0.5:

  Connections established 3; dropped 2
  Local host: 10.1.0.7, Local port: 179, IF Handle: 0x00000000
  Foreign host: 10.1.0.5, Foreign port: 43071
  Last reset 00:17:32, due to Address family activated

Activating l2vpn evpn reset the session to A-PE1, which will also affect the VPNv4 and VPNv6 address families of the L3VPNs.

CustB-Hub to CustB-Spk1

The EVPN routes from A-PE2 have next hop 10.1.0.6, and A-PE1 reaches 10.1.0.6 through Tunnel10:

A-PE1#show ip cef 10.1.0.6 detail
10.1.0.6/32, epoch 2, flags [attached]
  dflt local label info: global/1504 [0x3]
  3 RR sources [no flags]
  attached to Tunnel10

Tunnel10’s autoroute destination installed that route in the TE stage, so frames for CustB-Spk1 ride Tunnel10, as the VPWS does.

A ping from CustB-Hub to CustB-Spk1 across EVI 12 and Tunnel10

From CustB-Hub:

CustB-Hub#ping 10.20.12.2 source Eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.12.2, timeout is 2 seconds:
Packet sent with a source address of 10.20.12.1
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
CustB-Hub#ping 2001:db8:20:12::2 source Eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:20:12::2, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:20:12::1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/3/8 ms
CustB-Hub#show arp | i 10.20.12.2
Internet  10.20.12.2              0   aabb.cc00.1510  ARPA   Ethernet0/1.12
CustB-Hub#

IOS drops the packet that triggers an ARP request, so the first IPv4 echo was lost while CustB-Hub resolved 10.20.12.2. The ARP entry points to aabb.cc00.1510, the MAC in both bridge-domain tables.

From CustB-Spk1:

CustB-Spk1#ping 10.20.12.1 sou Eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.20.12.1, timeout is 2 seconds:
Packet sent with a source address of 10.20.12.2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/3 ms
CustB-Spk1#ping 2001:db8:20:12::1 source eth0/1.12
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:20:12::1, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:20:12::2
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
CustB-Spk1#show arp | i 10.20.12.1
Internet  10.20.12.1              1   aabb.cc00.1410  ARPA   Ethernet0/1.12
CustB-Spk1#

What’s Next

The CustA L3VPN between HQ and Br1 works over IPv4 and IPv6 after the reset:

CustA-HQ#ping 10.10.0.2 sour lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.0.2, timeout is 2 seconds:
Packet sent with a source address of 10.10.0.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 2/2/3 ms
CustA-HQ#ping 2001:db8:10::2 sou lo0
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 2001:DB8:10::2, timeout is 2 seconds:
Packet sent with a source address of 2001:DB8:10::1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
CustA-HQ#

The next stage builds an IP multicast core in SP-A.

Leave a Reply