




已阅读5页,还剩22页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
CamilloRossi,JohnWeston,TechnicalMarketingEngineer,DCNBU,31Jul2018,ACIHostBasedRoutingAdvertisement,InMulti-PodandMulti-SiteusecasescustomersmayconfiguredifferentL4/L7deviceclustersperpodorsiteEgresstrafficfromapodorsitewillpreferthelocalL3out.IngresstrafficcanarriveatL3outsineitherpodorsite.ThiscanleadtoAsymmetrictrafficflowswheretheingressandegresstrafficistakingadifferentpathresultinginFirewallsdroppingtheflow,Whyishostroutingfromborderleavesneeded?,IPN,WAN,L3Out-1WAN,L3Out-2WAN,BDSubnet192.168.0.1/24,Advertising192.168.0.0/24,Advertising192.168.0.0/24,192.168.0.100,192.168.0.100,CustomersUsingGOLF:GOLFisprimarilyusedbylargeSPsorlargeEnterprisecustomers15-20%customerBenefits:Auto-programmingofVRFsonGOLFrouters1BGP-EVPNsessionforallfabricVRFsVxLANdataplanehandofftoGOLFrouterEVPNroutetoL3VPNroutetranslationHostroutingWorkslikeacharmonceyougetitupIssues:ComplextodeployinreallifeespeciallywithOpflexASR9kteamONLYrecommendsManualGOLFandnotOpflexMissingmanybasicfeatures:Mcastvrfleakingtrustsec,etc,GOLFalreadysupportshostrouteadvertisement.WhynotuseGOLFforhostroutes?,InordertoensuretrafficsymmetryasofACI4.0itwillbepossibletoadvertisehostroutes(/32and/128)fromtheBorderLeavesThehostroutewillbeadvertisedonlyifthehostisconnectedtothelocalPODorlocalsite.IftheEPismovedawayfromthelocalPODorsite,oroncetheEPisremovedfromtheEPdatabase,therouteadvertisewillbewithdrawn.Remoteleafwilladvertisehostroutesforendpointsconnectedtotheremoteleafpairandthepodwheretheremoteleafisassociated.AddssupportforL3multicastwithhostbasedroutingusingregularL3Outs(SupportedonL3Outswithroutedandroutedsub-interfaces,notsupportedwithSVIinterfaces).SupportedRoutingProtocols:BGPOSPFEIGRP,Host-RouteAdvertisementOverview,SupportedonallCloudscaleandlaterswitches(EX/FX/FX2/FX3)Notsupportedon1stGenHardwareTestedborderleafhostscaleis30khostroutes(sumof/32and/128),HostBasedRoutingHW/Scale,HostRouteBehavior,Non-BorderLeaves,BorderLeaves,.1,.2,.3,.1,.2,10.1.10.0/24,10.1.20.0/24,BD1,BD2,AdvertiseHostRoutes:,AdvertiseHostRoutes:R,COOPOracles,COOPCitizens,HostRoutes,10.1.10.0/2410.1.10.1/3210.1.10.2/3210.1.10.3/32,Endpointinformationisstoredonspines(COOPOracles)inthefabric.WhenaBDisenabledwithHostRoutingtheborderleaveswilldownloadhostroutesfromthespinesOnlyendpointsthatcurrentlyintheCOOPdatabaseandlocaltothepod/sitearedownloadedNon-borderleavesdonotdownloadhostroutesfromspinesEnablingHostRoutingontheBridgeDomaindoesnotautomaticallyadvertisethehostroutesoutL3outsTheBDmustbeassociatedtotheL3outoranexplicitprefixlistmatchingthehostroutesmustbeconfiguredtoadvertisehostroutesoutofthefabric(existingbehaviorforBDsubnets),HostRouteBehavior,Non-BorderLeaves,BorderLeaves,.10,.11,.12,.1,.2,10.1.10.0/24,10.1.20.0/24,BD1,BD2,AdvertiseHostRoutes:,AdvertiseHostRoutes:R,COOPOracles,COOPCitizens,HostrouteswillappearasCOOProutesontheborderleafwithanexthopofNULL,HostRoutes,10.1.10.0/2410.1.10.10/3210.1.10.11/3210.1.10.12/32,HostroutesareaddedtotheRIBontheborderleafwhichallowstheroutestobeadvertisedoutoftheL3out.TheroutesarenotaddedtotheFIBsincetheyarenotrequiredforforwarding.ForwardingtotheNBLisbasedonthelearnedendpointinformation,WAN,ContractrequirementsforinstallingBDsubnetsandhostroutes,EPG,BD,10.1.10.0/24,L3OutExtEPG,AdvertiseExternally:R,RequirementstoadvertiseBDsubnetsoutanL3outBDsubnetmustbehavethe“AdvertiseExternally”optionenabled.BDmustbeassociatedtoanL3out(option1)L3outmusthaveexplicitroute-mapconfiguredmatchingBDsubnets(option2)TheremustbeacontractbetweentheEPGinthatBDandtheExternalEPGfortheL3outIfthereisnocontractbetweentheBD/EPGandtheExternalEPGtheBDsubnetandhostroutesmaynotbeinstalledontheborderleaf,C,Note:ContractrequirementforenforcedmodeVRFs.ContractnotrequiredifEPGandExtEPGareinapreferredgroup,WAN,Host-RouteDownloadMulti-PodandMulti-SiteandRemoteLeaf,IPN,Non-BorderLeaves,BorderLeaves,Non-BorderLeaves,BorderLeaves,192.168.10.1,192.168.10.20,192.168.10.5,192.168.10.8,192.168.10.1192.168.10.20,192.168.10.5192.168.10.8,192168.10.0/24192.168.10.1192.168.10.20,192168.10.0/24192.168.10.5192.168.10.8,BLsdownloadhostrouteslocaltothepodorsiteorremoteleafpair.TheCOOPendpointinformationincludesaflagthatindicatesifanendpointisremotetothepod/site/RL.ThisflagwillpreventremoteendpointsfrombeinginstalledashostroutesHostroutesareremovedfromtheBLwhentheendpointtimesoutormovesbetweenpods/sites/RL(vmotion),192.168.10.30,RL(Pod2),192168.10.0/24192.168.10.30,Pod2,Pod1,Configuration,ThisconfigurationisappliedonaperBridgeDomainlevelEnabled“HostBasedRouting”,GUIConfiguration,CLIConfiguration,apic1#configureapic1(config)#tenantapic1(config-tenant)#bridge-domainapic1(config-tenant-bd)#advertise-host-routesapic1(config-tenant-bd)#end,AdvertisingHostRouteOptions,AssociateBDtoL3outConfigureexplicitroute-mapunderL3outmatchingBDsubnetsBothoftheseoptionsaresupportedforhostrouteadvertisement,TwooptionsareavailabletoadvertiseroutesoutanL3out,Option1:AssociateBridgeDomaintoL3out,Option1:AssociateBridgeDomaintoL3out,BridgeDomain,Subnet:14.1.1.0/24,AdvertiseExternally:R,Subnet:15.1.1.0/24,AdvertiseExternally:R,L3Out,BDassociatedtoL3out,AssociatingtheBDtoanL3outautomatestheconfigurationoftheroute-mapfortheL3out.Theroute-mapconfiguredbythesystemwillmatchallBDsubnetsdefinedundertheBDthathaveAdvertiseExternallyTheroute-mapwillalsomatchallhostrouteswhenAdvertiseHostRoutesisenabledfortheBD.ThehostroutesadvertisedoutOSPFandEIGRPL3outswillincludethetag4294967295,AdvertiseHostRoutes:R,Explicitroutemapconfigurationallowsyoutoconfigurearoute-mapdirectlyundertheL3out.Theroutemapnamemustbedefault-exportforoutboundroutesRoute-mapscontaincontexts.Acontextisaroute-mapsequenceandcanbeapermitoradenyRoute-mapscancontainupto10contexts(0-9)Contextscontainmatchandsetrules.matchrulescanmatchipprefixesorBGPcommunitiessetrulescansettags,community,etcMatchandSetrulesaredefinedunderthetenantandcanbereusedacrossL3outs,Option2:explicitRouteMapoverview,AprefixmatchrulecanmatchoneormoreprefixesPrefixescanbeanexactmatchoranaggregatematchAnaggregatematchwillmatchtheroutewiththespecifiedmasklengthandalllongermasklengths(theprefix-listincludesthele32keyword)ThematchruleprefixescanmatchexternalroutesandBDroutesincludinghostroutesForOSPFandEIGRPL3outstheroute-mapisappliedatredistributionForBGPtheroute-mapisappliedonallBGPneighborsundertheL3outintheoutbounddirection,Option2:explicitRouteMapoverview,Option2:explicitRouteMaplogicalconfiguration,L3Out,Route-mapname:default-export,context0action:permit,matchrule:BD-subnetsmatchprefix10.1.1.0/24aggregatematchprefix10.2.2.0/24,route-mapdefault-exportpermit10matchipprefix-listBD-subnetsipprefix-listBD-subnetsseq110.1.1.0/24le32seq210.2.2.0/24,Logicalconfiguration,matchrule:BDsubnets,Switchroute-map*,actualroute-map/prefixlistnameswillbeinternallygenerated,Option2:Configuration:Route-Mapdefinition,route-mapsequence,Option2:Route-Map:MatchRuleconfiguration,HomesiteadvertisesBDsubnetrouteBackupsiteadvertisesonlyhostroutes,ExplicitRouteMapUsecaseexample,192.168.0.10,.11,.12,Explicitroute-mapforL3out1matchesBDsubnetonly(noaggregate),Explicitroute-mapforL3out2hostroutes(aggregateoption),RequiresseparateL3outsperpod,RouteMapUseCaseConfigurationexample,PermitBDsubnet,DenyBDsubnet,PermitBDhosts,L3Out1,L3Out2,SharedL3Out,HostbasedroutingissupportedforsharedL3outBorderlea
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026届江西省抚州市南城县第一中学化学高二上期末达标检测模拟试题含答案
- 2026届广东省吴川一中化学高三第一学期期末教学质量检测试题含解析
- 2025年教师资格证考试(中学科目二)教育知识与能力专项强化训练试卷
- 王道课件邓平速写
- 民法典学习课件
- 玉米趣味农业科普知识培训课件
- 玉石鉴定师知识培训课件
- 2025年国家级科研实验室项目聘用人员服务协议
- 2025新型车库物业管理及设施升级改造合同
- 2025年工艺美术品定制生产合作协议
- VDA6.3-2023版培训教材课件
- 2024年香水香氛品类趋势洞察-天猫美妆
- 骨科植入物在手术中的管理
- 透析中低血压预防及处理
- 《孙子兵法》全文及译文
- 2026年日历表全年表(含农历、周数、节假日及调休-A4纸可直接打印)-
- 《经济法基础》 (第2章) 第二章 会计法律制度
- 病案管理法律法规培训
- 电力系统安全运行与故障预警机制
- 企业员工工会建设计划
- 电信行业网络优化与安全保障措施
评论
0/150
提交评论