没有合适的资源?快使用搜索试试~ 我知道了~
首页H3C-VXLAN配置-扫盲必看.pdf
H3C-VXLAN配置-扫盲必看.pdf
需积分: 44 1.7k 浏览量
更新于2023-05-29
评论 2
收藏 900KB PDF 举报
H3C-VXLAN,H3设备的基础配置,其中里面有一部分扫盲配置,并带有相关基础配置,包括vxlan运行机制、配置vxlan
资源详情
资源评论
资源推荐

i
目 录
1 VXLAN简介 ········································································································································ 1-1
1.1 VXLAN网络模型 ································································································································ 1-1
1.2 VXLAN报文封装格式 ························································································································· 1-2
1.3 VXLAN运行机制 ································································································································ 1-2
1.3.1 建立VXLAN隧道并将其与VXLAN关联 ···················································································· 1-3
1.3.2 识别报文所属的VXLAN ·········································································································· 1-3
1.3.3 学习MAC地址 ························································································································· 1-4
1.3.4 接入模式 ································································································································· 1-4
1.3.5 转发单播流量 ·························································································································· 1-5
1.3.6 转发泛洪流量 ·························································································································· 1-6
1.4 ARP泛洪抑制 ···································································································································· 1-8
1.5 协议规范 ·········································································································································· 1-10
2 配置VXLA
N ········································································································································ 2-1
2.1 VXLAN配置任务简介 ························································································································· 2-1
2.2 创建VSI和VXLAN ······························································································································ 2-1
2.3 创建VXLAN隧道 ································································································································ 2-2
2.4 关联VXLAN与VXLAN隧道 ················································································································ 2-3
2.5 管理本地和远端MAC地址 ·················································································································· 2-4
2.5.1 配置增删本地MAC地址时记录日志 ························································································· 2-4
2.5.2 添加静态远端MAC地址 ··········································································································· 2-4
2.5.3 关闭远端MAC地址自动学习功能 ···························································································· 2-5
2.6 配置VSI泛洪抑制 ······························································································································· 2-5
2.7 配置VXLAN报文的目的UDP端口号 ··································································································· 2-6
2.8 配置VXLAN报文检查功能 ················································································································· 2-6
2.9 配置ARP泛洪抑制 ····························································································································· 2-7
2.10 VXLAN显示和维护 ·························································································································· 2-7
2.11 VXLAN典型配置举例 ······················································································································· 2-8
2.11.1 VXLAN头端复制配置举例 ····································································································· 2-8
3 VXLAN
IP网关 ··································································································································· 3-1
3.1 VXLAN IP网关简介···························································································································· 3-1
3.1.1 独立的VXLAN IP网关 ············································································································· 3-1
3.1.2 集中式VXLAN IP网关 ············································································································· 3-2

ii
3.1.3 集中式VXLAN IP网关保护组 ·································································································· 3-4
3.1.4 分布式VXLAN IP网关 ············································································································· 3-5
3.2 配置限制和指导 ································································································································· 3-8
3.3 配置集中式VXLAN IP网关 ················································································································· 3-8
3.4 配置集中式VXLAN IP网关保护组 ······································································································ 3-9
3.4.1 VXLAN IP网关上的配置 ·········································································································· 3-9
3.4.2 接入层VTEP上的配置 ··········································································································· 3-10
3.5 配置分布式VXLAN IP网关 ··············································································································· 3-10
3.6 配置VSI虚接口 ································································································································ 3-11
3.7 VXLAN IP网关显示和维护 ··············································································································· 3-12
3.8 VXLAN IP网关典型配置举例 ··········································································································· 3-12
3.8.1 集中式VXLAN IP网关配置举例 ····························································································· 3-12
3.8.2 分布式VXLAN IP网关连接IPv4 网络配置举例 ······································································ 3-17
3.8.3 分布式VXLAN IP网关连接IPv6 网络配置举例 ······································································ 3-28
4 ENDP ················································································································································· 4-1
4.1 ENDP简介 ········································································································································· 4-1
4.1.1 ENDP基本运行机制 ················································································································ 4-1
4.1.2 ENDP定时探测和老化 ············································································································ 4-1
4.1.3 ENDP认证功能 ······················································································································· 4-2
4.2 配置ENDP ········································································································································· 4-2
4.3 ENDP显示和维护 ······························································································································ 4-3
4.4 ENDP典型配置举例··························································································································· 4-4
4.4.1 VXLAN邻居自动发现配置举例 ································································································ 4-4
5 VXLAN
IS-IS协议 ······························································································································· 5-1
5.1 VXLAN IS-IS协议配置任务简介 ········································································································ 5-1
5.2 为VXLAN IS-IS指定预留VXLAN ······································································································· 5-1
5.3 自动关联VXLAN与VXLAN隧道 ········································································································· 5-1
5.4 配置通过VXLAN IS-IS同步MAC地址 ································································································ 5-2
5.5 配置通过VXLAN IS-IS同步主机路由 ································································································· 5-2
5.6 开启本地主机路由信息的代理功能 ···································································································· 5-2
5.7 开启主机路由中携带的MAC地址的学习功能 ····················································································· 5-3
5.8 调整和优化VXLAN IS-IS ··················································································································· 5-3
5.8.1 配置VXLAN IS-IS Hello报文的发送 ························································································ 5-3
5.8.2 配置DED的优先级和CSNP报文发送时间间隔 ········································································ 5-4
5.8.3 配置LSP相关参数 ··················································································································· 5-4
5.8.4 配置邻接状态变化的输出开关 ································································································· 5-5

iii
5.8.5 配置VXLAN IS-IS GR ············································································································· 5-6
5.8.6 配置VXLAN IS-IS虚拟系统 ····································································································· 5-6
5.9 VXLAN IS-IS显示和维护 ··················································································································· 5-7
5.10 VXLAN IS-IS典型配置举例 ·············································································································· 5-7
6 OVSDB-V
TEP ··································································································································· 6-1
6.1 简介 ··················································································································································· 6-1
6.2 协议规范 ············································································································································ 6-1
6.3 OVSDB-VTEP配置任务简介 ············································································································· 6-1
6.4 配置准备 ············································································································································ 6-2
6.5 与控制器建立OVSDB连接 ················································································································· 6-2
6.5.1 与控制器建立主动SSL连接 ····································································································· 6-3
6.5.2 与控制器建立被动SSL连接 ····································································································· 6-3
6.5.3 与控制器建立主动TCP连接 ···································································································· 6-3
6.5.4 与控制器建立被动TCP连接 ···································································································· 6-4
6.6 开启OVSDB服务器 ···························································································································· 6-4
6.7 开启OVSDB VTEP服务 ····················································································································· 6-4
6.8 配置VXLAN隧道的全局源地址 ·········································································································· 6-4
6.9 指定用户侧的接入端口 ······················································································································ 6-5
6.10 OVSDB-VTEP典型配置举例 ··········································································································· 6-5
6.10.1 OVSDB-VTEP头端复制配置举例 ························································································· 6-5

1-1
1 VXLAN简介
VXLAN(Virtual eXtensible LAN,可扩展虚拟局域网络)是基于 IP 网络、采用“MAC in UDP”封
装形式的二层 VPN 技术。VXLAN 可以基于已有的服务提供商或企业 IP 网络,为分散的物理站点
提供二层互联,并能够为不同的租户提供业务隔离。VXLAN 主要应用于数据中心网络。
VXLAN 具有如下特点:
• 支持大量的租户:使用 24 位的标识符,最多可支持 2 的 24 次方(16777216)个 VXLAN,
使支持的租户数目大规模增加,解决了传统二层网络 VLAN 资源不足的问题。
• 易于维护:基于 IP 网络组建大二层网络,使得网络部署和维护更加容易,并且可以充分地利
用现有的 IP 网络技术,例如利用等价路由进行负载分担等;只有 IP 核心网络的边缘设备需要
进行 VXLAN 处理,网络中间设备只需根据 IP 头转发报文,降低了网络部署的难度和费用。
目前,设备只支持基于 IPv4 网络的 VXLAN 技术,不支持基于 IPv6 网络的 VXLAN 技术。
1.1 VXLAN
网络模型
VXLAN 技术将已有的三层物理网络作为 Underlay 网络,在其上构建出虚拟的二层网络,即 Overlay
网络。Overlay 网络通过封装技术、利用 Underlay 网络提供的三层转发路径,实现租户二层报文跨
越三层网络在不同站点间传递。对于租户来说,Underlay 网络是透明的,同一租户的不同站点就像
工作在一个局域网中。
图1-1 VXLAN 网络模型示意图
如 图 1-1
所示,VXLAN的典型网络模型中包括如下几部分:

1-2
• VM(Virtual Machine,虚拟机):在一台服务器上可以创建多台虚拟机,不同的虚拟机可以属
于不同的 VXLAN。属于相同 VXLAN 的虚拟机处于同一个逻辑二层网络,彼此之间二层互通;
属于不同 VXLAN 的虚拟机之间二层隔离。VXLAN 通过 VXLAN ID 来标识,VXLAN ID 又称
VNI(VXLAN Network Identifier,VXLAN 网络标识符),其长度为 24 比特。
• VTEP(VXLAN Tunnel End Point,VXLAN 隧道端点):VXLAN 的边缘设备。VXLAN 的相关
处理都在 VTEP 上进行,例如识别以太网数据帧所属的 VXLAN、基于 VXLAN 对数据帧进行
二层转发、封装/解封装报文等。VTEP 可以是一台独立的物理设备,也可以是虚拟机所在的
服务器。
• VXLAN 隧道:两个 VTEP 之间的点到点逻辑隧道。VTEP 为数据帧封装 VXLAN 头、UDP 头
和 IP 头后,通过 VXLAN 隧道将封装后的报文转发给远端 VTEP,远端 VTEP 对其进行解封
装。
• 核心设备:IP核心网络中的设备(如 图 1-1 中的P设备)。核心设备不参与VXLAN处理,仅需
要根据封装后报文的目的IP地址对报文进行三层转发。
• VSI(Virtual Switch Instance,虚拟交换实例):VTEP 上为一个 VXLAN 提供二层交换服务的
虚拟交换实例。VSI 可以看做是 VTEP 上的一台基于 VXLAN 进行二层转发的虚拟交换机,它
具有传统以太网交换机的所有功能,包括源 MAC 地址学习、MAC 地址老化、泛洪等。VSI
与 VXLAN 一一对应。
1.2 VXLAN
报文封装格式
图1-2 VXLAN 报文封装示意图
如 图 1-2
所示,VXLAN报文的封装格式为:在原始二层数据帧外添加 8 字节VXLAN头、8 字节UDP
头和 20 字节IP头。其中,UDP头的目的端口号为VXLAN UDP端口号(缺省为 4789)。VXLAN头
主要包括两部分:
• 标记位:“I”位为 1 时,表示 VXLAN 头中的 VXLAN ID 有效;为 0,表示 VXLAN ID 无效。
其他位保留未用,设置为 0。
• VXLAN ID:用来标识一个 VXLAN 网络,长度为 24 比特。
1.3 VXLAN
运行机制
VXLAN 运行机制可以概括为:
(1) 发现远端 VTEP,在 VTEP 之间建立 VXLAN 隧道,并将 VXLAN 隧道与 VXLAN 关联。
(2) 识别接收到的报文所属的 VXLAN,以便将报文的源 MAC 地址学习到 VXLAN 对应的 VSI,并
在该 VSI 内转发该报文。
原始二层数据帧外层UDP头 VXLAN头外层IP头
标记位
RRRRIRRR
保留未用
VXLAN ID
保留未用
剩余98页未读,继续阅读















安全验证
文档复制为VIP权益,开通VIP直接复制

评论0