Configuring MACsec over VXLAN
Complete the following steps to configure MACsec over VXLAN.
- Configure MACsec for a loopback interface (p2 in MACsec over VXLAN Packet Flow, where ports p1 and p2 are part of the same VLAN).
- Configure the VXLAN tunnel with
cross-connect VNI mapping (port p3 is an untagged member of the extended VLAN).
- Configure a VXLAN gateway record.
- Set the VXLAN gateway type as a Layer 2 extension.
- Specify the loopback
interface with the IP address that will be used as the source IP address
for VXLAN tunnels.You must use a loopback interface, rather than an explicit IPv4 address, as the source address.
- Map the VLAN with an
untagged member as the loopback interface (port p3) to the cross-connect
VNI.The default VLAN (typically, VLAN 1) cannot be mapped to a VNI or extended over a VXLAN segment.
- Create a remote site (VXLAN tunnel) and configure the IP address for the site.
- Extend the mapped VLAN to the remote site.
The following example configures overlay gateway gate1 and maps VLAN 2 to cross-connect VNI 3. A VXLAN tunnel is configured by creating a remote site (site1) and configuring its IP address (67.67.67.1) as the destination address. Finally, the VLAN (VLAN 2) is extended over the overlay gateway.
device# configure terminal device(config)# overlay-gateway gate1 device(config-overlay-gw-gate1)# type layer2-extension device(config-overlay-gw-gate1)# ip interface loopback 1 device(config-overlay-gw-gate1)# map vlan 2 to vni 3 cross-connect device(config-overlay-gw-gate1)# site site1 device(config-overlay-gw-gate1-site1)# ip address 67.67.67.1 device(config-overlay-gw-gate1-site1)# extend vlan add 2 device(config-overlay-gw-gate1-site1)# end