Configuring VXLAN
Configuring a VXLAN gateway involves the following tasks.
- Configure a VXLAN gateway record.
- Set the VXLAN gateway type as a Layer 2 extension.
- Specify the loopback interface with the IP address
that will be used as the source IP address for VXLAN tunnels.
Note: The loopback interface must not belong to a user VRF. Be sure the specified IPv4 address is configured on this interface; otherwise, all VXLAN tunnels will be down.
- Map previously created VLANs, or a range of VLANs, to VXLAN Network Identifiers (VNIs).
- Configure one or more remote site records.
- For each remote site, specify the primary IP address of the remote site VTEP and up to 15 secondary IP addresses. The primary IP address is used as the destination address for the VXLAN tunnel to that remote site. If the connection to the primary IP address fails and failure detection is enabled, the secondary IP addresses are used in the configured order based on the assigned index provided.
- Make sure the remote VTEP IP addresses are reachable in the default VRF; otherwise, the VXLAN tunnel to the remote VTEP will be down.
- Configure failure detection.
- Extend each mapped VLAN, or range of VLANs, to the remote site.
Complete the following steps to configure a VXLAN overlay gateway.
- Name the overlay gateway and enter overlay-gateway configuration mode.
- Set the overlay gateway type as a Layer 2 extension.
- Use the
loopback interfacecommand in overlay-gateway configuration mode to configure the IP interface for the overlay gateway.Note: You must use a loopback interface, rather than an explicit IPv4 address, as the source address. - Map a VLAN you intend to extend
over the VXLAN segment (that is, over the overlay gateway) to a VXLAN Network
Identifier (VNI). Note: A maximum of 256 VLAN to VNI pairs can be configured.Note: The default VLAN (typically, VLAN 1) cannot be mapped to a VNI or extended over a VXLAN segment.
- Create a remote site (VXLAN
tunnel), and configure the IP addresses for the site. Note: Only IPv4 tunnels are supported.Note: A maximum of 32 remote sites can be created.Note: A maximum of 16 IP addresses; that is, one primary address and up to 15 secondary addresses can be configured per remote site. If the primary address fails, the secondary addresses will be tried in succession, based on the index number configured for each address. If a number has already been assigned to the IP address you configure, an error message is displayed. You must remove the existing configuration before you can reuse a configured number.
- Configure failure detection for the remote site. The allowable keep-alive interval is 1 through 20 seconds. The retry count can be configured as 1 through 5.
- Extend the mapped VLAN to the remote site.
The following example configures overlay gateway gate1. VLAN 2 maps to VNI 3. A VXLAN tunnel is configured by creating a remote site (site1) and configuring its IP address (67.67.67.1) as the destination address. Redundant addresses and failure detection are configured for the remote site. The mapped VLAN (VLAN 2) is extended over the overlay gateway.
device# configure terminal device(config)# overlay-gateway gate1 device(config-overlay-gw-gate1)# type layer2-extension device(config-overlay-gw-gate1)# ip interface loopback 1 device(config-overlay-gw-gate1)# map vlan 2 to vni 3 device(config-overlay-gw-gate1)# site site1 device(config-overlay-gw-gate1-site1)# ip address 67.67.67.1 primary device(config-overlay-gw-gate1-site1)# ip address 67.67.67.2 secondary 1 device(config-overlay-gw-gate1-site1)# ip address 67.68.0.1 secondary 2 device(config-overlay-gw-gate1-site1)# failure-detection keep-alive 20 retry 5 device(config-overlay-gw-gate1-site1)# extend vlan add 2 device(config-overlay-gw-gate1-site1)# end device# show running-config overlay-gateway overlay-gateway gateway1 type layer2-extension ip interface Loopback 1 map vlan 2 vni 3 site site1 ip address 67.67.67.1 primary ip address 67.67.67.2 secondary 1 ip address 67.68.68.1 secondary 2 extend vlan add 2 device# show overlay-gateway Overlay Gateway Name : gateway1 Type : layer2-extension Source IP Interface : loopback 1 (vrf: default-vrf, IP address: 32.32.31.13) Total Mapped Vlans : 1 Total Sites : 1
The following example configures overlay gateway gate1. A range of VLANs (VLAN 200 through VLAN 300) maps to VNI 20000 and starts the VNI. A VXLAN tunnel is configured by creating a remote site (s1). The mapped VLANs (VLAN 200 through VLAN 300) are extended over the overlay gateway.
device# configure terminal
device(config)# overlay-gateway gate1
device(config-overlay-gw-gate1)# type layer2-extension
device(config-overlay-gw-gate1)# ip interface loopback 1
device(config-overlay-gw-gate1)# map vlan-range 200 to 300 vni-start 20000
device(config-overlay-gw-gate1)# site s1
device(config-overlay-gw-v1-site-s1)# extend vlan-range add 200 to 300
device# show overlay-gateway
Current configuration for overlay-gateway:
overlay-gateway v1
type layer2-extension
ip interface loopback 1
map vlan-range 200 to 300 vni-start 20000
map vlan 400 to vni 20400
site s1
extend vlan-range add 200 to 300