BGP EVPN
Feature Overview
VXLAN is a network virtualization technology that allows for the virtualization of L2 networks over a physical network infrastructure by encapsulating L2 Ethernet frames within Layer 4 UDP packets. In a VXLAN, Virtual Tunnel End Points (VTEPs) can utilize BGP EVPN to exchange locally learned Layer 2 and Layer 3 destinations with remote VTEPs. This enables the learning of remote Media Access Control (MAC) addresses via the control plane. BGP EVPN also automates the creation of remote VTEPs and Virtual Network Identifiers (VNIs) for the VXLAN.
BGP EVPN provides the following benefits to a VXLAN:
- Auto-discovery of remote VTEPs and their Layer 2 EVPN membership information, eliminating the need for manual configuration of remote VTEP information.
- Distribution of locally learned MAC addresses to remote VTEPs, preventing the flooding of unknown unicast traffic.
- Distribution of locally learned MAC-IP bindings from the ARP table to remote VTEPs.
- Support for advanced features such as multi-homing, traffic load balancing, and ARP suppression.
In a VXLAN, the architecture is divided into two main components: the underlay network and the overlay network.
- Underlay Network: The underlay network is the physical infrastructure that supports the VXLAN, consisting of physical switches and routers that form a logical switching fabric. It handles the transportation of VXLAN-encapsulated traffic (Layer 4) between routers and uses IP-based routing protocols, such as OSPF or IS-IS, to ensure efficient and reliable data transport.
- Overlay Network: The overlay network runs on top of the underlay network and consists of Virtual Tunnel Endpoints (VTEPs), also known as Leafs, that encapsulate and decapsulate VXLAN packets. It provides Layer 2 and Layer 3 connectivity for tenant systems, such as customer edge devices or virtual machines, allowing them to communicate with each other.
Important Terminology for BGP EVPN
The below are common terms used in reference to BGP EVPN:
- CE: Customer Edge.
- EVPN: Ethernet Virtual Private Network. A common implementation is Ethernet over VXLAN. This is the implementation outlined in this chapter.
- MP-BGP: Multi-Protocol Border Gateway Protocol. BGP capability to carry routes for multiple, different address families.
- PE: Provider Edge.
- RR: Route Reflector for internal BGP peers.
- RT: Route Target.
- RD: Route Distinguisher.
- VNI: Virtual Network Identifier.
- VTEP: Virtual Tunnel End Point. In BGP EVPN terms, a VTEP can also be referred to as the leaf.
- VXLAN: Virtual Extensible Local Area Network.
Requirements
BGP is supported on:
Considerations
- When BGP EVPN is configured, remote MAC addresses are learned via the control plane only.
- VXLAN remote site configuration is not required when BGP EVPN is configured.
- BGP EVPN extensively uses standard and
extended BGP path attributes. The send-community option must be configured for each BGP
EVPN peer. Refer to BGP L2VPN EVPN Address Family or to the
neighbor send-communitycommand in the RUCKUS FastIron Command Reference for more information on this command. - Singlehoming and multihoming configurations are supported.
Best Practices
- To improve scalability and manageability, use Route Reflectors (RRs) to reduce the number of BGP sessions in the network.
- Enable ARP suppression to reduce ARP broadcast traffic within the VXLAN fabric. Refer to ARP Suppression for BGP EVPN Overview for more information.
- Carefully manage Broadcast, Unknown unicast, and Multicast (BUM) traffic to prevent network congestion. Use features like IGMP snooping and multicast routing to control BUM traffic.
- Secure your BGP sessions using authentication mechanisms like MD5. Additionally, implement access control lists (ACLs) to restrict BGP session establishment to trusted peers.
- Plan for scalability by considering the number of VTEPs, VNIs, and the overall size of the EVPN fabric. Ensure your hardware and software can support the expected growth.
Prerequisites
- Devices must support BGP EVPN and VXLAN protocols. For more details on BGP EVPN and VXLAN device support for RUCKUS ICX devices, refer to the RUCKUS FastIron Features and Standards Support Matrix.
- The underlay network must be already configured so that VTEPs are reachable to each other through an Interior Gateway Protocol (IGP).
- While IGP such as OSPF or RIP can be enabled for underlay routing, it is recommended to employ OSPF for optimal underlay routing.
- VLANs and VXLANs must be configured in advance.
- Define the VTEPs within the VXLAN topology.
Multiple modules in the system are involved in the implementation of BGP EVPN. These are described in subsequent sections.
EVPN Support in BGP
A new Address Family Identifier (AFI) and Subsequent Address Family Identifier (SAFI) combination of L2VPN EVPN is introduced in MP-BGP to carry EVPN routing protocol information between peers. Two BGP speakers, capable of both advertising and processing EVPN Network Layer Reachability Information (NLRI), are employed.
A VTEP advertises the IP address of a local tunnel endpoint and locally configured L2-VNIs to other VTEPs. Deletion of L2-VNI memberships is also advertised to other VTEPs. Consequently, receiving VTEPs gain knowledge about remote VTEPs and their L2 VPN memberships. Receiving VTEPs can then establish or terminate a VXLAN tunnel for the advertising VTEP, and update the ingress replication list for each L2-VNI common in both the local and remote member list.
VTEPs can learn MAC addresses of locally attached tenant systems from traffic sources such as data traffic, IEEE 802.1x, Link Layer Discovery Protocol (LLDP), or Address Resolution Protocol (ARP) generated by those tenant systems. Additionally, VTEPs learn remote MAC addresses by advertising locally learned MAC addresses to all other VTEPs in that EVPN instance.
EVPN Support in FDB
In BGP EVPN, MAC addresses are acquired from the control plane through BGP modules, deviating from the conventional data-plane MAC learning approach. MACs learned from the local access port within the BGP EVPN domain are exported to the BGP module from the Forwarding Database (FDB), enabling BGP to advertise these MACs.
These MAC addresses learned from the control plane are termed autonomous system (AS) remote-MACs and are exempted from the MAC aging process. Only the BGP control plane can add or remove remote MACs. This approach supports MAC mobility.
EVPN Manager
The BGP EVPN management system is designed to ensure the validation and processing of various message types received from peers, directing them to internal modules for local consumption.
Messages generated by internal modules undergo validation before being forwarded to BGP for peer advertisement. Configuration parameters, such as the mapping of Ethernet Tag-Id and VNI information, are received from the VXLAN manager. Tunnel IP information is also acquired and subsequently sent to BGP, which advertises it as an Integrated Routing and Bridging (IRB) Multicast Ethernet Tag (IMET) route to peers.
Additionally, the BGP EVPN management system receives MAC information from the FDB. This data is validated against the configurational database and then forwarded to BGP for peer advertisement. The management system also registers with BGP to obtain remote MAC IP information, which is validated and sent to the FDB and ARP modules. MAC IP information from the ARP module is validated and subsequently sent to BGP for peer advertisement.
