h3c和思科融合Vxlan

h3c和思科融合Vxlan

cisco N9k配置

N9k-1

vlan 11
  vn-segment 10011

interface Vlan11
  no shutdown
  ip address 11.1.1.254/24
  ip router ospf 1 area 0.0.0.0
  hsrp version 2
  hsrp 11 
    preempt 
    ip 11.1.1.252

interface nve1
  no shutdown
  source-interface loopback0
  member vni 10011
    ingress-replication protocol static
      peer-ip 2.2.2.7

interface Ethernet1/2
  no switchport
  ip address 1.1.1.1/24
  ip router ospf 1 area 0.0.0.0
  no shutdown

interface Ethernet1/1
  switchport mode access
    switch acc vlan 11

interface loopback0
  ip address 2.2.2.1/32
  ip router ospf 1 area 0.0.0.0
line console
line vty
router ospf 1
  router-id 2.2.2.1

H3C VSR2000 或者msr36-20配置Vxlan

開啓L2×××能力

[SH6800]l2*** enable 

創建VSI實例***a和Vxlan10011

[SH6800]vsi ***a 
[SH6800-vsi-***a]vxlan 10011 
[SH6800-vsi-***a-vxlan-10011]qui
[SH6800-vsi-***a]quit

配置接口loopback0 地址,作爲隧道的源端地址

[SH6800]interface LoopBack 0 
[SH6800-LoopBack0]ip add 2.2.2.7 255.255.255.255
[SH6800-LoopBack0]quit

在SH6800和N9K-1之間建立Vxlan隧道

  • 創建模式爲Vxlan的隧道接口Tunnel1
  • 指定隧道的源端地址爲本地接口loopback0的地址
  • 指定隧道目的端地址N9K-1的loopback0地址
[SH6800]interface Tunnel 1 mode vxlan 
[SH6800-Tunnel1]source 2.2.2.7 
[SH6800-Tunnel1]destination 2.2.2.1 
[SH6800-Tunnel1]quit

配置Tunnel1與Vxlan10011關聯

[SH6800]vsi ***a
[SH6800-vsi-***a]vxlan 10011
[SH6800-vsi-***a-vxlan-10011]tunnel 1
[SH6800-vsi-***a-vxlan-10011]quit
[SH6800-vsi-***a]quit

在接入服務器接口上與VSI實例***a關聯。

#當只有一個vlan通過的時候可以用這個方法。這裏只有vlan11。
[SH6800]interface GigabitEthernet 1/0
[SH6800-GigabitEthernet1/0]port link-mode route 
[SH6800-GigabitEthernet1/0]xconnect vsi ***a 
[SH6800-GigabitEthernet1/0]quit

#當有多個vlan通過Vxlan通信,就需要匹配vlan
[SH6800]interface GigabitEthernet 1/0
[SH6800-GigabitEthernet1/0]port link-mode route 
[SH6800-GigabitEthernet1/0]quit

[SH6800]interface GigabitEthernet 1/0.1 
#vid之後跟的是匹配的vlan
[SH6800-GigabitEthernet1/0.1]vlan-type dot1q vid 11 
#vsi之後跟的是相應的vsi實例
[SH6800-GigabitEthernet1/0.1]xconnect vsi ***a
[SH6800-GigabitEthernet1/0.1]quit

#例如還有一個vlan12 
[SH6800]interface GigabitEthernet 1/0.2
[SH6800-GigabitEthernet1/0.2]vlan-type dot1q vid 12
[SH6800-GigabitEthernet1/0.2]xconnect vsi ***a12
[SH6800-GigabitEthernet1/0.2]quit

#以下是6800的接口與VSI實例關聯方法
# 在接入服務器的接口HundredGigE1/0/1上創建以太網服務實例1000,該實例用來匹配VLAN 2的數據幀。
[SwitchC] interface hundredgige 1/0/1
[SwitchC-HundredGigE1/0/1] service-instance 1000
[SwitchC-HundredGigE1/0/1-srv1000] encapsulation s-vid 2
# 配置以太網服務實例1000與VSI實例***a關聯。
[SwitchC-HundredGigE1/0/1-srv1000] xconnect vsi ***a
[SwitchC-HundredGigE1/0/1-srv1000] quit
[SwitchC-HundredGigE1/0/1] quit 

H3C設備驗證VTEP設備

查看tunnel 1 接口信息

[SH6800]display interface Tunnel 1 
Tunnel1
Current state: UP
Line protocol state: UP
Description: Tunnel1 Interface
Bandwidth: 64kbps
Maximum Transmit Unit: 64000
Internet protocol processing: disabled
Output queue - Urgent queuing: Size/Length/Discards 0/100/0
Output queue - Protocol queuing: Size/Length/Discards 0/500/0
Output queue - FIFO queuing: Size/Length/Discards 0/75/0
Last clearing of counters: Never
Tunnel source 2.2.2.7, destination 2.2.2.1
Tunnel protocol/transport UDP_VXLAN/IP
Last 300 seconds input rate: 78 bytes/sec, 624 bits/sec, 0 packets/sec
Last 300 seconds output rate: 0 bytes/sec, 0 bits/sec, 0 packets/sec
Input: 1735 packets, 162159 bytes, 0 drops
Output: 440 packets, 43082 bytes, 0 drops

查看VSI信息,可以看到VSI內創建的VXLAN、與VXLAN關聯的VXLAN隧道、與VSI關聯的以太網服務實例等信息。

[SH6800]display l2*** vsi verbose 
VSI Name: ***a
  VSI Index               : 0
  VSI State               : Up
  MTU                     : 1500
  Bandwidth               : -
  Broadcast Restrain      : -
  Multicast Restrain      : -
  Unknown Unicast Restrain: -
  MAC Learning            : Enabled
  MAC Table Limit         : -
  MAC Learning rate       : -
  Drop Unknown            : -
  Flooding                : Enabled
  Statistics              : Disabled
  VXLAN ID                : 10011
  Tunnels:
    Tunnel Name          Link ID    State  Type
    Tunnel1              0x5000001  Up     Manual
  ACs:
    AC                               Link ID    State   
    GE1/0                            0          Up    

驗證主機ping

VPCS> sh ip 

NAME        : VPCS[1]
IP/MASK     : 11.1.1.3/24
GATEWAY     : 11.1.1.252
DNS         : 
MAC         : 00:50:79:66:68:0b
LPORT       : 20000
RHOST:PORT  : 127.0.0.1:30000
MTU         : 1500

VPCS> ping 11.1.1.1

84 bytes from 11.1.1.1 icmp_seq=1 ttl=64 time=52.298 ms
84 bytes from 11.1.1.1 icmp_seq=2 ttl=64 time=43.287 ms
84 bytes from 11.1.1.1 icmp_seq=3 ttl=64 time=56.294 ms
84 bytes from 11.1.1.1 icmp_seq=4 ttl=64 time=54.209 ms
84 bytes from 11.1.1.1 icmp_seq=5 ttl=64 time=44.216 ms

VPCS> ping 11.1.1.252

84 bytes from 11.1.1.252 icmp_seq=1 ttl=255 time=42.977 ms
84 bytes from 11.1.1.252 icmp_seq=2 ttl=255 time=128.824 ms
84 bytes from 11.1.1.252 icmp_seq=3 ttl=255 time=29.194 ms
84 bytes from 11.1.1.252 icmp_seq=4 ttl=255 time=39.773 ms
84 bytes from 11.1.1.252 icmp_seq=5 ttl=255 time=67.956 ms
發表評論
所有評論
還沒有人評論,想成為第一個評論的人麼? 請在上方評論欄輸入並且點擊發布.
相關文章