Data Center

 View Only
last person joined: 7 hours ago 

Ask questions and share experiences about Data Center Architecture and approaches.
  • 1.  cannot ping between irb on the same subnet

    Posted 02-14-2025 12:29

    Hi,

    I have setup 2 vMX as leaves (no spine at all) and configured them with routing instance type mac-vrf. I added the interface routing with irb. But I cannot ping between the irb on the same VLAN and VNI. Is there any mis-configuration on my setup?

    vMX1:

    set interfaces irb unit 100 family inet address 192.168.100.1/24

    set routing-instances v1100 instance-type mac-vrf
    set routing-instances v1100 protocols evpn encapsulation vxlan
    set routing-instances v1100 protocols evpn default-gateway no-gateway-community
    set routing-instances v1100 protocols evpn extended-vni-list 1100
    set routing-instances v1100 protocols evpn vni-options vni 1100 vrf-target target:100:100
    set routing-instances v1100 vtep-source-interface lo0.0
    set routing-instances v1100 bridge-domains v100 vlan-id 100
    set routing-instances v1100 bridge-domains v100 routing-interface irb.100
    set routing-instances v1100 bridge-domains v100 vxlan vni 1100
    set routing-instances v1100 service-type vlan-aware
    set routing-instances v1100 route-distinguisher 10.100.100.1:1
    set routing-instances v1100 vrf-target target:65000:1
    set routing-instances v1100 vrf-target auto

    vMX2:

    set interfaces irb unit 100 family inet address 192.168.100.10/24

    set routing-instances v1100 instance-type mac-vrf
    set routing-instances v1100 protocols evpn encapsulation vxlan
    set routing-instances v1100 protocols evpn default-gateway no-gateway-community
    set routing-instances v1100 protocols evpn extended-vni-list 1100
    set routing-instances v1100 protocols evpn vni-options vni 1100 vrf-target target:100:100
    set routing-instances v1100 vtep-source-interface lo0.0
    set routing-instances v1100 bridge-domains v100 vlan-id 100
    set routing-instances v1100 bridge-domains v100 routing-interface irb.100
    set routing-instances v1100 bridge-domains v100 vxlan vni 1100
    set routing-instances v1100 service-type vlan-aware
    set routing-instances v1100 route-distinguisher 10.100.100.2:1
    set routing-instances v1100 vrf-target target:65000:1
    set routing-instances v1100 vrf-target auto

    Thank you.

    MP



    ------------------------------
    Teguh Pribadi
    ------------------------------


  • 2.  RE: cannot ping between irb on the same subnet

    Posted 04-05-2025 09:00

    I confirmed that ping works with the following config:

     
    leaf1(vQFX)
     
    set interfaces irb unit 100 family inet mtu 9000
    set interfaces irb unit 100 family inet address 192.168.100.1/24
    set interfaces lo0 unit 0 family inet address 172.31.2.3/32
     
    set routing-instances v1100 instance-type mac-vrf
    set routing-instances v1100 protocols evpn encapsulation vxlan
    set routing-instances v1100 protocols evpn default-gateway advertise
    set routing-instances v1100 protocols evpn extended-vni-list all
    set routing-instances v1100 vtep-source-interface lo0.0
    set routing-instances v1100 service-type vlan-aware
    set routing-instances v1100 route-distinguisher 10.100.100.1:1
    set routing-instances v1100 vrf-target target:65000:1
    set routing-instances v1100 vlans v100 vlan-id 100
    set routing-instances v1100 vlans v100 interface xe-0/0/3.100
    set routing-instances v1100 vlans v100 l3-interface irb.100
    set routing-instances v1100 vlans v100 vxlan vni 1100
     
     
    leaf2(vQFX)
     
     
    set interfaces irb unit 100 family inet mtu 9000
    set interfaces irb unit 100 family inet address 192.168.100.10/24
    set interfaces lo0 unit 0 family inet address 172.31.2.4/32
    set routing-instances v1100 instance-type mac-vrf
    set routing-instances v1100 protocols evpn encapsulation vxlan
    set routing-instances v1100 protocols evpn default-gateway advertise
    set routing-instances v1100 protocols evpn extended-vni-list all
    set routing-instances v1100 vtep-source-interface lo0.0
    set routing-instances v1100 service-type vlan-aware
    set routing-instances v1100 route-distinguisher 10.100.100.2:1
    set routing-instances v1100 vrf-target target:65000:1
    set routing-instances v1100 vlans v100 vlan-id 100
    set routing-instances v1100 vlans v100 interface xe-0/0/3.100
    set routing-instances v1100 vlans v100 l3-interface irb.100
    set routing-instances v1100 vlans v100 vxlan vni 1100
     
     
     
    test@LEAF1> show evpn database 
    Instance: v1100
    VLAN  DomainId  MAC address        Active source                  Timestamp        IP address
         1100       00:00:00:09:09:09  172.31.2.4                     Apr 05 10:21:46  192.168.100.9
         1100       02:05:86:a8:3c:00  172.31.2.4                     Apr 05 10:21:46  192.168.100.10
         1100       02:05:86:c6:18:00  irb.100                        Apr 05 10:21:57  192.168.100.1

    I think the most important difference is "protocols evpn default-gateway advertise".



    ------------------------------
    RYOTA KOSAKA
    ------------------------------