Overview
Join Knox Hutchinson as he prepares you to begin your journey into EVPN-VXLAN by covering the VXLAN data plane.
Recommended Experience
- Completion of JNCIA-Junos and JNCIS-ENT is required
Related Certifications
- Juniper JNCIP-ENT
Related Job Functions
- Network engineers
- Network administrators
Knox Hutchinson has been a CBT Nuggets trainer since 2018 and has received a variety of Microsoft and Cisco certifications. His areas of expertise include data analysis, data visualization, and business intelligence solutions.
Introducing VXLAN
Our first step in learning EVPN-VXLAN is to break it apart and learn VXLAN first!
Layer 2 Everywhere... and the Problem
Spanning Tree Protocol makes stretching a layer 2 broadcast domain too challenging. But sometimes we need layer 2 traffic to reach across the campus. Let’s figure out why this is an issue.
Knowledge Check
Why can we not deploy routers everywhere when we need to extend layer 2 broadcast domains?
Separating Data Plane from Control Plane
Why is it called EVPN-VXLAN anyways? Let’s take a look at how one interacts with the other.
Knowledge Check
Which of the following serves as the control plane in EVPN-VXLAN?
VXLAN's Key Terms
There’s going to be some new words and letters you need to know in order to configure VXLAN!
Knowledge Check
What is used to uniquely identify a VLAN as it leaves or arrives on a VXLAN device?
VXLAN Deployment Designs (aka the Spine-Leaf Architecture)
VXLAN comes in a couple different shapes and sizes. Let’s explore the Spine Only and Spine-Leaf architectures.
Knowledge Check
Which deployment model trunks frames all the way up to the Spines?
Deciphering the VXLAN Packet
What is actually contained in a VXLAN packet? Let’s take a closer look at how VXLAN operates.
Knowledge Check
Where is the VNI indicated?
Interacting with Control Planes
VXLAN can interact with a few different control plane options. Let’s see why EVPN may be the best option.
Knowledge Check
Which of the following is the original control plane dictated by the VXLAN RFC?
Layer 2 and Layer 3 Gateways
Tunneling frames is one thing but how is traffic still routed between subsets? Let’s check out how VXLAN approaches this.
Knowledge Check
A layer 3 gateway routes towards which type of destination?
Summarizing VXLAN Foundations
Let’s recap what we’ve learned about VXLAN!
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Introducing VXLAN
0:05Now look, I know you are excited about this stuff,
0:07because this is the stuff-- when I'm looking at the exam
0:10blueprint, I point to that and say, ooh,
0:11that one's going to be fun.
0:13EVPN VXLAN-- that's a whole lot of letters,
0:16because it's a whole lot of technology.
0:20This is an absolutely massive topic
0:23that comes up in the JNCIP certification exams.
0:26You really have to learn EVPN VXLAN on the JNCIP Enterprise,
0:31as well as the JNCIP Data Center certification exams.
0:35There's a variant of EVPN on the service provider world,
0:39but it's EVPN MPLS.
0:40And you may be thinking to yourself,
0:42wait, EVPN VXLAN versus EVPN MPLS--
0:46what's the difference here?
0:47Well, that's kind of what this set of videos
0:49is really going to be all about.
0:51What is the difference between VXLAN, EVPN, MPLS?
0:55How do they all come together to make an awesome layer 2 VPN
0:59solution?
1:00We're focusing on the variant that uses VXLAN.
1:04This is already kind of fuzzy and confusing,
1:07and that's why we're going to break this down as much
1:09as possible, because this is a really, really massive topic.
1:13So if you really want to learn how EVPN VXLAN works,
1:16we need to first talk about VXLAN itself.
1:19There's a couple reasons why I like to tackle VXLAN first.
1:23VXLAN, at the end of the day, is simpler than EVPN.
1:27VXLAN is, what it's all about, moving data from point A
1:31to point B. How it makes that decision is up to EVPN.
1:35So let's start by talking about VXLAN in this set of videos.
1:39By the end of this set of videos,
1:40you'll understand what VXLAN does, how it is decoupled,
1:44and how it works with VPN in order
1:46to actually carry data from point A to point B.
1:49Why is it used in enterprises and data centers?
1:52How are the different designs, and layouts, and implications
1:55all going to work together?
1:57And we're definitely going to have
1:58to master the key terms that you need to know in order
2:00to understand how to actually deploy a VXLAN deployment,
2:03because these are the configurations
2:05that you're going to be typing in the upcoming set of videos.
2:07That's going to cover one part, one piece of the puzzle of EVPN
2:11VXLAN.
2:12It's going to cover the VXLAN portion.
2:14Once we got that under our belt, then we're
2:16going to talk about the EVPN portion
2:18in the next set of videos.
2:20At that point, you'll understand how EVPN and VXLAN work
2:23together, and then it'll be time to actually configure it.
2:27So let's get going as we start to introduce
2:28the major topic of EVPN VXLANs.
2:31We're going to recap what's the point of VPNs?
2:33What's the point of layer 2 VPNs?
2:35And then how does EVPN VXLAN solve some of the problems
2:39that layer 2 brought to the table?
2:40I'll see you there.
Layer 2 Everywhere... and the Problem
0:00[MUSIC PLAYING]
0:05I have a feeling that if I were to take a poll in fact, that's
0:08what I would do is soon as I get done recording this video,
0:09I'm going to start a Twitter poll.
0:11If I were to take a poll, what is your most hated protocol?
0:14When I were to list a few options probably right up
0:17there at the hop is going to be spanning tree protocol and DNS.
0:21Now we're going to focus on spanning
0:23tree protocol and really the problem with layer 2.
0:26Why can't we just have layer 2 absolutely everywhere
0:30in a gigantic enterprise campus or a data center?
0:33Then we're going to start to talk about and introduce
0:35the concepts of VPN and Layer 2 VPN, just fundamentally
0:40understanding what they do and how they could start
0:43to solve the problems the spanning tree protocol brings
0:46to the table.
0:46Let's get talking.
0:47So as I like to do before we embark on any journey
0:50into a new technology, I'd like to introduce the topology
0:53that we're going to be working with first.
0:55So this is it.
0:56This is what we're going to be working
0:57with as we explore EVPN VXLAN.
1:00Now, it's a pretty basic topology.
1:03We have some Q effect switches that are deployed
1:06throughout the entire environment
1:08and these could be enterprize--
1:09laid out in an enterprise style environment
1:11or it could be in a data center environment.
1:14The actual design about why they're laid out in the way
1:17that they're laid out we actually
1:18have a dedicated video coming up to that.
1:21Then we see that we've got some hosts right here
1:23we've got some hosts in the Peach or pinkish VLAN
1:27and then we've got some hosts in all of this
1:29are greenish VLAN as VLAN 512 and VLAN 1512.
1:34So now with all this set up, it's
1:35time to transition a little bit and start
1:37thinking fundamentally about what VPNs
1:40do at the end of the day and why spanning every protocol
1:43could actually be a problem.
1:45I mean, if you think about it right now if we're
1:47running spanning tree protocol in our environment
1:49maybe with an FHRP like VRRRP, somewhere along the way,
1:55we've got the potential for a loop don't we've
1:57going into a switch here and over to a switch
1:59here then over to a switch here and then back here and then
2:01over here and then back here then over here
2:02in the back here then over here the back on there
2:04and then it goes like this.
2:05There's loops everywhere in this topology.
2:08So immediately the first thing I know just by looking at this,
2:12somewhere there's going to be an interface that's blocking.
2:16I don't know where just yet.
2:17We're just hypothetically thinking
2:19about expanding tree protocol somewhere
2:21there's an interface that's blocking somewhere
2:25and when it comes to spanning tree protocol,
2:27unless you really know what you're
2:28doing which hopefully you do at the professional level.
2:31And if you're working in a large enterprise.
2:33There's going to be an interface that gets blocked.
2:36And almost always it's never just by default
2:39the interface that you want to get blocked,
2:41maybe it's going to end up the wrong switch maybe one
2:44of these switches down here, which would be like my access
2:47layer maybe this interface right here gets blocked
2:51and this switch over here ends up being the bridge
2:56and it's an access layer just thinking hypothetically
2:59how it can all happen.
3:00So what I know in this case is that, first of all,
3:03the root bridge or maybe the root bridge for a specific VLAN
3:06whatever the case may be, it might not
3:08be the preferred one that gets selected
3:10and secondly with interfaces being blocked I now
3:14and not having the optimal load sharing
3:16and bandwidth capabilities that are
3:19available in my environment.
3:20Even if I do things like bundle my interfaces together,
3:24we're still running spanning tree protocol
3:27on these bundled interfaces and somewhere
3:29even though there's a bundle here there's
3:31still a potential for a loop because if I
3:33look if I send a frame this way in a broadcast frame
3:35this way guess what, one of these interfaces in the middle
3:38is going to end up getting blocked right or the actual log
3:40itself could end up getting blocked depending
3:42on the environment.
3:43So the thing is was fading through protocol.
3:46It's just controlled chaos and it takes a lot of optimization
3:50and then the problem with it then
3:52is when we add new switches into the mix
3:54maybe at the access layer or the distribution layer,
3:58all of a sudden spanning tree protocols reconverging again
4:01and then all of these mechanisms that we
4:03put in place like root guard and BPDU guard, now all of those
4:06have to be considered before we just
4:08dump new switches into the mix and it just
4:11becomes an administrative nightmare
4:12to keep up with all of this thing.
4:14Look spanning trick protocol does
4:16what it says it's going to do and it
4:18does it well it stops switchboard's
4:20from enabling loops.
4:22So I don't want to rag on spanning protocol
4:24too much because it really is a protection mechanism that
4:27does exactly what it was designed to do,
4:29and it's done it well for decades.
4:32The problem is now our enterprises are gigantic
4:35and if we think about now today's modern campuses
4:37like a college campus, we've got dozens or hundreds of buildings
4:42spread out all over the place.
4:43And what happened now what am I going
4:45to do trunk VLANs from one building to the next
4:47to the next building to the next one and so on and so on.
4:49Now my gosh, just a nightmare to stretch our VLANs out
4:53that long.
4:54So what ends up happening, though,
4:56is well let's think for a minute why would we
4:58still want to do that?
4:59Well, let's say this is building A on a college campus
5:03and this is building C on a college campus
5:07and building A has accounting staff and building
5:11B also has accounting staff.
5:14Well guess what, these accounting staffs
5:16need to be on the same private network
5:19so that they can access the same resources.
5:21So the only way to do this by default is to truck VLAN 512
5:26up this way and then send VLAN 512 back down this way
5:30trunked back and forth and now we're
5:32extending our VLANs throughout the entire topology all
5:36based on Layer 2.
5:37I mean we're just thinking about how broadcast domains
5:40in general work right?
5:41That's what we're trying to get to here
5:43is we need to have a broadcast domain that's allowed to move
5:46throughout the entire topology.
5:48So the issue now becomes is I can't change this and put
5:52a router right here actually don't let
5:54me use a better color for this.
5:56I can't put a router right here because at this point,
6:00if this is my Layer 3 gateway, this is where the broadcast
6:03domain stops and layer 2 wouldn't
6:05be able to make its way over to the other side
6:08because that's it that's is far a router stops
6:11a broadcast domain that's where the endpoint is.
6:14So this is the challenge that we come up with in an enterprise
6:17campus is we need to get our hosts that
6:20are on the same subnet geographically separated.
6:24I mean think about that basically
6:26our IP address at the end of the day
6:28identifies our location right?
6:30So if we're trying to be in the same location
6:33or access the same resources, typically, we
6:36had to be in the same building.
6:37But that's just not the case, especially now
6:39that we live in an era where everybody is mobile,
6:41I mean something I read statistics lately of something
6:44like 70% of all devices on a campus
6:48are wireless devices that means we're moving.
6:51So as we move through of campus, we
6:53need to maintain the same types of access wherever we go.
6:57And this is where VXLAN and really VPN in general start
7:01to solve the problem for us.
7:03For a moment let me just hang on let me do this, consider
7:06for a moment what a VPN does, I mean,
7:08if you're going for a professional level exam,
7:11it wouldn't be a stretch to think that conceptually you
7:13understand what a VPN does.
7:15You don't necessarily need to know
7:17how to deploy it just understanding
7:18fundamentally what a VPN does.
7:20I have two routers here that sit on the edge of my network.
7:24Let me make sure I'm not covering this diagram here.
7:27And these are separated geographically.
7:30Maybe this router is in New York City
7:32and this router is in New Orleans, Louisiana, which
7:35is why we say NOLA for short.
7:36So these are separated by the internet.
7:40But maybe in New Orleans, Louisiana, we have a server--
7:43am I coverage no I'm not covering it yet.
7:45There are users in New York City need to access
7:48and they need to access it securely.
7:49So we're not going to send the traffic
7:51over the public internet.
7:52So what we do is we create a VPN tunnel
7:56over the public infrastructure of the internet.
7:59Now hosts on my private network of say 10.1.1.0/24 can directly
8:05access servers and hosts on my private network,
8:08let me move my head this way 192.168.1.0/24.
8:12Now these hosts can go over this private tunnel in order
8:16to directly reach this server here,
8:18that is in essence the point of a VPN.
8:22But this all took place at Layer 3 right?
8:24We're routing packets even private packets
8:27over this tunnel because that's what these routers do.
8:30Wouldn't it be nice if this switch right here
8:33could build a tunnel to this switch right here
8:36and we could send our users frames over this tunnel
8:41down that way?
8:42Well, that's exactly what EVPN VXLAN does
8:45and that's what really the rest of these sets of videos do.
8:47This in essence is called a Layer 2 VPN
8:51whereas this down here was a Layer 3 VPN.
8:54It was all about getting routed packets over a tunnel.
8:58So that it could be routed by a router onto its next stop.
9:00In this case, this is the default gateway in the Layer 3
9:03VPN, this New York City router is the default gateway
9:06and it routes over the tunnel to the NOLA router
9:09as its next stop.
9:10The NOLA router knows how to forward packets on that way.
9:13Whereas this case in our enterprise
9:15what we're trying to talk about here
9:17is moving frames in the same broadcast domain over a Layer 3
9:22infrastructure.
9:23So we're going to be moving a frame over a tunnel instead
9:26of a switchboard in order to get from one building to the next.
9:30Now, how does that really work?
9:31Don't worry because we're just trying
9:33to understand conceptually in this video
9:35why we're using a VPN.
9:37The VPN at the end of the day is replacing
9:39all of these Layer 2 links.
9:41All of these links that you see right
9:43here this link, this link, this link, this link, this link,
9:46this link, this link, this link, this link, we're
9:48replacing all of these Layer 2 links with Layer 3 links.
9:52This will now be a routed interface maybe /31.
9:55/31 everywhere that's right /31 /31s.
9:59So now QFX5 can route its way over to QFX6 build a tunnel
10:06and then send the frames that way.
10:08So this is what we're going to be unpacking
10:09throughout the rest of these sets of videos,
10:11we're getting away from spanning tree protocol because it
10:14becomes unscalable after a certain point,
10:17it becomes too difficult to add new infrastructure in
10:20or replace infrastructure in because of the security
10:24parameters involved with the ways
10:26that we need to prevent routing and switching loops
10:29but maintain our FHRP availability so that we're not
10:32accidentally blocking our upstream ports
10:35towards our master gateway in VRRP.
10:39You get the idea here is that Layer 2 we're just
10:41trying to get away from it to a more scalable solution that's
10:44based on Layer 3, and this is what EVPN and VXLAN brings
10:48to the table.
10:49At the end of the day, it is a Layer 2 VPN
10:52so that we can get frames over a layer 3 infrastructure.
10:57Now how we're doing that, that's what
10:59we're going to talk about in next problem
11:00with stretching our Layer 2 infrastructure absolutely
11:03everywhere.
11:03And now we're going to get focused in
11:05on how VXLAN fixes it.
11:07I hope this has been informative for you,
11:08and I'd like to thank you for viewing.
Separating Data Plane from Control Plane
0:00[MUSIC PLAYING]
0:06Now, an astute observer would have
0:07noticed that what we're really trying to tackle here,
0:10is how to understand how to deploy EVPN - VXLAN
0:14and how it works.
0:15But you notice that those are separated,
0:17by a hyphen aren't they?
0:18EVPN is on one side and VXLAN is on the other side.
0:22And if you watch the intro video and paid close attention
0:25you know that, there's also a different variation that
0:27solves the same problem in the service provider world.
0:30EVPN MPLS.
0:32Wait, what's going on here?
0:33What's really happening is we are separating the control
0:37plane from the data plane.
0:38Now how does that fundamentally work?
0:40That's what this video is all about.
0:41Let's get going.
0:42Now, I feel pretty strongly about this topic
0:45right here the control plane verses the data plane.
0:48At the end of the day, we are breaking down the difference
0:51between EVPN and VXLAN.
0:54I mean that is what we're talking about here at the end
0:56of day is EVPN - VXLAN right.
0:58Think about this for a moment on Junos devices,
1:01how do Junos devices forward data?
1:04There's the data plane, which is the forwarding engine, right?
1:07The Packet Forwarding Engine.
1:09So over here, I'm going to put PFE.
1:12And how does the Packet Forwarding Engine
1:14make its forwarding decision.
1:15Well its forwarding decision is derived from the Forwarding
1:19Table.
1:19Now where is the Forwarding Table come from.
1:22Well, that comes from the Routing Engine.
1:24And the Routing Engine drives the routing table, which then
1:28creates the Forwarding Table.
1:30And how do routes get populated, in the routing table.
1:35Well it's all about whatever protocol
1:36you're using to learn routes.
1:38Basically if we were thinking about IPv6 unicast
1:40for a second.
1:41We could use something like OSPF.
1:43So the control plane, is all about how OSPF shares prefixes
1:48and determines what is the best and fastest or the shortest
1:51cost I should say--
1:52the lowest cost to reach the next top
1:54or to reach the destination.
1:56Then it says, OK, well now that we know what
1:58is the preferred destination.
2:01I'm going to tell the forwarding table, your next hop
2:04or your exit address, you're at your Egress
2:06Interface should be this.
2:08So then it hands it down to the Packet Forwarding Engine,
2:10in the Packet Forwarding Engine can receive a packet in.
2:13It can look at the destination, and it knows what
2:15interface to point it out of.
2:17And it goes that simply.
2:18Well guess, what EVPN V X, if you think about
2:22that just for a second, there's a pretty clear separation
2:25between how a decision is derived.
2:28Basically this was the brains of the operation,
2:31and the data plane was just the order taker.
2:35It knew how to just do things because the control plane has
2:39handled all of the hard thinking for us up until that point,
2:42If you see that though, you see now
2:44there's a pretty clear separation, between the control
2:47plane and the data plane on Junos devices.
2:50Now this is a Junos specific technology.
2:53This is an open standard technology.
2:55EVPN is really at the end of the day, nothing more than BGP.
2:58And VXLAN has been open standard for a pretty long time now.
3:02So what we're talking about now is,
3:04what is the brains of the operation
3:06and what is the forwarding, or the order taker
3:09in the operation.
3:10EVPN because we know this is really just
3:12BGP at the end of the day, is the control plane.
3:15And VX LAN is the data plane.
3:19The data plane all it cares about, is trying to figure out,
3:23hey, where should I send this data out-- what
3:25interface should I send out.
3:27And it's just going to refer to the control plane
3:30to figure that out.
3:31In the Junos devices, there will be a VX LAN table,
3:36that the VXLAN protocol will just consult.
3:38So what, we need to do is we need
3:40to populate that VX LAN table with a control plane,
3:44to derive the forwarding table.
3:46And this is what EVPN does.
3:47Now what you're going to find out
3:49as we get to the end of this set of videos,
3:51is EVPN isn't the only option.
3:53We actually have different options
3:55to populate this VX LAN table.
3:57We don't have to use EVPN.
3:59However, you pretty much always use EVPN.
4:03But this kind of begs the question,
4:04what is it that we're actually trying to do here.
4:08So let's talk about this more, as a packet wall
4:10kind of example, on her diet.
4:12So we know based on this diagram,
4:14that we have this host here on PLAN 5 12.
4:17And we need to ping directly this hosts here, host 13
4:22in VLAN 512, in a completely separate building.
4:25Seems straightforward so far, except that we've now
4:29completely replaced all of these links.
4:32Right here we got rid of layer 2 it's gone completely.
4:36And all of these links now, are / 3 1 routed interface.
4:41Well if this is 192.
4:431 6 8.
4:441.
4:450 / 24 here, and this is 192.
4:481 6 8.
4:491.
4:500 /24 here.
4:52But my default gateway is QGX 5 and this device's default
4:56gateway is QFX 6.
4:58How are we going to get a broadcast or a layer 2 frame
5:04from this building all the way over to this building.
5:08Well the first thing we need to do
5:09is, since these are routable we need these devices here
5:13to build a tunnel to each other.
5:16To send that frame over the tunnel to each other.
5:19Look at me, look at me for this part right here.
5:21This is what VX LAN does.
5:24This is the data plane, this is what VX LAN
5:27is bringing to the table.
5:28VXLAN is the part of the solution, that
5:31builds a tunnel from one default gateway to the next
5:35and sends a frame over that layer 3
5:38infrastructure to that tunnel.
5:39The next question becomes, well, how
5:42did Q F X 5, know to build a tunnel to Q F X 6
5:47and send the frame over to that tunnel.
5:49This is where EVPN steps into the mix.
5:52The cool thing about this, let me clear the screen here
5:54because this is so important.
5:55When host 11 sends it.
5:57When you define you to host 11 your default gateway
6:00is Q FX 5, what happens immediately
6:03when you do that host 11, then opts to find out.
6:06What the Mac Address of QFX 5 is.
6:09It needs to know what the Mac Address is,
6:10of its default gateway.
6:11So that it can get off the subnet.
6:13The moment the queue affects 5 learns the Mac Address
6:17of host 11.
6:19It then advertises that Mac Address over to QFX 6.
6:24The same thing happens over here.
6:26Host 13 opts for its default gateway.
6:29QFX 6 learns that Mac Address and sends it over Q FX 5.
6:35So now our table, our forwarding table has been populated.
6:38That says, hey, if host 11 is trying to reach host 13's Mac
6:44Address, you now know to forward that over the tunnel to QFX 6
6:49because that's where we learn the Mac Address from.
6:53And it's so cool because EVPN at the end of the day,
6:56is nothing more than BGP.
6:58And BGP can advertise literally anything at this point in time.
7:02You can advertise IPv4 unicast, IPv4 multi cast, IPv6 unicast,
7:07IPv6 multi cast.
7:08It can do flow spec firewall policies.
7:11It can do Layer 2 VPN, layer 3 VPN which is called VPNv4.
7:16Now it can do EVPN signaling.
7:18Which is what we're going to be talking about in the next set
7:21of videos.
7:21We're just trying to understand conceptually,
7:24how the control plane and the data plane
7:26come together to build this amazing solution.
7:29VXLAN to recap, is the data plane.
7:32And it is what will build the tunnel
7:34from one device to the next and send
7:36the frames over the tunnel.
7:38But it doesn't know how to do that it doesn't know where
7:41the next hop destination is.
7:43Until we learn about other Mac Addresses
7:46and their sources via EVPN, which is really BGP first.
7:51The cool thing about it is it doesn't really
7:53care, about how it learns the next hop destination.
7:57You don't have to use EVPN you can
7:59use different technologies to learn the next hop destination.
8:02And look this is a pause, this is just an aside for a second.
8:05You don't have to use VX LAN service providers, don't.
8:09Service providers use a different tunneling technology
8:12you may have heard of this thing called MPLS.
8:14So EVPN can still be used to learn Mac Addresses from all
8:18of its clients.
8:19But instead of using a VX LAN tunnel to send the frames.
8:23It just literally label switches the tunnels over these links.
8:26It's wild, it's so cool, that now
8:29with these separations of the control plane from the data
8:32plane.
8:32We have a lot of flexibility and a lot of modularity.
8:35You could use E VPN and you can use VXLAN.
8:38Or you could use multi cast in VXLAN
8:41or you could use EVPN IN MPLS.
8:44It's wild how we can do.
8:46We can accomplish the same thing.
8:47But what you find out pretty quickly
8:49is VXLAN is what is used in enterprises in data centers,
8:53because of how the design is typically laid out.
8:56We're going to talk about the design
8:57and the spinely architecture more in an upcoming video--
9:00Like two videos away from now.
9:02But now we understand that the control plane
9:04is truly separated from the data plane
9:07and they interact with each other.
9:08And this is why we're talking about VXLAN first.
9:12It's easier to understand fundamentally
9:15how data will be flowed before we
9:18start talking about how the forwarding decision is actually
9:20made.
9:21Also, just a spoiler alert: EV PN
9:23is significantly more complicated than VXLAN.
9:26So get ready for that as we start
9:27to dig into EVPN in the next set of videos.
9:29So that's been understanding why the control plane and the data
9:32plane are separated from each other
9:34and why we're tackling VXLAN first.
9:36I hope this has been informative for you
9:37and I'd like to thank you for viewing.
VXLAN's Key Terms
0:00[MUSIC PLAYING]
0:05So what does VXLAN actually do?
0:08And how does it do it?
0:09That's actually the point of this video.
0:11In order to understand the key terms,
0:14we really have to start taking a closer
0:16look about what VXLAN does.
0:18How does it actually move frames throughout an entire topology?
0:22So in this video, we're going to introduce
0:23some of the key terms, and talk about how
0:26those terms or those words or those phrases or definitions
0:29actually go together to building out a basic VXLAN solution.
0:33Let's get going-- as we start to understand more
0:35about what VXLAN does.
0:36I'll see you there!
0:37So yeah, there's no escaping having
0:39to learn new terms and definitions when it
0:42comes to something like VXLAN.
0:43But let me put your mind at ease right now.
0:45The cool thing about VXLAN terms,
0:47is there's really only two terms that you need to know.
0:50And this is where you start to see VXLAN in action.
0:55The first thing I'm going to bring up is the VTEP--
0:58the virtual tunnel endpoint.
1:00So in our diagram--
1:01actually, let's just draw it out.
1:03If we had our computer here, and it
1:06was connecting in to its router or its switch,
1:09basically it could be a layer 3 gateway.
1:12That's what we've been looking at here.
1:14Then, it goes up into the distribution tier
1:17or the collapsed core tier.
1:19So we're going to have a couple links like this.
1:22Then, we have the other endpoint that we're trying to reach.
1:26This is the other device.
1:27Let's pretend our client here is trying
1:29to reach this server over here.
1:30That's the world's worst server.
1:32And my head is on top of it.
1:33Let's fix this.
1:35Let's just get rid of NOCs entirely.
1:37There we go.
1:38There, let's just redraw the server.
1:39So now, our client here, is trying
1:42to reach this server here.
1:43But this client is in building A,
1:46and this client is in building B. We know
1:51that what we're trying to do--
1:53since this is all layer three routed infrastructure--
1:56maybe with slash 31s, or slash 30s all over the place--
2:00whatever you want to deploy--
2:02that we can't just send in a broadcast frame, can we?
2:06Because this is where the broadcast domain ends
2:08right here for our customer.
2:11In fact, I'm changing the color up right here.
2:12So that when we see blue, we're talking
2:14about the traffic itself.
2:16So the customer's going to send in a broadcast frame,
2:18trying to figure out, hey, what's your Mac
2:20address over here Mr. Server?
2:23I need to reach you, because I know your IP address.
2:25Well, that's where it ends in a layer three infrastructure,
2:28because this is the default gateway.
2:30And that's where it goes.
2:31So we know that our default gateway device here
2:35is going to try and build a tunnel
2:37to get the frame over the infrastructure.
2:40And this device right here is called a VTEP--
2:44a virtual tunnel endpoint.
2:47This is where a tunnel can start and stop.
2:49And we can have as many different tunnels as we want.
2:53This gets into the design talk that we're
2:55going to come up to next.
2:56So I'm not going to get too far into it.
2:58But the idea is that routers that
3:00could serve as an ingress or an egress for any broadcast domain
3:06is a VTEP.
3:08And I keep saying routers-- this is routers or switches.
3:10The Juniper platforms, the QFX series, the EX series,
3:14and the EMEK series, those are switches and routers.
3:17They all support VXLAN as a data plane technology.
3:21You can even run it on the VMX series or VQFX series devices--
3:26got to write that x there.
3:28Right up.
3:28There we go.
3:29The VQFX series devices in your virtual lab,
3:31which is what you're going to see me
3:33do in an upcoming set of videos.
3:35So the VTEP is the endpoint that's
3:37going to be building the tunnel from one VTEP to the next.
3:42Now, the VTEPs come in different flavors.
3:44And we're going to talk-- we're not
3:45going to overwhelm you with information about the VTEPs
3:48at this point.
3:49We now need to start talking about how the data flows
3:52from one to the other.
3:53Because this is where it gets tricky.
3:54The customer sends in a frame--
3:56or the end user sends in a frame--
3:58and it's received on this interface.
4:01This interface is configured with a standard VLAN.
4:05What do we know about VLANs?
4:06Well, VLANs are 12 bits in length,
4:09which means they could be any number from 0 through 4,096
4:13except for some VLANs are reserved.
4:16So we really only get 4,094 VLANs that we can work with.
4:21Well, let me go back to me for a second.
4:23In this day and age, they're simply not enough VLANs,
4:27especially in a data center.
4:29So one of the hugest benefits that VXLAN brings to the table,
4:33is the fact that VXLAN maps a VLAN
4:36to what they call a virtual network identifier, or a VNI.
4:41This is the second key term.
4:42We've got VTEPs and VNIs.
4:44And this is 24 bits in length, which means they can be 16--
4:49it's actually closer to 17 million,
4:52but it's 16 million unique addresses.
4:56So now, we could have kind of overlapping VLANs
4:59if we want to, and just map it to a VNI.
5:02Now, this gets a little more complicated.
5:04So we're just going to focus right now on a basic VNI
5:06example.
5:07Let me go back to the full screen here.
5:09Since we now understand that a frame will
5:11come in on this interface, right here, which we've configured
5:15with VLAN 10, and we now know that that
5:17is mapped to VNI 16,010, which tells us
5:21who our peering tunnels interfaces are--
5:25like so.
5:26It's now time for us to get this frame over to that customer.
5:30How does this work?
5:32What ends up happening is, we take the frame--
5:35like the original-- we take the original frame,
5:39and we literally just encapsulate it inside
5:42of a new IP packet.
5:44VXLAN operates in layer four using UDP.
5:49We then determine that our next hop is this VTEP over here.
5:54So the destination will be the IP address--
5:56really a loopback address--
5:58of the VTEP.
5:59We'll just call this VTEP B--
6:02and a source address of-- let's call this VTEP a.
6:06And we'll also shimmy a little header in here
6:09that identifies the VNI that this is operating on.
6:13So when we route the packet up to this device here,
6:16it's just looking at the destination IP address
6:19and making a forwarding decision to make its way down
6:21to VTEP B. When it arrives on VTEP B,
6:24it's going to arrive on the UDP port
6:27that VXLAN is listening to.
6:29So it knows, OK, well, I need to look in the VNI header
6:32to determine which VLAN this is really associated with.
6:35When it sees that there is a VNI of 16,010,
6:38it goes, oh, well, that's my VLAN 10 over here.
6:42So let me strip off all of this unnecessary .
6:45Stuff I've now got my original frame.
6:48And I know how to punt it out, because I've already
6:50learned about the Mac addresses of the server right here.
6:54This is how VXLAN works.
6:57And this is why we're introducing
6:58the key terms in this way.
7:00Really, at the end of the day, all you really
7:02need to know about VXLAN is that the two key terms are
7:06VTEPs and VNIs.
7:07But we also introduce some cool little tidbits--
7:10some benefits-- about VXLAN that you may or may not have known.
7:13It uses UDP to transport traffic and over the layer three
7:17infrastructure.
7:20It also uses a 24-bit VNI to allow
7:24us to accept even more VLANs than we were originally
7:27configured for.
7:29So if I'm cleaning up the screen just a little bit,
7:32you're thinking to yourself, well, wait a minute,
7:34how does that really work?
7:35Well, if you think about cloud providers, like AWS or Azure
7:39for a moment, think about this.
7:41You go into Azure, and you spin up a new virtual machine.
7:44You're going to be the pink client here.
7:47And you want to use the private subnet of 10.0.0.0/24.
7:52Well, guess what?
7:53So does this customer over here--
7:5510.0.0.0/24.
7:57And maybe you even want to use the same VLAN.
7:59I mean, this may not be the best example ever,
8:01because you don't really have a lot of control over VLANs
8:03on a data center, or in a cloud data center.
8:06But this is the gist of it.
8:07On these interfaces here, you can create a virtual switch,
8:16which is like a VRF.
8:18And the same thing goes over here.
8:20We can create a virtual switch, which is like a VRF.
8:27So if I want to use this subnet and call this VLAN
8:3110 in the pink, and we call this one VLAN 10 in the yellow,
8:36well, guess what?
8:36We have an overlapping VLAN and an overlapping subnet.
8:40And the real mess here is that we absolutely positively
8:44do not want our core to have to keep up with any of this.
8:49We just want a packet to come in,
8:51and we want it to get routed out.
8:52We don't want to have multiple routing tables
8:55and multiple switching tables for every single client that
8:58exists in the infrastructure on every single networking device.
9:01So the cool thing is, is now we can just assign this a VNI--
9:05of make something up, like 16,011--
9:08and the pink can get a VNI of something like 16,010.
9:12And now, our core devices can forward them
9:14the same way that they've always forwarded them from one
9:17destination to the next.
9:18And as long as the remote VTEP also
9:21supports 16,010 in addition to VNI of 16,011, boom.
9:27Guess what?
9:28We've now found a way to have overlapping
9:32VLANs and overlapping subnets.
9:35So this is the real benefit that VXLAN brings to the table,
9:39and this is why you see it in data centers, especially
9:43public cloud or private cloud data centers
9:46in today's environments.
9:47That way, the end users--
9:48the customers who are renting the data center compute
9:51or the data center network--
9:53they now have the flexibility and control
9:55over what subnets and VLANs they actually
9:58use in their infrastructure.
9:59So this has been the VXLAN key terms.
10:01I hope this has been informative for you,
10:03and I'd like to thank you for viewing.
VXLAN Deployment Designs (aka the Spine-Leaf Architecture)
0:06VXLAN is interesting, because it's almost always deployed
0:09the same way, whether it's deployed
0:11in an enterprise or a data center environment.
0:13What we're really starting to introduce now
0:16is the spine-leaf architecture, which you find out
0:19pretty quickly, in the enterprise terms,
0:21this looks almost identical to a collapsed core architecture.
0:24But now how does the traffic actually flow?
0:27How does the traffic enter the fabric?
0:28And how does it leave the fabric?
0:30What even is a fabric?
0:31That's what we're talking about in this video.
0:33Let's get going talking about how a spine-leaf architecture,
0:36and therefore VXLAN enterprise environments,
0:38would be laid out.
0:39I'll see you there.
0:40This is honestly the fun part, because this
0:42is where the rubber starts to meet the road.
0:44Oh, I forgot to put switch ports on these.
0:46So this is where you actually get
0:48to start seeing how VXLAN would actually get implemented
0:51in a real world topology, and why I laid my topology out
0:55in that lab environment in the way that I did.
0:57You notice I didn't draw the cabling here yet,
0:59because this is actually an important thing to how
1:02VXLAN works.
1:03And it depends on the style of VXLAN
1:06that you want to implement.
1:07Let me get rid of Knox for a second
1:09so we can focus on the screen.
1:11When we talk about VXLAN, you see
1:13I've written spine-leaf architecture on the screen.
1:15Doesn't it look an awful lot like collapsed core?
1:19Yeah, it kind of does.
1:20In collapsed core, when we're talking about
1:22we just moved the core down to our distribution layer.
1:25But an interesting thing is how the redundant connections
1:29take place in spine-leaf architecture.
1:31It looks like this.
1:32Our leaves are down here on the bottom tier.
1:36So I'll call this LEAF1, LEAF2, and LEAF3.
1:41And our spines are up here.
1:44So I'll call this SPINE1 and SPINE2.
1:48So our leaves connect to spines, like so.
1:51But leaves never connect to other leaves,
1:54and spines never connect to other spines.
1:57Whoa.
1:58This just kind of blew my mind a little bit.
2:00[INAUDIBLE]
2:01Alexa, stop.
2:04Sorry, Alexa interrupted me there for a second.
2:06So this is how it's going to look.
2:09And one of the cool things about this--
2:11if I now start to draw hosts and servers in the mix here,
2:16one of the cool things about this is now to get anywhere
2:20at all in the data center--
2:22if I write this in a different color,
2:23I am one hop, two hops away.
2:27The response traffic is one hop and two hops away.
2:31If there's a host over here, and they're
2:33trying to reach this blue server over here,
2:36they're one hop here and one hop here away.
2:40That's right.
2:40The cool thing about this spine-leaf architecture
2:43is, no matter what, everything is laid out
2:46as either a spine or a leaf.
2:48Therefore, we can get to anywhere with two hops away.
2:54So you may be thinking to yourself, well, wait a minute.
2:59What happens if I run out of switch ports on the leaves?
3:02Well, guess what you can do?
3:04You could just add more leaves, and just
3:06draw them up like so, just to connect them into your spines.
3:09And you're like, well, wait a minute.
3:10What if I run out of switch ports on my spines?
3:12Well, just addd more spines, just like that.
3:16And then you start even getting into aggregation
3:18or high availability configurations,
3:21where you can actually do virtual chassis,
3:23and bundle these spines together, or the same thing
3:26with the leaves.
3:27So that way, you've got these massive chassis
3:29that have hundreds upon hundreds of switch
3:31ports available to you.
3:33And now you can just keep just adding
3:34more, and more, and more, and more, and more, all you want.
3:37And everything still remains two hops away.
3:39Look, I haven't even been using this space.
3:41I could do it like this, right?
3:44Look, it kind of throws you off when you
3:46see a leaf tier added up here.
3:48But look, I'm still only two hops away
3:50from every destination in the data center.
3:53That's wild, right?
3:54Well, that's the cool thing about
3:55the spine-leaf architecture, is how scalable it is.
4:00If we just need to add more leaves,
4:01we just add more leaves.
4:02If we need to add more spines, we just add more spines.
4:05And everything still remains only two hops away.
4:09But in the typical deployment-- here,
4:11let me clean up the screen, because I just
4:12drew a whole lot there.
4:13Let me just get rid of a lot of this mess here for a second.
4:16I'll put these links back, like so.
4:19The thing about this is how the actual traffic typically
4:23flows in a data center.
4:24Typically, what we do is we configure
4:27each one of these leaves to be the VTEP--
4:31oh, got to write better, VTEP.
4:32But the spines also know about VXLAN
4:36and can also help serving with VTEP technologies.
4:39And why?
4:39We're going to get to that in an upcoming video.
4:41That gets its own dedicated thing.
4:43The interesting thing about this is
4:45our spines are really only focused on switching.
4:50They just want to get traffic in and out as much as possible.
4:54They don't necessarily focus on the forwarding table.
4:57And we want a tunnel to exist, like so,
5:01and another tunnel to exist, like so.
5:04Kind of a full mesh of VTEPs, so to speak.
5:07So when a frame comes in on this VTEP, LEAF1,
5:11it's going to have to consult its forwarding table
5:14and look at the destination MAC address,
5:16and determine, oh, that needs to go over here to LEAF3.
5:20So let me encapsulate it in a packet
5:22so that my spine layer can get rid of it
5:24as quickly as possible.
5:26The interesting thing about this design
5:28is the brains of the operation really belongs
5:31on the leaf tier, which you kind of associate with the access
5:34tier typically, don't you?
5:36It's true.
5:37That's kind of how we want a spine-leaf architecture
5:40to typically be deployed, like so.
5:42So in this case, our core devices or our distribution
5:45tier--
5:45really, our spine tier,--
5:47is just moving.
5:48It's just moving data.
5:49It's just moving data as quickly as it can,
5:50without actually having to focus on, well,
5:52what tunnel does that belong in? and how does it--
5:54does it need to go to that VTEP? and which
5:56VNI-- nope, it's just, what's the destination IP?
5:58I'm punting it in that direction.
6:00That's the idea with the spine-leaf architecture,
6:02is we move the brains down to these leaves.
6:05We move the brains down to these leaves
6:07in such a way that-- pretend for a moment
6:10that we are a large campus, and this whole design right here
6:14is our enterprise, is our data center.
6:16And the rest of the enterprise, like the campus,
6:19connects in through our leaves.
6:22Yeah, that's right.
6:23Where people are roaming around connecting to Wi-Fi,
6:26and doing all of those things, yeah, they're
6:28connecting into our leaves.
6:30And maybe we have our network services,
6:32like our DHCP, and our NTP, or DNS-- maybe that's on a leaf
6:38up here.
6:39So our network services can still
6:41get out of the data center by being
6:43switched through two hops only.
6:45They know that, OK, well, if I need to get out,
6:47I need to get to this VTEP right here who can send me out
6:50to the rest of the campus.
6:52So in this architecture, this design
6:54is actually called the spine-leaf architecture.
6:57There is an alternative design--
6:59one that you will actually cover first when it comes time
7:02to configure VXLAN--
7:04and that is a spine-only architecture.
7:07Here, let me draw the switches back and clean up the screen
7:09just a little bit.
7:10In a spine-only architecture, what's going on here is
7:14these devices, our leaves, are literally
7:17just trunking their data up to our spine layer.
7:21And the spine layer serves as a VTEP.
7:24In this situation, we actually do link our two spines
7:28together.
7:28This is the exception to the rule in the spine leaf
7:31architecture, is here, when we want our spines to be
7:35the VTEPs and only the VTEPs, then in this case,
7:39we link these two together, and they will share MAC addresses
7:42back and forth.
7:43Now what's the reason for this?
7:44This Is when we start to get into the difference
7:46between a layer 2 gateway and a layer 3 gateway.
7:49And that's why we have a dedicated video coming up,
7:51and we'll talk about why the spine-only architecture may
7:55work in that particular scenario.
7:57Know right now that the most common deployment
7:59is the spine-leaf design, where these leaves are
8:03the VTEPs that are doing the brains of the operation.
8:05They're the ones who are building the tunnels
8:07in between each other and then sending the data throughout two
8:10hops away only.
8:12So this has been understanding the design
8:14of the spine-leaf architecture, and how VTEPs and VNIs
8:17will now all of a sudden start to work when we actually
8:19deploy it this way.
8:20I hope this has been informative for you,
8:22and I'd like to thank you for viewing.
Deciphering the VXLAN Packet
0:06So now comes the part where, honestly, when I was first
0:08studying networking, when I was getting into it,
0:10this is the part that I used to dread, when I actually
0:13had to look at what a packet contained,
0:15what was in the header.
0:16What we're going to do in this video
0:18is we're actually going to take a closer look at what
0:20happens actually with VXLAN.
0:22Let's actually look at what one of the packets looks like.
0:24Let's inspect it.
0:25And trust me, the more you get into
0:27these advanced technologies, the more
0:30that this information will benefit you.
0:32This is where you start to truly master what a protocol does
0:36and how traffic is supposed to flow throughout the topology.
0:40So let's take a closer look at a VXLAN packet.
0:42So sometimes, it helps to actually see it in action.
0:45So let's talk about how a frame could
0:48go from my customer piece of equipment here,
0:51their computer, destined remotely to this server
0:54over here.
0:55Of course, we see that they're separated by a layer 3 domain.
0:59There are /31s everywhere.
1:01So how does this work?
1:03So at this point, what we're going
1:04to do is we're going to say that this computer right
1:06here and this server right here, their default gateways
1:09are these switches.
1:11And more so, these are VTEPs.
1:14So we're going to say that this is VLAN 10, for simplicity's
1:18sake over here.
1:19VLAN 10.
1:19Write a better V. There we go, VLAN 10.
1:22And we're trying to get VLAN 10 traffic
1:24to come in on one of these interfaces
1:27and go out one of these interfaces
1:29and reverse the same scenario.
1:31We got to have return traffic coming back, too.
1:33So we enable VXLAN, and we're going
1:36to use EVPN as our control plane.
1:40So when we turn on EVPN, and we configure that this computer,
1:44its default gateway is going to be this VTEP.
1:46Let's call this leaf-1 and let's call this leaf-2.
1:49When our computer right here sees that its default gateway
1:53is leaf-1 for VLAN 10, it's going
1:55to ARP to find out its default gateway's MAC address, right?
1:59That's what it's going to do.
2:00And upon receiving that MAC address,
2:03leaf-1 is going to learn-- it's going to behave just
2:05like a switch has always done.
2:07When a new MAC address comes in on an interface,
2:09we're going to inspect that source MAC address,
2:12and install it into our Ethernet switching table,
2:14just like we've always done.
2:16But this also triggers EVPN to do what EVPN does.
2:20We've now learned about a MAC address on a specific VLAN.
2:24We need to let the other devices know what that MAC address is.
2:28The interesting thing is we've got
2:29the exact same configuration and thing taking place over here.
2:32When our server ARPs for its default gateway, leaf-2,
2:37leaf-2 is going to learn about that MAC address
2:39and advertise it back over to leaf-1.
2:42So now comes the time for our customer to ping the server.
2:45Let's skip a step.
2:46I know that the first ping, we're
2:49going to ARP for the MAC address of these server.
2:51Let's take BUM traffic out of the mix right now.
2:54We don't need to worry about Broadcast, Unknown Unicast,
2:56or Multicast address.
2:57Let's just pretend that since these leaves now
3:00know each other's remote MAC addresses, as well
3:03as their local MAC addresses, now
3:05let's say our customer goes to reach the server.
3:08And it sees, OK, well, this is on my local subnet,
3:11because my original packet is going
3:13to be sourced from 10.0.0.5.
3:17Write the source IP a little bit more like this.
3:20And it's going to be destined for 10.0.0.10.
3:24So since we know that we're on the same subnet,
3:26we're going to build a frame.
3:29So the computer builds a frame with a source MAC
3:32of, let's just write, A:A:A for simplicity's sake.
3:35And a destination MAC of B:B:B. And it's time to just send it
3:41up our switch port the way we've always done for VLAN 10.
3:44The frame arrives on the switch port, and leaf-1 goes, hold up.
3:48This is destined for B:B:B, and my switching table tells me
3:54that this is actually destined for the remote VTEP of leaf-2.
3:59And because I learned that remote MAC address over EVPN,
4:03I know that this is associated with a VNI.
4:07Maybe that VNI is something like 16010.
4:10Let's just reuse the same one.
4:12So what we're going to do is we're
4:13going to take this original frame right here,
4:16and we're going to encapsulate it inside
4:18of our own VXLAN packet.
4:20So we're going to have some layer 4 info.
4:22We know that this is going to be destined to a remote UDP port.
4:25The destination IP address is going to be leaf-2's loopback.
4:31Here, let me clean up this space right here,
4:33since we know the MAC addresses at this point.
4:35The source IP address is going to be leaf-1's loopback.
4:39We're going to shimmy in our VNI info.
4:42And then we're going to send this through the data--
4:45we're going to send this through the architecture,
4:47through the fabric, like we've always done.
4:50So the next hop for this destination IP address
4:52will be our next hop, which may be this spine switch here
4:56or this spine switch here.
4:58So we set the destination MAC address now
5:00to be whatever the spine is, and the source
5:02MAC will be our MAC address.
5:04So the packet gets routed over to a spine, which then routes
5:08it down towards this VTEP.
5:12We're going to receive this info, this data,
5:14on our UDP port that VXLAN listens to.
5:17So that triggers us to take a look
5:19at the VNI that says 16010.
5:22And we now know that this belongs--
5:2416010, the VNI, maps directly to this VLAN
5:28that this server is on.
5:30So at that point, that VTEP removes
5:33all of the outer information and is
5:36left with the original frame, which it can then
5:39send outbound, like so.
5:40At the end of the day, it's not that complicated.
5:44It's really just taking a frame and encapsulating a packet.
5:47Then the packet gets routed the way it always
5:50does until it reaches its final destination, which
5:52then de-encapsulates-- just strips off that outer packet,
5:56and now we're left with the inner packet
5:58or the original frame that we can send out
6:01to the original broadcast domain that it was destined to reach.
6:04So this is the packet walk.
6:05This is understanding how data is
6:07going to flow throughout a VXLAN topology
6:10when we're using the spine architecture.
6:12I hope this has been informative for you,
6:13and I'd like to thank you for viewing.
Interacting with Control Planes
0:05So we know that this entire set of videos, the ones that we're
0:08about to go through, are called EVPN VXLAN,
0:11and I've hinted at it a little bit up till this point,
0:13that the control plane in an EVPN VXLAN is EVPN.
0:18And really under the hood, that's just BGP.
0:21But that begs the question, is EV--
0:24since EVPN and VXLAN are truly decoupled from each other--
0:27VXLAN is just depending on a control plane--
0:30does EVPN have to be the control plane for VXLAN?
0:34No, it doesn't.
0:35There are other options that you can use.
0:37In fact, the original RFC doesn't specify
0:40anything about EVPN at all.
0:42What does it specify?
0:43PIM.
0:44It specifies multicast.
0:45Now, when we dig into some of these other options,
0:47you'll find out pretty quick, EVPN is definitely
0:50the way to go, albeit, it is very complicated,
0:53and that's why it gets its own set of videos.
0:55So let's going talking about the other control
0:56plane options that are available to you when you deploy VXLAN.
1:00So there's no getting away from talking about the control plane
1:03options with VXLAN, even though we
1:05know we're pretty much going to stick to EVPN.
1:08But let's take a moment to just recap some of our options
1:11when it comes to choosing how VXLAN will be smart enough
1:15to determine what the next hop is,
1:17where it can find MAC addresses that
1:19live off of remote devices separated by a Layer 3 domain.
1:24We already know the benefits, but now we're
1:26talking about the hows.
1:27So our first up, yeah, we're going to talk about EVPN.
1:30Here's the real thing that you may not
1:32have realized about BGP.
1:34BGP can share really all sorts of information.
1:38It can share, of course, routes and prefixes
1:40at the IP level at Layer 3.
1:43But it can also share other information.
1:45It can carry basically any info.
1:47It can carry info for multicast.
1:49It can carry info for OSPF.
1:51It can carry info for EIGRP, even though this
1:54is a Juniper course.
1:55It can carry firewall policies.
1:57That's what BGP flowspec is.
1:59And in this case, BGP can actually
2:01advertise MAC address info and some interesting ways
2:05that I'm just going to say this on a high level.
2:07It can advertise the topology design.
2:11That way you can actually help and prevent
2:13things like route loops or switch loops
2:15when we have an environment like this.
2:17I mean if there were no spanning tree in this environment, look,
2:20we could go here, here, here, here, here, here, here, here,
2:23here, here, here, here.
2:25See how there's a switch loop that's possible here?
2:27And this is all one direction.
2:29If a broadcast starts heading in this direction,
2:31it would switch around-- it would loop around,
2:33just like we just did.
2:34But if a broadcast started in the opposite direction,
2:37it could go like this.
2:38And if two broadcasts started on either side,
2:40you can [INAUDIBLE] in a whole bunch.
2:42It could-- we could have two loops going
2:43in two different directions.
2:45And the cool thing about EVPN is even though these are all Layer
2:493 links, it's still going to behave a lot like a Layer 2
2:53topology.
2:54The core, as far as our customer's
2:56going to see it, as far as these devices down here
2:59and the server that lives over here,
3:01as far as they're going to see it,
3:03they're just going to see this is one gigantic switch.
3:06That's how they're going to see all of these core networks
3:08that they're communicating to.
3:10So when it's just one gigantic switch
3:11and it kind of behaves like one gigantic switch,
3:14the whole idea, now BGP can actually
3:17carry attributes and advertisements
3:20that help to prevent routing loops, which is so fascinating.
3:23But the other thing to keep in mind about EVPN
3:25was what I just said, is it behaves like a Layer 2 switch.
3:29As frames come inbound on this particular device,
3:33this device is going to learn the source MAC address
3:36and build a MAC forwarding table.
3:39Then it forwards that info to the rest of the devices
3:41in the topology.
3:43So the MAC address and the bridge ID learning behavior
3:47is exactly the same, which I think
3:48is so, so cool, even though that this is all routers.
3:52This is all Layer 3 topology.
3:53Now, of course, in data centers and enterprises,
3:55it's going to be switches.
3:56But when you get into the service provider world
3:58these are MX Series routers.
3:59At the end of the day, VXLAN is VXLAN,
4:02irregardless of which platform you're working on.
4:05So you need to know that first of all, EVPN
4:07is going to be the preferred way that gets deployed here.
4:09And really at the end of the day is, the question becomes, why?
4:12And it's because BGP is so scalable and so flexible.
4:17With BGP, we can use things like route reflectors.
4:21That way, when we learn a MAC address,
4:23we can send it to a route reflector who then bounces it
4:26to all of the other VTEPs in our entire environment.
4:29And we can carry additional attributes.
4:32One of the other cool things that comes up in EVPN,
4:34especially in the service provider world,
4:36is you not only can run a Layer 2
4:38VPN like this on this infrastructure,
4:41you can also run a Layer 3 VPN at the same time using
4:45the same protocols in infrastructure.
4:47This makes it super, super scalable,
4:49because if we add a switch into the mix up here,
4:54a new leaf off of this joint, but it doesn't have
4:57the capabilities of running VXLAN,
4:59we can still send it /32 addresses using Layer 3 VPN.
5:04So when we learn about our locally connected device's MAC
5:08address, at the same time, we also ARP for it
5:11and learn about their IP address too.
5:13And if we run a Layer 3 VPN alongside our Layer 2 VPN with
5:18VXLAN, we can actually share the /32 learn prefixes throughout
5:22the entire Layer 3 VPN so that each one of our leaves,
5:26even if they don't use VXLAN, they still know exactly which
5:30VTEP they need to get to in order to send the traffic
5:32outbound.
5:33So VXLAN, because it's using BGP,
5:35can really do everything whenever we couple it
5:38with an EVPN control plane.
5:40So that's the first type of one that you should know about.
5:43And that's really--
5:43I don't know many VXLAN environments
5:46that don't run EVPN now.
5:48But the thing is, is it wasn't originally--
5:50VXLAN wasn't originally designed to use EVPN.
5:55No, it was designed to use-- uh-oh, got rid
5:57of one of my links.
5:58It was designed to use PIM, and it didn't really
6:01need a massive control plane in order to do that.
6:04So when we learned about our customer device
6:08and we learned their MAC address, what we ended up doing
6:11is we used PIM to send a multicast packet out
6:15into the environment that's specifically consumed by VXLAN.
6:19And as long as all of these VTEPs
6:20were participating in the same PIM tree,
6:23then they would receive the same multicast advertisement
6:26of a new MAC address.
6:28And this is how the RFC originally defined it to be.
6:31However, this is not as scalable,
6:33because it now has to use multicast in order
6:35to reach all of the potential destinations
6:38in a spine-leaf environment.
6:39And with the spine leaf topology,
6:41it's pretty much going to go everywhere,
6:43because that's how a data center's going to work anyway.
6:45BGP at least gives us the option to use
6:47things like route reflectors, or even some advanced BGP
6:51properties, like inspecting the advertisements and who
6:54would be interested in receiving an advertisement by inspecting
6:56things like the VRF targets.
6:58That's that target inspection, which is so, so cool.
7:01Now of course, there's one other option
7:03that you should know about, and I don't know
7:05why anybody would ever use it.
7:06But this is an actual static mapping.
7:08This is where we explicitly say, if you receive a frame that
7:11has a destination MAC address that looks like this,
7:14then you must send it over to this VTEP
7:17using this specific VNI.
7:19This is where you have to manually configure
7:21every single MAC address to every single VNI
7:23to every single VTEP.
7:25And the big problem with this is not so much
7:27that it's the manual configuration,
7:29it's the fact that we lose mobility.
7:31This is another huge perk to VXLAN that we haven't talked
7:34about up till this point.
7:36Whenever we have-- well, let's just start and let's redraw it.
7:38Whenever we have this computer here--
7:41let's say this is host A, and let's say
7:42host A is actually a laptop.
7:44If I were to be sitting at host A and I unplug the computer
7:48and I migrate my way all the way over to a new building
7:52and I sit down and I plug into the wall, well, guess what?
7:54I just plugged into this computer.
7:56What's going on here?
7:57When we use something like EVPN--
7:59oh, I'm writing on top of writing here.
8:01When we use something like EVPN, BGP will automatically
8:05handle the advertising of the MAC address from a new host,
8:09and the previously known host will also
8:11send out a withdrawal message.
8:13Now, this is getting into the EVPN behaviors,
8:15and that's what we're going to talk about a lot more
8:17in the next set of videos.
8:18But right now, I'm just highlighting the benefits
8:21of using a protocol like EVPN as opposed to manually setting
8:24these configurations, which now when we do things like static,
8:27we lose the ability to have MAC mobility, meaning MAC addresses
8:31are mobile throughout the topology,
8:33and we don't have to worry about updating tables,
8:35because they'll just discover it and repopulate new tables all
8:38the time.
8:39If you think about this in the concept of a data center,
8:42one of the biggest things about a data center
8:44is a virtual machine that lives on a server
8:46and is tied to a specific VLAN can migrate throughout the data
8:50center all day long.
8:52It's the idea of a data center is to evenly distribute
8:56our load by migrating VM.
8:57But when we do that, we're going to be
8:59moving those MAC addresses at the same time.
9:01And thanks to EVPN, we can now advertise
9:05whenever the MAC address moves, and that way, all of my devices
9:08maintain connectivity that way.
9:10So these are your control plane options when it comes to VXLAN.
9:12Clearly, EVPN is the winner, but you
9:15should know that PIM has been used, and was used,
9:18and [INAUDIBLE] RFC as a perfectly reasonable option
9:21for you whenever you want to deploy PIM as your control
9:23plane for VXLAN.
9:25That being said, we're highly focused on EVPN VXLAN,
9:28because this was the most modern deployment, the most scalable,
9:31and the most stable.
9:32So that's been understanding your VXLAN control plane
9:34options.
9:35I hope this has been informative for you,
9:36and I'd like to thank you for viewing.
Layer 2 and Layer 3 Gateways
0:05When you deploy your VTEPs in a VXLAN environment,
0:08you kind of have an option.
0:10They're either going to be a layer 2 gateway,
0:13or they can be a layer 2 and layer 3 gateway.
0:17What is this all about?
0:18This basically works the exact same way that
0:20routing used to work before.
0:21But now our layer 3 gateway, serving as a default gateway
0:24to any of our hosts, can act basically as a router.
0:27However, the interesting thing about it
0:29is it can route traffic outside of the network,
0:31or outside of the fabric, or it can route traffic
0:35within the fabric itself.
0:36Another way to put it is we can route
0:38traffic that goes from one VNI to a separate VNI.
0:42Let's get going taking a closer look about how this really
0:44works with layer 2 and layer 3 gateways.
0:47I'll see you there.
0:48I love, love, love, this topic, because you're oftentimes
0:51so focused on VXLAN that you forget about the basics.
0:55Think about it.
0:56Up until this point, we've talked a lot about how a frame
0:59coming from this device-- let me clear my head--
1:01from this device here can make its way over this layer 3
1:05"backbrone"--
1:06backbone, I should say.
1:07Excuse me-- over to this server, and they
1:09can have direct communication.
1:10It was all about building that tunnel between our VTEPs,
1:14and then how each EVPN can exchange MAC address prefixes.
1:18But here's the kicker.
1:19We know that this is all made really possible
1:21because this host here sees this router as its default gateway.
1:26And this server here sees this router as its default gateway.
1:29And they want to communicate directly.
1:31When that computer wants to communicate directly
1:33to the server, these routers will look at the frame
1:37as it comes inbound, and then make a forwarding decision, oh,
1:40that this needs to go over the VTEP tunnel.
1:42Well, that's great and all.
1:44But what happens when this computer, say, pings 8.8.8.8?
1:49Well, hang on a second, that's a different scenario.
1:53This device down here is still behaving
1:56like this router down here is a default
1:58gateway at the end of the day.
2:00And this is where it gets kind of interesting.
2:02These devices have a switched virtual interface,
2:05kind of like you always see on switches, where you configure
2:08a VLAN, then you configure an IP address on that VLAN
2:11so that the switch can service that particular VLAN.
2:15And specifically in Juniper devices,
2:17this is the internal routing and bridging interface.
2:21And then, of course, you have subunits,
2:22like 0, 512, whatever you want.
2:25And then you can configure it to have IP addresses, like so.
2:28The interesting thing about this is
2:31this is still operating in the context of VXLAN.
2:34We're still making forwarding decisions of VXLAN.
2:37So the next question becomes, well,
2:40is this frame destined to a different VNI,
2:45or is it destined to kind of a default route?
2:48In the case of 8.8.8.8, we know that this
2:51is going to be destined to a default route.
2:53So we need to get it off of our fabric,
2:56out of our VXLAN fabric, and over towards something
2:59like a firewall that's probably going
3:01to perform NAT or at least inspect the traffic before it
3:04goes outbound.
3:05So up here, we may have a VTEP that's
3:08connected towards a firewall out towards the internet.
3:12So we may still encapsulate this frame
3:14and send it over towards the next hop, which
3:17is going to be this VTEP, who de-encapsulates it, and then
3:20decides, ah, I need to forward this on towards the internet,
3:24like so.
3:25Or I think the more interesting use
3:26case is when we actually want to communicate to a different VNI.
3:31For instance, maybe we have a server over here.
3:34Very often, you may see something like a DNS server
3:37that's not on the same subnet as our clients, right?
3:40So if the host is trying to perform a DNS lookup,
3:43it will have its source IP address and a destination
3:46IP of the DNS server.
3:49And of course, the source MAC will be its MAC,
3:51and the destination MAC will be the MAC address of the IRB
3:56interface.
3:57So when this switch or router receives the frame on its IRB
4:01interface, and it sees, oh, I need
4:03to get this over to a DNS server--
4:06make up something like 10.1.1.99.
4:09I don't know.
4:10It now knows that this is going to be
4:12destined towards a different subnet or a different VLAN.
4:16Therefore, we need to look up a new VNI that this
4:19needs to communicate in.
4:20So it takes the original frame, but changes the VNI.
4:24Instead of this local VNI, we're going
4:27to put in the new VNI that's going to be destined
4:29for this DNS server over here.
4:31That VNI says we're going to send it over towards this VTEP,
4:34but this VTEP knows that when it de-encapsulates it,
4:37that it's going to exist on the blue subnet.
4:39So the DNS server can respond to this query like it always has,
4:43sending it back to its default gateway,
4:44where the return process takes place.
4:47And this is what's pretty cool about it.
4:48When VXLAN behaves the way it always behaves,
4:51when we're just allowing communication
4:53within the same VNI, these devices, these VTEPs,
4:57are considered layer 2 gateways.
4:58They're all considered layer 2 gateway.
5:00However, when there's routing involved,
5:03these are configured as layer 3 gateways.
5:05There's really not a lot of extra configuration.
5:08We just tell it where the IRB interface lives,
5:11and what VNI and VLAN it's associated with.
5:14The question then becomes in an enterprise environment--
5:16and this is getting a little outside the scope
5:18of this course.
5:19But we're just going to talk about it for a quick second.
5:22The question then becomes, well, do you really
5:24want to use the spine-leaf architecture, where
5:26each one of these devices becomes a layer 3 gateway?
5:30Or would you rather use the spine-only architecture,
5:34where we trunk everything up to these core devices,
5:37and they serve as the layer 3 gateway?
5:39And I think one of the other cool things
5:41that you need to consider about this is
5:43when you've got MAC mobility.
5:45Remember the scenario where this device can
5:47migrate to a different site.
5:49Well, what happens when it does, and this device
5:51didn't have the exact same IP address?
5:53That means it was actually configured incorrectly.
5:56What you want to do is you want to make sure all of your IRB
5:59interfaces for the same VLAN--
6:01say VLAN 512, which is going to be servicing VNI 16512--
6:07you want to make sure they all have the same IP address,
6:11and if you can pull it off, they all
6:13have the same MAC address, too.
6:15That way, when my computer migrates,
6:17it's got the exact same default gateway
6:20that it had before, the same IP address,
6:22and the same MAC address, so it doesn't even
6:24have to ARP for the new MAC address when we migrate.
6:26It's a beautiful thing, and that's
6:28what makes virtual machine mobility so powerful in a data
6:32center environment, is the fact that it doesn't actually
6:34have to waste any frames at all when it migrates just to find
6:38out who its default gateway is.
6:39So that's why we configure an anycast gateway
6:41on all of our VTEPs, and we also configure it to have
6:45the same MAC address, too.
6:46So consider for a moment that the layer 2 gateway
6:48does basic VXLAN functionality of tunneling
6:51a frame from one end to the other within the same VNI.
6:55But then we also talk about configuring the layer 3
6:57gateway.
6:58That way, we can also route our customers' or end
7:01users' traffic outside of the VNI,
7:03which is going to be a very common thing to do.
7:05When we need to reach network services, or specified servers,
7:09or the internet, or any other parts of the campus.
7:11We're going to have to have these layer 3 gateways done
7:14in time.
7:14So yeah, you can absolutely go through the configuration
7:17and configure VXLAN without layer 3,
7:19and you would have communication on the same subnet.
7:22But you really want to do a layer 3 gateway, too.
7:24That way, these devices can still
7:26have routeability outside of their own subnet and outside
7:29of their own VNI.
7:30So this is how gateways work within VXLAN.
7:33I hope this has been informative for you,
7:34and I'd like to thank you for viewing.
Summarizing VXLAN Foundations
0:00[AUDIO LOGO]
0:05So now, we fundamentally understand
0:07what VXLAN brings to the table.
0:09It is a tunneling technology that is just a data plane.
0:12It relies on a separate control plane, which we have options
0:16for, but it's most likely going to be EVPN,
0:18in order to make forwarding decisions.
0:20We now understand the key terms like VNIs and VTEPs.
0:23And when we see it in action, when we actually just
0:25think about it conceptually, it's not that bad.
0:28We just encapsulate a frame inside of a packet,
0:30look up in the routing table where it's supposed to go,
0:32we send it there.
0:33That's it.
0:34That's how VXLAN works.
0:35So now that we understand the simpler part of an EVPN VXLAN
0:38deployment, it's time to roll up our sleeves
0:40and dig deep into how EVPN actually transmits forwarding
0:45decisions and populates routing tables full of MAC addresses.
0:48In the next set of videos, I'll see you there
0:50as we talk about EVPN.
0:52In the meantime, that's been VXLAN.
0:54I hope this has been informative for you,
0:55and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year