Prévia do material em texto
Shortest Path Bridging Mac-in-MAC
SPB (IEEE 802.1aq Shortest Path Bridging)
Designed to expand Layer 2 Ethernet domains
Provide multi-path and resiliency capabilities including:
Multiple shortest path routing (inter server traffic)
Deterministic traffic flows
Flexible subnet – expand/shrink anywhere
Virtualization operates in subnet
Fully compatible with all 802.1, Data Center Bridging protocols & OA&M
Address isolation through mac-in-mac breaks the 4096 limit
Fast recovery
No loops
11
Spanning Tree
A single tree, the traffic always has to pass
through the ‘Root’ bridge
F to G requires five hops and it is right next
to G
Lots of blocked path, wasted bandwidth
SPB-M
Each switch is its own Root Bridge with
symmetrical trees
Traffic flows the Shortest path
Address isolation through Mac-in-Mac
Mesh topologies
No loops
Fast recovery
SPB-M
8
7
8
75
9
6
9
5
9
STP
F
B
C
E
G
D
A
11
8
7
8
75
9
6
9
5
9
F
B
C
E
G
D
A
Acronyms Definition
BCB Backbone Core Bridge
BEB Backbone Edge Bridge
B-MAC Backbone MAC Address
B-VID Backbone VLAN ID in 802.1ah PBB header
B-VLAN Backbone VLAN
ECT Equal Cost Tree
ECT-Algorithm 32 bit unique id of an SPF tie breaking set of rules
ECT-Mask 64 bit mask XORed with BridgeID during tie breaking
ISID Logical Grouping Identifier for C-VLAN
MAC-IN-MAC Ethernet in Ethernet framing as per PBB
PBN Provider Bridged Networks – 802.1ad
PBB Provider Backbone Bridge - 802.1ah
SAP Service Access Points
SDP Service Distribution Points
SPB-M Shortest Path Bridging - 802.1aq – Mac-in-Mac
TLV Tag-Length-Value
C-TAG Customer 802.1q Tag
S-TAG Service provider 802.1q Tag
SPB-V Shortest Path Bridging - 802.1aq – Q-in-Q mode
SPB builds upon and reuses well known proven protocols
IEEE 802.1ad Data Plane (Q-in-Q PB)
IEEE 802.1ah Data Plane (M-in-M PBB)
IEEE IS-IS SPB Control Plane
IEEE 802.1ag CFM ETH-OAM
Data switching based on 802.1ah PBB (« MAC in MAC »)
OS6900 OS6900
BVLANs
CVLAN/I-SID I-SID/CVLAN
Access 1 Access 1
ISID
1001
ISID
1002
ISID
1003
ISID
1001
ISID
1002
ISID
1003
Vlan
11
Vlan
12
Vlan
13
Vlan
11
Vlan
12
Vlan
13
OS6900 OS6900
Ethernet
802.3
Provider
Bridges
802.1ad
Ethernet
802.1Q
Consistent
Forwarding
I-SID = Service ID
B-VID = Backbone VID
B-DA = Backbone DA
B-SA = Backbone SA
SA = Source MAC address
DA = Dest MAC address
VID = VLAN ID
C-VID = Customer VID
S-VID = Service VID
Provider
Backbone
Bridges
802.1ah
SPB distribute traffic and make better use of redundant links in a meshed
network
Multi-path loop-free shortest path bridging
Up to 16 paths (Equal cost Tree Algorithms)
Head-end assignment of traffic to any of those 16 shortest paths
Deterministic routing easily predicted by offline TE tools
Excellent use of mesh connectivity
SPB-M
Network
BVLAN 4001
BVLAN 4002
BVLAN 4003
OS6900 OS6900
BVLANs
ISIDs
ISIDs
ISID
1001
ISID
1002
ISID
1003
ISID
1001
ISID
1002
ISID
1003
Access Port
Services
SAP
Layer 2 Profiles (option)
Loopback Detection (option)
BVLAN
ISIS Interface
SHORTEST PATH Bridging
Control plane
OS6900 OS6900
Shortest path bridge VLAN
No spanning tree control
No source @mac learning of Customer data traffic
No flooding of unknown destination or multicast frames
No IP interface are support on BVLANs
Each B-VLAN calculates its own Shortest Path Tree
AOS support: 16 BVlans
BVLAN 4001
B-MAC
44:55:66:77:00:0X
SPB-M
:01
:04 :05
:03
:07
:02
:06
Note: Nodes must have same BVLANs and ECT parameters for the Adjacency to come up
Configure BVLANs
Setup the control B-VLAN
-> spb bvlan 4001 admin-state enable
-> spb isis control-bvlan 4001
Network topology discovery
Build SPT from each system to the rest of the nodes
IS-IS reads the System ID (MAC address) of SPB devices
IS-IS Hello packets
Control BVLAN
Active SPB interfaces
IS-IS SPB extended « Hello TLV
Local address “SPSourceID” advertissement
ECT Algorithms and BVLAN
Link cost (Link Metric)
ISID et I-SIDs to B-VLAN mapping information
Create ISIS-SPB Interfaces
-> spb isis interface port 2/1
-> spb isis interface linkagg 5
All bridges use predefined ECT algorithms to calculate layer 2 congruency and symmetry
for switching
Standard provides 16 predefined algorithms
16 ECT index 1-16
Shortest path trees calculation
Metric (Link cost) lower metric = higher priority
Bridge ID = System ID+ Priority
System ID = System Base MAC Address
Priority (Default 32768)
ECT-Algorithm used when multiple links have an equal cost
Corresponding ECT-ID mask is applied to the Bridge ID
ECT-ID| MASKS | B-VID
1 0x00 4001
2 0xFF 4002
3 0x88
4 0x77
5 0x44
6 0x33
7 0xCC
8 0xBB
9 0x22
10 0x11
11 0x66
12 0x55
13 0xAA
14 0x99
15 0xDD
16 0xEE
Low 4001 ECT-MASK(1) = 0x00 default, will pick the lowest BridgeID
High 4002 ECT-MASK(2) = 0xFF will invert, pick the largest BridgeID
Assign ECT-algorithms to B-VLANs
Note: The next available ECT ID is automatically assigned to a BVLAN when the BVLAN is created
-> spb isis bvlan 4001 ect-id 1
OS6900
OS6900
OS6900
OS6900
OS6900
OS6900 OS6900
SPB-M
VLAN 4001
:01
:04 :05
:03
:07
:02
:06
ECT 1 -> {04,02} < {04,05} < {06,07}
Bridge :01's Unicast forwarding table routes toward B-MACs :07, :03 and :05 via interface
1/2 while its single hop paths are all direct as can be seen from its FDB
BRIDGE-1 -> show spb isis unicast-table
SPB ISIS Unicast MAC Table:
Destination Outbound
BVLAN (Name : MAC Address) Interface
-----+------------------------------+-----------
4001 BRIDGE-2 : 44:55:66:77:00:02 1/2
4001 BRIDGE-3 : 44:55:66:77:00:03 1/2
4001 BRIDGE-4 : 44:55:66:77:00:04 1/1
4001 BRIDGE-5 : 44:55:66:77:00:05 1/2
4001 BRIDGE-6 : 44:55:66:77:00:06 1/3
4001 BRIDGE-7 : 44:55:66:77:00:07 1/2
MAC Addresses: 6
BVLAN 4001
B-MAC
44:55:66:77:00:0X
:04
OS6900
BEB
BCB
BCB
BEB
:01
:05
:03
:07
:02
:06
1/1
1/2
1/3
1/1
1/2
1/31/4
1/5
1/6
1/1
1/2
1/3 1/1 1/2
1/3
1/1
1/2
1/3
1/1
1/21/3
1/1
1/2
1/3
BEBBEB
BCB
ISID
1001
ISID
1001
ISID
1001
ISID
1001
OS6900
OS6900
OS6900
Host A
Host B
Host C
Host D
BUM = Broadcast Unknown Multicast
ARPs packets, Boot-p/DHCP requests, etc.
SPBM supports two BUM traffic distribution methods for replicating and
forwarding multicast frames
Head-End (native mode)
Tandem (optimized)
MC mode can be specified on a per I-SID basis or globally
OS6900
BEB
BCB
BCB
BEB
:01
:05
:03
:07
:02
:06
1/1
1/3
1/1
1/2
1/31/4
1/5
1/6
1/1
1/2
1/3 1/1 1/2
1/3
1/1
1/2
1/3
1/1
1/21/3
1/1
1/2
1/3
BEBBEB
BCB
ISID
1001
ISID
1001
ISID
1001
ISID
1001
OS6900
OS6900
OS6900
1/2
BVLAN 4001
•
•
•
•
Node :01's sends 3 frames to each Node :02
1 frame for node :05,
1 frame for node :03
1 frame for node :07
Node :02 is the primary path and will provide replication services
-> service spb 2 multicast-mode head-end
Host A
Host B
Host C
Host D
-> show spb isis multicast-table
Legend: MCAST Source * indicates any source in GMODE bvlans
SPBISIS Multicast MAC Table:
MCAST Source Inbound Outbound
ISID BVLAN MCAST Group Address (Name : BMAC) Interface Interfaces
------+-------+-------------------+---------------------------------------+-----------+-----------
1000 4015 13:c6:05:00:03:e8 VC2 : e8:e7:32:11:c6:05 1/2
1000 4015 73:97:29:00:03:e8 VC1 : e8:e7:32:07:97:29 1/2
OS6900
BEB
BCB
BCB
BEB
:01
:05
:03
:07
:02
:06
1/1
1/3
1/1
1/2
1/31/4
1/5
1/6
1/1
1/2
1/3 1/1 1/2
1/3
1/1
1/2
1/3
1/1
1/21/3
1/1
1/2
1/3
BEBBEB
BCB
ISID
1001
ISID
1001
ISID
1001
ISID
1001
OS6900
OS6900
OS6900
1/2
BVLAN 4001
• For every ISID, each bridge builds a tree from every BEB using special Multicast Group B-MAC
• When receiving a multicast frame, if a bridge happens to be in the Shortest Path for the particular ISID and BEB, it
will replicate and forward the frame(s)
• More bandwidth-efficient
Node :01's sends 1 frame to
Node: 02 with a B-DA of its
SPSourceID
Node 2 sends 1 frame each
to Nodes :07, :03 and :05
-> service spb 2 multicast-mode tandem
Host A
Host B
Host C
Host D
SPBM Group MAC addresses are derived from of B-DA unicast address and I-SID information
Identifies the source BEB and the ISID
-I/G (multicast bit) = 1
-U/L (local bit) = 1
-SPBM type = 00
-SPSourceID == 20-bit ‘short-form’ node ID
-I-SID == 24-bit I-component identifier
OmniSwitch
-> show spb isis info
SPB ISIS Bridge Info:
System Id = e8e7.3211.c605,
System Hostname = VC2,
SPSourceID = 01-c6-05,
…………… Omitted lines …………………
SHORTEST PATH Bridging (SPB)
Data Plane
SERVICE 1
SERVICE 2
SAP
SAP
BEB BEB
SERVICE 1
SERVICE 2
SAP
SAP
SPB Network
OS6900
OS6900
SDP
SDPDemux
Demux
SPB Service configuration enables VM traffic to be
encapsulated and bridged across the PBB network
Service Distribution Point (SDP) acts as a logical forwarding link from BEB to another BEB.
SDP instances are dynamically created (no manual configuration)
Specify what type of VM traffic is allowed to enter and exit
from/to the DC network)
-> service access linkagg 5
-> service access port 1/3
Allows VM traffic to enter and egress on this port
Fixed port or Logical ports
Enables Service Access Points (SAPs) to be configured on the port
Static Service
Dynamic UNP
Create Static Access Ports
Maps I-SIDs to BVLANs
Create the services (ISID’s)
IS-IS distributes the information to all the BEB/BB nodes
All the SPBM nodes (BeB/BcB) are aware of all the services and end-points
AOS support
1024 ISIDs/Bvlan
4094 Vlans per ISID
ISID to BVLAN
MappingBEB
OS6900
BVLAN
4001
BVLAN
4002
BVLAN
4003
B CompI Comp
ISID
1001
ISID
1002
ISID
1003
Create the I-SIDs (Static Services)
-> service spb 10 isid 1001 bvlan 4001
A user can configure SAPs with different encapsulation types (untagged,
tagged, or QinQ) on the same access port
Dynamic SAPs are supported from UNP or EVB
-> service spb 2000 sap port 1/7:0
-> service spb 100 sap port 1/7:100
-> service spb 1000 sap port 1/7:100.200
-> service spb 10 sap 1/3:10
-> service spb 20 sap 1/5:all
-> service spb 50 sap linkagg 5:500
Create multiple SAPs on a access port Create SAPs
Associated with each SAP port
Specifies how control packets are processed on the SAP port (STP, LACP, LLDP…)
Default profile: def-access-profile
Applied to incoming traffic on an access (VM or switch facing) port
CVLAN
Tagged
CVLAN
Untagged
Access
Port
Protocol Default
STP tunnel
802.1x drop
802.1ab drop
802.3ad peer
GVRP tunnel
MVRP tunnel
AMAP discard
L2 Profile
(Control frames filtering)
Control Frames
Control Frames
BPDU0180C2000000
BPDU0180C2000000
CVLAN 10
CVLAN 20
CVLAN 30
OS6900
Peer: allows the access port to participate
in the specified protocol and Control
packets are not sent to the network side of
the node
Discard: discards the specified PDU
Tunnel: tunnels the specified PDU across
the provider network
drop
peer
tunnel
Loopback Detection (LBD)
Automatically Loop detection
Prevents forwarding loops on ports that have forwarded network traffic which has looped back to the originating
switch
Method
No need of STP/RSTP/MSTP
Periodically sends out LBD frames from all loop-back detection enabled ports
Based on specific multicast frames
D-MAC: ALU proprietary MAC 0x01-20-DA-02-01-71
S-MAC: Individual Port MAC
Available on legacy or service access ports (port/linkagg)
Actions
Port shutdown
Trap
Event log
Port recovery
Automatically after a configurable timer or manually
SPB Backbone
Switch A and B are AOS switches running enhanced loopback-detection
Switch C is a legacy switch or a non AOS switch or a hub
1/1/7 and 1/1/8 are SAP ports having
same ISID and path cost
Loopback-detection is enabled with
option ‘service-access’ on ports
1/1/7 and 1/1/8
Traffic loops through
1/1/7 and 1/1/8
OS6900 OS6900A B
1/1/7 1/1/8
C
-> show loopback-detection
Global LBD Status : enabled,
Global Remote-origin LBD Status : enabled,
Global LBD Transmission Timer : 10 sec,
Global LBD Auto-recovery Timer : 300 sec,
Port 1/1/7 is shutdown in case B has higher bridge
identifier, since 1/1/7 and 1/1/8 has equal path costs
In case the 2 SAP ports are on the same switch, port 1/1/8 is shutdown as this interface has higher port identifier
OS6900 OS6900A B
1/1/7 1/1/8
C
X
2014 May 31 01:44:55 Pod10sw7 swlogd: intfNi Drv info(5) eniPhyPortEnable(2020):IND:gport:6 1/0/7 portEnable:Disable autoNeg:Disable portAdv:0x0
2014 May 31 01:44:55 Pod10sw7 swlogd: portMgrCmm main info(5) pvr trap: Violation set, chass 1, slot 1, port 7: source LBD, reason lbd shutdown
2014 May 31 01:44:57 Pod10sw7 swlogd: portMgrNi main info(5) : [pmnHALLinkStatusCallback:216] LINKSTS 1/1/7 DOWN (gport 0x6) Speed 0 Duplex HALF
2014 May 31 01:44:57 Pod10sw7 swlogd: vfcn main info(5) [vfccQsHandleLinkEvents:487] 1/1/7 LINK DOWN
2014 May 31 01:44:57 Pod10sw7 swlogd: stpNi _SOKt info(5) stpnimsg_processMsgFromPM: PM_LINK_STATUS_MSGID gPort=x6 linkStatus=0
2014 May 31 01:44:57 Pod10sw7 swlogd: intfNi Drv info(5) niEsmHandleEvent: current NI state:RUNNING event:8
2014 May 31 01:44:57 Pod10sw7 swlogd: intfNi Drv info(5) niEsmSendLinkStatusChgMsg(796): linkstatus DOWN sent on peerId=1
2014 May 31 01:44:57 Pod10sw7 swlogd: intfCmm Mgr info(5) cmmEsmHandleNiMsg: Rx CMM_ESM_LINK_STATUS_CHG from chassis 1 NI 1
System Id = e8e7.32cd.63d3System Id = e8e7.32d4.850d
-> show loopback-detection port 1/1/7
Global LBD Status : enabled,
Global Remote-origin LBD Status : enabled,
Global LBD Transmission Timer : 10 sec,
Global LBD Auto-recovery Timer : 300 sec,
Port LBD Status : enabled,
Port Remote-origin LBD Status : disabled,
Port LBD State : ShutDown,
Port LBD Type : service-edge,
SPB monitoring
Displays the ISIS-SPB backbone VLAN (BVLAN) configuration for the switch
->show spb isis bvlan
Displays the unicast forwarding information for a specified BVLANs
->show spb isis unicast-table bvlan bvlan_id
-> show spb isis bvlans
SPB ISIS BVLANS:
Services Num Tandem Root Bridge
BVLAN ECT-algorithm In Use mapped ISIDS Multicast (Name : MAC Address)
-------+-----------------+-------+---------+------+----------+----------------------------------------4015 00-80-c2-01 YES YES 1 SGMODE
4016 00-80-c2-02 YES YES 1 SGMODE
-> show spb isis unicast-table
Destination Outbound
BVLAN (Name : MAC Address) Interface
------+----------------------------------------+-----------
4015 sw1 : e8:e7:32:81:3b:7d 1/1/5
4015 sw8 : e8:e7:32:a4:77:7d 1/1/5
4016 sw1 : e8:e7:32:81:3b:7d 1/1/5
4016 sw8 : e8:e7:32:a4:77:7d 1/1/5
Egress port to next hop
Displays the shortest path first (SPF) information to all known SPB switches for
a specific BVLAN.
-> show spb isis spf bvlan bvlan_id
-> show spb isis spf bvlan 4015 bmac e8:e7:32:a4:77:7d
SPB ISIS Path Details:
Path Hop Name Path Hop BMAC
--------------------+-------------------
sw8 e8:e7:32:a4:77:7d
sw1 e8:e7:32:81:3b:7d
-> show spb isis spf bvlan 4015
SPB ISIS Path Table:
Destination Outbound Next Hop SPB Num
(Name : BMAC) Interface (Name : BMAC) Metric Hops
----------------------------------------+----------+----------------------------------------+------+------
sw1 : e8:e7:32:81:3b:7d 1/1/5 sw1 : e8:e7:32:81:3b:7d 10 1
sw8 : e8:e7:32:a4:77:7d 1/1/5 sw1 : e8:e7:32:81:3b:7d 20 2
Sw1: Transit switch (next hop)
Displays information about the ISIS-SPB adjacencies SPB ISIS
->show spb isis adjacency
Displays the discovered node-level parameter values for all of the ISIS-SPB
switches participating in the topology
->show spb isis nodes
-> show spb isis adjacency
SPB ISIS Adjacency:
System
(Name : SystemId) Type State Hold Interface
-------------------------------------+------+-------+------+----------
sw1 : e8e7.3281.3b7d L1 UP 20 1/1/5
-> show spb isis nodes
SPB ISIS Nodes:
System Name System Id SourceID BridgePriority
----------------+---------------+--------+---------------
sw1 e8e7.3281.3b7d 0x13b7d 32768 (0x8000)
sw8 e8e7.32a4.777d 0x4777d 32768 (0x8000)
sw7 e8e7.32c2.4e93 0x24e93 32768 (0x8000)
-> show spb isis info
SPB ISIS Bridge Info:
System Id = e8e7.32a4.777d,
System Hostname = sw8,
SPSourceID = 04-77-7d,
SPBM System Mode = auto,
BridgePriority = 32768 (0x8000),
…………… Omitted lines …………………
Displays the service instance identifier (I-SID) mapping for bridges participating
in the SPB topology
->show spb isis services
Displays the Service Distribution Point (SDP) configuration for SPB services
->show service sdp spb
-> show spb isis services
Legend: * indicates locally configured ISID
SPB ISIS Services Info:
System
ISID BVLAN (Name : BMAC) MCAST(T/R)
------------+-------+----------------------------------------+-----------
* 1001 4015 sw8 : e8:e7:32:a4:77:7d
* 1001 4015 sw7 : e8:e7:32:c2:4e:93
* 1011 4016 sw8 : e8:e7:32:a4:77:7d
* 1011 4016 sw7 : e8:e7:32:c2:4e:93
-> show service sdp spb
Legend: (*) dyn unicast object (+) remote mcast object (#) local mcast object
SPB SDP Info
FarEnd Bind FarEnd
SdpId SysId:BVlan / GroupMac SourceId Oper Intf/Isid Count SystemName / PortList
-----------+----------------------+--------+----+---------+-------+-------------------------------
32768* e8e7.3281.3b7d:4015 0x13b7d Up 1/1/5 0 sw1
32769* e8e7.3281.3b7d:4016 0x13b7d Up 1/1/5 0 sw1
32774* e8e7.32a4.777d:4015 0x4777d Up 1/1/5 1 sw8
32775* e8e7.32a4.777d:4016 0x4777d Up 1/1/5 1 sw8
Checking status of SAP ports
->show service spb service_id ports
Monitoring the traffic forwarding on SAP ports
->show service spb service_id sap {slot/port | linkagg agg_num} [:0 | :all | :qtag1
:outer_qtag.inner_qtag]
Stats must be enabled
-> show service spb 11
SPB Service Detailed Info
Service Id : 11, Description : ,
ISID : 1011, BVlan : 4016,
Multicast-Mode : Headend, Tx/Rx Bits : 0/0,
Admin Status : Up, Oper Status : Up,
Stats Status : No, Vlan Translation : No,
Service Type : SPB, Allocation Type : Static,
MTU : 9194, Def Mesh VC Id : 11,
SAP Count : 1, SDP Bind Count : 1,
Ingress Pkts : 0, Ingress Bytes : 0,
Egress Pkts : 0, Egress Bytes : 0,
Mgmt Change : 02/21/2014 20:07:57, Status Change : 02/21/2014 20:07:57
-> show service spb 11 sap port 1/1/3:111
SAP Detailed Info
SAP Id : 1/1/3:111, Description : ,
Admin Status : Up, Oper Status : Up,
Stats Status : Yes, Vlan Translation : No,
Service Type : SPB, Allocation Type : Static,
Trusted : Yes, Priority : 0,
Ingress Pkts : 121544, Ingress Bytes : 8264992,
Egress Pkts : 0, Egress Bytes : 0,
Mgmt Change : 02/19/2014 01:34:25, Status Change : 02/19/2014 01:58:15
MAC-ping
Based on destination @MAC (BMAC) via control BVLAN
BMAC address identification (switch @BMAC)
show spb isis info
sw1-> show spb isis info
SPB ISIS Bridge Info:
System Id = e8e7.32a4.777d,
System Hostname = sw8,
SPSourceID = 04-77-7d,
SPBM System Mode = auto,
BridgePriority = 32768 (0x8000),
…………… Omitted lines …………………
sw2-> mac-ping dst-mac e8:e7:32:a4:77:7d vlan 4015
Reply from E8:E7:32:A4:77:7D - 1/1/5 : bytes=64 seq=1 time=109us
Reply from E8:E7:32:A4:77:7D - 1/1/5 : bytes=64 seq=2 time=96us
Reply from E8:E7:32:A4:77:7D - 1/1/5 : bytes=64 seq=3 time=106us
Reply from E8:E7:32:A4:77:7D - 1/1/5 : bytes=64 seq=4 time=114us
Reply from E8:E7:32:A4:77:7D - 1/1/5 : bytes=64 seq=5 time=111us
----E8:E7:32:A4:77:7D MAC-PING Statistics----
5 packets transmitted, 5 packets received, 0% packet loss
round-trip (us) min/avg/max = 96/107/114
Lab: Implementing a SPB
infrastructure
OmniSwitch AOS R8
Extending Layer 2 connections across a SPB-M service backbone network
Contents
1 Objective ....................................................................................... 2
2 Physical diagram .............................................................................. 2
3 Logical diagram ................................................................................ 3
4 Configure a scenario for extending Layer 2 connections across a SPB-M network ... 3
4.1. Creating the Backbone VLANs ........................................................................ 3
4.2. Defining the Control BVLAN On each switch, configure the control BVLAN
for management ....................................................................................... 3
4.3. Configure the ISIS interface on network ports .................................................... 4
4.4. ISIS protocol activation ............................................................................... 4
4.5. Understanding SPB-M protocol operations ......................................................... 4
4.6. Creation of a SPB service ............................................................................. 5
4.6.1. SPB service configuration ................................................................................. 6
4.6.2. Configuring SPB access ports..............................................................................6
4.6.3. Define and configure the SAP services ................................................................... 6
5 Analysis and understanding the concept of SPB services ................................ 7
5.1. Check the configuration .............................................................................. 7
5.2. Perform some quick test on end device connection ............................................. 7
5.3. Resiliency................................................................................................ 8
6 Test ............................................................................................. 9
2
Extending Layer 2 connections across a SPB-M service backbone network
1 Objective
This lab is designed to familiarize you with SPBM deployment and have a good understanding of SPBM
configuration with the Alcatel-Lucent OmniSwitch family.
You will configure a scenario for extending Layer 2 connections across a SPB-M service backbone network for
Customer VLANs 2 and 3
2 Physical diagram
3
Extending Layer 2 connections across a SPB-M service backbone network
3 Logical diagram
4 Configure a scenario for extending Layer 2 connections across a SPB-M
network
4.1. Creating the Backbone VLANs
On each node, create the backbone VLAN (BVLAN) 2000 & 2001:
-> spb bvlan 2000
-> spb isis bvlan 2000 ect-id 1
-> spb bvlan 2001
-> spb isis bvlan 2001 ect-id 2
Notes
BVLAN configuration must be the same on each SPB bridge to ensure proper ISIS-SPB neighbor discovery and
shortest path calculations throughout the backbone SPB network.
4.2. Defining the Control BVLAN
On each switch, configure the control BVLAN for management
-> spb isis admin-state disable
-> spb isis control-bvlan 2000
Notes
Control BVLAN carries the ISIS PDUs which are single tagged with the chosen BVLAN ID.
4
Extending Layer 2 connections across a SPB-M service backbone network
4.3. Configure the ISIS interface on network ports
On every switch (6860/6900), configure the ISIS protocol on appropriate network ports) accordingly to the
lab diagram:
Switch 7
->spb isis interface port 1/1/5
->spb isis interface port 1/1/6
->interface port 1/1/5 admin-state enable
->interface port 1/1/6 admin-state enable
Switch 8
->spb isis interface port 1/1/5
->spb isis interface port 1/1/6
->interface port 1/1/5 admin-state enable
->interface port 1/1/6 admin-state enable
Switch 1
->spb isis interface port 1/1/5
->spb isis interface port 1/1/6
->interface port 1/1/5 admin-state enable
->interface port 1/1/6 admin-state enable
Switch 2
->spb isis interface port 1/1/5
->spb isis interface port 1/1/6
->interface port 1/1/5 admin-state enable
->interface port 1/1/6 admin-state enable
Notes
ISIS must be setting up on ports attached to the SPB core network. These interfaces are called « Network port »
in SPB context.
4.4. ISIS protocol activation
On every SPB nodes, enable globally IS-IS SPB protocol:
OS6860 & OS6900
-> spb isis admin-state enable
4.5. Understanding SPB-M protocol operations
Check the ISIS adjacencies then confirm the SPB parameters displayed through the following commands :
-> show spb isis adjacency
-> show spb isis services
-> show spb isis unicast-table
-> show spb isis nodes
-> show spb isis database
-> show spb isis bvlans
-> show spb isis info
-> show vlan 401x (Backbone Control Vlan)
Notes
Refer to the CLI reference and Network Configuration Guides for detailed information about outputs.
- Determine if ISIS SPB is in “UP” state then check the ISIS SPB neighbors on each of the equipments.
-> show spb isis adjacency
- Check the virtual vlan BVLAN and the associated ECT algorithm on each of the system.
-> show spb isis bvlans
- Displays the ISIS interface states.
-> show spb isis interface
- Displays the global ISIS-SPB status and configuration information for the SPB bridge.
-> show spb isis info
- Verify the unicast addresses learned on each SPB switch in the ISIS-SPB backbone topology.
-> show spb isis unicast-table bvlan 2000
-> show spb isis unicast-table bvlan 2001
5
Extending Layer 2 connections across a SPB-M service backbone network
- Checks the shortest path first (SPF) information to all known SPB bridges for a specific BVLAN
-> show spb isis spf bvlan 2000
-> show spb isis spf bvlan 2000 bmac <BMAC>
-> show spb isis spf bvlan 2001
-> show spb isis spf bvlan 2001 bmac <BMAC>
What commands would be used to determine the following?
- System ID -> _______________________________
- Destination @MAC/Name -> _______________________________
- Outbound interface -> _______________________________
- Next Hop switch -> _______________________________
- SPB metric -> _______________________________
- Number of hops -> _______________________________
- Neighbors list -> _______________________________
Do the path are identical for each BVLAN? Explain the result.
4.6. Creation of a SPB service
- The purpose of this exercise is to demonstrate how the services are configured and implemented in the
SPBM network. The lab will focus on creating the service access port, service access profile, ISID, and
SAP services
- This step consists in configuring a Shortest Path Bridging (SPB) service and associates that service with
a backbone service instance identifier (I-SID) and BVLAN.
- First, we will create two VLAN (2 and 3) on access switches OS6450 distributed over SPB backbone
network.
This vlan will be tagged over uplinks towards the backbone.
- Proceed as follow :
OS6450-A
->vlan 2
->vlan 2 port default 1/1
->ip interface vlan2 address 192.168.2.5/24 vlan 2
->vlan 3
->vlan 3 port default 1/2
->ip interface vlan3 address 192.168.3.5/24 vlan 3
->vlan 2 802.1q 1/3
->vlan 3 802.1q 1/3
->interfaces 1/1 admin up
->interfaces 1/2 admin up
->interfaces 1/3 admin up
OS6450-B
->vlan 2
->vlan 2 port default 1/1
->ip interface vlan2 address 192.168.2.6/24 vlan 2
->vlan 3
->vlan 3 port default 1/2
->ip interface vlan3 address 192.168.3.6/24 vlan 3
->vlan 2 802.1q 1/3
->vlan 3 802.1q 1/3
->interfaces 1/1 admin up
->interfaces 1/2 admin up
->interfaces 1/3 admin up
6
Extending Layer 2 connections across a SPB-M service backbone network
4.6.1. SPB service configuration
On each of the BEB nodes, create two instances ISID 2000 and 2001 that will be associate respectively with
the BVLAN 2000 and 2001.
- For this exercise, create two services 2000 and 2001 on switches 6860-A and 6860-B, as follow :
-> service spb 2000 isid 2000 bvlan 2000 admin-state enable
-> service spb 2001 isid 2001 bvlan 2001 admin-state enable
Notes
ISID and BVLAN must be defined on all SPB network for network consistency.
Each SPB service is capable of learning customer MAC addresses from the access side (SAPs) and from the
network side (Mesh SDP) and then switching the traffic based on this information.
4.6.2. Configuring SPB access ports
- On each BEB nodes (6860-A et 6860-B), configure the service access port(s) accordingly to the lab diagram.
The service access port(s) is the entry point of the LAN Access switch. (OS6450-A et OS6450-B vlan 2 and 3)
Notes
Access ports are required to configure a SAP.
A SAP is the point at which customer traffic enters and exits the service.
SAPs are not configurable on other port types.
OS6860-A et OS6860-B
-> service access port 1/1/3
-> interfaces 1/1/3 admin-state enable
4.6.3. Define and configure the SAP services- This will define the type of customer traffic that is allowed to enter the SPBM network.
- In this exercise, we will associate the Vlan2 traffic to the service 2000 and Vlan3 to the service 2001 on
the two nodes OS6860 (A and B).
- Classify the Vlan 2 and Vlan3 traffic with the identifier 2 and 3 on the uplink port
-> service spb 2000 sap port 1/1/3:2 admin-state enable stats enable
-> service spb 2001 sap port 1/1/3:3 admin-state enable stats enable
Notes
A SAP ID is comprised of a customer-facing port (referred to
as an access port) and an encapsulation value that is used to
identify the type of customer traffic to map to the
associated service.
Configuring SAPs with different encapsulation types for the
same access port is allowed.
7
Extending Layer 2 connections across a SPB-M service backbone network
5 Analysis and understanding the concept of SPB services
5.1. Check the configuration
-> show service
-> show service access
-> show service spb
-> show service sdp spb
-> show service spb id ports
-> show service mesh-sdp
-> show service spb id counters
-> show service spb id debug-info
-> show mac-learning
Notes
Refer to the CLI reference and Network Configuration Guides for detailed information about outputs.
5.2. Perform some quick test on end device connection
- From Virtual machines connected on the access switch, run some connectivity test between machines
sharing the same SPB service (members of same user Vlan).
- In addition to the ping requests and use of tracert application, use the following commands on BEB
systems to verify le @MAC classified as well as the associated SAP.
-> show mac-learning domain spb
-> show service spb 2000 sap port 1/1/3:2
-> show service spb 2000 sap port 1/1/3:2 counters
-> show service spb 2001 sap port 1/1/3:3
-> show service spb 2001 sap port 1/1/3:3 counters
Test scenario
- Use the VMs connected on port 1/1 and 1/2 on each OS6450 (VLAN 2 and VLAN 3)
- On VM Clients 5 and 6: Allocate an @IP 192.168.2.10x/24 and a default gateway 192.168.2.x (x being the
switch ID)
- On VM Clients 9 and 10: Allocate an @IP 192.168.3.10x/24 and a default gateway 192.168.3.x (x being the
switch ID)
- Note the @MAC o each of the VM client
- Run continuous ping requests between the selected VM clients inside their proper VLANs.
Example:
-> show mac-learning domain spb
Legend: Mac Address: * = address not valid,
Mac Address: & = duplicate static address,
Domain Vlan/SrvcId/ISId Mac Address Type Operation Interface
------------+----------------------+-------------------+------------------+-------------+-------------------------
SPB 2000:2000 00:50:56:90:18:8b dynamic servicing sap:1/1/3:2
SPB 2000:2000 e8:e7:32:40:d9:2a dynamic servicing sap:1/1/3:2
SPB 2000:2000 00:50:56:90:16:91 dynamic servicing sdp:32782:2000
SPB 2001:2001 00:50:56:90:dd:3b dynamic servicing sap:1/1/3:3
SPB 2001:2001 e8:e7:32:40:d9:2a dynamic servicing sap:1/1/3:3
SPB 2001:2001 00:50:56:90:d3:19 dynamic servicing sdp:32780:2001
Total number of Valid MAC addresses above = 6
8
Extending Layer 2 connections across a SPB-M service backbone network
5.3. Resiliency
- Perform some basic tests of failover in the SPBM network.
- Monitor the rerouting of sessions between the clients.
- Determine the interface selected by SPB IS-IS between the nodes 7 and 8 for the proper service, then
disable the chosen interface to switch 8 then check the ping test.
Example (connectivity test between client 5 and 6)
sw7 -> show spb isis unicast-table
SPB ISIS Unicast MAC Table:
Destination Outbound
BVLAN (Name : MAC Address) Interface
------+----------------------------------------+-----------
2000 Pod10sw1 : e8:e7:32:77:f6:49 1/1/5
2000 Pod10sw2 : e8:e7:32:81:3a:d5 1/1/6
2000 Pod10sw8 : e8:e7:32:cd:63:d3 1/1/5
2001 Pod10sw1 : e8:e7:32:77:f6:49 1/1/5
2001 Pod10sw2 : e8:e7:32:81:3a:d5 1/1/6
2001 Pod10sw8 : e8:e7:32:cd:63:d3 1/1/6
MAC Addresses: 6
For instance, here for Vlan 2 traffic attached to SPB service 2000
sw7> interfaces 1/1/5 admin-state disable
sw7> show spb isis unicast-table
SPB ISIS Unicast MAC Table:
Destination Outbound
BVLAN (Name : MAC Address) Interface
------+----------------------------------------+-----------
2000 Pod10sw1 : e8:e7:32:77:f6:49 1/1/6
2000 Pod10sw2 : e8:e7:32:81:3a:d5 1/1/6
2000 Pod10sw8 : e8:e7:32:cd:63:d3 1/1/6
2001 Pod10sw1 : e8:e7:32:77:f6:49 1/1/6
2001 Pod10sw2 : e8:e7:32:81:3a:d5 1/1/6
2001 Pod10sw8 : e8:e7:32:cd:63:d3 1/1/6
MAC Addresses: 6
What commands would be used to determine the following?
- SAP identifiers list -> _______________________________
- Counters per Service -> _______________________________
- List of Service Distribution Points (SDP) -> _______________________________
- List of SAP for a specific port -> _______________________________
- Status of Service Access Points -> _______________________________
- @MAC addresses learned on a SAP -> _______________________________
9
Extending Layer 2 connections across a SPB-M service backbone network
SUMMARY
This lab introduced you to the SPBM and how it works in an Alcatel-Lucent environment. You
should have the basic knowledge on how SPBM operates and what is required to configure it on
the switches.
6 Test
1. What is the main objective by configuring the IEEE 802.1aq protocol?
2. Is it necessary to configure some Service Access points (SAP) to handle untagged
traffic? Why?
3. Which command allow to determine the data path used by Vlan 2 frames between
switches 5 and 6 ?
4. Indicate a use case where SPB-M technology is useful in LAN networks?
IP Routing over SPB-M
OmniSwitch AOS R8
Overview
VPN Lite method
L3 VPN method
IP routing over SPB Implementation in AOS
Agenda
Objectives
Allowing the mapping of Layer 3 traffic onto the underlying SPB-M infrastructure
Reducing the need for an additional tier
Single system acting as both Edge Bridge and router for the same traffic
No devices required specifically for routing between SPB-M services
No IGPs needed on Core switchs
AOS mechanisms
L3 VPN
IP-VPN Lite
IP Routing over SPB-M
Overview
BEB-1
Concepts
VRFs on different BEBs are tied together by ISIDs across SPB-M backbone
Operates on Backbone Edge Bridges in a SPB-M backbone
BEB will do layer 3 forwarding in a VRF and SPB bridging on a SAP, thus fulfilling L3
connectivity across SPB network
VRFs on different BEBs are tied together by ISIDs across SPB-M backbone
I-SID Mapping to IP Interface
ISID
ISID
VRF
VRF
BEB-1 BEB-2
VRF
VRF
ISID
ISID
SPB-M
Backbone
IP Routing over SPB
Configuration steps
IP-VPN LITE L3-VPN
Loopback Port
Loopback Ports
ISID-1
Customer1
Network A
VRF 1
ISID 1
Loopback
ports
L3 VPN Access PortL3 VPN Router Port
Between the two loopback ports,
the mapping of VRF to I-SID are
coordinated by VLAN IDs
AOS supported mechanisms
L3/IP-VPN routing over SPB-M
IP-VPN Lite over SPB-M
In both mechanisms, use of loopback
One side of as an access port for SPB
Other side is a ‘normal’ port configured for
routing only
Static linkagg port or a physical port
Multiple ports can be shared among different VRFs
Each router side use different VLANs
Loopback port on VRF side called
L3 VPN router-port
Loopback port on SAP side called
L3 VPN access-port
Loopback ports
BEB
SPB-M
Backbone
IP over SPB
Loopback Ports Configuration
-> vlan 500
-> vlan 500 members port 1/1 tagged
->(vrf default) ip interface L3vpn1 address 10.5.1.1/24 vlan 500
VRF Interfaces
-> spb bvlan 4015
-> service access port 1/2
-> service spb 1000 isid 1000 bvlan 4015 admin-state enable
-> service spb 1000 sap port 1/2:500
Service and association to loopback ports
Customer1
Network A
VRF default
VLAN 500
10.5.1.1/24
ISID 1000
BVLAN 4015
Loopback
ports
L3 VPN Access Port
L3 VPN Router Port
BEB
SPB-M
Backbone
1/1
1/2
Loopback ports
Configure the L3 VPN loopback for VPN-Lite or L3 VPN mechanisms
The loopback configuration consists of one port tagged with an IP interface VLAN that
belongs to a single VRF instance connected to another port that is assigned to an SPB
SAP, to which the VLAN ID associated with the other loopback port is assigned
IP over SPB
Loopback Ports Configuration
L3 VPN
Access Port
L3 VPN
Router Port
Port 1/1
Port 1/2
SAP 1/2:500
L3 VPN
Access Port
L3 VPN
Router Port
Port 1/23
SAP 1/2:500
BEB-1
vlan 500
vlan 500 members 1/23 tagged
spb bvlan 4015
service access port 1/24
service spb 10 isid 1000 bvlan 4015 admin-state enable
service spb 10 sap port 1/24:500
vrf 1
vrf 1 ip interface L3vpn1 vlan 500 address 10.5.1.2/24
vlan 500
vlan 500 members 1/1 tagged
spb bvlan 4015
service access port 1/2
service spb 1000 isid 1000 bvlan 4015 admin-state enable
service spb 1000 sap port 1/2:500
vrf 1
vrf 1 ip interface L3vpn1 vlan 500 address 10.5.1.1/24
Port 1/24
vrf 1
ISID-1000
ISID-1000
vrf 1
BEB-2
Dorsale
SPB-M
Loopback ports
IP-VPN Lite over SPB-M
SPB-M
BACKBONE
ISID 1001
ISID 1002
VRF1
VRF2
VRFs interconnections across
a SPB-M cloud
SPB-M acts more like a
physical media
SPB-M tunnel endpoint is
presented as just another VLAN
port for L2/L3 traffic
Routing or bridging based on S/D
@MAC
Static routing
Point To Point routing
Multi-point routing
Routing to IP interfaces in a VRF
attached to an end of the SPB-M tunnel
IP-VPN LITE
IP-VPN Lite
Configuration
vrf 1
L3 VPN Access
Port
L3 VPN
Router Port
Port 1/1
Port 1/2
SAP 1/2:500
vrf 1
L3 VPN Access
Port
L3 VPN
Router Port
Port 1/23
Port 1/24
SAP 1/2:500
vlan 500
vlan 500 members 1/23 tagged
spb bvlan 4015
service access port 1/24
service spb 10 isid 1000 bvlan 4015 admin-state enable
service spb 10 sap port 1/2:500
vrf 1
vrf 1 ip interface L3vpn2 vlan 500 address 10.1.1.2/24
vrf 1 ip static-route 30.1.1.0/24 gateway 10.5.1.2
or
vrf 1 ip load ospf
vrf 1 ip ospf interface L3vpn2
vrf 1 ip ospf interface L3vpn2 admin-state enable
vrf 1 ip ospf area 0.0.0.0
vrf 1 ip ospf interface L3vpn2 area 0.0.0.0
vrf 1 ip ospf admin-state enable
vlan 500
vlan 500 members 1/1 tagged
spb bvlan 4015
service access port 1/2
service spb 1000 isid 1000 bvlan 4015 admin-state enable
service spb 1000 sap port 1/2:500
vrf 1
vrf 1 ip interface L3vpn1 vlan 500 address 10.5.1.1/24
vrf 1 ip static-route 20.1.1.0/24 gateway 10.5.1.1
or
vrf 1 ip load ospf
vrf 1 ip ospf interface L3vpn1
vrf 1 ip ospf interface L3vpn1 admin-state enable
vrf 1 ip ospf area 0.0.0.0
vrf 1 ip ospf interface L3vpn1 area 0.0.0.0
vrf 1 ip ospf admin-state enable
Static
routing
Dynamic
routing
Dorsale
SPB-M
ISID-1000
ISID-1000
BEB-1
BEB-2
Static
routing
Dynamic
routing
IP-VPN LITE
L3 VPN routing
IS-IS
IS-IS
SPB-M
BACKBONE
L3 VPN routing information
advertised across the SPB-M
domain via ISIS-SPB
through ISIS TLV 184
VRFs interconnections using one
ISID-per-VRF mapping
No needs to run routing
protocols on L3 VPN IP
interfaces
AOS Switch acts as an access or
edge router to connect VRFs across
the SPB-M backbone PBB network
L3-VPN
L3 VPN routing
GRT: Global Routing Manager
IPRM: IP Route Manager
ISID
1001
ISID
1002
VRF1
VRF2
• ISIS-SPB protocol acts as an IGP protocol
• ISID represents the VRF/L3VPN
• Segregates the routing information
– 1 VRF to 1 ISID mapping
Routes can be selectively imported into
ISIS- SPB and advertised across the SPB-M
domain
VRF routes are imported and exported
from its IPRM Database into the GRM
SPB-M
BACKBONE
IS-IS
IS-ISIS-IS
GRT
GRT
IP routes are exported into a global routing
table (GRM) to generate IP route entries
L3-VPN
ISIS-SPB inter-ISID route leaking
Leaking between VRFs is allowed via additional configurations
Each represents import/export or redistribution process
L3 VPN routing
Concept
On BEB
Inter-VRF route leaking
vrf A and vrf B import/export
Inter-ISID route leaking
vrf A binds to ISID-1 and vrf B binds to ISID-2
ISID-1 to ISID-2 redistribution
VRF VRF
ISID ISID
Import/Export or Redistribution
concept
ISID to ISID route redistribution
VRF to VRF route import/export
ISID to VRF route import
VRF to ISID route redistribution
L3-VPN
L3 VPN
SPB/VRF Components
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
VRF “Default”
GRT
(Global
Routing
Table)
ISIS
(SPB IPVPN
Route table)
Redist
Route
Map
RIB - Routing Information Base
FIB – Forwarding Information Base
GRT – Global Route Table
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
VRF “1”
Redist
Route
Map
L3-VPN
L3 VPN routing
Concept
GRTISIS table
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
VRF “Default”
Redist
Route
Map
ISID 1
VRF default
Route
Map
Route
Map
ISID – VRF binding
ISID to ISID route redistribution
VRF to VRF route import/export
ISID to VRF route import
VRF to ISID route redistribution
ISID 1
ISID 2
ISID 2
ISID 1
ISID 2
VRF “other”
RIB
(Routing
Information
Base)
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
IPRM
Redist
Route
Map
L3-VPN
L3 VPN
Configuration
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
GRT
ISIS
-> spb ipvpn bind vrf default isid 4001 gateway 10.1.2.1 route-map net
-> spb ipvpn bind vrf default isid 4001 gateway 10.1.2.1 all-routes
ISID 4000
ISID 4001 ISID 4001
1
Redist
Route
Map
VRF “Default”
ISID 4001
Enables routes to be
imported and
exported
(bidirectional)
betweenVRF and
SPB-ISIS
via GRT table
Create a “bind” entry between <vrf, gateway IP> and VRFs
route-map:
imported routes
filtering
L3-VPN
L3 VPN
Configuration
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
GRT
ISIS
ISID 4000
ISID 4001
ISID 4001
Redist
Route
Map
VRF “Default”
ISID 4001
VRF default
-> vrf default ip export route-map net1
2
Redist
Route
Map
Export routes from a VRF to GRT table or to other VRF instances
All routes can be
exported or filtered
through a route-map
L3-VPN
L3 VPN
Configuration
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
GRT
ISIS
ISID 4000
ISID 4001 ISID 4001
Redist
Route
Map
VRF “Default”
ISID 4001
VRF default
Redist
Route
Map
Routes “import”
-> vrf default ip import isid 4001 route-map net3
3
Routes importation
from GRT to VRF
-> vrf default ip redist import into ospf route-map net5
4
Option: Routes « import »
redistribution inside VRF
Import VRF or SPB service instance (ISID) routes from the GRT to the destination VRF
All routes can be
exported or filtered
through a route-map
L3-VPN
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
L3 VPN
Configuration
GRT
ISIS
ISID 4000
ISID 4001
ISID 4002
ISID 4001
Redist
Route
Map
VRF “Default”
ISID 4001
VRF default
-> vrf default ip export route-map net1
Redist
Route
Map
2
1 -> spb ipvpn bind vrf default isid 4001 gateway 10.1.2.1 all-routes
ISID 4002
-> spb ipvpn redist source-vrf default destination-isid 4002 route-map net93
Inter-I-SID route leaking
Enable redistribution of routes from a VRF to an ISID or from one ISID to another ISID
All routes can be
exported or filtered
through a route-map
L3-VPN
L3 VPN
Monitoring
Local
Static
RIP
OSPF
BGP
IS-IS
Local
Static
RIP
OSPF
BGP
IS-IS
FIB
(Forwarding
Information
Base)
RIB
(Routing
Information
Base)
IPRM
VRF “Default”
GRT
(Global
Routing
Table)
ISIS
(SPB IPVPN
Route table)
-> show spb ipvpn route-table
-> show ip global-route-table
-> (vrf default) show ip router database
-> (vrf default) show ip routes
Redist
Route
Map
RIB - Routing Information Base
FIB – Forwarding Information Base
GRT – Global Route Table
L3-VPN
Display the contents of the Global Routing Table (GRT) for all the routes that are
exported from VRF instances or from SPB instance service identifiers (ISIDs)
L3 VPN
Monitoring
-> show ip global-route-table
-> show ip global-route-table
Type Source Destination Gateway Metric Tag
-----+--------------------+------------------+---------------+----------+----------
isid 2000 10.132.2.0/24 10.132.2.8 1 0
isid 2000 192.168.2.0/24 10.132.2.8 1 0
isid 2000 192.168.3.0/24 10.132.2.8 1 0
isid 2000 192.168.8.0/24 10.132.2.8 1 0
vrf default 10.132.2.0/24 10.132.2.7 1 0
vrf default 192.168.2.0/24 192.168.2.7 1 0
vrf default 192.168.3.0/24 192.168.3.7 1 0
vrf default 192.168.7.0/24 192.168.7.7 1 0
GRT
(Global
Routing
Table)
L3-VPN
Route imported from
ISID 2000
Display the contents of the SPB IPVPN route table
L3 VPN
Monitoring
-> show spb ipvpn route-table [ isid <isid-num>]
-> show spb ipvpn route-table
egend: * indicates IPVPN route has matching locally configured ISID
SPB IPVPN Route Table:
Source Bridge
ISID Destination Gateway (Name : BMAC) Metric
----------+--------------------+-----------------+-----------------------------------------+--------
* 2000 10.132.2.0/24 10.132.2.7 Pod10sw7 : e8:e7:32:d4:85:0d 1
* 2000 10.132.2.0/24 10.132.2.8 Pod10sw8 : e8:e7:32:cd:63:d3 1
* 2000 192.168.2.0/24 10.132.2.7 Pod10sw7 : e8:e7:32:d4:85:0d 1
* 2000 192.168.2.0/24 10.132.2.8 Pod10sw8 : e8:e7:32:cd:63:d3 1
* 2000 192.168.3.0/24 10.132.2.7 Pod10sw7 : e8:e7:32:d4:85:0d 1
* 2000 192.168.3.0/24 10.132.2.8 Pod10sw8 : e8:e7:32:cd:63:d3 1
* 2000 192.168.7.0/24 10.132.2.7 Pod10sw7 : e8:e7:32:d4:85:0d 1
* 2000 192.168.8.0/24 10.132.2.8 Pod10sw8 : e8:e7:32:cd:63:d3 1
Routes: 8
ISIS
(SPB IPVPN
Route table)
L3-VPN
Route learned from ISID
2000
Display the contents of the routing table (per VRF)
L3 VPN
Monitoring
-> show ip routes
-> vrf default show ip routes
Or
-> show ip routes
+ = Equal cost multipath routes
Total 6 routes
Dest Address Gateway Addr Age Protocol
------------------+-------------------+----------+-----------
10.132.2.0/24 10.132.2.7 00:00:12 LOCAL
127.0.0.1/32 127.0.0.1 00:01:36 LOCAL
192.168.2.0/24 192.168.2.7 00:00:12 LOCAL
192.168.3.0/24 192.168.3.7 00:00:12 LOCAL
192.168.7.0/24 192.168.7.7 00:00:12 LOCAL
192.168.8.0/24 10.132.2.8 00:00:05 IMPORT
L3-VPN
FIB
(Forwarding
Information
Base)
Route imported from GRT
L3 VPN Lab
Logical view
OmniSwitch AOS R8
Lab: Implementing IP Routing over SPB-M
Content
1 Objective ....................................................................................... 2
2 Topological diagram .......................................................................... 3
3 Logical Diagram ............................................................................... 3
4 Setup the L3 VPN mechanism in order to activate inter access
VLAN L3 routing ............................................................................... 4
4.1. IP Routing over SPBM .................................................................................. 4
4.2. Configure Vlan 7 (OS6860-A) and Vlan 8 (OS6860-B) ............................................ 4
4.3. “IP over SPB” routing configuration ................................................................ 4
4.3.1. Configure L3-VPN loopback ports ........................................................................ 4
4.3.2. Create a SPB SAP associated to the service 2000 over VPN Access Port ............................ 5
4.3.3. Configure VRF/ISID bindings to exchange routes between Switch 7 and Switch 8 ................ 5
4.4. Access VLAN 2 and 3 routing ......................................................................... 7
5 Analysis and understanding the concept of IP Routing over SPB ....................... 8
5.1. Routing tables .......................................................................................... 8
5.2. Test scenario ........................................................................................... 8
6 Test ............................................................................................. 9
2
Lab: ImplementingIP Routing over SPB-M
1 Objective
In this lab you will configure a scenario for routing L3 traffic over a L2 SPB-M backbone network.
BE SURE YOUR PARTNER GROUP HAS COMPLETED THE PREVIOUS LAB (SCENARIO FOR
EXTENDING L2 CONNECTIONS ACROSS A SPBM BACKBONE NETWORK BEFORE GOING ON WITH
THE FOLLOWING EXERCISES.
3
Lab: Implementing IP Routing over SPB-M
2 Topological diagram
3 Logical Diagram
4
Lab: Implementing IP Routing over SPB-M
4 Setup the L3 VPN mechanism in order to activate inter access VLAN L3
routing
4.1. IP Routing over SPBM
- In addition to L2 VPN, the OmniSwitch also provides an IP over SPB-M capability that consolidates the
routing functionality of Customer Edge (CE) devices into the BEB devices.
- The Virtual Routing and Forwarding (VRF) instances on different BEBs are tied together via backbone I-
SIDs across the same SPB-M backbone that is used to support L2 VPNs.
- The OmniSwitch IP over SPB-M solution supports two methods for combining L3 routing and L2 SPB-M in
the same switch: VPN-Lite and L3-VPN.
The L3-VPN solution consists in exchanging layer 3 routes between VRFs. Instead of running routing
protocols on L3 VPN IP interfaces as for VPN-Lite solution, IP routes are imported into ISIS from VRFs and
ISIS carries the routes in IPVPN TLVs over SPB-M network to the other SPB BEBs. ISIS also receives IPVPN
TLVs from SPB-M network and exports them to VRFs.
In this exercise, we will allow IP routing between the VLAN 2 on access switches OS6450 and vlan 7 et
8 configured on the OS6860 across SPB backbone by implementing the L3-VPN solution.
4.2. Configure Vlan 7 (OS6860-A) and Vlan 8 (OS6860-B)
Vlan 7 and Vlan 8 creation
Switch 6860-A
-> vlan 7
-> vlan 7 member port 1/1/1 untagged
-> ip interface vlan7 address 192.168.7.7/24 vlan 7
-> interfaces 1/1/1 admin-state enable
Switch 6860-B
-> vlan 8
-> vlan 8 member port 1/1/1 untagged
-> ip interface vlan8 address 192.168.8.8/24 vlan 8
-> interfaces 1/1/1 admin-state enable
4.3. “IP over SPB” routing configuration
4.3.1. Configure L3-VPN loopback ports
Notes
Both the VPN-Lite and L3 VPN solutions for routing IP over an SPBM backbone network require a physical
loopback port configuration on the BEB. A regular switch port or a static link aggregate can serve as a loopback
port.
Notes
The loopback configuration consists of one port tagged with an IP interface VLAN that belongs to a single VRF
instance connected to another port that is assigned to an SPB SAP, to which the VLAN ID associated with the
other loopback port is assigned.
Switch 7
-> vlan 777
-> vlan 777 members port 1/1/15 tagged
-> service access port 1/1/16
-> vrf default ip interface L3vpn777 address 10.132.2.7/24 vlan 777
-> interfaces 1/1/15-16 admin-state enable
5
Lab: Implementing IP Routing over SPB-M
Switch 8
-> vlan 777
-> vlan 777 members port 1/1/15 tagged
-> service access port 1/1/16
-> vrf default ip interface L3vpn777 address 10.132.2.8/24 vlan 777
-> interfaces 1/1/15-16 admin-state enable
Notes
Refer to the CLI reference and Network Configuration Guides for detailed information about outputs.
4.3.2. Create a SPB SAP associated to the service 2000 over VPN Access Port
Notes
L3-VPN solution is implemented by associating either one VRF to one ISID (binding) either by redistributing
some routes between VRFs and/or I-SIDs by their importation and/or exportation (import/export).
Switchs 7 and 8
-> service spb 2000 sap port 1/1/16:777 admin-state enable stats enable
Notes : In current OS6860 AOS release, we need to enable VLAN translation on the port and SAP
level as well as on the service.
Do not apply to the OS6900, OS9900 and OS10K.
Switchs 7 and 8
-> service access port 1/1/16 vlan-xlation enable
-> service 2000 spb isid 2000 bvlan 2000 vlan-xlation enable
-> service 2001 spb isid 2001 bvlan 2001 vlan-xlation enable
L2 connection between the nodes 7 et 8 is now established. Check L3 connectivity status by running a ping
between the two interfaces L3VPN.
4.3.3. Configure VRF/ISID bindings to exchange routes between Switch 7 and Switch 8
- OS6860-A
1. Create the association between the VRF « default » and the SPB services 2000
-> spb ipvpn bind vrf default isid 2000 gateway 10.132.2.7 all-routes
Notes
The VRF “default” is bound to SPB I-SID 2000 and gateway 10.132.2.7 identifies the loopback IP interfaces.
Enables the bidirectional exchange of routes between the VRF “default” and SPB ISID 2000 via the Global Route
Manager (GRM).
Notes
VRF import and export commands are used to exchange routes between the VRF and I-SID specified in the
binding configuration.
2. Export the local routes into GRT table
a. Create route-map identifying the local routes
-> ip route-map local-to-spb sequence-number 50 action permit
-> ip route-map local-to-spb sequence-number 50 match protocol local
6
Lab: Implementing IP Routing over SPB-M
b. Export these local routes into GRT table
-> ip export route-map local-to-spb
Notes : All routes in VRF “Default” are exported to the Global Route Manager (GRM), which then
exports the routes to I-SID 2000
A route map can be specified to filter exported routes.
3. Import learned SPB routes via the service 2000 into VRF « default » table
-> ip import isid 2000 all-routes
Notes: This command imports SPB service instance identifier (ISID) 2000 routes from the GRT to
the default VRF.
A route map can be specified to filter exported routes.
Perform the same on switch 8
- OS6860-B
1. Create the association between the VRF « default » and the SPB services 2000
-> spb ipvpn bind vrf default isid 2000 gateway 10.132.2.8 all-routes
2. Create route-map identifying the local routes
-> ip route-map local-to-spb sequence-number 50 action permit
-> ip route-map local-to-spb sequence-number 50 match protocol local
3. Export local routes into GRT table
-> ip export route-map local-to-spb
4. Import learned SPB routes via the service 2000 into VRF « default » table
-> ip import isid 2000 all-routes
7
Lab: Implementing IP Routing over SPB-M
4.4. Access VLAN 2 and 3 routing
Attach the Vlans 2 and 3 traffic respectively to the SPB services 2000 and 2001 in order to participate in
routing L3 traffic through the SPBM core switch 7 and 8.
- OS6860-A
-> vlan 2
-> ip interface vlan2 address 192.168.2.7/24 vlan 2
-> vlan 2 members port 1/1/15 tagged
-> service 2000 sap port 1/1/16:2 stats enable
-> vlan 3
-> ip interface vlan3 address 192.168.3.7/24 vlan 3
-> vlan 3 members port 1/1/15 tagged
-> service 2001 sap port 1/1/16:3 stats enable
- OS6860-B
-> vlan 2
-> ip interface vlan2 address 192.168.2.8/24 vlan 2
-> vlan 2 members port 1/1/15 tagged
-> service 2000 sap port 1/1/16:2 stats enable
-> vlan 3
-> ip interface vlan3 address 192.168.3.8/24 vlan 3
-> vlan 3 members port 1/1/15 tagged
-> service 2001 sap port 1/1/16:3 stats enable
8
Lab: Implementing IP Routing over SPB-M
5 Analysis and understanding the concept of IP Routing over SPB
5.1. Routing tables
From the information in your student guide, monitor and validate the routing tables as well as associated
configuration parameters.
Usefull commands :
-> show spb ipvpn bind
-> show ip global-route-table
-> show spb ipvpn route-table
-> show ip routes
-> show ip export
-> show ip import
-> show spb ipvpn redist
….
Notes
Refer to the CLI reference and Network Configuration Guides for detailed informationabout outputs.
From Virtual machines connected on the backbone switch, run some connectivity test between machines
sharing the same SPB service (members of user Vlan 7 and 8 on OS6860-A and OS6860-B).
5.2. Test scenario
- Use the Clients (5, 6, 7, 8, 9, 10) connected on OS6450 ports (VLAN 2/VLAN 3) and OS6860 (VLAN
7/VLAN8)
- On each of the clients, allocate the following an @ IP and default gateway
Client 5 @IP 192.168.2.105/24 – default gateway 192.168.2.7
Client 6 @IP 192.168.2.106/24 - default gateway 192.168.2.8
Client 7 @IP 192.168.7.107/24 - default gateway 192.168.7.7
Client 8 @IP 192.168.8.108/24 - default gateway 192.168.8.8
Client 9 @IP 192.168.3.115/24 - default gateway 192.168.3.7
Client 10 @IP 192.168.3.116/24 - default gateway 192.168.3.8
- Run continuous ping requests between the selected VM clients.
- Display the path used between each of the clients
- Analyze the routing tables and the data path.
- Display the mac address table and check for sap port and client @mac mapping
- Disable the appropriate interconnection port to verify the network resiliency.
9
Lab: Implementing IP Routing over SPB-M
SUMMARY
This lab introduced you to the OmniSwitch AOS implementation of SPB-M that supports simultaneously routing
functionality permitting SPBM network to combine L3 routing and L2 SPBM on the same SPB Network.
6 Test
1. What is the role of the L3 VPN loopback ports?
2. Was it necessary to export the routes from default VRF to the ISID 2001? Why?
3. Indicate in what case the use of « route-map » is required to filter the IP
address to be advertised or to be imported?
DAY 1
Shortest Path Bridging Mac-in-MAC
Overview: Shortest Path Bridging Mac-in-MAC
Lab: Deploying a network based on SPB-M technology
DAY 2
IP Routing over SPB-M
Overview: IP Routing over SPB-M
Lab: Implementing IP Routing over SPB-M