Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

ConnectorOps トポロジの例を設定する

次の手順を使用して、このApstra ConnectorOpsセットアップガイドで使用するトポロジーを正確に設定します。ファブリックの配線や設計を構成する方法はさまざまですが、これはほんの一例です。このプロセスで実行されるすべての設定は、このトポロジーに固有です。

独自のトポロジーを使用している場合は、ConnectorOpsがApstraでSRX構成をレンダリングするために必要なすべての 前提条件 を参照してください。大まかな手順:
  1. ファブリックのルーティングポリシーを作成する
  2. SRXとボーダーリーフ間の接続テンプレートを作成して割り当てる

  3. Apstraで外部(オーバーザトップ)ゲートウェイを作成し、それらを各SRXのファイアウォールとして指定します

  4. VNを作成し、ノードにルーティングゾーンを割り当てる

  5. セキュリティポリシーの設定

ファブリックのルーティングポリシーを作成するには

  1. 1. ステージング された> ポリシー > ルーティングポリシー に移動し> ルーティングポリシーを作成します
    ルーティングポリシーの作成ウィンドウが表示されます。
  2. 以下のパラメーターを使用してルーティングポリシーを設定します。

    BGP routing policy configuration named BGP-2-SRX showing import/export rules, routing settings, and associated endpoints.
  3. 作成をクリックします

SRXとボーダーリーフ間の接続テンプレートを作成して割り当てるには

  1. 1. ブループリントから、[ ステージング > 接続テンプレート ]>[ テンプレートの追加]に移動します。
    接続テンプレートの作成ウィンドウが表示されます。
  2. テンプレートの名前を入力し、[ プリミティブ ]タブを選択します。
  3. IPリンクBGPピアリング(汎用システム)、ルーティングポリシーを選択します。

    User interface for creating a connectivity template in a network automation platform, with tabs for configuration options, a primitives list, a visual diagram showing flow from application point to routing policy, and buttons to create or revert changes.
  4. パラメータータブを選択し、各プリミティブを以下のパラメーターで設定します。
    • IPリンク

      Configuration interface for IP link setup with options for routing zone (Default routing zone selected), interface type (Untagged selected), VLAN ID (disabled, set to 2), L3 MTU (empty), IPv4 addressing type (Numbered selected), and IPv6 addressing type (None selected). Parameters tab is active.
    • BGPピアリング(汎用システム)

      Configuration interface for BGP peering setup with options for IPv4 and IPv6 AFI toggles, TTL, BFD toggle, password, keep-alive and hold time timers, and addressing type selection for IPv4 and IPv6.

      Network settings interface with IPv6 Addressing Type options: None, Addressed, Link local; Local ASN pre-filled with 64497; Neighbor ASN Type options: Static, Dynamic; Peer From options: Loopback, Interface; Peer To options: Loopback, Interface/IP Endpoint, Interface/Shared IP Endpoint.
    • ルーティングポリシー:ルーティングポリシー

  5. 作成をクリックします
  6. 接続テンプレートを選択し、 割り当て ボタンをクリックします。

    User interface icons: chain link labeled Assign, pencil labeled Edit, and trash can labeled Delete.
  7. ボーダーリーフの各インターフェイスにテンプレートを割り当てます。
    これにより、目的の BGP ピアが指定されます。
  8. 割り当てをクリックします
    新しいBGPピアを確認するには、 ステージング > 仮想 > ルーティングゾーン に移動し>デフォルトのルーティングゾーン> インターフェイス セクションを選択します。

    User interface for assigning the BGP-2-SRX configuration to network devices in a hierarchical fabric structure with pods, racks, leaf switches, and interfaces connected to vSRX devices.
    '
  9. 割り当てをクリックします
  10. 汎用システムへのリンクIPの割り当て

    Warning: Removing existing pools may impact resource assignments. Status: 0/8 Link IPs - To Generic. Buttons: Edit, Reset, View details. Tooltip: Update assignments. Info: No pools assigned.

    ステージング>仮想>プロトコルセッションで検証できます。

  11. 変更をコミットします

Apstraに外部(オーバーザトップ)ゲートウェイを作成し、それらを各SRXのファイアウォールとして指定するには

  1. ステージング>DCI>オーバーザトップまたは外部ゲートウェイに移動し>オーバーザトップまたは外部ゲートウェイを作成します

    上または外部ゲートウェイの作成ウィンドウが表示されます。

  2. 2. 以下のパラメーターを使用して、各SRXの外部ゲートウェイを設定します。

    Configuration page for network device fw-1 showing IP 192.168.1.7, ASN 65001, TTL 30, keep-alive 10, hold-time 30, EVPN route type5_only, and two gateway nodes, borderleaf1 and borderleaf2, with roles Leaf, ASNs 64516 and 64517, and respective hostnames.
  3. 作成をクリックします
  4. 変更をコミットします

VNを作成し、ルーティングゾーンをノードに割り当てるには

  1. ステージング>仮想>ルーティングゾーンに移動し>ルーティングゾーンを作成します
    ルーティングゾーンの作成ウィンドウが表示されます。
  2. ルーティングゾーン(RZ)の名前と 仮想ネットワークインターフェイス (VNI)番号を入力し、 作成をクリックします
    ルートターゲットとVLAN IDが自動的に割り当てられます。
  3. ルーティングゾーンのリストが表示されるまで、このプロセスを繰り返します。以下に、ルーティングゾーンのリストの例を示します。

    Table showing VRF configurations with columns for VRF Name, Tags, Type, VLAN ID, Route Target, VNI, DHCP Servers, Routing Policy Name, and Actions. Key details include VRF types like EVPN and L3 Fabric, unique VLAN IDs and VNIs, Route Targets such as 20001:1, and a consistent routing policy name Default_immutable. No tags or DHCP Relay are configured. Actions column includes a delete option.
  4. 仮想ネットワークタブを選択します。
    作成した各RZに割り当てるVNを作成しましょう。
  5. 仮想ネットワークの作成」をクリックします。

    仮想ネットワークの作成ウィンドウが表示されます。

  6. 以下の情報を入力します。
    • 名前:VNの名前

    • ルーティングゾーン:VNに関連付けるRZを選択します。この例では、 green-1 は以前に作成した RZ green に関連付けられています。

    • VNI:

    • VLAN ID(リーフ上):

  7. [ ブループリント全体で予約] のボックスを選択します。
  8. 以下を入力します。
    • IPv4サブネット:VNがアドレス指定に使用するサブネット。

    • 仮想ゲートウェイIPv4: 仮想ゲートウェイに割り当てられているIPアドレス。

  9. 接続テンプレートの作成で、 タグなしのボックスを選択します。
  10. 割り当て先セクションで、各ボーダーリーフと、リーフペアを含むラックを選択します。
  11. 作成をクリックします
  12. 各RZにVNが関連付けられるまで、このプロセスを繰り返します。

    VNのリストが表示されます。次に、VNのループバックIPプールを指定します。

  13. 仮想>ルーティングゾーンに移動します。
  14. 割り当てボタンをクリックして、ループバックIPアドレッシング用のIPプールを割り当てます。

    User interface for managing resource allocation with sections By Routing Zones and By Resource Groups. By Routing Zones shows Leaf Loopback IPs with 0 of 1 resources assigned and a tooltip to change pool assignments. By Resource Groups shows EVPN L3 VNIs with all 4 resources assigned and green: Leaf Loopback IPs with 0 of 4 resources assigned.
  15. すべてのRZを選択し、上部のドロップダウンからIPプールを選択します。
  16. 選択項目を割り当てを選択し、更新をクリックします

    User interface for updating pool assignments with a dropdown to select a pool, a table listing routing zones cats, dogs, green, and red with checkboxes and pool assignment dropdowns, and Assign Selected, Unassign Selected, and Update buttons.
  17. 変更をコミットします
    次に、RZ を適切なノードに割り当てましょう。
  18. ステージング>接続テンプレートに移動します。
  19. リストから新しいVNを選択し、上部にある選択したテンプレートの割り当てボタンを選択します。
    選択したテンプレートの割り当てウィンドウが表示されます。表の上部にある各VNの列に注目してください。

    List of items with checkboxes, 4 selected: Untagged VxLAN cats-1, dogs-1, green-1, red-1. Toolbar with icons and tooltip Assign Selected Templates.
  20. 各VNを対応するインターフェイス(エンドポイント)に割り当てます。

    以下の例は、指定されたVN割り当てを示しています。


    Network configuration interface for assigning templates in a fabric, showing a hierarchy with pod1, racks, leaves, interfaces, VxLAN assignment checkboxes, tags, and an Assign button.
  21. ステージング>ファブリック設定に移動し>ファブリックポリシー>設定を変更します。

    ファブリックポリシー設定の変更ウィンドウが表示されます。

  22. 「汎用システムへのデフォルト IP リンク MTU」に 「9000」と入力します。
  23. 変更をコミットします

セキュリティポリシーを設定するには

このエンドツーエンドルーティングのトポロジー例でSRXデバイスに適用されている正確なセキュリティポリシーは次のとおりです。

このトポロジを設定したら、 ConnectorOpsの展開と接続の確認に進みます。