Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

캠퍼스 패브릭 코어 배포 구성

캠퍼스 패브릭에 대한 코어-배포 토폴로지를 구성하는 다음 단계를 따르십시오.

주니퍼 네트웍스 캠퍼스 패브릭은 모든 캠퍼스에 구축할 수 있는 표준 기반의 단일 EVPN-VXLAN 솔루션을 제공합니다. 캠퍼스 패브릭 코어-디스트리뷰션 솔루션은 EVPN 패브릭을 확장하여 여러 건물에 걸쳐 VLAN을 연결합니다. 이 네트워크 아키텍처에는 표준 LACP를 통해 액세스 스위칭 레이어와 통합되는 코어 및 배포 레이어가 포함됩니다.

캠퍼스 패브릭 코어 분산 아키텍처에 대한 자세한 배경 정보는 다음 문서를 참조하십시오.

참고:

2025년 5월 업데이트 이후 Mist 클라우드에 구축된 토폴로지에서 Mist는 모든 EVPN 루프와 중복 MAC 주소를 자동으로 탐지하고 보고합니다. 이러한 문제는 스위치 인사이트 페이지에 표시됩니다.

  • EVPN 루프 감지 - EVPN-VXLAN 경량 PE-CE 루프 감지는 다운스트림 리프 투 서버 또는 액세스 포트에서 LAN 이더넷 루프를 감지하고 차단하는 데 도움이 됩니다. 이 기능은 잘못 배선된 패브릭 구성 요소 또는 패브릭에 잘못 연결된 타사 스위치와 같은 문제로 인해 발생하는 루프를 감지할 수 있습니다. 이 기능이 작동하려면 스위치에서 Junos OS 버전 24.4R1 이상을 실행해야 합니다. 자세한 정보는 EVPN-VXLAN 경량 리프-서버 루프 감지를 참조하십시오.

  • 중복 MAC 주소 감지—EVPN 환경에서 서로 다른 인터페이스 또는 디바이스 간의 MAC 주소 이동(MAC 모빌리티)으로 인해 발생하는 문제를 식별하고 완화합니다. 일부 MAC 모빌리티가 예상되지만(예: 디바이스가 실제로 움직일 때), 급격한 변화는 네트워크 루프나 잘못된 구성과 같은 문제를 나타낼 수 있습니다. 자세한 내용은 중복 MAC 주소에 대한 루프 감지 구성을 참조하십시오.

캠퍼스 패브릭 구성 모범 사례

  • 스위치 템플릿 수준에서 VLAN을 구성하고 캠퍼스 패브릭을 구성하는 동안 VLAN을 가져옵니다. 템플릿은 스위치 또는 사이트 수준에서 특별히 요구되지 않는 한 모든 VLAN 및 포트 프로필에 대한 단일 정보 소스여야 합니다.
  • 액세스 레이어에서 명시적으로 요구되지 않는 한 모든 VLAN을 허용하는 트렁크 포트 프로필을 사용하지 마십시오.
  • 스위치 템플릿이 아닌 캠퍼스 패브릭을 통해 VRF 및 VRF 네트워크 구성을 생성합니다.
  • 역할별로 포트 할당을 생성하고 필요에 따라 개별 디바이스의 구성을 덮어씁니다.
  • 서비스 블록 디바이스를 제외하고 캠퍼스 패브릭 워크플로우를 통해 DHCP 릴레이 구성을 관리합니다.

캠퍼스 패브릭 core-distribution 구성:

  1. 조직 > 캠퍼스 패브릭를 클릭합니다.
  2. 사이트에 대한 캠퍼스 패브릭을 만들려면 페이지 머리글 옆에 있는 드롭다운 목록에서 사이트를 선택합니다. 전체 조직에 대한 캠퍼스 패브릭을 만들려면 드롭다운 목록에서 전체 조직 을 선택합니다.

    조직 수준의 캠퍼스 패브릭 토폴로지를 사용하여 여러 건물이 있는 캠퍼스 전체의 아키텍처를 구축할 수 있습니다. 그렇지 않으면 단일 코어, 배포 및 액세스 스위치 세트로 사이트별 캠퍼스 패브릭을 구축하십시오.

  3. 관련된 옵션을 클릭합니다. 다음을 클릭하십시오.
    • 캠퍼스 패브릭 구성 버튼(사이트에 연결된 캠퍼스 패브릭 구성이 없는 경우 표시됨)

    • 캠퍼스 패브릭 생성 버튼(사이트에 이미 하나 이상의 캠퍼스 패브릭 구성이 연결된 경우 표시됨)

    토폴로지 탭이 표시됩니다.
  4. 토폴로지 유형( 캠퍼스 패브릭 코어-배포)을 선택합니다.
  5. 아래에 설명된 대로 토폴로지 탭에서 토폴로지 이름 및 기타 설정을 구성합니다.
    참고:

    캠퍼스 패브릭에 연결된 네트워크와 충돌하지 않는 한 이 화면의 기본 설정을 사용하는 것이 좋습니다. 각 레이어 간의 포인트 투 포인트 링크는 /31 주소 지정을 활용하여 주소를 보존합니다.

    1. 구성 섹션에 다음을 입력합니다.
      • 토폴로지 이름 - 토폴로지의 이름을 입력합니다.

      • 토폴로지 하위 유형 - 다음 옵션 중 하나를 선택합니다.

        • CRB - 이 모델에서 레이어 3(L3) VXLAN 게이트웨이 기능은 코어 디바이스에서만 구성됩니다. 이는 코어 디바이스에 통합 라우팅 및 브리징(IRB) 인터페이스를 정의하여 L3 라우팅 서비스를 제공함으로써 수행됩니다. 이 옵션은 L3 서브넷에 참여하는 모든 디바이스에 대해 가상 게이트웨이 주소 지정을 사용합니다. 이 옵션을 활성화하면 코어 스위치가 각 L3 서브넷에 대해 공유 IP 주소로 구성됩니다. 이 주소는 두 코어 스위치 간에 공유되며 VLAN 내의 모든 디바이스에 대한 기본 게이트웨이 주소로 사용됩니다. 또한 Mist는 각 코어 디바이스에 고유한 IP 주소를 할당합니다.

          • 가상 게이트웨이 v4 MAC 주소 - WLAN에서 게스트 포털 리디렉션을 지원하려면 이 옵션을 활성화합니다. Mist는 각 L3 IRB 인터페이스(네트워크당)에 고유한 MAC 주소를 제공합니다. 이 옵션은 CRB를 선택한 경우에만 사용할 수 있습니다. 스위치는 안정적인 EVPN-VXLAN 운영을 유지하기 위해 일관된 가상 게이트웨이 MAC 주소 사용해야 합니다. 정의된 가상 게이트웨이 v4 MAC 주소가 없으면 스위치가 가상 MAC 대신 IRB MAC 주소를 사용하여 ARP 응답을 전송할 수 있으며, 이로 인해 패브릭 전체에서 알 수 없는 유니캐스트 플러딩이 발생할 수 있습니다. 가상 MAC 주소 구성은 예측 가능한 MAC 학습을 보장하고 불필요한 플러딩을 방지합니다.

            참조 항목: EVPN-VXLAN 또는 EVPN-MPLS 오버레이 네트워크의 기본 가상 게이트웨이에 대한 MAC 주소 이해

        • ERB - 이 모델에서 L2 및 L3 VXLAN 게이트웨이 기능은 배포 디바이스에서 구성됩니다. 이 경우 IRB 인터페이스는 L3 라우팅 서비스를 제공하기 위해 배포 디바이스에 정의됩니다. 이 옵션은 L3 서브넷에 참여하는 모든 디바이스에 대해 애니캐스트 주소 지정을 사용합니다. 이 경우 분산 스위치는 각 L3 서브넷에 대해 동일한 IP 주소로 구성됩니다.

    2. (기본 설정을 사용하지 않기로 선택한 경우) 토폴로지 설정 섹션에 다음을 입력합니다.
      • BGP 로컬 AS—Mist가 각 디바이스에 자동으로 할당하는 프라이빗 BGP AS 번호의 시작점을 나타냅니다. 구축에 적합한 프라이빗 BGP AS 번호 범위를 사용할 수 있습니다. Mist는 패브릭의 언더레이에서 루프백 IP 주소만 교환되도록 라우팅 정책를 프로비저닝합니다.

      • 언더레이 - 언더레이의 인터넷 프로토콜 버전을 선택합니다. 옵션은 IPv4 및 IPv6입니다. ERB 토폴로지만 IPv6을 지원합니다. 토폴로지 하위 유형으로 ERB를 선택한 경우에만 IPv6을 선택할 수 있는 옵션이 제공됩니다.

      • Subnet— Mist가 디바이스 간의 포인트 투 포인트 링크에 사용하는 IP 주소 범위입니다. 구축에 적합한 범위를 사용할 수 있습니다. Mist는 이 서브넷을 링크당 /31 서브넷 주소 지정으로 나눕니다. 특정 구축 규모에 맞게 이 수를 수정할 수 있습니다. 예를 들어, /24 네트워크는 최대 128개의 point-to-point /31 서브넷을 제공합니다.

      • IPv6 루프백 인터페이스 - 패브릭의 각 디바이스에서 IPv6 루프백 인터페이스를 자동 구성하는 데 사용되는 IPv6 루프백 인터페이스 서브넷을 지정합니다.

      • IPv4 자동 라우터 ID 서브넷/루프백 인터페이스 - Mist는 이 서브넷을 사용하여 패브릭의 각 디바이스(EVPN으로 구성되었는지 여부에 관계없이 액세스 디바이스 포함)에 라우터 ID를 자동으로 할당합니다. 라우터 ID는 디바이스 간 오버레이 피어링에 사용되는 루프백 인터페이스(lo0.0)입니다. 새 토폴로지의 경우, 이 필드는 수정할 수 있는 기본 서브넷 값(172.16.254.0/23)을 자동으로 채웁니다. 기존 토폴로지를 편집할 때 이 필드는 기본값을 채우지 않습니다. 라우터 ID는 BGP와 같은 라우팅 프로토콜을 구축할 때 식별자로 사용됩니다.

        IPv4 구축의 경우 자동 라우터 ID 할당을 비활성화하고 라우터 ID를 수동으로 구성할 수 있는 옵션이 있습니다. 이렇게 하려면 이 필드를 비워 둔 다음 노드 탭에서 라우터 ID를 수동으로 구성합니다.

        IPv4 구축의 경우, 스위치 구성 페이지의 라우팅 타일에 있는 라우터 ID 필드에서 루프백 인터페이스를 수동으로 구성하여 자동으로 할당된 라우터 ID를 덮어쓸 수도 있습니다(스위치 이름 > 스위치). 그러나 나중에 캠퍼스 패브릭 구성을 수정하는 경우 Mist는 수동으로 구성된 루프백 인터페이스를 대체하여 라우터 ID의 자동 할당을 다시 수행합니다.

      • VRF 서브넷당 루프백—Mist는 이 서브넷을 사용하여 DHCP 릴레이와 같은 서비스에 사용되는 가상 라우팅 및 포워딩(VRF) 인스턴스당 루프백 인터페이스(lo0.x)를 자동으로 구성합니다. 새 토폴로지의 경우, 이 필드는 수정할 수 있는 기본 서브넷 값(172.16.192.0/24)을 자동으로 채웁니다. 이 필드는 /19 이하의 서브넷(예: /24)을 지원합니다. 기존 토폴로지를 편집할 때 이 필드는 기본값을 채우지 않습니다.

        VRF별 루프백 IPv4 또는 IPv6 서브넷을 정의할 때 Mist는 전체 서브넷에 대해 해당 집계 경로를 자동으로 생성합니다. 네트워크 설정 탭의 VRF 수준에서 이 구성을 재정의할 수 있습니다.

  6. 계속을 클릭하여 노드 탭으로 이동하며, 여기서 캠퍼스 패브릭 구축의 일부를 구성하는 디바이스를 선택할 수 있습니다.
  7. 코어, 배포 및 액세스 계층 섹션에 스위치를 추가합니다.

    스위치 추가:

    1. 스위치를 추가할 섹션에서 스위치 선택 을 클릭합니다.
    2. 캠퍼스 패브릭에 추가할 스위치를 선택합니다.
    3. 선택을 클릭합니다.

    캠퍼스 패브릭을 생성하기 전에 스위치 인벤토리에서 각 디바이스의 존재를 검증하는 것이 좋습니다.

    기본적으로 Mist는 코어 스위치가 서비스 블록 기능을 실행하는 경계 노드로 작동하도록 구성합니다. 캠퍼스 패브릭 토폴로지에서 경계 노드는 방화벽, 라우터 또는 중요 디바이스와 같은 외부 디바이스를 상호 연결합니다. 외부 서비스 또는 디바이스(예: DHCP 및 RADIUS 서버)는 경계 노드를 통해 캠퍼스 패브릭에 연결됩니다. 코어 스위치에서 이 작업을 오프로드하고 전용 스위치를 경계 노드로 사용하려면 페이지 왼쪽 상단의 코어를 경계로 사용 확인란의 선택을 취소합니다. 그런 다음 최대 2개의 스위치를 전용 경계 노드로 추가할 수 있습니다.

    또한 Mist는 확장성 향상을 위한 포드를 제공합니다. 액세스 및 배포 디바이스가 포드로 그룹화됩니다. 포드는 건물을 나타낼 수 있습니다. 예를 들어 사이트의 각 건물에 대해 포드를 생성하고 해당 포드의 액세스 디바이스와 배포 디바이스 간에 연결을 생성할 수 있습니다. 여러 건물의 배포 디바이스에 동일한 액세스 디바이스 세트를 연결할 필요가 없습니다. +노드 추가를 클릭하여 여러 Pod를 생성할 수 있습니다.

    포드와 코어 스위치 사이에는 하나의 연결만 필요합니다. 포드의 각 분산 스위치를 사용되는 모든 코어 스위치에 연결할 필요는 없습니다. 코어-분산 토폴로지(CRB 또는 ERB)에서는 코어 및 배포 쌍당 하나의 연결만 필요합니다.

    참고:

    토폴로지 탭의 자동 라우터 ID 서브넷/루프백 인터페이스 필드를 비워 두면 스위치의 라우터 ID를 수동으로 구성해야 합니다. 이렇게 하려면 패브릭에 추가한 스위치를 선택하고 오른쪽에 나타나는 창에서 라우터 ID를 구성합니다. 수동 라우터 ID 할당은 IPv4 구축에서만 지원됩니다.

  8. 스위치를 선택한 후 계속 을 클릭하여 네트워크를 구성할 수 있는 네트워크 설정 탭으로 이동합니다.
  9. 아래 설명된 대로 네트워크 설정을 구성합니다.
    1. 네트워크 타일에서 구성에 네트워크 또는 VLAN을 추가합니다. 새 네트워크를 만들거나 조직 > 스위치 템플릿 페이지에 정의된 스위치 템플릿에서 네트워크를 가져올 수 있습니다.

      새 VLAN을 추가하려면 새 네트워크 생성 을 클릭하고 VLAN을 구성합니다. 설정에는 이름, VLAN ID 및 서브넷이 포함됩니다. 서브넷에 대한 IPv4 또는 IPv6 주소를 지정할 수 있습니다.

      구성한 IPv4 또는 IPv6 서브넷 외에 IPv4 및 IPv6 애니캐스트 게이트웨이 주소를 선택적으로 구성할 수 있습니다. Mist UI는 이러한 게이트웨이를 캠퍼스 패브릭의 모든 액세스 및 배포 스위치에서 애니캐스트 IP 주소 할당으로 액세스합니다. 구성.

      참고: 애니캐스트 게이트웨이 필드를 비워 두면 Mist UI는 서브넷의 첫 번째 IP 주소를 애니캐스트 주소로 사용하는 기존 논리를 사용합니다.

      템플릿에서 VLAN을 가져오려면:

      1. Add Existing Network(기존 네트워크 추가)를 클릭합니다.

      2. 템플릿 드롭다운 목록에서 스위치 템플릿을 선택하여 해당 템플릿에서 사용할 수 있는 VLAN을 확인합니다.

      3. 표시된 목록에서 필요한 VLAN을 선택하고 ✓ 표시를 클릭합니다.

      VLAN은 가상 네트워크 식별자(VNI)에 매핑됩니다. 선택적으로 VLAN을 VRF 인스턴스에 매핑하여 트래픽을 논리적으로 분리할 수 있습니다.

    2. 네트워크 섹션에서 네트워크를 지정한 후 정보가 자동으로 채워지는 기타 IP 구성 타일의 설정을 검토합니다.

      Mist는 각 VLAN에 대해 IRB의 자동 IP 주소 지정을 제공합니다. 그런 다음 포트 프로필이 VLAN을 지정된 포트와 연결합니다.

    3. 선택적으로 VRF 인스턴스를 구성합니다. 세그먼트 기반 캠퍼스 패브릭 아키텍처에서 유형 5(IP 접두사) 정책을 적용할 때 VRF를 사용하는 것이 좋습니다. 기본적으로 Mist는 모든 VLAN을 기본 VRF에 배치합니다. VRF 옵션을 사용하면 트래픽 격리 요구 사항에 따라 공통 VLAN을 동일한 VRF로 그룹화하거나 별도의 VRF로 그룹화할 수 있습니다. 각 VRF 내의 모든 VLAN은 서로 및 다른 외부 네트워킹 리소스와 완전히 연결됩니다. 일반적인 사용 사례는 인터넷 연결을 제외한 대부분의 엔터프라이즈 도메인에서 게스트 무선 트래픽을 격리하는 것입니다. 기본적으로 캠퍼스 패브릭은 VRF 간에 완전한 격리를 제공하여 VRF 간 통신이 방화벽을 통과하도록 강요합니다. VRF 간 통신이 필요한 경우 VRF에 대한 추가 경로를 포함해야 합니다. 추가 경로는 캠퍼스 패브릭이 외부 라우터를 사용하도록 지시하는 기본 경로일 수 있습니다. 또한 추가 보안 검사 또는 라우팅 기능을 위한 방화벽이 될 수도 있습니다.

      VRF를 생성하려면:

      1. VRF 타일에서 VRF 인스턴스 추가 를 클릭하고 설정을 지정합니다. 설정에는 다음이 포함됩니다.

        • VRF의 이름

        • VRF와 연결할 네트워크

        • VRF IPv4 서브넷당 루프백 및 VRF IPv4 서브넷당 루프백—Mist는 이 서브넷을 사용하여 DHCP 릴레이와 같은 서비스에 사용되는 VRF 인스턴스당 루프백 인터페이스(lo0.x)를 자동으로 구성합니다. Mist는 VRF당 루프백 IPv4 또는 IPv6 서브넷에 대한 집계 경로를 자동으로 생성합니다. 이 설정은 토폴로지 탭에 정의된 루프백 VRF별 IPv4 또는 IPv6 서브넷보다 우선합니다.

      2. 경로를 추가하려면 새 VRF 인스턴스 페이지에서 추가 경로 추가 링크를 클릭하고 정적 또는 집계 경로를 지정합니다. 고정 경로 탭에서 고정 경로 추가 링크를 클릭하여 고정 경로를 구성합니다. 마찬가지로 집계 경로 탭에서 집계 경로 추가 링크를 클릭하여 집계 경로를 구성합니다. 이러한 경로에 대해 IPv4 또는 IPv6 주소를 지정할 수 있습니다. 집계 경로는 방화벽이나 WAN 라우터와 같은 외부 피어에 보급하기 위해 내부 패브릭 경로를 요약하는 데 사용되며 경계 노드 또는 코어 노드(패브릭에 경계 노드가 없는 경우)로 정의된 디바이스에만 푸시됩니다. 집계 경로를 구성하기 위해 다음을 지정합니다.

        • 대상 - CIDR 표기법의 집계 경로 접두사입니다. IPv4(예: 192.168.0.0/16) 및 IPv6(예: 2001:db8::/32) 접두사가 모두 지원됩니다.

        • 메트릭(선택 사항) - 경로 선택에 사용되는 집계 경로에 할당된 라우팅 메트릭입니다. 유효한 범위: 0–4,294,967,295.

        • 기본 설정(선택 사항) - 집계 경로에 할당된 경로 기본 설정(관리 거리)입니다. 낮은 값은 더 높은 선호도를 나타냅니다. Junos OS의 집계 경로에 대한 기본 기본 설정은 130입니다. 유효한 범위: 0–4,294,967,295.

        • 폐기 (선택 사항) - 기본적으로 활성화되어 있습니다. 활성화되면 집계 접두사와 일치하지만 더 구체적인 기여 경로와 일치하지 않는 패킷은 자동으로 삭제됩니다. 이는 라우팅 루프를 방지하며 권장되는 구성입니다.

    4. 배포/액세스 포트 구성 타일에서 축소된 코어와 액세스 스위치 간의 ESI-LAG에 대한 포트 구성 또는 프로필 설정을 완료합니다. 포트 설정에는 이름 및 기타 포트 구성 요소가 포함됩니다.

      서로 다른 포드의 배포 스위치와 액세스 스위치 간의 ESI-LAG 연결에 대해 고유한 VLAN 세트를 할당할 수 있습니다. 요구 사항에 따라 여러 Pod에서 동일한 VLAN을 재사용하거나 Pod당 고유한 VLAN을 정의할 수 있습니다. VLAN 할당은 포트 프로필을 통해 구성됩니다. 각 포드에 대해 서로 다른 포트 프로파일을 생성할 수 있으므로 세그먼트 분할 및 설계에 더 큰 유연성을 제공할 수 있습니다. 각 포트 프로필에는 서로 다르거나 중첩되는 VLAN이 포함될 수 있습니다. 포트 프로필을 추가하려면 프로필 추가 옵션을 사용합니다.

      기본적으로 이 구성에는 같은 페이지의 네트워크 타일에 추가된 네트워크가 포함됩니다. 설정을 제거하거나 수정하려면 고급 표시 를 클릭하고 설정을 구성합니다. 화면의 팁을 사용하여 포트 프로필 설정을 구성합니다.

    5. DHCP 릴레이 타일에서 DHCP 릴레이 설정을 구성합니다. 다음과 같은 옵션이 있습니다.
      • 활성화 - 캠퍼스 패브릭의 모든 IRB 지원 디바이스에서 DHCP 릴레이를 구성합니다. 이 옵션을 사용하면 선택한 네트워크에서 DHCP 릴레이를 활성화할 수 있습니다. 네트워크는 같은 페이지의 네트워크 탭에 나열되어 있는 한 DHCP 릴레이 타일 내부에 채워집니다.

      • 비활성화 - 캠퍼스 패브릭의 디바이스에서 DHCP 릴레이를 비활성화합니다. 이 옵션을 선택하면 모든 IRB 지원 디바이스에서 DHCP 릴레이가 비활성화됩니다. 이 옵션을 선택하면 스위치 세부 정보 페이지에서 로컬로 정의된 DHCP 릴레이가 제거되므로 신중하게 선택해야 합니다.

      • 없음 - 이 옵션은 캠퍼스 패브릭 토폴로지에 DHCP 릴레이 구성 측면에서 디바이스가 혼합되어 있을 때 자동으로 선택됩니다. 즉, 일부 디바이스에서는 DHCP 릴레이가 활성화되고, 일부는 비활성화되며, 일부 디바이스는 정의되지 않았습니다. 이 옵션은 개별 스위치에 DHCP 릴레이가 로컬로 정의된 모든 캠퍼스 패브릭 토폴로지에 표시됩니다.

      로컬로 정의된 모든 DHCP 릴레이 네트워크를 제거하려면 사용을 선택한 다음 모든 기존 디바이스 수준 DHCP 네트워크 제거를 선택합니다. 캠퍼스 패브릭 워크플로우에서 구성 변경을 중앙 집중화하여 DHCP 릴레이 구축을 단순화할 수 있습니다.

      캠퍼스 패브릭 구성에서 DHCP 릴레이를 활성화하면 패브릭의 모든 IRB 정의 디바이스에서 활성화되고 나머지 디바이스에서는 비활성화됩니다. 예를 들어, 캠퍼스 패브릭 코어 배포(CRB) 토폴로지에서 DHCP 릴레이는 코어 디바이스에서 활성화되고 나머지에서는 비활성화됩니다. 마찬가지로 ERB(캠퍼스 패브릭 코어 배포)에서는 DHCP가 배포 디바이스에서 활성화되고 나머지에서는 비활성화됩니다.

  10. 계속을 클릭하여 포트 탭으로 이동하면 포트를 구성하고 코어, 배포 및 액세스 레이어 스위치 간에 연결을 생성할 수 있습니다.
  11. 아래 설명된 대로 코어 계층에서 스위치 포트를 구성합니다.
    1. 코어 섹션에서 스위치를 선택하여 스위치 포트 패널을 엽니다.
    2. 코어 스위치의 포트 패널에서 구성할 포트를 선택합니다.
    3. 포트 유형(예: ge 또는 xe)을 지정합니다.
    4. 링크가 종료될 분산 스위치를 선택합니다. 캠퍼스 패브릭의 일부가 되어야 하는 모든 포트를 구성해야 합니다.

    배포 계층에서 스위치 포트를 구성하려면 다음을 수행합니다.

    1. 배포 섹션에서 스위치를 선택하여 스위치 포트 패널을 엽니다.
    2. 스위치의 포트 패널에서 구성할 포트를 선택합니다.
    3. 포트 유형(예: ge 또는 xe)을 지정합니다.
    4. 선택:
      • 코어에 연결 하여 포트를 코어 스위치에 연결합니다.

      • 포트를 액세스 스위치에 연결하는 액세스 링크.

    5. 링크가 종료되어야 하는 코어 또는 액세스 스위치(이전 단계의 선택 사항에 따라)를 선택합니다. 캠퍼스 패브릭의 일부가 되어야 하는 모든 포트를 구성해야 합니다.
    액세스 레이어에서 스위치 포트를 구성하려면 다음을 수행합니다.
    1. 액세스 섹션에서 스위치를 선택하여 스위치 포트 패널을 엽니다.
    2. 스위치의 포트 패널에서 구성할 포트를 선택합니다.
    3. 포트 유형(예: ge 또는 xe)을 지정합니다.
      액세스 레이어가 VC(Virtual Chassis)를 사용하는 경우 기본 및 백업 탭에서 포트를 구성할 수 있습니다.

    액세스 스위치의 경우 분산 스위치와 상호 연결하는 데 사용해야 하는 인터페이스만 선택합니다. 시스템은 AE 인덱스 옵션을 통해 모든 인터페이스를 단일 이더넷 번들로 묶습니다. 액세스 디바이스에 대한 AE 인덱스 값을 지정할 수 있습니다.

    특정 포트의 구성 및 상태 정보를 보려면 포트 패널 UI에서 해당 포트를 나타내는 번호가 매겨진 상자 위로 마우스를 가져갑니다.

  12. 계속을 클릭하여 확인 탭으로 이동합니다.
  13. 각 스위치 아이콘을 클릭하여 구성을 보고 확인합니다.
  14. 구성을 확인한 후 변경 사항 적용 > 확인을 클릭합니다.
    이 단계에서는 캠퍼스 패브릭 구성을 Mist 클라우드에 저장하고 스위치에 적용합니다. 스위치가 오프라인 상태인 경우 다음에 스위치가 온라인 상태가 될 때 구성이 적용됩니다. 스위치가 구성을 완료하는 데 최대 10분이 걸릴 수 있습니다.
  15. 캠퍼스 패브릭 구성 닫기를 클릭합니다.

    Mist가 캠퍼스 패브릭을 구축한 후 또는 패브릭을 구축하는 동안 연결 테이블을 다운로드할 수 있습니다. 연결 테이블은 캠퍼스 패브릭의 물리적 레이아웃을 나타냅니다. 이 테이블을 사용하여 물리적 캠퍼스 패브릭 빌드에 참여하는 디바이스에 대한 모든 스위치 상호 연결을 검증할 수 있습니다. 연결 테이블을 클릭하여 다운로드합니다(.csv 형식).

  16. 캠퍼스 패브릭 구성을 확인합니다. 확인하려면 캠퍼스 패브릭 코어 배포 CRB(JVD)캠퍼스 패브릭 코어 배포 ERB(JVD)확인 섹션에 나열된 단계를 따르십시오.

For a demo, watch the following video:

Hello and welcome to this new edition of Wired Assurance. My name is Rohan Chadha and I am a part of the MIST product management team. Today we'll be talking about deployment of campus fabric core distribution topology with Wired Assurance.

This particular EVPN topology is one of the three main topologies recommended by Juniper for EVPN VxLAN in campus. Today we'll be talking about how to deploy this using Wired Assurance and I assure you none of this deployment will include any CLI configuration and we'll use the UI throughout with just a click of a few buttons. So let's just jump right into it and I'll walk you through the four steps to deploy this topology.

Before we begin, let's talk about the building blocks of campus fabric core distribution. What are the devices that we're going to use today? And what is essentially campus fabric core distribution? So today we'll be using two core devices that are QFX 10,000 use. We'll be using two distribution devices that are QFX 5120Y and we'll be using one access switch for the purposes of this video.

And this particular device is an EX440024T, a copper switch. In this case, it's a virtual chassis. You can use a standalone or you can use a virtual chassis for an access device in campus fabric core distribution.

Before we jump into building the topology in four steps, let's talk about if campus fabric core distribution is right for you or your network environment. I would highly recommend you watch the other video by Rick Bartosik in which he explains why should you use campus fabric core distribution versus, let's say, an IP CLO or an EVPN multi-homing topology. So if you're new to EVPN makes land and you're trying to explore this area, I would highly recommend you go watch that video.

But if you're sure that you want to use this topology and you want to learn how to build it, you're in the right spot. One other thing that I'd like to point out to you on this page is that all of these devices are not being managed by Wired Assurance at this moment. And what does that mean? That means that they are only in monitoring mode.

As you can see, the configuration is not being managed by MIST. There is a reason why I'm demoing it a certain way and I'll show you why. So none of these devices are being managed.

The configuration will not be pushed to the devices unless we explicitly ask the UI to do it. So towards the end of the video, I'll show you why we want it to be a certain way. So let's click on organization and under Wired, we'll click on campus fabric.

We'll build a site-based campus fabric. There is also something called an org-based campus fabric. And what that means is you can build a campus fabric for an entire organization using pods from multiple sites.

But today for the purposes of this video, we'll be building only a site-based campus fabric, campus fabric core distribution as they call it. So let's click on configure campus fabric. And as you can see that at the time of making of this video, campus fabric core distribution along with campus fabric IP Clo are in beta state.

So let's talk about choosing a campus fabric topology. As I mentioned earlier, if you're sure that you want to build campus fabric core distribution, then this is the right place for you. If you're not, then go watch the other video.

But let's talk about what campus fabric core distribution is. It is essentially a two-layer EVPN VXLAN fabric, which involves a core layer and a distribution layer. If you look at this diagram on the left side, you see a horizontal line.

This horizontal line basically differentiates what is EVPN VXLAN configured versus what is not. As you can see, the top is a core layer and a distribution layer. Below the horizontal line are access devices that are basically dual home to the distribution boxes.

These access devices are pure layer two dummy devices that can run LACP, but that's not a requirement. You can also directly connect servers or any other devices that you would like to single home directly to these distribution devices, and that can come outside of the campus fabric core distribution workflow. That is possible.

So let's begin by configuring a topology name. There are two kinds of topologies that we can build within campus fabric core distribution, CRB as well as ERB. As you can see on the screen, it's centrally routed and edge routed.

So centrally routed means routing on the core device, and edge routed means routing on the edge, which in this case, our edge is distribution. For the purposes of this video, we'll be building a campus fabric core distribution that is CRB. So let's give it a name.

After you've given a topology name, we have some other default settings that do not need to be changed if there isn't a reason. These are basically the overlay and the underlay settings. For this campus fabric core distribution, we do IBGP in the overlay, and we use EBGP in the underlay.

As you can see, we have 65,000 local is that will be assigned to all the devices in the overlay, and we have 65,001 that will be sequentially incremented on any device that you use in this fabric. All of these settings will be taken care of by campus fabric. As a user, you do not have to manually configure any of these settings on the device itself, as I mentioned earlier.

The loopback prefix is the prefix assigned to loopback interfaces for every VTEP in campus fabric core distribution. It's slash 24 by default. If you do not want to use this number, you can reduce it.

If your campus fabric core distribution is a smaller fabric, let's say 5 to 10 devices, something like a slash 28 would work for you. Subnet in this particular setting is basically the subnet that as a user, you would provide us, or you can use this default subnet. This will be used for the IP address allocation for the fabric links between the core and the distribution devices.

Again, all of this will be done and taken care of by campus fabric itself. The second step is basically selecting the campus fabric nodes. What nodes would you want to be a part of core distribution and access layer? There are a few requirements.

The first one that we see on the screen is service blog border. Let me talk a little about what this is. So if you're someone who would want their network environment core devices to be lean spine, and what that means is if you do not want the firewall or the WAN or DHCP DNS NTP services to be connected to the core devices, you can use something that's called service blog.

This service blog basically connects to the core and you can connect all of your services, including the connectivity to the cloud and your data centers in this particular service blog. For the purposes of this video, I'm going to keep it simple and we're going to be just building a fabric here and connecting. The service blog will not be a part of this video.

So we'll go ahead and select two devices that are a part of the core layer and that is, as I mentioned, core one and core two. We will select two distribution devices, distribution one and distribution two. As you can see in this little dropdown, there is all the information provided to you at your fingertips, including the name and the model.

And for the access layer, we'll be selecting a virtual chassis that is access switch three. Once you've selected all the devices, you can verify by clicking on these. You also need to provide the router IDs here.

These router IDs are used for loopback interfaces. These loopback interfaces are used to pair with each other for building the VX LAN tunnels. One more thing that I'd like to point out is that once you build the fabric, you can always come back and add more devices and you can scale as much as you would like.

You can add more distribution devices. You can add more access devices based on your network environment needs. So you do not have to connect all the devices in the same setting.

We understand that network environment needs grow. And without any impact to other devices or the network operations itself, you can always come in and add more access devices later if there is a need. The third step is basically to provide networks.

And if you'd like to do some segmentation between those networks, we have VRF settings as well for that. For networks, you can either create a new network. And I'll go and create a new network here.

And we'll call it EVPN-CRB. And I'll give it a VLAN ID 10. And I'll give it a VLAN subnet of 192.160.10.1.0.24. And then I'll assign it a virtual gateway.

This virtual gateway will be used on your gateways depending on if you've chosen a CRB or an ERB network. Once you've created a network, you can see that two IP addresses have automatically been chosen for two core devices. This is where the gateways will be set for this fabric.

And as you can see, since we chose CRB as our topology, core 1 and core 2 will have these two different IRB addresses on their devices. And that will be 192.160.10.2 and 10.3. And we know that 10.1 will be the virtual gateway since we've manually assigned that. We can go ahead and either create more networks or we can also add an existing network.

An existing network is basically something that is being used in your existing site. And in this case, this site called Bangalore-site has a bunch of devices. So we're going to go and choose one and two VLANs that are being used on other devices.

And we'll try to inherit these. What this does is it reduces our work of configuring VLANs manually time and again on every device. So as we can see, 4091 on the subnet and virtual gateway has been inherited without me inputting anything again.

So now we have three VLANs for which all of the gateways will reside on the core devices as we asked for. But what if you do not want the gateways to reside on the core and instead you would like the gateways to reside on outside the fabric, perhaps the firewall or the VAN itself, or perhaps your gateways are in the data center, right? That is an option as well. And that is something that's called bridge overlay.

We can create a new network. Let's call it VLAN 100. And we'll assign a VLAN ID 100.

And we don't have to assign the subnet or the virtual gateway. What this does is VLAN 100 will be a part of the fabric or VNI will be assigned to it and it will be existing on all devices. However, the gateway for VLAN 100 will not exist on the fabric.

And the assumption here is that it will exist somewhere outside the fabric. So it will be a layer to stretch from the access device all the way until where the gateway exists. And it could be the firewall or the router if that exists before.

So now that we've spoken about networks, let's talk about how can you segment these networks using VRF. I'll go ahead and enable these instances for VRFs. And I'll try and create some VRFs here where I'll try to keep CRB10 as a part of one VRF.

And then I'll keep the other two VLANs as a part of VRF2. What this does is it segments the traffic between VRF1 and VRF2. If you would like more security and segmentation where you want to keep these networks separate and have different routing tables, this is an option for you.

You can also add extra routes if that is a requirement for your network needs. The last step on this page is to assign a name to the distribution access configuration. Once you've built the fabric, there will be an ESL lag between your distribution and your access devices.

Your access devices will be dual-homed to your distribution devices. So let's give it a name and call it EBPN-ESI. We've automatically taken all four networks that you assigned to the fabric and you added it to the trunk networks list, assuming that all of them will be a part of the fabric and the ESI lag.

If for some reason you would not want to have any of the VLANs as a part of the ESI lag, you can always come in and remove that here. There are other properties that you can change. Most of them are default.

If you would like to change the MTU or enable storm control, or if you would like to set up a MAC limit, that is an option as well for you. The last and final step is to assign how these ports are connected to each other. So far, we've picked the devices.

We've picked the VLANs and the VRFs that we want, but we haven't really told Campus Fabric how to connect these devices. So what I'm going to do is I'm going to go ahead and connect these devices, and I'll fast-forward the video so you don't have to go through each of the connections that I picked. So as you can see here, I've connected all these devices to each other.

I've connected two links from the core to the distribution, and then upwards as well from distribution to the core, and then from distribution to access, I've connected two links as well. As you can see, we support a virtual chassis in the access layer, so you can very well use that as well here. And if you'd like to change the AE index number, that is an option as well, as long as it is within the AE index range.

So this was the last and final step. We'll hit Continue, and this is our final step to verify you've built the fabric at this point. Ensure that you have selected the right VLANs, your IP addresses on a per-device level that is selected here as you'd like it to be.

Verify your connections. Is the core connected to the right distribution devices? And as we can see, and as an example, this is our bridged overlay design wherein VLAN 100 does not have an IP address, and that means that it exists somewhere outside the fabric. Go ahead and hit Apply Changes, and click Confirm.

At this point, as I mentioned earlier, the devices are not being managed by MIST, and let's go to the switches, and let's look at each device, and let's understand the configuration that is being pushed here. So before I go through the UI and show you how the configuration is being displayed here in terms of VLANs and VRFs, let's talk about the configuration. If you're running a brownfield environment, what that means is if you have an existing campus fabric, and you are trying to convert to a wireless assurance-based campus fabric, and you do not want to afford any downtime, you can come in, you can onboard your devices to the cloud, but do not manage the devices.

Once you build the fabric, ensure that all the configurations are there. We have a nice utility called Download Genos Config. Without logging into the device, you can ensure that the configuration that you wanted to be on the device is there.

Now, this configuration is the point of view of the cloud, as in wired assurance. Wired assurance, once you turn on Manage by MIST, and you click Save, all the configuration through the CLI will be overwritten, and wired assurance will be the source of truth. So if you look at this configuration, you'll see that we've configured your underlay BGP, we've configured overlay BGP.

In your underlay BGP, we have two neighbors from core one to two distribution devices. Similarly, we have two overlay between core one and distribution one and distribution two. We have the appropriate EVPN configuration.

And similarly, we have the gateways on the core devices with the appropriate virtual gateway. As you can see, we have set appropriate Jumbo MTUs. If there's any configuration that you think does not match your requirement, you can always add or delete using the additional CLI commands.

So if, let's say, you would like to add an existing MTU configuration that is not supported by the UI, let's say, you can always come in and add it to the additional CLI command box. So going back to the configuration, we see that we have the gateways defined. We have the routing instances defined as we did for your segregation of the networks, right? So we can look that vRF1 has a particular network that's a part of it.

And similarly, vRF2 has two networks that are a part of it, and then appropriate routing policies that are needed to talk between the four VTEPs that is there as well. And similarly, all the VLANs that you want are here as well. If there's any configuration, as I mentioned, that can always be added by additional CLI commands.

So now let's go ahead and enable Manage by MIST. So as I mentioned earlier, let's go ahead and enable Manage by MIST. And we can do that for all devices in just a single click.

We do not have to manually do that for all devices. So I click on this particular checkmark next to Status and click on More and Enable Switch Configuration. As you can see, there is a warning here that says that if you have anything that is assigned via the CLI, please ensure that that will be overwritten.

So please take care of that. So what this does is at this point, all of the configuration that we built through the fabric will be pushed to the devices. Your responsibility as a network administrator is to ensure that the configuration that you've been managing through the CLI is the same as the configuration that you see in the downloaded configuration file.

And if you see that there is something that's missing, then you need to rectify that or add through additional CLI commands or perhaps go back to the Campus Fabric and edit the fields provided there. So now that we've reviewed the configuration for Campus Fabric core distribution, let's have a look at the topology itself. And we assume that it's been a while.

So BGP would have come up by now in the underlay and overlay and also the tunnels would have established between the core and the distribution devices. So as you can see, I am in the EVPN-CRV topology that I named and I can see two core devices, two distribution and one access. As I can see, if I click on the core device, all the properties that we saw earlier are available as well.

You would see some green and red links and they are not just the status of that link, but they also depict the traffic flow. So what I mean by that is if you see a thick link, that basically tells you that there's more traffic between those two devices versus if you look at distribution and access. So a good point of comparison would be if the link between core 1 and distribution 2 is thicker than distribution and core 2, you would know that there is more traffic passing through the left link versus the right link.

And that's a very useful way to understand how the traffic flow is working and if, you know, some sort of equal path load balancing is in play or not. So now that we've reviewed the topology itself, we know that since we know we see all these green links, but what if you saw red links and what if you saw some BGP issues over there or if you were seeing some errors? We can always click on a particular device and click on switch insights and see what's happening on that box. And we know for a fact that there are DDoS violations happening.

DDoS violations aren't a problem all the time, but if something's happening repetitively, then that is something that needs to be looked into. We see that there are a bunch of DDoS violations here, but we also see that at the time when we built the topology, the last BGP pure state change was open confirmed to established. Of course, we know that looking at the green links that the neighborhood is up, but if it wasn't, you can always come ahead and look at the switch insights and see that your BGP has gone through its regular steps of coming to an established state.

If for whatever reason, you'd also like to look at the device itself and log into the CLI, if you're used to operating a device a certain way, we've also provided an option for you to click on the remote shell for any device and a pop up window will open right here on the screen, using which you can run any outputs as you'd like. So let's go ahead and check BGP summary as we saw earlier. As we can see, BGP has been up here for 42 minutes.

Let's look at our EVPN database. We see a bunch of MAC addresses in the EVPN database. We see some updated timestamps as well.

Let's look at the Ethernet switching MAC table as well. Of course, we know that all of these devices have been populated. There are a bunch of devices that we have that are locally connected to this particular core device.

Now that we've looked at the topology itself, we know that the topology is up and running. What do you do on day two when your network environment requirements grow? You want to access more devices? You want to add more distribution devices? You can always edit the configuration and add more devices as your needs grow. There is no limit to the number of devices you can add.

There's always a minimum requirement, but there's no maximum limitation here. What if you want to add more networks? You want to do some more segmentation? Similar to what we showed you earlier, you can always come in and create new networks or add existing networks. Nothing changes really from that point.

You can always come in and modify the connectivity between these devices. This concludes our session for EVPN Campus Fabric Core Distribution. I hope that there are some good takeaways for you from this video.

If there's input for us, please send me an email at archada.juniper.net. Thank you.