Use Case and Reference Architecture
There are two main use cases that will be addressed as part of this JVDE.
- Inter-VRF Traffic : In an EVPN/VXLAN data center fabric, the SRX4600 firewall is configured with all the Virtual Routing and Forwarding (VRF) instances, configuration covered in section SRX Configuration. Inter-VRF traffic is forwarded to the SRX firewall by leaf (through spine), the SRX Series Firewall applies appropriate security policies on the inner VXLAN packet header. Based on the security policies, SRX then routes the traffic toward its intended destination while preserving VXLAN encapsulation across the fabric—without terminating the VXLAN tunnel on the firewall. This design eliminates the need for ACL configurations on the fabric switches.
- North-South: North-South traffic (fabric‑ to‑ Internet) is sent through the SRX firewall, which applies both basic and advanced security policies. Outbound traffic is routed through ‑the SRX using the default route injected by the underlying fabric architecture from the border leaf.
Figure 1 shows the EVPN-VXLAN architecture with SRX devices, and Figure 2 shows the typical traffic flow through this architecture.
Figure 1: Architecture: With
SRX Peering with the Spine
Figure 2: Traffic Flow: With
SRX Peering with the Spine