我有2个leaf,leaf2有两个实例user1和user2,2个实例进行交叉,都能学到33.33.33.33的路由,但是这个路由没有变成5类由发leaf2的evpn邻居
bgp 100
peer 2.2.2.2 as-number 100
peer 2.2.2.2 connect-interface LoopBack0
#
address-family ipv4 unicast
#
address-family l2vpn evpn
advertise l3vpn route
peer 2.2.2.2 enable
#
ip vpn-instance user1
#
address-family ipv4 unicast
import-route direct
#
address-family vpnv4
#
ip vpn-instance user2
#
address-family ipv4 unicast
network 33.33.33.33 255.255.255.255
[leaf2]dis cur conf vpn
#
ip vpn-instance user1
route-distinguisher 1:1
#
address-family ipv4
vpn-target 2:2 import-extcommunity
vpn-target 2:2 export-extcommunity
#
address-family evpn
vpn-target 1:1 import-extcommunity
vpn-target 1:1 export-extcommunity
#
ip vpn-instance user2
route-distinguisher 1:10
#
address-family ipv4
vpn-target 2:2 import-extcommunity
vpn-target 2:2 export-extcommunity
#
address-family evpn
vpn-target 1:1 import-extcommunity
vpn-target 1:1 export-extcommunity
#
return
[leaf2]dis cur conf bgp
#
bgp 100
peer 2.2.2.2 as-number 100
peer 2.2.2.2 connect-interface LoopBack0
#
address-family ipv4 unicast
#
address-family l2vpn evpn
advertise l3vpn route
peer 2.2.2.2 enable
#
ip vpn-instance user1
#
address-family ipv4 unicast
import-route direct
#
address-family vpnv4
#
ip vpn-instance user2
#
address-family ipv4 unicast
network 33.33.33.33 255.255.255.255
#
return
[leaf2]dis ip rov
[leaf2]dis ip rou
[leaf2]dis ip routing-table vpn
[leaf2]dis ip routing-table vpn-instance use
[leaf2]dis ip routing-table vpn-instance user2
Destinations : 17 Routes : 17
Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/32 Direct 0 0 127.0.0.1 InLoop0
33.33.33.33/32 Direct 0 0 127.0.0.1 InLoop0
44.44.44.44/32 BGP 130 0 127.0.0.1 InLoop0
127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0
127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0
127.255.255.255/32 Direct 0 0 127.0.0.1 InLoop0
192.168.1.0/24 BGP 130 0 192.168.1.254 Vsi1
192.168.1.1/32 BGP 255 0 1.1.1.1 Vsi3
192.168.1.2/32 BGP 130 0 192.168.1.2 Vsi1
192.168.1.254/32 BGP 130 0 127.0.0.1 InLoop0
192.168.2.0/24 BGP 130 0 192.168.2.254 Vsi2
192.168.2.1/32 BGP 255 0 1.1.1.1 Vsi3
192.168.2.2/32 BGP 130 0 192.168.2.2 Vsi2
192.168.2.254/32 BGP 130 0 127.0.0.1 InLoop0
224.0.0.0/4 Direct 0 0 0.0.0.0 NULL0
224.0.0.0/24 Direct 0 0 0.0.0.0 NULL0
255.255.255.255/32 Direct 0 0 127.0.0.1 InLoop0
[leaf2]dis ip routing-table vpn-instance user1
Destinations : 19 Routes : 19
Destination/Mask Proto Pre Cost NextHop Interface
0.0.0.0/32 Direct 0 0 127.0.0.1 InLoop0
33.33.33.33/32 BGP 130 0 127.0.0.1 InLoop0
44.44.44.44/32 Direct 0 0 127.0.0.1 InLoop0
127.0.0.0/8 Direct 0 0 127.0.0.1 InLoop0
127.0.0.1/32 Direct 0 0 127.0.0.1 InLoop0
127.255.255.255/32 Direct 0 0 127.0.0.1 InLoop0
192.168.1.0/24 Direct 0 0 192.168.1.254 Vsi1
192.168.1.1/32 BGP 255 0 1.1.1.1 Vsi3
192.168.1.2/32 Direct 0 0 192.168.1.2 Vsi1
192.168.1.254/32 Direct 0 0 127.0.0.1 InLoop0
192.168.1.255/32 Direct 0 0 192.168.1.254 Vsi1
192.168.2.0/24 Direct 0 0 192.168.2.254 Vsi2
192.168.2.1/32 BGP 255 0 1.1.1.1 Vsi3
192.168.2.2/32 Direct 0 0 192.168.2.2 Vsi2
192.168.2.254/32 Direct 0 0 127.0.0.1 InLoop0
192.168.2.255/32 Direct 0 0 192.168.2.254 Vsi2
224.0.0.0/4 Direct 0 0 0.0.0.0 NULL0
224.0.0.0/24 Direct 0 0 0.0.0.0 NULL0
255.255.255.255/32 Direct 0 0 127.0.0.1 InLoop0
[leaf2]
<leaf1>dis bgp l2vpn evpn
BGP local router ID is 1.1.1.1
Status codes: * - valid, > - best, d - dampened, h - history
s - suppressed, S - stale, i - internal, e - external
a - additional-path
Origin: i - IGP, e - EGP, ? - incomplete
Total number of routes from all PEs: 5
Route distinguisher: 1:1(user1)
Total number of routes: 7
* >i Network : [2][0][48][7425-8ae3-f293][32][192.168.1.2]/136
NextHop : 3.3.3.3 LocPrf : 100
PrefVal : 0 OutLabel : NULL
MED : 0
Path/Ogn: i
* >i Network : [2][0][48][7425-8ae3-f293][32][192.168.2.2]/136
NextHop : 3.3.3.3 LocPrf : 100
PrefVal : 0 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [5][0][24][192.168.1.0]/80
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [5][0][24][192.168.2.0]/80
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
* >i Network : [5][0][32][44.44.44.44]/80
NextHop : 3.3.3.3 LocPrf : 100
PrefVal : 0 OutLabel : NULL
MED : 0
Path/Ogn: ?
* > Network : [5][0][32][192.168.1.254]/80
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [5][0][32][192.168.2.254]/80
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
Route distinguisher: 100:10
Total number of routes: 5
* >i Network : [2][0][48][7425-8ae3-f293][32][192.168.1.2]/136
NextHop : 3.3.3.3 LocPrf : 100
PrefVal : 0 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [2][0][48][aabb-cc00-0130][0][0.0.0.0]/104
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [2][0][48][aabb-cc80-0100][32][192.168.1.1]/136
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [3][0][32][1.1.1.1]/80
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
* >i Network : [3][0][32][3.3.3.3]/80
NextHop : 3.3.3.3 LocPrf : 100
PrefVal : 0 OutLabel : NULL
MED : 0
Path/Ogn: i
Route distinguisher: 100:20
Total number of routes: 5
* >i Network : [2][0][48][7425-8ae3-f293][32][192.168.2.2]/136
NextHop : 3.3.3.3 LocPrf : 100
PrefVal : 0 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [2][0][48][aabb-cc00-0130][0][0.0.0.0]/104
NextHop : 0.0.0.0 LocPrf : 100
PrefVal : 32768 OutLabel : NULL
MED : 0
Path/Ogn: i
* > Network : [2][0][48][aabb-cc80-0100][32][192.168.2.1]/136
NextHop : 0.0.0.0 LocPrf : 100
Inactive timeout reached, logging out.
33.33.33.33是user2配置的本地环回口
EVPN‑VXLAN 5 类路由不发布问题分析(leaf2 上 33.33.33.33/32)
现象复盘
leaf2 上两个 VPN 实例user1、user2通过vpn‑target 2:2互相导入导出,user2 本地 network 33.33.33.33/32,user1 可以学到这条 BGP 路由;
leaf2 全局 BGP 下配置了address‑family l2vpn evpn、advertise l3vpn route,邻居也已经 enable;
33.33.33.33 没有生成 EVPN Type‑5 路由发给 leaf1,但 44.44.44.44 可以正常生成 5 类路由发给 leaf1;
查看 leaf1 的dis bgp l2vpn evpn,只能看到 44.44.44.44 的 [5] 类路由,看不到 33.33.33.33。
关键对比:
44.44.44.44/32:在 user1 实例内是Direct 路由,可以正常生成 EVPN‑5;
33.33.33.33/32:在 user2 是本地 network,但是进入 user1 实例之后是BGP (vpnv4) 学到的路由。
核心根因
advertise l3vpn route 只对本 VPN 实例内部的有效最优路由做 EVPN‑5 发布。
user2 实例:33.33.33.33 是本地 network,在 user2 路由表是本地有效;
但:user2 的 evpn 地址族下没有配置 vpn‑target 匹配导出这条路由到 EVPN。
看现有配置:
plaintext
ip vpn-instance user2
route-distinguisher 1:10
address-family ipv4
vpn-target 2:2 import-extcommunity
vpn-target 2:2 export-extcommunity
# 注意:下面evpn地址族vpn‑target是1:1,只做EVPN导入导出,**没有关联ipv4的VPN‑target 2:2**
address-family evpn
vpn-target 1:1 import-extcommunity
vpn-target 1:1 export-extcommunity
H3C EVPN‑L3VPN(advertise l3vpn route)规则:
把 VPN‑IPv4 路由转换 EVPN Type‑5,使用的是该 VPN 实例 address‑family ipv4 下的 export vpn‑target,放到 EVPN 路由的 ext‑community;
同时,该 VPN 实例必须在address‑family evpn下有对应的 export vpn‑target,才能把这条 Type‑5 路由发送给 EVPN 邻居。
现在 user2:
address‑family ipv4 export‑target:2:2;
address‑family evpn 只有1:1的 import/export,没有 2:2;
→ user2 内部 33.33.33.33 这条路由想要生成 EVPN‑5,生成出来携带 ext‑community 2:2,但是evpn 地址族没有 export 2:2,路由直接被过滤,不会发给 EVPN 邻居。
补充:为什么 44.44.44.44 能发?
44.44.44.44 在 user1 实例:
ipv4 地址族 export‑target 2:2;
evpn 地址族 export‑target 1:1;
user1 内 44.44.44.44 是本实例直连,生成 Type‑5 携带 ext‑community 2:2;同时 user1 evpn 下有vpn‑target 1:1 export‑extcommunity,该 RT 用于 EVPN 邻居发布策略,路由允许发送出去。
修复方案二选一
方案 1(推荐,补齐 evpn 地址族 vpn‑target)
plaintext
ip vpn-instance user2
address-family evpn
vpn-target 2:2 import-extcommunity
vpn-target 2:2 export-extcommunity
含义:EVPN 地址族也识别 RT‑2:2,本实例 ipv4 导出 RT=2:2 的路由转成 EVPN‑5 后,可以正常向 EVPN 邻居发布。
配置完成后,在 leaf2 执行:
plaintext
reset bgp l2vpn evpn
display bgp l2vpn evpn vpn-instance user2
观察是否出现 [5][0][32][33.33.33.33]/80 的 Type‑5 路由。
方案 2:调整 user2 ipv4 的 export‑target 改为 1:1,和 evpn 地址族保持一致
plaintext
ip vpn-instance user2
address-family ipv4
undo vpn-target 2:2 export-extcommunity
vpn-target 1:1 export-extcommunity
注意:此方案会改变原有 vpn‑target 交叉逻辑,如果 user1/user2 之间需要通过 vpn‑target 2:2 互访,不能用此方案。
排查验证命令(定位用)
在 leaf2 查看 user2 是否生成 Type‑5 路由(关键!如果这里看不到,就是本地生成阶段过滤)
plaintext
display bgp l2vpn evpn vpn-instance user2
如果配置完,该输出里面没有 33.33.33.33 的 5 类路由,说明本地转换发布被 RT 过滤;如果这里有,leaf1 看不到,那是 leaf1 的 evpn vpn‑target import 问题。
查看 BGP VPNv4 路由:
plaintext
display bgp vpnv4 all 33.33.33.33 32
看该路由的 Export‑RT 标记。
确认 advertise l3vpn route 配置位置正确性:
必须配置在bgp‑address‑family l2vpn evpn视图下,不是 VPN 实例内,用户当前配置位置是正确的。
额外注意点
advertise l3vpn route只会发布本 VPN 实例路由表内最优路由;
user1 学到的 33.33.33.33 是从 vpnv4 学来的,不会再由 user1 重新生成一份 EVPN‑5;路由起源在 user2,必须由 user2 实例输出 Type‑5。
不要混淆两套 RT:
address‑family ipv4 RT:用于 VPNv4 交叉;
address‑family evpn RT:用于 EVPN 路由接收 / 发送过滤;
EVPN‑5 类路由转换时,携带的 ext‑community 是 ipv4 族的 export RT;但路由能否发送给 EVPN 邻居,受 evpn 地址族下 export‑target 控制,这是 H3C 设备非常容易踩坑点。
故障复现逻辑总结
user2 ipv4 export RT=2:2 → 33.33.33.33 转 EVPN‑5,携带 ext‑community:2:2;
user2 evpn 地址族只有 RT‑1:1,没有 export‑RT 2:2;
BGP EVPN 输出过滤,该 Type‑5 路由本地生成但不发给 EVPN 邻居,leaf1 完全收不到。
不是本实例始发的,从别的途径学到的vpnv4路由不会被通告给evpn邻居?
不是本实例始发的,从别的途径学到的vpnv4路由不会被通告给evpn邻居?
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
33.33.33.33是user2配置的本地环回口