Hello,
i was able to peer Fortigate VM (acts as VTEP) with Proxmox SND EVPN. Everything is working fine, but i can't see Fortigate as "Exit node" on proxmox cluster.
I suspect i need to announce default route from Fortigate?
I guest i need to add?
Here is my frr.conf
i was able to peer Fortigate VM (acts as VTEP) with Proxmox SND EVPN. Everything is working fine, but i can't see Fortigate as "Exit node" on proxmox cluster.
I suspect i need to announce default route from Fortigate?
I guest i need to add?
Code:
route-map MAP_VTEP_IPV4_IN permit 10
match ip address prefix-list only_default
exit
router bgp 65000
address-family ipv4 unicast
neighbor VTEP activate
neighbor VTEP route-map MAP_VTEP_IPV4_IN in
Here is my frr.conf
Code:
frr version 8.5.2
frr defaults datacenter
hostname proxmox1-1
log syslog informational
service integrated-vtysh-config
!
!
vrf vrf_z10001
vni 10001
ip route 10.0.21.0/24 null0
ip route 10.0.22.0/24 null0
ip route 10.0.23.0/24 null0
ip route 10.0.24.0/24 null0
exit-vrf
!
vrf vrf_z10002
vni 10002
ip route 10.0.20.0/24 null0
ip route 10.0.22.0/24 null0
ip route 10.0.23.0/24 null0
ip route 10.0.24.0/24 null0
ipv6 route 2001:1ab9:f002:2::/118 null0
exit-vrf
!
vrf vrf_z10007
vni 10007
ip route 10.0.20.0/24 null0
ip route 10.0.21.0/24 null0
ip route 10.0.23.0/24 null0
ip route 10.0.24.0/24 null0
ipv6 route 2001:1ab9:f002:2::/118 null0
exit-vrf
!
vrf vrf_z10009
vni 10009
ip route 10.0.20.0/24 null0
ip route 10.0.21.0/24 null0
ip route 10.0.22.0/24 null0
ip route 10.0.24.0/24 null0
ipv6 route 2001:1ab9:f002:2::/118 null0
exit-vrf
!
vrf vrf_z10015
vni 10015
ip route 10.0.20.0/24 null0
ip route 10.0.21.0/24 null0
ip route 10.0.22.0/24 null0
ip route 10.0.23.0/24 null0
ipv6 route 2001:1ab9:f002:2::/118 null0
exit-vrf
!
router bgp 65000
bgp router-id 10.0.4.1
no bgp hard-administrative-reset
no bgp default ipv4-unicast
coalesce-time 1000
no bgp graceful-restart notification
neighbor VTEP peer-group
neighbor VTEP remote-as 65000
neighbor VTEP bfd
neighbor 10.0.4.3 peer-group VTEP
neighbor 10.0.4.4 peer-group VTEP
neighbor 10.0.7.2 peer-group VTEP
!
address-family ipv4 unicast
import vrf vrf_z10001
import vrf vrf_z10002
import vrf vrf_z10007
import vrf vrf_z10009
import vrf vrf_z10015
exit-address-family
!
address-family ipv6 unicast
import vrf vrf_z10001
import vrf vrf_z10002
import vrf vrf_z10007
import vrf vrf_z10009
import vrf vrf_z10015
exit-address-family
!
address-family l2vpn evpn
neighbor VTEP activate
neighbor VTEP route-map MAP_VTEP_IN in
neighbor VTEP route-map MAP_VTEP_OUT out
advertise-all-vni
exit-address-family
exit
!
router bgp 65000 vrf vrf_z10001
bgp router-id 10.0.4.1
no bgp hard-administrative-reset
no bgp graceful-restart notification
!
address-family ipv4 unicast
redistribute connected
exit-address-family
!
address-family ipv6 unicast
redistribute connected
exit-address-family
!
address-family l2vpn evpn
default-originate ipv4
default-originate ipv6
exit-address-family
exit
!
router bgp 65000 vrf vrf_z10002
bgp router-id 10.0.4.1
no bgp hard-administrative-reset
no bgp graceful-restart notification
!
address-family ipv4 unicast
redistribute connected
exit-address-family
!
address-family ipv6 unicast
redistribute connected
exit-address-family
!
address-family l2vpn evpn
default-originate ipv4
default-originate ipv6
exit-address-family
exit
!
router bgp 65000 vrf vrf_z10007
bgp router-id 10.0.4.1
no bgp hard-administrative-reset
no bgp graceful-restart notification
!
address-family ipv4 unicast
redistribute connected
exit-address-family
!
address-family ipv6 unicast
redistribute connected
exit-address-family
!
address-family l2vpn evpn
default-originate ipv4
default-originate ipv6
exit-address-family
exit
!
router bgp 65000 vrf vrf_z10009
bgp router-id 10.0.4.1
no bgp hard-administrative-reset
no bgp graceful-restart notification
!
address-family ipv4 unicast
redistribute connected
exit-address-family
!
address-family ipv6 unicast
redistribute connected
exit-address-family
!
address-family l2vpn evpn
default-originate ipv4
default-originate ipv6
exit-address-family
exit
!
router bgp 65000 vrf vrf_z10015
bgp router-id 10.0.4.1
no bgp hard-administrative-reset
no bgp graceful-restart notification
!
address-family ipv4 unicast
redistribute connected
exit-address-family
!
address-family ipv6 unicast
redistribute connected
exit-address-family
!
address-family l2vpn evpn
default-originate ipv4
default-originate ipv6
exit-address-family
exit
!
ip prefix-list only_default seq 1 permit 0.0.0.0/0
!
ipv6 prefix-list only_default_v6 seq 1 permit ::/0
!
route-map MAP_VTEP_IN deny 1
match ip address prefix-list only_default
exit
!
route-map MAP_VTEP_IN deny 2
match ipv6 address prefix-list only_default_v6
exit
!
route-map MAP_VTEP_IN deny 3
match ip address prefix-list only_default
exit
!
route-map MAP_VTEP_IN deny 4
match ipv6 address prefix-list only_default_v6
exit
!
route-map MAP_VTEP_IN deny 5
match ip address prefix-list only_default
exit
!
route-map MAP_VTEP_IN deny 6
match ipv6 address prefix-list only_default_v6
exit
!
route-map MAP_VTEP_IN deny 7
match ip address prefix-list only_default
exit
!
route-map MAP_VTEP_IN deny 8
match ipv6 address prefix-list only_default_v6
exit
!
route-map MAP_VTEP_IN deny 9
match ip address prefix-list only_default
exit
!
route-map MAP_VTEP_IN deny 10
match ipv6 address prefix-list only_default_v6
exit
!
route-map MAP_VTEP_IN permit 11
exit
!
route-map MAP_VTEP_OUT permit 1
exit
!
line vty
Last edited: