Hello,
I'm trying to understand the whole SDN concept and started with setting up a test environment.
Currently I have 2 nodes in a cluster and was able to setup a SDN evpn network.
I have the following:
What is puzzling me
:
I believe that Zones are used to isolate networks.
Communication between vnets in the same zone is possible, but not between vnets in different zones.
Zones can have a exitnode configured to route traffic from the vnets running in that zone.
Zone isolation works in my setup as long as the zone don't share the same exitnode.
If multiple zone are configured with the same exitnode, then traffic is getting routed between those zones.
Is it possible to isolate the zones from each other but still share the same exitnode?
Sorry for the noob questions, but your help is much appreciated.
I'm trying to understand the whole SDN concept and started with setting up a test environment.
Currently I have 2 nodes in a cluster and was able to setup a SDN evpn network.
I have the following:
Code:
evpn: ctrl1
asn 65000
peers 10.40.0.11,10.40.0.12
subnet: zone1-10.1.1.0-24
vnet vnet1
gateway 10.1.1.1
snat 1
subnet: zone1-10.1.2.0-24
vnet vnet2
gateway 10.1.2.1
subnet: zone2-10.2.1.0-24
vnet vnet3
gateway 10.2.1.1
snat 1
vnet: vnet1
zone zone1
tag 11000
vnet: vnet2
zone zone1
tag 12000
vnet: vnet3
zone zone2
tag 21000
evpn: zone1
controller ctrl1
vrf-vxlan 10000
exitnodes pvel1
ipam pve
mac AE:4C:6D:ED:C9:2E
evpn: zone2
controller ctrl1
vrf-vxlan 20000
exitnodes pvel1
ipam pve
mac 9E:AB:81:76:EF:74
What is puzzling me
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Smile :) :)"
I believe that Zones are used to isolate networks.
Communication between vnets in the same zone is possible, but not between vnets in different zones.
Zones can have a exitnode configured to route traffic from the vnets running in that zone.
Zone isolation works in my setup as long as the zone don't share the same exitnode.
If multiple zone are configured with the same exitnode, then traffic is getting routed between those zones.
Is it possible to isolate the zones from each other but still share the same exitnode?
Sorry for the noob questions, but your help is much appreciated.