Capstone: Spine-Leaf VXLAN Build

CCNP Data Center — DCCOR track EVE-NG — Nexus / ACI lab

مقصدObjectiveObjective

اس capstone میں آپ مکمل spine-leaf VXLAN/EVPN fabric بنائیں گے: 2 spines، 2 leaves، underlay OSPF، BGP EVPN اور end-to-end host connectivity۔Is capstone mein aap mukammal spine-leaf VXLAN/EVPN fabric banayenge: 2 spines, 2 leaves, underlay OSPF, BGP EVPN aur end-to-end host connectivity.In this capstone you will build a complete spine-leaf VXLAN/EVPN fabric: 2 spines, 2 leaves, underlay OSPF, BGP EVPN and end-to-end host connectivity.

آسان مثالSimple AnalogySimple Analogy

یہ capstone پورے ماڈل ہوائی جہاز کو جوڑنے جیسا ہے: جو حصے آپ نے الگ الگ بنائے (NX-OS، vPC concepts، VXLAN، EVPN) اب ایک اڑتی ہوئی مشین میں جڑ جائیں گے۔ اگر ایک حصہ غلط ہوا تو نہیں اڑے گا — اس لیے ہر قدم پر تصدیق کرتے جائیں۔Ye capstone poore model hawai jahaz ko jorne jaisa hai: jo hisse aap ne alag alag banaye (NX-OS, vPC concepts, VXLAN, EVPN) ab ek urte hue machine mein jur jayenge. Agar ek hissa ghalat hua to nahi urega — is liye har qadam par tasdeeq karte jayein.This capstone is like assembling a full model airplane: every part you built separately (NX-OS, vPC concepts, VXLAN, EVPN) now clicks together into one flying machine. If one piece is wrong, it will not fly — so verify as you go.

سیٹ اپLab SetupLab Setup

EVE-NG میں: 2x Nexus spines (Spine-1، Spine-2) اور 2x Nexus leaves (Leaf-1، Leaf-2)۔ ہر leaf ہر spine سے جڑا ہو۔ Leaf-1 پر ایک host (VLAN 10) اور Leaf-2 پر ایک host (VLAN 10)۔EVE-NG mein: 2x Nexus spines (Spine-1, Spine-2) aur 2x Nexus leaves (Leaf-1, Leaf-2). Har leaf har spine se jura ho. Leaf-1 par ek host (VLAN 10) aur Leaf-2 par ek host (VLAN 10).In EVE-NG: 2x Nexus spines (Spine-1, Spine-2) and 2x Nexus leaves (Leaf-1, Leaf-2). Every leaf connects to every spine. One host on Leaf-1 (VLAN 10) and one on Leaf-2 (VLAN 10).

اقداماتStepsSteps

Step 1

Topology plan: Leaf-1 loopback 10.1.1.1/32، Leaf-2 loopback 10.1.1.2/32، spines 10.2.2.1/32 اور 10.2.2.2/32۔ VNI 10010 VLAN 10 carry کرے گا۔ کسی ڈیوائس کو چھونے سے پہلے اسے بنا لیں۔Topology plan: Leaf-1 loopback 10.1.1.1/32, Leaf-2 loopback 10.1.1.2/32, spines 10.2.2.1/32 aur 10.2.2.2/32. VNI 10010 VLAN 10 carry karega. Kisi device ko chhoone se pehle isay bana lein.Topology plan: Leaf-1 loopback 10.1.1.1/32, Leaf-2 loopback 10.1.1.2/32, spines 10.2.2.1/32 and 10.2.2.2/32. VNI 10010 carries VLAN 10. Draw it before touching any device.

Step 2

Leaf-1 کی بنیاد: hostname، overlay features اور OSPF میں loopback۔ Leaf-2 پر اس کا آئینہ (mirror) دہرائیں۔Leaf-1 ki bunyad: hostname, overlay features aur OSPF mein loopback. Leaf-2 par is ka aaina (mirror) dohrayein.Leaf-1 basics: hostname, overlay features and the loopback in OSPF. Repeat the mirror image on Leaf-2.

configure terminal
hostname Leaf-1
feature nv overlay
feature bgp
feature interface-vlan
interface loopback0
ip address 10.1.1.1/32
ip router ospf UNDERLAY area 0.0.0.0
end

Step 3

Leaf-1 کے دونوں spines تک uplinks (routed interfaces)۔ تصدیق کریں کہ دونوں OSPF neighbors up آ گئے۔Leaf-1 ke dono spines tak uplinks (routed interfaces). Tasdeeq karein ke dono OSPF neighbors up aa gaye.Leaf-1 uplinks to both spines (routed interfaces). Confirm both OSPF neighbors come up.

configure terminal
interface ethernet 1/1
no switchport
ip address 10.10.1.1/30
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
interface ethernet 1/2
no switchport
ip address 10.10.2.1/30
ip router ospf UNDERLAY area 0.0.0.0
no shutdown
end
show ip ospf neighbors

Step 4

Leaf-1 سے دونوں spines تک BGP EVPN peering (دونوں leaves پر)۔ Spines route reflector کا کام کرتے ہیں۔Leaf-1 se dono spines tak BGP EVPN peering (dono leaves par). Spines route reflector ka kaam karte hain.BGP EVPN peering from Leaf-1 to both spines (on both leaves). The spines act as route reflectors.

configure terminal
router bgp 65001
neighbor 10.2.2.1 remote-as 65001
update-source loopback0
neighbor 10.2.2.2 remote-as 65001
update-source loopback0
address-family l2vpn evpn
neighbor 10.2.2.1 activate
neighbor 10.2.2.2 activate
send-community extended
exit
exit
end

Step 5

VNI/VLAN mapping، NVE tunnel اور SVI gateway (دونوں leaves پر)۔ چیک کریں کہ NVE peers بن گئے۔VNI/VLAN mapping, NVE tunnel aur SVI gateway (dono leaves par). Check karein ke NVE peers ban gaye.VNI/VLAN mapping, NVE tunnel and the SVI gateway (on both leaves). Check that NVE peers form.

configure terminal
vlan 10
vn-segment 10010
exit
interface nve1
no shutdown
source-interface loopback0
member vni 10010 mcast-group 239.1.1.1
exit
interface vlan 10
ip address 192.168.10.1/24
no shutdown
end
show nve peers

Step 6

Hosts connect کریں: ہر leaf پر VLAN 10 میں access ports۔ Hosts SVI (.1) کو اپنا gateway بنائیں۔Hosts connect karein: har leaf par VLAN 10 mein access ports. Hosts SVI (.1) ko apna gateway banayein.Connect the hosts: access ports in VLAN 10 on each leaf. Hosts use the SVI (.1) as their gateway.

configure terminal
interface ethernet 1/3
switchport mode access
switchport access vlan 10
no shutdown
end

Step 7

آخری control-plane check: دونوں spines تک BGP EVPN established، دونوں leaves پر VNIs programmed۔Aakhri control-plane check: dono spines tak BGP EVPN established, dono leaves par VNIs programmed.Final control-plane check: BGP EVPN established to both spines, VNIs programmed on both leaves.

show bgp l2vpn evpn summary
show nve vni

Step 8

End-to-end test: Leaf-1 کے host سے Leaf-2 کے host کو ping کریں۔ یہ کام کرنا چاہیے باوجود اس کے کہ hosts الگ switches پر ہیں۔End-to-end test: Leaf-1 ke host se Leaf-2 ke host ko ping karein. Ye kaam karna chahiye bawajood is ke ke hosts alag switches par hain.End-to-end test: ping from the Leaf-1 host to the Leaf-2 host. It must work even though the hosts are on different switches.

تصدیقVerifyVerify

Leaf-1 کا host Leaf-2 کے host کو کامیابی سے ping کرے، show nve peers میں دونوں leaves ہوں، اور show bgp l2vpn evpn summary میں sessions established نظر آئیں۔Leaf-1 ka host Leaf-2 ke host ko kamyabi se ping kare, show nve peers mein dono leaves hon, aur show bgp l2vpn evpn summary mein sessions established nazar aayein.The host on Leaf-1 pings the host on Leaf-2 successfully, show nve peers lists both leaves, and show bgp l2vpn evpn summary shows established sessions.

show nve peers
show bgp l2vpn evpn summary

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Leaf کے پار ping fail ہو رہا ہے۔Leaf ke paar ping fail ho raha hai.The cross-leaf ping fails.

✅ Bottom-up چیک کریں: کیا دور کا loopback reachable ہے (underlay)؟ کیا NVE peers بنے ہیں؟ اس کے بعد ہی EVPN routes دیکھیں۔Bottom-up check karein: kya door ka loopback reachable hai (underlay)? Kya NVE peers bane hain? Us ke baad hi EVPN routes dekhein.Check bottom-up: is the remote loopback reachable (underlay)? Are NVE peers formed? Only then look at EVPN routes.

⚠️ NVE peers بن گئے لیکن EVPN routes نہیں آ رہے۔NVE peers ban gaye lekin EVPN routes nahi aa rahe.NVE peers form but no EVPN routes arrive.

✅ تصدیق کریں کہ neighbor address-family l2vpn evpn کے اندر activate ہے اور دونوں sides پر send-community extended set ہے۔Tasdeeq karein ke neighbor address-family l2vpn evpn ke andar activate hai aur dono sides par send-community extended set hai.Confirm the neighbor is activated inside address-family l2vpn evpn and that send-community extended is set on both sides.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ Spine-leaf VXLAN build کا سب سے مشکل حصہ کیا ہے؟Spine-leaf VXLAN build ka sab se mushkil hissa kya hai?What is the hardest part of a spine-leaf VXLAN build?

Underlay اور overlay کا فرق سمجھنا: پہلے underlay (OSPF reachability) ٹھیک کریں، اس کے بعد overlay بنائیں۔Underlay aur overlay ka farq samajhna: pehle underlay (OSPF reachability) theek karein, us ke baad overlay banayein.Understanding the difference between underlay and overlay: fix the underlay (OSPF reachability) first, only then build the overlay.

❓ کیسے ثابت کریں گے کہ ٹریفک واقعی VXLAN سے جا رہا ہے؟Kaise sabit karenge ke traffic waqai VXLAN se ja raha hai?How do you prove traffic is actually going over VXLAN?

show nve peers اور encapsulation counters استعمال کریں۔ Underlay میں آپ کو صرف VTEP addresses نظر آتے ہیں — اصل host traffic tunnel کے اندر چھپا ہوتا ہے۔show nve peers aur encapsulation counters istemal karein. Underlay mein aap ko sirf VTEP addresses nazar aate hain — asal host traffic tunnel ke andar chhupa hota hai.Use show nve peers and the encapsulation counters. In the underlay you only ever see VTEP addresses — the real host traffic is hidden inside the tunnel.