Professional Documents
Culture Documents
• Controllerless technology
Abstracting Service from Infrastructure: Network as a Plug & Play Utility • Functions as an underlay as well as
an overlay technology
IP subnet 3 IP subnet 2
VLAN 30
Logical
Physical
BVLAN #1
BVLAN #2
MPLS layers
e.g. Draft Rosen
Connectivity Services independent from Infrastructure
Layer 3 Virtualized
Multicast Service Protocol
Infrastructure
Horizontally Independent
e.g. PIM
Layer 3 Multicast Service
Protocol
Infrastructure
e.g. RIP/OSPF
Layer 3 Unicast Protocol
Service Infrastructure
Physical Physical
Ethernet Ethernet
Infrastructure Infrastructure
CONFIDENTIAL. ©EXTREME NETWORKS, INC. ALL RIGHTS RESERVED.
Shortest Path Bridging - Fabric
§ Enable IS-IS Globally
§ Enable IS-IS per interface
§ IS-IS forms adjacencies Extreme Management Center
spbm
router isis
manual-area 49.0000
spbm 1
spbm 1 b-vid 4051-4052 primary 4051
spbm 1 nick-name 0.00.81
system-id 02bb.0000.8100
exit
vlan create 4051 name "B-VLAN-1" type spbm-bvlan
vlan create 4052 name "B-VLAN-2" type spbm-bvlan
VLAN 10 VLAN 10
VLAN 10 VLAN 10
I-SID 20010
FABRIC
VLAN 10 VLAN 10
IP subnet 1 IP subnet 2
VLAN 10 VLAN 10
I-SID 20010
FABRIC
VLAN 10 VLAN 10
BCB
BEB BEB
VLAN 20
VRF-lite deployment
Traditional
10.1.1.0/24 10.1.2.0/24
Tenant X Tenant X
10.1.1.0/24 L3 Virtual Service Network I-SID 300 10.2.1.0/24
VLAN 11 VLAN 12
10.1.2.0/24 10.2.1.0/24
‒ No I-SID (shortcut)
‒ Prefer L3VSN to attach users
BEB BEB BEB
‒ But users can be attached BEB
VLAN / IP Net 1
§ Provision service at the edge
VLAN / IP Net 2
‒ Create VLANs BCB BCB
‒ Create IP Networks in VLANs BEB
‒ Create L3VSN
‒ Attach L2VSN to L3VSN BEB
BEB BEB
BEB
§ Routing anywhere in the Fabric
‒ L3VSN or IP Shortcut
‒ IPv4 and IPv6 networks BCB
I-SID 3000001
BCB
BEB
BEB
VLAN 21
IP Net3
BCB
BEB I-SID 2000021 BEB
VLAN 21 VLAN 21
DC-1 DC-2
‒ Create L3VSN
‒ Attach L2VSN to L3VSN BEB
BEB 3000001
I-SID BEB
BEB
§ Routing anywhere in the Fabric
‒ L3VSN or IP Shortcut VRRP
‒ IPv4 and IPv6 networks BCB BCB
VLAN 21 VLAN 21
§ Use VRRP for Redundancy BEB IP Net3 IP Net3
‒ VRRP in the Fabric BEB
VLAN 21 VLAN 21
DC-1 DC-2
PIM-SM PIM-SM
Traditional
PIM-SM PIM-SM
OSPF OSPF OSPF OSPF IGMP Snoop
IGMP Snoop
Sender 1 Receiver 1
PIM Rendezvous
Point
IGMP
Join 239.0.0.10
‒ Class D IP address Extreme Management Center
IGMP
239.0.0.10
Receiver
IGMP
Join 239.0.0.10
Receiver
INFRASTRUCTURE
multicast enabled FA/UNI NNI NNI UNI
VIRTUALIZED SERVICES
L3VSN
‒ Switched UNI VLAN 201 VLAN 202
1.20.1.0/24 I-SID 3000002 1.20.2.0/24
‒ Transparent UNI 3000:20:1::0/64 3000:20:2::0/64
‒ ETREE UNI
VLAN 21
I-SID
VLAN 21 1.30.21.0/24
L2VSN 2000021
3000:30:21::0/64 VLAN 302
+ I-SID 3000003 1.30.2.0/24
L3VSN VLAN 22 3000:30:2::0/64
I-SID
20 VLAN 22 1.30.22.0/24 CONFIDENTIAL. ©EXTREME NETWORKS, INC. ALL RIGHTS RESERVED.
2000022
3000:30:22::0/64
L2VSN – UNI types - C-VLAN UNI
§ UNI is an Ethernet port / MLT § Reverse MAC learning is still used, so can be used with 3 or more
§ Ethernet UNI port / MLT is not VLAN tag aware end-points in an any-any service
§ Packets with or without a VLAN q-tag are transported into the ‒ NOTE: Learning across all VLANs (Shared VLAN learning)
L2VSN § MLT Transparent UNI ports are supported (on VOSS VSPs even
§ Untagged control traffic (STP, VLACP, LACP, LLDP, etc) is with LACP)
transparently forwarded § Transparent UNIs should not be assigned to the same I-SID as
‒ VLACP/LACP PDUs are forwarded (VOSS: unless configured on Switched UNI or CVLAN UNIs as this would create inconsistencies
UNI port / MLT) in the handling of egress q-tags
‒ Flow Control Pause frames remain link local and are not
transported CONFIDENTIAL. ©EXTREME NETWORKS, INC. ALL RIGHTS RESERVED.
L2VSN – UNI types - ETREE UNI
§ A Private VLAN (PVLAN) allows member ports to Hypervisor
be take one of 3 possible roles:
‒ Isolated: No communication with other
Isolated ports in VLAN and across ETREE BEB node BEB node
Fabric
service; always untagged Promiscous Connect Trunk
‒ Promiscuous: Connectivity with all devices in Untagged Port 1 tagged Port 1
the PVLAN and across ETREE service; always Vswitch
untagged Private Private
Isolated
VLAN L2VSN 2200001 VLAN
‒ Trunk: Use to interconnect PVLAN to other Untagged Port 2
101/102 101/102
PVLAN capable devices (e.g. VMware ESX)
§ Fabric Connect uniquely allows PVLANs to be Isolated Isolated
Untagged Port 3 Untagged Port 2
extended as a L2VSN service by simply assigning
an I-SID to the PVLAN/CVLAN
§ Switched UNIs and regular CVLAN UNIs can be
assigned to the same ETREE I-SID in which
case they will have Promiscuous connectivity into
the service
‒ However, if doing so, the CVLAN/Switched UNI
must use the exact same VLAN-id as the
PVLAN Primary VLAN-id, since these VLAN-ids
are used within the ETREE L2VSN service
SPB Backbone
FA: Fabric Attach
BEB
(Fabric Connect)
BCB BCB
Branch Core
• 802.1Qcj Automatic
BEB
Internet
SPB extended
Attachment to Provider BEB
over WAN
(Fabric Extend) BCB BCB
Hypervisors
Fabric Connect Simplicity
Comparaison configuration underlay en CLI
Fabric Connect EVPN/VXLAN
BEB1:1(config)#spbm Leaf1(config)# mtu 9216
BEB1:1(config)#router isis Leaf1(config)# ip mtu 9168
BEB1:1(config-isis)#spbm 1 Leaf1(config)# interface Ethernet 0/3
BEB1:1(config-isis)#spbm 1 b-vid 4051,4052 primary 4051 Leaf1(conf-if-eth-0/3)# ip address 10.20.10.0/31
BEB1:1(config-isis)#spbm 1 nick-name 0.00.41 Leaf1(conf-if-eth-0/3)# description To-Spine1
BEB1:1(config-isis)#manual-area 49.0000 Leaf1(conf-if-eth-0/3)# no shut
BEB1:1(config-isis)#system-id 02bb.0000.4100 Leaf1(conf-if-eth-0/3)# exit
BEB1:1(config-isis)#exit Leaf1(config)# interface Loopback 2
BEB1:1(config)#interface gigabitEthernet 1/11-1/14 Leaf1(config-Loopback-2)# ip address 10.10.10.1/32
BEB1:1(config-if)#isis Leaf1(config-Loopback-2)# no shut
BEB1:1(config-if)#isis spbm 1 Leaf1(config-Loopback-2)# exit
BEB1:1(config-if)#isis enable Leaf1(config)# router bgp
BEB1:1(config-if)#exit Leaf1(config-bgp-router)# local-as 64100
BEB1:1(config)#vlan create 4051 type spbm-bvlan Leaf1(config-bgp-router)# fast-external-fallover
BEB1:1(config)#vlan create 4052 type spbm-bvlan Leaf1(config-bgp-router)# neighbor 10.20.10.1 remote-as 65000
BEB1:1(config)#router isis enable Leaf1(config-bgp-router)# neighbor 10.20.10.1 bfd
Leaf1(config-bgp-router)# neighbor 10.30.10.1 remote-as 65000
Leaf1(config-bgp-router)# neighbor 10.30.10.1 bfd
Leaf1(config-bgp-router)# address-family ipv4 unicast
Leaf1(config-bgp-ipv4u)# maximum-paths 8
Leaf1(config-bgp-ipv4u)# exit
Leaf1(config-bgp-router)# address-family l2vpn evpn
Leaf1(config-bgp-evpn)# neighbor 10.20.10.1 encapsulation vxlan
Leaf1(config-bgp-evpn)# neighbor 10.20.10.1 allowas-in 1
Leaf1(config-bgp-evpn)# neighbor 10.20.10.1 enable-peer-as-check
Leaf1(config-bgp-evpn)# neighbor 10.20.10.1 activate
Leaf1(config-bgp-evpn)# neighbor 10.30.10.1 encapsulation vxlan
Leaf1(config-bgp-evpn)# neighbor 10.30.10.1 allowas-in 1
Leaf1(config-bgp-evpn)# neighbor 10.30.10.1 enable-peer-as-check
Leaf1(config-bgp-evpn)# neighbor 10.30.10.1 activate
29 Leaf1(config-bgp-evpn)# exit CONFIDENTIAL. ©EXTREME NETWORKS, INC. ALL RIGHTS RESERVED.
Leaf1(config-bgp-router)# address-family ipv4 unicast
Leaf1(config-bgp-ipv4u)# network 10.10.10.1/32
Comparaison d’ajout d’un service en CLI
Fabric Connect EVPN/VXLAN
Association d’un VLAN à un Service Association d’un VLAN à un Service
BEB1:1(config)#vlan create 42 name MyVlan type port-mstprstp 0 Leaf1(config)# vlan 100
BEB1:1(config)#vlan members add 42 1/9 Leaf1(config-vlan-100)# suppress-arp
BEB1:1(config)#vlan i-sid 42 12000555 Leaf1(config-vlan-100)# suppress-nd
Leaf1(config-vlan-100)# exit
Leaf1(config)# interface Ethernet 0/1
Leaf1(conf-if-eth-0/1)# switchport
Leaf1(conf-if-eth-0/1)# switchport mode trunk
Leaf1(conf-if-eth-0/1)# switchport trunk allowed vlan add 100
Leaf1(conf-if-eth-0/1)# no shut
Leaf1(conf-if-eth-0/1)# exit
Leaf1(config)# evpn evpn1
Leaf1(config-evpn-evpn1)# route-target both auto ignore-as
Leaf1(config-evpn-evpn1)# rd auto
Leaf1(config-evpn-evpn1)# vlan add 100
Leaf1(config-evpn-evpn1)# exit
Leaf1(config)# overlay-gateway PoD1
Leaf1(config-overlay-gw-PoD1)# type layer2-extension
Leaf1(config-overlay-gw-PoD1)# ip interface Loopback 2
Leaf1(config-overlay-gw-PoD1)# map vni auto
Leaf1(config-overlay-gw-PoD1)# activate
Leaf1(config-overlay-gw-PoD1)# exit
• Contrôle d'accès réseau granulaire • Visibilité et contrôle des applications • Alarme et gestion des événements • Solution de conformité des
basé sur les rôles et priorités de couche 7 configurations réseaux
• Configuration, inventaire et gestion
• Évaluation flexible • 1000s signatures applicatives du changement entièrement automatisée
personnalisation des app.
• Application de la conformité • Zero Touch Provisionning • Analyse et évalue les
• Tableaux de bord, diagnostics et configurations réseau pour la
• Portails d'invités et de remédiation dépannage • Capacity Planning
conformité
• Suivi des utilisateurs et des systèmes • Découverte et topologie
• État, performances et signalement • Rapports de modèles de
d'extrémité des menaces • Fabric Manager conformité prêts à l'emploi et
• Réponse d'incident automatisée définis par l'utilisateur, prêts à
l'emploi et prêts à l'emploi
ExtremeConnect
• Permet l'automatisation et l'intégration avec VMware, MS, OpenStack, BYOD, MDM, sécurité, NGFW, etc.
• Fournit un accès direct à l'API Open Management Center - Build-Your-Own-Integration
XMC : Comprendre votre infrastructure
§ Tableaux de bord pour comprendre les
utilisateurs, les équipements réseaux et
bien plus
33
XMC : Exploitez votre infrastructure
§ Voir
§ Statuts des équipements
§ Localisation des machines
§ Identité des utilisateurs
§ Gérer
§ Mise à jour des équipements
§ Alarmes et évènements
§ Gestion des Configurations
§ Rapports
§ FlexViews
§ Statistiques
§ Historique d’Alarmes
§ Diagnostiques
34
XMC : ZTP+
§ Automatisation des déploiements :
§ Mise à jour de l’équipement
§ Configuration de tous les paramètres
§ Ajout dans XMC
Extreme
DNS DHCP MGMT
P1
P2
P1
FAN
1
2
1
ACT Level
Management
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48
Cloud
TM
STACK NO. CONSOLE Summit X670V
My IP Request 1
Extreme
My IP Response Control
CONNECT Response
IMAGEUPGRADE Response
CONFIGURATION Response
35
XMC : Fabric Manager
§ Voir
§ Statuts des équipements
§ Topologie de la Fabric
§ Liste des Services
§ Provisionner
§ Création de Services
§ Affectation de Services
§ Diagnostiques
§ Voir les chemins de la Fabric
§ PingFabric
§ TracerouteFabric
36
XMC : Workflow
Automatisez la routine :
• Provisionnez automatiquement
l'ensemble de votre réseau avec
Zero Touch sécurisé (Gagnez du
temps sur les opérations
• Élimine les erreurs humaines et
s'adapte automatiquement aux
changements
37
XMC : ExtremeConnect
§ Sécurisation de bout-en-
bout
– DC
– MDM
– NGFW
– Etc.
Roadmap/New features
VOSS 8.3 : Increased Automation to Improve Efficiency
VOSS EXOS
Details
• XIQ agent
• LEM Advanced Software License
• VOSS and EXOS support
• Secure Boot capable
Enterprise SKUs
• 7720: 32x100G
• 7520: 48xSFP28 + 8x100G
• 7520: 48x10GBT + 6x100G
BCB1-1 BCB2-1
Router @
BEB1-1 BEB2-1
Fabric
Extend (via
x695)
BEB1-2
BEB2-2
BCB1-2 BCB2-2
PC SHOWROOM
PC MEETING ROOM
BCB1-1 BCB2-1
Shuttle Shuttle
ESXi-1 ESXi-2
VM Debian
Vmotion