Cisco APIC Layer 3 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 3 Networking Configuration Guide, Release 6.2(x)

Configure an SR-MPLS infra L3Out using the GUI

Want to summarize with AI?

Log in

Configure an SR-MPLS infrastructure L3Out to enable segment routing MPLS connectivity between ACI border leaf switches and external data center provider edge routers.


Enable SR-MPLS connectivity between ACI fabric and external networks by configuring the required infrastructure L3Out with underlay BGP-LU and overlay MP-BGP EVPN sessions.

The SR-MPLS infra L3Out is configured on the border leaf switch to establish underlay BGP-LU and overlay MP-BGP EVPN sessions for SR-MPLS handoff. This L3Out is scoped to a pod or remote leaf switch site, and multiple SR-MPLS infra L3Outs can be configured per pod or site.

You will configure the following components:

  • Nodes: Only leaf switches (border leaf and remote leaf) are supported. Each L3Out can contain border leaf switches from one pod or remote leaf switches from the same site. Nodes can belong to multiple SR-MPLS infra L3Outs if connecting to multiple SR-MPLS domains.

  • Interfaces: Supported types include routed interfaces/sub-interfaces and routed port channels/sub-interfaces with any VLAN tag support for sub-interfaces.

  • QoS rules: Configure MPLS ingress and egress rules through MPLS QoS policy. Without a custom policy, ingressing MPLS traffic receives default QoS level.

The configuration includes both underlay (BGP-LU and IPv4 peer) and overlay (MP-BGP EVPN peer) components.

Before you begin

  • Review the SR-MPLS guidelines and limitations provided in the SR-MPLS guidelines documentation, especially the L3Out-specific guidelines and limitations.

  • Configure an MPLS custom QoS policy if required for your deployment.

Procedure

1.

Navigate to Tenants > infra > Networking > SR-MPLS Infra L3Outs.

2.

Right-click on SR-MPLS Infra L3Outs and choose Create SR-MPLS Infra L3Out.

The Connectivity window appears.

3.

In the Connectivity window, enter the necessary information.

  1. In the Name field, enter a name for the SR-MPLS Infra L3Out.

    The name can be up to 64 alphanumeric characters and cannot be changed after saving.

  2. In the Layer 3 Domain field, choose an existing Layer 3 domain or choose Create L3 Domain to create a new layer 3 domain.

  3. In the Pod field, choose a pod, if you have a Multi-Pod configuration.

    If you do not have a Multi-Pod configuration, leave the selection at pod 1.

  4. (Optional) In the MPLS Custom QoS Policy field, choose an existing QoS policy or choose Create MPLS Custom QoS Policy to create a new QoS policy.

    If you do not create a custom QoS policy, default values are assigned: all incoming MPLS traffic is classified into QoS Level 3, original DSCP values are retained, and packets are forwarded with default MPLS EXP value (0).

  5. Navigate to the BGP-EVPN Connectivity area.

  6. (Optional) In the BFD Multihop Policy field, choose an existing BFD multihop policy or choose Create BFD Multihop Node Policy to create a new policy.

    For MP-BGP EVPN multihop sessions, BFD enables faster BGP session termination based on BFD timers instead of regular BGP timers.

  7. In the BGP-EVPN Remote IPv4 Address field, enter the MP-BGP EVPN remote IPv4 address.

    This is the loopback address of the DC-PE for overlay configuration.

  8. In the Remote ASN field, enter a number that uniquely identifies the neighbor autonomous system of the DC-PE.

    The Autonomous System Number can be in 4-byte plain format from 1 to 4294967295. ACI does not support ASDOT or ASDOT+ format AS numbers.

  9. In the TTL field, enter the connection time to live (TTL).

    The range is from 2 to 255 hops.

  10. Click Next.

    The Nodes and Interfaces window appears.

4.

In the Nodes and Interfaces window, enter the necessary information to configure the border leaf nodes and interfaces.

  1. In the Node Profile Name and Interface Profile Name fields, determine if you want to use the default naming convention for the node profile and interface profile names.

    The default node profile name is L3Out-name_nodeProfile, and the default interface profile name is L3Out-name_interfaceProfile.

  2. (Optional) In the BFD Interface Policy field, choose an existing BFD interface policy or choose Create BFD Interface Policy to create a new BFD interface policy.

  3. In the Transport Data Plane field, determine the type of routing for the handoff on the Cisco ACI border leaf switches.

    Options are MPLS for Multiprotocol Label Switching or SR-MPLS for segment routing MPLS.

  4. In the Interface Types area, make the necessary selections in the Layer 3 and Layer 2 fields.

    Layer 3 options: Interface (physical port or direct port-channel) or Sub-Interface (Layer 3 sub-interface). Layer 2 options: Port or Direct Port Channel.

  5. From the Node ID field drop-down menu, choose the border leaf switch for the L3Out.

    For multi-pod configurations, only leaf switches from the selected pod are displayed. If a router ID is already configured, you can use the same ID or configure a different one (requiring maintenance mode and node reload).

  6. In the Router ID field, enter a unique router ID (IPv4 or IPv6 address) for the border leaf switch.

    The router ID must be unique across all border leaf switches and the DC-PE. The BGP-EVPN Loopback and MPLS Transport Loopback fields are automatically populated with this value.

  7. (Optional) Enter an IP address in the BGP-EVPN Loopback field, if necessary.

    The BGP-EVPN loopback is used for control plane sessions. We recommend using a different IP address from the router ID for BGP-EVPN sessions, but the same loopback for BGP-EVPN and MPLS transport.

  8. In the MPLS Transport Loopback field, enter the address for the MPLS transport loopback.

    The MPLS transport loopback builds the data plane session between the ACI border leaf switch and DC-PE, becoming the next-hop for advertised prefixes.

  9. In the Segment ID (SID) Index field, enter the SID index.

    The SID index (0 to 4294967295) is configured per node for the MPLS transport loopback and must be unique across the entire segment routing domain.

  10. If you selected Port in the Layer 2 area, choose a port from the Interface field drop-down list.

  11. If you selected Direct Port Channel in the Layer 2 area, choose the port channel from the PC Paths field drop-down list.

  12. If you selected Sub-Interface in the Layer 3 area, enter the encapsulation in the VLAN Encap field.

  13. In the MTU (bytes) field, enter the maximum transmit unit of the external network.

    Acceptable entries are 576-9216. To inherit the value, enter inherit.

  14. In the IPv4 Address field, enter an IP address for the BGP-Label unicast source.

    This is the IP address assigned to the configured Layer 3 interface/sub-interface/port channel.

  15. In the Peer IPv4 Address field, enter the BGP-Label unicast peer IP address.

    This is the interface IP address of the router directly connected to the border leaf switch.

  16. In the Remote ASN field, enter the BGP-Label Autonomous System Number of the directly-connected router.

  17. Configure additional interfaces for this node if needed by clicking + in the Interfaces area.

  18. Configure additional nodes for this SR-MPLS infra L3Out if needed by clicking + in the Nodes area.

  19. Click Finish to complete the SR-MPLS Infra L3Out configuration.

The SR-MPLS infrastructure L3Out is configured with the specified nodes, interfaces, and BGP sessions, enabling SR-MPLS connectivity between the ACI fabric and external networks. The border leaf switches can now establish underlay BGP-LU and overlay MP-BGP EVPN sessions with the data center provider edge routers.