Explains VXLAN EVPN border gateway concepts and provides step-by-step guidance for configuring VXLAN infrastructure, virtual routing and forwarding stretch, and bridge domain configurations in Application Centric Infrastructure environments.
Beginning with Release 6.1(1), a new node type ACI Border Gateways (ACI BGW) is available as a new feature on Cisco ACI.
Procedures in this document describe how to configure ACI Border Gateways by using the GUI and REST API. You cannot configure ACI Border Gateways through the NX-OS style CLI at this time.
ACI border gateways
ACI border gateways enable the seamless extension of virtual routing and forwarding instances and bridge domains between Cisco ACI and VXLAN EVPN domains.
ACI border gateway implementation
ACI border gateways connect Cisco ACI fabrics to remote VXLAN EVPN fabrics and provide the components required to extend VRFs, bridge domains, policies, and services across the fabrics.
ACI border gateway deployment
ACI border gateways provide VXLAN connectivity between Cisco ACI and remote VXLAN EVPN domains.
Guidelines and limitations for ACI border gateways
ACI border gateways have specific hardware, software, configuration, and interoperability requirements for connections to VXLAN EVPN fabrics.
Discover ACI border gateways
Register leaf nodes as ACI border gateways by preconfiguring the nodes or by using DHCP discovery.
Configure a VXLAN Infra L3Out by using the GUI
Configure ACI border gateway nodes and interfaces to establish eBGP underlay adjacencies with devices in the intersite network.
Configure a VXLAN site ID
Assign the unique VXLAN site ID required to configure a border gateway set policy.
Create border gateway sets by using the GUI
Configure a border gateway set to assign external data-plane tunnel endpoint addresses to the border gateways in each pod.
Create remote VXLAN fabrics by using the GUI
Configure a remote VXLAN fabric policy to provide control-plane peering through the associated border gateway set.
Configure a VXLAN VRF stretch by using the GUI
Stretch a tenant VRF between Cisco ACI and VXLAN EVPN domains to enable routed communication through VXLAN data-plane encapsulation.
Configure a VXLAN bridge domain stretch by using the GUI
Stretch a tenant bridge domain between Cisco ACI and VXLAN EVPN domains to enable bridged communication through VXLAN data-plane encapsulation.
Create a VXLAN stretched bridge domain selector
Classify EVPN Type-2 routes received from remote Cisco NX-OS border gateways into an endpoint security group.
Create an external subnet selector
Classify EVPN Type-5 prefixes received from remote Cisco NX-OS border gateways into an endpoint security group.
Configure a remote security group tag for an endpoint security group
Assign a remote security group tag to an endpoint security group for policy-aware communication between Cisco ACI and a Cisco NX-OS site.
Create a custom VXLAN QoS policy by using the GUI
Configure ingress and egress rules that control the priority and marking of traffic between Cisco ACI and VXLAN EVPN fabrics.
Configure aggregated BUM storm control on an ACI border gateway
Rate-limit aggregated broadcast, unknown unicast, and multicast traffic across the DCI links on an ACI border gateway.