Segment Routing v6 Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

Segment Routing v6 Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

IPv4 L3VPNs over SRv6

Want to summarize with AI?

Log in

Explains how SRv6 transports IPv4 L3VPN traffic and provides guidance for configuring and verifying VPNv4 services, route leaking, SID allocation, and dual-stack operation.


IPv4 L3VPNs over SRv6 is an SRv6 L3VPN service that

  • provides Layer 3 VPN connectivity specifically for IPv4 traffic

  • utilizes an SRv6 network as the underlying transport, and

  • enables enterprise IPv4 internet connectivity.

This service allows operators to establish Layer 3 VPNs for IPv4 traffic using a SRv6 infrastructure. It leverages advanced routing capabilities to ensure efficient and scalable connectivity, particularly for enterprise environments requiring internet access through VPNs. It supports VPNv4 services, including route leaking between Global Routing Tables (GRT) and Virtual Routing and Forwarding (VRF) instances.


SRv6 VPN BGP route leaking

SRv6 VPN BGP route leaking is a BGP routing mechanism that

  • enables the controlled exchange of routing information between Global Routing Tables (GRT) and Virtual Routing and Forwarding (VRF) instances within an SRv6 network

  • facilitates VPNv4 services, and

  • is essential for providing enterprise IPv4 internet connectivity by allowing specific routes to be shared across different routing contexts.

Table 1. Feature History Table

Feature Name

Release

Description

SRv6 VPN BGP Route Leaking

Release 25.4.1

Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*)

*This feature is supported on:

  • 8711-48Z-M

  • 8011-32Y8L2H2FH

  • 8011-12G12X4Y-A/D

SRv6 VPN BGP Route Leaking

Release 25.1.1

Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])

This feature is now supported on:

  • 8712-MOD-M

  • 8011-4G24Y4H-I

SRv6 VPN BGP Route Leaking

Release 24.4.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100, K100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*)

*This feature is supported on:

  • 8212-48FH-M

  • 8711-32FH-M

  • 8712-MOD-M

  • 88-LC1-36EH

  • 88-LC1-12TH24FH-E

  • 88-LC1-52Y8H-EM

SRv6 VPN BGP Route Leaking

Release 7.8.1

This feature supports SRv6 VPN Route-leaking between Global Routing Table (GRT) and Virtual Routing and Forwarding (VRF). This enables Enterprise IPv4 internet connectivity.

This service allows operators to establish Layer 3 VPNs for IPv4 traffic using a SRv6 infrastructure. It leverages advanced routing capabilities to ensure efficient and scalable connectivity, particularly for enterprise environments requiring internet access through VPNs. It supports VPNv4 services, including route leaking between Global Routing Tables (GRT) and Virtual Routing and Forwarding (VRF) instances.

Key concepts of SRv6 VPN BGP route leaking

  • Global Routing Table (GRT): The Global Routing Table (GRT) is the main routing table within a router, containing all routes that are not associated with a specific VPN or VRF. It is used for forwarding traffic that is not part of any VPN.

  • Virtual Routing and Forwarding (VRF) Instance: A VRF instance is a virtual router within a physical router, allowing multiple independent routing tables to coexist on the same device. Each VRF instance maintains its own routing table, forwarding table, and interfaces, providing logical separation for different VPNs or customer networks.


Per-VRF-46 allocation mode

Per-VRF-46 allocation mode is an SRv6 SID allocation mode that

  • is configured within BGP under an address family

  • assigns a specific uDT46 SID to various types of routes when advertised to remote peers, and

  • aggregates multiple routes into a single entity for forwarding decisions, improving network efficiency and scalability.

Table 2. Feature History Table

Feature Name

Release

Description

Per-Prefix SRv6 Locator Assignment

Release 25.4.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*)

*This feature is supported on:

  • 8011-32Y8L2H2FH

  • 8011-12G12X4Y-A/D

Per-Prefix SRv6 Locator Assignment

Release 25.1.1

Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])

This feature is now supported on:

  • 8712-MOD-M

  • 8011-4G24Y4H-I

Per-Prefix SRv6 Locator Assignment

Release 24.4.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*)

*This feature is supported on:

  • 8212-48FH-M

  • 8711-32FH-M

  • 88-LC1-36EH

  • 88-LC1-12TH24FH-E

  • 88-LC1-52Y8H-EM

Per-Prefix SRv6 Locator Assignment

Release 7.8.1

This feature allows you to assign a specific SRv6 locator for a given prefix or a set of prefixes (IPv4/IPv6 GRT, IPv4/IPv6 VPN).

The egress PE advertises the prefix with the specified locator. This allows for per-prefix steering into desired transport behaviors, such as Flex Algo.


Dual-stack L3VPN services for SRv6 Micro-SID on IPv4 and IPv6

Dual-stack L3VPN services is an SRv6 L3VPN capability that

  • supports dual-stack (VPNv4/VPNv6) VRFs

  • enables SRv6 L3VPN service for both IPv4 (uDT4) and IPv6 (uDT6) on the same interface, sub-interface, or VRF, and

  • allows operators to simultaneously and independently access IPv4 and IPv6 without protocol translation, ensuring high processing efficiency and zero information loss.

Table 3. Feature History Table

Feature Name

Release

Description

Dual-Stack L3VPN Services (IPv4, IPv6) (SRv6 Micro-SID)

Release 25.4.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*)

*This feature is supported on:

  • 8011-32Y8L2H2FH

  • 8011-12G12X4Y-A/D

Dual-Stack L3VPN Services (IPv4, IPv6) (SRv6 Micro-SID)

Release 25.1.1

Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])

This feature is now supported on:

  • 8712-MOD-M

  • 8011-4G24Y4H-I

Dual-Stack L3VPN Services (IPv4, IPv6) (SRv6 Micro-SID)

Release 24.4.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*)

*This feature is supported on:

  • 8212-48FH-M

  • 8711-32FH-M

  • 88-LC1-36EH

  • 88-LC1-12TH24FH-E

  • 88-LC1-52Y8H-EM

Dual-Stack L3VPN Services (IPv4, IPv6) (SRv6 Micro-SID)

Release 7.8.1

This feature introduces support for Dual-stack (VPNv4/VPNv6) VRFs.

VPNv4/VPNv6 Dual-stack supports both IPv4 (uDT4) and IPv6 (uDT6) based SRv6 L3VPN service on the same interface, sub-interface, or VRF.

Dual stacking allows operators to access both IPv4 and IPv6 simultaneously and independent of each other. It avoids the need to translate between two protocol stacks. This results in high processing efficiency and zero information loss.

This feature is designed to provide comprehensive L3VPN connectivity over an SRv6 network for environments that require seamless handling of both IPv4 and IPv6 traffic.


Configure SRv6-based IPv4 L3VPN

To enable SRv6-based L3VPN services for IPv4 traffic by configuring SRv6 under BGP, specifying locators, and defining SID allocation modes.

SRv6-based L3VPNs allow for flexible and scalable IPv4 VPN services over an SRv6 network. The assignment of SRv6 locators and SID allocation modes can be configured at various levels within the BGP configuration.

Procedure

  1. Assign an SRv6 locator under BGP.

    • Use Case 1: Assigning SRv6 locator globally.

      This example shows how to enable SRv6 and configure the SRv6 locator name under BGP Global:

      Node1(config)# router bgp 100
      Node1(config-bgp)# segment-routing srv6
      Node1(config-bgp-gbl-srv6)# locator Node1-locator
      Node1(config-bgp-gbl-srv6)# exit
      Node1(config-bgp)# address-family vpnv4 unicast
      Node1(config-bgp-af)# exit
      Node1(config-bgp)# neighbor 3001::1:1:1:4
      Node1(config-bgp-nbr)# remote-as 100
      Node1(config-bgp-nbr)# address-family vpnv4 unicast
      Node1(config-bgp-nbr-af)# exit
      Node1(config-bgp-nbr)# exit
      Node1(config-bgp)# vrf vrf_cust1
      Node1(config-bgp-vrf)# rd 100:1
      Node1(config-bgp-vrf)# address-family ipv4 unicast
      Node1(config-bgp-vrf-af)# commit
      
      

      Running configuration

      router bgp 100
       segment-routing srv6
        locator Node1-locator
       !
       address-family vpnv4 unicast
       !
       neighbor 3001::1:1:1:4
        remote-as 100
        address-family vpnv4 unicast
        !
       !
       vrf vrf_cust1
        rd 100:1
        address-family ipv4 unicast
        !
       !
      !
      end
      
    • Use Case 2: Assigning SRv6 locator for all VRFs.

      This example shows how to enable SRv6 and configure the SRv6 locator for all VRFs under VPNv4 Address Family, with per-VRF label allocation mode:

      Node1(config)# router bgp 100
      Node1(config-bgp)# address-family vpnv4 unicast
      Node1(config-bgp-af)# vrf all
      Node1(config-bgp-af-vrfall)# segment-routing srv6
      Node1(config-bgp-af-vrfall-srv6)# locator Node1-locator
      Node1(config-bgp-af-vrfall-srv6)# alloc mode per-vrf
      Node1(config-bgp-af-vrfall-srv6)# exit
      Node1(config-bgp-af-vrfall)# exit
      Node1(config-bgp-af)# exit
      Node1(config-bgp)# neighbor 3001::1:1:1:4
      Node1(config-bgp-nbr)# remote-as 100
      Node1(config-bgp-nbr)# address-family vpnv4 unicast
      Node1(config-bgp-nbr-af)# exit
      Node1(config-bgp-nbr)# exit
      Node1(config-bgp)# vrf vrf_cust1
      Node1(config-bgp-vrf)# rd 100:1
      Node1(config-bgp-vrf)# address-family ipv4 unicast
      Node1(config-bgp-vrf-af)# commit
      
      

      Running configuration

      router bgp 100
       address-family vpnv4 unicast
        vrf all
         segment-routing srv6
          locator Node1-locator
          alloc mode per-vrf
         !
        !
       !
       neighbor 3001::1:1:1:4
        remote-as 100
        address-family vpnv4 unicast
        !
       !
       vrf vrf_cust1
        rd 100:1
        address-family ipv4 unicast
        !
       !
      !
      end
      
    • Use Case 3: Assigning SRv6 Locator for a specific VRF

      To configure the SRv6 locator for a specific VRF under IPv4 Address Family and specify the allocation mode, use the following commands:

      This example shows how to configure the SRv6 locator for an individual VRF, with per-VRF label allocation mode:

      Node1(config)# router bgp 100
      Node1(config-bgp)# address-family vpnv4 unicast
      Node1(config-bgp-af)# exit
      Node1(config-bgp)# neighbor 3001::1:1:1:4
      Node1(config-bgp-nbr)# remote-as 100
      Node1(config-bgp-nbr)# address-family vpnv4 unicast
      Node1(config-bgp-nbr-af)# exit
      Node1(config-bgp-nbr)# exit
      Node1(config-bgp)# vrf vrf_cust1
      Node1(config-bgp-vrf)# rd 100:1
      Node1(config-bgp-vrf)# address-family ipv4 unicast
      Node1(config-bgp-vrf-af)# segment-routing srv6
      Node1(config-bgp-vrf-af-srv6)# locator Node1-locator
      Node1(config-bgp-vrf-af-srv6)# alloc mode per-vrf
      Node1(config-bgp-vrf-af-srv6)# commit
      
      

      Running Config

      router bgp 100
       address-family vpnv4 unicast
       !
       neighbor 3001::1:1:1:4
        remote-as 100
        address-family vpnv4 unicast
        !
       !
       vrf vrf_cust1
        rd 100:1
        address-family ipv4 unicast
         segment-routing srv6
          locator Node1-locator
          alloc mode per-vrf
         !
        !
       !
      !
      end
      

      This example shows how to configure the SRv6 locator for an individual VRF, with per-CE label allocation mode:

      Node1(config)# router bgp 100
      Node1(config-bgp)# address-family vpnv4 unicast
      Node1(config-bgp-af)# exit
      Node1(config-bgp)# neighbor 3001::1:1:1:4
      Node1(config-bgp-nbr)# remote-as 100
      Node1(config-bgp-nbr)# address-family vpnv4 unicast
      Node1(config-bgp-nbr-af)# exit
      Node1(config-bgp-nbr)# exit
      Node1(config-bgp)# vrf vrf_cust1
      Node1(config-bgp-vrf)# rd 100:1
      Node1(config-bgp-vrf)# address-family ipv4 unicast
      Node1(config-bgp-vrf-af)# segment-routing srv6
      Node1(config-bgp-vrf-af-srv6)# locator Node1-locator
      Node1(config-bgp-vrf-af-srv6)# alloc mode per-ce
      Node1(config-bgp-vrf-af-srv6)# commit
      
      

      Running Config

      router bgp 100
       address-family vpnv4 unicast
       !
       neighbor 3001::1:1:1:4
        remote-as 100
        address-family vpnv4 unicast
        !
       !
       vrf vrf_cust1
        rd 100:1
        address-family ipv4 unicast
         segment-routing srv6
          locator Node1-locator
          alloc mode per-ce
         !
        !
       !
      !
      
      
    • Use Case 4: Assigning SRv6 Locator for a specific prefix

      This use case provides the ability to assign a specific SRv6 locator for a given prefix or a set of prefixes. The egress PE advertises the prefix with the specified locator. This allows for per-prefix steering into desired transport behaviors, such as Flex Algo.

      The following example shows a route policy specifying the SID allocation mode with destination-based match:

      Node1(config)# route-policy set_per_prefix_locator_rpl
      Node1(config-rpl)# if destination in (1.1.1.0/24) then
      Node1(config-rpl-if)# set srv6-alloc-mode per-vrf locator locator1
      Node1(config-rpl-if)# elseif destination in (2.2.2.0/24) then
      Node1(config-rpl-elseif)# set srv6-alloc-mode per-vrf locator locator2
      Node1(config-rpl-elseif)# elseif destination in (3.3.3.0/24) then
      Node1(config-rpl-elseif)# set srv6-alloc-mode per-vrf
      Node1(config-rpl-elseif)# elseif destination in (4.4.4.0/24) then
      Node1(config-rpl-elseif)# set srv6-alloc-mode per-ce
      Node1(config-rpl-elseif)# else
      Node1(config-rpl-else)# drop
      Node1(config-rpl-else)# endif
      Node1(config-rpl)# end-policy
      Node1(config)#
      
      

      To assign an SRv6 locator for a specific prefix, configure a route policy to specify the SID allocation mode based on match criteria. Examples of match criteria are destination-based match or community-based match.

      • Supported SID allocation modes are per-VRF and per-CE.

      • For per-VRF allocation mode, you can also specify the SRv6 locator.

        • If an SRv6 locator is specified in the route policy, BGP will use that to allocate per-VRF SID. If the specified locator is invalid, the SID will not be allocated.

        • If an SRv6 locator is not specified in the route policy, the default locator configured under BGP is used to allocate the SID. If the default locator is not configured, then the SID will not be allocated.

      • Per-CE allocation mode always uses the default locator configured under BGP to allocate the SID.

  2. Verify that the local and received SIDs have been correctly allocated under VPNv4 and specific VRF (vrf_cust1).

    Example:

    Node1# show bgp vpnv4 unicast local-sids 
    BGP router identifier 1.1.1.1, local AS number 100
    BGP generic scan interval 60 secs
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0x0   RD version: 0
    BGP main routing table version 50
    BGP NSR Initial initsync version 18 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    BGP scan interval 60 secs
    
    Status codes: s suppressed, d damped, h history, * valid, > best
                  i - internal, r RIB-failure, S stale, N Nexthop-discard
    Origin codes: i - IGP, e - EGP, ? - incomplete
       Network            Local Sid                                   Alloc mode   Locator
    Route Distinguisher: 8:8
    *>i8.8.8.8/32         NO SRv6 Sid                                 -            -
    * i                   NO SRv6 Sid                                 -            -
    Route Distinguisher: 1.1.1.1:0 (default for vrf vrf_cust1)
    *> 1.1.1.0/24         fc00:0:1:40::                               per-vrf      locator1
    *> 2.2.2.0/24         fc00:8:1:40::                               per-vrf      locator2
    *> 3.3.3.0/24         fc00:9:1:40::                               per-vrf      locator4
    *> 1.1.1.5/32         NO SRv6 Sid                                 -            -
    *> 3.3.3.3/32         NO SRv6 Sid                                 -            -
    *>i8.8.8.8/32         NO SRv6 Sid                                 -            -
    
    
    Node1# show bgp vpnv4 unicast received-sids  
    BGP router identifier 1.1.1.1, local AS number 100
    BGP generic scan interval 60 secs
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0x0   RD version: 0
    BGP main routing table version 50
    BGP NSR Initial initsync version 18 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    BGP scan interval 60 secs
    
    Status codes: s suppressed, d damped, h history, * valid, > best
                  i - internal, r RIB-failure, S stale, N Nexthop-discard
    Origin codes: i - IGP, e - EGP, ? - incomplete
       Network            Next Hop                            Received Sid
    Route Distinguisher: 8:8
    *>i8.8.8.8/32         10.1.1.2                            fc00:0:2:42::
    * i                   2400:2020:42:2fff::1
                                                              fc00:0:2:42::
    Route Distinguisher: 1.1.1.1:0 (default for vrf vrf_cust1)
    *> 1.1.1.0/24         11.1.1.2                            NO SRv6 Sid
    *> 2.2.2.0/24         11.1.1.2                            NO SRv6 Sid
    *> 3.3.3.0/24         11.1.1.2                            NO SRv6 Sid
    *> 4.4.4.0/24         11.1.1.2                            NO SRv6 Sid
    *> 1.1.1.5/32         11.1.1.2                            NO SRv6 Sid
    *> 3.3.3.3/32         13.2.2.2                            NO SRv6 Sid
    *>i8.8.8.8/32         10.1.1.2                            fc00:0:2:42::
    
    
    Node1# show bgp vrf vrf_cust1 local-sids 
    BGP VRF vrf_cust1, state: Active
    BGP Route Distinguisher: 1.1.1.1:0
    VRF ID: 0x60000004
    BGP router identifier 1.1.1.1, local AS number 1
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0xe0000013   RD version: 37
    BGP main routing table version 37
    BGP NSR Initial initsync version 18 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    
    Status codes: s suppressed, d damped, h history, * valid, > best
                  i - internal, r RIB-failure, S stale, N Nexthop-discard
    Origin codes: i - IGP, e - EGP, ? - incomplete
       Network            Local Sid                                   Alloc mode   Locator
    Route Distinguisher: 1.1.1.1:0 (default for vrf vrf_cust1)
    *> 1.1.1.0/24         fc00:0:1:40::                               per-vrf      locator1
    *> 2.2.2.0/24         fc00:8:1:40::                               per-vrf      locator2
    *> 3.3.3.0/24         fc00:9:1:40::                               per-vrf      locator4
    *> 4.4.4.0/24         fc00:9:1:41::                               per-ce       locator4
    *> 1.1.1.5/32         NO SRv6 Sid                                 -            -
    *> 3.3.3.3/32         NO SRv6 Sid                                 -            -
    *>i8.8.8.8/32         NO SRv6 Sid                                 -            -
    
    
    Node1# show bgp vrf vrf_cust1 received-sids 
    BGP VRF vrf_cust1, state: Active
    BGP Route Distinguisher: 1.1.1.1:0
    VRF ID: 0x60000004
    BGP router identifier 1.1.1.1, local AS number 1
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0xe0000013   RD version: 37
    BGP main routing table version 37
    BGP NSR Initial initsync version 18 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    
    Status codes: s suppressed, d damped, h history, * valid, > best
                  i - internal, r RIB-failure, S stale, N Nexthop-discard
    Origin codes: i - IGP, e - EGP, ? - incomplete
       Network            Next Hop                            Received Sid
    Route Distinguisher: 1.1.1.1:0 (default for vrf vrf_cust1)
    *> 1.1.1.0/24         11.1.1.2                            NO SRv6 Sid
    *> 2.2.2.0/24         11.1.1.2                            NO SRv6 Sid
    *> 3.3.3.0/24         11.1.1.2                            NO SRv6 Sid
    *> 4.4.4.0/24         11.1.1.2                            NO SRv6 Sid
    *> 1.1.1.5/32         11.1.1.2                            NO SRv6 Sid
    *> 3.3.3.3/32         13.2.2.2                            NO SRv6 Sid
    *>i8.8.8.8/32         10.1.1.2                            fc00:0:2:42::
    

Configure per-VRF-46 label allocation mode

Procedure

Assign SRv6 locator
  • Enable SRv6 and configure the SRv6 locator for all VRFs under VPNv4/v6 address family, with per-VRF-46 label allocation mode:

    Node1(config)# router bgp 200
    Node1(config-bgp)# address-family vpnv4 unicast
    Node1(config-bgp-af)# vrf all
    Node1(config-bgp-af-vrfall)# segment-routing srv6
    Node1(config-bgp-af-vrfall-srv6)# locator Node1-locator
    Node1(config-bgp-af-vrfall-srv6)# alloc mode per-vrf-46
    Node1(config-bgp-af-vrfall-srv6)# exit
    Node1(config-bgp-af-vrfall)# exit
    Node1(config-bgp-af)# exit
    Node1(config-bgp)# address-family vpnv6 unicast
    Node1(config-bgp-af)# vrf all
    Node1(config-bgp-af-vrfall)# segment-routing srv6
    Node1(config-bgp-af-vrfall-srv6)# locator Node1-locator
    Node1(config-bgp-af-vrfall-srv6)# alloc mode per-vrf-46
    Node1(config-bgp-af-vrfall-srv6)# exit
    Node1(config-bgp-af-vrfall)# exit
    Node1(config-bgp-af)# exit
    Node1(config-bgp)# neighbor 3001::1:1:1:4
    Node1(config-bgp-nbr)# remote-as 100
    Node1(config-bgp-nbr)# address-family vpnv4 unicast
    Node1(config-bgp-nbr-af)# exit
    Node1(config-bgp-nbr)# exit
    Node1(config-bgp)# vrf vrf_cust1
    Node1(config-bgp-vrf)# rd 100:1
    Node1(config-bgp-vrf)# address-family ipv4 unicast
    Node1(config-bgp-vrf-af)# commit
    
    
  • Configure the SRv6 locator for an individual VRF with per-VRF label allocation mode:

    Node1(config)# router bgp 100
    Node1(config-bgp)# address-family vpnv4 unicast
    Node1(config-bgp-af)# exit
    Node1(config-bgp)# neighbor 3001::1:1:1:4
    Node1(config-bgp-nbr)# remote-as 100
    Node1(config-bgp-nbr)# address-family vpnv4 unicast
    Node1(config-bgp-nbr-af)# exit
    Node1(config-bgp-nbr)# exit
    Node1(config-bgp)# vrf vrf_cust1
    Node1(config-bgp-vrf)# rd 100:1
    Node1(config-bgp-vrf)# address-family ipv4 unicast
    Node1(config-bgp-vrf-af)# segment-routing srv6
    Node1(config-bgp-vrf-af-srv6)# locator Node1-locator
    Node1(config-bgp-vrf-af-srv6)# alloc mode per-vrf
    Node1(config-bgp-vrf-af-srv6)# commit
    
    
  • Configure the SRv6 locator for an individual VRF for both IPv4 and IPv6 address families, with per-VRF-46 label allocation mode:

    Node1(config)# router bgp 200
    Node1(config-bgp)# address-family vpnv4 unicast
    Node1(config-bgp-af)# exit
    Node1(config-bgp)# neighbor 3001::1:1:1:4
    Node1(config-bgp-nbr)# remote-as 100
    Node1(config-bgp-nbr)# address-family vpnv4 unicast
    Node1(config-bgp-nbr-af)# exit
    Node1(config-bgp-nbr)# exit
    Node1(config-bgp)# vrf vrf_cust1
    Node1(config-bgp-vrf)# rd 100:1
    Node1(config-bgp-vrf)# address-family ipv4 unicast
    Node1(config-bgp-vrf-af)# segment-routing srv6
    Node1(config-bgp-vrf-af-srv6)# locator Node1-locator
    Node1(config-bgp-vrf-af-srv6)# alloc mode per-vrf-46
    Node1(config-bgp-vrf-af-srv6)# exit
    Node1(config-bgp-vrf-af)# exit
    Node1(config-bgp-vrf)# address-family ipv6 unicast
    Node1(config-bgp-vrf-af)# segment-routing srv6
    Node1(config-bgp-vrf-af-srv6)# locator Node1-locator
    Node1(config-bgp-vrf-af-srv6)# alloc mode per-vrf-46
    Node1(config-bgp-vrf-af-srv6)# commit
    
    

Verify the SRv6 based L3VPN configuration

To confirm that the SRv6-based L3VPN services for IPv4 traffic are correctly configured and operating as expected. This task helps ensure that SRv6 locators, SID allocation modes, and routing information are properly established.

This verification task is typically performed after configuring SRv6-based IPv4 L3VPNs. The examples provided in this task illustrate a common VPNv4 scenario where router Node1 acts as the Ingress Provider Edge (PE), and routers Node4 and Node5 function as Egress PEs.

Procedure

  1. Verify the SRv6 SID information using the show segment-routing srv6 sid command.

    Example:

    In this example, we can observe the uDT4 SIDs associated with the IPv4 L3VPN; where uDT4 behavior represents Endpoint with decapsulation and IPv4 table lookup, and uDX4 represents Endpoint with decapsulation and IPv4 cross-connect.
    Node1# show segment-routing srv6 sid
    
    *** Locator: 'Node1-locator' ***
    
    SID                         Behavior          Context                           Owner               State  RW
    --------------------------  ----------------  ------------------------------    ------------------  -----  --
    cafe:0:1::                  uN (PSP/USD)      'default':1                       sidmgr              InUse  Y
    cafe:0:1:e000::             uA (PSP/USD)      [Hu0/0/0/0, Link-Local]:0         isis-1              InUse  Y
    cafe:0:1:e001::             uA (PSP/USD)      [Hu0/0/0/1, Link-Local]:0         isis-1              InUse  Y
    cafe:0:1:e002::             uDT4              'vrf_cust1'                       bgp-100             InUse  Y
    cafe:0:1:e003::             uDT4              'vrf_cust2'                       bgp-100             InUse  Y
    cafe:0:1:e004::             uDT4              'vrf_cust3'                       bgp-100             InUse  Y
    cafe:0:1:e005::             uDT4              'vrf_cust4'                       bgp-100             InUse  Y
    cafe:0:1:e006::             uDT4              'vrf_cust5'                       bgp-100             InUse  Y
    
    
  2. Verify the detailed SRv6 SID information for a specific SID using the show segment-routing srv6 SID-prefix detail command.

    Example:

    Node1# show segment-routing srv6 sid cafe:0:1:e002:: detail
    Tue Feb  9 17:50:40.621 UTC
    
    *** Locator: 'Node1-locator' ***
    
    SID                         Behavior          Context                                 Owner               State  RW
    --------------------------  ----------------  ------------------------------          ------------------  -----  --
    cafe:0:1:e002::             uDT4              'vrf_cust1'                             bgp-100             InUse  Y
      SID Function: 0xe002
      SID context: { table-id=0xe0000011 ('vrf_cust1':IPv4/Unicast) }
      Locator: 'Node1-locator'
      Allocation type: Dynamic
      Created: Feb  9 17:41:07.475 (00:09:33 ago)
     
    
  3. Verify the BGP VPNv4 unicast summary using the show bgp vpnv4 unicast commands on Egress PE.

    Example:

    Node1# show bgp vpnv4 unicast summary
    
    BGP router identifier 1.1.1.1, local AS number 100
    BGP generic scan interval 60 secs
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0x0   RD version: 0
    BGP main routing table version 36
    BGP NSR Initial initsync version 16 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    BGP scan interval 60 secs
    
    BGP is operating in STANDALONE mode.
    
    
    Process       RcvTblVer   bRIB/RIB   LabelVer  ImportVer  SendTblVer  StandbyVer
    Speaker              36         36         36         36          36           0
    
    Neighbor        Spk    AS MsgRcvd MsgSent   TblVer  InQ OutQ  Up/Down  St/PfxRcd
    cafe:0:4::4       0   100      47      48       36    0    0 00:40:05          5
    cafe:0:5::5       0   100      47      47       36    0    0 00:39:56          5
    
    
    Node1# show bgp vpnv4 unicast rd 100:1
    
    BGP router identifier 1.1.1.1, local AS number 100
    BGP generic scan interval 60 secs
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0x0   RD version: 0
    BGP main routing table version 36
    BGP NSR Initial initsync version 16 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    BGP scan interval 60 secs
    
    Status codes: s suppressed, d damped, h history, * valid, > best
                  i - internal, r RIB-failure, S stale, N Nexthop-discard
    Origin codes: i - IGP, e - EGP, ? - incomplete
       Network            Next Hop            Metric LocPrf Weight Path
    Route Distinguisher: 100:1 (default for vrf vrf_cust1)
    *> 12.1.1.1/32        0.0.0.0                  0         32768 ?
    *>i12.4.4.4/32        cafe:0:4::4              0    100      0 ?
    *>i12.5.5.5/32        cafe:0:5::5              0    100      0 ?
    
    Processed 3 prefixes, 3 paths
    
    
    Node1# show bgp vpnv4 unicast rd 100:1 12.4.4.4/32
    
    BGP routing table entry for 12.4.4.4/32, Route Distinguisher: 100:1
    Versions:
      Process           bRIB/RIB  SendTblVer
      Speaker                 22          22
    Last Modified: Feb 23 22:57:56.756 for 00:40:08
    Paths: (1 available, best #1)
      Not advertised to any peer
      Path #1: Received by speaker 0
      Not advertised to any peer
      Local, (received & used)
        cafe:0:4::4 (metric 30) from cafe:0:4::4 (1.1.1.4)
          Received Label 0xe00400
          Origin incomplete, metric 0, localpref 100, valid, internal, best, group-best, import-candidate, imported
          Received Path ID 0, Local Path ID 1, version 22
          Extended community: RT:1:1 RT:100:1
          PSID-Type:L3, SubTLV Count:1
           SubTLV:
            T:1(Sid information), Sid:cafe:0:4::, Behavior:63, SS-TLV Count:1
             SubSubTLV:
              T:1(Sid structure):
          Source AFI: VPNv4 Unicast, Source VRF: vrf_cust1, Source Route Distinguisher: 100:1
    
    
  4. Verify the BGP VPNv4 unicast routes for a specific Route Distinguisher (RD) using the show bgp vpnv4 unicast rd route-distinguisher prefix command on Ingress PE.

    Example:

    
    RP/0/RP0/CPU0:SRv6-LF1# show bgp vpnv4 unicast rd 106:1 10.15.0.0/30 
    Wed Nov 21 16:11:45.538 EST
    BGP routing table entry for 10.15.0.0/30, Route Distinguisher: 106:1
    Versions:
      Process           bRIB/RIB  SendTblVer
      Speaker            2286222     2286222
    Last Modified: Nov 21 15:47:26.288 for 00:24:19
    Paths: (1 available, best #1)
      Not advertised to any peer
      Path #1: Received by speaker 0
      Not advertised to any peer
      200, (received & used)
        6::6 (metric 24) from 2::2 (6.6.6.6)
          Received Label 3 
          Origin IGP, localpref 200, valid, internal, best, group-best, import-candidate, not-in-vrf
          Received Path ID 1, Local Path ID 1, version 2286222
          Extended community: RT:201:1 
          Originator: 6.6.6.6, Cluster list: 2.2.2.2
          SRv6-VPN-SID: T1-cafe:0:0:66:44:: [total 1]
    
  5. Verify the SRv6 based L3VPN configuration using the show route vrf commands.

    Example:

    Node1# show route vrf vrf_cust1
    
    Codes: C - connected, S - static, R - RIP, B - BGP, (>) - Diversion path
           D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
           N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
           E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
           i - ISIS, L1 - IS-IS level-1, L2 - IS-IS level-2
           ia - IS-IS inter area, su - IS-IS summary null, * - candidate default
           U - per-user static route, o - ODR, L - local, G  - DAGR, l - LISP
           A - access/subscriber, a - Application route
           M - mobile route, r - RPL, t - Traffic Engineering, (!) - FRR Backup path
    
    Gateway of last resort is not set
    
    L    12.1.1.1/32 is directly connected, 00:44:43, Loopback100
    B    12.4.4.4/32 [200/0] via cafe:0:4::4 (nexthop in vrf default), 00:42:45
    B    12.5.5.5/32 [200/0] via cafe:0:5::5 (nexthop in vrf default), 00:42:45
    
    
    Node1# show route vrf vrf_cust1 12.4.4.4/32
    
    Routing entry for 12.4.4.4/32
      Known via "bgp 100", distance 200, metric 0, type internal
      Installed Feb 23 22:57:56.746 for 00:43:12
      Routing Descriptor Blocks
        cafe:0:4::4, from cafe:0:4::4
          Nexthop in Vrf: "default", Table: "default", IPv6 Unicast, Table Id: 0xe0800000
          Route metric is 0
      No advertising protos.
    
    
    Node1# show route vrf vrf_cust1 12.4.4.4/32 detail
    
    Routing entry for 12.4.4.4/32
      Known via "bgp 100", distance 200, metric 0, type internal
      Installed Feb 23 22:57:56.746 for 00:43:37
      Routing Descriptor Blocks
        cafe:0:4::4, from cafe:0:4::4
          Nexthop in Vrf: "default", Table: "default", IPv6 Unicast, Table Id: 0xe0800000
          Route metric is 0
          Label: None
          Tunnel ID: None
          Binding Label: None
          Extended communities count: 0
          Source RD attributes: 0x0000:100:1
          NHID:0x0(Ref:0)
          SRv6 Headend: H.Encaps.Red [f3216], SID-list {cafe:0:4:e004::}
      Route version is 0x1 (1)
      No local label
      IP Precedence: Not Set
      QoS Group ID: Not Set
      Flow-tag: Not Set
      Fwd-class: Not Set
      Route Priority: RIB_PRIORITY_RECURSIVE (12) SVD Type RIB_SVD_TYPE_REMOTE
      Download Priority 3, Download Version 3
      No advertising protos.
    
    
  6. Verify CEF information for a VRF using the show cef vrf commands.

    Example:

    Node1# show cef vrf vrf_cust1
    
    Prefix              Next Hop            Interface
    ------------------- ------------------- ------------------
    0.0.0.0/0           drop                default handler
    0.0.0.0/32          broadcast
    12.1.1.1/32         receive             Loopback100
    12.4.4.4/32         cafe:0:4::/128      <recursive>
    12.5.5.5/32         cafe:0:5::/128      <recursive>
    224.0.0.0/4         0.0.0.0/32
    224.0.0.0/24        receive
    255.255.255.255/32  broadcast
    
    
    Node1# show cef vrf vrf_cust1 12.4.4.4/32
    
    12.4.4.4/32, version 3, SRv6 Headend, internal 0x5000001 0x30 (ptr 0x78b9a61c) [1], 0x0 (0x0), 0x0 (0x88873720)
     Updated Feb 23 22:57:56.749
     Prefix Len 32, traffic index 0, precedence n/a, priority 3
       via cafe:0:4::/128, 3 dependencies, recursive [flags 0x6000]
        path-idx 0 NHID 0x0 [0x78e2da14 0x0]
        next hop VRF - 'default', table - 0xe0800000
        next hop cafe:0:4::/128 via cafe:0:4::/48
        SRv6 H.Encaps.Red SID-list {cafe:0:4:e004::}
    
    
    Node1# show cef vrf vrf_cust1 12.4.4.4/32 detail
    
    12.4.4.4/32, version 3, SRv6 Headend, internal 0x5000001 0x30 (ptr 0x78b9a61c) [1], 0x0 (0x0), 0x0 (0x88873720)
     Updated Feb 23 22:57:56.749
     Prefix Len 32, traffic index 0, precedence n/a, priority 3
      gateway array (0x88a740a8) reference count 5, flags 0x2010, source rib (7), 0 backups
                    [1 type 3 flags 0x48441 (0x789cbcc8) ext 0x0 (0x0)]
      LW-LDI[type=0, refc=0, ptr=0x0, sh-ldi=0x0]
      gateway array update type-time 1 Feb 23 22:57:56.749
     LDI Update time Feb 23 22:57:56.754
    
      Level 1 - Load distribution: 0
      [0] via cafe:0:4::/128, recursive
    
       via cafe:0:4::/128, 3 dependencies, recursive [flags 0x6000]
        path-idx 0 NHID 0x0 [0x78e2da14 0x0]
        next hop VRF - 'default', table - 0xe0800000
        next hop cafe:0:4::/128 via cafe:0:4::/48
        SRv6 H.Encaps.Red SID-list {cafe:0:4:e004::}
    
        Load distribution: 0 1 (refcount 1)
    
        Hash  OK  Interface                 Address
        0     Y   HundredGigE0/0/0/1        remote
        1     Y   HundredGigE0/0/0/0        remote
    
    
  7. Verify the BGP prefix information for VRF instances using the show bgp vrf commands:

    Example:

    Node1# show bgp vrf vrf_cust1 ipv4 unicast
    
    BGP VRF vrf_cust1, state: Active
    BGP Route Distinguisher: 100:1
    VRF ID: 0x60000002
    BGP router identifier 1.1.1.1, local AS number 100
    Non-stop routing is enabled
    BGP table state: Active
    Table ID: 0xe0000011   RD version: 32
    BGP main routing table version 36
    BGP NSR Initial initsync version 16 (Reached)
    BGP NSR/ISSU Sync-Group versions 0/0
    
    Status codes: s suppressed, d damped, h history, * valid, > best
                  i - internal, r RIB-failure, S stale, N Nexthop-discard
    Origin codes: i - IGP, e - EGP, ? - incomplete
       Network            Next Hop            Metric LocPrf Weight Path
    Route Distinguisher: 100:1 (default for vrf vrf_cust1)
    *> 12.1.1.1/32        0.0.0.0                  0         32768 ?
    *>i12.4.4.4/32        cafe:0:4::4              0    100      0 ?
    *>i12.5.5.5/32        cafe:0:5::5              0    100      0 ?
    
    Processed 3 prefixes, 3 paths
    
    
    Node1# show bgp vrf vrf_cust1 ipv4 unicast 12.4.4.4/32
    Tue Feb 23 23:39:57.499 UTC
    BGP routing table entry for 12.4.4.4/32, Route Distinguisher: 100:1
    Versions:
      Process           bRIB/RIB  SendTblVer
      Speaker                 22          22
    Last Modified: Feb 23 22:57:56.756 for 00:42:01
    Paths: (1 available, best #1)
      Not advertised to any peer
      Path #1: Received by speaker 0
      Not advertised to any peer
      Local, (received & used)
        cafe:0:4::4 (metric 30) from cafe:0:4::4 (1.1.1.4)
          Received Label 0xe00400
          Origin incomplete, metric 0, localpref 100, valid, internal, best, group-best, import-candidate, imported
          Received Path ID 0, Local Path ID 1, version 22
          Extended community: RT:1:1 RT:100:1
          PSID-Type:L3, SubTLV Count:1
           SubTLV:
            T:1(Sid information), Sid:cafe:0:4::, Behavior:63, SS-TLV Count:1
             SubSubTLV:
              T:1(Sid structure):
          Source AFI: VPNv4 Unicast, Source VRF: vrf_cust1, Source Route Distinguisher: 100:1