Segment Routing v6 Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

Segment Routing v6 Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

Layer 3 service gateway for interconnecting SRv6 domains

Want to summarize with AI?

Log in

Explains how Layer 3 service gateways connect SRv6 domains through route re-origination, summarization, SID-format translation, and packet re-encapsulation.


A Layer 3 service gateway is a mechanism that

  • extends L3 services between two distinct SRv6 domains

  • enables seamless service continuity on both control and data planes for SRv6-based networks, and

  • facilitates route re-origination and summarization between SRv6 VPNv4 and VPNv6 address families.

Table 1. Feature History Table

Feature Name

Release

Description

Layer 3 service gateway for interconnecting SRv6 domains

Release 25.3.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q200, P100])

Optimize network scalability and interoperability by reducing SID resource usage, and enabling seamless integration between distinct SRv6 domains. The Layer 3 service gateway provides a flexible mechanism to extend Layer 3 services across different SRv6 networks, supporting efficient route summarization, cross-locator compatibility, and consistent service continuity on both control and data planes.

Key concepts

  • Route re-origination is the process by which a network device, such as a Layer 3 service gateway, receives routes from one network domain and then advertises those routes as if they originated from itself in another domain. The received routes from one address family are imported and updated with a next-hop set to self and a locally generated SID. These routes are then re-advertised either within the same address family or into another compatible address family, appearing as newly originated routes from the gateway. This process is essential for stitching or interworking between different VPN address families, ensuring consistent route distribution and reachability across SRv6 domains.

  • Route summarization is the process of consolidating multiple specific routes into a single, more general route before advertising it into another domain. For example, several contiguous prefixes can be aggregated into a broader prefix, reducing the number of routes and SIDs that must be managed and propagated. This optimization applies to both VPNv4 and VPNv6 address families.

Key challenges

Managing large-scale networks while ensuring interoperability between different SRv6 domains involves two major challenges:

  • Encap ID consumption optimization: Large SRv6 networks generate numerous unique Segment Identifiers (SIDs), which can exhaust Encap ID resources on remote Provider Edge (PE) devices. This limitation impacts network scalability and efficiency.

  • Interconnecting SRv6 domains: Different SRv6 domains may use varying locator formats, such as base format and uSID-based locators, complicating seamless inter-domain connectivity and service continuity.

  • Cross-locator format interoperability: Supports both same-format (base-to-base or uSID-to-uSID) and different-format (base-to-uSID or uSID-to-base) domain interconnections, providing flexible integration for heterogeneous SRv6 deployments.

The Layer 3 service gateway addresses key challenges in large-scale SRv6 deployments by optimizing Encap ID consumption through network partitioning and SID summarization, and by interconnecting SRv6 domains that use different locator formats (base format and uSID-based) through Route Policy Language (RPL) based SID allocation.

Feature benefits

The SRv6 Layer 3 service gateway addresses these challenges by:

  • Network partitioning and SID summarization: Partitions the network into core and regional domains, enabling SID summarization and route re-origination at the gateway. This reduces the number of unique SIDs propagated into the core, optimizing Encap ID resource usage and simplifying network scaling

  • Flexible interconnection across domains: Acts as an effective intermediary to extend layer 3 VPN services across distinct SRv6 domains, ensuring seamless service delivery and integration.

  • Interconnecting different locator formats: Supports both base format and uSID locators, enabling interoperability between heterogeneous SRv6 deployments. Route Policy Language (RPL)-based SID allocation ensures that SIDs are allocated from the appropriate locator format for each prefix.

  • Robust control and data Plane operations: Facilitates route re-origination, summarization, importing, and re-advertising of service routes for both VPNv4 and VPNv6 address families, improving route management and efficiency. Also supports critical data plane functions such as packet pop/decapsulation, IP lookup, and encapsulation/push operations for smooth packet forwarding.

  • Service continuity for IPv4 and IPv6 VPNs: Manages routing information and maintains seamless service continuity across both control and data planes for SRv6-based networks, supporting both IPv4 and IPv6 VPNs.

  • From Release 26.1.1, Cisco IOS XR software sets the VLAN Priority Code Point (PCP) field based on the SRv6 header's Differentiated Services Code Point (DSCP) value rather than being fixed at zero. This optimization enables proper Quality of Service (QoS) marking and propagation through the VLAN header in the Interworking (IW) Gateway.


How SRv6 L3 service gateway works

The SRv6 L3 service gateway provides a robust solution for interconnecting disparate SRv6 domains. It enables efficient network partitioning and ensures seamless data plane connectivity and interoperability between domains that use different SRv6 formats. The process covers both scenarios where the source and destination SRv6 domains use the same SID format and where they use different SID formats.

Summary

The key components involved in the process are:

  • SRv6 L3 service gateway: The central network device that acts as a bridge, performing decapsulation, IP lookup, and re-encapsulation to forward traffic between SRv6 domains.

  • SRv6 domains: Distinct network segments that utilize SRv6 technology and are interconnected by the gateway.

  • Traffic (data plane): The IP packets and their associated SRv6 headers that flow through the gateway, undergoing transformation.

  • Regional domains: Specific SRv6 domains representing partitioned parts of a larger L3VPN network, connected to a core domain through the gateway.

  • Core domain: The central SRv6 domain in a partitioned L3VPN network, connected to regional domains through the gateway.

  • Base format SRv6 locators: A specific format of SRv6 locators used within certain SRv6 domains.

  • uSID-based SRv6 locators: Another specific format of SRv6 locators used within different SRv6 domains.

  • Route Policy Language (RPL): RPL is a mechanism used by the gateway to determine which locator format (base or uSID) is assigned to each prefix. RPL selects the appropriate SID format for each prefix, but only one SID can be allocated per prefix at the gateway.

The SRv6 L3 service gateway, acting as a central network device, interconnects disparate SRv6 domains. It achieves this by performing control plane SID re-origination, summarization, and format translation, alongside data plane packet decapsulation, IP lookup, and re-encapsulation. This comprehensive process ensures efficient network partitioning, seamless data plane connectivity, and interoperability across domains with varying SRv6 SID formats.

Workflow

These stages describe SRv6 layer 3 service gateway interconnect domains:

  1. Control plane stage: Re-origination and summarization of SIDs (Use case 1 - Regional to Core):

    • Regional to core: When VPN prefixes flow from a regional domain to the core, the gateway re-originates them using local per-VRF SIDs.

    • Core to regional: When VPN prefixes flow from the core to a regional domain, the gateway processes and forwards it into the appropriate regional domain, re-originating SIDs as needed for that regional domain.

  2. Control plane stage: Format translation between domains (Use case 2):

    When prefix crosses between domains using different SRv6 formats (for example, base format to uSID), the gateway utilizes RPL-based SID allocation to match prefixes from the source domain and assign a SID from the corresponding locator type of the destination domain.

    • When prefix flows from Domain 1 to 2, the gateway assigns a uSID corresponding to the prefix and advertises it into Domain 2.

    • When prefix flows from Domain 2 to 1, the gateway assigns a Base or F1 format SID for the prefix and advertises it into Domain 1.

  3. Data plane stage: Packet processing and forwarding.

    • Traffic arrival: Traffic originating from one SRv6 domain arrives at the SRv6 L3 service gateway.

    • Pop or decapsulation: The gateway decapsulates the incoming SRv6 packet by removing its existing SRv6 header.

    • IP lookup: The gateway performs an IP lookup on the exposed inner IP packet to determine its next hop or final destination within the target SRv6 domain.

    • Encapsulation or Push: Based on the IP lookup, the gateway encapsulates the IP packet with a new SRv6 header that is appropriate for the destination SRv6 domain.

      • Same SID format: The new SRv6 header uses the same SID format as the source domain, maintaining SID consistency across the gateway.

      • Different SID formats: The gateway translates the SID format as needed, for example, from base SID to uSID or vice versa, to match the destination domain’s requirements.

    • Traffic forwarding: The newly encapsulated traffic is then pushed out towards the target SRv6 domain.


Configure SRv6 layer 3 service gateway with different SID formats

Use this procedure when the core and regional domains use different SID formats, for example, base in the core and uSID in the regional domain.

Before you begin

Ensure that these tasks are completed:

  • Explicitly configure the per-VRF allocation mode.

Use this procedure when the core and regional domains use different SID formats, for example, base in the core and uSID in the regional domain.

Procedure

  1. Configure two locators, one using the base format and another using the uSID format.

    Example:

    Router(config)#segment-routing
    Router(config-sr)#srv6
    Router(config-srv6)#locators
    Router(config-srv6-locators)#locator base_locator
    Router(config-srv6-locator)#prefix 2001:DB8:0:5::/64
    Router(config-srv6-locator)#exit
    Router(config-srv6-locators)#locator usid_locator
    Router(config-srv6-locator)#prefix fccc:cc00:5::/48
    Router(config-srv6-locator)#exit
  2. Set up a route policy to allocate uSIDs for prefixes received from the base domain and allocate base format SIDs for prefixes received from the uSID domain.

    Example:

    Router(config-bgp-vrf-af)#route-policy alloc_sid_policy
    Router(config-rpl)#if destination in core_prefix_set then
    Router(config-rpl-if)#set srv6-alloc-mode per-vrf locator base_locator
    Router(config-rpl-if)#else
    Router(config-rpl-else)#set srv6-alloc-mode per-vrf locator usid_locator
    Router(config-rpl-else)#endif
    Router(config-rpl)#end-policy
    
    Router(config)#prefix-set core_prefix_set
    Router(config-pfx)#192.0.0.0/24 
    Router(config-pfx)#end-set 
  3. Configure the VRF to import and export route targets for both the core and regional domains.

    Example:

    Router(config)#vrf VRF1
    Router(config-vrf)#address-family ipv4 unicast
    Router(config-vrf-af)#import route-target
    Router(config-vrf-import-rt)#100:1 
    Router(config-vrf-import-rt)#200:1 stitching
    Router(config-vrf-import-rt)#exit
    Router(config-vrf-af)#export route-target
    Router(config-vrf-export-rt)#100:1
    Router(config-vrf-export-rt)#200:1 stitching
    Router(config-vrf-export-rt)#exit 
    Router(config-vrf-af)#exit
    
    Router(config-vrf)#address-family ipv6 unicast
    Router(config-vrf-af)#import route-target
    Router(config-vrf-import-rt)#100:1
    Router(config-vrf-import-rt)#200:1 stitching
    Router(config-vrf-import-rt)#exit
    Router(config-vrf-af)#export route-target
    Router(config-vrf-export-rt)# 100:1
    Router(config-vrf-export-rt)#200:1 stitching
    Router(config-vrf-export-rt)#exit
    Router(config-vrf-af)#exit
    Router(config-vrf)#exit
  4. Configure BGP neighbor for the regional and core domains.

    Example:

    Router(config)#router bgp 65001
    Router(config-bgp)# bgp router-id 10.5.5.5
    Router(config-bgp)#address-family vpnv4 unicast
    Router(config-bgp-af)#segment-routing srv6
    Router(config-bgp-af-srv6)#locator locator0
    Router(config-bgp-af-srv6)#alloc mode route-policy alloc-sid-policy-ipv4
    Router(config-bgp-af-srv6)#exit
    Router(config-bgp-af)#exit
    
    Router(config-bgp)#address-family vpnv6 unicast
    Router(config-bgp-af)#vrf all
    Router(config-bgp-af-vrfall)#segment-routing srv6
    Router(config-bgp-af-vrfall-srv6)#locator locator0
    Router(config-bgp-af-vrfall-srv6)#alloc mode per-vrf
    Router(config-bgp-af-vrfall-srv6)#exit
    Router(config-bgp-af-vrfall)#exit
    Router(config-bgp-af)#exit
    
    Router(config-bgp)#neighbor-group CORE-DOMAIN
    Router(config-bgp-nbrgrp)#remote-as 65001
    Router(config-bgp-nbrgrp)#update-source Loopback0
    Router(config-bgp-nbrgrp)#address-family vpnv4 unicast
    Router(config-bgp-nbrgrp-af)#import reoriginate stitching-rt
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv4 unicast re-originated
    Router(config-bgp-nbrgrp-af)#exit
    
    Router(config-bgp-nbrgrp)#address-family vpnv6 unicast
    Router(config-bgp-nbrgrp-af)# import reoriginate stitching-rt
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv6 unicast re-originated
    Router(config-bgp-nbrgrp-af)#exit
    Router(config-bgp-nbrgrp)#exit
    
    Router(config-bgp)#neighbor-group REGIONAL-DOMAIN
    Router(config-bgp-nbrgrp)#remote-as 65001
    Router(config-bgp-nbrgrp)#update-source Loopback0
    
    Router(config-bgp-nbrgrp)#address-family vpnv4 unicast
    Router(config-bgp-nbrgrp-af)#import stitching-rt reoriginate
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv4 unicast re-originated stitching-rt
    Router(config-bgp-nbrgrp-af)#exit
    
    Router(config-bgp-nbrgrp)#address-family vpnv6 unicast
    Router(config-bgp-nbrgrp-af)#import stitching-rt reoriginate
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv6 unicast re-originated stitching-rt
    Router(config-bgp-nbrgrp-af)#exit
    Router(config-bgp-nbrgrp)#exit
    
    Router(config-bgp)#neighbor 2001:DB8:0:1::1
    Router(config-bgp-nbr)#use neighbor-group REGINAL-DOMAIN
    Router(config-bgp-nbr)#exit
    Router(config-bgp)#neighbor fccc:cc00:3::1
    Router(config-bgp-nbr)#use neighbor-group CORE-DOMAIN
    Router(config-bgp-nbr)#exit
    
    Router(config-bgp)#vrf VRF1
    Router(config-bgp-vrf)#rd auto
    Router(config-bgp-vrf)#address-family ipv4 unicast
    Router(config-bgp-vrf-af)#segment-routing srv6
    Router(config-bgp-vrf-af-srv6)#locator locator-usid
    Router(config-bgp-vrf-af-srv6)#alloc mode route-policy alloc-sid-policy-ipv4
    Router(config-bgp-vrf-af-srv6)#exit

Configure SRv6 layer 3 service gateway with same SID formats

Use this procedure when both the core and regional domains use the same SID format, for example, both base or both uSID.

Before you begin

Ensure that these tasks are completed:

  • Configure SRv6 Locator Name, Prefix, and uSID-Related Parameters

  • Configure SRv6 under IS-IS

  • Configure per-VRF allocation mode

Follow these steps to configure the SRv6 L3 service gateways for seamless interconnection of domains with the same SID format.

Procedure

  1. Configure the VRF to import and export route targets for both the core and regional domains.

    Example:

    Router(config)#vrf VRF1
    Router(config-vrf)#address-family ipv4 unicast
    Router(config-vrf-af)#import route-target
    Router(config-vrf-import-rt)#100:1 
    Router(config-vrf-import-rt)#200:1 stitching
    Router(config-vrf-import-rt)#exit
    Router(config-vrf-af)#export route-target
    Router(config-vrf-export-rt)#100:1
    Router(config-vrf-export-rt)#200:1 stitching
    Router(config-vrf-export-rt)#exit 
    Router(config-vrf-af)#exit
    
    Router(config-vrf)#address-family ipv6 unicast
    Router(config-vrf-af)#import route-target
    Router(config-vrf-import-rt)#100:1
    Router(config-vrf-import-rt)#200:1 stitching
    Router(config-vrf-import-rt)#exit
    Router(config-vrf-af)#export route-target
    Router(config-vrf-export-rt)# 100:1
    Router(config-vrf-export-rt)#200:1 stitching
    Router(config-vrf-export-rt)#exit
    Router(config-vrf-af)#exit
    Router(config-vrf)#exit
  2. Configure BGP neighbor for the regional and core domains.

    Example:

    This example shows how to uSID to uSID VPNv4/v6 gateway:
    Router(config)#router bgp 65001
    Router(config-bgp)# bgp router-id 10.5.5.5
    Router(config-bgp)#address-family vpnv4 unicast
    Router(config-bgp-af)# vrf all
    Router(config-bgp-af-vrfall)#segment-routing srv6
    Router(config-bgp-af-vrfall-srv6)#locator locator0
    Router(config-bgp-af-vrfall-srv6)#alloc mode per-vrf
    Router(config-bgp-af-vrfall-srv6)#exit
    Router(config-bgp-af-vrfall)#exit
    Router(config-bgp-af)#exit
    
    Router(config-bgp)#address-family vpnv6 unicast
    Router(config-bgp-af)#vrf all
    Router(config-bgp-af-vrfall)#segment-routing srv6
    Router(config-bgp-af-vrfall-srv6)#locator locator0
    Router(config-bgp-af-vrfall-srv6)#alloc mode per-vrf
    Router(config-bgp-af-vrfall-srv6)#exit
    Router(config-bgp-af-vrfall)#exit
    Router(config-bgp-af)#exit
    
    Router(config-bgp)#neighbor-group CORE-DOMAIN
    Router(config-bgp-nbrgrp)# remote-as 65001
    Router(config-bgp-nbrgrp)#update-source Loopback0
    Router(config-bgp-nbrgrp)#address-family vpnv4 unicast
    Router(config-bgp-nbrgrp-af)#import reoriginate stitching-rt
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv4 unicast re-originated
    Router(config-bgp-nbrgrp-af)#exit
    
    Router(config-bgp-nbrgrp)#address-family vpnv6 unicast
    Router(config-bgp-nbrgrp-af)# import reoriginate stitching-rt
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv6 unicast re-originated
    Router(config-bgp-nbrgrp-af)#exit
    Router(config-bgp-nbrgrp)#exit
    
    Router(config-bgp)#neighbor-group REGIONAL-DOMAIN
    Router(config-bgp-nbrgrp)#remote-as 65001
    Router(config-bgp-nbrgrp)#update-source Loopback0
    
    Router(config-bgp-nbrgrp)#address-family vpnv4 unicast
    Router(config-bgp-nbrgrp-af)#import stitching-rt reoriginate
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv4 unicast re-originated stitching-rt
    Router(config-bgp-nbrgrp-af)#exit
    
    Router(config-bgp-nbrgrp)#address-family vpnv6 unicast
    Router(config-bgp-nbrgrp-af)#import stitching-rt reoriginate
    Router(config-bgp-nbrgrp-af)#route-reflector-client
    Router(config-bgp-nbrgrp-af)#encapsulation-type srv6
    Router(config-bgp-nbrgrp-af)#advertise vpnv6 unicast re-originated stitching-rt
    Router(config-bgp-nbrgrp-af)#exit
    Router(config-bgp-nbrgrp)#exit
    
    Router(config-bgp)#neighbor fccc:cc00:1::1
    Router(config-bgp-nbr)#use neighbor-group REGINAL-DOMAIN
    Router(config-bgp-nbr)#exit
    Router(config-bgp)#neighbor fccc:cc00:3::1
    Router(config-bgp-nbr)#use neighbor-group CORE-DOMAIN
    Router(config-bgp-nbr)#exit
    
    Router(config-bgp)# vrf VRF1
    Router(config-bgp-vrf)# rd auto
    Router(config-bgp-vrf)#address-family ipv4 unicast
    Router(config-bgp-vrf-af)#exit
    Router(config-bgp-vrf)#address-family ipv6 unicast
    Router(config-bgp-vrf-af)#exit
    Router(config-bgp-vrf)#exit
    Router(config-bgp)#exit