EVPN Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

PDF

EVPN Configuration Guide for Cisco 8000 Series Routers, Cisco IOS XR Releases

MAC mobility for EVPN E-LAN

Want to summarize with AI?

Log in

Details MAC mobility enhancements for EVPN E-LAN, covering feature highlights, duplicate MAC address detection and prevention, host duplication guidelines, and configuration steps to manage freezing and route advertisement in network devices and hosts.


MAC mobility is a network capability that

  • allows devices or virtual machines to move between different physical hosts or locations within a network

  • enables efficient resource utilization through dynamic traffic distribution and optimized routing based on MAC address location, and

  • maintains uninterrupted network connectivity during such moves.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

MAC Mobility for EVPN Single-Homing

Release 26.2.1

Introduced in this release on: Modular Systems (8800 [LC ASIC: K100])(select variants only*);

*This feature is supported on Cisco 88-LC1-48Y8H-EM line cards.

MAC Mobility for EVPN Single-Homing

Release 26.1.1

Introduced in this release on: Centralized Systems (8400 [ASIC: K100])(select variants only*)

*This feature is now supported on Cisco 8404-SYS-D routers.

MAC Mobility for EVPN Single-Homing

Release 25.4.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*)

*This feature is now supported on:

  • 8011-32Y8L2H2FH

  • 8011-12G12X4Y-A

  • 8011-12G12X4Y-D

MAC Mobility for EVPN Single-Homing

Release 25.1.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) (select variants only*)

*This feature is now supported on the Cisco 8011-4G24Y4H-I routers.

MAC Mobility for EVPN Single-Homing

Release 24.4.1

Introduced in this release on: Fixed Systems (8700) (select variants only*)

*The MAC mobility functionality is now extended to the Cisco 8712-MOD-M routers.

MAC Mobility for EVPN Single-Homing

Release 24.3.1

Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]) (select variants only*)

*The MAC mobility functionality is now extended to:

  • 8212-48FH-M

  • 8711-32FH-M

  • 88-LC1-52Y8H-EM

  • 88-LC1-12TH24FH-E

MAC Mobility for EVPN Single-Homing

Release 24.2.11

Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]) (select variants only*)

*The MAC mobility functionality is now extended to routers with the 88-LC1-36EH line cards.

MAC Mobility for EVPN Single-Homing

Release 7.11.1

Now, it is now possible to seamlessly move MAC addresses between various network devices or locations while preserving their connectivity and associated network services. This ensures uninterrupted communication for devices or virtual machines frequently changing their physical or virtual location within the network. The L2 gateway dynamically updates its forwarding table when a MAC address moves from one device to another within the EVPN E-LAN network, guaranteeing that packets destined for that MAC address are correctly forwarded to its new location.

This feature is supported only on Q200-based line cards.


Feature highlights of MAC mobility for EVPN E-LAN

  • Facilitates seamless movement of MAC addresses among different devices or network locations, maintaining uninterrupted connectivity. This agility allows devices or virtual machines to be flexible and mobile, accommodating dynamic workloads and efficient resource allocation.

  • Manages a substantial volume of mobile devices or virtual machines, permitting seamless movement across different network segments without causing disruptions or requiring manual reconfiguration.

  • Ensures that packets are appropriately forwarded to the updated MAC address locations, optimizing routing decisions, curbing unnecessary traffic, and enhancing overall network performance.

  • Eliminates the need for manual configuration changes when devices or virtual machines move within the network. This simplifies network management and reduces the likelihood of human errors or misconfigurations.

MAC Mobility includes the capability to detect and block duplicate MAC addresses, which enhances network stability and security. This function supports seamless mobility by preventing address conflicts that could disrupt connectivity or degrade performance, thereby maintaining reliable and efficient network operations.


Detect and block duplicate MAC addresses

Duplicate MAC address detection is a network capability that

  • identifies hosts with duplicate MAC addresses

  • blocks all routes associated with these duplicate addresses, and

  • prevents network instability caused by address conflicts.

Table 2. Feature History Table

Feature Name

Release Information

Feature Description

Detect and Block Duplicate MAC Addresses

Release 26.2.1

Introduced in this release on: Modular Systems (8800 [LC ASIC: K100])(select variants only*);

*This feature is supported on Cisco 88-LC1-48Y8H-EM line cards.

Detect and Block Duplicate MAC Addresses

Release 26.1.1

Introduced in this release on: Centralized Systems (8400 [ASIC: K100])(select variants only*)

* This feature is now supported on Cisco 8404-SYS-D routers.

Detect and Block Duplicate MAC Addresses

Release 25.4.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*)

*This feature is now supported on:

  • 8011-32Y8L2H2FH

  • 8011-12G12X4Y-A

  • 8011-12G12X4Y-D

Detect and Block Duplicate MAC Addresses

Release 25.1.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) (select variants only*)

*This feature is now supported on the Cisco 8011-4G24Y4H-I routers.

Detect and Block Duplicate MAC Addresses

Release 24.4.1

Introduced in this release on: Fixed Systems (8700) (select variants only*)

* The Detect and Block Duplicate MAC Addresses funtionality is now extended to the Cisco 8712-MOD-M routers.

Detect and Block Duplicate MAC Addresses

Release 24.3.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*)

* The Detect and Block Duplicate MAC Addresses funtionality is now extended to:

  • 8212-48FH-M

  • 8711-32FH-M

  • 88-LC1-52Y8H-EM

  • 88-LC1-12TH24FH-E

Detect and Block Duplicate MAC Addresses

Release 24.2.11

Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]) (select variants only*)

* The Detect and Block Duplicate MAC Addresses funtionality is now extended to routers with the 88-LC1-36EH line cards.

Detect and Block Duplicate MAC Addresses

Release 7.11.1

You can now effectively mitigate traffic disruptions, packet loss, and potential network outages in your network operations by detecting and freezing duplicate MAC addresses and blocking all associated routes.

This feature is supported only on Q200-based line cards.

The feature introduces the evpn mac secure command.


Handling duplicate MAC addresses in network devices

Multiple devices using the same MAC address cause MAC address flapping. This issue occurs when different devices intermittently claim the identical MAC address, forcing network devices to repeatedly update their forwarding tables. Duplicate MAC addresses can result in:

  • Excessive network traffic

  • Increased CPU load on network devices

  • Overall network instability

To overcome such issues, routers detect duplicate MAC addresses based on predefined parameters and freeze the offending MAC address to prevent further disruptions. However, a configurable option allows you to avoid permanently freezing the MAC address, providing greater flexibility in network management.


Handling MAC address mobility and duplicate detection in EVPN hosts

The router tracks MAC addresses as they move between hosts to manage EVPN host mobility. When two hosts share the same MAC address, the router learns and relearns the MAC routes from each host. Each new learning of a MAC route from a different host counts as one move, superseding the previous route. This back-and-forth learning continues until the router marks the MAC address as a duplicate based on configured parameters.

Use the evpn mac secure command to configure when the router marks a MAC address as duplicate and whether to freeze or unfreeze it during movement between hosts. The key configurable parameters are

  • move-count : Number of times a MAC address changes location between hosts within a specified period to be considered duplicate.

  • move-interval : Time period during which the MAC address must move the specified number of times to trigger duplicate detection.

  • freeze-time : Duration the MAC address remains locked after being detected as duplicate. After this, it unlocks and can be relearned.

  • retry-count : Number of times a MAC address can be unlocked after duplicate detection before it is frozen permanently.

When a MAC address is frozen, a syslog message notifies the user. While frozen, the router ignores new or updated MAC routes for that address. After the freeze-time expires, the MAC routes are unfrozen, and the move-count resets to zero. For unfrozen local MAC routes, the router initiates an ARP probe and flush, while remote MAC routes enter probe mode, restarting duplicate detection.

The router also tracks how many times a MAC address has been frozen and unfrozen. If a MAC address is marked duplicate after being unfrozen the configured retry-count times, it is frozen permanently. To clear permanently frozen hosts, you can:

  • Shut down the host causing duplicate traffic.

  • Use the clear l2route evpn frozen-mac frozen-flag command to clear frozen hosts.

This mechanism helps maintain network stability by managing MAC address mobility and preventing persistent duplicate MAC address issues.


How to prevent MAC address freezing

A MAC address is permanently frozen when it undergoes three duplicate detection and recovery events within a 24-hour period. Freezing disables the MAC address, potentially disrupting network connectivity. If duplicate detection events occur outside this 24-hour window, the count resets, and the MAC address is not permanently frozen.

Procedure

1.

Enable infinite duplicate detection.

To prevent permanent freezing, configure the MAC address to allow infinite duplicate detection and recovery cycles by entering this command:

Example:

Router# configure
Router(config)# evpn
Router(config-evpn)# mac secure retry-count infinity

This setting ensures the MAC address will not be frozen permanently despite repeated duplicate detection events.

2.

Configure reset interval for retry count (Optional).

By default, the router uses a 24-hour interval to track duplicate detection events. To customize this interval, use

Example:

Router# configure
Router(config)# evpn
Router(config-evpn)# mac secure reset-freeze-count-interval 30

This interval defines the period after which the retry count resets, preventing permanent freezing if events are spaced out.

The MAC address remains active and is not permanently frozen, allowing ongoing duplicate detection and recovery without network disruption.

What to do next

Monitor network behavior to verify MAC address stability and adjust the reset interval as needed to suit your environment.


Guidelines for managing host duplication and route advertisement

These guidelines ensure controlled handling of frequent host movements, preventing route flapping and promoting network stability.

  • Duplication threshold: Allow up to five host movements (duplications) within a 180-second window before marking the host as a duplicate.

  • Duplicate marking: When a host moves five times within 180 seconds, mark it as a duplicate for 30 seconds.

  • Route advertisement suppression: During the 30-second duplicate period, suppress all route advertisements for the affected host.

  • Duplicate status removal: After 30 seconds, remove the duplicate status to resume normal route advertisements.

  • Permanent freeze: If a host is detected as a duplicate for the fourth time, permanently freeze the host and suppress all its route advertisements indefinitely.


Configure duplicate MAC address detection and prevent MAC address freezing

Detect duplicate MAC addresses moving between hosts and control MAC address freezing to maintain network stability.

Use this task to enable duplicate MAC address detection on EVPN routers and configure parameters that determine when a MAC address is marked as duplicate and how freezing is handled.

Procedure

1.

Enable duplicate MAC address detection on host MAC addresses.

Example:

Router# configure
Router(config)# evpn
Router(config-evpn)# mac secure
2.

Set detection parameters to control duplicate MAC handling.

Example:

Router(config-evpn-mac-secure)# move-count 2
Router(config-evpn-mac-secure)# freeze-time 10 
Router(config-evpn-mac-secure)# retry-count 2
Router(config-evpn-mac-secure)# commit
3.

To prevent MAC address freezing permanently, configure infinite retries.

Example:

Router# configure
Router(config)# evpn
Router(config-evpn)# mac secure 
Router(config-evpn-mac-secure)# retry-count infinite
Router(config-evpn-mac-secure)# commit
4.

Running configuration of duplicate MAC address detection and preventing MAC address freezing.

Example:


evpn 
 mac secure 
  move-count 2
  freeze-time 10 
  retry-count 2
!
evpn 
 mac secure 
  retry-count infinite
 !
5.

Use the show l2route evpn mac-ip 10.47.177.225 detail command to verify duplicate MAC detection and freezing status.

In this example, the 0011.0000.0001 MAC address is identified as duplicate and subsequently frozen. The DmZm flag denotes that the MAC address has been marked as duplicate and frozen.

Example:

Router# show l2route evpn mac-ip 10.47.177.225 detail
Topo ID  Mac Address    IP Address      Producer    Next Hop(s)                              Seq No   Flags       
Opaque Data Type        Opaque Data Len 
Opaque Data Value 
Opaque NH Type          Opaque NH Len 
Opaque NH Value 
-------- -------------- --------------- ----------- ---------------------------------------- -------- --------
161      0011.0000.0001 10.47.177.225   LOCAL       Bundle-Ether8.1212, N/A                  43       BLDmZm      
N/A                     N/A 
N/A
N/A                     N/A 
N/A
    Last Update: Fri Nov 03 17:42:09.426 CET
161      0011.0000.0001 10.47.177.225   L2VPN       25000/I/ME, N/A                          42       DmZm        
0                       12 
0x06000000 0x3b010080 0x00000000 

The router detects duplicate MAC addresses based on configured parameters and controls freezing behavior to prevent network disruption.