<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Routing between virtual routers in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55456#M16002</link>
    <description>Paul,&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;In the meantime, you can   try to trick the system to enable such feature using a cable to   directly connect two ports in two VRs, and using VRRP to generate a   different mac.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;
I actually started out with both of my connected 8806s having both VLANs defined, both 8806s having the patch cable, and I configured VRRP on both the VRs - problem was that I was getting a bunch of "ignoring lower priority VRRP advertsising" notifications (quoted from memory) that I'm not used to get on other VRRPs, but that could've been because I didn't explicitely define "IP tracking", and it might have broadcasted to the entire network, seeing IPs on duplicate MACs and all that.&lt;BR /&gt;
&lt;BR /&gt;
I might revisit that, though, "just because!" (and I'm 'tenacious'). I'll also give Sumit Tokle's idea a shot, but one VLAN has to be in a full VR (because of ospf).&lt;BR /&gt;
&lt;BR /&gt;
Heck, if all else fails, we do have abusable 480s &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Thank you very much - I'll try things out and reply in here how it went.&lt;BR /&gt;
&lt;BR /&gt;
   Frank&lt;BR /&gt;</description>
    <pubDate>Wed, 26 Mar 2014 16:10:00 GMT</pubDate>
    <dc:creator>Frank</dc:creator>
    <dc:date>2014-03-26T16:10:00Z</dc:date>
    <item>
      <title>Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55450#M15996</link>
      <description>I'd like to revisit the question of "how do I route between virtual routers". I'm in a managed datacenter environment and have 8806s, 480s, 460s. all running XOS 15.3 or higher.&lt;BR /&gt;
&lt;BR /&gt;
Scenario: I have a dozen or so corporate-internal VLANs that are all connected to let's say "VR-Corp". Now, the problem is that I have a handful of colocated customers with their internal networks (private IP space) that we need to manage, so two or three of our corporate VLANs have to somehow get access to the customer VLANs.&lt;BR /&gt;
&lt;BR /&gt;
I do &lt;B&gt;not&lt;/B&gt; want to add those customer VLANs to our corporate VR. I'm not a big fan of ACLs that aren't straightforward, simple, and easily maintainable. VPN access to the customer is usually not an option, either.&lt;BR /&gt;
I would much rather add all those customer VLANs to a "VR-Cust" and somehow route between the to VRs - that approach makes for a much simpler configuration on the respective VRs. At least I won't have to worry about routing protocols - just good old fashioned static routes will do just fine here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
From previous discussions I do understand that I cannot do that "within" the switch. However, my 8806s do have a 48-port Ethernet blade, and my idea was to create one VLAN on each VR (different tags) that are the same IP network, assign one Ethernet port to each VLAN, and just patch them together with a short cable.&lt;BR /&gt;
&lt;BR /&gt;
This, however, does not seem to work. The ports are up, but I can only ping the IP address that's on the VR that I set the context to, and not the other. The ports are up, the VRs are up, the VLANs are up, and they're still invisible to each other. I would assume that if it doesn't work over Ethernet, it won't work over fiber either.&lt;BR /&gt;
&lt;BR /&gt;
I don't quite understand why it doesn't work - technically I'm leaving the switch out one port and come back in through another port.&lt;BR /&gt;
&lt;BR /&gt;
If everything else fails, I can of course introduce my 480 into the mix and have it be the "router between the VRs" (or rather: the cross-connect VLANs)", but I would find that a somewhat less-than-elegant solution (to a less-than-elegant problem/requirement).&lt;BR /&gt;
&lt;BR /&gt;
Thanks for your help!&lt;BR /&gt;
&lt;BR /&gt;
    Frank&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Mar 2014 16:33:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55450#M15996</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2014-03-25T16:33:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55451#M15997</link>
      <description>Good Morning Frank  Thanks for the question.  If I read your post correctly you have a two port VLAN (I will call it interconnect) that is in both VRs is that correct?  &lt;BR /&gt;
&lt;BR /&gt;
I assume that you are routing between the customer/corporate VLANs to the interconnect VLAN?&lt;BR /&gt;
&lt;BR /&gt;
I will do some checking internally but wanted to make sure that the interconnect VLAN was set as the routed segment.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
P&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Mar 2014 18:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55451#M15997</guid>
      <dc:creator>Paul_Russo</dc:creator>
      <dc:date>2014-03-25T18:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55452#M15998</link>
      <description>Correct. The idea would be "route customer to support vlan  nexthop interconnect vlan" and the corresponding "route support  technician vlan to customer vlan"&lt;BR /&gt;
&lt;BR /&gt;
 Basically the following setup.  I'm not even at the routing part, because vr-test1 can't even ping  172.18.18.252 (see very bottom)&lt;BR /&gt;
&lt;BR /&gt;
I'm starting to get a little out  of my depth here, but I think what's killing my plan is that (got this  from somewhere in the Concepts or Commands Guide PDF) &lt;I&gt;ALL &lt;/I&gt;the VRs (and VRFs etc.) on &lt;I&gt;ONE &lt;/I&gt;switch have the &lt;I&gt;SAME &lt;/I&gt;MAC  address - which also can't be manually configured on a per-VR/VLAN/port  basis. But as I said, there's a good chance that I'm not sure what I'm  talking about &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
"Of course" the end-goal if we get this to work  is to replicate it all on our second 8806, including setting up vrrp,  but right now I've left this out because that'll just complicate  matters. I think...&lt;BR /&gt;
&lt;BR /&gt;
Thank you for your fast reply! &lt;BR /&gt;
&lt;BR /&gt;
------------------------------------------------------------------&lt;BR /&gt;
create vr vr-test1&lt;BR /&gt;
vr "vr-test1" &lt;BR /&gt;
configure "vr-test1" add ports 5:24&lt;BR /&gt;
&lt;BR /&gt;
create vlan vlan_test1&lt;BR /&gt;
configure vlan "vlan_test1" tag 2000&lt;BR /&gt;
configure "vlan_test1" ipaddress 172.18.18.1/24 &lt;BR /&gt;
&lt;BR /&gt;
create vr vr-test2&lt;BR /&gt;
vr "vr-test2" &lt;BR /&gt;
configure "vr-test2" add ports 5:48&lt;BR /&gt;
&lt;BR /&gt;
create vlan vlan_test2&lt;BR /&gt;
configure vlan "vlan_test2" tag 2002&lt;BR /&gt;
configure "vlan_test2" ipaddress 172.18.18.252/24&lt;BR /&gt;
&lt;BR /&gt;
enable loopback-mode vlan_test1      (or disable, doesn't make a difference)&lt;BR /&gt;
enable loopback-mode vlan_test2      (----------^^---------)&lt;BR /&gt;
&lt;BR /&gt;
configure vlan_test1 add ports 5:24 untagged &lt;BR /&gt;
configure vlan_test2 add ports 5:48 untagged &lt;BR /&gt;
----------------------------------------------------------------&lt;BR /&gt;
Physical Ethernet cable connects 5:24 and 5:48.&lt;BR /&gt;
&lt;BR /&gt;
----------------------------------------------------------------&lt;BR /&gt;
&lt;BR /&gt;
Core-2 # vr vr-test1&lt;BR /&gt;
(vr vr-test1) Core-2.7 # ping 172.18.18.252&lt;BR /&gt;
Ping(ICMP) 172.18.18.252: 4 packets, 8 data bytes, interval 1 second(s).&lt;BR /&gt;
&lt;BR /&gt;
--- 172.18.18.252 ping statistics ---&lt;BR /&gt;
4 packets transmitted, 0 packets received, 100% loss&lt;BR /&gt;
round-trip min/avg/max = 0/0/0 ms&lt;BR /&gt;
&lt;BR /&gt;
(P.S.: Sorry, got confused with "comment" vs "reply". Hope "comment" works...)&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Mar 2014 18:44:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55452#M15998</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2014-03-25T18:44:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55453#M15999</link>
      <description>Hey Frank&lt;BR /&gt;
&lt;BR /&gt;
My suspicion was correct.  The issue is that the switch has one MAC for all VRs.&lt;BR /&gt;
&lt;BR /&gt;
Here's some information from an internal post&lt;BR /&gt;
&lt;BR /&gt;
At L2, a simple cable between the two VRs will do the job. Disable learning on the ports will help.&lt;BR /&gt;
&lt;BR /&gt;
At L3, we need an external device to go from one VR to another. And because we have a unique Mac for the whole   system, you may need 2 external devices... Hopefully, VRF leaking will   come one day (no idea of possible limitations). In the meantime, you can   try to trick the system to enable such feature using a cable to   directly connect two ports in two VRs, and using VRRP to generate a   different mac.&lt;BR /&gt;
&lt;BR /&gt;
I would recommend going to a 460/480 versus trying to do it with VRRP.&lt;BR /&gt;
&lt;BR /&gt;
Let me know if there is anything else I can help with.&lt;BR /&gt;
P&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Mar 2014 03:26:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55453#M15999</guid>
      <dc:creator>Paul_Russo</dc:creator>
      <dc:date>2014-03-26T03:26:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55454#M16000</link>
      <description>We do support below, &lt;BR /&gt;
&lt;BR /&gt;
PC1-----switch------PC2&lt;BR /&gt;
&lt;BR /&gt;
PC1:100.1.1.2/24&lt;BR /&gt;
PC2:200.1.1.2/24&lt;BR /&gt;
&lt;BR /&gt;
Configuration on switch:&lt;BR /&gt;
create virtual-router vrf1 type vrf "VR-Default"virtual-router vrf1&lt;BR /&gt;
configure vr "VR-Default" delete ports 7:8 7:9&lt;BR /&gt;
create vlan v1&lt;BR /&gt;
configure vlan v1 add ports 7:8&lt;BR /&gt;
configure v1 ipaddress 100.1.1.1/24&lt;BR /&gt;
en ipf&lt;BR /&gt;
&lt;BR /&gt;
create virtual-router vrf2 type vrf "VR-Default"&lt;BR /&gt;
virtual-router vrf2&lt;BR /&gt;
create vlan v2&lt;BR /&gt;
configure v2 add ports 7:9&lt;BR /&gt;
configure v2 ipaddress 200.1.1.1/24&lt;BR /&gt;
en ipf&lt;BR /&gt;
&lt;BR /&gt;
VRF forwarding will not be done. So am adding an static  route in vrf1 as&lt;BR /&gt;
&lt;BR /&gt;
    virtual-router vrf1  &lt;BR /&gt;
&lt;BR /&gt;
    &lt;B&gt;configure iproute add  200.1.1.0/24 200.1.1.2 vlan "v2"&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Mar 2014 11:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55454#M16000</guid>
      <dc:creator>Sumit_Tokle</dc:creator>
      <dc:date>2014-03-26T11:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55455#M16001</link>
      <description>That's an interesting approach. I'm surprised that works; I didn't even think of trying that!&lt;BR /&gt;
&lt;BR /&gt;
My "main" VLAN has to be in a full VR (routing protocols), I think, and as I would have to add and protect multiple VLANs in the VRF I'll have to see if I can set simple ACLs.&lt;BR /&gt;
&lt;BR /&gt;
 I'll play with that - thank you much!&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Mar 2014 11:27:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55455#M16001</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2014-03-26T11:27:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55456#M16002</link>
      <description>Paul,&lt;BR /&gt;
&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;In the meantime, you can   try to trick the system to enable such feature using a cable to   directly connect two ports in two VRs, and using VRRP to generate a   different mac.&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;
I actually started out with both of my connected 8806s having both VLANs defined, both 8806s having the patch cable, and I configured VRRP on both the VRs - problem was that I was getting a bunch of "ignoring lower priority VRRP advertsising" notifications (quoted from memory) that I'm not used to get on other VRRPs, but that could've been because I didn't explicitely define "IP tracking", and it might have broadcasted to the entire network, seeing IPs on duplicate MACs and all that.&lt;BR /&gt;
&lt;BR /&gt;
I might revisit that, though, "just because!" (and I'm 'tenacious'). I'll also give Sumit Tokle's idea a shot, but one VLAN has to be in a full VR (because of ospf).&lt;BR /&gt;
&lt;BR /&gt;
Heck, if all else fails, we do have abusable 480s &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Thank you very much - I'll try things out and reply in here how it went.&lt;BR /&gt;
&lt;BR /&gt;
   Frank&lt;BR /&gt;</description>
      <pubDate>Wed, 26 Mar 2014 16:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55456#M16002</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2014-03-26T16:10:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55457#M16003</link>
      <description>Well, so far, it's "a learning experience" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
Generating a new MAC via the VRID: doesn't work too well. Yes, I have a made-up MAC, and yes, it's unique, but the switch doesn't want to get tricked. I presume packets stays on L2 and don't want to get forced to L3, because the switch is just too smart.&lt;BR /&gt;
&lt;BR /&gt;
Sumit's approach: I can't guarantee the presence of "200.1.1.2" on that network or on that switch, so I can't use it, and I can't use the VR's IP because I run into MAC issues again. Or at least I think that's why that failed.&lt;BR /&gt;
&lt;BR /&gt;
I ended up using our 480s to act as an external router between virtual routers. So I have one network/vlan "vlan_test1" in "VR-Test1" (172.18.0.0/24) and a vlan "vlan_test2" in VR-Test2" (172.18.1.0/24), tag them both to the 480s.&lt;BR /&gt;
On the 480 I have "VR-XCHANGE", with both vlans (test1 and test2)", ipforwarding enabled.&lt;BR /&gt;
&lt;BR /&gt;
Since we're talking about two 8800s and two 480s (yay, VRRP!!!), I did accidentally assign the same VRID to the VR on the 8800s and the VR on the 480s. Bad bad bad idea, because all of a sudden they all thought they needed to be able to be redundant, but they saw different virtual IPs (Of course! One for the 480s, one for the 8800s) and freaked out. Changed the VRID on the 480s and voila! all is well!&lt;BR /&gt;
&lt;BR /&gt;
Now I know what else VRIDs do, other than change the virtual MAC  I think, Paul, you mentioned that in another thread about VRRPs - thanks, saved me today.&lt;BR /&gt;
&lt;BR /&gt;
It would be oh-so-nice if I could've just assigned MACs to ports and used a patch-cable, but I understand the design history/decision.&lt;BR /&gt;
&lt;BR /&gt;
Thanks for everyone's input - and if I ever find another way to skin that cat, I'll be back in this thread &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Apr 2014 21:53:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55457#M16003</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2014-04-02T21:53:00Z</dc:date>
    </item>
    <item>
      <title>RE: Routing between virtual routers</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55458#M16004</link>
      <description>Hey Frank&lt;BR /&gt;
&lt;BR /&gt;
Thanks for sharing this with the community as I am sure that it will help someone else down the road.&lt;BR /&gt;
&lt;BR /&gt;
P&lt;BR /&gt;</description>
      <pubDate>Wed, 02 Apr 2014 22:24:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/routing-between-virtual-routers/m-p/55458#M16004</guid>
      <dc:creator>Paul_Russo</dc:creator>
      <dc:date>2014-04-02T22:24:00Z</dc:date>
    </item>
  </channel>
</rss>

