EVPN-VXLAN · BGP leaf-spine · 400G / 800G

El fabric de centro de datos leaf-spine completo, en switches abiertos.

IP Infusion delivers a complete Leaf-spine EVPN-VXLAN data center fabric: 400G and 800G switches running OcNOS-DC, pre-loaded and supported under one contract. You add capacity by adding switches, a server keeps the same gateway on any leaf, and every tenant stays isolated, with a distributed anycast gateway, EVPN multihoming, a BGP underlay, and multi-tenant VRF isolation on open hardware.

Entregado y soportado como un solo sistema

Un switch validado, software y contrato de soporte.

IP Infusion cualifica el switch y OcNOS-DC juntos y les da soporte bajo un contrato, por lo que el fabric que usted diseña es el fabric que se envía. Cada afirmación a continuación se corresponde con una plataforma validada en la lista de hardware y una función soportada en la matrix.

Hardware validado

18 validated data center platforms

Cada switch leaf, spine y border es lab-qualified per platform with OcNOS-DC pre-loaded, from 100G access leaves to 800G Tomahawk 5 spines.

Feature depth

Verificable en la feature matrix

EVPN-VXLAN, la puerta de enlace anycast, el multihoming, el underlay BGP unnumbered y las VNI multi-tenant están cada uno mapped to the platforms that support them.

One contract

Switch, software y RMA juntos

Un equipo es dueño del software, switch, and RMA, and you still refresh the hardware and OcNOS-DC on independent cycles.

La arquitectura de referencia

Cómo se construye el fabric, y qué le aporta cada nivel.

Los servidores se conectan a los leaves, los leaves se conectan a cada spine, y un nivel border alcanza la WAN y el segundo sitio. La división del trabajo entre estos niveles es lo que le permite añadir capacidad a un nivel sin tocar los otros, y permite que un servidor mantenga la misma puerta de enlace donde sea que aterrice.

Topología de fabric DC: leaf-spine EVPN-VXLAN con leaves VTEP, uplinks eBGP ECMP y un border leaf para conectividad externa y reflexión de rutas EVPN
DC Fabric: leaf-spine EVPN-VXLAN con leaves VTEP, eBGP ECMP y un border leaf para conectividad externa.

La misma imagen OcNOS-DC ejecuta cada nivel, por lo que usted dimensiona y licencia por rol y opera una sola línea base de software en todo el fabric.

Dónde se conectan los servidores

Leaf: la rampa de entrada de cada rack

El leaf termina VXLAN y aloja el distributed anycast gateway, so a server sees the same gateway IP and MAC on any leaf. Move or add a workload and it keeps its default route with no re-addressing.

Usted añade capacidad de servidor añadiendo leaves, en un switch Trident 4 de 400G.

Dónde añade ancho

Spine: ancho de banda para todo el fabric

El spine lleva la Underlay BGP unnumbered, reflects EVPN routes, and spreads traffic with overlay ECMP. It holds no tunnel endpoints, so adding a spine adds bandwidth to the whole fabric.

Usted escala más ancho añadiendo spines, sin recablear los leaves.

Dónde sale el fabric

Border leaf: la salida controlada del fabric

El border leaf ejecuta el Puerta de enlace de capa 3 EVPN and advertises each tenant's IP prefixes outward, VRF by VRF. It is your one controlled handoff to the WAN and to the second site.

También es donde dos fabrics se unen para la interconexión coherente.

Qué mantiene el cableado simple

Underlay: cableado plug-and-peer

Cada enlace leaf-spine ejecuta BGP-unnumbered with extended next-hop encoding, so a link peers with no per-interface IP to assign or track. Cabling a new link is plug-and-peer.

Eso es lo que hace que el fabric sea rápido de cablear y rápido de hacer crecer.

Ingeniería EVPN-VXLAN

Cómo construye el switch el fabric.

El fabric crece añadiendo switches, no rearquitectando, y EVPN-VXLAN es lo que hace que eso funcione. VXLAN encapsula en túnel el tráfico de tenant entre leaves sobre el underlay IP, y EVPN anuncia dónde vive cada MAC, host y prefijo, so the switch forwards from a learned control plane instead of flooding to find a host.

RFC 7432 / 8365

EVPN anuncia MAC, IP y prefijos

El leaf ejecuta el EVPN de capa 2 para VXLAN control plane and the prefix route for EVPN IRB, so EVPN carries MAC and IP host routes and IP prefixes across the fabric and each leaf forwards from what it has learned.

Anycast GW

Puerta de enlace anycast distribuida

Cada leaf presenta la same gateway IP and MAC for a subnet, using multiple IP addresses on the IRB interface for the anycast gateway, so a server is always one hop from its gateway no matter which leaf it sits behind.

ESI-LAG

Multihoming EVPN, activo-activo

Multihoming EVPN de capa 2 para VXLAN attaches a server to two or more leaves in active-active mode over an Ethernet Segment. Both links forward, and there is no MLAG peer-link between the leaves.

RFC 7938

Underlay BGP unnumbered

Cada enlace leaf-spine ejecuta VXLAN EVPN con BGP unnumbered using extended next-hop encoding. A link peers without a per-interface IP address, which keeps the underlay simple to cable and grow.

Multi-tenant

Aislamiento VRF sobre VNI

Cada tenant vive en su propia VRF sobre sus propias VNI, y inter-VRF route leaking over EVPN-VXLAN passes only the prefixes you permit, so isolation is the default and any sharing between tenants is explicit.

ECMP + RR

ECMP de overlay y reflexión de rutas

Multipath de igual coste de overlay spreads traffic across every spine, and EVPN route reflection in the fabric passes routes between leaves without a full mesh, so the fabric scales wider by adding spines.

Automatización y operaciones

De switch básico a leaf de producción en minutos.

Un nuevo switch arranca, obtiene su configuración y se une al fabric sin una sesión de consola. A partir de ahí opera el fabric como código, con telemetría en streaming y configuración basada en modelos en cada plataforma.

Onboarding

ZTP at boot

Un switch obtiene su imagen y configuración mediante Zero Touch Provisioning, por lo que pasa de la caja a leaf de producción sin una sesión de consola.

Telemetría

gNMI streaming

gNMI streams telemetry to your collector, dial-in and dial-out, so leaf and spine state is a live feed instead of a poll.

Config as code

NETCONF, OpenConfig, Ansible

Los modelos NETCONF y OpenConfig con Ansible le permiten aplicar y verificar el estado de EVPN y VXLAN como código, de forma consistente en todo el fabric.

Visibility

sFlow, BFD, graceful restart

sFlow samples traffic for visibility, BFD detects a failure fast, and BGP graceful restart keeps the fabric forwarding while a neighbor reconverges.

Interconexión de centros de datos

Interconecte dos fabrics sobre DCI coherente.

Cuando un operador ejecuta dos centros de datos, los tenants de uno necesitan alcanzar a los tenants del otro, y el fabric se extiende por ambos sitios como una sola red. El border leaf in each fabric stitches the two VXLAN Layer 3 domains, each fabric advertises its tenant IP prefixes to the other over EVPN, and a 400G OpenZR+ coherent link carries the traffic between the sites, using the same routed-optical technique already proven on service provider routers.

The stitch

El border leaf une los dominios L3

The Puerta de enlace de capa 3 EVPN on each border leaf performs VXLAN Layer 3 stitching, so one fabric's VXLAN domain hands off to the other at Layer 3 rather than bridging one flat domain across the WAN.

The handoff

Prefijos Type-5, por tenant

Cada fabric anuncia sus prefijos IP de tenant al otro como Rutas de prefijo IP EVPN, reflected by the route servers, and inter-VRF route leaking keeps each tenant's VRF isolated across both sites.

The transport

400G ZR+ coherente, sin transponder

Un switch con capacidad ZR+ aloja un 400G OpenZR+ coherent optic directly in a faceplate port and lights the wavelength, with no separate transponder shelf. The same 400G coherent DCI runs on data center switches like the Edgecore AS9726-32DB and on the service provider routers already deployed for interconnect, and the 800G Tomahawk 5 fabric scales the port capacity behind it.

See it end to end

Cambie la vista entre el fabric de un sitio, la unión DCI coherente entre sitios, y el fabric remoto.

Selector de interconexión de centros de datos de dos sitios Dos fabrics leaf-spine EVPN-VXLAN, Sitio A a la izquierda y Sitio B a la derecha, cada uno con dos leaves y un spine y un border leaf, unidos en el centro por un enlace coherente 400G OpenZR+ entre los dos border leaves. Seleccione una vista para resaltar el fabric de un sitio, la unión de interconexión, o el fabric remoto. Leaf A1 VTEP Leaf A2 VTEP Spine A underlay RR SITE A Border A L3 gateway Border B L3 gateway 400G ZR+ coherente Handoff EVPN Type-5, unión L3 VXLAN Spine B underlay RR Leaf B1 VTEP Leaf B2 VTEP SITE B

Unión DCI coherente. Los dos border leaves unen los fabrics en la capa 3 y encienden un enlace coherente 400G OpenZR+ entre los sitios. Cada fabric anuncia sus prefijos IP de tenant al otro como rutas EVPN Type-5, y el aislamiento VRF por tenant se preserva en ambos sitios.

Platform sizing

Qué switch validado para qué rol.

IP Infusion entrega el fabric sobre 18 validated data center platforms from Edgecore and UfiSpace, each lab-qualified per platform with OcNOS-DC pre-loaded. Leaves size on port count and the anycast gateway; spines size on fabric width; the interconnect leaf sizes on the coherent optic.

Switches de centro de datos validados por rol de fabric. Última verificación: jul 2026.
Función Validated switch Silicio y capacidad Por qué encaja en el rol
Leaf (400G) Edgecore AS9726-32DB / UfiSpace S9300-32D Broadcom Trident 4, 12.8 Tbps, 400G El nivel VTEP: puertos orientados al servidor, la puerta de enlace anycast distribuida y el multihoming EVPN.
Spine (400G) Edgecore AS9736-64D Broadcom Tomahawk 4, 25.6 Tbps, 400G ECMP de underlay y reflexión de rutas EVPN, sin VTEP, dimensionado para el ancho del fabric.
Spine / super-spine (800G) Edgecore AIS800-64D / UfiSpace S9321-64E Broadcom Tomahawk 5, 51.2 Tbps, 800G Escalado horizontal de 800G para los fabrics más grandes. El AIS800-64D utiliza óptica QSFP-DD800.
Leaf de interconexión (400G coherente) Edgecore AS9726-32DB Broadcom Trident 4, 12.8 Tbps, 32×400G, 400G ZR+ coherent Aloja un pluggable coherente 400G OpenZR+ en un puerto QSFP-DD y enciende la longitud de onda de interconexión directamente, sin transponder externo.
Leaf / ToR de 100G Edgecore AS7726-32X / UfiSpace S9110-32X Broadcom Trident 3, 3.2 Tbps, 100G Leaves de nivel de acceso para racks de servidores de 25G y 100G.

18 validated data center platforms. See every validated platform, including the rest of the portfolio, in the lista de compatibilidad de hardware, y haga coincidir las funciones con el hardware en la matriz de funciones.

Compare todo el portafolio de silicio Broadcom en el que se ejecuta OcNOS, StrataXGS y StrataDNX →

Cómo dimensionar el fabric

  • Leaf tier. Ponga los leaves en Trident 4 de 400G para el VTEP, la puerta de enlace anycast y el multihoming EVPN, o en un leaf Trident 3 de 100G para racks de servidores de 25G y 100G.
  • Spine tier. Ponga los spines en Tomahawk 4 de 400G, o en Tomahawk 5 de 800G cuando el fabric necesite escalar más ancho, y añada spines en lugar de tocar los leaves.
  • Interconnect leaf. Use el AS9726-32DB con pluggables coherentes 400G OpenZR+ en sus puertos QSFP-DD cuando el fabric se extienda a un segundo sitio, para que el leaf de interconexión encienda la longitud de onda directamente.
  • One contract. IP Infusion valida y da soporte a cada rol como un solo sistema, y el switch y OcNOS-DC se renuevan en ciclos independientes.
Config: VTEP de leaf con puerta de enlace anycast

Configurar un VTEP de leaf.

Each leaf terminates VXLAN tunnels, hosts the distributed anycast gateway, and runs the EVPN address family in BGP. Below is a representative OcNOS-DC leaf configuration: VXLAN with integrated routing and bridging, a tenant with its layer 3 VNI and bridge domain, the distributed anycast gateway with a shared MAC, the VNI to tenant mapping, and EVPN under BGP.

OcNOS-DC · leaf VTEP
! Leaf VTEP: VXLAN overlay, distributed anycast gateway, EVPN in BGP
configure terminal
nvo vxlan enable
nvo vxlan irb
evpn irb-forwarding anycast-gateway-mac 0000.0000.1111
ip vrf tenant1
 l3vni 5010
mac vrf tenant1_l2
 rd 10.0.0.1:10
 route-target both 100:10
interface irb10
 ip vrf forwarding tenant1
 ip address 10.10.10.1/24 anycast
 evpn irb-if-forwarding anycast-gateway-mac
nvo vxlan id 10 ingress-replication inner-vid-disabled
 vxlan host-reachability-protocol evpn-bgp tenant1_l2
 evpn irb10
nvo vxlan vtep-ip-global 10.0.0.1
router bgp 65001
 neighbor 10.0.1.1 remote-as 65000
 address-family l2vpn evpn
  neighbor 10.0.1.1 activate

Qué hace cada línea

  1. nvo vxlan enable and nvo vxlan irb turn on VXLAN and integrated routing and bridging, so the leaf both switches inside a subnet and routes between subnets over the fabric.
  2. evpn irb-forwarding anycast-gateway-mac 0000.0000.1111 sets one shared gateway MAC for the whole fabric, so every leaf answers as the same default gateway.
  3. ip vrf tenant1 with l3vni 5010 gives the tenant its own routing table and the layer 3 VNI that carries routed traffic between subnets across the fabric.
  4. mac vrf tenant1_l2 with its rd and route-target both gives the tenant bridge domain a route distinguisher and import and export targets, so EVPN keeps each tenant's MAC and IP routes separate.
  5. interface irb10 is the tenant gateway: ip vrf forwarding tenant1 binds it to the tenant table, ip address sets the gateway IP, and evpn irb-if-forwarding anycast-gateway-mac applies the shared anycast MAC to this interface.
  6. The nvo vxlan id 10 block maps VNI 10 to the tenant, uses ingress replication for broadcast and multicast traffic, and sets host-reachability-protocol evpn-bgp so BGP EVPN learns host reachability.
  7. nvo vxlan vtep-ip-global 10.0.0.1 sets the tunnel-endpoint address, a loopback, that identifies this leaf in the fabric.
  8. router bgp 65001 with neighbor 10.0.1.1 remote-as 65000 forms the session to the spine, and the address-family l2vpn evpn block activates EVPN so the leaf advertises and learns MAC, IP, and prefix routes.

These are OcNOS-DC VXLAN and EVPN commands from the OcNOS-DC configuration guide, shown with example VNIs, VRF names, and addresses rather than copied from one device. Confirm the exact IDs, route targets, and addresses for your fabric against the OcNOS-DC VXLAN and EVPN configuration guide at documentation.ipinfusion.com.

Abierto frente a propietario

Switch de fabric abierto frente a un switch de centro de datos propietario.

Frente a Arista o Cisco, la pregunta sobre el fabric es si un switch abierto ejecuta leaf-spine EVPN-VXLAN de forma tan completa. OcNOS-DC lo hace, sobre silicio merchant que el operador puede comprar a más de un proveedor, todo bajo un único contrato de soporte.

Switch de fabric abierto sobre OcNOS-DC frente a plataformas de centro de datos propietarias. Última verificación: jul 2026.
Fabric capability Switch abierto (OcNOS-DC) Propietario (Arista EOS / Cisco NX-OS / Juniper Junos)
Fabric leaf-spine EVPN-VXLAN details →
Puerta de enlace anycast distribuida
Multihoming EVPN (ESI-LAG, sin dependencia de MLAG)
Underlay BGP unnumbered details →
Aislamiento VRF y VNI multi-tenant
ZTP, gNMI, NETCONF y OpenConfig
800G en Tomahawk 5
Aprovisionamiento de hardware Silicio merchant abierto de múltiples proveedores Switch de un solo proveedor
Entrega y soporte Switch completo, un contrato de soporte, renovación de switch y software por separado Vendor-bundled

Arista, EOS, Cisco, NX-OS, Nexus, Juniper y Junos son marcas comerciales de sus respectivos propietarios. IP Infusion no está afiliada a estos proveedores ni los respalda; la comparación refleja las capacidades de OcNOS-DC verificables en la matriz de funciones.

Antes de evaluar

Preguntas sobre el fabric de centro de datos.

Un fabric de centro de datos leaf-spine EVPN-VXLAN es una red de escalado horizontal que crece añadiendo switches. Cada leaf es un endpoint de túnel VXLAN, BGP transporta el underlay entre leaf y spine, y EVPN anuncia rutas de host MAC e IP y prefijos IP, por lo que el fabric reenvía desde un plano de control aprendido en lugar de inundar. IP Infusion lo ofrece como un solo sistema: el switch, OcNOS-DC precargado y un único contrato de soporte, con una puerta de enlace anycast distribuida, multihoming EVPN y aislamiento VRF multi-tenant.
Cada tenant obtiene su propio conjunto de identificadores de red VXLAN (VNI): las VNI de capa 2 transportan tráfico puenteado y las VNI de capa 3 transportan tráfico enrutado dentro de una VRF por tenant. Como el tráfico se encapsula por VNI y se enruta dentro de una VRF, un tenant no puede ver a otro tenant en el fabric compartido. Donde dos tenants necesitan comunicarse, la fuga de rutas inter-VRF sobre EVPN-VXLAN pasa solo los prefijos específicos que usted permita, por lo que el aislamiento sigue siendo el valor por defecto y la compartición es explícita.
El multihoming EVPN permite que un servidor se conecte a dos o más leaves a la vez en modo activo-activo usando un Ethernet Segment Identifier (ESI-LAG), por lo que ambos enlaces reenvían tráfico y el fallo de un leaf es transparente. Se señaliza por completo en el plano de control EVPN, así que no hay un peer-link dedicado ni emparejamiento propietario entre los dos leaves. Esa es la diferencia con MLAG, que empareja exactamente dos switches sobre un peer-link. OcNOS-DC admite ambos, por lo que un diseño que quiera dual-homing clásico aún puede usar MLAG.
El border leaf de cada fabric une los dos dominios de capa 3 VXLAN, y cada fabric anuncia sus prefijos IP de tenant al otro como rutas de prefijo IP EVPN, con el aislamiento VRF por tenant preservado entre los sitios. Para el transporte, una óptica coherente 400G OpenZR+ en un switch con capacidad ZR+, como el Edgecore AS9726-32DB o un router de proveedor de servicios ya desplegado para interconexión, enciende la longitud de onda directamente en un puerto QSFP-DD, por lo que no hay transponder separado. Los switches Tomahawk 5 de 800G llevan el fabric detrás. Para el análisis profundo de la óptica consulte la solución de óptica enrutada, y para la matemática de alcance coherente consulte la página de tecnología de DCI coherente.
Sí, para un fabric leaf-spine EVPN-VXLAN. OcNOS-DC ejecuta las mismas capacidades de fabric en switches de silicio merchant: EVPN-VXLAN con una puerta de enlace anycast distribuida, multihoming EVPN, un underlay BGP unnumbered, VNI multi-tenant, y ZTP con gNMI y NETCONF para operaciones. IP Infusion entrega el switch, el software y el soporte como un solo sistema bajo un contrato, y usted abastece hardware de más de un proveedor de hardware abierto y renueva el switch y el software en ciclos independientes.
Un nuevo switch arranca y obtiene su configuración mediante Zero Touch Provisioning, por lo que un switch pasa de la caja a leaf de producción sin una sesión de consola. A partir de ahí el fabric se opera con telemetría en streaming sobre gNMI, modelos NETCONF y OpenConfig, y Ansible, y los mismos modelos le permiten aplicar y verificar el estado de EVPN y VXLAN como código. IP Infusion envía el switch con OcNOS-DC precargado y una línea base validada, por lo que la imagen de Día 0 es consistente en cada leaf y spine.
Evaluar el fabric

Consulte el fabric de centro de datos abierto.

Vea cómo IP Infusion entrega el fabric leaf-spine EVPN-VXLAN como un solo sistema, o contáctenos para mapear sus leaves, spines e interconexión a las plataformas validadas adecuadas.