EVPN-VXLAN · BGP leaf-spine · 400G / 800G

Il fabric data center leaf-spine completo, su switch aperti.

IP Infusion delivers a complete Leaf-spine EVPN-VXLAN data center fabric: 400G and 800G switches running OcNOS-DC, pre-loaded and supported under one contract. You add capacity by adding switches, a server keeps the same gateway on any leaf, and every tenant stays isolated, with a distributed anycast gateway, EVPN multihoming, a BGP underlay, and multi-tenant VRF isolation on open hardware.

Fornito e supportato come un unico sistema

Un unico switch convalidato, software e contratto di supporto.

IP Infusion qualifica lo switch e OcNOS-DC insieme e li supporta sotto un unico contratto, così il fabric che progetta è il fabric che viene consegnato. Ogni affermazione qui sotto è mappata a una piattaforma convalidata nell'elenco hardware e a una funzionalità supportata nella matrix.

Hardware qualificato

18 validated data center platforms

Ogni switch leaf, spine e border è lab-qualified per platform with OcNOS-DC pre-loaded, from 100G access leaves to 800G Tomahawk 5 spines.

Feature depth

Verificabile nella feature matrix

EVPN-VXLAN, il gateway anycast, il multihoming, l'underlay BGP-unnumbered e i VNI multi-tenant sono ciascuno mapped to the platforms that support them.

One contract

Switch, software e RMA insieme

Un unico team possiede il software, switch, and RMA, and you still refresh the hardware and OcNOS-DC on independent cycles.

L'architettura di riferimento

Come è costruito il fabric, e cosa offre ogni livello.

I server si collegano ai leaf, i leaf si connettono a ogni spine, e un livello border raggiunge la WAN e il secondo sito. La suddivisione del lavoro tra questi livelli è ciò che ti consente di aggiungere capacità a un livello senza toccare gli altri, e consente a un server di mantenere lo stesso gateway ovunque atterri.

Topologia DC fabric: leaf-spine EVPN-VXLAN con leaf VTEP, uplink eBGP ECMP e un border leaf per la connettività esterna e la route reflection EVPN
DC Fabric: leaf-spine EVPN-VXLAN con leaf VTEP, eBGP ECMP e un border leaf per la connettività esterna.

La stessa immagine OcNOS-DC esegue ogni livello, così dimensioni e concedi in licenza per ruolo e gestisci un'unica baseline software su tutto il fabric.

Dove si collegano i server

Leaf: la rampa di accesso di ogni rack

Il leaf termina VXLAN e ospita il distributed anycast gateway, so a server sees the same gateway IP and MAC on any leaf. Move or add a workload and it keeps its default route with no re-addressing.

Aggiungi capacità server aggiungendo leaf, su uno switch Trident 4 400G.

Dove aggiungi ampiezza

Spine: banda per l'intero fabric

Lo spine trasporta la Underlay BGP-unnumbered, reflects EVPN routes, and spreads traffic with overlay ECMP. It holds no tunnel endpoints, so adding a spine adds bandwidth to the whole fabric.

Scali più ampio aggiungendo spine, senza ricablare i leaf.

Dove il fabric esce

Border leaf: l'uscita controllata del fabric

Il border leaf esegue il Gateway Layer 3 EVPN and advertises each tenant's IP prefixes outward, VRF by VRF. It is your one controlled handoff to the WAN and to the second site.

È anche dove due fabric si cuciono insieme per l'interconnessione coerente.

Cosa mantiene semplice il cablaggio

Underlay: cablaggio plug-and-peer

Ogni collegamento leaf-spine esegue BGP-unnumbered with extended next-hop encoding, so a link peers with no per-interface IP to assign or track. Cabling a new link is plug-and-peer.

Questo è ciò che rende il fabric rapido da cablare e rapido da far crescere.

Engineering EVPN-VXLAN

Come lo switch costruisce il fabric.

Il fabric cresce aggiungendo switch, non ri-architettando, ed EVPN-VXLAN è ciò che fa funzionare tutto questo. VXLAN incapsula in tunnel il traffico tenant tra i leaf sull'underlay IP, e EVPN annuncia dove risiede ogni MAC, host e prefisso, so the switch forwards from a learned control plane instead of flooding to find a host.

RFC 7432 / 8365

EVPN annuncia MAC, IP e prefissi

Il leaf esegue il EVPN Layer 2 per VXLAN control plane and the prefix route for EVPN IRB, so EVPN carries MAC and IP host routes and IP prefixes across the fabric and each leaf forwards from what it has learned.

Anycast GW

Gateway anycast distribuito

Ogni leaf presenta il same gateway IP and MAC for a subnet, using multiple IP addresses on the IRB interface for the anycast gateway, so a server is always one hop from its gateway no matter which leaf it sits behind.

ESI-LAG

Multihoming EVPN, active-active

Multihoming EVPN Layer 2 per VXLAN attaches a server to two or more leaves in active-active mode over an Ethernet Segment. Both links forward, and there is no MLAG peer-link between the leaves.

RFC 7938

Underlay BGP-unnumbered

Ogni collegamento leaf-spine esegue VXLAN EVPN con BGP unnumbered using extended next-hop encoding. A link peers without a per-interface IP address, which keeps the underlay simple to cable and grow.

Multi-tenant

Isolamento VRF sui VNI

Ogni tenant vive nella propria VRF sui propri VNI, e inter-VRF route leaking over EVPN-VXLAN passes only the prefixes you permit, so isolation is the default and any sharing between tenants is explicit.

ECMP + RR

Overlay ECMP e route reflection

Overlay multipath a costo uguale spreads traffic across every spine, and EVPN route reflection in the fabric passes routes between leaves without a full mesh, so the fabric scales wider by adding spines.

Automazione e operazioni

Dallo switch nudo a leaf di produzione in pochi minuti.

Un nuovo switch si avvia, recupera la sua configurazione e si unisce al fabric senza sessione console. Da lì gestisce il fabric come codice, con telemetria in streaming e configurazione model-driven su ogni piattaforma.

Onboarding

ZTP at boot

Uno switch recupera la sua immagine e configurazione tramite Zero Touch Provisioning, così passa dalla scatola a leaf di produzione senza una sessione console.

Telemetria

gNMI streaming

gNMI streams telemetry to your collector, dial-in and dial-out, so leaf and spine state is a live feed instead of a poll.

Config as code

NETCONF, OpenConfig, Ansible

I modelli NETCONF e OpenConfig con Ansible consentono di applicare e verificare lo stato EVPN e VXLAN come codice, in modo coerente su tutto il fabric.

Visibilità

sFlow, BFD, graceful restart

sFlow samples traffic for visibility, BFD detects a failure fast, and BGP graceful restart keeps the fabric forwarding while a neighbor reconverges.

Interconnessione data center

Interconnetti due fabric su DCI coerente.

Quando un operatore gestisce due data center, i tenant di uno devono raggiungere i tenant dell'altro, e il fabric si estende su entrambi i siti come un'unica rete. Il border leaf in each fabric stitches the two VXLAN Layer 3 domains, each fabric advertises its tenant IP prefixes to the other over EVPN, and a 400G OpenZR+ coherent link carries the traffic between the sites, using the same routed-optical technique already proven on service provider routers.

The stitch

Il border leaf cuce insieme i domini L3

The Gateway Layer 3 EVPN on each border leaf performs VXLAN Layer 3 stitching, so one fabric's VXLAN domain hands off to the other at Layer 3 rather than bridging one flat domain across the WAN.

The handoff

Prefissi Type-5, per-tenant

Ogni fabric annuncia i suoi prefissi IP tenant all'altro come Route EVPN IP-prefix, reflected by the route servers, and inter-VRF route leaking keeps each tenant's VRF isolated across both sites.

The transport

400G ZR+ coerente, senza transponder

Uno switch con capacità ZR+ ospita un 400G OpenZR+ coherent optic directly in a faceplate port and lights the wavelength, with no separate transponder shelf. The same 400G coherent DCI runs on data center switches like the Edgecore AS9726-32DB and on the service provider routers already deployed for interconnect, and the 800G Tomahawk 5 fabric scales the port capacity behind it.

See it end to end

Commuta la vista tra il fabric di un sito, la cucitura DCI coerente tra i siti e il fabric remoto.

Selettore di interconnessione data center a due siti Due fabric EVPN-VXLAN leaf-spine, il Sito A a sinistra e il Sito B a destra, ciascuno con due leaf e uno spine e un border leaf, uniti al centro da un collegamento coerente 400G OpenZR+ tra i due border leaf. Seleziona una vista per evidenziare il fabric di un sito, la cucitura di interconnessione o il fabric remoto. Leaf A1 VTEP Leaf A2 VTEP Spine A underlay RR SITE A Border A L3 gateway Border B L3 gateway 400G ZR+ coerente Handoff EVPN Type-5, cucitura L3 VXLAN Spine B underlay RR Leaf B1 VTEP Leaf B2 VTEP SITE B

Cucitura DCI coerente. I due border leaf cuciono i fabric a Layer 3 e accendono un collegamento coerente 400G OpenZR+ tra i siti. Ogni fabric annuncia i suoi prefissi IP tenant all'altro come route EVPN Type-5, e l'isolamento VRF per-tenant è preservato tra entrambi i siti.

Platform sizing

Quale switch convalidato per quale ruolo.

IP Infusion fornisce il fabric su 18 validated data center platforms from Edgecore and UfiSpace, each lab-qualified per platform with OcNOS-DC pre-loaded. Leaves size on port count and the anycast gateway; spines size on fabric width; the interconnect leaf sizes on the coherent optic.

Switch data center convalidati per ruolo di fabric. Ultima verifica: lug 2026.
Ruolo Validated switch Silicio e capacità Perché si adatta al ruolo
Leaf (400G) Edgecore AS9726-32DB / UfiSpace S9300-32D Broadcom Trident 4, 12.8 Tbps, 400G Il livello VTEP: porte rivolte ai server, il gateway anycast distribuito e il multihoming EVPN.
Spine (400G) Edgecore AS9736-64D Broadcom Tomahawk 4, 25.6 Tbps, 400G ECMP dell'underlay e route reflection EVPN, nessun VTEP, dimensionato per l'ampiezza del fabric.
Spine / super-spine (800G) Edgecore AIS800-64D / UfiSpace S9321-64E Broadcom Tomahawk 5, 51.2 Tbps, 800G Scale-out a 800G per i fabric più grandi. L'AIS800-64D utilizza ottiche QSFP-DD800.
Leaf di interconnessione (coerente 400G) Edgecore AS9726-32DB Broadcom Trident 4, 12.8 Tbps, 32×400G, 400G ZR+ coherent Colloca un pluggable coerente 400G OpenZR+ in una porta QSFP-DD e accende direttamente la lunghezza d'onda di interconnessione, senza transponder esterno.
Leaf / ToR 100G Edgecore AS7726-32X / UfiSpace S9110-32X Broadcom Trident 3, 3.2 Tbps, 100G Leaf del livello di accesso per rack server 25G e 100G.

18 validated data center platforms. See every validated platform, including the rest of the portfolio, in the hardware compatibility list, e abbina le funzionalità all'hardware nella matrice delle funzionalità.

Confronta l'intero portfolio di silicio Broadcom su cui gira OcNOS, StrataXGS e StrataDNX →

Come dimensionare il fabric

  • Leaf tier. Metti i leaf su Trident 4 400G per il VTEP, il gateway anycast e il multihoming EVPN, o su un leaf Trident 3 100G per rack server 25G e 100G.
  • Spine tier. Metti gli spine su Tomahawk 4 400G, o su Tomahawk 5 800G quando il fabric deve scalare più ampio, e aggiungi spine invece di toccare i leaf.
  • Interconnect leaf. Usa l'AS9726-32DB con pluggable coerenti 400G OpenZR+ nelle sue porte QSFP-DD quando il fabric si estende a un secondo sito, così il leaf di interconnessione accende la lunghezza d'onda direttamente.
  • One contract. IP Infusion convalida e supporta ogni ruolo come un unico sistema, e lo switch e OcNOS-DC si aggiornano su cicli indipendenti.
Config: leaf VTEP con anycast gateway

Configura un leaf VTEP.

Each leaf terminates VXLAN tunnels, hosts the distributed anycast gateway, and runs the EVPN address family in BGP. Below is a representative OcNOS-DC leaf configuration: VXLAN with integrated routing and bridging, a tenant with its layer 3 VNI and bridge domain, the distributed anycast gateway with a shared MAC, the VNI to tenant mapping, and EVPN under BGP.

OcNOS-DC · leaf VTEP
! Leaf VTEP: VXLAN overlay, distributed anycast gateway, EVPN in BGP
configure terminal
nvo vxlan enable
nvo vxlan irb
evpn irb-forwarding anycast-gateway-mac 0000.0000.1111
ip vrf tenant1
 l3vni 5010
mac vrf tenant1_l2
 rd 10.0.0.1:10
 route-target both 100:10
interface irb10
 ip vrf forwarding tenant1
 ip address 10.10.10.1/24 anycast
 evpn irb-if-forwarding anycast-gateway-mac
nvo vxlan id 10 ingress-replication inner-vid-disabled
 vxlan host-reachability-protocol evpn-bgp tenant1_l2
 evpn irb10
nvo vxlan vtep-ip-global 10.0.0.1
router bgp 65001
 neighbor 10.0.1.1 remote-as 65000
 address-family l2vpn evpn
  neighbor 10.0.1.1 activate

Cosa fa ogni riga

  1. nvo vxlan enable e nvo vxlan irb turn on VXLAN and integrated routing and bridging, so the leaf both switches inside a subnet and routes between subnets over the fabric.
  2. evpn irb-forwarding anycast-gateway-mac 0000.0000.1111 sets one shared gateway MAC for the whole fabric, so every leaf answers as the same default gateway.
  3. ip vrf tenant1 with l3vni 5010 gives the tenant its own routing table and the layer 3 VNI that carries routed traffic between subnets across the fabric.
  4. mac vrf tenant1_l2 with its rd e route-target both gives the tenant bridge domain a route distinguisher and import and export targets, so EVPN keeps each tenant's MAC and IP routes separate.
  5. interface irb10 is the tenant gateway: ip vrf forwarding tenant1 binds it to the tenant table, ip address sets the gateway IP, and evpn irb-if-forwarding anycast-gateway-mac applies the shared anycast MAC to this interface.
  6. The nvo vxlan id 10 block maps VNI 10 to the tenant, uses ingress replication for broadcast and multicast traffic, and sets host-reachability-protocol evpn-bgp so BGP EVPN learns host reachability.
  7. nvo vxlan vtep-ip-global 10.0.0.1 sets the tunnel-endpoint address, a loopback, that identifies this leaf in the fabric.
  8. router bgp 65001 with neighbor 10.0.1.1 remote-as 65000 forms the session to the spine, and the address-family l2vpn evpn block activates EVPN so the leaf advertises and learns MAC, IP, and prefix routes.

These are OcNOS-DC VXLAN and EVPN commands from the OcNOS-DC configuration guide, shown with example VNIs, VRF names, and addresses rather than copied from one device. Confirm the exact IDs, route targets, and addresses for your fabric against the OcNOS-DC VXLAN and EVPN configuration guide at documentation.ipinfusion.com.

Aperto vs proprietario

Switch fabric aperto rispetto a uno switch data center proprietario.

Rispetto ad Arista o Cisco, la questione del fabric è se uno switch aperto esegua leaf-spine EVPN-VXLAN in modo altrettanto completo. OcNOS-DC lo fa, su silicio merchant che l'operatore può acquistare da più di un fornitore, il tutto sotto un unico contratto di supporto.

Switch fabric aperto su OcNOS-DC rispetto a piattaforme data center proprietarie. Ultima verifica: lug 2026.
Fabric capability Switch aperto (OcNOS-DC) Proprietario (Arista EOS / Cisco NX-OS / Juniper Junos)
Fabric EVPN-VXLAN leaf-spine details →
Gateway anycast distribuito
Multihoming EVPN (ESI-LAG, nessuna dipendenza da MLAG)
Underlay BGP-unnumbered details →
Isolamento VRF e VNI multi-tenant
ZTP, gNMI, NETCONF e OpenConfig
800G su Tomahawk 5
Approvvigionamento hardware Silicio merchant aperto da più fornitori Switch single-vendor
Consegna e supporto Switch completo, un unico contratto di supporto, rinnovo di switch e software separatamente Vendor-bundled

Arista, EOS, Cisco, NX-OS, Nexus, Juniper e Junos sono marchi dei rispettivi proprietari. IP Infusion non è affiliata e non approva questi fornitori; il confronto riflette le capacità di OcNOS-DC verificabili nella matrice delle funzionalità.

Prima di valutare

Domande sul fabric data center.

Un fabric data center EVPN-VXLAN leaf-spine è una rete scale-out che cresce aggiungendo switch. Ogni leaf è un endpoint di tunnel VXLAN, BGP trasporta l'underlay tra leaf e spine, ed EVPN annuncia le route host MAC e IP e i prefissi IP, così il fabric inoltra da un piano di controllo appreso invece che tramite flooding. IP Infusion lo fornisce come un unico sistema: lo switch, OcNOS-DC preinstallato e un unico contratto di supporto, con un gateway anycast distribuito, multihoming EVPN e isolamento VRF multi-tenant.
Ogni tenant ottiene il proprio set di identificatori di rete VXLAN (VNI): i VNI Layer 2 trasportano traffico in bridging e i VNI Layer 3 trasportano traffico instradato all'interno di una VRF per tenant. Poiché il traffico è incapsulato per VNI e instradato all'interno di una VRF, un tenant non può vedere un altro tenant sul fabric condiviso. Dove due tenant devono raggiungersi, il route leaking inter-VRF su EVPN-VXLAN passa solo i prefissi specifici che consente, così l'isolamento resta l'impostazione predefinita e la condivisione è esplicita.
Il multihoming EVPN consente a un server di collegarsi a due o più leaf contemporaneamente in modalità active-active usando un Ethernet Segment Identifier (ESI-LAG), così entrambi i collegamenti inoltrano il traffico e il guasto di un leaf è trasparente. È segnalato interamente nel piano di controllo EVPN, quindi non c'è un peer-link dedicato né un accoppiamento proprietario tra i due leaf. Questa è la differenza rispetto a MLAG, che accoppia esattamente due switch su un peer-link. OcNOS-DC supporta entrambi, così un design che desidera il classico dual-homing può comunque usare MLAG.
Il border leaf in ogni fabric cuce insieme i due domini Layer 3 VXLAN, e ogni fabric annuncia i suoi prefissi IP tenant all'altro come route EVPN IP-prefix, con l'isolamento VRF per-tenant preservato tra i siti. Per il trasporto, un'ottica coerente 400G OpenZR+ in uno switch con capacità ZR+, come l'Edgecore AS9726-32DB o un service provider router già distribuito per l'interconnessione, accende la lunghezza d'onda direttamente in una porta QSFP-DD, così non c'è un transponder separato. Gli switch Tomahawk 5 800G trasportano il fabric dietro di esso. Per l'approfondimento sulle ottiche consulti la soluzione routed-optical, e per il calcolo della portata coerente consulti la pagina tecnologica DCI coerente.
Sì, per un fabric EVPN-VXLAN leaf-spine. OcNOS-DC esegue le stesse capacità di fabric su switch a silicio merchant: EVPN-VXLAN con un gateway anycast distribuito, multihoming EVPN, un underlay BGP-unnumbered, VNI multi-tenant, e ZTP con gNMI e NETCONF per le operazioni. IP Infusion fornisce lo switch, il software e il supporto come un unico sistema sotto un unico contratto, e reperisci l'hardware da più di un fornitore di hardware aperto e rinnovi lo switch e il software su cicli indipendenti.
Un nuovo switch si avvia e recupera la sua configurazione tramite Zero Touch Provisioning, così passa dalla scatola a leaf di produzione senza una sessione console. Da lì il fabric viene gestito con telemetria in streaming su gNMI, modelli NETCONF e OpenConfig, e Ansible, e gli stessi modelli consentono di applicare e verificare lo stato EVPN e VXLAN come codice. IP Infusion fornisce lo switch con OcNOS-DC preinstallato e una baseline convalidata, così l'immagine Day 0 è coerente su ogni leaf e spine.
Valuta il fabric

Consulti il fabric data center aperto.

Scopra come IP Infusion fornisce il fabric EVPN-VXLAN leaf-spine come un unico sistema, oppure ci contatti per mappare i suoi leaf, spine e interconnessione sulle piattaforme convalidate corrette.