EVPN-VXLAN · BGP leaf-spine · 400G / 800G

オープンスイッチ上の完全なリーフスパインデータセンターファブリック。

IP Infusion delivers a complete EVPN-VXLAN リーフ-スパイン data center fabric: 400G and 800G switches running OcNOS-DC, pre-loaded and supported under one contract. You add capacity by adding switches, a server keeps the same gateway on any leaf, and every tenant stays isolated, with a distributed anycast gateway, EVPN multihoming, a BGP underlay, and multi-tenant VRF isolation on open hardware.

一つのシステムとして提供およびサポート

検証済みのスイッチ、ソフトウェア、サポート契約を1つに。

IP Infusion はスイッチと OcNOS-DC を一体で認定し、一つの契約でサポートします。設計したファブリックがそのまま出荷されるファブリックになります。以下の各記載は、ハードウェアリストの検証済みプラットフォームと機能マトリクスのサポート済み機能に対応します。

検証済みハードウェア

18 validated data center platforms

各リーフ、スパイン、ボーダースイッチは lab-qualified per platform with OcNOS-DC pre-loaded, from 100G access leaves to 800G Tomahawk 5 spines.

Feature depth

機能マトリクスで検証可能

EVPN-VXLAN、エニーキャストゲートウェイ、マルチホーミング、BGP-unnumberedアンダーレイ、マルチテナントVNIはそれぞれ mapped to the platforms that support them.

One contract

スイッチ、ソフトウェア、RMA を一体で

1つのチームが担うのは software, switch, and RMA, and you still refresh the hardware and OcNOS-DC on independent cycles.

リファレンスアーキテクチャ

ファブリックの構築方法と、各ティアが提供する価値。

サーバーはリーフに接続し、リーフはすべてのスパインに接続し、ボーダーティアが WAN と第 2 サイトへ到達します。これらのティア間で処理を分割することにより、他のティアに手を触れずに 1 つのティアへ容量を追加でき、サーバーはどこに配置されても同一のゲートウェイを保持可能。

DCファブリックトポロジ: VTEPリーフ、eBGP ECMPアップリンク、外部接続とEVPNルートリフレクション用のボーダーリーフを備えたリーフスパインEVPN-VXLAN
DC Fabric: VTEPリーフ、eBGP ECMP、外部接続用ボーダーリーフを備えたEVPN-VXLANリーフスパイン。

同一の OcNOS-DC イメージがすべてのティアを実行するため、役割ごとにサイジングおよびライセンス付与を行い、ファブリック全体で 1 つのソフトウェアベースラインを運用可能。

サーバーが接続する場所

リーフ: 各ラックのオンランプ

リーフは VXLAN を終端し、次をホストします: distributed anycast gateway, so a server sees the same gateway IP and MAC on any leaf. Move or add a workload and it keeps its default route with no re-addressing.

Trident 4 400Gスイッチ上でleafを追加することにより、サーバー容量を拡張。

幅を追加する場所

スパイン:ファブリック全体のための帯域幅

スパインは次を運びます: BGP-unnumberedアンダーレイ, reflects EVPN routes, and spreads traffic with overlay ECMP. It holds no tunnel endpoints, so adding a spine adds bandwidth to the whole fabric.

leafを再配線することなくspineを追加し、より広くスケール。

ファブリックが出ていく場所

border leaf:ファブリックの制御された出口

ボーダーリーフは次を実行します: EVPN Layer 3ゲートウェイ and advertises each tenant's IP prefixes outward, VRF by VRF. It is your one controlled handoff to the WAN and to the second site.

ここは 2 つのファブリックがコヒーレント相互接続のために結合する地点でもあります。

配線をシンプルに保つ要素

アンダーレイ:プラグアンドピア方式の配線

各リーフスパインリンクは次を実行 BGP-unnumbered with extended next-hop encoding, so a link peers with no per-interface IP to assign or track. Cabling a new link is plug-and-peer.

これが、ファブリックの配線と拡張を迅速にする理由。

EVPN-VXLANエンジニアリング

スイッチがファブリックを構築する仕組み。

ファブリックは、再設計ではなくスイッチの追加によって拡張し、それを可能にするのが EVPN-VXLAN です。VXLAN は IP アンダーレイ上でリーフ間のテナントトラフィックをトンネリングし、 EVPNはすべてのMAC、ホスト、プレフィックスの所在をアドバタイズ, so the switch forwards from a learned control plane instead of flooding to find a host.

RFC 7432 / 8365

EVPNはMAC、IP、プレフィックスをアドバタイズ

リーフは次を実行します: VXLAN 向け Layer 2 EVPN control plane and the prefix route for EVPN IRB, so EVPN carries MAC and IP host routes and IP prefixes across the fabric and each leaf forwards from what it has learned.

Anycast GW

分散エニーキャストゲートウェイ

各リーフは次を提示 same gateway IP and MAC for a subnet, using multiple IP addresses on the IRB interface for the anycast gateway, so a server is always one hop from its gateway no matter which leaf it sits behind.

ESI-LAG

EVPNマルチホーミング、アクティブアクティブ

VXLAN 向け Layer 2 EVPN マルチホーミング attaches a server to two or more leaves in active-active mode over an Ethernet Segment. Both links forward, and there is no MLAG peer-link between the leaves.

RFC 7938

BGP-unnumberedアンダーレイ

各リーフスパインリンクは次を実行 BGP unnumbered併用のVXLAN EVPN using extended next-hop encoding. A link peers without a per-interface IP address, which keeps the underlay simple to cable and grow.

Multi-tenant

VNI上でのVRF分離

各テナントは自身のVNI上の自身のVRF内に存在し、さらに inter-VRF route leaking over EVPN-VXLAN passes only the prefixes you permit, so isolation is the default and any sharing between tenants is explicit.

ECMP + RR

オーバーレイECMPとルートリフレクション

オーバーレイの等コストマルチパス spreads traffic across every spine, and EVPN route reflection in the fabric passes routes between leaves without a full mesh, so the fabric scales wider by adding spines.

自動化と運用

素のスイッチから本番リーフまで数分で。

新しいスイッチは起動し、構成を取得し、コンソールセッションなしでファブリックへ参加します。そこからは、あらゆるプラットフォームでストリーミングテレメトリとモデル駆動型構成により、ファブリックをコードとして運用します。

Onboarding

ZTP at boot

スイッチはZero Touch Provisioningを通じてイメージと構成を取得するため、コンソールセッションなしで箱から本番leafへと立ち上がります。

テレメトリ

gNMI streaming

gNMI streams telemetry to your collector, dial-in and dial-out, so leaf and spine state is a live feed instead of a poll.

Config as code

NETCONF、OpenConfig、Ansible

Ansible と組み合わせた NETCONF および OpenConfig モデルにより、EVPN および VXLAN の状態をコードとしてプッシュ・検証し、ファブリック全体で一貫性を保てます。

Visibility

sFlow, BFD, graceful restart

sFlow samples traffic for visibility, BFD detects a failure fast, and BGP graceful restart keeps the fabric forwarding while a neighbor reconverges.

データセンターインターコネクト

2 つのファブリックをコヒーレント DCI 越しに相互接続します。

事業者が2つのデータセンターを運用する場合、一方のテナントが他方のテナントへ到達する必要があり、ファブリックは両サイトにまたがり1つのネットワークとして拡張。 border leaf in each fabric stitches the two VXLAN Layer 3 domains, each fabric advertises its tenant IP prefixes to the other over EVPN, and a 400G OpenZR+ coherent link carries the traffic between the sites, using the same routed-optical technique already proven on service provider routers.

The stitch

border leafがL3ドメインを接続

The EVPN Layer 3ゲートウェイ on each border leaf performs VXLAN Layer 3 stitching, so one fabric's VXLAN domain hands off to the other at Layer 3 rather than bridging one flat domain across the WAN.

The handoff

Type-5プレフィックス(テナントごと)

各ファブリックは自身のテナントIPプレフィックスを相手側へ次としてアドバタイズ EVPN IPプレフィックス経路, reflected by the route servers, and inter-VRF route leaking keeps each tenant's VRF isolated across both sites.

The transport

400G ZR+ コヒーレント、トランスポンダー不要

ZR+対応スイッチは、次を搭載します 400G OpenZR+ coherent optic directly in a faceplate port and lights the wavelength, with no separate transponder shelf. The same 400G coherent DCI runs on data center switches like the Edgecore AS9726-32DB and on the service provider routers already deployed for interconnect, and the 800G Tomahawk 5 fabric scales the port capacity behind it.

See it end to end

1 サイトのファブリック、サイト間のコヒーレント DCI ステッチ、リモートファブリックの間でビューを切り替え。

2サイトデータセンター相互接続セレクター 左のSite Aと右のSite Bという2つのEVPN-VXLAN leaf-spineファブリック。各サイトは2つのleaf、1つのspine、1つのborder leafで構成され、2つのborder leaf間を400G OpenZR+コヒーレントリンクで中央接続。ビューを選択すると、片方のサイトのファブリック、相互接続のつなぎ目、またはリモートファブリックをハイライト表示。 Leaf A1 VTEP Leaf A2 VTEP Spine A underlay RR SITE A Border A L3 gateway Border B L3 gateway 400G ZR+ コヒーレント EVPN Type-5ハンドオフ、VXLAN L3スティッチング Spine B underlay RR Leaf B1 VTEP Leaf B2 VTEP SITE B

コヒーレントDCIステッチ。 2 つのボーダーリーフがレイヤー 3 でファブリックをステッチし、サイト間で 400G OpenZR+ コヒーレントリンクを発光します。各ファブリックは、自らのテナント IP プレフィックスを EVPN Type-5 ルートとして相手側へアドバタイズし、テナントごとの VRF 分離が両サイトにわたって維持されます。

Platform sizing

どのロールにどの検証済みスイッチか。

IP Infusion は次の基盤でファブリックを提供します: 18 validated data center platforms from Edgecore and UfiSpace, each lab-qualified per platform with OcNOS-DC pre-loaded. Leaves size on port count and the anycast gateway; spines size on fabric width; the interconnect leaf sizes on the coherent optic.

ファブリックロール別の検証済みデータセンタースイッチ。最終検証:2026年7月。
役割 Validated switch シリコンと容量 そのロールに適合する理由
Leaf (400G) Edgecore AS9726-32DB/UfiSpace S9300-32D Broadcom Trident 4、12.8 Tbps、400G VTEP ティア:サーバー向けポート、分散アニーキャストゲートウェイ、EVPN マルチホーミング。
Spine (400G) Edgecore AS9736-64D Broadcom Tomahawk 4、25.6 Tbps、400G アンダーレイECMPとEVPNルートリフレクション。VTEPなし、ファブリック幅に合わせたサイジング。
スパイン / スーパースパイン(800G) Edgecore AIS800-64D/UfiSpace S9321-64E Broadcom Tomahawk 5、51.2 Tbps、800G 最大規模のファブリックに向けた800Gスケールアウト。AIS800-64DはQSFP-DD800光モジュールを使用します。
相互接続リーフ (400G コヒーレント) Edgecore AS9726-32DB Broadcom Trident 4, 12.8 Tbps, 32×400G, 400G ZR+ coherent 400G OpenZR+ コヒーレントプラガブルを QSFP-DD ポートに装着し、外部トランスポンダーなしでインターコネクト波長を直接発光。
100G leaf / ToR Edgecore AS7726-32X/UfiSpace S9110-32X Broadcom Trident 3、3.2 Tbps、100G 25Gおよび100Gサーバーラック向けのアクセス層leaf。

18 validated data center platforms. See every validated platform, including the rest of the portfolio, in the ハードウェア互換性リスト, 機能とハードウェアの対応は次でご確認いただけます フィーチャーマトリクス.

OcNOS が対応する Broadcom シリコンのフルポートフォリオ、StrataXGS と StrataDNX の比較 →

ファブリックのサイジング方法

  • Leaf tier. VTEP、anycastゲートウェイ、EVPNマルチホーミング向けにはleafを400G Trident 4に、25Gおよび100Gのサーバーラック向けには100G Trident 3のleafに配置。
  • Spine tier. spineは400G Tomahawk 4に配置、ファブリックをより広くスケールさせる必要がある場合は800G Tomahawk 5に配置し、leafには手を加えずspineを追加。
  • Interconnect leaf. ファブリックを第2サイトへ拡張する際は、AS9726-32DBのQSFP-DDポートに400G OpenZR+コヒーレントプラガブルを装着し、相互接続leafが波長を直接点灯。
  • One contract. IP Infusion はすべてのロールを一つのシステムとして検証・サポートし、スイッチと OcNOS-DC は独立したサイクルで更新されます。
構成:エニーキャストゲートウェイ付きleaf VTEP

leaf VTEPを構成します。

Each leaf terminates VXLAN tunnels, hosts the distributed anycast gateway, and runs the EVPN address family in BGP. Below is a representative OcNOS-DC leaf configuration: VXLAN with integrated routing and bridging, a tenant with its layer 3 VNI and bridge domain, the distributed anycast gateway with a shared MAC, the VNI to tenant mapping, and EVPN under BGP.

OcNOS-DC · leaf VTEP
! Leaf VTEP: VXLAN overlay, distributed anycast gateway, EVPN in BGP
configure terminal
nvo vxlan enable
nvo vxlan irb
evpn irb-forwarding anycast-gateway-mac 0000.0000.1111
ip vrf tenant1
 l3vni 5010
mac vrf tenant1_l2
 rd 10.0.0.1:10
 route-target both 100:10
interface irb10
 ip vrf forwarding tenant1
 ip address 10.10.10.1/24 anycast
 evpn irb-if-forwarding anycast-gateway-mac
nvo vxlan id 10 ingress-replication inner-vid-disabled
 vxlan host-reachability-protocol evpn-bgp tenant1_l2
 evpn irb10
nvo vxlan vtep-ip-global 10.0.0.1
router bgp 65001
 neighbor 10.0.1.1 remote-as 65000
 address-family l2vpn evpn
  neighbor 10.0.1.1 activate

各行の役割

  1. nvo vxlan enable and nvo vxlan irb turn on VXLAN and integrated routing and bridging, so the leaf both switches inside a subnet and routes between subnets over the fabric.
  2. evpn irb-forwarding anycast-gateway-mac 0000.0000.1111 sets one shared gateway MAC for the whole fabric, so every leaf answers as the same default gateway.
  3. ip vrf tenant1 with l3vni 5010 gives the tenant its own routing table and the layer 3 VNI that carries routed traffic between subnets across the fabric.
  4. mac vrf tenant1_l2 with its rd and route-target both gives the tenant bridge domain a route distinguisher and import and export targets, so EVPN keeps each tenant's MAC and IP routes separate.
  5. interface irb10 is the tenant gateway: ip vrf forwarding tenant1 binds it to the tenant table, ip address sets the gateway IP, and evpn irb-if-forwarding anycast-gateway-mac applies the shared anycast MAC to this interface.
  6. The nvo vxlan id 10 block maps VNI 10 to the tenant, uses ingress replication for broadcast and multicast traffic, and sets host-reachability-protocol evpn-bgp so BGP EVPN learns host reachability.
  7. nvo vxlan vtep-ip-global 10.0.0.1 sets the tunnel-endpoint address, a loopback, that identifies this leaf in the fabric.
  8. router bgp 65001 with neighbor 10.0.1.1 remote-as 65000 forms the session to the spine, and the address-family l2vpn evpn block activates EVPN so the leaf advertises and learns MAC, IP, and prefix routes.

These are OcNOS-DC VXLAN and EVPN commands from the OcNOS-DC configuration guide, shown with example VNIs, VRF names, and addresses rather than copied from one device. Confirm the exact IDs, route targets, and addresses for your fabric against the OcNOS-DC VXLAN and EVPN configuration guide at documentation.ipinfusion.com.

オープン対プロプライエタリ

オープンなファブリックスイッチとプロプライエタリなデータセンタースイッチの比較。

AristaやCiscoと比べたとき、ファブリックの論点は、オープンスイッチがEVPN-VXLAN leaf-spineを同等に完全に動かせるかどうかです。OcNOS-DCはそれを実現します。事業者が複数ベンダーから購入できるマーチャントシリコン上で、そのすべてを単一のサポート契約でカバーします。

OcNOS-DC上のオープンなファブリックスイッチと、プロプライエタリなデータセンタープラットフォームの比較。最終検証: 2026年7月。
Fabric capability オープンなスイッチ(OcNOS-DC) プロプライエタリ(Arista EOS/Cisco NX-OS/Juniper Junos)
EVPN-VXLANリーフスパインファブリック details →
分散エニーキャストゲートウェイ
EVPNマルチホーミング(ESI-LAG、MLAG依存なし)
BGP-unnumberedアンダーレイ details →
マルチテナントの VRF および VNI 分離
ZTP、gNMI、NETCONF、OpenConfig
Tomahawk 5上で800G
ハードウェア調達 複数ベンダーによるオープンなマーチャントシリコン シングルベンダースイッチ
提供とサポート 完全なスイッチ、1つのサポート契約、スイッチとソフトウェアを個別に更改 Vendor-bundled

Arista、EOS、Cisco、NX-OS、Nexus、Juniper、Junosは、各所有者の商標です。IP Infusionはこれらのベンダーと提携しておらず、推奨もしません。本比較は、次で検証可能なOcNOS-DCの機能を反映しています フィーチャーマトリクス.

評価の前に

データセンターファブリックに関する質問。

EVPN-VXLAN leaf-spineデータセンターファブリックは、スイッチを追加して拡張するスケールアウトネットワークです。すべてのleafはVXLANトンネルエンドポイントであり、BGPがleafとspine間のアンダーレイを運び、EVPNがMACおよびIPホストルートとIPプレフィックスをアドバタイズするため、ファブリックはフラッディングではなく学習済みコントロールプレーンから転送します。IP Infusionはこれを1つのシステムとして提供します:スイッチ、プリロード済みOcNOS-DC、1つのサポート契約に、分散エニーキャストゲートウェイ、EVPNマルチホーミング、マルチテナントVRF分離を備えます。
各テナントは独自のVXLANネットワーク識別子(VNI)のセットを持ちます。Layer 2 VNIがブリッジトラフィックを、Layer 3 VNIがテナントごとのVRF内のルーテッドトラフィックを収容します。トラフィックはVNIごとにカプセル化されVRF内でルーティングされるため、あるテナントが共有ファブリック上で別のテナントを見ることはできません。二つのテナントが相互に到達する必要がある場合、EVPN-VXLAN上のVRF間ルートリーキングは許可した特定のプレフィックスのみを通すため、分離が既定のまま維持され、共有は明示的になります。
EVPNマルチホーミングは、Ethernet Segment Identifier(ESI-LAG)を用いて、サーバーが二つ以上のリーフにアクティブアクティブモードで同時に接続できるようにするため、両方のリンクがトラフィックを転送し、リーフ障害は透過的になります。すべてがEVPNコントロールプレーンでシグナリングされるため、専用のピアリンクも二つのリーフ間の独自ペアリングも不要です。これは、ピアリンク経由でちょうど二台のスイッチをペアにするMLAGとの違いです。OcNOS-DCは両方に対応するため、従来型のデュアルホーミングを求める設計でもMLAGを利用できます。
各ファブリックのボーダーリーフが 2 つの VXLAN レイヤー 3 ドメインをステッチし、各ファブリックは自らのテナント IP プレフィックスを EVPN IP プレフィックスルートとして相手側へアドバタイズします。その際、テナントごとの VRF 分離がサイト間で維持されます。トランスポートには、Edgecore AS9726-32DB やインターコネクト向けにすでに導入済みのサービスプロバイダールーターなど、ZR+ 対応スイッチ内の 400G OpenZR+ コヒーレント光学が、QSFP-DD ポートで波長を直接発光するため、個別のトランスポンダーは不要です。その背後では 800G Tomahawk 5 スイッチがファブリックを運びます。光学の詳細についてはルーテッドオプティカルソリューションを、コヒーレントリーチの計算についてはコヒーレント DCI テクノロジーページをご覧ください。
はい、EVPN-VXLAN leaf-spineファブリックに対応。OcNOS-DCはマーチャントシリコンスイッチ上で同じファブリック機能を動作:分散anycastゲートウェイ併用のEVPN-VXLAN、EVPNマルチホーミング、BGP-unnumberedアンダーレイ、マルチテナントVNI、運用向けのgNMIおよびNETCONF対応ZTP。IP Infusionはスイッチ、ソフトウェア、サポートを単一契約のもと1つのシステムとして提供します。ハードウェアは複数のオープンハードウェアベンダーから調達し、スイッチとソフトウェアを独立したサイクルで刷新可能。
新しいスイッチはZero Touch Provisioningを通じて起動し構成を取得するため、コンソールセッションなしで箱から本番leafへと立ち上がります。そこからファブリックは、gNMI経由のストリーミングテレメトリ、NETCONFおよびOpenConfigモデル、Ansibleで運用され、同じモデルでEVPNとVXLANの状態をコードとして投入し検証します。IP Infusionは、OcNOS-DCをプリロードし検証済みベースラインを備えたスイッチを出荷するため、Day 0イメージはすべてのleafとspineで一貫します。
ファブリックを評価

オープンなデータセンターファブリックをご覧ください。

IP Infusion が EVPN-VXLAN リーフスパインファブリックを 1 つのシステムとして提供する方法をご覧ください。または、リーフ、スパイン、インターコネクトを適切な検証済みプラットフォームにマッピングするには、お問い合わせください。