EVPN-VXLAN · BGP leaf-spine · 400G / 800G

在開放式交換器上打造的完整 leaf-spine 資料中心 fabric。

IP Infusion delivers a complete EVPN-VXLAN leaf-spine data center fabric: 400G and 800G switches running OcNOS-DC, pre-loaded and supported under one contract. You add capacity by adding switches, a server keeps the same gateway on any leaf, and every tenant stays isolated, with a distributed anycast gateway, EVPN multihoming, a BGP underlay, and multi-tenant VRF isolation on open hardware.

以單一系統交付與支援

單一驗證交換器、軟體與支援合約。

IP Infusion 共同驗證交換器與 OcNOS-DC,並在同一份合約下提供支援,因此您設計的 fabric 就是實際交付的 fabric。以下每一項說明都對應到硬體清單中的已驗證平台,以及功能對照表中的受支援功能。

已驗證的硬體

18 validated data center platforms

每個 leaf、spine 與 border 交換器都是 lab-qualified per platform with OcNOS-DC pre-loaded, from 100G access leaves to 800G Tomahawk 5 spines.

Feature depth

可於功能矩陣中查證

EVPN-VXLAN、anycast 閘道、多歸屬、BGP-unnumbered underlay,以及多租戶 VNI,各自皆 mapped to the platforms that support them.

One contract

交換器、軟體與 RMA 一併涵蓋

由單一團隊負責 software, switch, and RMA, and you still refresh the hardware and OcNOS-DC on independent cycles.

參考架構

fabric 如何建構,以及每一層帶來的價值。

伺服器連接至 leaf,leaf 連接至每一個 spine,邊界層則連通 WAN 與第二站點。這些層級之間的工作分工,讓您能為單一層級增加容量而不影響其他層級,也讓伺服器無論部署在何處都能維持相同的閘道。

DC fabric 拓樸:leaf-spine EVPN-VXLAN 架構,包含 VTEP leaf、eBGP ECMP 上行連線,以及負責對外連線與 EVPN route reflection 的 border leaf
DC Fabric:EVPN-VXLAN leaf-spine 架構,包含 VTEP leaf、eBGP ECMP,以及負責對外連線的 border leaf。

同一份 OcNOS-DC 映像檔執行每一層,因此您可依角色進行規格配置與授權,並在整個 fabric 上維運單一軟體基準。

伺服器的接入位置

Leaf:每個機櫃的入口

leaf 終結 VXLAN 並承載 distributed anycast gateway, so a server sees the same gateway IP and MAC on any leaf. Move or add a workload and it keeps its default route with no re-addressing.

您可在 Trident 4 400G 交換器上藉由增添 leaf 來擴增伺服器容量。

增添寬度的位置

Spine:供整個 fabric 使用的頻寬

spine 承載 BGP-unnumbered 底層網路, reflects EVPN routes, and spreads traffic with overlay ECMP. It holds no tunnel endpoints, so adding a spine adds bandwidth to the whole fabric.

您可藉由增添 spine 來橫向擴充,且無需為 leaf 重新佈線。

fabric 的出口位置

border leaf:fabric 的受控出口

邊界 leaf 執行 EVPN Layer 3 閘道 and advertises each tenant's IP prefixes outward, VRF by VRF. It is your one controlled handoff to the WAN and to the second site.

這裡也是兩個 fabric 為相干互連而縫合之處。

讓佈線保持簡單的關鍵

Underlay:即插即對接佈線

每條 leaf-spine 鏈路都運行 BGP-unnumbered with extended next-hop encoding, so a link peers with no per-interface IP to assign or track. Cabling a new link is plug-and-peer.

這正是 fabric 能快速佈線、快速擴充的原因。

EVPN-VXLAN 工程

交換器如何建構 fabric。

Fabric 透過增加交換器來擴充,而非重新設計架構,而讓這一切得以運作的正是 EVPN-VXLAN。VXLAN 在 IP 底層網路上於 leaf 之間以隧道傳輸租戶流量,而 EVPN 通告每一個 MAC、主機與 prefix 所在的位置, so the switch forwards from a learned control plane instead of flooding to find a host.

RFC 7432 / 8365

EVPN 通告 MAC、IP 與 prefix

leaf 執行 適用於 VXLAN 的第 2 層 EVPN control plane and the prefix route for EVPN IRB, so EVPN carries MAC and IP host routes and IP prefixes across the fabric and each leaf forwards from what it has learned.

Anycast GW

分散式 anycast 閘道

每個 leaf 都呈現 same gateway IP and MAC for a subnet, using multiple IP addresses on the IRB interface for the anycast gateway, so a server is always one hop from its gateway no matter which leaf it sits behind.

ESI-LAG

EVPN 多歸屬,active-active

適用於 VXLAN 的第 2 層 EVPN 多重歸屬 attaches a server to two or more leaves in active-active mode over an Ethernet Segment. Both links forward, and there is no MLAG peer-link between the leaves.

RFC 7938

BGP-unnumbered 底層網路

每條 leaf-spine 鏈路都運行 採用 BGP unnumbered 的 VXLAN EVPN using extended next-hop encoding. A link peers without a per-interface IP address, which keeps the underlay simple to cable and grow.

Multi-tenant

在 VNI 上的 VRF 隔離

每個租戶都在自己的 VNI 上運行於自己的 VRF 中,且 inter-VRF route leaking over EVPN-VXLAN passes only the prefixes you permit, so isolation is the default and any sharing between tenants is explicit.

ECMP + RR

疊加層 ECMP 與路由反射

疊加層等價多重路徑 spreads traffic across every spine, and EVPN route reflection in the fabric passes routes between leaves without a full mesh, so the fabric scales wider by adding spines.

自動化與維運

從裸機交換器到正式 leaf,只需數分鐘。

全新交換器無需 console 連線即可開機、拉取組態並加入 fabric。此後您便能以程式碼方式操作 fabric,在每個平台上運用串流遙測與模型驅動的組態。

Onboarding

ZTP at boot

交換器透過 Zero Touch Provisioning 拉取其映像與組態,因此無需 console 連線即可從開箱狀態成為正式環境的 leaf。

遙測

gNMI streaming

gNMI streams telemetry to your collector, dial-in and dial-out, so leaf and spine state is a live feed instead of a poll.

Config as code

NETCONF、OpenConfig、Ansible

NETCONF 與 OpenConfig 模型搭配 Ansible,讓您以程式碼的方式推送並驗證 EVPN 與 VXLAN 狀態,並在整個 fabric 中保持一致。

Visibility

sFlow, BFD, graceful restart

sFlow samples traffic for visibility, BFD detects a failure fast, and BGP graceful restart keeps the fabric forwarding while a neighbor reconverges.

資料中心互連

透過相干 DCI 互連兩個 fabric。

當業者運行兩座資料中心時,其中一座的租戶需要連達另一座的租戶,而 fabric 會橫跨兩個站點延伸為單一網路。這個 border leaf in each fabric stitches the two VXLAN Layer 3 domains, each fabric advertises its tenant IP prefixes to the other over EVPN, and a 400G OpenZR+ coherent link carries the traffic between the sites, using the same routed-optical technique already proven on service provider routers.

The stitch

border leaf 縫合各 L3 網域

The EVPN Layer 3 閘道 on each border leaf performs VXLAN Layer 3 stitching, so one fabric's VXLAN domain hands off to the other at Layer 3 rather than bridging one flat domain across the WAN.

The handoff

Type-5 前綴,依租戶區分

每個 fabric 都將其租戶 IP prefix 通告給對方,作為 EVPN IP-prefix 路由, reflected by the route servers, and inter-VRF route leaking keeps each tenant's VRF isolated across both sites.

The transport

400G ZR+ 同調光,無需轉頻器

支援 ZR+ 的交換器可插入 400G OpenZR+ coherent optic directly in a faceplate port and lights the wavelength, with no separate transponder shelf. The same 400G coherent DCI runs on data center switches like the Edgecore AS9726-32DB and on the service provider routers already deployed for interconnect, and the 800G Tomahawk 5 fabric scales the port capacity behind it.

See it end to end

在單一站點的 fabric、站點之間的相干 DCI 縫合,以及遠端 fabric 之間切換檢視。

雙站點資料中心互連選擇器 兩座 EVPN-VXLAN leaf-spine fabric,左側為站點 A,右側為站點 B,各含兩個 leaf、一個 spine 與一個 border leaf,中央由兩個 border leaf 之間的一條 400G OpenZR+ coherent 鏈路相連。選擇檢視畫面以突顯某一站點的 fabric、互連縫接處或遠端 fabric。 Leaf A1 VTEP Leaf A2 VTEP Spine A underlay RR SITE A Border A L3 gateway Border B L3 gateway 400G ZR+ 同調光 EVPN Type-5 交接,VXLAN L3 縫合 Spine B underlay RR Leaf B1 VTEP Leaf B2 VTEP SITE B

同調 DCI 縫合。 兩個邊界 leaf 在 Layer 3 縫合各 fabric,並於站點之間點亮一條 400G OpenZR+ 相干鏈路。各 fabric 以 EVPN Type-5 路由的形式將其租戶 IP 前綴通告給另一方,且各租戶的 VRF 隔離在兩個站點之間皆維持不變。

Platform sizing

哪一款已驗證交換器對應哪個角色。

IP Infusion 交付 fabric,採用 18 validated data center platforms from Edgecore and UfiSpace, each lab-qualified per platform with OcNOS-DC pre-loaded. Leaves size on port count and the anycast gateway; spines size on fabric width; the interconnect leaf sizes on the coherent optic.

依 fabric 角色驗證的資料中心交換器。最後驗證:2026 年 7 月。
角色 Validated switch 晶片與容量 它為何適合此角色
Leaf (400G) Edgecore AS9726-32DB / UfiSpace S9300-32D Broadcom Trident 4,12.8 Tbps,400G VTEP 層:連接伺服器的埠、分散式 anycast 閘道,以及 EVPN 多歸屬。
Spine (400G) Edgecore AS9736-64D Broadcom Tomahawk 4,25.6 Tbps,400G Underlay ECMP 與 EVPN route reflection,無 VTEP,依 fabric 寬度規劃容量。
Spine / super-spine(800G) Edgecore AIS800-64D / UfiSpace S9321-64E Broadcom Tomahawk 5,51.2 Tbps,800G 適用於最大規模 fabric 的 800G 橫向擴充。AIS800-64D 採用 QSFP-DD800 光模組。
互連 leaf(400G 相干) Edgecore AS9726-32DB Broadcom Trident 4, 12.8 Tbps, 32×400G, 400G ZR+ coherent 將 400G OpenZR+ 相干可插拔光模組裝入 QSFP-DD 埠,直接點亮互連波長,無需外接轉發器。
100G leaf/ToR Edgecore AS7726-32X / UfiSpace S9110-32X Broadcom Trident 3,3.2 Tbps,100G 適用於 25G 與 100G 伺服器機架的接取層 leaf。

18 validated data center platforms. See every validated platform, including the rest of the portfolio, in the 硬體相容性清單,並於下列將功能對應至硬體,即 功能矩陣.

比較 OcNOS 運行的完整 Broadcom 晶片產品組合,StrataXGS 與 StrataDNX →

如何評估 fabric 的規模

  • Leaf tier. 將 leaf 部署在 400G Trident 4 上以承擔 VTEP、anycast 閘道與 EVPN 多歸屬,或部署在 100G Trident 3 leaf 上以服務 25G 與 100G 伺服器機架。
  • Spine tier. 將 spine 部署在 400G Tomahawk 4 上,或當 fabric 需要橫向擴展時部署在 800G Tomahawk 5 上,並以增添 spine 的方式擴充,而非變動 leaf。
  • Interconnect leaf. 當 fabric 延伸至第二站點時,在 AS9726-32DB 的 QSFP-DD 埠採用 400G OpenZR+ coherent 可插拔模組,讓互連 leaf 直接點亮波長。
  • One contract. IP Infusion 將每個角色驗證並支援為單一系統,交換器與 OcNOS-DC 則依各自獨立的週期汰換。
組態:具備 anycast 閘道的 leaf VTEP

設定 leaf VTEP。

Each leaf terminates VXLAN tunnels, hosts the distributed anycast gateway, and runs the EVPN address family in BGP. Below is a representative OcNOS-DC leaf configuration: VXLAN with integrated routing and bridging, a tenant with its layer 3 VNI and bridge domain, the distributed anycast gateway with a shared MAC, the VNI to tenant mapping, and EVPN under BGP.

OcNOS-DC · leaf VTEP
! Leaf VTEP: VXLAN overlay, distributed anycast gateway, EVPN in BGP
configure terminal
nvo vxlan enable
nvo vxlan irb
evpn irb-forwarding anycast-gateway-mac 0000.0000.1111
ip vrf tenant1
 l3vni 5010
mac vrf tenant1_l2
 rd 10.0.0.1:10
 route-target both 100:10
interface irb10
 ip vrf forwarding tenant1
 ip address 10.10.10.1/24 anycast
 evpn irb-if-forwarding anycast-gateway-mac
nvo vxlan id 10 ingress-replication inner-vid-disabled
 vxlan host-reachability-protocol evpn-bgp tenant1_l2
 evpn irb10
nvo vxlan vtep-ip-global 10.0.0.1
router bgp 65001
 neighbor 10.0.1.1 remote-as 65000
 address-family l2vpn evpn
  neighbor 10.0.1.1 activate

每一行的作用

  1. nvo vxlan enable and nvo vxlan irb turn on VXLAN and integrated routing and bridging, so the leaf both switches inside a subnet and routes between subnets over the fabric.
  2. evpn irb-forwarding anycast-gateway-mac 0000.0000.1111 sets one shared gateway MAC for the whole fabric, so every leaf answers as the same default gateway.
  3. ip vrf tenant1 with l3vni 5010 gives the tenant its own routing table and the layer 3 VNI that carries routed traffic between subnets across the fabric.
  4. mac vrf tenant1_l2 with its rd and route-target both gives the tenant bridge domain a route distinguisher and import and export targets, so EVPN keeps each tenant's MAC and IP routes separate.
  5. interface irb10 is the tenant gateway: ip vrf forwarding tenant1 binds it to the tenant table, ip address sets the gateway IP, and evpn irb-if-forwarding anycast-gateway-mac applies the shared anycast MAC to this interface.
  6. The nvo vxlan id 10 block maps VNI 10 to the tenant, uses ingress replication for broadcast and multicast traffic, and sets host-reachability-protocol evpn-bgp so BGP EVPN learns host reachability.
  7. nvo vxlan vtep-ip-global 10.0.0.1 sets the tunnel-endpoint address, a loopback, that identifies this leaf in the fabric.
  8. router bgp 65001 with neighbor 10.0.1.1 remote-as 65000 forms the session to the spine, and the address-family l2vpn evpn block activates EVPN so the leaf advertises and learns MAC, IP, and prefix routes.

These are OcNOS-DC VXLAN and EVPN commands from the OcNOS-DC configuration guide, shown with example VNIs, VRF names, and addresses rather than copied from one device. Confirm the exact IDs, route targets, and addresses for your fabric against the OcNOS-DC VXLAN and EVPN configuration guide at documentation.ipinfusion.com.

開放對比專有

開放 fabric 交換器對比專有資料中心交換器。

與 Arista 或 Cisco 相較,fabric 的關鍵問題在於開放式交換器能否同樣完整地運行 EVPN-VXLAN leaf-spine。OcNOS-DC 做得到,且運行於電信業者可向多家供應商採購的通用晶片上,全部納入單一支援合約。

運行 OcNOS-DC 的開放 fabric 交換器對比專有資料中心平台。最後查證:2026 年 7 月。
Fabric capability 開放交換器(OcNOS-DC) 專有(Arista EOS / Cisco NX-OS / Juniper Junos)
EVPN-VXLAN leaf-spine fabric details →
分散式 anycast 閘道
EVPN 多歸屬(ESI-LAG,無 MLAG 相依性)
BGP-unnumbered 底層網路 details →
多租戶 VRF 與 VNI 隔離
ZTP、gNMI、NETCONF 與 OpenConfig
採用 Tomahawk 5 的 800G
硬體採購 來自多家供應商的開放通用晶片 單一供應商交換器
交付與支援 完整交換器,單一支援合約,交換器與軟體分別汰換 Vendor-bundled

Arista、EOS、Cisco、NX-OS、Nexus、Juniper 與 Junos 均為各自所有者的商標。IP Infusion 與這些供應商並無隸屬關係,亦不對其背書;本比較反映的是可在下列來源驗證的 OcNOS-DC 能力: 功能矩陣.

在您評估之前

關於資料中心 fabric 的問題。

EVPN-VXLAN leaf-spine 資料中心 fabric 是一種透過增添交換器來成長的橫向擴充網路。每個 leaf 都是 VXLAN 通道端點,BGP 承載 leaf 與 spine 之間的底層網路,EVPN 則通告 MAC 與 IP 主機路由及 IP 前綴,因此 fabric 依據已學習的控制平面轉送,而非以洪泛方式運作。IP Infusion 將其作為單一系統交付:交換器、預載的 OcNOS-DC 與單一支援合約,並具備分散式 anycast 閘道、EVPN 多歸屬與多租戶 VRF 隔離。
每個租戶都擁有自己的一組 VXLAN network identifier(VNI):Layer 2 VNI 承載 bridged 流量,Layer 3 VNI 則在每租戶的 VRF 內承載 routed 流量。由於流量會依 VNI 進行封裝並在 VRF 內路由,因此某一租戶無法在共享 fabric 上看見另一租戶。當兩個租戶需要互相連通時,透過 EVPN-VXLAN 的 inter-VRF route leaking 只會傳遞你允許的特定 prefix,因此隔離維持為預設狀態,而共享則是明確指定的。
EVPN 多歸屬讓伺服器可透過 Ethernet Segment Identifier(ESI-LAG)以 active-active 模式同時連接兩個或多個 leaf,因此兩條鏈路都會轉送流量,且單一 leaf 故障對外透明。它完全在 EVPN control plane 中傳訊,因此兩個 leaf 之間不需要專屬的 peer-link,也沒有專有的配對機制。這正是它與 MLAG 的差異,MLAG 是透過 peer-link 精確配對兩台交換器。OcNOS-DC 兩者皆支援,因此若設計上想採用傳統的 dual-homing,仍可使用 MLAG。
各 fabric 中的邊界 leaf 會將兩個 VXLAN Layer 3 網域縫合在一起,且各 fabric 會以 EVPN IP-prefix 路由的形式將其租戶 IP 前綴通告給另一方,同時在站點之間維持各租戶的 VRF 隔離。在傳輸方面,於具備 ZR+ 能力的交換器(例如 Edgecore AS9726-32DB,或已部署用於互連的電信業者路由器)中安裝 400G OpenZR+ 相干光模組,即可在 QSFP-DD 埠中直接點亮波長,因此無需另備轉發器。其後由 800G Tomahawk 5 交換器承載 fabric。光模組深入內容請參閱路由光學解決方案,相干傳輸距離的計算請參閱相干 DCI 技術頁面。
是的,適用於 EVPN-VXLAN leaf-spine fabric。OcNOS-DC 在通用晶片交換器上運行相同的 fabric 能力:具分散式 anycast 閘道的 EVPN-VXLAN、EVPN multihoming、BGP-unnumbered underlay、多租戶 VNI,以及供維運使用、搭配 gNMI 與 NETCONF 的 ZTP。IP Infusion 以單一合約將交換器、軟體與支援交付為一套系統,而您可向不止一家開放硬體供應商採購硬體,並依各自獨立的週期更新交換器與軟體。
全新交換器透過 Zero Touch Provisioning 開機並拉取其組態,因此交換器無需 console 連線即可從開箱狀態成為正式環境的 leaf。此後便可透過 gNMI 上的串流遙測、NETCONF 與 OpenConfig 模型以及 Ansible 來操作 fabric,同樣的模型也讓您能以程式碼方式推送並驗證 EVPN 與 VXLAN 狀態。IP Infusion 出貨的交換器預載 OcNOS-DC 並具備經驗證的基準,因此 Day 0 映像在每個 leaf 與 spine 上都一致。
評估 fabric

檢視開放式資料中心 fabric。

了解 IP Infusion 如何將 EVPN-VXLAN leaf-spine fabric 以單一系統交付,或與我們聯絡,將您的 leaf、spine 與互連對應到合適的驗證平台。