EVPN-VXLAN · BGP leaf-spine · 400G / 800G

运行在开放交换机上的完整叶脊数据中心 fabric。

IP Infusion delivers a complete EVPN-VXLAN leaf-spine data center fabric: 400G and 800G switches running OcNOS-DC, pre-loaded and supported under one contract. You add capacity by adding switches, a server keeps the same gateway on any leaf, and every tenant stays isolated, with a distributed anycast gateway, EVPN multihoming, a BGP underlay, and multi-tenant VRF isolation on open hardware.

作为一个整体系统交付并提供支持

经过验证的交换机、软件与支持合同合而为一。

IP Infusion 将交换机和 OcNOS-DC 一并认证,并在同一份合同下提供支持,因此您设计的 fabric 就是交付的 fabric。下面每一项声明都对应硬件列表中经过验证的平台和矩阵中受支持的特性。

已验证的硬件

18 validated data center platforms

每个 leaf、spine 和 border 交换机都 lab-qualified per platform with OcNOS-DC pre-loaded, from 100G access leaves to 800G Tomahawk 5 spines.

Feature depth

可在功能矩阵中核验

EVPN-VXLAN、anycast 网关、多归属、BGP-unnumbered underlay 以及多租户 VNI 各自都 mapped to the platforms that support them.

One contract

交换机、软件与 RMA 一体交付

一个团队负责 software, switch, and RMA, and you still refresh the hardware and OcNOS-DC on independent cycles.

参考架构

fabric 如何构建,以及每一层为您带来什么。

服务器接入叶节点,叶节点连接每个脊节点,边界层则连通 WAN 与第二站点。各层之间的分工使您可以在不触及其他层的情况下为某一层扩容,也让服务器无论落在何处都能保持相同的网关。

DC 网络拓扑:leaf-spine EVPN-VXLAN 架构,包含 VTEP leaf、eBGP ECMP 上行链路,以及用于外部连接和 EVPN 路由反射的 border leaf
DC Fabric:EVPN-VXLAN leaf-spine 架构,包含 VTEP leaf、eBGP ECMP,以及用于外部连接的 border leaf。

同一套 OcNOS-DC 镜像运行每一层,因此您可按角色分别规划容量与授权,并在整个 fabric 上运维统一的软件基线。

服务器的接入位置

Leaf:每个机架的接入口

叶节点终结 VXLAN 并承载 distributed anycast gateway, so a server sees the same gateway IP and MAC on any leaf. Move or add a workload and it keeps its default route with no re-addressing.

您可通过在 Trident 4 400G 交换机上增加叶节点来扩充服务器容量。

扩展宽度的位置

脊层:为整个 fabric 提供带宽

脊节点承载 BGP-unnumbered 承载网, reflects EVPN routes, and spreads traffic with overlay ECMP. It holds no tunnel endpoints, so adding a spine adds bandwidth to the whole fabric.

您可通过增加脊节点来横向扩展,无需重新为叶节点布线。

架构的出口位置

border leaf:fabric 的受控出口

边界叶节点运行 EVPN 三层网关 and advertises each tenant's IP prefixes outward, VRF by VRF. It is your one controlled handoff to the WAN and to the second site.

这里也是两张 fabric 为相干互联而拼接之处。

是什么让布线保持简单

底层:即插即对接布线

每条 leaf-spine 链路都运行 BGP-unnumbered with extended next-hop encoding, so a link peers with no per-interface IP to assign or track. Cabling a new link is plug-and-peer.

这正是 fabric 便于布线、便于扩展的原因。

EVPN-VXLAN 工程实现

交换机如何构建 fabric。

fabric 通过增加交换机而非重新架构来扩展,而 EVPN-VXLAN 正是实现这一点的关键。VXLAN 在 IP 底层之上于叶节点之间为租户流量建立隧道,而 EVPN 通告每个 MAC、主机和前缀所在的位置, so the switch forwards from a learned control plane instead of flooding to find a host.

RFC 7432 / 8365

EVPN 通告 MAC、IP 和前缀

叶节点运行 面向 VXLAN 的二层 EVPN control plane and the prefix route for EVPN IRB, so EVPN carries MAC and IP host routes and IP prefixes across the fabric and each leaf forwards from what it has learned.

Anycast GW

分布式 anycast 网关

每个 leaf 都呈现 same gateway IP and MAC for a subnet, using multiple IP addresses on the IRB interface for the anycast gateway, so a server is always one hop from its gateway no matter which leaf it sits behind.

ESI-LAG

EVPN 多归属,双活

面向 VXLAN 的二层 EVPN 多归属 attaches a server to two or more leaves in active-active mode over an Ethernet Segment. Both links forward, and there is no MLAG peer-link between the leaves.

RFC 7938

BGP-unnumbered 承载网

每条 leaf-spine 链路都运行 采用 BGP unnumbered 的 VXLAN EVPN using extended next-hop encoding. A link peers without a per-interface IP address, which keeps the underlay simple to cable and grow.

Multi-tenant

基于 VNI 的 VRF 隔离

每个租户在自己的 VNI 之上、自己的 VRF 中运行,并且 inter-VRF route leaking over EVPN-VXLAN passes only the prefixes you permit, so isolation is the default and any sharing between tenants is explicit.

ECMP + RR

Overlay ECMP 与路由反射

Overlay 等价多路径 spreads traffic across every spine, and EVPN route reflection in the fabric passes routes between leaves without a full mesh, so the fabric scales wider by adding spines.

自动化与运维

在几分钟内从裸交换机变为生产级 leaf。

新交换机启动、拉取其配置并加入 fabric,无需 console 会话。此后,您以代码方式运维 fabric,在每个平台上使用流式遥测与模型驱动的配置。

Onboarding

ZTP at boot

交换机通过 Zero Touch Provisioning 拉取其镜像与配置,因此无需 console 会话即可从开箱状态直接成为生产 leaf。

遥测

gNMI streaming

gNMI streams telemetry to your collector, dial-in and dial-out, so leaf and spine state is a live feed instead of a poll.

Config as code

NETCONF, OpenConfig, Ansible

NETCONF 和 OpenConfig 模型配合 Ansible,让您以代码方式推送和验证 EVPN 与 VXLAN 状态,在整张 fabric 上保持一致。

Visibility

sFlow, BFD, graceful restart

sFlow samples traffic for visibility, BFD detects a failure fast, and BGP graceful restart keeps the fabric forwarding while a neighbor reconverges.

数据中心互联

通过相干 DCI 互联两张 fabric。

当运营商运营两个数据中心时,一个数据中心中的租户需要访问另一个数据中心中的租户,架构跨越两个站点延伸为一张网络。 border leaf in each fabric stitches the two VXLAN Layer 3 domains, each fabric advertises its tenant IP prefixes to the other over EVPN, and a 400G OpenZR+ coherent link carries the traffic between the sites, using the same routed-optical technique already proven on service provider routers.

The stitch

border leaf 缝合 L3 域

The EVPN 三层网关 on each border leaf performs VXLAN Layer 3 stitching, so one fabric's VXLAN domain hands off to the other at Layer 3 rather than bridging one flat domain across the WAN.

The handoff

Type-5 前缀,按租户划分

每个 fabric 向另一个 fabric 通告其租户 IP 前缀,形式为 EVPN IP 前缀路由, reflected by the route servers, and inter-VRF route leaking keeps each tenant's VRF isolated across both sites.

The transport

400G ZR+ 相干,无需转发器

支持 ZR+ 的交换机可安装一个 400G OpenZR+ coherent optic directly in a faceplate port and lights the wavelength, with no separate transponder shelf. The same 400G coherent DCI runs on data center switches like the Edgecore AS9726-32DB and on the service provider routers already deployed for interconnect, and the 800G Tomahawk 5 fabric scales the port capacity behind it.

See it end to end

在单站点 fabric、站点间相干 DCI 缝合以及远端 fabric 之间切换视图。

双站点数据中心互连选择器 两个 EVPN-VXLAN 叶脊架构,左侧为站点 A,右侧为站点 B,各配备两台叶节点、一台脊节点和一台边界叶节点,中间通过两台边界叶节点之间的 400G OpenZR+ 相干链路相连。选择一个视图以突出显示某一站点的架构、互连缝合或远端架构。 Leaf A1 VTEP Leaf A2 VTEP Spine A underlay RR SITE A Border A L3 gateway Border B L3 gateway 400G ZR+ 相干 EVPN Type-5 交接,VXLAN 三层拼接 Spine B underlay RR Leaf B1 VTEP Leaf B2 VTEP SITE B

相干 DCI 缝合。 两个边界叶节点在三层将两个 fabric 缝合,并在站点之间点亮一条 400G OpenZR+ 相干链路。每个 fabric 以 EVPN Type-5 路由向对方通告其租户 IP 前缀,逐租户的 VRF 隔离在两个站点间均得以保持。

Platform sizing

哪个经验证的交换机对应哪个角色。

IP Infusion 交付 fabric,运行于 18 validated data center platforms from Edgecore and UfiSpace, each lab-qualified per platform with OcNOS-DC pre-loaded. Leaves size on port count and the anycast gateway; spines size on fabric width; the interconnect leaf sizes on the coherent optic.

按架构角色验证的数据中心交换机。最近验证时间:2026 年 7 月。
角色 Validated switch 芯片与容量 它为何契合该角色
Leaf (400G) Edgecore AS9726-32DB / UfiSpace S9300-32D Broadcom Trident 4,12.8 Tbps,400G VTEP 层:面向服务器的端口、分布式 anycast 网关以及 EVPN 多归属。
Spine (400G) Edgecore AS9736-64D Broadcom Tomahawk 4,25.6 Tbps,400G 底层 ECMP 与 EVPN 路由反射,无 VTEP,按架构宽度适配规格。
脊 / 超级脊(800G) Edgecore AIS800-64D / UfiSpace S9321-64E Broadcom Tomahawk 5,51.2 Tbps,800G 面向最大规模 fabric 的 800G 横向扩展。AIS800-64D 采用 QSFP-DD800 光模块。
互联 leaf(400G 相干) Edgecore AS9726-32DB Broadcom Trident 4, 12.8 Tbps, 32×400G, 400G ZR+ coherent 在 QSFP-DD 端口中插入 400G OpenZR+ 相干可插拔模块,直接点亮互连波长,无需外部转发器。
100G leaf / ToR Edgecore AS7726-32X / UfiSpace S9110-32X Broadcom Trident 3,3.2 Tbps,100G 面向 25G 与 100G 服务器机架的接入层 leaf。

18 validated data center platforms. See every validated platform, including the rest of the portfolio, in the 硬件兼容性列表,并将功能与硬件相匹配,请见 功能矩阵.

比较 OcNOS 运行的完整 Broadcom 芯片产品组合,StrataXGS 与 StrataDNX →

如何为 fabric 选型

  • Leaf tier. 将 Leaf 部署在 400G Trident 4 上以承担 VTEP、anycast 网关和 EVPN 多归属,或部署在 100G Trident 3 Leaf 上以支持 25G 和 100G 服务器机架。
  • Spine tier. 将 Spine 部署在 400G Tomahawk 4 上,或在 Fabric 需要横向扩展时部署在 800G Tomahawk 5 上,通过增加 Spine 而非改动 Leaf 来扩展。
  • Interconnect leaf. 当架构扩展到第二个站点时,在 AS9726-32DB 的 QSFP-DD 端口中使用 400G OpenZR+ 相干可插拔光模块,使互连叶节点直接点亮波长。
  • One contract. IP Infusion 将每个角色作为一个系统进行验证和支持,交换机和 OcNOS-DC 按独立周期更新。
配置:带 anycast 网关的 leaf VTEP

配置一个 leaf VTEP。

Each leaf terminates VXLAN tunnels, hosts the distributed anycast gateway, and runs the EVPN address family in BGP. Below is a representative OcNOS-DC leaf configuration: VXLAN with integrated routing and bridging, a tenant with its layer 3 VNI and bridge domain, the distributed anycast gateway with a shared MAC, the VNI to tenant mapping, and EVPN under BGP.

OcNOS-DC · leaf VTEP
! Leaf VTEP: VXLAN overlay, distributed anycast gateway, EVPN in BGP
configure terminal
nvo vxlan enable
nvo vxlan irb
evpn irb-forwarding anycast-gateway-mac 0000.0000.1111
ip vrf tenant1
 l3vni 5010
mac vrf tenant1_l2
 rd 10.0.0.1:10
 route-target both 100:10
interface irb10
 ip vrf forwarding tenant1
 ip address 10.10.10.1/24 anycast
 evpn irb-if-forwarding anycast-gateway-mac
nvo vxlan id 10 ingress-replication inner-vid-disabled
 vxlan host-reachability-protocol evpn-bgp tenant1_l2
 evpn irb10
nvo vxlan vtep-ip-global 10.0.0.1
router bgp 65001
 neighbor 10.0.1.1 remote-as 65000
 address-family l2vpn evpn
  neighbor 10.0.1.1 activate

每一行的作用

  1. nvo vxlan enable and nvo vxlan irb turn on VXLAN and integrated routing and bridging, so the leaf both switches inside a subnet and routes between subnets over the fabric.
  2. evpn irb-forwarding anycast-gateway-mac 0000.0000.1111 sets one shared gateway MAC for the whole fabric, so every leaf answers as the same default gateway.
  3. ip vrf tenant1 with l3vni 5010 gives the tenant its own routing table and the layer 3 VNI that carries routed traffic between subnets across the fabric.
  4. mac vrf tenant1_l2 with its rd and route-target both gives the tenant bridge domain a route distinguisher and import and export targets, so EVPN keeps each tenant's MAC and IP routes separate.
  5. interface irb10 is the tenant gateway: ip vrf forwarding tenant1 binds it to the tenant table, ip address sets the gateway IP, and evpn irb-if-forwarding anycast-gateway-mac applies the shared anycast MAC to this interface.
  6. The nvo vxlan id 10 block maps VNI 10 to the tenant, uses ingress replication for broadcast and multicast traffic, and sets host-reachability-protocol evpn-bgp so BGP EVPN learns host reachability.
  7. nvo vxlan vtep-ip-global 10.0.0.1 sets the tunnel-endpoint address, a loopback, that identifies this leaf in the fabric.
  8. router bgp 65001 with neighbor 10.0.1.1 remote-as 65000 forms the session to the spine, and the address-family l2vpn evpn block activates EVPN so the leaf advertises and learns MAC, IP, and prefix routes.

These are OcNOS-DC VXLAN and EVPN commands from the OcNOS-DC configuration guide, shown with example VNIs, VRF names, and addresses rather than copied from one device. Confirm the exact IDs, route targets, and addresses for your fabric against the OcNOS-DC VXLAN and EVPN configuration guide at documentation.ipinfusion.com.

开放与专有对比

开放式 Fabric 交换机与专有数据中心交换机对比。

与 Arista 或 Cisco 相比,fabric 的问题在于开放交换机能否同样完整地运行 EVPN-VXLAN leaf-spine。OcNOS-DC 做到了,且运行在运营商可从多家供应商采购的通用芯片上,全部纳入一份支持合同。

基于 OcNOS-DC 的开放式 Fabric 交换机与专有数据中心平台对比。最近核实:2026 年 7 月。
Fabric capability 开放式交换机(OcNOS-DC) 专有(Arista EOS / Cisco NX-OS / Juniper Junos)
EVPN-VXLAN leaf-spine fabric details →
分布式 anycast 网关
EVPN 多归属(ESI-LAG,不依赖 MLAG)
BGP-unnumbered 承载网 details →
多租户 VRF 和 VNI 隔离
ZTP、gNMI、NETCONF 和 OpenConfig
基于 Tomahawk 5 的 800G
硬件采购 来自多家厂商的开放通用芯片 单一厂商交换机
交付与支持 完整交换机,一份支持合同,交换机与软件分别刷新 Vendor-bundled

Arista、EOS、Cisco、NX-OS、Nexus、Juniper 与 Junos 是其各自所有者的商标。IP Infusion 与这些厂商无隶属关系,也不为其背书;本对比反映的是 OcNOS-DC 能力,可在 功能矩阵.

在评估之前

关于数据中心 Fabric 的问题。

EVPN-VXLAN leaf-spine 数据中心 fabric 是一种通过增加交换机实现扩展的横向扩展网络。每一台 leaf 都是一个 VXLAN 隧道端点,BGP 在 leaf 与 spine 之间承载承载网,EVPN 通告 MAC 与 IP 主机路由以及 IP 前缀,因此 fabric 依据学习到的控制平面进行转发,而非泛洪。IP Infusion 将其作为一个整体系统交付:交换机、预装的 OcNOS-DC 以及一份支持合同,并具备分布式 anycast 网关、EVPN 多归属与多租户 VRF 隔离。
每个租户拥有自己的一组 VXLAN 网络标识符(VNI):二层 VNI 承载桥接流量,三层 VNI 在每租户 VRF 内承载路由流量。由于流量按 VNI 封装并在 VRF 内路由,因此在共享 fabric 上,一个租户无法看到另一个租户。当两个租户需要相互访问时,基于 EVPN-VXLAN 的 inter-VRF 路由泄漏只放行您允许的特定前缀,因此隔离始终是默认状态,共享则是显式的。
EVPN 多归属使用以太网段标识符(ESI-LAG),让一台服务器以双活模式同时接入两个或更多 leaf,因此两条链路都转发流量,某个 leaf 故障时也不会影响业务。它完全在 EVPN 控制平面中进行信令交互,因此不需要专用的 peer-link,两个 leaf 之间也没有私有配对。这正是它与 MLAG 的区别:MLAG 通过 peer-link 恰好配对两台交换机。OcNOS-DC 两者都支持,因此需要经典双归属的设计仍可使用 MLAG。
每个 fabric 中的边界叶节点将两个 VXLAN 三层域缝合在一起,两个 fabric 各自以 EVPN IP 前缀路由向对方通告其租户 IP 前缀,并在站点间保持逐租户的 VRF 隔离。在传输方面,支持 ZR+ 的交换机(如 Edgecore AS9726-32DB,或一台已部署用于互连的服务提供商路由器)中的 400G OpenZR+ 相干光模块直接在 QSFP-DD 端口中点亮波长,因此无需单独的转发器。其后由 800G Tomahawk 5 交换机承载 fabric。有关光模块的深入解析请参见路由光解决方案,有关相干传输距离的计算请参见相干 DCI 技术页面。
是的,对于 EVPN-VXLAN 叶脊架构而言如此。OcNOS-DC 在通用芯片交换机上运行相同的架构能力:带分布式任播网关的 EVPN-VXLAN、EVPN 多归属、BGP-unnumbered 底层、多租户 VNI,以及用于运维的 ZTP 配合 gNMI 和 NETCONF。IP Infusion 在单一合同下将交换机、软件和支持作为一个系统交付,您可从不止一家开放硬件供应商采购硬件,并按各自独立的周期刷新交换机和软件。
新交换机启动并通过 Zero Touch Provisioning 拉取其配置,因此交换机无需 console 会话即可从开箱状态直接成为生产 leaf。此后,fabric 通过 gNMI 上的流式遥测、NETCONF 与 OpenConfig 模型以及 Ansible 进行运维,同样的模型让您以代码方式下发并验证 EVPN 与 VXLAN 状态。IP Infusion 交付的交换机预装 OcNOS-DC 并带有经过验证的基线,因此 Day 0 镜像在每一台 leaf 与 spine 上都保持一致。
评估该 fabric

查看开放的数据中心 fabric。

了解 IP Infusion 如何将 EVPN-VXLAN 叶脊 fabric 作为一套完整系统交付,或联系我们,将您的叶节点、脊节点与互连映射到合适的经验证平台。