From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [IPv6:2a01:7e0:0:424::9]) by lore.proxmox.com (Postfix) with ESMTPS id 4A8EB1FF18C for ; Tue, 14 Apr 2026 18:34:46 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 35CB11F88D; Tue, 14 Apr 2026 18:34:04 +0200 (CEST) From: Stefan Hanreich To: pve-devel@lists.proxmox.com Subject: [PATCH pve-network 13/16] tests: test route filtering mechanism with multiple zones/controllers Date: Tue, 14 Apr 2026 18:33:10 +0200 Message-ID: <20260414163315.419384-14-s.hanreich@proxmox.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260414163315.419384-1-s.hanreich@proxmox.com> References: <20260414163315.419384-1-s.hanreich@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1776184326945 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.692 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: 3FHG5UFLYZLB2OIGUMT7BKAYTYXNZCRX X-Message-ID-Hash: 3FHG5UFLYZLB2OIGUMT7BKAYTYXNZCRX X-MailFrom: s.hanreich@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: When utilizing multiple controllers and assigning them to EVPN zones selectively, the outgoing routes get filtered - so EVPN controllers only announce routes of zones/vnets they are explicitly assigned to. This test case creates two zones and assigns one controller to both, another controller to only one zone to test the outgoing route filtering mechanism. Signed-off-by: Stefan Hanreich --- .../expected_controller_config | 78 ++++++++++++++++++ .../expected_sdn_interfaces | 81 +++++++++++++++++++ .../interfaces | 7 ++ .../sdn_config | 67 +++++++++++++++ 4 files changed, 233 insertions(+) create mode 100644 src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_controller_config create mode 100644 src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_sdn_interfaces create mode 100644 src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/interfaces create mode 100644 src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/sdn_config diff --git a/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_controller_config b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_controller_config new file mode 100644 index 0000000..3d5ec9d --- /dev/null +++ b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_controller_config @@ -0,0 +1,78 @@ +frr version 10.4.1 +frr defaults datacenter +hostname localhost +log syslog informational +service integrated-vtysh-config +! +vrf vrf_myzone + vni 1000 +exit-vrf +! +vrf vrf_myzone2 + vni 2000 +exit-vrf +! +router bgp 65000 + bgp router-id 192.168.0.1 + no bgp hard-administrative-reset + no bgp default ipv4-unicast + coalesce-time 1000 + no bgp graceful-restart notification + neighbor VTEP peer-group + neighbor VTEP remote-as 65000 + neighbor VTEP bfd + neighbor 192.168.0.2 peer-group VTEP + neighbor 192.168.0.3 peer-group VTEP + neighbor uplink peer-group + neighbor uplink remote-as external + neighbor uplink bfd + neighbor 198.51.100.1 peer-group uplink + neighbor 198.51.100.2 peer-group uplink + ! + address-family l2vpn evpn + neighbor VTEP activate + neighbor VTEP route-map MAP_VTEP_IN in + neighbor VTEP route-map MAP_VTEP_OUT out + neighbor uplink activate + neighbor uplink route-map MAP_VTEP_IN_uplink in + neighbor uplink route-map MAP_VTEP_OUT_uplink out + advertise-all-vni + exit-address-family +exit +! +router bgp 65000 vrf vrf_myzone + bgp router-id 192.168.0.1 + no bgp hard-administrative-reset + no bgp graceful-restart notification +exit +! +router bgp 65000 vrf vrf_myzone2 + bgp router-id 192.168.0.1 + no bgp hard-administrative-reset + no bgp graceful-restart notification +exit +! +bgp extcommunity-list standard pve_controller_cluster permit rt 65000:1000 +bgp extcommunity-list standard pve_controller_cluster permit rt 65000:2000 +bgp extcommunity-list standard pve_controller_cluster permit rt 65000:100 +bgp extcommunity-list standard pve_controller_cluster permit rt 65000:200 +! +bgp extcommunity-list standard pve_controller_uplink permit rt 65000:1000 +bgp extcommunity-list standard pve_controller_uplink permit rt 65000:100 +! +route-map MAP_VTEP_IN permit 1 +exit +! +route-map MAP_VTEP_IN_uplink permit 1 +exit +! +route-map MAP_VTEP_OUT permit 1 + match extcommunity pve_controller_cluster any +exit +! +route-map MAP_VTEP_OUT_uplink permit 1 + match extcommunity pve_controller_uplink any +exit +! +line vty +! diff --git a/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_sdn_interfaces b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_sdn_interfaces new file mode 100644 index 0000000..88706b7 --- /dev/null +++ b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/expected_sdn_interfaces @@ -0,0 +1,81 @@ +#version:1 + +auto myvnet +iface myvnet + address 10.0.0.1/24 + bridge_ports vxlan_myvnet + bridge_stp off + bridge_fd 0 + mtu 1450 + ip-forward on + arp-accept on + vrf vrf_myzone + +auto myvnet2 +iface myvnet2 + address 10.0.0.1/24 + bridge_ports vxlan_myvnet2 + bridge_stp off + bridge_fd 0 + mtu 1450 + ip-forward on + arp-accept on + vrf vrf_myzone2 + +auto vrf_myzone +iface vrf_myzone + vrf-table auto + post-up ip route add vrf vrf_myzone unreachable default metric 4278198272 + +auto vrf_myzone2 +iface vrf_myzone2 + vrf-table auto + post-up ip route add vrf vrf_myzone2 unreachable default metric 4278198272 + +auto vrfbr_myzone +iface vrfbr_myzone + bridge-ports vrfvx_myzone + bridge_stp off + bridge_fd 0 + mtu 1450 + vrf vrf_myzone + +auto vrfbr_myzone2 +iface vrfbr_myzone2 + bridge-ports vrfvx_myzone2 + bridge_stp off + bridge_fd 0 + mtu 1450 + vrf vrf_myzone2 + +auto vrfvx_myzone +iface vrfvx_myzone + vxlan-id 1000 + vxlan-local-tunnelip 192.168.0.1 + bridge-learning off + bridge-arp-nd-suppress on + mtu 1450 + +auto vrfvx_myzone2 +iface vrfvx_myzone2 + vxlan-id 2000 + vxlan-local-tunnelip 192.168.0.1 + bridge-learning off + bridge-arp-nd-suppress on + mtu 1450 + +auto vxlan_myvnet +iface vxlan_myvnet + vxlan-id 100 + vxlan-local-tunnelip 192.168.0.1 + bridge-learning off + bridge-arp-nd-suppress on + mtu 1450 + +auto vxlan_myvnet2 +iface vxlan_myvnet2 + vxlan-id 200 + vxlan-local-tunnelip 192.168.0.1 + bridge-learning off + bridge-arp-nd-suppress on + mtu 1450 diff --git a/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/interfaces b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/interfaces new file mode 100644 index 0000000..66bb826 --- /dev/null +++ b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/interfaces @@ -0,0 +1,7 @@ +auto vmbr0 +iface vmbr0 inet static + address 192.168.0.1/24 + gateway 192.168.0.254 + bridge-ports eth0 + bridge-stp off + bridge-fd 0 diff --git a/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/sdn_config b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/sdn_config new file mode 100644 index 0000000..e26fd42 --- /dev/null +++ b/src/test/zones/evpn/evpn_multiple_zones_cluster_ibgp_uplink_ebgp/sdn_config @@ -0,0 +1,67 @@ +{ + version => 1, + zones => { + ids => { + myzone => { + ipam => "pve", + type => "evpn", + controller => "cluster", + 'vrf-vxlan' => 1000, + 'secondary-controllers' => ['uplink'], + }, + myzone2 => { + ipam => "pve", + type => "evpn", + controller => "cluster", + 'vrf-vxlan' => 2000, + } + }, + }, + vnets => { + ids => { + myvnet => { + tag => "100", + type => "vnet", + zone => "myzone" + }, + myvnet2 => { + tag => "200", + type => "vnet", + zone => "myzone2" + }, + }, + }, + subnets => { + ids => { + 'myzone-10.0.0.0-24' => { + 'type' => 'subnet', + 'vnet' => 'myvnet', + 'gateway' => '10.0.0.1', + }, + 'myzone2-10.0.0.0-24' => { + 'type' => 'subnet', + 'vnet' => 'myvnet2', + 'gateway' => '10.0.0.1', + }, + } + }, + controllers => { + ids => { + cluster => { + type => "evpn", + peers => '192.168.0.1,192.168.0.2,192.168.0.3', + asn => "65000", + 'bgp-mode' => 'internal', + }, + uplink => { + type => "evpn", + peers => '198.51.100.1,198.51.100.2', + asn => "65000", + nodes => 'localhost', + 'bgp-mode' => 'external', + 'peer-group-name' => 'uplink', + } + }, + } +} + -- 2.47.3