public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Stefan Hanreich <s.hanreich@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH pve-network v2 13/18] tests: add rt_import test case when using multiple evpn controllers
Date: Mon,  4 May 2026 18:24:52 +0200	[thread overview]
Message-ID: <20260504162501.425135-14-s.hanreich@proxmox.com> (raw)
In-Reply-To: <20260504162501.425135-1-s.hanreich@proxmox.com>

When enabling multiple EVPN controllers, then the SDN stack
filters outgoing routes to only include extended communities with VNIs
that are explicitly configured as zones or vnets. In order to override
this behavior (e.g. when importing routes from different sites that
have other VNIs as well), rt-import can be used. In that case, only
the route targets explicitly specified in rt-import are announced via
the EVPN controller. Add a test case that checks proper FRR config
generation if an EVPN controller has a zone with rt-import set, and
another zone without rt-import set.

Signed-off-by: Stefan Hanreich <s.hanreich@proxmox.com>
---
 .../expected_controller_config                | 106 ++++++++++++++++++
 .../expected_sdn_interfaces                   |  81 +++++++++++++
 .../interfaces                                |  11 ++
 .../sdn_config                                |  77 +++++++++++++
 4 files changed, 275 insertions(+)
 create mode 100644 src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_controller_config
 create mode 100644 src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_sdn_interfaces
 create mode 100644 src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/interfaces
 create mode 100644 src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/sdn_config

diff --git a/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_controller_config b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_controller_config
new file mode 100644
index 0000000..68f9c3b
--- /dev/null
+++ b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_controller_config
@@ -0,0 +1,106 @@
+frr version 10.4.1
+frr defaults datacenter
+hostname localhost
+log syslog informational
+service integrated-vtysh-config
+!
+vrf vrf_myzone
+ vni 1000
+exit-vrf
+!
+vrf vrf_myzone2
+ vni 2000
+exit-vrf
+!
+router bgp 65000
+ bgp router-id 203.0.113.1
+ no bgp default ipv4-unicast
+ coalesce-time 1000
+ bgp disable-ebgp-connected-route-check
+ neighbor BGP peer-group
+ neighbor BGP remote-as external
+ neighbor BGP local-as 65001 no-prepend replace-as
+ neighbor BGP bfd
+ neighbor 198.51.100.10 peer-group BGP
+ neighbor VTEP peer-group
+ neighbor VTEP remote-as 65000
+ neighbor VTEP bfd
+ neighbor VTEP update-source dummy1
+ neighbor 203.0.113.2 peer-group VTEP
+ neighbor 203.0.113.4 peer-group VTEP
+ neighbor wan peer-group
+ neighbor wan remote-as external
+ neighbor wan bfd
+ neighbor wan update-source dummy1
+ neighbor 203.0.113.100 peer-group wan
+ neighbor 203.0.113.101 peer-group wan
+ !
+ address-family ipv4 unicast
+  network 203.0.113.1/32
+  neighbor BGP activate
+  neighbor BGP soft-reconfiguration inbound
+ exit-address-family
+ !
+ address-family l2vpn evpn
+  neighbor VTEP activate
+  neighbor VTEP route-map MAP_VTEP_IN in
+  neighbor VTEP route-map MAP_VTEP_OUT out
+  neighbor wan activate
+  neighbor wan route-map MAP_VTEP_IN_wan in
+  neighbor wan route-map MAP_VTEP_OUT_wan out
+  advertise-all-vni
+ exit-address-family
+exit
+!
+router bgp 65000 vrf vrf_myzone
+ bgp router-id 203.0.113.1
+ no bgp hard-administrative-reset
+ no bgp graceful-restart notification
+exit
+!
+router bgp 65000 vrf vrf_myzone2
+ bgp router-id 203.0.113.1
+ no bgp hard-administrative-reset
+ no bgp graceful-restart notification
+ !
+ address-family l2vpn evpn
+  route-target import 65000:2000
+  route-target import 65010:20000
+ exit-address-family
+exit
+!
+bgp extcommunity-list expanded pve_controller_cluster permit ^RT:.*:1000$
+bgp extcommunity-list expanded pve_controller_cluster permit ^RT:65000:2000$
+bgp extcommunity-list expanded pve_controller_cluster permit ^RT:65010:20000$
+bgp extcommunity-list expanded pve_controller_cluster permit ^RT:.*:100$
+!
+bgp extcommunity-list expanded pve_controller_wan permit ^RT:.*:1000$
+bgp extcommunity-list expanded pve_controller_wan permit ^RT:65000:2000$
+bgp extcommunity-list expanded pve_controller_wan permit ^RT:65010:20000$
+bgp extcommunity-list expanded pve_controller_wan permit ^RT:.*:100$
+!
+ip prefix-list loopbacks_ips seq 10 permit 0.0.0.0/0 le 32
+!
+route-map MAP_VTEP_IN permit 1
+exit
+!
+route-map MAP_VTEP_IN_wan permit 1
+exit
+!
+route-map MAP_VTEP_OUT permit 1
+ match extcommunity pve_controller_cluster any
+exit
+!
+route-map MAP_VTEP_OUT_wan permit 1
+ match extcommunity pve_controller_wan any
+exit
+!
+route-map correct_src permit 1
+ match ip address prefix-list loopbacks_ips
+ set src 203.0.113.1
+exit
+!
+ip protocol bgp route-map correct_src
+!
+line vty
+!
diff --git a/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_sdn_interfaces b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_sdn_interfaces
new file mode 100644
index 0000000..39f3beb
--- /dev/null
+++ b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/expected_sdn_interfaces
@@ -0,0 +1,81 @@
+#version:1
+
+auto myvnet
+iface myvnet
+	address 10.0.0.1/24
+	bridge_ports vxlan_myvnet
+	bridge_stp off
+	bridge_fd 0
+	mtu 1450
+	ip-forward on
+	arp-accept on
+	vrf vrf_myzone
+
+auto myvnet2
+iface myvnet2
+	address 10.0.0.1/24
+	bridge_ports vxlan_myvnet2
+	bridge_stp off
+	bridge_fd 0
+	mtu 1450
+	ip-forward on
+	arp-accept on
+	vrf vrf_myzone2
+
+auto vrf_myzone
+iface vrf_myzone
+	vrf-table auto
+	post-up ip route add vrf vrf_myzone unreachable default metric 4278198272
+
+auto vrf_myzone2
+iface vrf_myzone2
+	vrf-table auto
+	post-up ip route add vrf vrf_myzone2 unreachable default metric 4278198272
+
+auto vrfbr_myzone
+iface vrfbr_myzone
+	bridge-ports vrfvx_myzone
+	bridge_stp off
+	bridge_fd 0
+	mtu 1450
+	vrf vrf_myzone
+
+auto vrfbr_myzone2
+iface vrfbr_myzone2
+	bridge-ports vrfvx_myzone2
+	bridge_stp off
+	bridge_fd 0
+	mtu 1450
+	vrf vrf_myzone2
+
+auto vrfvx_myzone
+iface vrfvx_myzone
+	vxlan-id 1000
+	vxlan-local-tunnelip 203.0.113.1
+	bridge-learning off
+	bridge-arp-nd-suppress on
+	mtu 1450
+
+auto vrfvx_myzone2
+iface vrfvx_myzone2
+	vxlan-id 2000
+	vxlan-local-tunnelip 203.0.113.1
+	bridge-learning off
+	bridge-arp-nd-suppress on
+	mtu 1450
+
+auto vxlan_myvnet
+iface vxlan_myvnet
+	vxlan-id 100
+	vxlan-local-tunnelip 203.0.113.1
+	bridge-learning off
+	bridge-arp-nd-suppress on
+	mtu 1450
+
+auto vxlan_myvnet2
+iface vxlan_myvnet2
+	vxlan-id 200
+	vxlan-local-tunnelip 203.0.113.1
+	bridge-learning off
+	bridge-arp-nd-suppress on
+	mtu 1450
diff --git a/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/interfaces b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/interfaces
new file mode 100644
index 0000000..1736ffb
--- /dev/null
+++ b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/interfaces
@@ -0,0 +1,11 @@
+auto vmbr0
+iface vmbr0 inet static
+	address 198.51.100.1/24
+        bridge-ports eth0
+        bridge-stp off
+        bridge-fd 0
+
+auto dummy1
+iface dummy1 inet static
+        address 203.0.113.1/32
+        link-type dummy
diff --git a/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/sdn_config b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/sdn_config
new file mode 100644
index 0000000..daa1977
--- /dev/null
+++ b/src/test/zones/evpn/ebgp_evpn_ibgp_wan_evpn_ebgp_rt_import_mixed/sdn_config
@@ -0,0 +1,77 @@
+{
+    version => 1,
+    zones   => {
+        ids => {
+            myzone => {
+                ipam => "pve",
+                type => "evpn",
+                controller => "cluster",
+                'vrf-vxlan' => 1000,
+                'secondary-controllers' => ['wan'],
+            },
+            myzone2 => {
+                ipam => "pve",
+                type => "evpn",
+                controller => "cluster",
+                'vrf-vxlan' => 2000,
+                'secondary-controllers' => ['wan'],
+                'rt-import' => '65000:2000,65010:20000'
+            }
+        },
+    },
+    vnets   => {
+        ids => {
+            myvnet => {
+                tag => "100",
+                type => "vnet",
+                zone => "myzone"
+            },
+            myvnet2 => {
+                tag => "200",
+                type => "vnet",
+                zone => "myzone2"
+            },
+        },
+    },
+    subnets => {
+        ids => {
+            'myzone-10.0.0.0-24' => {
+                'type' => 'subnet',
+                'vnet' => 'myvnet',
+                'gateway' => '10.0.0.1',
+            },
+            'myzone2-10.0.0.0-24' => {
+                'type' => 'subnet',
+                'vnet' => 'myvnet2',
+                'gateway' => '10.0.0.1',
+            }
+        }
+    },
+    controllers  => {
+        ids => {
+            cluster => {
+                type => "evpn",
+                peers => '203.0.113.1,203.0.113.2,203.0.113.4',
+                asn => "65000",
+                'bgp-mode' => 'internal',
+            },
+            bgp => {
+                type => "bgp",
+                'peers' => '198.51.100.10',
+                ebgp => "1",
+                asn => "65001",
+                loopback => 'dummy1',
+                node => "localhost",
+            },
+            wan => {
+                type => "evpn",
+                peers => '203.0.113.100,203.0.113.101',
+                asn => "65000",
+                nodes => 'localhost',
+                'bgp-mode' => 'external',
+                'peer-group-name' => 'wan',
+            }
+        },
+    }
+}
+
-- 
2.47.3





  parent reply	other threads:[~2026-05-04 16:26 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-04 16:24 [PATCH docs/manager/network/proxmox-ve-rs v2 00/18] Extend EVPN controller functionality Stefan Hanreich
2026-05-04 16:24 ` [PATCH proxmox-ve-rs v2 01/18] frr: add local-as setting Stefan Hanreich
2026-05-04 16:24 ` [PATCH proxmox-ve-rs v2 02/18] frr: add support for extcommunity lists Stefan Hanreich
2026-05-04 16:24 ` [PATCH proxmox-ve-rs v2 03/18] frr-templates: render local-as setting Stefan Hanreich
2026-05-04 16:24 ` [PATCH proxmox-ve-rs v2 04/18] frr-templates: render community lists in templates Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 05/18] evpn controller: make nodes configurable Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 06/18] evpn controller: allow multiple evpn controllers in a cluster Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 07/18] evpn controller: add bgp-mode setting Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 08/18] evpn zone: add secondary-controllers and rt filtering Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 09/18] evpn controller: add ebgp-multihop setting Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 10/18] test: evpn: add test for ibgp + ebgp evpn controller Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 11/18] test: evpn: add legacy test Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 12/18] tests: add rt_import test case when using multiple evpn controllers Stefan Hanreich
2026-05-04 16:24 ` Stefan Hanreich [this message]
2026-05-04 16:24 ` [PATCH pve-network v2 14/18] tests: evpn: force ibgp over ebgp bgp controller with ebgp wan session Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-network v2 15/18] tests: test route filtering mechanism with multiple zones/controllers Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-manager v2 16/18] sdn: evpn: zone: controller: add new advanced fields Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-docs v2 17/18] sdn: evpn: document new zone / controller options Stefan Hanreich
2026-05-04 16:24 ` [PATCH pve-docs v2 18/18] sdn: fix typo in bgp controller Stefan Hanreich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260504162501.425135-14-s.hanreich@proxmox.com \
    --to=s.hanreich@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal