Mailing List Archive

EVPN/VXLAN over IPsec over Internet
Hi! Experts

Sorry for disturbing, we know that EVPN/VXLAN cannot fragment packets, but
we want to use IPsec/Internet as backup EVPN/VXLAN path, is there any
workaround to forwarding such packets in EVPN/VXLAN over IPsec over
Internet?

Thanks in advance.

--
BR!



James Chen
_______________________________________________
juniper-nsp mailing list juniper-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp
Re: EVPN/VXLAN over IPsec over Internet [ In reply to ]
I've done some hacks with an MX to do inline GRE frag+reassembly over the
internet with a looped macsec GigE port to get encrypted traffic with full
MTU. You could add VXLAN to that and get what you want kinda. MX GRE inline
frag/reassembly works well.



On Sat, Jun 1, 2019, 7:44 AM Chen Jiang <ilovebgp4@gmail.com> wrote:

> Hi! Experts
>
> Sorry for disturbing, we know that EVPN/VXLAN cannot fragment packets, but
> we want to use IPsec/Internet as backup EVPN/VXLAN path, is there any
> workaround to forwarding such packets in EVPN/VXLAN over IPsec over
> Internet?
>
> Thanks in advance.
>
> --
> BR!
>
>
>
> James Chen
> _______________________________________________
> juniper-nsp mailing list juniper-nsp@puck.nether.net
> https://puck.nether.net/mailman/listinfo/juniper-nsp
>
_______________________________________________
juniper-nsp mailing list juniper-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp
Re: EVPN/VXLAN over IPsec over Internet [ In reply to ]
Hi! Tim

Thanks for the advice, is it means encapsulated ethernet frames 1st in GRE,
then in EVPN/VXLAN tunnel?

Or 1st in EVPN/VXLAN, then in GRE tunnel?


On Sat, Jun 1, 2019 at 9:06 PM Tim Jackson <jackson.tim@gmail.com> wrote:

> I've done some hacks with an MX to do inline GRE frag+reassembly over the
> internet with a looped macsec GigE port to get encrypted traffic with full
> MTU. You could add VXLAN to that and get what you want kinda. MX GRE inline
> frag/reassembly works well.
>
>
>
> On Sat, Jun 1, 2019, 7:44 AM Chen Jiang <ilovebgp4@gmail.com> wrote:
>
>> Hi! Experts
>>
>> Sorry for disturbing, we know that EVPN/VXLAN cannot fragment packets, but
>> we want to use IPsec/Internet as backup EVPN/VXLAN path, is there any
>> workaround to forwarding such packets in EVPN/VXLAN over IPsec over
>> Internet?
>>
>> Thanks in advance.
>>
>> --
>> BR!
>>
>>
>>
>> James Chen
>> _______________________________________________
>> juniper-nsp mailing list juniper-nsp@puck.nether.net
>> https://puck.nether.net/mailman/listinfo/juniper-nsp
>>
>

--
BR!



James Chen
_______________________________________________
juniper-nsp mailing list juniper-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp