How to Deploy a VRF Lite Gateway in VMware NSX-T 3.2

A virtual routing and forwarding (VRF) gateway makes it possible for multiple instances of a routing table to exist within the same gateway at the same time. VRFs are the layer 3 equivalent of a VLAN. A VRF gateway must be linked to a tier-0 gateway. From the tier-0 gateway, the VRF gateway inherits the HA mode, Edge cluster, internal transit subnet, T0-T1 transit subnets, and BGP routing configuration.

If you are using NSX Federation, you can use the Global Manager to create a VRF gateway on a tier-0 gateway if the tier-0 spans only one location. VRF gateway is not supported on stretched tier-0 gateways in NSX Federation. EVPN is not supported in NSX Federation.

Note that even though a VRF gateway has an HA mode, it does not have a mechanism to respond to a communication failure that is independent of the tier-0 gateway’s mechanism. If a VRF gateway loses connectivity to a neighbor but the criteria for the tier-0 gateway to fail over are not met, the VRF gateway will not fail over. The only time a VRF gateway will fail over is when the tier-0 gateway does a failover.

How to Deploy a VRF Lite GW

First let us create an uplink trunk segment that is connected to the uplink interfaces of each VRF GW

NSX-T segment editor configuring a VLAN transport-zone trunk segment for VRF Lite gateway uplinks.

Provide a name

Select your VLAN TZ

Also put in the VLANs you already setup

NSX-T VRF gateway configuration showing the Set control for interfaces.
NSX-T Tier-0 Gateways page with VRF selected as the new gateway type beneath the parent Tier-0 gateway.

Select VRF

VRF gateway editor naming the gateway and connecting it to the TX-Prod parent Tier-0 and edge cluster.

Provide a name

Select a T0 GW to connect to

Save

Yes

NSX-T VRF gateway configuration showing the Set control for interfaces.

Set

Set Interfaces dialog for the VRF gateway before an external interface is added.

Add interface

VRF external-interface form with name, IP mask, uplink trunk segment, edge node, and VLAN fields.

Provide a name, IP, and connect to the pre-created segment

Also select an edge node and provide the VLAN ID

VRF gateway interface list showing the external uplink connected to the trunk segment in Success status.
VRF gateway BGP settings with local AS, ECMP, graceful restart, route aggregation, and neighbor controls.

Set BGP neighbors

Set BGP Neighbors dialog for the VRF gateway before a peer is configured.

Add BGP neighbor

VRF BGP-neighbor form with peer IP, source address, remote AS, graceful restart, and hop-limit fields.

Enter I address

Remote AS number

Source Address

Save

Close

VRF gateway route-redistribution section showing the Set control and BGP status enabled.

Set

Set Route Re-distribution dialog for the VRF gateway before a redistribution rule is added.

Add

Tier-0 Gateways inventory showing the TO-VRF-NPC gateway nested under the TX-Prod parent Tier-0.

Now you can create T1 GW and segments and use the VRF GW like you would a traditional T0 GW

Continue reading

Create Stretched Networks in VMware NSX-T Federation

Explore another guide in this topic and build on what you have just read. Read the article

Leave a Reply

Discover more from Digital Thought Disruption

Subscribe now to keep reading and get access to the full archive.

Continue reading