Create Stretched Tier-0 Gateway in VMware NSX-T Federation

It is time to deploy a Stretched Tier-0 Gateway

  1. Configure segments for the Tier-0 Uplink
  2. Create a Stretched Tier-0 GW
  3. Connect the Stretched Tier-1 GW to the Stretched Tier-0 GW
  4. Test end to end connectivity

First we need to log into the Primary Global Manager

NSX-T Set BGP Neighbors panel showing zero neighbors and the Add BGP Neighbor control.

Networking > Conenectivity > Segments

ADD SEGMENT

NSX-T segment editor configuring the Dallas primary-site VLAN segment used as a stretched Tier-0 uplink.

Name the Segment – I recommend putting something to indicate stretched uplink

Choose the primary location and the primary VLAN Transport Zone

Provide the VLAN ID and save

NSX-T confirmation that the Dallas primary-site stretched Tier-0 uplink segment was created successfully.

No

NSX-T segment row showing the Dallas stretched Tier-0 uplink segment in Success status.

Confirm the status is successful

NSX-T segment editor configuring the Fort Worth secondary-site VLAN segment used as a stretched Tier-0 uplink.

Create a second segment for the other uplink

Provide a name that indicates this is a VLAN from the secondary site and that it is for stretching

Select your secondary location and the VLAN Transport Zone for your second site

Provide the VLAN ID

Save

NSX-T confirmation that the Fort Worth stretched Tier-0 uplink segment was created successfully.

No

NSX-T Segments inventory showing the Dallas and Fort Worth stretched Tier-0 uplink segments in Success status.

Confirm the status is success

Global Manager Tier-0 Gateways page with the control for adding a stretched Tier-0 gateway.

Networking > Connectivity > Tier-0 Gateways

ADD TIER-0 GAEWAY

Stretched Tier-0 gateway editor using Active-Active mode with the Dallas primary location and RTEP edge cluster.

Enter a name for this gateway

HA Mode set to Active Active

Pick the primary location and the edge cluster that has the RTEP

ADD LOCATION

Stretched Tier-0 gateway setting with the Mark all locations as Primary option disabled before adding the secondary location.

Disable Mark all locations as Primary

Stretched Tier-0 gateway locations showing Dallas as primary and Fort Worth configured as secondary with its RTEP cluster.

Enter in your secondary location and RTEP Cluster

Set Mode to Secondary

Failback Preferences to Priority 1

SAVE

NSX-T confirmation that the Dallas-Fort Worth stretched Tier-0 gateway was created successfully.

Yes

Stretched Tier-0 gateway interface section listing separate Dallas and Fort Worth location groups.

Set

Set Interfaces dialog for the stretched Tier-0 gateway before external interfaces are added.

ADD Interface

Interface form for the stretched Tier-0 gateway with the Dallas location, external type, IP address, segment, and edge-node fields.

Provide a name to indicate this interface belongs to the primary site

Select the primary location

Provide the IP address for the uplink

Connect to the primary location T0-uplink segment

Then select the edge node that supports the RTEP

Save

Stretched Tier-0 interface list showing the Dallas external uplink connected to its segment in Success status.

Confirm the status successful

ADD INTERFACE

Repeat the process for the second uplink to the secondary location

Stretched Tier-0 interface list showing successful external uplinks for the Dallas and Fort Worth locations.

Confirm both uplinks are up

Stretched Tier-0 BGP configuration with local AS, ECMP, graceful-restart options, and neighbor controls for both locations.

Change the local AS to whatever is in your environment

Click Set under BGP Neighbors

NSX-T Set BGP Neighbors panel showing zero neighbors and the Add BGP Neighbor control.

ADD BGP NEIGHBOR

BGP-neighbor form for the stretched Tier-0 gateway with peer IP, Dallas location, BFD, remote AS, and source-address fields.

Enter the IP for the neighbor

Select your primary site LM

Enter the remote AS number

Put in the remote IP

Save

Stretched Tier-0 BGP-neighbor list showing the Dallas peer in Success status.

ADD BGP NEIGHBOR

Repeat process but for your secondary site

Stretched Tier-0 BGP-neighbor list showing the Dallas and Fort Worth peers in Success status.

Confirm status is successful

Route-redistribution section with separate Set controls for the Dallas and Fort Worth locations.

Click Set for the primary location

Primary-location route-redistribution dialog before any redistribution rule has been added.

ADD ROUTE RE-DISTRIBUTION

Primary-location route-redistribution form naming the Dallas stretched redistribution rule and opening source selection.

Provide a name

Click Set

Route-source selector for static routes and connected interfaces and segments from Tier-0 and advertised Tier-1 subnets.

Select Static Routes and Connected Interfaces & Segments for both Tier-0 and Tier-1

Apply

Primary-location route-redistribution list showing the Dallas stretched redistribution rule after its sources are selected.

Repeat for secondary site too

Stretched Tier-0 configuration showing route redistribution set independently for the Dallas and Fort Worth locations.

Confirm Route Re-Distribution is set for both locations

Save

Close Editing

Tier-0 Gateways inventory showing the Dallas-Fort Worth stretched gateway in Active-Active mode with Success status.

Confirm the status is successful

Global Manager Tier-1 Gateways page used to edit the Dallas-Fort Worth stretched Tier-1 gateway.

Edit your stretched T1

Stretched Tier-1 gateway editor with the Dallas-Fort Worth stretched Tier-0 selected as its linked gateway.

Add the stretched T0 GW to the stretched T1 GW

Tier-1 Gateways inventory showing the stretched Tier-1 linked to the stretched Tier-0 with Success status.

Confirm the status

Finally we need to test connectivity from an outside workstation to the test virtual machines in your Primary and Secondary locations

Windows command prompt showing successful pings from outside NSX-T to virtual machines at both stretched-network locations.

This proves the ability to ping from outside the NSX-T network to virtual machines inside the NSX-T network

Keep exploring

Choose your next step

Continue with the path that best matches the architecture or operating challenge in front of you.

Leave a Reply

Discover more from Digital Thought Disruption

Subscribe now to keep reading and get access to the full archive.

Continue reading