Page 2
, H3CS, H3CIE, H3CNE, Aolynk, Care, , IRF, NetPilot, Netflow, SecEngine, SecPath, SecCenter, SecBlade, Comware, ITCMM and HUASAN are trademarks of Hangzhou H3C Technologies Co., Ltd. All other trademarks that may be mentioned in this manual are the property of their respective owners Notice The information in this document is subject to change without notice.
Page 3
Preface This command reference describes VXLAN configuration commands. This preface includes the following topics about the documentation: • Audience. • Conventions. • About the H3C S6800 documentation set. • Obtaining documentation. • Technical support. • Documentation feedback. Audience This documentation is intended for: •...
Page 4
GUI conventions Convention Description Window names, button names, field names, and menu items are in Boldface. For Boldface example, the New User window appears; click OK. Multi-level menus are separated by angle brackets. For example, File > Create > > Folder.
Page 5
Obtaining documentation Access the most up-to-date H3C product documentation on the World Wide Web at http://www.h3c.com. Click the following links to obtain different categories of product documentation: [Technical Documents]—Provides hardware installation, software upgrading, and software feature...
Page 6
Technical support service@h3c.com http://www.h3c.com Documentation feedback You can e-mail your comments about product documentation to info@h3c.com. We appreciate your comments.
VXLAN commands For Release 2416, VXLAN requires a license. For Release 2418P01 and later versions, VXLAN does not require a license. For information about feature licensing, see Fundamentals Configuration Guide. Basic VXLAN commands arp suppression enable Use arp suppression enable to enable ARP flood suppression. Use undo arp suppression enable to restore the default.
undo description Default A VSI does not have a description. Views VSI view Predefined user roles network-admin Parameters text: Specifies the VSI description, a case-sensitive string of 1 to 80 characters. Examples # Configure a description for the VSI vpn1. <Sysname>...
Total entries: 3 Table 1 Command output Field Description Link ID Link ID that uniquely identifies an AC or a VXLAN tunnel on a VSI. Remaining lifetime (in minutes) of the ARP flood suppression entry. When Aging the timer expires, the entry is deleted. Related commands •...
225.1.1.1 Idle 225.1.1.2 Idle # Display detailed information about all multicast groups that contain IGMP host-enabled interfaces. <Sysname> display igmp host group verbose Vlan-interface10(1.1.1.20): IGMP host groups in total: 2 Group: 225.1.1.1 Group mode: Exclude Member state: Idle Expires: Off Source list (sources in total: 0): Group: 225.1.1.2 Group mode: Exclude...
Page 12
Syntax display l2vpn mac-address [ vsi vsi-name ] [ dynamic ] [ count ] Views Any view Predefined user roles network-admin network-operator Parameters vsi vsi-name: Specifies a VSI name, a case-sensitive string of 1 to 31 characters. If you do not specify a VSI, the command displays MAC address entries for all VSIs.
Field Description Entry aging state: • Aging Aging. • NotAging. Related commands reset l2vpn mac-address display l2vpn service-instance Use display l2vpn service-instance to display information about Ethernet service instances. Syntax display l2vpn service-instance [ interface interface-type interface-number [ service-instance instance-id ] ] [ verbose ] Views Any view Predefined user roles...
Page 14
Field Description Interface Name of a Layer 2 Ethernet interface or Layer 2 aggregate interface. SrvID Ethernet service instance ID. VSI name. This field is empty if an Ethernet service instance is not mapped to Owner any VSI. LinkID Ethernet service instance's link ID on the VSI. Ethernet service instance state: •...
Statistics : Enabled Input Statistics: Octets Packets Output Statistics: Octets Packets Table 5 Command output Field Description Interface Name of a Layer 2 Ethernet interface or Layer 2 aggregate interface. Service Instance Ethernet service instance ID. Frame match criterion of the Ethernet service instance. If the Ethernet service Encapsulation instance does not contain a frame match criterion, the command does not display this field.
Page 16
Parameters name vsi-name: Specifies a VSI by its name, a case-sensitive string of 1 to 31 characters. If you do not specify a VSI, the command displays information about all VSIs. verbose: Displays detailed information about VSIs. If you do not specify this keyword, the command displays brief information about VSIs.
Field Description Bandwidth Maximum bandwidth in kbps on the VSI. Broadcast Restrain Broadcast restraint ratio. Multicast Restrain Multicast restraint ratio. Unknown Unicast Unknown unicast restraint ratio. Restrain MAC Learning State of the MAC learning function. MAC Table Limit Maximum number of MAC address entries on the VSI. Action on source MAC-unknown frames received after the maximum number of Drop Unknown MAC entries is reached.
Page 18
Syntax display vxlan tunnel [ vxlan-id vxlan-id ] Views Any view Predefined user roles network-admin network-operator Parameters vxlan-id: Specifies a VXLAN ID in the range of 0 to 16777215. If you do not specify a VXLAN, the command displays VXLAN tunnel information for all VXLANs. Examples # Display VXLAN tunnel information for all VXLANs.
Field Description Flood proxy state: • Enabled—Flood proxy is enabled. The VTEP sends broadcast, multicast, and Flooding proxy unknown unicast traffic to a flood proxy server through the tunnel. The flood proxy server replicates and forwards flood traffic to remote VTEPs. •...
only-tagged: Matches only PVID-tagged frames. To match both untagged frames and PVID-tagged frames, do not specify this keyword. s-vid vlan-id c-vid vlan-id: Matches frames that are tagged with the specified outer and inner 802.1Q VLAN IDs. The vlan-id argument specifies an 802.1Q VLAN ID in the range of 1 to 4094. This option is available in Release 2422 and later versions.
Predefined user roles network-admin Usage guidelines By default, the device floods unknown unicast frames received from the local site to the following interfaces in the frame's VXLAN: • All interfaces in the local site except for the incoming interface. • All VXLAN tunnel interfaces.
NOTE: For VXLANs that use the same multicast group address, you must configure the same source IP address for their multicast VXLAN packets. If you execute the group command multiple times for a VXLAN, the most recent configuration takes effect. Examples # Set the multicast group address to 233.1.1.1 for flood traffic in VXLAN 100.
• group • multicast routing (IP Multicast Command Reference) l2vpn enable Use l2vpn enable to enable L2VPN. Use undo l2vpn enable to disable L2VPN. Syntax l2vpn enable undo l2vpn enable Default L2VPN is disabled. Views System view Predefined user roles network-admin Usage guidelines You must enable L2VPN before you can configure L2VPN settings.
interface tunnel tunnel-number: Specifies the VXLAN tunnel interface for the remote MAC address. The tunnel-number argument represents the tunnel interface number. The tunnel interface must already exist. vsi vsi-name: Specifies the VSI name, a case-sensitive string of 1 to 31 characters. Usage guidelines A remote MAC address is the MAC address of a VM in a remote site.
reset arp suppression vsi Use reset arp suppression vsi to clear ARP flood suppression entries on VSIs. Syntax reset arp suppression vsi [ name vsi-name ] Views User view Predefined user roles network-admin Parameters name vsi-name: Specifies a VSI by its name, a case-sensitive string of 1 to 31 characters. If you do not specify a VSI, this command clears ARP flood suppression entries on all VSIs.
selective-flooding mac-address Use selective-flooding mac-address to enable selective flood for a MAC address. Use undo selective-flooding mac-address to disable selective flood for a MAC address. Syntax selective-flooding mac-address mac-address undo selective-flooding mac-address mac-address Default Selective flood is not enabled for any MAC addresses. Views VSI view Predefined user roles...
Parameters instance-id: Specifies an Ethernet service instance ID in the range of 1 to 4096. Examples # On the Layer 2 Ethernet interface FortyGigE 1/0/1, create Ethernet service instance 1 and enter Ethernet service instance view. <Sysname> system-view [Sysname] interface fortygige 1/0/1 [Sysname-FortyGigE1/0/1] service-instance 1 [Sysname-FortyGigE1/0/1-srv1] Related commands...
undo tunnel { tunnel-number | all } Default A VXLAN does not contain VXLAN tunnels. Views VXLAN view Predefined user roles network-admin Parameters tunnel-number: Specifies a tunnel number in the range of 0 to 1023. The tunnel must be a VXLAN tunnel.
undo tunnel global source-address Default No global source address is specified for VXLAN tunnels. Views System view Predefined user roles network-admin Parameters ipv4-address: Specifies an IPv4 address. Usage guidelines A VXLAN tunnel uses the global source address if you do not specify a source interface or source address for a VXLAN tunnel.
[Sysname-vsi-vxlan10] Related commands display l2vpn vsi vtep group member remote Use vtep group member remote to specify a VXLAN VTEP group and its member VTEPs. Use undo vtep group member remote to restore the default. NOTE: This command is available in Release 2418P01 and later versions. Syntax vtep group group-ip member remote member-ip&<1-8>...
Parameters vxlan-id: Specifies a VXLAN ID in the range of 0 to 16777215. Usage guidelines You can create only one VXLAN for a VSI. The VXLAN ID for each VSI must be unique. Examples # Create VXLAN 10000 for VSI vpna and enter VXLAN view. <Sysname>...
Use undo vxlan invalid-vlan-tag discard to restore the default. Syntax vxlan invalid-vlan-tag discard undo vxlan invalid-vlan-tag discard Default The device does not check whether a VXLAN packet has 802.1Q VLAN tags in the inner Ethernet header. Views System view Predefined user roles network-admin Usage guidelines If a remote VTEP uses the Ethernet access mode for an Ethernet service instance, its VXLAN...
With the information center, you can set log message filtering and output rules, including output destinations. For more information about configuring the information center, see Network Management and Monitoring Configuration Guide. Examples # Enable VXLAN local-MAC change logging. <Sysname> system-view [Sysname] vxlan local-mac report vxlan tunnel mac-learning disable Use vxlan tunnel mac-learning disable to disable remote-MAC address learning.
Parameters port-number: Specifies a UDP port number in the range of 1 to 65535. As a best practice, specify a port number in the range of 1024 to 65535 to avoid conflict with well-known ports. Usage guidelines You must configure the same destination UDP port number on all VTEPs in a VXLAN. Examples # Set the destination UDP port number to 6666 for VXLAN packets.
In VLAN access mode, VXLAN packets sent between VXLAN sites do not contain 802.1Q VLAN tags. VXLAN can provide Layer 2 connectivity for different 802.1Q VLANs between sites. You can use different 802.1Q VLANs to provide the same service in different sites. •...
Predefined user roles network-admin Parameters ca-filename: Specifies the CA certificate file name, a case-insensitive string. The file name cannot contain the slot string. bootstrap: Obtains a CA certificate file from the controller if the specified CA certificate file does not exist.
Use undo ovsdb server enable to disable the OVSDB server. Syntax ovsdb server enable undo ovsdb server enable Default The OVSDB server is disabled. Views System view Predefined user roles network-admin Usage guidelines Before you enable the OVSDB server, you must establish an OVSDB SSL or TCP connection with a minimum of one controller.
ovsdb server pssl Use ovsdb server pssl to enable the device to listen for OVSDB SSL connection requests. Use undo ovsdb server pssl to disable the device to listen for OVSDB SSL connection requests. Syntax ovsdb server pssl port [ port-number ] undo ovsdb server pssl Default The device does not listen for OVSDB SSL connection requests.
Parameters port-number: Specifies a port on which the device listens for TCP connection requests. The value range for the port-number argument is 1 to 65535. If you do not specify a port, the device uses the default port number 6640. Usage guidelines The device can listen for TCP connection requests on only one port.
Use undo ovsdb server tcp to remove the OVSDB TCP connection to a controller. Syntax ovsdb server tcp ipv4-address port port-number undo ovsdb server tcp ipv4-address port port-number Default The device does not have active TCP connections. Views System view Predefined user roles network-admin Parameters...
[Sysname] interface fortygige 1/0/1 [Sysname-FortyGigE1/0/1] vtep access port vtep enable Use vtep enable to enable VTEP mode. Use undo vtep enable to disable VTEP mode. Syntax vtep enable undo vtep enable Default VTEP mode is disabled. Views System view Predefined user roles network-admin Usage guidelines You must enable VTEP mode for the device to exchange information with the controller for VXLAN...
Page 43
Examples # Enable flood proxy on all multicast VXLAN tunnels. <Sysname> system-view [Sysname] vxlan tunnel service node...
Index A D E F G I L M O R S T V X ovsdb server ptcp,32 ovsdb server ssl,33 arp suppression enable,1 ovsdb server tcp,33 description,1 reserved vxlan,17 display arp suppression vsi,2 reset arp suppression vsi,18 display igmp host group,3 reset l2vpn mac-address,18 display l2vpn mac-address,4 display l2vpn service-instance,6...
Need help?
Do you have a question about the S6800 Series and is the answer not in the manual?
Questions and answers