Overlay Network
Diagrama de Servicios Lógicos

Descripción de la Capa de Servicios
El Overlay representa los servicios lógicos VPRN y VPLS que operan sobre el underlay MPLS. La arquitectura utiliza dos VPRNs (9998 para suscriptores y 9999 para Internet/NAT) con route-leaking bidireccional via VPN-IPv4 communities.
VPRNs
VPRN 9998 - Subscriber VRF
Contiene toda la infraestructura de suscriptores:
- Subscriber Interface "services" con tres Group Interfaces
- DHCP Servers (IPv4 + IPv6)
- NAT Inside (CGNAT, NAT64, One-to-One)
- SRRP Instances
- Redundant Interface via SDP
VPRN 9999 - Internet VRF
Contiene la conectividad upstream:
- Interfaces hacia Carrier 1 y Carrier 2
- Interface hacia LIG
- NAT Outside Pools (dtpool, nat64-pool, one-to-one)
- eBGP con Carriers
Esquema de VLANs y MAC-VRFs
La OLT SR Linux utiliza MAC-VRFs para bridging entre los BNGs y las ONTs:
| MAC-VRF | S-VLAN | C-VLAN | Service | Group Interface |
|---|---|---|---|---|
| bd-50 | 50 | 150 | IPv6-only | ipv6-only |
| bd-51 | 51 | 200 | Dual-Stack | dual-stack |
| bd-52 | 52 | 300 | VIP (IPv4 1:1) | vip |
| bd-srrp | 4094 | - | SRRP Messages | - |
- S-VLAN 50 / C-VLAN 150: Servicio IPv6-only con NAT64 (ipv6-only GI)
- S-VLAN 51 / C-VLAN 200: Servicio Dual-Stack con CGNAT determinístico (dual-stack GI)
- S-VLAN 52 / C-VLAN 300: Servicio VIP con NAT One-to-One (vip GI)
Service Chaining por Flujo
Esta vista resume el recorrido lógico de cada servicio de extremo a extremo. Es útil para demos, formación y troubleshooting porque conecta acceso, política, VPRN/NAT y salida hacia Internet en una sola tabla.
| Servicio | Encapsulación / Entrada | Procesamiento en BNG | Salida | ATP relacionado |
|---|---|---|---|---|
| ONT1 WAN1 IPv6-only | ONT1 -> OLT bd-50 -> S-VLAN 50 / C-VLAN 150 | Capture-SAP -> GI ipv6-only -> VPRN 9998 -> route-leaking con VPRN 9999 -> NAT64/DNS64 si aplica | Carrier 1 / Carrier 2 -> Internet | NAT64 |
| ONT1 WAN2 Dual-Stack | ONT1 -> OLT bd-51 -> S-VLAN 51 / C-VLAN 200 | Capture-SAP -> GI dual-stack -> VPRN 9998 -> CGNAT para IPv4 + IPv6 nativo -> VPRN 9999 | Carrier 1 / Carrier 2 -> Internet | Observabilidad |
| ONT1 WAN3 VIP | ONT1 -> OLT bd-52 -> S-VLAN 52 / C-VLAN 300 | Capture-SAP -> GI vip -> VPRN 9998 -> NAT One-to-One -> VPRN 9999 | Carrier 1 / Carrier 2 -> Internet | CGNAT / NAT policies |
| ONT2 WAN1 PPPoE | ONT2 -> OLT bd-50 -> S-VLAN 50 / C-VLAN 150 | PPPoE + RADIUS -> GI ipv6-only -> VPRN 9998 -> NAT64 si aplica -> VPRN 9999 | Carrier 1 / Carrier 2 -> Internet | ESM |
Diagramas de Flujo de Servicio
ONT1 WAN2 Dual-Stack
ONT2 WAN1 PPPoE
Route Leaking Inter-VPRN
Las rutas se intercambian entre VPRN 9998 y 9999 mediante BGP VPN-IPv4 con communities:
# Community para rutas del Internet VRF
/configure policy-options community "internet-vrf" member "target:65510:9999"
# Community para rutas del Subscriber VRF
/configure policy-options community "subscriber-vrf" member "target:65510:9998"
Capture SAP
Cada Capture-SAP en el VPLS intercepta tráfico según S-VLAN y lo asigna al Group Interface correspondiente:
# S-VLAN 50 → GI ipv6-only (SRRP 1)
/configure service vpls "capture-sap" capture-sap 1/1/c2/1:50.*
msap-defaults group-interface "ipv6-only"
track-srrp 1
# S-VLAN 51 → GI dual-stack (SRRP 2)
/configure service vpls "capture-sap" capture-sap 1/1/c2/1:51.*
msap-defaults group-interface "dual-stack"
track-srrp 2
# S-VLAN 52 → GI vip (SRRP 3)
/configure service vpls "capture-sap" capture-sap 1/1/c2/1:52.*
msap-defaults group-interface "vip"
track-srrp 3