- About this Document
- Solution Benefits
- Solution Architecture
- Validation Framework
- Test Objectives
- Recommendations
- APPENDIX: Example ERB Fabric Creation
- APPENDIX: ERB Fabric Verification (Optional)
- APPENDIX: WAN Router Integration into the Fabric
- APPENDIX: EVPN Insights
- APPENDIX: Junos Configuration from This Fabric
Validation Framework
Test Bed
In the diagram below, you will see the suggested topology used for the phase 2 lab evaluating an ERB fabric with multiple PoDs design.

The suggested lab design provides the ability to evaluate the following:
- Five-stage ERB multi-site fabric with:
- Two redundant core switches acting as spines.
- Pod1/Building1:
- Two redundant distribution switches acting as leafs.
- One 4 Member Virtual Chassis Access Switch acting as ToR.
- One 2 Member Virtual Chassis Access Switch acting as ToR.
- Pod2/Building2:
- Two redundant distribution switches acting as leafs.
- Two standalone access switches acting as ToR.
- Service block function via:
- Integrated to existing core switches (default) acting as service leaf and core at the same time.
- Attached WAN routers via Layer 2 or Layer 3 exit.
- Attached servers via ESI-LAG redundant links.
- WAN router integration:
- Layer 2 fabric exit.
- ESI-LAG-based trunks.
- Layer 3 fabric exit.
- OSPF as routing protocol.
- eBGP as routing protocol
- Attached to:
- Core switch.
- Redundant WAN router design:
- Two Juniper MX routers.
- Two Juniper SRX Firewalls in cluster configuration.
- Layer 2 fabric exit.
- Wi-Fi Access Points:
- Local-attached to the access switches with Power over Ethernet (PoE).
- Various Wi-Fi clients.
- Basic Wi-Fi roaming.
- Overlay server attached to service block functionality:
- DHCP server.
- Other services.
- RADIUS server:
- Server location:
- Local server attached to underlay network.
- Remote Juniper Mist Access Assurance via public cloud.
- Authentication for the following clients:
- Wired clients attached to access switches.
- Wi-Fi clients using the access points.
- Authentication based on Clients:
- MAC address.
- 802.1X EAP authentication.
- Dynamic authorization profiles:
- Single VLAN assigned.
- Multiple VLANs assigned.
- Server location:
- Testing fabric features such as:
- DHCP relay
- Protect RE-Filter
- DHCP snooping
- Storm control
- MAC address limit with aging
- DNS
- NTP
Platforms / Devices Under Test (DUT)
The devices tested and on which Junos version is reported in the table below:
Devices Under Test | ||
---|---|---|
Fabric function | Device | Junos Release |
Core Switches | QFX5120 | 22.4R3-S2 |
Distribution Switches Pod1 | QFX5120 | 22.4R3-S2 |
Distribution Switches Pod2 | QFX5120 | 22.4R3-S2 |
Access Virtual Chassis Pod1 | EX4400 | 22.4R3-S2 |
Access Virtual Chassis Pod1 | EX4100 | 22.4R3-S2 |
Access Switch Pod2 | EX3400 | 22.4R3-S2 |
Access Switch Pod2 | EX3400 | 22.4R3-S2 |
WAN-Router | SRX1500 |