Validation Framework
The diagram in Figure 1 explains the connectivity for the EWAN JVD topology and includes the router models shown in Table 1. Four WAN edge routers are configured as PE routers of the MPLS WAN network and connected to traffic generators—T-GENs—emulating L2/L3 CE-nodes of the enterprise campus and branch, public cloud segments, or data center gateway. To validate dual-homed connectivity to the campus (CE1.1) and the data center gateway (CE4.1), a helper router (ACX7100-48L or MX480) is configured as an L2 mode switch, which is used for most of the test cases.
Links P1-to-Wan Edge 3 and P2-to-Wan Edge 2 are configured with MACsec consistently throughout all test cases.
To Validate DDoS protection functionality, traffic generators TGEN 3.1 and TGEN 2.2 are configured as security devices. These devices established BGP flowspec sessions with respective edge nodes and are installing dynamic stateless firewall policies into the edge routers Wan Edge 2 (MX10004) and Wan Edge 3 (ACX7509).
