Do you need secure, isolated multi-tenant connectivity across Kubernetes and cloud infrastructures. JCNR supports SRv6 L3VPN with micro-Segment Identifiers (uSIDs) in various SRv6 endpoint behaviors (End.DT4, End.DT6, End.DT46).
Juniper Cloud-Native Router (JCNR) is a containerized, cloud-native routing solution that brings enterprise-grade networking capabilities to cloud and containerized environments. Built on Juniper's proven routing technologies, JCNR delivers the same robust features and characteristics as traditional Juniper routers while being optimized for modern cloud-native infrastructures.
Segment Routing over IPv6 (SRv6) is a modern networking paradigm that leverages the IPv6 protocol to provide advanced traffic engineering, service programming, and network simplification. SRv6 combines the benefits of segment routing with the ubiquity of IPv6 enabling sophisticated network services through native IPv6 packet processing.
In this article, we will demonstrate SRv6 and SRv6 L3VPN solution offered by JCNR. The feature is supported starting from Junos 24.2.
Layer 3 Virtual Private Networks (L3VPNs) represent a fundamental service model in modern networking that enables organizations to establish secure, isolated communication channels across shared infrastructure. This enables admins to host multiple customers on a shared infrastructure for better resource utilization and yet providing services.
SRv6 L3VPN leverages IPv6 segment routing to provide Layer 3 VPN services across cloud-native network infrastructures. Unlike traditional MPLS-based L3VPN implementations, SRv6 utilizes IPv6 addresses as segment identifiers, enabling service programming directly within the IPv6 header with and without Segment Routing Header (SRH) extension.
JCNR supports l3vpn service with SR-MPLS as ingress, transit and egress nodes in the MPLS network. L3VPN service is supported with SRv6 as ingress and egress node. JCNR offers carrier grade routing functionality with support for IS-IS and OSPF as IGP while BGP offering VPN functionality in control plane.
JCNR offers multiple customers hosted on the same instance with flexibility in attaching users on the fly like other JUNOS platforms. Along with this, JCNR support L3VPN solution in CNI mode where a PoDs running on the same Kubernetes cluster can be hosted on a VPN instance providing connectivity to the service to its end points. All of this is also offered with IPSec service when service chained with cSRX, if user desired security along with L3VPN with SRv6.
Segment Routing over IPv6 (SRv6) in Juniper Cloud-Native Router (JCNR) is supported with micro segment identifiers (uSID). Micro-Segment Identifiers (uSIDs) represent a significant optimization technique in SRv6 that addresses the header overhead concerns of traditional SRv6 implementations. While standard SRv6 uses full 128-bit IPv6 addresses as segment identifiers, uSIDs enable the packing of multiple segments within a single IPv6 address, dramatically reducing the Segment Routing Header (SRH) size and improving network efficiency. In some cases, removing the need for SRH header as uSIDs fit in destination address of IPv6 header. JCNR supports max of 6 uSIDs which requires no SRH header addition.
SRv6 combines the benefits of segment routing with the native IPv6 forwarding plane providing enhanced service programming capabilities through segment identifier (SID) functions. JCNR supports SRv6 head-end and egress nodes roles in a SRv6 network. Support for transit node is in the pipeline.
SRv6 has multiple end point behaviors. In JCNR, following end points are supported.
End.DT4: Endpoint with decapsulation and specific IPv4 table lookup function for SRv6 instantiation of Global or IPv4 L3VPN (transport IPv4 services over SRv6 underlay)
End.DT6: Endpoint with decapsulation and specific IPv6 table lookup function for SRv6 instantiation of Global or IPv6 L3VPN (Transport IPv6 services over SRv6 underlay)
End.DT46: Endpoint with decapsulation and specific IP table lookup function for SRv6 instantiation of Global, IPv4 or IPv6 L3VPN (Transport both IPv4 and IPv6 services over SRv6 underlay). It is shared across IPv4 and IPv6 prefixes.
JCNR functions as a comprehensive Container Network Interface (CNI) plugin for Kubernetes, providing advanced networking capabilities directly integrated with the container orchestration platform. JCNR operates also as a Cloud-Native Network Function (CNF), providing traditional network services (routing, switching, security) in containerized form. As a CNF, JCNR delivers carrier-grade network functions with cloud-native operational characteristics. SRv6 is supported in both CNI and CNF modes giving the flexibility for users to deploy SRv6 solution in any cloud native environments. JCNR supports up to 6 uSIDs.
In this document, we will demonstration the following solution with JCNR. In this topology, PE1 and PE2 are JCNR acting as SRv6 head-end and egress nodes in the network. There is a BGP session between PE1 and PE2 for providing VPN solution with AS 64512. IS-IS is used as IGP. There is a redundant path between PE1 and provide node to demonstrate ECMP support with SRv6.
CE1 and CE2 in this solution are PoDs connected to JCNR. JCNR is acting as secondary CNI in this solution demonstrating the ability to provide SRv6 connectivity in CNI mode.
In the context of 5G and Open RAN (O-RAN) network architecture, the midhaul is the transport network link that connects the Distributed Unit (DU) to the Centralized Unit (CU). JCNR with SRv6 can be used as gateway for DU where JCNR is providing connectivity over SRv6 network in midhaul to CU. In the same use case, JCNR can be the gateway for CU providing connectivity to multiple DUs.
Protocol and data path state from PE1 and PE2 from this topology given below. In this topology CE1 and CE2 are connected to JCNR as PoDs in CNI mode. Yet, they are going over SRv6 network as VPN traffic. This demonstrates the advantage of JCNR as SRv6 node in cloud native environments.
root@jcnr3-kvm# run show isis adjacency
Interface System L State Hold (secs) SNPA
enp10s0 jcnr2 2 Up 587
enp7s0 jcnr2 2 Up 587
enp9s0 jcnr6-kvm 2 Up 591
Packet received from PE1 at PE2 does a VRF lookup which is represented by this next-hop. PE2 removes SRv6 header and maps the SID to a VRF and a route lookup is done on inner packet.
set interfaces lo0 unit 0 family inet address 3.3.3.3/32
set interfaces lo0 unit 0 family inet6 address 3333::1/128
set interfaces lo0 unit 0 family iso address 49.0002.0192.0168.0003.00
set interfaces enp7s0 unit 0 family iso
set interfaces enp9s0 unit 0 family iso
set interfaces enp10s0 unit 0 family iso
set routing-options router-id 3.3.3.3
set routing-options route-distinguisher-id 3.3.3.3
set protocols isis interface lo0.0
set protocols isis interface enp7s0 level 2 hello-interval 15
set protocols isis interface enp7s0 level 2 hold-time 600
set protocols isis interface enp7s0 hello-padding disable
set protocols isis interface enp7s0 point-to-point
set protocols isis interface enp9s0 level 2 hello-interval 15
set protocols isis interface enp9s0 level 2 hold-time 600
set protocols isis interface enp9s0 hello-padding disable
set protocols isis interface enp9s0 point-to-point
set protocols isis interface enp10s0 level 2 hello-interval 15
set protocols isis interface enp10s0 level 2 hold-time 600
set protocols isis interface enp10s0 hello-padding disable
set protocols isis interface enp10s0 point-to-point
set protocols isis level 1 disable
set protocols isis source-packet-routing srv6 locator u_loc micro-node-sid
set routing-options source-packet-routing srv6 block usid_blk_with_statics fcbb:bb01::/32
set routing-options source-packet-routing srv6 block usid_blk_with_statics local-micro-sid maximum-static-sids 2000
set routing-options source-packet-routing srv6 locator u_loc fcbb:bb01:300::/48
set routing-options source-packet-routing srv6 locator u_loc micro-sid block-name usid_blk_with_statics
set routing-options source-packet-routing srv6 locator u_loc micro-sid flavor none
set routing-options resolution preserve-nexthop-hierarchy
set routing-options transport-class auto-create
set routing-options forwarding-table srv6-chain-merge
set routing-options forwarding-table export pplb
set routing-options forwarding-table channel vrouter export pplb
set policy-options policy-statement pplb then load-balance per-packet
set system processes routing bgp tcp-listen-port 178
set protocols bgp tcp-connect-port 178
set protocols bgp group PE_3_4 type internal
set protocols bgp group PE_3_4 multihop
set protocols bgp group PE_3_4 local-address 3.3.3.3
set protocols bgp group PE_3_4 family inet unicast extended-nexthop
set protocols bgp group PE_3_4 family inet unicast advertise-srv6-service
set protocols bgp group PE_3_4 family inet unicast accept-srv6-service
set protocols bgp group PE_3_4 family inet-vpn unicast extended-nexthop
set protocols bgp group PE_3_4 family inet-vpn unicast advertise-srv6-service
set protocols bgp group PE_3_4 family inet-vpn unicast accept-srv6-service
set protocols bgp group PE_3_4 family inet6 unicast advertise-srv6-service
set protocols bgp group PE_3_4 family inet6 unicast accept-srv6-service
set protocols bgp group PE_3_4 family inet6-vpn unicast advertise-srv6-service
set protocols bgp group PE_3_4 family inet6-vpn unicast accept-srv6-service
set protocols bgp group PE_3_4 family evpn signaling
set protocols bgp group PE_3_4 local-as 64512
set protocols bgp group PE_3_4 neighbor 4.4.4.4
set protocols bgp source-packet-routing srv6 locator u_loc micro-dt4-sid
set protocols bgp source-packet-routing srv6 locator u_loc micro-dt6-sid
set protocols bgp source-packet-routing srv6 locator u_loc micro-dt46-sid
set protocols source-packet-routing srv6
set routing-instances srv6 protocols bgp source-packet-routing srv6 locator u_loc micro-dt4-sid
set routing-instances srv6 protocols bgp source-packet-routing srv6 locator u_loc micro-dt6-sid
set routing-instances srv6 protocols bgp source-packet-routing srv6 locator u_loc micro-dt46-sid
set groups cni routing-instances srv6 instance-type vrf
set groups cni routing-instances srv6 routing-options rib srv6.inet6.0 static route 1234::1e1e:e0b/128 qualified-next-hop 1234::1e1e:e0b interface vhostnet5-6b7ae4ee-dedd-4410-b3
set groups cni routing-instances srv6 routing-options static route 30.30.14.11/32 qualified-next-hop 30.30.14.11 interface vhostnet5-6b7ae4ee-dedd-4410-b3
set groups cni routing-instances srv6 interface vhostnet5-6b7ae4ee-dedd-4410-b3
set groups cni routing-instances srv6 vrf-target target:64512:4