Description

In some cases, there may be a traffic blackhole occur on the EVPN-VxLAN fabric. One possibility is that overlay next-hop value may somehow be incorrectly programmed as "0" (zero), which caused the traffic blackhole.

Symptoms

>>> The symptom is specifically collected on QFX5130 (Junos EVO) platforms.
>>> To check overlay next-hop programming, we need to login to "PFE-CLI" as below.

root@QFX5130_Border-Leaf_1:pfe> show evo-pfemand nh detail index <NH index ID extracted from RE-CLI command "show route forwarding-table destination <DST IP>">

Example of incorrect programming:

root@QFX5130_Border-Leaf_1:pfe> show evo-pfemand nh detail index 80851

Index        : 80851
GUID         : 837518630640
Nh Type      : composite                                                                         0x00000000

EalCompositeNh Details  :
 Object GUID            : 837518630642
 Composition Function   : Dynamic Tunnel Composite function

EalCompNhTunnel Details :
 Tunnel Id              : 0
 Tunnel Type            : 3
 Tunnel Mode            : 0
 Tunnel Encap Rtb Id    : 0
 Tunnel Decap Rtb Id    : 119
 Tunnel MTU             : 0
 Tunnel Encap Data Len  : 53
 Tunnel Encap Data      : 01 8b 01 fc 0a 00 00 00 00 00 00 00 00 00 00 00 00 83 01 fc 0a 00 00 00 00 00 00 00 00 00 00 00 00 fc 55 00 00 fc 55 00 00 c8 fe 6a 08 2f 00 00 cc 34 bc 09 2d
 Tunnel Spec  Data Len  : 0
 Tunnel Spec  Data      :
 VPN Label Valid        : 0
 VPN Label              : 0x00000000
 VPN Label Attributes   : 0x00000000

 _ealNh: 0x7faf99f9a400
Brcm-VxlanTunnel-NH     : 0
Vxlan Tunnel Src IP     : <Vxlan_Tunnel_Src_IP>
Vxlan Tunnel Dest Ip    : <Vxlan_Tunnel_Dest_Ip>
Vxlan Encap VnId:       : 22012
Vxlan Decap VnId        : 22012
Overlay smac Addr       : 0:cc:34:bc:9:2d
Overlay dmac Addr       : c8:fe:6a:8:2f:0
Underlay Egress Nh      : 232769

Overlay Egress Nh       : 0  <<<<<<<<<<<<<<<<<< this is wrong

Decap VPN Hw Id         : 32768
Decap VFI Hw Id         : 4096
Encap VPN Hw Id         : 32768
Encap VFI Hw Id         : 4096
Network Vport Id        : 0xb0000104


Example of correct programming:

root@QFX5130_Border-Leaf_2:pfe> show evo-pfemand nh detail index 80776

Index        : 80776
GUID         : 837518629695
Nh Type      : composite                                                                         0x00000000

EalCompositeNh Details  :
 Object GUID            : 837518629697
 Composition Function   : Dynamic Tunnel Composite function

EalCompNhTunnel Details :
 Tunnel Id              : 0
 Tunnel Type            : 3
 Tunnel Mode            : 0
 Tunnel Encap Rtb Id    : 0
 Tunnel Decap Rtb Id    : 119
 Tunnel MTU             : 0
 Tunnel Encap Data Len  : 53
 Tunnel Encap Data      : 01 8c 01 fc 0a 00 00 00 00 00 00 00 00 00 00 00 00 83 01 fc 0a 00 00 00 00 00 00 00 00 00 00 00 00 fc 55 00 00 fc 55 00 00 c8 fe 6a 08 2f 00 00 cc 34 bc 2c 2d
 Tunnel Spec  Data Len  : 0
 Tunnel Spec  Data      :
 VPN Label Valid        : 0
 VPN Label              : 0x00000000
 VPN Label Attributes   : 0x00000000

 _ealNh: 0x7f06fa3efa00
Brcm-VxlanTunnel-NH     : 100005
Vxlan Tunnel Src IP     : <Vxlan_Tunnel_Src_IP>
Vxlan Tunnel Dest Ip    : <Vxlan_Tunnel_Dest_Ip>
Vxlan Encap VnId:       : 22012
Vxlan Decap VnId        : 22012
Overlay smac Addr       : 0:cc:34:bc:2c:2d
Overlay dmac Addr       : c8:fe:6a:8:2f:0
Underlay Egress Nh      : 232769

Overlay Egress Nh       : 100005  <<<<<<<<<<<<<<<<< this is correct

Decap VPN Hw Id         : 32800
Decap VFI Hw Id         : 4128
Encap VPN Hw Id         : 32800
Encap VFI Hw Id         : 4128
Network Vport Id        : 0xb0000104

Solution

>>> The workaround is to restart daemon "evo-pfemand" or reboot the device.
>>> Permanent fix is to upgrade Junos to one of the fixed versions as per PR#1745711.

Here is the external link to the PR.

https://prsearch.juniper.net/problemreport/PR1745711

Modification History

Draft Created
For publish.