Skip to content

Add EVPN monitoring with tenant-aware queries and ADD-PATH support - #12

Open
jbemmel wants to merge 2 commits into
FastNetMon:mainfrom
jbemmel:feature/evpn-symmetric-irb
Open

jbemmel wants to merge 2 commits into
FastNetMon:mainfrom
jbemmel:feature/evpn-symmetric-irb

Conversation

@jbemmel

@jbemmel jbemmel commented Oct 1, 2026

Copy link
Copy Markdown

This PR adds support for monitoring BGP L2VPN EVPN routes through BGP and BMP, including ADD-PATH sessions.

What’s included

  • Dedicated EVPN RIB — stores EVPN routes separately from global unicast, with identity based on route type, wire-format RD, route-specific keys, and ingress, including ADD-PATH identity.
  • EVPN route decoding — decodes Type 2 MAC/IP and Type 5 IP prefix advertisements, partially decodes Types 1, 3, and 4, and preserves unknown RD-bearing route types as opaque records. Raw NLRI is retained for inspection.
  • Route-target filtering — selects routes by advertised route target, allowing tenant-related state to be inspected across multiple RDs.
  • Symmetric IRB visibility — exposes fields useful for correlating MAC-VRF and IP-VRF advertisements, including MAC/IP addresses, Ethernet tags, ESIs, gateways, both Type 2 label fields, router MAC communities, and next hops.
  • Lifecycle handling — integrates EVPN into withdrawals, peer-down handling, and ingress cleanup, including address-family-scoped withdrawals. Route identity excludes applicable forwarding fields, so label changes do not prevent withdrawal matching.
  • REST API and CLI — adds GET /api/v1/ribs/l2vpnevpn/routes and netom-cli show evpn, with filters for RD, route target, route type, VNI, prefix, ingress, and retained withdrawn routes.
  • BMP output — includes EVPN in live rebuilt updates and initial RIB dumps, preserving next hops, communities, and ADD-PATH IDs.

Label fields are exposed as raw 24-bit values; the VNI filter matches these values for VXLAN monitoring. Withdrawn records are available when withdrawn-attribute retention is enabled.

Why this matters

EVPN monitoring provides visibility into advertised overlay state across tenants and forwarding domains. Route-target filtering supports inspection across multiple RDs, while separating route identity from forwarding attributes enables consistent tracking of route updates and withdrawals.

This provides a foundation for analyzing EVPN fabrics, correlating MAC-VRF and IP-VRF advertisements, and deriving resource inventories from observed control-plane data. It reports advertised state without inferring VRF membership, assigning L2/L3 VNI roles, or simulating import policy and forwarding resolution.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant