How do I learn VXLAN EVPN on SONiC?

Read the RFCs once, then watch the control plane do it: two leaves, one spine, BGP EVPN between them, a VLAN mapped to a VNI, and show bgp l2vpn evpn plus show vxlan tunnel after every step. SONiC's config is config_db.json, so the lab also teaches how a change is applied and saved on that OS. With NetPilot connected in your assistant, you install the SONiC image once from the NetPilot app and then ask for the fabric in plain words, and the assistant builds it and runs each verification command on the devices.

The lab, in seven steps

  1. 1

    Add the SONiC image once

    SONiC runs as a bring-your-own image. Add the community SONiC VS image in the NetPilot app under Images. From then on the assistant can deploy SONiC nodes in any lab on your VM.

  2. 2

    Ask for the fabric in plain words

    Two leaves, one spine, the AS numbers, the loopbacks, one host per leaf. The assistant designs the topology, writes the config for each node and deploys the lab with containerlab.

  3. 3

    Check the underlay

    The leaves must reach each other's loopback before any overlay exists. On a leaf, show ip bgp summary shows the spine session Established, and show ip route shows the other leaf's loopback learned over it.

  4. 4

    Check the EVPN session

    BGP on SONiC is FRR, so the EVPN address family is read through vtysh. show bgp l2vpn evpn summary on each leaf shows the EVPN neighbour Established and a prefix count once the VNIs are advertised.

  5. 5

    Map the VLAN to a VNI

    This is the step that teaches the SONiC way of doing things: config vlan add, config vlan member add, config vxlan add for the VTEP with the loopback as source, config vxlan evpn_nvo add to bind the VTEP to EVPN, and config vxlan map add for the VLAN to VNI mapping. show vxlan vlanvnimap and vtysh -c "show evpn vni" confirm it.

  6. 6

    Send traffic and read the routes

    Ping from the host on leaf1 to the host on leaf2. show vxlan tunnel now lists the remote VTEP, show vxlan remotemac all lists the remote host's MAC learned over EVPN, and vtysh -c "show bgp l2vpn evpn route type macip" shows the type-2 route that carried it.

  7. 7

    Save it the SONiC way

    config save -y writes the running state to /etc/sonic/config_db.json. show runningconfiguration all prints the same JSON, which is what you read when something does not come back after a reload.

Say this to the assistant

Build two SONiC leaves and one SONiC spine. eBGP underlay on point-to-point links, spine AS 65000, leaf1 AS 65001, leaf2 AS 65002, loopbacks 10.1.1.1 and 10.1.1.2 on the leaves. BGP EVPN overlay between the leaves through the spine. On each leaf create VLAN 100, map it to VNI 10100 and attach one Linux host in VLAN 100. After each step run the verification command and show me the output.

The VLAN to VNI step on SONiC

These are the SONiC CLI lines for step five on leaf1, with 10.1.1.1 as the VTEP source and Ethernet4 as the host port. Each config command writes to the running config database, and config save writes it to config_db.json. The assistant runs them for you and reads the result, and you can type them yourself on the device over SSH.

leaf1
admin@leaf1:~$ sudo config vlan add 100
admin@leaf1:~$ sudo config vlan member add -u 100 Ethernet4
admin@leaf1:~$ sudo config vxlan add vtep1 10.1.1.1
admin@leaf1:~$ sudo config vxlan evpn_nvo add nvo1 vtep1
admin@leaf1:~$ sudo config vxlan map add vtep1 100 10100
admin@leaf1:~$ sudo config save -y

What the output looks like

The EVPN session through vtysh, then the three vxlan show commands after the hosts have exchanged traffic. The remote VTEP in show vxlan tunnel and the remote MAC in show vxlan remotemac all are the two lines that say the overlay is carrying the host's reachability.

leaf1: EVPN session
admin@leaf1:~$ vtysh -c "show bgp l2vpn evpn summary"
BGP router identifier 10.1.1.1, local AS number 65001 vrf-id 0
Neighbor        V    AS MsgRcvd MsgSent   TblVer  InQ OutQ  Up/Down State/PfxRcd   PfxSnt
10.0.1.0        4 65000     132     128        0    0    0 00:58:12            3        3
leaf1: VXLAN state
admin@leaf1:~$ show vxlan vlanvnimap
+---------+-------+
| VLAN    |   VNI |
+=========+=======+
| Vlan100 | 10100 |
+---------+-------+
Total count : 1

admin@leaf1:~$ show vxlan tunnel
vxlan tunnel name    source ip    destination ip    tunnel map name    tunnel map mapping(vni -> vlan)
-------------------  -----------  ----------------  -----------------  ---------------------------------
vtep1                10.1.1.1     10.1.1.2          map_10100_Vlan100  10100 -> Vlan100

admin@leaf1:~$ show vxlan remotemac all
+---------+-------------------+--------------+-------+---------+
| VLAN    | MAC               | RemoteVTEP   |   VNI | Type    |
+=========+===================+==============+=======+=========+
| Vlan100 | aa:c1:ab:12:34:02 | 10.1.1.2     | 10100 | dynamic |
+---------+-------------------+--------------+-------+---------+
Total count : 1

What you need

  • A NetPilot account on Pro, Max, Team or Signature, including a Team seat or a Signature seat in an organization. On Free or Plus you can connect and sign in, and each tool answers with a note that the feature is included from Pro.
  • NetPilot connected in your assistant: ChatGPT, Claude.ai, Claude Code or Meta Muse. The lab VM is created the first time you ask the assistant to start it.
  • The community SONiC VS image, added once in the NetPilot app under Images (bring-your-own-image, BYOI). Nokia SR Linux and FRR are built in and run the same EVPN lab if you want to start before adding SONiC.

Run it from the chat you already have open

  1. 1Connect NetPilot in ChatGPT, Claude or Meta Muse: how to connect, step by step.
  2. 2A NetPilot account on Pro, Max, Team or Signature, including a Team seat or a Signature seat in an organization. On Free or Plus you can connect and sign in, and each tool answers with a note that the feature is included from Pro. Plans and lab credits.

Common questions

Build the smallest fabric that exercises every part: two SONiC leaves, one spine, an eBGP underlay, a BGP EVPN overlay, one VLAN mapped to a VNI and a host on each leaf. Then run the verification command after every step, show ip bgp summary for the underlay, show bgp l2vpn evpn summary through vtysh for the overlay, show vxlan vlanvnimap and show vxlan tunnel for the data plane, and read what changed. With NetPilot connected in ChatGPT, Claude or Meta Muse, you add the community SONiC image once in the NetPilot app, ask for the fabric in plain words, and the assistant builds it on your lab VM and runs each command for you.
Underlay: show ip bgp summary (spine session Established) and show ip route (the remote loopback present). Overlay: vtysh -c "show bgp l2vpn evpn summary" (EVPN neighbour Established with a prefix count) and vtysh -c "show evpn vni" (the VNI listed with its VLAN). Data plane: show vxlan vlanvnimap (the VLAN to VNI mapping), show vxlan tunnel (the remote VTEP as a tunnel destination) and show vxlan remotemac all (the remote host MAC learned over EVPN). A ping between the hosts that succeeds while show vxlan remotemac all is populated is the end-to-end proof.
SONiC runs as a bring-your-own image (BYOI): you add the community SONiC VS image once in the NetPilot app, under Images, and the assistant deploys it from then on. Nokia SR Linux and FRR are built in, and both speak BGP EVPN, so a first EVPN lab can run on them before you add SONiC. Arista cEOS, Juniper cRPD and Cisco images are BYOI too, which is how a mixed fabric with a SONiC leaf next to an Arista or Cisco leaf is built.

Build the fabric from the chat you already have open

Create a NetPilot account, pick Pro or above, add the SONiC image, and connect NetPilot in ChatGPT, Claude or Meta Muse.