The Tier-0 gateway in the NSX-T Edge cluster provides a gateway service between the logical and physical network in VMware Cloud Foundation. The NSX-T Edge cluster can back multiple Tier-0 gateways.
Procedure
- In a Web browser, log in to the user interface of NSX-T Manager.
Setting Value URL https://sfo01wnsx01.sfo01.rainpole.local User name admin Password nsx_admin_password - On the main navigation bar, click Networking.
- In the navigation pane, click Tier-0 gateways.
- Create the Tier-0 gateway.
- On the Tier-0 gateways page, click Add Tier-0 gateway.
- Configure the settings and click Save.
Setting Value Name sfo01-w-tier0-01 High Availability Mode Active-Active Edge Cluster sfo-w-edge-cluster01
- Configure route re-distribution.
- Expand Route Re-Distribution and click Set.
- On the Set route re-distribution dialog box, select all Tier-0 subnets and Advertised Tier-1 subnet sources, and click Apply.
- On the Add Tier-0 gateway page, in the Route re-distribution section, click Save.
- Add the uplink interfaces to the NSX-T Edge nodes.
- Expand Interfaces and click Set.
- In the Set interfaces dialog box, click Add interface, configure the settings, and click Save.
Name Type IP Address / Mask Connected to (Segment) Edge Node MTU sfo01wesg01-Uplink01 External 172.16.47.2/24 sfo01-w-uplink01 sfo01wesg01 9000 sfo01wesg01-Uplink02
External 172.16.48.2/24 sfo01-w-uplink02 sfo01wesg01 9000 sfo01wesg02-Uplink01 External 172.16.47.3/24 sfo01-w-uplink01 sfo01wesg02 9000 sfo01wesg02-Uplink02 External 172.16.48.3/24 sfo01-w-uplink02 sfo01wesg02 9000 sfo02wesg01-Uplink01 External 172.16.67.2/24 sfo02-w-uplink01 sfo02wesg01 9000 sfo02wesg01-Uplink02 External 172.16.68.2/24 sfo02-w-uplink02 sfo02wesg01 9000 sfo02wesg02-Uplink01 External 172.16.67.3/24 sfo02-w-uplink01 sfo02wesg02 9000 sfo02wesg02-Uplink02 External 172.16.68.3/24 sfo02-w-uplink02 sfo02wesg02 9000 - Repeat this step for the remaining interfaces and click Close.
- On the Add Tier-0 gateway page, in the Interfaces section, click Close.
- Create an IP prefix list.
- Expand Routing.
- In the IP prefix list section, click Set.
- In the Set IP prefix list dialog box, click Add IP prefix list.
- Enter Any-Prefix as the Name and click Set.
- In the Set prefixes dialog box, click Add Prefix, configure the settings, click Add and click Apply.
Setting Value Network any Action Permit - In the Set IP prefix list dialog box, click Save and click Close.
- Create a route map.
- Expand Routing.
- In the Route maps section, click Set.
- In the Set route maps dialog box, click Add route map.
- Enter az2-route-map for Name.
- In the Match criteria column, click Set.
- On the Set match criteria dialog box, click Add match criteria, configure the settings, click Add and click Apply.
Setting Value Type IP Prefix Members Any-Prefix AS path prepend 65000 Action Permit - In the Set route maps dialog box, click Save and click Close.
- Configure BGP.
- Expand BGP, configure the settings, and click Save.
Setting Value Local AS 65000 BGP On Graceful Restart Disable Graceful Restart Timer 180 Graceful Restart Stale Timer 600 Inter SR iBGP On ECMP On Multipath Relax On - Click Set for BGP neighbors.
- In the Set BGP neighbors dialog box, click Add BGP neighbor, configure the settings for the first neighbour, and click Save.
IP Address BFD Remote AS Hold Down Time Keep Alive Time Password Out Filter In Filter 172.16.47.1 Disabled 65001 12 4 bgp_password - - 172.16.48.1 Disabled 65001 12 4 bgp_password - - 172.16.67.1 Disabled 65002 12 4 bgp_password az2-route-map az2-route-map 172.16.68.1 Disabled 65002 12 4 bgp_password az2-route-map az2-route-map Note: Enable BFD if the network supports and is configured for BFD. - Repeat for the other neighbor, click Save and click Close.
- On the Add Tier-0 gateway page, in the BGP section, click Close editing.
- Expand BGP, configure the settings, and click Save.
- Generate a BGP summary for the Tier-0 gateway.
- On the main navigation bar, click Advanced networking & security.
- In the navigation pane, click Routers and select sfo-w-tier0-01.
- From the Actions drop-down menu, select Generate BGP summary.
- Verify that each transport node has five established connections: one to each neighbor in its availability zone and one to each of the other three transport nodes.