Concept Guide

DellEMC#show cam mac stack-unit 1 port-set 0
VlanId Mac Address Region Interface
500 14:18:77:0a:53:82 STATIC Po 1
500 ff:ff:ff:ff:ff:ff STATIC 00001
28674 00:00:00:cc:00:00 DYNAMIC 0x80000001(vxlan)
28674 00:00:bb:00:00:00 DYNAMIC 0x80000006(vxlan)
0 ff:ff:ff:ff:ff:ff STATIC 00001
1 00:01:e8:8b:7a:6e DYNAMIC Po 11
20 00:00:00:cc:00:00 STATIC Po 1
0 00:10:18:ff:ff:ff STATIC Invalid
500 34:17:eb:37:11:02 DYNAMIC Po 1
0 f4:8e:38:2b:3e:87 LOCAL_DA 00001
0 f4:8e:38:2b:3e:87 LOCAL_DA 00001
0 14:18:77:0a:53:82 LOCAL_DA 00001
Conguring and Controlling VXLAN from the NSX Controller
GUI
You can congure and control VXLAN from the NSX controller GUI, by adding a hardware device to NSX and authenticating the device.
1 Generate a certicate in your system and add it to the NSX before adding a hardware device for authentication.
To generate a certicate, use the following command:
crypto cert generate self-signed cert-file flash://vtep-cert.pem key-file flash://vtep-
privkey.pem
To view the certicate, use the following command:
show file flash://vtep-cert.pem
The output appears similar to the following example:
-----BEGIN CERTIFICATE-----
MIID3jCCAsagAwIBAgIBATANBgkqhkiG9w0BAQUFADCBmTELMAkGA1UEBhMCVVMxFTATBgNVBAMMDHd3dy5kZWxsLmNvb
TENMAsGA1UECgwERGVsbDEYMBYGA1UECwwPRGVsbCBOZXR3b3JraW5nMREwDwYDVQQHDAhTQU4gSm9zZTETMBEGA1UECA
wKQ2FsaWZvcm5pYTEiMCAGCSqGSIb3DQEJARYTc29tZW9uZUBleGFtcGxlLmNvbTAeFw0xNTExMjAwMzA0NTNaFw0yNTE
xMTcwMzA0NTNaMIGZMQswCQYDVQQGEwJVUzEVMBMGA1UEAwwMd3d3LmRlbGwuY29tMQ0wCwYDVQQKDAREZWxsMRgwFgYD
VQQLDA9EZWxsIE5ldHdvcmtpbmcxETAPBgNVBAcMCFNBTiBKb3NlMRMwEQYDVQQIDApDYWxpZm9ybmlhMSIwIAYJKoZIh
vcNAQkBFhNzb21lb25lQGV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqGaGq3Cv4/
RpuoiuePrnayORRhzEW/H2Ypv8OKEcew1gySmFz24LQttzSHo4AO+qF3LkILvFW2RaHZ1mxbmm95d3PnZ8fXg2wgPz+
+T6coHGYH0o0+LkHVBb3IIXd/CSp+TBRzAwWMPS7tnaRv1UqiJtm6/RjcJghbf6zcQWUcg2CTtKe5ej/
rS2tIU9EBGCzL3xs6DRB3lvScgmuckc5L18qWqNHRWMdKFgKwHKUOOvHakPFs9RNJNy5Sxwfe/kgkVmqA/
KWiRIecLIgmgYjKu2E0uC3URpuydoN7UwPSeigXWeR3JyhzfFVEr5LtyXVpo9zS2JGyygKtzZBpke1wIDAQABoy8wLTAM
BgNVHRMEBTADAQH/MB0GA1UdDgQWBBTaOaPuXmtLDTJVv++VYBiQr9gHCTANBgkqhkiG9w0BAQUFAAOCAQEAn5E/
w3BLQrX3e3Jv3EUFftGV0NABXOQxb/ODH4doA/68nQcvW7GZgpwoxe77YQH+C/uBNFwSBFxsu9ZkXhKu2q8wrCd
+cnuaNu7Kq2V0DGSdR7eIkDTHkflttHbMmRfStHLetk3bA0HgXTW5c+vFn79EX/nJqxIvkl5ADT7k5JZR
+j6i9eskgUlvBuV5OOZKzh29Gy4sjXvdYL5GirZFon8iZNY5FON
+WlpcLJ9GjMvVfwvJx7exVs9cqXvm6UZ4Bf262STKbm+Q4qz30tyjDdF1xDBcBjL83UcEvSW65V/
sSFKBohqu40EWXIBJ0QbKvFWv91rbjkgtsrHVTdohrA==
-----END CERTIFICATE-----
Copy and paste the generated certicate to the NSX.
NOTE
: Once controller connectivity is established from VLT peers, if you want to generate a new certicate and use it
for controller connection, generate the certicate from the node (node that is directly connected to controller). If you
do not generate a new certicate from the node, system shows inconsistent behavior.
2 Create a VXLAN Gateway.
To create service node, the required elds are the IP address and SSL certicate of the server. The Service node is responsible for
broadcast/unknown unicast/multicast trac replication. The following is the snapshot of the user interface for the creation of service
node:
Virtual Extensible LAN (VXLAN)
1173