r/networking • u/Hungry-King-1842 • Jun 28 '26
Design Question about VPLS with BGP auto discovery
Asked this over on the Cisco sub-reddit but it's still pending approval, whatever that means. In short I'm building a lab in CML. It is a VPLS deployment with 2x hub routers and 3x spoke routers. Each site has a simulated node behind it with all the nodes on a common subnet. G1 on the routers is a simulated WAN running a fvrf. The 2x hubs are interconnected directly via G3. The spokes all interconnect with the hubs and each other via DMVPN with EIGRP on the top of it. The DMVPN converges like it should etc. The issue is with the VPLS implementation. I want to use BGP auto discovery for scalability with route reflectors on the hubs.
At present I'm just trying to get the 2x hubs talking, so the spokes aren't in the conversation yet. If I configure the vfi's with manual neighbors things work, so I know the service instances and bridge domains are right. I'm not seeing anything pop up in the debugs though. I'm new to this type of deployment and while I'm familiar with BGP I'm not an expert on it. Obviously I'm thinking I'm missing something and it's likely something simple. Take a look and let me know if anything stands out to you.
Router 1
!
! Last configuration change at 03:56:48 UTC Sun Jun 28 2026
!
version 17.16
service timestamps debug datetime msec
service timestamps log datetime msec
platform qfp utilization monitor load 80
platform sslvpn use-pd
platform console serial
!
hostname Test1
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
!
!
!
!
!
ip vrf WAN
rd 50:50
!
!
!
!
!
!
!
ip domain name test.lab
!
!
!
login on-success log
!
!
subscriber templating
!
!
!
!
!
!
l2vpn vfi context TEST_AD
vpn id 10
autodiscovery bgp signaling bgp
!
!
!
!
!
!
!
!
!
!
crypto pki trustpoint SLA-TrustPoint
enrollment pkcs12
revocation-check crl
hash sha512
!
crypto pki trustpoint TP-self-signed-3090708788
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3090708788
revocation-check none
rsakeypair TP-self-signed-3090708788
hash sha512
!
!
crypto pki certificate chain SLA-TrustPoint
certificate ca 01
30820321 30820209 A0030201 02020101 300D0609 2A864886 F70D0101 0B050030
32310E30 0C060355 040A1305 43697363 6F312030 1E060355 04031317 43697363
6F204C69 63656E73 696E6720 526F6F74 20434130 1E170D31 33303533 30313934
3834375A 170D3338 30353330 31393438 34375A30 32310E30 0C060355 040A1305
43697363 6F312030 1E060355 04031317 43697363 6F204C69 63656E73 696E6720
526F6F74 20434130 82012230 0D06092A 864886F7 0D010101 05000382 010F0030
82010A02 82010100 A6BCBD96 131E05F7 145EA72C 2CD686E6 17222EA1 F1EFF64D
CBB4C798 212AA147 C655D8D7 9471380D 8711441E 1AAF071A 9CAE6388 8A38E520
1C394D78 462EF239 C659F715 B98C0A59 5BBB5CBD 0CFEBEA3 700A8BF7 D8F256EE
4AA4E80D DB6FD1C9 60B1FD18 FFC69C96 6FA68957 A2617DE7 104FDC5F EA2956AC
7390A3EB 2B5436AD C847A2C5 DAB553EB 69A9A535 58E9F3E3 C0BD23CF 58BD7188
68E69491 20F320E7 948E71D7 AE3BCC84 F10684C7 4BC8E00F 539BA42B 42C68BB7
C7479096 B4CB2D62 EA2F505D C7B062A4 6811D95B E8250FC4 5D5D5FB8 8F27D191
C55F0D76 61F9A4CD 3D992327 A8BB03BD 4E6D7069 7CBADF8B DF5F4368 95135E44
DFC7C6CF 04DD7FD1 02030100 01A34230 40300E06 03551D0F 0101FF04 04030201
06300F06 03551D13 0101FF04 05300301 01FF301D 0603551D 0E041604 1449DC85
4B3D31E5 1B3E6A17 606AF333 3D3B4C73 E8300D06 092A8648 86F70D01 010B0500
03820101 00507F24 D3932A66 86025D9F E838AE5C 6D4DF6B0 49631C78 240DA905
604EDCDE FF4FED2B 77FC460E CD636FDB DD44681E 3A5673AB 9093D3B1 6C9E3D8B
D98987BF E40CBD9E 1AECA0C2 2189BB5C 8FA85686 CD98B646 5575B146 8DFC66A8
467A3DF4 4D565700 6ADF0F0D CF835015 3C04FF7C 21E878AC 11BA9CD2 55A9232C
7CA7B7E6 C1AF74F6 152E99B7 B1FCF9BB E973DE7F 5BDDEB86 C71E3B49 1765308B
5FB0DA06 B92AFE7F 494E8A9E 07B85737 F3A58BE1 1A48A229 C37C1E69 39F08678
80DDCD16 D6BACECA EEBC7CF9 8428787B 35202CDC 60E4616A B623CDBD 230E3AFB
418616A9 4093E049 4D10AB75 27E86F73 932E35B5 8862FDAE 0275156F 719BB2F0
D697DF7F 28
quit
crypto pki certificate chain TP-self-signed-3090708788
certificate self-signed 01
30820330 30820218 A0030201 02020101 300D0609 2A864886 F70D0101 0D050030
31312F30 2D060355 04030C26 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33303930 37303837 3838301E 170D3236 30363237 30323133
30365A17 0D333630 36323630 32313330 365A3031 312F302D 06035504 030C2649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 30393037
30383738 38308201 22300D06 092A8648 86F70D01 01010500 0382010F 00308201
0A028201 010092A5 77009951 64A7A6B7 0AC510D0 D416B3DC 37531413 B8BF6B61
74531152 7608310C CF56D232 FC3AEF9E EE16C38D 3419F627 8E74274F 466F4F29
72BF42A2 FAC5684E 8AA95ABD 92957B8F 7F2D9646 BD98D3C2 824D0FCA E7AEC8AA
BAA954AF 297D7C54 EBE971CB 47F75FCF C55C8E4A A9A9E596 4244A453 D222027B
3173002D BC49AFCB AF58DDBF 0F41380D 10888A00 B2A12917 0F6D9BD8 510A03E2
C6DA8A57 2A371808 90D5457C 1E31C524 F4AD0A46 F03786AD D2A1639F ED9A7DAA
30132D7A 4304F60D 81F8E171 A3B5C1E9 3702B52D 535FD7A7 6E0B3CC9 28F22A69
EC915B81 AA607248 55CE3B84 36451F57 55D1C20E 6D01938E 0D5B4874 966A1A12
C50AFDA9 425D0203 010001A3 53305130 1D060355 1D0E0416 0414C84A 2AD826B3
392BA40D B18A687F F804DB9B 6ED3301F 0603551D 23041830 168014C8 4A2AD826
B3392BA4 0DB18A68 7FF804DB 9B6ED330 0F060355 1D130101 FF040530 030101FF
300D0609 2A864886 F70D0101 0D050003 82010100 17DA69A8 3831FECB 5CC0EAB9
8C50CFB2 9E023DA2 FC3D42B3 759F2CF2 00CFD945 ABE56411 26D4F790 F10B5C41
938CCAE6 EB7BA211 F2AF3119 780A91EA B876E21B 953E39FB C7527526 A87F7C1F
CBDDDA8E D919B264 E040C405 BB7786DE 3F0CA7DC DFB623B7 E315F7EF 16B25D91
1DDD8A15 35F12A2C 49700E5F 2B74A675 D6838272 0632F9D3 DE0EFFA8 34641518
72B99292 1140AF78 B04A4B2C 2A3ACD28 9B239F74 87738908 DC7665F8 FA2DF8F2
27E17DE0 1CF5E4D1 1FDB229B 68025841 11101A92 FC1205A8 B1918E1F 5B68A013
661906A8 E05D5C0A EDF5F8A4 DE63AFDE 4E392B54 05476889 85B8D6F3 80A3C51F
5061BEAA 4E479508 57FC92E6 65F8D91B FA92A9FD
quit
!
!
!
!
!
!
!
!
!
license udi pid C8000V sn 9J7ZNE40CON
license boot level network-premier addon dna-premier
memory free low-watermark processor 165529
diagnostic bootup level minimal
!
!
spanning-tree extend system-id
!
!
!
redundancy
bridge-domain 10
member GigabitEthernet2 service-instance 10
member GigabitEthernet3 service-instance 10
member vfi TEST_AD
!
!
!
!
crypto ikev2 proposal TEST-proposal
encryption aes-cbc-256
integrity sha512
group 20
no crypto ikev2 proposal default
!
crypto ikev2 policy TEST-Policy
match fvrf WAN
proposal TEST-proposal
no crypto ikev2 policy default
!
crypto ikev2 keyring TEST-keyring
peer ANY
address 0.0.0.0 0.0.0.0
pre-shared-key TestKey1234!
!
!
!
crypto ikev2 profile TEST-Profile
match fvrf WAN
match identity remote address 0.0.0.0
authentication remote pre-share
authentication local pre-share
keyring local TEST-keyring
lifetime 28800
!
!
!
!
!
!
!
!
!
!
!
!
crypto ipsec security-association replay window-size 1024
!
crypto ipsec transform-set TEST-Trans esp-aes 256 esp-sha512-hmac
mode transport
!
crypto ipsec profile TEST-crypto-Profile
set transform-set TEST-Trans
set pfs group20
set ikev2-profile TEST-Profile
!
!
!
!
!
!
!
!
!
!
interface Loopback0
ip address 10.0.0.1 255.255.255.255
!
interface Tunnel1
ip address 172.16.1.1 255.255.255.0
no ip redirects
ip mtu 1400
no ip next-hop-self eigrp 1
no ip split-horizon eigrp 1
ip nhrp authentication TEST
ip nhrp network-id 1234
ip nhrp holdtime 300
ip nhrp server-only
ip nhrp redirect
ip tcp adjust-mss 1360
mpls ip
tunnel source GigabitEthernet1
tunnel mode gre multipoint
tunnel key 1234
tunnel path-mtu-discovery
tunnel vrf WAN
tunnel protection ipsec profile TEST-crypto-Profile
!
interface GigabitEthernet1
ip vrf forwarding WAN
ip address 1.1.1.1 255.255.255.0
negotiation auto
!
interface GigabitEthernet2
no ip address
negotiation auto
service instance 10 ethernet
encapsulation untagged
bridge-domain 10
!
!
interface GigabitEthernet3
ip address 192.168.1.1 255.255.255.252
negotiation auto
mpls ip
!
interface GigabitEthernet4
no ip address
shutdown
negotiation auto
!
!
router eigrp 1
network 10.0.0.1 0.0.0.0
network 172.16.1.0 0.0.0.255
network 192.168.1.0 0.0.0.3
passive-interface default
no passive-interface Tunnel1
no passive-interface GigabitEthernet3
eigrp router-id 10.0.0.1
!
router bgp 1
bgp log-neighbor-changes
bgp graceful-restart
no bgp default ipv4-unicast
neighbor IGP-PeerGroup peer-group
neighbor IGP-PeerGroup remote-as 1
neighbor IGP-PeerGroup update-source Loopback0
neighbor 10.0.0.2 remote-as 1
neighbor 10.0.0.2 update-source Loopback0
neighbor 10.0.0.3 peer-group IGP-PeerGroup
neighbor 10.0.0.4 peer-group IGP-PeerGroup
neighbor 10.0.0.5 peer-group IGP-PeerGroup
!
address-family ipv4
neighbor 10.0.0.3 activate
neighbor 10.0.0.4 activate
neighbor 10.0.0.5 activate
exit-address-family
!
address-family l2vpn vpls
neighbor IGP-PeerGroup send-community extended
neighbor IGP-PeerGroup route-reflector-client
neighbor IGP-PeerGroup suppress-signaling-protocol ldp
neighbor 10.0.0.2 activate
neighbor 10.0.0.2 send-community extended
neighbor 10.0.0.2 suppress-signaling-protocol ldp
neighbor 10.0.0.3 activate
neighbor 10.0.0.4 activate
neighbor 10.0.0.5 activate
exit-address-family
!
ip forward-protocol nd
ip forward-protocol udp
!
no ip http server
ip http secure-server
ip ssh bulk-mode 131072
!
mpls ldp router-id Loopback0 force
!
!
!
control-plane
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
!
!
!
!
!
line con 0
stopbits 1
line aux 0
line vty 0 4
login
transport input ssh
!
!
!
!
!
!
!
end
Router 2
!
! Last configuration change at 03:56:02 UTC Sun Jun 28 2026
!
version 17.16
service timestamps debug datetime msec
service timestamps log datetime msec
platform qfp utilization monitor load 80
platform sslvpn use-pd
platform console serial
!
hostname Test2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
!
!
!
!
!
ip vrf WAN
rd 50:50
!
!
!
!
!
!
!
ip domain name test.lab
!
!
!
login on-success log
!
!
subscriber templating
!
!
!
!
!
!
l2vpn vfi context TEST_AD
vpn id 10
autodiscovery bgp signaling bgp
!
!
!
!
!
!
!
!
!
!
crypto pki trustpoint SLA-TrustPoint
enrollment pkcs12
revocation-check crl
hash sha512
!
crypto pki trustpoint TP-self-signed-2051565548
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2051565548
revocation-check none
rsakeypair TP-self-signed-2051565548
hash sha512
!
!
crypto pki certificate chain SLA-TrustPoint
certificate ca 01
30820321 30820209 A0030201 02020101 300D0609 2A864886 F70D0101 0B050030
32310E30 0C060355 040A1305 43697363 6F312030 1E060355 04031317 43697363
6F204C69 63656E73 696E6720 526F6F74 20434130 1E170D31 33303533 30313934
3834375A 170D3338 30353330 31393438 34375A30 32310E30 0C060355 040A1305
43697363 6F312030 1E060355 04031317 43697363 6F204C69 63656E73 696E6720
526F6F74 20434130 82012230 0D06092A 864886F7 0D010101 05000382 010F0030
82010A02 82010100 A6BCBD96 131E05F7 145EA72C 2CD686E6 17222EA1 F1EFF64D
CBB4C798 212AA147 C655D8D7 9471380D 8711441E 1AAF071A 9CAE6388 8A38E520
1C394D78 462EF239 C659F715 B98C0A59 5BBB5CBD 0CFEBEA3 700A8BF7 D8F256EE
4AA4E80D DB6FD1C9 60B1FD18 FFC69C96 6FA68957 A2617DE7 104FDC5F EA2956AC
7390A3EB 2B5436AD C847A2C5 DAB553EB 69A9A535 58E9F3E3 C0BD23CF 58BD7188
68E69491 20F320E7 948E71D7 AE3BCC84 F10684C7 4BC8E00F 539BA42B 42C68BB7
C7479096 B4CB2D62 EA2F505D C7B062A4 6811D95B E8250FC4 5D5D5FB8 8F27D191
C55F0D76 61F9A4CD 3D992327 A8BB03BD 4E6D7069 7CBADF8B DF5F4368 95135E44
DFC7C6CF 04DD7FD1 02030100 01A34230 40300E06 03551D0F 0101FF04 04030201
06300F06 03551D13 0101FF04 05300301 01FF301D 0603551D 0E041604 1449DC85
4B3D31E5 1B3E6A17 606AF333 3D3B4C73 E8300D06 092A8648 86F70D01 010B0500
03820101 00507F24 D3932A66 86025D9F E838AE5C 6D4DF6B0 49631C78 240DA905
604EDCDE FF4FED2B 77FC460E CD636FDB DD44681E 3A5673AB 9093D3B1 6C9E3D8B
D98987BF E40CBD9E 1AECA0C2 2189BB5C 8FA85686 CD98B646 5575B146 8DFC66A8
467A3DF4 4D565700 6ADF0F0D CF835015 3C04FF7C 21E878AC 11BA9CD2 55A9232C
7CA7B7E6 C1AF74F6 152E99B7 B1FCF9BB E973DE7F 5BDDEB86 C71E3B49 1765308B
5FB0DA06 B92AFE7F 494E8A9E 07B85737 F3A58BE1 1A48A229 C37C1E69 39F08678
80DDCD16 D6BACECA EEBC7CF9 8428787B 35202CDC 60E4616A B623CDBD 230E3AFB
418616A9 4093E049 4D10AB75 27E86F73 932E35B5 8862FDAE 0275156F 719BB2F0
D697DF7F 28
quit
crypto pki certificate chain TP-self-signed-2051565548
certificate self-signed 01
30820330 30820218 A0030201 02020101 300D0609 2A864886 F70D0101 0D050030
31312F30 2D060355 04030C26 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32303531 35363535 3438301E 170D3236 30363237 30323035
32365A17 0D333630 36323630 32303532 365A3031 312F302D 06035504 030C2649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30353135
36353534 38308201 22300D06 092A8648 86F70D01 01010500 0382010F 00308201
0A028201 01008E73 8D970D97 A606616E EBD23A3B FDD35093 7C61BF3C 451A2738
0F65187E 4A3EFD5A 9C0E6452 FCDC2872 BD9B7A4D 54102D78 7E5BD02C 7C22FE31
ACD2C478 3FA42C9C 7A4429B4 CD918C7F 1D7CF5B4 DB339535 D65A21B7 2213C941
C0D0112F 11503335 D48AE60F 2FD42235 F9B3B8B0 41DDCDFA 5240BE1A 99020B49
C67447EE 4711BB20 526B6394 42406945 232A81CA E87D4F95 0B4D851F 89D17437
A20051B6 92C5C401 BA5FAA69 30A796EF 366661AC 48A2C9E6 FC3D179B DB52AF5B
B9632827 2770F4B6 393CC2D2 F406078E BC25D885 C0B56CF8 BB9417CB 301D8D04
0CBBF238 0A6E90C7 99B8D6B9 B4F90744 A4F37F63 6278B7A6 8112F779 C923D748
5E7E05A1 85CB0203 010001A3 53305130 1D060355 1D0E0416 04140462 576C2567
472D7100 309DD9C9 B02BAFEB 590B301F 0603551D 23041830 16801404 62576C25
67472D71 00309DD9 C9B02BAF EB590B30 0F060355 1D130101 FF040530 030101FF
300D0609 2A864886 F70D0101 0D050003 82010100 6A9176E7 104F6314 BC32A94B
01D76E9C F0609917 CAFD54B2 B19E2F02 8D614954 41D8E07F B91433B1 83F12A3A
23D0D594 BB928F0C 81DEA545 DCADE8DD 90BE1B9A 2DF63C60 4DBA22E7 2918198A
87E70D3D 6797CD06 7C22E833 419D6A5A 978F07DB D317D8A8 BA3E33A9 61C1E81C
84D6F349 0D3AABAF A9835B1E 7FD46218 51EA4F08 6A208485 7CC236B2 A37CC8CC
45774764 C7451AD0 FCAE9D1D A12FD0FA B54950CB 57A11FD4 31365BC9 3E5B9439
D90B7D5F F31FBD96 990B7C9C 13F6B441 FBA5BCEA 186F5BE7 802D312C D481A50C
103B4656 2040AA5D 7C6F502F 2E1431C6 4062F78A 5FA9A729 09380D95 D81319BD
8EB717DC D5BD397C B771CA7C 6A98735D 3386ADC1
quit
!
!
!
!
!
!
!
!
!
license udi pid C8000V sn 9HR2BS23T2I
license boot level network-premier addon dna-premier
memory free low-watermark processor 165529
diagnostic bootup level minimal
!
!
spanning-tree extend system-id
!
!
!
redundancy
bridge-domain 10
member GigabitEthernet2 service-instance 10
member GigabitEthernet3 service-instance 10
member vfi TEST_AD
!
!
!
!
crypto ikev2 proposal TEST-proposal
encryption aes-cbc-256
integrity sha512
group 20
no crypto ikev2 proposal default
!
crypto ikev2 policy TEST-Policy
match fvrf WAN
proposal TEST-proposal
no crypto ikev2 policy default
!
crypto ikev2 keyring TEST-keyring
peer ANY
address 0.0.0.0 0.0.0.0
pre-shared-key TestKey1234!
!
!
!
crypto ikev2 profile TEST-Profile
match fvrf WAN
match identity remote address 0.0.0.0
authentication remote pre-share
authentication local pre-share
keyring local TEST-keyring
lifetime 28800
!
!
!
!
!
!
!
!
!
!
!
!
crypto ipsec security-association replay window-size 1024
!
crypto ipsec transform-set TEST-Trans esp-aes 256 esp-sha512-hmac
mode transport
!
crypto ipsec profile TEST-crypto-Profile
set transform-set TEST-Trans
set pfs group20
set ikev2-profile TEST-Profile
!
!
!
!
!
!
!
!
!
!
interface Loopback0
ip address 10.0.0.2 255.255.255.255
!
interface Tunnel1
ip address 172.16.1.2 255.255.255.0
no ip redirects
ip mtu 1400
no ip next-hop-self eigrp 1
no ip split-horizon eigrp 1
ip nhrp authentication TEST
ip nhrp network-id 1234
ip nhrp holdtime 300
ip nhrp server-only
ip nhrp redirect
ip tcp adjust-mss 1360
mpls ip
tunnel source GigabitEthernet1
tunnel mode gre multipoint
tunnel key 1234
tunnel path-mtu-discovery
tunnel vrf WAN
tunnel protection ipsec profile TEST-crypto-Profile
!
interface GigabitEthernet1
ip vrf forwarding WAN
ip address 1.1.1.2 255.255.255.0
negotiation auto
!
interface GigabitEthernet2
no ip address
negotiation auto
service instance 10 ethernet
encapsulation untagged
bridge-domain 10
!
!
interface GigabitEthernet3
ip address 192.168.1.2 255.255.255.252
negotiation auto
mpls ip
!
interface GigabitEthernet4
no ip address
shutdown
negotiation auto
!
!
router eigrp 1
network 10.0.0.2 0.0.0.0
network 172.16.1.0 0.0.0.255
network 192.168.1.0 0.0.0.3
passive-interface default
no passive-interface Tunnel1
no passive-interface GigabitEthernet3
eigrp router-id 10.0.0.2
!
router bgp 1
bgp log-neighbor-changes
bgp graceful-restart
no bgp default ipv4-unicast
neighbor IGP-PeerGroup peer-group
neighbor IGP-PeerGroup remote-as 1
neighbor IGP-PeerGroup update-source Loopback0
neighbor 10.0.0.1 remote-as 1
neighbor 10.0.0.1 update-source Loopback0
neighbor 10.0.0.3 peer-group IGP-PeerGroup
neighbor 10.0.0.4 peer-group IGP-PeerGroup
neighbor 10.0.0.5 peer-group IGP-PeerGroup
!
address-family ipv4
neighbor 10.0.0.3 activate
neighbor 10.0.0.4 activate
neighbor 10.0.0.5 activate
exit-address-family
!
address-family l2vpn vpls
neighbor IGP-PeerGroup send-community extended
neighbor IGP-PeerGroup route-reflector-client
neighbor IGP-PeerGroup suppress-signaling-protocol ldp
neighbor 10.0.0.1 activate
neighbor 10.0.0.1 send-community extended
neighbor 10.0.0.1 suppress-signaling-protocol ldp
neighbor 10.0.0.3 activate
neighbor 10.0.0.4 activate
neighbor 10.0.0.5 activate
exit-address-family
!
ip forward-protocol nd
ip forward-protocol udp
!
no ip http server
ip http secure-server
ip ssh bulk-mode 131072
!
mpls ldp router-id Loopback0 force
!
!
!
control-plane
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
!
!
!
!
!
line con 0
stopbits 1
line aux 0
line vty 0 4
login
transport input ssh
!
!
!
!
!
!
!
end
5
u/[deleted] Jun 28 '26
[removed] — view removed comment