Automatic routed underlay
Instead of hand-configuring routing on every node, you define a fabric — a logical layer that sets up the routing protocol on chosen interfaces and provides L3 connectivity between cluster nodes. On that routed base you then run Ceph traffic or an EVPN/VXLAN overlay.
The fabric routing protocols — OpenFabric, OSPF and BGP — use FRR. Install the frr and frr-pythontools packages. A WireGuard fabric is a tunnel, not an FRR protocol, and needs the wireguard-tools package.
Four protocols to choose from
In Proxmox VE 9.0 a fabric runs on one of two routing protocols from the FRR suite. Version 9.2 adds two more fabric types — BGP (also from FRR) and WireGuard (an encrypted tunnel rather than a routing protocol):
- OpenFabric — a modern, easy-to-maintain link-state protocol; the router-ID can be an IPv4 or IPv6 address.
- OSPF — the classic, widely known protocol; router-ID as an IPv4 address (dotted notation).
- BGP (from PVE 9.2) — eBGP unnumbered, a unique ASN per node, peering over physical interfaces without assigning IP addresses on the fabric links. The session comes up on automatic IPv6 link-local addresses.
- WireGuard (from PVE 9.2) — encrypted tunnels between nodes; private keys for Proxmox node interfaces are generated automatically. Non-Proxmox peers can join the fabric too (external nodes, for which you enter their public key and endpoint). It does not route dynamically by itself (it only creates routes to the peers' allowed IPs) — combine it with OSPF or BGP (details: WireGuard and BGP in SDN).
Each node in a fabric needs a unique router-ID (e.g. 192.0.2.1) — its identity in the routing domain.
A fabric step by step
You set it all up from the UI — no hand-editing FRR files:
| Step | Where / what |
|---|---|
| Create a fabric | Datacenter → SDN → Fabrics → "Add Fabric", pick the protocol |
| Add nodes | use the "+" button to select nodes and the interfaces linking them |
| Router-ID | give each node a unique router-ID |
| Apply | SDN → Apply — the routing config rolls out across the cluster |
Full-mesh for Ceph and EVPN
- Full-mesh for Ceph — connect nodes directly (no dedicated switch) and let the fabric handle routing. During Ceph setup you pick the fabric network from the list of available networks.
- Underlay for EVPN/VXLAN — the fabric is the routed base on which the EVPN controller builds the overlay for guests.
Meshing 3 nodes over a fabric gives a cheap, fast Ceph backend without an expensive 100GbE switch in the middle — a popular choice when consolidating after a VMware migration.
We'll design the SDN network in your cluster
We'll plan the fabric (OpenFabric, OSPF, BGP or WireGuard), a full-mesh for Ceph and an EVPN/VXLAN overlay — cleanly and with performance in mind after a VMware migration.
⚡ Free consultation → WireGuard & BGP in SDN