Nexus vPC | Routing over vPC

preview_player
Показать описание
Let me tell you a sad story...

Some time ago, I ran into a problem. I was in the data centre all night and nearly pulled my hair out in frustration. No matter what I tried, I couldn't get vPC to work with #OSPF or #EIGRP

Let me save you this pain, and show you the pitfall of routing over #vPC, and how to avoid it, using layer-3 peer-router

This video is particularly helpful to network engineers working with vPC in production.

Also useful for CCNP Data Center, and CCIE Data Center

Part 1: How vPC Works - vPC adds redundancy to the data centre, while avoiding the older technologies like spanning-tree. See how it fits into your solution, and parts under the hood

Part 2: vPC Configuration - Now you know how vPC works, you can start configuring. See how it's done by watching live config on real Nexus switches

Part 3: Routing over vPC - Be careful! There are pitfalls when running routing protocols over vPC! I fell into one of these myself. See how you can avoid this

Some platforms now support hitless vPC role changes.

300-180 DCIT
300-160 DCID
300-165 DCII
layer3 peer-router
Рекомендации по теме
Комментарии
Автор

I love your storytelling combining with the real-time troubleshooting approach, that's really helped me a lot to understand the whole situation on how to apply dedicated command regarding your scenario. Great video !!

xeifora
Автор

This issue is fundamentally caused by the fact that vPC makes two switches look like one device at layer 2 but NOT at layer 3.

kellymoses
Автор

Excellent video, it took me weeks of research to fully understand what you explained in minutes. I have a similar project where we were having issues with EIGRP, "layer3 peer-router" fixed it!

ibrennan
Автор

Really loved it
That is exactly what I've experienced last week after an upgrade to nxos 7.3.7 with eigrp
Lucky me, i remembered your video
Thanks

francescogalli
Автор

That is really good information on Routing Over VPC. Short, Simple and Amazing information. Thank you.

chetanpadshala
Автор

Thx a lot for sharing your issue, will keep note of this.

shawn_
Автор

Thanks 👍
You kept us waiting a while for this video 🙂

CiscoPhipse
Автор

Thank you for this video as it served as a sanity check. I’m having an issue where a port-channel has 2 links to an adjacent firewall and both sides are forming a BGP adjacency and the peering is stable. However, when both port-channel members are UP, there are packet drops seen when trying to reach a loop back interface on the firewall. If I disable the port-channel link going to VPC with secondary role, the traffic to the loopback stabilizes. I saw you have the command ip arp synchronize which I do not have. What does that command do beyond the obvious inference? Do you think this may help?

ElGuapoSalsero
Автор

heheh I like how it begins. "Oh, the horror!!! Routing and
:-D

rajpjunior
Автор

does this solution of applying the 'layer3 peer-router' command is suitable for multicast traffic as well?
BTW - great video great explanations!

motiamiful
Автор

4:20 sw2 and router connected interfaces are different networks?? As far as I know, the TTL is not reduced for the same network. Therefore, if it is the same network, the TTL will not be 0, so I don't think there is a problem with OSPF. What do you think in my opinion?

musalyh
Автор

thanks for the video. we have a pair of vpc 9ks that we're attempting to do BGP neighborship with an active/standby ASA so they can excahange routes. Do you recommend we that we use the same AS on both the 9ks or different AS numbers?

Soundwave-FZ
Автор

Thanks, How configuration EBGP from VPC to VSS switch, should we use L2 link or L3 link ?should we have additional link between vpc switch ?

OkaKeanu
Автор

Could you please share the full config of the topology

alihabib
Автор

Thanks for video.How do i announce my subnet in ospf in nx-os.For example: in isr router press command network 10.1.1.0 0.0.0.255 area 1
But in nexus not found this command

headdstrong
Автор

So in summary from what i have understood:

it is the purpose that the router forms a neighborship with only one of the NX-OS devices that are bundled in the VPC domain. even thought both the NX-OS devices act as 1 device

It can happen that the router sends IGP related data to the other NX-OS device ( because of the LAG hashing algortihm)

With the peer-router command configured on the NX-OS devices this is no problem because the NX-OS device that receives the IGP related data which was not ment for him, he will send it over the peer-link to the other NX-OS device. But the problem is that he will decrement the TTL which in many times with IGPs is 1 (so it will become 0 and hence discarded), so the NX-OS device for which the IGP related data was ment never receives it.

result = IGP neighborship flapping

solution: add layer3 peer-router command or increase the IGP ttl to 2.

does this describe the issue correctly?

AH-psuv
Автор

So the big question on everybody's mind is if I add the layer3 peer router command to both switches will traffic be interrupted? I have this exact issue with my edge switch and I'd like to fix it during a maintenance window but I need to tell my business if there's going to be a possible downtime. Thx.

mauricewalker
Автор

These videos are everything. I have to connect two 5k (5548, 5596) to a Nexus 2k in the morning. From your video's can I connect the 2k to Vlan 20?

Emerb