Everyone in this room is a GENIUS

Size: px
Start display at page:

Download "Everyone in this room is a GENIUS"

Transcription

1

2 Everyone in this room is a GENIUS 2

3 What are Best Practices? Learning from Others Mistakes 3

4 Learning from your mistakes makes you SMART Learning from others mistakes makes you GENIUS 4

5 vpc Best Practices and Design on NXOS Nazim Khan, CCIE#39502 (DC/SP) Network Consulting Engineer, Data Center Group BRKDCT-2378

6 Session Focus Best Practices and Designs for vpc Nexus 2000 (FEX) will only be addressed from vpc standpoint Fabricpath / vpc+ Overview vpc with FCOE vpc with VXLAN vpc with ACI.

7 Pick the great from the good

8 We Are Not Covering vpc troubleshooting Scalability Fabricpath vpc+ VXLAN FCoE ACI

9 Related Sessions at Cisco Live Berlin Session Id BRKDCT-2404 BRKDCT-3313 BRKDCT-2458 BRKACI-2601 BRKDCT-2333 Session Name VXLAN deployment models - A practical perspective Fabricpath Operations and Troubleshooting Nexus 9000/7000/6000/5000 Operations and Maintenance Best Practices Real World ACI Deployment and Migration Data Centre Network Failure Detection 9

10 Agenda Feature Overview Configuration Best Practices Design Best Practices vpc Operations and Upgrade vpc with Fabric Technologies Reference Material 10

11 Data Center Technology Evolution MPLS, OTV, LISP MPLS, OTV, LISP FabricPath with vpc+ FEX with vpc VPC STP 2010 VXLAN ACI

12 Why vpc?

13 13

14 there s something about vpc 14

15 Role of vpc in the Evolution of Data Center vpc launched in 2009 Deployed by almost 95% of Nexus customers Used to redundantly connect network entities at the edge of the Fabric Dual-homed servers (bare metal, blades, etc.) Network services (Firewalls, Load Balancers, etc.) Unified Fabric 15

16 Agenda Feature Overview Concepts and Benefits Terminology 16

17 vpc Feature Overview vpc Concept & Benefits S1 S2 S1 S2 S1 S2 STP S3 S3 vpc Physical Topology S3 vpc Logical Topology No Blocked Ports, More Usable Bandwidth, Load Sharing Fast Convergence 17

18 Feature Overview vpc Terminology vpc Peer Layer 3 Cloud vpc Domain Peer-Link vpc Peer Keepalive Link Orphan Port S1 CFS S2 vpc vpc Member Port Orphan Device S3 18

19 vpc Failure Scenario vpc Peer-Keepalive Link up & vpc Peer-Link down For Your Reference vpc peer-link failure (link loss): vpc peer-keepalive up Status of other vpc peer known Both peers Active Secondary vpc peer disables all vpc s Traffic from vpc primary. Orphan devices connected to secondary peer will be isolated S1 P vpc1 SW3 vpc Peer-keepalive vpc_plink vpc2 SW4 S S2 Suspend secondary vpc Member Ports Keepalive Heartbeat P S Primary vpc Secondary vpc 19

20 vpc Failure Scenario Dual Active vpc Peer-Keepalive down followed by vpc Peer-Link down For Your Reference 1. vpc peer-keepalive DOWN 2. vpc peer-link DOWN 3. DUAL-ACTIVE or SPLIT BRAIN vpc primary peer remains primary and secondary peer becomes operational primary role S1 P vpc1 vpc Peer-keepalive vpc_plink Traffic Loss / Uncertain Traffic Behavior vpc2 PS S2 Result in traffic loss / uncertain traffic behavior SW3 SW4 When links are restored, the operational primary (former secondary) keeps the primary role & former primary becomes operational secondary P S Primary vpc Secondary vpc 20

21 Agenda vpc Configuration Best Practices Building a vpc domain Domain-ID Peer-Link Peer-Keepalive Link Spanning-Tree Peer-switch Private VLAN (PVLAN) Auto-recovery Object tracking 21

22 vpc Configuration Best Practices Building a vpc domain Configuration Steps 1. Define domains 2. Establish Peer Keepalive connectivity S1 S2 3. Create a Peer link CFS 4. Create vpcs 5. Make Sure Configurations are Consistent (Order does Matter!) S3 22

23 vpc Configuration Best Practices vpc Domain-ID vpc Domain 10 The vpc peer devices use the vpc domain ID to automatically assign a unique vpc system MAC address You MUST use unique Domain id s for all vpc pairs defined in a contiguous layer 2 domain! Configure the vpc Domain ID It should be unique within the layer 2 domain NX-1(config)# vpc domain 20! Check the vpc system MAC address NX-1# show vpc role <snip> vpc system-mac : 00:23:04:ee:be:14 S1 S3 S2 S4 vpc Domain 20 S5 23

24 vpc Configuration Best Practices vpc Peer-Link S1 S2 S1 S2 S3 S3 vpc Peer-link should be a point-to-point connection Peer-Link member ports can be 10/40/100GE interfaces Peer-Link bandwidth should be designed as per the vpc vpc imposes the rule that peer-link should never be blocking 24

25 vpc Configuration Best Practices vpc Peer-Keepalive link Recommendations (in order of preference): Preference Nexus 7X00 / 9500 series 1 Dedicated link(s) (1GE/10GE LC) Nexus 9300 /6000 / 5X00 / 3X00 series mgmt0 interface 2 mgmt0 interface Dedicated link(s) (1GE/10GE LC) 3 L3 infrastructure L3 infrastructure 25

26 vpc Configuration Best Practices vpc Peer-Keepalive link Dual Supervisors For Your Reference Management Switch Management Network When using dual supervisors and mgmt0 interfaces to carry the vpc peer-keepalive, DO NOT connect them back to back between the two switches vpc_pkl vpc_pkl Only one management port will be active a given point in time and a supervisor switchover may break keepalive connectivity vpc1 vpc_pl vpc2 Use the management interface when you have an outof-band management network (management switch in between) Standby Management Interface Active Management Interface 26

27 vpc Configuration Best Practices Spanning Tree (STP) STP is running to manage loops outside of vpc domain, or before initial vpc configuration! S1 S2 S3 S4 S5 All switches in Layer 2 domain should run either Rapid-PVST+ or MST Do not disable spanning-tree protocol for any VLAN Always define the vpc domain as STP root for all VLAN in that domain 27

28 vpc Configuration Best Practices vpc Peer-Gateway Allows a vpc switch to act as the active gateway for packets addressed to the peer router MAC Keeps forwarding of traffic local to the vpc node and avoids use of the peer-link Allows Interoperability with features of some NAS or load-balancer devices S1 S3 S4 S2 N7k(config-vpc-domain)# peer-gateway 28

29 vpc Configuration Best Practices vpc Peer-switch Without Peer-switch Primary vpc Secondary vpc STP for vpcs controlled by vpc primary. vpc primary send BPDU s on STP designated ports vpc secondary device proxies BPDU s to primary BPDUs With Peer-switch Peer-Switch makes the vpc peer devices to appear as a single STP root BPDUs processed by the logical STP root formed by the 2 vpc peer devices N7k(config-vpc-domain)# peer-switch Primary vpc Secondary vpc 29

30 vpc Configuration Best Practices PVLAN on vpc PVLAN configuration across both VPC switches should be identical PVLAN configuration not supported on Peer-Link vpc Primary vpc Secondary Type-1 Compatibility Check Port mode is a type-1 check vpc leg brought down if PVLAN port mode different on vpc legs Type-2 Compatibility Check PVLAN will bring down mismatched tuple S1 PVLAN- PROMISC (3500, 3501) P C P S2 PVLAN- PROMISC (3500, 3501) Community VLAN Note : This feature is currently not supported on N9X00 30

31 vpc Configuration Best Practices PVLAN VPC type 1 Consistency Check vpc Primary vpc Secondary vpc Primary vpc Secondary S1 P P S2 S1 I I S2 Pvlan Promiscuous trunk S3 Pvlan Isolated trunk S3 vpc Primary vpc Secondary S1 I T S2 Type 1 Consistency Failure S3 31

32 vpc Configuration Best Practices PVLAN VPC type 2 Consistency Check vpc Primary vpc Secondary vpc Primary vpc Secondary S1 P P S2 S1 I I S2 PVLAN- PROMISC (10, 201) S3 PVLAN- PROMISC (10, 201) Secondary Trunk (2,31) (3,30), (4,100) S3 Secondary Trunk (2,31) (3,30), (4,100) vpc Primary vpc Secondary Type 2 Consistency Failure S1 I I S2 Secondary Trunk (3,31) (2,30), (4,100) S3 Secondary Trunk (2,31) (3,30), (4,100) 32

33 vpc Configuration Best Practices vpc auto-recovery Operational Primary P S P S P S1 S2 S1 S2 S1 S2 S3 S3 S3 1. vpc peer-link down : S2 - secondary shuts all its vpc member ports 2. S1 down : vpc peer-keepalive link down : S2 receives no keepalives 3. After 3 keepalive timeouts, S2 changes role and brings up its vpc P S vpc Primary vpc Secondary 33

34 vpc Configuration Best Practices vpc auto-recovery For Your Reference Auto-recovery addresses two cases of single switch behavior Peer-link fails and after a while primary switch (or keepalive link) fails Both VPC peers are reloaded and only one comes back up How it works If Peer-link is down on secondary switch, 3 consecutive missing peer-keepalives will trigger auto-recovery After reload (role is none established ) auto-recovery timer (240 sec) expires while peer-link and peer-keepalive still down, autorecovery kicks in Switch assumes primary role VPCs are brought up bypassing consistency checks Nexus(config)# vpc domain 1 Nexus(config-vpc-domain)# auto-recovery 34

35 vpc Configuration Best Practices Why Object-Tracking? S4 S5 Modules hosting peer-link and uplink fail on the vpc primary Peer-Link is down and vpc Secondary shut all its vpc Primary Secondary Auto-Recovery does not kick in as peerkeepalive link is active S1 S2 Traffic is black holed S3 35

36 vpc Configuration Best Practices Object-tracking vpc object tracking, tracks both peer-link and uplinks in a list of Boolean OR Object Tracking triggered when the track object goes down Suspends the vpcs on the impaired device Traffic forwarded over the remaining vpc peer! Track the vpc peer link track 1 interface port-channel11 line-protocol! Track the uplinks track 2 interface Ethernet1/1 line-protocol track 3 interface Ethernet1/2 line-protocol S4 S1 S5 S2! Combine all tracked objects into one.! OR means if ALL objects are down, this object will go down track 10 list boolean OR object 1 object 2 object 3! If object 10 goes down on the primary vpc peer,! system will switch over to other vpc peer and disable all local vpcs vpc domain 1 track 10 S3 36

37 vpc Configuration Best Practices Spanning Tree Bridge Assurance Stopped receiving BPDUS! Root Network Network BPDUs BA Inconsistent BPDUs Network Network Malfunctioning switch BPDUs Network Network Blocked BA Inconsistent Edge Edge Stopped receiving BPDUS! %STP-2-BRIDGE_ASSURANCE_BLOCK: Bridge Assurance blocking port Ethernet2/48 VLAN0700 switch# show spanning vl 700 in -i bkn Eth2/48 Altn BKN* Network P2p *BA_Inc

38 Spanning Tree Bridge Assurance Almost like a routing protocol For Your Reference Turns STP into a bidirectional protocol Ensures spanning tree fails closed rather than open All ports with network port type send BPDUs regardless of state If network port stops receiving BPDUs, port is placed in BA-Inconsistent state (blocked) %STP-2-BRIDGE_ASSURANCE_BLOCK: Bridge Assurance blocking port Ethernet2/48 VLAN0700. switch# sh spanning vl 700 in -i bkn Eth2/48 Desg BKN* Network P2p *BA_Inc 38

39 vpc Configuration Best Practices vpc & Bridge Assurance (BA) STP Bridge Assurance is enabled by default on vpc Peer-Link DON T disable Bridge Assurance on vpc Peer-link NO Bridge Assurance on vpc member ports (even with peer-switch) 39

40 vpc Configuration Best Practices Unidirectional Link Detection (UDLD) Light-weight Layer 2 failure detection protocol Designed for detecting: One-way connections due to physical or soft failure Mis-wiring detection (loopback or triangle) Cisco proprietary, but listed in informational RFC 5171 Runs on any single Ethernet link, even inside bundle Centralized implementation in switching platforms Message interval: 7-90 sec (default: 15 seconds) Detection: 2.5 x interval + timeout value (4 sec) ~ 41 sec Rx Rx Tx Tx For Your Reference 40

41 vpc Configuration Best Practices UDLD with vpc UDLD NOT recommended on vpc peer-link UDLD NOT recommended on vpc member ports if LACP is used UDLD only in normal mode on vpc member ports if required 41

42 Agenda vpc Design Best Practices Mixed Hardware across vpc Peers FHRP with vpc Hybrid topology (vpc and non-vpc) vpc and Network Services vpc Fex Supported Topologies Physical port vpc vpc as Data Center Interconnect (DCI) Dynamic Routing over VPC vpc and Multicast 42

43 Design Best Practices Mixed Hardware across vpc Peers : Line Cards Always use identical line cards on either sides of the peer link and VPC legs! Examples vpc Primary vpc Secondary vpc Primary vpc Secondary S1 N7000 F3 vpc Peer-link F2E F2E vpc F3 S2 N7700 S1 vpc Peer-link M1 M2 vpc S2 43

44 Design Best Practices Mixed Hardware across vpc Peers : Nexus 9500 S1 N9500 vpc Primary X X vpc Peer-link vpc vpc Secondary Y Y S2 N9500 X Y vpc N9K-X9636PQ N9K-X9432PQ N9K-X9564PX N9K-X9464PX N9K-X9564TX N9K-X9464TX N9K-X9536PQ N9K-X9736PQ 44

45 Design Best Practices Mixed Hardware across vpc Peers : Chassis & Supervisors N7000 and N7700 in same vpc Construct -Supported VDC type should match on both peer device vpc peers can have mixed SUP version* (SUP1, SUP2, SUP2E) N5500 and N5600 in same vpc Construct Not Supported vpc Primary vpc Secondary vpc Primary vpc Secondary S1 N7000 S2 N7700 S1 N5500 N5600 S2 *Recommended only for short period such as migration 45

46 Design Best Practices FHRP with vpc FHRP Active : Active for shared L3 MAC FHRP Standby : Active for shared L3 MAC S1 S2 S3 S4 FHRP in Active/Active mode with vpc No requirement for aggressive FHRP timers Best Practice : Use default FHRP timers 46

47 Design Best Practices Backup Routing Path Use one transit vlan to establish L3 routing backup path over the vpc peerlink in case L3 uplinks were to fail, all other SVIs can use passive-interfaces Point-to-point dynamic routing protocol adjacency between the vpc peers to establish a L3 backup path to the core through PL in case of uplinks failure P S3 OSPF/EIGRP S4 P Define SVIs associated with FHRP as routing passive-interfaces in order to avoid routing adjacencies over vpc peer-link A single point-to-point VLAN/SVI (aka transit vlan) will suffice to establish a L3 neighbor L3 L2 P S1 Primary vpc VLAN 99 OSPF/EIGRP Secondary vpc P S2 Alternatively, use an L3 point-to-point link between the vpc peers to establish a L3 backup path P S5 Routing Protocol Peer 47

48 Hybrid topology (vpc and non-vpc) Bridge Priority VLAN 1 4K VLAN 2 8K STP Root VLAN 1 S1 vpc Primary STP Root VLAN 1 VLAN 2 vpc Secondary S2 STP Root VLAN 2 Bridge Priority VLAN 1 8K VLAN 2 4K S3 vpc1 peer-switch S4 VLAN 1 (blocked) VLAN 2 (blocked) Supports hybrid topology where vpc and non-vpc are connected to the same vpc domain Need additional configuration parameters : spanning-tree pseudo-information STP pseudo configuration takes precedence over global STP configuration 48

49 Design Best Practices ASA Cluster Cluster Control Link Cluster Data Link ASA Cluster Mode Use unique vpc for ASA Cluster Data Links to vpc domain Use vpc per ASA device for Cluster Control Link (CCL) to vpc domain Leverage peer-switch configuration 49

50 Nexus 2000 (FEX) Straight-Through Deployment with VPC Port-channel connectivity from the server Two Nexus switches bundled into a vpc pair Suited for servers with Dual NIC and capable of running Port-Channel S1 Fabric Links S2 HIF Fex 100 HIF Fex 101 VPC 50

51 Nexus 2000 (FEX)Active-Active Deployment with VPC S1 S2 Fabric Extender connected to two Nexus 5X00 / 6000 Suited for servers with Single NIC or Dual NIC not having port-channel capability. Scale implications of less FEX per system and less VPC Fabric Links Note : This design is currently not supported on Nexus 9X00 Nexus 7X00 will support this from release 7.2 Fex 100 HIF HIF Fex

52 Nexus 2000 (FEX) Active-Active Scale & Limitations (N7X00) N7X00 can support up to 64 FEXs N7X00 supports only 15 Active-Active FEX in 7.2(0)D1(1) Straight-Through FEX and Active-Active FEX cannot exist on the same ASIC instance Layer 3 HIF ports are not supported with Active-Active FEX Active-Active FEX is not supported with vpc+

53 Nexus 2000 (FEX) - Enhanced VPC Port-channel connectivity to dual-homed FEXs From the server perspective a single access switch with port-channel support each line card supported by redundant supervisors Ideal design for a combination of single NIC and Dual NIC servers with portchannel capability Scale implications of less FEX per system and less VPC Note : This design is currently not supported on N7000 / N7700 and N9X00 S1 S2 Fabric Links Fex 100 Fex 101 HIF HIF 53

54 Nexus 2000 (FEX) Active-Active (Unsupported) 54

55 Physical Port vpc vpc domain vpc domain FEX101 e101/1/1 Po1 VPC1 VPC1 Po1 FEX102 e102/1/1 FEX101 e101/1/1 VPC1 VPC1 FEX102 e102/1/1 Port-channel vpc interface e101/1/1 switchport vpc 1 lacp mode active Physical port vpc vpc configuration on a physical Layer 2 port as opposed to a port-channel Front panel ports and FEX ports connected to F2/F2e/F3 only Improves scaling as separate PC interface not created for single-link VPC leg Key benefit: more than 1000 host facing VPCs with FEX 55

56 ACCESS AGGR CORE vpc - Data Center Interconnect(DCI) DC 1 DC 2 vpc domain 11 Long Distance Dark Fiber vpc domain 21 N E Network port Edge or portfast - Normal port type - N R N - R - - N N E E F F F F E E N N - - R - N R - N CORE AGGR B F R BPDUguard BPDUfilter Rootguard 802.1AE (Optional) - - R R vpc domain 10 vpc domain R R - E B E B - ACCESS Server Cluster Server Cluster 56

57 Design Best Practices vpc as Data Center Interconnect (DCI) PROS vpc is easy to configure and it provides robust and resilient interconnect solution CONS Maximum of only two Data Centers can be interconnected Layer 3 peering between Data Centers cannot be done through vpc and separate links are required 57

58 Design Best Practices vpc -Data Center Interconnect (DCI) vpc Domain id for vpc layers should be UNIQUE BPDU Filter on the edge devices to avoid BPDU propagation STP Edge Mode to provide fast Failover times No Loop must exist outside the vpc domain No L3 peering between Nexus 7000 devices (i.e. pure layer 2) 58

59 Dynamic routing over vpc? 59

60 Dynamic routing over vpc Use Case 1 : Firewall at Aggregation layer Peering Firewalls in routed mode over vpc L3 Cloud Firewalls may be in active-standby mode Static routing / L3 P2P links NOT required External and internal traffic traverse same port channel to firewall. S1 S2 FW-A FW-B Dynamic Peering Relationship 60

61 Dynamic routing over vpc Use Case 2 : Remote Orphan Site Peering in DCI Deployment vpc as Data Center Interconnect (DCI) Remote Site 1 Remote Site 2 Each Switch has routing adjacency with both vpc device in other DC Each DC connected to a remote site by orphan port Remote sites forms routing adjacency with both peers of its directly connected DC S1 S2 S3 S4 61

62 Dynamic Routing over vpc New Supported Designs

63 Dynamic routing over vpc Supported Designs Layer 3 services devices with vpc Layer 3 over DCI - vpc P P P P P P P Note : Supported only in Nexus 7X00 on F3 and F2E Line Cards starting from release 7.2. Supported on Nexus 9X00 in ACI mode Currently not supported on Nexus 5X00, Nexus 3X00, Nexus 9X00 (standalone mode), Nexus 7000 M-series Line card 63

64 Dynamic routing over vpc Supported Designs STP inter-connection using a vpc VLAN Orphan device with vpc peers over vpc VLAN P P P P P P Note : Supported only in Nexus 7X00 on F3 and F2E Line Cards starting from release 7.2. Supported on Nexus 9X00 in ACI mode Currently not supported on Nexus 5X00, Nexus 3X00, Nexus 9X00 (standalone mode), Nexus 7000 M-series Line card 64

65 Dynamic routing over vpc Supported Designs Peering with vpc peers over FEX vpc host interfaces P P P Note : Supported only in Nexus 7X00 on F3 and F2E Line Cards starting from release 7.2(0)D1(1) Currently not supported on Nexus 5X00, Nexus 3X00, Nexus 9X00 (standalone mode), Nexus 7000 M-series Line card 65

66 Dynamic Routing over vpc Unsupported Designs 66

67 Dynamic routing over vpc Unsupported Design Peering across vpc interfaces with unequal L3 metrics The routing metric on S1 is less than the routing metric on S2 (preferred path using S1). B Router2 Int VLAN 20 Po2 SVI Traffic from A to B may hash to S2. This traffic will need to traverse to peer-link to get to B through S1. Due to the vpc loop avoidance rule S1 will not allow traffic to flow to B. Int VLAN 20 S2 Int VLAN 10 Metric 20 Po100 Po1 Router1 Int VLAN 10 Int VLAN 20 S1 Int VLAN 10 Metric 10 SVI A 67

68 Dynamic routing over vpc Configuration L3 over vpc Configuration on Nexus 7x00 platform Command: Layer3 peer-router Mode: config-vpc-domain Default: Disabled Need to configure on BOTH the peers Requirements Command configured on both the peers. Peer-Gateway should be enabled. Peer link should be up. Both peer should run image supporting L3 over vpc feature. Auto Enabling Peer-Gateway If Layer3 peer-router command is enabled without Peer-Gateway a syslog will be displayed to enable Peer-Gateway. 68

69 Dynamic routing over vpc Example Configuration and Verification on Nexus 7x00 vpc domain 200 peer-keepalive destination source peer-gateway layer3 peer-router P P vpc domain 200 peer-keepalive destination source peer-gateway layer3 peer-router show vpc brief Peer Gateway : Enabled Operational Layer3 Peer : Enabled (output truncated for display) show vpc brief Peer Gateway : Enabled Operational Layer3 Peer : Enabled (output truncated for display) P 69

70 Benefits of Dynamic Routing over vpc No Static routes No Parallel links No design changes and loss of business Route peering across vpc s over existing infrastructure Routing between vpc DCI Most wanted by majority vpc customers 70

71 Dynamic Routing over vpc Devices without L3 over vpc support Don t attach routers to VPC domain via L2 port-channel Common workarounds: Individual L3 links for routed traffic Static route to FHRP VIP A B SVI 1 IP Y VIP A SVI 1 IP Z VIP A SVI 1 IP Y VIP A SVI 1 IP Z VIP A SVI 1 IP Y VIP A SVI 1 IP Z VIP A S1 S2 L3 ECMP S1 S2 S1 S2 SVI 2 IP X Router SVI 2 IP X Router SVI 2 IP X Router Static Route to VIP A 71

72 Design Best Practices vpc and Multicast S1 Source S2 vpc supports PIM-SM only vpc uses CFS to sync IGMP state Sources in vpc domain both vpc peers are forwarders Duplicates avoided via vpc loop-avoidance logic Sources in Layer 3 cloud Active forwarder elected on unicast metric vpc Primary elected active forwarder in case metric are equal Source Receivers 72

73 Agenda vpc Operations and Upgrade vpc Self Isolation vpc Shutdown Graceful Insertion and Removal ISSU / ISSD with vpc 73

74 P vpc Configuration Best Practices vpc Self-Isolation Error Triggered S P Self- Isolate S ISOLATED Operational Primary P S1 S2 S1 S2 S1 S2 S3 S3 S3 1. Error Triggered : All Line cards Fail or All Vlans s down on peer-link 2. S1 sends self-isolation message through the peer-keepalive 3. S2 takes over as operational Primary and S1 is isolated from the vpc domain P S vpc Primary vpc Secondary 74

75 vpc Configuration Best Practices Example Configuration and Verification on Nexus 7x00 vpc domain 100 peer-keepalive destination peer-gateway self-isolation vpc domain 100 peer-keepalive destination peer-gateway self-isolation sh vpc brief vpc domain id : 100 Self-isolation : Enabled (output truncated for display) sh vpc brief vpc domain id : 100 Self-isolation : Enabled (output truncated for display) 75

76 vpc Configuration Best Practices vpc Self-Isolation vpc self-isolation is turned OFF by default No Impact on vpc operation if sellf-isolation enabled Functional only when enabled on both vpc peers. Not part of vpc type-1 and type-2 consistency checks 76

77 vpc Configuration Best Practices vpc Shutdown Isolates a switch from the vpc complex Isolated switch can be debugged, reloaded, or even removed physically, without affecting the vpc traffic going through the non-isolated switch Primary vpc Secondary S1 S2 switch# configure terminal switch(config)# vpc domain 100 switch(config-vpc)# shutdown S3 77

78 Graceful Insertion and Removal Change window begins vpc system mode maintenance vpc One command! Pre-change System Snapshot 78

79 Graceful Insertion and Removal Change window complete vpc vpc system mode normal One command! Pre/Post-change Snapshot Comparison 79

80 Graceful Insertion and Removal Flexible framework providing a comprehensive, systemic method to isolate a node. Configuration profile foundation in NX-OS Initial support for: vpc/vpc+ ISIS OSPF EIGRP BGP Interface Per VDC on Nexus 7x00 Platform Release Nexus 5x00/6000 NX-OS 7.1 Nexus 7x00 NX-OS 7.2 Nexus 9000 NX-OS 7.X 80

81 ISSU / ISSD with vpc ISSU is the recommended system upgrade in a multi-device vpc environment vpc system can be independently upgraded with no disruption to traffic Upgrade is serialized and must be run one peer at a time (config lock will prevent synchronous upgrades) Configuration is locked on other vpc peer during ISSU Similar process of downgrades (ISSD) Check ISSU / ISSD compatibility matrix & ensure ISSU is supported from current to target release 5.2(x) / 6.2(x) 81

82 Agenda vpc with Fabric Technologies vpc with Fabricpath (vpc+) vpc with FCOE vpc with VXLAN vpc with ACI 82

83 FabricPath: an Ethernet Fabric Shipping on Nexus 7x00, Nexus 600x and Nexus 5x00 FabricPath Eliminates Spanning tree limitations High resiliency, fast network re-convergence Any VLAN, Anywhere in the Fabric Connect a group of switches using an arbitrary topology With a simple CLI, aggregate them into a Fabric N7K(config)# interface ethernet 1/1 N7K(config-if)# switchport mode fabricpath 83

84 VPC vs VPC+ Architecture of vpc and FabricPath with vpc+ CE FP CE Port FP Port CE VLAN s FP VLAN s vpc vpc+ Physical architecture of vpc and vpc+ is the same from the access edge Functionality/Concepts of vpc and vpc+ are the same Key differences are addition of Virtual Switch ID and Peer Link is a FP Core Port vpc+ is not supported on Nexus 9X00 & Nexus 3X00 Series 84

85 Dynamic Routing over vpc+ Layer 3 devices can form routing adjacencies with both the vpc+ peers over vpc The peer link ports and VLAN are configured in FabricPath mode. Fabricpath Core vpc N55xx, N56xx, N6000 support this design with IPv4/IPv6 unicast and PIM-SM multicast This design is not supported on N7X00 P P N55xx, N56xx, N6000 Router/ Firewall P Fabricpath Link Dynamic Peering Relationship Routing Protocol Peer P 85

86 vpc with FCoE Unified Fabric Design vpc with FCoE is ONLY supported between hosts and N5X00 or N5X00 & N2232 pairs. Must follow specific rules: A vfc interface can only be associated with a single-port port-channel. While the port-channel configurations are the same on both switches, the FCoE VLANs are different. FCoE VLANs are not carried on the vpc peer-link (automatically pruned): FCoE and FIP ethertypes are not forwarded over the vpc peer link. vpc carrying FCoE between two FCF s is NOT supported. Best Practice: Use static port channel rather than LACP with vpc and boot from SAN. [If NX-OS is prior to 5.1(3)N1(1)] VLAN 10,20 LAN Fabric Nexus 5000 FCF-A Fabric A VLAN 10 ONLY HERE! VLAN 10,30 Fabric B Nexus 5000 FCF-B STP Edge Trunk vpc contains only 2 X 10GE links one to each Nexus 5X00 86

87 Why VXLAN? Problems being addressed: VLAN scale VXLAN extends the L2 segment ID field to 24-bits, potentially allowing for up to 16 million unique L2 segments over the same network Layer 2 segment elasticity over Layer 3 boundary VXLAN encapsulates L2 frame in IP-UDP header High Level Technology Overview: MAC-in-UDP encapsulation. Leverages multicast in the transport network to simulate flooding behavior for broadcast, unknown unicast and multicast in the same segment Leverage ECMP to achieve optimal path usage over the transport network 87

88 Dst. VXLAN Packet Format Outer Mac Header Outer IP Header UDP Header VXLAN Header Original L2 Frame FCS FCS MAC Addr. Src. MAC Addr. VLAN Type 0x8100 VLAN ID Tag Ether Type 0x0800 IP Header Misc Data Protocol 0x11 Header Checksum Outer Src. IP Outer Dst. IP UDP Src. Port VXLAN Port UDP Length Checksum 0x0000 VXLAN RRRR1RRR Reserved VNID Reserved For Your Reference 14 Bytes (4 bytes optional) 20 Bytes 8 Bytes 8 Bytes VXLAN is a Layer 2 overlay scheme over a Layer 3 network. VXLAN uses Ethernet in UDP encapsulation VXLAN uses a 24-bit VXLAN Segment ID (VNI) to identify Layer-2 segments 88

89 VXLAN Terminology VTEP Virtual Tunnel End Point Transport IP Network VTEP IP Interface VTEP IP Interface Local LAN Segment Local LAN Segment End System End System End System End System VXLAN terminates its tunnels on VTEPs (Virtual Tunnel End Point). VTEP has two interfaces : 1. Bridging functionality for local hosts 2. IP identification in the core network for VXLAN encapsulation / de-encapsulation. 89

90 vpc VTEP When vpc is enabled an anycast VTEP address is programmed on both vpc peers Multicast topology prevents BUM traffic being sent to the same IP address across the L3 network (prevents duplication of flooded packets) vpc peer-gateway feature must be enabled on both peers VXLAN header is not carried on the vpc Peer link vpc VTEP vpc VTEP VLAN VXLAN 90

91 VXLAN & VPC VPC Configuration Map VNI to VLAN Source Interface individual IP is used for single attached Hosts anycast IP is used for VPC attached Hosts VTEP1 vlan 10 vn-segment For Your Reference interface loopback 0 ip address <VTEP individual IP orphan) ip address <VTEP anycast IP per VPC domain> secondary! interface nve1 source-interface loopback0 member vni mcast-group VXLAN Tunnel Interface vtep 1 vtep 2 vtep 3 vtep 4 VTEP2 vlan 10 vn-segment interface loopback 0 ip address <VTEP individual IP - orphan> ip address <VTEP anycast IP per VPC domain> secondary! interface nve1 source-interface loopback0 member vni mcast-group H VLAN 10 (vpc) H VLAN 10 (vpc) 91

92 VXLAN & VPC VPC Configuration For Your Reference VTEP1 vlan 10 vn-segment VTEP3 vlan 10 vn-segment interface loopback 0 ip address /32 ip address /32 secondary! Interface nve1 source-interface loopback0 member vni mcast-group interface loopback 0 ip address /32 ip address /32 secondary! Interface nve1 source-interface loopback0 member vni mcast-group VTEP2 vlan 10 vn-segment vtep 1 vtep 2 vtep 3 vtep 4 VTEP4 vlan 10 vn-segment interface loopback 0 ip address /32 ip address /32 secondary! Interface nve1 source-interface loopback0 member vni mcast-group interface loopback 0 ip address /32 ip address /32 secondary! Interface nve1 source-interface loopback0 member vni mcast-group H VLAN 10 (vpc) H VLAN 10 (vpc) 92

93 VXLAN & VPC Dual attached Host to dual attached Host (Layer-2) Host 1 (H1) and Host 2 (H2) are dual connected to a VPC domain As H1 is behind a VPC interface, the anycast VTEP IP is the source for the the VXLAN encapsulation vtep 1 vtep 20 vtep 2 vtep 3 vtep 30 vtep 4 As H2 is behind a VPC interface, the anycast VTEP IP is the target H VLAN 10 (vpc) H VLAN 10 (vpc) 93

94 Nexus APIC = ACI APIC APICAPIC 94

95 ACI uses a policy based approach that focuses on the application. QoS Filter Web QoS Service App QoS Filter DB External Network 95

96 vpc and ACI ACI fabric utilised for control-plane No dedicated peer-link between vpc peers: vpc Domains vpc peers Fabric itself serves as the MCT No out-of-band mechanism to detect peer liveliness: Due to rich fabric-connectivity (leaf-spine), it is very unlikely that peers will have no active path between them vtep 1 vtep 3 vtep 2 ACI fabric CFS (Cisco Fabric Services) is replaced by Zero Message Queue (ZMQ) As ACI fabric is VXLAN-based, an anycast VTEP is shared by both leaf switches in a vpc domain vpc vpc 96

97 Agenda Reference Material 97

98 Reference Material For Your Reference vpc Best Practices Design Guide: e.pdf vpc design guides: vpc and VSS Interoperability white Paper: VXLAN Overview : Fabrcipath whitepaper : ACI Overview 98

99 Key Take-Aways vpc in 2016 VXLAN, ACI, Fabricpath vpc Benefits No Blocked Ports High availability Fast Convergence Fabricpath Eliminates Spanning-Tree * High resiliency vpc+ for legacy switches, servers, hosts VXLAN L2 segment scalability VTEP redundancy with vpc ACI Policy Based Fabric for vpc control plane FCoE Unified Fabric for LAN & SAN 99

100 Call to Action Visit the World of Solutions for Cisco Campus Walk in Labs Technical Solution Clinics Meet the Engineer Lunch and Learn Topics DevNet zone related sessions 100

101 Complete Your Online Session Evaluation Please complete your online session evaluations after each session. Complete 4 session evaluations & the Overall Conference Evaluation (available from Thursday) to receive your Cisco Live T-shirt. All surveys can be completed via the Cisco Live Mobile App or the Communication Stations 101

102 Many Things there s Something About vpc 102

103 Thank you 103

104

Best Practices come from YOU Cisco and/or its affiliates. All rights reserved.

Best Practices come from YOU Cisco and/or its affiliates. All rights reserved. Best Practices come from YOU 2 Apple iphone4 launched in June 2010 3 Antennagate 4 IPHONE4 Best Practices from CUSTOMERS 5 vpc Best Practices and Design on NXOS Nazim Khan, CCIE#39502 (DC/SP) Technical

More information

vpc Best Practices and Design on NX-OS

vpc Best Practices and Design on NX-OS vpc Best Practices and Design on NX-OS Nemanja Kamenica (nkamenic@cisco.com) Engineer, Technical Marketing BRKDCN-2378 Cisco Spark How Questions? Use Cisco Spark to chat with the speaker after the session

More information

Configuring Virtual Port Channels

Configuring Virtual Port Channels Configuring Virtual Port Channels This chapter describes how to configure virtual port channels (vpcs) on Cisco Nexus 5000 Series switches. It contains the following sections: Information About vpcs, page

More information

Configuring Virtual Port Channels

Configuring Virtual Port Channels This chapter contains the following sections: Information About vpcs, page 1 Guidelines and Limitations for vpcs, page 10 Configuring vpcs, page 11 Verifying the vpc Configuration, page 25 vpc Default

More information

Configuring Virtual Port Channels

Configuring Virtual Port Channels This chapter contains the following sections: Information About vpcs vpc Overview Information About vpcs, on page 1 Guidelines and Limitations for vpcs, on page 11 Verifying the vpc Configuration, on page

More information

Configuring Virtual Port Channels

Configuring Virtual Port Channels This chapter contains the following sections: Information About vpcs, page 1 Guidelines and Limitations for vpcs, page 10 Verifying the vpc Configuration, page 11 vpc Default Settings, page 16 Configuring

More information

Implementing VXLAN in DataCenter

Implementing VXLAN in DataCenter Implementing VXLAN in DataCenter LTRDCT-1223 Lilian Quan Technical Marketing Engineering, INSBU Erum Frahim Technical Leader, ecats John Weston Technical Leader, ecats Why Overlays? Robust Underlay/Fabric

More information

Deploying Virtual Port Channel in NX-OS

Deploying Virtual Port Channel in NX-OS Deploying Virtual Port Channel in NX-OS 2 Housekeeping We value your feedback- don't forget to complete your online session evaluations after each session & the Overall Conference Evaluation which will

More information

Layer 2 Implementation

Layer 2 Implementation CHAPTER 3 In the Virtualized Multiservice Data Center (VMDC) 2.3 solution, the goal is to minimize the use of Spanning Tree Protocol (STP) convergence and loop detection by the use of Virtual Port Channel

More information

VXLAN Design with Cisco Nexus 9300 Platform Switches

VXLAN Design with Cisco Nexus 9300 Platform Switches Guide VXLAN Design with Cisco Nexus 9300 Platform Switches Guide October 2014 2014 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 39 Contents What

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, on page 1 Licensing Requirements for VXLAN EVPN Multi-Site, on page 2 Guidelines and Limitations for VXLAN EVPN Multi-Site, on

More information

Nexus 7000 F3 or Mx/F2e VDC Migration Use Cases

Nexus 7000 F3 or Mx/F2e VDC Migration Use Cases Nexus 7000 F3 or Mx/F2e VDC Migration Use Cases Anees Mohamed Network Consulting Engineer Session Goal M1 VDC M1/M2 VDC M2/F3 VDC M1/F1 VDC M1/M2/F2e VDC F2/F2e/F3 VDC F2 VDC F3 VDC You are here This Session

More information

VXLAN Deployment Use Cases and Best Practices

VXLAN Deployment Use Cases and Best Practices VXLAN Deployment Use Cases and Best Practices Azeem Suleman Solutions Architect Cisco Advanced Services Contributions Thanks to the team: Abhishek Saxena Mehak Mahajan Lilian Quan Bradley Wong Mike Herbert

More information

"Charting the Course... Troubleshooting Cisco Data Center Infrastructure v6.0 (DCIT) Course Summary

Charting the Course... Troubleshooting Cisco Data Center Infrastructure v6.0 (DCIT) Course Summary Description Troubleshooting Cisco Data Center Infrastructure v6.0 (DCIT) Course Summary v6.0 is a five-day instructor-led course that is designed to help students prepare for the Cisco CCNP Data Center

More information

VXLAN EVPN Multihoming with Cisco Nexus 9000 Series Switches

VXLAN EVPN Multihoming with Cisco Nexus 9000 Series Switches White Paper VXLAN EVPN Multihoming with Cisco Nexus 9000 Series Switches 2017 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 27 Contents Introduction...

More information

Cisco Configuring Cisco Nexus 7000 Switches v3.1 (DCNX7K)

Cisco Configuring Cisco Nexus 7000 Switches v3.1 (DCNX7K) Course Overview View Course Dates & Register Today This course is designed for systems and field engineers who configure the Cisco Nexus 7000 Switch. This course covers the key components and procedures

More information

Implementing VXLAN. Prerequisites for implementing VXLANs. Information about Implementing VXLAN

Implementing VXLAN. Prerequisites for implementing VXLANs. Information about Implementing VXLAN This module provides conceptual information for VXLAN in general and configuration information for layer 2 VXLAN on Cisco ASR 9000 Series Router. For configuration information of layer 3 VXLAN, see Implementing

More information

VXLAN Overview: Cisco Nexus 9000 Series Switches

VXLAN Overview: Cisco Nexus 9000 Series Switches White Paper VXLAN Overview: Cisco Nexus 9000 Series Switches What You Will Learn Traditional network segmentation has been provided by VLANs that are standardized under the IEEE 802.1Q group. VLANs provide

More information

Exam Questions

Exam Questions Exam Questions 642-997 DCUFI Implementing Cisco Data Center Unified Fabric (DCUFI) v5.0 https://www.2passeasy.com/dumps/642-997/ 1.Which SCSI terminology is used to describe source and destination nodes?

More information

Configuring Cisco Nexus 7000 Series Switches

Configuring Cisco Nexus 7000 Series Switches Configuring Cisco Nexus 7000 Series Switches DCNX7K v3.1; 5 Days, Instructor-led Course Description The Configuring Cisco Nexus 7000 Switches (DCNX7K) v3.0 course is a 5-day ILT training program that is

More information

Configuring Enhanced Virtual Port Channels

Configuring Enhanced Virtual Port Channels This chapter contains the following sections: Information About Enhanced vpcs, page 2 Licensing Requirements for Enhanced vpc, page 4 Configuring Enhanced vpcs, page 4 Verifying Enhanced vpcs, page 5 Enhanced

More information

Deploying Virtual Port Channel (vpc) in NX-OS

Deploying Virtual Port Channel (vpc) in NX-OS Deploying Virtual ort Channel () in NX-OS Sutharsan Sivapalan Customer Support Engineer #clmel Session Abstract This session is targeted at Network Engineers, Network Architects and IT Administrators who

More information

Návrh serverových farem

Návrh serverových farem Návrh serverových farem DCTECH4 Martin Diviš Consulting Systems Engineer mdivis@cisco.com Sponsor Sponsor Sponsor Sponsor Logo Logo Logo Logo CIscoEXPO 1 Agenda Introduction 5k/2k update Basic Concepts

More information

"Charting the Course... Implementing Cisco Data Center Infrastructure (DCII) Course Summary

Charting the Course... Implementing Cisco Data Center Infrastructure (DCII) Course Summary Description Course Summary v6.0 is a five-day instructor-led course that is designed to help students prepare for the Cisco CCNP Data Center certification and for professional-level data center roles.

More information

Module 5: Cisco Nexus 7000 Series Switch Administration, Management and Troubleshooting

Module 5: Cisco Nexus 7000 Series Switch Administration, Management and Troubleshooting The Detailed course Modules for (DCNX7K) Configuring Cisco Nexus 7000 Switches Training Online: Module 1: Cisco Nexus 7000 Series Switches Cisco unified fabric trends Nexus 7000 series switch Deployment

More information

Migrate from Cisco Catalyst 6500 Series Switches to Cisco Nexus 9000 Series Switches

Migrate from Cisco Catalyst 6500 Series Switches to Cisco Nexus 9000 Series Switches Migration Guide Migrate from Cisco Catalyst 6500 Series Switches to Cisco Nexus 9000 Series Switches Migration Guide November 2013 2013 Cisco and/or its affiliates. All rights reserved. This document is

More information

Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric)

Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric) White Paper Optimizing Layer 2 DCI with OTV between Multiple VXLAN EVPN Fabrics (Multifabric) What You Will Learn This document describes how to achieve a VXLAN EVPN multifabric design by integrating Virtual

More information

Configuring Rapid PVST+ Using NX-OS

Configuring Rapid PVST+ Using NX-OS Configuring Rapid PVST+ Using NX-OS This chapter describes how to configure the Rapid per VLAN Spanning Tree (Rapid PVST+) protocol on Cisco NX-OS devices. This chapter includes the following sections:

More information

Contents. Introduction. Prerequisites. Requirements. Components Used

Contents. Introduction. Prerequisites. Requirements. Components Used Contents Introduction Prerequisites Requirements Components Used Background Information Terminology What is VXLAN? Why VXLAN? Configure Network Diagram Configurations 3172-A 9396-A 9396-B Verify Example

More information

Configuring Fabric and Interfaces

Configuring Fabric and Interfaces Fabric and Interface Configuration, on page 1 Graceful Insertion and Removal (GIR) Mode, on page 2 Configuring Physical Ports in Leaf Nodes and FEX Devices Using the NX-OS CLI, on page 3 Configuring Port

More information

Hierarchical Fabric Designs The Journey to Multisite. Lukas Krattiger Principal Engineer September 2017

Hierarchical Fabric Designs The Journey to Multisite. Lukas Krattiger Principal Engineer September 2017 Hierarchical Fabric Designs The Journey to Multisite Lukas Krattiger Principal Engineer September 2017 A Single Fabric, a Single Data Center External Layer-3 Network Pod 1 Leaf/ Topologies (aka Folded

More information

Configuring Private VLANs Using NX-OS

Configuring Private VLANs Using NX-OS This chapter describes how to configure private VLANs on Cisco NX-OS devices. Private VLANs provide additional protection at the Layer 2 level. This chapter includes the following sections: Finding Feature

More information

Implementing Cisco Data Center Infrastructure v6.0 (DCII)

Implementing Cisco Data Center Infrastructure v6.0 (DCII) Implementing Cisco Data Center Infrastructure v6.0 (DCII) COURSE OVERVIEW: Implementing Cisco Data Center Infrastructure (DCII) v6.0 is a five-day instructor-led course that is designed to help students

More information

Data Center Access Design with Cisco Nexus 5000 Series Switches and 2000 Series Fabric Extenders and Virtual PortChannels

Data Center Access Design with Cisco Nexus 5000 Series Switches and 2000 Series Fabric Extenders and Virtual PortChannels Design Guide Data Center Access Design with Cisco Nexus 5000 Series Switches and 2000 Series Fabric Extenders and Virtual PortChannels Updated to Cisco NX-OS Software Release 5.1(3)N1(1) Design Guide October

More information

Verified Scalability Limits

Verified Scalability Limits This chapter describes the Cisco NX-OS configuration limits for the Cisco Nexus 9000 Series switches. Introduction, page 1, page 1 Deployment Case Studies, page 6 Introduction The values provided in this

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, page 1 Guidelines and Limitations for VXLAN EVPN Multi-Site, page 2 Enabling VXLAN EVPN Multi-Site, page 2 Configuring VNI Dual

More information

Configuring Rapid PVST+

Configuring Rapid PVST+ This chapter describes how to configure the Rapid per VLAN Spanning Tree (Rapid PVST+) protocol on Cisco NX-OS devices using Cisco Data Center Manager (DCNM) for LAN. For more information about the Cisco

More information

Introduction to External Connectivity

Introduction to External Connectivity Before you begin Ensure you know about Programmable Fabric. Conceptual information is covered in the Introduction to Cisco Programmable Fabric and Introducing Cisco Programmable Fabric (VXLAN/EVPN) chapters.

More information

Configuring StackWise Virtual

Configuring StackWise Virtual Finding Feature Information, page 1 Restrictions for Cisco StackWise Virtual, page 1 Prerequisites for Cisco StackWise Virtual, page 2 Information About Cisco Stackwise Virtual, page 2 Cisco StackWise

More information

Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003

Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003 Cisco ACI Multi-Pod/Multi-Site Deployment Options Max Ardica Principal Engineer BRKACI-2003 Agenda ACI Introduction and Multi-Fabric Use Cases ACI Multi-Fabric Design Options ACI Stretched Fabric Overview

More information

Data Center Configuration. 1. Configuring VXLAN

Data Center Configuration. 1. Configuring VXLAN Data Center Configuration 1. 1 1.1 Overview Virtual Extensible Local Area Network (VXLAN) is a virtual Ethernet based on the physical IP (overlay) network. It is a technology that encapsulates layer 2

More information

Cisco Nexus 7000 Series NX-OS VXLAN Configuration Guide

Cisco Nexus 7000 Series NX-OS VXLAN Configuration Guide First Published: 2015-05-07 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 2016

More information

Configuring SPAN. Finding Feature Information. About SPAN. SPAN Sources

Configuring SPAN. Finding Feature Information. About SPAN. SPAN Sources This chapter describes how to configure an Ethernet switched port analyzer (SPAN) to analyze traffic between ports on Cisco NX-OS devices. Finding Feature Information, on page 1 About SPAN, on page 1 Licensing

More information

Verified Scalability Limits

Verified Scalability Limits This chapter describes the Cisco NX-OS configuration limits for the Cisco Nexus 9000 Series switches. Introduction, page 1, page 1 Deployment Case Studies, page Introduction The values provided in this

More information

ARCHITETTURA DATA CENTERS AS-IS

ARCHITETTURA DATA CENTERS AS-IS ARCHITETTURA DATA CENTERS AS-IS 7K1-VDC -AGGREG po1 7K2-VDC-AGGREG po100 po200 po100 po200 7K1-VDC-DIST1 po1 7K2-VDC-DIST1 po1 VDC-DIST3 po1 7K1-VDC-DIST2 7K2-VDC-DIST2 Distribution / Core level N7K-1-AGGREG

More information

Overview. Overview. OTV Fundamentals. OTV Terms. This chapter provides an overview for Overlay Transport Virtualization (OTV) on Cisco NX-OS devices.

Overview. Overview. OTV Fundamentals. OTV Terms. This chapter provides an overview for Overlay Transport Virtualization (OTV) on Cisco NX-OS devices. This chapter provides an overview for Overlay Transport Virtualization (OTV) on Cisco NX-OS devices., page 1 Sample Topologies, page 6 OTV is a MAC-in-IP method that extends Layer 2 connectivity across

More information

Evolution with End-to-End Data Center Virtualization

Evolution with End-to-End Data Center Virtualization Evolution with End-to-End Data Center Virtualization Yves Louis DC Virtualisation Technical Solution Architect Agenda Data Center Virtualization Overview Front-End Data Center Virtualization Core Layer

More information

Configuring Port Channels

Configuring Port Channels CHAPTER 5 This chapter describes how to configure port channels and to apply and configure the Link Aggregation Control Protocol (LACP) for more efficient use of port channels in Cisco DCNM. For more information

More information

MP-BGP VxLAN, ACI & Demo. Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017

MP-BGP VxLAN, ACI & Demo. Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017 MP-BGP VxLAN, ACI & Demo Brian Kvisgaard System Engineer, CCIE SP #41039 November 2017 Datacenter solutions Programmable Fabric Classic Ethernet VxLAN-BGP EVPN standard-based Cisco DCNM Automation Modern

More information

Configuring SPAN. About SPAN. SPAN Sources

Configuring SPAN. About SPAN. SPAN Sources This chapter describes how to configure an Ethernet switched port analyzer (SPAN) to analyze traffic between ports on Cisco NX-OS devices. This chapter contains the following sections: About SPAN, page

More information

Configuring VXLAN Multihoming

Configuring VXLAN Multihoming VXLAN EVPN Multihoming Overview, page 1 Configuring VXLAN EVPN Multihoming, page 4 Configuring Layer 2 Gateway STP, page 7 Configuring VXLAN EVPN Multihoming Traffic Flows, page 11 Configuring VLAN Consistency

More information

Troubleshooting Cisco Data Center Unified Fabric

Troubleshooting Cisco Data Center Unified Fabric Troubleshooting Cisco Data Center Unified Fabric Number: 642-980 Passing Score: 800 Time Limit: 120 min File Version: 1.0 http://www.gratisexam.com/ Exam A QUESTION 1 Which command displays the traffic

More information

PracticeTorrent. Latest study torrent with verified answers will facilitate your actual test

PracticeTorrent.   Latest study torrent with verified answers will facilitate your actual test PracticeTorrent http://www.practicetorrent.com Latest study torrent with verified answers will facilitate your actual test Exam : 642-980 Title : Troubleshooting Cisco Data Center Unified Fabric (DCUFT)

More information

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV.

Enterprise. Nexus 1000V. L2/L3 Fabric WAN/PE. Customer VRF. MPLS Backbone. Service Provider Data Center-1 Customer VRF WAN/PE OTV OTV. 2 CHAPTER Cisco's Disaster Recovery as a Service (DRaaS) architecture supports virtual data centers that consist of a collection of geographically-dispersed data center locations. Since data centers are

More information

Cisco EXAM Cisco ADVDESIGN. Buy Full Product.

Cisco EXAM Cisco ADVDESIGN. Buy Full Product. Cisco EXAM - 352-001 Cisco ADVDESIGN Buy Full Product http://www.examskey.com/352-001.html Examskey Cisco 352-001 exam demo product is here for you to test the quality of the product. This Cisco 352-001

More information

Cisco Certdumps Questions & Answers - Testing Engine

Cisco Certdumps Questions & Answers - Testing Engine Cisco Certdumps 642-996 Questions & Answers - Testing Engine Number: 642-996 Passing Score: 797 Time Limit: 120 min File Version: 16.8 http://www.gratisexam.com/ Sections 1. A 2. B 3. C 4. Exhibit Case

More information

Configuring VXLAN EVPN Multi-Site

Configuring VXLAN EVPN Multi-Site This chapter contains the following sections: About VXLAN EVPN Multi-Site, page 1 Licensing Requirements for VXLAN EVPN Multi-Site, page 2 Guidelines and Limitations for VXLAN EVPN Multi-Site, page 2 Enabling

More information

Architecting Scalable Clouds using VXLAN and Nexus 1000V

Architecting Scalable Clouds using VXLAN and Nexus 1000V Architecting Scalable Clouds using VXLAN and Nexus 1000V Lawrence Kreeger Principal Engineer Agenda Session Is Broken Into 3 Main Parts Part 1: VXLAN Overview What is a VXLAN? Why VXLANs? What is VMware

More information

Data Center InterConnect (DCI) Technologies. Session ID 20PT

Data Center InterConnect (DCI) Technologies. Session ID 20PT Data Center InterConnect (DCI) Technologies Session ID 20PT Session Objectives The main goals of this session are: Highlighting the main business requirements driving Data Center Interconnect (DCI) deployments

More information

Nexus 9000/3000 Graceful Insertion and Removal (GIR)

Nexus 9000/3000 Graceful Insertion and Removal (GIR) White Paper Nexus 9000/3000 Graceful Insertion and Removal (GIR) White Paper September 2016 2016 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 21

More information

Cisco NX-OS Interfaces Commands

Cisco NX-OS Interfaces Commands This chapter describes the Cisco NX-OS interfaces commands. IF-1 attach fex attach fex To access the command-line interface (CLI) of a connected Fabric Extender to run diagnostic commands, use the attach

More information

Configuring Basic Interface Parameters

Configuring Basic Interface Parameters This chapter describes how to configure the basic interface parameters on Cisco NX-OS devices. About the Basic Interface Parameters, page 1 Licensing Requirements, page 7 Guidelines and Limitations, page

More information

PrepAwayExam. High-efficient Exam Materials are the best high pass-rate Exam Dumps

PrepAwayExam.   High-efficient Exam Materials are the best high pass-rate Exam Dumps PrepAwayExam http://www.prepawayexam.com/ High-efficient Exam Materials are the best high pass-rate Exam Dumps Exam : 642-997 Title : Implementing Cisco Data Center Unified Fabric (DCUFI) Vendor : Cisco

More information

Configuring Optional STP Features

Configuring Optional STP Features CHAPTER 29 This chapter describes how to configure optional STP features. For complete syntax and usage information for the commands used in this chapter, see the Cisco IOS Master List, at this URL: http://www.cisco.com/en/us/docs/ios/mcl/allreleasemcl/all_book.html

More information

Versatile architecture using Nexus 7000 with a mix of F and M modules to deliver FEX, FabricPath, MPLS, LISP and Multihop FCoE all at the same time

Versatile architecture using Nexus 7000 with a mix of F and M modules to deliver FEX, FabricPath, MPLS, LISP and Multihop FCoE all at the same time Versatile architecture using Nexus 7000 with a mix of F and modules to deliver FEX,, PLS, LISP and ultihop FCoE all at the same time David Klebanov Technical Solutions Architect klebanov@cisco.com Umar

More information

Configuring STP Extensions Using Cisco NX-OS

Configuring STP Extensions Using Cisco NX-OS This chapter describes how to configure Spanning Tree Protocol (STP) extensions on Cisco NX-OS devices. This chapter includes the following sections: Finding Feature Information, page 1 Information About

More information

Network-Level High Availability

Network-Level High Availability This chapter describes Cisco NX-OS network high availability and includes the following sections: Information About, page 1 Licensing Requirements, page 2 Spanning Tree Protocol, page 2 Virtual Port Channels,

More information

Configuring Rapid PVST+

Configuring Rapid PVST+ This chapter contains the following sections: Information About Rapid PVST+, page 1, page 16 Verifying the Rapid PVST+ Configuration, page 24 Information About Rapid PVST+ The Rapid PVST+ protocol is the

More information

Page 2

Page 2 Page 2 Mgmt-B, vmotion-a vmotion-b VMM-Pool-B_ Connection-B -Set-A Uplink-Set-A Uplink-Set-B ACI-DC Standard Aggregation L3 Switch Configuration for existing Layer 2 : Nexus 6K-01 switch is

More information

Configuring Q-in-Q VLAN Tunnels

Configuring Q-in-Q VLAN Tunnels Information About Q-in-Q Tunnels, page 1 Licensing Requirements for Interfaces, page 7 Guidelines and Limitations, page 7 Configuring Q-in-Q Tunnels and Layer 2 Protocol Tunneling, page 8 Configuring Q-in-Q

More information

ARISTA DESIGN GUIDE Data Center Interconnection with VXLAN

ARISTA DESIGN GUIDE Data Center Interconnection with VXLAN ARISTA DESIGN GUIDE Data Center Interconnection with VXLAN Version 1.0 November 2014 The requirement to operate multiple, geographically dispersed data centers is a fact of life for many businesses and

More information

Cisco Nexus 7000 Series NX-OS FabricPath Configuration Guide

Cisco Nexus 7000 Series NX-OS FabricPath Configuration Guide Last Modified: 2015-01-28 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 Text Part

More information

Cisco FabricPath Best Practices

Cisco FabricPath Best Practices White Paper Cisco FabricPath Best Practices Updated February 2016 2016 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information. Page 1 of 44 Contents What You Will Learn...

More information

Configuring Port Channels

Configuring Port Channels CHAPTER 5 This chapter describes how to configure port channels and to apply and configure the Link Aggregation Control Protocol (LACP) for more efficient use of port channels using Cisco Data Center Network

More information

Vendor: Cisco. Exam Code: Exam Name: Designing Cisco Data Center Unified Fabric (DCUFD) Version: Demo

Vendor: Cisco. Exam Code: Exam Name: Designing Cisco Data Center Unified Fabric (DCUFD) Version: Demo Vendor: Cisco Exam Code: 642-996 Exam Name: Designing Cisco Data Center Unified Fabric (DCUFD) Version: Demo DEMO QUESTION 1 Which three Cisco technologies or solutions are used during the virtualization

More information

Vendor: Cisco. Exam Code: Exam Name: DCID Designing Cisco Data Center Infrastructure. Version: Demo

Vendor: Cisco. Exam Code: Exam Name: DCID Designing Cisco Data Center Infrastructure. Version: Demo Vendor: Cisco Exam Code: 300-160 Exam Name: DCID Designing Cisco Data Center Infrastructure Version: Demo Exam A QUESTION 1 Which three options are features of a Cisco Nexus 7700 Switch? (Choose three.)

More information

Cisco - DCNX7K: Configuring Cisco Nexus 7000 Switches

Cisco - DCNX7K: Configuring Cisco Nexus 7000 Switches Cisco - DCNX7K: Configuring Cisco Nexus 7000 Switches Duration: 5 Days Course Price: $3,995 Course Description This course is designed primarily for systems and field engineers who install and implement

More information

FCoE Configuration Between VIC Adapter on UCS Rack Server and Nexus 5500 Switch

FCoE Configuration Between VIC Adapter on UCS Rack Server and Nexus 5500 Switch FCoE Configuration Between VIC Adapter on UCS Rack Server and Nexus 5500 Switch Document ID: 117280 Contributed by Padmanabhan, Cisco TAC Engineer. Mar 25, 2014 Contents Introduction Prerequisites Requirements

More information

Configuring VLANs. Understanding VLANs CHAPTER

Configuring VLANs. Understanding VLANs CHAPTER CHAPTER 11 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the Cisco ME 3400 Ethernet Access switch. It includes information

More information

Data Center Interconnect Solution Overview

Data Center Interconnect Solution Overview CHAPTER 2 The term DCI (Data Center Interconnect) is relevant in all scenarios where different levels of connectivity are required between two or more data center locations in order to provide flexibility

More information

VLAN Configuration. Understanding VLANs CHAPTER

VLAN Configuration. Understanding VLANs CHAPTER CHAPTER 11 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the CGR 2010 ESM. It includes information about VLAN membership

More information

Configuring Port Channels

Configuring Port Channels This chapter contains the following sections: Information About Port Channels, page 1, page 10 Verifying Port Channel Configuration, page 21 Verifying the Load-Balancing Outgoing Port ID, page 22 Feature

More information

Configuring FCoE NPV. Information About FCoE NPV. This chapter contains the following sections:

Configuring FCoE NPV. Information About FCoE NPV. This chapter contains the following sections: This chapter contains the following sections: Information About FCoE NPV, page 1 FCoE NPV Model, page 3 Mapping Requirements, page 4 Port Requirements, page 5 NPV Features, page 5 vpc Topologies, page

More information

Versatile architecture of using Nexus 7000 with F and M-series I/O modules to deliver FEX, FabricPath and Multihop FCoE all at the same time

Versatile architecture of using Nexus 7000 with F and M-series I/O modules to deliver FEX, FabricPath and Multihop FCoE all at the same time Versatile architecture of using Nexus 7000 with F and -series I/O modules to deliver FEX, and ultihop FCoE all at the same time David Klebanov Technical Solutions Architect CCIE #13791 klebanov@cisco.com

More information

Overview. Information About High Availability. Send document comments to CHAPTER

Overview. Information About High Availability. Send document comments to CHAPTER CHAPTER 1 Cisco NX-OS is a resilient operating system that is specifically designed for high availability at the network, system, and process level. This chapter describes high availability (HA) concepts

More information

Real4Test. Real IT Certification Exam Study materials/braindumps

Real4Test.   Real IT Certification Exam Study materials/braindumps Real4Test http://www.real4test.com Real IT Certification Exam Study materials/braindumps Exam : 400-101 Title : CCIE Routing and Switching Written Exam v5.1 Vendor : Cisco Version : DEMO Get Latest & Valid

More information

MC-LAG to VPLS Technology and Solution Overview

MC-LAG to VPLS Technology and Solution Overview CHAPTER 3 MC-LAG to VPLS Technology and Solution Overview Virtual Private LAN Service (VPLS) is an architecture that provides multipoint Ethernet LAN services, often referred to as Transparent LAN Services

More information

Cisco Exam Questions & Answers

Cisco Exam Questions & Answers Cisco 642-997 Exam Questions & Answers Number: 642-997 Passing Score: 900 Time Limit: 120 min File Version: 36.4 http://www.gratisexam.com/ Cisco 642-997 Exam Questions & Answers Exam Name: Implementing

More information

Question: 2 Which option accurately describes the implementation of Fabre Channel domain IDs?

Question: 2 Which option accurately describes the implementation of Fabre Channel domain IDs? Volume: 186 Questions Question: 1 What is the status of FC interface associated with ethernet 1/5 indicate? A. Trunk VSAN 11 is isolated B. Inteface vfc 5 is up and running for the assigned VSAN C. Trunk

More information

Configuring VLANs. Understanding VLANs CHAPTER

Configuring VLANs. Understanding VLANs CHAPTER CHAPTER 14 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the Catalyst 3750 switch. It includes information about VLAN

More information

Configuring VLANs. Understanding VLANs CHAPTER

Configuring VLANs. Understanding VLANs CHAPTER CHAPTER 9 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094). It includes information about VLAN membership modes, VLAN configuration

More information

Configuring Spanning Tree Protocol

Configuring Spanning Tree Protocol Finding Feature Information, page 1 Restrictions for STP, page 1 Information About Spanning Tree Protocol, page 2 How to Configure Spanning-Tree Features, page 14 Monitoring Spanning-Tree Status, page

More information

Question No: 1 What is the maximum number of switches that can be stacked using Cisco StackWise?

Question No: 1 What is the maximum number of switches that can be stacked using Cisco StackWise? Volume: 283 Questions Question No: 1 What is the maximum number of switches that can be stacked using Cisco StackWise? A. 4 B. 5 C. 8 D. 9 E. 10 F. 13 Answer: D Question No: 2 A network engineer wants

More information

Configuring STP and RSTP

Configuring STP and RSTP 7 CHAPTER Configuring STP and RSTP This chapter describes the IEEE 802.1D Spanning Tree Protocol (STP) and the ML-Series implementation of the IEEE 802.1W Rapid Spanning Tree Protocol (RSTP). It also explains

More information

Configuring VLANs. Understanding VLANs CHAPTER

Configuring VLANs. Understanding VLANs CHAPTER CHAPTER 12 This chapter describes how to configure normal-range VLANs (VLAN IDs 1 to 1005) and extended-range VLANs (VLAN IDs 1006 to 4094) on the switch. It includes information about VLAN membership

More information

Describing the STP. Enhancements to STP. Configuring PortFast. Describing PortFast. Configuring. Verifying

Describing the STP. Enhancements to STP. Configuring PortFast. Describing PortFast. Configuring. Verifying Enhancements to STP Describing the STP PortFast Per VLAN Spanning Tree+ (PVST+) Rapid Spanning Tree Protocol (RSTP) Multiple Spanning Tree Protocol (MSTP) MSTP is also known as Multi-Instance Spanning

More information

Finding Feature Information, page 2 Information About DHCP Snooping, page 2 Information About the DHCPv6 Relay Agent, page 8

Finding Feature Information, page 2 Information About DHCP Snooping, page 2 Information About the DHCPv6 Relay Agent, page 8 This chapter describes how to configure the Dynamic Host Configuration Protocol (DHCP) on a Cisco NX-OS device. This chapter includes the following sections: Finding Feature Information, page 2 Information

More information

Instant Access - Virtual Switching System Hands on Lab

Instant Access - Virtual Switching System Hands on Lab Instant Access - Virtual Switching System Hands on Lab LTRCRS 2004 Vivek Baveja Sr. Technical Marketing Lila Rousseaux Consulting System Engineer Agenda Virtual Switching Systems Concepts Instant Access

More information

Nexus 7000 Peer Switch Configuration (Hybrid Setup)

Nexus 7000 Peer Switch Configuration (Hybrid Setup) Nexus 7000 Peer Switch Configuration (Hybrid Setup) Document ID: 116140 Contributed by Andy Gossett and Rajesh Gatti, Cisco TAC Engineers. Aug 09, 2013 Contents Introduction Prerequisites Requirements

More information

Troubleshooting Cisco Data Center Infrastructure (DCIT) 6.0

Troubleshooting Cisco Data Center Infrastructure (DCIT) 6.0 Troubleshooting Cisco Data Center Infrastructure (DCIT) 6.0 Duration: 5 days; Instructor-led WHAT YOU WILL LEARN Troubleshooting Cisco Data Center Infrastructure (DCIT) is a five days instructor-led course

More information