Professional Documents
Culture Documents
BRKDCT-2334
Cisco Public
BRKDCT-2334
Cisco Public
Abstract
The seminar will discuss real world Nexus Deployment scenarios to make sure
your network will meet the demands for performance and reliability. This
session will provide and equip you with the latest information on Cisco data
centre network architecture and best practices around those designs. This
session will focus on STP, vPC, Fabric Path, QOS, routing and service node
insertion from the core of the network to the host. This session will not cover all
of the possible options just the best practices to make sure we are all
successful.
BRKDCT-2334
Cisco Public
Agenda
Fundamental Data Centre Design
Overlays
BRKDCT-2334
Cisco Public
Acronym Slide
VPC - Virtual Port Channel
VPC+ - Virtual Port Channel using Fabric Path as the protocol between the peer nodes
Fabric Path - enable highly scalable Layer 2 multipath networks without Spanning Tree
Protocol
Leaf - access node used for end node attachment
Spine - used to interconnect all leaf nodes
OTV - Overlay Transport Virtualisation
FEX - Fabric Extender
UDLD - Unidirectional Link Detection
LACP - Link Aggregation Control Protocol
SVI - Switch Virtual Interface
MCEC - Multi-chassis EtherChannel
BRKDCT-2334
Cisco Public
Problem Statement:
Cisco Public
Rack-Wide VM Mobility
DC
DC
VLAN
VLAN
VLAN
POD
POD
POD
POD
VLAN
BRKDCT-2334
Cisco Public
10
DC
POD
DC
BRKDCT-2334
DC
POD
POD
POD
VLAN
VLAN
Network protocols enable broader VM Mobility
Implementable on Virtual and Physical
Examples: VPC, FabricPath/TRILL, VXLAN
WAN
DC
Cisco Public
11
IDS/IPS
Client Routing
Cisco Public
12
Aggregation
Layer 3 Links
Layer 2 Trunks
Access
Remote
Access
Cisco Public
13
Enterprise Network
Border Leaf
L2 Links
Routed Links
Spine
L2 / L3 boundary
Routed Links
Leaf
Layer 2 Trunks
Remote
Access
Cisco Public
Oversubscription Ratio
Access to Core/Aggregation
Line Cards
1:1
(3:1)*(1:1)
Aggregation
Oversubscription
Ratios
4:1 to 12:1
Access
16 10 GEs
48 10 GEs
48:16=3:1
Cisco Public
15
Oversubscription Ratio
Goal 12:1 to 4:1 and
Line Cards 1:1
(4:1)*(12:1)*(1:1)
(4:1)*(6:1)*(1:1)
48:1 Oversubscription
24:1 Oversubscription
Aggregation
4 10 GEs
8 10 GEs
48 10 GEs
48 10 GEs
48:4=12:1
48:8=6:1
Access
Access
16 Servers
8 10 GEs
8 10 GEs Possible
32 10 Gs
Using 4
32:8=4:1
4 10 GEs
16 10 Gs
16:4=4:1
BRKDCT-2334
Cisco Public
16
Consistent Latency
Cisco UCS enclosuure
active/active
data path
BRKDCT-2334
Cisco Public
17
Spine
Oversubscription
Leaf
8 40 GEs
48 10 GEs
48:32=1.5:1
Ratios defined by
number of spines and
uplink ports
True horizontal scale
BRKDCT-2334
Cisco Public
18
MTP Panel
BRKDCT-2334
MTP to LC Panel
MTP Jumper
MTP to 8 LC breakout
Cisco Public
MTP Trunk
(12-144 Fibre)
With CSR4 and SR4 you lose 33% of the fibre capacity.
BRKDCT-2334
Cisco Public
QSFP SR4/CSR4
QSFP-BIDI
TX
TX/RX
4 x 10G
12-Fibre
infrastructure
2 x 20G
12-Fibre
infrastructure
Duplex
Multimode
Fibre
4 x 10G
RX
2 x 20G
Duplex
Multimode
Fibre
TX/RX
QSFP-BIDI
Cisco Public
Code Version
Nexus 9000
FCS
Nexus 7700
Nexus 7000
QSFP+ SKU
Cable
Type
Nexus 600X
7.0.1N1
QSFP-40GSR-BD
850nm
LC Duplex
100m (OM3)
125m (OM4)
Nexus 3100
6.0.2A
BRKDCT-2334
Cisco Public
UDLD Behaviour
UDLD is running as a conditional feature, it needs to be enabled:
NEXUS(config)# feature udld
Tx
Rx
Tx
Rx
Cisco Public
24
Port-Channel
Link Aggregation - IEEE 802.3ad
Active/Active
Recommended
LACP rate
normal
Channel
interface eth1/1
channel-group 1 mode <Active|Passive|On>
Recommendation:
Recommended
interface eth1/1
channel-group 1 mode active
lacp rate <normal|fast>
Recommendations:
BRKDCT-2334
Cisco Public
25
Protect STP root switch by enforcing root guard on its physical ports
Spanning Tree costs without pathcost method long may provide unusual results
NX-OS(config)# spanning-tree guard root
BRKDCT-2334
Cisco Public
26
system qos
service-policy type network-qos jumbo
Each qos-group on the
Nexus 5000/3000 supports a
unique MTU
Nexus 6000
Interface ethernet 1/x
Mtu 9216
BRKDCT-2334
Cisco Public
27
interface Vlan10
ip address 10.87.121.28/27
mtu 9216
default 9216
Layer 3 MTU changed under Interface
Nexus 7000 FCoE policy sets MTU
lower per policy-map than jumbomtu
Interface MTU overrides network-qos
mtu 2112
BRKDCT-2334
Cisco Public
28
N
-
N
E
B
R
L
N
R -
E
B
N
E
B
Network port
Edge or Edge Trunk
Normal port type
BPDUguard
Rootguard
Loopguard
E
B
E
B
E
B
E
B
POD
Cisco Public
29
MCEC
vPC Peers
MCEC
Cisco Public
30
NX7K-2
to a vPC Domain
Recommendations:
Access device to support
vPC
vPC
Cisco Public
31
vPC Peer-switch
Unified STP Root with vPC: Improving Convergence
STP Root
VLAN 1
VLAN 2
vPC Primary
vPC Secondary
Bridge Priority
VLAN 1 4K
VLAN 2 4K
vPC Peer-link
S1
S2
vPC2
S3
S4
Cisco Public
32
vPC Peer-Gateway
RMAC A
RMAC B
L3
vPC PKL
L2
vPC PL
vPC1
vPC2
Nexus7K(config-vpc-domain)# peer-gateway
Note: Disable IP redirects on all interfacevlans of this vPC domain for correct
operation of this feature
BRKDCT-2334
See notes section
for more information
Recommendation:
Cisco Public
33
HSRP/VRRP
Standby: Active
for shared L3 MAC
L3
L2
Recommendations:
Do not tune HSRP timers (use default ones)
Cisco Public
34
L3 network
L3 link
L3
L2
VPC Domain 100
Cisco Public
35
L3 network
SVI
SVI
N6K-1
N6K-2
L3
L2
L3 network
L3
N6K-1
N6K-2
L2
L3 link
BRKDCT-2334
Cisco Public
36
L3
VLAN 99
OSPF/EIGRP
L2
Primary
vPC
Secondary
vPC
vpc domain 10
...
P
Cisco Public
37
Cisco Public
38
Cisco Public
BRKDCT-2334
Cisco Public
40
Default Queue
Mapping
COS Values
Buffer
Allocated
Queue 0
COS 0 to COS 4
90% 1.35 MB
Queue 1
COS 5 to COS 7
10% 0.15 MB
http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/MSDC/1.0/MSDC1_C.html#wp1120251
BRKDCT-2334
2014 Cisco and/or its affiliates. All rights reserved.
Cisco Public
Default Queue
Mapping
COS Values
Buffer
Allocated
Queue 0
COS 0 to COS 3
50% 2.6 MB
Queue 1
COS 4 to COS 7
50% 2.6 MB
BRKDCT-2334
Cisco Public
10Gbps
Shared
Storage array
UPC
40Gbps
16 MB
Ingress
25 MB
Egress
16 MB
Ingress
25 MB
40Gbps
9 MB
9 MB
Egress
10Gbps
Ingress UPC
Ingress
Buffer
SHARED
Egress
Buffer
Unicast
Control
Dedicated
Pool 1
Multicast
SPAN
Pool 2
Pool 1
Egress UPC
Default class
Cisco Public
Default
Pool 3
Pool 4
Pool 2
So what about
Snap Mirror Traffic
Long Distance VMotion
Video Bridging
Voice Transcoding
Clustering Traffic
Replication Traffic
DC1
BRKDCT-2334
DC3
Cisco Public
BRKDCT-2334
Enterprise Network
Cisco Public
46
2232
2232
BRKDCT-2334
2248
2248
2248
2248
2248
2248
2248
Cisco Public
47
For Your
Reference
F3
F3
Topology Description
Scale Attributes
64K MAC Table size (4 times F2e scale)
64K FIB Table size (2 times F2e scale)
BRKDCT-2334
Cisco Public
For Your
Reference
Topology Description
F3
Scale Attributes
64 FEX with SUP2E
64K MAC Table size (4 times F2e scale)
64K FIB Table size (2 times F2e scale)
BRKDCT-2334
VM
#2
VM
#3
VM
#4
Cisco Public
Enterprise Network
Layer 3 Links
Layer 2 Trunks
Aggregation
Access
BRKDCT-2334
Cisco Public
50
Enterprise Network
Layer 3 Links
Layer 2 Trunks
Access
UCS
C-Series
BRKDCT-2334
Cisco Public
51
Nexus
7x00
Series
Investment Protection
Multi-Protocol / Services
17 Tbps
Nexus
6004
Up to 7.68 Tbps
BRKDCT-2334
Cisco Public
52
Layer 2 Trunks
Aggregation
BRKDCT-2334
Cisco Public
53
eBGP
Aggregation tier.
eBGP to provide routing into Data Centre
against Loopback interfaces, multihop
BRKDCT-2334
eBGP
Layer 3 Links
Layer 2 Trunks
Aggregation
Access
Cisco Public
54
BRKDCT-2334
Layer 3 Links
Layer 2 Trunks
Aggregation
Cisco Public
55
BRKDCT-2334
Layer 2 Trunks
Aggregation
Access
Cisco Public
56
Enterprise Network
POD
BRKDCT-2334
Cisco Public
58
Dial in
Oversubscription
here
Active Active uplinks
cause more peerlink
traffic
Embedded
switches offer poor
trouble shooting.
LACP easier than
VPC
Active active or
active Passive
POD uplinks. Active
Active can break
local switching
Cisco Public
59
VPC to Northbound
switch
Dial in
Oversubscription
here to access tier
Port Channel between
IOM and FI
POD
BRKDCT-2334
Cisco Public
60
Enterprise Network
Cisco Public
61
Enterprise Network
62
Enterprise Network
POD
BRKDCT-2334
Cisco Public
63
Scaling Limitations
F3 Modules today support 64K MAC addresses
F2 and F2e Modules today support 16k MAC addresses
Cisco Public
64
EtherChannel/vPC Maximums
Nexus 7000 Verified
Nexus 7000 Verified
Nexus 7000 Verified
Nexus 7000 Verified
Feature
Limit (Cisco NX-OS 6.2) Limit (Cisco NX-OS 6.1) Limit (Cisco NX-OS 6.0) Limit (Cisco NX-OS 5.2)
Port Channels Per System
744
528
528
384
Virtual Port Channels ( vPCs) (total)
per system
744
528
528
244
Number of vPCs (FEX) per system
528
528
528
244
244
244
244
244
Feature
Nexus 6000
Verified Topology
Nexus 6000
Verified Maximum
Nexus 5548
Verified Maximum
Nexus 5596
Verified Maximum
48
96
576
576
48
576
BRKDCT-2334
Cisco Public
65
CFS
vPC Domain 20
CFS
BRKDCT-2334
Cisco Public
66
Cisco Public
67
Enterprise Network
POD
BRKDCT-2334
Cisco Public
69
Enterprise Network
POD
BRKDCT-2334
Cisco Public
70
Built-in loop-mitigation
Time-to-Live (TTL)
RPF Check
BRKDCT-2334
Cisco Public
71
FabricPath
Header
S11
C
S11
A
DATA
S11
Ingress Switch
STP
FabricPath
Domain
A
FabricPath Routing
S42
S42
Egress Switch
C
A
A
STP Domain 1
STP Domain 2
DATA
A
BRKDCT-2334
A
2014 Cisco and/or its affiliates. All rights reserved.
Cisco Public
L2 Bridging
C
72
IF
S1
L1
S2
L2
S3
L3
S4
L4
S12
S42
BRKDCT-2334
S1
L1
S11
S2
S3
S4
L2L3
L4
S12
L2 Fabric
Cisco Public
S42
73
Switch
IF
S42
IF
1/1
S42
L1
S11
L2
L3
L4
S2
S12
S3
S4
L2 Fabric
S42
1/1
A
BRKDCT-2334
C
Cisco Public
74
OTV
OTV
vPC
L3
Domain
vPC
Border LEAF
SPINE
Port Channels
L2
Domain
LEAF
vPC+
domain 2
vPC+
domain 3
FP L2 link
CE L2 link
L3 link
BRKDCT-2334
Cisco Public
75
Active HSRP
Active HSRP
Switch-id
122
Switch-id
121
vPC+
Switch-ID
111
Switch-ID
112
Switch-ID
113
BRKDCT-2334
Cisco Public
76
Active
HSRP
Standby
HSRP
vPC
Primary
Po
10
Po1
SW1
Po2
Po1
SW2
Po2 Po1
Po2
Po1
SW4
SW3
Backup routing
path
BRKDCT-2334
Recommendation:
Po2
2 L2 port-channel trunk.
Use a dedicated VLAN (in CE mode) as
transit VLAN inside this L2 trunk link.
3 Use vPC+ Peer-Link. Use a dedicated
VLAN (in FP mode) as transit VLAN ( N6K
required Mode)
Cisco Public
77
vPC+
domain
Emulated
Switch
SW1
SW2
SW3
Active
HSRP
Root for
FTAG 2
SW4
Active
HSRP
Root for
FTAG 1
Cisco Public
78
SW-1
Host1
SW-3
Po300
PO101
FEX
101
Host2
BRKDCT-2334
PO102
FEX
102
Host3
Host4
Cisco Public
79
Switch
-id
122
Switch
-id
121
Int eth1/5
vpc orphan-port
suspend
Switch-ID
111
Primary
peer
vPC+
Secondary
peer
Switch-ID
112
Emulated
Switch-ID
100
Host1
Recommendation:
Hos
t4
FEX101
Host3
Host2
Cisco Public
SW
1
SW
2
80
FabricPath - vPC+
vPC+ And Network Services
FP fabric
ASA keep-alive
link
vPC+
S1
S2
vPC+
vPC+
vPC+
ASA
Active
ASA
Standby
CE-2
CE-1
BRKDCT-2334
Cisco Public
81
FabricPath - vPC+
vPC+ And ASA in Transparent Mode
FP fabric
ASA keep-alive
link
vPC+
S1
S2
Po1
Po1
vPC+
Transparent
mode
Transparent
mode
vPC+
vPC+
ASA
Active
ASA
Standby
CE-1
CE-2
Cisco Public
82
FabricPath - vPC+
vPC+ And ASA in Transparent Mode
Logical
topology
interface Port-channel1.200
vlan 200
nameif outside
bridge-group 1
security-level 0
S2
S1
SVI
200
SVI
200
vPC+
vPC+
CE-1
interface Port-channel1.100
vlan 100
nameif inside
bridge-group 1
security-level 100
interface Port-channel1.100
vlan 100
nameif inside
bridge-group 1
security-level 100
interface Port-channel1.200
vlan 200
nameif outside
bridge-group 1
security-level 0
FP fabric
CE-2
VLAN 100
Cisco Public
83
OTV
vPC
Border LEAF
vPC
Primary/Second
ary Multicast
Roots
L3
Domain
SPINE
Port Channels
LEAF
vPC+
domain 2
L2
Domain
vPC+
domain 3
FP L2 link
CE L2 link
L3 link
vPC
BRKDCT-2334
Cisco Public
84
Spine
Enterprise
Core
FCoE
iSCSI
NAS
Nexus 6001
Leaf
10 or 1-Gig attached
UCS C-Series
BRKDCT-2334
UCS B-Series
Systems
10 or 1-Gig attached
UCS C-Series
Cisco Public
OTV/DCI
85
Bundled functions are modular and simplified for scale and automation
Optimised
Fabric
Network
Management
BRKDCT-2334
Virtual
Workload
Fabrics
Automation
Optimised
Fabric
Network
Management
Virtual
Workload
Fabrics
Automation
Cisco Public
87
BRKDCT-2334
Cisco Public
88
Folded CLOS
L3 Cloud
L3 Cloud
Full Mesh
Three Tiers (Fat Tree)
L3 Cloud
BRKDCT-2334
L3 Cloud
Cisco Public
89
Control Plane
1 - IS-IS as Fabric Control Plane
L3 Core
Host Routes
Host originated control traffic
Server subnet information
BRKDCT-2334
IS-IS Adjacencies
Cisco Public
90
Control Plane
Control External
Subnet Route Injection
L3 Cloud
ARP, ND, IGMP, DHCP originated on servers are terminated on Leaf nodes
Contain floods and failure domains, distribute control packet processing
Terminate PIM, OSPF, eBGP from external networks on Border Leafs
BRKDCT-2334
Cisco Public
91
Control Plane
RR
External Subnet
Route Injection
Fabric Host/Subnet
Route Injection
L3 Cloud
iBGP Adjacencies
Host Route Distribution decoupled from the Fabric link state protocol
Use MP-BGP on the leaf nodes to distribute internal host/subnet routes and
external reachability information
MP-BGP enhancements to carry up to 100s of thousands of routes and
reduce convergence time
BRKDCT-2334
Cisco Public
92
Optimised Network
Distributed Gateway at the Leaf
Anycast Gateway
L3
L2
GW IP: 10.10.10.1
GW MAC:
0011:2222:3333
GW IP: 11.11.11.1
GW MAC:
0011:2222:3333
Any subnet anywhere => Any leaf can instantiate any subnet
All leafs share gateway IP and MAC for a subnet (No HSRP)
ARPs are terminated on leafs, No Flooding beyond leaf
Cisco Public
Optimised Network
IP Forwarding within the Same Subnet
S3
1.
2.
3.
BRKDCT-2334
L1 RIB
10.10.10.20/32 NH L4_IP
L1 ARP Table
L4_IP L4_MAC
CPU
L1
L4
vSwitch
H1
10.10.10.10
H2
10.10.10.20
H1 ARP Cache
10.10.10.20 G_MAC
Cisco Public
94
Optimised Network
IP Forwarding within the Same Subnet (2)
S1
S2
S3
DSID L4
4.
5.
6.
7.
SSID L1
DMAC L4_MAC
SMAC L1_MAC
DIP 10.10.10.20
SIP 10.10.10.10
L4 RIB
L1 RIB
10.10.10.20/32 e1/1
10.10.10.20/32 NH L4_IP
L1 ARP Table
L4_IP L4_MAC
L1
L4
e1/1
DMAC G_MAC
SMAC G_MAC
SMAC H1_MAC
DIP 10.10.10.20
DIP 10.10.10.20
SIP 10.10.10.10
H1
10.10.10.10
H2
10.10.10.20
10.10.10.20 G_MAC
vSwitch
SIP 10.10.10.10
H1 ARP Cache
BRKDCT-2334
DMAC H2_MAC
Cisco Public
95
Optimised Network
Introducing L3 Conversational Learning
Use of /32 host routes may lead to scaling issues if all the routes are installed in the
HW tables of all leaf nodes
L3 conversational learning is introduced to alleviate this concern
Disabled by default all host routes are programmed in the HW
With L3 conversational learning, host routes for remote endpoints will be programmed
into the HW FIB (from the SW RIB) upon detection of an active conversation with a
local endpoint
Default Behaviour (No L3 Conversational Learning)
L1 RIB
10.1.1.20/32 NH L2_IP
10.1.2.10/32 NH L3_IP
10.1.1.20/32 NH L2_IP
10.1.2.10/32 NH L3_IP
L1 FIB
L1 FIB
10.1.1.20/32 NH L2_IP
10.1.2.10/32 NH L3_IP
10.1.1.20/32 NH L2_IP
L1
L2
L2
L3
L3
L1
L2
L2
vSwitch
H1
10.1.1.10
BRKDCT-2334
H2
10.1.1.20
H3
10.1.2.10
L3
L3
vSwitch
H1
10.1.1.10
H2
10.1.1.20
Cisco Public
H3
10.1.2.10
96
Finance
Manufacturing
Sales
Advantages
Any workload, any vFabric, rapidly
Scalable Secure vFabrics
BRKDCT-2334
Cisco Public
97
Virtual Fabrics
Introducing Segment-ID Support
FabricPath Frame Format
Traditionally VLAN space is expressed
over 12 bits (802.1Q tag)
Limits the maximum number of segments in a
data centre to 4096 VLANs
BRKDCT-2334
Cisco Public
802.1Q
802.1Q
98
Virtual Fabrics
802.1Q Tagged Traffic to Segment-ID Mapping
Fabric
802.1q Trunks
802.1q Trunk
VLANs
VLANs
Segment-IDs (Global)
Cisco Public
99
Auto-config Triggers
VDP
DHCP/ARP-ND
N1kv/OVS
Virtual Machines
DCNM (CPoM)
Physical Machines
*VDPBRKDCT-2334
(VSI Discovery and Configuration
Protocol)
IEEE All
802.1Qbg
Clause 41
2014
Cisco and/or is
its affiliates.
rights reserved.
Cisco Public
100
Overlays
Robust Underlay/Fabric
High Capacity Resilient Fabric
Flexibility/Programmability
Reduced number of touch points
BRKDCT-2334
Cisco Public
102
V
M
1
V
M
2
V
M
3
Virtual
Switch
IP Addr
1.1.1.1
IP Network
IP Addr
2.2.2.2
V
M
4
Virtual
Switch
IP/UDP Packets
Hypervisor
BRKDCT-2334
Hypervisor
Cisco Public
V
M
5
V
M
6
Cisco Public
16 M logical networks
Mapped into local bridge domains
Outer
MAC
DA
Outer
MAC
SA
Outer
802.1Q
Outer IP
DA
Outer IP
SA
Outer
UDP
VXLAN ID (24
bits)
Inner
MAC
DA
VXLAN Encapsulation
BRKDCT-2334
Inner
MAC
SA
Optional
Inner 802.1Q
Original
Ethernet
Payload
CRC
NVGRE: IETF draft assumes end points knows destination via management
plane provisioning, control plane distribution, or data plane learning
BRKDCT-2334
Cisco Public
NVGRE
Tunnel between End Points
16 M logical networks
Mapped into local bridge domains
Outer
MAC
SA
GRE
Header
Inner
Virtual
MAC DA
Subnet ID (24
bits)
NVGRE Encapsulation
BRKDCT-2334
Outer
MAC
DA
Inner
MAC
SA
Optional
Inner 802.1Q
Original
Ethernet
Payload
CRC
Controller, management/provisioning
Gateway Nodes: provide connectivity for Physical and non-NSX-OVS Nodes
BRKDCT-2334
Cisco Public
Packet
* Ident
F
L
A
G
M
VLAN Context
S
ID
ID
S
Inner
MAC
DA
STT Header
Inner
MAC
SA
CRC
Original
Ethernet
Payload
Cisco Public
Cisco Public
110
What is a vApp?
A Cloud Provider using vCloud Director offers catalogs of vApps to their Users
When cloned, new vApps retain the same MAC and IP addresses
Duplicate MACs within different vApps requires L2 isolation
Duplicate IP addresses requires L2/L3 isolation (NAT of externally facing IP
addresses)
Usage of vApps causes an explosion in the need for isolated L2 segments
vApp
vApp App Net
vApp DB Net
DB
VMs
BRKDCT-2334
App
VMs
Web
VMs
Org Network
Edge
Gateway
Cisco Public
111
IP1
GWY
vxlan 1
web
vxlan 2
V
M
db
V
M
web
vxlan 21
V
VSG M
vxlan 22
V
appvxlan 3M
db
BRKDCT-2334
GWY
V
M
app
IP1
V
M
VSG
vxlan 23
Cisco Public
112
GREEN
VXLAN L2
Gateway
green segment
VXLAN-to-VXLAN Routing
VXLAN
(L3 Gateway)
Ingress VXLAN packet on
SVI
VXLANBLUE
GREEN
VXLAN
Router
green segment
VXLAN-to-VLAN Routing
(L3 Gateway)
SVI
VXLANGREEN
VXLAN
Router
Cisco Public
DB
VMs
BRKDCT-2334
VXLAN 5501
App
VMs
VXLAN 5502
VLAN 55
CSR 1000V,
ASA 1000V
1kv Gateway
Web
VMs
Cisco Public
Fault
Domain
Fault
Domain
LAN Extension
Fault
Domain
BRKDCT-2334
North
Data
Centre
Cisco Public
Fault
Domain
Path Optimisation
Optimal Routing Challenges
Layer 2 extensions represent a
challenge for optimal routing
Challenging placement of
gateway and advertisement of
routing prefix/subnet
Ingress Routing
Localisation:
Clients-Server
Hypervisor
Egress Routing Localisation:
BRKDCT-2334
Server-Client
Hypervisor
Server-Server
116
Path Optimisation
Egress Routing with LAN Extension
Extended VLANs typically have associated HSRP groups
By default, only one HSRP router elected active, with all servers
pointing to HSRP VIP as default gateway
Result: sub-optimal (trombone) routing
HSRP Hellos
HSRP
Active
HSRP
Standb
y
HSRP
Listen
HSRP
Listen
VLAN
20
BRKDCT-2334
Cisco Public
VLAN
10
117
Path Optimisation
Egress Routing with LAN Extension
Extended VLANs typically have associated HSRP groups
By default, only one HSRP router elected active, with all servers pointing to
HSRP VIP as default gateway
ARP for
HSRP VIP
ARP
reply
HSRP
Active
HSRP
Standb
y
HSRP
Listen
HSRP
Listen
VLAN
20
BRKDCT-2334
Cisco Public
VLAN
10
118
Path Optimisation
Egress Routing with LAN Extension
Extended VLANs typically have associated HSRP groups
By default, only one HSRP router elected active, with all servers pointing to
HSRP VIP as default gateway
Result: sub-optimal (trombone) routing
Packet from
Vlan 10 to Vlan 20
DMAC = DGW
Routing
HSRP
Active
HSRP
Standb
y
HSRP
Listen
HSRP
Listen
Packet from
Vlan 10 to Vlan 20
DMAC = Host Vlan 20
VLAN
20
BRKDCT-2334
Cisco Public
VLAN
10
119
HSRP Hellos
HSRP
Active
HSRP Filtering
HSRP
Standb
y
HSRP
Active
HSRP
Standb
y
ARP
reply
ARP for
HSRP VIP
Cisco Public
VLAN
20
VLAN
10
120
ISP B
Layer 3 Core
Data Centre
A
HSRP
Active
Data Centre
B
HSRP
Standby
HSRP
Active
HSRP Filtering
HSRP
Standby
Public Network
Agg
VLAN A
Asymmetrical flows
No Stateful device
Low ingress traffic
Access
Node A
HA cluster Node A
HA cluster Node B
Cisco Public
Scale
Intra-DC
Inter-DC
Layer 2 connectivity
FabricPath, VXLAN
OTV, VPLS
IP Mobility
LISP, OTV
Secure Segmentation
VXLAN / Segment-ID
LISP, MPLS-IP-VPNs
LISP
IP mobility
(Inter-DC)
IP Network
DC-west
DC-east
POD
POD
App
App
App
OS
OS
OS
Fabric Path
(Intra-DC L2)
BRKDCT-2334
POD
POD
OTV, VPLS
(Inter-DC L2-x-L3)
App
App
App
OS
OS
OS
Fabric Path
(Intra-DC L2)
2014 Cisco and/or its affiliates. All rights reserved.
Cisco Public
EF, LISP
(Intra-DC mobility)
Recommended Reading
BRKDCT-2334
Cisco Public
123
Q&A
BRKDCT-2334
Cisco Public
125