Professional Documents
Culture Documents
GENIUS
What are Best Practices ?
ACI
VXLAN
VPC
2014-2015
STP
2013-2014
2010
2010
2009
2008
Why vPC in 2015 ?
12
vPC is Foundation
Role of vPC in the Evolution of Data Center
• vPC launched in 2009
S1 S2
S1 S2 S1 S2
S3 S3
S3
STP vPC Physical Topology vPC Logical Topology
Layer 3 Cloud
vPC vPC Domain vPC Peer
Peer Keepalive Link
Peer-Link
Orphan
CFS S2
Port S1
vPC Member
vPC Port
Orphan
Device S3
For Your
vPC Failure Scenario Reference
• vPC peer-keepalive up
• Status of other vPC peer known
vPC_PLink
• Both peers Active Suspend secondary
vPC Member Ports
• Secondary vPC peer disables all vPC’s
vPC1 vPC2
• Traffic from vPC primary.
• Orphan devices connected to secondary peer will SW3 SW4
be isolated
Keepalive Heartbeat
P Primary vPC
S Secondary vPC
vPC Failure Scenario – Dual Active For Your
Reference
vPC Peer-Keepalive down followed by vPC Peer-Link down
1. vPC peer-keepalive DOWN
P P
S
vPC Peer-keepalive
2. vPC peer-link DOWN
3. DUAL-ACTIVE or SPLIT BRAIN
vPC_PLink
• vPC primary peer remains primary and Traffic Loss / Uncertain Traffic
secondary peer becomes operational primary Behavior
role vPC1 vPC2
1. Define domains S1 S2
2. Establish Peer Keepalive connectivity
4. Create vPCs
S3
vPC Configuration Best Practices
vPC Domain-ID vPC Domain 10
S3 S4
! Configure the vPC Domain ID – It should be unique within the layer 2
domain
NX-1(config)# vpc domain 20
S5
vPC Configuration Best Practices
vPC Peer-Link
S1 S2
S1 S2
S3
S3
S4
S3
S5
N7k(config-vpc-domain)# peer-gateway
vPC Configuration Best Practices
vPC Peer-switch
Primary Secondary
vPC vPC
Without Peer-switch
BPDUs
• STP for vPCs controlled by vPC primary.
• vPC primary send BPDU’s on STP designated ports
• vPC secondary device proxies BPDU’s to primary
N7k(config-vpc-domain)# peer-switch
vPC Configuration Best Practices
PVLAN on vPC
• PVLAN configuration across both VPC switches
should be identical
• PVLAN configuration not supported on Peer- vPC Primary vPC Secondary
Link
• Type-1 Compatibility Check S1 S2
• Port mode is a type-1 check P P
• vPC leg brought down if PVLAN port mode PVLAN- PVLAN-
PROMISC PROMISC
different on vPC legs (3500, 3501) (3500, 3501)
S1 S2 S1 S2
P P I I
S1 S2
Type 1 I T
Consistency
Failure
S3
vPC Configuration Best Practices
PVLAN VPC type 2 Consistency Check
S1 S2 S1 S2
P P I I
S1 S2
Type 2 I I
Consistency
Failure Secondary
Trunk (3,31)
Secondary
Trunk (2,31)
(2,30), (4,100) S3 (3,30), (4,100)
vPC Configuration Best Practices
vPC auto-recovery
Operational
Primary
P S P S
P
S1 S2 S1 S1
S2 S2
S3 S3 S3
1. vPC peer-link down : S2 - secondary shuts all its vPC member ports
2. S1 down : vPC peer-keepalive link down : S2 receives no keepalives
3. After 3 keepalive timeouts, S2 changes role and brings up its vPC P
vPC Primary
S vPC Secondary
vPC Configuration Best Practices For Your
vPC auto-recovery Reference
How it works
• If Peer-link is down on secondary switch, 3 consecutive missing peer-keepalives will
trigger auto-recovery
• After reload (role is ‘none established’) auto-recovery timer (240 sec) expires while
peer-link and peer-keepalive still down, autorecovery kicks in
• Switch assumes primary role
• VPCs are brought up bypassing consistency checks
Always use identical line cards on either sides of the peer link and VPC legs !
Examples
X Y vPC
vPC Primary vPC Secondary
N9K-X9636PQ N9K-X9432PQ
S1 S2 S1 S2
N7000 N7700
N5500 N5600
FHRP FHRP
“Active”: “Standby”:
Active for Active for
shared L3 MAC shared L3 MAC
S1 S2
S3 S4
Cluster
Data Link
VPC
Nexus 2000 (FEX)Active-Active Deployment with VPC
S1 S2
interface e101/1/1
Port-channel vPC switchport Physical port vPC
vpc 1
lacp mode active
CORE
CORE
B BPDUguard
E F F E
- - F BPDUfilter
N N R Rootguard
802.1AE (Optional)
N N
- E F F E -
R
R -
- - R R
AGGR
AGGR
N N N N
- -
- -
R R
R R
vPC domain 10 vPC domain 20
ACCESS
ACCESS
- -
E E
B B
PROS
• vPC is easy to configure and it provides robust and resilient interconnect
solution
CONS
• Maximum of only two Data Centers can be interconnected
• Layer 3 peering between Data Centers cannot be done through vPC and
separate links are required
Design Best Practices
vPC -Data Center Interconnect (DCI)
L3 Cloud
• Peering Firewalls in routed mode over vPC
• Firewalls may be in active-standby mode
• Static routing / L3 P2P links NOT required
S2
S1
• External and internal traffic traverse same
port channel to firewall.
FW-A FW-B
P P P P
P P
Note : Supported only in Nexus 7X00 on F3 and F2E Line Cards starting from release 7.2.
Supported on Nexus 9X00 in ACI mode
Currently not supported on Nexus 5X00, Nexus 3X00, Nexus 9X00 (standalone mode), Nexus 7000 M-series Line card
Dynamic routing over vPC
Supported Designs
STP inter-connection using a vPC VLAN Orphan device with vPC peers over vPC VLAN
P P P P
P
P
Note : Supported only in Nexus 7X00 on F3 and F2E Line Cards starting from release 7.2.
Supported on Nexus 9X00 in ACI mode
Currently not supported on Nexus 5X00, Nexus 3X00, Nexus 9X00 (standalone mode), Nexus 7000 M-series Line card
Dynamic Routing over vPC
Devices without L3 over vPC support
• Don’t attach routers to VPC domain via L2 port-channel
• Common workarounds:
• Individual L3 links for routed traffic
• Static route to FHRP VIP
A B
L3 ECMP S2 S1 S2
S1 S2 S1
Source Receivers
vPC : Get it Right the very First time
Agenda
Note : This Feature is currently not supported on Nexus 3X00 and 9X00 series
Graceful Insertion and Removal
vPC vPC
One command!
Pre-change System Snapshot
Graceful Insertion and Removal
vPC vPC
One command!
Pre/Post-change Snapshot Comparison
Graceful Insertion and Removal
• Flexible framework providing a comprehensive, systemic method to isolate a
node.
• Configuration profile foundation in NX-OS
• Initial support for:
• vPC/vPC+
• ISIS
• OSPF
• EIGRP
• BGP
• Interface Platform Release
Nexus 5x00/6000 NX-OS 7.1
• Per VDC on Nexus 7x00
Nexus 7x00 NX-OS 7.2
Nexus 9000 NX-OS 7.X
ISSU / ISSD with vPC
• ISSU is the recommended system upgrade in a
multi-device vPC environment
• vPC system can be independently upgraded with
no disruption to traffic
• Upgrade is serialized and must be run one peer at
a time (config lock will prevent synchronous
upgrades) 5.2(x) / 6.2(x)
FabricPath
CE FP
CE Port FP Port
CE VLAN’s FP VLAN’s
vPC vPC+
• Physical architecture of vPC and vPC+ is the same from the access edge
• Functionality/Concepts of vPC and vPC+ are the same
• Key differences are addition of Virtual Switch ID and Peer Link is a FP Core Port
• vPC+ is not supported on Nexus 9X00 & Nexus 3X00 Series
Dynamic Routing over vPC+
• Layer 3 devices can form routing adjacencies with
both the vPC+ peers over vPC Fabricpath Core
N55xx, N56xx,
N6000
Router/ Firewall
Fabricpath Link P
Dynamic Peering Relationship
P Routing Protocol Peer
vPC with FCoE
LAN Fabric
Unified Fabric Design Fabric A Fabric B
14 Bytes
(4 bytes optional) 20 Bytes 8 Bytes 8 Bytes
VXLAN Port
UDP Length
Reserved
RRRR1RRR
IP Header
MAC Addr.
Misc Data
MAC Addr.
Reserved
Checksum
VLAN Type
Ether Type
Checksum
Src. Port
Protocol
Dst. IP
VLAN ID
Outer
Header
0x8100
Src. IP
0x0000
0x0800
Outer
0x11
VNID
VXLAN
UDP
Dst.
Src.
Tag
48 48 16 16 16 72 8 16 32 32 16 16 16 16 8 24 24 8
Transport IP Network
VTEP VTEP
IP Interface IP Interface
interface loopback 0
ip address <VTEP individual IP - orphan>
ip address <VTEP anycast IP – per VPC domain> secondary
!
interface nve1
source-interface loopback0
member vni 10000 mcast-group 235.1.1.1
H1 H2
10.10.10.10 10.10.10.20
VLAN 10 VLAN 10
(vpc) (vpc)
VXLAN & VPC For Your
Reference
VPC Configuration
VTEP1 VTEP3
vlan 10 vlan 10
vn-segment 10000 vn-segment 10000
APIC
APIC
APIC
ACI uses a policy based approach
that focuses on the application.
QoS QoS QoS
Web App DB
External
Network
vPC and ACI
vPC
ACI fabric utilised for control-plane vPC peers
Domains
• No dedicated peer-link between vPC peers:
Fabric itself serves as the MCT
ACI
• No out-of-band mechanism to detect peer fabric
liveliness: vtep vtep
1 2
• Scalability
vPC Scalability
For Latest Scalability numbers please refer to the scalability limits pages for the platform
Nexus 7X00
http://www.cisco.com/en/US/docs/switches/datacenter/sw/verified_scalability/b_Cisco_Nexus_7000_Series_NX-OS_Verified_Scalability_Guide.html
Nexus 5X00
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5600/sw/verified_scalability/701N11/b_N5600_Verified_Scalability_701N11/b_N6000_Verified_
Scalability_700N11_chapter_01.html
Nexus 600X
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus6000/sw/verified_scalability/602N21/b_N6000_Verified_Scalability_602N21/b_N6000_Verified_
Scalability_602N12_chapter_01.html
Nexus 9X00
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/7-x/scalability/guide_703I12/b_Cisco_Nexus_9000_Series_NX-
OS_Verified_Scalability_Guide_703I12.html
Nexus 3X00
http://www.cisco.com/en/US/docs/switches/datacenter/nexus3000/sw/configuration_limits/503_u5_1/b_Nexus3k_Verified_Scalability_503U51.html
84
Agenda
• Reference Material
Reference Material For Your
Reference
• Fabrcipath whitepaper :
http://www.cisco.com/c/en/us/products/collateral/switches/nexus-7000-series-switches/white_paper_c11-687554.html
ACI Overview
http://www.cisco.com/c/en/us/products/collateral/cloud-systems-management/aci-fabric-controller/white-paper-c11-729587.html
Key Take-Aways
vPC in 2015 VXLAN
• L2 segment scalability
VXLAN, ACI, Fabricpath • VTEP redundancy with
vPC
• You can submit an entry for more than one of your “favorite” speakers
• Don’t forget to follow @CiscoLive and @CiscoPress
• View the official rules at http://bit.ly/CLUSwin
Complete Your Online Session Evaluation
• Give us your feedback to be
entered into a Daily Survey
Drawing. A daily winner
will receive a $750 Amazon
gift card.
• Complete your session surveys
though the Cisco Live mobile
app or your computer on
Cisco Live Connect.
Don’t forget: Cisco Live sessions will be available
for viewing on-demand after the event at
CiscoLive.com/Online
Continue Your Education
• Demos in the Cisco campus
• Walk-in Self-Paced Labs
• Table Topics
• Meet the Engineer 1:1 meetings
• Related sessions
Thank you