Professional Documents
Culture Documents
Home » Blog » Nexus 5000 vPC Peer Keepalive Options and Config-Sync Issue
! Security (10)
interface mgmt0 ACS (1)
vrf member management ASA (2)
Certificate (1)
ip address 192.168.0.1/30
DMVPN (1)
! ISE (6)
vpc domain 1
Wireless (2)
peer-keepalive destination 192.168.0.2 source 192.168.0.1 vrf management
QoS (1)
!
vWLC (1)
- Given the switches have L3 daughter card installed, you can connect the two switches through routed interfaces (ie.
‘no switchport’). The benefit is that now you can use fiber cable, which allows much longer distance if there is a
requirement to extend beyond what copper Ethernet supports. The link can also be 10G, although there is not much
reason to, plus it is an added cost to use 10G SFP+. It is still recommend placing the interfaces under its own VRF.
Note that they cannot be added to the management VRF as it is reserved for mgmt0 and console. If you plan to use
any non-management VRF for the vPC keepalive, including the ‘default’ VRF, do not forget to define it on the ‘peer-
keepalive’ command under ‘vpc domain’.
!
vrf conext KEEPALIVE
!
interface ethernet1/1
no switchport
vrf member KEEPALIVE
ip address 192.168.0.1/30
!
vpc domain 1
peer-keepalive destination 192.168.0.2 source 192.168.0.1 vrf KEEPALIVE
!
1 of 3 16-09-19, 4:09 PM
Nexus 5000 vPC Peer Keepalive Options and Config-Sync Issue | Lab M... http://www.labminutes.com/blog/2012/08/nexus-5000-vpc-peer-keepaliv...
- If you need the distance of fiber but do not have the L3 daughter card, you can create a dedicated VLAN and use the
SVI for the vPC keepalive. This is similar to Option2 so the separate VRF recommendation still holds. The interfaces
can be the dot1q trunk or access port, but why use a trunk if it carries just one VLAN, right?
!
vlan 10
name KEEPALIVE
!
vrf context KEEPALIVE
!
interface Ethernet 1/1
switchport access vlan 10
spanning-tree port type network
!
802.1x anyconnect asa bgp byod
interface Vlan10 certificate eap-tls firepower flexvpn ftd
no shutdown
vrf member KEEPALIVE
guest ikev2 ipsec ISE ise 1.3 ise 2.0 ise 2.2
ip address 192.168.0.1/30 mpls NAT ngfw pi 3.1 prime radius routing
!
sourcefire vpn wired wireless
vpc domain 1
peer-keepalive destination 192.168.0.2 source 192.168.0.1 vrf KEEPALIVE wireshark wlc
More
!
Any of the three options should works fine until you need to
enable config-sync. According to Cisco documentation, config-
sync traffic is carried over mgmt0 interface (see balow). If you
cannot use mgmt0 for vPC keepalive, you probably cannot use
it for config-sync neither. If you attempt to configure switch-
profile peer with any non-mgmt0 IP, the switch will show ‘Peer
not Reachable’, even though the IP is pingable. You probably
need to resort to some form of media converter to convert fiber to copper at both ends, if config-sync feature is
mandatory.
With SVI
With mgmt0
2 of 3 16-09-19, 4:09 PM
Nexus 5000 vPC Peer Keepalive Options and Config-Sync Issue | Lab M... http://www.labminutes.com/blog/2012/08/nexus-5000-vpc-peer-keepaliv...
http://www.linkedin.com/in/methachiewanichakorn
3 of 3 16-09-19, 4:09 PM