<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: North-South traffic in SD-Access (border node MAC address) in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175987#M936</link>
    <description>&lt;P&gt;That's not a problem. Let me know if you find any other resources that supports this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I just noticed from my packet capture that my fabric edge to border node source MAC address isn't actually 00:00:0c:9f:ad:f1. The last 2 bytes of ad:f1 are correct, however the first 4 bytes have been replaced by the same 4 bytes used by the source MAC address within the inner header. ARP resolution between the fabric edge and border node is correct so I'm not sure why this is unless it is something odd that Wireshark has changed.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2020 17:26:08 GMT</pubDate>
    <dc:creator>willwetherman</dc:creator>
    <dc:date>2020-10-29T17:26:08Z</dc:date>
    <item>
      <title>North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175757#M929</link>
      <description>&lt;P&gt;My question is on a typical north-south packet walk scenario where a host in an SD-Access fabric needs to communicate with an external node. Below is a simple representation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Src_Host------[Edge_Node]-------[Underlay]--------[Border_Node]-------[Fusion_Rtr]--------Dst_Host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the Edge_Node looks up the IP address of Dst_Host from the Control_Plane/Map_Server/Resolver node (not shown above), the Control_Plane node returns a negative map reply (i.e. if the Border_Node did not explicitly register the address of Dst_Host). The Edge_Node will then send the packet to its configured Proxy_Etr (Which is the Border_Node).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is...given the packet will be encapsulated in VXLAN before sending to Underlay, what source and destination MAC address does Edge_Node use for the Original frame, prior to encapsulation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you need any clarifying details. Appreciate the help on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 12:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175757#M929</guid>
      <dc:creator>axe1501</dc:creator>
      <dc:date>2020-10-29T12:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175812#M930</link>
      <description>&lt;P&gt;I think the below link will help you to understand more on L2 EID and L3 EID where MAC address using LISP Instance Id.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/R6BGArNQ/TECCRS-3810.pdf" target="_blank"&gt;https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/R6BGArNQ/TECCRS-3810.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Inderdeep Singh&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.thenetworkdna.com" target="_blank"&gt;www.thenetworkdna.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 13:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175812#M930</guid>
      <dc:creator>inderdeeps</dc:creator>
      <dc:date>2020-10-29T13:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175819#M931</link>
      <description>&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why is this important? Because the L2 part isn't important between the border and Edge.&lt;/P&gt;&lt;P&gt;If traffic is going to the PETR the traffic is routed so at that moment the mac address doesn't matter anymore in my opinion.&lt;/P&gt;&lt;P&gt;Can you please clarify what you want to achieve with this question?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kristoff&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 14:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175819#M931</guid>
      <dc:creator>kristoff1</dc:creator>
      <dc:date>2020-10-29T14:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175868#M932</link>
      <description>&lt;P&gt;Sure...and thanks for the response. I'm trying to understand the behavior of VXLAN when forwarding via L3 VNI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the L2 VNI case, its straightforward...the MAC addresses in the VXLAN packet represent the src and dst hosts (which is what the Fabric_Edge_Node queried the Map Server to retrieve).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However in the L3 VNI forwarding case, after the Fabric_Edge_Node performs a LISP lookup and determines the RLOC to be the PETR/Border_Node (i.e. in my original example), because a VXLAN packet needs to be sent to the Border_Node, there needs to be a src and dst MAC address embedded in the frame (VXLAN requires this vs. LISP which does not). I understand this wouldn't be needed (i.e. given this is a L3 forwarding scenario) and in fact isn't needed if this were a pure LISP-encapsulated packet. However in the VXLAN case there needs to be a src and dst MAC address and i'm trying to understand the Fabric_Edge_Node's logic in determining those addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there's something fundamental i'm missing please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 15:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175868#M932</guid>
      <dc:creator>axe1501</dc:creator>
      <dc:date>2020-10-29T15:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175874#M933</link>
      <description>&lt;P&gt;Thanks for the reference document. I will take a look&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 15:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175874#M933</guid>
      <dc:creator>axe1501</dc:creator>
      <dc:date>2020-10-29T15:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175935#M934</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/280104"&gt;@axe1501&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked into this recently as well as I couldn't find any supporting documentation that explains this logic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I took a packet capture when a host within the fabric (10.120.0.10) pings a host outside the fabric (10.1.10.11). From what I can see, the fabric edge node inserts a dummy source/destination MAC address into the inner header of the L3VNI VXLAN encapsulated packet when it is sent to the PETR/Border node. See attached that I put together.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source MAC: 00:00:0c:9f:00:00&lt;/P&gt;&lt;P&gt;Destination MAC: ba:25:cd:f4:ad:38&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I took a packet capture on different fabric edge node to border node uplinks, on different fabric edge nodes as well as for different source/destination IP addresses, and the encapsulated source/destination MAC addresses were the same every time so I'm assuming that these are programmed in software just for the purposes for L3VNI VXLAN encapsulation&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully someone else can confirm this behaviour as I'm interested to know myself.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 13:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175935#M934</guid>
      <dc:creator>willwetherman</dc:creator>
      <dc:date>2020-10-30T13:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175954#M935</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/295375"&gt;@willwetherman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks so much for that response! This answers my question. That makes sense if Cisco uses dummy values since MAC addresses aren't relevant for L3VNI comms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate the pcaps...it really helped!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 16:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175954#M935</guid>
      <dc:creator>axe1501</dc:creator>
      <dc:date>2020-10-29T16:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175987#M936</link>
      <description>&lt;P&gt;That's not a problem. Let me know if you find any other resources that supports this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I just noticed from my packet capture that my fabric edge to border node source MAC address isn't actually 00:00:0c:9f:ad:f1. The last 2 bytes of ad:f1 are correct, however the first 4 bytes have been replaced by the same 4 bytes used by the source MAC address within the inner header. ARP resolution between the fabric edge and border node is correct so I'm not sure why this is unless it is something odd that Wireshark has changed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 17:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175987#M936</guid>
      <dc:creator>willwetherman</dc:creator>
      <dc:date>2020-10-29T17:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: North-South traffic in SD-Access (border node MAC address)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175996#M937</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/295375"&gt;@willwetherman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Interesting. There prob. a formula Cisco uses to vary the value.&lt;/P&gt;&lt;P&gt;Will let you know if I find any other theories.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 17:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/north-south-traffic-in-sd-access-border-node-mac-address/m-p/4175996#M937</guid>
      <dc:creator>axe1501</dc:creator>
      <dc:date>2020-10-29T17:45:03Z</dc:date>
    </item>
  </channel>
</rss>

