<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OTV intermittent when passing through ACI in Controllers</title>
    <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891938#M3158</link>
    <description>&lt;P&gt;That's strange, from an ACI point of view I don't see why this intermediate L2 hop is changing the behaviour.&lt;/P&gt;
&lt;P&gt;Is site B's BD running in flood or proxy mode? And what's the difference regarding the L1/L2 connection between OTV router direct connected or via L2 hop (in the layout I see OTV router is single connected to one leaf, what about the intermediate switch, is it connected also with just one link, or do you use a vPC)?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jul 2023 08:43:17 GMT</pubDate>
    <dc:creator>Marcel Zehnder</dc:creator>
    <dc:date>2023-07-25T08:43:17Z</dc:date>
    <item>
      <title>OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4890150#M3153</link>
      <description>&lt;P&gt;Recently, we performed a migration where we decommissioned our old N7K (network switch) and moved all devices to ACI (Application Centric Infrastructure).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The task involved moving the existing OTV (Overlay Transport Virtualization) router from its current connection in the N7K to the new ACI infrastructure. The original setup had the OTV router connected as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- OTV (Outside peer link L3) connected to N7K EXT VDC (Virtual Device Context).&lt;/P&gt;
&lt;P&gt;- OTV (Inside L2 Link) connected to N7K-Server Farm VDC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the new infrastructure, the OTV router was connected as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- OTV (Outside peer link L3) connected to a WAN SWITCH.&lt;/P&gt;
&lt;P&gt;- OTV (Inside L2 Link) connected to an L2Out ACI Trunk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the migration, an issue arose with communication to the gateway (10.0.130.1/24 ACI Gateway) located on VLAN 50 at Site A (BGI). The network path for pinging the gateway from Site HTV was as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Site HTV --&amp;gt; OTV L2 --&amp;gt; OTV --&amp;gt; L3 --&amp;gt; WAN Switch --&amp;gt; DWDM (Dense Wavelength Division Multiplexing) --&amp;gt; OTV HTV L3 --&amp;gt; WAN Switch --&amp;gt; OTV L2 --&amp;gt; ACI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is that pinging the gateway (10.0.130.1) from Site HTV was inconsistent. While it was possible to ping other servers within the same subnet, pinging the gateway on the BGI site ACI was erratic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm reaching out to the community for some help. If anyone has faced similar sanario&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 16:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4890150#M3153</guid>
      <dc:creator>freemen810</dc:creator>
      <dc:date>2023-07-22T16:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891715#M3154</link>
      <description>&lt;P&gt;Hi, so your gateway is configured as a BD-IP on ACI and you stretching this BD with a L2out over OTV to another OTV site? Can you post the settings of that BD and also the port configuration of the L2out (vPC, PC or single port)? Second thing: Is there a specific reason why you use a L2out, would it be also possible to stretch this an EPG static port?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 06:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891715#M3154</guid>
      <dc:creator>Marcel Zehnder</dc:creator>
      <dc:date>2023-07-25T06:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891768#M3155</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Below is the diagram. The Gateway for site B is sitting in site A BD 50 in the ACI. The intermittent ping only happens when the host in Site B Vlan 50 ping to the BD gateway in Site A. When pinging to host in Site A Vlan 50 there is no ping loss.&lt;/P&gt;
&lt;P&gt;I noticed something peculiar, when adding in a L2 HOP (Test Scenario) the intermittency issue is resolved. I cant seem to pinpoint where the issue is, as far as i can see the ACI is forwarding the packet to the correct path which is to the ASR router for the OTV&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="freemen810_1-1690267318075.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192427i48E6AB3BCE2AEE21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="freemen810_1-1690267318075.png" alt="freemen810_1-1690267318075.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="freemen810_0-1690267169850.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192426i3AEBB6484278C6AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="freemen810_0-1690267169850.png" alt="freemen810_0-1690267169850.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="freemen810_2-1690267351117.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192429iEE2180168E3A31ED/image-size/medium?v=v2&amp;amp;px=400" role="button" title="freemen810_2-1690267351117.png" alt="freemen810_2-1690267351117.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 06:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891768#M3155</guid>
      <dc:creator>freemen810</dc:creator>
      <dc:date>2023-07-25T06:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891839#M3156</link>
      <description>&lt;P&gt;Site-A and B are two individiual ACI Fabrics? How does the BD Settings for "VLAN" 50 look in these two fabrics and can you confirm unicast routing on BD-50 is only enabled in Site-A?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 07:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891839#M3156</guid>
      <dc:creator>Marcel Zehnder</dc:creator>
      <dc:date>2023-07-25T07:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891882#M3157</link>
      <description>&lt;P&gt;Yes they are independent fabrics. the BD VLAN 50 in Site A has unicast routing enabled, and BD in Site B has unicast routing disabled. furthermore, BD in Site B does not hold any IP.&lt;/P&gt;
&lt;P&gt;since the VLAN 50 is extended over OTV to Site A. The Gateway for Site B sits in BD in SITE A.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in the details i mentioned above the issue only happens when we try to ping the SITE A BD vlan 50 gateway 10.0.130.1 and there for we cannot reach anything outside the subnet. furthermore, when adding an additional L2 hop in-between magickly solves the intermittency issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is where we are stuck. why is it behaving in such a manner?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 07:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891882#M3157</guid>
      <dc:creator>freemen810</dc:creator>
      <dc:date>2023-07-25T07:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891938#M3158</link>
      <description>&lt;P&gt;That's strange, from an ACI point of view I don't see why this intermediate L2 hop is changing the behaviour.&lt;/P&gt;
&lt;P&gt;Is site B's BD running in flood or proxy mode? And what's the difference regarding the L1/L2 connection between OTV router direct connected or via L2 hop (in the layout I see OTV router is single connected to one leaf, what about the intermediate switch, is it connected also with just one link, or do you use a vPC)?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 08:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891938#M3158</guid>
      <dc:creator>Marcel Zehnder</dc:creator>
      <dc:date>2023-07-25T08:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891943#M3159</link>
      <description>&lt;P&gt;Site B is set to flooding.&lt;/P&gt;
&lt;P&gt;There is no inherit difference between Level 1 connection and level 2 apart from the N7K.&lt;/P&gt;
&lt;P&gt;In level 1 the OTV had it's layer 3 link connected to the N7K via the ext vdc and the layer 2 link via the serverfarm vdc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's crucial to note that the N7k is a single chasis running 2 vdc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At site B we have one OTV router while site A have 2 and all are in an otv adjacency peer to each other.&lt;/P&gt;
&lt;P&gt;So if site A OTV R1 fails it can use R2 to go over to site A.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And yes I've tried failing over the OTV router as well an the issue still persist.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 08:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891943#M3159</guid>
      <dc:creator>freemen810</dc:creator>
      <dc:date>2023-07-25T08:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891947#M3160</link>
      <description>&lt;P&gt;I meant whether there is a difference between the two "red" links in the layout:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-07-25 105403.png" style="width: 444px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192470iE306DABCBD6B113C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-07-25 105403.png" alt="Screenshot 2023-07-25 105403.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 08:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891947#M3160</guid>
      <dc:creator>Marcel Zehnder</dc:creator>
      <dc:date>2023-07-25T08:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891965#M3161</link>
      <description>&lt;P&gt;Ohh.. nop they are the same trunk port with mtu 9000&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 09:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891965#M3161</guid>
      <dc:creator>freemen810</dc:creator>
      <dc:date>2023-07-25T09:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891997#M3162</link>
      <description>&lt;P&gt;Maybe&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/300010"&gt;@dpita&lt;/a&gt;,&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320756"&gt;@RedNectar&lt;/a&gt; or&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1017682"&gt;@Sergiu.Daniluk&lt;/a&gt;&amp;nbsp; has an idea...&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 10:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4891997#M3162</guid>
      <dc:creator>Marcel Zehnder</dc:creator>
      <dc:date>2023-07-25T10:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: OTV intermittent when passing through ACI</title>
      <link>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4893637#M3163</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;PROBLEM DESCRIPTION&lt;/STRONG&gt;&lt;BR /&gt;----------------------------------------&lt;BR /&gt;&lt;BR /&gt;Intermittent connectivity between server 10.0.130.20 in SITE_B site, and its default gateway 10.0.130.1 in BGI site.&lt;BR /&gt;&lt;BR /&gt;Server 10.0.130.20 is connected to ACI SITE_B fabric, and default gateway is connected to BGI ACI fabric. Both fabrics are completely independent of each other and are connected via ASR1k OTV.&lt;BR /&gt;&lt;BR /&gt;The ping from server 10.0.130.20 to gateway 10.0.130.1 works for some time, say 10-20 consecutive successful pings, and then drops for 20-30 pings. Exact success/drop counters change over time, but that's the idea -- there are periods with 100% success ping rate, and periods with 100% failure ping rate. &lt;BR /&gt;&lt;BR /&gt;At the same time, ping from server 10.0.130.20 in SITE_B site to server 10.0.130.40 in BGI site works fine all the time. This flow is using same path through the network as the problem flow between server 10.0.130.20 and default gateway 10.0.130.1.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;TROUBLESHOOTING STEPS&lt;/STRONG&gt;&lt;BR /&gt;----------------------------------------&lt;BR /&gt;&lt;BR /&gt;We took built-in ACI SPAN capture on SITE_B site and see that server 10.0.130.20 keeps sending ICMP requests even when it doesn't receive reply from default gateway. So, it doesn't seem to be ARP resolution issue in SITE_B site.&lt;BR /&gt;&lt;BR /&gt;On BGI Leaf 301 in BGI site we captured packets with tcpdump and see ICMP Requests from 10.0.130.20 received and replied to immediately. However, on same capture, when server 10.0.130.20 starts seeing drops, packet capture 'stops' -- we don't even receive ICMP Requests from 10.0.130.20 during failure periods.&lt;BR /&gt;&lt;BR /&gt;ASR1k team checked the traffic and see the packets getting dropped on ASR1k in SITE_B site when destination MAC 00:22:bd:f8:19:ff, which is the MAC of default gateway 10.0.130.1 and is supposed to be learned from BGI site, is getting learned from SITE_B site.&lt;BR /&gt;&lt;BR /&gt;SITE_B_ASR_OTV1#show platform packet-trace summary &lt;BR /&gt;Pkt Input Output State Reason&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;0 Te0/0/1.EFP50 Te0/0/1.EFP50 DROP 263 (L2BDSourceFilter)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;1 Te0/0/1.EFP50 Te0/0/1.EFP50 DROP 263 (L2BDSourceFilter)&lt;BR /&gt;2 Te0/0/1.EFP50 Te0/0/1.EFP50 DROP 263 (L2BDSourceFilter)&lt;BR /&gt;3 Te0/0/1.EFP50 Te0/0/1.EFP50 DROP 263 (L2BDSourceFilter)&lt;BR /&gt;4 Te0/0/1.EFP50 Te0/0/1.EFP50 DROP 263 (L2BDSourceFilter)&lt;BR /&gt;5 Te0/0/1.EFP50 Te0/0/1.EFP50 DROP 263 (L2BDSourceFilter)&lt;BR /&gt;&lt;BR /&gt;Here is the output from SITE_B ASR1k that shows destination MAC of default gateway 10.0.130.1 &lt;STRONG&gt;being incorrectly learned from SITE_B site&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;SITE_B_ASR_OTV1#sh otv route vlan 50&lt;BR /&gt;&lt;BR /&gt;Codes: BD - Bridge-Domain, AD - Admin-Distance,&lt;BR /&gt;SI - Service Instance, * - Backup Route&lt;BR /&gt;&lt;BR /&gt;OTV Unicast MAC Routing Table for Overlay1&lt;BR /&gt;&lt;BR /&gt;Inst VLAN BD MAC Address AD Owner Next Hops(s)&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;0 50 50 0022.bdf8.19ff 40 BD Eng Te0/0/1:SI50 &amp;lt;&amp;lt; OTV SITE B INTERFACE to ACI&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;0 50 50 00fc.ba63.d391 50 ISIS MYSEL_BGI_L3_ASR_OTV1&lt;BR /&gt;0 50 50 3429.8f73.256b 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 4006.d5aa.475a 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 482e.723a.01b6 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 482e.724b.9668 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 98be.940c.dc50 50 ISIS MYSEL_BGI_L3_ASR_OTV1&lt;BR /&gt;0 50 50 b026.28e5.6cdc 50 ISIS MYSEL_BGI_L3_ASR_OTV1&lt;BR /&gt;0 50 50 cc16.7ec1.f73c 50 ISIS MYSEL_BGI_L3_ASR_OTV1&lt;BR /&gt;0 50 50 e4c7.2200.3245 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;&lt;BR /&gt;10 unicast routes displayed in Overlay1&lt;BR /&gt;&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;10 Total Unicast Routes Displayed&lt;BR /&gt;&lt;BR /&gt;SITE_B_ASR_OTV1#&lt;BR /&gt;&lt;BR /&gt;Once the MAC table on ASR1k has 00:22:bd:f8:19:ff pointing to SITE-A site, connectivity restores.&lt;BR /&gt;&lt;BR /&gt;SITE_B_ASR_OTV1#sh otv route vlan 50&lt;BR /&gt;&lt;BR /&gt;Codes: BD - Bridge-Domain, AD - Admin-Distance,&lt;BR /&gt;SI - Service Instance, * - Backup Route&lt;BR /&gt;&lt;BR /&gt;OTV Unicast MAC Routing Table for Overlay1&lt;BR /&gt;&lt;BR /&gt;Inst VLAN BD MAC Address AD Owner Next Hops(s)&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;0 50 50 0022.bdf8.19ff 50 ISIS SITE_A_ASR_OTV1&amp;nbsp;&amp;lt;&amp;lt; OTV SITE A L3 Interface&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;0 50 50 00fc.ba63.d391 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 3429.8f73.256b 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 4006.d5aa.475a 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 482e.723a.01b6 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 482e.724b.9668 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 98be.940c.dc50 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 b026.28e5.6cdc 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 cc16.7ec1.f73c 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 e4c7.2200.3245 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;&lt;BR /&gt;10 unicast routes displayed in Overlay1&lt;BR /&gt;&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;10 Total Unicast Routes Displayed&lt;BR /&gt;&lt;BR /&gt;SITE_B_ASR_OTV1#&lt;BR /&gt;&lt;BR /&gt;We performed SPAN packet capture on SITE_B ACI LEAF 401 interface towards ASR1k, and see IGMPv3 membership reports being sent towards ASR1k from SITE_B site, using source MAC 00:22:bd:f8:19:ff&lt;BR /&gt;&lt;BR /&gt;ACI SPAN session configuration is shown below&lt;BR /&gt;&lt;BR /&gt;APIC-DR-01# fabric 401 show monitor session 7&lt;BR /&gt;----------------------------------------------------------------&lt;BR /&gt;Node 401 (SITE_B_BLF_0401)&lt;BR /&gt;----------------------------------------------------------------&lt;BR /&gt;session 7&lt;BR /&gt;---------------&lt;BR /&gt;name : span-source-10.0.130.1&lt;BR /&gt;description : Span session 7&lt;BR /&gt;type : local&lt;BR /&gt;state : up (active)&lt;BR /&gt;mode : access&lt;BR /&gt;Filter Group : None&lt;BR /&gt;source intf :&lt;BR /&gt;rx : &lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;tx : [Eth1/34]&lt;/STRONG&gt;&lt;/FONT&gt; &lt;BR /&gt;both : &lt;BR /&gt;source VLANs :&lt;BR /&gt;rx : &lt;BR /&gt;tx : &lt;BR /&gt;both : &lt;BR /&gt;filter VLANs : filter not specified&lt;BR /&gt;filter L3Outs : filter not specified&lt;BR /&gt;destination ports : Eth1/3&lt;BR /&gt;&lt;BR /&gt;APIC-DR-01#&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The result of local SPAN capture is as follows&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="freemen810_1-1690456637642.png" style="width: 937px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/192727iC1F7BCA9D437F2FC/image-dimensions/937x371?v=v2" width="937" height="371" role="button" title="freemen810_1-1690456637642.png" alt="freemen810_1-1690456637642.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Checking IGMP snooping operation on SITE_B LEAF 401, we see IGMP membership reports received from port-channel 2: below outputs suggest that internal vlan 86 (which represents Bridge Domain SITE_B-2-PROD-DC:VLAN0050_AS400_PROD_BD) has IGMP snooping enabled&lt;BR /&gt;&lt;BR /&gt;SITE_B_BLF_0401# show ip igmp snooping groups &lt;BR /&gt;Type: S - Static, D - Dynamic, R - Router port, F - Fabricpath core port&lt;BR /&gt;&lt;BR /&gt;Vlan Group Address Ver Type Port list&lt;BR /&gt;86 */* - R Eth1/34&lt;BR /&gt;86 239.255.102.18 v3 D Po2&lt;BR /&gt;86 239.255.255.250 v3 D Po2&lt;BR /&gt;SITE_B_BLF_0401#&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;SITE_B_BLF_0401# show vlan id 86 extended &lt;BR /&gt;&lt;BR /&gt;VLAN Name Encap Ports &lt;BR /&gt;---- -------------------------------- ---------------- ------------------------ &lt;BR /&gt;86 SITE_B2-PROD- vxlan-15433636 Eth1/23, Eth1/34, &lt;BR /&gt;DC:VLAN0050_AS400_PROD_BD Eth1/35, Eth1/36, Po1, &lt;BR /&gt;Po2, Po3 &lt;BR /&gt;SITE_B_BLF_0401#&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;APIC-DR-01# fabric 401 show ip igmp snooping&lt;BR /&gt;----------------------------------------------------------------&lt;BR /&gt;Node 401 (SITE_B_BLF_0401)&lt;BR /&gt;----------------------------------------------------------------&lt;BR /&gt;Global IGMP Snooping Information:&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;IGMP Snooping enabled&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Optimised Multicast Flood (OMF) enabled&lt;BR /&gt;IGMPv1/v2 Report Suppression enabled&lt;BR /&gt;IGMPv3 Report Suppression disabled&lt;BR /&gt;Link Local Groups Suppression enabled&lt;BR /&gt;…&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;IGMP Snooping information for vlan 86&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;IGMP snooping enabled&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;Lookup mode: IP&lt;BR /&gt;Optimised Multicast Flood (OMF) disabled&lt;BR /&gt;IGMP querier present, address: 10.188.210.66, version: 3, i/f Eth1/34&lt;BR /&gt;Querier interval: 60 secs&lt;BR /&gt;Querier last member query interval: 1 secs&lt;BR /&gt;Querier robustness: 2&lt;BR /&gt;Switch-querier disabled&lt;BR /&gt;IGMPv3 Explicit tracking enabled&lt;BR /&gt;IGMPv2 Fast leave disabled&lt;BR /&gt;IGMPv1/v2 Report suppression enabled&lt;BR /&gt;IGMPv3 Report suppression enabled&lt;BR /&gt;Link Local Groups suppression enabled&lt;BR /&gt;Router port detection using PIM Hellos, IGMP Queries&lt;BR /&gt;Number of router-ports: 1&lt;BR /&gt;Number of groups: 2&lt;BR /&gt;VLAN vPC function enabled&lt;BR /&gt;Multicast Routing disabled on VLAN&lt;BR /&gt;Active ports:&lt;BR /&gt;Eth1/23 Eth1/34 Eth1/35 Eth1/36 &lt;BR /&gt;Po1 Po2 Po3&lt;BR /&gt;&lt;BR /&gt;…&lt;BR /&gt;&lt;BR /&gt;We configured new IGMP snooping policy under tenant, which disables IGMP snooping, and applied it to Bridge Domain SITE_B-2-PROD-DC:VLAN0050_AS400_PROD_BD. After that IGMP snooping shows as disabled under the vlan 86&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;APIC-DR-01# fabric 401 show ip igmp snooping&lt;BR /&gt;----------------------------------------------------------------&lt;BR /&gt;Node 401 (SITE_B_BLF_0401)&lt;BR /&gt;----------------------------------------------------------------&lt;BR /&gt;Global IGMP Snooping Information:&lt;BR /&gt;IGMP Snooping enabled&lt;BR /&gt;Optimised Multicast Flood (OMF) enabled&lt;BR /&gt;IGMPv1/v2 Report Suppression enabled&lt;BR /&gt;IGMPv3 Report Suppression disabled&lt;BR /&gt;Link Local Groups Suppression enabled&lt;BR /&gt;…&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;IGMP Snooping information for vlan 86&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;IGMP snooping disabled&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;Lookup mode: IP&lt;BR /&gt;Optimised Multicast Flood (OMF) disabled&lt;BR /&gt;IGMP querier none&lt;BR /&gt;Switch-querier disabled&lt;BR /&gt;IGMPv3 Explicit tracking disabled&lt;BR /&gt;IGMPv2 Fast leave disabled&lt;BR /&gt;IGMPv1/v2 Report suppression disabled&lt;BR /&gt;IGMPv3 Report suppression disabled&lt;BR /&gt;Link Local Groups suppression disabled&lt;BR /&gt;Router port detection using PIM Hellos, IGMP Queries&lt;BR /&gt;Number of router-ports: 0&lt;BR /&gt;Number of groups: 0&lt;BR /&gt;Multicast Routing disabled on VLAN&lt;BR /&gt;Active ports:&lt;BR /&gt;Eth1/23 Eth1/34 Eth1/35 Eth1/36 &lt;BR /&gt;Po1 Po2 Po3&lt;BR /&gt;…&lt;BR /&gt;&lt;BR /&gt;Once the old entry for MAC address 00:22:bd:f8:19:ff expires from SITE_B ASR1k OTV route table, and correct entry is learned from BGI site, connectivity restores again, and stays up&lt;BR /&gt;&lt;BR /&gt;SITE_B_ASR_OTV1#sh otv route vlan 50&lt;BR /&gt;&lt;BR /&gt;Codes: BD - Bridge-Domain, AD - Admin-Distance,&lt;BR /&gt;SI - Service Instance, * - Backup Route&lt;BR /&gt;&lt;BR /&gt;OTV Unicast MAC Routing Table for Overlay1&lt;BR /&gt;&lt;BR /&gt;Inst VLAN BD MAC Address AD Owner Next Hops(s)&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;0 50 50 0022.bdf8.19ff 50 ISIS SITE_A_ASR_OTV1 &amp;lt;&amp;lt; Correctly learned Mac address&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;0 50 50 00fc.ba63.d391 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 3429.8f73.256b 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 4006.d5aa.475a 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 482e.723a.01b6 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 482e.724b.9668 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;0 50 50 98be.940c.dc50 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 b026.28e5.6cdc 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 cc16.7ec1.f73c 50 ISIS SITE_A_ASR_OTV1&lt;BR /&gt;0 50 50 e4c7.2200.3245 40 BD Eng Te0/0/1:SI50&lt;BR /&gt;&lt;BR /&gt;10 unicast routes displayed in Overlay1&lt;BR /&gt;&lt;BR /&gt;----------------------------------------------------------&lt;BR /&gt;10 Total Unicast Routes Displayed&lt;BR /&gt;&lt;BR /&gt;SITE_B_ASR_OTV1#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in summery&lt;/P&gt;
&lt;P&gt;the root cause was due to both Site A ACI fabric and Site B ACI fabric using the same mac address&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;0022.bdf8.19ff. &lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;ACI by design is made to use the same mac address accross the fabric but when an external extention of vlan is introduced the mac address is seen on the other end via IGMP and not via broadcast. that is why in the senario when we added in the c9300 the issue went away. it is because the 9300 also has its own igmp enabled by defauly there for becoming a proxy and sending its own mac address to the otv router rather then the ACI one.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;i hope this helps anyone who faces such issue in the future.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;special thanks to CISCO TAC&amp;nbsp;Nikolay Kartashev&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 11:24:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/controllers/otv-intermittent-when-passing-through-aci/m-p/4893637#M3163</guid>
      <dc:creator>freemen810</dc:creator>
      <dc:date>2023-07-27T11:24:23Z</dc:date>
    </item>
  </channel>
</rss>

