cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1238
Views
0
Helpful
4
Replies

aci 1.2 l3out issue

Mohitdbhall
Level 1
Level 1

HI , i have created a tenant named test with application profile test with epg test.

I binded the epg to a bridge-domain test-bd which has a gateway ip 

192.168.99.254/24 , it is advertised externally. This bd is binded to vrf bgp-test-vrf.

i have also created a l3out network for bgp which is binded to the same vrf above.

my bgp neighborship with my 7k is fine,

my epg can reach its gateway.

 

now i added this l3out to my bd and  created a simple contract scope tenant and subject to filter ICMP .

the contract is provided by the epg and consumed by the l3out network.

i was suppose to ping my epg machine from my 7k but no success, i captured traffic and found traffic is reach my end machine. end machine has default route pointing toward my bd's subnet, i have verified the routing and other issues thouroughly , 

KIndly help if anyone find anything missing, if you need any other information do let me know . 

thanks and regard. 

4 Replies 4

Manuel Velasco
Cisco Employee
Cisco Employee

Under your l3out EPG.  Did you define the subnet outside ACI from where you are sourcing the ping from your n7k and added the “External Subnet for the External EPG” flag?

 

I would also try to add you L3out as the provider and your test EPG as the consumer.

 

1BC729B4-D567-49F5-A80A-067312041DC0.jpeg

 

 

 

Thanks for the help , but yes i did that, I am able to find that the issue is my sipne and leaf are not building there mpbgp neighborship and error code on the leaves is 

 f0299

image.png

Thanks for the help, but yes I did that, I am able to find that the issue is my spine and leaf are not building their MPBGP neighborship and error code on the leaves is 

 f0299

image.png

The following is a sample XML file that can be posted to the APIC in order to create a tenant (named “Tenant2”), the private network (“CTX1”), bridge domain (“bd1”), and its three subnets. The XML file will also associate the layer 3 outside connection, named “L3OUT-1” (not created by this XML post), and specify one subnet of the bridge domain to be a public subnet.

<fvTenant name='Tenant2'>
<fvCtx name="CTX1"\>
<!—Create bridge domain and enable routing-->
<fvBD name="bd1" unicastRoute="yes">
<!—Associate the bridge domain with L3 outside connection-->
<fvRsBDToOut tnL3extOutName='L3OUT-1'/>
<fvSubnet ip="1.1.1.1/16"/>
<fvSubnet ip="1.2.1.1/16"/>
<fvSubnet ip='40.1.1.1/24' scope='public'/>
<fvRsCtx tnFvCtxName="CTX1"/>
</fvBD>
</fvTenant>.

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License