08-07-2018 06:30 AM - edited 03-01-2019 05:36 AM
I have a weird issue with the BGP session between ACI leaf and one external ASR.
I successfully configured an external routed network with eBGP peering, then I created an EPG with the bridge domain attached to the L3-out and with the subnet advertised externally.
The strange behaviour is that if I set the "Policy control enforcement preference" on the VRF to "Unenforced", the leaf correctly announce the prefix to the ASR; if I set it to "Enforce" (both with Egress or Ingress direction), the prefix is no longer announced (but the BGP peering remains up).
Is it an expected behaviour or am I doing something wrong?
I must restrict ingress traffic, so the Policy control enforcement is mandatory for me.
Solved! Go to Solution.
08-07-2018 07:25 AM
08-07-2018 07:25 AM
08-07-2018 09:29 AM
It works!
I see that even if I put an "all deny" policy on the contract, the leaf still makes the prefix advertisement, while if I leave the contract applied but without filters, the prefix is no longer being advertised.
That's a weird behaviour imho.
Thanks for the solution!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide