cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3035
Views
11
Helpful
4
Replies

Subnet Scope under Bridge domain IN ACI

Hello, can some please help me to understand below questions.

While creating the subnet under Bridge domain we have three scopes

1> Private to VRF.

2> advertise externally.

3> shared between VRF.

A> My 1st question is if i select private to VRF then, will that subnet be advertised to externally or to other VRF.

B> My 2nd question is if i select advertise externally then,  subnet will be advertised external and as well as private to VRF and to between the VRF?

C> if i select between VRF then that subnet will not be advertised to external and to private to VRF.

 

Please help to clear my doubt. Similar for L3 out subnet scops.

 

Regards

Deepak

3 Accepted Solutions

Accepted Solutions

joezersk
Cisco Employee
Cisco Employee

Hi Deepak. 

Private to VRF = This subnet will only be routed internal to the ACI fabric.  This is to say it won't be advertised via any L3outs.

Advertise Externally = The opposite of Private.  This means you want this subnet to participate in any associated L3outs. 

Shared Between VRFs = This is used when you want to do route leaking between different VRFs

So the answers to your questions are:

A - No.  It will only be reachable by any other BDs in that VRF

B- No. It will only be advertised via the L3outs in that same VRF, and reachable by any other BDs in that VRF

C- No.  This box only sets this subnet to be eligible to be leaked to other VRFs inside ACI.  This box can be used in combination with the other two options.  It is not mutually exclusive.

View solution in original post

Good answer @joezersk 

This screen is so confusing Cisco modified it in V5.  See if you can spot the difference...

image.png

See how they have removed the confusing Private to VRF option?

One of Cisco's better moves IMHO

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

View solution in original post

Yeah, running 5.0.2 in my lab and I saw that too.  I did not mention it as our OP is on an older version where all three still show. I agree, fewer exposed nerd knobs is usually a better experience. 

View solution in original post

4 Replies 4

joezersk
Cisco Employee
Cisco Employee

Hi Deepak. 

Private to VRF = This subnet will only be routed internal to the ACI fabric.  This is to say it won't be advertised via any L3outs.

Advertise Externally = The opposite of Private.  This means you want this subnet to participate in any associated L3outs. 

Shared Between VRFs = This is used when you want to do route leaking between different VRFs

So the answers to your questions are:

A - No.  It will only be reachable by any other BDs in that VRF

B- No. It will only be advertised via the L3outs in that same VRF, and reachable by any other BDs in that VRF

C- No.  This box only sets this subnet to be eligible to be leaked to other VRFs inside ACI.  This box can be used in combination with the other two options.  It is not mutually exclusive.

Good answer @joezersk 

This screen is so confusing Cisco modified it in V5.  See if you can spot the difference...

image.png

See how they have removed the confusing Private to VRF option?

One of Cisco's better moves IMHO

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Yeah, running 5.0.2 in my lab and I saw that too.  I did not mention it as our OP is on an older version where all three still show. I agree, fewer exposed nerd knobs is usually a better experience. 

Thanks Dear Joezersk & Rednectar to clear the doubt...

 

 

Regards

Deepak

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Save 25% on Day-2 Operations Add-On License