cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6097
Views
30
Helpful
5
Replies

TCPDump on Leaf (ACI)

PatrickH1
Level 1
Level 1

Hello Community,

 

I have a question about TCPdump on a leaf Switch (ACI). When I start a TCPdump for an IP address learned via an L3OUT on the Border Leaf, see the ping in the TCPdump. When I start a TCPdump for an IP address learned as EPG -> BD, I don't see the ping in the TCPDump. I am in any case pinging from an IP outside the fabric.

 

Why can't I see the ping?

 

Many greetings

Patrick

5 Replies 5

micgarc2
Cisco Employee
Cisco Employee

That is expected that type of traffic is not punted to the CPU. Tcpdump will only work for packets punted from the ASIC to the CPU.

Hello Micgarc2,

 

thank you for Explanation, that makes sense. Which traffic type is punted to CPU in ACI Fabric?

 

Best Regards

 

Patrick

micgarc2
Cisco Employee
Cisco Employee

If you source traffic from the BD SVI to a deployed EP within that BD you will see it in a tcpdump output. Same goes for sourcing traffic from an external SVI (L3 out interface) to an external EP.

Apologies for hijacking this old topic, but does this mean that traffic between endpoints (in either same or different EPGs) passing through the Leaf switches (with gateway on ACI) cannot be tcpdump'ed on the Leaf themselves?

 

Tuan

"If you source traffic from the BD SVI to a deployed EP within that BD you will see it in a tcpdump output" - meaning if you ping from leaf you will see the traffic in tcpdump.

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License