08-23-2018 05:52 AM - edited 03-01-2019 05:37 AM
Hello Community,
I have a question about TCPdump on a leaf Switch (ACI). When I start a TCPdump for an IP address learned via an L3OUT on the Border Leaf, see the ping in the TCPdump. When I start a TCPdump for an IP address learned as EPG -> BD, I don't see the ping in the TCPDump. I am in any case pinging from an IP outside the fabric.
Why can't I see the ping?
Many greetings
Patrick
08-25-2018 08:26 AM
That is expected that type of traffic is not punted to the CPU. Tcpdump will only work for packets punted from the ASIC to the CPU.
08-27-2018 01:50 AM
Hello Micgarc2,
thank you for Explanation, that makes sense. Which traffic type is punted to CPU in ACI Fabric?
Best Regards
Patrick
08-25-2018 08:34 AM
If you source traffic from the BD SVI to a deployed EP within that BD you will see it in a tcpdump output. Same goes for sourcing traffic from an external SVI (L3 out interface) to an external EP.
10-31-2022 12:35 AM
Apologies for hijacking this old topic, but does this mean that traffic between endpoints (in either same or different EPGs) passing through the Leaf switches (with gateway on ACI) cannot be tcpdump'ed on the Leaf themselves?
Tuan
10-31-2022 01:28 AM - edited 10-31-2022 01:28 AM
"If you source traffic from the BD SVI to a deployed EP within that BD you will see it in a tcpdump output" - meaning if you ping from leaf you will see the traffic in tcpdump.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide