cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
393
Views
0
Helpful
3
Replies
JefferySung53210
Beginner

promiscuous mode for virtual switch when deploying aci simulator

Why is promiscuous mode needed for virtual switch when deploying aci simulator? Can I do away with it?

3 REPLIES 3
Robert Burns
Cisco Employee

Not if you want it to work   Because the Simulator is running on an mininet instance, the MACs are nested and therefore will not be able to receive traffic intended for the APICs virtual MAC.  It's the same reason when you run a nested VM instances of a hypervisor like ESX, you also need promisc. mode enabled.

Robert

Hi Robert,
Thanks for your prompt reply. My main concern here is security with promicious mode enabled, is there a way to create in a isolated VMware environment?

One option is to connect the APIC Sim to a dedicated vSwitch without any physical uplinks.  Then add a VM/Jumpbox with one Interface in the same vSwitch/Port Group as the Sim, and a second interface attached to your external/routed network vSwitch/portgroup.  This would limit the exposure of the Sim to only the jumpbox which could be running a FW to prevent external access.  

Robert