We have a setup of Nexus 93180YC-EX running running 7.0(3)I7(6) OS version. On one of the VLAN/VXLAN we want to limit communication between hosts.
Host should be reachable only from outside network, but inside VLAN only communication with Anycast gateway should be allowed.
To achieve that, following config was applied ( MAC aaaa.bbbb.cccc in this case is distributed anycast gateway MAC):
mac access-list ACL-NETWORK
10 permit aaaa.bbbb.cccc 0000.0000.0000 any #Allow any traffic from anycast gateway
20 permit any aaaa.bbbb.cccc 0000.0000.0000 #Allow any traffic to anycast gateway
30 permit any ffff.ffff.ffff 0000.0000.0000 #Allow direct broadcast for ARP
vlan access-map VACL-NETWORK 10
match mac address ACL-NETWORK
vlan filter VACL-NETWORK vlan-list 1695
This configuration works, but I‘ve noted that if hosts still have ARP cache, or configured static ARP entries, they able to communicate within VLAN. Issue does not depend on whenever devices connected to same switch, or the VXLAN between different LEAF‘s used.
Howdy out there in automation land!!!! Again... two in one day... wow :) So onwards we press. If you have not read Part 1, please go back and do that as it might not make sense. In this part of the Less is More series we are going to install Cloud...
Howdy out there in Automation land!!! Today... I have the start of a long set of two blogs for my readers. We are going to do something exciting and really useful... but purely about system setup and design... no real "automation" today. But first...
Cisco Intersight Account Reset Tool
The Cisco Intersight Account Reset Tool is designed to increase the efficiency of developers, engineers, sellers and trainers working with Cisco Intersight by automating the Intersight account reset process.
Howdy out there in Automation land!! Hope everyone is having a great summer. We draw into the last true month of summer and we are going to take you further on your Action Orchestrator journey. Since we are on our last "Back to the Basics", I think we wil...