One Issue often seen when using OTV ADJACENCY SERVER is occasional flaps of ISIS Adjacency across the network and Local Site. Thi is usually seen when a large amount of Traffic is flowing through the Nexus.
There is a primary difference in the type of packet that is formed when using multicast in the Core vs using Adjacency Server Scenario where the packets are Unicast.
Here is how a packet looks when using Multicast in the Core.This capture is taken on the Core side of the Network.
The packet format is IP-GRE-MPLS-L2
Here is how a Packet looks when using Adjacency Server. This capture was taken on the Core side of the Network.
The Packet format is IP-UDP-DATA. Notice this packet is destined to UDP Port 8472.
Now if the CoPP policies are not updated correctly on the Nexus these Adjacency Server IS-IS Hello Packets are going to fall under the Default Copp Class and will be dropped when there are too many packets falling under the Default Policy.
This can be easily identified by observing the CoPP policy and checking to see if there is any Class matching the UDP port 8472. If there is none then this is most likely the cause of IS-IS flaps.
What we are looking for in the class-Map is something like this
ip access-list copp-system-p-acl-otv-as
permit udp any any eq 8472
Which is under this CLASS CRITICAL.
class-map type control-plane match-any copp-system-p-class-critical
match access-group name copp-system-p-acl-igmp
match access-group name copp-system-p-acl-msdp
match access-group name copp-system-p-acl-bgp
match access-group name copp-system-p-acl-eigrp
match access-group name copp-system-p-acl-rip
match access-group name copp-system-p-acl-rip6
match access-group name copp-system-p-acl-ospf
match access-group name copp-system-p-acl-pim
match access-group name copp-system-p-acl-bgp6
match access-group name copp-system-p-acl-ospf6
match access-group name copp-system-p-acl-pim6
match access-group name copp-system-p-acl-vpc
match access-group name copp-system-p-acl-mac-l2pt
match access-group name copp-system-p-acl-otv-as
If this is not present then we need to add this to make sure the IS-IS hellos are matched explicitly under this class.
Hello, I have one problem with Cisco prime. I am not getting recent change information from the tab. I have done everything but for no purpose. The picture is attached. Please guide me so that I can check my recent changes in cisco 2960. Cisco ...
How a switch can recognize traffic as “video” and what knobs inside a switch are available for a network designer to achieve this requirement???There are Media net on the switch that can automatically detect the device type connected to the...
Hi all. For a couple of years I've had two Cisco 1941 routers running IOS and BVI interfaces to support some end user devices. I have two Cisco ISR4321 running IOS-XE which from what I've read you must do BDI interfaces. I attached a diagram and applicabl...
Dear all,Now I have been investigating whether Cat65-MSFC can configureNetFlow NAT record or not. For instance other vendor such as FortiGate can support so I think Cisco might support for this.https://docs.fortinet.com/document/fortigate/6.0.6/handb...
Hello, I have to change a Cisco 3845 and install a Cisco ISR 4451. The problem is I have a subinterface with 30 helper-address: When I insert more than 16 directions using helper-address command, I have an error message which says that the router does not...