Selectively Filtering HSRP Traffic Over an OTV Overlay per-VLAN
Hi - In reading the Cisco documentation on the best practices for OTV implementation , I am unable to determine if FHRP isolation can be applied per-VLAN or not. While I understand the vACL and ARP inspection commands prevent the HSRP packets from traversing the overlay, and that these are applied per-VLAN, the filter that is then applied to the IS-IS control plane (as per the example at the very end) appears to not take VLAN in to account thus prevents (??) neighboring overlay sites the ability to learn those MAC addresses.
In my specific situation, all SVI's which are spanned between the data centres using OTV are enabled for HSRP on all Nexus 7000-series switches however for a selected few VLAN's we wish to enable FHRP isolation so that those VLAN's egress traffic is via the local data centre switches and not carried over the overlay. So, by enabling the vACL and ARP inspection for those specific VLAN's, I believe one of the data centre switches will become active (based on priority) at each data centre, however will the IS-IS control plane filter affect those which are not subject to the vACL and ARP inspection?
redistribute filter route-map OTV_HSRP_filter
From other documentation I am to believe that this filter prevents the neighboring site from learning the HSRP-specific MAC address and prevents the OTV VDC from reporting MAC addresses flapping between the internal interfaces and the overlay. I have not been able to find for this scenario and am unsure what the real impact will be if only half of the best practice example is implemented.
Howdy out there in automation land!!!! Again... two in one day... wow :) So onwards we press. If you have not read Part 1, please go back and do that as it might not make sense. In this part of the Less is More series we are going to install Cloud...
Howdy out there in Automation land!!! Today... I have the start of a long set of two blogs for my readers. We are going to do something exciting and really useful... but purely about system setup and design... no real "automation" today. But first...
Cisco Intersight Account Reset Tool
The Cisco Intersight Account Reset Tool is designed to increase the efficiency of developers, engineers, sellers and trainers working with Cisco Intersight by automating the Intersight account reset process.
Howdy out there in Automation land!! Hope everyone is having a great summer. We draw into the last true month of summer and we are going to take you further on your Action Orchestrator journey. Since we are on our last "Back to the Basics", I think we wil...