cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
258
Views
0
Helpful
0
Replies
Highlighted

How to solve RPF check failure when using HSRP in Nexus56K?

Hi,

I am trying to activate pim sm multicast routing between a firewall cluster (non cisco) and two nexus 5648 (no vpc).

Firewall cluster has one ip address (in each zone), nexus use hsrp (in each vrf).

Well known multicast problem: firewall drops pim and multicast traffic because of failing rpf check.

 

Unbenannt.PNG

 

How can we solve this?

We see the following possibilities:

  1. using a dynamic routing protocol instead of static routing with HSRP -> not wanted by security team probably
  2. deactivating RPF-check on firewall -> not supported probably
  3. static routing without hsrp, instead of this two static routes on firewall with next hops = physical ip addresses of the nexus. Prefer one of this routes on firewall, use health check to monitor nexus and change to second one if health check to first one fails. -> not supported maybe. more workaround character than solution
  4. using static multicast routes on firewall (like mroute in ios), also two, with health checks. For unicast routing still use with HSRP. -> better than 3. but not supported probably
  5. exchanging nexus by a different router system which does not need HSRP, maybe Cat6K with VSS -> high costs
  6. exchanging nexus by a different router system which supports HSRP aware PIM -> high costs

Does anybody know a different hopefully easy trick to solve this issue?

 

Best Regards

Thorsten

 

 

CreatePlease to create content
Content for Community-Ad
July's Community Spotlight Awards