How to solve RPF check failure when using HSRP in Nexus56K?
I am trying to activate pim sm multicast routing between a firewall cluster (non cisco) and two nexus 5648 (no vpc).
Firewall cluster has one ip address (in each zone), nexus use hsrp (in each vrf).
Well known multicast problem: firewall drops pim and multicast traffic because of failing rpf check.
How can we solve this?
We see the following possibilities:
using a dynamic routing protocol instead of static routing with HSRP -> not wanted by security team probably
deactivating RPF-check on firewall -> not supported probably
static routing without hsrp, instead of this two static routes on firewall with next hops = physical ip addresses of the nexus. Prefer one of this routes on firewall, use health check to monitor nexus and change to second one if health check to first one fails. -> not supported maybe. more workaround character than solution
using static multicast routes on firewall (like mroute in ios), also two, with health checks. For unicast routing still use with HSRP. -> better than 3. but not supported probably
exchanging nexus by a different router system which does not need HSRP, maybe Cat6K with VSS -> high costs
exchanging nexus by a different router system which supports HSRP aware PIM -> high costs
Does anybody know a different hopefully easy trick to solve this issue?
Hi Everyone,I have 2 queries1. After we configure the IPSec VPN in a Cisco Router, how do we identify and check that the traffic is flowing through the tunnel? Are there any commands and ways to find it out?2. What are some of t...
Cisco Champion Radio · S7|E29 Increase Visibility and Enhance Security with Cisco AI Endpoint Analytics
Cisco is on a journey to making networking smarter with artificial intelligence and machine learning. The latest stop in this journey, Cisco AI...
Community Live video- Introduction to Smart Licensing on Catalyst Switches
(Live event - formerly known as Webcast- Thursday 30 July, 2020 at 10 am Pacific/ 1 pm Eastern / 7 pm Paris)
This event had place on Thursday 30th, July 2020 at 10hrs PDT&nb...
To participate in this event, please use the button to ask your questions
This topic is a chance to clarify your questions about smart licensing on Cisco Catalyst switches, including 9000 (9200, 93...