12-19-2016 05:25 AM
A cliënt has two datacenters which are connected with two DCI (DataCenter Interconnect) links.
In the past they would use a 3750 stack on both sides with a port-channel for the DCI. Life was easy then.
In the new datacenter they have 4 nexus 5600's connected in a redundant way.
- All nexus devices are connected to 1 local nexus (vpc peerlink) and 1 remote nexus (vpc).
- All vlans are stretched
- HSRP will be active on all Nexus devices, with ACL's for filtering HSRP, so Nexus L3 routing is local in both datacenters.
- The firewalls (2) are connected directly to only 1 nexus in each datacenter.
- Only one of the two datacenters has an active firewall. Firewall routing will travel over the DCI VPC.
The network has been running for 4 weeks without problems, however, after a network hickup we discovered that some L3 traffic is VPC blackholed.
We solved the problem (for now) by disabling one of the DCI links.
- I could remove the VPC between the datacenters, but then I would have spanning-tree.
Is there any way to configure the DCI in a smart way so we have a redundant active/active setup without spanning-tree?
08-04-2017 01:50 PM
Hi Arjen K,
You need to connect one of the wire of the DCI to each 5K by DC.
DC1-5K1 <-------------------------------->DC2-5K1
DC1-5K2 <-------------------------------->DC2-5K2
using VPC to has both link active-active.
Sergio
09-28-2017 06:08 PM
Sergio, buenas noches
Como sería la configración para tener active/active el Gateway en los dos Sites, asumiendo que las VLAN´s se extienden entre los dos Sites?
Otra consulta, es si se puede generar mas de un vPC para interconectar los dos Sites, o la tecnologia vPC no lo permite?
Gracias,
Gustavo.
09-28-2017 06:06 PM
Hi... Can I have more than one vPC between the two Sites?
Thanks,
Gustavo.
10-03-2017 11:47 AM - edited 02-15-2018 10:33 AM
You could, but as I stated I would make those links non-VPC links and Routed Layer 3 and use EIGPR and or OSFP and let the ECMP do it's thing.
10-02-2017 01:43 PM
Never use a Layer3 link to vPC member ports. Have them seperated and have the IGP do their own ECMP.
With vPC you'll run into an issue where a quarter of the traffic (packets) will go out one vPC switch and then the next flow will go from second vPC link and will get blocked because it will go over the vPC peer-link and will not be able to go out any member port.
This is a very common problem that I see all the time.
02-14-2018 10:53 PM
Fabric Path between the two DCs with VPC+
02-15-2018 10:44 AM
02-15-2018 09:27 PM
02-15-2018 10:40 PM - edited 02-15-2018 10:41 PM
I think he said they are already running Fabricpath with VPC+, but it's not in the diagram he listed in his first port.
12-03-2018 07:26 PM
Hi Rick,
Could you please able to grab the Nexus 5K configurations from both data centers if possible. We have on a DCI deployment with Nexus 5K Layer 2 extension and it will help me to build the Nexus configurations and I can get the output / leanings and share with you all for reference.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide