cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
953
Views
10
Helpful
5
Replies

On N5Ks, HSRP gateway on orphan port routers?

ck.chaminda
Level 1
Level 1

Hello,

We have a situation, where on a 2 x N5K environment it is necessary for a VPC VLAN to be terminated on down stream routers via HSRP. The routers themselves are single armed to each Nexus, so are orphan ports.The design constraints are forced on us by the WAN-OP PBR design.

The implication is packets hitting the secondary N5K via VPC will need to travel the VPC peer-link to reach the active HSRP gateway.

Does anyone know if this causes any restriction on future TAC support for the environment?

Thanks,

CK.

1 Accepted Solution

Accepted Solutions

Hi Chaminda,

 

The peer-gateway feature will not help you in this sitaution since these are orphan ports. Peer-gateway help to forward packet irrespective of whether it is received on HSRP standby or active but this happens only when traffic received on VPC ports. 

Does anyone know if this causes any restriction on future TAC support for the environment?

It may not, but TAC may advice you to change the design  as it is not a good practice to use the Peer-link for non VPC traffic. So as a best practice use another L2 trunk port between N5k to carry this Orphan traffic.

Hope this helps you.

Thanks,

Madhu.

 

 

View solution in original post

5 Replies 5

Reza Sharifi
Hall of Fame
Hall of Fame

Hi,

There is feature in Nexus OS called "peer-gateway".  If you add this command to both 5ks, than when a packet hits the secondary 5k, it will forward it upstream without sending it over the VPC peer-link.

Here is more info:

http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/command/reference/vpc/n5k-vpc-cr/n5k-vpc_cmds_p.html#wp1219702

HTH

Unfortunately as each router is connected to each N5K via a single link only, there is no way for packets ending up on the secondary N5K to hit the primary ASR (which has HSRP Active) without crossing the peer-link :(.

Hi ck.chaminda,

 

when using orphan ports in nexus, it is recommended to provide a separate "ordinary trunk" between the 2 nexus device. This is so that non-vpc vlans will use this link for their ordinary trunking needs.

 

Regards,

CCIE (R&S) #27666 CCSI HP MASE

Thanks every one for your replies. Madhu hit the nail here. 

Well I submitted a case with TAC, and was told it will be supported, because it is not explicitly defined anywhere in documentation the topology is not supported.

Hi Chaminda,

 

The peer-gateway feature will not help you in this sitaution since these are orphan ports. Peer-gateway help to forward packet irrespective of whether it is received on HSRP standby or active but this happens only when traffic received on VPC ports. 

Does anyone know if this causes any restriction on future TAC support for the environment?

It may not, but TAC may advice you to change the design  as it is not a good practice to use the Peer-link for non VPC traffic. So as a best practice use another L2 trunk port between N5k to carry this Orphan traffic.

Hope this helps you.

Thanks,

Madhu.

 

 

Review Cisco Networking for a $25 gift card