Tuesday, September 3, 2019

Cisco ACI L3Out - Cat9500 Router OSPF

Hello fellow network gents,

I’m running into a peculiar problem using Cisco ACI L3Out.

So the setup is a multi-pod with 2 physical separated sites. We have built an L3Out for each Tenant. So every L3Out has a separate VRF in a separate user Tenant.

When we establish a neighbour ship with our router at the other end (OSPF). The router at the other end is a Catalyst 9500 running IOS-xe. When we establish the neighbourship something very odd happens. All routes that have been learned by the 9500 from ACI, from totally different Tenants are withdrawn. They remain withdrawn for at least 12 minutes, after that the Cat9500 will relearn them as type-5 routes.

So I am establishing a neighbour from 1 tenant and when it’s done, it will withdraw all the learned routes from other L3Outs in separate VRF and separate Tenants.

I’ve tested removing the neighbour and nothing happens, but when I re add it, i can’t ping any gateways (Bridge Domains) anymore inside of ACI and the route is removed from the OSPF database on my Cat9500.

We are using a redundant vPC connection to the Cat9500 to peer the L3Outs on, using sub interfaces. The OSPF configuration is on the sub interface.



No comments:

Post a Comment