top of page

PBR end-to-end Packet Flow

  • Writer: Mukesh Chanderia
    Mukesh Chanderia
  • Mar 29, 2024
  • 1 min read

Updated: Mar 11

  1. Each EGP is represented by PCTag


ree

2. Shadow EPG (Firewall) connect to the service Device (EPG)


ree

3. Traffic in between EGPs will be redirected & from shadow EGP towards EGPs will be unidirectional.


ree

The priority is fully_qual(7), indicating that this rule has a high priority.


The priority src_dst_any(9) suggests it is a lower-priority rule compared to the fully qualified rules.


uni-dir-ignore seems to be a special case where certain flows are ignored but redirection still occurs.


4. EG1 sends packet to EP2 via Leaf1. L1 does route & policy lookup - Redirect to Service BD/Service MAC (If Leaf1 doesn't know where the MAC of Fw interface resides than it will send it to Spine).


Bridge Domain of Firewall


ree


ree

5. Command Line Verification


ree


ree

ree

ree


ree


ree


TROUBLESHOOTING STEPS FOR MULTIPOD SYMMETRIC PBR


Routed flow between EPs 172.16.11.1 to 172.16.12.1

Redirected to one the Firewall HA pair.

FW are one-arm attached to ACI.



ree


Check 1: Is the Graph Deployed?


ree

Check 2: Is the Service EPG deployed?


ree

Check 3: Zoning-Rules


ree


Check 4: Redirect Info


ree

Check 5: Coop DB on Spine

Verify COOP DB if hashing gives you FW MAC


ree

Example Check ingress leaf


ree

Recent Posts

See All
MultiCast In ACI

Understanding Multicast in Cisco ACI 1. Multicast Traffic Flow in ACI In ACI, multicast traffic is primarily managed within Bridge...

 
 
 
Quality of Service (QoS) in Cisco ACI

Configuring Quality of Service (QoS)  in Cisco ACI (Application Centric Infrastructure)  involves creating and applying QoS policies that...

 
 
 

Comments


Follow me

© 2021 by Mukesh Chanderia
 

Call

T: 8505812333  

  • Twitter
  • LinkedIn
  • Facebook Clean
©Mukesh Chanderia
bottom of page