Explains the Layer 2 forwarding constructs within the fabric and their relationship to VRF instances and subnets.
A bridge domain must be linked to a VRF instance (also known as a context or private network). With the exception of a Layer 2 VLAN, it must have at least one subnet (fvSubnet) associated with it. The bridge domain defines the unique Layer 2 MAC address space and a Layer 2 flood domain if such flooding is enabled. While a VRF instance defines a unique IP address space, that address space can consist of multiple subnets. Those subnets are defined in one or more bridge domains that reference the corresponding VRF instance.
Subnet options under a bridge domain or EPG include:
-
Public: The subnet can be exported to a routed connection.
-
Private: The subnet applies only within its tenant.
-
Shared: The subnet can be shared with and exported to multiple VRF instances in the same tenant or across tenants as part of a shared service. An example of a shared service is a routed connection to an EPG present in another VRF instance in a different tenant. This enables traffic to pass in both directions across VRF instances. An EPG that provides a shared service must have its subnet configured under that EPG (not under a bridge domain), and its scope must be set to advertised externally, and shared between VRF instances.
Shared subnets must be unique across the VRF instance involved in the communication. When a subnet under an EPG provides a Layer 3 external network shared service, such a subnet must be globally unique within the entire Cisco Application Centric Infrastructure (ACI) fabric.
Bridge domain packet behavior can be controlled in these ways:
|
Packet type |
Mode |
|---|---|
|
ARP |
You can enable or disable ARP Flooding; without flooding, ARP packets are sent with unicast.
|
|
Unknown Unicast |
L2 Unknown Unicast, which can be Flood or Hardware Proxy.
Modifying the L2 Unknown Unicast setting causes traffic to bounce (go down and up) on interfaces to devices attached to EPGs associated with this bridge domain. |
|
Unknown IP Multicast |
L3 Unknown Multicast Flooding Flood: Packets are flooded on ingress and border leaf switch nodes only. With N9K-93180YC-EX, packets are flooded on all the nodes where a bridge domain is deployed. Optimized:Multicast flooding is limited to the ingress border leaf switch node only. With N9K-93180YC-EX, it is limited to the nodes where a bridge domain is deployed and the border leaf switch nodes. |
|
IPv6 Unknown Multicast |
IPv6 Unknown Multicast Flooding Flood: Packets are flooded on ingress and border leaf switch nodes only. With N9K-93180YC-EX, packets are flooded on all the nodes where a bridge domain is deployed. Optimized: Multicast flooding is limited to the ingress border leaf switch node only. With N9K-93180YC-EX, it is limited to the nodes where a bridge domain is deployed and the border leaf switch nodes. |
|
Multi Destination Flooding |
Multi Destination Flooding
|
Beginning with Cisco APIC release 3.1(1), on the Cisco N 9000 series switches (with names ending with EX and FX and onwards), the following protocols can be flooded in encapsulation or flooded in a bridge domain: OSPF/OSPFv3, BGP, EIGRP, LACP, ISIS, IGMP, PIM, ST-BPDU, ARP/GARP, RARP, and ND.
Bridge domains can span multiple switches. A bridge domain can contain multiple subnets, but a subnet is contained within a single bridge domain. If the bridge domain (fvBD) limitIPLearnToSubnets property is set to yes, endpoint learning will occur in the bridge domain only if the IP address is within any of the configured subnets for the bridge domain or within an EPG subnet when the EPG is a shared service provider. Subnets can span multiple EPGs; one or more EPGs can be associated with one bridge domain or subnet. In hardware proxy mode, ARP traffic is forwarded to an endpoint in a different bridge domain when that endpoint has been learned as part of the Layer 3 lookup operation.