Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

Local proxy ARP

Want to summarize with AI?

Log in

Local proxy Address Resolution Protocol (ARP) routes same-subnet traffic through the Cisco Application Centric Infrastructure (ACI) fabric so that IP-based security policies can be applied.


Beginning with Cisco ACI Release 6.2(3), you can enable proxy ARP independently on a bridge domain through the Local Proxy ARP option. This feature supports IPv4 ARP and IPv6 Neighbor Discovery (ND).

Proxy ARP behavior

In this sub-section, proxy ARP refers to both proxy ARP provided through existing features and Local Proxy ARP, introduced in Cisco ACI release 6.2(3). Both enable endpoints in the same network or subnet to communicate without learning each other's MAC addresses. A typical use case is a private VLAN (PVLAN) with isolated secondary VLANs, where ARP requests are not flooded within the network.

When proxy ARP is enabled, the ACI leaf switch intercepts ARP requests and responds with the MAC address of the bridge domain switched virtual interface (SVI). The endpoints use the SVI MAC address as the destination MAC address for subsequent traffic. The fabric then treats the traffic as routed traffic.

A PVLAN with proxy ARP can be used when IP-based security policies, such as contracts, must be applied to bridged traffic. For example, an endpoint security group (ESG) can use IP-based selectors. The isolated PVLANs prevent an intermediate switch, such as a virtual switch, from locally bridging the traffic before the ACI fabric can enforce its security policies. Proxy ARP enables ACI to treat traffic within the same subnet as routed traffic and apply IP-based policies.

Note

ACI applies MAC-based security policies to bridged traffic and IP-based security policies to routed traffic.

Proxy ARP behavior with related features

Before Release 6.2(3), proxy ARP was coupled with the following features to support PVLAN use cases:

Table 1. Proxy ARP behavior before Release 6.2(3)

Feature

Proxy ARP behavior

Use case

Virtual machine manager (VMM) microsegmentation

Proxy ARP is enabled implicitly on VLANs that are deployed through VMM.

Implicitly enabled PVLANs prevent intermediate non-ACI switches from bridging Layer 2 traffic between different microsegmented endpoint groups (uSeg EPGs) or ESGs without passing the traffic through ACI. Proxy ARP enables the Layer 2 traffic to be classified into a uSeg EPG or ESG according to its IP address.

Intra-EPG isolation

Proxy ARP can be enabled explicitly as an additional option on all VLANs in the EPG.

Intra-EPG isolation blocks all Layer 2 traffic, including ARP, between isolated endpoints. Proxy ARP can be enabled to allow communication between the endpoints the endpoints in different isolated EPGs given that necessary contracts are configured between them.

Intra-EPG contracts

Proxy ARP is enabled implicitly on all VLANs in the EPG.

Intra-EPG contracts provide the same proxy ARP behavior as intra-EPG isolation, but proxy ARP is always enabled implicitly.

Flood in Encap

Proxy ARP is enabled implicitly for traffic that crosses VLANs.

Flood in Encap limits the flooding domain to each encapsulation VLAN, which also blocks ARP. Proxy ARP is enabled implicitly to allow communication between those VLANs.

Bridge-domain use cases with Local Proxy ARP

The Local Proxy ARP option was introduced for use cases that require proxy ARP to be enabled independently at the bridge-domain level:

  1. ESGs with both IP-based and EPG selectors: When EPG selectors are used, security settings, including intra-EPG isolation, cannot be modified at the EPG level. Apply these settings to the matched ESG instead.

    Previously, using IP-based selectors required proxy ARP, which required intra-EPG isolation on the EPG. Therefore, when EPG selectors were also used, intra-ESG isolation had to be enabled on the matched ESG.

    Note

    The Local Proxy ARP option alone does not fully support this use case because PVLAN functionality still requires intra-EPG isolation.

  2. ESGs with IP-based selectors across border gateways (BGWs): When a bridge domain that contains IP addresses matching an ESG IP-based selector is stretched to another site through BGWs, enable proxy ARP at the bridge-domain level and on the local EPG VLANs. This configuration enables proxy ARP on the BGWs for IP addresses behind remote BGWs. Because bridge domains, but not EPGs, are deployed on BGWs, proxy ARP must be enabled at the bridge-domain level.

Comparison with proxy ARP

The following table compares proxy ARP and local proxy ARP.

Table 2. Proxy ARP and local proxy ARP

Attribute

Proxy ARP

Local proxy ARP

Configuration level

EPG

Bridge domain

Isolation requirement

Requires intra-EPG isolation

No isolation requirement

Scope of the ARP response

Only endpoints within the isolated EPG receive the bridge domain MAC address.

All EPGs in the bridge domain receive the bridge domain MAC address.


Enable local proxy ARP on a bridge domain using the GUI

This procedure enables local proxy ARP on a bridge domain by using the Cisco APIC GUI.

Before you begin

Ensure that the following prerequisites are met:

  • The tenant, virtual routing and forwarding (VRF) instance, and bridge domain are configured.

  • The bridge domain does not contain an EPG that has proxy ARP, flood in encapsulation, or intra-EPG contracts configured. Local proxy ARP and EPG-level proxy ARP are mutually exclusive, whether EPG-level proxy ARP is enabled explicitly through intra-EPG isolation or implicitly by another feature.

Procedure

  1. From the menu bar, choose Tenants > tenant_name.

  2. In the Navigation pane, choose Networking > Bridge Domains > bridge_domain_name.

  3. In the Work pane, click Policy > General.

  4. Check the Local Proxy ARP check box.

  5. In the Properties area, check the Local Proxy ARP check box.

  6. Click Submit.


Guidelines and limitations for local proxy ARP

Use these guidelines and limitations when you enable local proxy ARP on a bridge domain.

Feature compatibility and topology support

The Local Proxy ARP option on a bridge domain is not supported with the following features because these features also enable proxy ARP:

  • Intra-EPG isolation with proxy ARP.

  • Intra-EPG contracts.

  • Flood in Encapsulation.

The Local Proxy ARP option on a bridge domain is supported in all topologies, including Multi-Pod, Remote Leaf, Cisco Nexus Dashboard Orchestrator (NDO) Multi-Site, and border gateway (BGW) Multi-Site.

Local proxy ARP has Enhanced Mixed Version fabric scope. For more information, see Operations Allowed During Mixed Versions on Cisco ACI Switches in the Cisco APIC Installation and ACI Upgrade and Downgrade Guide.