Local proxy Address Resolution Protocol (ARP) routes same-subnet traffic through the Cisco Application Centric Infrastructure (ACI) fabric so that IP-based security policies can be applied.
Beginning with Cisco ACI Release 6.2(3), you can enable proxy ARP independently on a bridge domain through the Local Proxy ARP option. This feature supports IPv4 ARP and IPv6 Neighbor Discovery (ND).
Proxy ARP behavior
In this sub-section, proxy ARP refers to both proxy ARP provided through existing features and Local Proxy ARP, introduced in Cisco ACI release 6.2(3). Both enable endpoints in the same network or subnet to communicate without learning each other's MAC addresses. A typical use case is a private VLAN (PVLAN) with isolated secondary VLANs, where ARP requests are not flooded within the network.
When proxy ARP is enabled, the ACI leaf switch intercepts ARP requests and responds with the MAC address of the bridge domain switched virtual interface (SVI). The endpoints use the SVI MAC address as the destination MAC address for subsequent traffic. The fabric then treats the traffic as routed traffic.
A PVLAN with proxy ARP can be used when IP-based security policies, such as contracts, must be applied to bridged traffic. For example, an endpoint security group (ESG) can use IP-based selectors. The isolated PVLANs prevent an intermediate switch, such as a virtual switch, from locally bridging the traffic before the ACI fabric can enforce its security policies. Proxy ARP enables ACI to treat traffic within the same subnet as routed traffic and apply IP-based policies.
ACI applies MAC-based security policies to bridged traffic and IP-based security policies to routed traffic.
Proxy ARP behavior with related features
Before Release 6.2(3), proxy ARP was coupled with the following features to support PVLAN use cases:
|
Feature |
Proxy ARP behavior |
Use case |
|---|---|---|
|
Virtual machine manager (VMM) microsegmentation |
Proxy ARP is enabled implicitly on VLANs that are deployed through VMM. |
Implicitly enabled PVLANs prevent intermediate non-ACI switches from bridging Layer 2 traffic between different microsegmented endpoint groups (uSeg EPGs) or ESGs without passing the traffic through ACI. Proxy ARP enables the Layer 2 traffic to be classified into a uSeg EPG or ESG according to its IP address. |
|
Intra-EPG isolation |
Proxy ARP can be enabled explicitly as an additional option on all VLANs in the EPG. |
Intra-EPG isolation blocks all Layer 2 traffic, including ARP, between isolated endpoints. Proxy ARP can be enabled to allow communication between the endpoints the endpoints in different isolated EPGs given that necessary contracts are configured between them. |
|
Intra-EPG contracts |
Proxy ARP is enabled implicitly on all VLANs in the EPG. |
Intra-EPG contracts provide the same proxy ARP behavior as intra-EPG isolation, but proxy ARP is always enabled implicitly. |
|
Flood in Encap |
Proxy ARP is enabled implicitly for traffic that crosses VLANs. |
Flood in Encap limits the flooding domain to each encapsulation VLAN, which also blocks ARP. Proxy ARP is enabled implicitly to allow communication between those VLANs. |
Bridge-domain use cases with Local Proxy ARP
The Local Proxy ARP option was introduced for use cases that require proxy ARP to be enabled independently at the bridge-domain level:
-
ESGs with both IP-based and EPG selectors: When EPG selectors are used, security settings, including intra-EPG isolation, cannot be modified at the EPG level. Apply these settings to the matched ESG instead.
Previously, using IP-based selectors required proxy ARP, which required intra-EPG isolation on the EPG. Therefore, when EPG selectors were also used, intra-ESG isolation had to be enabled on the matched ESG.
The Local Proxy ARP option alone does not fully support this use case because PVLAN functionality still requires intra-EPG isolation.
-
ESGs with IP-based selectors across border gateways (BGWs): When a bridge domain that contains IP addresses matching an ESG IP-based selector is stretched to another site through BGWs, enable proxy ARP at the bridge-domain level and on the local EPG VLANs. This configuration enables proxy ARP on the BGWs for IP addresses behind remote BGWs. Because bridge domains, but not EPGs, are deployed on BGWs, proxy ARP must be enabled at the bridge-domain level.
Comparison with proxy ARP
The following table compares proxy ARP and local proxy ARP.
|
Attribute |
Proxy ARP |
Local proxy ARP |
|---|---|---|
|
Configuration level |
EPG |
Bridge domain |
|
Isolation requirement |
Requires intra-EPG isolation |
No isolation requirement |
|
Scope of the ARP response |
Only endpoints within the isolated EPG receive the bridge domain MAC address. |
All EPGs in the bridge domain receive the bridge domain MAC address. |