Describes guidelines and limitations for configuring HSRP in Cisco ACI, including state synchronization, dual-stack addressing, interface support, and traffic-forwarding behavior.
HSRP guidelines and limitations are operational requirements that
-
maintain consistent IPv4 and IPv6 HSRP states,
-
define MAC address requirements for dual-stack configurations, and
-
identify supported interfaces, features, and traffic-forwarding behavior.
HSRP operational constraints
The following guidelines and limitations apply to HSRP configurations:
-
Configure priority and preemption so that IPv4 and IPv6 HSRP maintain the same state, including after a failover.
-
Cisco ACI supports only one IPv4 HSRP group and one IPv6 HSRP group on the same subinterface. For a dual-stack configuration, configure the same virtual MAC address for both groups.
-
BFD for IPv4 and IPv6 is supported when the network between the HSRP peers is a Layer 2-only network. Configure different router MAC addresses on the leaf switches. The BFD sessions become active only when the leaf interfaces use different MAC addresses.
-
The HSRP virtual IP address must be in the same subnet as the interface IP address.
-
Configure an interface delay for HSRP.
-
HSRP is supported only on routed interfaces and subinterfaces. It is not supported on VLAN interfaces or switched virtual interfaces (SVIs). Therefore, HSRP does not support virtual port channels (vPCs).
-
HSRP does not support object tracking.
-
HSRP does not support the HSRP Management Information Base (MIB) for SNMP.
-
HSRP does not support multiple group optimization (MGO).
-
HSRP does not support ICMP redirects for IPv4 or IPv6.
-
HSRP does not support cold standby or Nonstop Forwarding (NSF) because HSRP cannot restart in a Cisco ACI fabric.
-
HSRP does not support an extended hold-down timer. HSRP is supported only on leaf switches, not on spine switches.
-
Cisco APIC does not support changing the HSRP version in an existing configuration. Remove the configuration, and then configure the new version.
-
HSRP version 2 does not interoperate with HSRP version 1. An interface cannot run both versions. Different physical interfaces on the same router can run different versions.
-
On Cisco Nexus 93128TX, Cisco Nexus 9396PX, and Cisco Nexus 9396TX leaf switches, route segmentation is programmed when HSRP is active on an interface. Therefore, these switches do not compare the destination MAC (DMAC) address with the router MAC address for routed packets on the interface. This limitation does not apply to Cisco Nexus 93180LC-EX, Cisco Nexus 93180YC-EX, or Cisco Nexus 93108TC-EX leaf switches.
-
HSRP configurations are not supported in Basic GUI mode, which was deprecated in Cisco APIC release 3.0(1).
-
Traffic from the fabric to a Layer 3 Out is load-balanced across all HSRP leaf switches, regardless of their HSRP state. If the HSRP leaf switches span multiple pods, this traffic uses leaf switches in the same pod.
-
On some earlier Cisco Nexus 93128TX, Cisco Nexus 9396PX, and Cisco Nexus 9396TX switches, change the MAC address of one routed interface or subinterface to prevent MAC address flapping on the external Layer 2 device. Cisco APIC assigns the same MAC address, 00:22:BD:F8:19:FF, to every logical interface under the logical interface profiles.