Describes how the Advertise Host Routes feature advertises individual host routes from border leaf switches to external networks based on local endpoint connectivity and bridge domain associations.
The Advertise Host Routes feature is an ACI configuration feature that
-
advertises /32 and /128 prefixes from border leaf switches.
-
requires a bridge domain (BD) association with an L3Out or an explicit prefix list.
-
limits route advertisement to the pod where the endpoint connects.
-
automatically withdraws route information when the endpoint moves or is removed from the local pod.
Host route advertisement requirements
Before you enable host route advertisement, complete these configurations:
-
Associate the BD with an L3Out, or configure the L3Out with an explicit route map that matches the BD subnets.
-
Enable the Advertised Externally option for the BD subnet.
-
Configure a contract between the endpoint group (EPG) in the specified BD and the external EPG for the L3Out.
-
If the BD is associated with an EPG that uses the same subnet for internal route leaking, also enable the Advertised Externally option for the EPG subnet.
You can configure host route advertisement by associating a BD with an L3Out or by using an explicit route map. Use an explicit route map for greater control.
Without a contract between the BD or EPG and the external EPG, the border leaf switch does not install the BD subnet or host routes.
Supported switches
The Advertise Host Routes feature requires a Generation 2 or later switch, such as a Cisco Nexus N9K model with EX, FX, or FX2 at the end of its model name.
Pod and site advertisement behavior
The Advertise Host Routes feature uses these route advertisement behaviors:
-
When the feature advertises a host route, it sets the VRF Transit Route Tag to prevent the route from being advertised back into the fabric and installed. External routers must preserve this route tag when advertising the route to another L3Out.
-
A border leaf switch withdraws a host route when its endpoint ages out or is removed from the database.
-
When an endpoint moves between sites or pods, the fabric withdraws the host route from the original site or pod and advertises it in the new site or pod.
-
A border leaf switch advertises an endpoint learned on a BD as a host route only through an L3Out in the same pod.
-
Border leaf switches do not advertise host routes between pods.
-
Border leaf switches in one site do not advertise endpoints or host routes learned in another site.
Remote leaf advertisement behavior
These restrictions apply to host route advertisement from remote leaf switches:
-
A locally learned endpoint on a remote leaf switch is advertised only through an L3Out deployed on remote leaf switches in the same pod.
-
Border leaf switches in the main pod or another pod do not advertise endpoints or host routes learned on a remote leaf switch.
-
An L3Out on a remote leaf switch does not advertise endpoints or host routes learned in the main pod, whether the remote leaf switch is in the same pod or another pod.
Shared services and route limitations
The following shared-services and route limitations apply:
-
The Advertise Host Routes feature supports shared services and allows host routes to be imported from one VRF into another through a shared contract.
-
When you enable the feature on a BD, you cannot use a route map to set a custom tag on the BD subnet.
When you enable the feature on a BD that is associated with an L3Out, the fabric marks the BD subnet as public. If the BD contains a rogue endpoint, the fabric advertises that endpoint through the L3Out.