Provides concepts, topology, requirements, configuration tasks, and verification commands for directing same-subnet IPv4 traffic through firewall inspection by using local-proxy ARP and Layer 2 isolation.
This chapter describes how local-proxy ARP and Layer 2 isolation support micro-segmentation and how to configure and verify the feature.
Local-proxy ARP and Layer 2 isolation
Explains how local-proxy ARP and Layer 2 isolation direct same-subnet IPv4 traffic through a service firewall for policy enforcement and session-state processing.
Topology for local-proxy ARP and Layer 2 isolation
Provides an example topology that maps an isolated secondary VLAN to a primary service VLAN and places the Layer 3 gateway on the smart switch.
Guidelines and limitations for local-proxy ARP and Layer 2 isolation
Lists supported traffic, configuration requirements, VLAN mapping behavior, and software upgrade considerations for local-proxy ARP with Layer 2 isolation on smart switches.
Configure local-proxy ARP with Layer 2 isolation
Configure local-proxy ARP, receive-only VLAN mapping, and service VLAN isolation to route eligible same-subnet IPv4 traffic through a service firewall.
Configure local-proxy ARP on an EVPN SVI
Configure local-proxy ARP on an Ethernet VPN SVI that uses the anycast gateway to direct supported same-subnet traffic to the gateway.
Verification commands for local-proxy ARP and Layer 2 isolation
Lists CLI commands used to verify VLAN mapping, ARP entries, Layer 2 isolation, service acceleration, and local-proxy ARP operational status on smart switches.