Advance OTV Configure Verify and Troubleshoot
Advance OTV Configure Verify and Troubleshoot
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Build The Bridge
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Introduction
Overlay Transport Virtualisation (OTV) in a Nutshell
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Introduction
Terminology: Edge Device
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
Introduction
Terminology: Internal Interfaces
Internal Interfaces
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Introduction
Terminology: Join Interface
Join Interfaces
Uplink on Edge device that joins the
Overlay
Forwards OTV control and data traffic otv otv
Layer 3 interface
Currently supported only on M-series
modules
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Introduction
Terminology: Overlay Interface
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Introduction
Terminology: Authoritative Edge Device
AED for odd
OTV supports multiple edge devices per VLANs
site
A single OTV device is elected as AED otv otv
on a per-vlan basis
The AED is responsible for advertising
MAC reachability and forwarding traffic
into and out of the site for its VLANs
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Introduction
Terminology: Authoritative Edge Device
AED for even
OTV supports multiple edge devices per VLANs
site
A single OTV device is elected as AED otv otv
on a per-vlan basis
The AED is responsible for advertising
MAC reachability and forwarding traffic
into and out of the site for its VLANs
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
Introduction
Terminology: Site VLAN
Prior to 5.2(1) OTV used only I’m AED for I’m AED for
Even VLANs Odd VLANs
communication on the site vlan for AED
election
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
Introduction
Terminology: Site VLAN
Prior to 5.2(1) OTV used only I’m AED for I’m AED for
All VLANs All VLANs
communication on the site vlan for
AED election
otv otv
Misconfiguration or connectivity issues
on the site vlan could result in
active/active AED mode
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Introduction Core
Terminology: Site VLAN and Site Identifier
5.2(1) added Dual Site Adjacency I’m AED for I’m AED for
Even VLANs Odd VLANs
1. Site Adjacency established across the
site vlan OTV Hello OTV Hello
otv
Site-ID 1.1.1 otv
Site-ID 1.1.1
2. Overlay Adjacency established via the
Join interface across Layer 3 network
Full
Adjacency
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
Introduction Core
Terminology: Site VLAN and Site Identifier
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
Introduction Core
Terminology: Site VLAN and Site I’m not AED I’m now AED
Identifier capable ALL VLANs
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
Introduction Core
Terminology: Site VLAN and Site I’m not AED I’m now AED
Identifier capable ALL VLANs
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Introduction Core
Terminology: Site VLAN and Site I’m now AED I’m now AED
Identifier EVEN VLANs ODD VLANs
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Introduction
Overlay Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Configuration
Enable OTV Feature
feature otv
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Configuration
Site VLAN and Site Identifier
Site VLAN needs to be configured and active even if you do not have multiple
OTV devices in the same site
site VLAN should not be extended across overlay
Site Identifier can be any number between 0000.0000.0001 and ffff.ffff.ffff.
Value will always be displayed in MAC format
Site Identifier must be unique for each site
Site Identifier is required in 5.2(1) and above for overlay to come up. This
must be kept in mind when performing an ISSU from a pre-5.2(1)
Service Impacting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Configuration
Site VLAN and Site Identifier
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Configuration
Join Interface
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Configuration
Multicast Transport: Overlay
interface Overlay1
otv join-interface port-channel100
otv control-group 239.1.1.1
otv data-group 232.1.1.0/24
otv extend-vlan 200-209
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Configuration
Multicast Transport: Full Picture
WEST_OTVA EAST_OTVA
feature otv feature otv
otv site-vlan 210 otv site-vlan 210
otv site-identifier 0001.0001.0001 otv site-identifier 0002.0002.0002
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Configuration
Unicast Transport: Overlay
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Configuration
Unicast Transport: Primary Adjacency Server Overlay
interface Overlay1
otv join-interface port-channel100
otv extend-vlan 200-209
otv adjacency-server unicast-only
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Configuration
Unicast Transport: Secondary Adjacency Server Overlay
interface Overlay1 Primary Server
otv join-interface port-channel100
otv extend-vlan 200-209
otv use-adjacency-server 172.16.1.34 unicast-only
otv adjacency-server unicast-only
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Configuration
Unicast Transport: Client Overlay Primary Server
interface Overlay1
Secondary Server
otv join-interface port-channel100
otv extend-vlan 200-209
otv use-adjacency-server 172.16.1.34 172.16.1.26 unicast-only
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
EAST_OTVA
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Configuration
Unicast Transport: Full Picture
WEST_OTVB EAST_OTVB
feature otv feature otv
otv site-vlan 210 otv site-vlan 210
otv site-identifier 0001.0001.0001 otv site-identifier 0002.0002.0002
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Configuration
Authentication
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Verification
Adjacency: IP Connectivity
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Verification
Adjacency: Overlay
WEST_OTVA# show otv Multicast Transport WEST_OTVA# show otv Unicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Verification
Adjacency: ISIS Hello (IIH) statistics
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Verification
Adjacency: ISIS Hello over Multicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Verification
Adjacency: ISIS Hello over Unicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Verification
Adjacency: ISIS Overlay Adjacencies
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Verification
Adjacency: OTV Overlay Adjacencies
WEST_OTVA# show otv adjacency
Overlay Adjacency database
Overlay-Interface Overlay1 :
Hostname System-ID Dest Addr Up Time State
EAST_OTVA 6c9c.ed40.1741 172.16.1.26 19:34:34 UP
EAST_OTVB 64a0.e741.c841 172.16.1.30 19:34:30 UP
WEST_OTVB 64a0.e741.c842 172.16.1.38 19:34:30 UP
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Verification
Adjacency: ISIS Site Adjacencies
WEST_OTVA# show otv isis site
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Verification
Adjacency: OTV Site Adjacencies
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Verification
Authoritative Edge Device (AED)
WEST_OTVA# show otv vlan 200-201
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Verification
Authoritative Edge Device (AED)
WEST_OTVB# show otv vlan 200-201
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Verification
Adjacency: OTV Overlay Adjacencies for Multicast Transport
For multicast transport, OTV join interfaces are configured with IGMPv3.
Therefore, from the transport's perspective, the OTV edge devices appear as
host sending and requesting traffic from the control-group
West East
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Verification
Address Resolution Protocol (ARP)
Host on vlan 201 AED vlan 201 AED vlan 201 Host on vlan 201
IP 10.201.0.101 IP 10.201.0.102
MAC 001b.d419.1842 MAC 001f.6c75.1d42
West East
otv otv
Core
otv otv
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Verification
Address Resolution Protocol (ARP)
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Verification
ARP: Host at West Site Sends ARP Request for Host at East
West East
otv
WEST_OTVA# show mac address-table vlan 201
otv
Po103 Po100 Legend: Po100 Po101
Core
* - primary entry, G - Gateway MAC, (R) - Routed MAC, O - Overlay MAC
age - seconds since last seen,+ - primary entry using vPC Peer-Link
VLAN MAC Address Type age Secure NTFY Ports/SWID.SSID.LID
vlan 201 vlan 201
---------+-----------------+--------+---------+------+----+------------------
10.201.0.101 * 201 001b.d419.1842 dynamic 0 F F Po103 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Verification
ARP: Host at West Site Sends ARP Request for Host at East
4. On learning new MAC, West AED sends ISIS update to all OTV devices
• Single packet on multicast control group (Multicast Transport)
• Or, unicast to each adjacency (Unicast Transport)
5. Only AED at remote sites program new MAC into OTV route and CAM tables
West East
otv otv
Po103 Po100 Po100 Po101
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Verification
ARP: Host at West Site Sends ARP Request for Host at East
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Verification
ARP: Host at West Site Sends ARP Request for Host at East
8. AED at East site receives packet on Join interface, decapsulates and sends
it on internal interface toward host
Non AED at East will also receive packet but will not forward
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Verification
ARP: Host at East Site Sends ARP Reply for Host at West
West East
otv otv
Po103 Po100 Po100 Po101
EAST_OTVA# show mac address-table vlan 201 Core
Legend:
* - primary entry, G - Gateway MAC, (R) - Routed MAC, O - Overlay MAC
vlan 201 vlan 201
age - seconds since last seen,+ - primary entry using vPC Peer-Link
10.201.0.101 10.201.0.102
VLAN MAC Address
001b.d419.1842 Type age Secure NTFY Ports/SWID.SSID.LID 001f.6c75.1d42
---------+-----------------+--------+---------+------+----+------------------
O 201 001b.d419.1842 dynamic 0 F F Overlay1
* 201 001f.6c75.1d42 dynamic 0 F F Po101
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Verification
ARP: Host at East Site Sends ARP Reply for Host at West
3. On learning new MAC, East sends ISIS update to all OTV devices
• Single packet on multicast control group (Multicast Transport)
• Or, unicast to each adjacency (Unicast Transport)
4. Only AED at remote sites program new MAC into OTV route and CAM tables
West East
otv WEST_OTVA# show mac address-table vlan 201 otv
Legend:
Po103 Po100 Po100
* - primary entry, G - Gateway MAC, (R) - Routed Po101
MAC, O - Overlay MAC
Core
age - seconds since last seen,+ - primary entry using vPC Peer-Link
VLAN MAC Address Type age Secure NTFY Ports/SWID.SSID.LID
vlan 201 ---------+-----------------+--------+---------+------+----+------------------
vlan 201
10.201.0.101 * 201 001b.d419.1842 dynamic 0 F F Po103 10.201.0.102
001b.d419.1842 O 201 001f.6c75.1d42 dynamic 0 F F Overlay1001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Verification
ARP: Host at East Site Sends ARP Reply for Host at West
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Reference Slide
Verification
ARP: Encapsulated ARP Reply
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Verification
ARP: Host at East Site Sends ARP Reply for Host at West
7. West receives packet on Join Interface, decapsulates packet and sends out
internal interface toward host
8. West updates ARP-ND cache for East Host from ARP reply
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Verification
Unicast Forwarding
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Verification
Unicast Forwarding: User on Site West Sends Unicast Packet to Site East
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Verification
Unicast Forwarding: User on Site West Sends Unicast Packet to Site East
Overlay-Interface Overlay1 :
Hostname System-ID Dest Addr Up Time State
EAST_OTVA 6c9c.ed40.1741 172.16.1.26 19:34:34
East UP
West EAST_OTVB 64a0.e741.c841 172.16.1.30 19:34:30 UP
otv
WEST_OTVB 64a0.e741.c842 otv
172.16.1.38 19:34:30 UP
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Verification
Unicast Forwarding: User on Site West Sends Unicast Packet to Site East
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Verification
Unicast Forwarding: User on Site West Sends Unicast Packet to Site East
DI: 0x421
Core
DIP: 172.16.1.26 SIP: 172.16.1.34
LIF: 0x4074 ccc: 6 L2_FWD: NO RDT: YES
Packets: 0 Bytes: 0 zone enforce: 0
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Verification
Unicast Forwarding: Encapsulated Packet
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Verification
Unicast Forwarding: User on site West sends unicast packet to site East
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Verification
Unicast Forwarding: User on site West sends unicast packet to site East
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Verification
Unicast Forwarding: User on site West sends unicast packet to site East
Packet will be sent out internal interface at site East and L2 switched to the
host
Return path from East to West will be the same
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
10.201.0.101 10.201.0.102
001b.d419.1842 001f.6c75.1d42
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Verification
Multicast Forwarding: IGMP Join from Client
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
Multicast Client Multicast Server
10.201.0.101 10.201.0.102
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Verification
Multicast Forwarding: IGMP Join from Client
Multicast Transport
WEST_OTVA# show ip igmp snooping groups vlan 201
Type: S - Static, D - Dynamic, R - Router port, F - Fabricpath core port
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Verification
Multicast Forwarding: IGMP Join from Client
(r) means there is a receiver that exists
Multicast Transport across the overlay
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Verification
Multicast Forwarding: IGMP Join from Client
Unicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Verification
Multicast Forwarding: Multicast Server Discovery
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
Multicast Client Multicast Server
10.201.0.101 10.201.0.102
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Verification
Multicast Forwarding: Multicast Server Discovery
Multicast Transport
EAST_OTVA# show otv mroute vlan 201 detail
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Verification
Multicast Forwarding: Multicast Server Discovery
(s) means there is a source that exists
Multicast Transport across the overlay
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Verification
Multicast Forwarding: Multicast Server Discovery
Unicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Verification
Multicast Forwarding: Multicast Server Discovery
Unicast Transport
No state created on West site
West East
otv otv
Po103 Po100 Po100 Po101
Core
vlan 201 vlan 201
Multicast Client Multicast Server
10.201.0.101 10.201.0.102
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Verification
Multicast Forwarding: Source and Client Present
Multicast Transport
West Edge Device sends an IGMPv3
SSM join for the Delivery Source and
the Delivery Group on its Join interface
WEST_OTVA# show otv mroute vlan 201 detail
OTV Multicast Routing Table For Overlay1
West East
(201, 10.201.0.102, 224.10.10.10), metric: 0, uptime: 00:04:47, overlay(s)
otv Outgoing interface list: (count: 0)
Remote Delivery: s = 172.16.1.26, g = 232.1.1.0
otv
Po103 Po100 Po100 Po101
WEST_OTVA# show otv data-group
Remote Active Sources for Overlay1
Core
vlan 201 VLAN Active-Source Active-Group Delivery-Source Delivery-GroupvlanJoined-I/F
201
Multicast Client Multicast
---- --------------- --------------- --------------- --------------- Server
----------
10.201.0.101 201 10.201.0.102 224.10.10.10 172.16.1.26 232.1.1.0 10.201.0.102
Po100
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Verification
Multicast Forwarding: Source and Client Present
Multicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Verification
Multicast Forwarding: Encapsulated Packet, Multicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Verification
Multicast Forwarding: Source and Client Present
Since core does not support multicast, West site
cannot send SSM join for group. Instead, West
Unicast Transport needs only to communicate to East that it has a
receiver and it will receive the group via unicast.
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Verification
Multicast Forwarding: Source and Client Present
Unicast Transport
Each multicast group is sent via
EAST_OTVA# show otv mroute vlan 201 unicast to each site with receivers
OTV Multicast Routing Table For Overlay1 present
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Verification
Multicast Forwarding: Encapsulated Packet, Unicast Transport
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Agenda
OTV Introduction
Configuration
Multicast Transport
Unicast-only Transport
Verification
Adjacency
ARP
Unicast Forwarding
Multicast Forwarding
Troubleshooting
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Troubleshooting
MTU
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Troubleshooting
Partial Adjacency
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Troubleshooting
Partial Adjacency
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Troubleshooting
ARP and CAM timer issue
Asymmetrical routing with mis-match ARP timers can cause traffic to black-
hole across OTV
West East
otv otv
N7k Po103 Po100 Po100 Po101 6500
Core
Vlan 201: 10.201.0.1 Vlan 201: 10.201.0.3
Vlan 202: 10.202.0.1 Vlan 202: 10.202.0.3
6c9c.ed40.1744 0014.f179.b640
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Troubleshooting
ARP and CAM timer issue
Since the traffic flow between Host1 and Host2 is routed traffic, OTV will only
see source MAC of the gateways and destination of the Hosts
CAM ARP
ARP CAM
30 min 4 hours
25 min 30 min
DA: Host2 DA: Host2 DA: Host2 DA: Host2
West SA: N7k1 SA: N7k1 SA: N7k1 SA: N7k1 East
otv otv
N7k Po103 Po100 Po100 Po101 6500
Core
Vlan 201: 10.201.0.1 DA: Host2
Vlan 201: 10.201.0.3
DA: N7k
SA: Host1Vlan 202: 10.202.0.1 SA: N7k1
Vlan 202: 10.202.0.3
6c9c.ed40.1744 0014.f179.b640
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Troubleshooting
ARP and CAM timer issue
Since the traffic flow between Host1 and Host2 is routed traffic, OTV will only
see source MAC of the gateways and destination of the Hosts
CAM ARP
ARP CAM
30 min 4 hours
25 min 30 min DA: Host1
DA: Host1 DA: Host1 DA: Host1
SA: 6500 SA: 6500 SA: 6500 East
West SA: 6500
otv otv
N7k Po103 Po100 Po100 Po101 6500
Core
Vlan 201: 10.201.0.1 Vlan 201: 10.201.0.3
DA: Host1 DA: 6500
SA: 6500 Vlan 202: 10.202.0.1 Vlan 202: 10.202.0.3
SA: Host2
6c9c.ed40.1744 0014.f179.b640
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Troubleshooting
ARP and CAM timer issue
OTV does not send unknown unicast traffic across Overlay
Subsequent packets from East toward Host1 will be dropped until Host1
MAC is relearned on West
West East
otv otv
N7k Po103 Po100 Po100 Po101 6500
Core
EAST_OTVA# show mac add vlan 201
Vlan 201: 10.201.0.1 Vlan 201: 10.201.0.3
Legend:
Vlan 202: 10.202.0.1 Vlan 202: 10.202.0.3
* - primary entry, G - Gateway MAC, (R) - Routed MAC, O - Overlay MAC
6c9c.ed40.1744 0014.f179.b640
age - seconds since last seen,+ - primary entry using vPC Peer-Link
VLAN MAC Address Type age Secure NTFY Ports/SWID.SSID.LID
---------+-----------------+--------+---------+------+----+------------------ Host 2, vlan 202
Host 1, vlan 201
* 201 0014.f179.b640 dynamic 0 F F Po101 10.202.0.102, GW: 10.202.0.3
10.201.0.101, GW: 10.201.0.1
O 201 6c9c.ed40.1744 dynamic 0 F F Overlay1 001f.6c75.1d46
001b.d419.1842
! Host1 (001b.d419.1842) MAC has been removed
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
Troubleshooting
ARP and CAM timer issue - Solution
Solution: Change 6500 ARP timer to be less than OTV CAM timer
CAM ARP
ARP CAM
30 min 25 min
25 min 30 min
West East
otv otv
N7k Po103 Po100 Po100 Po101 6500
Core
Vlan 201: 10.201.0.1 Vlan 201: 10.201.0.3
Vlan 202: 10.202.0.1 Vlan 202: 10.202.0.3
6c9c.ed40.1744 0014.f179.b640
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
Troubleshooting
Network Load Balancer Services
Some network load balancer services (NLBS) rely on flooding to reach all
devices in the cluster
Clusters that rely on a unicast IP to multicast MAC will be forwarded across
overlay in same fashion as a broadcast packet without any additional
configurations
Encapsulated within the control group (multicast transport)
Unicast to each OTV neighbour (unicast transport)
Clusters that rely on a unicast IP to unicast MAC will be dropped
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
Troubleshooting
Network Load Balancer Services - Solution
A static unicast MAC entry can be configured at a single site
EAST_OTVA# show run | i static
mac address-table static 0200.0ac9.00a2 vlan 201 interface port-channel101
Future support
EAST_OTVA# show otv route vlan 201
planned for selective
unicast flooding OTV Unicast MAC Routing Table For Overlay1
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
The Bridge with OTV
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
Q&A
Complete Your Online Session Evaluation
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
BRKDCT - 3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public
Appendix
ASR 1000
Support beginning in 3.5S Core
Advance Enterprise Image or Advance IP Service
(AES or AIS) to have the cli enabled
Extended and site VLANs configured via EFP’s and otv otv
bridge-domains
Multi-homing ASR and N7k OTV at same site is not
supported (must be located at different sites)
Support for multicast transport only (unicast
transport planned in future release)
http://www.cisco.com/en/US/docs/ios-
xml/ios/wan_otv/configuration/xe-3s/wan-otv-
confg.html
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Appendix
ASR 1000 – Configuration Internal Interface
Core
Site-ID and Site Bridge-Domain required
Bridge-Domain must be forwarding on internal
interface before adjacencies will be built
otv otv
otv site bridge-domain 210
otv site-identifier 0003.0003.0003
interface GigabitEthernet1/0/2
no ip address
cdp enable
Bridge-domain for an
extended VLAN service instance 201 ethernet
encapsulation dot1q 201
bridge-domain 201
Site Bridge-domain must
service instance 210 ethernet
be active on internal encapsulation dot1q 210
interface bridge-domain 210
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Appendix
ASR 1000 – Configuration Join Interface
Core
Join Interface must be configured with IGMPv3
for multicast transport.
Multicast routing must be enabled
Enable IGMP snooping querier otv otv
Configure PIM Passive mode on Join Interface
ip multicast-routing distributed
ip igmp snooping querier version 3
ip igmp snooping querier
interface GigabitEthernet1/0/1
mtu 9000
ip address 172.16.1.18 255.255.255.252
ip pim passive
ip igmp version 3
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 116
Appendix
ASR 1000 – Configuration Overlay
Core
Configure control and data-groups
Specify join-interface
Create service instance for each bridge-domain
that should be extended across overlay otv otv
Do not extend site bridge-domain
interface Overlay1
no ip address
otv control-group 239.1.1.1
otv data-group 232.1.1.0/24
otv join-interface GigabitEthernet1/0/1
service instance 201 ethernet
encapsulation dot1q 201
bridge-domain 201
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Appendix
ASR 1000 – Verify Overlay is UP
Core
SOUTH_OTVA#show otv
Overlay Interface Overlay1
VPN name : None
VPN ID : 1
State : UP otv otv
AED Capable : Yes
IPv4 control group : 239.1.1.1
Mcast data group range(s): 232.1.1.0/24
Join interface(s) : GigabitEthernet1/0/1
Join IPv4 address : 172.16.1.18
Tunnel interface(s) : Tunnel0
Encapsulation format : GRE/IPv4
Site Bridge-Domain : 210
Capability : Multicast-reachable
Is Adjacency Server : No
Adj Server Configured : No
Prim/Sec Adj Svr(s) : None
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Appendix
ASR 1000 – Verify Site Adjacency and AED
Core
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 119
Appendix
ASR 1000 – Verify Overlay Adjacencies
Core
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
Appendix
ASR 1000 – Verify Locally and Remotely Learned Routes
Core
SOUTH_OTVA#show bridge-domain 201 mac dynamic address
Port MAC Address
Gi1/0/2 ServInst 201 001a.e2be.52cd
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 121
Appendix
ASR 1000 – Multicast Local Receiver
Core
SOUTH_OTVA#show otv mroute
OTV Multicast Routing Table for Overlay1
Bridge-Domain = 201, s = *, g = *
Outgoing interface list:
Default, NoRedist
otv otv
(Bridge-domain, *,G) Incoming interface count = 0, Outgoing interface count = 1
programmed based on
IGMP join from client
Bridge-Domain = 201, s = *, g = 224.10.10.10
Outgoing interface list:
Service Instance 201, GigabitEthernet1/0/2
(Bridge-domain, S,G) Incoming interface count = 0, Outgoing interface count = 1
created to deliver to local
receiver once received Bridge-Domain = 201, s = 10.201.0.102, g = 224.10.10.10
from overlay Incoming interface list:
Service Instance 201, Overlay1, 001f.6c75.1d42
Incoming interface count = 1, Outgoing interface count = 0
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
Appendix
ASR 1000 – Multicast Local Receiver
Core
BRKDCT-3103 © 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 123
Appendix
ASR 1000 – Multicast Local Source
SOUTH_OTVA#show otv data-group
Core
No remote data-group mappings
Flags: D - Local active source dynamically detected
S - Local active source statically configured
J - Data group has been joined in the core Local Source Flag
U - Data group has not been joined in the core