Preview Tool

Cisco Bug: CSCun99528 - N7K ARP packets dropped by netstack with F1 linecard and private-vlan

Last Modified

Feb 27, 2018

Products (7)

  • Cisco Nexus 7000 Series Switches
  • Cisco Nexus 7000 10-Slot Switch
  • Cisco Nexus 7000 4-Slot Switch
  • Cisco Nexus 7000 18-Slot Switch
  • Cisco Nexus 7700 18-Slot Switch
  • Cisco Nexus 7000 9-Slot Switch
  • Cisco Nexus 7700 10-Slot Switch

Known Affected Releases

5.2(9) 6.1(3) 6.2(2a)

Description (partial)

On VPC environment with private-vlan configuration we can see that for traffic, which is not going directly to access switch, but through peer and peer-link, ARP is not being resolved and communication is broken.

This happens due to ARP replies are dropped on return path on F1 peer-link at receiving peer (source of ICMP requests) as they not correctly processed - as reply sent in secondary private-vlan. (This is due ARP tunneling mechanism implemented on F1 ports)

To see issue this should be met: 
- VPC with peer-gateway enabled
- private-vlan configured on Nexus 7000 and access switch
- peer-link should be built on F1 ports
- traffic affected should go not directly to access switch but through peer and peer-link
Bug details contain sensitive information and therefore require a account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.