Guest

Preview Tool

Cisco Bug: CSCvs78956 - N9K: IPv6 RAGuard policy with device-role router causes RAs to have incorrect FCS

Last Modified

Jun 12, 2020

Products (1)

  • Cisco Nexus 9000 Series Switches

Known Affected Releases

7.0(3)I7(7)

Description (partial)

Symptom:
The issue occurs on a leaf switch where RAGuard with device role router is configured.
We have a client router sending IPv6 RAs to the leaf and the policy is applied on this interface. This results in the RAs having an incorrect FCS.

e.g.:

Leaf1 has below policy:

ipv6 nd raguard policy ROUTER
 device-role router

int e1/1
  switchport
  switchport access vlan 1001
  ipv6 nd raguard attach-policy ROUTER

int e1/2
 switchport
 switchport access vlan 1001

Client Router (IPV6) --- e1/1 leaf e1/2 --- spine

The client router sends RAs towards the leaf. These RAs are then flooded out towards the spine, however the RAs have an incorrect FCS.

Conditions:
This issue is observed when RAGuard policy with device-role router is applied on the client facing interface.
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.