Comprehensive and Detailed 200 to 250 words of Explanation From Designing Cisco Data Center Infrastructure for Traditional and AI Workloads topics:
Option D is the only valid combination matching all three requirements. Enabling Enforce Subnet Check restricts endpoint IP learning to subnets configured within bridge domains associated with the VRF. It also removes inappropriate remote endpoint entries. Consequently, a border leaf without a valid remote endpoint entry forwards the traffic through the Cisco ACI spine proxy and COOP database instead of relying on stale endpoint information. Cisco recommends this control to improve endpoint-learning accuracy and reduce IP-spoofing risks. Cisco ACI Fabric Endpoint Learning White Paper
Egress Policy Control enforcement places L3Out contract classification and policy enforcement primarily on the border leaf. This is required when incoming external traffic must be classified at the L3Out rather than forwarding it to a compute leaf for ingress enforcement. Cisco explains that egress enforcement keeps the external EPG classification and relevant policy rules on the border leaf. Cisco ACI Contract Guide
IP Data-plane Learning must remain enabled so leaf switches learn an endpoint’s source IP address from routed traffic. When the endpoint moves and transmits from another leaf, the new leaf immediately learns the updated location and advertises it to the spine COOP database. Disabling this feature would make IP movement detection dependent primarily on ARP, GARP, or other control-plane mechanisms. Cisco ACI Design Guide
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit