Recommended Settings for the Cisco Application Policy Infrastructure Controller
We recommend the following settings for the Cisco Application Policy Infrastructure Controller (Cisco APIC):
Navigation Path |
Property |
Value |
Description |
---|---|---|---|
|
Enforce Subnet Check |
Put a check in the box. |
This feature enforces subnet checks at the VRF instance level, when the Cisco Application Centric Infrastructure (Cisco ACI) learns the IP address as an endpoint from the data plane. Although the subnet check scope is the VRF instance, this feature can be enabled and disabled only globally under the fabric-wide setting policy. You cannot enable this option only in one VRF instance. If you put a check in the box for this option, the fabric will not learn IP addresses from a subnet other than the one configured on the bridge domain. This feature prevents the fabric from learning endpoint information in this scenario. |
|
IP Aging Policy |
Enabled |
The IP aging policy tracks and ages unused IP addresses on an endpoint. Tracking is performed by using the endpoint retention policy, which is configured for the bridge domain to send ARP requests (for IPv4) and neighbor solicitations (for IPv6) at 75% of the local endpoint aging interval. When no response is received from an IP address, that IP address is aged out. |
|
Admin State |
Enabled |
This enables the Mis-cabling Protocol (MCP) |
Controls: Enable MCP PDU per VLAN |
Put a check in the box. |
MCP detects other types of loops that can be caused by various issues, such as misconfiguration, that LLDP and STP cannot discover. This option enables MCP to send packets on a per-EPG basis. |