With the LHR16 core switch, we needed it send traffic from the network_mgmt interface to a specific gateway. Because this device is a layer3 switch, it uses its routing table in order to handle this traffic, routing the response out either an attached interface (eg 10.16.63.1), or sending it to the ASR to be handled if there’s not a more specific route.
This behavior was controlled by this config line: pvlo-lhr16-sw-core-03509-rack46-01#sh run | inc ip route 0.0.0.0 ip route 0.0.0.0 0.0.0.0 10.16.1.2
Now, it is not desirable for us to change that system-wide default route. In order to get our desired behavior, with the interface 10.16.254.11 specifically using 10.16.254.1 as the gateway, we need to use a VRF. You can think of VRFs as basically a separate routing table for specific tagged traffic.
The 9500 comes with a default management VRF, Mgmt-vrf. Unfortunately, this is permanently bound to the management ethernet port Gi0/0. In Seattle, I used this port, but I wanted to find a more flexible solution for LHR (and everywhere else going forward). This is okay though, because we can just make our own VRF and use that for this purpose, on Vlan1801.
This manual describes the Mgmt-vrf, as well as related steps I used to set up our custom management VRF: https://www.cisco.com/c/en/us/td/docs/routers/asr1000/configuration/guide/chassis/xe-17/asr1000-software-config-guide-17-1/mgmt-ether-asr.pdf (I realize this is the manual for the ASR1000, but it’s the same content)
Here’s the commands I used to update this switch with the desired config. I also updated DNS and NTP addresses.
vrf definition pvlo-network-mgmt ! address-family ipv4 exit-address-family ! address-family ipv6 exit-address-family ! int vlan1801 description network_mgmt_lhr16 access vrf forwarding pvlo-network-mgmt ip add 10.16.254.11 255.255.255.0 ! ip route vrf pvlo-network-mgmt 0.0.0.0 0.0.0.0 10.16.254.1 ! no ip name-server 10.16.62.11 10.16.62.12 ip name-server 10.19.62.11 10.19.62.12 ip domain name vrf pvlo-network-mgmt pvlo.amazonavoc.com ip name-server vrf pvlo-network-mgmt 10.19.62.11 10.19.62.12 ip domain lookup vrf pvlo-network-mgmt source-interface vlan1801 ip tftp source-interface vlan1801 ! snmp-server source-interface traps Vlan1801 ! no logging host 10.19.64.12 no logging host 10.19.64.14 logging host 10.19.64.12 vrf pvlo-network-mgmt logging host 10.19.64.14 vrf pvlo-network-mgmt ! ! line vty 0 15 no access-class router-management in access-class router-management in vrfname pvlo-network-mgmt transport preferred none ! no ntp server 10.16.62.32 minpoll 10 prefer no ntp server 10.16.62.31 minpoll 10 prefer no ntp server 0.pool.ntp.org minpoll 10 ntp server vrf pvlo-network-mgmt 10.19.62.32 minpoll 10 prefer ntp server vrf pvlo-network-mgmt 10.19.62.31 minpoll 10 prefer ntp server 0.pool.ntp.org minpoll 10 ! call-home vrf pvlo-network-mgmt !
I *think* this is everything needed for the VRF setup on this core switch, but we should test everything including the logging, config backup, etc.