On this page
Source - Cisco NX-OS EVPN ESI multi-homing
Overview
Summary of Cisco NX-OS EVPN Ethernet Segment Identifier (ESI) multi-homing behavior used to define production baseline controls for multi-homed tenant attachment in EVPN/VXLAN fabrics.
Context
This source is used for target-lane failover, convergence, and fault-tolerance behavior where EVPN ESI multi-homing is selected as baseline instead of vPC-first attachment patterns.
Decisions
- Architecture usage in this vault: informs ESI baseline controls in openshift-evpn-production-target-baseline and implementation behavior in topic-network-nxos-evpn-implementation.
- Architecture usage in this vault: informs VIP/PIP transition expectations and L2FRR evidence checks.
- Policy adoption remains owned by ADR and architecture notes, not by this source summary.
Current State
- ESI multi-homing controls include RT1 signaling, Type-2 re-origination, DF election, and delay-restore timers.
- Next-hop behavior follows active-peer count: VIP with two or more active ESI peers, PIP when one peer remains.
- L2FRR protects traffic during convergence; in PIP mode, FRR anycast source IP is mandatory, shared within the ESI cluster where required, and unique across the fabric.
- Core-link tracking is required so ES state tracks upstream availability.
- EAD-EVI is disabled by default in NX-OS implementations where Type-2 re-origination already provides path visibility.
- Platform and release limits must be enforced in profile policy; for validated NX-OS 10.6(x) profiles this includes up to 4-way ESI and documented topology/mode constraints.
- vPC and ESI coexistence is constrained at node role level; a VTEP operates in either vPC-VTEP or ESI-VTEP mode for the scoped design.
References
- Cisco Nexus 9000 NX-OS VXLAN Configuration Guide, Release 10.6(x)
- Cisco Nexus 9000 Configuration Guides index
Future Work
- Pin ESI behavior and limits to the exact NX-OS train used in production evidence bundles.
- Add explicit failover test cases for PIP to VIP and VIP to PIP transitions in standard validation gates.