Cisco SD-WAN OMP Route and TLOC Verification Commands - 夜莺博客

Cisco SD-WAN OMP Route and TLOC Verification Commands

Overlay Management Protocol (OMP) is the control plane that makes Cisco SD-WAN more than a stack of IPsec tunnels: it carries the customer prefixes learned at each site together with the transport locators (TLOCs) that say how to reach them. When a branch prefix is unreachable over the SD-WAN fabric, the data plane is rarely the first suspect — the OMP route or its TLOC resolution usually is. This guide shows how OMP routes, TLOCs and service routes fit together, then lists the exact CLI commands that confirm or disprove each layer of overlay reachability on IOS XE Catalyst SD-WAN devices and vEdge-style routers.

What OMP carries across the overlay

OMP runs inside the DTLS/TLS control connections between an edge device and the SD-WAN Controller (vSmart). It never forwards data. Four route types travel over the session:

  • OMP routes (vRoutes) — customer prefixes with attributes such as TLOC, origin, originator, preference, site ID, VRF and the TLOC's originator.
  • TLOCs — a system IP address, a colour (link type such as biz-internet or mpls) and an encapsulation (IPsec or GRE). A vRoute that cannot resolve to a TLOC is unusable.
  • Service routes — service-side reachability, for example a firewall or IPS device behind a TLOC that traffic must be redirected through.
  • TLOC routes — attributes of the transport itself: preference, weight, carrier, and the private/public IP pair used for tunnel setup.

On an IOS XE device the local site advertises connected and static routes by default; dynamic protocols must be explicitly advertised into OMP:

config-transaction
 sdwan
  omp
   no shutdown
   address-family ipv4
    advertise static
    advertise connected
    advertise ospf external
    advertise bgp
   exit

Step 1: confirm the control connections are up

show sdwan control connections
show sdwan control connection-history
show sdwan control local-properties
show sdwan control affinity config

OMP state is only meaningful inside an established control connection to the Controller. If the peer personality vsmart shows up with a stable uptime, move on; if it shows challenge or teardown, fix orchestration (certificate, port 12346) before looking at routes.

Step 2: check the OMP peering and route counters

show sdwan omp peers
show sdwan omp summary
show sdwan omp routes
show sdwan omp routes vpn 1
show sdwan omp routes 192.168.10.0/24 detail

The peer table should list the Controller with STATE up. The summary exposes counters that matter operationally:

show sdwan omp summary
  oper-status          up
  num-routes-received  428
  num-routes-sent      176
  num-routes-installed 412
  route-discarded      0

A non-zero route-discarded usually means policy on the Controller is dropping prefixes — check control policy before blaming the transport.

Step 3: verify TLOC resolution for the prefix in question

show sdwan omp tlocs
show sdwan omp tlocs color biz-internet
show sdwan omp routes 0.0.0.0/0 detail
show sdwan omp tloc-paths

In the detail output for a prefix, confirm that tloc is populated, that state is resolved, and that the TLOC's encapsulation matches something both ends support. An OMP route with an unresolved TLOC appears in the overlay table but never lands in the transport FIB — the classic "I see the route but pings fail" symptom.

Step 4: follow the route into the RIB and FIB

show sdwan omp routes 10.20.30.0/24 detail
show ip route vrf 1
show ip route 10.20.30.0
show sdwan policy from-vsmart
show sdwan policy data-policy-filter

Locally, the OMP route competes with the site's own protocols using the configured administrative distance (default 250 for OMP on IOS XE, tunable with omp distance). If the prefix is in the OMP table but a static or BGP route to the same prefix wins in the VRF, traffic will never enter the fabric.

Symptom-to-cause quick map

  • OMP route present, no TLOC — transport tunnel down, wrong colour, or no matching TLOC route; check show sdwan omp tlocs and BFD state.
  • OMP route absent entirely — local route not advertised (missing advertise statement) or filtered by Controller policy.
  • Route learned but no traffic — OMP administrative distance or VRF route leaking; verify with show ip route vrf.
  • Intermittent prefix loss — BFD flapping on the transport; correlate with show sdwan bfd sessions.

Related reading: Cisco Catalyst SD-WAN architecture and components, BGP ECMP configuration across Cisco, Juniper and Arista, and gNMI streaming telemetry on IOS XE.

原文链接:https://www.cisco.com/c/en/us/td/docs/routers/sdwan/26x-later/routing/routing-configuration-guide/OMP-routing-protocol-ref/omp-route-advertisements.html