Symptom
A limitation exists on first-generation Cisco Nexus 9000 devices with Broadcom ASICs where a policy-based routing (PBR) route map with a set ip next-hop statement that resolves to an egress interface of the vPC Peer-Link while the vPC Convergence TCAM region is allocated will drop policy-based routed traffic.
Conditions
1. First-generation Broadcom-based Nexus 9300 series switch or first-generation Broadcom-based Nexus 9500 series line card
2. vPC Convergence TCAM region is allocated (which is the default setting)
3. Policy-based routing (PBR) policy is applied to an interface with a set ip next-hop statement.
4. IP defined in set ip next-hop statement resolves to using the vPC Peer-Link as the egress interface.
Workaround
Disable the vPC Convergence TCAM region by configuring "hardware access-list tcam region vpc-convergence 0", then reloading the Nexus device.
Further Problem Description
This bug corrects the following configuration guides to document this limitation:
* Cisco Nexus 9000 Series NX-OS Interfaces Configuration Guides
* Cisco Nexus 9000 Series NX-OS Unicast Routing Configuration Guides
Additional details about the limitation itself can be found in CSCur87839.