Bridge Assurance is enabled by default when configuring vPC peer-link. Do not disable it on vPC peer-link It is not necessary to enable Bridge Assurance on vPC (Bridge Assurance is enabled when the vPC member port is defined as spanning-tree port type network) Configure vPC member port as spanning-tree port type normal (so not using Bridge Assurance on the link) Reference: https://networkengineering.stackexchange.com/questions/49638/bridge-assurance-with-vpc-on- port-type-network