cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
519
Views
0
Helpful
1
Replies

ACI L3OUT query

hashimwajid1
Level 3
Level 3

Hi Team,

 

I've 2 queries about ACI L3OUT and Connectivity with Firewall.

 

1- when we configure L3OUT with static routing, do we have to call L3OUT inside Bridge Domain  (I've seen one customer configured L3OUT but did not call under Bridge Domain) and its working fine ? only Contract configured between EPGs and L3OUT.

 

2- we've 2 x Uplink firewall for L3OUT connectivity with static routing and each firewall will be connecting with Border Leaf (FW01 will connect with Leaf01 only and FW02 will connect with Leaf02 only) we have to configure static routing and on firewall it will be port channel for VLAN 10 (VLAN10 will be used between FW and border Leaf) FW01 will be active and FW02 will be Standby.

 

FW01 >>>>> Leaf01 

FW02 >>>>> Leaf02 

 

 

may I know what configuration we should configure only on ACI ?

1- shall we configure single vPC on ACI for both Firewalls or do we need to configure separate vPC for both firewalls. 

2- and on ACI I'll be configuring SVI along with secondary IP as VIP ? 

 

Thanks in Advance

1 Reply 1

marce1000
VIP
VIP

 

 - You may find this document useful :

            https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/guide-c07-743150.html

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !
Review Cisco Networking products for a $25 gift card