Site icon

L3out – Connecting to Active/Standby FW

A common use-case for ACI deployments is to attach a pair of firewalls northbound of ACI to filter traffic in and out of the fabric.

For this use case, we will be using “UNMANAGED” mode to connect the FW pair, by attaching the firewall via an L3out (External Routed Connection), and pointing static routes (0.0.0.0/0) to the firewall pair in question.

Assumptions for this design:

Prerequisites for this design:

Caveats for this design:

From our border leafs, (leaf 201/202), we will configure an SVI-based, L3out. HSRP-like functionality will be provided by selecting a “secondary” address for each of our border leafs, in this case, 10.1.1.1/24.

Configuration Steps

Define your L3out (Tenant > Networking > External Routed Networks)

Configure Node Profiles (a node profile for each border leaf)

Configure Interface Profiles (an interface profile for each border leaf)

Configure L3EPG

 

Exit mobile version