<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L3 port-channel between Borders &amp;amp; Fabric nodes in Cisco Catalyst Center</title>
    <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456912#M3966</link>
    <description>&lt;P&gt;A6: We are getting into some questions about the design here, and I think you should try and follow the Design guides. You can connect servers in a lot of ways. Configure them in a DMZ on the Fusion Router/firewall, connect them on a port on the borders, that are not part of the fabric, or put them in the central datacenter.&lt;/P&gt;&lt;P&gt;Remember that the ISE servers needs to be accessible in the underlay. And the L2 handoff feature is only for overlay handoff.&lt;/P&gt;&lt;P&gt;Take a look at figure 1 here:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A7: take a look at the design guide to see what handoff mode you need:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In the examples I have seen we only have 1 set of bordernodes and they do all traffic handoff. Hence they are&amp;nbsp;&lt;SPAN&gt;EXTERNAL &amp;amp; INTERNAL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Take a look at figure 21 and 22:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You default route in the fabric will be an external BN, and if you only want internal specific routes you need the internal BN feature.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Aug 2021 13:37:55 GMT</pubDate>
    <dc:creator>rasmus.elmholt</dc:creator>
    <dc:date>2021-08-30T13:37:55Z</dc:date>
    <item>
      <title>L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4455549#M3938</link>
      <description>&lt;P&gt;The customer asked the below for example to increase the BW&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fabric nodex---------L3 port-channel(2x links)---------Border 1-----------EBGP------Fusion&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;---------L3 port-channel(2 x links)---------Border-2-----------EBGP------Fusion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the DNAC is out of the fabric so to discover the fabric , we will use the routed mode and ISIS configuration between the fabric nodes and the Border-1 &amp;amp; 2&amp;nbsp; and then EBGP between the two borders and the Fusion so my question&amp;nbsp; can i configure L3 port-channel between the fabirc-nodes and the Borders and then apply the ISIS configuration between them manually or the L3 port-channel between them is not supported&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 18:54:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4455549#M3938</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-26T18:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456210#M3944</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can make the underlay as you want, the only important thing for the fabric is L3 routing between the Loopback interfaces on all the nodes(FE-&amp;gt;BN). So yes, you could make a L3 LAG between the FE and the BN and run ISIS on that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I would personally just configure all 4 links as routed links and then let my ECMP handle the load balancing, since it IMHO does it better than LAG.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you do choose to use a LAG remember to tune the load-balancing as the Cat9k is using L2 src-mac(as far as i remember) as the default for load balancing:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/configuration_guide/b_166_lyr2_lyr3_9300_cg/b_166_lyr2_lyr3_9300_cg_chapter_011.html#con_1275731" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-6/configuration_guide/b_166_lyr2_lyr3_9300_cg/b_166_lyr2_lyr3_9300_cg_chapter_011.html#con_1275731&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And source MAC could not make sense on a L3 LAG, as all packets have the same source MAC address.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 02:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456210#M3944</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2021-08-28T02:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456249#M3946</link>
      <description>&lt;P&gt;Thanks for your answer so if i will use normal routed interface dual homed to the border without aggregation ,,the end points which connected to the edge nodes can utilize the two links through the isis when will go to the border , my target to utilize the two links correct ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fabric nodex---------1 x link ISIS---------Border 1-----------EBGP------Fusion&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;---------1 x LINK ISIS---------Border-2-----------EBGP------Fusion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 08:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456249#M3946</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-28T08:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456295#M3947</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I thought you would have 4 links in all. 2 from the EN to each BN?&lt;/P&gt;&lt;P&gt;Yes, they will use both borders and links, remember that alle user traffic is encapsulated in VXLAN, so the EN will use both equal cost path from its own Loopback interface to the BNs Loopback interface.&lt;/P&gt;&lt;P&gt;Yes, both BNs will be used to loadbalance traffic, please be aware of asynchronous routing and the support for such on the Fusion Firewall&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 11:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456295#M3947</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2021-08-28T11:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456310#M3949</link>
      <description>&lt;P&gt;I added more links to increase the bw because i think the edge nodes with two to borders will use one link but the isis will make load balance&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the fusion will be cat 9500 and there will be bgp for the global to discover the relay and bgp per vrf for the traffic for each vn and the border will be external to be a default router for the edge nodes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have another question&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;two borders——-shared service——fusion&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;——-employee&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;——-contract&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ——non-it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fusion————dc fw(shared services)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ————dmz fw (internet , voice gw)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my question&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;between the two borders and fusion woll be bgp per vrf and leaking between the shared services and the other vpn’s&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and from fusion to dc fw. ,, vrf shared service from fusion and global from dc fw and i will make ibgp to advertise the shared service subnets correct ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;for the fusion and dmz fw &amp;nbsp;,,, vrf shared service from fusion and global from dmz fw and i will make default route point to dmz fw and router back in the dmz fw&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so i will make the fusion router as a default route for the border by add command neigbour default-orginate in fusion for each neighbor per vrf with border correct ?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 13:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456310#M3949</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-28T13:52:25Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456360#M3950</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am not sure I follow your questions 100% but it seems like you got the essence of it.&lt;/P&gt;&lt;P&gt;The BN to Fusion connection is like any other VRF-Lite setup. Each VN on each VLAN.&lt;/P&gt;&lt;P&gt;The scenarios I have done the border nodes, handed the traffic of in each VRF/VN/VLAN towards the fusion firewall, and on the firewall it was all in the Global routing table. Or if you want, you can keep one of the VRF(Guest normally) in its own VRF/context.&lt;/P&gt;&lt;P&gt;You can even do route leaking just at you would in a normal VRF-Lite setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 20:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456360#M3950</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2021-08-28T20:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456372#M3951</link>
      <description>&lt;P&gt;Thanks for your answer but i means&amp;nbsp; i have the below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edge nodes-----------2x Borders---------Fusion----------DC FW(shared services DHCP , DNS , DNAC)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ----------DMZ FW-------Voice GW + Internet routers&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2x Borders---EBGP------Shared servcie VN---- Fusion&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;---EBGP------Employee------------&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ----EBGP-----Contract-------------&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And there will be a leaking between VN's to make the Shared service subnets &amp;amp; Employee &amp;amp; Contract to reach to each other&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions here&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q1:&lt;/P&gt;&lt;P&gt;from Fusion----IBGP--Shared-service VN-------Global--FW DC (subents of the DHCP , DNAC , NTP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question , The DC FW will make IBGP with the fusion to send the shared service subnets as well as to recieve the subnets of the employees &amp;amp; contract and it is ok correct ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;from Fusion---Shared Service VN-----Static-----DMZ FW------Voice GW&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ------Internet routers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question between fusion and the DMZ FW , how i can make te routing ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assumed to use vrf Shared Service from the fusion router and global from DMZ FW and make the static routes in the two direction (from fusion default route point to the DMZ FW under this vrf&amp;nbsp; &amp;amp; from DMZ FW routes back for the employees &amp;amp; Contract subnets) correct ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q3:&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the border per vrf (employees , contract ) need default route point to the Fusion if any end point need (employee , contract) to access the internet so i will add command neigbour default-originate&amp;nbsp; from fusion per vrf point to the border to send default route to the border per vrf correct ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Aug 2021 21:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456372#M3951</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-28T21:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456518#M3953</link>
      <description>&lt;P&gt;A1: yes, this seems correct.&lt;/P&gt;&lt;P&gt;A2: This is an ok option to configure it that way as well.&lt;/P&gt;&lt;P&gt;A3: Yes this is the way I would do it as well.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 13:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456518#M3953</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2021-08-29T13:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456534#M3954</link>
      <description>&lt;P&gt;Thanks for your answers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another questions:-&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q1:&lt;/P&gt;&lt;P&gt;I have ISE (access port) will connect the Borders direct so i will configure this port as a Layer 2 handoff but this will generate the port as a trunk but it should be access because the ISE port is access how i can fix this problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q2:&lt;/P&gt;&lt;P&gt;As you see that the Border will be a GW for the outside so i will select it as external or internal + external when i will configure L3 handoff&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 14:47:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456534#M3954</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-29T14:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456864#M3964</link>
      <description>&lt;P&gt;Sorry for another questions below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q6:&lt;/P&gt;&lt;P&gt;I have ISE (access port) will connect the Borders direct so i will configure this port as a Layer 2 handoff but this will generate the port as a trunk but it should be access because the ISE port is supported only access port how i can fix this problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q7:&lt;/P&gt;&lt;P&gt;As you see that the Border will be a GW for the outside so i will select it as external or internal + external when i will configure L3 handoff&amp;nbsp; or external will be enough&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 11:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456864#M3964</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-30T11:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456912#M3966</link>
      <description>&lt;P&gt;A6: We are getting into some questions about the design here, and I think you should try and follow the Design guides. You can connect servers in a lot of ways. Configure them in a DMZ on the Fusion Router/firewall, connect them on a port on the borders, that are not part of the fabric, or put them in the central datacenter.&lt;/P&gt;&lt;P&gt;Remember that the ISE servers needs to be accessible in the underlay. And the L2 handoff feature is only for overlay handoff.&lt;/P&gt;&lt;P&gt;Take a look at figure 1 here:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/213525-sda-steps-to-configure-fusion-router.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A7: take a look at the design guide to see what handoff mode you need:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In the examples I have seen we only have 1 set of bordernodes and they do all traffic handoff. Hence they are&amp;nbsp;&lt;SPAN&gt;EXTERNAL &amp;amp; INTERNAL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Take a look at figure 21 and 22:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You default route in the fabric will be an external BN, and if you only want internal specific routes you need the internal BN feature.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 13:37:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456912#M3966</guid>
      <dc:creator>rasmus.elmholt</dc:creator>
      <dc:date>2021-08-30T13:37:55Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456961#M3968</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Remember that the ISE servers needs to be accessible in the underlay. And the L2 handoff feature is only for overlay handoff.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Waleed(said) No , we need the ISE to connect overlay to get the reachability only to be reachable to the DNAC which connected to behind the DC-FW and i think the L2 handoff will be Ok and i asked cisco and they recomended to connect it to the Border but my question here layer2 handoff will generate trunk configuration but ISE data ports is supported only access (not tagging)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For Q7:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;External is enough , so the border will be the GW for any destination that any end point need to reach&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 14:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456961#M3968</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-30T14:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456978#M3969</link>
      <description>&lt;P&gt;Sorry answer for&amp;nbsp; Q7 , I will use the Border for handoff L3 as a Internal + external option to use the lisp for the known subnets because i will get the known subnets from the DC(e.g. DHCP&amp;nbsp; , DNAC )nd normal default route for the internet (unknow subnets)&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 14:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4456978#M3969</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-30T14:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4457155#M3973</link>
      <description>&lt;P&gt;For A6:-&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Waleed(said) I dont think so , we need the ISE to connect overlay to get the reachability only to be reachable to the DNAC which connected to behind the DC-FW to integrate&amp;nbsp;with it&amp;nbsp; and i think the L2 handoff will be Ok and i asked cisco and they recomended to connect it to the Border directly but my question here &lt;U&gt;layer2 handoff will generate trunk configuration but ISE data ports is supported only access (not tagging) how i can solve this issue ?&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edge Nodes--------Border---------Fusion-------DC FW----(Shared services DNAC , DHCP , DNS)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;/&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A7:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;I will use the Border for handoff L3 as a Internal + external option to use the lisp for the known subnets because i will get the known subnets from the DC(e.g. DHCP&amp;nbsp; , DNAC )nd normal default route for the internet (unknow subnets) correct ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 20:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4457155#M3973</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-08-30T20:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: L3 port-channel between Borders &amp; Fabric nodes</title>
      <link>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4458345#M3982</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Waleed(said) I dont think so , we need the ISE to connect overlay to get the reachability only to be reachable to the DNAC which connected to behind the DC-FW to integrate&amp;nbsp;with it&amp;nbsp; and i think the L2 handoff will be Ok and i asked cisco and they recomended to connect it to the Border directly but my question here&amp;nbsp;&lt;U&gt;layer2 handoff will generate trunk configuration but ISE data ports is supported only access (not tagging) how i can solve this issue ? or i can remove the two ISE to connect the DC FW&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edge Nodes--------Border---------Fusion-------DC FW----( DNAC , DHCP , DNS) , Connect ISE here ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;/&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ISE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A7:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;I will use the Border for handoff L3 as a Internal + external option to use the lisp for the known subnets because i will get the known subnets from the DC(e.g. DHCP&amp;nbsp; , DNAC )nd normal default route for the internet (unknow subnets) correct ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 15:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-catalyst-center/l3-port-channel-between-borders-amp-fabric-nodes/m-p/4458345#M3982</guid>
      <dc:creator>waleedmatter</dc:creator>
      <dc:date>2021-09-01T15:46:22Z</dc:date>
    </item>
  </channel>
</rss>

