<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connetion between two borders nodes (Anywhere) in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4279371#M1091</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Because in the future i will connect my DataCenter ( ACI ) directly to the border node for this reason i think the best solution is anyware border&amp;nbsp;&lt;/P&gt;&lt;P&gt;i can't work with one border external and the other border internal because in my architecture i will guard the symmetric&lt;/P&gt;</description>
    <pubDate>Mon, 25 Jan 2021 22:50:22 GMT</pubDate>
    <dc:creator>oussama.benkraiem</dc:creator>
    <dc:date>2021-01-25T22:50:22Z</dc:date>
    <item>
      <title>Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4277496#M1085</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have two Border nodes Anyware and two fusion routers&amp;nbsp;&lt;BR /&gt;i configure EBGP bentween two borders (Anywhere) and two fusion&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i configure iBGP between the two border (Anywhere)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;B1--&amp;gt;Fusion1 : EBGP&lt;/P&gt;
&lt;P&gt;B2--&amp;gt;Fusion2 : EBGP&lt;/P&gt;
&lt;P&gt;B1--&amp;gt;B2 : iBGP&lt;/P&gt;
&lt;P&gt;when i loss the connection between B2 and Fusion router i check my routing table on B2 i see the default route 0.0.0.0 through the EDGE node with ISIS so in this stat i have my problem&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Community cisco.PNG" style="width: 615px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/102469i25763388FEAE7CC2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Community cisco.PNG" alt="Community cisco.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4277496#M1085</guid>
      <dc:creator>oussama.benkraiem</dc:creator>
      <dc:date>2021-01-25T21:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Connexion between two borders nodes(anyware)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4278031#M1086</link>
      <description>&lt;P&gt;You are receiving the default route from the edge because iBGP uses a higher administrative distance than IS-IS. Therefore Border 2 will prefer the default route which has been redistributed into IS-IS over the iBGP default route.&lt;/P&gt;&lt;P&gt;I would recommend 2 options:&lt;/P&gt;&lt;P&gt;1. Use IS-IS to connect the Border routers instead of iBGP, or&lt;/P&gt;&lt;P&gt;2. Use a new BGP AS on Border 2 to form an eBGP neighbourship instead of iBGP and advertise only the default route between them. With this method, you will need to ensure your eBGP route via the fusion router is more preferred than the eBGP route via Border 1.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 03:29:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4278031#M1086</guid>
      <dc:creator>Joshua Marks</dc:creator>
      <dc:date>2021-01-23T03:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4279338#M1090</link>
      <description>&lt;P&gt;Can I ask why you are using Anywhere border nodes?&lt;BR /&gt;Based on your topology, external-only appears to be the best option.&amp;nbsp; &lt;BR /&gt;In fact, external-only is really the best option for 95+% of use cases.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:55:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4279338#M1090</guid>
      <dc:creator>Jonathan Cuthbert</dc:creator>
      <dc:date>2021-01-25T21:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4279371#M1091</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Because in the future i will connect my DataCenter ( ACI ) directly to the border node for this reason i think the best solution is anyware border&amp;nbsp;&lt;/P&gt;&lt;P&gt;i can't work with one border external and the other border internal because in my architecture i will guard the symmetric&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 22:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4279371#M1091</guid>
      <dc:creator>oussama.benkraiem</dc:creator>
      <dc:date>2021-01-25T22:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4281817#M1099</link>
      <description>&lt;P&gt;Create an IS-IS peering between both borders using either an SVI or L3 interface, you can do it either manually or using lan automation.&lt;BR /&gt;&lt;BR /&gt;Then the default route will point to Border 1 using ISIS and this only is relevant for INFRA_VN/GRIB.&lt;BR /&gt;&lt;BR /&gt;If you still want&amp;nbsp; to use iBGP (even though using ISIS has no difference) you can use administrative distance to use iBGP:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ip access-list standard 95&lt;BR /&gt;10 permit 0.0.0.0&lt;BR /&gt;router isis&lt;BR /&gt;distance 201 0.0.0.0 255.255.255.255 95&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For VRF/VN default route communication, that is another story. But as you are mentioning IS-IS, I assume this is all-about underlay&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 23:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4281817#M1099</guid>
      <dc:creator>jalejand</dc:creator>
      <dc:date>2021-01-28T23:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4291988#M1141</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/270098"&gt;@Jonathan Cuthbert&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have always been sceptic about need of E-W routing interconnecs in legacy scenarios with similar topology :0) but looks like in SDA it's mandatory (i'd be glad to be mistaken :0)&lt;/P&gt;&lt;P&gt;so... can we replace "recommended" iBGP with unified fabric site underlay proto here?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 20:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4291988#M1141</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-02-15T20:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292019#M1142</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;&amp;nbsp;but looks like in SDA it's mandatory (i'd be glad to be mistaken :0)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If I may answer your question with another question:&lt;BR /&gt;&lt;BR /&gt;What do you think IBGP between redundant border nodes is "&lt;STRONG&gt;mandatory&lt;/STRONG&gt;?"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two of the most common questions or common misconceptions in SD-Access revolve around these two subjects:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;What kind of border node should I provision (Internal-Only, External-Only, and Anywhere)?&lt;/LI&gt;
&lt;LI&gt;Should I use IBGP between my redundant border nodes?&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Interestingly, both of these questions came up in this post.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;What kind of border node should I provision (Internal-Only, External-Only, and Anywhere)?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;I am currently recording some content for our YouTube channel that I hope will add additional clarity as an answer to this question.&amp;nbsp; To sum things up here, +95% of deployments should use external-only Border Nodes.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the diagram provided in the original question.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OPs Topology.png" style="width: 561px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104407i511C69263C880B85/image-size/large?v=v2&amp;amp;px=999" role="button" title="OPs Topology.png" alt="OPs Topology.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;These should be external-only border nodes. Based on the information provided, they should not be anywhere border nodes.&amp;nbsp; It's adding configuration (and thus &lt;EM&gt;potential&lt;/EM&gt; complexity/interactions) that are unneeded.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OPs Topology with CrossLinks.png" style="width: 561px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/104409i06438C876255FAC5/image-size/large?v=v2&amp;amp;px=999" role="button" title="OPs Topology with CrossLinks.png" alt="OPs Topology with CrossLinks.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Adding in even further, there should absolutely be crosslinks here.&amp;nbsp; This topology is a square. Square topologies do not provide the resilience and failover and deterministic convergence needed in networks today.&amp;nbsp; They should be avoided unless there is simply not enough fiber to make it possible.&amp;nbsp; Saying another way: avoid them unless there is absolutely no other choice.&amp;nbsp; I covered this heavily in the SD-Access CVD.&amp;nbsp; "&lt;I&gt;build triangles, not squares, to take advantage of equal-cost redundant paths for the best deterministic convergence&lt;/I&gt;."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html#Layer_3_Routed_Access_and_SDA_Design" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html#Layer_3_Routed_Access_and_SDA_Design&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html#External_Connectivity_Design_Considerati" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html#External_Connectivity_Design_Considerati&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.&amp;nbsp; Should I use IBGP between my redundant border nodes?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a question that is pretty large in scope to answer.&amp;nbsp; There is no definitive yes and definitive no.&amp;nbsp; It is all based on what the network is trying to accomplish along with the topology.&amp;nbsp; I am working on answering this question in all the variations and permutations in a guide I am working on.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Bear in mind that when we are discussing IBGP, we are asking two questions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Should I use IBGP between my redundant border nodes (in the underlay)&lt;/LI&gt;
&lt;LI&gt;Should I use IBGP between my redundant border nodes (in the overlay)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It's insufficient to just answer one and not the other, as they both accomplish completely different things and neither are strictly due to SDA.&amp;nbsp; The underlay question has to do with how to avoid using the IGP to 'heal' the BGP domain and the overlay question has to do with how to address VRFs continuity in BGP while providing deterministic failover and redundancy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 21:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292019#M1142</guid>
      <dc:creator>Jonathan Cuthbert</dc:creator>
      <dc:date>2021-02-15T21:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292201#M1144</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/270098"&gt;@Jonathan Cuthbert&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would answer then in this way: what if we remove LISP &amp;amp; stay with MPBGP/EVPN for overlay CP? :0)&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 08:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292201#M1144</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-02-16T08:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292373#M1145</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/270098"&gt;@Jonathan Cuthbert&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i would answer then in this way: what if we remove LISP &amp;amp; stay with MPBGP/EVPN for overlay CP? :0)&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This is a bit of a detour from the original conversation and perhaps best addressed in a whole new post.&lt;/P&gt;
&lt;P&gt;Would you mind opening a whole new question?&amp;nbsp; Happy to answer there.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 13:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292373#M1145</guid>
      <dc:creator>Jonathan Cuthbert</dc:creator>
      <dc:date>2021-02-16T13:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292579#M1147</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/28779"&gt;@jonathan&lt;/a&gt;&lt;/P&gt;&lt;P&gt;ok. let's come back to dynamic protocols on the BN's E-W &amp;amp; North perimeter. is dynamic protocol selection there only the subject of redundancy &amp;amp; fast convergency or also of adding some control information into LISP neither ISIS nor OSPF can provide?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S. i've found something optimistic. so other protocols r allowed , but not recommended. Why?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 19:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4292579#M1147</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2021-02-16T19:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Connetion between two borders nodes (Anywhere)</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4949425#M2735</link>
      <description>&lt;P&gt;Do I understand correctly that in the case of redundant borders running single AS, you still allow no iBGP session between them? Where I can find the guide that you were&lt;SPAN&gt;&amp;nbsp;working on?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 04:28:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/connetion-between-two-borders-nodes-anywhere/m-p/4949425#M2735</guid>
      <dc:creator>Michal Rzepecki</dc:creator>
      <dc:date>2023-10-27T04:28:33Z</dc:date>
    </item>
  </channel>
</rss>

