<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217594#M3586</link>
    <description>&lt;P&gt;First i would suggest to go through the deployment guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Campus/sda-fabric-deploy-2019oct.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Campus/sda-fabric-deploy-2019oct.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are pros and cons of both SVL and Seperated (better engage with system integrator or partner to deploy large scale deployment for the good suggest for Long term support)&lt;/P&gt;
&lt;P&gt;1. my view i go with seperate nodes Layer 3 model&lt;/P&gt;
&lt;P&gt;2. same question answered above.&lt;/P&gt;
&lt;P&gt;3. Its all depends on how you connection to the Uplink switch, the traffic flow depepends on where the Active Firewall located and what kind of Routing arrangement you have here.&lt;/P&gt;
&lt;P&gt;4. again that is purely what traffic need to go which firewall and your routing decision.&lt;/P&gt;
&lt;P&gt;5. check the design guide, where the WLC shouldbe ( should be in DC or manangement Domain) look is this SDA-Wireless or over the top.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2024 17:57:22 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2024-10-30T17:57:22Z</dc:date>
    <item>
      <title>Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configuration</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217588#M3585</link>
      <description>&lt;P&gt;Hey Cisco Community,&lt;/P&gt;&lt;P&gt;Sorry for long post.&lt;/P&gt;&lt;P&gt;We are working on an SDA solution for a customer who plans to retain a pair of 3rd party firewalls as the fusion device. This is entirely greenfield deployment.&lt;/P&gt;&lt;P&gt;Network design involves connecting border nodes to the fusion firewall via BGP, using VLANs on trunk interfaces (dot1q trunk). I would appreciate some insights from the community on a few questions related to this setup:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;We will deploy Catalyst 9600R as border nodes. Should we configure them as a Stackwise pair, or would it be better to set them up as two separate fabric borders?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If we proceed with separate borders rather than a StackWise setup, would we need to manually configure IBGP between the border nodes, or is there an option to automate this in a recent DNAC software release?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Given that the firewalls are in HA mode (active &amp;amp; standby), how would traffic flow be if the borders are configured in either Stackwise mode or as two separate nodes&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&amp;nbsp;The customer has two distinct firewalls—one for the Internet Edge (WAN/internet traffic) and another for the Data Center (DC traffic). Should we establish two separate BGP peering—one with the Internet Edge firewall for internet-bound traffic and another with the DC firewall for data center-bound traffic? This would help ensure that internet traffic routes through the Internet Edge firewall and DC traffic routes through the DC firewall.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Should the Cisco WLC connect in the DC&amp;nbsp; or directly to the border nodes? Should be fabric enabled or not?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 17:50:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217588#M3585</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-10-30T17:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217594#M3586</link>
      <description>&lt;P&gt;First i would suggest to go through the deployment guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Campus/sda-fabric-deploy-2019oct.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Campus/sda-fabric-deploy-2019oct.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are pros and cons of both SVL and Seperated (better engage with system integrator or partner to deploy large scale deployment for the good suggest for Long term support)&lt;/P&gt;
&lt;P&gt;1. my view i go with seperate nodes Layer 3 model&lt;/P&gt;
&lt;P&gt;2. same question answered above.&lt;/P&gt;
&lt;P&gt;3. Its all depends on how you connection to the Uplink switch, the traffic flow depepends on where the Active Firewall located and what kind of Routing arrangement you have here.&lt;/P&gt;
&lt;P&gt;4. again that is purely what traffic need to go which firewall and your routing decision.&lt;/P&gt;
&lt;P&gt;5. check the design guide, where the WLC shouldbe ( should be in DC or manangement Domain) look is this SDA-Wireless or over the top.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 17:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217594#M3586</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-10-30T17:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217618#M3587</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1- In seperate nodes Layer 3 model for BNs. would we need to manually configure IBGP between the border nodes, or is there an option to automate this in a recent DNAC software release?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2- I have drawn up diagram to better explain the proposed network design. Please feel free to add your valuable inputs and recommendations.&lt;/P&gt;&lt;P&gt;3- For routing&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;internet traffic routes through the Internet Edge firewall and DC traffic routes through the DC firewall.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Do we need setup two separate BGP peering—one with the Internet Edge firewall for internet-bound traffic and another with the DC firewall for data center-bound traffic? How would be VN/VRF setup here?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 18:32:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217618#M3587</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-10-30T18:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217666#M3588</link>
      <description>&lt;P&gt;1. I'd avoid consolidation of BN|CPs into Stackwise (unless it's FIAB but it's not your case afaiu). Some accounts still consolidate BN|CPs into VSL which make it more reliable than Stackwise. In this particular case VSL would fit better than others.&lt;BR /&gt;2. with Pub/Sub enabled it will be configured automatically in a single VPNV4 peering (no VRF Option A peering)&lt;BR /&gt;3. Keeping in mind that Active FW will be single point for eBGP peering with BN|CP layer, VSL'ed BN|CP will better fit here as there is single session is needed. Also BGP in case of FW failover will have better convergence. In case of separated BN|CPs u'll have 2 options: a) peering in the same transit VLAN (per VRF); b) peering in 2 different transit VLANs (per VRF) . In last case u'll need to configure 2xINSIDEs in the single Zone on the FW.&amp;nbsp;&lt;BR /&gt;4. basically it doesnt look like you have better options here :0)&lt;BR /&gt;5. I'd say WLC must be fabric enabled. U never connect it to BNs but outside the Fabric.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 19:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217666#M3588</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-10-30T19:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217696#M3589</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Some accounts still consolidate BN|CPs into VSL which make it more reliable than Stackwise. In this particular case VSL would fit better than others.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here you mean VSS. I second this, VSS would be much better to avoid create lot of BGP peerings. But VSS could be problamtic for maintenance window on software upgrade. BN/CP will be unavailable&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;with Pub/Sub enabled it will be configured automatically in a single VPNV4 peering (no VRF Option A peering)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I couldn't get this, could you please clarify more&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;basically it doesnt look like you have better options here :0)&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;But is it advisable or standard practice to make seperate bgp peering with each firewalls Internet Edge and DC, if the customer two seperate firewall deployments&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I'd say WLC must be fabric enabled. U never connect it to BNs but outside the Fabric.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In both cases Fabric enabled and non fabric enabled, where would WLC connect on the network&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 20:28:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5217696#M3589</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-10-30T20:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5218940#M3595</link>
      <description>&lt;P&gt;Appreciate any further suggestions&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 10:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5218940#M3595</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-11-02T10:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5218943#M3597</link>
      <description>&lt;P&gt;VSL vs Separated BN|CPs: it's up to u to decide looking on all cons&amp;amp;pros&lt;BR /&gt;VRF OptionA: is essentially peering in arbitrary VRF:&amp;nbsp;address-family ipv4 vrf CAPMUS. that is what BN|CPs are doing toward FNs.&lt;BR /&gt;between itselves they are peering in&amp;nbsp;address-family vpnv4. with this they exchange VPNV4 NLRIs for each their VRFs in single peering.&lt;BR /&gt;peering with FNs of different kind: CVD recommends to use separate BN-layers to peer with Internal entities &amp;amp; Internet (Internal BN &amp;amp; External BN). if u want to stay with single BN-layer u need to use Anywhere BN.&lt;BR /&gt;WLC location: u may use eWLC on the your BN|CPs. it will work both for VSL'ed &amp;amp; separate nodes. but with separate nodes your Wireless redundancy will base on primary &amp;amp; secondary WLS instead of HA SSO with VSL.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 11:26:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5218943#M3597</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-02T11:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5218965#M3602</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;In case of separated BN|CPs u'll have 2 options: a) peering in the same transit VLAN (per VRF); b) peering in 2 different transit VLANs (per VRF) . In last case u'll need to configure 2xINSIDEs in the single Zone on the FW.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For option B, do we need a dedicated L2 switch between firewalls and BN/CP?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 12:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5218965#M3602</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-11-02T12:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219001#M3604</link>
      <description>&lt;P&gt;no. u just connect each FW-unit to BN|CP1 &amp;amp; BN|CP2 with separate phy link. on both side it has to be interface with .1Q encap (l.s. VLAN 300-302 for peering with FW from BN|CP1 in 3 different VRFs &amp;amp; VLAN 310-312 for peering with FW from BN|CP2 in same 3 VRFs).&lt;BR /&gt;then u create sessions between FW (manually) &amp;amp; BN|CPs (L3-handoff workflows).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H4 id="toc-hId--1891542787"&gt;stuff u also have to consider (on the example of ASA &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118050-config-bgp-00.html#:~:text=individual%20routing%20protocols.-,BGP%20and%20Failover,-BGP%20is%20supported" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118050-config-bgp-00.html#:~:text=individual%20routing%20protocols.-,BGP%20and%20Failover,-BGP%20is%20supported&lt;/A&gt;&amp;nbsp;)&lt;/H4&gt;</description>
      <pubDate>Sat, 02 Nov 2024 13:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219001#M3604</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-02T13:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219028#M3609</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I updated the diagram. Given that, &lt;SPAN&gt;two separate borders, both border nodes would have separate, active BGP peerings with the Internet Edge and Data Center firewalls. Each border can independently route traffic to and from these firewalls.&amp;nbsp;Advertise a default route to the fusion firewalls from the internet firewalls.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Appreciate your valuable input&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 14:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219028#M3609</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-11-02T14:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219032#M3610</link>
      <description>&lt;P&gt;looks simple as diagrams from CVD :0)&lt;BR /&gt;1. there is also routed IS-IS link between BN|CPs which is used for IBGP peering in VPNv4 AF.&lt;BR /&gt;2. be encouraged to review all your Internet access use-cases to properly address it with that simple diagram&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 14:55:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219032#M3610</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-02T14:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219036#M3611</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why do we need iBGP between the borders as there will be no traffic passing on that link? Links from each border to the fusion is fine.&lt;/P&gt;&lt;P&gt;Fabric edge will have LISP sessions with both BN/CP kind of load balancing fashion.&lt;/P&gt;&lt;P&gt;Both borders having BGP peering with Fusion so again both BNs/CPs will load balance to Fusion as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 16:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219036#M3611</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-11-02T16:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219038#M3612</link>
      <description>&lt;P&gt;answer is here &lt;A href="https://community.cisco.com/t5/software-defined-access-sd-access/lisp-pub-sub-and-ibgp/td-p/5027862#:~:text=Hello%2C%20you%20will,Best%20regards%2C%20Jerome" target="_blank"&gt;https://community.cisco.com/t5/software-defined-access-sd-access/lisp-pub-sub-and-ibgp/td-p/5027862#:~:text=Hello%2C%20you%20will,Best%20regards%2C%20Jerome&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Nov 2024 16:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219038#M3612</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-02T16:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219274#M3616</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For border redundancy we will use the &lt;STRONG&gt;LISP Pub/Sub &lt;/STRONG&gt;when configuring them as BN/CP, this should allow for a dynamic default border setup.&lt;/P&gt;&lt;P&gt;I have updated network diagram.&lt;/P&gt;&lt;P&gt;We’ll also be setting up two physical links between the border nodes&amp;nbsp;My question is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Do these inter-border links need manual configuration, or will Cisco DNA Center automatically push and configure these links as part of the LISP Pub/Sub setup?&lt;/LI&gt;&lt;LI&gt;WLC will be fabric enabled. Can we connect WLC to upstream switches in Data center space (Nexus switches)&amp;nbsp; as shown in diagram but there is a firewall in between BNs and Nexus Switches&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Appreciate your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Nov 2024 19:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219274#M3616</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-11-03T19:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219481#M3621</link>
      <description>&lt;P&gt;Inter BN|CP link: it's stated to be configured automatically with PubSub:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-border-nodes-interconnection-design/td-p/5137340#:~:text=If%20the%20Fabric%20Site%20is%20Pub/Sub%20then%20there%27s%20no%20need%20for%20manual%20per%2DVRF%20IBGP%20between%20Border%20Nodes.%20The%20Catalyst%20Center%20will%20automatically%20configure%20VPNv4%20IBGP%20between%20BN%20and%20CP%20for%20route%20transport%20scenarios%2C" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-border-nodes-interconnection-design/td-p/5137340#:~:text=If%20the%20Fabric%20Site%20is%20Pub/Sub%20then%20there%27s%20no%20need%20for%20manual%20per%2DVRF%20IBGP%20between%20Border%20Nodes.%20The%20Catalyst%20Center%20will%20automatically%20configure%20VPNv4%20IBGP%20between%20BN%20and%20CP%20for%20route%20transport%20scenarios%2C&lt;/A&gt;&amp;nbsp;. But i observe Cisco CX prefers to configure it manually as part of prestaging before migrations in brown fields... i didnt try automation of this subject.&lt;BR /&gt;WLC: if u have solid reasons to avoid Primary/Secondary eWLC deployment on BN|CPs u can do it as soon as RTTs etc stuff is compliant to SDA requirements. i'm sure u wont forget to open CAPWAP &amp;amp; LISP on the FW for APs-WLC &amp;amp; CP-WLC interfactions.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 08:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219481#M3621</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-04T08:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219642#M3622</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for all the feedback! Appreciate your time&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We’ve updated the design to use the data center distribution switch as the Fusion device for L3 handoff. The firewalls will also connect to this L3 switch, and we’ll assign the zones or interfaces on the firewalls to specific VRFs accordingly to advertise the routes.&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;If we connect the WLC to the Fusion device, what’s the best approach to allow Fabric-enabled APs to reach the WLC.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Additionally, if we utilize LISP Pub/Sub to&lt;SPAN&gt;&amp;nbsp;achieve Border Redundancy, would a physical link between the BN/CP nodes required?&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 12:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219642#M3622</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-11-04T12:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219680#M3623</link>
      <description>&lt;P&gt;1. sounds good&lt;BR /&gt;2. Approach for APs to reach WLC doesnt change. It's CAPWAP.&lt;BR /&gt;3.&amp;nbsp;&lt;A href="https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-border-nodes-interconnection-design/td-p/5137340#:~:text=The%20CatC%20automated,of%20this%20thread" target="_blank"&gt;https://community.cisco.com/t5/software-defined-access-sd-access/sd-access-border-nodes-interconnection-design/td-p/5137340#:~:text=The%20CatC%20automated,of%20this%20thread&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 13:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219680#M3623</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-04T13:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219959#M3628</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;many thanks for your replies and appreciate your time and efforts. This discussion is getting interesting and learning new things.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Since we updated the design and introduced Nexus Switch as Fusion,&amp;nbsp;what’s the recommended L3 handoff configuration now?. Firewalls HA are connected to the same Nexus switches as well.&lt;/LI&gt;&lt;LI&gt;For border redundancy, if the Fabric Site is Pub/Sub and BN/CP&amp;nbsp;are combined on the same physical device, per-VRF (VPNv4) iBGP sessions are indeed handled automatically configured by the Catalyst Center.&amp;nbsp;No Need for a Physical Link Between BN/CP Nodes?&lt;/LI&gt;&lt;LI&gt;What happens if BN1/CP1 loses connectivity with the Fusion switch or if BN1/CP1 fails completely? How does the convergence occur?&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 04 Nov 2024 21:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5219959#M3628</guid>
      <dc:creator>thenetadmin</dc:creator>
      <dc:date>2024-11-04T21:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5220180#M3631</link>
      <description>&lt;P&gt;Hi, haven't digested the whole thread, just answering the most recent question.&lt;/P&gt;
&lt;P&gt;1. In a Pub/Sub network each BN should have at least one Layer 3 handoff (EBGP peering) to fusion device.&lt;/P&gt;
&lt;P&gt;2. It's not strictly necessary but it is recommended to have at least one point-to-point routed underlay link between BN pairs. That link would use whatever routing protocol the rest of the underlay uses e.g. ISIS.&lt;/P&gt;
&lt;P&gt;3. If BN1/CP1 loses connectivity to fusion it essentially removes itself&amp;nbsp; a valid path in LISP Pub/Sub, I will be covering this in my new Cisco Live Melbourne LISP talk next week, remind me in a few weeks and I'll share the recording link, if you're interested. If BN1/CP1 completely fails then it is withdrawn from underly IGP and that triggers all other nodes in the SDA fabric to route to BN2/CP2.&lt;/P&gt;
&lt;P&gt;Best regards, Jerome&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 07:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5220180#M3631</guid>
      <dc:creator>jedolphi</dc:creator>
      <dc:date>2024-11-05T07:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Seeking Guidance on SDA Deployment - Fusion FWs and BGP Configurat</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5220183#M3632</link>
      <description>&lt;P&gt;1. Recommended L3-handoff is one automated by DNAC via co-named workflow in BN|CP configuration pane.&lt;BR /&gt;2. u could conclude that w/o direct link bw BN|CPs &amp;amp; still BGP automated between BN|CP's Lo0 session would traverse EdgeNode layer. Does it sound good for u?&lt;BR /&gt;3. BN|CP1 either undeclares itself as PETR or disappear form Underlay &amp;amp; thus stops to participate in traffic transfer. Convergence occurs as usually - from lower to up layers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 07:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/seeking-guidance-on-sda-deployment-fusion-fws-and-bgp/m-p/5220183#M3632</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-05T07:39:42Z</dc:date>
    </item>
  </channel>
</rss>

