<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route single VRF Traffic to another Interface in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224771#M3712</link>
    <description>&lt;P&gt;it's well known fact that FNs r not part of the Fabric in supported designs as well as VPNv4 BGP AIF Option A is used for BN-FN peering. it doesnt bring any matter to analysis yet to be done. as i said above: start with investigation on FNs of how default route gets injected into VRF.&amp;nbsp;&lt;BR /&gt;UPD. i guess simplest way for u would be replacing target VRF's interconnect on FNs from that toward Core to&amp;nbsp; one toward new FW. Injection of default route into VRF on FNs is matter of technique.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2024 10:06:23 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2024-11-15T10:06:23Z</dc:date>
    <item>
      <title>Route single VRF Traffic to another Interface</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224716#M3709</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a requirement where we need to route single VRF (SSOL_Vrf) Traffic in SDA Fabric. Currently all vrf traffic is being forwarded based on default route, as a new requirement we need to forward it to new&amp;nbsp; firewall being a part of SDA Fabric.&lt;/P&gt;&lt;P&gt;Sharing topology below for your reference and Border1 and&amp;nbsp; Fusion 1 switch Configuration for review&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="otgnwp_0-1731647523699.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/233892i7971E161C061B85D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="otgnwp_0-1731647523699.png" alt="otgnwp_0-1731647523699.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mohammed Asif&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 05:16:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224716#M3709</guid>
      <dc:creator>otgnwp</dc:creator>
      <dc:date>2024-11-15T05:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Route single VRF Traffic to another Interface</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224723#M3710</link>
      <description>&lt;P&gt;i'd start with analysis of how default route currently injected into VRF (FNs would be good place to start) &amp;amp; then develop action plane to replace it with one from new FW.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 05:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224723#M3710</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-15T05:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Route single VRF Traffic to another Interface</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224729#M3711</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Please refer attached Border 1 Switch and Fusion 1 Switch configuration.&lt;/P&gt;&lt;P&gt;Border 1 Switch is part of SDA Fabric. Where as Fusion 1 Switch not a part of SDA fabric. BGP routing Protocol uses between Border 1 switch and Fusion 1 switch to route vrf traffic outside SDA Fabric.&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mohammed Asif&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 06:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224729#M3711</guid>
      <dc:creator>otgnwp</dc:creator>
      <dc:date>2024-11-15T06:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Route single VRF Traffic to another Interface</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224771#M3712</link>
      <description>&lt;P&gt;it's well known fact that FNs r not part of the Fabric in supported designs as well as VPNv4 BGP AIF Option A is used for BN-FN peering. it doesnt bring any matter to analysis yet to be done. as i said above: start with investigation on FNs of how default route gets injected into VRF.&amp;nbsp;&lt;BR /&gt;UPD. i guess simplest way for u would be replacing target VRF's interconnect on FNs from that toward Core to&amp;nbsp; one toward new FW. Injection of default route into VRF on FNs is matter of technique.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 10:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224771#M3712</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-15T10:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Route single VRF Traffic to another Interface</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224789#M3713</link>
      <description>&lt;P&gt;Am I interpreting this correctly?&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Traffic is currently being routed to your fusion node, which in turn is forwarding it directly to the core&lt;/LI&gt;&lt;LI&gt;You wish to force this traffic to be routed towards your firewall from your fusion node&lt;/LI&gt;&lt;LI&gt;The firewall is external to the fabric, as shown in your topology drawing&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;If that is the case I would configure a new "intermediate" VRF on your fusion nodes used only for routing between the border and your firewall. This way you can have&amp;nbsp;one FW interface in each VRF(one in the "SDA peering" VRF and one in the "upstream" VRF) to force traffic through your FW. I would also consider connecting both fusion nodes to the firewall such that you get fusion node redundancy for the VRF.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see the following diagram for a better depiction of what I mean:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="community.png" style="width: 370px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/233901iB77E01C686158C8C/image-size/large?v=v2&amp;amp;px=999" role="button" title="community.png" alt="community.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 08:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224789#M3713</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-11-15T08:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Route single VRF Traffic to another Interface</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224795#M3714</link>
      <description>&lt;P&gt;Hi Torbjon,&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Thanks for Response,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Traffic is currently being routed to your fusion node, which in turn is forwarding it directly to the core - Yes&lt;/LI&gt;&lt;LI&gt;You wish to force this traffic to be routed towards your firewall from your fusion node - Yes, i have Mutliple Vrf Border node, which i need route only one vrf traffic to New Firewall not all vrf Traffic.&lt;/LI&gt;&lt;LI&gt;Will Intermediate Vrf forward traffic of all vrf or only single vrf i.e; SSOL_Vrf.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks in Advance,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mohammed Asif&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 15 Nov 2024 09:29:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224795#M3714</guid>
      <dc:creator>otgnwp</dc:creator>
      <dc:date>2024-11-15T09:29:36Z</dc:date>
    </item>
    <item>
      <title>Re: Route single VRF Traffic to another Interface</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224807#M3715</link>
      <description>&lt;P&gt;On your fusion node you should:&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create new intermediate VRF on your fusion node(s)&lt;/LI&gt;&lt;LI&gt;Move the interface you use for peering against the&amp;nbsp;&lt;SPAN&gt;SSOL_Vrf VN into the new intermediate VRF&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Create a new subinterface or move a physical interface connected to your firewall to the intermediate VRF&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Configure routing within the new VRF such that you both have a BGP peering against your SDA border handoff and against the firewall.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Create a new subinterface or move a separate physical interface connected to your firewall to your desired "upstream" VRF&lt;/LI&gt;&lt;LI&gt;Configure routing between the "upstream vrf" on your fusion node and the "upstream vrf" interface of your firewall.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;This will result in a configuration that only forces the traffic in your&amp;nbsp;&lt;SPAN&gt;SSOL_Vrf VN through the firewall. Routing for all other VNs should be unaffected by this change.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2024 09:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/route-single-vrf-traffic-to-another-interface/m-p/5224807#M3715</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-11-15T09:54:20Z</dc:date>
    </item>
  </channel>
</rss>

