<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue Configuring L3 Handoff on second border node on same VLAN in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227983#M3781</link>
    <description>&lt;P&gt;I agree that this mainly is a question regarding how to handle the handoff configuration.&lt;/P&gt;&lt;P&gt;I do however think&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/917321"&gt;@techno.it&lt;/a&gt; should account for STP when planning his handoff in this case.&amp;nbsp; Convergence could be limited by STP if the L2 topology results in blocking ports, which sounds like it would be the case if there's L2 switching over the trunk between the border nodes. This can be avoided by either converting the link between the borders to routed links, or he could manually prune the VLANs such that there won't be any blocking ports in the STP topology. Please do correct me if you see something that I don't regarding this&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 23 Nov 2024 12:42:33 GMT</pubDate>
    <dc:creator>Torbjørn</dc:creator>
    <dc:date>2024-11-23T12:42:33Z</dc:date>
    <item>
      <title>Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227510#M3774</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are building an SDA network with two separate border and control plane nodes ( collated both roles on same device) that are connected by BGP to a fusion firewall (Active/Standby). When DNAC configures the L3 border handoff, I provided manual /29 subnet between the Border Node and the external device.&amp;nbsp; There is a L2 trunk between the border nodes and from each border node there is a L2 trunk towards the firewall. I want to use the same transit VLAN on both Border nodes for the connection with the firewall. BN1 and Firewall already have L3 handoff configured with VLANs 3001 for VRF-X.&amp;nbsp; When attempting to create an L3 handoff between BN2 and Firewall using the same transit VLAN 3001, DNAC throws an error message "&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Layer 3 Handoff VLAN 3002 is already being used for another Layer 3 Handoff. Change the VLAN and retry."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions what could be the issue? &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 00:40:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227510#M3774</guid>
      <dc:creator>techno.it</dc:creator>
      <dc:date>2024-11-22T00:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227575#M3775</link>
      <description>&lt;P&gt;&amp;nbsp;i've totally forgotten about this limitation of the DNAC. u need to configure L3-handoff on the BN|CP#2 manually.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 07:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227575#M3775</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-22T07:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227597#M3776</link>
      <description>&lt;P&gt;Alternatively you can use separate VLANs per border node.&lt;/P&gt;&lt;P&gt;Are your borders connected directly to your fusion nodes? If not you should keep in mind that STP could become an issue.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 08:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227597#M3776</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-11-22T08:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227610#M3777</link>
      <description>&lt;P&gt;he has intermediate L2-switch in the middle. it's exactly for the purpose to simplify BN|CP&amp;lt;&amp;gt;FN peering. STP has nothing to do with this issue. it's limitation of DNAC to produce multiple peering in the same L3-handoff VLAN.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 09:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227610#M3777</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-22T09:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227638#M3778</link>
      <description>&lt;P&gt;That's correct. We have Nexus vPC for L2 transit and making adjacency between Border and Fusion Firewall.&lt;/P&gt;&lt;P&gt;Kindly confirm and to be precise, what is the exact manual config needs to be done on borders to overcome this.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 10:29:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227638#M3778</guid>
      <dc:creator>techno.it</dc:creator>
      <dc:date>2024-11-22T10:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227657#M3779</link>
      <description>&lt;P&gt;BGP. it will be similar to one u have on BN|CP#1 but with use of BN|CP#2 specific IPs.&lt;BR /&gt;Another option would be to fallback to double peering from FW side in 2 different VLANs (per BN|CP). Quick Q: does your FW A/S require unique IPs for A &amp;amp; S units per directly attached subnet? if so, then u have to stay with /29 per transfernet per BN|CP.&lt;/P&gt;
&lt;P&gt;UPD: try to trick DNAC &amp;amp; provide dummy not used VLAN for the L3-handoff for BN|CP#2. May be even in different subnet &amp;amp; then via configuration preview grab stuff which DNAC prepared &amp;amp; discard L3-handoff workflow. then tweak collected config with IP's/VLANs u need &amp;amp; apply it manually&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 11:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227657#M3779</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-22T11:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227814#M3780</link>
      <description>&lt;P&gt;Good idea&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;&amp;nbsp; Thank you for the suggestion.&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/964504"&gt;@Torbjørn&lt;/a&gt;&amp;nbsp;for your inputs as well.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 18:53:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227814#M3780</guid>
      <dc:creator>techno.it</dc:creator>
      <dc:date>2024-11-22T18:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227983#M3781</link>
      <description>&lt;P&gt;I agree that this mainly is a question regarding how to handle the handoff configuration.&lt;/P&gt;&lt;P&gt;I do however think&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/917321"&gt;@techno.it&lt;/a&gt; should account for STP when planning his handoff in this case.&amp;nbsp; Convergence could be limited by STP if the L2 topology results in blocking ports, which sounds like it would be the case if there's L2 switching over the trunk between the border nodes. This can be avoided by either converting the link between the borders to routed links, or he could manually prune the VLANs such that there won't be any blocking ports in the STP topology. Please do correct me if you see something that I don't regarding this&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293790"&gt;@Andrii Oliinyk&lt;/a&gt;.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 12:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227983#M3781</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-11-23T12:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227989#M3782</link>
      <description>&lt;P&gt;not sure it worth any discussing coz whatever L2 in the middle he will switch dedicated VLAN(s) with only 2 isls (per BN|CP) connected to vPC. do u think STP will block any of ports connected to FW &amp;amp; BN|CPs keeping in mind that BN|CPs have no isl between them?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 13:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227989#M3782</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-23T13:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227997#M3783</link>
      <description>&lt;P&gt;&lt;SPAN&gt;From the original post: "There is a &lt;U&gt;L2 trunk between the border nodes&lt;/U&gt; and from each border node there is a L2 trunk towards the firewall. I want to use the same transit VLAN on both Border nodes for the connection with the firewall.". I interpret this as that the link between his borders are regular trunks carrying the handoff VLANs as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Assuming that the connected switch/another upstream switch being the root bridge for the handoff VLANs. Wouldn't this result in one of the ports on the link between the border nodes to be in blocking state during regular operation and rely on STP convergence in case of certain failure states? It might not matter for all I know, I might just be making faulty assumptions as I haven't tried configuring the handoff in this specific manner before.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 13:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5227997#M3783</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-11-23T13:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5228004#M3784</link>
      <description>&lt;P&gt;it seems to be worthless dispute. "&lt;SPAN&gt;Wouldn't this result in one of the ports on the link between the border nodes" - No, there is no L2 links between BN|CPs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 13:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5228004#M3784</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-23T13:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5228007#M3785</link>
      <description>&lt;P&gt;I misinterpreted the OP.&lt;BR /&gt;No L2 link = no issue. Thank you for clarifying!&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 13:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5228007#M3785</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2024-11-23T13:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: Issue Configuring L3 Handoff on second border node on same VLAN</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5228011#M3786</link>
      <description>&lt;P&gt;no issues. hopefully u will help me some day with API'ing SDA - i have a lot of challenges exactly there :0)&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 14:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/issue-configuring-l3-handoff-on-second-border-node-on-same-vlan/m-p/5228011#M3786</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2024-11-23T14:03:56Z</dc:date>
    </item>
  </channel>
</rss>

