<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco SD-Access design when all gateways are external in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362142#M4291</link>
    <description>&lt;P&gt;i dont really get what is the showstopper. u have DNAC with its unisolated L3-intfs (e.g.&amp;nbsp;Management,&amp;nbsp;Enterprise,&amp;nbsp;Cloud / Internet) connected to FW, just bring to the same FW INFRA_VN (GRT) &amp;amp; configure FW to pass traffic bw DNAC &amp;amp; managed devices according to requirements (you can easily find which ports must be open for any intf to operate as expected).&lt;BR /&gt;"&lt;SPAN&gt;First, keep the network as it is, we will only discover the devices on DNAC and in this case DNAC will work in monitoring mode and no other benefits." how r u going to provision devices from DNAC with monitoring (assurance) only? &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;i didnt get 2nd option clearly.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jan 2026 13:17:47 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2026-01-16T13:17:47Z</dc:date>
    <item>
      <title>Cisco SD-Access design when all gateways are external</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362110#M4290</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;We are currently planning to deploy one catalyst center appliance in our office. However, the current gateways for all subnets are on firewall.&lt;/P&gt;
&lt;P&gt;So, we proposed one of the below solutions:&lt;/P&gt;
&lt;P&gt;First, keep the network as it is, we will only discover the devices on DNAC and in this case DNAC will work in monitoring mode and no other benefits.&lt;/P&gt;
&lt;P&gt;Second, provision all devices and configure l2 VNs and l2 handoff, in this case all the traffic will be going the same way to their gatways.&lt;/P&gt;
&lt;P&gt;These two solutions were proposed because the network security team is denying to remove the gateways from firewalls&lt;/P&gt;
&lt;P&gt;Anyways, please suggest what can we do and If there's a third and better solution please advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 12:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362110#M4290</guid>
      <dc:creator>Hashem1323</dc:creator>
      <dc:date>2026-01-16T12:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco SD-Access design when all gateways are external</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362142#M4291</link>
      <description>&lt;P&gt;i dont really get what is the showstopper. u have DNAC with its unisolated L3-intfs (e.g.&amp;nbsp;Management,&amp;nbsp;Enterprise,&amp;nbsp;Cloud / Internet) connected to FW, just bring to the same FW INFRA_VN (GRT) &amp;amp; configure FW to pass traffic bw DNAC &amp;amp; managed devices according to requirements (you can easily find which ports must be open for any intf to operate as expected).&lt;BR /&gt;"&lt;SPAN&gt;First, keep the network as it is, we will only discover the devices on DNAC and in this case DNAC will work in monitoring mode and no other benefits." how r u going to provision devices from DNAC with monitoring (assurance) only? &lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;i didnt get 2nd option clearly.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 13:17:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362142#M4291</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-16T13:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco SD-Access design when all gateways are external</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362251#M4292</link>
      <description>&lt;P&gt;perhaps i didn't explain my point correctly.&lt;/P&gt;
&lt;P&gt;let's say in the current network design all end-users subnets gateways are through FW.&lt;/P&gt;
&lt;P&gt;As I know, to have an SDA solution we need to change the gateways for these subnets to be through SDA and we can't do that.&lt;/P&gt;
&lt;P&gt;to solve this we proposed that we will only discover the devices (no provisioning) to keep the config of SW as it is. using this DNAC will collect telemetry data and this is what i meant by monitoring mode.&lt;/P&gt;
&lt;P&gt;my previous second point was to provision the devices and create L2 handoff so that everything will stay the same and gateway will still be FW for end-users subnets.&lt;/P&gt;
&lt;P&gt;I haven't tested any of these points and would like to be corrected if this is wrong.&lt;/P&gt;
&lt;P&gt;note that i need to know weather discovering the switches alone will give me some monitoring data at dnac or not. like through snmp or whatever.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 18:08:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362251#M4292</guid>
      <dc:creator>Hashem1323</dc:creator>
      <dc:date>2026-01-16T18:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco SD-Access design when all gateways are external</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362259#M4293</link>
      <description>&lt;P&gt;L3-gw (FW) outside of the Fabic Site is classical case with 2 options as resolution: a) L2-BN terminating traffic on the FW (less preferred as requires L2-flood L2VNs) b) anycast GWs on the ENs with L3-handoffs (L3NB) to FW (1 handoff per isolation purpose in its separated VN) - recommended design&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 19:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362259#M4293</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-16T19:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco SD-Access design when all gateways are external</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362260#M4294</link>
      <description>&lt;P&gt;&amp;amp;, yeah, for OAM you doesnt need tenants VNs to be reachable from DNAC. Infra_VN(GRT) is for this purpose&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jan 2026 07:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/cisco-sd-access-design-when-all-gateways-are-external/m-p/5362260#M4294</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-01-17T07:52:31Z</dc:date>
    </item>
  </channel>
</rss>

