<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SDA Border Node Connection to HA Fusion in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-border-node-connection-to-ha-fusion/m-p/5372169#M4345</link>
    <description>&lt;P&gt;We are working on the design for an SD Access deployment and I have a question about border node configuration.&lt;/P&gt;&lt;P&gt;Our typical WAN connectivity is via a pair of high availability FortiGate Firewalls. These will act as the Fusion device. In a HA configuration the firewall appear as a single device and share the same configuration (IPs, BGP etc.) so while we have physical redundancy effectively there is a single Fusion device.&lt;/P&gt;&lt;P&gt;On the Fabric side the border node will typically be a stack of switches and the FortiGate's will be physically connected to different members. So again physical redundancy but a single Border node.&lt;/P&gt;&lt;P&gt;The set up is illustrated below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="SDA-Border1.png" style="width: 346px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/260135i5E9DEE44DD8129AC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SDA-Border1.png" alt="SDA-Border1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions is how do I configure the interface that links to the second firewall?&lt;/P&gt;&lt;P&gt;Catalyst Center does seem to allow me to add it as part of the Border Node configuration (complains about duplicate addresses).&lt;/P&gt;&lt;P&gt;Looking at the configuration deployed on a Border node interface its it just a basic trunk port.&lt;/P&gt;&lt;P&gt;Is ok to just configure the second link as a Trunk port? Or is there some other configurations required that designate it as an "exit" point from the Fabric?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Feb 2026 10:44:52 GMT</pubDate>
    <dc:creator>pinglis</dc:creator>
    <dc:date>2026-02-24T10:44:52Z</dc:date>
    <item>
      <title>SDA Border Node Connection to HA Fusion</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-border-node-connection-to-ha-fusion/m-p/5372169#M4345</link>
      <description>&lt;P&gt;We are working on the design for an SD Access deployment and I have a question about border node configuration.&lt;/P&gt;&lt;P&gt;Our typical WAN connectivity is via a pair of high availability FortiGate Firewalls. These will act as the Fusion device. In a HA configuration the firewall appear as a single device and share the same configuration (IPs, BGP etc.) so while we have physical redundancy effectively there is a single Fusion device.&lt;/P&gt;&lt;P&gt;On the Fabric side the border node will typically be a stack of switches and the FortiGate's will be physically connected to different members. So again physical redundancy but a single Border node.&lt;/P&gt;&lt;P&gt;The set up is illustrated below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="SDA-Border1.png" style="width: 346px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/260135i5E9DEE44DD8129AC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SDA-Border1.png" alt="SDA-Border1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My questions is how do I configure the interface that links to the second firewall?&lt;/P&gt;&lt;P&gt;Catalyst Center does seem to allow me to add it as part of the Border Node configuration (complains about duplicate addresses).&lt;/P&gt;&lt;P&gt;Looking at the configuration deployed on a Border node interface its it just a basic trunk port.&lt;/P&gt;&lt;P&gt;Is ok to just configure the second link as a Trunk port? Or is there some other configurations required that designate it as an "exit" point from the Fabric?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 10:44:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-border-node-connection-to-ha-fusion/m-p/5372169#M4345</guid>
      <dc:creator>pinglis</dc:creator>
      <dc:date>2026-02-24T10:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: SDA Border Node Connection to HA Fusion</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-border-node-connection-to-ha-fusion/m-p/5372180#M4346</link>
      <description>&lt;P&gt;In the&amp;nbsp;Fabric Provisioning&amp;nbsp;workflow, select the&amp;nbsp;Port Channel&amp;nbsp;as the external interface for the Border Node.&lt;/P&gt;
&lt;P&gt;Some example reading :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://netcraftsmen.com/securing-sd-access-traffic/" target="_blank"&gt;https://netcraftsmen.com/securing-sd-access-traffic/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 11:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-border-node-connection-to-ha-fusion/m-p/5372180#M4346</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-02-24T11:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: SDA Border Node Connection to HA Fusion</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-border-node-connection-to-ha-fusion/m-p/5372181#M4347</link>
      <description>&lt;P&gt;u want to configure 2nd link exactly as 1st. but are u really able to add 2nd link in BN-L3HO workflow for the same IP-transit?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;finally, it's bad idea to have BN stacked as you lose hitless SWIM for site (assuming u have single pair of BN &amp;amp; FN there)&lt;/P&gt;</description>
      <pubDate>Tue, 24 Feb 2026 11:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-border-node-connection-to-ha-fusion/m-p/5372181#M4347</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2026-02-24T11:14:06Z</dc:date>
    </item>
  </channel>
</rss>

