07-14-2022 05:33 AM - edited 07-14-2022 05:55 AM
Hi all,
i want to ask about a scenario. here the detail.
here some picture of my design.
My Question is, can i just create 1 L3out with static route, but with 2 SVI with different vlan encap 916 and 917. SVI 916 will have p2p ip address from leaf to fw, and SVI 917 will have p2p ip address from leaf to edge switch.?
in hope to differ traffic from server that need to go to firewall and to core. with just adding static route configuration with different hop.
is it the best practice? or better using 2 l3outs. pls advice
Thanks
07-14-2022 07:30 AM
try using VLAN mapping if that what you looking for
07-14-2022 08:48 PM
Hi @MHM Cisco World , thanks for your reply.
but pls can u help elaborate your answer?
is creating 2 different SVI with different vlan and ip is what u mean?
07-16-2022 09:49 AM
Hi,
For your use case, there are two valid configuration:
1. A single L3Out, which contains:
2. Two individual L3Outs, one for each node, with it's own set of SVIs and it's own set of "external subnets for external epg"
I find the second option more appealing to me, simply because of it's clear separation of everything, but maybe that's just me.
The only disadvantage I know is if you would need a change to a dynamic routing protocol in the future, first option would give you some problems with export route control (this action has effect over the whole L3Out).
Other than that both are perfectly fine. Maybe other community peers may add to advantages/disadvantages.
Take care,
Sergiu
07-17-2022 11:04 PM
hi @Sergiu.Daniluk ,
thanks for your answer,
well noted by me. i'll choose point 1. and i'll get back after implementing it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide