cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
389
Views
1
Helpful
1
Replies

Access intenert on ACI

We have a problem in ACI, I want to connect 2 Firewall because this firewall has internet but when I connect 1 interent its working good, whe I try to connect the second Internet its not working, so In the ACI we have diferrent Bridge Domain and Differents EPG's, so I want that differents EPG go to the Internet 1 and the otrhers EPG go to the second link internet

 

1 Reply 1

BANERJEE SHIBASISH
Cisco Employee
Cisco Employee

Hi @AdanHernandez99826 

 

Cisco ACI provides the capability to insert L4-L7 service using Service Graph and you can leverage the benefit of Policy-Based Redirect (PBR) in Service Graph while using L4-L7 Service like Firewall in your case.

 

PBR requires a service graph attached to the contract between endpoint groups (EPGs). Traffic redirection is based on the source EPG, destination EPG, and filter (protocol, source Layer 4 port, and destination Layer 4 port) configuration in the contract.

For example, if you have Contract-A with a PBR service graph between the L3Out EPG and EPG-A, only the traffic between the L3Out EPG subnet and an endpoint in EPG-A will be redirected to service node FW1. If you have another EPG, EPG-B, that uses another contract, Contract-B, to communicate with the same L3Out interface, you can redirect traffic to another Service node FW2.

Reference : https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739971.html

(Figure 2)

 

I hope this clarifies your query.

 

Example: Use of different PBR policy based on the source and destination EPG combination

 

-----------------------------------------
If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.

You can also learn more about Cisco ACI through our live Ask the Experts (ATXs) session. Check out the ATXs Resources [https://community.cisco.com/t5/data-center-and-cloud-knowledge/cisco-aci-ask-the-experts-resources/ta-p/4394491] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.
-----------------------------------------

 

Regards,

Shibasish

 

 

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License