Hello,
we need a recommendation for connecting a Checkpoint Firewall Cluster to a ACI fabric. It should be a layer 3 connectivity and each Cluster member must be connected to a different leaf switch.
Between the Cluster and the ACI fabric there is a transfer network and the cluster is working in active/standby.
I noticed there are different solutions to solve this.
1. HSRP VIP on ACI side - > CP Cluster has a static route to this VIP
2. SVI on ACI side - > CP Cluster has a static route to this SVI IP Address
...tbd
There is no Portchannel between the fabric and the CP cluster. There are single connections. The CP Cluster has also a VIP configured and each physical interface has its own IP Address. From the fabric there a static routed pointing to the firewall VIP.
Are there any best practices for this design?
Thanks
Udo