It could be any branded firewalls but for simplicity, lets just use ASA within a two-Pod multipod fabric as an example for this post...
If I remember correctly, within a Single Pod ACI Fabric, the redundant ASA management links (including the HA link or control link) are recommended to NOT be connected through the ACI fabric, especially when using Service Graph.
Now coming to the ACI Multi-Pod with redundant firewalls, high-level speaking, Cisco supports and recommends to deploy redundant firewalls/ASAs in two ways:
- Active/Standby pair with one ASA in Pod 1 and the other ASA in Pod 2.
- Active/Active firewall cluster with multiple ASAs spread across two Pods.
So my questions:
- For the Active/Standby ASA pair, how would the two ASAs to be connected for HA links? Through the ACI Multi-Pod fabric?
- For the Active/Active Cluster, how would the control links be connected for the ASAs located in two Pods?