cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
336
Views
0
Helpful
2
Replies

BGP between ACI and firewall, strange routing learned to firewall

I have an ACI fabric with 3 POD's.  2 leaf's in vpc in each POD.
To each leafpair in each POD, I have an Catalyst 4500X connected with port-channel.
And in POD1 and POD3 I have a Checkpoint firewall connected with port-channel.
The attached jpg-file shows more info about the issue.
The issue is that the active FW is connected to Leaf201/202, and the 3 Cat4500X are connected to 201/202, 401/402 and 601/602.
The l3out between FW are up, and the firewall learns the routes.  But why does the firewall learn the subnet from 4500X-1 connected to Leaf201/202 from the IP of Leaf601?