cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
610
Views
0
Helpful
2
Replies

Citrix netscaler and ASA using ACI Platform (2 node Service Graph)

mesghalir
Level 1
Level 1

As Part of Data center project I am dealing with Citrix Netscaler and ASA using ACI Platform , I am looking for a document which describes different models of combinations and best practice. and a config guide to help me to make this service graph. 

Is there any way to use both of them in routed mode, or must be only bridge mode both of pbr nodes?

Thanks 

Rasoul Mesghali

2 Replies 2

dpita
Cisco Employee
Cisco Employee

Hello

Thanks for using SupportForums

Regarding service chains and in general, service graphs. There is one main question you need to ask yourself before deciding on service graphs.

"Will my environment require rapid teardown and construction of service insertion?" 

In other words, do you need to constantly be creating contracts with service graphs between EPGs OR is your environment more stable and have a predictable traffic flow such as DMZ > Prod where traffic must ALWAYS go through a firewall. If the latter is the case, a service graph provides little benefit and maybe unmanaged or static integration is what you really will benefit from 

Here are some documents regarding design of service graphs and chains

http://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-734298.html

http://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-732493.html

http://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/aci-fundamentals/b_ACI-Fundamentals/b_ACI-Fundamentals_chapter_01100.html

Thanks for your response,

I am using 2 different VRFs in each tenant, and both VRFs are using L3out which connected to The Firewall !

Internal-VRF----------l3out-----Firewall-----l3out-------External-VRF

Firewall= routed mode + go through

In this Model, I'm going to add Load balancer after Firewall in Internal-VRF, What do you recommend in this matter?

I think it's possible to use only one VRF and Use both PBR nodes in Transparent mode.

Thanks

Save 25% on Day-2 Operations Add-On License