06-27-2017 03:25 AM - edited 03-01-2019 05:16 AM
Hi All,
I have an urgent requirement, please assist me to figure out a way.
In ACI I have configured 5 EPGs in 5 BDs respectively in single tenant/ single VRF. In those EPGs vlans may be reused as well. Is it possible to extend the traffic to external firewall in this scenario since the default GW is defined externally? If so what is the appropriate method? Please assist I am bit confused on this ACI concept.
Solved! Go to Solution.
07-05-2017 08:24 PM
To workaround the tagged/untagged issue you can change the untagged ports to 802.1p mode. This will allow this scenario to work and the packets will just be tagged as VLAN zero.
06-27-2017 09:33 PM
Hi Thushan Pramod,
Is it possible to extend the traffic to external firewall in this scenario since the default GW is defined externally?
Yes
If so what is the appropriate method?
The simple approach
This approach is quick, but doesn't make use of any of the ACI advances features.
Another approach would be to create additional bridge domains and use ACI's PBR to redirect just the traffic you want to go to the firewall, but involves considerably more configuration
See http://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/L4-L7_Services_Deployment/guide/b_L4L7_Deploy_ver201/b_L4L7_Deploy_ver201_chapter_01001.html
Also http://d2zmdbbm9feqrf.cloudfront.net/2017/anz/pdf/BRKACI-2016.pdf (Cisco Live login required)
Regarding:
In those EPGs vlans may be reused as well.
Remember that a VLAN in ACI is nothing like a VLAN in the traditional world. In ACI:
RedNectar
aka Chris Welsh
Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem
07-05-2017 08:24 PM
To workaround the tagged/untagged issue you can change the untagged ports to 802.1p mode. This will allow this scenario to work and the packets will just be tagged as VLAN zero.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide