08-08-2016 07:18 AM - edited 03-01-2019 05:00 AM
Hi Team,
I am facing one issue in leaking the routes between the L3 outs configured in different Tenants. Below is the description in detail
1. I have one L3 out in Common tenant , which is not binded to any EPG
2. I have second L3 out in Tenant X, which also not binded to any EPG
3. First L3 out lets Say A in common tenant has few routes and Seccond L3Out , lets say B in Tenant X has few routes
Now, I have achieved the route leaking between them by putting both the L3 outs in common VRF, but this is not what i needed. Because in future i will have so many Tenants whose out connection is from common tenant L3 outs. Hence i have to have different route tables for every tenant
My question is how can i achieve route leaking between two L3 outs of different tenant who do not have EPGs.
I have tried creating contract with Global scope but no luck. I have also tried enabling "External Subnets for External EPG", "Shared route control subnet",
"shared security import subnet" options inside External network in L3 out but no luck.
Thanks in advance
Rajhans
Solved! Go to Solution.
08-12-2016 01:29 PM
Rajhan,
Are you talking about the scenario below?
L3 Out: L3-Out-Common
Tenant: Common
VRF: Common
L3 Out: L3-Out-X
Tenant: X
VRF: X
Route leaking between two L3 Outs in 2 different VRFs is unsupported. Supported routing leaking configurations are EPG (VRF-A) <> EPG (VRF-B) which is known as "Shared Services" and EPG (VRF-A) <> L3-Out (VRF-B) which is known as "Shared L3."
For Shared L3 you will need the following options enabled under the external networks EPG:
External Subnets for External EPG - Contract/policy is applied to the subnet(s) listed
Shared Route Control Subnet - Subnet/prefix can be leaked into other VRFs
Shared Security Import Subnet - Policy is applied to leaked subnet(s)
08-12-2016 01:29 PM
Rajhan,
Are you talking about the scenario below?
L3 Out: L3-Out-Common
Tenant: Common
VRF: Common
L3 Out: L3-Out-X
Tenant: X
VRF: X
Route leaking between two L3 Outs in 2 different VRFs is unsupported. Supported routing leaking configurations are EPG (VRF-A) <> EPG (VRF-B) which is known as "Shared Services" and EPG (VRF-A) <> L3-Out (VRF-B) which is known as "Shared L3."
For Shared L3 you will need the following options enabled under the external networks EPG:
External Subnets for External EPG - Contract/policy is applied to the subnet(s) listed
Shared Route Control Subnet - Subnet/prefix can be leaked into other VRFs
Shared Security Import Subnet - Policy is applied to leaked subnet(s)
08-23-2016 01:20 AM
Thanks Jason for the explanation.
:)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide