cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1168
Views
5
Helpful
2
Replies

How to Achieve Route leaking between L3 Out without EPGs

Rajhans Shere
Level 1
Level 1

Hi Team,

 

I am facing one issue in leaking the routes between the L3 outs configured in different Tenants. Below is the description in detail

 

1. I have one L3 out in Common tenant , which is not binded to any EPG

2. I have second L3 out in Tenant X, which also not binded to any EPG

3. First L3 out lets Say A in common tenant has few routes and Seccond L3Out , lets say B in Tenant X has few routes

 

Now, I have achieved the route leaking between them by putting both the L3 outs in common VRF, but this is not what i needed. Because in future i will have so many Tenants whose out connection is from common tenant L3 outs. Hence i have to have different route tables for every tenant

 

My question is how can i achieve route leaking between two L3 outs of different tenant who do not have EPGs.

 

I have tried creating contract with Global scope but no luck. I have also tried enabling "External Subnets for External EPG", "Shared route control subnet",

"shared security import subnet" options inside External network in L3 out but no luck.

 

 

Thanks in advance

 

Rajhans

1 Accepted Solution

Accepted Solutions

Jason Williams
Level 1
Level 1

Rajhan, 

Are you talking about the scenario below?

L3 Out: L3-Out-Common

Tenant: Common

VRF: Common

L3 Out: L3-Out-X

Tenant: X

VRF: X 

Route leaking between two L3 Outs in 2 different VRFs is unsupported. Supported routing leaking configurations are EPG (VRF-A) <> EPG (VRF-B) which is known as "Shared Services" and EPG (VRF-A) <> L3-Out (VRF-B) which is known as "Shared L3."  

For Shared L3 you will need the following options enabled under the external networks EPG:

External Subnets for External EPG - Contract/policy is applied to the subnet(s) listed

Shared Route Control Subnet - Subnet/prefix can be leaked into other VRFs

Shared Security Import Subnet - Policy is applied to leaked subnet(s)

View solution in original post

2 Replies 2

Jason Williams
Level 1
Level 1

Rajhan, 

Are you talking about the scenario below?

L3 Out: L3-Out-Common

Tenant: Common

VRF: Common

L3 Out: L3-Out-X

Tenant: X

VRF: X 

Route leaking between two L3 Outs in 2 different VRFs is unsupported. Supported routing leaking configurations are EPG (VRF-A) <> EPG (VRF-B) which is known as "Shared Services" and EPG (VRF-A) <> L3-Out (VRF-B) which is known as "Shared L3."  

For Shared L3 you will need the following options enabled under the external networks EPG:

External Subnets for External EPG - Contract/policy is applied to the subnet(s) listed

Shared Route Control Subnet - Subnet/prefix can be leaked into other VRFs

Shared Security Import Subnet - Policy is applied to leaked subnet(s)

Thanks Jason for the explanation. 

:)

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License