09-09-2021 08:32 AM
ow to Connect cisco ASA in ACI fabric. Do we need to connect multiple interface from ASA to Leaf switches for inside, outside and DMZ or just one port from ASA to Leaf via VPC ?
09-09-2021 08:58 AM
Recommend you start with these VoDs:
And this whitepaper:
Robert
09-12-2021 06:09 PM
Hi Robert,
Thanks for the useful links. Please see below diagram and looking for some help.
09-12-2021 12:13 PM
Hello @Pankaj_Agrawal
All you've mentioned are possible, but for better help please specify your purpose to connect ASA to ACI fabric. Do you need to external L3 connection or need ASA to use as an East/West firewall and insert as a service in ACI fabric?
09-12-2021 12:27 PM
Would like to connect ASA for north south traffic and to host DMZ there.
so would like to know how firewall should be physically connected to leaf switches ?
Traffic flow -
ACI ——> Firewall ——> router —— internet
for DMZ ——
internet ——> router —-> firewall (dmz) —-> ACI
09-12-2021 03:04 PM
You can connect ASA to ACI in several scenarios:
You can connect via vPC, Port Channel, or one port.
In the vPC scenario, at least 2 different ports on ASA are connected to ports on 2 different leaf switches.
In the PC scenario, Some port channeled ports on ASA connected to one leaf switch ports.
and finally, in one port connection, I think everything is clear.
After physical connectivity, you need to configure l3Out and choose your routing protocol using APIC GUI or CLI.
if you need any additional information, do not hesitate.
Regards
09-12-2021 06:07 PM
Thanks for the reply, please see below and help.
09-23-2021 04:38 AM
Hi @Pankaj_Agrawal
1 - The interfaces should be in port-channel, also in ACI you should configure SVI if you want to establish vPC
2- You need Transit Routing
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/aci-fundamentals/Cisco-ACI-Fundamentals-42x/Cisco-ACI-Fundamentals-41X_chapter_0111.html
Regards,
Ali
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide