cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3869
Views
5
Helpful
7
Replies

How to Connect cisco ASA in ACI fabric

Pankaj_Agrawal
Level 1
Level 1

ow to Connect cisco ASA in ACI fabric. Do we need to connect multiple interface from ASA to Leaf switches for inside, outside and DMZ or just one port from ASA to Leaf via VPC ?

7 Replies 7

Hi Robert,

 

Thanks for the useful links. Please see below diagram and looking for some help.

 

ACI-FW.png 

 

 

 

 

Ali Aghababaei
Level 1
Level 1

Hello @Pankaj_Agrawal 

All you've mentioned are possible, but for better help please specify your purpose to connect ASA to ACI fabric. Do you need to external L3 connection or need ASA to use as an East/West firewall and insert as a service in ACI fabric? 

Would like to connect ASA for north south traffic and to host DMZ there.

 

so would like to know how firewall should be physically connected to leaf switches ?

 

Traffic flow -

 

ACI  ——> Firewall ——> router —— internet


for DMZ ——

 

internet ——> router —-> firewall (dmz) —-> ACI

You can connect ASA to ACI in several scenarios: 

You can connect via vPC, Port Channel, or one port. 
In the vPC scenario, at least 2 different ports on  ASA are connected to ports on 2 different leaf switches.
In the PC scenario, Some port channeled ports on ASA connected to one leaf switch ports.
and finally, in one port connection, I think everything is clear. 

After physical connectivity, you need to configure l3Out and choose your routing protocol using APIC GUI or CLI.

if you need any additional information, do not hesitate.

Regards

Thanks for the reply, please see below and help.

 

 

ACI-FW.png

Hi @Pankaj_Agrawal 

1 - The interfaces should be in port-channel, also in ACI you should configure SVI if you want to establish vPC

2- You need Transit Routing 

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/4-x/aci-fundamentals/Cisco-ACI-Fundamentals-42x/Cisco-ACI-Fundamentals-41X_chapter_0111.html


Regards,
Ali

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License