cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1822
Views
10
Helpful
1
Replies

L3 Out(SVI) - Static Routing in VPC and Different Leafs (A/S FW Case)

OBD
Level 1
Level 1

Hi Guys,

 I have 2 questions about Act/Stby Fw and L3 Out static routing (SVI) . Assume that my ACI fabric's default gateway is on FW. So if packet needs to leave ACI fabric ,  it must  go to the FW.

1) If Firewall pairs are connected to  different switch pairs , I need to write static route on Leaf101-Leaf102 and Leaf103-Leaf104.
But I guess that other leaf switches see 0.0.0.0/0 MP-BGP route over to the  that Leaf101-Leaf102-Leaf103-Leaf104.  Am I wrong ? Doesn't it cause blackhole ? How can we handle this problem ?   How can we make traffic go over to the only active firewall?


OBD_0-1663789166314.png



2) If my A/S fw pairs are connected to same vpc pair switches. I write static route to the FW Virtual IP and Leaf101-102 advertise 0.0.0.0/0 route to the rest of fabric. There is no problem about blackholing in this scenario because A/P firewalls are in the same vpc pair switches and Active FW can be found by ARP table.

 My question come into play now ,  if Active FW's one port would be down on Leaf101 , wouldn't occur blackhole in Leaf101? Because Leaf 101 still advertise 0.0.0.0 to the rest of fabric . If I use Auto State enabled , it wouldnt fixed it because in Leaf101 there is Passive FWs port. So SVI couldn't be down status.

 

OBD_1-1663790090886.png

 To sum up , Am I wrong in my ideas? Could you clarify me about my concerns

 

1 Accepted Solution

Accepted Solutions

OBD
Level 1
Level 1

Hi guys,

 I've tested these both scenarios and saw that there is no blackholing . Because if we use same L3-Out in every Leaf switches , they'll use same VxLAN , and their arp packets  flooded all over the same L3-Out borders. So  that if packet goes to Leaf101 (assume it has no port member of Active switch) , it will forward packet to the active switch border by looking ARP table.

OBD_0-1663851809234.png

 

View solution in original post

1 Reply 1

OBD
Level 1
Level 1

Hi guys,

 I've tested these both scenarios and saw that there is no blackholing . Because if we use same L3-Out in every Leaf switches , they'll use same VxLAN , and their arp packets  flooded all over the same L3-Out borders. So  that if packet goes to Leaf101 (assume it has no port member of Active switch) , it will forward packet to the active switch border by looking ARP table.

OBD_0-1663851809234.png

 

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License