06-18-2020 08:42 PM
Hi,
I have a solution with two FWs in VPC towards two LEAFs, these FWs work Active-Passive. Will be possible to configure L3OUT on these VPCs to handle high availability?
06-22-2020 04:35 AM
Sure. Single L3Out, SVI configured on the two Leaf switches. Next hop via VIP of the FW. The active FW will respond to ARP. When the failover happens, the new FW will take over the traffic.
Let me know if you have any questions.
Stay safe,
Sergiu
06-23-2020 08:47 AM - edited 06-23-2020 08:50 AM
Hi,
I make the following configuration on the L3OUT. In each VPC I configured the same SVI, and the same addressing, additional I configured static route (default) pointing to the Firewall.
I have no way now to test the FW switch, but I would like to know if this is the best way to configure in this scenario.
06-23-2020 10:35 PM
Yes. Looks good. And I believe on the firewall, you have the next hop the secondary IP cfg of the ACI, right?
Regards,
Sergiu
07-12-2020 03:04 AM
Hello,
please, if are using OSPF between firewall and leaf, is it same solution?
07-12-2020 05:34 AM
no, it is static routing
07-12-2020 05:32 AM
Yeah that's right
07-12-2020 06:11 AM
1) I know it's static route, but in case we use dynamic routing (ospf) could we follow same configuration here without default route next hope VIP of the firewall?
2) this solution support only SVI interface?
07-12-2020 07:55 AM
if you connect the FW in VPC, this means you need to configure SVIs on ACI.
If you use OSPF, then the routing protocol will take care of the next hop ^_^
Stay safe,
Sergiu
07-12-2020 08:23 AM
thanks for your response,
what is the best practice design in this case (l3out FW ha failover ) ,
- two link from each fw to leaf switch using svi vpc
or
- two link from each fw to leaf switch using routed interface
or
sub interface
?
07-12-2020 11:02 AM
As usual, it depends. It depends on your setup / tenant(s) design / routing protocol etc. I would suggest to read the L3Out whitepaper where you will find out about pros vs cons of different l3out designs and you can choose one based on your setup:
Stay safe,
Sergiu
04-06-2021 08:30 PM
Hi Oscar
did this config work. I am working on ACI and F5 which is also active standby. I am not sure about the same IP address for both the active and standby units
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide