cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1126
Views
0
Helpful
3
Replies

L4-L7 Service graph insertion

IslamOmar
Level 1
Level 1

Hello All ,

 

I have a setup where two Firewalls will be installed within the fabric as a cluster . Service graph with unmanaged mode will be used .

 

The N-S will have service graph and E-W will have service graph as planned to be implemented , is this doable or not .

considering that these FW's will be connected to services leafs and broder leafs will have anohter L3-Out connection outside the fabric .

 

 

3 Replies 3

micgarc2
Cisco Employee
Cisco Employee

Yes this will work fine.

In general, you can create your L4-L7 device (with 2 devices as a cluster with 2 interfaces or one-arm ) and  use it as a L4-L7 service graph in multiple subjects in multiple contacts, assuming you have contracts/subjects between you E-W EPGs and EPGs and Net-EPG  in L3OUT for Internet access.  However you need to be careful how you using  contact subjects and FW rules. If you are limiting your source/destination protocol/ports in contract  and using FW for inspection only, you are OK.  If you allow wide range of ports (or IP) in contact and using ACL in FW,  it will be more complex. 

ralphcarter
Level 1
Level 1

I have deployed this exact configuration here: 

https://youtu.be/ryNmeVFYpF0

 

CCIE 26175
www.techsnips.com
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Save 25% on Day-2 Operations Add-On License