cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1439
Views
0
Helpful
2
Replies

Managing two ISPs in ACI

Antonio Macia
Level 3
Level 3

Hi,

 

In a scenario with two ISP providing Internet access where some BDs must use one ISP1 and other BDs the ISP2, how do we deal with this in ACI.

  • Using a single L3Out we cannot differentiate which ISP to use.
  • Using two different L3Outs with two external EPGs (0.0.0.0/0) and static routes pointing to the corresponding ISP router on each L3Out, seems not an option either.

My customer currenlty has two edge firewalls, one per each ISP, and each one has its own default route towards the corresponding ISP router.

I'm trying to move the routing to ACI and use the firewalls in service-graph mode.

 

Initially I thought on two different L3Outs providing two different contracts with the service-graph attached to them and using different firewalls, so depending the contract the EPG consumes it would use an ISP link, but after some labbing this is not like that.

 

What is the correct approach?

Thanks.

2 Replies 2

Robert Burns
Cisco Employee
Cisco Employee

Will the BDs need to use ONLY one of the ISPs exclusively? Or do they need the ability to failover to the other in the event their primary is unavailable?

Robert

From the ACI perspective we can consider that each BD will use one ISP exclusively. We provide redundancy at the edge routers using HSRP, but this is outide ACI control. ACI L3out default static route will point to the virtual HSRP address provided by the edge routers.

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License