05-18-2021 09:50 AM
Hi,
In a scenario with two ISP providing Internet access where some BDs must use one ISP1 and other BDs the ISP2, how do we deal with this in ACI.
My customer currenlty has two edge firewalls, one per each ISP, and each one has its own default route towards the corresponding ISP router.
I'm trying to move the routing to ACI and use the firewalls in service-graph mode.
Initially I thought on two different L3Outs providing two different contracts with the service-graph attached to them and using different firewalls, so depending the contract the EPG consumes it would use an ISP link, but after some labbing this is not like that.
What is the correct approach?
Thanks.
05-18-2021 10:05 AM
Will the BDs need to use ONLY one of the ISPs exclusively? Or do they need the ability to failover to the other in the event their primary is unavailable?
Robert
05-18-2021 03:13 PM
From the ACI perspective we can consider that each BD will use one ISP exclusively. We provide redundancy at the edge routers using HSRP, but this is outide ACI control. ACI L3out default static route will point to the virtual HSRP address provided by the edge routers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide