- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-30-2016 07:47 AM - edited 03-01-2019 05:02 AM
Hi all,
I'm very new to ACI, but learning as much as I can. We are in the midst of building up an ACI fabric mostly for lab use, running the latest v2.0 ACI code.
I'm trying to create a Shared L3Out (to the Internet) that all tenants will share. I have a firewall connected to my ISPs that is connected to the ACI over a vPC. I have not been able to find much into about how to do this. Most documentation guides assume that I want to use a "routed interface" (or sub-interface), not a vPC.
This would be simple to do in a traditional network - a small transit network between the firewall and an SVI on the switch, but I can't figure out how to do this on ACI.
Do I need an EPG in the Common tenant for the "vlan" between fabric and firewall, then another EPG that gets Shared to the tenants?
Does anyone have a link to a good tutorial or something?
My mind is officially blown -- and that's after taking several Cisco training courses on ACI...
Much appreciated!
J
Solved! Go to Solution.
- Labels:
-
Cisco ACI

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-19-2016 07:46 AM
how did you configure the L3out ? What scopes do you have selected for the L3out ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-19-2016 11:46 AM
Leon
Thanks for using the Cisco ACI Support Community. The original question has been answer correctly. For any other questions regarding ACI, please open a new discussion and someone will assist.
Thanks
Jason
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-19-2016 11:45 AM
Thanks for using the Cisco ACI Support Community. The original question has been answer correctly. For any other questions regarding ACI, please open a new discussion and someone will assist.
Thanks
Jason
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-02-2018 05:16 AM
I'm building this shared l3out configuration in my lab. I'm Including some of the original post config below.
In the tenant Common
- Create a VRF (common-v1)
- Create an External Routed Network (common-l3-ospf)
In the Tenant-Black
- Create a VRF (black-v1)
- Create a BD (black-bd1
In the tenant White
- Create a VRF (white-v1)
- Create a BD (white-bd1)
I'm providing and consuming the contacts as listed in the original post.
I have questions on what the routing tables look like. First, I do see routes leaked between vrfs. In common-v1 I see white-bd1 and black-bd1 routes. On the external router I also see white and black bd routes. I was expecting that. What I don't see is the external router routes getting advertised into white and black VRF's. I do see them in the common vrf.
What could be wrong?
Thanks

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-26-2018 02:23 PM

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-26-2018 06:06 PM
Thanks

- « Previous
-
- 1
- 2
- Next »