cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1254
Views
4
Helpful
2
Replies

Unmanaged Service Graph, without PBR?

Timothy ACI
Level 1
Level 1

Is this case practically unused? I have asked around for some production deployments that have Service Graph, and they all use PBR.

 

As far as I could understand, Service Graph (in case of Routed firewall and ADCs) makes ACI render connectivity and contract. The Routed firewall will be the gateway of the EPGs. However, this can be easily achieved by using Static Port or VMM association already, and since ACI is not the gateway, L2 BDs for those EPGs are sufficient. Same goes for ADCs.

 

With PBR though, the ACI can be the gateway, but still can redirect traffic to L4-L7 devices at will. It also has bypass mechanism (manually remove graph binding to contract subject, or SLA-based)

 

Is anyone still using Unmanaged Service Graph without PBR in their deployment?

2 Replies 2

m1xed0s
Spotlight
Spotlight

It is a little bit surpised that no one answered on this...

To me, without PBR, ACI can still be the default gateway for the consumer/provider EPGs' workloads of the service graph but you would lose the flexibility. Plus if the service graph template was added without Route Redirect option enabled, you would have to delete and recreate the template if you want to use the PBR with the same service graph template down the road in production.

RedNectar
VIP
VIP

Hi @Timothy ACI ,

I think your question ...


Is anyone still using Unmanaged Service Graph without PBR in their deployment?


...has answered itself.

The number of sites "using Unmanaged Service Graph without PBR in their deployment" is probably = the number of "Yes" replies you have got to this post in 2.5 years

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Save 25% on Day-2 Operations Add-On License