cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
709
Views
2
Helpful
4
Replies

vpc static port mapping

Monsinka
Frequent Visitor
Frequent Visitor

helle , i have ACI  operating as pure Layer 2 and the servers’ default gateway is on the firewall. The firewall is connected to two ACI leafs using a vPC that is already configured for an L3Out (SVI + vPC).

Do I need to use that same firewall vPC to carry the Layer 2 VLANs of the servers so they can reach their gateway on the firewall? or i create a seperate vpc 

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame
In an ACI design where the Firewall acts as the Default Gateway (L2-only ACI), the VPC used for the L3Out is logically distinct from the VPCs used for your servers.
You do not use the same VPC (Interface Selector) for your servers that you used for your Firewall L3Out.
i believe you may need separate for each Server vPC group.
 
 

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

hello , I have modified my previous problem description because it was a bit misleading.

HaiCa
Level 1
Level 1

As my understanding, your logical topology may look like attached image:

ACI Firewall gateway and L3Out.png

If you WANT TO use the same physical interfaces/same vPC, so yes, you need to static binding the corresponding VLAN - that mapping with Server/LB/Storage subnet - in EPG that Server/LB/Storage belonging to.

You may think to configure an other vPC for Server/LB/Storage's gateway, like inside zone. Then the vPC configure as L3Out will be in outside zone.

Best regards!

ankushtayade
Community Member

This is a very common scenario today, especially with the increasing adoption of ACI in enterprise networks. I have written a detailed practical post on Layer 2 bridging—please take a look and let me know if you have any questions.Cisco ACI FortiGate as Gateway with Servers Behind ACI(L2) future image.jpg

Cisco ACI: FortiGate as Gateway with Servers Behind ACI(L2) 

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License