02-23-2026 05:26 AM - edited 02-23-2026 12:18 PM
helle , i have ACI operating as pure Layer 2 and the servers’ default gateway is on the firewall. The firewall is connected to two ACI leafs using a vPC that is already configured for an L3Out (SVI + vPC).
Do I need to use that same firewall vPC to carry the Layer 2 VLANs of the servers so they can reach their gateway on the firewall? or i create a seperate vpc
02-23-2026 05:49 AM
=====️ Preenayamo Vasudevam ️=====
***** Rate All Helpful Responses *****
02-23-2026 12:20 PM
hello , I have modified my previous problem description because it was a bit misleading.
02-26-2026 11:29 PM
As my understanding, your logical topology may look like attached image:
If you WANT TO use the same physical interfaces/same vPC, so yes, you need to static binding the corresponding VLAN - that mapping with Server/LB/Storage subnet - in EPG that Server/LB/Storage belonging to.
You may think to configure an other vPC for Server/LB/Storage's gateway, like inside zone. Then the vPC configure as L3Out will be in outside zone.
Best regards!
03-22-2026 11:18 PM
This is a very common scenario today, especially with the increasing adoption of ACI in enterprise networks. I have written a detailed practical post on Layer 2 bridging—please take a look and let me know if you have any questions.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide