04-29-2020 09:57 PM - edited 04-29-2020 09:58 PM
Hi community,
Recently deployed an FTD pair in one-armed mode. Despite pingable from the service leaf, and the BD associated with the L3out with its subnet Advertised Externally, when I tried to ping from outside of the L3out to the PBR node it's inaccessible.
That'sreally fine for FTD since it's managed via another interface. Now I'm about to migrate a CheckPoint from the old network, after that there would only be one sub-interface left on the CheckPoint. Would there be anyway that I can access the CheckPoint for management in this topology?
Thanksa lot.
Solved! Go to Solution.
04-30-2020 12:43 AM
Is the L3Out consumer/provider of the SG? If yes, do you have "Direct Connect" option enabled? This setting, when enabled in the service graph, enables communication (individually):
For additional details about this option can be found in the ACI PBR white paper: https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739971.html
Regards,
Sergiu
04-30-2020 12:43 AM
Is the L3Out consumer/provider of the SG? If yes, do you have "Direct Connect" option enabled? This setting, when enabled in the service graph, enables communication (individually):
For additional details about this option can be found in the ACI PBR white paper: https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-739971.html
Regards,
Sergiu
04-30-2020 01:37 AM
04-30-2020 04:29 AM
With pleasure! Happy to hear that it's all good now ^_^
Cheers,
Sergiu
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide