ACI and external Firewall Cluster - Recommendation
we need a recommendation for connecting a Checkpoint Firewall Cluster to a ACI fabric. It should be a layer 3 connectivity and each Cluster member must be connected to a different leaf switch.
Between the Cluster and the ACI fabric there is a transfer network and the cluster is working in active/standby.
I noticed there are different solutions to solve this.
1. HSRP VIP on ACI side - > CP Cluster has a static route to this VIP
2. SVI on ACI side - > CP Cluster has a static route to this SVI IP Address
There is no Portchannel between the fabric and the CP cluster. There are single connections. The CP Cluster has also a VIP configured and each physical interface has its own IP Address. From the fabric there a static routed pointing to the firewall VIP.
Re: ACI and external Firewall Cluster - Recommendation
We did the setup with a CP FW cluster (Active/Standby) spanning 2 different datacenters, we do have vPC's between the CP and the leaf switches per datacenter. We configured a L3Out in the common tenant so this can be used by different tenants (on a per needed base).
We solved this with using SVI interfaces, meaning configuring a /28 for each vPC we have (.1 VIP CP, .2 CP1, .3 CP2 and .4 LF1 [side A IP] and .5 LF2 [side B IP].
HSRP is not working with Fabric pathHi all. I am testing HSRP with FabricPath by virl I can ping from Access switch to Active router(titanium-nexus), Standby router(titanium-nexus) but both nexus is Active (HSRP), can you guys check fo...
Cisco Intersight Universal API Calls
The Cisco Intersight Universal API Calls module provides a set of functions that simplify creation, retrieval, modification, and deletion of resources on Cisco Intersight. Any available API types listed in the Cisco I...
Day 2: ✅. Day 3, ready to roll! Want to fine-tune your agenda for today? These sessions still have space:
Data Center Networking
BRKACI-2403: Meeting Business Compliance and IT Governance Using Cisco Network Assurance Engine (NAE)
Day 1 is done! If you're thinking about dinner plans, we hear San Diego has great food. While you're waiting for your first shot of tequlia table, keep building your Cisco Live agenda! There are more great sessions still open for tomorrow,&n...
We hope you're on your way to join us at CLUS in San Diego! While you're waiting for your flight (or waiting for your flight to land!), keep building your Cisco Live agenda! There are plenty of great sessions still open on June 10. Here are s...