I am experiencing a very strange configuration on ACI.
Please have a look at the topology as below:
We have 4 ASA, which are configure in two clusters.
Each firewall has a port-channel 1 that will be configured as sub-interface for each subnet (each EPG)
On aci, I configured two unmanaged clusterd devices, one is INT-FW, the other is SRV-FW.
On the Firewalls, I confiugre sub-interface as normal.
The strange thing is about the configuration of INT-FW inside interface and SRV-FW outside interface on ACI.
If, on ACI, I configure the inside and outside interface with the same vlan encap, connection between INT-FW and SRV-FW fail (cannot ping between x.x.10.1 and x.x.10.10 and no packet is transferred between them). However, if the configured vlan encap on inside interface and outside interface are different, the ping is success (sub-interface on FW config is still in the same vlan).
I have opened a case for this issue but it seem there is not many aci expert.
By default the switch will consider a Vlan ID to map with a given EPG on the whole Leaf (within a given Physical Domain), which is called Global Scope. In that case, the 2 EPGs representing Inside and Outisde probably conflict with faults raised.
Check the Leaf Access port policy that you use for the FW ports and note the L2 Interface Policy field. Check the corresponding Interface Policy to see its VLAN Scope. If it is set to Global scope, try to set it as Port Local scope. That gives the Vlan ID a local port significance.
Howdy out there in automation land!!!! So.... To Atomic or Not To Atomic.. that is the question? Is it not? This post is going to break into the string of "back to the basics" as we have gotten a lot of interest in Action Orchestrator of late (which is st...
HSRP is not working with Fabric pathHi all. I am testing HSRP with FabricPath by virl I can ping from Access switch to Active router(titanium-nexus), Standby router(titanium-nexus) but both nexus is Active (HSRP), can you guys check fo...
Cisco Intersight Universal API Calls
The Cisco Intersight Universal API Calls module provides a set of functions that simplify creation, retrieval, modification, and deletion of resources on Cisco Intersight. Any available API types listed in the Cisco I...
Day 2: ✅. Day 3, ready to roll! Want to fine-tune your agenda for today? These sessions still have space:
Data Center Networking
BRKACI-2403: Meeting Business Compliance and IT Governance Using Cisco Network Assurance Engine (NAE)
Day 1 is done! If you're thinking about dinner plans, we hear San Diego has great food. While you're waiting for your first shot of tequlia table, keep building your Cisco Live agenda! There are more great sessions still open for tomorrow,&n...