cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4141
Views
16
Helpful
5
Replies

different BGP AS numbers in ACI per tenant?

sandevsingh
Level 1
Level 1

Hi Folks, we are in a process of designing and planning a multi-tenant ACI fabric. We have come up with AS number 65510 for the MP-BGP route-reflector policy. This will be for the leaf to spine MP-BGP session. We are wondering do we need to use the same AS number for each tenant if we want to do layer3 Out using BGP OR can each Tenant have its own separate private AS number? 

1 Accepted Solution

Accepted Solutions

stcorry
Cisco Employee
Cisco Employee
Hello! You can put a different local as number for each tenant's L3 External under the BGP options with the local-as field. If the field is left blank, it will use the Fabric MP-BGP AS number.

View solution in original post

5 Replies 5

stcorry
Cisco Employee
Cisco Employee
Hello! You can put a different local as number for each tenant's L3 External under the BGP options with the local-as field. If the field is left blank, it will use the Fabric MP-BGP AS number.

thanks.. so how does it gets leaked into the MP-BGP process if the AS numbers are different? 

Hi stcorry,

 

I am really new in Cisco ACI world., but from this document https://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-737909.html, I have had a different understandment.

It looked like we could only configure one ASN for internal (iBGP) and external (eBGP) connections with exterior routers.

 

"The Cisco ACI fabric supports one Autonomous System (AS) number. The same AS number is used for internal MP-BGP and for the BGP session between the border leaf switches and external routers."

 

Could you clarify me?

 

Thanks in advance,

 

Mauricio Naegele

I believe what this means is that Cisco ACI utilizes a single BGP ASN internally and if you were to peer with the ACI fabric using iBGP, it would be using this ASN. 

There is no issue with using a different BGP ASN for your external routers/switches/firewalls when peering with ACI. This is totally normal. You can also configure "local-as" in the BGP peering under the L3OUT and change your BGP ASN when peering with the Cisco ACI Fabric.

CCIE 26175
www.techsnips.com

Using a different number in the local-as field will fool the external peer in question, but it does not represent the Actual ASN for the local system. How that looks in the local routing table, is the true AS is still there, but the 'spoofed' local-AS is added to the AS-Path as if it was another router between the 2.

Save 25% on Day-2 Operations Add-On License