ow to Connect cisco ASA in ACI fabric. Do we need to connect multiple interface from ASA to Leaf switches for inside, outside and DMZ or just one port from ASA to Leaf via VPC ?
Recommend you start with these VoDs:
And this whitepaper:
All you've mentioned are possible, but for better help please specify your purpose to connect ASA to ACI fabric. Do you need to external L3 connection or need ASA to use as an East/West firewall and insert as a service in ACI fabric?
Would like to connect ASA for north south traffic and to host DMZ there.
so would like to know how firewall should be physically connected to leaf switches ?
Traffic flow -
ACI ——> Firewall ——> router —— internet
for DMZ ——
internet ——> router —-> firewall (dmz) —-> ACI
You can connect ASA to ACI in several scenarios:
You can connect via vPC, Port Channel, or one port.
In the vPC scenario, at least 2 different ports on ASA are connected to ports on 2 different leaf switches.
In the PC scenario, Some port channeled ports on ASA connected to one leaf switch ports.
and finally, in one port connection, I think everything is clear.
After physical connectivity, you need to configure l3Out and choose your routing protocol using APIC GUI or CLI.
if you need any additional information, do not hesitate.
1 - The interfaces should be in port-channel, also in ACI you should configure SVI if you want to establish vPC
2- You need Transit Routing