cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1105
Views
5
Helpful
2
Replies

Pure L2 Bridge Domain in Tenant

robertke1
Level 1
Level 1

Hi,

I have a basic question about creating pure L2 Bridge Domains within Tenant:

Can we use ACI Fabric as pure L2 switch between different hosts - all routing/firewalling  would be done outside fabric? The reason is that I don't want to add additional p2p links between different systems - so direct links between Router-FW, FW-Proxy, Proxy-Host.

See attached diagram for clarification.

Thanks,

Robert

1 Accepted Solution

Accepted Solutions

Claudia de Luna
Spotlight
Spotlight

Absolutely, Robert.

In these pure L2 BD I'd suggest making sure you disable 'Unicast Routing' (Alternatively you can enable "Limit IP Learning to Subnet' but for these constructs i like disabling Unicast routing).

You need to disable ACI's "greedy" learning behavior for these or else you won't get the traffic patterns you expect.  

Having said that I always caution clients to not use their ACI fabric for core or distribution functions but it can be done.

Claudia

View solution in original post

2 Replies 2

Claudia de Luna
Spotlight
Spotlight

Absolutely, Robert.

In these pure L2 BD I'd suggest making sure you disable 'Unicast Routing' (Alternatively you can enable "Limit IP Learning to Subnet' but for these constructs i like disabling Unicast routing).

You need to disable ACI's "greedy" learning behavior for these or else you won't get the traffic patterns you expect.  

Having said that I always caution clients to not use their ACI fabric for core or distribution functions but it can be done.

Claudia

Thanks.

Save 25% on Day-2 Operations Add-On License