cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
11110
Views
15
Helpful
20
Replies
bcn-jbrooks
Beginner

Shared L3Out in Common?

Hi all,

I'm very new to ACI, but learning as much as I can.  We are in the midst of building up an ACI fabric mostly for lab use, running the latest v2.0 ACI code.

I'm trying to create a Shared L3Out (to the Internet) that all tenants will share.  I have a firewall connected to my ISPs that is connected to the ACI over a vPC.  I have not been able to find much into about how to do this.  Most documentation guides assume that I want to use a "routed interface" (or sub-interface), not a vPC.

This would be simple to do in a traditional network - a small transit network between the firewall and an SVI on the switch, but I can't figure out how to do this on ACI.

Do I need an EPG in the Common tenant for the "vlan" between fabric and firewall, then another EPG that gets Shared to the tenants?

Does anyone have a link to a good tutorial or something?

My mind is officially blown -- and that's after taking several Cisco training courses on ACI... 

Much appreciated!

J

20 REPLIES 20

how did you configure the L3out ? What scopes do you have selected for the L3out ? 

Leon

Thanks for using the Cisco ACI Support Community. The original question has been answer correctly. For any other questions regarding ACI, please open a new discussion and someone will assist. 

Thanks

Jason

t.houmaiza

Thanks for using the Cisco ACI Support Community. The original question has been answer correctly. For any other questions regarding ACI, please open a new discussion and someone will assist. 

Thanks

Jason

I'm building this  shared  l3out configuration in my lab. I'm Including  some of the original post config below.

 

In the tenant Common
- Create a VRF (common-v1)
- Create an External Routed Network (common-l3-ospf)

 

In the Tenant-Black
- Create a VRF (black-v1)
- Create a BD (black-bd1

 

In the tenant White
- Create a VRF (white-v1)
- Create a BD (white-bd1)

 

I'm providing and consuming the contacts as listed in the original post.

I have questions on what the routing tables look like.  First, I do see routes leaked between vrfs. In common-v1 I see white-bd1 and black-bd1 routes. On the external router I also see white and black bd routes. I was expecting that. What I don't see is the external router routes getting advertised into white and black VRF's. I do see them in the common vrf. 

 

What could be wrong?

 

Thanks

Hi jgesualdi, I'm facing the same issue, did you fix this issue and how? Thanks

Never mind, I found the issue. BGP RR policy was missing from POD policy.

Thanks