08-19-2023 06:06 AM
Hi
We are deploying an SDA fabric that will be handed off to an existing fortinet firewall as a fusion device. Is it possible to extend the SGT information to the fortinet then we can use the SGT’s in the firewall rules? If so how do we extend the SGT information to the fortinet when it is stripped off at the fabric border handoff ?
Thanks, Kev.
08-19-2023 07:00 AM
Hi @KevinR99
As the fusion device is a device outside the fabric, theorically it could be any device. The question that needs to be done is does the Fortnet will support to be the fusion?
If we look at the fusion role configuration on cisco docs, we have some specific requirements like support for BGP and enable to perform route linking.
"Fusion - Cisco Router with Support for Inter-VRF leaking"
"Fusion device is outside the fabric, though, and so is configured manually."
08-19-2023 07:44 AM
Flavio
My firewall does support BGP and route leaking is simply achieved via routing on the firewall. Each vrf can see other vrf routes and traffic between them is controlled by firewall routes. So I return to my original question, how does the firewall get the SGT information on which to base rules on if the SGTs are stripped at the Border handoff?
Kev
08-19-2023 09:56 AM - edited 08-19-2023 09:56 AM
@KevinR99 now I will say based on what I've seing and done.
The SGT is meant to be used in lateral control not in north/South communication.
When creating the SGT map on the DNAC you create devices groups and control the communication between those groups by using SGTs. This is called microsegmentation.
I do believe the SGT will not get to the Fusion device because it is not part of the fabric and it would be a north/South communication.
08-20-2023 09:15 PM - edited 08-20-2023 09:19 PM
Hi team, SGTs can be sent from the SD-Access Fabric to external devices, either in the data plane or the control plane, see this Cisco Live presentation where we do exactly that.
In this case we need to find out if Fortinet support SGTs and how they support SGTs. This would be a question best directed to your Fortinet representative please. (A quick web search suggests they have some level of support on some software/hardware). Best regards, Jerome
08-21-2023 11:22 AM - edited 08-21-2023 11:22 AM
Thanks Jerome, that Cisco Live presentation was very useful. I think it ran on a bit so hopefully you didn’t get marked down.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide