cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7623
Views
5
Helpful
16
Replies

How to route traffic via Firewall in EVPN + VxLAN fabric

satish.txt1
Level 1
Level 1

This is what i am trying to design new network, this is just on paper nothing finalized and i am sure it has lots of issue like firewall should be on leaf not border leaf etc. so that is why i am here to clear all those doubts. I have following question related Spine-leaf design.

  • If we use anycast gateway in this design in that case leaf would be my edge gateway for all hosts connected to that leaf so how does Host-A will send traffic to Host-B via firewall?
  • Should i disable anycast gateway so each VLAN traffic route via firewall (my firewall is gateway for all VLANs)
  • what do you think about this design or this is not something i should be using?

temp_s_l (2).png

16 Replies 16

@Francesco Molino _ thanks for the wonderful explanation. So in Option 3 the VLAN gateways will sit on firewall and there will be L3 routing bw Spine & Firewall so that any inter-vlan comms will happen on the Firewall (as FW is supposed to be hosting gateways of all the VLANs)?

It represents how to handle an asa in a vxlan fabric for inter-vrf routing for example. 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question