el 09-12-2024 07:10 AM
Hi,
Does anyone know of a step-by-step guide (detailled configuration of BD, Health Groups, Redirect Polices, L4-L7 Devices, Service Graph and Device Selection Policies), for deploy multinode (FW + IPS) service graph?
We have this enviroment and we can make work fine only single node service graph (only firewall or only IPS).
Regards.
el 09-12-2024 07:17 AM
To deploy a multinode (FW + IPS) service graph, follow these general steps:
Configure Bridge Domains (BD): Ensure your BDs are correctly mapped to the subnets and associated with appropriate EPGs.
Health Groups: Create health groups to monitor the health of the services (FW and IPS) by setting up probes for both nodes.
Redirect Policies: Set up traffic redirection to the service devices (FW + IPS) using a service graph template.
L4-L7 Devices: Add your firewall and IPS as L4-L7 devices, configuring them in the service graph for proper traffic flow.
Service Graph: Create a service graph template that chains the FW and IPS nodes, ensuring traffic flows through both in the correct order.
Device Selection Policies: Define selection policies for distributing traffic to specific instances of the FW and IPS nodes.
For detailed steps, refer to Cisco ACI’s official documentation on service graph deployment.
el 09-12-2024 07:50 AM
Hi,
We know what are the general steps, in fact the enviroment works with single node service graph (only with firewall or only with ips), so we need one detailled guide from this case because the Cisco ACI's official docuementation don't cover it.
Regards.
Descubra y salve sus notas favoritas. Vuelva a encontrar las respuestas de los expertos, guías paso a paso, temas recientes y mucho más.
¿Es nuevo por aquí? Empiece con estos tips. Cómo usar la comunidad Guía para nuevos miembros
Navegue y encuentre contenido personalizado de la comunidad