cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

323
Views
0
Helpful
0
Replies
Justin Westover
Beginner

Extend L2 using OTV with Stateful firewalls as gateways

I have an OTV design related question.  We currently use Cisco ASA firewalls as the L3 gateways between our different web and application and database tiers and several other tiers. We are now beginning to look into an extended L2 datacenter design where we extend our L2 domains over our current DCI using a technology such as OTV. Has anyone seen or heard of an OTV deployment where the LANs being extended over the overlay had a gateway of an ASA firewall? The problem I see with this is if two or more datacenters share the same IP as the gateway the clients use (on the firewalls) and a VM migrates from one DC to the other, the firewall at the other datacenter won't have a state table from the VM and drop any existing traffic the VM had going. The only solution I see around this is clustering the ASAs so they share state tables. I was also curious if anyone has seen this work with transparent firewalls where the gateway now lives on a different device other than the ASA such as the Nexus switch itself on an SVI. Any guidance here would be appreciated. Thanks 

0 REPLIES 0