cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
361
Views
0
Helpful
1
Replies

L2VN to L3VN migration options

bhaertel
Level 1
Level 1

Hi there,

I am planning to set up an L2VN without anycast gateway / SVIs in the fabric for a migration use case. The gateway of the corresponding L2VN will remain outside of the fabric at least throughout the migration period for several reasons and will be made available through a dedicated L2-Handoff Border Node that connects the existing environment.

At the moment it's not sure / under discussion if the gateway will remain outside of fabric just for the migration or even after that has been completed. But, if one day the client decides that they want to move the gateway functionality inside the fabric, is there a way to turn the previously created L2VN to a full-featured L3VN?

I am thinking about the following options and need to verify if they are actually supported or feasible:

  1. use the "Create Anycast Gateway" Workflow on the L2VN by providing a dedicated IP address pool (assuming this would also create the corresponding L3VN constructs etc.)
  2. Create an L3VN (including an L2VN) in the first place,
    1. but without assigning an IP address pool / Anycast Gateway
    2. by assigning an IP address pool already but deleting the Anycast Gateway  
  3. Deleting the L2VN and adding a new L3VN (including an L2VN) that uses the same VNI / VLAN-ID parameters as the previous L2-only VN (taking into account that this would result in a temporary disruption of connectivity)

Which of the options would actually be feasible and what would be the best approach? Feel free to also add other options / approaches if you want.

Edit: Using Catalyst-Center 2.3.5.6

Thanks, Benjamin

 

 

1 Reply 1

1. Though u can assign arbitrary VLAN to new AcGW during its configuration it wont work for existing L2VN. i've just tried to "migrate" L2VN to AcGW in our LAB & it failed with:

andydoesntlikeuucp_0-1727434103350.png

2. L2VN is VRF. u dont associate L2VN with L3VN but AcGW.
3. it will be the disaster for endpoints previously migrated to fabric in L2VN(s).
last but not least, the recommended approach is always to move GW to fabric unless there is strict requirement (e.g. stateful inspection of inter-VLAN traffic on the FW). So unless mentioned requirement is your case be encouraged to move GW(s) to L2-BN for every target VLAN(s) & create AcGW(s) in fabric. & be mindful with populations u treat: Cisco SD-Access & Operational Technology (OT) (packetpushers.net)