09-27-2024 02:39 AM - edited 09-27-2024 02:50 AM
Hi there,
I am planning to set up an L2VN without anycast gateway / SVIs in the fabric for a migration use case. The gateway of the corresponding L2VN will remain outside of the fabric at least throughout the migration period for several reasons and will be made available through a dedicated L2-Handoff Border Node that connects the existing environment.
At the moment it's not sure / under discussion if the gateway will remain outside of fabric just for the migration or even after that has been completed. But, if one day the client decides that they want to move the gateway functionality inside the fabric, is there a way to turn the previously created L2VN to a full-featured L3VN?
I am thinking about the following options and need to verify if they are actually supported or feasible:
Which of the options would actually be feasible and what would be the best approach? Feel free to also add other options / approaches if you want.
Edit: Using Catalyst-Center 2.3.5.6
Thanks, Benjamin
09-27-2024 03:59 AM
1. Though u can assign arbitrary VLAN to new AcGW during its configuration it wont work for existing L2VN. i've just tried to "migrate" L2VN to AcGW in our LAB & it failed with:
2. L2VN is VRF. u dont associate L2VN with L3VN but AcGW.
3. it will be the disaster for endpoints previously migrated to fabric in L2VN(s).
last but not least, the recommended approach is always to move GW to fabric unless there is strict requirement (e.g. stateful inspection of inter-VLAN traffic on the FW). So unless mentioned requirement is your case be encouraged to move GW(s) to L2-BN for every target VLAN(s) & create AcGW(s) in fabric. & be mindful with populations u treat: Cisco SD-Access & Operational Technology (OT) (packetpushers.net)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide