11-14-2024 09:16 PM
Hi,
We have a requirement where we need to route single VRF (SSOL_Vrf) Traffic in SDA Fabric. Currently all vrf traffic is being forwarded based on default route, as a new requirement we need to forward it to new firewall being a part of SDA Fabric.
Sharing topology below for your reference and Border1 and Fusion 1 switch Configuration for review
Thanks in advance
Regards,
Mohammed Asif
11-14-2024 09:53 PM
i'd start with analysis of how default route currently injected into VRF (FNs would be good place to start) & then develop action plane to replace it with one from new FW.
11-14-2024 10:20 PM
Hi,
Please refer attached Border 1 Switch and Fusion 1 Switch configuration.
Border 1 Switch is part of SDA Fabric. Where as Fusion 1 Switch not a part of SDA fabric. BGP routing Protocol uses between Border 1 switch and Fusion 1 switch to route vrf traffic outside SDA Fabric.
Thanks in Advance
Regards,
Mohammed Asif
11-14-2024 11:44 PM - edited 11-15-2024 02:06 AM
it's well known fact that FNs r not part of the Fabric in supported designs as well as VPNv4 BGP AIF Option A is used for BN-FN peering. it doesnt bring any matter to analysis yet to be done. as i said above: start with investigation on FNs of how default route gets injected into VRF.
UPD. i guess simplest way for u would be replacing target VRF's interconnect on FNs from that toward Core to one toward new FW. Injection of default route into VRF on FNs is matter of technique.
11-15-2024 12:50 AM
Am I interpreting this correctly?
If that is the case I would configure a new "intermediate" VRF on your fusion nodes used only for routing between the border and your firewall. This way you can have one FW interface in each VRF(one in the "SDA peering" VRF and one in the "upstream" VRF) to force traffic through your FW. I would also consider connecting both fusion nodes to the firewall such that you get fusion node redundancy for the VRF.
Please see the following diagram for a better depiction of what I mean:
11-15-2024 01:29 AM
Hi Torbjon,
Thanks for Response,
Thanks in Advance,
Regards,
Mohammed Asif
11-15-2024 01:54 AM
On your fusion node you should:
This will result in a configuration that only forces the traffic in your SSOL_Vrf VN through the firewall. Routing for all other VNs should be unaffected by this change.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide