cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
316
Views
0
Helpful
2
Replies

SDA Border Node Connection to HA Fusion

pinglis
Level 5
Level 5

We are working on the design for an SD Access deployment and I have a question about border node configuration.

Our typical WAN connectivity is via a pair of high availability FortiGate Firewalls. These will act as the Fusion device. In a HA configuration the firewall appear as a single device and share the same configuration (IPs, BGP etc.) so while we have physical redundancy effectively there is a single Fusion device.

On the Fabric side the border node will typically be a stack of switches and the FortiGate's will be physically connected to different members. So again physical redundancy but a single Border node.

The set up is illustrated below.

SDA-Border1.png

 

My questions is how do I configure the interface that links to the second firewall?

Catalyst Center does seem to allow me to add it as part of the Border Node configuration (complains about duplicate addresses).

Looking at the configuration deployed on a Border node interface its it just a basic trunk port.

Is ok to just configure the second link as a Trunk port? Or is there some other configurations required that designate it as an "exit" point from the Fabric?

Thanks

 

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

In the Fabric Provisioning workflow, select the Port Channel as the external interface for the Border Node.

Some example reading :

https://netcraftsmen.com/securing-sd-access-traffic/

BB

=====️ Preenayamo Vasudevam ️=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

u want to configure 2nd link exactly as 1st. but are u really able to add 2nd link in BN-L3HO workflow for the same IP-transit?  
finally, it's bad idea to have BN stacked as you lose hitless SWIM for site (assuming u have single pair of BN & FN there)