05-29-2023 12:46 PM
Hello all,
I'm new to Cisco SD-ACCESS technology, and i have to migrate two 2 and 2 firewalls to the SDA Fabric on the border switch, the two routers are connected to the traditionnal campus with BGP, but the 2 firewalls have only static routes, i'm wondering how should i connect them to the fabric? For the two routers i understand i can use L3handoff but for the firewalls how can i add static routes on the border to reach specific subnets behind these firewalls ?
05-29-2023 01:08 PM
Hi
It shouldn´t be a problem either with green field or brown field SDA. You can take a look here
05-29-2023 01:22 PM
On this article they show how to add static route on the DNA itself, but in my case The 2 firewalls will be connected to the border switch, so i want to create a simple L3 routed link and add static routes for specific subnets on the border switch
05-29-2023 02:27 PM
I added the wrong link, sorry. Let me find here and I will share.
05-29-2023 02:37 PM
Okay thank you i appreciate it
05-29-2023 03:57 PM
Here it. It is a vídeo actually. But the scenario seems to be similar to yours
https://m.youtube.com/watch?v=KPSWLnNvBpQ&feature=youtu.be#bottom-sheet
05-31-2023 10:40 AM
If the firewall cannot support BGP, still configure the L3 handoffs/IP Transit in the Borders, this will configure both BGP and SVI configuration; use it to create the L3 interfaces between the Border and Firewall.
With these created, you can just use static routes in the Firewall to point to the interfaces created by the L3 Handoff/IP Transit feature.
Of course, using BGP will give you the advantage of importing specific prefixes into LISP and do dynamic routing, but static can do the job too.
05-31-2023 02:16 PM
How can i add static routes on the border from the DNAC please?
05-31-2023 10:23 PM
u must use network templates for this.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide