04-05-2020 11:41 PM
Hi All
A customer has 2 data centres with active firewall in one DC and standby firewall in second DC. The firewall connects to internet through a pair of Nexus 9ks in vpc. The firewall connects to a WAN routers through a separate pair of Nexus 9k in vpc.
There is a WAN router in each DC and an Internet router in each DC.
We need to extend a layer 2 section between the firewall and the WAN layer so that firewall can build routing neighborship with both WAN routers.
We need to extend a layer 2 section between the firewall and the Internet layer so that firewall can build routing neighborship with both Internet routers.
How can i extend layer 2 between the two DCs? Would a back to back VPC be a better option or VXLAN?
If using back to back VPC between the DC and using 2 links, how does loop prevention work?
Please find a pic of the sample topology that i am looking for.
As shown i need to extend Internet connection between [Nexus9k-1, Nexus9k-2, Nexus 9k-5, Nexus9k-6].
and so that i can run HSRP between the firewall and run a static route.
I need to extend WAN connection between [Nexus9k-3, Nexus9k-4, Nexus 9k-7, Nexus9k-6] so that the WAN routers can run routing protocol with the active firewall.
Regards
Rohan
04-06-2020 12:39 AM
Hello,
how are both data centers currently connected ?
04-06-2020 12:52 AM
Hi Georg
These are not connected at the moment, they are not sharing the Internet and WAN links. I am looking for options to connect them..
Regards
Dattaram
04-06-2020 01:06 AM
04-06-2020 01:34 AM - edited 04-06-2020 01:54 AM
Thanks ngkin
The data centres are in an active passive fashion. The split active will be taken care of network advertisements. BGP running from WAN routers to WAN and from Internet routers to the internet to make sure the active data centre is preferred.
The problem with point to point is how can i extend the single circuit to the vpc devices? And what about a single point of failure when the device terminating the DCI fails.
Regards
Rohan
04-06-2020 01:56 AM - edited 04-06-2020 02:09 AM
Hi,
Do you mean you have only 1 single across site circuit? I think you should have at least two to deal with the single point of failure.
btw, please see if you find this document is useful.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide