Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,
I'm working on an ACI design for our new datacenters.
We will have Customer tenants, and a specific tenant that will propose shared services to the customers tenants (DNS, NTP, backup, VTOM scheduling...).
First I planned to use a standard tenant...
Hi,
(I've included a quick diagram with this post to give a better view of what i'm trying to explain )
I'm planning to use two nexus 9332pq as core switches for a small datacenter, in nxos (non aci) mode.
These new switches would concentrate exis...
I've got a question about Nexus9K (9300), VCP and HSRP/VRRP limits/scaling.
I'm thinking about a configuration with 2 Nexus9K running as L3 core, and some other Nexus 9K running as L2 access switches.
The 2 core swicthes will peer with L2 access sw...
We have a network topology I would like to modify for standardization purpose to match the following configuration.My question will deal mainly with icmp redirect.
On a single interconnexion network, 192.168.1.0/24, we would have :- our provider gat...
Hi,
I just got a new job, and inherited a network architecture where ASA5520 are facing Internet.
Network load is very low for now (<10M), but could increase a lot as we will host a new application that will be accessed by many new customers (I aske...
And what about L2 security ? I mean, with a single bridge domain (and a single large subnet over it) with many EPG, how does the fabric mitigates (or not) the risk of arp poisoning ?Host1 in EPG1 is compromised and send a malicious garp/arp response ...
Yes, I was given a workaround.
As contract filters are L4 stateless filters (ie simple ACL), we can define the "Resources" Tenant as provider for all contracts, even those where the connections are initiated from the others Tenants/VzAny.
We only nee...
Interesting, thank you.
When I looked at Cisco verified scalability guide for nexus9300, i found this table :
Feature
9500 Series Verified Limit
9300 Series Verified Limit
Unicast Routing
BFD sessions (echo mode)
512
256
BGP neighbors
2000
...
OK, so there would be no problem sharing a standard interface between security contexts and admin contexts.
One step further, would it be possible to share the management interface this way ?
I mean, would it be possible to allocate management inter...