End-of-Life (EoL)
Create an External Routed Network
The firewalls pass IP routing information
to the ACI ovar a Layer 3 OSPF network. ACI uses a switch virtual
interface (SVI) on the leaf switches with an IP address on each
switch for connection resilience. Create a Layer 3 routed network
to peer with the firewall using OSPF.
- On theTenantstab, double-click on the name of your tenant.
- Select.NetworkingExternal Routed Networks
- Right-clickExternal Routed Networksand selectCreate Routed Outside.
- Enter a descriptiveNamefor yourExternal Routed Network.
- Select your VRF with external connectivity from theVRFdrop-down.
- Select the external routed domain you created previously form theExternal Routed Domaindrop-down.
- SelectOSPF.
- Enter anOSPF Area ID. The Area ID can be expressed in decimal number or dotted decimal form. For example, Area 1 is the same as Area 0.0.0.1 or Area 271 is the same as Area 0.0.1.15. The Area ID range is 0 (0.0.0.0) to 4294967295 (255.255.255.255).
- SelectRegular Areafor theOSPF Area Type.
- Click the plus (+) button to the right ofNodes and Interface Profilesto create a Node Profile with a node that for the border-leaf switches that connect to the firewall.
- Enter a descriptiveNamefor yourNode Profile.
- Attach nodes to your Node Profile.
- Click the plus (+) button to the right ofNodes. This opens theSelect Nodewindow.
- Select the node that your firewall is connected to from theNode IDdrop-down.
- Enter the IP address of the router attached to the leaf switch inRouter ID.
- ClickOK.
- Click the plus (+) button to the right ofNodes and Interface Profiles.
- Enter a descriptiveNamefor yourNode Profile.
- Click the plus (+) button to the right ofNodes. This opens theSelect Nodewindow.
- Select the node that your secondary HA firewall is connected to from theNode IDdrop-down.
- Enter the IP address of the router attached to the second leaf switch inRouter ID.
- ClickOK.
- Attach an OSPF Interface Profile for your Node Profile.
- Enter a descriptiveNamefor your OSPF Interface Profile.
- ClickNext.
- SelectCreate OSPF Interface Policyfrom the OSPF Policy drop-down.
- Enter a descriptiveNamefor your OSPF Interface Policy.
- SelectMTU Ignore.
- ClickSubmit.
- ClickNext.
- ClickSVI.
- Click the plus (+) button to the right ofSVI Interfaces. This opens theSelect SVIwindow.
- ClickVirtual Port Channel.
- Select the Path to the port and port channel interface where the firewall connects to the leaf switch.
- InEncap, enter the VLAN encapsulation used for your layer 3 outside profile.
- SelectTrunkfor Mode.
- In theSide A IPv4 Primary Addressfield, enter the primary IP address of the path attached to the layer 3 outside profile.
- In theSide B IPv4 Primary Addressfield, enter the secondary IP address of the path attached to the layer 3 outside profile.
- ClickOK.
- ClickOKto close the Create Interface Profile window.
- ClickOKto close the Create Node Profile window.
- ClickNext.
- Click the plus (+) button to the right ofExternal EPG Networks. This opens theCreate Routed Outsidewindow.
- Enter a descriptiveNamefor you External Network.
- Add a subnet to you External Network.
- Click the plus (+) button to the right ofSubnets.
- Enter the IP address and mask of the subnet’s default gateway.
- SelectExport Route Control Subnet.
- SelectExternal Subnets for External EPG.
- ClickOK.
- ClickFinish.
Recommended For You
Recommended Videos
Recommended videos not found.