EMAIL SUPPORT

dclessons@dclessons.com

LOCATION

AF

Service Node Integration with Multi-Pod

Service Node Integration with Multi-Pod

Service Node Integration with Multi-Pod

Cisco ACI offers the capability to insert Layer 4 to Layer 7 services, for example, firewalls, load balancers, and intrusion prevention systems (IPSs), using a manual configuration of bridge domains and EPGs, or with a managed-mode service graph or an unmanaged-mode service graph. 

Several deployment models are available for integrating network services in a Cisco ACI Multi-Pod fabric. To determine the best options to choose, you should consider all the specific requirements and characteristics of the design, more precisely:

  • Service node location and function

    1. North-south service node (or perimeter service node), for controlling communications between the data center and the external Layer 3 network domain. An example is a firewall that protects web servers from an external network.

    2. East-west service node, for applying policies for traffic flows within the data center. For the east-west enforcement, there are two cases to consider:

      • The service node, such as firewall, is used to apply policies between EPGs that are part of the same VRF.

      • The service node, such as firewall (or firewall context), is front-ending each tenant/VRF (very commonly deployed), which enables you to apply security policies to all inter-VRF traffic. This option can be used also to apply north-south policies when the external network domain is also reachable by a VRF through a firewall.

  • Service node mode of operation

    1. Transparent (Layer 2 mode)

    2. Routed as default gateway for the endpoints

    3. Routed with L3Out peering

    4. Routed with PBR

  • Service node high-availability model

    1. Active-standby service node pair stretched across pods

    2. Active-active service node cluster stretched across separate pods (supported from Cisco ACI Release 3.2(4d))

    3. Independent active-standby service node pair in each pod

  • Connectivity to the external Layer 3 network domain

    1. Traditional L3Outs deployed on the border leaf nodes

    2. Layer 3 EVPN services over fabric WAN

When integrating service nodes with Cisco ACI Multi-Pod fabrics, such as firewalls, the following provides more details for the options depending on the chosen high-availability model:


Comment

    You are will be the first.

LEAVE A COMMENT

Please login here to comment.