[HD] How to deploy Cisco ACI Service Graphs with PBR to load-balance to One-Arm Firewalls

แชร์
ฝัง
  • เผยแพร่เมื่อ 15 ก.ย. 2024

ความคิดเห็น • 24

  • @EE-eg2bp
    @EE-eg2bp ปีที่แล้ว +1

    Thanks so much for this! It helped me figure out the missing piece in my deployment that I was struggling with. I simply forgot to point the default route on the Palos to the service BD's gateway.

  • @nash.p9781
    @nash.p9781 2 ปีที่แล้ว

    Great video Ralph, super presentation.

  • @PascalBoegli
    @PascalBoegli 4 ปีที่แล้ว

    Thank you, very useful step by step config

  •  4 ปีที่แล้ว

    Thank you, very detailed and useful step by step config

  • @hugolinprsnickus
    @hugolinprsnickus 4 ปีที่แล้ว

    Ralph, thank you for the effort, very useful video!

  • @alanhao1978
    @alanhao1978 4 ปีที่แล้ว

    Great video,and very clear explanation! Thank you !

  • @harrisonias8726
    @harrisonias8726 4 ปีที่แล้ว

    Thank you, this was very helpful and informative!

  • @TariqASheikh
    @TariqASheikh 3 ปีที่แล้ว +2

    font size is small in topology. can you share jpg file separately. i can't read names of some of constructs.

  • @danieloctavianus2295
    @danieloctavianus2295 ปีที่แล้ว

    Question :
    Why you have to configure the BD ip address on subnet section?
    that is for route leak, right?

  • @juliogarcia878
    @juliogarcia878 3 ปีที่แล้ว

    Great video and diagram. Could you please share with us what tool you used to build that diagram?

  • @yahiaccnp1310
    @yahiaccnp1310 2 ปีที่แล้ว

    can we connect firewall as a per metal server and put gateway on it and all communication from Fabric went through it.

  • @MrGlaska
    @MrGlaska ปีที่แล้ว

    What if you are using active/standby FW? Do you need select L3 VIP then?

  • @philuxe
    @philuxe 3 ปีที่แล้ว

    great video, very helpfull, I have got one question : can we use the same one arm firewall (or cluster) for filtering north-to-south ?
    also it would be great to have the same kind of demo with loadbalancer insertion :p

  • @wimrotor
    @wimrotor 4 ปีที่แล้ว

    Hi Ralph, Nice overview ! Thx.
    Question: in the case of vZANY-to-vZANY PBR, you mention that it includes all EPGs related to the VRF.
    But does it also includes the External-EPG used at the L3OUT ?
    E.g.: traffic from APP_EPG going to "internet", will it also travers the PBR construct before passing the L3out?

    • @2emptywords
      @2emptywords 3 ปีที่แล้ว

      Correct, L3out extEPG is also included in vzany

  • @toaster09
    @toaster09 4 ปีที่แล้ว

    Thank you

  • @user-hi7ym9qp4r
    @user-hi7ym9qp4r 3 ปีที่แล้ว

    Good Day! Why a separate contract was created between the web and the database, why not through Palo Alto?

    • @igormordiuk8900
      @igormordiuk8900 3 ปีที่แล้ว

      The point here is to pass all internal DC communications between all EPGs through Palo, but with one exclusion: we want Web and Database EPG to talk to each other directly through the fabric (not traversing Palo). So adding the contract between Web and Database without L4-L7 services tells the fabric to treat this communication on the contract base only.

  • @roysegev6172
    @roysegev6172 ปีที่แล้ว

    What is the service bridge domain?

  • @johngabrieldejesus
    @johngabrieldejesus 4 ปีที่แล้ว

    When deploying this use case, the ACI Fabric is the gateway of the servers?

    • @ralphcarter769
      @ralphcarter769  4 ปีที่แล้ว +1

      Yes ACI is the default gateway.

    • @johngabrieldejesus
      @johngabrieldejesus 4 ปีที่แล้ว

      @@ralphcarter769 thanks for your reply. Great video.