Posts for: #Service_graph

Common Concepts For Cisco ACI Standard Service Graphs and Service Graph Redirects

These are common concepts for Standard Service Graphs and Service Graph Redirects. Service Graph with L4-7 Device in Go-To mode == L3 Service Graph. L4-7 Device in Go-To mode and the SGT has PBR enabled == L3 PBR Node.

Concepts

L4-7 Service Graph

requires the Service Graph Template

Service Graph Contract

aka SG Contract The contract associated with the Service Graph.

Service Node

referrs to one concrete device. In Cisco litterature the term Service Node is used more than Concrete Device.

[Read]

ACI and Active-Active Firewall Cluster in Single-Pod and Multi-Pod Designs

ACI Single Pod, Active-Active Firewall Cluster in Go-To Mode

L4-7 Device Config

A single Concrete Device, one or more Concrete Device Interfaces and one or more Cluster Interfaces, depending on the physical topology. See the document Service Graph Design Guide for ACI 5.2 and Later, page=55.

ACI Multi-Pod, Active-Active Firewall Cluster in Go-To Mode

Stretched Active-Active Firewall Cluster in Go-To Mode, in ACI Multi-Pod Designs

Designing cluster nodes in more than one data center is supported by ACI Multi-Pod. Each ACI pod has one or more firewalls in the active role. See the document ACI Multi-Pod and Service Node Integration, page=5.

[Read]

Cisco ACI L4-7 Service Insertion: Standard Service Graphs with Firewall in Go-To Mode

#QA SSG with L4-7 Device in Go-To mode: in which situations do we need only layer-2 BDs attached to the Device? Layer-3 BDs? one Layer-2 and one Layer-3 BD? what is the recommended design? Go-To mode == Routed mode When NAT needed on the L4-7 Device: use Service Graph in Go-To mode with NAT. another ‘sub-mode’ is an L3Out between the L4-7 Device and ACI. With both NAT sub-mode and L3Out sub-mode:

[Read]