Posts for: #Service_insertion

ACI L4-7 Service Insertion - Active-Standby Firewalls with Standard Service Graphs (SSG) in ACI Multi-Site Designs

Stretched HA Firewall

Cisco supports a stretched Active-Standby firewall system if:

  • ACI operates in layer 2,
  • the firewall operates as the IP default gateway for the endpoints or the firewall operates in Transparent mode or the active and standby nodes are connected with an L3Out.

Independent HA Firewalls

If I have to deploy Active-Standby Firewalls, Cisco recommends to deploy them as independent HA firewalls in the ACI sites (i.e. not across the intersite link)

[Read]

ACI L4-7 Service Insertion of an Active-Standby Firewall in Go-To Mode in an ACI Single-Pod Design

One concrete device per firewall –> 2 concrete devices under the L4-7 device.

If I have a two-arm firewall design: For all Concrete Devices within a L4-7 Device I must map all Concrete Interfaces of the same direction to the Cluster Interfaces ( #PersoNote symmetrical interface mapping):

  • add one Cluster Interface for the Consumer side and associate it with all Consumer-side interfaces of all [[#Concrete Device]]s,
  • add one Cluster Interface for the Provider side and associate it with all Provider-side interfaces of all [[#Concrete Device]]s.

If I have a one-arm firewall design: add one Cluster Interface that includes both Concrete Interfaces of the firewalls. #verifyThis

[Read]

ACI L4-7 Service Insertion_Failover Traffic Management

Failover traffic is not managed by L4-7 Service Graphs

See the document ACI Service Graph Design Guide for ACI 5.2 and Later.pdf, page=50.

With the ‘out-of-band’ method

Use the dedicated firewall failover link ports and firewall stateful failover link ports, or designate some ports for that role; Failover traffic and stateful failover traffic are said to be managed ‘out-of-band’

With the ‘in-band’ method

i.e. use the physical network of the data traffic for failover and stateful failover traffic too. When the firewall is attached to ACI, the physical network path of firewall traffic is the ACI fabric.

[Read]

ACI Multi-Site and Active-Standby Firewall Clusters with Service Graph Redirect

Technology in Nexus Dashboard Orchestrator Equivalent on APIC
define a Service Service Device Cluster L4-7 Device, SGT

EPG-to-EPG PBR contract in ACI multi-site with independent HA-firewalls: I must define the BD subnet also under the consumer EPG and set the no Gateway SVI flag.

Contract Enforcement vs PBR Contract Enforcement vs PBR Policy Enforcement Contract enforcement == zoning rules are deployed to a leaf X. So leaf X takes action on the contract-matched traffic based on the deployed zoning rules. Leaf X is determined according to the Contract Policy Enforcement Locations table in the document ACI Contract Guide White Paper, page=20.

[Read]

ACI L4-7 Service Insertion: Service Graph Mgmt Modes

There are three ways to manage L4-7 services when we use service graphs. So if no service graph is inserted, we do not talk about these management modes!

[!Abstract] Unless otherwise specified, when Service Graphs are mentioned, then I am referring to the Unmanaged Mode.

Service Graph in Managed Mode (deprecated concept)

aka Service Policy mode: horizontal integration; requires a Device Package.

Device Package

sc1

adding a Device Package

sc2

[Read]

ACI L4-7 Service Insertion: Service Graph with PBR

[!TLDR] Personal Observation I find few sources discussing standard SG and more literature discussing SGR. It seems to me that Cisco is pushing toward SG with PBR whenever a design involves L4-7 Service Devices.

aka Service Graph with Policy-Based Redirect, Service Graph Redirect. I call it SGR. One-Node SGR: Service Graph with one PBR Node.

Concept of a multi-node Service Graph

the concept of node in the terms ‘single-node SG’ or ‘multi-node SG’ refers to the L4-7 Devices in the SG. So, the term ‘multi-node Service Graph’ refers to a Service Graph with multiple L4-7 Devices, where each L4-7 Device could be:

[Read]