mknomad.blogg.se

Cisco asav policy based routing
Cisco asav policy based routing












For example, you cannot put the PBR node in VRF3, which is neither a consumer nor a provider VRF instance.įigure 3. The PBR node must be in either the consumer or provider VRF instance (Figure 3). The PBR node can be between VRF instances or within one of the VRF instances. Example of supported PBR topologies 1įigure 2. More information about service graph designs is provided later in this document.įigure 1. These examples show two-arm-mode PBR nodes, but you can also deploy a one-arm-mode PBR node except in L1/L2 PBR. This section shows supported and unsupported topology examples for PBR.

  • Provider connector: PBR node interface facing the provider side.
  • Consumer connector: PBR node interface facing the consumer side.
  • PBR node: L4-L7 device that is used for a PBR destination.
  • Policy: In Cisco ACI, “policy” can mean configuration in general, but in the context of this document “policy” refers specifically to the Access Control List (ACL)–like Ternary Content-Addressable Memory (TCAM) lookup used to decide whether a packet sourced from one security zone (EPG) and destined for another security zone (EPG) is permitted, redirected, or dropped.
  • This document uses the following terms with which you must be familiar:

    cisco asav policy based routing cisco asav policy based routing

    The traffic instead is redirected to the node based on the PBR policy. The use of PBR simplifies configuration because the VRF sandwich configuration is now not required to insert a Layer 3 firewall between security zones.

    cisco asav policy based routing

    With PBR, the Cisco ACI fabric can redirect traffic between security zones to L4-L7 devices, such as a firewall, Intrusion-Prevention System (IPS), or load balancer, without the need for the L4-L7 device to be the default gateway for the servers or the need to perform traditional networking configuration such as Virtual Routing and Forwarding (VRF) sandwiching or VLAN stitching.

    #Cisco asav policy based routing how to#

    This article describes how to configure Policy-Based Redirect (PBR) service in the Cisco ACI using Cisco ASAv as a PBR node.












    Cisco asav policy based routing