Wednesday, March 7, 2018

Pretty granular and specific question here. PBR on FEX ports coming off an N9k. Some suggest it isn't possible.

To give the run down we have two types of servers. Server Group A and Server Group B, which must have their external traffic routed to respective firewalls. Group A will route to Firewall A and Group B to Firewall B.

We currently use PBR to do this with a next hop of A or B if it matches an ACL.

We are moving these said servers to FEX ports off an N9K.

This link here says

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/6-x/unicast/configuration/guide/l3_cli_nxos/l3pbr.html

"Policy-based routing is not supported with inbound traffic on FEX ports."

Given this sound straightforward as traffic destined TO hosts on FEX ports, I wanted to be extra sure.

Thoughts?



No comments:

Post a Comment