Friday, November 30, 2018

VXLAN Design Question - Firewalling and VXLAN

Question for those of you VXLAN experts. If a person wants to do an HA pair of firewalls (lets say through PAN), and they want to run one firewall in DC A and another in DC B. Because it is in HA they need to be in the same network.

So the admin creates 10.0.0.0/24. Each firewall is going to a pair of leafs.

Is it possible to run ospf on the 10.0.0.0/24 network on the leafs if they are running in anycast gateway mode? If not, then how can you stretch the layer 2, when you also want to use layer 3 to advertise things like your default route from your firewalls.



No comments:

Post a Comment