Thursday, January 3, 2019

Pair of Nexus 9ks as core, VPC to Palo firewall, things break when 1/2 the VPC goes down

Hi y'all, I'm hoping someone here can sanity check me, cause I think I'm missing something pretty obvious and I'm going crazy after staring at all 50,000 of Cisco's diagrams of Nexus>VPC>Router/Firewall/L3 device configurations.

Here's a brief diagram of what I have setup. I can add more if I'm missing pieces. https://drive.google.com/file/d/17KCigIwe9pSAWCgQSHXkuWYYNlufsvSC/view

Diagram doesn't include any routing -- it's all static. There's a /29 shared between the 3 devices. .1 is fw, nexus hsrp locals are .4 and .5 with hsrp of .6. Default route on core 0.0.0.0/0 points to the .1. This svi is only used for routing traffic between firewall and core. Palo has a static route back pointing at the .6.



No comments:

Post a Comment