PA 3250 HA Pair bgp peering

cancel
Showing results for 
Search instead for 
Did you mean: 

PA 3250 HA Pair bgp peering

L0 Member


Hi

I am looking for a design/ best practice recommendation for the following topology (See cover photo)

 

HA Firewall + 2 Nexus 9Ks BGP peering.png

 

I am looking at implementing BGP between the swtiches (Nexus 9Ks) and the firewalls (PA 3250's) Firewalls are in a HA pair. Switches use VPC's as well as HSRP for VLAN/gateway redundancy etc. 

 

As the firewalls are configured in a HA active/standby pair. I am not sure how I can peer with the 9Ks as they are standalone thus there will always be 2 IPs. Peering to the HSRP/VRRP etc. address will not work as its a Virtual IP. Two BGP peers may be an option from the firewalls to each 9k switch. I haven't been able to find any design guides for the attached topology. Any ideas will be greatly appreciated.

 

Kind regards

3 REPLIES 3

L4 Transporter

Thank you for the post @Matt.Smith123 

 

I am running the identical design in multiple sites. We are also using a pair of Nexus 9K with HSRP. The only difference is, we do not run a vPC between Nexus 9K and PA Firewalls. We have established BGP peering from PA Firewall to each of the Nexus. On each of the Nexus the BGP peer is terminated on Vlan interface where we also run HSRP. We have also BGP peer between each of the Nexus.

 

For running eBGP over vPC, there are a few caveats. Please check below article, refer to section: "Several problems are posed when trying to enable routing protocol peering over a vPC"

https://www.cisco.com/c/en/us/support/docs/ip/ip-routing/217099-ebgp-peering-over-vpc-on-nexus.html

 

Kind Regards

Pavel

  

Pavel Kucera

L3 Networker

Hi @Matt.Smith123 ,

 

This is the design guide for Nexus VPCs -> https://www.cisco.com/c/dam/en/us/td/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practice....  Even though it says N7K, the concepts apply to all Nexus (although it's best to double check your specific model).  For years, the recommended design for L3 connections was not VPC, but L3 links.  Only recently has support been added for L3 over VPC.  So, @PavelK 's design is the tried and true design for years.  The URL has much info about L3 links to Nexus.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L0 Member

Hi both

 

Thanks for the feedback. Tom - I will have a read with regard to the VPC documentation. Hoping to lab this up when I get an opportunity.

 

Regards

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!