- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-09-2017 04:44 PM
Folks,
I'm new to the PA's, so I wanted to present this question for you. I have two PA 5020's, in Active/Passive configuration shown above. On each PA, eth1/4 and eth1/5 is in an aggregate group. I have two Nexus 9504's as our core switches. I two layer 2 VLAN's created. One for each of our internet circuits. I've created vPC for each of the interfaces for the port channels. On the PA's, I've IP'd each aggregate sub-interface with the respective IP for each of the internet circuits. Let's say that I have subinterface 299 and 300. Sub-interface 299 is 1.1.1.2/30, and Sub-interface 300 is 2.2.2.2/30. When I add a default 0 route, on the Nexus core swithces, that points to the public address of VLAN 299, the route doesn't add to the route table. I'm assuming this is because the ARP table doesn't contain the public IP of the internet circuits. Was wondering if anyone had any luck with this type of configuration, and if there was any insight you could give for this type of setup.
12-12-2017 05:47 AM
I haven't used Panorama in a while, so I'm not sure about the current interface.
Templates and groups are where you put settings that will be on multiple devices.
For settings like this that are specific to the individual device you change context to the specific PA in Panorama and then configure the setting there.
12-10-2017 02:21 PM
In order for routes to be active the next hop has to be reachable. So if you want to use vlan 299 and your default route the next hop in your example would be 1.1.1.2 on the PA interface. This will be reachable on the Nexus and the route will be active.
12-10-2017 03:01 PM
12-12-2017 05:47 AM
I haven't used Panorama in a while, so I'm not sure about the current interface.
Templates and groups are where you put settings that will be on multiple devices.
For settings like this that are specific to the individual device you change context to the specific PA in Panorama and then configure the setting there.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!