Hello everyone and thank you for your answers, I would like to implement segmentation in the data center, we will create VRFs in a Cisco Nexus Core switch and each VRF will have its own OSPF process to peer with a Palo Alto Firewall, all VRF traffic needs to go through the Palos for policy and routing, the question is: -Should we create multiple virtual routers in the Palos so each can peer with each of the “cisco VRF OSPF” processes? Or a single virtual router in the Palo is ok to peer with all of the VRF OSPF peers? networks need to reach each other through Palos and also all networks need to reach the internet from an upstream router.
... View more