Cisco ACI L3Out (Layer 3 Out)
Cisco ACI L3Out (Layer 3 Out)
Cisco ACI L3Out (Layer 3 Out)
In a Cisco ACI fabric, the bridge domain is not meant for the connectivity of routing
devices, and this is why you cannot configure static or dynamic routes directly on a Cisco ACI
bridge domain. Spine Nodes
You need to use a specific construct for routing configurations: the L3Out.
Localisation : Tenant > Networking > External Routed Domains
Cisco ACI
A L3Out policy is used to configure interfaces, protocols, and protocol parameters Leaf Nodes
necessary to provide IP connectivity to external routing devices.
Part of the L3Out configuration involves also defining an external network (also L3out
known as an external EPG) for the purpose of access-list filtering.
The external network is used to define which subnets are potentially accessible APIC Cluster
through the Layer 3 routed connection.
Name L3out.VLANPo ol
Tenant: ACME Vlan: 10
VRF: Networklife
Right click and c hoose create L3out 5 Configure Interface Policy Groups
Name: WAN-L3out External En dpoint Localisation : Fabric > Acces s Policies > Inte rface > Leaf
VRF: Networklife Interface > Policy Groups > Acces s Port
External Routed Domain: WAN-L3out.RoutedDomain
Name: ExternalRouter.APPG
- If you need dynamic routing, tick the BGP, OSPF or Link: 1G-Auto
EIGRP. For this example, we will configure static routing. STP: STP-BPDU-Guard-on
Don’t forget to STP: STP-BPDU-Filter-on
attach your L3out PFC: PFC-auto
5 Configure Node Profile LACP: LACP-ac tive
Localisation : Tenant > Networking > External Routed to each BD. AAEP: ExternalRouter.AEP
Networks
- Inside the L3out object > Po lic y > Node Profiles, Configure Interface Profiles
Click « + »
Don’t forget the 6 Localisation : Fabric > Acces s Policies > Inte rface > Leaf
Name : ACINodeProfile contract. Interface > Profiles
- Nodes, clic k « + », select the ID of the leaf 102 and
Name: Leaf101-LeafProf
configure the Router ID IP address
- Acces s Port Selector: Eth1.01
- Set the static ro ute 0.0.0.0/0 with the external router IP
- Acces s Bloc k Port: 1/1
as a ne xt-hop.
- Interface Policy Group: StandaloneServe r.APPG
Configure Logical Interface Profiles
Name: Leaf102-LeafProf
6 Localisation : Te nant > Networking > External Routed
Networks > Logical Node Profiles > ACINodeProfile > - Acces s Port Selector: Eth1.01
Logical Interfac e Profiles - Acces s Bloc k Port: 1/1
- Interface Policy Group: ExternalRouter.APPG
Name: Leaf102-IntPro f
- Configure the local IP in the same subnet as the
external router, you can use Routed sub-interfaces,
Routed interfac es or SVI. Policy Universe
- Choose the Po rt 1/1 previously c reated and
encapulation vlan-10.
Name: WAN-ExtNet
Subnets: 0.0.0.0/0
WAN-L3out WAN-L3out.RoutedDomain
Standalone.AP Standalone.BD Networklife
L3 Ext Outside Layer 3 External
AP BD VRF
Networks Domain Profile
Configuration Steps
Shared L3out with multiple Tenants
3 validated designs are possible for « shared services »:
Option 1 - BD in Common Tenant Option 2 - BD in User tenant Option 3 - Inter-VRF Leaking with Shared L3out
- Shared L3 out for the fabric with static/dynamic
- Shared L3 out for the fabric with static/dynamic - Shared L3out for the fabric with static/dynamic routing
routing in Tenant Common.
routing in Tenant Common. in Tenant Common.
- All Endpoint groups (EPGs), Bridge Domains
- All Endpoint groups (EPGs) are configured in - All Endpoint groups (EPGs), Bridge Domains (BDs),
(BDs), and subnets are configured within the
respective user Tenant(s) subnets and VRFs are configured within the customer’s
customer’s respective user Tenant(s)
- Bridge Domains (BDs), subnets, and VRFs are all respective user Tenant(s)
- The VRF is configured in the Tenant common
configured in the Tenant common. - Only L3out is configured in the common tenant.
where the L3out is configured.
Router Router Router
BD + Subnet BD + Subnet
logical configuration is changing. On L3 configuration, enable unic ast routing and On L3 configuration, enable unic ast routing and
create the subnet 10.1.1.1/24 with the following create the subnet 10.2.2.1/24 with the following
options: options:
- Advertise Externally - to advertis e these gateway - Advertise Externally - to advertis e these gateway
subnets out to Shared L3Out to the internet subne ts out to Share d L3Out to the internet
- Shared between VRFs - To leak the subnets to the - Shared between VRFs - To le ak the subnets to the
common tenant. common te nant.
Router
NOTE – Do not assoc iate L3out listed on the BD; when NOTE – Do not assoc iate L3out listed on the BD; when
we use an Inter-vrf Shared L3out, we do not need to we use an Inte r-vrf Shared L3out, we do not need to
as sociate the user Tenant BDs with the L3out in as sociate the user Te nant BDs with the L3out in
Tenant Common. Te nant Common.
static
Configure the AP & EPG Configure the AP & EPG
Vlan-10 3 Localisation : Tenant > Application Profiles 3 Localisation : Tenant > Application Profiles