Manualsbrain.com
it
English
Deutsch
Español
Français
Português
Русский
조선말, 한국어
日本語
中文
Manuali
Marche
Cisco
Cisco Nexus 5010 Switch
Libro bianco
Cisco Cisco Nexus 5010 Switch Libro bianco
Scarica
Like
Schermo intero
Standard
Pagina
di
75
Vai
© 2016 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 2 of 75
Contents
Introduction .............................................................................................................................................................. 3
Target Audience .................................................................................................................................................... 4
Prerequisites ......................................................................................................................................................... 4
Overview: Layer 2 Domains, Protected Subnets, and East-West Firewalls ........................................................ 4
Overview: VRF Instances and Tenant-Edge Firewalls .......................................................................................... 8
East-West Firewall Deployment Scenarios ............................................................................................................ 9
Basic Leaf Configuration for Protected Networks .................................................................................................. 9
Configuration 1a: IPVLAN-Based Leaf Switch Connecting to Hosts ................................................................ 9
Configuration 1b: IPBD-Based Leaf Switch Connecting to Hosts ................................................................... 10
Basic Leaf Configuration for Attaching the East-West Firewall ........................................................................... 11
Configuration 2a: IPVLAN-Based Leaf Switch Connecting to Firewall ........................................................... 11
Configuration 2b: IPBD-Based Leaf Switch Connecting to Firewall ............................................................... 13
Routing Peering Configuration between the Standalone East-West Firewall and the Fabric .............................. 15
Static Routing Peering between the Fabric and the Standalone Firewall ....................................................... 15
Configuration 3a: IPVLAN-Based Leaf Switch Connecting to Firewall ........................................................... 15
Configuration 3b: IPBD-Based Leaf Switch Connecting to Firewall ............................................................... 16
Dynamic Routing Peering between the Fabric and the Standalone Firewall .................................................. 17
Configuration 4a: IPVLAN-Based Leaf Switch ............................................................................................... 17
Configuration 4b: IPBD-Based Leaf Switch .................................................................................................... 17
Active-Standby Failover East-West Firewalls in Routed Mode ........................................................................... 18
vPC Dual-Homed Active-Standby Firewall Connectivity in Routed Mode ...................................................... 18
Single-Attached Active-Standby Firewall Connectivity in Routed Mode ......................................................... 19
Configuration 5a: IPVLAN-Based Leaf Switch ............................................................................................... 19
Configuration 5b: IPBD-Based Leaf Switch .................................................................................................... 20
Clustered East-West Firewalls in Routed Mode .................................................................................................. 20
Configuration 6a: IPVLAN-Based Leaf Switch ............................................................................................... 21
Configuration 6b: IPBD-Based Leaf Switch .................................................................................................... 23
Active-Standby Failover East-West Firewalls in Transparent Mode with vPC Connectivity ................................ 25
Configuration 7a: IPVLAN-Based Leaf Switch ............................................................................................... 26
Configuration 7b: IPBD-Based Leaf Switch .................................................................................................... 28
Active-Standby Failover East-West Firewalls in Transparent Mode .................................................................... 30
Clustered East-West Firewalls in Transparent Mode .......................................................................................... 31
Tenant-Edge Firewall Deployment Scenarios ..................................................................................................... 31
Active-Standby Failover: Single-Attached Tenant-Edge Firewalls in Routed Mode with Static Routing ............. 34
Configuration 8a: IPVLAN-Based Leaf Switch ............................................................................................... 35
Configuration 8b: IPBD-Based Leaf Switch .................................................................................................... 38
Active-Standby Failover: Single-Attached Tenant-Edge Firewalls in Routed Mode with Dynamic Routing ........ 41
Configuration 9a: IPVLAN-Based Leaf Switch ............................................................................................... 42
Configuration 9b: IPBD-Based Leaf Switch .................................................................................................... 45
Clustered Mode: vPC Dual-Attached Tenant-Edge Firewalls in Routed Mode with Static Routing ..................... 49
Clustered Mode: Single-Attached Tenant-Edge Firewalls in Routed Mode with Dynamic Routing ..................... 49
Configuration 10a: IPVLAN-Based Leaf Switch ............................................................................................. 50
Configuration 10b: IPBD-Based Leaf Switch .................................................................................................. 53
Complex Deployment Scenarios .......................................................................................................................... 56
Active-Standby Failover: Single-Attached Tenant-Edge Firewalls in Routed Mode with Dynamic Routing and
East-West Firewall Elements .............................................................................................................................. 57
Configuration 11a: IPVLAN-Based Leaf Switch ............................................................................................. 58
Configuration 11b: IPBD-Based Leaf Switch .................................................................................................. 62
Clustered Mode: vPC Dual-Attached Tenant-Edge Firewalls in Routed Mode with Static Routing and East-West
Firewall Elements ................................................................................................................................................ 66
Configuration 12a: IPVLAN-Based Leaf Switch ............................................................................................. 67
Configuration 12b: IPBD-Based Leaf Switch .................................................................................................. 71
For More Information ............................................................................................................................................. 74
Prec
Successivo
1
2
3
4
…
75