QuestionQ25

External Network Connectivity

Question Image

Refer to the exhibit. A customer is deploying a WAN with the following requirements:

  • Routers 1 and 2 must receive only routes 192.168.11.0/24 and 192.168.21.0/24 from the Cisco ACI fabric.
  • Reachability to WAN users must be allowed only for the servers located in vrf_prod.

Which settings must be configured to satisfy these objectives?

Explanation

Cisco ACI advertises only subnets marked Advertised Externally to routers through an L3Out; Private to VRF subnets remain internal to the fabric. Therefore, 192.168.11.0/24 and 192.168.21.0/24 are advertised, while 192.168.31.0/24 is kept private. Configuring 0.0.0.0/0 as External Subnets for the External EPG classifies WAN addresses as external endpoints, enabling contract-based access only from the permitted internal EPGs in vrf_prod. Shared Route Control Subnet is intended for route leaking between VRFs and is unnecessary for this design.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!