Description

This article provides more information about shared external connectivity point and a sample scenario in which it would be useful.

Symptoms

I am a Juniper Apstra user and I am trying to create a single Juniper Apstra Blueprint External Connectivity Point (ECP) with two MLAG/vPCs, one for an active firewall and another for the standby firewall. What would be the topology and configuration that I should use?

Solution

Topology

 

To create a shared external connectivity point for the example scenario:

  • A shared upstream gateway (for example Active/Passive Firewalls) must be connected to a leaf or an MLAG/vPCs leaf-pair

  • The default or any new security zone must be connected to two external firewalls by using a single IP connectivity point (the shared virtual IP address)

    • This will enable each security zone to use a different IP connectivity point (with a different SVI interface/VLAN ID and different VIP).

  • Then on each border leaf, one EBGP session is established between its SVI and the shared virtual IP address of the firewall pair

When the above topology setup is configured, Juniper Apstra automatically creates the required configuration for shared external connectivity.

Additionally, custom export/import policies per security zone can be defined:

  • Enable/disable export of l2edge_subnets.

  • Import specific prefix-list (new).

  • Export aggregated subnets (new).