Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Double Sided vPC with Cisco ASAs topology flow

Hey all, I am having an issue conceptual understanding how flow would work with the following. For Access Layer devices trying to leave the internal network.


On the Core Nx7K's I have an HSRP of, also there is a static default gateway route set to go to (the ASA)

For the Nx5K they are aggregate switches. They don't have layer 3 info, but separte different traffic zones based on local VLANs on them.

The ASA's are in Active/Standby with heartbeat between them.

My question is a host with IP of ,as depicted, trying to go out to The host will see it has to use the default gateway and the frame will be sent to either Nx7K. Each Nx7K in it's routing table has a static default gateway to go to the next hop of (which is the active VIP of the ASA). The thing I am having trouble understanding is how will the Nx7K's (CORE) now how to get to teh ASA? Which Nx5K will the frame be sent to? does it matter? Do I need a layer 3 presecens on the 5k's ?


this all stems from, currently we have a single  Nx5K acting as an aggreagte switch. I am trying to add an additional  Nx5K with vPC and Port-Channeling on the ASA side to add failover in  case a Nx5K fails.

Thanks everyone for taking the time to look.


Hall of Fame Super Silver

Double Sided vPC with Cisco ASAs topology flow

The 7k knows how to get to the ASA based on it's ARP processes determining and then caching (in the ARP cache table) the MAC address for the gateway.

As long as the VLAN where address extends through the portchannel (and there's an associated VPC on the 5k for those portchannels) and through the VPC 1 from your 5ks to 7ks it should work fine.

The 5ks don't need to be involved in L3 forwarding decisions for flows out to the ASAs - only L2 as they will determine the correct physical port based on the destination MAC address (and load balance across the portchannel to the active ASA based on the load balancing algorithm - default is source-dest MAC so in the case where most everything comes from the 7k MAC and to the ASA MAC, you may want to change that to source-dest ip to optimize. Reference.)