hi,GldenJoe: Many thinks to your helpful guide. My switch is C9300X-M,so it should support uplink SVI ,i.e 10.1.1.2,as its manangement IP. I will verify it. On this implement, actually, each site has two non-cisco FWs run as a FW HA, and two C9300X-M builded as a stack and as core switch of site( logical as a single failure point yet). OSPF run between FW and core switch,FW will originate default route into OSPF when its external link up and withdraw default route when external link down. so each site core switch will learn two default route but different cost. That is my design for site resilience to avoid INTERNET uplink down. B.R/Vincent
... View more