Thursday, 4 January 2018

ACI: Applying a Service Graph Template to Endpoint Groups Using the GUI

(This is from ACI Built in Help)



You must have created the following things:
  • Application endpoint groups
  • A service graph template
The following procedure explains how to apply a service graph template to endpoint groups:
  1. On the menu bar, choose Tenants > All Tenants.
  2. In the Work pane, double click the tenant's name.
  3. In the Navigation pane, choose Tenant tenant_name > L4-L7 Services > L4-L7 Service Graph Templates > template_name.
  4. In the Work pane, choose Actions > Apply L4-L7 Service Graph Template.
    You will be associating a Layer 4 to Layer 7 service graph template to your consumer and provider endpoint groups.
  5. In the Apply L4-L7 Service Graph Template To EPGs dialog, in the EPG Information section, complete the following fields:
    Name
    Description
    Consumer EPG/External Network drop-down list
    Choose a consumer endpoint group.
    Provider EPG/External Network drop-down list
    Choose a provider endpoint group.
  6. In the Contract Information section, complete the following fields:
    Name
    Description
    Contract radio buttons
    Choose to create a contract or choose an existing contract.
    Contract Name field
    (Only for creating a contract) Enter the name of the contract.
    No Filter (Allow All Traffic) check box
    (Only for creating a contract) Put a check in the box to allow all traffic, or remove the check from the box to filter traffic.
    Filter Entries
    (Only for filtering traffic) Click + and enter the filter information, then click Update.
    Existing Contract With Subjects drop-down list
    (Only for choosing an existing contract) Choose an existing contract.
  7. Click Next.
  8. In the Graph Template drop-down list, choose a service graph template.
  9. (Only for a Layer 4 to Layer 7 device) In the L4L7_device_name Information section for each Layer 4 to Layer 7 device, complete the following fields:
    Name
    Description
    Router Config drop-down list
    (Only if you chose Route Peering for the consumer type or provider type) The router configuration to use for policy-based redirect.
    Consumer Connector
    Name
    Description
    Type radio buttons
    The connector type. The type can be:
    • General
    • Route Peering—Enables route peering on the device.
    BD drop-down list
    (Only if you chose General for the type) Choose or create a bridge domain for the consumer connector. The bridge domain is used for the data path traffic.
    L3 Ext Network drop-down list
    (Only if you chose Route Peering for the type) Choose a Layer 3 external (outside) network for the consumer connector.
    Cluster Interface drop-down list
    Choose or create an interface for the consumer connector.
    Provider Connector
    Name
    Description
    Type radio buttons
    The connector type. The type can be:
    • General
    • Route Peering—Enables route peering on the device.
    BD drop-down list
    (Only if you chose General for the type) Choose or create a bridge domain for the provider connector. The bridge domain is used for the data path traffic.
    L3 Ext Network drop-down list
    (Only if you chose Route Peering for the type) Choose a Layer 3 external (outside) network for the provider connector.
    Cluster Interface drop-down list
    Choose or create an interface for the provider connector.
    The Application Policy Infrastructure Controller (APIC) uses the chosen bridge domains for data path traffic between function nodes as required by the chosen service graph template. Refer to the online help for the service graph templates to learn more about how this bridge domain is used.
  10. (Only for a copy device) In the copy_device_name Information section for each copy device, in the Cluster Interface drop-down list, choose the cluster interface that you defined for that copy device.
  11. (Only for a managed Layer 4 to Layer 7 device) Click Next.
  12. (Only for a managed Layer 4 to Layer 7 device) In the Parameters screen, in the Required Parameters tab, enter the names and values, as appropriate, for all of the required parameters.
  13. Click Finish.
    You now have an active service graph template. The APIC populates the Layer 4 to Layer 7 parameters based on the chosen function profile and colors the mandatory parameters in green if they are configured correctly.

ACI: Creating an Application Profile Using the GUI

(This is from ACI Built in Help)


  1. On the menu bar, choose TENANTS. In the Navigation pane, expand the tenant, right-click Application Profiles, and click Create Application Profile.
  2. In the Create Application Profile dialog box, in the Name field, add the application profile name (OnlineStore).

ACI: Configuring a Layer 3 Outside for Tenant Networks Using the GUI

(This is from ACI Built in Help)



  • The tenant, VRF, and bridge domain are created.
  • The external routed domain is created and associated to the interface.
The external routed network configured in the example can also be extended to support IPv4. Both IPv4 and IPv6 routes can be advertised to and learned from the external routed network.
  1. On the menu bar, click TENANTS.
  2. In the Navigation pane, expand the Tenant_name > Networking > External Routed Networks and perform the following actions:
    1. Right-click External Routed Networks and click Create Routed Outside.
    2. In the Create Routed Outside dialog box, in the Name field, enter a name for the routed outside.
    3. In the area with the routing protocol check boxes, check the desired protocol.
      The options available are BGP, OSPF, EIGRP. Later in the steps, this will make available, the route summarization policy in the Create External Network dialog box.
    4. In the VRF field, from the drop-down list, choose the appropriate VRF.
    5. From the External Routed Domain drop-down list, choose the appropriate external routed domain.
    6. Check the check box for the desired protocol.
      Depending on the protocol you choose, the properties that must be set.
    7. Expand Nodes and Interfaces Protocol Profiles.
    8. In the Create Node Profile dialog box, in the Name field, enter a name.
    9. Expand Nodes.
    10. In the Select Node dialog box, from the Node ID drop-down menu, choose the appropriate node ID.
    11. In the Router ID field, enter the router ID.
    12. If the Use Router ID as Loopback Address check box is checked, the Router ID is used as the Loopback Address, otherwise, expand Loopback Addresses, enter an IP address, and click Update.
      Note:
      In the Loopback Addresses fields, create an IPv4 and/or IPv6 loopback as desired.
    13. Click OK.
  3. Expand Interface Profiles, and perform the following actions:
    1. In the Create Interface Profile dialog box, in the Name field, enter a name for the profile.
    2. Expand Routed Interfaces.
    3. In the Select Routed Interface dialog box, from the Path drop-down list, choose the interface path.
    4. In the IP Address field, enter the IP address.
      Note:
      To configure IPv6, you must enter the link-local address in the Link-local Address field in the dialog box.
    5. Click OK.
      The routed interface details are displayed in the Create Interface Profile dialog box.
    6. Click OK.
  4. In the Create Node Profile dialog box, click OK.
  5. In the Create Routed Outside dialog box, click Next.
  6. In the External EPG Networks area, expand External EPG Networks.
  7. In the Create External Network dialog box, in the Name field, enter a name for the external network.
  8. Expand Subnet.
  9. In the Create External Network dialog box, perform the following actions:
    1. Expand Subnet to add another subnet.
    2. In the Create Subnet dialog box, in the IP Address field, enter an IP address.
    3. In the Scope field, check the appropriate check boxes. Click OK.
      Note:
      • The import control policy is not enabled by default but can be enabled by the user. The import control policy is supported for BGP and OSPF, but not for EIGRP. If the user enables the import control policy for an unsupported protocol, it will be automatically ignored.
      • The export control policy is supported for BGP, EIGRP, and OSPF.
      • Route aggregation is also supported and the user can optionally choose route aggregation in the desired export or import direction. This feature is available for 0.0.0.0/0 and for the security option. If the import control policy is not enabled, an example of the check boxes to check are Export Subnet, Shared Security Import Subnet, and Aggregate Export. The user must choose route map and security options.
      • If an explicit route control policy is configured for a Layer 3 outside, then only specific Layer 3 outside policies are supported. Explicit route control policies are not supported for aggregate routes.
    4. Optional: In the Route Summarization Policy field, from the drop-down list, choose an existing route summarization policy or create a new one as desired and you must check the check box for Export Route Control Subnet.
    5. In the Create External Network dialog box, click OK.
  10. Optional: In the Create Subnet dialog box, perform the following actions:
    1. In the IP Address field, enter the IP address and subnet.
    2. In the Scope field, check the appropriate check box. Click OK.
  11. In the Create Routed Outside dialog box, click Finish.
  12. In the Navigation pane, under Tenant_name > Networking > Bridge Domains and choose the Bridge_Domain_name.
  13. In the Navigation pane, choose the BD you created.
    Note:
    If the L3 Out is static, you are not required to choose any settings.
    1. In the Work pane, choose the L3 Configurations tab.
    2. In the Associated L3 Outs field, associate the desired L3 Out and click Update.
    3. In the L3 Out for Route Profile field, choose the desired L3 Out and click Submit.
  14. Note:
    To set attributes for BGP, OSPF, or EIGRP communication for all routes we receive, create default-import route control profile, create the appropriate set actions and no match actions.
    In the Navigation pane, click Route Maps/Profiles, right-click Create Route Map, and in the Create Route Map dialog box, perform the following actions:
    1. In the Name field, enter a name.
    2. In the Type field, you must click Match Routing Policy Only. Click Submit.
  15. Optional: To enable additional communities using the BGP protocol, right-click Set Rules for RouteMaps, click Create Set Rules for a Route Map.
  16. Optional: In the Create Set Rules for a Route Map dialog box,click the Add Communities field and follow the steps to assign multiple BGP communities per route prefix if desired.

ACI: Creating a Layer 4 to Layer 7 Service Graph Template Using the GUI

(This is from ACI Built in Help)



You must have configured a tenant.
A service graph template is a sequence of Layer 4 to Layer 7 functions, Layer 4 to Layer 7 devices, or copy devices and their associated configuration, which can be provided by using function profiles. The service graph template must be associated with a contract to be "rendered"—or configured—on the Layer 4 to Layer 7 device or copy device, and on the fabric.
  1. On the menu bar, choose Tenants > All Tenants.
  2. In the Work pane, double click the tenant's name.
  3. In the Navigation pane, choose Tenant tenant_name > L4-L7 Services > L4-L7 Service Graph Templates.
  4. In the Work pane, choose Actions > Create a L4-L7 Service Graph Template.
  5. In the Create a L4-L7 Service Graph Template dialog box, in the Device Clusters section, if necessary create one or more Layer 4 to Layer 7 devices or copy devices. To create a device, click the +, choose Create L4-L7 Devices or Create Copy Devices, and follow the dialog.
  6. Complete the following fields:
    Name
    Description
    Graph Name field
    Enter the name of the service graph template.
    Graph Type radio buttons
    Choose to create a new service graph template or clone an existing service graph template.
    Existing Graphs drop-down list
    (Only for cloning an existing service graph template) Choose an existing service graph template to clone. The remaining sections of this dialog become populated with the information from the cloned service graph template.
  7. Optional: (Only for cloning an existing service graph template) If you want to remove any of the nodes from the cloned service graph template, right click a node that you want to remove and choose Remove Node.
  8. To create a service node, drag a Layer 4 to Layer 7 device from the Device Clusters section and drop it between the consumer endpoint group and provider endpoint group. To create a copy node, drag and drop a copy device. This step is optional if you cloned an existing service graph template and the service graph template has all of the nodes that you want to use.
    You can drag and drop multiple devices to create multiple nodes. The maximum number of service nodes is 3, although you can drag and drop greater numbers of other devices.
    The location where you drop a copy device becomes the point in the data flow from where the copy device copies the traffic.
  9. If you created one or more service nodes, in the device_name Information section for each Layer 4 to Layer 7 device, complete the fields. The fields vary depending on the device type.
  10. Click Submit.
  11. Optional: In the Navigation pane, click the service graph template.
    The work pane displays a graphic topology of the service graph template.

ACI: Creating a Copy Device Using the GUI

(This is from ACI Built in Help)



You must have configured a tenant.
A copy device is used as part of the copy services feature to create a copy node. A copy node specifies at which point of the data flow between endpoint groups to copy traffic.
This procedure only creates a copy device and does not configure anything else that is required to use the copy services feature. For information about configuring copy services, see Configuring Copy Services Using the GUI.
  1. On the menu bar, choose Tenants > All Tenants.
  2. In the Work pane, double click the tenant's name.
  3. In the Navigation pane, choose tenant_name > L4-L7 Services > L4-L7 Devices.
  4. In the Work pane, choose Actions > Create Copy Devices.
  5. In the Create Copy Devices dialog box, in the General section, complete the following fields:
    Name
    Description
    Name field
    Enter a name for the copy device.
    Device Type buttons
    The device type. A copy device can only be a physical device.
    Physical Domain drop-down list
    Choose the physical domain for the device.
  6. In the Device 1 section, click + to add a device interface, complete the following fields, and then click Update:
    Name
    Description
    Name field
    Enter a name for the device interface.
    Path drop-down list
    Choose a port, port channel, or virtual port channel for the device interface to use. The copy device connects to that port, port channel, or virtual port channel and copies traffic from it.
  7. In the Cluster section, click + to add a cluster interface, complete the following fields, and then click Update:
    Name
    Description
    Name field
    Enter a name for the cluster interface.
    Concrete Interfaces drop-down list
    Choose one or more concrete interfaces for the cluster interface to use.
    Encap field
    Enter a VLAN to use for encapsulation. The VLAN name format is as follows:
    vlan-#
    # is the VLAN's ID. For example:
    vlan-12
  8. Click Submit.

ACI: Creating a Layer 4 to Layer 7 Device Using the GUI

(This is from ACI Built in Help)



  • You must have configured a tenant.
When you create a Layer 4 to Layer 7 device, you can connect to either a physical device or a virtual machine. The fields are slightly different depending on the type to which you are connecting. When you connect to a physical device, you specify the physical interface. When you connect to a virtual machine, you specify the VMM domain, the virtual machine, and the virtual interfaces. Additionally, you can select an unknown model, which allows you to configure the connections manually.
Note:
When you configure a Layer 4 to Layer 7 device that is a load balancer, the context aware parameter is not used. The context aware parameter has a default value of single context, which can be ignored.
  1. On the menu bar, choose Tenants > All Tenants.
  2. In the Work pane, double click the tenant's name.
  3. In the Navigation pane, choose tenant_name > L4-L7 Services > L4-L7 Devices.
  4. In the Work pane, choose Actions > Create L4-L7 Devices.
  5. In the Create L4-L7 Devices dialog box, in the General section, complete the following fields:
    Name
    Description
    Managed check box
    Put a check in the box to create a managed device, or remove the check from the box to create an unmanaged device.
    Name field
    Enter a name for the device.
    Service Type drop-down list
    Choose the service type.
    Device Type buttons
    Choose the device type.
    Physical Domain orVMM Domain drop-down list
    Choose the physical domain or VMM domain.
    View radio buttons
    Choose the view for the device. The view can be:
    • Single Node—Only one node
    • HA Node—High availability nodes (two nodes)
    • Cluster—3 or more nodes
    Device Package drop-down list
    (Only for managed devices) Choose the vendor-provided device package that you will use.
    Model drop-down list
    (Only for managed devices) Choose the model of the device.
  6. (Only for managed devices) In the Connectivity section, complete the following fields:
    Name
    Description
    APIC to Device Management Connectivity radio buttons
    Choose the type of connectivity. Choose Out-of-Bandwhen you are connecting to a device that is outside of the fabric or In-Band when you are connecting to a device through the fabric.
  7. (Only for managed devices) In the Credentials section, complete the following fields:
    Name
    Description
    User Name field
    Enter your user name.
    Password field
    Enter your password.
    Confirm Password field
    Enter your password again.
  8. In the Device 1 section, complete the following fields:
    Name
    Description
    Management IP Address field
    (Only for managed devices) Enter the management IP address of the device to which you are connecting.
    Management Port field and drop-down list
    (Only for managed devices) Enter the management port or choose a value from the drop-down list.
    VM drop-down list
    (Only for the virtual device type) Choose a virtual machine.
    Chassis drop-down list
    (Only for managed devices) Choose a chassis.
  9. In the Device Interfaces table, click the + button to add an interface and complete the following fields:
    Name
    Description
    Name drop-down list
    Choose the interface name.
    VNIC drop-down list
    (Only for the virtual device type) Choose a vNIC.
    Path drop-down list
    Choose a port, port channel, or virtual port channel to which the interface will connect.
  10. Click Update.
  11. (Only for an HA cluster) Complete the fields for each device.
  12. Complete the fields for the Cluster section.
    For an HA cluster, make sure that the cluster interfaces are mapped to the corresponding interfaces on both concrete devices in the cluster.
  13. Click Next.
    The Device Configuration page displays a list of possible features and parameters for the package you are using. You see a tab with the Basic parameters displayed and another tab All Parameters that displays all the available parameters with your device package. The basic parameters are included under All Parameters.
  14. In the Features section, choose the set of features that you want to use.
    The set of parameters changes depending on the specific package you are using and the specific feature you select.
  15. For the parameters of the chosen features, supply the values as follows:
    1. Double-click in the field you want to modify.
    2. Enter the required information in the fields that appear.
    3. Click Update.
  16. Click Finish.

Demo: Interface Profiles

Create Leaf Interface Profile