cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7262
Views
7
Helpful
38
Replies

cisco ACI - Error 400

titusroz03
Level 4
Level 4

Dear ACI Experts,

We are running a problem with ACI, none of our BDs are able to get submitted and we are getting the below 400 error for all BDs in our prod tenant. we have mapped all our BDs to EPGs in one-to-one basis.

 

titusroz03_1-1758187569190.png

subnets are configured in EPG and BD with below scope options.

EPG scope option settings

titusroz03_2-1758187806518.png

BD Scope option settings

titusroz03_3-1758187854521.png

when we raised TAC they are saying to download and do offline modification on scope settings, but this issue is not only with scope settings but throughout the BD, any changes we do in BD we couldn't submit.

We used a TEST BD and moved it to common vrf and tested it works fine, could modify any options. But the same we tried to revert back to prod-vrf but couldn't do it

Can anyone help me with this

 

 

 

38 Replies 38

@RedNectar Thank you for your suggestion. But I was able to concatenate and run the ACI simulator in same 5.0(8) versiion successfully. I got my virtual leaves and spines up and active, but now I am skeptical to import/deploy the production fabric Tenant configs in this simulator. Because this ACI sim is running in a VM which is on a ESXI connected to our Staging Tenant in fabric, I know that ACI simulator doesn't have data plane and will not act beyond the MGMT and the box, but still I am doubtful on this. Could you advise if running the ACI simulator doesn't make any harm to fabric ..?

Hi @titusroz03 ,

The ACI Simulator cannot harm the fabric - be assured you can import your tenant config to the Simulator without changing anything onthe production fabric.

Sorry I took so long to answer.

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

@RedNectar No problem on the late reply, anyways your answers are always worthy to wait. To understand your reply, I shouldn't do any changes on the production fabric, but out of curiosity can I ask what will happen If I do and import...?

We have two tenants - Prod and Pre-prod and simulator is in running in a BD in Pre-prod Tenant.

And another question is I want to test the inter-tenant route leak by creating BDs and EPGs in network centric model..? Can I experiment it in Simulator before testing this import config test...?

 

Hi @titusroz03 ,


No problem on the late reply, anyways your answers are always worthy to wait.

Thanks.

To understand your reply, I shouldn't do any changes on the production fabric,

Correct

but out of curiosity can I ask what will happen If I do and import...?

Well, if you make changes on the production tenant and import them to the Simulator, then the changes you made will be reflected in the Simulator.

If you make changes in theSimulator and import them to the production tenant, then the changes you made will be reflected in the production tenant.

We have two tenants - Prod and Pre-prod and simulator is in running in a BD in Pre-prod Tenant.

Don't worry about where the simulator is running, That is irelevant

And another question is I want to test the inter-tenant route leak by creating BDs and EPGs in network centric model..? Can I experiment it in Simulator before testing this import config test...?

You can do the configuration in the simulator, but you won't see any route leaking, so you won't really know if it is correct. To see the route leaking you need physical switches.

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

@RedNectar Thanks for your reply, I am going to make these following steps, i.e exporting the Json file for Prod tenant, remediating the scope and importing it to simulator and observe. My question from the beginning is in this scenario will it impact the original fabric since simulator is running in a VM in fabric but in different tenant.

 

Hi @titusroz03 ,

Relax. The simulator can't touch your production tenant!

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

titusroz03
Level 4
Level 4

 @RedNectar I need your help in this topic again, we were exploring an option for remediating the config through a POSTMAN script from API..? My understanding is any config change is going to be through APIC only or willl an attempt through API bypasses the APIC

Hi @titusroz03 ,

When you rum POSTMAN, the first thing you (or your script) is going to have to do is log into the APIC (via the API). All subsequent POSTs will then be sent to the APIC, never directly to any leaf or spine switch. So in short, you can't bypass the APIC using this method.

Although I've never done it, if you crafted your scripts to log into a particular leaf rather than the APIC, then you could potentially make changes to a leaf, but you'd have to know what you are doing and wouldn't happen by accident, and most likely the payload of the POSTs would be different to what would be sent to the APIC

So, if you want to be absolutely sure, check which device your POSTMAN script logs into before running it. If it is an APIC, you are good to go. 

Relax 

RedNectar_0-1770926388408.png

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

@RedNectar Yes, it is APIC. We tested to run a HTML based web script in APIC Simulator and we are able to make the Scope definition changes as expected.But not sure in the production environment if this will work as expected, because in Simulator we don't have the misconfiguration locked in subnets but in production we have..

@RedNectar I just now read again your post, I can understand that targetting the particular Leaf were the EPG is deployed will work instead of APIC..? But unfortunately I can't test this APIC Simulator, and I want my script to be crafted accordingly. Could you help me with a sample script for this..?

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License