08-14-2023 08:41 PM
Hello,
I am trying to configure the Access Policies, and I am trying to do it by the Interface Configuration wizard. However, when I create the AAEP, I can`t create new Physical Domains. There is only this "phys" domain. Why does it say for me to select a Domain if I can`t create one without going outside the Wizard? If I can`t create new Domains, I can`t associate VLANs Pools. Is this wizard incomplete?
As you can see, there is no way to create a Domain. And there is only this "phys" domain. Is it supposed to all the interface be put in this "phys" Domain with no VLAN Pool?
I am failing to see the purpose of the Interface Configuration wizard if I can`t assign VLAN Pools.
Solved! Go to Solution.
08-15-2023 06:42 AM
The Create Domain workflow will be added into the 6.1 release. The gap is known by our UI team.
For now, just pre-create the domain/VLAN Pools.
Robert
08-14-2023 11:08 PM
Hi @BertiniB ,
I see your point. I strongly suggest you hit the Feedback icon and report this deficiency
BUT...
On the other hand I'd suggest that it is good practice to have your VLAN Pools, Domains and AAEP (often one AAEP is enough) all created BEFORE you start assigning interfaces - the reason being that creating VLAN Pools, Domains and AAEP is something you do VERY occasionally, possibly only once in the lifetime of an ACI deployment, whereas assigning interfaces and creating Interface Policy Groups is part of day-to-day ongoing maintenance.
It MIGHT be Cisco's intention to make it difficult to create the entire Access Policy Chain using the Interface Configuration Wizard just so end users don't go creating lots of AAEPs and Domains that are going to cause nightmares (most likely overlapping VLAN pools) later in life - although if that was the intention, it would have been a good idea to force the creation of an AAEP before reaching the dead-end that you found.
You may gain some insight into the way the ACI "Access Policy Chain" works by googling that term, although most of the articles you find will relate to ACI before the Interface Configuration Wizard was available.
As a side-note, if you also create your Interface Policy Group (Fabric > Access Policies >> Interfaces > Leaf Interfaces > Policy Groups > [Leaf Access Port | PC Interface | VPC Interface] ) before using the Wizard, you can actually complete the rest of the Access Policy Chain from that point. (i.e. create an AAEP, and while creating the AAEP, create a Physical Domain, and while creating a Physical Domain, create a VLAN Pool)
08-15-2023 06:10 AM
When you make a request for input on these forums, please include the basic info needed like SW version and/or model info. We can't always assist unless we know the version you're working with.
Robert
08-15-2023 06:42 AM
The Create Domain workflow will be added into the 6.1 release. The gap is known by our UI team.
For now, just pre-create the domain/VLAN Pools.
Robert
08-15-2023 07:07 AM
Hello,
I am still new here in the forum. A little bit of context:
APIC Version: 5.2(7g)
Switches image: n9000-14.2(7w) (I am aware of the mismatch of versions, this is not a production environment, only a lab with old equipment, however the problem of not being able to create a Domain in the Interface Configuration is in the APIC GUI not in the processing of applying it).
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide