cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3821
Views
0
Helpful
8
Replies

In-band NTP config in Cisco ACI

Thushan Pramod
Level 1
Level 1

Hi All,

In my setup we have two spines (9336PQ) and two leafs (93128TX). In-band management gateway is defined in the external firewall and firewall will do the routing to access the NTP server which is in a different IP subnet. Here what I am going to do is, Simply configure a L2 OUT towards the firewall in mgmt tenant to extend in-band management vlan towards the firewall.

Then I will configure fabric policies through the wizard for APICs in order to configure in-band management.

After assigning in-band management IP addresses will I be able to reach the in-band management gateway since i have already configured L2 OUT. Then in the NTP configuration i will assign EPG as in-band default EPG. Will this work?

1 Accepted Solution

Accepted Solutions

RedNectar
VIP
VIP

Hi Thushan Pramod

Did you get this to work?  I haven't tried the approach you describe, but if I wanted to reach an external NTP server I'd probably take a L3 Out approach rather than a L2 Out approach.

You might find some more help configuring inband management using a Google search such as cisco ACI inband management tutorial.  For me, I found Cisco’s official documentation for configuring In-Band management on the Cisco APIC pretty disappointing.

I hope this helps


Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem

 

 

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

View solution in original post

8 Replies 8

RedNectar
VIP
VIP

Hi Thushan Pramod

Did you get this to work?  I haven't tried the approach you describe, but if I wanted to reach an external NTP server I'd probably take a L3 Out approach rather than a L2 Out approach.

You might find some more help configuring inband management using a Google search such as cisco ACI inband management tutorial.  For me, I found Cisco’s official documentation for configuring In-Band management on the Cisco APIC pretty disappointing.

I hope this helps


Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem

 

 

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Hi Chrish,

I tried to do it as cisco guide says but it does not work. Thanks for the reply. Do we need to allocate specific IP segment for in-band IP management for ACI fabric which will not be used in anywhere in the network for other devices to manage in-band.?

And by the way do you have a video of configuring in-band management access via a L3OUT for  which you have described in your blog, it will be great Please do reply and share the video if you can.

To answer your questions:

Do we need to allocate specific IP segment for in-band IP management for ACI fabric which will not be used in anywhere in the network for other devices to manage in-band.?

I'm not quite sure exactly what you are asking, so I'll give several answers

  • You will need to allocate an inband IP address to each APIC.
    1. If your management station is connected to the same EPG, these IP addresses don't need to be advertised or seen outside this subnet.  As per scenario #1 or #2
      • In this case the IP subnet need not be seen anywhere else
    2. If you want this IP address range to be advertised outside, then you'll need to configure a L3Out as per scenario #3
      • In this case the IP subnet will be seen in your external network
  • You will need to allocate an IP address to the inb Bridge Domain, and this will be the default gateway IP for the APIC's inband IP addresses.
    • As far as I know, you can't configure the APIC's inband IP address to use an external firewall or router as its default gateway.
  • You don't need to allocate inband IP addresses to your leaf or spine switches, but you can do so if you wish via the mgmt tenant
And by the way do you have a video of configuring in-band management access via a L3OUT for  which you have described in your blog, it will be great Please do reply and share the video if you can.

Unfortunately, I don't have any videos.  I have several that I'd like to do, perhaps I'll get time one day.

I hope this helps

RedNectar
aka Chris Welsh


RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Hello Chris,

 

I'm a bit stuck in the L3out situation. At the end, I am able to ping all the switches from via the L3out (which is located in the common:default in my case) but I cannot reach the APIC's. 

 

I can reach the APIC's if I login to the Leaf switches and even via a VM inside the ACI fabric. So all seems fine, except L3outside to the APIC's. 

 

I'm using SVI on the L3out, and the subnet is redistributed into EIGRP. I verified that it is visible on the outside networks.

 

Do you have any clue what I am missing? 

 

regards

Michel

Hi Michel,

 

I'm not soo sure what your problem is. The only thing that springs to mind quickly is to check that you have set the APIC's managment preference to inband via:

Fabric > Fabric Policies > Global Policies > Connectivity Preferences

 

However, be careful doing this - it is possible to loose all connectivity with the APIC once this has been set to inband (if your L3 out is not set up correctly)

 

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Hello Chris,

 

Thanks for your prompt reply. I have changed that option, and I can reach for example vCenter via inband to an EPG inside the Fabric. It's a strange issue, because I can reach all switches on the inband mgmt IP address from outside the Fabric, except for the APIC's

 

I'm probably going to open a TAC case on Monday, let see what they have to say. I'll let you know what the outcome is

 

Thanks again

Michel

Hello Chris,

 

I'm a bit stuck in the L3out situation. At the end, I am able to ping all the switches from via the L3out (which is located in the common:default in my case) but I cannot reach the APIC's. 

 

I can reach the APIC's if I login to the Leaf switches and even via a VM inside the ACI fabric. So all seems fine, except L3outside to the APIC's. 

 

I'm using SVI on the L3out, and the subnet is redistributed into EIGRP. I verified that it is visible on the outside networks.

 

Do you have any clue what I am missing? 

 

regards

Michel

Were you able to resolve the issue of not being able to ping the APIC in-band IPs from outside the fabric while all the other switches are reachable?

Save 25% on Day-2 Operations Add-On License