07-26-2017 01:27 AM - edited 03-01-2019 05:18 AM
Hi All,
In my setup we have two spines (9336PQ) and two leafs (93128TX). In-band management gateway is defined in the external firewall and firewall will do the routing to access the NTP server which is in a different IP subnet. Here what I am going to do is, Simply configure a L2 OUT towards the firewall in mgmt tenant to extend in-band management vlan towards the firewall.
Then I will configure fabric policies through the wizard for APICs in order to configure in-band management.
After assigning in-band management IP addresses will I be able to reach the in-band management gateway since i have already configured L2 OUT. Then in the NTP configuration i will assign EPG as in-band default EPG. Will this work?
Solved! Go to Solution.
07-28-2017 02:01 PM - edited 02-09-2018 11:36 AM
Did you get this to work? I haven't tried the approach you describe, but if I wanted to reach an external NTP server I'd probably take a L3 Out approach rather than a L2 Out approach.
You might find some more help configuring inband management using a Google search such as cisco ACI inband management tutorial. For me, I found Cisco’s official documentation for configuring In-Band management on the Cisco APIC pretty disappointing.
I hope this helps
Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem
07-28-2017 02:01 PM - edited 02-09-2018 11:36 AM
Did you get this to work? I haven't tried the approach you describe, but if I wanted to reach an external NTP server I'd probably take a L3 Out approach rather than a L2 Out approach.
You might find some more help configuring inband management using a Google search such as cisco ACI inband management tutorial. For me, I found Cisco’s official documentation for configuring In-Band management on the Cisco APIC pretty disappointing.
I hope this helps
Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem
07-29-2017 06:13 AM
Hi Chrish,
I tried to do it as cisco guide says but it does not work. Thanks for the reply. Do we need to allocate specific IP segment for in-band IP management for ACI fabric which will not be used in anywhere in the network for other devices to manage in-band.?
And by the way do you have a video of configuring in-band management access via a L3OUT for which you have described in your blog, it will be great Please do reply and share the video if you can.
07-29-2017 01:03 PM
To answer your questions:
Do we need to allocate specific IP segment for in-band IP management for ACI fabric which will not be used in anywhere in the network for other devices to manage in-band.?
I'm not quite sure exactly what you are asking, so I'll give several answers
And by the way do you have a video of configuring in-band management access via a L3OUT for which you have described in your blog, it will be great Please do reply and share the video if you can.
Unfortunately, I don't have any videos. I have several that I'd like to do, perhaps I'll get time one day.
I hope this helps
RedNectar
aka Chris Welsh
02-09-2018 05:53 AM
Hello Chris,
I'm a bit stuck in the L3out situation. At the end, I am able to ping all the switches from via the L3out (which is located in the common:default in my case) but I cannot reach the APIC's.
I can reach the APIC's if I login to the Leaf switches and even via a VM inside the ACI fabric. So all seems fine, except L3outside to the APIC's.
I'm using SVI on the L3out, and the subnet is redistributed into EIGRP. I verified that it is visible on the outside networks.
Do you have any clue what I am missing?
regards
Michel
02-09-2018 11:47 AM
Hi Michel,
I'm not soo sure what your problem is. The only thing that springs to mind quickly is to check that you have set the APIC's managment preference to inband via:
Fabric > Fabric Policies > Global Policies > Connectivity Preferences
However, be careful doing this - it is possible to loose all connectivity with the APIC once this has been set to inband (if your L3 out is not set up correctly)
02-09-2018 11:53 AM
Hello Chris,
Thanks for your prompt reply. I have changed that option, and I can reach for example vCenter via inband to an EPG inside the Fabric. It's a strange issue, because I can reach all switches on the inband mgmt IP address from outside the Fabric, except for the APIC's
I'm probably going to open a TAC case on Monday, let see what they have to say. I'll let you know what the outcome is
Thanks again
Michel
02-09-2018 06:58 AM
Hello Chris,
I'm a bit stuck in the L3out situation. At the end, I am able to ping all the switches from via the L3out (which is located in the common:default in my case) but I cannot reach the APIC's.
I can reach the APIC's if I login to the Leaf switches and even via a VM inside the ACI fabric. So all seems fine, except L3outside to the APIC's.
I'm using SVI on the L3out, and the subnet is redistributed into EIGRP. I verified that it is visible on the outside networks.
Do you have any clue what I am missing?
regards
Michel
05-12-2022 02:01 PM
Were you able to resolve the issue of not being able to ping the APIC in-band IPs from outside the fabric while all the other switches are reachable?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide