01-29-2025 10:29 AM
Hi community,
ACI fabric uses SSL certificate to establish SSL session between APIC and Leafs/Spines. But these SSL certificates have an expiration date. I'm going to change fabrick-security-mode from strict to permissive, in order to switches can communicate with APIC without SSL connections. Can i do this while my fabric is running? Will this change not destruct my fabric?
Solved! Go to Solution.
01-29-2025 11:08 PM
Hello @config
Yes, you can change the fabric-security-mode
from strict
to permissive
while your ACI fabric is running, and it will not disrupt your fabric. However, it is a temporary workaround, and you should address the underlying certificate issue and revert to strict
mode as soon as possible to maintain the security of your ACI fabric.
Hope This Helps!!!
AshSe
Forum Tips:
01-29-2025 11:08 PM
Hello @config
Yes, you can change the fabric-security-mode
from strict
to permissive
while your ACI fabric is running, and it will not disrupt your fabric. However, it is a temporary workaround, and you should address the underlying certificate issue and revert to strict
mode as soon as possible to maintain the security of your ACI fabric.
Hope This Helps!!!
AshSe
Forum Tips:
01-29-2025 11:39 PM
@AshSe thanks a lot for you help!)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide