cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
294
Views
1
Helpful
2
Replies

Inter-Fabric Messaging (IFM)

config
Level 1
Level 1

Hi community,

ACI fabric uses SSL certificate to establish SSL session between APIC and Leafs/Spines. But these SSL certificates have an expiration date.  I'm going to change fabrick-security-mode from strict to permissive, in order to switches can communicate with APIC without SSL connections. Can i do this while my fabric is running? Will this change not destruct my fabric? 

 

1 Accepted Solution

Accepted Solutions

AshSe
VIP
VIP

Hello @config 

Yes, you can change the fabric-security-mode from strict to permissive while your ACI fabric is running, and it will not disrupt your fabric. However, it is a temporary workaround, and you should address the underlying certificate issue and revert to strict mode as soon as possible to maintain the security of your ACI fabric.

 

Hope This Helps!!!

AshSe

Forum Tips: 

  1. Insert photos/images inline - don't attach.
  2. Always mark helpful and correct answers, it helps others find what they need.
  3. For a prompt reply, kindly tag @name. An email will be automatically sent to the member.

View solution in original post

2 Replies 2

AshSe
VIP
VIP

Hello @config 

Yes, you can change the fabric-security-mode from strict to permissive while your ACI fabric is running, and it will not disrupt your fabric. However, it is a temporary workaround, and you should address the underlying certificate issue and revert to strict mode as soon as possible to maintain the security of your ACI fabric.

 

Hope This Helps!!!

AshSe

Forum Tips: 

  1. Insert photos/images inline - don't attach.
  2. Always mark helpful and correct answers, it helps others find what they need.
  3. For a prompt reply, kindly tag @name. An email will be automatically sent to the member.

@AshSe thanks a lot for you help!)

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License