cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1962
Views
0
Helpful
3
Replies

LAB Setup Requirement for ACI

NDP
Level 1
Level 1

Could someone confirm if We have only one leaf used for required testing ( ACI Lab), Will there be any challenges

I was going through an article and understood that Leaf switch has some limitation on Normalization process to differentiate the VxLAN IDs for different EPGs.

Please advise me if One leaf is enough for all testing or should We need two leaf switches minimum. 

Thanks in advance

1 Accepted Solution

Accepted Solutions

Durga,

Now I understand where you are coming from.

As I said before, when ACI normalizes a VLAN/VXLAN, it maps it to an internal VLAN.  By default, VLAN-30 will map to the same VLAN across the switch - and in version 1.0 code you were stuck with this, and indeed you would not have been able to do what you are suggesting.

However, somewhere around v1.2 (can't remember when), Cisco introduced a feature commonly referred to as Per Port VLAN (I wrote about why I needed to use it here) which overcomes the problem, but it does mean that in you situation, you will have to make sure that the Interface Policy Group (in your case, if the ESXi hosts are single attached, this will be an Access Port Policy Group) has the poorly named L2 Interface Policy set, and that the said L2 Interface Policy has been configured for Port Local Scope as shown below.  You'll have to watch out for a couple of other things too, like ensuring you use two different VLAN Pools, but I've covered all that in the article I referred to earlier.

perportVLAN

HTH

RedNectar
aka ChrisWelsh


Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

View solution in original post

3 Replies 3

RedNectar
VIP
VIP

For basic concept testing, the minimum lab you could deploy is one leaf, one spine and one APIC.

But if you want to explore a little deeper, you would want to expand to two leaves, and if you want to use it in production the minimum supported configuration would include two spines, two leaves and three APICs.

But I'm curious as to the "limitation on Normalization"  you referred to.  

Normailization is the process of mapping external encapsulations (VLAN or VXLAN) to internal VLANs.  Each leaf switch has over 4000 VLANs available, so is that the limitation you were referring to?  If so, do you see this as being a problem?  Remember that every leaf switch does it's own mapping, so if you add a second leaf switch, that switch starts afresh with its own 4000+ VLANs, which should be sufficient in a Data Centre environment.

If you could share a link to the article, I'd be curious to read it!

RedNectar

aka Chris Welsh

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Hi Chris,

I forgot the URL but I read that the following is not possible 

ESXi A host connected to port 1/3 on leaf101

ESXi B host connected to port 1/4 on leaf101

if

(1) We wanted to map VLAN-30 tagged on port 1/3 to EPG APP and 

(2) wanted to map VLAN-30 tagged on port 1/4 to EPG WEB

I heard that the above was not possible on same leaf. But, This can be done with the help of different leaf. Please correct me If I am wrong.

Would like to hear those type of challenges if any with Single Leaf

Durga,

Now I understand where you are coming from.

As I said before, when ACI normalizes a VLAN/VXLAN, it maps it to an internal VLAN.  By default, VLAN-30 will map to the same VLAN across the switch - and in version 1.0 code you were stuck with this, and indeed you would not have been able to do what you are suggesting.

However, somewhere around v1.2 (can't remember when), Cisco introduced a feature commonly referred to as Per Port VLAN (I wrote about why I needed to use it here) which overcomes the problem, but it does mean that in you situation, you will have to make sure that the Interface Policy Group (in your case, if the ESXi hosts are single attached, this will be an Access Port Policy Group) has the poorly named L2 Interface Policy set, and that the said L2 Interface Policy has been configured for Port Local Scope as shown below.  You'll have to watch out for a couple of other things too, like ensuring you use two different VLAN Pools, but I've covered all that in the article I referred to earlier.

perportVLAN

HTH

RedNectar
aka ChrisWelsh


Don't forget to mark answers as correct if it solves your problem. This helps others find the correct answer if they search for the same problem

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License