cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1185
Views
0
Helpful
9
Replies

Query on L2 EPG out

sateeshk10
Level 1
Level 1

Hi,

Layer3 vlan configured on switch and my fex are connected to leaf nad server connected fex port X

SWITCH(layer3 configured) -vpc- LEAF - pc - FEX - serve. 

Example:

L3 vlan on switch - 100

i have configured VPC between switch and leaf, configured static bindings in EPG pointing to VPC and encap as 100 off couse, my vlan pool range configured (90-100) in ACI and mapped to physical domain.

I have integrated fex with leaf (port-channel), now the question is..

1) Do i need to create a VLAN pool for this server? and create a physical dom and map it to separate AEP?? or directly in EPG do the static binding to Port-channel(connected to FEX) and give encap - 100?

Thanks

kumar

9 Replies 9

dpita
Cisco Employee
Cisco Employee

Hello

thanks for using support forums!

Thats a good question! If the server is to also be in VLAN-100, i would probably use the same pool but create a new domain for the server instead of using the domain you created for the external switch. I think it helps to separate and categorize things. 

That being said, technically you will be able to just add the static binding to vlan-100 on the port where the server is connected and from access policies, you can configure the server but just tie the new AAEP to the existing domain which will then use the existing vlan pool. 

there are definitely options depending on the level of organization or reusability you wish to get into!

hope that helps! what other questions do you have?

Thanks for your immediate response, here are couple of queries.

1) I have created port-channel for fex, assume need to map this new  server-AEP which we have created for server?

2) if so, can we do the static bindings to fex port-channel in EPG with encap-100 instead of port? so that you  all the servers  will get the access connected to this fex if we go with port by port need lot of static bindings ?

3) Do i need to create a access policy for server access port and map server-AEP again here also?

Finally, will have two static bindings and two physical domain in EPG- static bindings

    - one with switches (VPC)  encap - 100

    - Second one for server with encap-10

  EPG- Domain:

     - switch physical domain

    - Server physical domain.

    

Thanks in advance..

Regards

Kumar

Hello

i think i need to clarify little. did you create the end host vPC FEX configuration? or did you connect the FEX to the leaf and configure a FEX?

1)use the fexP profile in the access policies to configure the ports where the servers are connected on the FEX. once the port is specified then the interface policy group can be configured. the interface policy group is what contains the relationship to the AEP

2)you use the fex path for the static binding. for example, something like 101/111/1/25. yes you will need to go port by port. 

3)i think this question is answered by my answer to number 1.

4)that seems like a valid config. one EPG with two domains and two static bindings. should not be a problem. 

hope that helps! 

Hi,

I appreciate ur quick help, i understood the EPG stuff  whats needs be done ..

As i mentioned earlier, Here is the my connectivity.

SWITCH(layer3 configured) -vpc- LEAF - port-channel - FEX  - accessport -server.

Here are next steps, if i am not wrong please correct me.

1) Between leaf and FEX used one AEP , same AEP can be used for FEX and server?

2) you use the fex path for the static binding. for example, something like 101/111/1/25. yes you will need to go port by port---> lets`s assume i have 10 ports configured same VLAN-100, need to bind all 10 ports(fex101/1/1-10 ) one by one? instead can i map the port-channel configured between( leaf and fex)? 

Regards

Kumar

Hello

1)Don't think you can use the same AEP. I'm not even positive if there is an AEP for the Leaf to FEX policies. You need a specific AEP for the ports where the server will be connected on the FEX

2)You need to do them one by one. Even if the port-channel is available for a static path you should not do that, i would file a bug if the FEX port-channel is available for configuration, that shouldn't be allowed. 

You wouldn't configure the port-channel for a FEX in a traditional Nexus/FEX topology would you? Its pretty much just create the port-channel, configure "switch port mode fex", "fex associate 101" and let it discover the FEX. Why would it be any different in ACI? =)

Cheers,

Daneil

Hi, 

I have done the similar way but unable to ping my gateway which sits on L3 switch,

here are the steps

1) created physical domain and pool (90-120) and created a policies for switches and mapped to switch-AEP

2) created VPC for my L3 switches and showing up on both the ends

3) created physical domain with same pool (90-120) and created a policies for switches and mapped to server-AEP

4) created static binding in epg  pointing to VPC with encap-100

5) created static binding pointing to server interface 100/1/X with encap -100

6) Added two physical domain in EPG

6) Able to see end host mac address in EPG for server as well.

If you have any troubleshooting steps please let me know.

Thanks

Kumar

On the Bridge Domain which both EPGs belong to change the L2 Unknown Unicast mode from HW Proxy to Flood mode. ARP Flooding should also be enabled with this feature.

http://www.cisco.com/c/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/white-paper-c11-731960.html

Robert

Hi,

Here are current settings on BD.

L2 unicast - FLOOD

L3 unknown multicast flooding - FLOOD

ARP flooding enabled

Multicast destination flooding - FLOOD IN BD

One more thing, application profile health is  showing 98% if add the physical domain which i have configured separatly for server(also showing all end hosts in EPG - Client end hosts(switches and server MAC add)  and if  i remove physical domain it showing (created for server ) showing 100% but not  showing server end host MAC address.

Regards

kumar

Hard to tell without looking into it but if they are in the same EPG it should be ok. It is worrisome that you have some faults and your health score goes down. could you possibly provide the following output when the EPG has both domains and both static paths configured?

-show endpoint (from the leaf)

-show vlan ex (from the leaf)

-show vpc (from the leaf)

also, please look around for faults on that EPG when the score is 98. 

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License